@Meta@facebook
Your last move against drugs is quiet annoying for some reasons.
I'm part of a small band called "Super Acid Bros"
For the record, our name has NOTHING to do with drugs. This is an absolute nightmare for a band our size who depend on the platform for reach 1/2
Well, since no one had ever made DC-coupled firmware for the @HAGIWO1 MOD2, I decided to create some =)
So here’s a list of firmware: https://t.co/3cZnMcaRkd
Mine are mostly DC-oriented, but I actually made two AC ones too!
Looking forward to hearing your thoughts about it !
🚨 Anthropic just showed a 27-minute workshop on how to actually do prompts for Claude.
Taught by the people who built it.
Free. No registration. No paywall.
I've seen $300 courses that don't cover what they teach in the first 8 minutes.
Watch it and Bookmark it now
🇫🇷🚨Choc: La semaine prochaine, alors que beaucoup d’eurodéputés sont en vacances, le #ChatControl 1.0 (scannage de masse) pourrait être adopté via un 3e vote! 🕵️♂️
ℹ️https://t.co/VUcdoUmErW
Stoppe le coup&ALERTE tes élus: https://t.co/uKRZ4amMZs ✍️
📲 Saviez-vous que dans iOS 27, Apple a prévu une liste de pays où le chiffrement des messages RCS (SMS) est interdit ?
Chine 🇨🇳. Corée du Sud 🇰🇷. France 🇫🇷.
Le reste du monde déploie l'E2EE, le chiffrement de bout en bout entre iPhone et Android. Une avancée majeure pour la confidentialité de vos SMS.
En France, c'est bloqué.
Les opérateurs sont prêts techniquement. Ce n'est pas un problème d'infrastructure. C'est un choix politique.
Les raisons sont multiples, la France ayant toujours une longueur d'avance pour affaiblir votre sécurité et s'assurer de pouvoir garder un oeil sur vous. Mais l'une des pistes probables : La PNIJ - la Plateforme Nationale des Interceptions Judiciaires. Un outil qui permet à l'État d'accéder à vos communications. Le chiffrement de bout en bout sur ces millions d'échanges quotidiens lui couperait l'accès. Définitivement.
Alors notre gouvernement fait tout pour que vous restiez exposés.
Analyzed a PowerShell malware loader that hides its second stage inside a seemingly legitimate MP3 file.
Key observations:
• Downloads result.mp3
• Extracts bytes from a fixed offset (12345)
• Decrypts the blob using an RC4-like stream cipher with key "ZHOPA"
• Attempts in-memory execution via VirtualAlloc + NtCreateThreadEx
This is a nice example of payload smuggling using non-executable media files.
https://lincdiiin[.]com/homework.txt
https://lincdiiin[.]com/Program.exe
https://lincdiiin[.]com/loader.hta
https://lincdiiin[.]com/result.mp3
Just stumbled upon OSIRIS AI, an 'Open Source Palantir', a global intelligence dashboard that aggregates live flight and satellite tracking, CCTV networks, earthquake monitoring, conflict zone mapping, and 24/7 news feeds.
Free. Open Source. No sign-up required.
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots.
Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy.
▪️ AI surfaces a massive wave of 0-day RCEs.
▪️ Submissions overwhelm ZDI past max capacity.
▪️ Slots run out. Researchers with working chains get rejected.
▪️ "Revenge disclosures" begin. ← we are here.
Confirmed casualties so far:
▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land.
▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla.
▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere.
▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel.
▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected.
▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected.
Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in.
ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
This might be the most dangerous GitHub repo ever published.
Someone built a full 10.5 GHz radar system that can track targets up to 20km away and open sourced the entire thing.
It ships with:
→ Complete PCB designs and schematics
→ FPGA signal processing code
→ STM32 firmware
→ Python GUI with map integration
→ GPS/IMU integration
→ MIT license (100% free)
6.8k stars on GitHub already
This is the kind of project defense contractors would charge you a fortune for.
One dev just put it on GitHub.
@durov it is, if your opsec lvl is good enough, but hell, each year we are stepping back ...
I love my country, but hate my government and all those stupids law made by people who doesn't know anything about CS ..
We no longer have any active servers in France and are continuing the process of leaving OVH. We'll be rotating our TLS keys and Let's Encrypt account keys pinned via accounturi. DNSSEC keys may also be rotated. Our backups are encrypted and can remain on OVH for now.
Our App Store verifies the app store metadata with a cryptographic signature and downgrade protection along with verification of the packages. Android's package manager also has another layer of signature verification and downgrade protection.
Our System Updater verifies updates with a cryptographic signature and downgrade protection along with another layer of both in update_engine and a third layer of both via verified boot. Signing channel release channel names is planned too.
Our update mirrors are currently hosted on sponsored servers from ReliableSite (Los Angeles, Miami) and Tempest (London). London is a temporary location due to an emergency move from a provider which left the dedicated server business and will move. More sponsored update mirrors are coming.
Our ns1 anycast network is on Vultr and our ns2 anycast network is on BuyVM since both support BGP for announcing our own IP space. We're moving our main website/network servers used for default OS connections to a mix of Vultr+BuyVM locations.
We have 5 servers in Canada with OVH with more than static content and basic network services: email, Matrix, discussion forum, Mastodon and attestation. Our plan is to move these to Netcup root servers or a similar provider short term and then colocated servers in Toronto long term.
France isn't a safe country for open source privacy projects. They expect backdoors in encryption and for device access too. Secure devices and services are not going to be allowed. We don't feel safe using OVH for even a static website with servers in Canada/US via their Canada/US subsidiaries.
We were likely going to be able to release experimental Pixel 10 support very soon and it's getting disrupted. The attacks on our team with ongoing libel and harassment have escalated, raids on our chat rooms have escalated and more. It's rough right now and support is appreciated.
@le_Parisien, vous n'avez pas honte de poster un article complètement faux sur @GrapheneOS ?
Votre article est stupide est préjudiciable, le but du journalisme n'est pas de faire un travail de fond et de verifier ses propos ? Bravo pour votre incompétence
🔥Nouvelle vidéo ! Probablement une de mes enquêtes les plus importantes, je trouve. Le sujet est assez grave : l'infiltration des délires new age et de la charlatanerie dans les hôpitaux... Merci d'avance pour vos RT chamaniques😘 https://t.co/4XaiEqYwqm