Bookmarks

Bookmarks

46225 bookmarks
Custom sorting
Marshal madness: A brief history of Ruby deserialization exploits
Marshal madness: A brief history of Ruby deserialization exploits
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
·blog.trailofbits.com·
Marshal madness: A brief history of Ruby deserialization exploits
Unlocking Ractors: generic instance variables
Unlocking Ractors: generic instance variables
In two previous posts, I explained that one of the big blockers for Ractors’ viability is that while they’re supposed to run fully in parallel, in many cases, they’d perform worse than a single thread because there were numerous codepaths in the Ruby virtual machine and runtime that were still protected by the global VM lock.
·byroot.github.io·
Unlocking Ractors: generic instance variables
How Incorrect Shopify Webhook Parsing Led to Complete Database Deletion
How Incorrect Shopify Webhook Parsing Led to Complete Database Deletion
A detailed analysis of a critical security incident where improper payload parsing in a Shopify webhook handler resulted in complete database deletion, and the lessons learned for preventing similar issues.
·ingressr.com·
How Incorrect Shopify Webhook Parsing Led to Complete Database Deletion
AI Gateway is now generally available - Vercel
AI Gateway is now generally available - Vercel
AI Gateway is now generally available, providing a single interface to access hundreds of AI models with transparent pricing and built-in observability.
·vercel.com·
AI Gateway is now generally available - Vercel
Intro | Code Web Chat
Intro | Code Web Chat
Designed for software engineers, a 100% free and open-source tool for AI-assisted pair programming. With its simple, non-agentic approach, CWC provides unmatched accuracy, speed and cost efficiency. Built by an independent developer for VS Code and its derivatives (Cursor, Windsurf, VSCodium, etc.).
·codeweb.chat·
Intro | Code Web Chat
ruvnet/claude-flow: Claude-Flow v2.0.0 Alpha represents a leap in AI-powered development orchestration. Built from the ground up with enterprise-grade architecture, advanced swarm intelligence, and seamless Claude Code integration.
ruvnet/claude-flow: Claude-Flow v2.0.0 Alpha represents a leap in AI-powered development orchestration. Built from the ground up with enterprise-grade architecture, advanced swarm intelligence, and seamless Claude Code integration.
Claude-Flow v2.0.0 Alpha represents a leap in AI-powered development orchestration. Built from the ground up with enterprise-grade architecture, advanced swarm intelligence, and seamless Claude Cod...
·github.com·
ruvnet/claude-flow: Claude-Flow v2.0.0 Alpha represents a leap in AI-powered development orchestration. Built from the ground up with enterprise-grade architecture, advanced swarm intelligence, and seamless Claude Code integration.
DoneDeal0/codefather: Codefather protects your codebase by controlling who can change what. Set authorization levels, lock down files, and enforce your rules—offline via CLI or online with GitHub Actions.
DoneDeal0/codefather: Codefather protects your codebase by controlling who can change what. Set authorization levels, lock down files, and enforce your rules—offline via CLI or online with GitHub Actions.
Codefather protects your codebase by controlling who can change what. Set authorization levels, lock down files, and enforce your rules—offline via CLI or online with GitHub Actions. - DoneDeal0/co...
·github.com·
DoneDeal0/codefather: Codefather protects your codebase by controlling who can change what. Set authorization levels, lock down files, and enforce your rules—offline via CLI or online with GitHub Actions.
Hyprnote: Private, Local-First AI Notetaker for Secure Meetings
Hyprnote: Private, Local-First AI Notetaker for Secure Meetings
Hyprnote is an open-source AI notetaker built for compliance and privacy. Take and organize meeting notes entirely on your device with no data leaving your control. Imagine Granola AI, but runs all locally on your device.
·hyprnote.com·
Hyprnote: Private, Local-First AI Notetaker for Secure Meetings