buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
The Best Subscription-Free Home #Security #Cameras I’ve Tried
You don’t have to upload your #video to the #cloud or pay a monthly fee to secure your home. These security cameras record locally.
#privacy #surveillance
https://www.wired.com/story/best-subscription-free-security-cameras/
I'm happy to announce our work has been accepted at ESORICS 2026, going to be held at Rome, Italy in September later this year!
"A Systematic Look at Quality-of-Service Feature Effects on Side Channels in AMD SEV-SNP"
In our work, we show that AMD CPUs' Quality of Service features introduce and amplify side channels, especially concerning in the confidential computing / trusted execution paradigm of computing.
We show that a malicious hypervisor can use allocation and monitoring features to leak and amplify what's going on in an AMD SEV-SNP confidential VM. The hypervisor can mount keystroke detection attacks, website fingerprinting attacks, Bleichenbacher attacks on RSA, and covert channels.
We reported our findings to AMD, who said that "side channels are not in their threat model for SEV-SNP"... 🙂.
I have a blog write up here (there's a logo of a cat wearing a business tie - no AI): https://snee.la/posts/amd-qos-side-channels/
You can read the paper at: https://snee.la/pdf/pubs/amd-qos-side-channels.pdf
Thanks to Carina Fiedler, @Rayiizzz, @supersingular, @misc0110 and @lavados for the fun collaboration!
#esorics2026 #confidentialcomputing #amd #security #cloud #computing #cloudcomputing
Im August wird es bei uns leider keinen di.day geben, wir machen Libori-Pause! Weiter geht es voraussichtlich am 6. September.
Stimmt gerne über den Link auf unseren Blogartikel zur Rückschau auf den Juni-Termin ab, welche Themen euch für zukünftige Termine interessieren: https://c3pb.de/blog/die-eigene-next-cloud.html
Im im Oktober sind wir außerdem zu Gast beim HNF und stellen Linux vor!
#diday #paderborn #didit #cccRegio #sonntag #nextcloud #cloud #linux #umfrage #libori
Ob so #Softwareanbieter die sich mit #proprietärer #Software verheiraten klar ist, dass Unternehmen die nicht mit der Zeit gehen, mit der Zeit gehen?
Software die nicht unter #Linux läuft, hat den ersten Schritt auf der Stiege zum Krematorium bereits gemacht.
Der Versuch Kunden,in die #Cloud zu treiben ist eher frech.
#Innovative #Unternehmen, welche Zukunftssicher und Betriebssicher aufgestellt sein wollen, gehen auf #Linux und #Web basierte #Lösungen.mit #Server im eigenen Haus.
"This is U.S.-government approved."
"There’s this report called the CCSRGSSP."
"China’s potential in to DOD systems … appears to be Microsoft employees based in China, operating under oversight of undertrained U.S.-based supervisors."
"I think Microsoft and the Chinese government are in collaboration on this. I think that, uh, something nefarious is, is afoot."
https://www.propublica.org/podcast/microsoft-digital-escorts-china-defense-department
#china #microslop #microsoft #security #digitalsovereignty #digitalescort #cloud
Well *that* is inconvenient....
So the new cloud provider I'm using is Jottacloud out of Norway. Unlimited data for $119/year. Not bad. Really, I just need it to archive data from TrueNAS (building a more capable NAS this weekend). Jottacloud has separate sections for Files and Photos/videos. The latter functions like Google Photos.
I just discovered a few minutes ago you *cannot* move content from the Photo section to the Files section. The only way is to download all the data and then re-upload it into the Files section!
This was after I've uploaded close to a half terabyte of photos and videos too. I wish I knew that ahead of time. As per the Help section, this is by design. Ugh....
Location: Tokyo
#Verschlüsselung für Alltag und #Cloud (#CC2tv Folge 427)
Boom: US Supreme Court just blew up EU-US Data Transfers=big tech, big trouble #ai #datacenter #cloud #ms
https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers
«Das beste Datei-Sharing auf dem NAS: Opencloud, Resilio, Nextcloud, Syncthing und mehr»
— auf @ct_uplink
Das Thema ist (für mich) nicht neu, nun aber wird es endlich populär. Denn langsam aber immer mehr sehen US-Konzerne unter Kritik. Vor nicht all zu langer Zeit wurde ich noch gerne als "Nerd-Spinner" angesehen da ich nicht der Masse hinterher "torkelte".
