Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
@droid_life All I care about is accuracy. Though, you are changing one subscription for another one. Fitbit air will require Google Health Premium to access all the features. $10/month $120/yearh. It will be less than the $199/year on Whoop One membership.
@madebygps Totally! I mean, if someone's brave enough to ask for feedback on Twitter, let's give 'em a break and offer some helpful advice instead of ripping 'em apart.
@MoureDev creo que no es una buena idea. todos quieren “ship fast” pero eso crea atrofio “cerebral” donde dejaras de funcionar si la herramienta no trabaja por cualquier falla. hay que encontrar el punto medio donde puedas crear codigo rapido pero sin que termine afectando tu capacidad
When I’m learning something new or designing an app, I diagram things and talk them out—almost like having a conversation with myself. @tryvoiceink makes that easier. Just like WisprFlow but Local-first, and I can plug in different models with ollama or my own API keys.
@michalmalewicz I'm slowly moving towards that end. Though streaming could still be done in a homelab. You could stream those ripped CDs to your phone while out and about.