Tootfinder

Opt-in global Mastodon full text search. Join the index!

@johl@mastodon.xyz
2025-12-05 10:27:49

🎅 🌲 💫
Weihnachtlich erstrahlen Gassen
Auf zum Einkauf hasten Massen
Drinnen leuchten Kerzen hell
Nur Systemadministratoren
Lauschen bang dem Netz-Rumoren
Horch! Es naht #React2Shell!

@hanno@mastodon.social
2025-12-02 10:32:05

I've recently stumbled upon an RCE "exploit" for the Serendipity blog software, which I happen to use and have contributed to in the past. From what I can tell, it does nothing interesting (it does not even work due to broken indents, if one fixes that it uploads a PHP shell given existing credentials, but that won't be executed unless you have a server config that executes .inc files). I'm 95% certain this is bogus. Yet... in case anyone wants to have a look:

@newsie@darktundra.xyz
2026-02-03 16:33:38

Russian state hackers exploit new Microsoft Office flaw in attacks on Ukraine, EU therecord.media/russian-state-

@heiseonline@social.heise.de
2025-12-27 13:03:00

„MongoBleed“: Exploit für kritische Lücke in MongoDB erleichtert Angriffe
Wer für eine MongoDB-Instanz verantwortlich ist, kann sich nicht zurücklehnen: Ein Exploit für eine schwerwiegende Lücke macht Upgrades jetzt noch dringender.

@primonatura@mstdn.social
2025-12-02 13:00:07

"EU seeks to exploit nature-based products for competitiveness push, green groups say"
#EU #EuropeanUnion #Nature

@NFL@darktundra.xyz
2026-02-05 10:31:52

Inside Patriots-Seahawks Super Bowl matchup: What to watch when New England has the ball nytimes.com/athletic/7019593/2

@heiseonline@social.heise.de
2025-12-27 14:29:00

„MongoBleed“: Exploit für kritische Lücke in MongoDB erleichtert Angriffe
Wer für eine MongoDB-Instanz verantwortlich ist, kann sich nicht zurücklehnen: Ein Exploit für eine schwerwiegende Lücke macht Upgrades jetzt noch dringender.

@NFL@darktundra.xyz
2025-12-04 15:19:36

The Playbook: Shadow Reports, lineup locks for Week 14 espn.com/fantasy/football/stor

@ber@social.tchncs.de
2026-02-02 11:29:26

"human fracking
The use of information technology to exploit human attention in ways that are net counterproductive to the persons thus exploited
" en.wiktionary.org/wiki/human_f

Just learned about the term, reading

@metacurity@infosec.exchange
2026-01-28 14:16:24

Check out today's Metacurity to stay up-to-date on the critical infosec developments you should know, including
--The interim head of CISA uploaded sensitive documents to ChatGPT,
--Koreans to be notified of possible data breaches,
--Operations at Russian security systems outfit were disrupted by a cyberattack,
--EU-India security deal omits hackers-for-hire,
--Threat actors exploit a high-severity vulnerability in WinRAR,
--Mustang Panda can steal logi…

Fundamentalist Christian influencer Allie Beth Stuckey
doesn’t see empathy as a failure of evolution (like Elon Musk does).
As a creationist who denies the scientific reality of prehistoric dinosaurs,
she doesn’t even believe in evolution.
Stuckey has made it her mission to rewrite the teachings of Jesus so that her savior is a harsh disciplinarian
whose “love” has little to do with empathy.
Stuckey’s book
“Toxic Empathy: How Progressives Exploit C…

@philip@mastodon.mallegolhansen.com
2025-12-29 02:40:41

@… As a “computer person” in this equation, it strikes me as obvious that, if some exploit exists, no matter how hard you try to keep it secret, bad actors are already out there who posses the knowledge.
Trying to keep it under wraps only serves to allow those actors to exploit the issue, without the rest of us being any wiser.
I suppose that’s ex…

@ErikJonker@mastodon.social
2025-12-26 17:46:23

“you can just supply an IP address of a MongoDB instance and it’ll start ferreting out in memory things such as database passwords (which are plain text), AWS secret keys etc. The exploit specifically looks for those class of credentials and secrets, too.”
doublepulsar.com…

@Techmeme@techhub.social
2025-11-27 06:26:01

South Korean crypto exchange Upbit suspended deposits and withdrawals after saying $37M worth of Solana tokens were moved to an unauthorized external wallet (Sidhartha Shukla/Bloomberg)
bloomberg.com/news/articles/20

@gray17@mastodon.social
2026-01-29 19:15:10

"AI democratizes creativity and talent" => "AI offers everyone a minion they can exploit ruthlessly"
... sure it's possible to ethically use dollar-store fluffers when you can't afford professionals or can't attract volunteers, but maybe don't delude yourself into thinking it's something else?

