Tech & Leaks Zone
18.3K subscribers
7.42K photos
766 videos
30 files
2.5K links
Stay Updated on the latest tech-related news inclusive of smartphones, Tech news
NO need to wander on Google or check websites now

Advertise on our channel to reach a highly engaged audience to grow your brand
Buy ads: https://telega.io/c/techleakszone
Download Telegram
Forwarded from XIAOMI Fuckups
Xiaomi users dreams may finally come true.
๐Ÿคฃ173๐Ÿคก22โค12โ˜ƒ5๐Ÿ‘Ž4๐ŸŽ‰2
Forwarded from vx-underground
Meanwhile in Bug Bounty:

AI slop bug reports overflowing vendors. Vendors can't handle the slop. Slop code, slop exploits, and slop write-ups result in vendor exiting program.

AI slop is choking Bug Bounty
๐Ÿ‘53๐Ÿคก24โค3๐Ÿฅด3
The Bitwarden security team identified and contained a malicious package briefly distributed through the npm delivery path for the Bitwarden CLI v2026.4.0 in connection with the broader Checkmarx supply chain incident. No user vault data or production systems were compromised or at-risk.

The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.

Read more:
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127/4
โค53๐Ÿ‘2๐Ÿ˜1
Forwarded from Winaero
๐Ÿ”ตMicrosoft is developing a major Start menu update for Windows 11, part of the "Windows K2" project aimed at restoring user trust and improving the OS. The design will largely match the current layout but Settings will include expanded personalization controls, letting users choose a compact or expanded Start menu and disable sections such as Recommended, pinned icons or All Apps.

The Start menu will be rebuilt on WinUI 3, replacing the current React-based implementation (which has performance issues), with a focus on speed and responsiveness. Developers aim for instant opening even under high CPU load and improved search behavior so users can begin typing immediately without losing initial characters. These changes target usability and performance for power users and everyday workflows, along with "native apps" replacing Calendar agenda, Widgets, and maybe File Explorer - all are parts of "Windows K2".
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ53๐Ÿคก36โค11๐Ÿ—ฟ1
This GitHub incident is insane. Merge queue commits have been reverting previously merged commits at random

GitHub notes that when using merge queue with either squash merges or rebases. If you use merge queue in this configuration, some pull requests may have been merged incorrectly between 2026-04- 23 16:05-20:43 UTC.

GitHub has fixed this issue and they will soon share guidance for impacted organizations on how to remediate impacted branch state as soon as available alongside a detailed root cause analysis.

Follow @TechLeaksZone
๐Ÿคก37โค6๐Ÿ†’1
Forwarded from ATT โ€ข Tech News (ฮ‘gam)
Man who allegedly leaked new Avatar: The Last Airbender film arrested for illegal server access

A 26 year-old from Singapore, who allegedly leaked the unreleased film The Legend Of Aang: The Last Airbender, has been arrested. Various electronic devices were seized, and a copy of the film was recovered from his devices.

According to Singapore Police Force, the man had gained remote access to the media-content server and downloaded the film. He is currently being investigated for unauthorised access to computer material, which carries a maximum jail term of seven years, a fine not exceeding $50,000, or both.

๐Ÿ”— The Straits Times
๐Ÿง‘โ€๐Ÿ’ป @agamtechtricks
๐Ÿ˜จ62๐Ÿคก14โค3๐Ÿคฃ3๐Ÿ˜ข2๐Ÿ‘1
Forwarded from ATT โ€ข Tech News (ฮ‘gam)
Firefox Has Quietly Integrated Brave's Adblock Engine

Firefox 149 has quietly implemented adblock-rust, Brave's open source Rust-based ad and tracker blocking engine. This is disabled by default and no user interface and filters are included.

To enable it:
privacy.trackingprotection.content.protection.enabled = true

privacy.trackingprotection.content.protection.test_list_urls = https://easylist.to/easylist/easylist.txt|https://easylist.to/easylist/easyprivacy.txt


๐Ÿ”— It's FOSS
๐Ÿง‘โ€๐Ÿ’ป @agamtechtricks
๐Ÿค”64โค30๐Ÿ†’8๐Ÿ’”5โšก4๐Ÿ‘Ž3๐Ÿ˜3๐Ÿคฌ1
Google Workspace icons are getting a slight redesign with a gradient overhaul

According to 9to5Google, all Google Workspace apps are getting a big overhaul.

There gradients now have all the 4 Google colors in the form of gradient components. For example, Red mixed with Blue is producing the purple colour gradient.

