Destaque

publicação mais vista
🔥 Mais popular
И
Ит Вакансии / Работа программиста
@hr_itwork
5.1K

Mirantis is hiring: Principal HPC Network Engineer Location: EU - remote/hybrid Employment: Full-time Compensation: Flexible depending on experience and hiring location.

Mirantis is a global open-source infrastructure company building Kubernetes, cloud-native and AI infrastructure platforms. The company works with customers across 90 countries and helps organisations deploy and operate GPU-powered infrastructure across on-premises, cloud, hybrid and edge environments.

We are looking for a Principal HPC Network Engineer to take technical ownership of high-performance networking environments supporting large-scale HPC and AI/ML infrastructure. This is a senior hands-on role focused on the architecture, deployment, optimisation and troubleshooting of InfiniBand and Ethernet fabrics.

What you’ll work on: Design, deploy and operate high-performance networks for HPC and AI clusters. Own the architecture and optimisation of InfiniBand fabrics. Manage switches, HCAs, subnet managers and fabric configurations. Troubleshoot complex latency, throughput, routing and connectivity issues across InfiniBand and Ethernet environments. Lead performance tuning, monitoring and capacity planning. Deploy and support Fortinet solutions, including FortiGate, FortiManager and FortiAnalyzer. Partner with compute, storage and platform teams to support cluster operations. Lead critical incident escalations, network upgrades, migrations and new deployments. Define network standards, operational procedures and technical documentation.

What we’re looking for: Deep hands-on experience with InfiniBand, ideally Mellanox/NVIDIA. Strong networking expertise across TCP/IP, BGP, OSPF, VLANs, QoS and network architecture. Experience supporting HPC, data centre or large-scale AI/ML infrastructure. Practical experience with Fortinet products and firewall configuration. Knowledge of RDMA, MPI and low-latency networking concepts. Linux administration and automation skills using Bash or Python. Experience with Ansible, Terraform or other Infrastructure-as-Code tools is a plus. Ability to independently own complex technical challenges and act as a senior escalation point.

Why join Mirantis? Work directly with advanced NVIDIA, InfiniBand, HPC and AI infrastructure rather than conventional enterprise networking. Take real technical ownership of architecture, performance and reliability. Solve complex production problems where network design directly affects GPU utilisation and AI workload performance. Influence standards, tooling and future infrastructure deployments instead of only maintaining an established environment. Work across networking, compute, storage, Kubernetes and AI platform teams. Join a company deeply involved in Kubernetes, open-source infrastructure and the development of next-generation AI platforms.

Interested? Send me a direct message with your LinkedIn profile or CV, and I’ll share more details @Yuliana_S_22

Mais de outros canais

254 publicações no total
🤖 Tudo Sobre IA
@tudosobreia
151

Hook: Quer um assistente de código super inteligente e grátis pra projetos grandes? Essa IA faz exatamente isso!

O que faz: O plandex é um agente de IA open source que atua como seu copiloto de código. Ele é feito sob medida para tocar projetos de programação maiores e lidar com desafios reais.

Destaque prático: Seu diferencial é atuar como um agente autônomo, mergulhando fundo em projetos complexos de verdade e não só gerando snippets.

Perfeito para... Devs, engenheiros e qualquer um que trabalhe em projetos de código ambiciosos e precise de um agente de IA robusto e gratuito.

Link direto: 👉 Acesse aqui: https://github.com/plandex-ai/plandex

I
Information Security
@information_security_channel
281

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/

Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research (https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/) appeared first on SecurityWeek (https://www.securityweek.com/).

B
BleepingComputer
@bleepingcomputer
627

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]

https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/

I
INCUBE.AI | Нейросети и не только
@incubeai_pro
694

Собираем свой навигатор: на GitHub вышел GeoLibre — бесплатная open-source платформа для работы с геоданными.

Внутри — более 700 инструментов для обработки карт, 3D-здания, полноценные глобусы Земли и других небесных тел. Есть даже уличные панорамы с архивом снимков за 10 лет.

Можно собирать эффектные визуализации или анимации и даже завайбкодить свой аналог Google Maps с офлайн-картами.

Забираем тут.

INCUBE.AI | ПОДПИСАТЬСЯ

T
Technogram Inside | IT
@techograminside
1.3K

Найден убийца PowerPoint

Вышел опенсорсный редактор презентаций Bento. Он работает без интернета, весит всего 560 КБ и поддерживает PDF-экспорт, графики, комментарии, анимации и совместное редактирование в реальном времени.

