RE: union.place/@jaythurbershow/11…
This IS a good time to help @jerry for a last-minute...I was GOING to say "tax writeoff," but I honestly don't know whether he's got it set up as a charity or not.
So maybe just a good feeling, at Christmastime 😇
Jay Thurber Show (@jaythurbershow@union.place)
Attached: 1 image Fediverse pals, if your instance is run by a non-profit organization or a volunteer, now is a good time to see if they need a donation.Jay Thurber Show (The Union Place)
Liam Neeson Narrates Anti-Vax, Pro-RFK Documentary
The Taken actor can be heard calling mRNA COVID vaccines “dangerous experiments.”Walker Bragman (Important Context)
Contro la casa di vetro. Opacità, schedatura e potere nell’età digitale. 17° Convegno Nexa su Internet & Società a Torino Lunedì 15 dicembre 2025
Lunedì 15 dicembre 2025
ore 9.00 – 18.00
Sala Conferenze “Luigi Ciminiera”
DAUIN, Politecnico di Torino, 5° piano
Corso Castelfidardo 34/D, Torino (mappa)
Hashtag del convegno: #nexa2025
Per motivi organizzativi, è gradita la segnalazione della propria partecipazione all’indirizzo: Mobilizon
Con @smaurizi @RL @RossellaLatempa @avetro e altri che non sono ancora su mastodon 😅
L’ingresso è libero e gratuito fino ad esaurimento posti.
17° Convegno Nexa su Internet & Società - Nexa Center for Internet & Society
Contro la casa di vetro. Opacità, schedatura e potere nell'età digitale | Lunedì 15 dicembre 2025 | Sala Luigi Ciminiera, DAUIN, Politecnico di TorinoNexa Admin (Nexa Center for Internet & Society)
reshared this
Hello @Raroun hope you're well. every now & then, when i have joined a different #Friendica instance in the past, i ask this same question of its Owners / Admins. always it's the same negative answer, but i live in hope!
on Masto & Sharkey instances, if the Admins are willing, it is technically possible to add FOSS emojis to the servers. consequently, on many of my instances i've been able to include these in various posts when applicable:
:linux: :archlinux: :kde: :plasma: :zenbrowser: :floorp: :firefox_nightly: :firefox: :thunderbird: :fedora: :opensuse: :debian:
so... is there yet any way that such emojis can be added to your instance, please?
cc: @Friendica Support
securityaffairs.com/185593/hac…
#securityaffairs #hacking
Critical Gogs zero-day under attack, 700 servers hacked
Hackers exploited an unpatched Gogs zero-day, allowing remote code execution and compromising around 700 Internet-facing servers.Pierluigi Paganini (Security Affairs)
securityaffairs.com/185574/hac…
#securityaffairs #hacking
GeminiJack zero-click flaw in Gemini Enterprise allowed corporate data exfiltration
Google fixed GeminiJack, a zero-click Gemini Enterprise flaw that could leak corporate data via crafted emails, invites, or documents.Pierluigi Paganini (Security Affairs)
@Random Penguin Capabilities are really flexible, but it would have to be wired in so many parts of the Friendica codebase that it isn't realistic given the (lack of) manpower Friendica enjoys at the moment.
It will have to be a simple flag at first, and then if need arises it could be made more complex.
I would like to have a separated "Moderator" role, but the sad truth is that I guess that I don't have the capacity to add it. There are a lot of things that would be nice to see them being added to Friendica, but my available time is limited. The list of issues on our repository is constantly growing and just maintaining and improving already existing functionality eats up most of my time.
I guess that we will only have this in the system when we find additional coding resources.
"The extremists do not want a two-state solution or a one-state solution. The extremists do not want to give us our state or be part of their state. They want the land without the people. They just want us gone".
Don't miss #EwenMacAskill's reportage from the #WestBank:
theguardian.com/world/2025/dec…
I used to report from the West Bank. Twenty years after my last visit, I was shocked by how much worse it is today
The long read: Among the many people I met, there was a pervasive feeling of hopelessness and a sense that resistance is slowly becoming a memoryEwen MacAskill (The Guardian)
en.wikipedia.org/wiki/Lunch_at…
it's fairly boring abstract interpretation, but the qemu jit optimizer/middle end does it. It has a known bits abstract domain and reasons about signed ranges (but rounded up to nearest power of two). Code is here: github.com/qemu/qemu/blob/mast…
Why do you ask?
qemu/tcg/optimize.c at master · qemu/qemu
Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are ignored. Please only use release tarballs from the QEMU website. - qemu/qemuGitHub
ah, you work on compcert, super cool!
I'm moving in the opposite direction. I've worked on JIT compilers for ages and have started to become more interested in pragmatic approaches for verifying parts of them. would you be interested in setting up a call some time next year?
MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25
cwe.mitre.org/top25/archive/20…
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.cwe.mitre.org
Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.or…
This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbers…
Notepad++ v8.8.9: Vulnerability-fix
Notepad++ release 8.8.9 is available: https://notepad-plus-plus.org/news/v889-released/ Notepad++ v8.8.9 new security enhancement, new features, regression f...Community
Ambient Music: Satie, Eno, Cage and the Ignorable
This philosophical deep dive explores ambient music, a genre defined by the paradox that it uniquely asks the listener not to listen to it actively. The core...YouTube
monumental-movement-records reshared this.
Dietro Has Fidanken, l’eroe di Drive In che non poteva sbagliare
Come è nato Has Fidanken: l'assurdo genius dell'immobilità. Aneddoti, il generale paracadutista, gli autori di Drive In e il tormentone che fece ridere l'Italia.
this is an experimental quote-share from my #Friendica #newsbots #Circle, whose default Permissions disallow anyone outside this Circle being able to see or access it. i have now done a one-off flip of the Permissions, just for this individual post, to Public, so...
Hello? (Hello, hello, hello)
Is there anybody in there?
Just nod if you can hear me
Is there anyone home?
Come on (Come on, come on), now
I hear you're feeling down
Well, I can ease your pain
And get you on your feet again
Relax (Relax, relax, relax)
I'll need some information first
Just the basic facts
Can you show me where it hurts?
♲ Unofficial SBS News Bot - 2025-12-11 20:24:04 GMT
Time magazine names 'Architects of AI' as Person of the Year. Here's who's pictured sbs.com.au/news/article/time-m… #World
🔥 Mastodon NON è il Fediverso
Mastodon concentra oltre il 70% degli utenti e rischia di sembrare l’unica cosa che conti.
Ma il Fediverso è infinitamente più grande, ricco e variegato, c'è chi:
🎬 crea video
📸 condivide immagini
🎙️ produce podcast
📚 pubblica libri
🚴 traccia percorsi in bici
e molto altro.
Ridurre tutto a Mastodon significa limitare la nostra visione ma per conoscere gli altri progetti si può seguire:
👉 La lista di account: fedidevs.com/s/Nzcz/
👉 Il gruppo: @fediverso
«I am proud to be a European citizen. 🇪🇺
A united, democratic and free Europe is our future.
Let’s protect it together.»
#Europe #EuropeanUnion #EuropeanCitizen #UnitedEurope #EUvalues #Democracy #HumanRights #Freedom #Unity #EuropeTogether #FutureOfEurope
Per cortesia, causa crash della istanza, se mi seguite da una istanza friendica su @luca
potreste fare unfollow / follow ?
mi vengono in mente
@informapirata@poliverso.org @informapirata
@simona @lapo
ma ce ne saranno sicuramente altri
Se stai programmando una vacanza negli USA, controlla i tuoi post sui social anche vecchi di 5 anni
Gli USA vogliono rendere obbligatorio l'accesso ai profili social per i visitatori europei prima di farli entrare alla frontiera. A meno che non siano milionariRiccardo Piccolo (Wired Italia)
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle
Da quando diversi fondatori e amministratori delegati delle grandi aziende tecnologiche hanno sposato l’agenda politica dell’amministrazione Trump, il governo degli Stati Uniti si è esposto in prima linea per difendere gli interessi di queste aziende.
valigiablu.it/big-tech-lobby-u…
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle - Valigia Blu
Le Big Tech stanno diventando un potere politico globale, capace di influenzare governi e bloccare leggi che limitano i loro profitti e modelli di business. Un’inchiesta internazionale ha documentato quasi 3.Valigia Blu
reshared this
IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE.
@Informatica (Italy e non Italy 😁)
Nel gennaio 1945 il SIM mutò la denominazione in “Ufficio Informazioni dello Stato Maggiore Generale” ma la struttura rimase pressoché invariata.
L'articolo IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE. proviene da GIANO NEWS.
#DIFESA
securityaffairs.com/185566/hac…
#securityaffairs #hacking
Google fixed a new actively exploited Chrome zero-day
Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild.Pierluigi Paganini (Security Affairs)
Yes that's the charme of it, just like the player character you are thrown into this strange, brutal world and have to figure out how to survive. The beginning is difficult, but that makes it all the more satisfying later in the game when you actually become powerful.
Regarding mods, you should definitely get one for improved inventory, and there's also a DirectX 11 mod for better graphics.
682/730
When we bought our new olive oil, I knew immediately that I had to do something with it.
📷 Fujifilm XT-5
#fujiFilm #fuji #photography #fotografie #730Project #dailyPhoto #obxPhoto #stillLife
Mi trovo a dover scrivere la 'letterina' a Babbo Natale e, oltre alla pace del mondo (mai ricevuta), di solito chiedo sempre almeno un libro.