Follow @TechLeaksZone
๐Ÿ‘Ž108๐Ÿ‘61๐Ÿคก14โคโ€๐Ÿ”ฅ6๐Ÿ˜6๐Ÿ˜ญ6๐Ÿฅด4โค2๐ŸŒญ1๐Ÿ’‹1
Forwarded from ATT โ€ข Tech News (ฮ‘gam)
Your Smart TV is Spying On You

A hidden feature called "Automatic Content Recognition (ACR)" in Smart TVs captures screenshots of whatever is being displayed, at regular intervals. It is also used to identify your entire viewing behaviour. The data even includes TV Model, a unique device ID, IP address and HDMI Input.

Samsung takes a screenshot every minute and LG takes a screenshot every 15 seconds. Vizio has earned $598M (2023) and LG has earned $750M (2024) from Ads and Data.

To disable ACR:
Samsung TV: Menu - Settings - General & Privacy - Terms & Privacy - Uncheck "Viewing Information Services"
LG TV: Settings - General-  System - Additional Settings - Turn Off "Live Plus"
Sony TV: Settings - All Settings - Disable "Samba Interactive TV"
Roku, TCL, Hisense, Philips, Insignia, Onn, Sharp & more TVs: Settings - Privacy - Smart TV Experience - Uncheck "Use Info from TV Inputs"
Xiaomi TV with FireTV OS: Settings - Preferences - Turn off "Automatic Content Recognition"


โ–ถ Beebom
๐Ÿง‘โ€๐Ÿ’ป @agamtechtricks
๐Ÿ˜ก100โค13๐Ÿ‘5๐Ÿคก5
This media is not supported in your browser
VIEW IN TELEGRAM
Read this once. There won't be a second message.

Brainlancer just launched today.

Investor-backed marketplace for ALL AI freelancers. Designers, builders, copywriters, marketers, video creators, automation experts, consultants.

If you build, design, write, or sell anything with AI, this is your moment.

How it works:

โ€ข Register free at brainlancer.com
โ€ข Stripe verification, 5 minutes, instant approval
โ€ข List up to 5 services from $49 to $4,999
โ€ข Add monthly subscriptions on top if you want
โ€ข We bring the clients. You keep 80%.

The deal:

No subscription.
No bidding.
No chasing.
We pay all marketing.

Real talk: no services live yet. We just launched. Whoever joins first gets seen first.

The first 100 Brainlancers are onboarding right now.

In 6 months others will have founding status, recurring income, featured services on the homepage.

You'll scroll past and remember this post.

Don't.

โ†’ brainlancer.com
๐Ÿคก135๐Ÿ˜ญ11๐Ÿ‘Ž8โค5๐Ÿคฃ2โœ1๐Ÿฅด1๐Ÿคช1๐Ÿ’˜1
So according to VISA, refunding the customer's money is far better than implementing a simple security check like Mastercard does to prevent fraudulent transactions.

VISA doesn't even care about customers getting scared after losing thousands of dollars because they can simply refund it later.

https://youtu.be/PPJ6NJkmDAo
๐Ÿ˜32๐Ÿ‘6
Forwarded from Winaero
๐Ÿ”ตHere are some internal details on the "Windows K2" initiative. Launched in late 2025, it targets performance, attention to detail, and stability to restore user confidence in Windows 11. Microsoft acknowledged that aggressive AI feature additions and rapid release cadence harmed core performance and stability, including degraded game performance, slower File Explorer operations, and UI responsiveness issues.

* Microsoft plans optimizations to narrow the performance gap with SteamOS on identical hardware, improve File Explorer navigation and in-app search, and reduce background RAM usage and overall OS size to benefit low-end and high-end systems. In some tests, Windows 10 still outperforms Windows 11; Microsoft intends to address that gap.
* Windows Update should require reboots less frequently, with drivers updated primarily during reboots.
* The company will accelerate WinUI 3 adoption, develop a System Composer to lower UI latency and memory use, and rebuild the Start menu for greater speed and personalization. The taskbar will be resizable.
* Microsoft is improving WinUI 3 performance to make native interface elements faster and more reliable, enabling modern controls to replace legacy elements such as the Run dialog box and Control Panel.

The project also targets internal team workflows: not just fixing Windows 11 based on feedback, but changing how developers write and deploy code. A major cultural shift is reportedly underway within Microsoft that is driving the K2 initiative.

