Sign in

Matt "msw" Wilson

@msw.bsky.social
790 followers 300 following 210 posts

“For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled.”

PostsRepliesMedia
Matt "msw" Wilson @msw.bsky.social · 25/06/2026
We have just launched Akrites at The Linux Foundation, a coordinated industry effort to harden the world’s most critical open source software in the era of AI-assisted vulnerability discovery. www.linuxfoundation.org/press/linux-...
linuxfoundation.org
Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats
Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats
182
Matt "msw" Wilson @msw.bsky.social · 22/06/2026
Severity is not risk
010
Matt "msw" Wilson @msw.bsky.social · 21/06/2026
mstdn.social/@msw/1167825...
mstdn.social
Matt "msw" Wilson (@msw@mstdn.social)
Sometimes the response to a software defect that is discovered, fixed, and disclosed as a "security vulnerability" has a far worse effect than the defect itself. There was never any indication that t...
010
Matt "msw" Wilson @msw.bsky.social · 17/06/2026
when it comes to addressing newly discovered flaws in your software dependencies (some of which might be classified as "security vulnerabilities") ... pruning > patching That's it. That's the post.
010
Matt "msw" Wilson @msw.bsky.social · 09/06/2026
Personally, I miss the days of Free and Open Source when folks debated if NDAs were compatible (at minimum, in spirit) with the conditions of the GPL. Now, I see the slight possibility of a world where folks rush to share fixes for vulnerabilities in a private club. And if that software is GPL?
150
Matt "msw" Wilson @msw.bsky.social · 21/05/2026
For folks who are thinking about locally patching open-source software to fix what they think is a bug (_especially_ if they think it's a security vulnerability), I think that's a path to www.xkcd.com/424/
xkcd.com
Security Holes
120
Reposted by Matt "msw" Wilson
Cassidy @cassidoo.co · 20/05/2026
Heads up maintainers of packages, this is a big deal: github.com/orgs/communi...
github.com
npm granular access token invalidation to prevent supply chain attacks · community · Discussion #196340
As initially announced on npm’s X channel, we have invalidated granular access tokens with write access that bypass two-factor authentication. This action was taken to help prevent supply chain att...
37424
Matt "msw" Wilson @msw.bsky.social · 19/05/2026
Y'all, AI models seem to be *really good* at triaging vulnerabilities that are discovered with AI tooling! Try this prompt: > read gitlab.gnome.org/GNOME/libxml... and tell me if CVE-2026-6732 applies to github.com/libarchive/l... [...] Conclusion Not affected.
  The Vulnerability
                                                                                                    
  The libxml2 issue (GitLab work item #1097) is a type confusion in xmlParseReference() that occurs exclusively when streaming XSD schema validation is active. The bug passes ctxt (parser context) instead of ctxt->userData to SAX characters() / cdataBlock() callbacks. This only causes a crash when xmlSchemaSAXPlug has redirected those callbacks — meaning schema validation must be enabled on the reader/parser. 

How libarchive uses libxml2

  libarchive uses libxml2 solely for parsing XAR archive table-of-contents XML in archive_read_support_format_xar.c. It uses the xmlTextReader pull-parsing API:                           
  - xmlTextReaderRead()
  - xmlTextReaderNodeType()
  - xmlTextReaderConstLocalName()
  - xmlTextReaderConstValue()
  - xmlTextReaderMoveToFirstAttribute() / MoveToNextAttribute()

  It does not call any schema validation functions:
  - No xmlTextReaderSchemaValidate()
  - No xmlSchemaSAXPlug()                                   
  - No xmlSchemaValidateStream()
  - No xmlSchemaNewValidCtxt()
                                                               
