Tootfinder

Opt-in global Mastodon full text search. Join the index!

@macandi@social.heise.de
2026-06-19 08:38:00

Böser Bug: „Unpatchbarer“ SoC-Fehler bis hoch zum iPhone 11
Schon früher gab es in den A-Chips Jailbreak-fähige Bugs, die sich per Software nicht beheben ließen. Nun sind erstmals Modelle bis zum iPhone 11 betroffen.

@metacurity@infosec.exchange
2026-05-18 14:21:18

So much has happened in cyberworld since Friday, so don't miss today's Metacurity for the most critical infosec developments you might have missed over the weekend, including
--Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems,
--Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced,
--Grafana Labs rejected hackers' extortion demand,
--DeFi protocol Verus lost nearly $12m in ongoing exploit,

@Techmeme@techhub.social
2026-05-18 08:40:37

In his weekly Linux kernel post, Linus Torvalds says "AI tools are great" but the flood of duplicate AI bug reports has made the security list "unmanageable" (Simon Sharwood/The Register)

@beoz@det.social
2026-05-19 06:46:16

Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.

@grork@mastodon.social
2026-05-19 04:07:08

The need to call customer service is often, in reality, a failing of UX: a bug, an explicit decision to employ a dark pattern. ‘Why is my account not letting me do x or y’: bug. ‘Why can’t I cancel the website?’: dark pattern. ‘Why can’t I schedule this appointment right now’: UX failing. 1/2

@kubikpixel@chaos.social
2026-05-18 09:35:39

«Linus Torvalds — Flut KI-gestützter Bug-Reports belastet Linux-Team:
Der Entwickler des Linux-Kernels, Linus Torvalds, hat bei der Vorstellung des vierten Release-Kandidaten von Linux 7.1 ungewöhnlich deutliche Kritik an der zunehmenden Nutzung von KI-Werkzeugen geäußert.»
Auch wenn Linus Torvalds anhand seines Verhaltens häufig kritisiert wird, muss ich ihm recht geben. KI ist nicht "Die Lösung" für alles.
🐧

@primonatura@mstdn.social
2026-05-18 12:00:17

"Don’t reach for the bug spray: scientists find insects may feel pain after crickets nurse sore antennae"
#Bugs #Insects

@joxean@mastodon.social
2026-06-15 16:18:28

I have just published a new bug fixes minor release for #Diaphora, version 3.4.1.
github.com/joxeankoret/diaphor

@fanf@mendeddrum.org
2026-06-18 17:42:04

from my link log —
zlib-rs in Firefox and an Intel CPU hardware bug.
trifectatech.org/blog/zlib-rs-
saved 2026-06-16

@benny@norden.social
2026-06-18 18:30:09

Zwei Rankscale-Werte für denselben Brand: 57 % vs. 48,8 % KI-Sichtbarkeit. 📊
Kein Bug. Der Search-Terms-Report trennt Varianten auf: "Brand GmbH", "BRAND", "brand" zählen als drei Datenpunkte. Die UI aggregiert dedupliziert. Ergebnis hier: Platz 3 im Report, Platz 2 in der UI.
Messung immer am Dashboard-Wert festmachen, nie am gemittelten Search-Terms-Report.
#GEO

@shacker@zirk.us
2026-05-19 15:02:49

Meanwhile, on the Python/Django side of life… Over the past few evenings I’ve made numerous updates and bug fixes to my reusable, pluggable, multi-user/multi-group task assignment system for Django. Live on the demo site and installable now. Hope it’s useful!
django-todo.org/

@ripienaar@devco.social
2026-05-20 08:19:38

Writing a CM system is all fun and games until you realise you're using Unix and its a shitshow.
> The bug is most likely this: Store() uses fchown on the open temp file descriptor (tf.Chown(uid, gid)), while the chown CLI uses path-based chown. On certain bind-mount setups (Docker Desktop for
Mac/Windows with gRPC FUSE or VirtioFS, NFS, FUSE-backed mounts), fchown can silently no-op or fail to persist while path-based chown works fine.

