‼️ zei

@zei
55 Followers
47 Following
374 Posts
I write some code, and get paid both to break and fix things.

So let me see if I have this right:

Not only did BlueSky accept $100 million in funding from a Bain Capital Crypto - an obviously crypto associated investment firm - but a few weeks ago the notably transphobic CEO stepped down, not to leave the company, but to allow an AI-boosting, investment fund asshole figurehead take over the CEO position while she continues to pollute the C-suite elsewhere?

Yeah.

Yeah, that sounds like it's going to turn out GREAT.

I am POSITIVE this is going to be the bastion of safety and community that people keep telling me it is. I'm sure NOTHING will go sideways.

https://bsky.social/about/blog/03-19-2026-series-b

https://bsky.social/about/blog/03-09-2026-a-new-chapter-for-bluesky

Bluesky's 2025 $100M Series B Lays Foundation for Open Social Web - Bluesky

In April 2025, Bluesky raised $100 million in Series B funding led by Bain Capital Crypto. Since our Series A, we've grown from 13 million to over 43 million global users.

Bluesky

> The leak, which Meta confirmed, happened when an employee asked for guidance on an engineering problem on an internal forum. An AI agent responded with a solution, which the employee implemented – causing a large amount of sensitive user and company data to be exposed to its engineers for two hours.

lol and - furthermore - lmao

https://www.theguardian.com/technology/2026/mar/20/meta-ai-agents-instruction-causes-large-sensitive-data-leak-to-employees

Meta AI agent’s instruction causes large sensitive data leak to employees

Artificial intelligence agent instructed engineer to take actions that exposed user and company data internally

The Guardian

The "Bluetooth Headphone Jacking" talk at #39c3 was awesome, too. They reversed a popular SOC that powers Bluetooth earbuds and headphones.

They found that (even without being paired to the headphone), they could dump flash and RAM from the device. Then they dumped a bunch of info from the device - e.g. the #Bluetooth address and "master" encryption keys used for the communication with paired devices (e.g. a #phone).

Then they impersonated the headphone from their laptop and connected to the phone (pretending to be the headphone).
The headphone (or the laptop impersonating the phone) has permissions to do some things on the phone, e.g. accept calls, increase/decrease volume, etc.

Then they started recovering access a #WhatsApp account via some account recovery mechanisms. That required some one-time security key which would normally be delivered via SMS, but that could be delivered via phone call as a fallback option, too. Since the phone thought it was connected to the Bluetooth headphone, phone call audio would go to the laptop via Bluetooth.

As the cherry on top, they escalated into the victim's #Amazon account.

Scary shit. #YouCannotBeParanoidEnough #security

Do you use Spotify Premium? Cancel your subscription until Spotify stops running ICE ads. There are other streaming options that don’t profit from exploiting artists while recruiting for ICE: https://indivisible.org/cancel-spotify?source=mastodon #CancelSpotify
This mastodon client came to me in a fever dream.
I had to waste the whole day, but now you too can bunnyhop through your fedi feed.
https://files.burning.homes/experimental/hall-of-toots/index.html

* webgl required
* mobile somewhat supported
* yes this html file is a whole client and the entire source
* it would run smoother and look better if you launch it locally so it don't have to bypass CORS, but oauth won't work and you'll have to use access token
* you can click urls and images
* you don't really have to login, and can just hop around the public timelines (i.e. Instance = https://mastodon.social , empty token, Federated timeline, Use Access Token)
* but I'm too tired to support CW and sensitive, so it'll kinda be full of porn
* admins will hate you
* 429 error means you won
* I am in dire need of salvation
would you like a baby introduction to the idea of remote code execution through a buffer overflow vulnerability, but Animal Crossing flavored? https://m.youtube.com/watch?v=pV0xnIsgGXE
Remote Code Execution in Animal Crossing: New Leaf

YouTube

🚨AirBorne: Full PoC Framework for CVE-2025-24252 & CVE-2025-24132

AirBorne is a combined proof-of-concept (PoC) framework targeting two serious vulnerabilities in Apple's AirPlay service.

GitHub: https://github.com/ekomsSavior/AirBorne-PoC

This is a good summary of how the vaguely odious vibes that DHH has been giving off for a decade have boiled over. If you don’t know who that is/don’t have any personal investment in Ruby, you have my blessing to keep scrolling and not worry about it https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thought/
DHH Is Way Worse Than I Thought | jakelazaroff.com

DHH's politics are not normal. Maybe they used to be, I don't know, but as of right now the dude is way outside of what most people would consider moral or acceptable.

You asked, the Rust/TUI community delivered.

**desktop-tui** ~ A full desktop environment... without graphics.

src: https://github.com/Julien-cpsn/desktop-tui

#rustlang #terminal #desktop