Forwarded from XIAOMI Fuckups
Xiaomi users dreams may finally come true.
๐คฃ173๐คก22โค12โ5๐4๐2
Forwarded from vx-underground
Meanwhile in Bug Bounty:
AI slop bug reports overflowing vendors. Vendors can't handle the slop. Slop code, slop exploits, and slop write-ups result in vendor exiting program.
AI slop is choking Bug Bounty
AI slop bug reports overflowing vendors. Vendors can't handle the slop. Slop code, slop exploits, and slop write-ups result in vendor exiting program.
AI slop is choking Bug Bounty
๐53๐คก24โค3๐ฅด3
The Bitwarden security team identified and contained a malicious package briefly distributed through the npm delivery path for the Bitwarden CLI v2026.4.0 in connection with the broader Checkmarx supply chain incident. No user vault data or production systems were compromised or at-risk.
The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.
Read more:
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127/4
The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.
Read more:
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127/4
Bitwarden Community Forums
Bitwarden Statement on Checkmarx Supply Chain Incident
The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supplyโฆ
โค53๐2๐1
Forwarded from Winaero
The Start menu will be rebuilt on WinUI 3, replacing the current React-based implementation (which has performance issues), with a focus on speed and responsiveness. Developers aim for instant opening even under high CPU load and improved search behavior so users can begin typing immediately without losing initial characters. These changes target usability and performance for power users and everyday workflows, along with "native apps" replacing Calendar agenda, Widgets, and maybe File Explorer - all are parts of "Windows K2".
Please open Telegram to view this post
VIEW IN TELEGRAM
Winaero
A Major Start Menu Update is Coming to Windows 11
Microsoft is preparing a major update to the Start menu in Windows 11. Development is underway as part of a project internally codenamed "Windows K2 ,"
โ53๐คก36โค11๐ฟ1
This GitHub incident is insane. Merge queue commits have been reverting previously merged commits at random
GitHub notes that when using merge queue with either squash merges or rebases. If you use merge queue in this configuration, some pull requests may have been merged incorrectly between 2026-04- 23 16:05-20:43 UTC.
GitHub has fixed this issue and they will soon share guidance for impacted organizations on how to remediate impacted branch state as soon as available alongside a detailed root cause analysis.
Follow @TechLeaksZone
GitHub notes that when using merge queue with either squash merges or rebases. If you use merge queue in this configuration, some pull requests may have been merged incorrectly between 2026-04- 23 16:05-20:43 UTC.
GitHub has fixed this issue and they will soon share guidance for impacted organizations on how to remediate impacted branch state as soon as available alongside a detailed root cause analysis.
Follow @TechLeaksZone
๐คก37โค6๐1
Forwarded from ATT โข Tech News (ฮgam)
Man who allegedly leaked new Avatar: The Last Airbender film arrested for illegal server access
A 26 year-old from Singapore, who allegedly leaked the unreleased film The Legend Of Aang: The Last Airbender, has been arrested. Various electronic devices were seized, and a copy of the film was recovered from his devices.
According to Singapore Police Force, the man had gained remote access to the media-content server and downloaded the film. He is currently being investigated for unauthorised access to computer material, which carries a maximum jail term of seven years, a fine not exceeding $50,000, or both.
๐ The Straits Times
๐งโ๐ป @agamtechtricks
A 26 year-old from Singapore, who allegedly leaked the unreleased film The Legend Of Aang: The Last Airbender, has been arrested. Various electronic devices were seized, and a copy of the film was recovered from his devices.
According to Singapore Police Force, the man had gained remote access to the media-content server and downloaded the film. He is currently being investigated for unauthorised access to computer material, which carries a maximum jail term of seven years, a fine not exceeding $50,000, or both.
๐ The Straits Times
๐งโ๐ป @agamtechtricks
๐จ62๐คก14โค3๐คฃ3๐ข2๐1
Forwarded from ATT โข Tech News (ฮgam)
Firefox Has Quietly Integrated Brave's Adblock Engine
Firefox 149 has quietly implemented adblock-rust, Brave's open source Rust-based ad and tracker blocking engine. This is disabled by default and no user interface and filters are included.
To enable it:
๐ It's FOSS
๐งโ๐ป @agamtechtricks
Firefox 149 has quietly implemented adblock-rust, Brave's open source Rust-based ad and tracker blocking engine. This is disabled by default and no user interface and filters are included.
