This is how to get Ethernet out of a Starlink Mini (panda_prod2 and panda_prod3 revisions).
These terminals lack an internal Ethernet PHY and instead use a direct SGMII connection between the Starlink SoC and the router SoC.
I figured out the required MDIO parameters and SGMII wiring (there are a few tricks!) and got an external 1 Gbps PHY working.
Now I have a direct Ethernet connection to this Mini panda_prod2.
I took apart my block clock what I found will surprise you! Sealed deep inside the mechanism was an authentic high-tech Russian military-grade listening device — the ultra-obscure GRU-issue “Ухо-9” (Ukho-9) nano-acoustic sensor. This thing is so advanced it can capture private sounds with insane precision, right down to the exact faint hammering of individual letters into steel plates. Absolute spy-movie stuff.
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Compromised packages (confirmed malicious) include:
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- qlik/[email protected]
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)
In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.
The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.
Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.
Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
What's happening on the Swedish grid right now is not only hard to believe, but a window into the future regarding the Bitcoin usecase the world embraces first.
Here's a snapshot.
Brussels is preparing a plan to lower Europe’s electricity bills.
Network charges represent 24–29% of household electricity bills and 21% for businesses, while taxes and levies add another 24% for households and 16% for firms.
For energy-intensive industries, electricity taxes could even be reduced to zero.
The long-term objective is clear. Europe must electrify more than half of its total energy consumption and, together with Norway, produce most of that energy within Europe.
But in the short term, Europe has no choice but to use targeted public policy to lower electricity costs, protect industry and accelerate the transition away from fossil fuel dependence.
https://t.co/Nn9w48mppn
De @Tesla community houdt hier al geruime tijd de vinger aan de pols over de toelating voor de FSD-technologie op onze Vlaamse en Belgische wegen.
Uit waardering voor jullie niet-aflatende interesse (en aanmoediging 😉), krijgen jullie hierbij de primeur: ik heb net de toelating getekend! 🚘
Deze beslissing gaat nu naar onze dienst homologatie, zij zullen @RDWnl op de hoogte brengen van de goedkeuring. Vlaanderen omarmt innovatie!
Bypassing #EU#AgeVerification using their own infrastructure.
I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly.
Step 1: Install the extension
Step 2: Register an identity (just once)
Step 3: Continue using the web as normal
The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts".
This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring.
Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.