Life in Kharkiv continues amid the sounds of nearby explosions, a grim hallmark of russia's war against #Ukraine where children are growing accustomed to blasts as the backdrop of their daily routines. 💔
📽️: labsmystar
United 24 Media / Instagram
reshared this
#EU leaders to push defense readiness amid russia 'hybrid attack' warnings
by Gabriel Gavin
Shared capabilities and funding for #Ukraine will be top of the agenda for next week's European Council summit.
politico.eu/article/eu-leaders…
EU leaders to push defense readiness amid Russia ‘hybrid attack’ warnings
Shared capabilities and funding for Ukraine will be top of the agenda for next week’s European Council summit.Gabriel Gavin (POLITICO)
reshared this
Address by the President #Zelenskyy to the Participants of the Meeting of the Coalition of the Willing
reshared this
Ukrainian Team Led by the President #Zelenskyy Held a Conversation with the U.S. Side on the Security Guarantees Document
reshared this
B4Ukraine, a coalition of 100 civil society groups, insists peace in #Ukraine must prioritize human rights, justice, and full restoration of Ukraine’s sovereignty -rejecting territorial concessions, demanding russian troop withdrawal, and ensuring accountability for war crimes.
True peace requires defunding russia’s war economy and involving Ukraine and Europe in negotiations as equals.
Read more here 📎 b4ukraine.org/whats-new/positi…
B4Ukraine Position on Human-Centred, Just Peace Negotiations
B4Ukraine reaffirms that the only meaningful path to peace is one that protects people, upholds justice, and restores Ukraine’s sovereignty and territorial integrity.Business For Ukraine (B4Ukraine)
reshared this
US wants #Ukraine to withdraw from Donbas and create ‘free economic zone’, says #Zelenskyy
by Shaun Walker (in Kyiv)
Ukrainian president says plan would not be fair without guarantees that russia would not simply take over zone
theguardian.com/world/2025/dec…
US wants Ukraine to withdraw from Donbas and create ‘free economic zone’, says Zelenskyy
Ukrainian president says plan would not be fair without guarantees that Russia would not simply take over zoneShaun Walker (The Guardian)
reshared this
1/6
President #Zelenskyy
💬 "Today, we had a constructive and in-depth discussion with the American team on one of the three documents we are currently working on – security guarantees. Representing the United States were Marco Rubio, Pete Hagseth, Steve Witkoff, Jared Kushner,
reshared this
5/6
Therefore, it is now important that this document on security guarantees provides specific answers to what concerns Ukrainians most: what actions will our partners take if russia decides to renew its aggression.
reshared this
6/6
We have agreed that the teams will work actively to ensure that there is a concrete understanding of security guarantees in the near future. Thank you to everyone who is helping"
reshared this
#EU Finds Workaround for Hungary’s Veto, Moving #Ukraine Closer to EU Membership
At an informal meeting of the EU General Affairs Council, a new format for technical negotiations with Ukraine was announced, bypassing the Hungarian veto. This announcement was made by Danish Minister for EU Affairs, Marri Bjerre, and EU Commissioner for Enlargement, Marta Kos
united24media.com/latest-news/…
EU Finds Workaround for Hungary’s Veto, Moving Ukraine Closer to EU Membership
A new technical negotiation format for Ukraine’s EU accession has been announced, bypassing Hungary's veto, ensuring continued reform progress.Cyril Barabaltchouk (UNITED24 Media)
reshared this
#Zelenskyy: Peace Plan Must Include Equal Withdrawals and Clear Governance
Zelenskyy said that the US proposal for a compromise regarding Donetsk contains a number of unresolved questions and does not align with Ukraine’s interests.
united24media.com/latest-news/…
Zelenskyy: Peace Plan Must Include Equal Withdrawals and Clear Governance
President Zelenskyy critiques the US compromise on Donetsk, highlighting unanswered questions and urging equitable troop withdrawal for Ukraine's interests.Dariia Mykhailenko (UNITED24 Media)
reshared this
RE: infosec.exchange/@catsalad/115…
I wonder what happens if I quote your toot and you edit yours to quote mine. 
Cat 🐈🥗 (D.Burch) :blobcatrainbow: (@catsalad@infosec.exchange)
Hey @cR0w, I heard if you post, quote that post, then edit the first to quote the second it does this: :aneobot_explode:Cat 🐈🥗 (D.Burch) :blobcatrainbow: (Infosec Exchange)
Months ago I got a nut milk maker.
