@Gab10438Gabriel@CentralDoCAM Mas isso é cíclico. Ronaldinho saiu e tivemos momentos de alegria com o Pratto, depois parei de acompanhar e do nada veio o Hulk.
Se falar que Datolo, Guilherme e Pratto não são ídolos vc N é torcedor.
@poptime Se pelo menos o carro valesse... Entendo quem faz isso com Ferrari, McLaren, Lamborghini, placa preta, mas a porcaria de um 718... É se achar o que não é
@NBAdoPovo Isso é normal do Houston. N tinha esperança nenhuma neles. Se com Mike D'Antoni, Harden, CP3, Ariza, Howard (não todo mundo simultaneamente) não rolou, não é com esse time merda atual que vai rolar.
@RuanBarbos26938@brasilcoast2 Bem vindo! Está sendo assim desde 2013. Comecei a assistir basquete por causa do Dwight Howard no Rockets e é estressante torcer pra eles nos playoffs desde sempre
@brasilcoast2 Sou torcedor do Houston desde 2013 +/- e depois de: Toco do Manu Ginobili pelas costas do Harden, CP3 machucado contra o Warriors, Trevor Ariza 0/17 e tentando clutch entre outras várias situações eu reconheci que esse time é amaldiçoado... não rola
Lovable, the AI app builder with millions of users, has a mass data breach affecting every project created before their patch in November 2025. Any free account can access other users' source code, database credentials, AI chat histories, and real customer data through five unauthenticated API calls. The bug was reported 48 days ago on HackerOne. It's still open. Here's the breakdown:
> The vulnerability is Broken Object Level Authorization. Lovable's API verifies Firebase auth tokens but never checks whether the requesting user actually owns the project. Any authenticated user can query any project.
> @weezerOsint created a free account today and accessed another user's full source tree, including an admin panel built for Connected Women in AI, a real Danish nonprofit. The project was last edited 10 days ago with 3,703 edits this year. This is active work.
> The source code contained hardcoded Supabase credentials (SUPABASE_URL, SUPABASE_PUBLISHABLE_KEY, SUPABASE_SERVICE_ROLE_KEY). The developer queried the database and got back real names, real companies, real LinkedIn profiles. Speakers from Accenture Denmark and Copenhagen Business School. Not test data.
> Affected endpoints include /projects/{id}/*, /git/files, /git/file, and /documents. All return 200 OK for pre-patch projects.
> Every AI conversation is stored and accessible through the same bug. Developers discuss database schemas, paste error logs, share credentials, and walk through business logic with the AI. All of it is readable.
> Lovable patched new projects but left existing ones exposed. A project created in April 2026 returns 403 Forbidden. The same developer's older project, same API, same endpoint, same free account, same session, returns 200 OK with the full source tree.
> The first HackerOne report (#3583821) was filed March 3, 2026. Lovable triaged it, shipped ownership checks for new projects, and left every existing project wide open. 48 days later, nothing has changed.
> Employees from Nvidia, Microsoft, Uber, and Spotify all have Lovable accounts. The exposure is not limited to hobby projects.
Dois anos se passaram e eu ainda me emociono: 💔
Um ladrão roubou o celular de um aposentado e, ao atravessar a rua, foi atropelado por um ônibus.
Adoro histórias com finais felizes. 😭😭