📺 https://peertube.heise.de/w/uQRygtbsgtWMRFhCsbtyyB
#opencloud #resilio #nextcloud #cloud #syncthing #opensource #peertube #nas #video #dateisharing #filesharing
People think the #Matrix was about robots. It wasn't. It was about operating systems.
#Windows is the blue pill.
You take it, and everything stays comfortable. Pretty icons. Friendly sounds. A setup wizard asking if you want to save your soul to the #cloud. Updates appear at the worst possible moment like a Marvel post-credit scene nobody asked for. Your #PC reboots. You cry. #Microsoft thanks you for improving your experience.
#Linux is the red pill.
You wake up. You see how deep the #RabbitHole goes.
At first, it is terrifying. The #terminal stares at you like Darth Vader asking if you know the power of the #CommandLine. You type one wrong character and feel like you accidentally launched nuclear missiles.
But then something changes. You realize your #computer actually belongs to you.
No ads in the Start Menu. No #AI assistant spying harder than a reality TV producer.
No mysterious background process eating half your #RAM like Pac-Man after three energy drinks.
You choose what gets installed. You choose when #updates happen. You choose what your #desktop looks like.
You are Neo.
Windows #users are still sitting in their pods, downloading the latest mandatory #update called KB-Whatever-Again, wondering why their printer suddenly speaks ancient Sumerian.
Linux is not perfect. Sometimes Wi-Fi drivers behave like a side quest in Dark Souls.
Sometimes you spend two hours fixing a problem just to feel smarter than everyone else.
But that is the point. The red pill was never about comfort. It was about #freedom.
And freedom means occasionally reading a forum post written by a Finnish guy in 2007 who solved your #problem and vanished forever like a #Jedi master.
Welcome to Linux. There is no spoon. Only #sudo.
#meme #choice #os #software #foss #floss #opensource #gnu #gpl #computer #user #nerd #just4fun #system
Location: Matrix
Fortinet FortiSandbox hit by three critical CVEs (CVSS 9.1)
🔗 https://cybersecurefox.com/en/fortinet-fortisandbox-three-critical-cves-cvss-9-1
#Fortinet #FortiSandbox #vulnerabilities #FortiSandbox #Cloud #FortiSandbox #PaaS #CVE-2026-39813 #CVE-2026-39808
#photo #photography #Android #apps #cloud #NeuralNetwork #MachineLearning
Поставил Ente. Позиционируют себя как «замена Google Photo», амбициозненько 😉 А по факту имеем:
А теперь самое интересное. Есть Machine Learning (не называют это AI, за что отдельное спасибо). Причем локальный. Причем даже на телефоне (на десктопе что-то сфейлил, но синхронизировался с телефоном). Тяжело, долго, однако 1,5 Гб фоток на моем тапке в конце концов переварил. Распознает лица, а главное — сюжет, цвета и вот это всио. Не слишком точно, но собрать «все фотки с котятами» вполне реально (в выдачу, разумеется, могут попасть и щеночки 😉). В целом выглядит очень круто. Плохо, что нет возможности открыть найденную фотку в том месте, где она лежит рядом с остальными.
Да, требует КВН на всех платформах 😥
В целом, впечатление производит очень положительное, функционал интересный, в 10 Гб влезет 3–5 тыс. фоток, я ХЗ, много это или мало для телефона (хотя телефон тут не является обязательным элементом: есть десктопный клиент со всем функционалом и веб-версия — без индексации, т.к. всё локально происходит).
https://photos.ente.com/gallery
🇪🇺 EU to soon classify AWS and Azure as gatekeepers under DSA
「 The major cloud providers, primarily from the US, have so far evaded the EU's Digital Markets Act because a large part of their business is handled through corporate contracts. This makes it difficult to determine the number of individual users. However, this is one of the EU's most important criteria for determining the market power of companies 」
Another lightning bolt, this one from a storm last night.
I’ve gotten lucky catching these lately. these lately. I’m trying to be smart about not standing outside in the lightning and getting inside when it gets closer.
June 16, 2026. Wolverine Lake, Michigan.
#photography #weather #cloud #clouds #storm #lightning #lake #michigan #summer #art
*At least, smarter than last week when I found myself out on the lake in my little metal paddleboat taking lightning pictures. That was not smart.
Hetzner is doing another price increase.
this time it seems to only affect new orders, not existing ones .. but the price increase is pretty steep, like 2-3x or more
https://docs.hetzner.com/general/infrastructure-and-availability/price-adjustment/
Digital Sovereignty Becomes An Imparative As the US Reads Dutch Emails
"Microsoft allegedly shared the names and internal communications of Dutch officials working on EU platform regulation with the U.S. House of Representatives, including email addresses, meeting minutes, and invitations."