@beoz@det.social
2026-05-19 06:46:16

Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.

@Nathan@social.lostinok.com
2026-06-19 01:15:58

Squash Bug War Report:
1 Adult, 2 Egg Pods
Too tired for story time, a simple harvest report will have to do. Getting some nice zucchinis plus a handful of blackberries daily. Onions are coming off the rack and harvested our first jalapeño of the year in nice purple hue.
#gardening #oklahoma

Onions, blackberries, zucchinis and a purple jalapeño on a table in front of a basket.
@lukem@hachyderm.io
2026-06-19 09:16:45

Corporate: no more MacBooks, here are crappy Windows laptops, you’re supposed to use them for your daily work.
Also corporate: here’s a bug that affects Safari browser, please fix
😓😤

@kexpmusicbot@mastodonapp.uk
2026-05-18 16:49:46

🇺🇦 #NowPlaying on KEXP's #MorningShow
The Bug Club:
🎵 A Good Day for Dying
#TheBugClub
open.spotify.com/track/5RcBPGJ

@stsquad@mastodon.org.uk
2026-06-17 15:44:00

Today I spent a long time staring at the #linux kernel's dsb_sev(); trying to figure out why it wasn't triggering the WFE patches I've written for #qemu and it turns out we've tripped an errata workaround. So the bug isn't in my code, but there is still a bug ;-)

@Techmeme@techhub.social
2026-07-17 03:20:47

Source: Microsoft plans to release an AI security tool this month using models from Anthropic, OpenAI, and itself, as a cost-effective Mythos alternative (Aaron Holmes/The Information)
theinformation.com/briefings/e

@metacurity@infosec.exchange
2026-05-19 11:44:34

South Korea is significantly expanding its financial apps and bug bounty program.
koreabizwire.com/korean-regula

@publicvoit@graz.social
2026-05-17 20:35:25

With every company announcement event, I get even more nervous because #enshittification is a strong trend these days. 🫣
It's a really good announcement when there's actually not too much news.
Upcoming anxiety: #Google actively killing the healthy ecosystem of

@brian_gettler@mas.to
2026-07-17 19:04:34

I've had to bug a colleague who's on vacation several times lately but apparently only when he and the family are at the same Italian restaurant. I keep pulling him back in?

@johl@mastodon.xyz
2026-05-14 15:07:29

OMG, someone actually went ahead and filed that as a bug! (Well, three years ago)
Ho mia Zamenhof, iu vere registris tion kiel cimon! (Nu, antaŭ tri jaroj)
codeberg.org/forgejo/forgejo/i

@grumpybozo@toad.social
2026-06-17 15:21:40

It is always an iffy proposition to open a bug in the CPAN RT (rt.cpan.org/Ticket/Display.htm) when all the unresolved tickets for a module are years old and all the resolved ones are far older.
Anyway: if the latest Net::CIDR::Lite update broke your use of i…

@usul@piaille.fr
2026-05-15 04:22:46

NYC*BUG dmesgd
dmesgd.nycbug.org/dmesgd?do=vi

@Nathan@social.lostinok.com
2026-06-20 01:18:25

Squash Bug War Report:
3 adults, 2 egg pods, 10 nymphs. Total: 15.
Yes, I killed them. The adults were soldiers. The egg pods were weapons caches. The nymphs? The tribunal calls them children. I call them future war criminals in soft exoskeletons.
. . .
#gardening #oklahoma

Dr Strangelove
@grahamperrin@bsd.cafe
2026-07-18 08:24:14

FreeBSD in Oracle VirtualBox
A pleasant change with FreeBSD-16.0-CURRENT-amd64-20260713-60382b4a04fa-287406-disc1.iso
― it seems that hw.efi.poweroff is no longer preset to 1.
Two related bug reports:
— #22021 (FreeBSD VM with EFI: "poweroff" fails) – Oracle VirtualBox — <virtualbox.org/ticke…

