"Urgent Security Notice re: Your Sentry Organization"
Someone tried to hack Sentry-using apps that use coding agents by
1. Sending a fake bug alert to their project (all you need is the app's public Data Source Name)
2. The fake bug tried tricking a coding agent trying to fix it into installing some a compromised NPM package
3. The compromised package would send the env contents of the machine to advisory-tracker[.]com/api/v1/telemetry
This highlights a crucial thing for using agents in an automated way:
Gave up on Bitwarden before seeing this article, which talks of leadership changes that explains why the implementation is stagnated. BW has problems, such as accessibility issues, missing features, and in light of recent exploits, we need more.
blog.ppb1701.com/the-quiet-r…
🚀 Huge milestone for ApplicationSet UI in Argo CD!
All ApplicationSet UI PRs are now merged and will officially be part of Argo CD v3.5 🎉
A massive thank you to Peter Jiang for leading this amazing effort and pushing the AppSet UI experience forward for the community 👏
One of the latest PRs that landed:
👉 github.com/argoproj/argo-cd/…
Excited to see all of this available in the next release 🚀
J'ai enfin décidé de consolider mes petits bidouillages IETF dans un outil (en @v_language :p). Il ne pouvait pas venir sans sa commande "bortzmeyer" qui ouvre l'article correspondant du blog de @bortzmeyer s'il existe 😅
💥 Introducing "Dirty Frag"
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation.
Details:
dirtyfrag.io
J'ai un test assez long qui dure depuis plus de 10 ans : en mai 2015, j'avais rempli des clés USB et de temps en temps (une fois par an au mieux), je vérifie si les données sont encore là et sans erreurs. Ben j'ai la première erreur depuis 2015.
N'oubliez pas de lire attentivement la manuel utilisateur (user guide) d'Ariane 6, sait on jamais, si vous l'utilisez un jour...
ariane.group/app/uploads/sit…
[Press Release 🗞️]
At the #OBSummit, Orange Business launches Orange Drone Guardian, Europe’s first anti-drone as-a-Service solution.
Read more about this reveal: orange-business.com/en/press…