Sign in

fromveeko.bsky.social

@fromveeko.bsky.social
111 followers 416 following 33 posts

Learning things, Shielder-surfing. some stuff at fromveeko.github.io

PostsRepliesMedia
fromveeko.bsky.social @fromveeko.bsky.social · 22h
Smol boi / dirty monitor
Photo of a screen showing a soldered cable on a smd resistor. In the background, the schematics of a device.
010
fromveeko.bsky.social @fromveeko.bsky.social · 28/09/2026
If any of you folks happens to be @ romhack camp / rome in general, let me know! It would be nice to share a beer
001
fromveeko.bsky.social @fromveeko.bsky.social · 24/09/2026
@maitai.bsky.social dancing tip tap
000
Reposted by @fromveeko.bsky.social
Micah Lee @micahflee.com · 16/09/2026
This Flock camera is running obsolete, end-of-life software. - It's on Android 8.1, released in 2017, support ended in 2021 - It's on Android patch level 2018-06-5 - It's running Linux 3.18, released in 2017 This shit is like 8 or 9 years old, and full of vulnerabilities.
221443308
Reposted by @fromveeko.bsky.social
David Ho @davidho.bsky.social · 12/09/2026
I resigned from ExxonMobil today. I spent the last three years doing fossil fuel extraction research at both BP and ExxonMobil. Neither company is acting responsibly. They are racing to maximize extraction while the window to act closes, and gambling with our lives. More below.
145136944893
Reposted by @fromveeko.bsky.social
Micah Lee @micahflee.com · 08/09/2026
Post from Mastodon user @intransitivelie@beige.party:

I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

I'm happy to give you all the information you need to reproduce these unfortunate and completely unforeseen errors yourself.
327770
Reposted by @fromveeko.bsky.social
Kévin Gervot (Mizu) @mizu.re · 07/09/2026
A logical bug that I've reported to MariaDB has just been disclosed! 🎉 It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D You can find more details 👇 hackerone.com/reports/3876...
195
Reposted by @fromveeko.bsky.social
Goodnews @goodnews.computer · 04/09/2026
Take a break from being depressed that everything you love is being destroyed by slop for a moment and let me tell you about the beautiful symbiotic relationship between graffiti writers, train yard workers, and model train enthusiasts.
A hand holding a model train with a replica of the same graffiti on the full scale train car behind it.A model train with two graffiti pieces on opposite sides.
895483549
Reposted by @fromveeko.bsky.social
Massimo Mainardi @mainowski.bsky.social · 05/09/2026
Enorme ritiro del ghiacciaio Corvatsch negli ultimi 57 anni; è pazzesco quello che sta succedendo e ancora di più che non ci rendiamo conto che non abbiamo più un solo minuto da perdere
1820280
Reposted by @fromveeko.bsky.social
Brian PJ Cronin @brianpjcronin.bsky.social · 03/09/2026
Chat is it bad that every single website / app / tech product that we have found ourselves entangled with over the past 15 years eventually reveals themselves to be pro-fascism
17775175
Reposted by @fromveeko.bsky.social
Barry Dorrans @blowdart.me · 01/09/2026
I am a good teacher. In a discussion of security principles. "Table stakes. As in I will break the leg off a table and stake it through your intestines if you don't do it."
2205
Reposted by @fromveeko.bsky.social
Micah Lee @micahflee.com · 29/08/2026
The US just designated an Italian hacker collective (similar to Riseup) a terrorist organization. Please read this article about Autistici/Inventati, which I’ve reposted micahflee.com/the-server-c...
micahflee.com
The Server Called Paranoia: Defend Autistici/Inventati
For twenty-five years, an Italian hacker collective has built communications infrastructure designed to survive censorship, surveillance and police raids. On August 26, the United States designated it...
111477
Reposted by @fromveeko.bsky.social
Francesco Tucci @francesco.iltucci.com · 13/08/2026
4 anni ❤️ (Disegno adorabile di @danielcuello.com )
1242
Reposted by @fromveeko.bsky.social
Sio @scottecs.bsky.social · 11/08/2026
Internet è cambiato molto da quando è stato inventato negli anni 60
1
Vediamo un tizio al computer.
Sullo schermo, vediamo una finestra con scritto "Non sono un robot".
Il tizio conferma cliccando "Ok".
2
Sullo schermo ora vediamo una finestra con scritto "Ho più di 18 anni".
Il tizio conferma cliccando "Ok".
3
Sullo schermo infine vediamo una finestra con scritto "Accetto i cookies.".
Il tizio conferma di nuovo cliccando "Ok".
4
Sullo schermo appare la scritta: "Benvenuto sul sito dei Fan dei biscotti maggiorenni anti-automazione!"
Il tizio è felice di essere entrato in questo forum.
FINE
0343
Reposted by @fromveeko.bsky.social
Evariste @evaristegal0is.eurosky.social · 05/08/2026
Finalmente Plico è pronta 🎉 Con Plico (plico.cc) potete compilare e poi firmare con la CIE i vostri documenti PDF, direttamente sul vostro smartphone, senza che i documenti lascino mai il vostro smartphone. Un progetto a cui io e @massi.pippi.im abbiamo lavorato perché davvero stufi dei vari SaaS.
plico.cc
Plico | Firma documenti PDF con CIE in modo semplice
Plico: app iOS e Android per firmare PDF localmente sul dispositivo.
32312
Reposted by @fromveeko.bsky.social
Rairii :win3_progman: :win3: @rairii.labyrinth.zone.ap.brid.gy · 04/08/2026
i didn’t think it was physically possible, but there’s finally something worse than `curl | sh`
Install with an AI agent (recommended)

