#Zelenskyy: Peace Plan Must Include Equal Withdrawals and Clear Governance
Zelenskyy said that the US proposal for a compromise regarding Donetsk contains a number of unresolved questions and does not align with Ukraineโs interests.
united24media.com/latest-news/โฆ
Zelenskyy: Peace Plan Must Include Equal Withdrawals and Clear Governance
President Zelenskyy critiques the US compromise on Donetsk, highlighting unanswered questions and urging equitable troop withdrawal for Ukraine's interests.Dariia Mykhailenko (UNITED24 Media)
reshared this
RE: infosec.exchange/@catsalad/115โฆ
I wonder what happens if I quote your toot and you edit yours to quote mine. 
Cat ๐๐ฅ (D.Burch) :blobcatrainbow: (@catsalad@infosec.exchange)
Hey @cR0w, I heard if you post, quote that post, then edit the first to quote the second it does this: :aneobot_explode:Cat ๐๐ฅ (D.Burch) :blobcatrainbow: (Infosec Exchange)
Months ago I got a nut milk maker.
"I don't remember being drunk enough to buy this."
Put it away.
Today, pick up box - curious. Look at label. It's my neighbor's lol.
The advantage of December birthday is that you can beg your parents for one really expensive present, instead of separate birthday and Christmas presents like normal.
The disadvantage is shit's only festive once per year and they're both sort of diluted.
Ma non รจ detto che questo aiuti per contrastare il poisoning
RE: union.place/@jaythurbershow/11โฆ
This IS a good time to help @jerry for a last-minute...I was GOING to say "tax writeoff," but I honestly don't know whether he's got it set up as a charity or not.
So maybe just a good feeling, at Christmastime ๐
Jay Thurber Show (@jaythurbershow@union.place)
Attached: 1 image Fediverse pals, if your instance is run by a non-profit organization or a volunteer, now is a good time to see if they need a donation.Jay Thurber Show (The Union Place)
Liam Neeson Narrates Anti-Vax, Pro-RFK Documentary
The Taken actor can be heard calling mRNA COVID vaccines โdangerous experiments.โWalker Bragman (Important Context)
Contro la casa di vetro. Opacitร , schedatura e potere nellโetร digitale. 17ยฐ Convegno Nexa su Internet & Societร a Torino Lunedรฌ 15 dicembre 2025
Lunedรฌ 15 dicembre 2025
ore 9.00 โ 18.00
Sala Conferenze โLuigi Ciminieraโ
DAUIN, Politecnico di Torino, 5ยฐ piano
Corso Castelfidardo 34/D, Torino (mappa)
Hashtag del convegno: #nexa2025
Per motivi organizzativi, รจ gradita la segnalazione della propria partecipazione allโindirizzo: Mobilizon
Con @smaurizi @RL @RossellaLatempa @avetro e altri che non sono ancora su mastodon ๐
Lโingresso รจ libero e gratuito fino ad esaurimento posti.
17ยฐ Convegno Nexa su Internet & Societร - Nexa Center for Internet & Society
Contro la casa di vetro. Opacitร , schedatura e potere nell'etร digitale | Lunedรฌ 15 dicembre 2025 | Sala Luigi Ciminiera, DAUIN, Politecnico di TorinoNexa Admin (Nexa Center for Internet & Society)
reshared this
Hello @Raroun hope you're well. every now & then, when i have joined a different #Friendica instance in the past, i ask this same question of its Owners / Admins. always it's the same negative answer, but i live in hope!
on Masto & Sharkey instances, if the Admins are willing, it is technically possible to add FOSS emojis to the servers. consequently, on many of my instances i've been able to include these in various posts when applicable:
:linux: :archlinux: :kde: :plasma: :zenbrowser: :floorp: :firefox_nightly: :firefox: :thunderbird: :fedora: :opensuse: :debian:
so... is there yet any way that such emojis can be added to your instance, please?
cc: @Friendica Support
securityaffairs.com/185593/hacโฆ
#securityaffairs #hacking
Critical Gogs zero-day under attack, 700 servers hacked
Hackers exploited an unpatched Gogs zero-day, allowing remote code execution and compromising around 700 Internet-facing servers.Pierluigi Paganini (Security Affairs)
securityaffairs.com/185574/hacโฆ
#securityaffairs #hacking
GeminiJack zero-click flaw in Gemini Enterprise allowed corporate data exfiltration
Google fixed GeminiJack, a zero-click Gemini Enterprise flaw that could leak corporate data via crafted emails, invites, or documents.Pierluigi Paganini (Security Affairs)
@Random Penguin Capabilities are really flexible, but it would have to be wired in so many parts of the Friendica codebase that it isn't realistic given the (lack of) manpower Friendica enjoys at the moment.
