@hipsterelectron @arichtman "untrusted" is a good weasel word to describe "code that you wouldn't choose to run if they gave you a choice"
@emily_s @arichtman it's used by google and microsoft to describe "code we haven't backdoored yet"
Discussion
@hipsterelectron @arichtman "untrusted" is a good weasel word to describe "code that you wouldn't choose to run if they gave you a choice"
@emily_s @arichtman it's used by google and microsoft to describe "code we haven't backdoored yet"
We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.
It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.
Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
If you run Hollo, update to a current patched release now. Fedify has disclosed two vulnerabilities, one of which affects Hollo: CVE-2026-77632, a high-severity server-side request forgery vulnerability in Fedify's authenticated document loader.
Hollo relies on the authenticated document loader when it fetches remote documents such as actors and public keys with a signed HTTP request. Affected Fedify versions checked that the initial URL resolved to a public network destination, but did not apply the same check when that URL returned an HTTP redirect. An attacker who controlled the public URL could therefore redirect the signed request to a loopback address, a link-local cloud metadata service, or an RFC 1918 private address.
An unauthenticated attacker could reach this path by sending an inbox request with a signature whose keyId points to an attacker-controlled public URL. Fedify has to fetch the key before it can verify the signature, so even a bogus signature is enough to trigger the request. The demonstrated attack is blind SSRF: the internal response is consumed while resolving the remote document and is not automatically returned to the attacker.
The fix validates every redirect target before fetching it. Hollo's existing ALLOW_PRIVATE_ADDRESS option still permits private destinations when an operator explicitly opts in, such as for a closed federation or test environment.
The other disclosed vulnerability, CVE-2026-69132, concerns unbounded circuit-breaker state in Fedify 2.3.0 through 2.3.4. Hollo's supported 0.8.x and 0.9.x release lines use Fedify 2.1.x and 2.2.x respectively, so this issue does not affect them.
For full technical details, see the Fedify security advisories for CVE-2026-77632 and CVE-2026-69132, and the Fedify security announcement.
All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.9 and 0.9.12 are affected by CVE-2026-77632. The fix first appeared in 0.8.10 for the 0.8.x series and 0.9.13 for the 0.9.x series. The current releases are 0.8.11 and 0.9.14, and those are the versions we recommend installing.
Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version.
For 0.8.x deployments, update to 0.8.11:
docker pull ghcr.io/fedify-dev/hollo:0.8.11For 0.9.x deployments, update to 0.9.14:
docker pull ghcr.io/fedify-dev/hollo:0.9.14After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart.
Thanks to Jace for reporting CVE-2026-77632 and to @nyanrus for reporting CVE-2026-69132, and for their responsible disclosure to the Fedify project.
If anything is unclear, ask below.
Die oberen 10000: "Der Beklagte habe zwar die Berechnung seiner damaligen Ehefrau im Scheidungsverfahren, die den Daytona 1 mit 600.000 € beim Zugewinnausgleich berücksichtigt hatte, bestritten und dort ausgeführt, nicht Eigentümer zu sein. Dies sei ersichtlich jedoch im Kontext des Zugewinnausgleichsverfahrens erfolgt."
RE: https://hessen.social/@Oberlandesgericht_FfM/117160922244946691
"hier Ferrari Daytona"
An amazing read on an amazing woman: the first woman marine engineer in the UK, and the first woman member of the Institute of Marine Engineers.
On 25 Aug 1940 Victoria Drummond was the engineer on watch on the ship Bonita in N Atlantic when the Luftwaffe attacked. Remaining alone & injured at post she managed to get up to 12.5 knots, avoiding being hit whenever bombed in an attack lasting 30+ minutes.
After being repeatedly failed in examination for Chief Engineer (gallantly, the examiners also failed the men who scored lower than her, ie virtually everybody), Drummond finally passed when she realised Panama accepted examination by post, an error greatly reducing the chance of anybody noticing her gender ...