The fastest way to get ghidrasql running end-to-end is to point an AI coding agent (Claude Code, Cursor, Codex, Aider, etc.) at the bundled installer prompt:

(link to install-prompt.md)
16245280
Reposted by @fromveeko.bsky.social
Francesco Tucci @francesco.iltucci.com · 02/08/2026
(sono in vena di thread, potrei riaprire il blog, non lo so, spero non vi diano fastidio) Al fondo trovate il link con il thread facile da leggere Partendo da questo articolo www.ilpost.it/2026/08/02/t... e ricordando i miei anni a guidare ambulanze, prima dell'avvento del TomTom, alcuni consigli
ilpost.it
Un comune in Veneto ha troppe vie con lo stesso nome
A Setteville, in provincia di Belluno, i casi di omonimia tra le strade sono molti, e recentemente c'è stata anche una conseguenza tragica
311
Reposted by @fromveeko.bsky.social
Rob Palmer @robpalmer.bsky.social · 27/07/2026
ECMAScript excitement 😉 Congrats to my coworker @ashley-c.bsky.social at TechAtBloomberg on advancing Await Dictionary to Stage 3 at TC39 🎉 Promise.all returns positional results as an array. Promise.allKeyed allows named results inside an object 👍 github.com/tc39/proposa...
const {
  shape,
  color,
  mass,
} = await Promise.allKeyed({
  shape: getShape(),
  color: getColor(),
  mass: getMass(),
});
116621
Reposted by @fromveeko.bsky.social
Nicolas Grégoire @agarri.fr · 21/07/2026
My on-site training in Roma doesn't have many registrations yet and *may* be cancelled. So, if you are interesting in attending this session, do book your seat NOW! romhack.io/training/202...
romhack.io
Burp Suite Pro, 100% hands-on - RomHack Security Conference
001
Reposted by @fromveeko.bsky.social
raptor @raptor.infosec.exchange.ap.brid.gy · 15/07/2026
RE: infosec.exchange/@hnsec/11692323964… My #Semgrep C/C++ ruleset is ready for prime time again! Grab it before our new robot overlords take over the field of #VulnerabilityResearch entirely 🤖
041
Reposted by @fromveeko.bsky.social
Derek Powazek @fraying.bsky.social · 06/07/2026
People are going to blame the kids for the damage that academic institutions, amoral tech billionaires, and corrupt politicians have done and I hate it. futurism.com/future-socie...
futurism.com
Bosses Horrified as "AI Native" College Graduates Hit the Workplace
"AI native" college graduates are hitting the workplace -- and, as experts warned, bosses are finding their performance disappointing.
1153
Reposted by @fromveeko.bsky.social
Shielder @shielder.com · 01/07/2026
With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬
144
Reposted by @fromveeko.bsky.social
Massi @massi.pippi.im · 02/07/2026
I miss when corporations used to go above and beyond to hide misconduct and deceive the public.
011
Reposted by @fromveeko.bsky.social
Giulio Betti @giuliofirenze.bsky.social · 26/06/2026
Ondata di calore all’apice. Sabato la storica ondata di calore che da circa due settimane tiene in ostaggio gran parte d’Europa raggiungerà l’apice. Sarà una delle giornate più calde mai registrate nel nostro continente; da ovest a est le temperature massime raggiungeranno valori estremi…1/6
1126694
Reposted by @fromveeko.bsky.social
Patrick O'Doherty @patrickod.com · 23/06/2026
we have known for a long time what was to come
011
Reposted by @fromveeko.bsky.social
Zack Whittaker @zackwhittaker.com · 22/06/2026
In a new privacy policy, Anthropic says Claude will soon require you to upload your driver's license or passport for a variety of reasons. The ID checker is Persona, a firm funded by Trump ally Peter Thiel. As a U.S. company, Persona is also subject to gov't demands for people's verification data. 👀
techcrunch.com
Anthropic says Claude may want to see your ID | TechCrunch
Claude's chatbot may ask to verify your age and identity "in certain circumstances," such as with a passport or driver's license, according to a privacy policy change.