@heiseonline@social.heise.de
2026-04-26 15:11:00

OpenAI startet Bug-Bounty-Programm für Bio-Sicherheit
OpenAI startet ein Bug-Bounty-Programm, um Schwachstellen in den Biosicherheits-Safeguards von ChatGPT 5.5 zu finden.
he…

@azonenberg@ioc.exchange
2026-05-17 00:39:55

Floating static geometry bug IRL
(Looks around for matrix agents in suits and earpieces)

Parked car with a Norwegian flag on a wooden stick hovering in the air above the back of the cabin, presumably attached to a radio antenna too small and dark in color to be visible from this distance
@frankel@mastodon.top
2026-06-30 17:07:04

How we found a #bug in the #hyper #HTTP library
blog.clo…

@aredridel@kolektiva.social
2026-05-13 19:52:04

RE: mastodon.social/@mikemcquaid/1
Have always done this. If I find bug, I fix bug and make a PR.

@BBC6MusicBot@mastodonapp.uk
2026-06-20 10:02:14

🇺🇦 #NowPlaying on #BBC6Music's #TheBethDittoShow
Mark Ronson:
🎵 Ooh Wee (feat. Ghostface Killah & Nate Dogg)
#MarkRonson
scottyhotpockets.bandcamp.com/

@metacurity@infosec.exchange
2026-05-15 13:33:10

Don't leave for the weekend until you've checked out today's Metacurity for the most critical infosec developments you should know, including
--AI bug hunters expose new weak point in Apple’s locked-down macOS,
--Shai-Hulud attack campaign hit two OpenAI employees,
--Hackers unwisely targeted Amnesty International's Security Lab chief,
--US and China to discuss AI guardrails,
--Anthropic warns of CCP AI dominance,
--DPRK's APT 37 is now…

@inthehands@hachyderm.io
2026-05-16 00:16:28

The trouble is, as Doctorow points out, that this vision makes AI a multi-billion dollar industry, not a multi-trillion dollar industry.
Even if you can claim that your ML / LLM thinger can reduce software bug rates or failure rates by 10x — which would be •wild• — demand for that is simply not going to fund data centers the size of Manhattan.
But make the claim of •speeding up• by 10x — an even wilder claim, but one some people are desperate to believe! — and all the money in the world will beat a path to your door.
5/

@gla@mastodon.social
2026-05-18 08:39:32

Finally found a nifty app to disable those pesky macOS Spaces animations!
#macOS #opensource #utility

@aardrian@toot.cafe
2026-05-15 22:16:32

In many cases, the people citing the LLM to me either won’t listen to why it’s wrong or don’t care.
Because their employee reviews are a function of how much they use the LLM versus accuracy, bug-free code, giving a shit, …
bsky.app/profile/scottohara.me

@xtaran@chaos.social
2026-07-16 10:53:29

Und ich dachte schon, #DPD hat einen Bug in ihrer Benachrichtigungssoftware, weil die Benachrichtigung mit "Ihr Paket von SENDER wird heute …" begann.
Aber es lag wohl an dem Dienstleister, der das Paket für den lokalen Transport neu und eher suboptimal gelabelt hat. 🙈
#FAIL

Foto des Absenderteils eines Paketaufklebers: Links oben das DPD-Logo. Rechts zwei Adressen:

0619/DPD Schweiz AG
Via Campagna
CH-6512 Giubiasco

[Trennlinie]

Sender account 7535[Rest abgeschnitten]
SENDER
Via Moree 16
CH - 6850 Mendrisio
@cheeaun@mastodon.social
2026-05-15 13:31:20

It's been few months. #PhanpySocial changelog ✨
🔄 Experimental paginated timeline
🪣 Multi-filters for profile posts
🧘 Wellbeing: hide trending, local or federated timelines
📱 Haptics
🐛 Bug fixes
🔗 phanpy.social/

@colinpurrington@flipping.rocks
2026-06-05 10:11:50

Review of bug zappers that concludes, like all other reviews of bug zappers, that they are completely ineffective and kill tens of thousands of innocent insects. #mosquitoes #insects #nature nytimes.com/wirecutter/blog/do

@thomastraynor@social.linux.pizza
2026-07-17 01:08:14

And another senior citizen rant.
When you post what the update does do NOT use "bug fixes and performance improvements". How about a short update on what you really did like "fixed overflow that may cause a security issue" or "fixed spelling errors".
When I update my code it always has a short description of the change. If there is a RFC to it I include that so you can find the details, the proposed fix, test cases and test results.