Пробуем бесплатно – тут.

Technogram Inside

S
SITREP - Independent OSINT Channel
@sitreports
566

🤖 Autonomous AI agents enter the offensive cyber stack

Resecurity’s analysis outlines how tools including T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula can automate attack-surface mapping, vulnerability discovery, exploit validation, and reporting with minimal human input. The report frames these systems as dual-use and increasingly accessible beyond high-skill operators.

The operational effect is a lower barrier for financially motivated actors and faster scaling of intrusion workflows. The core shift is from scripted automation to adaptive, multi-stage decision-making, compressing time between reconnaissance and exploitation while forcing defenders toward hybrid AI-plus-human security models.

🛰️ Open sources - closed narratives @sitreports

Y
Yandex for Frontend
@yandex4frontend
2.1K

🔆 Авторские каналы наших фронтендеров

В Яндексе мы не только пишем код, но и много размышляем о технологиях, управлении, AI и даже искусстве.

➡️ Собрали для вас классную подборку авторских каналов, где ребята делятся мыслями, инсайтами и личным опытом

Кто пишет сейчас:

🟡 Veged and Code Сергей Бережной, CTO Практикума и директор по взаимодействию с разработчиками, ведёт канал о работе в IT, принятии решений и опенсорсе.

🟡 mefody.dev Никита Дубко, Chief Contest Officer, пишет про фронтенд, тимлидство и спикерство.

🟡 Synaptic Garden Роман Барлос, руководитель группы Storage Platform UI, и его канал на стыке AI, науки, философии и искусства.

🟡 Даниэль Ленц — блог Даниэль Ленц, разработчик интерфейсов, говорит про фронтенд и делится личным опытом.

🟡 ТОП — Тёма о программировании Тёма Сенюков, руководитель сектора в службе разработки AI-продуктов, преподаёт и рассказывает о частых проблемах во фронтенде, обучении, карьере.

🟡 axaxadev Денис Князев, старший разработчик интерфейсов, ведёт канал про фронтенд, UX/UI, дизайн-системы, DX и Node.js.

🟡 nikalexxx Александр Николаичев, руководитель разработки IDP, делает инфраструктуру Яндекса, рисует и любит математику.

🟡 Гриненко про ИИ, бизнес и образование Владимир Гриненко, предприниматель и экс-CTO Яндекс ID, рассказывает про переход из найма в своё дело и про то, как AI меняет правила игры.

Подписывайтесь: 💬 @Yandex4Frontend

I
INCUBE.AI | Нейросети и не только
@incubeai_pro
728

Slaide — open source инструмент, который превращает Markdown в презентации с помощью AI.

Слайды можно описывать обычным текстом в Markdown, а нейросеть затем собирает из них готовую презентацию. Готовый файл открывается в PowerPoint, поэтому им удобно делиться и дорабатывать его в привычном редакторе.

Подойдёт тем, кто предпочитает делать презентации текстом, а не собирать блоки мышкой.

INCUBE.AI | ПОДПИСАТЬСЯ

S
SITREP - Independent OSINT Channel
@sitreports
476

🔍 U.S. troop telecom exposure remains a known but unresolved vulnerability

A DefenseScoop analysis argues that hostile actors can exploit legacy telecom signaling systems such as SS7 to track service members, intercept calls and texts, spoof numbers, and disrupt service without phishing or malware. The piece links the issue to recent concern over Iran targeting U.S. personnel via smartphones and notes the Pentagon’s current cellular contracting cycle runs to 2034.

The key point is structural: user discipline does not mitigate a network-level weakness. The article frames the gap as a policy and procurement failure spanning carriers, regulators, Congress, and DoD, with battlefield mobility now directly tied to insecure commercial telecom infrastructure.

🛰️ Open sources - closed narratives @sitreports

Я
Яндекс нанимает | Вакансии для разработчиков
@ya_jobs
1K

❣️ Руководитель команды в группу LLM

Мы делаем Алису умнее. Для этого нужны комплексные инструменты. Мы создаём агентов для взаимодействия с реальным миром: бронирования, Заметки, Яндекс 360 — всё это срез задач ML-консьержа. Эти инструменты нужно правильно применять. Поэтому мы разрабатываем агента Zero — решаем задачу оркестрации для всей функциональности Алисы. Наша глобальная цель — сделать единую точку входа для решения произвольных задач пользователей.

