A cool looking retro accessory with an 8x8 monochrome screen!
https://github.com/glutesha/bitlace
#cpp
https://github.com/glutesha/bitlace
#cpp
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
- PoC
- Patch (commit)
- Patch (PR)
#vulnerability #cve #rce
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
_from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.- PoC
- Patch (commit)
- Patch (PR)
#vulnerability #cve #rce
Action bias
Action bias is the psychological phenomenon where people tend to favor action over inaction, even when there is no indication that doing so would point towards a better result.
It is an automatic response, similar to a reflex or an impulse and is not based on rational thinking. One of the first appearances of the term "action bias" in scientific journals was in a 2000 paper by Patt and Zechenhauser titled "Action Bias and Environmental Decisions", where its relevance in politics was expounded.
People tend to have a preference for well-justified actions. The term “action bias” refers to the subset of such voluntary actions that one takes even when there is no explicitly good reason to do so.
Action bias is the psychological phenomenon where people tend to favor action over inaction, even when there is no indication that doing so would point towards a better result.
It is an automatic response, similar to a reflex or an impulse and is not based on rational thinking. One of the first appearances of the term "action bias" in scientific journals was in a 2000 paper by Patt and Zechenhauser titled "Action Bias and Environmental Decisions", where its relevance in politics was expounded.
People tend to have a preference for well-justified actions. The term “action bias” refers to the subset of such voluntary actions that one takes even when there is no explicitly good reason to do so.
An HTML5/Canvas implementation of 8-bit color cycling
http://www.effectgames.com/demos/canvascycle/?sound=0
https://github.com/jhuckaby/canvascycle
http://www.effectgames.com/demos/canvascycle/?sound=0
https://github.com/jhuckaby/canvascycle
Effectgames
Canvas Cycle: True 8-bit Color Cycling with HTML5
Be Careful with Go Struct Embedding
Embedding structs can quietly mask deeper-nested fields: a duplicate field name isn’t ambiguous unless it appears at the same ‘depth’, meaning your program may choose an unintended value.
https://mattjhall.co.uk/posts/be-careful-with-go-struct-embedding.html
#go
Embedding structs can quietly mask deeper-nested fields: a duplicate field name isn’t ambiguous unless it appears at the same ‘depth’, meaning your program may choose an unintended value.
https://mattjhall.co.uk/posts/be-careful-with-go-struct-embedding.html
#go
mattjhall.co.uk
Be Careful with Go Struct Embedding - Matt Hall
The gophers nested too greedily and too deep.
Meshtastic® is a project that lets you use inexpensive LoRa radios as a long range off-grid communicator for areas without reliable cellular service. These radios are great for hiking, skiing, paragliding - essentially any hobby where you don't have reliable internet access. Each member of the mesh can send and view text messages and enable optional GPS based location features.
The radios automatically create a mesh to forward packets as needed, so everyone in the group can receive messages from even the furthest member. The radios will optionally work with your phone, but no phone is required.
https://meshtastic.org/
- firmware
The radios automatically create a mesh to forward packets as needed, so everyone in the group can receive messages from even the furthest member. The radios will optionally work with your phone, but no phone is required.
https://meshtastic.org/
- firmware
🤓1
AMD accidentally posted FSR4's source code (and then tried to delete it all):
https://github.com/GPUOpen-LibrariesAndSDKs/FidelityFX-SDK/commit/01446e6a74888bf349652fcf2cbf5f642d30c2bf
daily reminder that GitHub will keep track of ANY commit you push to your repository even after you WIPE IT OUT from all the branch histories
https://github.com/GPUOpen-LibrariesAndSDKs/FidelityFX-SDK/commit/01446e6a74888bf349652fcf2cbf5f642d30c2bf
daily reminder that GitHub will keep track of ANY commit you push to your repository even after you WIPE IT OUT from all the branch histories
https://support.apple.com/en-us/124925
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Apple Support
About the security content of iOS 18.6.2 and iPadOS 18.6.2 - Apple Support
This document describes the security content of iOS 18.6.2 and iPadOS 18.6.2.
Do It by Code
https://support.apple.com/en-us/124925 Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
High net worth individuals in crypto are currently being targeted because of a Zero-Day exploit in the apple ecosystem
If anyone sends you a picture (iOS or macOS), they can drain your wallets.
Update to the newest iOS and macOS versions immediately.
Logged as CVE-2025-43300, the bug is an out-of-bounds write issue in ImageIO, the component apps rely on to read and write standard image formats. Apple warned that the flaw could let miscreants hijack devices with a booby-trapped image – and for some iDevice users, it sounds like the damage has already been done.
btw iOS exploits are crazy hard and require like 10+ vulnerabilities together sometimes.
source
If anyone sends you a picture (iOS or macOS), they can drain your wallets.
Update to the newest iOS and macOS versions immediately.
Logged as CVE-2025-43300, the bug is an out-of-bounds write issue in ImageIO, the component apps rely on to read and write standard image formats. Apple warned that the flaw could let miscreants hijack devices with a booby-trapped image – and for some iDevice users, it sounds like the damage has already been done.
btw iOS exploits are crazy hard and require like 10+ vulnerabilities together sometimes.
source