@Techmeme@techhub.social
2026-05-18 08:01:25

Companies running bug bounty programs are tightening background checks and building AI agents to triage a flood of low-quality reports generated by AI (Jamie John/Financial Times)
giftarticle.ft.com/giftarticle

@cyrevolt@mastodon.social
2026-05-15 20:18:53

I was wondering why none of my #FreeBSD systems got the latest #nginx - so I searched... and it took me a good hour again to figure out that the OS is by default insecure; you need to actively change the repo settings in order to get recent software with bug fixes - latest instead of quarterly:

@rasterweb@mastodon.social
2026-07-08 11:45:24

Bug Report: There is a “feature” on my pocket computer where if I press the wrong button a human being may start talking to me through the device! This is obviously a bug and should be fixed.

@thomasfuchs@hachyderm.io
2026-06-12 14:13:42

Wikipedia app just popped up a modal asking me if I want to play today’s new game
CAN U NOT
anyway, reported it as a bug

@kubikpixel@chaos.social
2026-07-08 06:30:42

«16 Jahre alter Linux-Bug öffnet Hackern Tür zu Cloud-Servern:
Ein Fehler im KVM-Code des Linux-Kernels steckt seit rund 16 Jahren im Quelltext, ohne aufzufallen.»
Nun mal sehen was dies betrifft oder was auch nicht. Linux hat ja noch nie versprochen, dass die "Die Sichersten" sind.
🐧

@shaun@mastodon.xyz
2026-07-08 05:05:55

Welcome to #Tennessee! Watch out for explosive bowel movements.
tennessean.com/story/news/heal

@fanf@mendeddrum.org
2026-07-17 11:42:02

from my link log —
Parsing Rust strings into slices.
wduquette.github.io/parsing-st
saved 2019-08-15

@metacurity@infosec.exchange
2026-06-16 13:38:02

The cyber news is coming out fast and furious this week, so don't miss today's Metacurity for the most crucial developments you should know, including
--Why the White House turned on Anthropic,
--Chinese spies hid in research networks for two years,
--Copilot bug let attackers steal Microsoft 365 data,
--Crypto scammers now send couriers for cash,
--Judge keeps Meta AI scraping lawsuit alive,
--Feds dismantle $389m crypto laundering op,
--iRhy…

@thesaigoneer@social.linux.pizza
2026-05-16 08:34:16

@…
Bug hunting 101: for some obscure reason Spectacle wasn't working in Slim 6.7. (Re)install tesseract and leptonica (available in your repo anyway), all good!
It's always the user that effs something up 😆
#slackware

Scrot of fetch in Slackware Current, running the slimmed down KDE 6.7 Beta.
@radioeinsmusicbot@mastodonapp.uk
2026-06-16 11:07:13

🇺🇦 Auf radioeins läuft...
Fontaines D.C.:
🎵 Bug
#NowPlaying #FontainesDC
open.spotify.com/track/0MXmiqd

@gwire@mastodon.social
2026-06-15 14:26:42

Another reiteration from NCSC/DSIT that the existence of AI bug-hunting tools shouldn't be used to stop working in the open.
gov.uk/government/case-studies

@matthiasott@mastodon.social
2026-06-13 22:10:59

I went to the beautiful little town of Bietigheim today, because my son had a rehearsal with the Youth Philharmonic Ludwigsburg there. Anyway, the old town is lovely. Stunning half-timbered houses, a 14th-century city gate, a music school in an old castle, and also … this. 😳