Какие задачи вас ждут:

• Руководство ML-командой Вы будете управлять командой ML-разработчиков: ставить цели, налаживать взаимодействие со смежниками, курировать полный цикл ML-разработки. Важной задачей будет развитие команды: рост экспертного опыта, поиск кандидатов и проведение собеседований, создание новых задач.

• Обучение моделей Вам предстоит обучать большие LLM-системы: заводить SFT и RL поверх внутренних (YaGPT) и внешних (SOTA Open Source) моделей.

• Развитие продукта Вы будете анализировать данные, генерировать направления роста, проверять гипотезы в проде и делать продукт лучше.

• Внедрение SOTA-подходов Нужно будет следить за трендами в сфере, ставить амбициозные цели, проводить эксперименты и доводить успешные исследования до внедрения.

Мы ждем, что вы: • Руководили ML-командой • Работали над кросс-функциональными проектами • Запускали ML-системы в продакшен • Разбираетесь в SOTA-подходах • Хотите сделать Алису лучше

Будет плюсом, если вы: • Работали с RAG-системами и агентами • Выступали на конференциях

Что мы предлагаем: Сотрудники Яндекса бесплатно участвуют в профильных конференциях. А для тех, кто на них выступает, у нас есть школа подготовки спикеров. Это далеко не все бонусы — больше можно узнать тут.

📩 Откликайтесь на вакансию на нашем сайте

#алиса_и_умные_устройства #senior #lead #тимлид #ML #LLM #алиса #AI #офис #гибрид #москва #минск

S
SITREP - Independent OSINT Channel
@sitreports
432

📡 Air Force widens vendor pool for CCA Increment 2

The U.S. Air Force says up to six vendors could move into early prototyping for CCA Increment 2 after roughly 10 more months of concept refinement with nine unnamed companies. The program will then proceed to prototype and production awards, while propulsion work already spans six vendors across small and medium engine classes, including clean-sheet designs.

The structure shows the Air Force preserving competition deeper into the acquisition cycle than Increment 1. The engine decision is also a key signal: Increment 2 requirements are diverging from rapid fielding priorities toward higher-performance, longer-life robotic wingmen within the NGAD ecosystem.

🛰️ Open sources - closed narratives @sitreports

G
GitHub Trends
@githubtrending
431

#typescript #hacktoberfest #hono #issue_management #issue_tracker #jira_alternative #kanban #linear_alternative #project_management #react #self_hosted #typescript

Kaneo is a free, open-source, self-hosted project management tool made for simple, fast teamwork, with a clean interface, strong performance, and full control over your data. It helps you manage tasks and collaborate without extra complexity, so you can stay focused and work faster while keeping your own setup and privacy.

https://github.com/usekaneo/kaneo

З
Записки Безопасника
@infosec_globe
591

🏠 Кто на самом деле Domain Admin в вашем AD

Adalanche – опенсорс-визуализатор графа атак в Active Directory от Ларса Карлслунда, показывающий, кто в реальности способен получить права администратора домена.

— В отличие от BloodHound не требует neo4j и установки: один бинарник собирает дамп AD и поднимает веб-граф в браузере, подсвечивая проблемы делегирования, kerberoastable-аккаунты и уязвимости AD CS.

Результат появляется за минуты даже у непривилегированного пользователя, те же пути, что увидит и злоумышленник внутри домена.

🖥 GitHub

☑️ Записки Безопасника

⭐️ max.ru/infosec_globe

S
SITREP - Independent OSINT Channel
@sitreports
396

📡 Teams vishing chain tied to Chaos ransomware

Sophos says threat cluster STAC4749 targeted dozens of North American organizations from February to June 2026 by posing as IT support in Microsoft Teams chats and calls. Victims were pushed to launch Quick Assist or RemSupp, after which attackers used PowerShell to drop persistence and backdoor access. At least three intrusions ended with Chaos ransomware, including one case where encryption began in under 17 hours.

The campaign shows a compressed social-engineering-to-encryption timeline and a shift toward legitimate remote admin tooling that blends into normal support workflows. The repeated use of fake support personas, .top IT-themed domains, and backup access tools indicates a disciplined access playbook rather than opportunistic spam.

