Sign in

Sébastien Duquette

@sduquette.bsky.social
36 followers 61 following 48 posts

software & security ekse.github.io/blog

PostsRepliesMedia
Sébastien Duquette @sduquette.bsky.social · 25/09/2026
Cross-tenant code execution in Atlassian Rovo mononclemich.medium.com/so-apparentl...
mononclemich.medium.com
So Apparently Rovo Has Neighbors
How Rovo’s sandbox proxy bypass became cross-user and cross-tenant code execution
010
Reposted by Sébastien Duquette
EricLaw 🎻 @ericlawrence.com · 18/09/2026
github.com/ericlaw1979/... Clearinet is intended to be a drop-in replacement for the Fiddler Web Debugger which Progress/Telerik took away from the community. A huge amount of work to come, but I'm optimistic that Coding Agents + the Community will bring this to fruition.
github.com
GitHub - ericlaw1979/Clearinet: https://clearinet.app
https://clearinet.app. Contribute to ericlaw1979/Clearinet development by creating an account on GitHub.
2105
Reposted by Sébastien Duquette
Zeke Hausfather @zekehausfather.com · 13/08/2026
Pretty neat exploration of storylines of possible climate futures by Dagomar Degroot and colleagues: after2c.com
after2c.com
After 2C - Histories of the Future of Global Warming
An interactive exploration of five plausible, research-grounded climate futures, written as history papers looking back from the year 2100.
211656
Sébastien Duquette @sduquette.bsky.social · 13/08/2026
lethain.com/decisions-no...
lethain.com
Roadmap decisions rather than dates.
One thing that bothered me about Imprint’s product after joining was our lack of passkey support. Passkey support is a rare opportunity to increase resiliency to phishing attacks while simultaneously ...
000
Reposted by Sébastien Duquette
Naomi Saphra @nsaphra.bsky.social · 09/08/2026
I've been unsettled lately when reading messages and papers. It feels like I'm dissociating. Everything seems a bit alien, even if it's completely human. I've had a realization: When our simulations finally exited the Uncanny Valley, they brought the Uncanny with them.
nsaphra.net
Life on the Uncanny Precipice | Naomi Saphra
We were wrong about the Uncanny Valley.
1026461
Reposted by Sébastien Duquette
Mayor Zohran Kwame Mamdani @mayor.nyc.gov · 22/07/2026
Benjamin Netanyahu is a war criminal.
20368812524828
Reposted by Sébastien Duquette
James @43081j.com · 08/07/2026
npm v12 🎉 - allowScripts defaults to false, scripts have to be approved - git dependencies are disallowed - remote URL dependencies are disallowed (e.g. http) big wins!
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
0447
Sébastien Duquette @sduquette.bsky.social · 06/07/2026
shape is the new emdash.
000
Sébastien Duquette @sduquette.bsky.social · 04/07/2026
Testcontainers (testcontainers.com) are really neat for integration tests. I use them in a project to create an instance of the database on postgresql.
110
Sébastien Duquette @sduquette.bsky.social · 27/06/2026
Been using lazygit (tui for git) for about a week and it's a super well made. Check it out github.com/jesseduffiel...
github.com
GitHub - jesseduffield/lazygit: simple terminal UI for git commands
simple terminal UI for git commands. Contribute to jesseduffield/lazygit development by creating an account on GitHub.
000
Reposted by Sébastien Duquette
sophie alpert @sophiebits.com · 25/06/2026
got frustrated recently at work about people writing using AI instead of using their brains! here's my take on it: sophiebits.com/2026/06/25/t...
sophiebits.com
There are no lossless transformations of natural-language text
1522165
Reposted by Sébastien Duquette
Grantham Research Institute at LSE @granthamlse.bsky.social · 23/06/2026
We regret that our event on Extreme Heat: Improving governance and strengthening action around the world has been cancelled due to the red extreme heat warning issued by the UK Met Office. Our apologies to everyone who was planning to attend the event.
7719981152
Sébastien Duquette @sduquette.bsky.social · 11/06/2026
npm merged a PR today to support exclusions for dependency cooldowns. Exciting as this was the missing piece for us to be able to implement cooldowns at work github.com/npm/cli/pull...
github.com
feat: add min-release-age-exclude config by JamieMagee · Pull Request #9534 · npm/cli
Manual backport of #9532 to release/v11. min-release-age-exclude exempts packages (exact name or glob, e.g. @myorg/*) from the min-release-age / before publish-time filter. Applied in install, upd...