Bronze sculpture of a dark, cartoonishly bizarre cow with a bulging, googly eye and golden horns, balancing atop a silver milk can bristling with metal rods. A large convex mirror disc is embedded in the cow's side, and a set of udders protrudes from its rear. The cow's exaggerated, bug-eyed stare gives it a hilariously unhinged expression
@jake4480@c.im
2026-06-07 03:29:34

When all the bug ladies be checkin you out

Bug ladies giving goo goo eyes in 1936 short Bing Crosbyana by Friz Freleng
@heiseonline@social.heise.de
2026-04-26 16:00:34

Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenAI startet Bug-Bounty-Programm für Bio-Sicherheit

@adamhotep@infosec.exchange
2026-06-04 15:26:35

A 20yo security bug in Outlook got noticed … thanks to Dovecot on Fedora
fedoramagazine.org/fedora-43-u

@servelan@newsie.social
2026-04-30 22:55:28

No bugs. Duh.
Drivers help study road-trip mystery: what became of bug splats?
phys.org/news/2026-04-drivers-

@hynek@mastodon.social
2026-07-12 12:49:25

i see apple still hasn't fixed the bug in keynote where the d key randomly stops working when editing speaker notes in rehearsal mode 🫠

@laf0rge@chaos.social
2026-05-09 09:31:09

analyzing why #osmocom ARM package building is taking too long: Turns out the build worker is spending 7.5 times more time in post-installation of latex (for setting up the package build) than it is taking to actually build osmo-sgsn including its user manual:

@Nathan@social.lostinok.com
2026-06-18 01:48:07

Squash Bug War Casualty Report:
Seven Adults, One Egg POD
We few, we happy few, we band of gardeners —
For he today that squashes bugs with me
Shall be my brother; be he ne'er so vile,
This day shall gentle his condition.
And gentlemen in beds now safe from harm
Shall think themselves accursed they were not here,
And hold their trowels cheap whilst any speaks
That fought with us upon Saint Crispian's Day.
Seven adults. One egg pod. ALL vanquished.
. …

Kenneth Branagh as Henry V on a horse shouting Once More Onto the Breach
@Xavier@infosec.exchange
2026-06-04 17:27:58

Another researcher skipped coordinated disclosure entirely and dropped a critical 1-click GitHub token theft in public because he doesn't want to deal with MSRC. In his own words: "I really don't want to deal with MSRC on VSCode bugs."
The bug: just clicking a link can hand an attacker a GitHub token that reads AND writes to all your repos, including private ones. It lives in github[.]dev, GitHub's browser-based VSCode editor, which passes the browser an OAuth tok…

@grahamperrin@bsd.cafe
2026-07-13 17:58:07

@… <bugs.freebsd.org/bugzilla/show> with or without xf86-video-qxl?

@losttourist@social.chatty.monster
2026-06-19 17:55:56

Of course December 25th, 1999 will be the last ever #TOTP because in just a matter of days the millennium bug will wipe out the entirety of human civilisation.

@penguin42@mastodon.org.uk
2026-07-13 01:29:12

Hmm, after a couple of weeks of Qualcomm DSP/fastrpc/llama.cpp debugging, I've found a bug saying it's fixed in new firmware; but it's not at all obvious if there's a new firmware version for this CPU, and fairly confident there isn't for this machine. Arse.

@mgorny@social.treehouse.systems
2026-06-01 02:39:46

It's always important to have a consistent #security policy.
For example, a policy of "If somebody filed a CVE, it's an important security issue, and we will fix it as such, no matter how meaningless the fix is. If nobody did, it's just a glorified bug fix, no matter how serious the bug was."
So we've just seen a #pip security release over "installing random packages can overwrite pip's files and pip can lazy-import some of them immediately afterwards", with a fix of "pip will no longer load them until you run it again" (leaving the underlying security issue of "any #Python package can override files installed by any other Python package" as intended behavior). As Eli Schwartz beautifully put it, you are not expected to be using the virtual environment; you should create it, install packages into it (at most once!), and then frame it and put it on the wall to admire.
Now we're seeing a "bug fix" for "malicious entry point names can write outside of virtual environment". If nobody filed a CVE, it's obviously not a security issue at all. At least upstream graced us with fixing it without correcting the spec to forbid that first.
github.com/pypa/pip/issues/140

@macandi@social.heise.de
2026-06-02 15:48:00

Apple fixt Ladeproblem beim iPhone 17 und Shutdown-Bug auf M5-Macs
Apple verteilt iOS 26.5.1 und macOS Tahoe 26.5.1. Die Updates beheben ein Ladeproblem bei iPhone 17 und iPhone Air sowie Abstürze auf M5-Macs.

