Sign in

Clara Leigh

@clara42.bsky.social
1.6K followers 877 following 275 posts

Laravel, VueJS, Cyber Security 🌈

PostsRepliesMedia
Reposted by Clara Leigh
💜 phonakins 🍉🌲 @phonakins.com · 27/07/2026
"There were metal shavings found in bread products … products that were supposed to be dairy-free, that were not dairy-free, [which] were only caught by accident because somebody happened to put it together after their child or they themselves got sick, not because the company had worked it out."
abc.net.au
Horse meat has been sold as minced beef or lamb in Australia, documents show
Government documents show hundreds of businesses operating in Australia have breached food safety laws, with one politician warning "you could be eating a minced horse".
031
Clara Leigh @clara42.bsky.social · 30/04/2026
This is the coolest exploit I've seen on linux for a little while: copy.fail
copy.fail
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
000
Reposted by Clara Leigh
Guardian Australia @australia.theguardian.com · 21/04/2026
Labor under internal pressure on gas tax as influencer says government ‘stopped working for the punters’
theguardian.com
Labor under internal pressure on gas tax as influencer says government ‘stopped working for the punters’
Party’s environment action network tells parliamentary inquiry into gas export tax to consider ‘very substantial’ levy on windfall profits * Follow our Australia news live blog for latest updates * Get our breaking news email, free app or daily news podcast The Albanese government is facing internal pressure to raise taxes on gas companies as a prominent social media influencer warns Labor not to underestimate the scale of public outrage about the existing regime. Labor’s environment action network (LEAN) used evidence to a parliamentary inquiry into the tax settings for the gas sector to encourage the government to consider a “very substantial tax” on windfall profits. Continue reading...
46417
Clara Leigh @clara42.bsky.social · 12/03/2026
My first #PigeonSky post!!! 🪶 The pigeons where just minding their business and then the magpie came in and gave them a big scare
Two pigeons being scared by a bossy magpie
061
Reposted by Clara Leigh
Stephen Rees-Carter @valorin.bsky.social · 25/02/2026
PSA for @statamic.com folks - update your sites ASAP! ⚠️ A CRITICAL vuln was discovered that allows full account takeover via password resets! 😱 All the details: cvereports.com/reports/CVE-...
github.com
CVE-2026-27593 - GitHub Advisory Database
Statamic is vulnerable to account takeover via password reset link injection
096
Clara Leigh @clara42.bsky.social · 18/02/2026
Shipping spaghetti is still shipping 😭
020
Clara Leigh @clara42.bsky.social · 18/02/2026
Tip I leaned today: Disable networking on your GH Action Tests Even if you block it in code, things could still leak
GitHub Action with the text:
        name: Run tests without networking
        run: |
          sudo unshare --net -- bash -lc '
            ip link set lo up
            php artisan test --exclude-group manual --parallel
          '
000
Clara Leigh @clara42.bsky.social · 13/02/2026
Anyone else's PHP github actions suddenly taking an insane time to complete? Mine are taking 20mins-1hr and I cannot replicate any problem on local or even brand new machines setup
100
Clara Leigh @clara42.bsky.social · 19/01/2026
kinda neat, I saw something else recently but in a code that compiles code that compiles other code nesting egg
010
Reposted by Clara Leigh
Larabelles @larabelles.com · 13/01/2026
We have another giveaway: a ticket to Laracon India 🎉. Since this is a last-minute giveaway, it is only open to people already basedin Ahmedabad, India, and it's only open until January 17th, 2026. Retweet/share for reach, and enter via our website, link below ⬇️.
146
Reposted by Clara Leigh
Patrick C Miller @patrickcmiller.bsky.social · 10/01/2026
Why governments need to treat fraud like cyberwarfare, not customer service cyberscoop.com/industrializ...
cyberscoop.com
Why governments need to treat fraud like cyberwarfare, not customer service
Fraud has become industrialized and weaponized by syndicates and hostile states. This op-ed argues it’s a global security threat and outlines a new US-UK-backed public-private task force to fight it.
