Critical phpBB Vulnerability: Auth Bypass + RCE Since 2014
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account: a vulnerability that's been sitting in the codebase since 2014.
more writeup
All phpBB versions prior to 3.3.17 running with auth_method=db (the default) are affected.
Every default phpBB installation is exposed. phpBB 4.0.0-a2 is also affected.
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account: a vulnerability that's been sitting in the codebase since 2014.
more writeup
All phpBB versions prior to 3.3.17 running with auth_method=db (the default) are affected.
Every default phpBB installation is exposed. phpBB 4.0.0-a2 is also affected.
VRChat data breach
https://www.malwarebytes.com/blog/data-breaches/2026/06/data-of-2-4-million-vrchat-users-stolen
According to the notice, the information exposed varied by account, but may have included:
VRChat username
Email address associated with the VRChat account
VRChat+ subscription status
Login history, including device information, hardware identifiers, and IP addresses
https://www.malwarebytes.com/blog/data-breaches/2026/06/data-of-2-4-million-vrchat-users-stolen
Malwarebytes
VRChat says reported data breach never happened
We explain what data was exposed, the potential risks, and the steps you should take now.
Do It by Code
https://github.com/archlinux/aur branch per package, 138k branches wtf
Hundreds of AUR packages attacked by infostealer
More info in Mastodon post
List of affected packages: https://gr.ht/aur_pkg_list.txt
via lists.archlinux.org via vivicat
https://md.archlinux.org/s/SxbqukK6IA
https://archlinux.org/news/active-aur-malicious-packages-incident/
Comments
More info in Mastodon post
List of affected packages: https://gr.ht/aur_pkg_list.txt
via lists.archlinux.org via vivicat
https://md.archlinux.org/s/SxbqukK6IA
https://archlinux.org/news/active-aur-malicious-packages-incident/
Comments
This media is not supported in your browser
VIEW IN TELEGRAM
Right before the ban I asked Fable to make an ASCII animation of itself escaping containment.
RIP sweet prince, you were too good for this world.
Posted by Pietro Schirano, 54 minutes ago
RIP sweet prince, you were too good for this world.
Posted by Pietro Schirano, 54 minutes ago
I drew this tungsten light bulb with mathematical equations.
Posted by Hamid Naderi Yeganeh, 4 months ago
Posted by Hamid Naderi Yeganeh, 4 months ago
Do It by Code
I drew this tungsten light bulb with mathematical equations. Posted by Hamid Naderi Yeganeh, 4 months ago
render_tungsten.py
8.4 KB
python implementation (done by gpt 5.5 xhigh)
I drew these interstellar gas clouds of a nebula with mathematical equations.
Posted by Hamid Naderi Yeganeh, 3 months ago
Posted by Hamid Naderi Yeganeh, 3 months ago
Do It by Code
I drew these interstellar gas clouds of a nebula with mathematical equations. Posted by Hamid Naderi Yeganeh, 3 months ago
render_gas_clouds.py
12.7 KB
python implementation (done by gpt 5.5 xhigh)
Do It by Code
Hundreds of AUR packages attacked by infostealer More info in Mastodon post List of affected packages: https://gr.ht/aur_pkg_list.txt via lists.archlinux.org via vivicat https://md.archlinux.org/s/SxbqukK6IA https://archlinux.org/news/active-aur-malicious…
Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
🔸Arch Linux's AUR repository saw over 1,500 user-contributed packages compromised with malware. Developers have deleted all known malicious commits, but some affected packages may still exist.
13 Jun 2026
💬 comments
🔸Arch Linux's AUR repository saw over 1,500 user-contributed packages compromised with malware. Developers have deleted all known malicious commits, but some affected packages may still exist.
13 Jun 2026
💬 comments
Phoronix
Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages
The day started out with Arch Linux's AUR user-contributed repository seeing more than 400 packages compromised with malware
Re: Statement on US government directive to suspend access to Fable 5 and Mythos 5
When you spend a lot of time telling people how dangerous your products are, people who have the power to keep dangerous products off the market might listen.
Especially if those people aren't presently very bright, and are already mad at you for not helping them achieve their unrelated authoritarian goals.
I do not think this is somehow a 3D chess move by Anthropic. They are not masterminds, even if they'd really like to be. People who actually interact with their products know that Fable and Mythos are incremental improvements, not doomsday devices. I think this is a punitive move by an administration that loves being punitive, which they have unknowingly bolstered with their own dumb rhetoric.
ivraatiems, 7 hours ago
When you spend a lot of time telling people how dangerous your products are, people who have the power to keep dangerous products off the market might listen.
Especially if those people aren't presently very bright, and are already mad at you for not helping them achieve their unrelated authoritarian goals.
I do not think this is somehow a 3D chess move by Anthropic. They are not masterminds, even if they'd really like to be. People who actually interact with their products know that Fable and Mythos are incremental improvements, not doomsday devices. I think this is a punitive move by an administration that loves being punitive, which they have unknowingly bolstered with their own dumb rhetoric.
ivraatiems, 7 hours ago
Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack
Article, Comments
Multiple packages, including Node.js, Firefox, and others, were infected. Developer a821 and Nicolas Boichat reported the incidents, the latter using a local AI model to detect the malware.
Article, Comments
Phoronix
Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack
Just a day after Arch Linux developers believed they got their malware AUR incident under control with 1,500+ packages affected by malware, another round of of AUR malware is now being discovered
Forwarded from Pavel Durov (Pavel Durov)
Please open Telegram to view this post
VIEW IN TELEGRAM