000
Sébastien Duquette @sduquette.bsky.social · 04/06/2026
LLM generated text is so boring, everything looks the same. I'm at the point where if I see a blog is LLM-generated I close the tab and move on.
110
Reposted by Sébastien Duquette
Émilio Gonzalez @res260.xyz · 23/05/2026
Cette année au nsec CTF, nous avons demandé aux gens d’autodéclarer les flags trouvés par un agent IA. Nous avons aussi demandé à la communauté leur opinion sur le rôle+impact des agents IA dans les CTFs Plus de 40% des participants ont répondu au sondage! J’ai écrit un blogpost qui analyse le tout
res260.medium.com
Retour sur nsec 2026: le pouls de la communauté sur l’agentic CTF
Si vous avez assisté à la cérémonie de fermeture, passez directement à la section Sondage de rétroaction, la première section répète les…
153
Sébastien Duquette @sduquette.bsky.social · 03/05/2026
This is such a bad look for you @vscode.dev. I'm usually all for giving the benefit of the doubt but you're making it very difficult with this one news.ycombinator.com/item?id=4798...
news.ycombinator.com
VS Code inserting 'Co-Authored-by Copilot' into commits regardless of usage | Hacker News
010
Sébastien Duquette @sduquette.bsky.social · 29/04/2026
This is hilarious. With AI generated music polluting Tidal feeds of existing artists I could see myself join this movement. fuckoffaimusic.com
fuckoffaimusic.com
fuckoffaimusic
fuck off ai music
000
Sébastien Duquette @sduquette.bsky.social · 25/04/2026
JetBrains Rider has a very clever way to handle cases were there are multiple function calls on the same line when debugging, you use the arrows to select which one you want to step into. It's the first time I see this and now I wish all debuggers supported it.
141
Sébastien Duquette @sduquette.bsky.social · 23/04/2026
Bitwarden cli compromised in supply chain attack socket.dev/blog/bitward...
socket.dev
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
000
Sébastien Duquette @sduquette.bsky.social · 21/04/2026
www.theguardian.com/world/2026/a...
theguardian.com
Israeli soldiers using sexual assault to force Palestinians out of West Bank, report says
Experts say attacks, also carried out by settlers, are leading girls to quit school and enter early marriages
000
Reposted by Sébastien Duquette
Socket @socket.dev · 31/03/2026
🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...
socket.dev
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
39868
Reposted by Sébastien Duquette
James @43081j.com · 21/03/2026
new post on my personal blog. i think these three areas often go unexplained, so hopefully this explains why some of these packages exist. these are fine to exist but the majority of developers shouldn't have to pay the cost for them.
43081j.com
The Three Pillars of JavaScript Bloat
A brief look at the three main causes of bloat in our JavaScript dependency trees, and how we can start to address them.
1315045
Reposted by Sébastien Duquette
Matthew Sanabria @matthewsanabria.com · 12/03/2026
A tale in two images.
Screenshot showing GitHub's status page saying "All Systems Operational".A GitHub error page with a pink unicorn saying they are having issues processing the request.
1233
Reposted by Sébastien Duquette
Senator Bernie Sanders @sanders.senate.gov · 28/02/2026
The U.S. Senate must be clear: no war with Iran.
1327223826281
Reposted by Sébastien Duquette
Filippo Valsorda @filippo.abyssdomain.expert · 20/02/2026
Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulns. That hurts security! Just turn it off and set up a pair of scheduled GitHub Actions, one running govulncheck and the other running CI with the latest version of your deps. Less work, less risk, better results!
words.filippo.io
Turn Dependabot Off
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
49220
Sébastien Duquette @sduquette.bsky.social · 24/11/2025
Yet another episode of infected npm packages www.aikido.dev/blog/shai-hu...
aikido.dev
Shai Hulud 2.0 Strikes Again: Malware Supply-Chain Attack Hits Zapier & ENS Domains
The threat actor behind “Shai Hulud 2.0” launched a new malware campaign compromising the supply chain of Zapier, ENS Domains and more — exposing secrets, injecting malicious code, and enabling widesp...
000
Sébastien Duquette @sduquette.bsky.social · 05/11/2025
Trying Ubuntu in Hyper-V once again and the experience is not great. The clipboard randomly stops working, I have to close and reopen the session.