🛰️ Open sources - closed narratives @sitreports

Н
Нейро Ликбезик | Кирилл Безиков
@kirillbezikov
442

Топ-5 репозиториев с GitHub за эту неделю⚡️

Продолжаю делиться с вами полезными находками под разные задачи

1️⃣ Awesome Claude Skills 70К ⭐️ · github.com/ComposioHQ/awesome-claude-skills

Что это: готовая библиотека из 200+ расширений для Claude. Устанавливаешь и Claude начинает работать иначе: не придумывает лишнего, задаёт правильные вопросы, держит стиль. Кому подойдёт: всем, кто работает с Claude и хочет получать более точные результаты без долгой настройки. Какую задачу решает: вместо того чтобы каждый раз объяснять Claude как себя вести, ставишь скилл один раз и он работает по правилам автоматически. 🇷🇺 Просто текстовые файлы, работают без ограничений.

2️⃣ i-have-adhd 14К ⭐️ · github.com/ayghri/i-have-adhd

Что это: скилл для Claude, который убирает воду из ответов — выдаёт чёткий результат без лишних объяснений и предисловий. Кому подойдёт: тем, кого раздражает когда Claude пишет три абзаца вместо одного конкретного ответа. Какую задачу решает: ставишь скилл один раз и агент сразу переходит к делу 🇷🇺 Работает без ограничений, скилл это текстовый файл.

3️⃣ Sim Studio 29К ⭐️ · github.com/simstudioai/sim

Что это: визуальный конструктор агентных систем — строишь агента мышкой, соединяешь блоки, запускаешь без кода. Кому подойдёт: предпринимателю или специалисту, который хочет собрать рабочий агент без программиста. Какую задачу решает: убирает техническую часть, не нужно писать код, разбираться в API. Нарисовал схему и агент работает. 🇷🇺 Open-source, ставится локально или через Docker без ограничений по географии.

4️⃣ Open SEO 8К ⭐️ · github.com/every-app/open-seo

Что это: бесплатная замена Semrush и Ahrefs, которую ставишь к себе. Кому подойдёт: маркетологу, SEO-специалисту или агентству, которое платит за дорогие подписки на аналитику. Какую задачу решает: анализ ключевых слов, проверка ссылочной массы, интеграция с Google Search Console — всё без ежемесячных платежей. 🇷🇺 Устанавливается локально, Google Search Console работает в России без ограничений.

5️⃣ Claude Code Merge Queue HN↑41 · github.com/funador/claude-code-merge-queue

Что это: инструмент, который следит за тем, чтобы несколько ИИ-агентов не мешали друг другу, когда работают над одним проектом одновременно. Кому подойдёт: тем, кто запускает несколько агентов параллельно на один и тот же проект. Какую задачу решает: когда два агента редактируют один и тот же файл, возникают ошибки. Этот инструмент выстраивает очерёдность — каждый агент дожидается своей очереди и не ломает чужую работу. 🇷🇺 Работает полностью локально, без регистрации и подписок.

——————————— Кстати, если хотите разобраться как выстраивать работу с ИИ под свои задачи — жду вас на НейроМаксе: практический марафон по ИИ-инструментам и автоматизации с нуля.

👉 Забрать доступ

#ИИ #GitHub #Агенты #Автоматизация #ClaudeCode

N
no system is safe // cybersec
@nsis_cybersec
1.2K

😈 RCE-уязвимость в Fastjson используется в атаках

Хакеры начали эксплуатировать критическую уязвимость в Java-библиотеке Fastjson. Баг позволяет удаленно выполнять код без аутентификации и взаимодействия с пользователем.

Fastjson — опенсорсная Java-библиотека, разработанная компанией Alibaba, которая используется для сериализации объектов Java в JSON и обратно.

➖Проект набрал более 25 600 звезд и имеет 6400 форков на GitHub и особенно популярен в китайском сегменте корпоративного ПО, а также применяется в проектах, созданных на платформе Alibaba.

➡️https://xakep.ru/2026/07/30/fastjson/

#News #Fastjson #RCE #Hack #Attack #Patch #Vulnerability // @nsis // max.ru/nsis

S
SITREP - Independent OSINT Channel
@sitreports
371

🔍 DPRK-Linked macOS Malvertising Pushes Fake Updates

A new macOS malvertising campaign linked to DPRK actors uses fake software update lures to deliver cryptocurrency-stealing malware. The operation targets Apple users through deceptive update prompts, with the payload focused on wallet and asset theft rather than broader system disruption.

The tradecraft blends low-friction social engineering with platform-specific targeting, showing continued DPRK emphasis on direct revenue generation. Fake update chains remain effective because they exploit routine user behavior while masking malware delivery inside a familiar security action.