It will have to be a simple flag at first, and then if need arises it could be made more complex.
I would like to have a separated "Moderator" role, but the sad truth is that I guess that I don't have the capacity to add it. There are a lot of things that would be nice to see them being added to Friendica, but my available time is limited. The list of issues on our repository is constantly growing and just maintaining and improving already existing functionality eats up most of my time.
I guess that we will only have this in the system when we find additional coding resources.
"The extremists do not want a two-state solution or a one-state solution. The extremists do not want to give us our state or be part of their state. They want the land without the people. They just want us gone".
Don't miss #EwenMacAskill's reportage from the #WestBank:
theguardian.com/world/2025/decโฆ
I used to report from the West Bank. Twenty years after my last visit, I was shocked by how much worse it is today
The long read: Among the many people I met, there was a pervasive feeling of hopelessness and a sense that resistance is slowly becoming a memoryEwen MacAskill (The Guardian)
en.wikipedia.org/wiki/Lunch_atโฆ
it's fairly boring abstract interpretation, but the qemu jit optimizer/middle end does it. It has a known bits abstract domain and reasons about signed ranges (but rounded up to nearest power of two). Code is here: github.com/qemu/qemu/blob/mastโฆ
Why do you ask?
qemu/tcg/optimize.c at master ยท qemu/qemu
Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are ignored. Please only use release tarballs from the QEMU website. - qemu/qemuGitHub
ah, you work on compcert, super cool!
I'm moving in the opposite direction. I've worked on JIT compilers for ages and have started to become more interested in pragmatic approaches for verifying parts of them. would you be interested in setting up a call some time next year?
MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25
cwe.mitre.org/top25/archive/20โฆ
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.cwe.mitre.org
Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.orโฆ
This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbersโฆ
Notepad++ v8.8.9: Vulnerability-fix
Notepad++ release 8.8.9 is available: https://notepad-plus-plus.org/news/v889-released/ Notepad++ v8.8.9 new security enhancement, new features, regression f...Community
Ambient Music: Satie, Eno, Cage and the Ignorable
This philosophical deep dive explores ambient music, a genre defined by the paradox that it uniquely asks the listener not to listen to it actively. The core...YouTube
monumental-movement-records reshared this.
Dietro Has Fidanken, lโeroe di Drive In che non poteva sbagliare
Come รจ nato Has Fidanken: l'assurdo genius dell'immobilitร . Aneddoti, il generale paracadutista, gli autori di Drive In e il tormentone che fece ridere l'Italia.
this is an experimental quote-share from my #Friendica #newsbots #Circle, whose default Permissions disallow anyone outside this Circle being able to see or access it. i have now done a one-off flip of the Permissions, just for this individual post, to Public, so...
Hello? (Hello, hello, hello)
Is there anybody in there?
Just nod if you can hear me
Is there anyone home?
Come on (Come on, come on), now
I hear you're feeling down
Well, I can ease your pain
And get you on your feet again
Relax (Relax, relax, relax)
I'll need some information first
Just the basic facts
Can you show me where it hurts?
โฒ Unofficial SBS News Bot - 2025-12-11 20:24:04 GMT
Time magazine names 'Architects of AI' as Person of the Year. Here's who's pictured sbs.com.au/news/article/time-mโฆ #World
๐ฅ Mastodon NON รจ il Fediverso
Mastodon concentra oltre il 70% degli utenti e rischia di sembrare lโunica cosa che conti.