  Conclusion
                                                                                                                         
  Not affected. The vulnerable code path requires XSD streaming validation to be plugged into the SAX layer. libarchive  
  never enables schema validation — it just reads XML nodes from XAR TOC data. Without the schema validation SAX plug    
  active, the type confusion in xmlParseReference() cannot be triggered, even if the XML being parsed contains entity    
  references.
110
Matt "msw" Wilson @msw.bsky.social · 29/04/2026
Super curious what folks think about this 🧵. Especially @adamhjk.me
100
Matt "msw" Wilson @msw.bsky.social · 22/04/2026
Yesterday the QEMU team released 11.0.0, which features a new special purpose accelerator and machine model for AWS Nitro Enclaves. Check it out! www.qemu.org/docs/master/...
qemu.org
AWS Nitro Enclaves — QEMU documentation
140
Matt "msw" Wilson @msw.bsky.social · 25/03/2026
Fun fact: when you have more than 1,000 notices on GitHub, it says you have 1. It should be like tabs in Chrome on mobile devices, where past 100 it shows ":)"
Screenshot showing Inbox, Saved, and Done labels from Github. There's a 1 in a circle
150
Matt "msw" Wilson @msw.bsky.social · 19/03/2026
"Dealing with the rate of change in software development" Asked 17 years, 6 months ago. If only I had a time machine to suggest to folks that they try to enjoy the "good 'ole days". stackoverflow.com/questions/10...
stackoverflow.com
Dealing with the rate of change in software development
I am primarily a .NET developer, and in that sphere alone there are at any given time probably close to a dozen fascinating emerging technologies, some of them real game-changers, that I would love...
032
Reposted by Matt "msw" Wilson
OpenSSF @openssf.org · 17/03/2026
The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and OpenSSF) Anthropic, AmazonWebServices (AWS), GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource openssf.org/press-releas...
Linux Foundation Announces 12.5 Million in Grant Funding to Advance Open Source Security
073
Matt "msw" Wilson @msw.bsky.social · 09/03/2026
Some folks in and around Free and Open Source Software (FOSS) are asking, "does AI change everything?" If you think that FOSS only exists because software is expensive to write, reuse is efficiency, and AI shifts the economics ("we rewrote Next.js in a week with AI!"), you may be worried. I'm not.
270
Reposted by Matt "msw" Wilson
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 22/12/2025
I added a sentence to the #curl hackerone submission page: "Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim."
0102
Matt "msw" Wilson @msw.bsky.social · 05/12/2025
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) aws.amazon.com/blogs/securi...
aws.amazon.com
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services
Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g...
000
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a “0-day”.
070
Matt "msw" Wilson @msw.bsky.social · 03/12/2025
A public service announcement regarding CVEs: one identified vulnerability gets one CVE. Each vendor doesn't get their own CVE that corresponds to their security bulletin. CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182 www.cve.org/CVERecord?id...
cve.org
230
Reposted by Matt "msw" Wilson
Kate Holterhoff, PhD @kateholterhoff.com · 03/12/2025
To celebrate #awsreinvent, @redmonk.com has been publishing New Builders conversations w @awscloud.bsky.social leaders every day this week & TODAY IS MY DAY 🎉🎉🎉!! Hear AWS's Ali Maaz & Jessie VanderVeen chat all things #AI & #DevTools w me redmonk.com/videos/insid... www.youtube.com/shorts/Ot0gy...
