2.8K Followers
82 Following
6.2K Posts
When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
Homepagehttps://0xdeadbeef.info
GitHubhttps://github.com/0xdea
This is someting I wish I'd realized a lot sooner in life.
Warning to open source maintainers: the Axios supply chain attack started with some
very sophisticated social engineering targeted at one of their developers https://simonwillison.net/2026/Apr/3/supply-chain-social-engineering/
The Axios supply chain attack used individually targeted social engineering

The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …

Simon Willison’s Weblog
Microsoft Copilot terms of service have been updated to include this gem: "Copilot is for entertainment purposes only." https://www.theregister.com/2026/04/02/copilot_terms_of_service/
Even Microsoft knows Copilot shouldn't be trusted with anything important

: Terms admit it is for entertainment only and may get things wrong

The Register

docs.rs builds are about to change. If you have crates published on crates.io/docs.rs, I recommend you read this blog post in case you might be impacted by this change: https://blog.rust-lang.org/2026/04/04/docsrs-only-default-targets/

#rust #rustlang

docs.rs: building fewer targets by default | Rust Blog

Empowering everyone to build reliable and efficient software.

you ever write code so inefficient they have to update the whole power grid
It has been −2,147,483,648 days since our last integer overflow.
https://xkcd.com/3228/
Python Blood Could Hold the Secret To Healthy Weight Loss - Slashdot

Longtime Slashdot reader fahrbot-bot writes: CU Boulder researchers are reporting that they have discovered an appetite-suppressing compound in python blood that helps the snakes consume enormous meals and go months without eating yet remain metabolically healthy. The findings were published in the...

#CyberSecurity
#SupplyChain
#CERTEU

A compromised version of Trivy gave attackers access to the European Commission’s europa.eu platform hosted on AWS.

We have published our analysis – what happened, who is affected, and what to do – in full transparency and in agreement with the European Commission.

https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain

European Commission cloud breach: a supply-chain compromise

European Commission cloud breach: a supply-chain compromise

🫡 We’re back.

Today, we’re publishing vulnerabilities we discovered, disclosed, and chained to achieve pre-auth RCE against Progress ShareFile.

Enjoy the journey with us, while you sob into your hands 🫠

https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)

If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions. While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent role in the CISA

watchTowr Labs
Probably going to get a viral blog out of this experience, I'm trying to report a 4tb exposed cloud bucket to a company using their responsible disclosure programme... but they replaced the people with a GenAI ticket system that refuses to discuss the case as it thinks exploring open buckets is unethical and against its rules.