@stefan@gardenstate.social
2026-01-28 02:04:59

Hard to argue with this.
platformer.news/social-media-s

The next time you go to Las Vegas, you'll notice that there are no 13-year-olds in the
casinos. The reason is not because a series of longitudinal studies proved to the
satisfaction of the gaming industry that gambling causes anxiety and depression. Rather,
there are no 13-year-olds in casinos because we know that the environment is designed to
exploit them.

US plans to exploit Venezuela’s oil reserves could by 2050 consume 🔥more than a tenth of the world’s remaining carbon budget to limit global heating to 1.5C, according to an exclusive analysis.
The calculation highlights how any moves to further exploit the
South American nation’s oil reserves
– the largest in the world,
at least on paper
– would put increasing pressure on climate goals,
and risk plunging the globe further into climate catastrophe.
<…

@metacurity@infosec.exchange
2025-11-06 22:02:44

Chris Krebs compared the Balancer exploit to the scheme from Office Space, where the idea was to skim fractions of a penny off the top of many individual transactions.
Krebs also pointed to the possible use of artificial intelligence in crafting the exploit code as another interesting aspect of the situation.

@Mediagazer@mstdn.social
2025-12-11 15:01:44

Disney sends Google a cease-and-desist, accusing Google of copyright infringement on a "massive scale" and using AI to "exploit and distribute" the content (Todd Spangler/Variety)
variety.com/2025/digital/news/

@newsie@darktundra.xyz
2026-02-02 14:04:10

Notepad hijacked by suspected state-sponsored hackers therecord.media/popular-text-e

@pre@boing.world
2025-11-23 20:40:43
Content warning: re: bitcoin conference report

The conference is over now. I likely wouldn't have come for just a bitcoin thing, but I am very interested in redecentralizing the web, so it's attachment to the nostr day pulled me in.
Everyone I met was friendly and interesting and seems much more interested in making a better money system than in making money for themselves.
Our government and bank money systems are dysfunctional in all kinds of ways which are often less visible than they should be too people using them, especially to those in Europe and America who benefit from the way those systems exploit the global south.
I'm not convinced that fixing that would end wars and fix broken government as some seem to think, but I am sure our money is the source of many problems.
There are many bright, well meaning, and intelligent people building to improve bitcoin in fascinating ways with the hope of having a parallel system to transition to. With lots of work still to be done.
Can it work?
I'm sure I don't know, and I'm sure even if it's a better system it'll come with it's own unfairness and cruelty. Money will continue to be a source of suck and worry.
I'm told that the bigger conferences are often full of shitcoin scammers and suit wearing banksters who are in fact all in it too get rich and rip people off, but I found none of that here.
Here there is a real community of people trying to make the world a better place and improve the lives of their neighbours and governance of their countries.
And in the end building community is the most radical and effective way to change the world regardless of the problems of it's money system.
I had a great time. Thanks to those organising it.
#bitfest #bitcoin

@deprogrammaticaipsum@mas.to
2025-11-22 11:38:28

"In Phrack Magazine, this author learned at the end of the 1990s the subtle art of smashing the stack, an exploit that would become the starting point of many a computer security book afterward.
There is one magazine that has been around for a decade: the “International Journal of Proof-of-Concept or Get The Fuck Out”, or “PoC||GTFO”.
(I should have probably warned readers about the profanity in the title, but nah, I assume them to be adults at this point.)"

@hex@kolektiva.social
2025-11-21 10:25:31

It's also interesting that we're only tangentially making the connection between shit social media and fascism. What we are not saying is that control of social space *is* a form of governance. Humans have the right to free social spaces, both physical and digital.
When we think about social media as a system of control, as a government, we see that capitalist social media results in incredibly abusive dictatorships. These dictatorships exist solely to exploit their citizens, extracting both labor and attention, for the gain of a few. They manipulate their citizens to keep them locked in. It's not a coincidence that these systems algorithmically promote fascist ideology. They are themselves a type of fascist government that pushes fascism into the physical space.

