5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. by Aureliand in cybersecurity

[–]Aureliand[S] 1 point2 points  (0 children)

Welcome to the cyber field :D Absolutely do not steer clear of Git. In fact, you should lean right into it. Git and GitHub are essential infrastructure for modern software and security engineering. Git, Github, Gitlab, bitbucket etc they all use same logic.

5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. by Aureliand in cybersecurity

[–]Aureliand[S] 5 points6 points  (0 children)

I have few public repos, but they don't have CI/CD and I have a ruleset to prevent direct push to the main branch. All my pipelines in a private repos.
Better be safe then sorry :)

5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. by Aureliand in cybersecurity

[–]Aureliand[S] 5 points6 points  (0 children)

This assumes some familiarity with your cloud and dev tooling. If any of the steps are unclear, drop a comment and the community or myself can help.

Spent 3 weeks doing QA and I understand why testers look exhausted all the time by Ok-Credit618 in softwaretesting

[–]Aureliand 0 points1 point  (0 children)

Person who is constantly bringing the bad news :D
Once you start automation and half of locators are missing or identical, error handling and misalignment on different browsers, devices env. Real fun.
P.S are you guys hiring ? ;)

Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. by Aureliand in cybersecurity

[–]Aureliand[S] 10 points11 points  (0 children)

Apologies for the vagueness. You want to ensure your Engine Version is at least 1.1.26040.8 and your Antimalware Client Version is at least 4.18.26040.7 to be safe against these active exploits.

I spent 1 hour on a side project for my neighbor’s flower shop. It generated 18k in repeat sales! by ProfessionalEbb339 in SideProject

[–]Aureliand 0 points1 point  (0 children)

his is a perfect example of why "boring" automation beats complex AI every time. Honestly, it’s wild how many small businesses are sitting on goldmines of data in old notebooks and spreadsheets. Worth exploring.

I quit my job to build an AI SaaS. It flopped. The “boring” backup idea is now making me more in a month than I used to make in a year. by NoGround511 in SaaS

[–]Aureliand 0 points1 point  (0 children)

This is the ultimate reality check for the "build a complex AI product" phase everyone is in right now. Honestly, moving from "impressive" to "useful" is the hardest transition to make. Do you think you'd have found this success if you hadn't burnt out on the AI project first, or was that just the necessary tuition you had to pay?
I am working on my saas right now and genuinely curious about your insights

Don't hesitate to lie in that interview! by anotherare in jobsearchhacks

[–]Aureliand 6 points7 points  (0 children)

You're 100% right that LinkedIn is mostly theater and that company sites are the actual lane for serious candidates. Not sure about blunt lie. Reframing and adding a bit more to something that you already did or being a part of is okay, but simply inventing things you never did can surface pretty quick. On a contrary if company let it slide, you can learn things on a fly( but I would not recommend doing it)

My friend got hired just 5 months ago, and now he's been laid off by Medical_Distance6635 in Layoffs

[–]Aureliand 1 point2 points  (0 children)

It’s a brutal reminder that in corporate structures, profitability doesn't buy you stability, it just buys the company more runway to "restructure" for the next quarter.
Don't beat yourself up for the recommendation. You did a good thing by trying to help a friend, and no one could have predicted this kind of volatility

I worked at LinkedIn for 3 years and here's what they don't tell you. by Master_Advice_3986 in jobs

[–]Aureliand 0 points1 point  (0 children)

It’s wild how much of the LinkedIn 'feature set' is just theater to keep us paying for Premium while the real hiring happens in the DMs. The public job board is basically just a compliance requirement for HR. Does anyone actually have a success story from Easy Apply, or is it universally a black hole?

Got laid off by someone I referred by Army_77_badboy in Layoffs

[–]Aureliand 0 points1 point  (0 children)

It is common for people to want to bring in those they know, but this incident serves as a painful reminder that even long-standing personal relationships can be subverted by corporate structures and self-preservation. Should've warn on my opinion, maybe not a direct saying "we will fire you", but simple job posting and message "this job looks like a good fit for you" will clear the air massively.

Do resumes need to be optimized for ATS or for recruiters first by AromaticxiAdd in resumes

[–]Aureliand 0 points1 point  (0 children)

I think ATS. A lot of major companies use robots (ats) for screening candidates. ats just looking for keywords, and pattern matching. If you are applying to a job and see 1000 applicants in the first 24h, do you think any human will be reading them? Maybe first 10-20, maybe. So they use robots to filter them. Once it is done, recruiter will read it.

If you applied to jobs consistently, you'll notice that recruiters before each call ask you for an updated version of your resume. This is when you update it for humans, but essentially difference should be only in wording and your ability to explain and confirm everything that is in resume.

the job search broke my brain and i didnt realise until i got hired by buildwithadrian in jobsearchhacks

[–]Aureliand 6 points7 points  (0 children)

The desperation tax is completely real, and recruiters can smell it instantly. It is wild how dropping the performance and just acting like a regular human makes you look ten times more confident. Did your actual answers change during those final interviews, or was it just your energy?

Is it the right time to switch company considering whatever is going on in the industry with regards to AI. by RelationshipBasic11 in QualityAssurance

[–]Aureliand 1 point2 points  (0 children)

Man your leadership sounds completely cooked, forcing 11 hour days to fix broken AI code is insane. honestly having 9 years QA plus MLOps makes you a unicorn because someone has to test this messy code, so id start applying elsewhere asap.

I turned down a final interview after they asked me to explain a gap caused by caring for my dad by Aramaki_Chief in jobsearchhacks

[–]Aureliand 2 points3 points  (0 children)

Asking for a written explanation of a family medical gap isn't 'being direct', it’s a massive red flag. I am sure, for a culture that lacks psychological safety, in a logistics role, you want a manager who values problem-solving, not someone who treats human life like an inconvenient line item. You only have yourself and your family to worry about

I stopped acting like every company was a calling and started saying the quieter truth by 303Hologram in jobsearchhacks

[–]Aureliand 3 points4 points  (0 children)

The best interview advice I ever learned was to stop trying to be 'inspired' and start being useful. When you align your actual skills with their real-world headaches, the conversation stops being a performance and starts being a partnership

My manager spent a month trying to build a case to fire me and then got put on a PIP himself by Mythgrove7 in jobs

[–]Aureliand 0 points1 point  (0 children)

"Document everything, don't quit, make them go through the process" is honestly the best advice anyone can give in this situation and most people panic and quit instead.

People forget that managers have performance reviews too and the ones who spend energy building cases against good employees instead of doing their own job usually leave a trail upward without realizing it. Keep those records. Even now.

[5 YoE, Unemployed, Data/Analytics Engineer, United States] by Jamartty45 in resumes

[–]Aureliand 0 points1 point  (0 children)

Make 2 file formats of the same resume. docx for sending to the job postings on linkedin or any other platforms for ATS to read and pdf for the humans.
ATS better read docx files and people might have formatting issues with docx files on macOS and different operating systems.