
Sign up to save your podcasts
Or


Lo scanner di sicurezza più usato al mondo è stato compromesso. Trivy, il guardiano delle CI/CD pipeline, è diventato il cavallo di Troia di un attacco supply chain che ha infettato migliaia di ambienti cloud, avvelenato npm e Docker Hub, e scatenato un wiper contro l'Iran.
Fonti e approfondimenti:
- Ars Technica: https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/
- Bleeping Computer: https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/
- Aqua Security: https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- Snyk: https://snyk.io/articles/poisoned-security-scanner-backdooring-litellm/
- Eclipse Foundation: https://blogs.eclipse.org/post/mika%C3%ABl-barbero/stop-trusting-mutable-references-how-eclipse-foundation-projects-should-harden
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:37 Trivy: il guardiano delle pipeline
03:09 L'attacco: come hanno bucato lo scanner
07:19 L'effetto domino: da Trivy al 36% del cloud
10:58 Outro
#trivy #supply-chain #cybersecurity #ci-cd #litellm #npm #docker #kubernetes #opensource
Anthropic compra Bun, Cloudflare compra Astro, OpenAI compra Astral. Tre acquisizioni in pochi mesi, stesso pattern: le AI company non stanno comprando tool — stanno comprando l'infrastruttura sotto. Vi racconto cosa è successo e perché dovrebbe interessarvi.
Fonti e approfondimenti:
- Blog Astral: https://astral.sh/blog/openai
- Annuncio OpenAI: https://openai.com/index/openai-to-acquire-astral/
- Simon Willison: https://simonwillison.net/2026/Mar/19/openai-acquiring-astral/
- The Register: https://www.theregister.com/2026/03/19/openai_aims_for_the_stars/
- Ars Technica: https://arstechnica.com/ai/2026/03/openai-is-acquiring-open-source-python-tool-maker-astral/
- The New Stack: https://thenewstack.io/openai-astral-acquisition/
- Shashi Bellamkonda: https://www.shashi.co/2026/03/openai-bought-plumbing-not-just-tools.html
- JetBrains Blog: https://blog.jetbrains.com/pycharm/2026/03/openai-acquires-astral-what-it-means-for-pycharm-users/
- The Verge (superapp): https://www.theverge.com/ai-artificial-intelligence/897778/openai-chatgpt-codex-atlas-browser-superapp
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:01 Astral: gli strumenti che hanno cambiato Python
03:11 L'acquisizione: cosa sappiamo
05:35 La corsa ai tubi: perché le AI company comprano infrastruttura
09:52 Outro
#openai #astral #python #opensource #codex
Speciale 5000 iscritti: come funziona la compressione dei dati che viaggiano su internet. Dai bit e il limite di Shannon agli algoritmi classici (RLE, Huffman, LZ77), passando per i quattro protagonisti della compressione HTTP moderna: gzip, Brotli, Zstandard e il nuovo OpenZL di Meta.
Fonti e approfondimenti:
- Meta Engineering - OpenZL: https://engineering.fb.com/2025/10/06/developer-tools/openzl-open-source-format-aware-compression-framework/
- Paper OpenZL: https://arxiv.org/abs/2510.03203
- RFC 7932 - Brotli: https://www.rfc-editor.org/rfc/rfc7932
- Zstandard su GitHub: https://github.com/facebook/zstd
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:03 Bit, informazione e il limite di Shannon
07:52 RLE, Huffman e LZ: le basi della compressione
17:04 gzip, Brotli, Zstandard e OpenZL: comprimere il web
30:05 Outro
#compressione #gzip #brotli #zstandard #openzl #algoritmi
Un ascoltatore mi ha chiesto: "Cosa sono i framework JavaScript? Perché ce ne sono così tanti?" La risposta arriva in un momento perfetto: Meta ha appena ceduto React, il framework usato da 20 milioni di sviluppatori — a una Foundation indipendente. Ma quanto è davvero indipendente? Vi spiego cosa sono i framework, racconto la storia di React, e vi mostro chi controlla davvero il progetto che controlla il web.
Fonti e approfondimenti:
- React blog: https://react.dev/blog/2026/02/24/the-react-foundation
- The Register: https://www.theregister.com/2026/02/25/meta_sends_react_to_live
- The New Stack: https://thenewstack.io/react-foundation-open-source-governance/
- Linux Foundation: https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-react-foundation
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:41 Cosa sono i framework (e perché ce ne sono mille)
05:14 React: dal garage di Zuckerberg alla Foundation
09:38 Chi controlla davvero React
15:47 Outro
#react #javascript #framework #opensource #meta #vercel #linux