96529348
Reposted by @fromveeko.bsky.social
Vale @vale.rocks · 19/06/2026
There are only two file formats: disguised zips and renamed text files. JSON? Text. EPUB? Zip. CSV? Text. EXE? Zip. SVG? Text. DOCX? Zip. ICS? Text. APK? Zip.
451063264
Reposted by @fromveeko.bsky.social
b0n0b0 @b0n0b0.bsky.social · 17/06/2026
Just published a blog post about the Kdenlive RCE we found If you’re into FFmpeg arguments and reading docs, you won’t want to miss it! codeanlabs.com/2026/06/cve-...
codeanlabs.com
CVE-2026-45184 - Popping calc on Kdenlive - Codean Labs
041
fromveeko.bsky.social @fromveeko.bsky.social · 12/06/2026
i tamango hanno fatto uscire musica. è una cosa bella, com'è bello un venerdì di giugno dove il cielo è terso e la sera si sta bene con una felpina
000
Reposted by @fromveeko.bsky.social
John Scott-Railton @jsrailton.bsky.social · 10/06/2026
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order "safety" is risky. 1/
4533189
Reposted by @fromveeko.bsky.social
Lukasz Olejnik @lukaszolejnik.bsky.social · 05/06/2026
Mythos AI is being used by National Security Agency in offensive cyber operations / cyberattacks. Anthropic has even embedded engineers inside the NSA to help deploy the model. Are frontier AI labs becoming active contractors in state cyber conflict? www.ft.com/content/d02d...
11910
Reposted by @fromveeko.bsky.social
Federico Fuga (HappyCactus) @happycactus.org · 03/06/2026
Una giornata molto triste per tutta l'informatica italiana, per il mondo del giornalismo serio e professionale. Se n'è andata Carola Frediani. www.guerredirete.it/addio-carola/
guerredirete.it
Addio Carola - Guerre di Rete
Oggi, 3 Giugno 2026, è venuta a mancare all'affetto della sua famiglia e dei suoi amici Carola Frediani. Carola è stata anima e linfa di Guerre di Rete e lascia un vuoto incolmabile in tutti coloro ch...
199
Reposted by @fromveeko.bsky.social
Minas Karamanis @minaskar.bsky.social · 30/03/2026
Hey, I wrote a thing about AI in astrophysics ergosphere.blog/posts/the-ma...
ergosphere.blog
The machines are fine. I'm worried about us.
On AI agents, grunt work, and the part of science that isn't replaceable.
1101782530
fromveeko.bsky.social @fromveeko.bsky.social · 27/05/2026
Lol, i guess
000
Reposted by @fromveeko.bsky.social
Kris 🧙‍♂️ Kowal @kriskowal.com · 26/05/2026
Some more validation for hardenedjs.org: Mythos pen-testing in Firefox was frequently thwarted by frozen prototypes in the host process. hacks.mozilla.org/2026/05/behi...
hardenedjs.org
Hardened JavaScript
What is Hardened JavaScript
23311
Reposted by @fromveeko.bsky.social
Rebane @rebane2001.bsky.social · 20/05/2026
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
518229
Reposted by @fromveeko.bsky.social
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 19/05/2026
DOMPurify XSS via `selectedcontent` re-clone github.com/cure53/DOMPurify/securit… This is one of the most interesting bypasses we have seen in a long time, and it feels that this new HTML element will cause lots of trouble in the future.
github.com
DOMPurify XSS via `selectedcontent` re-clone
### Summary DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers "re-clone" an XSS payload after sanitization, effectively bypassing DOMPurify. ### Details ...
001
Reposted by @fromveeko.bsky.social
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
Big slay! maitai (@MaitaiThe) of Doyensec was able to exploit OpenAI Codex! If confirmed, they win $40,000 and 4 Master of Pwn points. They're off to the disclosure room for the deep dive. #Pwn2Own #P2OBerlin
021
Reposted by @fromveeko.bsky.social
Osservatorio Nessuno OdV @osservatorionessuno.org · 07/05/2026