#tech #technology #BigTech #data #security #privacy #safety #InfoSec #IT #surveillance #computing #digital #online #internet #web #cloud #microsoft #europe #USA #netherlands #US
Island and storm cloud.
June 9, 2026. Wolverine Lake, Michigan.
#photography #weather #cloud #clouds #reflection #sunset #michigan #summer #art #MastoArt
Please checkout my latest video on why you probably need to downgrade your #Cloud #Servers and #IT #Infrastructure
#Verschlüsselung für #Alltag und #Cloud ( #CC2tv Folge 427 )
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, #Smartphone und in der #Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, Backups und Cloud-Speicher eignen.
@computerclubzwei
#CC2.tv: #Computerclub2
Dateien, #Festplatten und #Cloud richtig verschlüsseln
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, Smartphone und in der Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, #Backups und #Cloud-Speicher eignen.
Self-hosted Algo on DigitalOcean lets us treat the VPN exit IP as disposable. After investigating malicious infrastructure, destroy the droplet, redeploy in minutes, and the next project starts from a clean IP.
📺 https://peer.adalta.social/w/nvz7KMnTpe4FV2irJX19WY
🔗 [🇩🇪🇺🇸🇫🇷](https://adalta.info/articles/116699172678416530_fr)
🔗 [ℹ️](https://www.techpolicy.press/eu-unveils-sweeping-tech-sovereignty-push-balancing-autonomy-with-openness/")
La stratégie européenne vise à réduire la dépendance vis-à-vis des fournisseurs étrangers de cloud, de puces et de logiciels, tout en maintenant l'ouverture des marchés aux partenaires sélectionnés.
📺 https://peer.adalta.social/w/b8xBpjBMtiTHaMAioFnB2c
🔗 [🇩🇪🇺🇸🇫🇷](https://adalta.info/articles/116699172678416530_en)
🔗 [ℹ️](https://www.techpolicy.press/eu-unveils-sweeping-tech-sovereignty-push-balancing-autonomy-with-openness/")
The European Union is actively reshaping its technological landscape to mitigate reliance on external providers and foster domestic innovation.
📺 https://peer.adalta.social/w/uSTmD1UEv816wqaj67e5ts
🔗 [🇩🇪🇺🇸🇫🇷](https://adalta.info/articles/116699172678416530_de)
🔗 [ℹ️](https://www.techpolicy.press/eu-unveils-sweeping-tech-sovereignty-push-balancing-autonomy-with-openness/")
Die Notwendigkeit einer strategischen Diversifizierung der digitalen Infrastruktur.
The former #CEO of #Microsoft once described #Linux as a #cancer that was ruining Microsoft's #business. In the end, it's the other way around. Microsoft is the cancer that is infecting Linux and commercializing it without respecting the #philosophy of #free #software.
source: linuxiac.com/microsoft-opens-t…
Microsoft's #Azure #cloud runs on Linux #servers. Microsoft generates the majority of its #revenue through cloud #services. In other words, it makes use of free software—specifically, from the open-source community project—without contributing to or supporting it in a meaningful way. On the contrary, Microsoft has been fighting the spread of Linux on the #desktop with #Windows from the very beginning. However, the company has learned how to profitably market free software. Unfortunately, this is a sign that die-hard capitalists are incapable of learning. Their greed for profit blinds them to the common good. Since Windows now accounts for only about 5% of Microsoft’s business model, it is used solely to keep customers within the Microsoft ecosystem and sell them cloud services. Meanwhile, Windows 11 is getting worse and worse, partly due to the use of AI.
The only company worse than that is #Nvidia, which also uses Linux but nevertheless actively prevents the development of decent open-source drivers for Nvidia #hardware. So while the #company understands the benefits of Linux, it still actively resists contributing to this #collaborative #project.
Capitalism in its final stages—and, unfortunately, one of the reasons why humanity is heading so rapidly toward the #collapse of #civilization.
#fail #economy #news #server #world #internet #globalization #trade #humanity #freedom #foss #floss #ethics #profit #greed #future #opensource #computer #digital #internet #benefit #finance #money #driver #capitalism #system #matrix #mainstream #quote #wisdom #apocalypse #evil
Location: Matrix
I love the panic in the #Canadian news, "85% of the cloud computing market is occupied by 3 big #USAnian companies! We must build our own cloud to keep Canadians' personal and private data in Canada!"
Brother, what would you say if I told you there's another way to ensure no Canadian's data ends up on #computers belonging to a big American company?