Ma il Fediverso รจ infinitamente piรน grande, ricco e variegato, c'รจ chi:
๐ฌ crea video
๐ธ condivide immagini
๐๏ธ produce podcast
๐ pubblica libri
๐ด traccia percorsi in bici
e molto altro.
Ridurre tutto a Mastodon significa limitare la nostra visione ma per conoscere gli altri progetti si puรฒ seguire:
๐ La lista di account: fedidevs.com/s/Nzcz/
๐ Il gruppo: @fediverso
ยซI am proud to be a European citizen. ๐ช๐บ
A united, democratic and free Europe is our future.
Letโs protect it together.ยป
#Europe #EuropeanUnion #EuropeanCitizen #UnitedEurope #EUvalues #Democracy #HumanRights #Freedom #Unity #EuropeTogether #FutureOfEurope
Per cortesia, causa crash della istanza, se mi seguite da una istanza friendica su @luca
potreste fare unfollow / follow ?
mi vengono in mente
@informapirata@poliverso.org @informapirata
@simona @lapo
ma ce ne saranno sicuramente altri
Se stai programmando una vacanza negli USA, controlla i tuoi post sui social anche vecchi di 5 anni
Gli USA vogliono rendere obbligatorio l'accesso ai profili social per i visitatori europei prima di farli entrare alla frontiera. A meno che non siano milionariRiccardo Piccolo (Wiredย Italia)
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle
Da quando diversi fondatori e amministratori delegati delle grandi aziende tecnologiche hanno sposato lโagenda politica dellโamministrazione Trump, il governo degli Stati Uniti si รจ esposto in prima linea per difendere gli interessi di queste aziende.
valigiablu.it/big-tech-lobby-uโฆ
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle - Valigia Blu
Le Big Tech stanno diventando un potere politico globale, capace di influenzare governi e bloccare leggi che limitano i loro profitti e modelli di business. Unโinchiesta internazionale ha documentato quasi 3.Valigia Blu
reshared this
IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE.
@Informatica (Italy e non Italy ๐)
Nel gennaio 1945 il SIM mutรฒ la denominazione in โUfficio Informazioni dello Stato Maggiore Generaleโ ma la struttura rimase pressochรฉ invariata.
L'articolo IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE. proviene da GIANO NEWS.
#DIFESA
securityaffairs.com/185566/hacโฆ
#securityaffairs #hacking
Google fixed a new actively exploited Chrome zero-day
Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild.Pierluigi Paganini (Security Affairs)
682/730
When we bought our new olive oil, I knew immediately that I had to do something with it.
๐ท Fujifilm XT-5
#fujiFilm #fuji #photography #fotografie #730Project #dailyPhoto #obxPhoto #stillLife
Mi trovo a dover scrivere la 'letterina' a Babbo Natale e, oltre alla pace del mondo (mai ricevuta), di solito chiedo sempre almeno un libro.
Quest'anno ho seguito poco le novitร e quindi ti chiedo: titoli interessanti e originali del 2025, magari di genere fantastico, weird, o (se proprio butta male) saggistica?
(titoli facili da trovare, altrimenti non ricevo niente)
Grazie!
Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)
pushsecurity.com/blog/consentfโฆ
ConsentFix: Browser-native ClickFix hijacks OAuth grants
Analysing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.Luke Jennings (Push Security)
Google is rolling out a new feature for Android users that will let them share live video with emergency services.
The new feature is being rolled out in the US and some regions in Mexico and Germany.
It will be available for Android 8 (2017) devices or higher
blog.google/products/android/eโฆ
Share live video with emergency services to get the help you need
During an emergency call or text, a dispatcher can send a request to your Android phone to share live video.Alastair Breeze (Google)
RE: mastodon.social/@campuscodi/11โฆ
More research of this type
Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202โฆ
Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-โฆ
Itโs 2 AM. Do You Know Which AIs Your MCP Server Is Talking To?
Bitsight TRACE research team found roughly 1,000 exposed MCP servers with no authorization in place, revealing new AI vulnerabilities. Read the report now.Joรฃo Cruz (BitSight)
Piccolo gioiello che sto sentendo in questi giorni dei favolosi #Frost (super)gruppo #Prog
Dobbiamo pensare di vivere ogni momento, come se fosse l'ultimo, senza paura, con coraggio e leggerezza
youtube.com/watch?v=hQjvSda3poโฆ
[Verse]The air is warming up again
The summer sounds are like old friends
I see the sunlight through the trees
I wonder if the sun can see me?
