Avatar
Gonçalo Valério
c1f508d6095df2f21aad0aa196584a9cb74f804fe8e181daf205ecdc9a74b700
Full-stack developer with special interest in cybersecurity. Advocate of a free and safe Internet. Nature admirer and sports enthusiast.

"Google will now only release Android source code twice a year"

https://www.androidauthority.com/aosp-source-code-schedule-3630018/

And kids, this is just another example of why we need a viable alternative to the existing duopoly.

#android #google #mobile #os #opensource

"Bye Bye Big Tech: How I Migrated to an almost All-EU Stack (and saved 500€ per year)"

https://www.zeitgeistofbytes.com/p/bye-bye-big-tech-how-i-migrated-to

#buyfromeu

"MongoBleed explained simply"

https://bigdata.2minutestreaming.com/p/mongobleed-explained-simply

#security #infosec #netsec #mongodb

"Merry Christmas Day! Have a MongoDB security incident."

https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb

#security #infosec #netsec #mongodb

"NPM Package With 56K Downloads Caught Stealing WhatsApp Messages"

https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages

#security #infosec #nodejs #npm

"Over 10,000 Docker Hub images found leaking credentials, auth keys"

https://www.bleepingcomputer.com/news/security/over-10-000-docker-hub-images-found-leaking-credentials-auth-keys/

#security #infosec #dockerhub

More app recommendations

The good part of having a personal blog is that I can write about whatever comes to my mind. Today I was thinking of how people find the software they use, how many people end up using the same apps because they don’t know any alternatives, and the fact that many creators (especially open-source ones) deserve more recognition.

Over the years I already shared some of the software I use, and I’m […]

https://blog.ovalerio.net/archives/3212

#apps #software #Technology #tools

"GitHub Actions Has a Package Manager, and It Might Be the Worst"

https://nesbitt.io/2025/12/06/github-actions-package-manager.html

#github #githubactions #security #supplychain

Fairphone open-sources Fairphone 5 and 6 software, and Moments switch

https://www.fairphone.com/en/2025/12/04/were-big-fans-of-open-source-buildable-code-at-fairphone-heres-why/

💪 Nice

#fairphone #mobile #eualternatives #opensource

"When Password FieldsAren’t Enough – Client-Side SecretExposure in PagerDuty Cloud Runbook"

https://www.praetorian.com/blog/cve-2025-52493-when-password-fieldsarent-enough-client-side-secretexposure-in-pagerduty-cloud-runbook/

#security #cybersecurity #infosec

"Critical Security Vulnerability in React Server Components"

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

#security #infosec #netsec #reaxtjs #javascript #npm

"Django security releases issued: 5.2.9, 5.1.15, and 4.2.27"

https://www.djangoproject.com/weblog/2025/dec/02/security-releases/

* CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL

* CVE-2025-64460: Potential denial-of-service vulnerability in XML serializer text extraction

#python #django #security

"Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours"

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24

#security #infosec #supplychain #cybersecurity #nodejs #npm

"The privacy nightmare of browser fingerprinting"

https://kevinboone.me/fingerprinting.html

#privacy #web

"Yes, Steam Machine is optimized for gaming, but it's still your PC. Install your own apps, or even another operating system. Who are we to tell you how to use your computer?"

👏 👏 👏

A breath of fresh air… given the current status of the industry.

#steam #steammachine

"sudo-rs Affected By Multiple Security Vulnerabilities - Impacting Ubuntu 25.10"

https://www.phoronix.com/news/sudo-rs-security-ubuntu-25.10

#security #infosec #ubuntu #sudors

"Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault"

https://cyata.ai/blog/cracking-the-vault-how-we-found-zero-day-flaws-in-authentication-identity-and-authorization-in-hashicorp-vault/

#security #cybersecurity #infosec #hashicorp #vault