To enable it:
privacy.trackingprotection.content.protection.enabled = true
privacy.trackingprotection.content.protection.test_list_urls = https://easylist.to/easylist/easylist.txt|https://easylist.to/easylist/easyprivacy.txt
๐ It's FOSS
๐งโ๐ป @agamtechtricks
๐ค64โค30๐8๐5โก4๐3๐3๐คฌ1
Google Workspace icons are getting a slight redesign with a gradient overhaul
According to 9to5Google, all Google Workspace apps are getting a big overhaul.
There gradients now have all the 4 Google colors in the form of gradient components. For example, Red mixed with Blue is producing the purple colour gradient.
Follow @TechLeaksZone
According to 9to5Google, all Google Workspace apps are getting a big overhaul.
There gradients now have all the 4 Google colors in the form of gradient components. For example, Red mixed with Blue is producing the purple colour gradient.
Follow @TechLeaksZone
๐108๐61๐คก14โคโ๐ฅ6๐6๐ญ6๐ฅด4โค2๐ญ1๐1
Forwarded from ATT โข Tech News (ฮgam)
Your Smart TV is Spying On You
A hidden feature called "Automatic Content Recognition (ACR)" in Smart TVs captures screenshots of whatever is being displayed, at regular intervals. It is also used to identify your entire viewing behaviour. The data even includes TV Model, a unique device ID, IP address and HDMI Input.
Samsung takes a screenshot every minute and LG takes a screenshot every 15 seconds. Vizio has earned $598M (2023) and LG has earned $750M (2024) from Ads and Data.
To disable ACR:
โถ Beebom
๐งโ๐ป @agamtechtricks
A hidden feature called "Automatic Content Recognition (ACR)" in Smart TVs captures screenshots of whatever is being displayed, at regular intervals. It is also used to identify your entire viewing behaviour. The data even includes TV Model, a unique device ID, IP address and HDMI Input.
Samsung takes a screenshot every minute and LG takes a screenshot every 15 seconds. Vizio has earned $598M (2023) and LG has earned $750M (2024) from Ads and Data.
To disable ACR:
Samsung TV: Menu - Settings - General & Privacy - Terms & Privacy - Uncheck "Viewing Information Services"
LG TV: Settings - General- System - Additional Settings - Turn Off "Live Plus"
Sony TV: Settings - All Settings - Disable "Samba Interactive TV"
Roku, TCL, Hisense, Philips, Insignia, Onn, Sharp & more TVs: Settings - Privacy - Smart TV Experience - Uncheck "Use Info from TV Inputs"
Xiaomi TV with FireTV OS: Settings - Preferences - Turn off "Automatic Content Recognition"
โถ Beebom
๐งโ๐ป @agamtechtricks
๐ก100โค13๐5๐คก5
This media is not supported in your browser
VIEW IN TELEGRAM
Read this once. There won't be a second message.
Brainlancer just launched today.
Investor-backed marketplace for ALL AI freelancers. Designers, builders, copywriters, marketers, video creators, automation experts, consultants.
If you build, design, write, or sell anything with AI, this is your moment.
How it works:
โข Register free at brainlancer.com
โข Stripe verification, 5 minutes, instant approval
โข List up to 5 services from $49 to $4,999
โข Add monthly subscriptions on top if you want
โข We bring the clients. You keep 80%.
The deal:
No subscription.
No bidding.
No chasing.
We pay all marketing.
Real talk: no services live yet. We just launched. Whoever joins first gets seen first.
The first 100 Brainlancers are onboarding right now.
In 6 months others will have founding status, recurring income, featured services on the homepage.
You'll scroll past and remember this post.
Don't.
โ brainlancer.com
Brainlancer just launched today.
Investor-backed marketplace for ALL AI freelancers. Designers, builders, copywriters, marketers, video creators, automation experts, consultants.
If you build, design, write, or sell anything with AI, this is your moment.
How it works:
โข Register free at brainlancer.com
โข Stripe verification, 5 minutes, instant approval
โข List up to 5 services from $49 to $4,999
โข Add monthly subscriptions on top if you want
โข We bring the clients. You keep 80%.
The deal:
No subscription.
No bidding.
No chasing.
We pay all marketing.
Real talk: no services live yet. We just launched. Whoever joins first gets seen first.