[Pre-Chorus]
I hear the echoes of those days
Reflecting back at me in waves
Carved into
1/2
CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates
security.googleblog.com/2025/1โฆ
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...Google Online Security Blog
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
๐ Link all'articolo : redhotcyber.com/post/700-000-rโฆ
Un nuovo allarme arriva dal sottobosco del cybercrime arriva poche ore fa. A segnalarlo lโazienda ParagonSec, societร specializzata nel #monitoraggio delle #attivitร delle cyber gang e dei marketplace clandestini, che ha riportato la comparsa su un #forum #underground di un presunto #database contenente oltre 700.000 record #appartenenti ad un Registro Professionale Italiano.
A cura di Redazione RHC
#redhotcyber #news #cybersecurity #hacking #malware #database #registroprofessionale #nazionalitaliano #sicurezzainformatica #protezionedatidipersonali #databreach #furtodidati #informazionisensibili #violazione sicurezza
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
Un database con 700.000 record di un Registro Professionale Italiano รจ in vendita su un forum underground, con informazioni sensibili e dati personali.Redazione RHC (Red Hot Cyber)
UK ICO fines LastPass ยฃ1.2m for 2022 data breach
ico.org.uk/about-the-ico/mediaโฆ
Password manager provider fined ยฃ1.2m by ICO for data breach affecting up to 1.6 million people in the UK
The Information Commissionerโs Office (ICO) has fined password manager provider LastPass UK Ltd ยฃ1.2 million following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users.ยico.org.uk
Osservare, immaginare, aspettare; l'atto di scattare รจ puramente marginale.
Hรฉbรฉ รง'a รฉtรฉ long.
Longtemps au dรฉbut pour deviner de qui deux indices ne parlaient PAS mais disaient quelque chose ; et oubli de compter Will, me demande pas comment, il s'est mis derriรจre un autre je sais pas.
@Siestโถcorta Bien jouรฉ ! Pour moi il y avait beaucoup trop de 50/50 qui allaient dans tous les sens. ๐ตโ๐ซ
Clues by Sam - Dec 11th 2025 (Tricky)
Less than 10 minutes
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
Vulnerabilitร zero-day in Chrome: Google rilascia una patch urgente, installiamola subito
@Informatica (Italy e non Italy ๐)
Google ha rilasciato un aggiornamento urgente per Chrome a causa di un bug zero-day sfruttato attivamente. Lโanalisi esplora le implicazioni per le aziende e gli utenti, fornendo consigli pratici per proteggersi e mitigare i rischi
Winston Churchill, la scuola non era fatta per lui
๐I fallimenti di un giovane troppo brillante๐
boomerissimo.it/2024/05/27/winโฆ
Winston Churchill somaro: troppo geniale per una scuola normale - Boomerissimo
Winston Churchill รจ stato un gigante del suo tempo ma uno scolaro fallimentare. Aveva un problema che nemmeno la scuola moderna รจ riuscita a superare.Antonio Pintรฉr (Boomerissimo)
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
๐ Link all'articolo : redhotcyber.com/post/netsupporโฆ
#redhotcyber #news #cybersecurity #hacking #malware #ransomware #netSupportRAT #javascript
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
Gli specialisti di Securonix hanno scoperto una campagna malware multilivello per installare NetSupport RAT. L'attacco si sviluppa attraverso fasi nascoste per garantire massima discrezione.Redazione RHC (Red Hot Cyber)
This single mom is squeezed by LAโs cost of living. Now sheโs running for mayor.
https://19thnews.org/2025/12/rae-huang-la-mayor-campaign/?utm_source=flipboard&utm_medium=activitypub
Posted into The 19th @the-19th-19thnews
Rae Huang struggled with LA's affordability. Now she's running for mayor.