@cheeaun@mastodon.social
2026-05-14 08:01:12

Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- …

@andres4ny@social.ridetrans.it
2026-06-04 20:59:10

it's like raaaaaaaaaaaaaaaaaaaaaaaaaaaaaain on your wedding day

An email with the subject line "Bug#1138842: Multiple vulnerabilities: CVE-2026-46447 CVE-2026-48681 CVE-2026-44917" and the body following a machine-readable format for a debian bug report. The (source) package name is "ironic" and the version is "1:29.0.0-7".
@newsie@darktundra.xyz
2026-04-29 13:06:40

Apple Fixes Bug That Let FBI Extract Deleted Signal Messages After 404 Media Coverage 404media.co/apple-fixes-bug-th

@Techmeme@techhub.social
2026-06-12 04:50:46

Oracle warns customers of a critical PeopleSoft flaw after ShinyHunters claimed breaches of 100 organizations using PeopleSoft; Oracle has not issued a patch (Lorenzo Franceschi-Bicchierai/TechCrunch)
techcrunch.com/2026/06/11/orac

@fanf@mendeddrum.org
2026-06-16 17:42:03

from my link log —
Pinning down a hardware bug in Intel 13th/14th gen CPUs.
fgiesen.wordpress.com/2025/05/
saved 2026-06-16

@azonenberg@ioc.exchange
2026-07-14 18:34:20

Is anyone actively using the DisplayPort Aux Channel decode in ngscopeclient? I think I found a bit ordering bug but before I start poking stuff I want to know who's been using it and if you have any known good waveforms you've checked it against etc

@colinpurrington@flipping.rocks
2026-06-06 16:25:47

Friends, I managed to come up with a full ten (10) reasons why you shouldn't buy bug zappers. At the top of the list, of course, is that they barely kill any mosquitoes. But they also create noise pollution and can burn your house down, among other problems. #mosquitoes #insects #nature colinpurrington.com/2026/06/10

@kubikpixel@chaos.social
2026-06-12 09:31:00

«Kernel-Bug — FreeBSD-Exploit "Bumsrakete" verleiht Root-Zugriff:
Ein Exploit namens Bumsrakete gefährdet alle FreeBSD-Versionen der letzten fünf Jahre. Die Entdecker nehmen es mit reichlich Humor»
Weshalb wahrscheinlich einige Server kurz offline waren/sind. Sicherheitsrelevante Updates müssen auf der Stelle eingespielt werden, denn die par Minuten das die User einschränkt ist harmlos dem Bug gegenüber.
😈

@cyrevolt@mastodon.social
2026-07-08 16:19:37

I found a #bug

@BBC6MusicBot@mastodonapp.uk
2026-05-18 21:21:31

🇺🇦 #NowPlaying on #BBC6Music's #RileyAndCoe
The Bug Club:
🎵 A Good Day For Dying
#TheBugClub
open.spotify.com/track/5RcBPGJ

@macandi@social.heise.de
2026-05-06 12:38:00

watchOS 26.5: Apple behebt SMS-Bug bei Dual-SIM und Training-Hinweisen
Apple hat den Release Candidate von watchOS 26.5 veröffentlicht. Das Update behebt zwei Fehler bei Dual-SIM-iPhones und Training-Alerts.