@hipsterelectron @arichtman "untrusted" is a good weasel word to describe "code that you wouldn't choose to run if they gave you a choice"
@elena they're funding specifically eugen rochko and team to mess with our protocols, i'm not concerned about the server
@hipsterelectron @elena lol what are you talking about? Even if there is EU founding in play, the little money isn't enough to make them compromise their standards. Actually I think all money that goes into building an open and truly decentralized web is a good investment even if it would come from Donald Trump.
picked up my home made honey today that I got in return for a few months of the sizzle - lovely guy and the honey is very tasty
also if anyone wants to barter for a sizzle subscription (https://thesizzle.com.au), I am totally up for that
Die Digitalisierung macht uns zu Sklavenarbeitern der Netzkonzerne – Statt Zeit zu sparen, bürdet uns die Digitalisierung immer mehr Arbeit auf. Wir geben Adressen ein, folgen App-Anleitungen und erledigen Aufgaben, die früher Dienstleister übernahmen. Ein Gastbeitrag.
https://www.fr.de/meinung/gastbeitraege/digitalisierung-macht-uns-zu-sklavenarbeitern-der-netzkonzerne-94460547.html
RE: https://mastodon.social/@YazanIbnGaza/117161529360268801
This has to be a very serious issue. No matter what happens in the coming storm, how many of these sun-perished tents will survive the winter?
They aren't designed to be permanent habitation. They're designed to house people for a few months, through an emergency. The materials of which they're made deteriorate in ultra-violet light.
Many people in #Gaza will need to be rehoused this winter. There will be many deaths from lack of shelter.
As ever, please give if you can.
-Russia starts blocking DoH and DoT
-NoName057 leaks data on Spanish police and military
-China orders govt agencies to ditch Windows 10
-China and South Korea detain vishing gang
-AI malware is not that common
-Hackers target high-ranking EU officials
-ReliaQuest denies ShinyHunters hack
-DDoS attack targets Norway's government
-Autism Services of Saskatoon hit by ransomware
-Nutex Health data breach
N: https://news.risky.biz/risky-bulletin-russia-starts-blocking-doh-and-dot/
P: https://risky.biz/RBNEWS605/
X contraint Nitter et XCancel à suspendre leur service alternatif - https://next.ink/brief-article/x-contraint-nitter-et-xcancel-a-suspendre-leur-service-alternatif/
Ça m'a toujours fait rigoler Nitter. C'est un truc foireux qui répond aux besoins de Twitter de gens qui n'arrivent pas à s'en passer. Autant dire que sa disparition me fait lâcher un gros osef.
Allez vous servir de Twitter, assumez.
@dada
Sauf que certain service n'utilisent que Twitter pour communiquer.
Genre des lignes de transport en commun, des communes
-CERT-FR tells Apple spyware victims to reach out
-Supply chain attacks exploded this year
-New stealthy SLEEPWALKER backdoor
-New PhaaS platforms: AnonyMousKIT and ZeroTokens
-WeedHack stealer returns
-ERMAC to HookBot evolution
-WordPress security team force-pushes a plugin security update
-Oracle bug enters exploitation
-BRIDGEHEAD campaign hits npm
-Minimus security firm shuts down
-New WinFlesher and Fortitool tools
POKEMON WORLDS THIS WEEKEND!!!!!!!!!
RE: https://mamot.fr/@pluralistic/117159662819871806
This is a really good article.
I very recently tried to record some tutorials that I had _subscribed_ to (tutorials on how to play a musical instrument). I wanted to purchase the tutorials outright so I could use them to practice over and over, but the company requires a continual monthly subscription - even to watch the same video over and over.
I figured I have video and audio on my Linux computer.
It should be easy to capture that video and audio.
Well, it's not. Screen capture without audio is easy, but audio capture is not intuitive up front. There are some methods to use the program FFmgep to capture some audio/visual by pulling a video link from the source code of the streaming service, but this service used a codec that actively prevents that. (edit: read - uses some heavy DRM)
I tried to find a decent program to just screenrecord audio and visual as it played on my monitor, but I didn't have much success.
I need to try again.
Otherwise I'll be paying a monthly fee to play the same handful of videos over and over and over again.
And that's silly.
(Edit to add: Absolutely please please please suggest methods to do this in the replies! This is a call for help and all replies and suggestions are requested and consented to! Hahaha!)
@Yaku è che la roba nei luoghi di vacanza costa molto di più.
@Madmonkey
Vero, ho provato a comprare un missile balistico a Porto Cervo, ma santo cielo che prezzi!
@x io credo che sia giusto fare i complimenti, tu invece fai un po' come cazzo te pare, ma lontano da me
@vruz @cyrilwinstanley if Isak doesn't sky an undefended, wide open chance gifted from Gakpo in the box... how different is the conversation? If the keeper doesn't make a brilliant save on Wirtz's low drive to the far post?
The performance was still uneven, but the narrative completely different.
I've long said a 6 is needed and we keep missing on signing them and then declaring that all of our 8s and 10s can play as 6s. Iraola saying we don't need a 6 was eye-opening and I'm eager to see why.
Five minutes Mike.
Sorry, the app encountered an unexpected error