Progressive housing advocate and single mom Rae Huang is challenging Karen Bass for Los Angeles mayor, promising free transit and social housing.Jireh Deng, LA Public Press (19th News)
Looks like Twitter finally took down the NoName057 account after yesterday's indictment
Terremoto? No, AI-Fake! Unโimmagine generata dallโIA paralizza i treni britannici
๐ Link all'articolo : redhotcyber.com/post/terremotoโฆ
#redhotcyber #news #intelligenzaartificiale #rete neurale #cybersecurity #sicurezzainformatica #treni #trasporti
Terremoto? No, AI-Fake! Unโimmagine generata dallโIA paralizza i treni britannici
Treni sospesi in Inghilterra per un'immagine falsa di un ponte danneggiato generata da una rete neurale.Redazione RHC (Red Hot Cyber)
This is what our cats do when they want their dinner now. Both of them come down to my cabin where I work, sit on the decking outside and stare at me until I feed them.
Hustlers. The pair of them.
SOAPwn -- new bugs that can lead to RCE in .NET apps
Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more
Microsoft did not fix them
labs.watchtowr.com/soapwn-pwniโฆ
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee.Piotr Bazydlo (@chudyPB) (watchTowr Labs)
The EU aims to agree by Friday on a long-term freeze of Russian central bank assets, a major legal shift that would remove the need to renew the freeze every six months. This would block veto threats from Hungary or Slovakia and pave the way for using the โฌ210B as collateral for loans to Ukraine.
Belgium, holding โฌ185B, remains cautious due to legal risks, but the EU is preparing guarantees to protect it from Russian lawsuits.
Ukraineโs defense industry is working to localize S-300 and S-400 missile production with the goal of integrating them with European radar systems, Fire Pointโs chief designer Denys Shtylerman told the BBC. The company has already cloned key components and plans to begin engine tests in January 2026.
Until full integration is possible, the FP-7 is being used as a short-range ballistic missile with a 200 km range. The longer-range FP-9, reaching up to 855 km, is also in development.
During a meeting with military leadership, Putin claimed that Russian forces hold the strategic initiative and ordered the continuation of combat operations โaccording to plan.โ Gerasimov reported advances in Sumy and near Vovchansk, control over parts of Kostyantynivka, and the capture of Kurylivka, Kucherivka, and Siversk. Putin praised the armyโs performance and said progress in Donbas and โNovorossiyaโ is on track.
๐คทโโ๏ธ
Ukraineโs General Staff confirms it's streamlining transfers between units by shifting to a fully electronic system. Requests now go directly to HQ, cutting out lower-level approvals and reducing manipulation.
But the key message: self-inflicted absences (ะกะะง) won't help soldiers transfer to preferred units. All returns from ะกะะง go to combat brigades in need, including Air Assault and assault forces.
Dictator playbook 101.
Bloomberg reports Viktor Orbรกn is preparing for life after the April 2026 election by planning a power grab through the presidency. Orbรกn is exploring how to rewrite laws to turn Hungaryโs ceremonial presidential role into the most powerful office in the country. Fidesz has already passed a law making it harder to remove the president, and insiders say Orbรกn is considering using his supermajority to push through constitutional changes before the vote.
NEW: Right-wing messaging app Freedom Chat had security flaws that allowed a researcher to guess all numbers registered on the platform, and one that exposed user PINs to other users.
The researcher enumerated around 2,000 phone numbers.
techcrunch.com/2025/12/11/secuโฆ
Security flaws in Freedom Chat app exposed users' phone numbers and PINs | TechCrunch
The founder of Freedom Chat said the company has reset user PINs and released a new version to app stores.Zack Whittaker (TechCrunch)
Dutch prosecutors are seeking an eight-month prison sentence for a man who launched DDoS attacks against the country's 112 emergency line.
The suspect allegedly tried to frame some business partners for the attack
om.nl/actueel/nieuws/2025/12/1โฆ
Zakelijk conflict leidt tot DDoS-aanval 112-centrale: celstraf geรซist
Het Landelijk Parket (LP) van het Openbaar Ministerie (OM) heeft woensdag een onvoorwaardelijke gevangenisstraf van acht maanden en een geldboete geรซist tegen een 47-jarige man uit Delft.www.om.nl

Jerry ๐ฆ๐๐ฆ
in reply to cR0w • • •