17 Followers
52 Following
33 Posts
Probably contains graphic violence, adult language, and some sexual content

Merry Christmas to everybody, except that dude who works for Elastic, who decided to drop an unauthenticated exploit for MongoDB on Christmas Day, that leaks memory and automates harvesting secrets (e.g. database passwords)

CVE-2025-14847 aka MongoBleed

Exp: https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py

This one is incredibly widely internet facing and will very likely see mass exploitation and impactful incidents

Impacts every MongoDB version going back a decade.

Shodan dork: product:"MongoDB"

So, 86box has gotten General Modem Emulation in 4.2, and you can absolutely dial up with SLIP to access the internet over SLiRP, and it absolutely works.

Dialog Boxes you have not seen in Quite Some Time, volume 5.

#RetroComputing #86box #emulation #windows98 #OldComputers

I accidentally found a security issue while benchmarking postgres changes.

If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongly recommend upgrading ASAP.

https://www.openwall.com/lists/oss-security/2024/03/29/4

oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise

Trump’s jet and Elon Musk’s jet have just both landed at West Palm Beach International Airport. Within 10 minutes of each other.
We considered ourselves to be a powerful restaurant.
@w7voa Lovely views of fountaining over on the USGS livestream. https://www.youtube.com/live/tBh-ZhIB1Nk?si=SfURj2qRYmQkBkO5
Kīlauea Volcano, Hawaii (Halemaʻumaʻu crater)

YouTube
#Kīlauea#volcano is erupting. #Hawaii