"I don't remember being drunk enough to buy this."
Put it away.
Today, pick up box - curious. Look at label. It's my neighbor's lol.
The advantage of December birthday is that you can beg your parents for one really expensive present, instead of separate birthday and Christmas presents like normal.
The disadvantage is shit's only festive once per year and they're both sort of diluted.
Ma non è detto che questo aiuti per contrastare il poisoning
RE: union.place/@jaythurbershow/11…
This IS a good time to help @jerry for a last-minute...I was GOING to say "tax writeoff," but I honestly don't know whether he's got it set up as a charity or not.
So maybe just a good feeling, at Christmastime 😇
Jay Thurber Show (@jaythurbershow@union.place)
Attached: 1 image Fediverse pals, if your instance is run by a non-profit organization or a volunteer, now is a good time to see if they need a donation.Jay Thurber Show (The Union Place)
Liam Neeson Narrates Anti-Vax, Pro-RFK Documentary
The Taken actor can be heard calling mRNA COVID vaccines “dangerous experiments.”Walker Bragman (Important Context)
Contro la casa di vetro. Opacità, schedatura e potere nell’età digitale. 17° Convegno Nexa su Internet & Società a Torino Lunedì 15 dicembre 2025
Lunedì 15 dicembre 2025
ore 9.00 – 18.00
Sala Conferenze “Luigi Ciminiera”
DAUIN, Politecnico di Torino, 5° piano
Corso Castelfidardo 34/D, Torino (mappa)
Hashtag del convegno: #nexa2025
Per motivi organizzativi, è gradita la segnalazione della propria partecipazione all’indirizzo: Mobilizon
Con @smaurizi @RL @RossellaLatempa @avetro e altri che non sono ancora su mastodon 😅
L’ingresso è libero e gratuito fino ad esaurimento posti.
17° Convegno Nexa su Internet & Società - Nexa Center for Internet & Society
Contro la casa di vetro. Opacità, schedatura e potere nell'età digitale | Lunedì 15 dicembre 2025 | Sala Luigi Ciminiera, DAUIN, Politecnico di TorinoNexa Admin (Nexa Center for Internet & Society)
reshared this
Hello @Raroun hope you're well. every now & then, when i have joined a different #Friendica instance in the past, i ask this same question of its Owners / Admins. always it's the same negative answer, but i live in hope!
on Masto & Sharkey instances, if the Admins are willing, it is technically possible to add FOSS emojis to the servers. consequently, on many of my instances i've been able to include these in various posts when applicable:
:linux: :archlinux: :kde: :plasma: :zenbrowser: :floorp: :firefox_nightly: :firefox: :thunderbird: :fedora: :opensuse: :debian:
so... is there yet any way that such emojis can be added to your instance, please?
cc: @Friendica Support
securityaffairs.com/185593/hac…
#securityaffairs #hacking
Critical Gogs zero-day under attack, 700 servers hacked
Hackers exploited an unpatched Gogs zero-day, allowing remote code execution and compromising around 700 Internet-facing servers.Pierluigi Paganini (Security Affairs)
securityaffairs.com/185574/hac…
#securityaffairs #hacking
GeminiJack zero-click flaw in Gemini Enterprise allowed corporate data exfiltration
Google fixed GeminiJack, a zero-click Gemini Enterprise flaw that could leak corporate data via crafted emails, invites, or documents.Pierluigi Paganini (Security Affairs)
@Random Penguin Capabilities are really flexible, but it would have to be wired in so many parts of the Friendica codebase that it isn't realistic given the (lack of) manpower Friendica enjoys at the moment.
It will have to be a simple flag at first, and then if need arises it could be made more complex.
I would like to have a separated "Moderator" role, but the sad truth is that I guess that I don't have the capacity to add it. There are a lot of things that would be nice to see them being added to Friendica, but my available time is limited. The list of issues on our repository is constantly growing and just maintaining and improving already existing functionality eats up most of my time.
I guess that we will only have this in the system when we find additional coding resources.
"The extremists do not want a two-state solution or a one-state solution. The extremists do not want to give us our state or be part of their state. They want the land without the people. They just want us gone".