@metacurity@infosec.exchange
2026-05-04 18:17:13

Hackers are still exploiting the cPanel bug to gain control of thousands of websites
techcrunch.com/2026/05/04/hack

@Nathan@social.lostinok.com
2026-06-17 02:35:21

Squash Bug War Casualty Report:
Adults: 0, Egg Pods: 0
I know I’m lacking on Dad humor missives, but it seems we’ve come to a cease fire in the war. Two days now and only one egg pod to show for it. Going to go quiet until they return. I know they are out there somewhere.
#gardening #oklahoma

Guy with binoculars watching.
@Techmeme@techhub.social
2026-05-01 17:55:53

A bug in popular cPanel, WHM, and WP Squared software has reportedly been exploited since Feb.; CISA it gives a 9.8 CVSS score, tells agencies to patch by May 3 (Jonathan Greig/The Record)
therecord.media/cisa-orders-fe

@azonenberg@ioc.exchange
2026-05-15 03:04:08

Fun engineering/privacy problem: design a device that plugs into an ESP32 based sensor node that has a microphone and reports ambient noise levels in dBa via MQTT or similar.
That's the easy part.
The hard part is to do so in a way that you can prove it's incapable of being used as a bug/listening device even in the worst case scenario (attacker running arbitrary code on any programmable component).
My initial thought is to record audio from a MEMS mic into a tiny M…

@grahamperrin@bsd.cafe
2026-06-06 04:12:29

FreeBSD bug 263171 – add loader(8) and boot loader menu support for boot with OpenZFS-encrypted ROOT
bugs.freebsd.org/bugzilla/show
@…

@colinpurrington@flipping.rocks
2026-06-07 16:07:17

We also need bird organizations to come out against bug zappers. Because when billions of insects are electrocuted there's less food available. And you could use an illustration of begging chicks in a nest near a glowing bug zapper surrounded by moths (make the parent birds emaciated and worried). That graphic would go viral. #birds #insects #birding

@Techmeme@techhub.social
2026-05-11 08:36:29

The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development time, and critical issues must be patched immediately (Himanshu Anand)
blog.himanshuanand.com/2026/05

@metacurity@infosec.exchange
2026-05-08 13:50:07

Cybersecurity is, as they say, moving at machine speed, so don't leave for the weekend until you check out today's Metacurity for the critical infosec developments you should know, including
--Canvas chaos: ShinyHunters breach throws schools into disarray
--Firefox bug fixes soar after using Mythos,
--Virginia man found guilty of destroying government databases,
--OpenAI rolls out GPT 5.5 to vetted cyber defenders,
--PCPJack steals cloud creds while remov…

@Nathan@social.lostinok.com
2026-06-12 02:07:29

SQUASH BUG WAR CASUALTY REPORT
KIA: 0, Egg Pods Destroyed: 0
No contact with the enemy today. Not one bug. Not one egg. The leaves are still. TOO still.
This is not a victory. This is a TRAP.
#gardening #oklahoma

Martin Sheen rising from the water in Apocalypse Now.
@grahamperrin@bsd.cafe
2026-06-04 01:53:29

FreeBSD bug 100782 – [keyboard] Default keymap to support ALT Left, ALT Right console switching
bugs.freebsd.org/bugzilla/show
@…

@metacurity@infosec.exchange
2026-05-06 11:05:33

Google Raises Top Android Bug Bounty to $1.5 Million to Combat AI-Era Threats
hothardware.com/news/google-an

@Techmeme@techhub.social
2026-04-23 11:01:12

Apple fixes a bug that stored notifications for deleted messages on iPhone and iPad, following a report that police used it to extract deleted Signal messages (Lorenzo Franceschi-Bicchierai/TechCrunch)
techcrunch.com/2026/04/22/appl

@Techmeme@techhub.social
2026-05-15 01:30:55

Security research firm Calif says it used Mythos to help build a macOS kernel memory corruption exploit circumventing Apple's Memory Integrity Enforcement tech (Robert McMillan/Wall Street Journal)
wsj.com/tech/ai/anthropic-myth

@grahamperrin@bsd.cafe
2026-06-13 19:13:02

@… thanks. Make a bug report, if you like.
Neither of the two open reports is a match: <

