Avatar
Gonçalo Valério
c1f508d6095df2f21aad0aa196584a9cb74f804fe8e181daf205ecdc9a74b700
Full-stack developer with special interest in cybersecurity. Advocate of a free and safe Internet. Nature admirer and sports enthusiast.

"Admins wonder if the cloud was such a good idea after all"

https://www.theregister.com/2024/09/04/cloud_buyers_regret/

Some valid points here: https://news.ycombinator.com/item?id=41444966

#cloud

"Unprotected container registries"

https://dreher.in/blog/unprotected-container-registries

#docker #containers #security #infosec #netsec #cybersecurity #supplychain

"Django security releases issued: 5.1.1, 5.0.9, and 4.2.16"

https://www.djangoproject.com/weblog/2024/sep/03/security-releases/

* Potential denial-of-service vulnerability in django.utils.html.urlize()

* Potential user email enumeration via response status on password reset

#python #django #security

"How some Let's Encrypt renewal failures pointed to an AWS traffic hijacking issue"

https://chair6.net/lets-encrypt-renewal-failures-and-aws-traffic-hijacking.html

#security #netsec #aws

"Practices of Reliable Software Design"

https://two-wrongs.com/practices-of-reliable-software-design

#softwaredevelopment #programming #dev

"Bypassing airport security via SQL injection"

https://ian.sh/tsa

#security #cybersec #cybersecurity #sqli #web

"Open source templates you can use to bootstrap your security programs"

https://www.sectemplates.com/

#security #cybersecurity #cybersec

"European alternatives for digital products"

"We help you find European alternatives for digital service and products, like cloud services and SaaS products."

https://european-alternatives.eu

Unfortunately, in the couple of categories I was seeking alternatives, the ones listed here weren't good enough or valid alternatives at all.

Perhaps some will work for you.

#cloud #technology #europe #eu

#digitalsovereignty

"Django: create sub-commands within a management command"

https://adamj.eu/tech/2024/08/14/django-management-command-sub-commands/

#python #django

"Django: create sub-commands within a management command"

https://adamj.eu/tech/2024/08/14/django-management-command-sub-commands/

#python #django

"CPython: CVE-2024-8088: Infinite loop when iterating over zip archive entry names"

https://seclists.org/oss-sec/2024/q3/229

#python #security

“No "Hello", No "Quick Call", and no Meetings Without an Agenda”

https://switowski.com/blog/no-hello-no-quick-call-no-agendaless-meetings/

The tone is a bit off, but the tips are good.

#remote #remotework #workasync

"MIT leaders describe the experience of not renewing its largest journal contract as overwhelmingly positive."

https://sparcopen.org/our-work/big-deal-knowledge-base/unbundling-profiles/mit-libraries/

#openaccess #research #academicjournals

"Understanding AWS Networking: A Guide for Network Engineers"

https://www.robertdemeyer.com/post/understanding-aws-networking-a-guide-for-network-engineers

#aws #networking #cloud

"Micro-libraries need to die already"

https://bvisness.me/microlibraries/

Not sure if the examples used are the best ones, but I do think the author has a point.

#softwaredevelopment #programming #dev #webdev

"Mitigating Attack Vectors in GitHub Workflows"

https://openssf.org/blog/2024/08/12/mitigating-attack-vectors-in-github-workflows/

#security #github #githubactions

Tip: Search and go through the documentation of your software development tools in a single place.

https://devdocs.io/

#programming #dev #webdev #softwaredevelopment

"Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources"

https://www.aquasec.com/blog/bucket-monopoly-breaching-aws-accounts-through-shadow-resources/

#aws #security #cloudsec #infosec