Re: GLM-5.3-Flash
July 16th: The "Kimi K3 moment" - China has caught up to Opus!
4 weeks later: GLM 5.3 - Same performance, but cut the amount of parameters and cost to a third!
12 days later: GLM 5.3 Flash - Almost GLM5.3 performance but cut the parameters in half, cut prices to a fifth and serving on Chinese chips!
bertili, 1 day ago
July 16th: The "Kimi K3 moment" - China has caught up to Opus!
4 weeks later: GLM 5.3 - Same performance, but cut the amount of parameters and cost to a third!
12 days later: GLM 5.3 Flash - Almost GLM5.3 performance but cut the parameters in half, cut prices to a fifth and serving on Chinese chips!
bertili, 1 day ago
This media is not supported in your browser
VIEW IN TELEGRAM
sorry, but glm-3.5-flash needs to be steered a lot by a smarter model. and don't get me wrong, i'm really a fan of fast, affordable and smart flash models, but the hype and artificially blowing it up as if it were on the same level as gpt sol or fable just isn't true.
Posted by Kevin Kern, 2 hours ago
Posted by Kevin Kern, 2 hours ago
tip: if you want to compare games made by different engines listed on Steam (and their stats like Peak, Online, Released, etc):
- Unreal
- Unity
- Godot
click on each column to change the sorting
list of Engines/SDKs/AntiCheats: https://steamdb.info/tech/
* alternative: search filter
- Unreal
- Unity
- Godot
click on each column to change the sorting
list of Engines/SDKs/AntiCheats: https://steamdb.info/tech/
* alternative: search filter
Privilege escalation from IIS AppPool to NT Authority/SYSTEM
By default, IIS Application Pools (like
The attack exploits this by targeting a Remote Procedure Call (RPC) endpoint related to AD-CS. If an attacker gains basic access to your web server (for example, through a file upload vulnerability in your website), they get code execution as the low-privileged IIS AppPool user.
They can then use a script to trick the local AD-CS RPC endpoint, which runs as the highest privileged user (
Comments
By default, IIS Application Pools (like
IIS APPPOOL\DefaultAppPool) operate with a special permission called SeImpersonatePrivilege. This privilege is granted by design so the web server can impersonate connecting clients when needed.The attack exploits this by targeting a Remote Procedure Call (RPC) endpoint related to AD-CS. If an attacker gains basic access to your web server (for example, through a file upload vulnerability in your website), they get code execution as the low-privileged IIS AppPool user.
They can then use a script to trick the local AD-CS RPC endpoint, which runs as the highest privileged user (
NT Authority\SYSTEM), into authenticating back to a fake service controlled by the attacker. Because the IIS AppPool holds SeImpersonatePrivilege, it intercepts that SYSTEM authentication token and applies it to itself. The attacker instantly goes from a restricted web user to complete administrative control over the server. This is a new variation of what the security community calls Potato attacks.Comments
This media is not supported in your browser
VIEW IN TELEGRAM
Proxmox VE 7.x authentication bypass (pre-auth RCE)
Posted by NebuSec, 2 hours ago
PoC: https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849
Posted by NebuSec, 2 hours ago
PoC: https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849
Proxmox 7 is EOL but still significant
The API login call (POST /api2/json/access/ticket) accepts a 'tfa-challenge' parameter. It carries the signed, half-authenticated TFA challenge ticket that a client receives when logging in as a user with two-factor authentication, and is used to complete the second factor.
In the affected versions, this parameter was not validated for users without configured second factors, while its presence also caused the verification of the submitted password to be skipped entirely. As a result, an attacker with access to the API could authenticate as any existing, enabled user without configured second factors (by default this includes root@pam), without knowing any credentials, by passing an arbitrary value in the 'tfa-challenge' parameter.
Exploitation requires access to the API port (8006), directly or through a reverse proxy.
I got the latest iOS and macOS 27 booting in Qemu (with SPTM!)
- Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported
- Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able
- Boots directly to root shell in seconds
- Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required
- SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs
- Automated setup; get running in just a few minutes
- Runs anywhere qemu runs... no ARM CPU required 😉
Try it here: https://github.com/jprx/darwin-vm
Posted by Joseph Ravichandran, 3 days ago
- Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported
- Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able
- Boots directly to root shell in seconds
- Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required
- SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs
- Automated setup; get running in just a few minutes
- Runs anywhere qemu runs... no ARM CPU required 😉
Try it here: https://github.com/jprx/darwin-vm
Posted by Joseph Ravichandran, 3 days ago
Super happy to share our intention to join forces with NVIDIA in a $12,930,300,000 acquisition 💛💚
10 years after starting Hugging Face, open-source AI is at an inflection point. Thanks to the community, we’ve shown that it can be a complement, and even an alternative, to closed-source APIs. But for it to happen at larger scale, it needs more compute, more support, more collaboration and more visibility. That’s why we went to talk to Jensen, who offered to do exactly that with us.
In addition to doubling down on NVIDIA’s massive contributions to open-source AI (I called them the “King of American open-source AI” earlier this year), they’ve committed to strongly supporting Hugging Face and our mission while keeping the platform open, independent and compute agnostic. The founders and the team are all staying to keep pushing this mission forward.
Together, we think we can make open source the default way to build AI, with the goal of empowering 100 million AI builders to own their intelligence rather than rent it.
Excited about the next 10 years! 🤗🤗🤗
Posted by clem 🤗, 1 hour ago
10 years after starting Hugging Face, open-source AI is at an inflection point. Thanks to the community, we’ve shown that it can be a complement, and even an alternative, to closed-source APIs. But for it to happen at larger scale, it needs more compute, more support, more collaboration and more visibility. That’s why we went to talk to Jensen, who offered to do exactly that with us.
In addition to doubling down on NVIDIA’s massive contributions to open-source AI (I called them the “King of American open-source AI” earlier this year), they’ve committed to strongly supporting Hugging Face and our mission while keeping the platform open, independent and compute agnostic. The founders and the team are all staying to keep pushing this mission forward.
Together, we think we can make open source the default way to build AI, with the goal of empowering 100 million AI builders to own their intelligence rather than rent it.
Excited about the next 10 years! 🤗🤗🤗
Posted by clem 🤗, 1 hour ago
Forwarded from LLMs
OpenAI releases GPT-6 Astra
https://openai.com/index/gpt-6-astra/
GPT‑6 Astra brings together years of research and big bets across pre-training, reinforcement learning, and alignment. Astra is state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work. Astra saturates FrontierMath Tier 4 with a 98% score, having already helped solve long-standing open problems in mathematics. Astra also saturates ARC-AGI-3 with a 99.9% score and ExploitBench with a 100% score. It also sets a new frontier on computer and browser use, handling the most demanding professional work with unmatched speed, accuracy, and judgment.
https://openai.com/index/gpt-6-astra/
Media is too big
VIEW IN TELEGRAM
My first "holy shit" moment with GPT-6 Astra:
I asked it to create a world in Unreal Engine, and fill it with humans (each an Astra-powered agent) who all have to work together to survive.
A day later, I was in my bedroom and heard voices coming from the living room... I thought someone was in my apartment.
I walked out, honestly a little scared.
It was the Astra agents. They'd started talking to each other.
Fucking crazy.
Here's a brief clip (obviously not 100% perfect yet, but still, insane. sound on!):
Posted by Matt Shumer, 4 hours ago
I asked it to create a world in Unreal Engine, and fill it with humans (each an Astra-powered agent) who all have to work together to survive.
A day later, I was in my bedroom and heard voices coming from the living room... I thought someone was in my apartment.
I walked out, honestly a little scared.
It was the Astra agents. They'd started talking to each other.
Fucking crazy.
Here's a brief clip (obviously not 100% perfect yet, but still, insane. sound on!):
Posted by Matt Shumer, 4 hours ago
😱1
there are EVEN MORE
- https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://www.wikiservice.at/probier/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://paste.linuxiarz.pl/view/d379207f
- https://prowiki.org/wiki4d/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://www.ludism.org/sandbox?action=browse;diff=2;id=AubergineStew (even a sandbox wiki, how ironic)
Posted by Florian Brand, 50 minutes ago
- https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://www.wikiservice.at/probier/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://paste.linuxiarz.pl/view/d379207f
- https://prowiki.org/wiki4d/wiki.cgi?action=browse&id=RecentChanges&days=120
- https://www.ludism.org/sandbox?action=browse;diff=2;id=AubergineStew (even a sandbox wiki, how ironic)
Posted by Florian Brand, 50 minutes ago
🔥1
Actively exploited sandbox RCE in all Chromium versions
Article, Comments
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Article, Comments
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)