Sign in

Ruggero Tonelli

@ruggero.bsky.social
43 followers 77 following 34 posts

Performance, Security & Automation at scale - OpenSource - Linux | 改善 | Head of Platforms|SRE @netquest

PostsRepliesMedia
Ruggero Tonelli @ruggero.bsky.social · 06/04/2026
The web is becoming a minefield for autonomous AI. 🕸️🤖 Google DeepMind paper introduces the first systematic framework for AI Agent Traps/adversarial content designed to manipulate, deceive, and exploit visiting agents... 1/2
110
Ruggero Tonelli @ruggero.bsky.social · 31/03/2026
A supply chain attack targeting the widely used HTTP client Axios has introduced a malicious dependency into specific npm releases, including axios@1.14.1 and axios@0.30.4. buff.ly/DGx0GMx #sbom #security 3npm #node
socket.dev
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
000
Ruggero Tonelli @ruggero.bsky.social · 23/03/2026
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets socket.dev/blog/trivy-u... If you use(d) aquasecurity/trivy-action please take action. #security #sbom
buff.ly
Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
000
Ruggero Tonelli @ruggero.bsky.social · 20/03/2026
HarmonicSecurity/claudit-sec: Security audit tool for #Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions. github.com/HarmonicSecu... #ai #security
github.com
GitHub - HarmonicSecurity/claudit-sec: Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.
Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions. - HarmonicSecurity/c...
020
Ruggero Tonelli @ruggero.bsky.social · 14/03/2026
In case you read #security news only during the weekend: CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys blog.qualys.com/vulnerabilit... since 2017 over 12.6 million #linux servers #debian #ubuntu #suse
blog.qualys.com
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys
Qualys TRU has discovered confused deputy vulnerabilities in AppArmor (named “CrackArmor”) that allow unprivileged users to bypass kernel protections, escalate to root, and break container isolation.…
010
Ruggero Tonelli @ruggero.bsky.social · 21/01/2026
Rust's standard library on the #GPU www.vectorware.com/blog/rust-st... [...] "We are cleaning up our changes and preparing to #opensource them" #rust #performance 🦀
010
Ruggero Tonelli @ruggero.bsky.social · 04/01/2026
Is #StackOverflow dead? 2y old question answered by data. It was killed by #llms, by SO own rules, or by users' democracy? An @hackernews thread worth reading news.ycombinator.com/item?id=4648...
000
Ruggero Tonelli @ruggero.bsky.social · 28/12/2025
We’re closing an incredible year for coding #GenAI but 'Correctness-Congruence Gap' in #LLM-generated Infrastructure as Code (#IaC) is still an issue: LLMs often produce syntactically correct code that not aligned with the intended architectural design and #security requirements
A robot scratching his head looking to AWS infra and Terraform / Pulumi code
100
Ruggero Tonelli @ruggero.bsky.social · 25/11/2025
A simple, yet brilliant idea. aikidosec/safe-chain "wraps around the npm cli, npx, yarn, pnpm, pnpx, bun, bunx, and pip to provide extra checks before installing new packages[...] preventing downloading or running the malware." Thank you @AikidoSecurity www.npmjs.com/package/@aik...
npmjs.com
010
Ruggero Tonelli @ruggero.bsky.social · 13/11/2025
Whisper Leak: a side-channel attack on Large Language Models arxiv.org/abs/2511.03675. #llm #ai #security
010
Ruggero Tonelli @ruggero.bsky.social · 12/11/2025
Trixter: A #Chaos Proxy for Simulating Network Faults biriukov.dev/posts/trixte...
000
Ruggero Tonelli @ruggero.bsky.social · 20/10/2025
Not an AWSome morning for the ones "living" in #AWS us-east-1 and the correlated regions. #awsdown #awsoutage
000
Ruggero Tonelli @ruggero.bsky.social · 18/10/2025
5 years since the last senior #SRE opening in our team. Lots of stuff have been archived since then but we still have some interesting challenges for #performance, #automation and #security motivated talents. And we're #AI friendly ...Are you in? buff.ly/h2IXb1i
010
Ruggero Tonelli @ruggero.bsky.social · 17/10/2025
Days ago @karpathy released #nanochat: "The best ChatGPT that $100 can buy." github.com/karpathy/nan... The real deal is not the price but the ~8000 lines of code: The entire pipeline from start to end with tokenization, pretraining, finetuning, evaluation, inference, and GUI. #ai
110
Ruggero Tonelli @ruggero.bsky.social · 14/10/2025
Apache Cloudberry (Incubating) [..] an advanced and mature #opensource Massively Parallel Processing (MPP) database, [..] built on [..] PostgreSQL kernel [..]. can serve as a #data warehouse and [..] large-scale analytics and AI/ML workloads. cloudberry.apache.org
cloudberry.apache.org
Apache Cloudberry (Incubating) | Apache Cloudberry (Incubating)
Apache Cloudberry ships with PostgreSQL 14.4 as the kernel. It is 100% open source and helps you leverage the value of your data.
010
Ruggero Tonelli @ruggero.bsky.social · 14/10/2025