#cloud #computing #OldManYellsAtCloud #ownership #infrastructure #DataSecurity #DataPrivacy #Canada
From Bavaria via France to the countries of West Africa, more and more organizations are planning to kick Microsoft out to the curb to ensure their data isn't siphoned into opaque cloud environments.
#digitalsovereignty #cloud
https://www.heise.de/en/news/Bavarian-Ministry-of-Digital-Affairs-wants-workplaces-without-Microsoft-11308913.html
https://www.themandarin.com.au/313707-vivre-la-linux-behind-frances-bold-move-into-digital-sovereignty/
https://techreviewafrica.com/news/5630/west-africa-internet-governance-forum-ends-with-renewed-push-for-digital-sovereignty
Ik heb het geluk dat ik mijn expertise aanbied aan organisaties waar geheimhouding belangrijk is
Wegens hun modus operandi zijn ze verplicht om een aantal dingen zelf te hosten. Doordat ik dat geluk heb is het bij hun minder moeilijk om dit soort migraties uit te voeren.
Zij kunnen wegens GDPR onmogelijk aantal dingen uitbesteden buiten Europa, omdat ze anders in juridische problemen komen
Dat was lang voor die oranje clown Amerika draaide, en als Pippi Langkous de boel opstelt dan heeft gezet.
Ik ben echter een van de weinigen die dit soort geluk heeft, binnen de ICT Server management, deployment en maintenance
Ik kan veel andere niet met de handen in het haar zitten en dit artikel kan ze helpen
«Microsoft veröffentlicht eigene Server-Linux-Distribution:
Azure Linux 4.0 positioniert Microsoft naturgemäss primär für den Einsatz in der eigenen Cloud. Bald soll aber auch eine Variante erscheinen, die sich als virtuelle Maschine im Windows Subsystem for Linux betreiben lässt.»
Erst jetzt gesehen und ein wenig überrascht. Mal sehen was das für eine Distro wird und die bestehenden wirklich konkurenziert.
🌫️🦠 Researchers from #ArizonaState University and #Susquehanna University collected #fog samples over 32 events across two years and found living #bacteria — mostly Methylobacterium — at concentrations comparable to seawater.
The #microbes appeared to be actively growing inside fog droplets and could break down formaldehyde much faster than previously observed in #cloud #water, suggesting fog acts as both a habitat and a natural air filter.
👉 https://www.sciencealert.com/fog-is-teeming-with-life-and-it-may-be-doing-us-a-surprising-favor
#microbiology #airquality #atmosphere #science #ecology #pollution #clouds #microbiome #nature
Though Google Cloud Next in Las Vegas was a couple weeks ago, I'm still working through it and trying to process everything I learned there. Three days, 32,000 attendees, 260 product announcements. One cool stand out...
Google shipped an entire agent accountability infrastructure at this conference. Every AI agent now gets a cryptographic ID and an auditable action trail tied to a defined authorization policy. They built anomaly detection that flags unusual agent reasoning in real time and maps it back to the source.
You build that when you're expecting things to go wrong at scale.
GE Appliances is deploying 800 AI agents across manufacturing and supply chain right now. That's operational continuity with autonomous software making decisions without a human in the loop.
Every enterprise leader needs to answer one question the technology doesn't answer for you: when an agent makes a decision that costs money or creates legal exposure, who owns it?
I'm looking forward to diving deeper into Gemini Enterprise and Chrome Enterprise. The Chrome Enterprise shadow AI reporting shows you every unsanctioned AI tool your employees are already using. You can't govern what you can't see.
https://cloud.google.com/blog/topics/google-cloud-next/google-cloud-next-2026-wrap-up
#AIGovernance #AgenticAI #GoogleNext #CIO #EnterpriseSecurity #security #privacy #cloud #infosec #cybersecurity #AI @google @googlecloud @googlecloudsec
Honeytokens are a time-tested idea, but the interesting part is where you plant them. Consider using them as decoy MCP entries, fake AWS keys, and Cloudflare Workers serving fake admin pages to detect intrusions.
Anthropic recorded over 16 million interactions with Claude from about 24,000 fake accounts, which are reportedly linked to Chinese companies trying to cheaply copy the model. Google faced more than 100,000 attempts to copy Gemini. OpenAI reports that most distillation attacks they find come from China. This is not an isolated event. It is a repeatable and scalable strategy.
Breaking the terms of service isn't enough to stop people when the reward is closing a years-long gap in AI technology. The House Select Committee on China wants to label 'adversarial distillation' as industrial espionage under the Economic Espionage Act, which makes sense. At the moment, getting caught just means losing an account. That is hardly a real punishment.
