Cisco's Talos Intelligence Group Blog: CCleanup: A Vast Number of Machines at Risk
Aaargh. Avast seems to have had a build server hacked in order to implant something nasty into production software
Using GraphQL? Why Facebook Now Owns You 🐲
Compelling argument for why GraphQL is not worth supporting because:

> Facebook's GraphQL spec doesn't grant a patent license. Therefore, for reasons as set forth below, most GraphQL users infringe Facebook's patents.
15 Essential Open Source Security Tools | HackerTarget.com
1. Nmap - map your network and ports with the number one port scanning tool. Nmap now features powerful NSE scripts that can detect vulnerabilities, misconfiguration and security related information around network services. After you have nmap installed be sure to look at the features of the included ncat - its netcat on steroids.

2. OpenVAS - open source vulnerability scanning suite that grew from a fork of the Nessus engine when it went commercial. Manage all aspects of a security vulnerability management system from web based dashboards. For a fast and easy external scan with OpenVAS try our online OpenVAS scanner.

3. OSSEC - host based intrusion detection system or HIDS, easy to setup and configure. OSSEC has far reaching benefits for both security and operations staff.

4. Security Onion - a network security monitoring distribution that can replace expensive commercial grey boxes with blinking lights. Security Onion is easy to setup and configure. With minimal effort you will start to detect security related events on your network. Detect everything from brute force scanning kids to those nasty APT's.

5. Metasploit Framework - test all aspects of your security with an offensive focus. Primarily a penetration testing tool, Metasploit has modules that not only include exploits but also scanning and auditing.
Dear Amazon, We Picked Your New Headquarters for You - The New York Times
Let’s skip the nationwide bidding war and cut right to the winner.
amazon 
