Salta al contenuto principale



in reply to 🇪🇺 Herr Vorragend 🌻

Das Bild zeigt eine Person auf einem Pferd, die eine amerikanische Flagge hochhält. Die Person trägt einen Cowboyhut und eine dunkle Kleidung. Der Hintergrund ist in Schwarz-Weiß gehalten und zeigt eine Berglandschaft mit einem Fluss. Die Flagge ist in Farbe dargestellt und weht im Wind. Der Text im Bild lautet: "They said strength meant more spending. We say strength is standing tall on principle. Balanced budgets. Strong borders. Unshakable resolve. The America Party rides for the future — not the debt." Es folgen die Hashtags #AmericaParty, #cowboy, #unitedstates, #elonmusk, #leadership, #confidence, #forward.

Bereitgestellt von @altbot, privat und lokal generiert mit Ovis2-8B

🌱 Energieverbrauch: 0.193 Wh


in reply to DutchKing

Das Bild zeigt eine detaillierte Ansicht der unteren Teile eines Dampflokomotivs. Im Vordergrund ist ein großer, schwarzer Lokomotivrad mit einem sichtbaren Zahnrad zu sehen. Dampf steigt aus dem Rad und der Umgebung auf, was auf die aktive Funktion des Dampflokoms hinweist. Auf der Oberseite des Lokomotivs ist die Nummer "705" in goldenen Ziffern sichtbar, zusammen mit der roten Nummer "1081" und dem Text "PV 74". Ein kastanienbraunes Rohr führt von der Lokomotive weg, vermutlich zur Abführung von Dampf. Der Boden ist feucht und hat eine gelbe Linie, die möglicherweise als Sicherheitslinie dient. Die Lichtverhältnisse und die Dampfentwicklung vermitteln ein Gefühl von Bewegung und Kraft.

Bereitgestellt von @altbot, privat und lokal generiert mit Ovis2-8B

🌱 Energieverbrauch: 0.239 Wh




Imparare dagli errori: il caldo, la siccità e i possibili incendi

@lavoro
puntosicuro.it/imparare-dagli-…
Esempi di incendi correlati alle conseguenze dei prolungati periodi di siccità. Focus su un documento sugli stabilimenti a pericolo di incidente rilevante e sui possibili incendi di vegetazione esterni agli stabilimenti.



A bunch of Trump appointees, like Commerce Secretary Howard Lutnick, the multibillionaire, stand to benefit financially if weather forecasts are privatized. People who can’t afford weather forecasts are going to die.

apnews.com/article/trump-lutni…



Exploit RCE 0day per WinRAR e WinZIP in vendita su exploit.in per email di phishing da urlo


In questi giorni, sul noto forum underground exploit.in, attualmente chiuso e accessibile solo su invito – sono stati messi in vendita degli exploit per una vulnerabilità di tipo 0day che colpiscono i noti software WinRAR e WinZIP. L’annuncio, pubblicato dall’utente zeroplayer, propone tali exploit tra 80.000 e 100.000 dollari.

Specifica che non si tratta di un semplice 1day (cioè un exploit per una vulnerabilità già nota come CVE-2025-6218), ma di un bug sconosciuto e non ancora patchato.

Cosa sono gli exploit e cosa significa “0day”


Gli exploit sono strumenti o porzioni di codice che permettono di sfruttare vulnerabilità software per ottenere comportamenti non previsti dal programma, come l’esecuzione di codice malevolo, il furto di dati o il controllo completo di un sistema.

Quando parliamo di 0day, intendiamo vulnerabilità che non sono ancora conosciute dal produttore del software e per le quali non esistono patch: proprio per questo motivo sono particolarmente preziose nel mercato nero e incredibilmente pericolose.

Perché i bug su software come WinRAR o ZIP sono così critici


WinZIP e WinRAR sono i software più utilizzati al mondo per la gestione di archivi compressi come file ZIP e RAR. Una vulnerabilità RCE (Remote Code Execution) su questo tipo di programma permette a un attaccante di far eseguire codice malevolo semplicemente inducendo la vittima ad aprire o visualizzare un archivio compromesso.

Un possibile scenario d’attacco prevede l’uso di email di phishing, in cui l’utente riceve un allegato ZIP o RAR apparentemente innocuo. Basta un clic per attivare l’exploit e compromettere completamente il sistema, installando malware, ransomware o backdoor per il controllo remoto.