Previously, the Windows team prioritized development speed. Teams released new features quickly and frequently, but that came at the cost of quality and stability. With each release, users grew more disillusioned. Teams now prioritize quality over rapid feature development. New features are not permitted in public test builds until they pass rigorous internal review. The quality bar remains but is now higher.

Windows K2 has no specific end date. It is an ongoing initiative intended to set higher standards for Windows development. The goal is to clean up Windows 11, restore user confidence and maintain that standard consistently. Early changes appear in Windows 11 test builds, with more arriving through the summer.
Please open Telegram to view this post
VIEW IN TELEGRAM
โค46๐Ÿคก22๐Ÿ‘2๐Ÿ˜2
Forwarded from ATT โ€ข Tech News (ฮ‘gam)
OpenAl Is Building an Al-First Smartphone Replacing Apps with AI Agents

OpenAI is co-developing smartphone chips with Qualcomm and MediaTek and has selected Luxshare as the exclusive partner for system co-design and manufacturing.

OpenAI wants control of hardware and the operating system to deliver its agent service. Apps will be replaced with AI Agents.

The project is described as early stage and final specifications and supplier decisions expected by late 2026 or early 2027. Mass production is targeted for 2028.

๐Ÿ”— Ming-Chi Kuo
๐Ÿง‘โ€๐Ÿ’ป @agamtechtricks
๐Ÿคก156๐Ÿคฃ22โค4๐Ÿค”4โœ2๐Ÿ‘2๐Ÿ˜2
Forwarded from Winaero
Windows 11 is gaining an accessibility feature called Screen Tint in build 26300.8289. The tool is hidden by default, and offers six preset tint colors and an option to choose a custom color. Each preset includes a short description of its intended use and a strength slider to adjust intensity. /* Screen Tint aims to help users reduce glare and improve contrast for comfortable viewing. */ Found by phantomofearth on X.
โค33๐Ÿ‘9๐Ÿคก6๐Ÿ”ฅ1
Google Expands Digital IDs to more countries

Google is expanding access to digital IDs in Google Wallet in select countries, all built with advanced privacy features like selective disclosure to keep your data secure.

Rolling out now:
๐Ÿ‡ฎ๐Ÿ‡ณ In India, youโ€™ll be able to save Aadhaar Verifiable Credentials directly on your device.

๐Ÿ‡ธ๐Ÿ‡ฌ ๐Ÿ‡น๐Ÿ‡ผ ๐Ÿ‡ง๐Ÿ‡ท And in Singapore, Taiwan and Brazil youโ€™ll be able to create a secure ID pass based on your passport information. This offers a simple and private way to verify identity or age for in-person and online services that require it, like when needed to sign into your accounts.

Follow @TechLeaksZone
๐Ÿ‘Ž44โค22๐Ÿคก9๐Ÿ‘3๐Ÿคฌ3๐Ÿค“1
WhatsApp is working on its own encrypted cloud backup provider

WhatsApp is developing its own "Cloud Backup Provider" as an alternative to Google Drive/iCloud.

Users can choose it to store chat backups directly on WhatsApp's servers, which will offer up to 2GB of free storage, LOL, and possibly a paid 50GB tier as well.

This improves convenience by providing dedicated space, avoiding shared limits with photos/other apps, and eliminating extra third-party storage costs. It will also be end-to-end encrypted by default, with options including passkey (default, using biometrics/device lock), password, or a 64-digit key

Follow @TechLeaksZone
๐Ÿคก124โค4๐Ÿคทโ€โ™€4๐Ÿค”3
Remote Code Execution on GitHub allows access to millions of private repositories belonging to users & organizations

Wiz, now owned by Google, discovered a Remote Code Execution (RCE) vulnerability on GitHub triggered by a single git push. (CVE-2026-3854)

Researchers extracted GHES compiled binaries & used IDA MCP to reconstruct internal protocols.

They found that git push options (git push -o) were embedded into an internal header without sanitizing the delimiter. A single semicolon allowed attackers to override security-critical fields, bypass the production sandbox, and inject a malicious hook definition pointing to an arbitrary binary, resulting in unsandboxed RCE on GHES.

This did not work on GitHub.com. Researchers then injected a debug flag & saw hooks weren't running. With the help of AI-assisted RE, they found a flag gating enterprise-mode behavior, and discovered it was also injectable.
Result: RCE on GitHub.com.

GitHub fixed the flaw on the same day of disclosure.

Follow @TechLeaksZone
โค24๐Ÿฅฐ3