Lorenzo ha ricondiviso questo.

We just released Mastodon 4.6.4, 4.5.14 and 4.4.21.

Those updates include multiple security fixes, including fixes for two major issues.

We encourage server administrators to update as soon as possible, as one of the issues can expose PII of local users. We are investigating potential uses of this exploit and will soon share more information.

Full release notes and update instructions are available on the GitHub release page.

github.com/mastodon/mastodon/r…

#MastoAdmin

Questa voce è stata modificata (1 mese fa)
Lorenzo ha ricondiviso questo.

Today, we made a difficult decision to lay off 7% of our AI agents
Lorenzo ha ricondiviso questo.

HuggingFace incident report:

huggingface.co/blog/agent-intr…

The report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s 😀 Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like a URL?).

I feel sorry for blue teams not because they'll have to respond to more incidents but because they'll have to wade through reports like this...

Questa voce è stata modificata (1 mese fa)

reshared this

Lorenzo ha ricondiviso questo.

🎙️ Risky Business #846 -- OpenAI built a fireplace out of wood

risky.biz/RB846/

#846

reshared this

Lorenzo ha ricondiviso questo.

"My annoyance with the Fediverse is all the scammers.". The constant requests for money "from Gaza" and the doubts of @NetscapeNavigator@vivaldi.net


@fediverse

Warning: A few hours after this post, the user NetscapeNavigator was suspended from the Vivaldi instance

I've been vilely attacked in the past, with reports and private messages, simply for writing this

We don't deserve to be bombarded by thousands of tragic requests for help that we can't directly verify and that prey on our pity, or worse, our guilt.
Sending private messages is harassment. Sending private messages asking for money is even more odious, because we know that sooner or later, someone vulnerable will donate.


A mastostar, a guy with 47,000 followers who passes for a prominent figure in the Fediverse, told me I'm "just a hugely privileged twat throwing his toys out of the pram because he is being forced to see things he’d rather ignore" and that perhaps I lack a moral compass.

I imagine if I've been subjected to harassment for saying something trivial, poor @NetscapeNavigator@vivaldi.net will be subjected to harassment, stalking, doxxing, and multiple reports to force him to close his account.

But what did Netscape write?

Here's his message before it was deleted:

My annoyance with the Fediverse is all the scammers.
I do not suspect they're scammers — I know they're scammers, because they're using the same photos as the next person. I also have the unique perspective from my job where I deal with this sort of thing professionally (I work for Meta/Facebook).
Some of them are not just staged or stock photos, but even A.I. photos too. Honestly, I always get a small laugh when I see the old photo re-shared with 6 fingers. The stupid scammers are so low-effort here that I doubt they noticed, and I doubt they care. Like all scammers, they want your money quick and easy. Which is why they often re-share the same photos and videos among themselves.
They use both a repeated heart-bleeding story to tug at people's sympathy, but the reason why they repeat themselves is volume. They're not so much trying to convince people as they are hoping to flood timelines so someone who is more gullible and who wears their heart on their sleeve will act and give them money.
It is the same marketing tactic corporations use. You see an ad repeated for a soda, and become thirsty, and if you happen to buy their soda, all the better. Just as the scammers repeat their heartfelt story over and over, and you feel sorry, and if you happen to pay them, all the better.
If there is substance, it always circles back to the scam.
A normal person may post a photo of their home and ask for tips on decorating or point out how cool the new couch looks in their living room. The scammer will point out the couch and claim it's too bad they have to sell it or no longer have it, but it would be better if you gave them money.
A normal person may post a photo of their spouse and children, talking about how proud they are of them or how lucky they feel to have them in their life. The scammer will claim they love their spouse and kids, but it would be better if they had your money.
Everything circles back to needing your money. Everything reinforces the scam.

You're unlikely to see content that does not circle back to wanting and needing your money.


An assessment of the accusation and the critical issues surrounding the #GazaVerified project


Objectively, @NetscapeNavigator@vivaldi.net's accusation is not supported by evidence. I'd love to see a dossier from Netscape or a post from @iftas, or even better, a journalistic investigation, but nothing of the sort currently exists.

But what is the verification method for "GazaVerified"? Here it is:

What does the verification process look like?
It’s very simple: we have a quick video chat to verify that you are a Palestinian from Gaza and the same person you say you are on your Mastodon account, after which we add you to Gaza Verified.


A damn video call? Is this the verification method for a fundraising system that moves hundreds of thousands of euros? In an environment heavily influenced by a terrorist organization like Hamas? And so with the risk that donors could be accused of financing a terrorist organization? And with another terrorist organization (the Israeli government) eager to infiltrate the donation request system?

It seems to me like the perfect recipe for creating a gigantic explosive backpack to blow yourself up inside four reinforced concrete walls...

infosec.exchange/@NetscapeNavi…


the problem is that you're a pain in the ass asking for money here in the Fediverse!
This is a nonprofit organization based on volunteers, and for many, it's a safe haven from the terrible things happening in the world.

We don't deserve to be bombarded by thousands of tragic requests for help that we can't directly verify and that prey on our pity, or worse, our guilt.
Sending private messages is harassment. Sending private messages asking for money is even more odious, because we know that sooner or later, someone vulnerable will donate.
Here in the Fediverse, we have a duty to defend our users' "right to levity," we have a duty to help each other prevent the Fediverse from turning into a street full of beggars, and we have a duty to report to our administrators anyone who contacts us privately asking for money.

@fabio @aral


Questa voce è stata modificata (4 settimane fa)

reshared this

in reply to Al Kath

Like it or not: Sending money to individuals in Gaza is a really, really bad idea. You do not want to have a money trail linking you to Hamas. Yes, not everyone in Gaza is part of Hamas, but you really do know nothing about the woman writing you that dm. So if you want to help, donate your money to legitimate aid organizations. They also are able to provide help to those palestinians who are not able to write in English and use the internet to chat with you on the fediverse.

reshared this

Lorenzo ha ricondiviso questo.

russia’s FSB reported bringing charges against Telegram founder Pavel Durov for facilitating terrorist activity and placing him on the international wanted list.

According to the security service, the administration of the messaging app fails to delete channels and bots that, according to the russian side, are used to coordinate terrorist attacks and acts of sabotage in russia.

en.interfax.com.ua/news/genera…

reshared this

Lorenzo ha ricondiviso questo.

I will remind you that OpenAI is worth nearly $1,000,000,000,000.
The going rate for an engineer that knows how to secure a website is $166,000/year.

cyberplace.social/@GossiTheDog…


Google search:

site:claude.ai/public

Coming soon to
claude.ai/robots.txt

/share was full of chats but they added it to robots.txt


reshared this

Lorenzo ha ricondiviso questo.

Writeup of the openai attack on HuggingFace via @campuscodi
Key points
- access to source: OSS code, trivially decompiled JAR files,... allows for the LLMs to perform offline searches for vulnerabilities at scale. Then, when the goal "solve this problem" could only be met by attacking an external company, it did.

Interesting hypothesis that part of the attack may have involved supplying malicious artifacts to other systems to get them to run your exploit. This is why package managers must require signed artifacts & build tools must check them

#cybersecurity

hacktron.ai/blog/here-is-how-o…

reshared this

Lorenzo ha ricondiviso questo.

GrapheneOS protections against data extraction from locked devices
L: discuss.grapheneos.org/d/40700…
C: news.ycombinator.com/item?id=4…
posted on 2026.07.26 at 01:57:22 (c=0, p=3)

reshared this