Rory McCune's Avatar

Rory McCune

@mccune.org.uk

Security geek, Containers, Kubernetes, Golang/Ruby, hillwalking Home Page :- https://www.mccune.org.uk Blog:- https://raesene.github.io

5,701
Followers
458
Following
269
Posts
24.04.2023
Joined
Posts Following

Latest posts by Rory McCune @mccune.org.uk

Video thumbnail

Yesterday I filmed several baby birds walking across a street directly at my camera and asked Bluesky to suggest music

Several dozen folks did

Some even dubbed music over the original clip.

I haven't been able to get this out of my head.

So I give you

A Bluesky exclusive:

Reservoir Ducks

๐Ÿฃ ๐Ÿชถ

09.03.2026 03:46 ๐Ÿ‘ 2033 ๐Ÿ” 719 ๐Ÿ’ฌ 63 ๐Ÿ“Œ 61

Indeed my talk *should* have been recorded, so hopefully will be available soon :)

06.03.2026 08:52 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

If you want to get your company shouted out on our socials, get an advert in our brochure, and get mentioned in both the opening and closing talks, please get in touch, we are always looking for more sponsors.

04.03.2026 11:37 ๐Ÿ‘ 8 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Obsidian 1.12 is now available to everyone!

- Obsidian CLI
- Bases search
- Image resizing
- Automatically clean up unused images
- Better copy/paste into rich text apps like Google Docs
- Native iOS share sheet

27.02.2026 16:13 ๐Ÿ‘ 169 ๐Ÿ” 22 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 8
Picture of a shop front sign Couper Carpets of Cuper

Picture of a shop front sign Couper Carpets of Cuper

@ministraitor.bsky.social not sure if you're coming across to Dundee for Securi-Tay but if so, you should see if you can get here, so we can have Cooper at Couper Carpets of Cuper!

26.02.2026 19:48 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Really looking forward to Securi-Tay from the Abertay Ethical Hacking Society tomorrow.

If you're there and interested in hearing what 20 years of speaking experience has taught me and how you can hopefully improve your next talk, I'm on at 11:30am in track 3!

securi-tay.co.uk/schedule

26.02.2026 17:15 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Google API Keys Weren't Secrets. But then Gemini Changed the Rules. โ—† Truffle Security Co. Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's no longer true.

If you're using GCP and have enabled Gemini on any of your projects, this one is worth reading, as you may have some checking to do. trufflesecurity.com/blog/google-...

26.02.2026 07:53 ๐Ÿ‘ 7 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I see they're still using the Jags for this, I wonder what proportion of their sales Waymo's make up!

I had the chance to try these out in San Francisco last year, pleasantly surprised by how easy it was and also how well they handled chaotic traffic situations.

24.02.2026 10:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

As the hardware price hikes start impacting server hosting costs, could be a good time to look out those old laptops and desktop you're hoarding (or that could just be me) and see if you can self-host!

22.02.2026 14:48 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
A Look Ahead: Producerโ€™s Letter fromย Toleroย  Read more about the year ahead in Dungeons & Dragons Online in a new Producerโ€™s Letter!

If you are returning to Dungeons & Dragons Online for our anniversary, make sure to read up on our plans for the year in our recently released Producer's Letter on DDO.com: https://www.ddo.com/news/ddo-producer-letter-feb-2026 #DDO

21.02.2026 18:58 ๐Ÿ‘ 6 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Looking forward to the conf. BTW the date on the sessionize page is right, but on that one (kcd.ist/cfp/) it's got the CFP close as Feb 16.

18.02.2026 18:39 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Cloud Native Rejekts Europe 2026 Sat, March 21, 2026

๐Ÿšจ This is not a drill!!! ๐Ÿšจ

The tickets for Cloud Native Rejekts are available NOW! ๐Ÿ˜ฎ

We can't wait to see you all in Amsterdam! ๐Ÿ‡ณ๐Ÿ‡ฑ

pretix.eu/rejekts/reje...

16.02.2026 16:40 ๐Ÿ‘ 10 ๐Ÿ” 8 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 3

There's definitely a lot of new tooling options coming along, although for me a standard dedicated VM for the agent and possibly a scratch VM for doing testing work cover a lot of what's needed and are pretty well understood options from a threat mode/isolation perspective.

16.02.2026 13:25 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I've not written it up yet (I probably should) but yeah for running on hosts, I'd be carefully watching it, definitely no YOLO mode.

For agentic development where I'm letting it do the work I use a dedicated agent VM which only has the code + access to a blank VM for testing.

16.02.2026 13:23 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

@averagemarcus.bsky.social getting started on his talk at @containerdays.bsky.social

11.02.2026 10:57 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Tech impersonators: ClickFix and MacOS infostealers | Datadog Security Labs Datadog identified an active campaign employing fake GitHub repositories impersonating software companies and leveraging the ClickFix initial access technique to deliver macOS infostealers.

