Matt "msw" Wilson @msw.bsky.social · 30/06/2026Apologies, I missed those two words on my small screen. 010
Matt "msw" Wilson @msw.bsky.social · 29/06/2026That is not correct. The Nitro Hypervisor supports VBS. docs.aws.amazon.com/AWSEC2/lates...docs.aws.amazon.comCredential Guard for Windows instances - Amazon Elastic Compute CloudUnderstand the concepts, requirements, and usage of Credential Guard. 100
Matt "msw" Wilson @msw.bsky.social · 25/06/2026I think this is a reasonable approach to most things in life, especially when you have a large industry consortium motion involved. 010
Matt "msw" Wilson @msw.bsky.social · 25/06/2026Maintainers deserve a coordinated partnership, not a flood of reports. AWS is committed to securing the projects our customers depend on and building this shared infrastructure alongside the community. 010
Matt "msw" Wilson @msw.bsky.social · 25/06/2026Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before. That's an enormous opportunity for defenders, and Akrites ensures we seize it together. 110
Matt "msw" Wilson @msw.bsky.social · 25/06/2026We have just launched Akrites at The Linux Foundation, a coordinated industry effort to harden the world’s most critical open source software in the era of AI-assisted vulnerability discovery. www.linuxfoundation.org/press/linux-...linuxfoundation.orgLinux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber ThreatsLinux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats 182
Matt "msw" Wilson @msw.bsky.social · 21/06/2026github.com/spanio/SPAN-...github.comGitHub - spanio/SPAN-API-Client-Docs: SPAN API Client DocumentationSPAN API Client Documentation. Contribute to spanio/SPAN-API-Client-Docs development by creating an account on GitHub. 010
Matt "msw" Wilson @msw.bsky.social · 21/06/2026mstdn.social/@msw/1167825...mstdn.socialMatt "msw" Wilson (@msw@mstdn.social)Sometimes the response to a software defect that is discovered, fixed, and disclosed as a "security vulnerability" has a far worse effect than the defect itself. There was never any indication that t... 010
Matt "msw" Wilson @msw.bsky.social · 20/06/2026There is an API for first generation SPAN, and a HA integration. 2nd generation API is in the works. But it is a very installer-centric product, and not as open / DIY homeowner friendly as it could be. 210
Matt "msw" Wilson @msw.bsky.social · 17/06/2026when it comes to addressing newly discovered flaws in your software dependencies (some of which might be classified as "security vulnerabilities") ... pruning > patching That's it. That's the post. 010
Matt "msw" Wilson @msw.bsky.social · 09/06/2026I guess membership such a hypothetical club means promising to not share, despite the GPL giving you all the fundamental permissions needed to do so. 040
Matt "msw" Wilson @msw.bsky.social · 09/06/2026Personally, I miss the days of Free and Open Source when folks debated if NDAs were compatible (at minimum, in spirit) with the conditions of the GPL. Now, I see the slight possibility of a world where folks rush to share fixes for vulnerabilities in a private club. And if that software is GPL? 150
Matt "msw" Wilson @msw.bsky.social · 21/05/2026For those who may have forgotten... www.schneier.com/blog/archive...schneier.comRandom Number Bug in Debian Linux - Schneier on SecurityThis is a big deal: On May 13th, 2008 the Debian project announced that Luciano Bello found an interesting vulnerability in the OpenSSL package they were distributing. The bug in question was caused b... 020
Matt "msw" Wilson @msw.bsky.social · 21/05/2026For folks who are thinking about locally patching open-source software to fix what they think is a bug (_especially_ if they think it's a security vulnerability), I think that's a path to www.xkcd.com/424/xkcd.comSecurity Holes 120
Reposted by Matt "msw" WilsonCassidy @cassidoo.co · 20/05/2026Heads up maintainers of packages, this is a big deal: github.com/orgs/communi...github.comnpm granular access token invalidation to prevent supply chain attacks · community · Discussion #196340As initially announced on npm’s X channel, we have invalidated granular access tokens with write access that bypass two-factor authentication. This action was taken to help prevent supply chain att... 37424
