"The extremists do not want a two-state solution or a one-state solution. The extremists do not want to give us our state or be part of their state. They want the land without the people. They just want us gone".
Don't miss #EwenMacAskill's reportage from the #WestBank:
theguardian.com/world/2025/decโฆ
I used to report from the West Bank. Twenty years after my last visit, I was shocked by how much worse it is today
The long read: Among the many people I met, there was a pervasive feeling of hopelessness and a sense that resistance is slowly becoming a memoryEwen MacAskill (The Guardian)
en.wikipedia.org/wiki/Lunch_atโฆ
it's fairly boring abstract interpretation, but the qemu jit optimizer/middle end does it. It has a known bits abstract domain and reasons about signed ranges (but rounded up to nearest power of two). Code is here: github.com/qemu/qemu/blob/mastโฆ
Why do you ask?
qemu/tcg/optimize.c at master ยท qemu/qemu
Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are ignored. Please only use release tarballs from the QEMU website. - qemu/qemuGitHub
ah, you work on compcert, super cool!
I'm moving in the opposite direction. I've worked on JIT compilers for ages and have started to become more interested in pragmatic approaches for verifying parts of them. would you be interested in setting up a call some time next year?
MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25
cwe.mitre.org/top25/archive/20โฆ
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.cwe.mitre.org
Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.orโฆ
This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbersโฆ
Notepad++ v8.8.9: Vulnerability-fix
Notepad++ release 8.8.9 is available: https://notepad-plus-plus.org/news/v889-released/ Notepad++ v8.8.9 new security enhancement, new features, regression f...Community
Ambient Music: Satie, Eno, Cage and the Ignorable
This philosophical deep dive explores ambient music, a genre defined by the paradox that it uniquely asks the listener not to listen to it actively. The core...YouTube
monumental-movement-records reshared this.
Dietro Has Fidanken, lโeroe di Drive In che non poteva sbagliare
Come รจ nato Has Fidanken: l'assurdo genius dell'immobilitร . Aneddoti, il generale paracadutista, gli autori di Drive In e il tormentone che fece ridere l'Italia.
this is an experimental quote-share from my #Friendica #newsbots #Circle, whose default Permissions disallow anyone outside this Circle being able to see or access it. i have now done a one-off flip of the Permissions, just for this individual post, to Public, so...
Hello? (Hello, hello, hello)
Is there anybody in there?
Just nod if you can hear me
Is there anyone home?
Come on (Come on, come on), now
I hear you're feeling down
Well, I can ease your pain
And get you on your feet again
Relax (Relax, relax, relax)
I'll need some information first
Just the basic facts
Can you show me where it hurts?
โฒ Unofficial SBS News Bot - 2025-12-11 20:24:04 GMT
Time magazine names 'Architects of AI' as Person of the Year. Here's who's pictured sbs.com.au/news/article/time-mโฆ #World
๐ฅ Mastodon NON รจ il Fediverso
Mastodon concentra oltre il 70% degli utenti e rischia di sembrare lโunica cosa che conti.
Ma il Fediverso รจ infinitamente piรน grande, ricco e variegato, c'รจ chi:
๐ฌ crea video
๐ธ condivide immagini
๐๏ธ produce podcast
๐ pubblica libri
๐ด traccia percorsi in bici
e molto altro.
Ridurre tutto a Mastodon significa limitare la nostra visione ma per conoscere gli altri progetti si puรฒ seguire:
๐ La lista di account: fedidevs.com/s/Nzcz/
๐ Il gruppo: @fediverso
ยซI am proud to be a European citizen. ๐ช๐บ
A united, democratic and free Europe is our future.
Letโs protect it together.ยป
#Europe #EuropeanUnion #EuropeanCitizen #UnitedEurope #EUvalues #Democracy #HumanRights #Freedom #Unity #EuropeTogether #FutureOfEurope
Per cortesia, causa crash della istanza, se mi seguite da una istanza friendica su @luca
potreste fare unfollow / follow ?
mi vengono in mente
@informapirata@poliverso.org @informapirata
@simona @lapo
ma ce ne saranno sicuramente altri
Se stai programmando una vacanza negli USA, controlla i tuoi post sui social anche vecchi di 5 anni
Gli USA vogliono rendere obbligatorio l'accesso ai profili social per i visitatori europei prima di farli entrare alla frontiera. A meno che non siano milionariRiccardo Piccolo (Wiredย Italia)
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle
Da quando diversi fondatori e amministratori delegati delle grandi aziende tecnologiche hanno sposato lโagenda politica dellโamministrazione Trump, il governo degli Stati Uniti si รจ esposto in prima linea per difendere gli interessi di queste aziende.
valigiablu.it/big-tech-lobby-uโฆ
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle - Valigia Blu
Le Big Tech stanno diventando un potere politico globale, capace di influenzare governi e bloccare leggi che limitano i loro profitti e modelli di business. Unโinchiesta internazionale ha documentato quasi 3.Valigia Blu
reshared this
IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE.