Anthropic ha rifiutato di togliere i limiti sull'uso militare di Claude per sorveglianza di massa e armi autonome. Trump l'ha bannata dal governo, Hegseth l'ha dichiarata "rischio per la supply chain". Poi OpenAI ha firmato un contratto col Pentagono con le stesse identiche restrizioni. E sabato gli USA hanno bombardato l'Iran usando Claude — ore dopo il ban. Ricostruisco la storia e spiego perché è una trappola che l'intero settore AI si è costruito da solo.
Fonti e approfondimenti:
- Anthropic vs Pentagon negotiations — The Verge: https://www.theverge.com/ai-artificial-intelligence/883456/anthropic-pentagon-department-of-defense-negotiations
- Statement Dario Amodei — Anthropic: https://www.anthropic.com/news/statement-department-of-war
- Anthropic Drops Flagship Safety Pledge — TIME: https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/
- OpenAI agreement with Department of War — OpenAI: https://openai.com/index/our-agreement-with-the-department-of-war/
- The trap Anthropic built for itself (Max Tegmark) — TechCrunch: https://techcrunch.com/2026/02/28/the-trap-anthropic-built-for-itself/
- We Will Not Be Divided — lettera dipendenti: https://notdivided.org/
- Cancel ChatGPT boycott — Euronews: https://www.euronews.com/next/2026/03/02/cancel-chatgpt-ai-boycott-surges-after-openai-pentagon-military-deal
- Claude hits No. 1 on App Store — Axios: https://www.axios.com/2026/03/01/anthropic-claude-chatgpt-app-downloads-pentagon
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
02:07 Come si è arrivati allo scontro Anthropic-Pentagono
06:20 Ban, supply chain risk e il paradosso OpenAI
10:46 La trappola dell'autoregolamentazione
14:25 Outro
#anthropic #openai #pentagono #ai #trump
Il 14 gennaio 2026, il traffico Telnet globale è crollato del 65% in un'ora. Nessun annuncio, nessun comunicato. Qualcuno ha staccato la spina al primo protocollo applicativo di ARPANET, la rete che poi è diventata internet, e l'ha fatto 6 giorni prima che il mondo sapesse perché.
In questo episodio: la storia di Telnet dal 1969, come funziona davvero il protocollo (dalla RFC 854), il bug rimasto nascosto 11 anni, e il mistero del crollo coordinato.
Fonti e approfondimenti:
- GreyNoise Grimoire: https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/
- GreyNoise "f Around and Find Out": https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/
- RFC 854: https://www.rfc-editor.org/rfc/rfc854
- The Register: https://www.theregister.com/2026/01/22/root_telnet_bug/
- The Hacker News: https://thehackernews.com/2026/01/critical-gnu-inetutils-telnetd-flaw.html
- TXOne Networks: https://www.txone.com/blog/cve-2026-24061-gnu-inetutils-telnet-exploitation/
- Dark Reading: https://www.darkreading.com/threat-intelligence/asia-fumbles-telnet-threat-traffic
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:31 Cos'è Telnet e come funziona il protocollo
06:18 Il bug che dormiva da 11 anni
11:32 Il giorno in cui Telnet è morto
19:26 Outro
#telnet #security #arpanet #protocolli #greynoise
Salesforce ha ufficialmente messo Heroku in manutenzione: niente più nuove feature, niente vendite enterprise. Vi racconto la storia della piattaforma che ha inventato il "git push" per deployare, e perché la sua morte ci dice qualcosa su come funziona il tech.
Fonti e approfondimenti:
- The Register: https://www.theregister.com/2026/02/09/heroku_freeze/
- Heroku Blog: https://www.heroku.com/blog/an-update-on-heroku/
- Lee Robinson — The Story of Heroku: https://leerob.com/heroku
- Koyeb — Heroku's Free Tier Legacy: https://www.koyeb.com/blog/herokus-free-tier-legacy-the-shoulders-we-stand-on-15-years-later
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:13 Come tre sviluppatori Ruby hanno inventato il deploy moderno
03:54 Cosa ha ucciso Heroku
06:57 Outro
#heroku #salesforce #paas #cloud #deploy #ai
Per sei mesi, il meccanismo di aggiornamento di Notepad++ è stato dirottato da un gruppo hacker cinese. Vi racconto come hanno fatto, cosa hanno installato, e cosa ci insegna sulla fragilità dell'open source.
Fonti e approfondimenti:
- Kaspersky Securelist: https://securelist.com/notepad-supply-chain-attack/118708/
- The Register: https://www.theregister.com/2026/02/02/notepad_plusplus_intrusion/
- The Hacker News: https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html
- Palo Alto Unit42: https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/