Il ruolo dei forum underground come exploit.in


Forum chiusi come exploit.in fungono da veri e propri marketplace per la compravendita di vulnerabilità, malware, dati rubati e altri strumenti usati nel cybercrime. Gli utenti che vendono exploit, come nel caso di zeroplayer, spesso offrono garanzie di affidabilità attraverso servizi interni chiamati Garant, che fanno da intermediari per evitare truffe tra criminali.

L’utente zeroplayer, che ha pubblicato gli annunci, appare come un profilo nuovo e ancora privo di una reputazione consolidata. Registrato sul forum exploit.in solo il 30 giugno 2025, conta appena 3 post e non ha ancora concluso transazioni certificate tramite il sistema di Garant interno alla piattaforma, che solitamente serve a ridurre il rischio di truffe tra venditori e acquirenti.

Sebbene abbia effettuato una registrazione a pagamento, pratica comune nei forum underground più chiusi per filtrare account fake e inattivi, questo elemento da solo non basta a definirlo affidabile agli occhi della community. Un account così recente potrebbe indicare due scenari contrapposti: da un lato, un vendor realmente in possesso di un exploit molto prezioso che sceglie di aprire un nuovo profilo per motivi di anonimato; dall’altro, un tentativo di frode per monetizzare la paura attorno a una vulnerabilità critica e ancora sconosciuta. La mancanza di feedback e attività passata rende difficile distinguere tra le due possibilità, ma sottolinea quanto sia complesso — perfino nei circuiti del cybercrime — fidarsi senza prove concrete dell’esistenza e dell’efficacia dell’exploit offerto.

La vendita di un exploit 0day per WinRAR rappresenta una seria minaccia, vista la diffusione globale del software. È un ulteriore richiamo all’importanza di mantenere i programmi sempre aggiornati, usare strumenti di sicurezza affidabili e prestare la massima attenzione alle email sospette, soprattutto se contengono allegati compressi.

L'articolo Exploit RCE 0day per WinRAR e WinZIP in vendita su exploit.in per email di phishing da urlo proviene da il blog della sicurezza informatica.



#pastpuzzle 72
🟩🟩🟥🟥 (-42)
🟩🟩🟥🟥 (+13)
🟩🟩🟩🟥 (-1)
🟩🟩🟩🟥 (-5)

x/4 🟥
pastpuzzle.de



Socialists back von der Leyen in return for pledge on social budget
https://www.euronews.com/my-europe/2025/07/10/socialists-back-von-der-leyen-in-return-for-pledge-on-social-budget?utm_source=flipboard&utm_medium=activitypub

Posted into Europe News @europe-news-euronews




russia's summer push in #Ukraine targets three fronts but faces stern resistance

by Abdujalil Abdurasulov, BBC News in Kyiv, BBC Visual Journalism Team

"its advance remains relatively slow. At this pace it would take more than 70 years to capture the entire country."

bbc.com/news/articles/c70rl6lk…



Scriptorium si distingue come un progetto elegante e funzionale, pensato per chi lavora con documenti strutturati e desidera un ambiente flessibile per manipolarli, analizzarli e pubblicarli. #Linux #UnoLinux

linuxeasy.org/scriptorium-stru…




Wrench , Gracias por mi nueva intro.
youtube.com/watch?v=Pto5eYNLhd…


Dall’ultima apparizione in M3GAN 2.0 fino a Barbie, la bambola al cinema ha cambiato volto e significato. Qual è il filo che lega queste rappresentazioni così diverse? Un viaggio nella storia di un’ic...

👇👇👇
hynerd.it/m3gan-2-0-barbie-evo…



Merz riconosce nuove tensioni con la Francia sul progetto del caccia FCAS euractiv.it/section/capitali/n…


L’Ucraina si prepara a un’estate “difficile” mentre l’aiuto occidentale vacilla euractiv.it/section/capitali/n…


Domestic racially motivated violent extremism perpetrated by violent white supremacists is the foremost terror threat in the United States, and the disparity is significant.

The glorification violence and its acceptance have fostered an elitist-driven rage.

judiciary.senate.gov/imo/media…

dhs.gov/archive/news/2009/04/1…

#nokings #resist #usa #europeanunion #Canada #nato #eu









Good job AI. Yes, that is clearly what I wanted. Feel free to take over the world with your genius.