000
Reposted by Sébastien Duquette
Marc-André Moreau @awakecoding.com · 28/10/2025
So it turns out GitHub Copilot in VSCode is much better at doing code search on a very large code base because it could benefit from automatic remote indexing from GitHub, where Claude Code is basically just grepping files locally with no auto indexing: code.visualstudio.com/docs/copilot...
code.visualstudio.com
Make chat an expert in your workspace
Learn how workspace context gives chat a deep understanding of your entire codebase to provide accurate, contextual answers.
101
Reposted by Sébastien Duquette
Marc-André Moreau @awakecoding.com · 29/07/2025
New blog post! 📰 I tried "vibe coding" in VSCode using GitHub Copilot (Claude Sonnet) to build an MCP proxy tool in Rust — I didn't touch a line of code, just pure agent mode magic 🧙‍♂️ 🚀👇 awakecoding.com/posts/vibe-c...
awakecoding.com
Vibe coding a Rust MCP proxy in VSCode with GitHub Copilot
A hands-off experiment building a Rust-based Model Context Protocol (MCP) proxy tool using only GitHub Copilot agent mode. Covers setup, multi-transport support, and lessons learned from letting Copil...
012
Reposted by Sébastien Duquette
Thorsten Butz @thorsten.butz.io · 27/06/2025
Check out the #PSCONFEU 2025 playlist. We finished the summit yesterday, we published the 1st video on the finaly day (aka yesterday) and 2nd one TODAY. Guess what will be next! Better subscribe to the channel. Playlist for 2025 below. youtube.com/playlist?lis...
youtube.com
PSCONFEU 2025 - YouTube
01510
Reposted by Sébastien Duquette
Avalonia UI @avaloniaui.net · 24/06/2025
🎉 Big news! We've secured a $3M, three-year sponsorship from @devolutions.net This sponsorship will allow us to speed up development, improve docs & tooling for all the community's benefit! 🚀 Read about it here: github.com/AvaloniaUI/...
65211
Reposted by Sébastien Duquette
Chris Short @chrisshort.net · 11/06/2025
Arguing point-by-point considered harmful #SuggestedRead #devopsish www.seangoedecke.com...
seangoedecke.com
Arguing point-by-point considered harmful | sean goedecke
Engineers love to have technical discussions point-by-point: replying to every idea in turn, treating each as its own mini-discussion. It just makes sense! A…
001
Reposted by Sébastien Duquette
Eric Geller @ericjgeller.com · 06/06/2025
NEW: Trump today signed an executive order to rescind parts of Obama and Biden cyber EOs and modify others. Text is TBD, but here's a fact sheet: www.whitehouse.gov/fact-sheets/... Still in: secure software development, BGP, PQC Out: Some AI safety, digital ID, and cyber-related sanctions stuff
48338
Reposted by Sébastien Duquette
Jeff (Hot Type) Jarvis @jeffjarvis.bsky.social · 19/03/2025
"I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped" www.theguardian.com/us-news/2025...
theguardian.com
I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped
I was stuck in a freezing cell without explanation despite eventually having lawyers and media attention. Yet, compared with others, I was lucky
13524661062
Sébastien Duquette @sduquette.bsky.social · 06/03/2025
Lots of interesting insights in this thread
010
Sébastien Duquette @sduquette.bsky.social · 05/03/2025
Cancelled Youtube Music (switched to Tidal), Netflix, Disney+ and Microsoft Game Pass. My money will go anywhere but the US whenever I can until this nonsense ends. I have nothing against Americans but Trump can go fuck himself.
020
Sébastien Duquette @sduquette.bsky.social · 28/02/2025
This is completely insane. What the 6 minutes video to get a sense of the scale of the work involved to get this running. Huge props to @michigantypescript.com .
010
Reposted by Sébastien Duquette
Marc-André Moreau @awakecoding.com · 30/01/2025
🚀 Join my webinar: Decrypting RDP Traffic in Wireshark! 🔍 📅 Date: February 11th ⏰ Time: 09:00 AM – 10:00 AM EST Learn how to analyze and decrypt RDP traffic like a pro. Can't make it live? No worries—register now, and you'll get the slides & recording afterward! 🔗 Register now 👇
events.ringcentral.com
Decrypting RDP Traffic in Wireshark
Get tickets to Decrypting RDP Traffic in Wireshark, taking place 11/02/2025. RingCentral Events is your source for engaging events and experiences.