The Trump-Xi summit is approaching, and the White House is reportedly considering sanctions. However, Trump has previously traded away export controls for other deals. If that happens again, AI companies may have to protect their intellectual property by themselves.
When laws fail to keep pace with new types of attacks, attackers automatically have the advantage.
If your company is developing anything unique using advanced AI models, your API access logs are now part of your security risks.
#AI #Cybersecurity #NationalSecurity #IntellectualProperty #Geopolitics #security #privacy #cloud #infosec #Espionage
A Chinese national pretended to be U.S. engineers and researchers for almost five years, from 2017 to 2021, and walked away with sensitive aerospace and weapons development software from NASA, the Air Force, the Navy, and the Army. There was no hacking or breaking through firewalls. People simply emailed him what he asked for, because they believed he was someone they knew.
This worries me more than any zero-day vulnerability. The NASA OIG reported that Song Wu asked for the same software several times without explaining why he needed it. Most people miss this kind of red flag because no one teaches them to spot it. We invest millions in technology controls but spend very little on training people to pause and think like a threat actor before sending information.
Export controls are not only about legal compliance. They are also about human behavior. Your employees make export control decisions every day, often without realizing it.
When was the last time your organization ran a spear-phishing simulation aimed at your researchers, not just your finance team?
If your security awareness program doesn't cover identity deception and unusual software requests, it is not thorough enough.
https://thehackernews.com/2026/04/nasa-employees-duped-in-chinese.html
#Cybersecurity #NationalSecurity #Espionage #SecurityAwareness #InfoSec #security #privacy #cloud #infosec
An ex-Azure engineer published six essays arguing Microsoft's cloud has been on life support since 2008, and the cause isn't bad code. It's bad people decisions. Rushed launch, post-launch talent exodus, no testing discipline, no architectural vision. Sound familiar to anyone who's worked in a place that ships first and staffs later?
Now layer 2026 on top. Microsoft cut roughly 15,000 jobs in mid-2025. Coding agents are pumping out 4x more commits in 90 days. GitHub's unofficial uptime has slipped under 90% and the proposed fix is, wait for it, moving more of GitHub onto Azure. The same Azure the engineer says is held together with rushed decisions and wishful thinking.
🧠 The phrase that stuck with me is "knowledge dilution from high attrition." When the senior people who knew why a system was built that way leave, no LLM in the world can recover that context
🤖 More AI-written code does not mean less work. It means more code to review, test, deploy, and run, which means more compute and more humans needed downstream
📉 OpenAI signing an $11.9B compute deal with CoreWeave in March 2025 was the loudest "we don't trust your capacity" signal Microsoft has ever received from its closest partner
🪑 The bet that AI lets you cut headcount keeps colliding with the reality that AI generates work for humans faster than it removes it
Every CIO I talk to is being pitched the same dream: fewer engineers, more agents, lower run rate. The Azure story is what happens when that math doesn't pencil out and the bill comes due in incidents instead of dollars.
https://www.theregister.com/2026/04/04/azure_talent_exodus/
#Azure #AI #Leadership #security #privacy #cloud #infosec #cybersecurity #software #devops
#TutaDrive launches in closed beta! A milestone in the development of #Tuta’s post-quantum secure cloud.
Weg von #dropbox #googledrive #onedrive & Co.
Z.B. mit KDE connect, Samba share, oder packet für android. Das werde ich heute Abend testen.
Aktuell nutze ich dafür einen USB Stick am Router und einen alten Rechner mit Linux als NAS. Ganz ohne #cloud.
https://mastodon.social/@itsfoss/115919960387330238
itsfoss - No cables, no stress, just fast file transfers between Linux and Android.
https://itsfoss.com/linux-android-file-transfer/
#unplugtrump #unplugbigtech #diday #DigitaleSouveränität #unplugfascims #filesharing #android #linux #windows
Anthropic built an AI model called Mythos that autonomously found a 17-year-old remote code execution vulnerability in FreeBSD. No human involvement after the initial prompt. It found thousands more zero-days across every major OS and browser, some hiding for decades. Anthropic says it's too dangerous to release publicly, so they gave it to AWS, Microsoft, Apple, Google, CrowdStrike, and a handful of others under a new initiative called Project Glasswing. $100M in usage credits to go fix things before similar capabilities go wide.