How do commercial phone unlocking tools like Cellebrite actually work? In this technical overview, we explore the attack surfaces exposed by modern mobile devices, how those tools exploit them, and what can be done to better defend our privacy rights. osservatorionessuno.org/blog/2026/05...
osservatorionessuno.org
Demystifying phone unlocking tools: A technical overview
Demystifying phone unlocking tools: A technical overview
036
Reposted by @fromveeko.bsky.social
Willem Huiskamp @willemh.bsky.social · 05/05/2026
Always nice to start the day with some good news 🫠 #EGU26
Summary slide showing AMOC tipping risk is much higher than we thought 10 years ago
712964
fromveeko.bsky.social @fromveeko.bsky.social · 04/05/2026
sharing here a cool resource for automating boring login process via Burp Extension: github.com/I-blank-I/CO... One of our folks in the office put some love and effort in this :)
github.com
GitHub - I-blank-I/COOOKIES: A powerful Burp Suite extension for automating complex authentication flows and managing session tokens across multiple user accounts
A powerful Burp Suite extension for automating complex authentication flows and managing session tokens across multiple user accounts - I-blank-I/COOOKIES
041
Reposted by @fromveeko.bsky.social
Marisa Kabas @marisakabas.bsky.social · 31/03/2026
the process is part of the work. it’s not supposed to be easy. the effort creates good work. i can’t believe this needs to be explained to people who call themselves journalists.
372068205
Reposted by @fromveeko.bsky.social
Shielder @shielder.com · 30/04/2026
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
shielder.com
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
097
Reposted by @fromveeko.bsky.social
Giulio Betti @giuliofirenze.bsky.social · 29/04/2026
L’Europa è il continente che si scalda più velocemente, con l’impressionante ritmo di 0,56 gradi per decade. La regione artica mostra un rateo di incremento ancora più marcato: +0,75 gradi/decennio. Sono solo alcuni dei dati contenuti nel report dello stato del clima europeo 2025 di Copernicus. 1/6
714550
Reposted by @fromveeko.bsky.social
Osservatorio Nessuno OdV @osservatorionessuno.org · 23/04/2026
Today we are releasing an analysis of Morpheus, a low-cost, highly sophisticated Android spyware made in Italy. Among its features, the spyware disables the microphone/camera indicator, connects locally to ADB, and eludes WhatsApp fingerprint verification. osservatorionessuno.org/blog/2026/04...
osservatorionessuno.org
Morpheus: A new Spyware linked to IPS Intelligence
Morpheus: A new Spyware linked to IPS Intelligence
033
Reposted by @fromveeko.bsky.social
Zeke Hausfather @zekehausfather.com · 20/04/2026
With the latest set of El Niño forecasts, NOAA's CFSv2 model needs to get a larger y-axis scale 😯
1714244
Reposted by @fromveeko.bsky.social
Prof. Stefan Rahmstorf @rahmstorf.bsky.social · 17/04/2026
New study: most climate models underestimate the decline of the Atlantic overturning circulation #AMOC. The AMOC is on course to slow by more than 50% by the end of the century. 🌊 Very likely the AMOC will then be past the tipping point for full shutdown. 😨 us.cnn.com/2026/04/16/c...
us.cnn.com
A vital system of Atlantic Ocean currents is weakening and closer to collapse than thought, new studies find | CNN
New research provides alarming evidence this ocean circulation is slowing and could be heading toward a shutdown, which would have catastrophic impacts on the planet’s weather and climate.
12477273
Reposted by @fromveeko.bsky.social
Evariste @evaristegal0is.eurosky.social · 16/04/2026
Hello 👋 I am a Security Engineer, and I would like to contribute to open-source projects for security reviews or security implementations. I worked on different codebases (Typescript, JavaScript, Clojure, Python, Golang, C++), and I managed vulnerability triage. If you need help, ping me :)
444