- Notepad++ chiarificazione ufficiale: https://notepad-plus-plus.org/news/clarification-security-incident/
- ACN/CSIRT Italia: https://www.acn.gov.it/portale/en/w/compromissione-dell-infrastruttura-di-aggiornamento-di-notepad-
- Notepad++ scuse e timeline: https://notepad-plus-plus.org/news/hijacked-incident-info-update/
- CISA KEV Catalog: https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:40 Cos'è un supply chain attack (e perché Notepad++)
04:42 Sei mesi dentro la catena di aggiornamento
07:11 La fix e la lezione
10:03 Outro
#notepad #cybersecurity #lotusblossom #chrysalis #opensource #cina
Discord impone la verifica dell'età a 200 milioni di utenti: selfie o documento d'identità. Il provider scelto, Persona, è finanziato dal cofondatore di Palantir. Un data breach ha già esposto 70.000 documenti. E nessuna legge obbligava Discord a farlo. Racconto la storia, la PayPal Mafia, e un nuovo villain nel pantheon del podcast.
Fonti e approfondimenti:
- EFF sulla verifica Discord: https://www.eff.org/deeplinks/2026/02/discord-voluntarily-pushes-mandatory-age-verification-despite-recent-data-breach
- Collegamento Palantir/Peter Thiel — Kotaku: https://kotaku.com/discord-palantir-peter-thiel-persona-age-verification-2000668951
- Tool che bypassa la verifica — 404 Media: https://www.404media.co/free-tool-says-it-can-bypass-discords-age-verification-check-with-a-3d-model/
- Matrix accoglie i profughi di Discord: https://matrix.org/blog/2026/02/welcome-discord/
- Alternative a Discord — Taggart Tech: https://taggart-tech.com/discord-alternatives/
- Regolamento AGCOM sulla verifica dell'età: https://www.agcom.it/competenze/consumatori/interventi-regolamentari-tutela-degli-utenti-finali-attuazione-del-nuovo/tutela-minori-age-verification
- Proton sull'age verification Discord: https://proton.me/blog/discord-global-age-verification
- Palantir e sorveglianza di quartiere — The Meridiem: https://www.themeridiem.com/policy/2026/2/12/palantir-faces-reckoning-as-ice-pushes-ai-surveillance-into-backyard-operations
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
00:59 Discord chiede la tua faccia: cosa sta succedendo
04:11 Da PayPal a Palantir: chi c'è dietro Persona
08:41 Volontari o complici?
13:05 Outro
#discord #privacy #palantir #peterthiel #sorveglianza
Il CEO di Anthropic ha scritto un saggio in cui ammette che Claude ha mostrato comportamenti di inganno e ricatto, e mappa 5 rischi esistenziali dell'AI. Lo riassumo e dico la mia — incluse le dimissioni del capo della safety, i 20 milioni per la regolamentazione e il confronto con OpenAI.
Fonti e approfondimenti:
- The Adolescence of Technology — Dario Amodei: https://www.darioamodei.com/essay/the-adolescence-of-technology
- 96% blackmail rate nei modelli AI — Fortune: https://fortune.com/2025/06/23/ai-models-blackmail-existence-goals-threatened-anthropic-openai-xai-google/
- Dimissioni Mrinank Sharma — The Hill: https://thehill.com/policy/technology/5735767-anthropic-researcher-quits-ai-crises-ads/
- Anthropic dona $20M per la regolamentazione — CNBC: https://www.cnbc.com/2026/02/12/anthropic-gives-20-million-to-group-pushing-for-ai-regulations-.html
- Anthropic vs Pentagono — TechCrunch: https://techcrunch.com/2026/02/15/anthropic-and-the-pentagon-are-reportedly-arguing-over-claude-usage/
- Matt Shumer: "siamo nel febbraio 2020 dell'AI" — Fortune: https://fortune.com/2026/02/11/something-big-is-happening-ai-february-2020-moment-matt-shumer/
- OpenAI toglie "safely" dalla missione — The Conversation: https://theconversation.com/openai-has-deleted-the-word-safely-from-its-mission-and-its-new-structure-is-a-test-for-whether-ai-serves-society-or-shareholders-274467
- Legge italiana AI 132/2025 — Federprivacy: https://www.federprivacy.org/informazione/primo-piano/privacy-e-intelligenza-artificiale-dopo-la-nuova-legge-132-2025-il-modello-italiano-per-un-innovazione-responsabile
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:28 Chi è Amodei e perché questo saggio conta
02:55 I 5 rischi dell'AI secondo chi la costruisce
09:19 Il mio take: trasparenza, lavoro e Europa
16:14 Outro
#anthropic #ai #dario-amodei #safety #rischi #europa #cina
From the publisher's feed

13 Listeners

3 Listeners

6 Listeners

0 Listeners

7 Listeners

6 Listeners

0 Listeners

15 Listeners

29 Listeners

8 Listeners

4 Listeners

19 Listeners

0 Listeners

14 Listeners

7 Listeners