@Informatica (Italy e non Italy ๐)
Nel gennaio 1945 il SIM mutรฒ la denominazione in โUfficio Informazioni dello Stato Maggiore Generaleโ ma la struttura rimase pressochรฉ invariata.
L'articolo IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE. proviene da GIANO NEWS.
#DIFESA
securityaffairs.com/185566/hacโฆ
#securityaffairs #hacking
Google fixed a new actively exploited Chrome zero-day
Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild.Pierluigi Paganini (Security Affairs)
Yes that's the charme of it, just like the player character you are thrown into this strange, brutal world and have to figure out how to survive. The beginning is difficult, but that makes it all the more satisfying later in the game when you actually become powerful.
Regarding mods, you should definitely get one for improved inventory, and there's also a DirectX 11 mod for better graphics.
682/730
When we bought our new olive oil, I knew immediately that I had to do something with it.
๐ท Fujifilm XT-5
#fujiFilm #fuji #photography #fotografie #730Project #dailyPhoto #obxPhoto #stillLife
Mi trovo a dover scrivere la 'letterina' a Babbo Natale e, oltre alla pace del mondo (mai ricevuta), di solito chiedo sempre almeno un libro.
Quest'anno ho seguito poco le novitร e quindi ti chiedo: titoli interessanti e originali del 2025, magari di genere fantastico, weird, o (se proprio butta male) saggistica?
(titoli facili da trovare, altrimenti non ricevo niente)
Grazie!
Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)
pushsecurity.com/blog/consentfโฆ
ConsentFix: Browser-native ClickFix hijacks OAuth grants
Analysing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.Luke Jennings (Push Security)
Google is rolling out a new feature for Android users that will let them share live video with emergency services.
The new feature is being rolled out in the US and some regions in Mexico and Germany.
It will be available for Android 8 (2017) devices or higher
blog.google/products/android/eโฆ
Share live video with emergency services to get the help you need
During an emergency call or text, a dispatcher can send a request to your Android phone to share live video.Alastair Breeze (Google)
RE: mastodon.social/@campuscodi/11โฆ
More research of this type
Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202โฆ
Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-โฆ
Itโs 2 AM. Do You Know Which AIs Your MCP Server Is Talking To?
Bitsight TRACE research team found roughly 1,000 exposed MCP servers with no authorization in place, revealing new AI vulnerabilities. Read the report now.Joรฃo Cruz (BitSight)
Piccolo gioiello che sto sentendo in questi giorni dei favolosi #Frost (super)gruppo #Prog
Dobbiamo pensare di vivere ogni momento, come se fosse l'ultimo, senza paura, con coraggio e leggerezza
youtube.com/watch?v=hQjvSda3poโฆ
[Verse]The air is warming up again
The summer sounds are like old friends
I see the sunlight through the trees
I wonder if the sun can see me?
[Pre-Chorus]
I hear the echoes of those days
Reflecting back at me in waves
Carved into
1/2
CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates
security.googleblog.com/2025/1โฆ
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...Google Online Security Blog
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
๐ Link all'articolo : redhotcyber.com/post/700-000-rโฆ
Un nuovo allarme arriva dal sottobosco del cybercrime arriva poche ore fa. A segnalarlo lโazienda ParagonSec, societร specializzata nel #monitoraggio delle #attivitร delle cyber gang e dei marketplace clandestini, che ha riportato la comparsa su un #forum #underground di un presunto #database contenente oltre 700.000 record #appartenenti ad un Registro Professionale Italiano.
A cura di Redazione RHC
#redhotcyber #news #cybersecurity #hacking #malware #database #registroprofessionale #nazionalitaliano #sicurezzainformatica #protezionedatidipersonali #databreach #furtodidati #informazionisensibili #violazione sicurezza
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
Un database con 700.000 record di un Registro Professionale Italiano รจ in vendita su un forum underground, con informazioni sensibili e dati personali.Redazione RHC (Red Hot Cyber)
UK ICO fines LastPass ยฃ1.2m for 2022 data breach
ico.org.uk/about-the-ico/mediaโฆ
Password manager provider fined ยฃ1.2m by ICO for data breach affecting up to 1.6 million people in the UK
The Information Commissionerโs Office (ICO) has fined password manager provider LastPass UK Ltd ยฃ1.2 million following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users.ยico.org.uk
Osservare, immaginare, aspettare; l'atto di scattare รจ puramente marginale.