Don't miss #EwenMacAskill's reportage from the #WestBank:
theguardian.com/world/2025/dec…
I used to report from the West Bank. Twenty years after my last visit, I was shocked by how much worse it is today
The long read: Among the many people I met, there was a pervasive feeling of hopelessness and a sense that resistance is slowly becoming a memoryEwen MacAskill (The Guardian)
en.wikipedia.org/wiki/Lunch_at…
it's fairly boring abstract interpretation, but the qemu jit optimizer/middle end does it. It has a known bits abstract domain and reasons about signed ranges (but rounded up to nearest power of two). Code is here: github.com/qemu/qemu/blob/mast…
Why do you ask?
qemu/tcg/optimize.c at master · qemu/qemu
Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are ignored. Please only use release tarballs from the QEMU website. - qemu/qemuGitHub
ah, you work on compcert, super cool!
I'm moving in the opposite direction. I've worked on JIT compilers for ages and have started to become more interested in pragmatic approaches for verifying parts of them. would you be interested in setting up a call some time next year?
MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25
cwe.mitre.org/top25/archive/20…
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.cwe.mitre.org
Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.or…
This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbers…
Notepad++ v8.8.9: Vulnerability-fix
Notepad++ release 8.8.9 is available: https://notepad-plus-plus.org/news/v889-released/ Notepad++ v8.8.9 new security enhancement, new features, regression f...Community
Ambient Music: Satie, Eno, Cage and the Ignorable
This philosophical deep dive explores ambient music, a genre defined by the paradox that it uniquely asks the listener not to listen to it actively. The core...YouTube
monumental-movement-records reshared this.
Dietro Has Fidanken, l’eroe di Drive In che non poteva sbagliare
Come è nato Has Fidanken: l'assurdo genius dell'immobilità. Aneddoti, il generale paracadutista, gli autori di Drive In e il tormentone che fece ridere l'Italia.
this is an experimental quote-share from my #Friendica #newsbots #Circle, whose default Permissions disallow anyone outside this Circle being able to see or access it. i have now done a one-off flip of the Permissions, just for this individual post, to Public, so...
Hello? (Hello, hello, hello)
Is there anybody in there?
Just nod if you can hear me
Is there anyone home?
Come on (Come on, come on), now
I hear you're feeling down
Well, I can ease your pain
And get you on your feet again
Relax (Relax, relax, relax)
I'll need some information first
Just the basic facts
Can you show me where it hurts?
♲ Unofficial SBS News Bot - 2025-12-11 20:24:04 GMT
Time magazine names 'Architects of AI' as Person of the Year. Here's who's pictured sbs.com.au/news/article/time-m… #World
🔥 Mastodon NON è il Fediverso
Mastodon concentra oltre il 70% degli utenti e rischia di sembrare l’unica cosa che conti.
Ma il Fediverso è infinitamente più grande, ricco e variegato, c'è chi:
🎬 crea video
📸 condivide immagini
🎙️ produce podcast
📚 pubblica libri
🚴 traccia percorsi in bici
e molto altro.
Ridurre tutto a Mastodon significa limitare la nostra visione ma per conoscere gli altri progetti si può seguire:
👉 La lista di account: fedidevs.com/s/Nzcz/
👉 Il gruppo: @fediverso
«I am proud to be a European citizen. 🇪🇺
A united, democratic and free Europe is our future.
Let’s protect it together.»
#Europe #EuropeanUnion #EuropeanCitizen #UnitedEurope #EUvalues #Democracy #HumanRights #Freedom #Unity #EuropeTogether #FutureOfEurope
Per cortesia, causa crash della istanza, se mi seguite da una istanza friendica su @luca
potreste fare unfollow / follow ?
mi vengono in mente
@informapirata@poliverso.org @informapirata
@simona @lapo
ma ce ne saranno sicuramente altri
Se stai programmando una vacanza negli USA, controlla i tuoi post sui social anche vecchi di 5 anni
Gli USA vogliono rendere obbligatorio l'accesso ai profili social per i visitatori europei prima di farli entrare alla frontiera. A meno che non siano milionariRiccardo Piccolo (Wired Italia)
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle
Da quando diversi fondatori e amministratori delegati delle grandi aziende tecnologiche hanno sposato l’agenda politica dell’amministrazione Trump, il governo degli Stati Uniti si è esposto in prima linea per difendere gli interessi di queste aziende.
valigiablu.it/big-tech-lobby-u…
Come le big tech influenzano i governi per bloccare le leggi che dovrebbero regolamentarle - Valigia Blu
Le Big Tech stanno diventando un potere politico globale, capace di influenzare governi e bloccare leggi che limitano i loro profitti e modelli di business. Un’inchiesta internazionale ha documentato quasi 3.Valigia Blu
reshared this
IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE.