Tech impersonators: ClickFix and MacOS infostealers

securitylabs.datadoghq.com/articles/tec...

10.02.2026 14:23 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Voucher redemption :: ContainerDays & MCPconference London 2026

ContainerDays London is THIS WEEK! ๐ŸŽ‰ And I have a โœจ free โœจ ticket code to give away!

If you can make it, but don't have a ticket, grab one for FREE with the following link: pretix.eu/docklandmedi...

09.02.2026 07:58 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

wow didn't expect something like this for heroku!

06.02.2026 17:01 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

If Bilbo had Chat GPT

27.01.2026 16:24 ๐Ÿ‘ 3731 ๐Ÿ” 1065 ๐Ÿ’ฌ 39 ๐Ÿ“Œ 40
Preview
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows | Datadog Security Labs A deep dive into OpenSSLโ€™s January 2026 CMS and PKCS#12 vulnerabilities, including a pre-auth stack overflow and a PKCS#12 parsing bug.

Want a clear analysis of the latest OpenSSL CMS/PKCS#12 vulnerabilities and their real-world impact? Our post explains the conditions required for exploitation and how to evaluate practical risk in your environment.
securitylabs.datadoghq.com/articles/ope...

27.01.2026 19:07 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Introducing IDE-SHEPHERD: Your shield against threat actors lurking in your IDE | Datadog Security Labs IDE-SHEPHERD is an open-source IDE security extension that provides real-time monitoring and protection for VS Code and Cursor. It intercepts malicious process executions, monitors network activity, a...

IDEs are the new browser: massive attack surface, privileged access to various things, and lots of โ€œjust trust it.โ€ Today the Security Research Team at Datadog dropped IDE-SHEPHERD: a tool that watches extensions at runtime and blocks dangerous behavior.

securitylabs.datadoghq.com/articles/ide...

26.01.2026 14:41 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

THE WAIT IS OVER!

CFP is finally live ๐Ÿ’ฃ ๐Ÿ’ฅ

Lessons learned, things that broke, things that worked.... Bring'em all to the stage.

Here is the link:

sessionize.com/kcd-istanbul...

#cfp #community #event #kubernetes #cncf

23.01.2026 17:23 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

Yes, I was replying to Jarno and agreeing with you... not sure why you would read that differently :)

16.01.2026 15:33 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I'd say it somewhat depends on your route into the field. My degree is accountancy, but I went to IT first then to security . The Big-4 in the early 2000's hired a load of non IT grads and trained them up, many of those people are now senior in Infosec/cyber roles.

16.01.2026 15:27 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Cloud Native Rejekts EU 2026: Call for Speakers Cloud Native Rejekts is the b-side conference giving a second chance to the many wonderful, but rejected talks leading to KubeCon + CloudNativeCon.Clo...

Do you have a KubeCon proposal that didn't get accepted? The CFP for Cloud Native Rejekts Amsterdam is still open, until January 17!

Submit!!! แ••(แ›)แ•—

sessionize.com/cloud-native...

14.01.2026 13:04 ๐Ÿ‘ 6 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554 | Datadog Security Labs A look at how Kubernetes CVE-2020-8554 works

I've been meaning to write more about "the unpatchable 4", which are a set of Kubernetes CVEs for which there are no patches, you need to mitigate them with configuration or architecture choices.

First up is CVE-2020-8554.

securitylabs.datadoghq.com/articles/unp...

14.01.2026 09:46 ๐Ÿ‘ 11 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Security BSides Dublin : #BSidesDUB #BSidesDublin Security BSides Dublin is an Information Security conference, by the community, for the community. Follow: @BSidesDublin

๐Ÿ“ข#BsidesDublin2026 - 23/05/26๐Ÿ“ข

Mark those calendars. We are back with #BsidesDublin2026 on the 23 May 2026 in Trinity Business School, Trinity College, Dublin 2.

#earlyBird tickets on sale 10am 13th January ๐Ÿฅณ
www.bsidesdub.ie/tickets.php

08.01.2026 18:46 ๐Ÿ‘ 7 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
07.01.2026 06:07 ๐Ÿ‘ 265 ๐Ÿ” 65 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0
Post image

Merry Christmas and Happy New Venue! Santa has been very kind to us and we're genuinely stoked to announce that Hack Glasgow 2026 will be hosted on Saturday 15th August at the Citizens Theatre!

Youโ€™ll hear more from us in the new year but for now, go tan that last mince pie.

Here we, here weโ€ฆ
HG x

25.12.2025 12:01 ๐Ÿ‘ 6 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Klustered '26 - Live Kubernetes Debugging Competition Where Kubernetes clusters meet their ultimate challenge. Watch experts debug sabotaged clusters live, with real chaos and no safety nets. Sign up to compete or spectate.

Can I temp anyone to a new season of Klustered?

18.12.2025 16:44 ๐Ÿ‘ 7 ๐Ÿ” 2 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1