021
Reposted by Clara Leigh
maia arson crimew 🏴 @crimew.gay · 27/12/2025
gpg.fail
724861
Clara Leigh @clara42.bsky.social · 24/12/2025
There should be a “same product, same features” law If a country forces a company to have better privacy options or allow third party app stores or whatever it might be, you should be forced to offer that same feature here in Australia
020
Clara Leigh @clara42.bsky.social · 12/12/2025
Reminder folks, chatgpt is designed to agree with you and "solve" issues so it rarely tells you that you're misunderstanding things. It will absolutely mislead you or say its found the issue when really it's just giving its best guess Getting tired of seeing low quality github issues hey
251
Clara Leigh @clara42.bsky.social · 04/12/2025
Stay safe friends
231
Clara Leigh @clara42.bsky.social · 01/12/2025
My favourite part of the city is the KP cliffs. Absolutely stunning views 😍 Whenever I need time to myself, this is where I go
View of Brisbane city at night
040
Clara Leigh @clara42.bsky.social · 04/11/2025
I wrote a research paper on this topic just last month This issue is entirely preventable. The only reason we keep seeing this style of attack is because our industry keeps repeating the same mistakes over and over again 😔
150
Reposted by Clara Leigh
Joe Tannenbaum @joe.codes · 04/11/2025
Whoa this is stunning
061
Clara Leigh @clara42.bsky.social · 27/10/2025
✨Microsoft security✨
000
Reposted by Clara Leigh
DESIGN THINKING! Comic @designthinking.lol · 20/10/2025
With the AWS outage, now‘s as good a time as any to post this old strip.
1526451043
Clara Leigh @clara42.bsky.social · 09/10/2025
Working on Crypto in the #laravel world? Hit me up, I want to see what you're doing! I've got solana stablecoin p2p, offramps to banks and more going on over here 😍
010
Clara Leigh @clara42.bsky.social · 05/10/2025
Once upon a time, USBs and CDs could auto run. That’s how worms like stuxnet and Agent.BTZ spread everywhere We learned the hard way and killed autorun Now we `npm install` 1,000 different dependencies from the internet and consider it “safe”, forgetting that it does the exact same thing
050
Reposted by Clara Leigh
Joe Tannenbaum @joe.codes · 30/09/2025
Curious what it looks like to implement the new Inertia Infinite Scroll component? Have 3 minutes? That's all it takes. I whipped up a little demo: youtu.be/gQB6DdPHzSY
youtu.be
Infinite Scrolling with Laravel + Inertia
YouTube video by Laravel
1218
Clara Leigh @clara42.bsky.social · 30/09/2025
Is username enumeration (UE) a real vulnerability? Yes, and it matters more today than it did a few years ago. As phishing attacks look more legitimate, even smart people are getting tricked This week I saw a UE+phish lead to an account take over, and the URL in the Phish was a legitimate url
220
Clara Leigh @clara42.bsky.social · 28/09/2025
If there is one thing I've learned in the last year, it's never use a property named "type" I have lost so many hours debugging this exact bug but alas I am a goldfish just did it again, for the third time this week 😭
160
Clara Leigh @clara42.bsky.social · 26/09/2025
This would have saved me a few hours making some things GDPR compliant!
141
Clara Leigh @clara42.bsky.social · 23/09/2025
“Think like a hacker” is one of my favourite phrases It leads to the zero trust mindset. Assume a breach will happen and brainstorm what you can do to reduce that risk Short liven tokens are just one thing that can help. I encourage you to research OIDC tokens, it might just save you one day
040
Clara Leigh @clara42.bsky.social · 23/09/2025
I love a community that listens! Securing the supply chain is my current research topic and the more I learn, the more I find we can do
1101
Reposted by Clara Leigh
Packagist @packagist.com · 20/09/2025
🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc
02540
Clara Leigh @clara42.bsky.social · 21/09/2025
Today I leaned about OIDC tokens and how you can use them to prevent GitHub actions from having access to long lived secrets (like AWS) While its not yet supported by my main provider, I can certainly clean up my AWS actions and hope others add it to their roadmap 🙏 docs.github.com/en/enterpris...
docs.github.com
OpenID Connect - GitHub Enterprise Cloud Docs
OpenID Connect allows your workflows to exchange short-lived tokens directly from your cloud provider.
110
Clara Leigh @clara42.bsky.social · 20/09/2025
Today I learned about NPM Provenance, and how it helps prevent some supply chain attacks but it turns out its widely un-used and even some orgs don't use it yet (looking at you @laravel.com) If you run any NPM repo at all, you should look at implementing it! docs.npmjs.com/generating-p...
docs.npmjs.com
Generating provenance statements | npm Docs
Documentation for the npm registry, website, and command-line interface
151
Clara Leigh @clara42.bsky.social · 18/09/2025
Best game I've played in a while, if you have an hour or so to loose
010
Clara Leigh @clara42.bsky.social · 18/09/2025
In the past month, I've noticed a huge decrease in quality of code produced by AI. Coincidentally in the past month, I've also seen a huge jump in external providers shipping broken features and updates 🤔
010
Clara Leigh @clara42.bsky.social · 17/09/2025
Another day, another supply chain attack. Stay safe out there www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Self-propagating supply chain attack hits 187 npm packages
Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the comprom...