@metacurity@infosec.exchange
2026-06-10 13:47:27

Fasten your seat belts because the cyber developments are off the charts this week. Stay ahead of the curve and check out today's Metacurity for the most crucial developments, including
--Anthropic releases Mythos-derived model with cyber guardrails,
--Admin halts AI safety reports amid fight over oversight,
--Microsoft patches record 200 flaws as AI fuels bug discovery,
--Nightmare Eclipse drops fresh Windows zero-day,
--China's hackers target tech firms…

@Nathan@social.lostinok.com
2026-06-15 02:59:29

Squash Bug War Casualty Report: Adults 0, Egg Pods 0.
No enemy contact, but I know they are out there, it’s like they are taunting me . . .
“Hallo, you tiny-brained gardener! You frighten no one! Today we did not come, because we did not feel like it!”
#gardening #oklahoma

The taunting French knight from Monty Python and the Holy Grail
@grahamperrin@bsd.cafe
2026-05-03 03:02:08

@… this bug?
287569 – bsdinstall: restarting installation: Error: No disk(s) present to configure — <bugs.freebsd.org/bugzilla/show

@Nathan@social.lostinok.com
2026-06-10 01:08:55

Evening Squash Bug War: Casualty Report
10 adults KIA, 4 egg pods destroyed.
O cursed stinkèd foe, thou crept upon my vine!
But lo — my thumb of justice, swift and firm,
Hath crushed thy copper eggs and broke thy line.
The Union garden stands. Begone, thou bug.
#gardening #oklahoma

Union soldiers crossing a field firing.
@metacurity@infosec.exchange
2026-04-22 14:53:50

To help defenders prioritize patches amid the coming onslaught of bug reports, Anthropic recommends that they rely on a vulnerability framework known as the Exploit Prediction Scoring System (EPSS).
Check out my latest CSO piece on how EPSS works.
Many thanks to Michael Roytman and Ed Bellis of Empirical Security, James Robinson of Netskope, Aaron Weismann of Main Line Health, and Ramy Houssaini of Cloudflare for their insight.
Anthropic bets on EPSS for the coming bug surg…

@Nathan@social.lostinok.com
2026-06-14 03:06:58

Squash Bug War Casualty Report:
Adults: 1, Egg Pods: 2
Too tired to attempt dad humor tonight, but feels like we have reached a equilibrium. Great news is the it’s in our favor, we got 4 more squashes and zucchinis tonight.
#gardening #oklahoma

@grahamperrin@bsd.cafe
2026-05-07 08:26:28

272902 – Security: allow passphrases for WPA-EAP to be saved without using clear text
<#FreeBSD

@Techmeme@techhub.social
2026-05-11 16:10:42

curl founder Daniel Stenberg says Mythos identified five vulnerabilities in curl, but a manual review found three were false positives and one was a bug (Daniel Stenberg/daniel.haxx.se)
daniel.haxx.se/blog/2026/05/11

@Techmeme@techhub.social
2026-05-11 13:20:38

Google's TIG reports the first confirmed instance of "prominent cybercrime threat actors" using AI to find and weaponize a zero-day in a web-based admin tool (Dustin Volz/New York Times)
nyti…

@Nathan@social.lostinok.com
2026-06-13 02:04:59

Squash Bug War Report: 4 bugs, 0 Eggs
Hearken, cowards of the cucumber! We, the Shield-Pair of the Raised Bed, walked the battlefield at dawn and four of thy foul kin now feast in the void.
We lifted the leaves and found thy warriors hiding beneath like thralls afraid of the frost. Come forth and face us in open combat! Do not skulk in the leaf darkness!
The Jarl-Wife crushed two with the calm of a seasoned berserker. I dispatched two more into the Bucket of Soapy Doom.

A viking with a sword
@Techmeme@techhub.social
2026-07-10 20:50:54

Apple alleges that a former Apple engineer kept a work-issued Apple laptop and exploited a bug to access Apple's cloud file storage while employed by OpenAI (Megan Morrone/Axios)
axios.com/2026/07/10/apple-sue