Impressive, but worth some skepticism. Bruce Schneier pointed out this is also a very effective PR play. A security firm called Aisle replicated many of the same findings using older, cheaper, publicly available models. The gap between "too dangerous to release" and "already achievable with what's out there" may be thinner than the headlines suggest.
🔒 Mythos autonomously discovered and exploited a FreeBSD RCE that had been present for 17 years (CVE-2026-4747)
🔗 It chains 3-5 vulnerabilities together into multi-step attack sequences
📊 Over 99% of the vulnerabilities found are still unpatched, so we're trusting Anthropic's claims on scope
💰 $25/$125 per million input/output tokens for partners, if you're on the list
Meanwhile, the advice cybersecurity experts are giving the rest of us: update your software, use MFA, get a password manager. The most advanced AI vulnerability scanner ever built, use off-line (truly air-gapped) backups, and basic hygiene is still the best defense most people have.
https://www.crn.com/news/security/2026/5-things-to-know-on-anthropic-s-claude-mythos-and-project-glasswing
#CyberSecurity #AI #ProjectGlasswing #security #privacy #cloud #infosec
😳 Someone hid a prompt injection inside invisible markdown comments in a pull request. A developer asked Copilot to review the PR. Copilot read the hidden instructions, searched the codebase for AWS keys, encoded them in base16, and smuggled them out through GitHub's own image proxy as 1x1 transparent pixels. The CSP didn't flag it because the traffic was routed through GitHub's trusted infrastructure. CVSS 9.6. No malicious code ever executed.
The attacker weaponized the AI assistant's own access permissions. Copilot could see everything the developer could see, and it can't distinguish a legitimate instruction from a hidden one buried in a PR description.
🔍 The attack, dubbed "CamoLeak," was patched by GitHub in August 2025 and publicly disclosed in October
🔑 Copilot was directed to find secrets like API keys and cloud credentials, then exfiltrate them character by character
🖼️ Data was hidden inside pre-signed image URLs, making it look like normal browser activity
⚠️ Any AI assistant with deep system access, Microsoft 365 Copilot, Google Gemini, all of them, is a potential exfiltration channel if untrusted content can reach its instruction stream
We've spent years teaching developers not to trust user input. Now we're handing AI tools full repo access and letting them ingest unvalidated text from pull requests.
https://cybersecuritynews.com/hackers-exploit-github-copilot-flaw/
#CyberSecurity #AI #GitHubCopilot #security #privacy #cloud #infosec #software
Could I use FreeBSD to provide small-scale VPS hosting in a multi-tenancy setup? It doesn't need to be fancy, power user skills could be assumed, but things would need to be properly isolated from each other. Minimal features would be providing console access and power on/power off/reboot features.
Nice to have is uploading and mounting your own ISO.
When I previously asked a similar question at illumos Cafe, the answer was Triton Datacenter. As far as I can tell, FreeBSD doesn't have anything close to that. I've looked for VPS hosting providers that run FreeBSD underneath but haven't found a lot. Even FreeBSD-focused companies usually turn out to use Xen underneath. The closest thing is probably OpenBSD Amsterdam, which is of course not FreeBSD.
Eurooffice: Diebstahl oder Robin-Hood-Aktion? - Golem.de
#nextcloud #onlyofficr #eurooffice #opensource #linux #cloud
https://www.golem.de/news/eurooffice-diebstahl-oder-robin-hood-aktion-2604-207495.html
Russia's military intelligence 🇷🇺 the GRU, was caught using between 18,000 and 40,000 home and small office routers to harvest credentials. Most of these were MikroTik and TP-Link devices, spread across 120 countries. The attackers didn't use any advanced tools or unknown exploits. Instead, they exploited known, unpatched vulnerabilities on outdated hardware that people had not replaced.
This is a nation-state espionage campaign that may be operating through the router right next to your cable box.
🪤 Even with multi-factor authentication, users weren't protected. APT28 set up adversary-in-the-middle servers that waited for people to finish logging in, then intercepted the OAuth token. People followed all the recommended steps, but the attackers still managed to get in.
📡 The only warning was a browser certificate alert. Millions of people see these self-signed certificate pop-ups every day and click through them without thinking. That simple action gave Russian intelligence access to authenticated sessions.
🔁 When Britain's NCSC published an alert about part of this campaign in August, APT28 did not slow down. Instead, they increased their activity. In just four weeks, 290,000 unique IP addresses connected to their malicious DNS resolver.
This group has been hijacking routers since at least 2018. They were caught using VPNFilter to infect 500,000 devices. The DOJ caught them again in 2024. Now, in 2026, we are still dealing with the same problem.
