Google will begin verifying the identity of ALL DEVELOPERS who distribute apps on Android, even if it's outside the Play Store!
🔗https://www.androidauthority.com/android-developer-verification-requirements-3590911/
Google says that hobbyist & student devs will NOT have to pay the $25 registration fee.
Also, any info you provide won't be shown to Android users, unlike on Google Play.
This is to prevent malware developers from using anonymity as a shield.
🔗https://www.androidauthority.com/android-developer-verification-requirements-3590911/
Google says that hobbyist & student devs will NOT have to pay the $25 registration fee.
Also, any info you provide won't be shown to Android users, unlike on Google Play.
profileTabGifts#4d4bd46a = ProfileTab;
profileTabMedia#72c64955 = ProfileTab;
profileTabMusic#9f27d26e = ProfileTab;
profileTabGifs#a2c0f695 = ProfileTab;
profileTabFiles#ab339c00 = ProfileTab;
profileTabPosts#b98cd696 = ProfileTab;
profileTabLinks#d3656499 = ProfileTab;
profileTabVoice#e477092e = ProfileTab;
channels.setMainProfileTab#3583fcb1 channel:InputChannel tab:ProfileTab = Bool;
> Layer 213
Grok 2.5 is now open source. Grok 3 will be open source in about 6 months
https://huggingface.co/xai-org/grok-2
- hn post
- twitter post
https://huggingface.co/xai-org/grok-2
- hn post
- twitter post
CVE-2025-24893: (severity: 9.8/10)
XWiki Remote code execution as guest via
Any guest can perform arbitrary remote code execution through a request to
This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1.
- PoC (python)
- GitHub Advisory Database
- Template Source
- Macros.vm source
- patch commit
Weakness Enumeration:
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
#cve #vulnerability #java
XWiki Remote code execution as guest via
SolrSearchMacros request.Any guest can perform arbitrary remote code execution through a request to
SolrSearch. This impacts the confidentiality, integrity and availability of the whole XWiki installation.This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1.
- PoC (python)
- GitHub Advisory Database
- Template Source
- Macros.vm source
- patch commit
Weakness Enumeration:
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
#cve #vulnerability #java
Do It by Code
Data-snooping bias Data snooping bias, also known as data dredging or data fishing, occurs when patterns in a dataset are discovered through repeated analysis, and these patterns are then mistakenly taken as real relationships that can be used for prediction…
lets say a simple min-max prediction model has lots of parameters in it, leading to mostly data-snooping.
do you think in such a model, we can solve the data-snooping bias by adding millions of patterns with complex parameters, so it can cover more strict cases but also somehow DOES detect patterns?
do you think in such a model, we can solve the data-snooping bias by adding millions of patterns with complex parameters, so it can cover more strict cases but also somehow DOES detect patterns?
NPM debug and chalk packages compromised
🔸A malicious code was pushed to 18 popular npm packages, hijacking crypto and web3 activity in browsers. The attacker was caught and informed the maintainer after Aikido's intel feed alert, and some compromises were cleaned up.
🔸A malicious code was pushed to 18 popular npm packages, hijacking crypto and web3 activity in browsers. The attacker was caught and informed the maintainer after Aikido's intel feed alert, and some compromises were cleaned up.
Do It by Code
NPM debug and chalk packages compromised 🔸A malicious code was pushed to 18 popular npm packages, hijacking crypto and web3 activity in browsers. The attacker was caught and informed the maintainer after Aikido's intel feed alert, and some compromises were…
packages list:
- backslash (0.26m downloads per week)
- chalk-template (3.9m downloads per week)
- supports-hyperlinks (19.2m downloads per week)
- has-ansi (12.1m downloads per week)
- simple-swizzle (26.26m downloads per week)
- color-string (27.48m downloads per week)
- error-ex (47.17m downloads per week)
- color-name (191.71m downloads per week)
- is-arrayish (73.8m downloads per week)
- slice-ansi (59.8m downloads per week)
- color-convert (193.5m downloads per week)
- wrap-ansi (197.99m downloads per week)
- ansi-regex (243.64m downloads per week)
- supports-color (287.1m downloads per week)
- strip-ansi (261.17m downloads per week)
- chalk (299.99m downloads per week)
- debug (357.6m downloads per week)
- ansi-styles (371.41m downloads per week)
- backslash (0.26m downloads per week)
- chalk-template (3.9m downloads per week)
- supports-hyperlinks (19.2m downloads per week)
- has-ansi (12.1m downloads per week)
- simple-swizzle (26.26m downloads per week)
- color-string (27.48m downloads per week)
- error-ex (47.17m downloads per week)
- color-name (191.71m downloads per week)
- is-arrayish (73.8m downloads per week)
- slice-ansi (59.8m downloads per week)
- color-convert (193.5m downloads per week)
- wrap-ansi (197.99m downloads per week)
- ansi-regex (243.64m downloads per week)
- supports-color (287.1m downloads per week)
- strip-ansi (261.17m downloads per week)
- chalk (299.99m downloads per week)
- debug (357.6m downloads per week)
- ansi-styles (371.41m downloads per week)
> do largest supply chain attack in history
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise
I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT
(stole this post from here)
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise
I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT
(stole this post from here)
🤓2
Do It by Code
> do largest supply chain attack in history > potentially infect millions of apps > doesnt do the thing good > makes $0 from compromise I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of…
Researchers grouped the attacker’s wallets on Arkham under an entity named “NPM attack.” The data shows the attacker managed to steal only $66.
Windows KASLR Bypass – CVE-2025-53136
🔸Microsoft fixed a kernel address leak vulnerability in Windows 11/Server 2022 24H2, but introduced a new bug in CVE-2024-43511. The new bug allows a powerful kernel address leak through a race condition in the RtlSidHashInitialize() function.
11 Sep 2025
comments
🔸Microsoft fixed a kernel address leak vulnerability in Windows 11/Server 2022 24H2, but introduced a new bug in CVE-2024-43511. The new bug allows a powerful kernel address leak through a race condition in the RtlSidHashInitialize() function.
11 Sep 2025
comments
Astrophysics Source Code Library
The Astrophysics Source Code Library (ASCL) is a free online registry and repository for source codes used in astronomy and astrophysics research. It is indexed by the SAO/NASA Astrophysics Data System (ADS) and Web of Science.
The Astrophysics Source Code Library (ASCL) is a free online registry and repository for source codes used in astronomy and astrophysics research. It is indexed by the SAO/NASA Astrophysics Data System (ADS) and Web of Science.