Hรฉbรฉ รง'a รฉtรฉ long.
Longtemps au dรฉbut pour deviner de qui deux indices ne parlaient PAS mais disaient quelque chose ; et oubli de compter Will, me demande pas comment, il s'est mis derriรจre un autre je sais pas.
@Siestโถcorta Bien jouรฉ ! Pour moi il y avait beaucoup trop de 50/50 qui allaient dans tous les sens. ๐ตโ๐ซ
Clues by Sam - Dec 11th 2025 (Tricky)
Less than 10 minutes
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ
Vulnerabilitร zero-day in Chrome: Google rilascia una patch urgente, installiamola subito
@Informatica (Italy e non Italy ๐)
Google ha rilasciato un aggiornamento urgente per Chrome a causa di un bug zero-day sfruttato attivamente. Lโanalisi esplora le implicazioni per le aziende e gli utenti, fornendo consigli pratici per proteggersi e mitigare i rischi
Winston Churchill, la scuola non era fatta per lui
๐I fallimenti di un giovane troppo brillante๐
boomerissimo.it/2024/05/27/winโฆ
Winston Churchill somaro: troppo geniale per una scuola normale - Boomerissimo
Winston Churchill รจ stato un gigante del suo tempo ma uno scolaro fallimentare. Aveva un problema che nemmeno la scuola moderna รจ riuscita a superare.Antonio Pintรฉr (Boomerissimo)
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
๐ Link all'articolo : redhotcyber.com/post/netsupporโฆ
#redhotcyber #news #cybersecurity #hacking #malware #ransomware #netSupportRAT #javascript
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
Gli specialisti di Securonix hanno scoperto una campagna malware multilivello per installare NetSupport RAT. L'attacco si sviluppa attraverso fasi nascoste per garantire massima discrezione.Redazione RHC (Red Hot Cyber)
This single mom is squeezed by LAโs cost of living. Now sheโs running for mayor.
https://19thnews.org/2025/12/rae-huang-la-mayor-campaign/?utm_source=flipboard&utm_medium=activitypub
Posted into The 19th @the-19th-19thnews
Rae Huang struggled with LA's affordability. Now she's running for mayor.
Progressive housing advocate and single mom Rae Huang is challenging Karen Bass for Los Angeles mayor, promising free transit and social housing.Jireh Deng, LA Public Press (19th News)
Looks like Twitter finally took down the NoName057 account after yesterday's indictment
Terremoto? No, AI-Fake! Unโimmagine generata dallโIA paralizza i treni britannici
๐ Link all'articolo : redhotcyber.com/post/terremotoโฆ
#redhotcyber #news #intelligenzaartificiale #rete neurale #cybersecurity #sicurezzainformatica #treni #trasporti
Terremoto? No, AI-Fake! Unโimmagine generata dallโIA paralizza i treni britannici
Treni sospesi in Inghilterra per un'immagine falsa di un ponte danneggiato generata da una rete neurale.Redazione RHC (Red Hot Cyber)
This is what our cats do when they want their dinner now. Both of them come down to my cabin where I work, sit on the decking outside and stare at me until I feed them.
Hustlers. The pair of them.
SOAPwn -- new bugs that can lead to RCE in .NET apps
Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more
Microsoft did not fix them
labs.watchtowr.com/soapwn-pwniโฆ
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee.Piotr Bazydlo (@chudyPB) (watchTowr Labs)
The EU aims to agree by Friday on a long-term freeze of Russian central bank assets, a major legal shift that would remove the need to renew the freeze every six months. This would block veto threats from Hungary or Slovakia and pave the way for using the โฌ210B as collateral for loans to Ukraine.
Belgium, holding โฌ185B, remains cautious due to legal risks, but the EU is preparing guarantees to protect it from Russian lawsuits.
Ukraineโs defense industry is working to localize S-300 and S-400 missile production with the goal of integrating them with European radar systems, Fire Pointโs chief designer Denys Shtylerman told the BBC. The company has already cloned key components and plans to begin engine tests in January 2026.
Until full integration is possible, the FP-7 is being used as a short-range ballistic missile with a 200 km range. The longer-range FP-9, reaching up to 855 km, is also in development.