Quest'anno ho seguito poco le novità e quindi ti chiedo: titoli interessanti e originali del 2025, magari di genere fantastico, weird, o (se proprio butta male) saggistica?
(titoli facili da trovare, altrimenti non ricevo niente)
Grazie!
Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)
pushsecurity.com/blog/consentf…
ConsentFix: Browser-native ClickFix hijacks OAuth grants
Analysing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.Luke Jennings (Push Security)
Google is rolling out a new feature for Android users that will let them share live video with emergency services.
The new feature is being rolled out in the US and some regions in Mexico and Germany.
It will be available for Android 8 (2017) devices or higher
blog.google/products/android/e…
Share live video with emergency services to get the help you need
During an emergency call or text, a dispatcher can send a request to your Android phone to share live video.Alastair Breeze (Google)
RE: mastodon.social/@campuscodi/11…
More research of this type
Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202…
Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-…
It’s 2 AM. Do You Know Which AIs Your MCP Server Is Talking To?
Bitsight TRACE research team found roughly 1,000 exposed MCP servers with no authorization in place, revealing new AI vulnerabilities. Read the report now.João Cruz (BitSight)
Piccolo gioiello che sto sentendo in questi giorni dei favolosi #Frost (super)gruppo #Prog
Dobbiamo pensare di vivere ogni momento, come se fosse l'ultimo, senza paura, con coraggio e leggerezza
youtube.com/watch?v=hQjvSda3po…
[Verse]The air is warming up again
The summer sounds are like old friends
I see the sunlight through the trees
I wonder if the sun can see me?
[Pre-Chorus]
I hear the echoes of those days
Reflecting back at me in waves
Carved into
1/2
CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates
security.googleblog.com/2025/1…
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...Google Online Security Blog
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
📌 Link all'articolo : redhotcyber.com/post/700-000-r…
Un nuovo allarme arriva dal sottobosco del cybercrime arriva poche ore fa. A segnalarlo l’azienda ParagonSec, società specializzata nel #monitoraggio delle #attività delle cyber gang e dei marketplace clandestini, che ha riportato la comparsa su un #forum #underground di un presunto #database contenente oltre 700.000 record #appartenenti ad un Registro Professionale Italiano.
A cura di Redazione RHC
#redhotcyber #news #cybersecurity #hacking #malware #database #registroprofessionale #nazionalitaliano #sicurezzainformatica #protezionedatidipersonali #databreach #furtodidati #informazionisensibili #violazione sicurezza
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
Un database con 700.000 record di un Registro Professionale Italiano è in vendita su un forum underground, con informazioni sensibili e dati personali.Redazione RHC (Red Hot Cyber)
UK ICO fines LastPass £1.2m for 2022 data breach
ico.org.uk/about-the-ico/media…
Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK
The Information Commissioner’s Office (ICO) has fined password manager provider LastPass UK Ltd £1.2 million following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users.ico.org.uk
Osservare, immaginare, aspettare; l'atto di scattare è puramente marginale.
Hébé ç'a été long.
Longtemps au début pour deviner de qui deux indices ne parlaient PAS mais disaient quelque chose ; et oubli de compter Will, me demande pas comment, il s'est mis derrière un autre je sais pas.
@SiestⒶcorta Bien joué ! Pour moi il y avait beaucoup trop de 50/50 qui allaient dans tous les sens. 😵💫
Clues by Sam - Dec 11th 2025 (Tricky)
Less than 10 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
Vulnerabilità zero-day in Chrome: Google rilascia una patch urgente, installiamola subito
@Informatica (Italy e non Italy 😁)
Google ha rilasciato un aggiornamento urgente per Chrome a causa di un bug zero-day sfruttato attivamente. L’analisi esplora le implicazioni per le aziende e gli utenti, fornendo consigli pratici per proteggersi e mitigare i rischi
Winston Churchill, la scuola non era fatta per lui
🛑I fallimenti di un giovane troppo brillante👇
boomerissimo.it/2024/05/27/win…
Winston Churchill somaro: troppo geniale per una scuola normale - Boomerissimo
Winston Churchill è stato un gigante del suo tempo ma uno scolaro fallimentare. Aveva un problema che nemmeno la scuola moderna è riuscita a superare.Antonio Pintér (Boomerissimo)
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
📌 Link all'articolo : redhotcyber.com/post/netsuppor…
#redhotcyber #news #cybersecurity #hacking #malware #ransomware #netSupportRAT #javascript
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
Gli specialisti di Securonix hanno scoperto una campagna malware multilivello per installare NetSupport RAT. L'attacco si sviluppa attraverso fasi nascoste per garantire massima discrezione.Redazione RHC (Red Hot Cyber)
This single mom is squeezed by LA’s cost of living. Now she’s running for mayor.
https://19thnews.org/2025/12/rae-huang-la-mayor-campaign/?utm_source=flipboard&utm_medium=activitypub
Posted into The 19th @the-19th-19thnews
Rae Huang struggled with LA's affordability. Now she's running for mayor.