Apache SeaTunnel: Multimodal, high-performance, distributed, massive #data integration tool [...] for Transaction DB, Cloud DB, SaaS, Binlog with SQL-like code or Drag & Drop. #performance #opensource buff.ly/cfZGPNn
seatunnel.apache.org
Apache SeaTunnel | Apache SeaTunnel
APache SeaTunnel Logo
010
Ruggero Tonelli @ruggero.bsky.social · 12/10/2025
When Oracle Drops the Ball: Why #MariaDB is the Future of the #MySQL World. An interesting take by @kajarno #opensource MariaDB.org
mariadb.org
When Oracle Drops the Ball: Why MariaDB is the Future of the MySQL World - MariaDB.org
The news has circulated quietly in industry corners, but the implications are far too significant to brush aside: Oracle seems to have ended the Open Source era of MySQL. … Continue reading "When…
051
Ruggero Tonelli @ruggero.bsky.social · 24/09/2025
The EU’s €2T budget overlooks a key tech pillar: #Opensource thenextweb.com/news/eu-budg...
ALL MODERN DIGITAL INFRASTRUCTURE / A PROJECT SOME RANDOM PERSON IN NEBRASKA HAS BEEN THANKLESSLY MAINTAINING SINCE 2003
000
Ruggero Tonelli @ruggero.bsky.social · 24/09/2025
OpenSSF warns that #opensource infrastructure doesn't run on thoughts and prayers. Foundations say billions of downloads rely on registries running on fumes – and someone's gotta pay the bills
theregister.com
OpenSSF to freeloaders: Open source infra isn't free
: Foundations say billions of downloads rely on registries running on fumes – and someone's gotta pay the bills
010
Ruggero Tonelli @ruggero.bsky.social · 08/04/2025
phoronix : PostgreSQL Turns To AVX-512 For CRC32 Computations: Up To 3x Faster (where supported) buff.ly/fSlCOAG [...] In addition to the recent optional IO_uring support for the #PostgreSQL database server on Linux and async I/O batch mode[...] #performance #opensource
030
Ruggero Tonelli @ruggero.bsky.social · 07/04/2025
GitHub - doxx/darkflare: DarkFlare Firewall Piercing (TCP over CDN) buff.ly/3DphmCR "A stealthy command line tool to create TCP-over-CDN(http) tunnels that keep your connections cozy and comfortable"
buff.ly
GitHub - doxx/darkflare: DarkFlare Firewall Piercing (TCP over CDN)
DarkFlare Firewall Piercing (TCP over CDN). Contribute to doxx/darkflare development by creating an account on GitHub.
010
Ruggero Tonelli @ruggero.bsky.social · 07/04/2025
CISA, FBI, nations warn of fast flux DNS threat • The Register buff.ly/y4JdM1s "Malicious cyber actors use #fastflux to obfuscate the locations of malicious servers " #cybersec
012
Ruggero Tonelli @ruggero.bsky.social · 24/03/2025
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
buff.ly
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
010
Ruggero Tonelli @ruggero.bsky.social · 22/03/2025
The Biggest #SupplyChain Hack Of 2025: 6M Records For Sale Exfiltrated from #Oracle Cloud Affecting over 140k Tenants | CloudSEK cloudsek.com/blog/the-big... #ransomware
cloudsek.com
The Biggest Supply Chain Hack Of 2025: 6M Records For Sale Exfiltrated from Oracle Cloud Affecting over 140k Tenants | CloudSEK
CloudSEK uncovers a major breach targeting Oracle Cloud, with 6 million records exfiltrated via a suspected undisclosed vulnerability. Over 140,000 tenants are impacted, as the attacker demands ransom...
020
Ruggero Tonelli @ruggero.bsky.social · 03/03/2025
fosrl/pangolin: Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI
buff.ly
GitHub - fosrl/pangolin: Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI
Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI - fosrl/pangolin
010
Ruggero Tonelli @ruggero.bsky.social · 24/02/2025
Valkey · Reducing application latency and lowering Cloud bill by setting up your client library
buff.ly
Valkey · Reducing application latency and lowering Cloud bill by setting up your client library
By implementing AZ affinity routing in Valkey and using GLIDE, you can achieve lower latency and cost savings by routing requests to replicas in the same AZ as the client.
020
Reposted by Ruggero Tonelli
Orhun Parmaksız @orhun.dev · 22/02/2025
Breaking news for the crab people 🚨 🦀 Ring, a widely used Rust cryptography library, is now unmaintained. 🔐 Security advisory: rustsec.org/advisories/R... ➡️ Details: github.com/briansmith/r... #rustlang #opensource #library #security #cryptography
rustsec.org
RUSTSEC-2025-0007: ring: *ring* is unmaintained › RustSec Advisory Database
Security advisory database for Rust crates published through https://crates.io
1289
Ruggero Tonelli @ruggero.bsky.social · 17/01/2025
Amazon Web Services plugin | Steampipe Hub
buff.ly
Steampipe Hub
Query AWS with SQL! Open source CLI. No DB required.
010
Ruggero Tonelli @ruggero.bsky.social · 20/12/2024
spegel-org/spegel: Stateless cluster local OCI registry mirror.
buff.ly
GitHub - spegel-org/spegel: Stateless cluster local OCI registry mirror.
Stateless cluster local OCI registry mirror. Contribute to spegel-org/spegel development by creating an account on GitHub.
020
Ruggero Tonelli @ruggero.bsky.social · 20/12/2024
fn main() { println!("Hello World!"); }
020