🛰️ Open sources - closed narratives @sitreports

L
Lobby X
@lobbyx
1.6K

​​🛫 ArduPilot Integration Engineer до Postman

Огляд: Postman — швидкозростаючий український виробник безпілотних авіаційних систем — шукає до команди спеціаліста з ArduPilot та інтеграції обладнання.

Основні обов‘язки: • налаштування та конфігурація БПЛА на базі ArduPilot • інтеграція сенсорів, камер, GNSS-модулів, телеметрії, Starlink та інших • проведення тестових польотів на полігоні • налаштування PID-регуляторів, калібрування систем та аналіз польотних логів • пошук і усунення технічних проблем під час інтеграції та випробувань

Обов’язкові вимоги: • практичний досвід роботи з ArduPilot, PX4 або іншими open-source стеками автопілотів • досвід пілотування БПЛА літакового типу • досвід налаштування PID-регуляторів • досвід із Mission Planner, QGroundControl або іншими наземними станціями управління • розуміння принципів роботи БПЛА, систем стабілізації, основ аеродинаміки та конструкції літальних апаратів

Умови роботи: • офіційне працевлаштування • бронювання для військовозобов'язаних • робота в офісі у м. Одеса

Щоб ознайомитися з деталями та залишити відгук на вакансію — переходьте на сайт: https://thelobbyx.com/tor/ardupilot-integration-engineer-m-odesa-to-postman-rec/

#miltech #engineering

S
SITREP - Independent OSINT Channel
@sitreports
378

🔍 JetBrains flags critical TeamCity auth bypass with RCE impact

JetBrains says CVE-2026-63077 affects all TeamCity On-Premises versions, allowing an attacker with HTTPS access to bypass authentication via the agent polling protocol and execute OS commands with server-level privileges. Fixed builds are 2025.11.7 and 2026.1.3, while a patch plugin is available for TeamCity 2017.1+ in the advisory. TeamCity Cloud is not affected.

The flaw directly impacts CI/CD infrastructure, with potential exposure of stored credentials, build artifacts, server configuration, and pipeline integrity. JetBrains also warns that internet-facing TeamCity instances increase risk, even when only the login page or REST API is exposed.

🛰️ Open sources - closed narratives @sitreports

S
SITREP - Independent OSINT Channel
@sitreports
359

🔍 VMware patches critical auth bypass and VM escape flaws

Broadcom released emergency fixes for five VMware vulnerabilities affecting vCenter, ESX, Workstation, Fusion, and related cloud/telco stacks. Three are critical: CVE-2026-59309 and CVE-2026-59310 enable unauthenticated access and code execution on vCenter, while CVE-2026-47876 allows a VM escape via the VMXNET3 adapter. No workarounds are available.

The issue set directly impacts core virtualization management and host isolation. Broadcom classed the updates as emergency changes; vCenter patching interrupts management access, and ESX updates require host restarts or live migration planning. The vendor says there is no sign of in-the-wild exploitation.

🛰️ Open sources - closed narratives @sitreports

S
SITREP - Independent OSINT Channel
@sitreports
368

🔍 Amazon ties npm supply-chain breaches to Sapphire Sleet

Amazon has linked the 2025–2026 compromises of typo-crypto, debug, chalk, and axios in the npm ecosystem to Sapphire Sleet, the DPRK-linked actor also known as BlueNoroff and Stardust Chollima. The assessment is made with medium confidence and is based on shared TTPs, C2 infrastructure, and operational overlap. Amazon says maintainers were socially engineered before malicious updates were pushed downstream.

The key point is continuity across several major package incidents, not isolated breaches. Amazon also points to more mature tradecraft: months-long trust building, split malicious logic across packages, remote staging, stronger encryption, and environment-aware execution to evade static analysis and sandboxes.

🛰️ Open sources - closed narratives @sitreports

D
DevOps&SRE Library
@devopslibrary
1.7K

Build your own Managed Kubernetes Service on Proxmox with CAPI

Cluster API (CAPI) is an open-source Kubernetes sub-project. Its goal is to bring Kubernetes-style, declarative APIs and controllers to the problem of bootstrapping, configuring, upgrading and operating entire Kubernetes clusters, treating clusters themselves as first-class Kubernetes resources rather than as external, manually-provisioned infrastructure.

https://itnext.io/build-your-own-managed-kubernetes-service-on-proxmox-with-capi-8d9786644818