During a meeting with military leadership, Putin claimed that Russian forces hold the strategic initiative and ordered the continuation of combat operations โaccording to plan.โ Gerasimov reported advances in Sumy and near Vovchansk, control over parts of Kostyantynivka, and the capture of Kurylivka, Kucherivka, and Siversk. Putin praised the armyโs performance and said progress in Donbas and โNovorossiyaโ is on track.
๐คทโโ๏ธ
Ukraineโs General Staff confirms it's streamlining transfers between units by shifting to a fully electronic system. Requests now go directly to HQ, cutting out lower-level approvals and reducing manipulation.
But the key message: self-inflicted absences (ะกะะง) won't help soldiers transfer to preferred units. All returns from ะกะะง go to combat brigades in need, including Air Assault and assault forces.
Dictator playbook 101.
Bloomberg reports Viktor Orbรกn is preparing for life after the April 2026 election by planning a power grab through the presidency. Orbรกn is exploring how to rewrite laws to turn Hungaryโs ceremonial presidential role into the most powerful office in the country. Fidesz has already passed a law making it harder to remove the president, and insiders say Orbรกn is considering using his supermajority to push through constitutional changes before the vote.
NEW: Right-wing messaging app Freedom Chat had security flaws that allowed a researcher to guess all numbers registered on the platform, and one that exposed user PINs to other users.
The researcher enumerated around 2,000 phone numbers.
techcrunch.com/2025/12/11/secuโฆ
Security flaws in Freedom Chat app exposed users' phone numbers and PINs | TechCrunch
The founder of Freedom Chat said the company has reset user PINs and released a new version to app stores.Zack Whittaker (TechCrunch)
Dutch prosecutors are seeking an eight-month prison sentence for a man who launched DDoS attacks against the country's 112 emergency line.
The suspect allegedly tried to frame some business partners for the attack
om.nl/actueel/nieuws/2025/12/1โฆ
Zakelijk conflict leidt tot DDoS-aanval 112-centrale: celstraf geรซist
Het Landelijk Parket (LP) van het Openbaar Ministerie (OM) heeft woensdag een onvoorwaardelijke gevangenisstraf van acht maanden en een geldboete geรซist tegen een 47-jarige man uit Delft.www.om.nl
Il Digital Wellness Coaching: i 3 passi per un mindsetfix e lโuso intenzionale della tecnologia
๐ Link all'articolo : redhotcyber.com/post/il-digitaโฆ
#redhotcyber #news #stressdigitale #crisidigitali #benesseredigitale #identitร digitale #consapevolezzadigitale
Il Digital Wellness Coaching: i 3 passi per un mindsetfix e l'uso intenzionale della tecnologia
Viviamo nella dissociazione: lodiamo lโequilibrio tra lavoro e vita privata, eppure ci ritroviamo costantemente online, come marionette in balia di fili invisibili Il vero problema non รจ la tecnologia, ma come noi, esseri umani, rispondiamo ad essa QโฆDaniela Farina (Red Hot Cyber)
Su Twitter/X la spunta blu รจ diventata un prodotto a pagamento.
Su Mastodon, invece, la verifica con la spunta verde nella bio รจ gratuita, trasparente e basata su standard aperti.
Ho scritto un post dove spiego tre modi reali per ottenere quella spunta verde che vedi in molti profili (e no, non รจ una semplice emoji):
#privacy #fediverso #mastodon #Identitร Online
emanuelegori.uno/twitter-x-comโฆ
Twitter/X: come verificare la tua identitร senza pagare con Mastodon
Da quando Elon Musk ha trasformato la storica spunta blu di Twitter in un servizio a pagamento da 3 a 38 euro al mese, molti si sono chiesti: esiste davvero unโalternativa gratuita e credibile per verificare la propria identitร online? La risposta รจ โฆHomelab Notes
No, non serve per forza avere un sito web o un dominio.
La verifica tramite dominio รจ solo uno dei tre metodi.
Se non hai un sito puoi comunque ottenere la spunta verde usando:
Gravatar โ soluzione semplice per tutti
Keyoxide โ piรน tecnica, basata su OpenPGP
Entrambe permettono la verifica senza possedere un dominio
#MiniReview #VideoGames I gave a fair shot to Pathfinder: Kingmaker (2018) even after realizing it was yet another D20 role-playing game system computer adaptation. While the game is very well produced, it trips the player at every possible turn to ruin the enjoyment.