Linda Yaccarino lascia la guida di X dopo due anni di trasformazione aziendale. La sua uscita coincide con lo scandalo del chatbot Grok, mentre Musk punta sull'integrazione con l'IA. #SocialMedia #ElonMusk #TwitterNews


Millionen Monsterfliegen im Jet: Die #USA importieren sterilisiertes „Ungeziefer“ aus #Panama – um eine fleischfressende #Fliege zu bekämpfen, die eine tödliche #Rinderseuche auslöst. Sandra Weiss mit den Hintergründen zu dieser besonderen Methode: riffreporter.de/de/internation…
in reply to RiffReporter

@RiffReporter

So hat man doch schon in den 1980ern in Italien Moskitos bekämpft... und die Methode dchrint zum Eindämmen nicht ungeeignet...



💸 Politieke partijen gaven in 2024 ruim 61 miljoen euro uit aan verkiezingspropaganda: meer dan 70% van de subsidies die ze ontvangen. In Vlaanderen staan Vlaams Belang en N-VA op eenzame hoogte: samen gaven ze vorig jaar 16,5 miljoen euro uit aan verkiezingspropaganda.
apache.be/2025/07/09/partijsub…


State of the Bird June 2025


State of the Bird June 2025


The State of the Bird is a recap of what has been happening in the project.

We used to do these quarterly as an interactive live stream, but we're nowdoing these as a monthly posts instead.

You can find the playlist with all of the old videos on YouTube.

Retrospective


Our last State of the Bird was June 9th 2025 and can be found here.

Like last month, things have been a bit slower due to summer but because of some other stuff we'll get into shortly.

Metrics


We have a number of metrics we keep an eye on which you can see below.

Contibutors


Our number of contributors continues to average around 3 per month and we are still seeing some casual contributors popping up from time to time.

[chart type="bar" backgroundColors="#db3a83,#e76a2a,#4cdc8b" title="Contibutors" xAxisTitle="Time Frame" ]2025-01 | 2025-02 | 2025-03 | 2025-04 | 2025-05 | 2025-06Developers | 2 | 2 | 1 | 2 | 2 | 2Crazy Patch Writers | 0 | 1 | 1 | 0 | 1 | 0Casual | 1 | 0 | 0 | 0 | 1 | 1[/chart]

Review Requests


Review requests are what we call our code reviews and this is a look at how many were open and closed each month.

[chart type="bar" backgroundColors="#db3a83,#e76a2a" title="Review Requests" xAxisTitle="Time Frame" ]2025-01 | 2025-02 | 2025-03 | 2025-04 | 2025-05 | 2025-06Open | 92 | 72 | 78 | 44 | 26 | 20Closed | 88 | 72 | 82 | 43 | 22 | 25[/chart]

Issues


This is a look at the number of issues that were opened in our issue tracker as well as how many were closed by month.

[chart type="bar" backgroundColors="#db3a83,#e76a2a" title="Issues" xAxisTitle="Time Frame" ]2025-01 | 2025-02 | 2025-03 | 2025-04 | 2025-05 | 2025-06Open | 44 | 30 | 41 | 16 | 6 | 11Closed | 34 | 18 | 18 | 6 | 5 | 10[/chart]

Commits


This is a break down of commits to each project per month. In most cases a review request is just a single commit, but this chart helps to see what projects are being worked on.

[chart type="bar" backgroundColors="#ed207b,#9eb83b,#0088cc,#b3b5b4,#8c6238,#231f20,#f1592a,#ffea61,#bf1e2e,#0088cc,#57e389,#7f007f" title="Commits" xAxisTitle="Time Frame" ]2025-01 | 2025-02 | 2025-03 | 2025-04 | 2025-05 | 2025-06Pidgin 3 | 46 | 22 | 27 | 28 | 15 | 10 |Pidgin 2 | 8 | 0 | 0 | 0 | 0 | 4 |GPlugin | 0 | 1 | 1 | 0 | 2 | 0 |HASL | 10 | 5 | 1 | 0 | 1 | 4 |Birb | 12 | 1 | 6 | 0 | 5 | 0 |Xeme | 2 | 5 | 7 | 0 | 0 | 0 |Ibis | 16 | 10 | 27 | 11 | 0 | 0 |Hiya | 0 | 0 | 15 | 2 | 0 | 0 |Myna | 0 | 0 | 0 | 0 | 0 | 0 |Seagull | 0 | 23 | 8 | 0 | 0 | 13 |Traversity | 0 | 8 | 0 | 0 | 0 | 0 |retro-purple | 0 | 0 | 0 | 0 | 38 | 48 |[/chart]

Infrastructure


  • We've federated our Discourse server so all news and releases will automatically get posted via Activity Pub! Announcement


Pidgin 3
Retrospective


Not a whole lot happened with Pidgin 3 this month as we had our focus on other projects.