youtube.com
Not overselling #aideveloper and #devtools as magical at #aws with Ali Maaz & Jessie VanderVeen
YouTube video by RedMonk
0101
Matt "msw" Wilson @msw.bsky.social · 12/11/2025
Unpopular opinion: through an economics lens, the optimal number of CVEs in most software systems is almost never 0.
150
Matt "msw" Wilson @msw.bsky.social · 12/11/2025
Culture eats AI adoption strategy for breakfast, lunch, and dinner.
030
Matt "msw" Wilson @msw.bsky.social · 06/11/2025
"Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than $20M in monthly revenue, you shall prominently display 'Kimi K2' on the user interface"
121
Matt "msw" Wilson @msw.bsky.social · 31/10/2025
#FerryLife #WAWX #Seattle #Sunrise
The sun rises at the horizon, reflecting of the water of Eagle Harbor. The car deck of the Washington State ferry Tacoma is in the foreground.
0122
Matt "msw" Wilson @msw.bsky.social · 04/10/2025
"As adoption has grown, so has our responsibility to ensure the project remains sustainable and continues to thrive. That’s why, with the release of Liquibase 5.0, we are updating the license for Liquibase Community." www.liquibase.com/blog/liquiba...
liquibase.com
Strengthening Liquibase Community for the Future
Liquibase Community now uses the Functional Source License (FSL). Learn what this means for developers, contributors, and enterprises, and how it protects sustainability.
210
Matt "msw" Wilson @msw.bsky.social · 12/09/2025
PSA: attacks on public infrastructure like software package registries are on the rise. Here’s an active one targeting folks who have crates.io accounts.
crates.io
crates.io: Rust Package Registry
143
Reposted by Matt "msw" Wilson
Micah Hausler @micahhausler.com · 27/07/2025
It’s really hard for OSS projects too. Imagine a leaked GH access token from a project maintainer who is not responding, and who is not an employee because OSS isn’t a company. How do you the project get that token revoked? You can’t. You have to de-list the maintainer from your GH org.
021
Matt "msw" Wilson @msw.bsky.social · 26/07/2025
From my POV, the most important message for everyone who is doing the hazardous work of developing software in public on platforms like GitHub: you have to pay *close attention* to GitHub token permission scoping. It’s not well known outside of security research circles how often GitHub tokens leak.
3255
Matt "msw" Wilson @msw.bsky.social · 22/07/2025
There's much to agree with in Dan's piece on defending the definition of Open Source. On details, I quibble. "Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source." Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...
thenewstack.io
Open Source Is Too Important To Dilute
The definition of "open source" is quietly eroding. When these lines blur, trust breaks — and open source doesn’t work without trust.
220
Reposted by Matt "msw" Wilson
Clare Liguori @clare.dev · 14/07/2025
Thrilled for the launch of @kiro.dev today! We started with two main ideas that led to Kiro's spec-driven development features: 1) AI can help us build better products through rapid prototyping 2) Devs can declare their app's requirements to get better results from AI, close to production-grade code
A ghost nightlight with the word Kiro
0122
Reposted by Matt "msw" Wilson
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/07/2025
It has officially begun. The CRA info request counter is no longer at zero.
Hello,