@Informatica (Italy e non Italy 😁)
Nel gennaio 1945 il SIM mutò la denominazione in “Ufficio Informazioni dello Stato Maggiore Generale” ma la struttura rimase pressoché invariata.
L'articolo IL DOPOGUERRA SINO AL SERVIZIO INFORMAZIONI DIFESA (SID). PRIMA PARTE. proviene da GIANO NEWS.
#DIFESA
securityaffairs.com/185566/hac…
#securityaffairs #hacking
Google fixed a new actively exploited Chrome zero-day
Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild.Pierluigi Paganini (Security Affairs)
Yes that's the charme of it, just like the player character you are thrown into this strange, brutal world and have to figure out how to survive. The beginning is difficult, but that makes it all the more satisfying later in the game when you actually become powerful.
Regarding mods, you should definitely get one for improved inventory, and there's also a DirectX 11 mod for better graphics.
682/730
When we bought our new olive oil, I knew immediately that I had to do something with it.
📷 Fujifilm XT-5
#fujiFilm #fuji #photography #fotografie #730Project #dailyPhoto #obxPhoto #stillLife
Mi trovo a dover scrivere la 'letterina' a Babbo Natale e, oltre alla pace del mondo (mai ricevuta), di solito chiedo sempre almeno un libro.
Quest'anno ho seguito poco le novità e quindi ti chiedo: titoli interessanti e originali del 2025, magari di genere fantastico, weird, o (se proprio butta male) saggistica?
(titoli facili da trovare, altrimenti non ricevo niente)
Grazie!
Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)
pushsecurity.com/blog/consentf…
ConsentFix: Browser-native ClickFix hijacks OAuth grants
Analysing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.Luke Jennings (Push Security)
Google is rolling out a new feature for Android users that will let them share live video with emergency services.
The new feature is being rolled out in the US and some regions in Mexico and Germany.
It will be available for Android 8 (2017) devices or higher
blog.google/products/android/e…
Share live video with emergency services to get the help you need
During an emergency call or text, a dispatcher can send a request to your Android phone to share live video.Alastair Breeze (Google)
RE: mastodon.social/@campuscodi/11…
More research of this type
Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202…
Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-…
It’s 2 AM. Do You Know Which AIs Your MCP Server Is Talking To?
Bitsight TRACE research team found roughly 1,000 exposed MCP servers with no authorization in place, revealing new AI vulnerabilities. Read the report now.João Cruz (BitSight)
Piccolo gioiello che sto sentendo in questi giorni dei favolosi #Frost (super)gruppo #Prog
Dobbiamo pensare di vivere ogni momento, come se fosse l'ultimo, senza paura, con coraggio e leggerezza
youtube.com/watch?v=hQjvSda3po…
[Verse]The air is warming up again
The summer sounds are like old friends
I see the sunlight through the trees
I wonder if the sun can see me?
[Pre-Chorus]
I hear the echoes of those days
Reflecting back at me in waves
Carved into
1/2
CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates
security.googleblog.com/2025/1…
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...Google Online Security Blog
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
📌 Link all'articolo : redhotcyber.com/post/700-000-r…
Un nuovo allarme arriva dal sottobosco del cybercrime arriva poche ore fa. A segnalarlo l’azienda ParagonSec, società specializzata nel #monitoraggio delle #attività delle cyber gang e dei marketplace clandestini, che ha riportato la comparsa su un #forum #underground di un presunto #database contenente oltre 700.000 record #appartenenti ad un Registro Professionale Italiano.
A cura di Redazione RHC
#redhotcyber #news #cybersecurity #hacking #malware #database #registroprofessionale #nazionalitaliano #sicurezzainformatica #protezionedatidipersonali #databreach #furtodidati #informazionisensibili #violazione sicurezza
700.000 record di un Registro Professionale Italiano in vendita nel Dark Web
Un database con 700.000 record di un Registro Professionale Italiano è in vendita su un forum underground, con informazioni sensibili e dati personali.Redazione RHC (Red Hot Cyber)
UK ICO fines LastPass £1.2m for 2022 data breach
ico.org.uk/about-the-ico/media…
Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK
The Information Commissioner’s Office (ICO) has fined password manager provider LastPass UK Ltd £1.2 million following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users.ico.org.uk
Osservare, immaginare, aspettare; l'atto di scattare è puramente marginale.