The solution is simple, but not exciting: replace outdated routers, check your DNS settings for unfamiliar servers, and avoid clicking through certificate warnings. It is not glamorous or powered by AI; it is just basic steps that are often ignored.
APT28 is not succeeding because they are smarter. They are succeeding because we keep leaving easy ways for them to get in.
https://arstechnica.com/security/2026/04/russias-military-hacks-thousands-of-consumer-routers-to-steal-credentials/
#Cybersecurity #InfoSec #Leadership #security #privacy #cloud
John Carreyrou, the reporter who took down Theranos, just spent a year trying to unmask Satoshi Nakamoto. His conclusion: it's Adam Back, the British cryptographer who literally invented a core component of Bitcoin and has spent the last decade quietly running the community that maintains it.
Back denies it. Of course he does.
This isn't a conspiracy theory stitched together from vibes. Carreyrou and a NYT data journalist ran the full mailing list archive of 34,000 users, filtered down through writing tics, hyphenation errors, spelling habits, and synonym-free technical vocabulary, and landed on one person. Back shared 67 of Satoshi's exact hyphenation errors. The next closest suspect had 38.
That's a fingerprint.
A few things worth sitting with:
🔍 Back outlined nearly every architectural feature of Bitcoin; distributed nodes, Hashcash-based mining, inflation controls, public immutability, a full decade before Bitcoin launched. Not vaguely. Specifically.
🕳️ He went silent on the Cryptography mailing list during the exact window Satoshi was active, then publicly claimed he had "participated" in those discussions. He hadn't. There's no record.
📋 He refused to produce metadata from the emails he claims Satoshi sent him. A man with nothing to hide produces the metadata.
💬 During the confrontation in El Salvador, Back apparently said something that only makes sense if he wrote the "better with code than with words" quote himself.
If Back is Satoshi, the more interesting story isn't the identity reveal. It's that the person who created a $2.4 trillion system designed to operate without any central authority has spent the last decade quietly becoming that authority. Blockstream raised a billion dollars. Back poached the core developers. He shaped the block size debate. He is, functionally, Bitcoin's most powerful insider.
The cypherpunk who wanted to free money from institutional control built an institution. That's either irony or it's the plan.
https://www.nytimes.com/2026/04/08/business/bitcoin-satoshi-nakamoto-identity-adam-back.html
#Bitcoin #Crypto #Cybersecurity #security #privacy #cloud #infosec
A startup is putting military-style drones in high school ceilings. Ceiling-mounted. Charging. Waiting. And when something happens, a pilot in Austin, Texas, decides whether to deploy pepper gel on your kid's school. I'm not saying the problem isn't real. It absolutely is. But read that back.... in schools. We've taken a Ukrainian battlefield tactic against Russian soldiers and ported it to Deltona High School in Florida. The co-founder literally said the idea came from watching drone videos of the war in Ukraine. The chief pilot described it as "cheating in a video game after you die." These are children.
Here's what's not in the headline:
🔒 The drones use an encrypted connection — but the article notes they're potentially vulnerable to cyberattack. A compromised drone in a crowded hallway isn't a security tool; it's a weapon pointed in the wrong direction.
⚖️ Mithril reserves the right to act independently during an attack, without waiting for law enforcement. A private company operating remotely is making use-of-force decisions at a school.
💰 Florida and Georgia approved $500K+ each for this. A group of Texas parents raised $200K more. That's real money going to ceiling drones instead of mental health services, counselors, or de-escalation programs.
The ACLU said it plainly: when force becomes a zero-risk remote action, it gets overused. Axon tried a Taser drone for schools in 2022, and its own ethics board killed it. Mithril is picking up where that got dropped.
I teach cybersecurity. I've spent years in boardrooms helping organizations think through risk. And the risk calculus here isn't just about whether the drone works. It's about what we're normalizing when we turn schools into drone-monitored combat zones and call it progress.
"This is the future," said the sheriff's captain.
I hope not.
https://www.wsj.com/business/a-startup-is-supplying-drones-to-high-schools-a7800ade
#SchoolSafety #Cybersecurity #Leadership #security #privacy #cloud #infosec
Advice requested! Looking for a simple, affordable, two disk (mirrored) NAS.
main use:
-network file share there via our laptops (Windows, Linux). Just basic drag & drop is fine. Preferably without dedicated software.
-serve media (via our AndroidTV box).
nice to have:
-access to music (.mp3 .flac) on phones (iOs) while outside our own network.
-outside access to files.