@fanf@mendeddrum.org
2025-12-20 18:42:01

from my link log —
What they don't tell you about demand paging in school.
offlinemark.com/2020/10/14/dem
saved 2020-10-17

@metacurity@infosec.exchange
2026-01-22 14:28:39

Even if you're gearing up for a monster winter storm, take the time to check out today's Metacurity for the most crucial cybersecurity developments you should know, including
--Acting CISA head got grilled on mass firings at the agency,
--EU's CIRCL launches GCVE system,
--DeFi project EVM was exploited for $6m,
--Attackers exploit patch bypass for FortiGate flaw,
--Cisco fixes Unified Communications and Webex Calling RCE flaw,
--Mass spam wave …

@Techmeme@techhub.social
2025-12-11 14:59:29

Disney sends Google a cease-and-desist, accusing Google of copyright infringement on a "massive scale" and using AI to "exploit and distribute" the content (Todd Spangler/Variety)
variety.com/2025/digital/news/

@NFL@darktundra.xyz
2025-12-31 22:19:14

The Playbook: Shadow Reports, lineup locks and projected scores for Week 18 espn.com/fantasy/football/stor

A massive WhatsApp security flaw exposed the phone number of almost every user on the planet
– despite the fact that parent company Meta had been alerted to the vulnerability way back in 2017.
Security researchers were able to use what they described as a “simple” exploit to extract a total of 3.5 billion phone numbers from the messaging service …
The researchers say that if the same exploit had been used by bad actors, the result would have been “the largest data leak in …

@grumpybozo@toad.social
2026-01-12 02:49:41

Using MS365 for email is accepting the combined unknown unknowns of both MS operating policy choices and their other customers’ security.
And the KNOWN risk that it makes phishing much easier to execute in ways which are harder to catch.
#Sysadminnery @…

@newsie@darktundra.xyz
2025-11-26 14:43:07

Hackers exploit 3D design software to target game developers, animators therecord.media/hackers-blende

@joxean@mastodon.social
2025-11-10 09:50:59

Rapid insights for malware analysts, by Marc Rivero (@…).
Talk about r2inspect "a framework for static malware analysis built on top of radare2 and r2pipe, providing accurate detection of obfuscated strings, cryptographic signatures, exploit mitigation analysis, and more".

@geant@mstdn.social
2025-11-11 12:51:49

🚨An email pops up: “Quick! Can you upload the contract here? My VPN’s down!”
It looks like your colleague. It feels urgent. But is it real? 👀
Smishing messages like these exploit trust and urgency, making us act before we think.
It’s easy to slip into autopilot when we’re busy.
But #digitalmindfulness means slowing down, even if for just a few seconds.
🔗 W…

GÉANT Cybersecurity 2025 campaign: Animated video 4
@pre@boing.world
2025-11-22 10:59:21
Content warning: re: bitcoin conference report

A panel of people from a few different countries.
The UK, where the event is, and the US currently have money which perhaps is good enough that the people there don't see much need to replace the money. Running global reserve currency helps exploit other poorer countries. The problems are fairly invisible.
But in other countries, poorer countries with even worse money, countries more exploited by debasement of the global reserve currencies, the problems with government money are more evident. They see the need for an alternative more strongly.
Adoption is important though. Money is only money if it's widely accepted. So given the choice of more users or higher price, the panel would all pick more users.
#bitfest #bitcoin

@metacurity@infosec.exchange
2026-01-20 14:21:06

Don't miss today's Metacurity for a concise round-up of the most critical infosec developments you should know, including
--UK's NCSC warns of Russian-aligned hacktivist groups,
--UK and China enter a forum to discuss cyberattacks,
--Makina Finance lost $4.2m in an exploit,
--Ingram Micro report ransomware attack affecting 42k,
--Minnesota DHS breach affected 304k,
--SK Telecom appeals $91m fine,
--NexShield malvertising campaign crashes b…

@Mediagazer@mstdn.social
2025-11-20 21:26:06

A look at Rupert Murdoch's California Post, which will focus on LA, Silicon Valley, and Sacramento when it launches in 2026; Ian Mohr will lead CA Page Six (Lachlan Cartwright/Vanity Fair)
vanityfair.com/hollywood/story

@cosmos4u@scicomm.xyz
2025-12-06 16:45:43

TDCOSMO 2025 - Cosmological constraints from #StrongLensing time delays: aanda.org/articles/aa/full_htm -> A speed camera for the universe: u-tokyo.ac.jp/focus/en/press/z - researchers exploit gravitational lensing to see how fast the universe is really expanding.

@cellfourteen@social.petertoushkov.eu
2025-12-07 20:27:04

This kind of circular causality is exactly the reason why I don't have even a burner account on X. As a social website, it went belly up more times than his owner's talk of colonizing anything in space.
X axes European Commission’s ad account after €120M EU fine – POLITICO

@metacurity@infosec.exchange
2025-12-17 14:21:59

Check out today's packed Metacurity for the most critical infosec developments you should know, including
--Venezuela's state-run oil company PDVSA was hit by a cyberattack,
--Coupang's founder failed to show at parliamentary hearing,
--Vast majority of parked domains foist scams and malware,
--FTC orders Nomad to pay victims after hackers stole cryptocurrency,
--noyb alleges data exposure by TikTok, Grindr and AppFlyer,
--Hackers exploit critica…

@NFL@darktundra.xyz
2025-11-27 22:04:30

The Playbook: Shadow Reports, lineup locks espn.com/fantasy/football/stor

@pre@boing.world
2025-11-21 14:55:36

Wouter constant is talking about permissionlessness. Nostr is a protocol that doesn't need some central server to authenticate your requests. Which is good. But this means that, say, children can use it without parents permission.
Online safety act and others are closing down the internet to protect them kids. So can nostr have accounts that do need permission? Can it be made kid safe? Of only to satisfy crazy governments under parent pressure.
Weboftrustfoundation exists to try and build kidstr, some kind of nostr for children.
Mostly just asking questions so far. How can it work? How can it avoid labelling vulnerable people to exploit?
#nostr #permissionlessness #nostrshire

@primonatura@mstdn.social
2026-01-09 15:00:03

"A ‘fossil-fuelled war': Trump’s plans to ‘exploit’ Venezuela’s oil reserves sparks climate backlash"
#US #USA #America #Vanezuela

@metacurity@infosec.exchange
2026-01-16 15:12:28

Before you head out for the weekend, check out today's Metacurity for the most critical infosec developments you should know, including
--Trump officials might boycott RSAC citing Easterly's CEO position,
--Grubhub confirms data breach,
--China's UAT-8837 breached CIC orgs in N. America,
--Hackers exploit top severity flaw in Modular DS WordPress plugin,
--Flaw in MD CPUs exposes secure virtualization environment,
--Gemini 'personal intelli…

@Techmeme@techhub.social
2025-12-07 15:05:52

Nikita Bier accuses the European Commission of trying to deceptively amplify the reach of its post about the €120M fine on X; X terminates the EC's ad account (Bjarke Smith-Meyer/Politico)
politico.eu/article/x-axes-eur

@primonatura@mstdn.social
2026-01-16 15:00:10

"US plan to exploit Venezuela’s oil could eat up 13% of carbon budget to keep 1.5C limit"
#US #USA #America #Venezuela

@NFL@darktundra.xyz
2025-12-21 13:44:34

The Playbook: Shadow Reports, lineup locks for Week 16 espn.com/fantasy/football/stor

@NFL@darktundra.xyz
2025-12-18 15:05:28

The Playbook: Shadow Reports, lineup locks for Week 16 espn.com/fantasy/football/stor

@hex@kolektiva.social
2025-11-19 06:07:23

Part of why #Trump has always been so hard to pin down politically is that he was always representing highly conflicting interests. Now, as that eats him alive, the GOP is fracturing in to two main groups: the Pinochet/Franco wing and the Hitler wing.
The Pinochet/Franco wing (let's call them PF) are lead by Vance. PF are also a coalition with some competing interests, but basically it's evangelical leaders, Opus Dei (fascist catholics), tech fascists (Yarvinites), pharma, and the other normal big republican donors. They support Israel, some because apartheid is extremely profitable and some because they support the genocide of Palestinian in order to bring the end of the world. They are split between extremely antisemitic evangelicals and Zionists, wanting similar things for completely different reasons. PF wants strong immigration enforcement because it lets them exploit immigrants, they don't want actual ethnic cleansing (just the constant threat). They want H1B visas because they want to a precarious tech work force. They want to end tariffs because they support free trade and don't actually care about things being made here.
The Hitler wing are lead by Nick Fuentes. I think they're a more unified group, but they're going to try to pull together a coalition that I don't think can really work. They're against Israel because they believe in some bat shit antisemitic conspiracy theory (which they are trying to inject along side legitimate criticism of Israel). They are focused on release of the #EpsteinFiles because they believe that it shows that Epstein worked for Mossad. They don't think that the ICE raids are going far enough, they oppose H1Bs because they are racists. They want a full ethnic cleansing of the US where everyone who isn't "white" is either enslaved for menial labor, deported, or dead. But they're also critical of big business (partially because of conspiracy theories but also) because they think their best option is to push for a white socialism (red/brown alliance).
Both of them want to sink Trump because they see him as standing in the way of their objectives. Both see #Epstein as an opportunity. Both of them have absolutely terrifying visions of authoritarian dictatorships, but they're different dictatorships.with opposing interests. Even within these there may be opportunities to fracture these more.
While these fractures decrease the likelihood of either group getting enough people together, their vision is more clear and thus more likely to succeed if they can make that happen. Now is absolutely *not* the time to just enjoy the collapse, we need to keep up or accelerate anti-fascist efforts to avoid repeating some of the mistakes of history.
Edit:
I should not that this isn't *totally* original analysis. I'll link a video later when I have time to find it.
Here it is:
#USPol

@NFL@darktundra.xyz
2025-11-06 14:49:06

The Playbook: Lineup locks, Shadow Reports for Week 10 espn.com/fantasy/football/stor