Forwarded from Gianmarco Gargiulo Mastodon Bridge
This media is not supported in your browser
VIEW IN TELEGRAM
1/2
Apple in 2007: here’s 400 videos playing at the same time, with interactive search and real-time animations (via https://t.me/ilyabirman_channel/12350)
Apple in 2007: here’s 400 videos playing at the same time, with interactive search and real-time animations (via https://t.me/ilyabirman_channel/12350)
🔥1
Far alzare il cortisolo agli altri se non per reali emergenze dovrebbe essere illegale
🔥3👍1
journalctl -u micro
Neanche una settimana dopo, non ci facciamo mancare nulla https://www.phoronix.com/news/Dirty-Frag-Linux
Depthfirst
NGINX Rift
An 18 year old memory corruption flaw in NGINX Plus and NGINX Open Source lets an unauthenticated attacker crash worker processes or execute remote code with crafted HTTP requests.
Con tutte ste vulnerabilità serie trovate dalle AI ad una velocità impressionante, conviene che andiamo tutti in vacanza un mese e si aggiorna tutto alla fine
journalctl -u micro
https://depthfirst.com/nginx-rift
Red Hot Cyber
Fragnesia: arriva un terzo bug LPE in Linux che mette a rischio i sistemi
La vulnerabilità Fragnesia colpisce il kernel Linux, consentendo agli utenti malintenzionati di ottenere i privilegi di root. Scopri di più su come proteggerti
😭1
Il rasoio di Occam ha quasi sempre ragione.
Il dispositivo continua a disconnettersi?
Indovinate la causa...la scheda di rete
Puntualmente leschede realtek USB che siano per wifi o ethernet su Linux fanno davvero piangere.
Il dispositivo continua a disconnettersi?
Indovinate la causa
Puntualmente le
Installato PiHole dopo tanto tempo che mi dicevo di farlo, un'ora in tutto.
• configurato docker compose, passwd custom, domini custom
• disabilitata la funzione dns dell'istanza dnsmasq nativa
(che agisce comunque da dhcp, nel caso docker morisse)
• aggiunto una blocklist custom con letteralmente tutto
https://github.com/hagezi/dns-blocklists#ultimate
• testato con domini consentiti e bloccati
• configurato docker compose, passwd custom, domini custom
• disabilitata la funzione dns dell'istanza dnsmasq nativa
(che agisce comunque da dhcp, nel caso docker morisse)
• aggiunto una blocklist custom con letteralmente tutto
https://github.com/hagezi/dns-blocklists#ultimate
• testato con domini consentiti e bloccati
GitHub
GitHub - hagezi/dns-blocklists: DNS-Blocklists: For a better internet - keep the internet clean!
DNS-Blocklists: For a better internet - keep the internet clean! - hagezi/dns-blocklists
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments.
The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
FixupX
Microsoft Threat Intelligence (@MsftSecIntel)
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage…
🔥1
Forwarded from Gianmarco Gargiulo Mastodon Bridge
You REALLY should remove the tracking codes from Youtube links now.
They started showing a popup about who sent the link and offering a (maybe new) DM feature, potentially revealing your personal account name to anyone who opens the link.
They started showing a popup about who sent the link and offering a (maybe new) DM feature, potentially revealing your personal account name to anyone who opens the link.
Forwarded from Gianmarco Gargiulo Mastodon Bridge
you can anonymize the link by removing the part of the link after the “?”
(at least for youtube currently, this can be different on other platforms and may also change in the future)
(at least for youtube currently, this can be different on other platforms and may also change in the future)