For more details, I hijacked a thread from @silverwizard to describe the death by a thousand cuts I suffered at the hand of this game before eventually throwing in the towel 25 hours in: friendica.mrpetovan.com/displaโฆ
La Grande Truffa del #greenwashing: Come Ci Manipolano Ogni Giorno
youtube.com/watch?v=9i41aDLsYJโฆ
Le aziende parlano di sostenibilitร piรน di qualunque altra cosa: foglie verdi, packaging โecoโ, slogan dolcissimi e campagne pensate per farci sentire dalla parte giusta. Ma cosa cโรจ davvero dietro questa immagine?
C'รจ la Grande Truffa Verde: unโindagine su come i brand usano la #sostenibilitร come strumento di marketing, spesso senza cambiare nulla nella realtร .
Pubblicato nel gruppo @ambiente@diggita.com
La Grande Truffa dei Brand: Come Ci Manipolano Ogni Giorno
Le aziende parlano di sostenibilitร piรน di qualunque altra cosa: foglie verdi, packaging โecoโ, slogan dolcissimi e campagne pensate per farci sentire dalla ...YouTube
rainews.it/articoli/2025/12/tiโฆ
Time Persona dell'Anno 2025: gli architetti dell'Intelligenza Artificiale
Era previsto e la conferma รจ arrivata. "Qualunque fosse la domanda, AI era la risposta", scrivono i giornalisti della prestigiosa rivista. In copertina "un'immagine che esprime il dualismo prodotto dall'IA: uomo contro macchinaโRedazione di Rainews (RaiNews)
๐ฌ Intensifying attacks on human rights defenders and anti-war voices in #Russia point to a dramatic decline in the countryโs human rights situation and the growing insecurity of a state that fears accountability, a UN expert warned today.
๐ท๐บ๐ข๐ #Russiaโs oil export revenues dropped in November to their lowest monthly level since Moscow invaded Ukraine in 2022, the International Energy Agency said on Thursday.
euractiv.com/news/russian-oil-โฆ
Russian oil export revenue hit lowest level since invading Ukraine
Both volumes and prices have fallen, "dragging export revenues to their lowest since Russia's invasion of Ukraine in February 2022," the International Energy Agency said.Victoria Becker (Euractiv)
๐ท๐บ๐บ๐ธ #Russia's Lukoil favours U.S. bank Xtellus Partners' bid for its global assets over a dozen rival bids, as it takes the form of a cashless deal that would return U.S.-held securities to the Russian oil company, Reuters reports.
reuters.com/business/energy/luโฆ
#usa
๐จ๐พ๐ฒ๐น Discussions on the need to tighten sanctions on #Russia, including the possibility of a blanket ban on providing maritime services, should not be at the expense of legitimate businesses in the industry, key EU shipping nations Cyprus and Malta said.
Hackers have breached โMicord,โ a key developer of Russiaโs unified military registry system. The group responsible says it accessed internal documents, emails, and damaged parts of the infrastructure. The rights group โIdite Lesomโ shared the data, promising to publish the files soon.
Micordโs director confirmed the cyberattack but refused to comment on their role in building the registry. The system, launched in October 2025 and developed by Rostelecom, now supports e-draft notices.
๐ช๐บ๐บ๐ฆ๐ "On 11 December 2025, following the informal meeting of Ministers for European Affairs held in Lviv, we reaffirm our shared commitment to advancing Ukraine's accession to the EU, accelerating key reforms, and we underscore the EU's resolute political, financial, economic, humanitarian, military, and diplomatic support for Ukraine."
ec.europa.eu/commission/presscโฆ
Joint Statement between Commissioner Marta Kos and Deputy Prime Minister of Ukraine Taras Kachka
On 11 December 2025, following the informal meeting of Ministers for European Affairs held in Lviv, we reaffirm our shared commitment to advancing Ukraine\'s accession to the EU, accelerating key reforEuropean Commission - European Commission
โข๏ธ The U.N. General Assembly approved a resolution on Dec. 10 to boost international cooperation and reduce the impact of the Chornobyl nuclear disaster, with 97 countries voting in favor and eight against.
#Russia, Belarus, China, North Korea, and the U.S. voted against the document.
kyivindependent.com/us-sides-wโฆ
US sides with Russia on UN resolution on Chornobyl disaster
Washington's representative said the U.S. voted against the resolution not because it opposed nuclear safety measures, but because it objected to references to the UN's 2030 Agenda for Sustainable Development.Kateryna Denisova (The Kyiv Independent)

Hypolite Petovan
in reply to JP • • •