Hébé ç'a été long.
Longtemps au début pour deviner de qui deux indices ne parlaient PAS mais disaient quelque chose ; et oubli de compter Will, me demande pas comment, il s'est mis derrière un autre je sais pas.
@SiestⒶcorta Bien joué ! Pour moi il y avait beaucoup trop de 50/50 qui allaient dans tous les sens. 😵💫
Clues by Sam - Dec 11th 2025 (Tricky)
Less than 10 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
Vulnerabilità zero-day in Chrome: Google rilascia una patch urgente, installiamola subito
@Informatica (Italy e non Italy 😁)
Google ha rilasciato un aggiornamento urgente per Chrome a causa di un bug zero-day sfruttato attivamente. L’analisi esplora le implicazioni per le aziende e gli utenti, fornendo consigli pratici per proteggersi e mitigare i rischi
Winston Churchill, la scuola non era fatta per lui
🛑I fallimenti di un giovane troppo brillante👇
boomerissimo.it/2024/05/27/win…
Winston Churchill somaro: troppo geniale per una scuola normale - Boomerissimo
Winston Churchill è stato un gigante del suo tempo ma uno scolaro fallimentare. Aveva un problema che nemmeno la scuola moderna è riuscita a superare.Antonio Pintér (Boomerissimo)
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
📌 Link all'articolo : redhotcyber.com/post/netsuppor…
#redhotcyber #news #cybersecurity #hacking #malware #ransomware #netSupportRAT #javascript
NetSupport RAT: il malware invisibile che gli antivirus non possono fermare
Gli specialisti di Securonix hanno scoperto una campagna malware multilivello per installare NetSupport RAT. L'attacco si sviluppa attraverso fasi nascoste per garantire massima discrezione.Redazione RHC (Red Hot Cyber)
This single mom is squeezed by LA’s cost of living. Now she’s running for mayor.
https://19thnews.org/2025/12/rae-huang-la-mayor-campaign/?utm_source=flipboard&utm_medium=activitypub
Posted into The 19th @the-19th-19thnews
Rae Huang struggled with LA's affordability. Now she's running for mayor.
Progressive housing advocate and single mom Rae Huang is challenging Karen Bass for Los Angeles mayor, promising free transit and social housing.Jireh Deng, LA Public Press (19th News)
Looks like Twitter finally took down the NoName057 account after yesterday's indictment
Terremoto? No, AI-Fake! Un’immagine generata dall’IA paralizza i treni britannici
📌 Link all'articolo : redhotcyber.com/post/terremoto…
#redhotcyber #news #intelligenzaartificiale #rete neurale #cybersecurity #sicurezzainformatica #treni #trasporti
Terremoto? No, AI-Fake! Un’immagine generata dall’IA paralizza i treni britannici
Treni sospesi in Inghilterra per un'immagine falsa di un ponte danneggiato generata da una rete neurale.Redazione RHC (Red Hot Cyber)
This is what our cats do when they want their dinner now. Both of them come down to my cabin where I work, sit on the decking outside and stare at me until I feed them.
Hustlers. The pair of them.
SOAPwn -- new bugs that can lead to RCE in .NET apps
Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more
Microsoft did not fix them
labs.watchtowr.com/soapwn-pwni…
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee.Piotr Bazydlo (@chudyPB) (watchTowr Labs)

Eugene McParland 🇺🇦
in reply to Eugene McParland 🇺🇦 • • •2/3
and it is important that the United States is with us and supports us. No one is interested in a third russian invasion. And now, defence support for Ukraine is especially important because russia is not stopping its attacks,
reshared this
PTN PNH ☮️ 🇺🇦 🇮🇱 reshared this.
Eugene McParland 🇺🇦
in reply to Eugene McParland 🇺🇦 • • •3/3
and there must be more protection of life so that diplomacy can work towards a just peace.
Thank you to everyone who is helping."
reshared this
PTN PNH ☮️ 🇺🇦 🇮🇱 reshared this.