Floresta 0.9.1 is out, fixing two potential DoS vectors. Please upgrade to the latest version. We will publish more about those two vulnerabilities soon.
@__tinygrad__ In the projects I’m working on, I enforce interactions such as discussions on issues before opening any PR, and considering even attendance at public calls to address any questions
I was reviewing some PRs and it’s incredible how typos in String text have virtually disappeared since the advent of LLMs.
Maybe I should start using that to distinguish between LLM code and human code🤔
Floresta v0.9.0 is out.
This release aligns our networking layer with the Utreexo messaging flow (BIP-0183), while improving validation, testing, and performance across the stack.
Checkout our in-depth post for more info https://t.co/1HgE2TcJ3l
Finding a block with a Bitaxe is "impossible"... until it actually happens. ⚡️⛏️
Huge win for the Brazilian 🇧🇷 Bitcoin community!
One of our own just found a block. We’re a small group, but the talent is real: 3 awarded BTC++ hackers, Bitdevs builders, node runners, LoRa mesh hackers, cybersec experts, and now one very lucky (and happy) solo miner. ⛏️✨
Some say you're "elite" just for owning BTC. I disagree.
The real elite comes from being surrounded by a community of builders and dreamers like this. Incredibly proud of what we’re growing here. 🚀
BLOCO, vcs são FODA!
#Bitcoin #Bitaxe #SoloMining #BitcoinBrazil #btc
@Cointelegraph@BrCointelegraph@DecryptMedia@CoinDesk@criptofacil@BitcoinNewsCom@TheBlockCo@BitcoinMagazine
🧵👇
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Nesta quinta (26/03) às 16h ⚡️
Vamos discutir canais com transações v3 (TRUC): sem update_fee, menos risco de force-close em picos de mempool, mais resistência a pinning attacks e menor footprint on-chain vs anchor outputs.
Com: @pins_btc
Participe 👇