Q: Why do people use Photoshop instead of GIMP?
A: Trying to put a text on a picture with GIMP:

#gimp #bug #buggy #ux #badux #linux #unreliable #defective #os #opensource #oss #opensourcesoftware

Grafana Breach Exposes Codebase, Sparks Extortion Attempt

Grafana recently experienced a security breach, where an unauthorized party gained access to its GitHub environment, downloading its codebase, but fortunately, no customer data or personal info was compromised. The company swiftly responded, taking measures to prevent further unauthorized access and thwarting an attempted extortion…

https://osintsights.com/grafana-breach-exposes-codebase-sparks-extortion-attempt?utm_source=mastodon&utm_medium=social

#Grafana #CodebaseBreach #ExtortionAttempt #EmergingThreats #OpenSourceSoftware

Grafana Breach Exposes Codebase, Sparks Extortion Attempt

Learn about the Grafana breach that exposed its codebase and sparked an extortion attempt, and find out what measures the company took to respond and prevent future incidents - read now.

OSINTSights

ChatGPT su Mac, attacco hacker a OpenAI: ecco cosa fare ora
#openai ha confermato la compromissione di due dispositivi aziendali a causa di una libreria #opensource manomessa, ed è corsa subito ai ripari con un aggiornamento urgente per Mac. Qualcuno l’ha compromessa, e da lì l’infezione ha raggiunto due dispositivi usati da dipendenti di OpenAI, creando un punto d’accesso ai repository interni dell’azienda.

#mac #macos #opensourcesoftware #chatgpt

#attaccohacker

https://www.punto-informatico.it/chatgpt-mac-attacco-hacker-openaiecco-cosa-fare-ora/

ChatGPT su Mac, attacco hacker a OpenAI: ecco cosa fare ora

Un attacco hacker ha colpito due Mac di OpenAI. L'app ChatGPT per Mac riceverà un aggiornamento entro il 12 giugno.

Punto Informatico
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages

Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions issued GITHUB_TOKENs or GitHub App installation tokens to the GitHub Actions logs. GitHub introduced a

Private Packagist

Editorial Opportunity at the Journal of Open Source Software

The Journal of Open Source Software – known to its friends as JOSS – is is a developer friendly, diamond open access journal for research software packages which has been running since 2016 and is enormously successful, publishing Open Source software across many fields of science. Its UR, joss.theoj.org, is a giveaway that it is a stablemate of astro.theoj.org, aka the Open Journal of Astrophysics.

The driving force behind JOSS, responsible for getting it off the ground at the very beginning, is Arfon Smith whom I’ve known since Nottingham days and it iis fair to say that without his considerable help, OJAp would never have started. Both journals started off as speculative ventures, and OJAp has taken a considerable time to establish itself, but JOSS took off very quickly indeed and has now published over 3,500 papers. There are numerous differences between the two journals but, like OJAp, all publications in JOSS are free to authors and readers.

Arfon has held the role of Editor-in-Chief at JOSS since 2016 but in a recent blog post he explains that he is stepping down from his role as Editor-in-Chief, although he will remain at JOSS. The call for a replacement is here. It’s an opportunity that will appeal to anyone interested in open-source research software and open-access publishing so if that’s you then please consider applying. It will be a substantial investment of time, probably about a day a week. I quote:

Candidates should have the capacity to commit the time this role requires. For those in institutional positions, we ask for a brief letter or statement from your employer or supervisor confirming support for this commitment. Independent researchers, consultants, or others without a traditional institutional affiliation should include a brief statement describing how they plan to allocate the time.

P.S. Today OJAp published its 100th paper of 2026 so far

P.P.S. I’ll be stepping down as Editor-in-Chief at OJAp in a couple of years, when I retire, and we’ll be doing a similar search nearer the date.

#ArfonSmith #DiamondOpenAccessPublishing #JOSS #JournalOfOpenSourceSoftware #OJAp #OpenJournalOfAstrophysics #openSourceSoftware #TheOpenJournalOfAstrophysics

Mee-thos? Meye-thos? Mi-thos?

A month in, I still couldn't tell you.

The loudest opinions on AI vulnerability research almost never come from the people actually using it or contributing to making the world more secure.

Since Anthropic shipped Mythos and OpenAI Codex Cyber, my feed has been wall-to-wall thought leadership. Sage wisdom. Whitepapers. Panels. Frameworks for "AI-augmented vulnerability discovery." Panels about the frameworks. And one framework about panels

Meanwhile, the engineers I know, the ones helping secure the internet, have gone quiet. There's usually a reason for that.

The actual work is unglamorous. You read code. You read more code. You look upstream at the open source the whole world depends on. You find things. You report them carefully. You wait. And hopefully you've made the world a little more secure.

That's what our team at LinkedIn has been doing, inside our own stack and across the dependencies we all share. I'll share more when I can.

One thing I won't wait to say:

To the open source maintainers who've fielded our reports, triaged with patience, and shipped fixes through what has genuinely been an unprecedented stretch, thank you. I owe you many coffees/beers/waters. Much love.

Wu-Tang said it in '93: protect ya neck. You've been doing it for the rest of us ever since. No royalties, no panels, no merch.

Just the work.

Back to research and helping fix upstream.

#opensourcesoftware #cybersecurity

So what's new in the world of digital ham radio? This could be a big deal and might knock proprietary protocols and waveforms on the head. #Mercury #Hermes #opensourcesoftware #vara #packetradio

Good news for Linux ops too!
https://www.ardc.net/wp-content/uploads/Mercury-Press-Release-07-MAY-2026.pdf

Totally gave up on exiftool, I have better things to do than read pages and pages of instructions when I just wanna add copyright info and where the photo was taken.

Found digiKam and it removed all the headaches.

I also saw it has a GPS correlator so not only can I use my Garmin Etrex with it, I also have an actual use beyond "toy bought because I always wanted one but never had a plan of how to use it" for the Etrex.

#photography #photoediting #opensourcesoftware #digikam #KDE #exiftool