I hope this message finds you well.

As part of our ongoing efforts to comply with the EU Cyber Resilience Act (CRA), we are currently conducting a cybersecurity risk assessment of third-party software vendors whose products or components are integrated into our systems.

To support this initiative, we kindly request your input on the following questions related to your software product "libcurl" with version 7.87.0. Please provide your responses directly in the table below and do reply to all added in this email,
144179
Matt "msw" Wilson @msw.bsky.social · 11/07/2025
OH: "And so, it begins."
061
Matt "msw" Wilson @msw.bsky.social · 09/07/2025
This is not an adventure that FOSS maintainers should have to endure, in my opinion. Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product... www.cve.org/resourcessup....
cve.org
110
Matt "msw" Wilson @msw.bsky.social · 22/06/2025
I do not like this timeline.
041
Matt "msw" Wilson @msw.bsky.social · 22/06/2025
While there is much more that industry can do, and NEEDS to do, we should recognize that in the past Google has directly sponsored libxml2 development. It's not *just* been Project Zero sending vulnerability disclosures to the maintainer. gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org
NEWS · master · GNOME / libxml2 · GitLab
XML parser and toolkit
060
Matt "msw" Wilson @msw.bsky.social · 20/06/2025
The innovation of piped water and sewer systems had an enormous impact on public health and economic growth. It's infrastructure that we generally take for granted in developed industrialized nations.
050
Matt "msw" Wilson @msw.bsky.social · 17/06/2025
A dimension of open source software supply chain risk management that we don't discuss enough... ⬇️
030
Matt "msw" Wilson @msw.bsky.social · 12/06/2025
#hugops to all that operate, no matter who you work for.
020
Matt "msw" Wilson @msw.bsky.social · 12/06/2025
The story of #CVE-2016-1000027 is a tell of woe for Open Source maintainers. A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!). github.com/spring-proje...
github.com
Sonatype vulnerability CVE-2016-1000027 in Spring-web project · Issue #24434 · spring-projects/spring-framework
Affects: \5.2.3.RELEASE Issue Title : Sonartype vulnerability CVE-2016-1000027 in Spring-web project Description Description from CVE Pivotal Spring Framework 4.1.4 suffers from a potential remote ...
110
Matt "msw" Wilson @msw.bsky.social · 11/06/2025
Not all Foundations are the same.
110
Matt "msw" Wilson @msw.bsky.social · 11/06/2025
Oh the _feels_ when reading this announcement! I was one of the GNOME project’s first sysadmins, back in the days of a single CVS server running on a machine hosted at Red Hat’s office. It’s amazing to see their journey to the cloud! foundation.gnome.org/2025/06/10/g...
foundation.gnome.org
GNOME Has a New Infrastructure Partner: Welcome AWS! – The GNOME Foundation
160
Matt "msw" Wilson @msw.bsky.social · 10/06/2025
Is an emergent behavior of a system an anomaly if no human notices? 🤔
031
Matt "msw" Wilson @msw.bsky.social · 22/05/2025
This is disappointing. The Red Hat I knew understood that its whole existence hinged on the permissions granted to all, indiscriminately, by all Free and Open Source licenses.
111
Reposted by Matt "msw" Wilson
AWS Blogs on 🦋 @awsblogs.bsky.social · 16/05/2025
📰 New article by Clare Liguori Introducing Strands Agents, an Open Source AI Agents SDK #AWS #OpenSource
aws.amazon.com
Introducing Strands Agents, an Open Source AI Agents SDK
Today I am happy to announce we are releasing Strands Agents. Strands Agents is an open source SDK that takes a model-driven approach to building and running AI agents in just a few lines of code. Strands scales from simple to complex agent use cases, and from local development to deployment in production. Multiple teams [...]
142
Reposted by Matt "msw" Wilson
The New Stack @thenewstack.io · 16/05/2025
AWS today launched a new SDK for building AI agents, with support for LLMs from its own Bedrock service, LiteLLM and Ollama. By @fredericl.bsky.social
bit.ly
AWS Launches Its Take on an Open Source AI Agents SDK
AWS today launched a new SDK for building AI agents, with support for LLMs from its own Bedrock service, LiteLLM and Ollama.
043
Reposted by Matt "msw" Wilson
Clare Liguori @clare.dev · 16/05/2025
Excited to open source Strands Agents today! LLMs have gotten so good at reasoning and tool use that building model-driven agents with Strands is easy AND powerful Models + Tools = 🧬 Read more: aws.amazon.com/blogs/openso...
aws.amazon.com
Introducing Strands Agents, an Open Source AI Agents SDK | Amazon Web Services
Today I am happy to announce we are releasing Strands Agents. Strands Agents is an open source SDK that takes a model-driven approach to building and running AI agents in just a few lines of code. Str...
0178
Reposted by Matt "msw" Wilson
Clare Liguori @clare.dev · 16/05/2025
Fun chat about Strands Agents, I love it when the space station is involved in demos www.youtube.com/watch?v=Ausm...
youtube.com
Model Driven Agents - Strands Agents (A New Open Source, Model First, Framework for Agents)
YouTube video by AWS Developers
1146
Matt "msw" Wilson @msw.bsky.social · 08/05/2025
“AWS-LC looks like a very active project with a strong community. […] Even the recently reported performance issue was quickly fixed and released with the next version. […] This is definitely a library that anyone interested in the topic should monitor.” www.haproxy.com/blog/state-o...
haproxy.com
The State of SSL Stacks
The SSL landscape has shifted dramatically. In this paper, we examine OpenSSL 3.x, BoringSSL, LibreSSL, WolfSSL, and AWS-LC with HAProxy.
000
Matt "msw" Wilson @msw.bsky.social · 08/05/2025
What’s old is new again… (SugarCRM… iykyk) Another “badgeware” license. docs.openwebui.com/license/
docs.openwebui.com
⚖️ Open WebUI License | Open WebUI
Keeping Open WebUI Free, Fair, and Sustainable
020
Reposted by Matt "msw" Wilson
Will Norris @willnorris.com · 07/05/2025
This is absolutely the right take. AGPL and SSPL were written with wildly different (and in many ways, completely contradictory) motivations.
011
Matt "msw" Wilson @msw.bsky.social · 07/05/2025
“They set out to craft a license that followed in the AGPL’s footsteps by not applying reciprocal provisions to software hosted in a network fashion, but dramatically expanding the scope of these protections beyond the boundaries of the protected software itself and into adjacent software.” Nah.
130