Progressive housing advocate and single mom Rae Huang is challenging Karen Bass for Los Angeles mayor, promising free transit and social housing.Jireh Deng, LA Public Press (19th News)
Looks like Twitter finally took down the NoName057 account after yesterday's indictment
Terremoto? No, AI-Fake! Un’immagine generata dall’IA paralizza i treni britannici
📌 Link all'articolo : redhotcyber.com/post/terremoto…
#redhotcyber #news #intelligenzaartificiale #rete neurale #cybersecurity #sicurezzainformatica #treni #trasporti
Terremoto? No, AI-Fake! Un’immagine generata dall’IA paralizza i treni britannici
Treni sospesi in Inghilterra per un'immagine falsa di un ponte danneggiato generata da una rete neurale.Redazione RHC (Red Hot Cyber)
This is what our cats do when they want their dinner now. Both of them come down to my cabin where I work, sit on the decking outside and stare at me until I feed them.
Hustlers. The pair of them.
SOAPwn -- new bugs that can lead to RCE in .NET apps
Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more
Microsoft did not fix them
labs.watchtowr.com/soapwn-pwni…
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee.Piotr Bazydlo (@chudyPB) (watchTowr Labs)
The EU aims to agree by Friday on a long-term freeze of Russian central bank assets, a major legal shift that would remove the need to renew the freeze every six months. This would block veto threats from Hungary or Slovakia and pave the way for using the €210B as collateral for loans to Ukraine.
Belgium, holding €185B, remains cautious due to legal risks, but the EU is preparing guarantees to protect it from Russian lawsuits.
Ukraine’s defense industry is working to localize S-300 and S-400 missile production with the goal of integrating them with European radar systems, Fire Point’s chief designer Denys Shtylerman told the BBC. The company has already cloned key components and plans to begin engine tests in January 2026.
Until full integration is possible, the FP-7 is being used as a short-range ballistic missile with a 200 km range. The longer-range FP-9, reaching up to 855 km, is also in development.
During a meeting with military leadership, Putin claimed that Russian forces hold the strategic initiative and ordered the continuation of combat operations “according to plan.” Gerasimov reported advances in Sumy and near Vovchansk, control over parts of Kostyantynivka, and the capture of Kurylivka, Kucherivka, and Siversk. Putin praised the army’s performance and said progress in Donbas and “Novorossiya” is on track.
🤷♂️
Ukraine’s General Staff confirms it's streamlining transfers between units by shifting to a fully electronic system. Requests now go directly to HQ, cutting out lower-level approvals and reducing manipulation.
But the key message: self-inflicted absences (СЗЧ) won't help soldiers transfer to preferred units. All returns from СЗЧ go to combat brigades in need, including Air Assault and assault forces.
Dictator playbook 101.
Bloomberg reports Viktor Orbán is preparing for life after the April 2026 election by planning a power grab through the presidency. Orbán is exploring how to rewrite laws to turn Hungary’s ceremonial presidential role into the most powerful office in the country. Fidesz has already passed a law making it harder to remove the president, and insiders say Orbán is considering using his supermajority to push through constitutional changes before the vote.
NEW: Right-wing messaging app Freedom Chat had security flaws that allowed a researcher to guess all numbers registered on the platform, and one that exposed user PINs to other users.
The researcher enumerated around 2,000 phone numbers.
techcrunch.com/2025/12/11/secu…
Security flaws in Freedom Chat app exposed users' phone numbers and PINs | TechCrunch
The founder of Freedom Chat said the company has reset user PINs and released a new version to app stores.Zack Whittaker (TechCrunch)

Giulio Cesare Solaroli
in reply to quinta - Stefano Quintarelli • • •quinta - Stefano Quintarelli
in reply to Giulio Cesare Solaroli • • •Giulio Cesare Solaroli
in reply to quinta - Stefano Quintarelli • • •Quindi il vantaggio che i motori di ricerca avevano (informazioni sulla “qualità” delle fonti) tenderà a svanire man mano che gli utenti smetteranno di dare il loro feedback, perché portati ad usare i prompt.
Giulio Cesare Solaroli
in reply to Giulio Cesare Solaroli • • •quinta - Stefano Quintarelli
in reply to Giulio Cesare Solaroli • • •GaMe
in reply to quinta - Stefano Quintarelli • • •Ma non è detto che questo aiuti per contrastare il poisoning
quinta - Stefano Quintarelli
in reply to GaMe • • •