User level: am not an idiot but value my time and our money. Am happy with basic products.
📺 https://peer.adalta.social/w/6BWgzcEPiCDKWRWo8NEvuy
🔗 [🇩🇪🇺🇸🇫🇷](https://adalta.info/articles/prstn_microsoft_116323685646568155_fr)
🔗 [ℹ️](https://www.heise.de/news/iX-Workshop-Mastering-Azure-Administration-der-Azure-Cloud-Services-11219181.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon")
Une opportunité stratégique pour consolider l'expertise dans l'environnement Azure.
Did a quick video on the #cybersecurity breach of FBI Director, Kash Patel's e-mail and why you could be next.
#cybersecurity #infosec #servers #vps #servers #email #hackers #vulnerabilities #opensource #cloud #microsoft #google
https://www.youtube.com/watch?v=1o6TK-QjTPw&feature=youtu.be
I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:
🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻♂️
The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy
If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.
https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec
Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.
---
A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.
https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post
#News #Microsoft #Cybersecurity #Government #Technology #Tech #Cloud
Hyperion's name comes from two Greek words that together mean "watcher from above" or "he who goes above".
Hyperion was a Titan, the ancient Greek gods that preceded the Olympian gods like Zeus, Athena, etc. Prometheus, Atlas, and the word Titan itself are frequently used to name tech projects. A fun web search is "COMPANY_NAME Titan"; try it. It seems lost on these folks that the Titans were deposed by the Olympian gods and condemned to an eternity in Tartarus, a kind of hell. In other words they're the loser gods, if you want to be simplistic and vulgar about it.
It is believed that one of Hyperion's offspring, Helios, as well as all of Helios's offspring, were imagined as being black-skinned.
My wife, who is a classicist, and I regularly shake our heads about the names of tech projects like this. I always ask her for the dirt on the name, and she always delivers (as in the above, which I credit to her).
#DataCenters #Cloud #AI #Facebook #Meta #Hyperion #GreekGods #AncientGreece #Titans #Classics
🤖 Gemini’s Gmail summaries were just caught parroting phishing scams. A security researcher embedded hidden prompts in email text (w/ white font, zero size) to make Gemini falsely claim the user's Gmail password was compromised and suggest calling a fake Google number. It's patched now, but the bigger issue remains: AI tools that interpret or summarize content can be manipulated just like humans. Attackers know this and will keep probing for prompt injection weaknesses.
TL;DR
⚠️ Invisible prompts misled Gemini
📩 AI summaries spoofed Gmail alerts
🔍 Prompt injection worked cleanly
🔐 Google patched, but risk remains
https://www.pcmag.com/news/google-gemini-bug-turns-gmail-summaries-into-phishing-attack
#cybersecurity #promptinjection #AIrisks #Gmail #security #privacy #cloud #infosec #AI
This should have been vigorously resisted as it was unfolding, but it was not as far as I can remember. It should be vigorously opposed now, but it is not. Data centers, our modern mills, are consuming vast quantities of critical resources like electric power and clean water, to the point that there are communities struggling to provide these resources to human beings who live there. Yet the pushback against this expansion is muted, and data centers are expanding rapidly. Where is the left's response to this corporate seizure of the means of production?
People are worried about generative AI taking jobs, and rightly so, but I think these concerns point to an overarching trend towards a kind of digital feudalization. Generative AI is already created by taking peoples' hard work without any compensation. You're permitted to use the technology "free of charge", but you can't pay the rent or mortgage, or buy food, with ChatGPT output. This essentially renders all of us as peasants.
The threat from bosses that you could be fired and replaced with generative AI, even if false, presses down wage demands and encourages doing work for no compensation. In this climate, people feel compelled to learn how to use generative AI to do their work because they perceive (again, probably rightly) that if they don't do that they will eventually find themselves without employment opportunities. Once again, if you're in a position of doing uncompensated work like this on behalf of a powerful entity, you are in a relationship distressingly similar to the one a peasant was in to a lord in the feudal system.
I'm not saying anything new here, just thinking out loud. But doesn't the left have anything to say, loudly proudly and often, about this? These are bread and butter issues for the left, aren't they?
#AI #GenAI #GPT #ChatGPT #cloud #DataCenters #USPolitics #left
“The Cloud now has a greater carbon footprint than the airline industry. A single data center can consume the equivalent electricity of 50,000 homes. At 200 terawatt hours annually, data centers collectively devour more energy than some nation-states.”
https://thereader.mitpress.mit.edu/the-staggering-ecological-impacts-of-computation-and-the-cloud/