Do It by Code
54 subscribers
715 photos
100 videos
15 files
1.25K links
We uhhhhh... do things by coding them.
Download Telegram
🤓1
Do It by Code
Critical RCE Vulnerabilities in React and Next.js Severity: 10/10 The important part to know: - Even if your app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components. - The vulnerability…
apparently there are so many AI-generated slop PoC out there for this that it takes hours to find a proper working PoC among them
most of them are just nonsense

I found a few that don't seem to be AI slop:
- msanft/CVE-2025-55182
- acheong08/CVE-2025-55182-detection
- mrknow001/RSC_Detector
- emredavut/CVE-2025-55182

one of the AI-generated ones made its way to the official cve website and people complained in its issue section
Do It by Code
cloudflare is down again 🙏
this time they are not even showing their cool page 😭
Do It by Code
- mrknow001/RSC_Detector
exploitation of CVE-2025-55182 has reached a new level. There’s now a publicly available Chrome extension on GitHub that automatically scans for and exploits vulnerable sites as you browse.
source - @sbrugnadlbot
rest in peace
source - @sbrugnadlbot
A year ago, we verified a preview of an unreleased version of @OpenAI o3 (High) that scored 88% on ARC-AGI-1 at est. $4.5k/task

Today, we’ve verified a new GPT-5.2 Pro (X-High) SOTA score of 90.5% at $11.64/task

This represents a ~390X efficiency improvement in one year
source - @govd_bot
We also verified that GPT-5.2 Pro (High) is SOTA for ARC-AGI-2, scoring 54.2% for $15.72/task

(Due to API timeouts, we were unable to reliably verify GPT 5.2 Pro X-High on ARC-AGI-2)

All verified GPT-5.2 family scores:
Hacker News
Denial of service and source code exposure in React Server Components Article, Comments
The patches published earlier are vulnerable. 
If you already updated for the Critical Security Vulnerability last week, you will need to update again 😇

Or just don't use javascript and react in backend
Telegram is updating its censorship circumvention code to mimic Google Chrome's Post-Quantum Cryptography handshake (the TLS fingerprinting)

ml_kem_768_key function in this commit is a function that generates a fake ML-KEM-768 (Kyber) key so that deep packet inspection firewalls (DPI) think the packet just belongs to google chrome sending data over TLS, but Telegram servers likely ignore these random bytes and just uses the underlying MTProto encryption instead
CVE-2025-14174 (works only on Mac)

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

couldn't find any PoC for it and since I don't have mac, I can't really test it

#cve
GitHub is updating its Actions pricing structure:

On March 1, 2026, we are introducing a new $0.002 PER-MINUTE GitHub Actions cloud platform charge THAT WILL APPLY TO SELF-HOSTED runner usage. Any usage subject to this charge will count toward the minutes included in your plan.
Forwarded from HN Best Comments
Re: Pricing Changes for GitHub Actions

It is us, developers, who convinced our management to purchase GitHub Enterprise to be our forge. We didn't pay any heed to the values of software freedom. A closed source, proprietary software had good features. We saw that and convinced our management to purchase it. Never mind what cost it would impose in the future when the good software gets bad owners. Never mind that there were alternatives that were inferior but were community-developed, community-maintained and libre.

The writing is in the wall. First it was UX annoyances. Then it was GitHub Actions woes. Now it is paying money for running their software on your own hardware. It's only going to go downhill. Is it a good time now to learn from our mistakes and convince our teams and management to use community-maintained, libre alternatives? They may be inferior. They may lack features. But they're not going to pull user hostile tricks like this on you and me. And hey, if they are lacking features, maybe we should convince our management to let us contribute time to the community to add those features? It's a much better investment than sinking money into a software that will only grow more and more user hostile, isn't it?

throwaway150, 5 hours ago
1
bruh
Forwarded from vx-underground
I have a website for my malware source code. I have named it "malwaresourcecode", a very unique and inspiring name

malwaresourcecode.com
Forwarded from HN Best Comments
Re: Beginning January 2026, all ACM publications will be made open access

The financials of open access are interesting.

Instead of journals getting revenue from subscribers, they charge authors an “Article Processing Charge” (APC) which for ACM is $1450 in 2026 and expected to go up. Authors from lower-middle income countries get a discount. [1]

Authors are often associated with institutions (e.g. universities) who can cover the APC on behalf of the author through a deal with the journal. For the institution, now instead of paying the subscriber fee and publishing for free, they pay a publishing fee and everyone reads for free.

1. https://authors.acm.org/open-access

trainyperson, 13 hours ago