02313
Reposted by Sébastien Duquette
Zeke Hausfather @zekehausfather.com · 15/01/2025
I have a new paper in Dialogues on Climate Change exploring climate outcomes under current policies. I find that we are likely headed toward 2.7C by 2100 (with uncertainties from 1.9C to 3.7C), and that high end emissions scenarios have become much less likely. journals.sagepub.com...
14361140
Reposted by Sébastien Duquette
Raphael Satter @raphae.li · 30/12/2024
New: “Major incident” at U.S. Treasury after alleged Chinese hackers steal a cryptographic key used by vendor BeyondTrust. Government workstations breached. www.reuters.com/technology/c...
reuters.com
US Treasury says Chinese hackers stole documents in 'major incident'
Chinese state-sponsored hackers broke into the U.S. Treasury Department earlier this month and stole documents from its workstations, according to a letter to lawmakers that was provided to Reuters on Monday.
514681
Reposted by Sébastien Duquette
Charity Majors @charity.wtf · 17/12/2024
I (finally) wrote up my thoughts on "Founder Mode" and the Brian Chesky morality tale about how he turned around Airbnb company culture. This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out. charity.wtf/2024/12/17/f...
charity.wtf
“Founder Mode” and the Art of Mythmaking
I’ve never been good at “hot takes”. Anyone who knows anything about marketing can tell you that the best time to share your opinion about something is when everyone is all worked up about it. Hot …
2629393
Sébastien Duquette @sduquette.bsky.social · 11/12/2024
hey @semgrep.bsky.social, big fan of your tool here. Being cold emailed 5 times in a week by one of your sales rep, not so much.
100
Reposted by Sébastien Duquette
David Kean @keansbox.com · 25/11/2024
Good read of @ericlaw.bsky.social's mistakes building Fiddler as a side-project while working at Microsoft. Super tempted to deep dive into that Thread Pool problem he hints at towards the start, something Visual Studio itself thinks about a lot! textslashplain.com/2024/11/24/f...
textslashplain.com
Fiddler – My Mistakes
On a flight back from Redmond last week, I finally read Linus Torvalds’ 2002 memoir “Just For Fun.” I really enjoyed its picture of Linux (and Torvalds) early in its success, with…
0144
Reposted by Sébastien Duquette
Luc @ocx64.dev · 24/11/2024
Just wrote my first blog post, its about Rust and Slack, check it out! ocx64.dev/blog/rust-sl...
ocx64.dev
Using Rust inside a Slack Workflow app with WASM
Slack workflows are pretty cool, they use deno and I'm going to show you how you can use Rust!
032
Reposted by Sébastien Duquette
Barry Dorrans @blowdart.me · 13/11/2024
Omg www.infosecurity-magazine.com/news/new-cit...
infosecurity-magazine.com
New Citrix Zero-Day Vulnerability Allows Remote Code Execution
watchTowr has found a flaw in Citrix’s Session Recording Manager that can be exploited to enable unauthenticated RCE against Citrix Virtual Apps and Desktops
4203
Reposted by Sébastien Duquette
Mattias Karlsson @devlead.se · 13/11/2024
.NET 9 Released 🎉 Announcing .NET 9 devblogs.microsoft.com/dotnet/annou... Visual Studio 2022 v17.12 with .NET 9 devblogs.microsoft.com/visualstudio... .NET 6 end of life devblogs.microsoft.com/dotnet/dotne... #dotnet
devblogs.microsoft.com
Announcing .NET 9 - .NET Blog
Announcing the release of .NET 9, the most productive, modern, secure, intelligent, and performant release of .NET yet. With updates across ASP.NET Core, C#, .NET MAUI, .NET Aspire, and so much more.
110818
Reposted by Sébastien Duquette
Sonia Cuff @soniacuff.com · 07/11/2024
Hypervisor isolation is great for security, but not known for fast cold starts. Meet Hyperlight - an open source Rust library that can create new VMs in one to two milliseconds. opensource.microsoft.com/blog/2024/11...
opensource.microsoft.com
Introducing Hyperlight: Virtual machine-based security for functions at scale - Microsoft Open Source Blog
The Microsoft Azure Core Upstream team is excited to announce the Hyperlight project, an open-source Rust library you can use to create very small VMs for embedded functions. Learn more.
0116
Sébastien Duquette @sduquette.bsky.social · 02/11/2024
Note mostly for future me; if github.dev displays "Unable to resolve resource vscode-vfs" when opening a repo, disable Enhanced Tracking Protection in Firefox.
020