Containers: Rootful, Rootless, Privileged and Super Privileged – Infosec Adalid

1_r/devopsish
Intrusion detection for containers
The Engineering Blog from Vinted. These are the voyages of code tailors that help create Vinted.
yangshun/tech-interview-handbook: 💯 Curated coding interview preparation materials for busy software engineers
💯 Curated coding interview preparation materials for busy software engineers - yangshun/tech-interview-handbook: 💯 Curated coding interview preparation materials for busy software engineers
Fully Automated Releases for Rust Projects
FOSS • Linux • Programming
Microsoft's great tax battle
The IRS says Microsoft owes $29 billion plus penalties and interest. Now comes the challenge — collecting it.
This Python code uses the Jira API to create a new issue from the last Git commit message. It can be used as a precommit hook to create Jira tickets from Git commit history.
This Python code uses the Jira API to create a new issue from the last Git commit message. It can be used as a precommit hook to create Jira tickets from Git commit history. - jira-precommit.py
Why you should probably be using SQLite
Where you store your application data has enormous impacts on your entire application. There are implications on the entire stack based on what you decide to...
Using Discord Bots for OSINT Investigations
Facial recognition, hash cracking, dark web, Shodan, reverse email address, reverse IP address, reverse username, paste search
live? nah he dead
How to create and set up a virtual environment in Python
Make your Python project a success with the right tools and knowledge
watchOS 10: The MacStories Review
In my watchOS 9 Review last year, I spent the introduction reminiscing on the more exciting days of watchOS yore. Those early years were full of whimsy and foolishness, with many wild and ambitious new features that failed far more often than they succeeded. By my count, it took until watchOS 4 for Apple to
Linux Mint Starts Working On Wayland For Cinnamon, Likely Not Fully Ready Until 2026
Tucked away within the October 2023 monthly status updates for the Linux Mint project is word they have begun working on their Wayland support.
Linux Foundation Adopting Terraform Fork Provokes Ire of HashiCorp CEO
Less than a month after a handful of small companies forked HashiCorp's flagship IaC software, the Linux Foundation swooped in to support the project. This did not sit right with HashiCorp CEO David McJannet.
Announcing managed Arm CI for CNCF projects
Ampere Computing and The Cloud Native Computing Foundation are sponsoring a pilot of actuated's managed Arm CI for CNCF projects.
*cough* Okta Support *cough* |har-sanitizer
Contribute to cloudflare/har-sanitizer development by creating an account on GitHub.
iPhones have been exposing your unique MAC despite Apple’s promises otherwise
“From the get-go, this feature was useless,” researcher says of feature put into iOS 14.
Microsoft CEO Satya Nadella admits giving up on Windows Phone and mobile was a mistake
Nadella, Gates, and Ballmer have all admitted to Microsoft’s mobile mistakes.
Amazon Web Services to Launch AWS European Sovereign Cloud
AWS European Sovereign Cloud will be a new, independent cloud for Europe that gives customers in highly regulated industries and the public sector further choice and flexibility to address evolving data residency and resilience requirements in the European Union (EU)
NetBSD as a Kubernetes Pod - iMil.net
How to create a NetBSD pod running on a Kubernetes cluster
iLeakage
KubeCon NA 2023 Parties – Unofficial list of KubeCon NA Conference and Vendor Parties
Amazon reports better-than-expected results, as revenue jumps 13%
Amazon reported earnings after the bell. Here are the results.
Generate images in one second on your Mac using a latent consistency model
How to run a latent consistency model on your M1 or M2 Mac
Alphabet shares drop as cloud miss overshadows better-than-expected overall results
Alphabet reported earnings after the bell. Here are the results.
Meta’s Reality Labs loses $3.7 billion in third quarter as Zuckerberg's big bet keeps bleeding cash
Mark Zuckerberg's bet on the metaverse has so far been a money-burning endeavor, and the losses keep mounting
Securing the IaC Supply Chain - Jesse Sanford, Autodesk & Jason Hall, Chainguard
Don’t miss out! Join us at our upcoming event: KubeCon + CloudNativeCon Europe 2023 in Amsterdam, The Netherlands from April 17-21. Learn more at https://kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.Securing the IaC Supply Chain - Jesse Sanford, Autodesk & Jason Hall, ChainguardSecure software supply chain practices have begun to permeate all aspects of software development. But what about the orchestration of our infrastructure? With the proliferation of infrastructure as code, many of the same threats posed to software supply chains are also threats to our IaC ecosystems. IaC provides clear advantages to platform teams, bringing uniformity and productivity to developers, but with the great power bestowed to it, it also presents a juicy target for supply chain attacks, often while no one is looking. It's only a matter of time before our Site Reliability Engineers will need to defend against the same attack vectors as their Software Engineer counterparts. How can DevSecOps practitioners learn from the patterns and practices being developed by projects like SLSA? Can IaC pipelines build on tooling like Sigstore and in-toto? This talk covers the application of software supply chain security principles to modern IaC pipelines. Jesse and Jason discuss design changes to the Crossplane package management system and it’s forthcoming integration with Sigstore, enabling IaC provenance and attestations. Finally, a demo showcasing the equivalent of “admission control” for IaC will provide inspiration for further work on Secure IaC Supply Chains.
Introducing the AI Bill of Materials
What’s in the black box? As we go forward we will need a model and machine readable bill of materials. It’s becoming increasingly clear that we’re going to need an AI bill of Materials (AIBOM). Just as with a Software Bill of Materials (SBOM), there are a set of potentially important questions when we take
NASA just patched Voyager 2’s software, sparing Voyager 1
The upgrade might not go well, so prioritized the probe doing better science
Exclusive: Nvidia to make Arm-based PC chips in major new challenge to Intel
Nvidia dominates the market for AI computing chips. Now it is coming after Intel’s longtime stronghold.
Spy vs. spy: How Israelis tried to stop Russia’s information war in Africa
In the two years since an Israelis company first tried to thwart a Russian disinformation campaign in Burkina Faso, coups or rebels have removed the governments of five former French colonies, replacing them with pro-Russia leaders.