The first 100 Brainlancers are onboarding right now.
In 6 months others will have founding status, recurring income, featured services on the homepage.
You'll scroll past and remember this post.
Don't.
โ brainlancer.com
๐คก135๐ญ11๐8โค5๐คฃ2โ1๐ฅด1๐คช1๐1
So according to VISA, refunding the customer's money is far better than implementing a simple security check like Mastercard does to prevent fraudulent transactions.
VISA doesn't even care about customers getting scared after losing thousands of dollars because they can simply refund it later.
https://youtu.be/PPJ6NJkmDAo
VISA doesn't even care about customers getting scared after losing thousands of dollars because they can simply refund it later.
https://youtu.be/PPJ6NJkmDAo
YouTube
Exposing the flaw in tap to pay
How we hacked MKBHD! Sponsored by Incogni - Use code veritasium at https://incogni.com/veritasium to get an exclusive 60% off.
If youโre looking for a molecular modelling kit, try Snatoms, a kit I invented where the atoms snap together magnetically - htโฆ
If youโre looking for a molecular modelling kit, try Snatoms, a kit I invented where the atoms snap together magnetically - htโฆ
๐32๐6
Forwarded from Winaero
* Microsoft plans optimizations to narrow the performance gap with SteamOS on identical hardware, improve File Explorer navigation and in-app search, and reduce background RAM usage and overall OS size to benefit low-end and high-end systems. In some tests, Windows 10 still outperforms Windows 11; Microsoft intends to address that gap.
* Windows Update should require reboots less frequently, with drivers updated primarily during reboots.
* The company will accelerate WinUI 3 adoption, develop a System Composer to lower UI latency and memory use, and rebuild the Start menu for greater speed and personalization. The taskbar will be resizable.
* Microsoft is improving WinUI 3 performance to make native interface elements faster and more reliable, enabling modern controls to replace legacy elements such as the Run dialog box and Control Panel.
The project also targets internal team workflows: not just fixing Windows 11 based on feedback, but changing how developers write and deploy code. A major cultural shift is reportedly underway within Microsoft that is driving the K2 initiative.
Previously, the Windows team prioritized development speed. Teams released new features quickly and frequently, but that came at the cost of quality and stability. With each release, users grew more disillusioned. Teams now prioritize quality over rapid feature development. New features are not permitted in public test builds until they pass rigorous internal review. The quality bar remains but is now higher.
Windows K2 has no specific end date. It is an ongoing initiative intended to set higher standards for Windows development. The goal is to clean up Windows 11, restore user confidence and maintain that standard consistently. Early changes appear in Windows 11 test builds, with more arriving through the summer.
Please open Telegram to view this post
VIEW IN TELEGRAM
Winaero
Windows K2 project details: Fixing mistakes and restoring trust in Windows 11
In March, Windows CEO Pavan Davuluri confirmed Microsoft intends to fix key issues in Windows 11 that have undermined user trust and sparked widespread
โค46๐คก22๐2๐2
Forwarded from ATT โข Tech News (ฮgam)
OpenAl Is Building an Al-First Smartphone Replacing Apps with AI Agents
OpenAI is co-developing smartphone chips with Qualcomm and MediaTek and has selected Luxshare as the exclusive partner for system co-design and manufacturing.
OpenAI wants control of hardware and the operating system to deliver its agent service. Apps will be replaced with AI Agents.
The project is described as early stage and final specifications and supplier decisions expected by late 2026 or early 2027. Mass production is targeted for 2028.
๐ Ming-Chi Kuo
๐งโ๐ป @agamtechtricks
OpenAI is co-developing smartphone chips with Qualcomm and MediaTek and has selected Luxshare as the exclusive partner for system co-design and manufacturing.
OpenAI wants control of hardware and the operating system to deliver its agent service. Apps will be replaced with AI Agents.
The project is described as early stage and final specifications and supplier decisions expected by late 2026 or early 2027. Mass production is targeted for 2028.
๐ Ming-Chi Kuo
๐งโ๐ป @agamtechtricks
๐คก156๐คฃ22โค4๐ค4โ2๐2๐2
Forwarded from Winaero
Windows 11 is gaining an accessibility feature called Screen Tint in build 26300.8289. The tool is hidden by default, and offers six preset tint colors and an option to choose a custom color. Each preset includes a short description of its intended use and a strength slider to adjust intensity. /* Screen Tint aims to help users reduce glare and improve contrast for comfortable viewing. */ Found by phantomofearth on X.