040
Clara Leigh @clara42.bsky.social · 15/09/2025
This week I solved a really hard coding problem which is going to save me about 2hrs a day. I initially thought it would be impossible, but ~100 lines of regex and ~50 if() statements has solved it! I’m going to be riding the high from this feat for a while 🥰
060
Clara Leigh @clara42.bsky.social · 05/09/2025
I wish I knew about this laravel helper function earlier 😍
Alt text: Laravel docs screenshot for `Str::headline()`. It explains that the method converts strings separated by casing, hyphens, or underscores into space delimited title case. The PHP example shows:

```php
use Illuminate\Support\Str;

$headline = Str::headline('steve_jobs');        // Steve Jobs
$headline = Str::headline('EmailNotificationSent'); // Email Notification Sent
```
010
Clara Leigh @clara42.bsky.social · 05/09/2025
I need a tool that lets me easily share code snippets, but also it’ll have auto ai conversions to other code languages, but you can step in and clean it up when it’s not quite right
000
Clara Leigh @clara42.bsky.social · 04/09/2025
My niece is an amazing young lady who loves helping others Her absent prick of a father tried to stop her volunteering with a special school over in Malaysia but she won in court! If you have some spare change, pls consider supporting her great work gofundme.com/f/klang-special-school-in-malaysia
gofundme.com
Donate to A Journey to Empower Special Kids – Your Support Matters, organized by Millie Wilson
Wow, I just want to say a huge thank you to everyone who has do… Millie Wilson needs your support for A Journey to Empower Special Kids – Your Support Matters
000
Clara Leigh @clara42.bsky.social · 03/09/2025
Some of y'all still need to do this! I just found a site running the vulnerable version of livewire. Update now fools!
061
Reposted by Clara Leigh
Larabelles @larabelles.com · 02/09/2025
We just added a whole lot of new profiles to the Larabelles directory. 83 in total right now! 🎉 Go and learn about some of our incredible members. We all come from different paths of life, have different interests and stories, but together we are making the tech industry better. 💪
292
Clara Leigh @clara42.bsky.social · 28/08/2025
The feast was a success 🔥
The work team having an American bbq feast
050
Clara Leigh @clara42.bsky.social · 27/08/2025
Being fully WFH, I find it harder to socialise with my workmates. So today I’m inviting them over to my house for an American style bbq feast 🤤 Ribs, beans, mac n cheese, cornbread, coleslaw, veggie kebabs (w halloumi, cherry tom, capsicum, mushroom, red onion, zucchini)
Pictured: Ribs, beans, mac n cheese, cornbread, coleslaw, veggie kebabs (w halloumi, cherry tom, capsicum, mushroom, red onion, zucchini)
290
Clara Leigh @clara42.bsky.social · 26/08/2025
Clickbait articles that never answer their own headline should be open to takedown requests on Google 😤
020
Clara Leigh @clara42.bsky.social · 25/08/2025
Do you ever repost something then totally forget about it? I find myself finding cool tips in my own timeline. Having worked with laravel for over a decade, I often forget the neat little helper functions that've been created along the way
130
Clara Leigh @clara42.bsky.social · 17/08/2025
What really grinds my gears is Saas products built for companies that will cut you off instantly when billing fails Please, I will give you the money, just give me one working day to fix it. Don’t make me login on a Sunday while I’m out with family to fix a work project 😫
110
Reposted by Clara Leigh
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/08/2025
🎥 Missed one of my past conference talks? Let’s fix that. I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs. “Security is Everybody’s Job” 📽️ twp.ai/9PUtHm #CyberSecurity #SecurityAwareness #appsec #devops #devsecops
twp.ai
www.youtube.com
June 2019 - Tanya Janca - Security is Everyone's Job
051
Reposted by Clara Leigh
BSides Canberra @bsidescbr.bsky.social · 11/08/2025
Only 3 days left to apply for the BSides Canberra 2025 Assistance Program! If you’re based in Australia or NZ, over 18, and facing financial barriers to attending, now’s the time. Apply here: forms.gle/LtcXQE9Yv2rZ... Applications close 14 August.
forms.gle
BSides Canberra 2025 Assistance Program
BSides Canberra is thrilled to announce the launch of its highly anticipated Financial Assistance Program for the year 2025. This program aims to support individuals facing financial constraints, ensu...
012
Clara Leigh @clara42.bsky.social · 08/08/2025
My GPT 5 first impression is that this is a massive step backwards Completely unusable for anything I’ve thrown at it One simple array had 7 duplicates 🤦🏼‍♀️
120
Clara Leigh @clara42.bsky.social · 07/08/2025
This is your reminder to: `composer audit` and `npm audit` your projects Remember, most breaches come from known vulnerabilities. Save yourself a future headache <3
0185