Matt "msw" Wilson @msw.bsky.social · 19/05/2026So often I've seen a "it's too hard to triage CVEs, so we should always assume the worst and apply the 'fix' as quickly as possible." Being able to demote a "critical security vulnerability" to "this should be addressed via regularly scheduled maintenance" is a very useful capability. 030
Matt "msw" Wilson @msw.bsky.social · 19/05/2026Y'all, AI models seem to be *really good* at triaging vulnerabilities that are discovered with AI tooling! Try this prompt: > read gitlab.gnome.org/GNOME/libxml... and tell me if CVE-2026-6732 applies to github.com/libarchive/l... [...] Conclusion Not affected. 110
Matt "msw" Wilson @msw.bsky.social · 29/04/2026Super curious what folks think about this 🧵. Especially @adamhjk.me 100
Matt "msw" Wilson @msw.bsky.social · 22/04/2026And the KIWI operating system image builder now has an example of how to build an attestable AWS Nitro Enclave image! Very cool! github.com/OSInside/kiw...github.comAdd confidential compute image for AWS by schaefi · Pull Request #2962 · OSInside/kiwiAdd a Trusted Execution Environment in form of an image as a read-only system that is also dm-verity baked. The image build provides PCR measuerd UKI image (kernel+initrd+bootloader). The PCR value... 010
Matt "msw" Wilson @msw.bsky.social · 22/04/2026Yesterday the QEMU team released 11.0.0, which features a new special purpose accelerator and machine model for AWS Nitro Enclaves. Check it out! www.qemu.org/docs/master/...qemu.orgAWS Nitro Enclaves — QEMU documentation 140
Matt "msw" Wilson @msw.bsky.social · 25/03/2026Fun fact: when you have more than 1,000 notices on GitHub, it says you have 1. It should be like tabs in Chrome on mobile devices, where past 100 it shows ":)" 150
Matt "msw" Wilson @msw.bsky.social · 19/03/2026"Dealing with the rate of change in software development" Asked 17 years, 6 months ago. If only I had a time machine to suggest to folks that they try to enjoy the "good 'ole days". stackoverflow.com/questions/10...stackoverflow.comDealing with the rate of change in software developmentI am primarily a .NET developer, and in that sphere alone there are at any given time probably close to a dozen fascinating emerging technologies, some of them real game-changers, that I would love... 032
Reposted by Matt "msw" WilsonOpenSSF @openssf.org · 17/03/2026The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and OpenSSF) Anthropic, AmazonWebServices (AWS), GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource openssf.org/press-releas... 073
Matt "msw" Wilson @msw.bsky.social · 09/03/2026Some folks in and around Free and Open Source Software (FOSS) are asking, "does AI change everything?" If you think that FOSS only exists because software is expensive to write, reuse is efficiency, and AI shifts the economics ("we rewrote Next.js in a week with AI!"), you may be worried. I'm not. 270
Reposted by Matt "msw" Wilsondaniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 22/12/2025I added a sentence to the #curl hackerone submission page: "Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim." 0102
Matt "msw" Wilson @msw.bsky.social · 05/12/2025China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) aws.amazon.com/blogs/securi...aws.amazon.comChina-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web ServicesWithin hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g... 000
Matt "msw" Wilson @msw.bsky.social · 04/12/2025Throwback Thursday... socket.dev/blog/node-js...socket.devNode.js EOL Versions CVE Dubbed the "Worst CVE of the Year" ...Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases. 010
Matt "msw" Wilson @msw.bsky.social · 04/12/2025These were the rules when the original plan was made to issue CVEs merely because Node.js versions were EOL. This outcome was easy to predict... nodejs.org/en/blog/vuln...nodejs.orgNode.js — Updates on CVE for End-of-Life VersionsNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025Why? Because 4.1.13 The state of a Product being EOL, by itself, MUST NOT be determined to be a Vulnerability. www.cve.org/resourcessup....cve.org 100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025Vendored deps are not unusual at all... But, unfortunately, misuse of the CVE program is all too common in the NodeJS community. Let's take CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 for example. All of these CVEs are REJECTED. nodejs.org/en/blog/vuln...nodejs.orgNode.js — Tuesday, January 21, 2025 Security ReleasesNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025> The decision to publish a second CVE for Next.js was made due to these exceptional circumstsances: Next.js does not include React as a traditional dependency - instead, they bundle it "vendored" react2shell.comreact2shell.comReact2Shell (CVE-2025-55182) 100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a “0-day”. 070