Updates


  • Disabled the SIP protocol plugin by default as we determine how to proceed.
  • Removed the old versioned API from the IRCv3 protocol.
  • Removed some unused purple_markup API.
  • Updated the flatpak to GNOME 48.


Releases


We did originally rlease 2.92.0 but I noticed immediately when I went to update the flatpak that I forgot to update the version in the metadata file so we had to cut 2.92.1 right away to address that.

Future Plans


  • Finish up the conversation persistence that we were trying to get into Experimental 3.
  • Determine how to proceed with the SIP protocol plugin. We're probably going to create yet another library to handle it.
  • After conversation persistence is done, we need to add persistence to the contact list as well.
  • Get Hiya to a usable state.

As always, you can view the burn down chart here.

Pidgin 2


We have decided that we're going to do a 2.15.0 release. The decision and announcement can be found here.

Retrospective


  • Added support to display protocols, loaders, and other "hidden" plugins in the plugins list but made them not unloadable.
  • Fixed log viewing for protocols that are no longer loadable.
  • Removed the "retro" protocols plugins. The ones that still existed have been moved to the new retro-prpl project.


Releases


None yet, we're trying to finalize some things before releasing 2.15.0.

Future Plans


We're still working on updating the versions of GLib and GTK for the windows build as well as creating an official pre-built development bundle/SDK.

GPlugin


GPlugin is our GObject based plugin library that is used in Pidgin 3.

Retrospective


No notable changes

Releases


None

Future Plans


GPlugin is pretty stable at the moment but there's quite a lot of maintenance stuff to get too, but it's not as high of a priority as the other stuff at the moment.

HASL


HASL is the Hassle-free Authentication and Security Layer library. It implements SASL in a modern and easy use way compared to the existing libraries.

Retrospective


  • We fixed our error domains which were not implemented in a way that would work in language bindings.


Releases


None

Future Plans


We have been in the progress of implementing the SCRAM Mechanisms which will be included in the next release.

Birb


Birb is a library of GLib utilities that we use across all of our projects.

Retrospective


No notable changes

Releases


None

Xeme


Xeme is our XMPP integration library. It is the basis for both the Link Local Messaging (Bonjour) and XMPP protocols in Pidgin 3. It is still early in development and has not yet had a release.

Ibis


Ibis is our IRCv3 integration library. It has seen a lot of active development as it is used in the IRCv3 protocol plugin in Pidgin 3.

We are nearing known feature completion on it and expect to do a 1.0 release in the near future.

Retrospective


No notable changes

Releases


None

Future Plans


Continue working through the open issues and watching new IRCv3 specifications for things we should be including.

Hiya


Hiya is a new client abstraction library for mDNS. It was created to help make implementation of the Link Local Messaging protocol easier as we would have to abstract out the different platform implementations and by putting it in a library that abstraction can be used by other projects.

Hiya has not yet had a release.

Myna


Myna is a new integration library for Matrix. It is still extremely early in development.

Seagull


Seagull is a new library we created to make working with SQLite feel more like a GLIB/GNOME library and force usage of prepared statements with named parameters and other similar things.

Retrospective


  • Added aliases for columns.
  • Added support for binding objects.
  • Added support for retrieving columns from objects.
  • Added support for creating statements from resources.
  • Added API for date times, enums, and flags.
  • Fixed a bug were non prefixed parameters would match even though a prefix was specified.


Releases



Future Plans


We have a few features to fill out yet and a few ideas that need a bit more time in the oven.

More specific details can be found in our open issues.

Traversity


Traversity is a new library for traversing NATs. There are many different ways to traverse a NAT and the goal of Traversity is to hide that from developers who just need to traverse a NAT.

It is still early in development and has not yet had an official release.

retro-prpl


retro-prpl is a new repository we've created on GitHub. This repository contains all of the abandoned protocols that have ever lived in our code base and is meant to make them easier to study and for people to use with services like Retro AIM Server and NINA.

Retrospective


We've wrapped up just about all the development here and are just waiting for Pidgin 2.15.0 before releasing.

Releases


None

Future Plans


Right now we didn't add any support for protocol specific emojis because we completely forgot about them. Anyways we're looking at creating a custom emoji theme that will include everything for these retro protocols.

