Tootfinder

Opt-in global Mastodon full text search. Join the index!

@Techmeme@techhub.social
2026-04-14 14:50:49

Adobe patches a zero-day in Acrobat DC, Reader DC, and Acrobat 2024, which hackers have been actively exploiting for at least four months (Zack Whittaker/TechCrunch)
techcrunch.com/2026/04/14/adob

@eitch@mstdn.gsi.li
2026-04-14 07:49:07

The @… community just released the latest version 4.0.1. It fixes an issue with more than 4 GPIOs enabled at the same time and other miscellaneous fixes.
Details are here: github.com/Pi4J/pi4j…

@inthehands@hachyderm.io
2026-01-15 16:07:22

Does anybody have a connection at Signal who could receive some urgent app design feedback? The app has several very specific problems / limitations / design quirks that are causing major headaches for neighbor groups trying to communicate here in Minneapolis.
(I’ll eventually try to write up some feedback through normal channels so it can go through the normal user feedback pipeline — but I’m sure any fixes that arrive that way will arrive far too late to be useful to us, so I’m not even bothering now. If there’s any chance of having some issues prioritized, I’d sure appreciate it.)
[ETA: I already tagged Mer__edith, but I’m sure she’s far too busy and her mentions are far too crowded for her to give this attention]

@ruario@vivaldi.net
2026-03-14 12:50:40

@… This includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.

@trochee@dair-community.social
2026-02-14 01:26:32

I have finally figured out a way to cope with CJK scripts at work, and I've made _huge_ progress on a largely untested codebase
So of course the PMs are super change averse
"Look, I have been doing character encoding fixes since literally 2001"
"can you trust that the tests that I added are the right things"
"you do realize that the current system *doesn't work*, right?"
And each of them gets a "oh I don't know, so…

@bencurthoys@mastodon.social
2026-04-15 15:36:36

I find myself in want of an affordable way of doing regular cybersecurity scans. Anyone have anything good or bad to say about barrion.io/?

@metacurity@infosec.exchange
2026-02-12 16:13:25

Don't miss today's packed Metacurity for the most critical infosec developments you should know, including
--US drops China Telecom, TP-Link router, and other data security bans before trade talks,
--Crypto-funded transactions for human trafficking soared in 2025,
--Prosecutors confirm former defense contractor exec stole and sold spy tools,
--APT hackers use Gemini AI to support all stages of an attack,
--Apple fixes zero-day exploit in sophisticated att…

@andres4ny@social.ridetrans.it
2026-03-11 23:30:54

Holy shit, why am I maintaining #chromium packages instead of hunting for security holes in it?!

"This update includes 29 security fixes. Please see the Chrome Security Page for more information."

Then there's a list of CVEs, with things like "Critical CVE-2026-3913: Heap buffer overflow in WebML. Reported by Tobias Wienand on 2026-02-10"

The first CVE paid out $33k. The next two paid $43k each, and the one after that $36k. The next one is _only_ $11k.

That's $166k in payouts to security researchers, and it's only 5 out of the listed 29 security fixes!
@azonenberg@ioc.exchange
2026-03-13 05:52:44

Years ago I had a "ReworkCTF" board with 20-odd PCB layout bugs designed into it on purpose, ranging from backwards LEDs to missing vias under a BGA to inner layer differential pair swaps.
The original board had some design issues that made some of the fixes easier/harder than intended, and also ancient, I think now EOL, parts (a Spartan-3A FPGA - even if not EOL nobody wants to use one of those in 2026).
I'm hoping to do a gen 2 of the challenge soon probably based…

@ruario@vivaldi.net
2026-03-14 12:50:02

@… For the curious, this includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
And yes, we somehow beat the Chrome team getting this out even though they did the fix. 😂

@EarthOrgUK@mastodon.energy
2026-04-11 19:51:02

On Website Technicals (2026-03) - Tech updates: EOM, Mastodon share button, bug fixes, low, RSS sadness, routing snafu. - earth.org.uk/note-on-site-tech

@aral@mastodon.ar.al
2026-04-10 13:06:09

🥳 New Kitten¹ Release
Fixes:
• The `kitten.html` shorthands for plain HTMX client-side event handling of a Kitten Page’s default WebSocket lifecycle (`on:connecting`, `on:connect`, and `on:disconnect`) were generating faulty HTMX code (the Alpine.js versions, `@on:connecting`, `@on:connect`, and `@on:disconnect`, were fine). The plain HTMX versions now also generate working code.

• Replaced direct `eval` in a statement in the Kitten Introspection API to improve safet…

@metacurity@infosec.exchange
2026-03-13 11:40:57

Don't leave for the weekend until you've checked out today's Metacurity for the most critical infosec developments you should know, including
--International operation takes down massive cybercrime proxy network SocksEscort,
--Telus probes purported ShinyHunters hack,
--Stryker cyberattack by alleged Iran-aligned hacking group continues to disrupt operations ,
--Leidos CTO John Solly ID'ed as DOGE SSA data thief,
--GAO finds gaps in CMMC program, …

@adulau@infosec.exchange
2026-04-06 08:29:57

rss-tool 1.2 release adds Markdown Journals and Calendar Heatmaps Latest
Version 1.2 brings two new tools to rss-tools, major improvements to Markdown journal generation, and a broad set of fixes and robustness updates across the codebase.
#rss #atom

@nobodyinperson@fosstodon.org
2026-04-14 09:04:51

So about the #Kyocera #CUPS driver needing insecure #pypdf3 situation:
I guess this is not only a #NixOS problem…

@ruari@velocipederider.com
2026-02-13 06:07:50

RE: velocipederider.com/@archiveto
No security fixes this time but some performance stuff and bugs fixed so might as well update.

@macandi@social.heise.de
2026-04-02 09:26:00

Apples CloudKit: Entwickler berichten über Probleme
CloudKit, mit dem Apple Entwicklern eine einfache Synchronisation von App-Daten ermöglicht, scheint mit iOS 26.4 nicht mehr rundzulaufen. Fixes fehlen.

@raiders@darktundra.xyz
2026-02-22 23:18:56

Raiders Hope Their Latest Coaching Hire Fixes Significant OL Issue si.com/nfl/raiders/onsi/las-ve

@azonenberg@ioc.exchange
2026-02-11 16:14:41

Thinking about future release plans for ngscopeclient.
There have been massive performance improvements and some significant bug fixes since v0.1.1 and the ThunderScope dev edition units are going to manufacture so we'll be getting a lot of additional users in ~2 months.
But there's also a lot of ongoing backend refactoring and changes to filter graph blocks that won't be strictly backwards compatible (old filter graphs will need updating) and while I freely break sof…

@fanf@mendeddrum.org
2026-02-19 21:42:04

from my link log —
Linux CVE assignment process.
kroah.com/log/blog/2026/02/16/
saved 2026-02-19

@Techmeme@techhub.social
2026-03-09 17:26:37

OpenAI agrees to acquire Promptfoo, which fixes security issues in AI systems being built and is "trusted by 25% of Fortune 500", to fold into OpenAI Frontier (OpenAI)
openai.com/index/openai-to-acq

@seeingwithsound@mas.to
2026-04-08 15:11:51

The vOICe for Android 2.81 released play.google.com/store/apps/det Fix for view no longer tracking device orientation. Stereo sound now default enabled even w/o headphones because many modern phones feature stereo speakers. Minor bug fixes. App now r…

Look ma, no echolocation! The vOICe for Android running with AI depth view active (menu Options | AI depth view).
@metacurity@infosec.exchange
2026-04-08 13:42:21

Someday, I will send out a Metacurity email that doesn't get clipped by Gmail for having too much information, but that day is not today.
Check out today's intensely packed Metacurity that covers a host of critical infosec developments, including
--Iran-linked hackers target critical infrastructure controls, risking disruption and sabotage,
--Anthropic's Glasswing could upend bug discovery and fixes,
--GRU-linked hackers infiltrate routers to steal email a…

@EarthOrgUK@mastodon.energy
2026-04-06 19:51:02

On Website Technicals (2026-03) - Tech updates: EOM, Mastodon share button, bug fixes, low, RSS sadness, routing snafu. - earth.org.uk/note-on-site-tech

@keen456@infosec.exchange
2026-03-08 02:18:26

@… Have you seen this story? phoronix.com/news/ATI-R300-Occ Developer in Czechia working on fixing up R300…

@andres4ny@social.ridetrans.it
2026-04-09 18:52:46

Chromium does weekly stable releases, and typically there are at least a few CVE fixes in a new release. Sometimes there's just one or two, but usually there's around 10-20.
The latest #chromium stable release (147.0.7727.55) has *60* CVEs. I don't know if that's LLMs being better at finding security holes or what, but that's the most I've ever seen by far.

@knurd42@social.linux.pizza
2026-01-23 19:01:20

Martin Stransky highlights some recent major achievements for #Firefox on Linux: ""HDR video playback support, reworked rendering for fractionally scaled displays, and asynchronous rendering implementation. All this progress was enabled by advances in the Wayland compositor ecosystem, with new features implemented by Mutter and KWin.
[…]
And there are even more challenge…

@ruari@velocipederider.com
2026-04-09 10:06:49

I just spam the Vivaldi browser update posts with pictures of my cycles because I can and nobody stops me! 🤣
vivaldi.com/blog/desktop/deskt

@keithp@fosstodon.org
2026-02-04 08:11:25

I added enough Linux support to picolibc to run lua; the lua test suite found a number of core picolibc bugs. This whole adventure suddenly turns out to have actual value and not just comic relief.
I now have a shell script that adapts gcc to using picolibc and have built a small number of applications including snek, nickle and lua.
exec cc -static --specs=picolibc.specs "$@"

@cheeaun@mastodon.social
2026-01-31 13:12:38

#PhanpySocial changelog ✨
⌨️ More sequential hotkeys, g>s (Settings), g>p (Profile), g>b (Bookmarks)
💈 Redesigned poll
🛬 Redesigned landing page
🐛 Bug fixes
🔗 phanpy.social/

Screen recording of new landing page design, scrolled from top to bottom.
@thomastraynor@social.linux.pizza
2026-02-06 13:49:34

Client told DEV the changes looks good in test, deploy.
DEV told our support person, deploy the fix.
Me? STOP, CEASE, DESIST!
1. It is a Friday and we have three special set of 'apps' running this evening. They must run tonight!
2. There were zero backups that would allow a rollback if there are problems.
3. No process defined to verify the before and after.
4. NEVER DEPLOY FIXES ON A FRIDAY UNLESS IT IS AN EMERGENCY!

@raiders@darktundra.xyz
2026-02-22 19:07:48

Raiders Hope Their Latest Coaching Hire Fixes Significant OL Issue si.com/nfl/raiders/onsi/las-ve

@metacurity@infosec.exchange
2026-02-11 14:18:48

Metacurity is the independent, non-hype, non-personality-dependent cybersecurity newsletter that delivers a daily dose of critical developments you need to know.
Check out today's issue, which covers
--CISA warns US infrastructure owners following Russian attack on Poland's power grid,
--Russia throttles Telegram accusing it of failing to protect personal data or combat crime,
--N. Korean hackers targeted crypto company with unique malware and multiple scams,…

@aral@mastodon.ar.al
2026-03-02 19:03:15

🥳 New Kitten release
Several but fixes, thanks to wunter8 (codeberg.org/wunter8):
• Default socket doesn't work when testing with a local mobile device (

@cowboys@darktundra.xyz
2026-03-25 05:02:04

Cowboys 7-round mock draft: 5 trades net 2 vets, fixes all roster holes cowboyswire.usatoday.com/story

@newsie@darktundra.xyz
2026-02-26 14:28:14

After years of government cyber trouble, UK turns to automated scanning to speed fixes therecord.media/united-kingdom

@hynek@mastodon.social
2026-03-24 15:54:38

Here’s a prometheus-async 26.1.0 with improved Twisted support courtesy of the Twisted Lord @… himself!
github.com/hynek/prometheus-as

@kurt@nelson.fun
2026-02-02 22:32:39

Ugh, fare inspectors, SFPD, Bart PD, etc are all over the Mission probably because our pretty boy wants to look good on TV.
Is this what having Newsom (fixes my hair) as mayor was like?

@nemobis@mamot.fr
2026-03-25 14:25:32

The EU is looking for short fixes to reduce gas demand and has failed to find any.
euronews.com/my-europe/2026/03
China is ex…

@NFL@darktundra.xyz
2026-03-17 18:26:16

Jerry Jones says the Cowboys would've made a playoff run with 'a lick of defense.' Here are five bargain fixes

cbssports.com/nfl/news/cowboys

@DamonHD@mastodon.social
2026-02-26 07:37:58

#today there is a little urgent-ish #lifeAdmin to do, at least a little #NewScientist article splurge, and then hopefully the few lines of initial code fixes for my

@zachleat@zachleat.com
2026-03-20 20:31:27

If you (like me) were attempting to npm publish via GitHub Actions using `npm@latest` (currently v11.12.0) and saw an error message involving `--prefer-online` and `--prefer-offline`, reverting to npm@11.11.1 fixes the issue.
Related: github.com/npm/cli/issues/9133

@adulau@infosec.exchange
2026-04-03 16:47:46

We are happy to announce the release of MISP v2.5.36, which includes new geolocation and map visualisation capabilities, the continued development of the Overmind UI, a new interactive CLI shell UI, important security fixes, and installer improvements.
#misp #cti

MISP now supports rich geolocation visualisation for objects containing geographic data. When enabled, geolocation objects display an interactive map icon that renders coordinates on a tile-based map.
@stf@chaos.social
2026-02-23 02:38:53

just released pwdsphinx 2.0.4
includes a security fix to pwd rules breaking unlinkability - thx dnet!
also lots of improvements and fixes since last march.
pwdsphinx is a simple online #passwordmanager which has security properties that go way beyond other popular password managers offer. for more information see

@emilis@social.linux.pizza
2026-01-26 15:50:48

One of the stupidest fixes I ever did (after two days of searching how to fix the problem).
The problem was Kobo Books iOS app opening links to book chapters inside popups, instead of jumping to the target page.
😞
#epub #kobo

Code diff.
Added non-breaking spaces around var "number" inside some template generating an HTML link.
@al3x@hachyderm.io
2026-01-26 21:10:43

I suspect that my VS Code is completely "borken" as I cannot imagine how so many people are productive using it.
1. The selection behavior I have shared earlier continues to manifest sporadically. A restart fixes it. Sometimes.
2. I can't recall any keyboard shortcuts as they don't use any historical paradigms and they are all of the place.
3. Frequently used functionality (e.g. stage changes) has no shortcuts.
I am sure this is will be unpopular opinion.
It's been my experience so far. Very frustrating and I almost gave up a few times already.

@macandi@social.heise.de
2026-03-19 16:16:00

iOS 26.4 bringt bald Neuerungen: Apple geht die Problemstellen an
Von der unzuverlässigen iPhone-Tastatur über die konservative Familienfreigabe bis zu Liquid-Glass-Geblinke: Version 26.4 verspricht wichtige Fixes.

@mcdanlj@social.makerforums.info
2026-03-20 01:06:26

I was reading the most recent @… WIP Wednesday and saw:
There are 2 release blockers for v1.1 currently, down by 2 from last week.
If I read those two release bl…

@todbot@mastodon.social
2026-03-21 19:10:49

I'm so glad I have a Linux box on my desk to MOUNT USB DRIVES because #MacOS just decides to forget how to do it (and hangs Disk Utility). The device is there! It works! It shows up in USB Prober! A reboot fixes it! WHY? Apple, you used to do USB MSC so well, what happened? It's so tiring.

Me holding up a regular FAT-formatted USB thumb drive that works on every other system, but somehow flabbergasts Apple's MacOS. Behind it is my MacBook's screen showing USB Prober recognizing the drive but Disk Utility hanging. I love my Mac, but MacOS basic functionality has really gone down.
‪@todbot@mastodon.social‬
2026-03-21 19:10:49

I'm so glad I have a Linux box on my desk to MOUNT USB DRIVES because #MacOS just decides to forget how to do it (and hangs Disk Utility). The device is there! It works! It shows up in USB Prober! A reboot fixes it! WHY? Apple, you used to do USB MSC so well, what happened? It's so tiring.

@EarthOrgUK@mastodon.energy
2026-03-29 03:23:05

On Website Technicals (2026-03) - Tech updates: EOM, Mastodon share button, bug fixes, low, RSS sadness, routing snafu... - earth.org.uk/note-on-site-tech

@aral@mastodon.ar.al
2026-02-27 17:54:46

🥳 New Kitten Release
This one fixes a bug that you would have encountered had you had an asynchronous component (component with asynchronous render method) nested more than one-level deep within synchronous components.
(Kitten’s html renderer transparently supports both synchronous and asynchronous render methods.)
So, this (taken from my unit test), for example, works correctly now:
```js
class AsynchronousOtherName extends KittenComponent {
async htm…

@cellfourteen@social.petertoushkov.eu
2026-03-19 11:44:45

Oh wow, oh lol 😁

TheRazerMD OPTI 15:02
@everyone Thanks to community effort, we're ready to present a new version of FSR4 INT8 which significantly improves the RDNA2 experience

. Labelled as 4.0.2b
Fixes RDNA2 ghosting (or atleast significantly improves it)
· Works now on latest drivers
o Should remove the need for RDNA2 running old modified drivers
· No changes for other arches, should work as before

Edit: There's been an upload of an earlier test build labelled as 4.5.0 (blame the original fork), so best to…
@cheeaun@mastodon.social
2026-02-24 15:16:58

#PhanpySocial changelog ✨
📤 Allow receiving shared data with the Web Share Target API
🔐 Timeline access controls
👤 New shortcut: "Profile"
📝 "Only followings" filter for Mentions
↕️ Preliminary support for vertical-lr writing mode
🐛 Bug fixes
🔗

@metacurity@infosec.exchange
2026-04-07 14:15:31

Although it might be hard to focus on cybersecurity today, check out today's Metacurity for a quick scan of the most critical infosec developments you should know, including
--Russia aids Iran with satellite targeting, cyber ops against Middle East infrastructure, report,
--Cyber-enabled fraud reached $17.6b in 2025,
--Hackers accessed files of Jones Day,
--Storm-1175 deploys n-day and zero day exploits,
--GPU rowhammering enters new territory,
--CISA o…

@macandi@social.heise.de
2026-03-18 11:05:00

Schwer zu finden: Apple spielt Background-Security-Improvement-Update aus
Apple will mit sogenannten BSIs schneller Geräte aktualisieren, wenn es um kleinere Fixes geht. Das Problem: Die verstecken sich tief in den Einstellungen.

@piger@mastodon.social
2026-02-20 17:27:02

“Mattermost v11.3.1 contains medium to high severity level security fixes.”
and this is the weekend where I throw this piece of garbage in the bin

@Techmeme@techhub.social
2026-02-27 18:55:53

Court docs from a New Mexico trial reveal internal divisions at Meta as Instagram teen safety initiatives conflicted with growth and engagement goals (The Atlantic)

@fanf@mendeddrum.org
2026-02-24 20:14:35

on my blog!
dotat.at/@/2026-02-24-nsnotify
i have released nsnotifyd-2.4
it has a new feature and some minor bug fixes
the new -S option tells nsnotifyd to send all SOA queries to a specific server
thanks to

@EarthOrgUK@mastodon.energy
2026-03-24 19:51:04

On Website Technicals (2026-03) - Tech updates: EOM, Mastodon share button, bug fixes, low, RSS sadness, routing snafu... - earth.org.uk/note-on-site-tech

@metacurity@infosec.exchange
2026-01-22 14:28:39

Even if you're gearing up for a monster winter storm, take the time to check out today's Metacurity for the most crucial cybersecurity developments you should know, including
--Acting CISA head got grilled on mass firings at the agency,
--EU's CIRCL launches GCVE system,
--DeFi project EVM was exploited for $6m,
--Attackers exploit patch bypass for FortiGate flaw,
--Cisco fixes Unified Communications and Webex Calling RCE flaw,
--Mass spam wave …

@raiders@darktundra.xyz
2026-02-03 17:51:41

The Raiders’ O-line: A 2025 disaster that exposed deeper issues raiderramble.com/2026/02/03/th

@aral@mastodon.ar.al
2026-03-18 19:51:43

🥳 New Kitten¹ Release
• Fixes: Page infinitely refreshes if class does not extend `kitten.Page`
Kitten now shows a helpful error message for this authoring error.
(The issue was due to the page getting rendered without the necessary scaffolding provided by the base class for maintaining the web socket connection,. leading to Kitten thinking the socket connection had failed and triggering a reload to reestablish it.)
Full changelog of today’s updates:

@NFL@darktundra.xyz
2026-03-18 11:34:25

20 contenders, 20 lingering weaknesses: Barnwell fixes roster holes as free agency slows down espn.com/nfl/story/_/id/482276

@metacurity@infosec.exchange
2026-01-21 14:55:21

Don't miss today's packed Metacurity for the most critical infosec developments you need to know, including
--DOGE workers shared SSN data with outsiders, derailed DISA operations,
--UK launches national fraud reporting service,
--China blames Taiwan for cyberattacks,
--EU proposes freezing out Chinese tech suppliers,
--New Zealand launches Manage My Health breach probe,
--Curl ends its bug bounty program due to AI flood,
--Cloudflare fixes WAF…

@aral@mastodon.ar.al
2026-02-19 17:44:11

🥳 @small-web/kitten version 6.2.2 released
This is Kitten’s type library (see kitten.small-web.org/tutorials for a tutorial).
This release fixes a few type errors that crept in in the previous release that were stopping it from being compiled with ts…

@metacurity@infosec.exchange
2026-02-26 12:35:11

After the launch of a UK government vulnerability monitoring service (VMS), serious security weaknesses in public sector websites have been fixed 6 times faster – cutting the average time from nearly 2 months to just over a week.

@raiders@darktundra.xyz
2026-02-16 17:31:47

No more half-measures for the Raiders under Klint Kubiak and John Spytek raiderramble.com/2026/02/16/no

@mgorny@social.treehouse.systems
2026-03-19 12:23:26

Proper #security nightmare time.
#LMDB is a database that's designed to operate on trusted input. Upstream has historically rejected all bug reports regarding problems with malformed input.
Py-LMDB project provides #Python bindings to LMDB that are normally built against bundled LMDB. Someone recently started mass-filing "untrusted input" vulnerabilities against py-lmdb, and py-lmdb started #slop - coding fixes to their bundled LMDB. Of course, nobody even bothered reporting most of these bugs upstream, and the one that I've seen reported was rejected as "don't do that".
Py-LMDB supports building against system LMDB, and #Gentoo was doing that so far. However, now we are facing a problem: system LMDB operates under the assumption that it is working on trusted input, while py-lmdb (and its bundled LMDB) operates under the assumption that it may be working with untrusted input. The guarantees no longer align.
If we continue to use system LMDB (and skip all the added slop tests that literally cause Python to crash), then Gentoo's py-lmdb package will now have different input expectations than upstream py-lmdb. And of course we can't just remove that crap because someone added exactly one package (TorchVision, i.e. part of the plagiarism machine suite) depending on it.
bugs.gentoo.org/971352