Matt "msw" Wilson @msw.bsky.social · 03/12/20254.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities. www.cve.org/resourcessup...cve.org 100
Matt "msw" Wilson @msw.bsky.social · 03/12/2025A public service announcement regarding CVEs: one identified vulnerability gets one CVE. Each vendor doesn't get their own CVE that corresponds to their security bulletin. CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182 www.cve.org/CVERecord?id...cve.org 230
Reposted by Matt "msw" WilsonKate Holterhoff, PhD @kateholterhoff.com · 03/12/2025To celebrate #awsreinvent, @redmonk.com has been publishing New Builders conversations w @awscloud.bsky.social leaders every day this week & TODAY IS MY DAY 🎉🎉🎉!! Hear AWS's Ali Maaz & Jessie VanderVeen chat all things #AI & #DevTools w me redmonk.com/videos/insid... www.youtube.com/shorts/Ot0gy...youtube.comNot overselling #aideveloper and #devtools as magical at #aws with Ali Maaz & Jessie VanderVeenYouTube video by RedMonk 0101
Matt "msw" Wilson @msw.bsky.social · 12/11/2025Unpopular opinion: through an economics lens, the optimal number of CVEs in most software systems is almost never 0. 150
Matt "msw" Wilson @msw.bsky.social · 12/11/2025Culture eats AI adoption strategy for breakfast, lunch, and dinner. 030
Matt "msw" Wilson @msw.bsky.social · 06/11/2025"Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than $20M in monthly revenue, you shall prominently display 'Kimi K2' on the user interface" 121
Matt "msw" Wilson @msw.bsky.social · 06/11/2025I mean, honesty is a human trait. The humans who built that particular AI system biased the set of mysterious numbers (through reinforcement, filtering, etc.) so it assembles tokens in a way that conveys information about the properties and limitations of the system they built. That's all. 010
Matt "msw" Wilson @msw.bsky.social · 04/10/2025"As adoption has grown, so has our responsibility to ensure the project remains sustainable and continues to thrive. That’s why, with the release of Liquibase 5.0, we are updating the license for Liquibase Community." www.liquibase.com/blog/liquiba...liquibase.comStrengthening Liquibase Community for the FutureLiquibase Community now uses the Functional Source License (FSL). Learn what this means for developers, contributors, and enterprises, and how it protects sustainability. 210
Matt "msw" Wilson @msw.bsky.social · 02/10/2025Metrics are increasingly employed as trust deteriorates. Recommended reading ⬇️ #monktoberfest a.co/d/im8AStVa.coThe Tyranny of Metrics: Muller, Jerry Z.: 9780691191911: Amazon.com: BooksBuy The Tyranny of Metrics on Amazon.com ✓ FREE SHIPPING on qualified orders 063
Matt "msw" Wilson @msw.bsky.social · 02/10/2025Ref: Edgar H. Schein sloanreview.mit.edu/article/comi... #monktoberfestsloanreview.mit.eduComing to a New Awareness of Organizational Culture 000
Matt "msw" Wilson @msw.bsky.social · 02/10/2025“Organizational culture is the pattern of basic assumptions that a given group has invented, discovered, or developed in learning to cope with its problems […], and that has worked well enough to be considered valid, and, therefore, to be taught to new members.” The stories we tell are how we teach. 100
Matt "msw" Wilson @msw.bsky.social · 14/09/2025"apparently web traffic is down because Google is giving you an answer already in the results, and you no longer have the need to visit a website" I mean, this has been a complaint for a while, even before AI entered the timeline? Who needs to go to a music lyrics website when it's in the Info Box? 000
Matt "msw" Wilson @msw.bsky.social · 14/09/2025"Piracy lost, but it was always going to lose. Streaming won." But did the reader / listener / viewer win? And did the content creators win? 🤔 120