DevOps Bulletin

DevOps Bulletin

Digest #183: GitHub Actions Exploit, Malicious MCP Server, Redis RCE, Scaling MySQL for 150M+ users

Orca Security exposes a GitHub Actions exploit letting forked PRs inject malicious code, Snyk finds a fake MCP server harvesting emails, Wiz reveals a critical Redis RCE bug + open source projects.

Mohamed Labouardy's avatar
Mohamed Labouardy
Oct 10, 2025
∙ Paid

Welcome to this week’s edition of the DevOps Bulletin!

Orca Security exposed a new GitHub Actions exploit, letting forked PRs inject malicious code, while Snyk found a fake MCP server on npm stealing emails. Wiz uncovered a critical Redis RCE flaw affecting thousands of instances, and Flipkart shared how it built a highly available MySQL cluster for 150M…

Keep reading with a 7-day free trial

Subscribe to DevOps Bulletin to keep reading this post and get 7 days of free access to the full post archives.

Already a paid subscriber? Sign in
© 2025 Mohamed Labouardy
Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture