This is just one example. "MCP" the protocol for "AI agents" is basically without security measures. It's like running random code on your infrastructure and data.
(Original title: GitHub MCP Exploited: Accessing private repositories via MCP)
https://simonwillison.net…
Analytics company founder: Hosters demands over server costs are unworkable
„The hosting platforms will just have to give us servers for free“ Daniel said in an interview, while wearing a onesie Pyjama in the form of an octopus. https://mastodon.social/@jensscholz/114573315…
Bilan de "poc-sveltekit-custom-server" pour exécuter des tâches "cron" dans un projet Monolith en SvelteKit :
#Sveltekit
Chaplin but not Keaton, Hitler but not Mussolini, Schreiber but not Burns, and surprisingly my grandmother but not my grandfather.
If anyone is playing Remedy's new game "FBC: Firebreak", and you're not in the official Discord server for it, come join us! We chat, form groups with voice comms (there's a bot thing so you can create 3-person temporary channels), we have lore discussion etc.
https://discord.gg/Control…
Man könnte ja denken das diese ganze Agent/MCP Geschichte grad doch sehr fast and loose abläuft ....
https://simonwillison.net/2025/May/26/github-mcp-exploited/
from my link log —
A language server protocol (LSP) implementation for PostgreSQL.
https://github.com/supabase-community/postgres-language-server
saved 2025-03-29
I am once again getting a wave of right-wing spam SMSes from Hillsdale College (purportedly). Are they actually letting their institution’s name be attached to political spam? I realize there are all kinds of super gross things about Hillsdale as an institution, but even so, I’d think the institution would want to preserve some shred of self-respect, or at least try to keep up appearances.
The spam links are all the domain rght.io followed by 6-character alphanumeric codes, such as:
http://rght.io/jjne75
http://rght.io/ip0l3b
http://rght.io/646anh
http://rght.io/aem0ai
http://rght.io/8gplnp
http://rght.io/mncl8i
http://rght.io/eo556l
http://rght.io/15bk46
http://rght.io/igd8ga
http://rght.io/pp2ggf
(Those are random examples, I don’t want them validating my number; I just want to send the typical Fedi server traffic their way.)
I haven’t investigated the domain, server, etc. at all, but if anyone is inspired…have at it!
Es ist nun wieder Ende des Monats und das heißt neue Rechnungen für die Server! Wir haben diverse Ausgaben und Moderationsarbeit nimmt leider viel Zeit, weswegen wir uns über eine kleine Unterstützung sehr freuen würden! :boost_requested:
:liberapay: LiberaPay
:paypal:
You can play with (a supercharged server-driven version of it) today with Kitten:
https://kitten.small-web.org/tutorials/dynamic-pages/