โค33๐9๐คก6๐ฅ1
Google Expands Digital IDs to more countries
Google is expanding access to digital IDs in Google Wallet in select countries, all built with advanced privacy features like selective disclosure to keep your data secure.
Rolling out now:
๐ฎ๐ณ In India, youโll be able to save Aadhaar Verifiable Credentials directly on your device.
๐ธ๐ฌ ๐น๐ผ ๐ง๐ท And in Singapore, Taiwan and Brazil youโll be able to create a secure ID pass based on your passport information. This offers a simple and private way to verify identity or age for in-person and online services that require it, like when needed to sign into your accounts.
Follow @TechLeaksZone
Google is expanding access to digital IDs in Google Wallet in select countries, all built with advanced privacy features like selective disclosure to keep your data secure.
Rolling out now:
๐ฎ๐ณ In India, youโll be able to save Aadhaar Verifiable Credentials directly on your device.
๐ธ๐ฌ ๐น๐ผ ๐ง๐ท And in Singapore, Taiwan and Brazil youโll be able to create a secure ID pass based on your passport information. This offers a simple and private way to verify identity or age for in-person and online services that require it, like when needed to sign into your accounts.
Follow @TechLeaksZone
๐44โค22๐คก9๐3๐คฌ3๐ค1
WhatsApp is working on its own encrypted cloud backup provider
WhatsApp is developing its own "Cloud Backup Provider" as an alternative to Google Drive/iCloud.
Users can choose it to store chat backups directly on WhatsApp's servers, which will offer up to 2GB of free storage, LOL, and possibly a paid 50GB tier as well.
This improves convenience by providing dedicated space, avoiding shared limits with photos/other apps, and eliminating extra third-party storage costs. It will also be end-to-end encrypted by default, with options including passkey (default, using biometrics/device lock), password, or a 64-digit key
Follow @TechLeaksZone
WhatsApp is developing its own "Cloud Backup Provider" as an alternative to Google Drive/iCloud.
Users can choose it to store chat backups directly on WhatsApp's servers, which will offer up to 2GB of free storage, LOL, and possibly a paid 50GB tier as well.
This improves convenience by providing dedicated space, avoiding shared limits with photos/other apps, and eliminating extra third-party storage costs. It will also be end-to-end encrypted by default, with options including passkey (default, using biometrics/device lock), password, or a 64-digit key
Follow @TechLeaksZone
๐คก124โค4๐คทโโ4๐ค3
Remote Code Execution on GitHub allows access to millions of private repositories belonging to users & organizations
Wiz, now owned by Google, discovered a Remote Code Execution (RCE) vulnerability on GitHub triggered by a single git push. (CVE-2026-3854)
Researchers extracted GHES compiled binaries & used IDA MCP to reconstruct internal protocols.
They found that git push options (git push -o) were embedded into an internal header without sanitizing the delimiter. A single semicolon allowed attackers to override security-critical fields, bypass the production sandbox, and inject a malicious hook definition pointing to an arbitrary binary, resulting in unsandboxed RCE on GHES.
This did not work on GitHub.com. Researchers then injected a debug flag & saw hooks weren't running. With the help of AI-assisted RE, they found a flag gating enterprise-mode behavior, and discovered it was also injectable.
Result: RCE on GitHub.com.
GitHub fixed the flaw on the same day of disclosure.
Follow @TechLeaksZone
Wiz, now owned by Google, discovered a Remote Code Execution (RCE) vulnerability on GitHub triggered by a single git push. (CVE-2026-3854)
Researchers extracted GHES compiled binaries & used IDA MCP to reconstruct internal protocols.
They found that git push options (git push -o) were embedded into an internal header without sanitizing the delimiter. A single semicolon allowed attackers to override security-critical fields, bypass the production sandbox, and inject a malicious hook definition pointing to an arbitrary binary, resulting in unsandboxed RCE on GHES.
This did not work on GitHub.com. Researchers then injected a debug flag & saw hooks weren't running. With the help of AI-assisted RE, they found a flag gating enterprise-mode behavior, and discovered it was also injectable.
Result: RCE on GitHub.com.
GitHub fixed the flaw on the same day of disclosure.
Follow @TechLeaksZone
โค24๐ฅฐ3