Closing


We hope you all are enjoying the new format and if you have any questions of comments please leave them below!

Discuss this on our forum.



Mijn diploma gehaald aan #TallandCollege , voor de opleiding #technicushoutenrestauratie , oftewel, #restauratietimmerman , zoals ik het liever noem.

Wat een leuke, mooie, gave #opleiding is dit! Heb je een zoon of dochter die iets supertofs wil leren, maar niet perse met z'n neus in de boeken wil zitten, maar ze wel goed op en rijtje heeft, dan is deze opleiding misschien wel iets.

Dit is gewoon hogeschool timmeren! Dank aan alle leraren!

#zaandam #houtbewerken #vakopleiding #mbo



ウルトラめん


#Ultaman #Ultraman Day

今日は「ウルトラマンの日」です。



Ho scattato tre pessime foto del Villaggio Arcade. Ho dovuto sforzarmi per scattarle con l'intenzione di pubblicarle qua altrimenti. Sforzato nel senso che, nonostante ci sono stato mezza giornata, è stato superdivertente e interessante e ho conosciuta nuova gente con cui parlare attivamente di puzzle game su playstation.
E' una di quelle situazioni in cui arrivi e non sai cosa aspettarti e succede anche l'inaspettabile e ritrovi persone conosciute in altre situazioni vagamente simili.
in reply to Gecco

Tra l'altro ho scoperto che ancora esiste un mercato di videogiochi piratati (su floppy) per Amiga 500.
Inoltre ho scambiato un alimentatore per Amiga (che avevo a casa inutilizzato) per un joystick Albatros (io ho un Amiga 500 ma mi mancava il joystick).
Abbiamo mangiato tutti insieme la pizza cotta al forno, c'è stato un workshop di lotta e tiravano con gli archi.
Poi dopo cena ho detto ad alta voce "Adesso finisco Metal Slug con un gettone" (poi ovviamente non l'ho fatto)


Albertini vota Vlahovic: "Non si discute, lo prenderei a occhi chiusi"
https://www.gazzetta.it/Calcio/Calciomercato/Milan/10-07-2025/albertini-vlahovic-non-si-discute-lo-prenderei-a-occhi-chiusi_preview.shtml?reason=unauthenticated&utm_source=flipboard&utm_medium=activitypub

Pubblicato su Calcio @calcio-Gazzetta



L'euro è in lieve aumento sul dollaro a quota 1,1739 - Ultima ora - Ansa.it
https://www.ansa.it/sito/notizie/topnews/2025/07/10/leuro-e-in-lieve-aumento-sul-dollaro-a-quota-11739_aa68183c-fe12-48c4-b4eb-1fcb6554c671.html?utm_source=flipboard&utm_medium=activitypub

Pubblicato su ANSA Ultima ora @ansa-ultima-ora-AgenziaAnsa




Vacheron Constantin racconta lo zodiaco... a modo suo
https://www.esquire.com/it/stile/accessori-uomo/a65350170/vacheron-constantin-zodiaco/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Stile @stile-Esquireitalia2



Le intelligenze aliene potrebbero esistere: secondo gli scienziati alcuni pianeti favorirebbero un'evoluzione più rapida
https://www.esquire.com/it/lifestyle/scienza/a65031386/intelligenze-aliene/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Lifestyle @lifestyle-Esquireitalia2



Fellowship opportunity coming up! 📢

For a fifth time, #AlgorithmWatch is looking for new Algorithmic Accountability Reporting fellows. Apply now if you have research ideas concerning the relation between Artificial Intelligence and power and its consequences.

Application deadline: 15 September 2025 23:59 CET

👉 algorithmwatch.org/en/open-cal…

reshared this



Understanding the Ethernet II 802.3 Frame and VLAN tagging
youtube.com/watch?v=P-OvBLCNa2…


What? Wow!

Eine im renommierten Fachjournal @PNASNews erschienene Studie zeigt, dass jeder Kilometer neuer #Radweg im Schnitt für mehr als 13.000 Kilometer mehr Radfahrten pro Jahr sorgt. 🤯

Hinzu kommt, dass durch mehr aktive Mobilität jährlich Milliarden Gesundheitskosten gespart werden könnten.

Im #Deutschlandfunk wurden die Ergebnisse aufbereitet: deutschlandfunknova.de/nachric…

#Fahrrad #MdRzA @mastobikes_de #BikeTooter #fahrradalltag

reshared this