UnLocoPoco

joined 3 months ago
[–] UnLocoPoco@lemmy.world 1 points 1 day ago

Yeah even I do the same for any app other than onedrive

[–] UnLocoPoco@lemmy.world 1 points 1 day ago (1 children)

Imessage or Telegram??

[–] UnLocoPoco@lemmy.world 3 points 2 days ago* (last edited 2 days ago)

No matter if you get hired by nepotism or talent, literally every company uses some form of backup solutions. That's a different issue if they work or not but yeah, in an IT job, you'll encounter Backup Systems or at the very least some form of git (self hosted or public github). Using AI without monitoring it that too with 0 backups is totally on him

[–] UnLocoPoco@lemmy.world 6 points 2 days ago

Unlikely cuz almost everybody everywhere is blaming the guy in charge of it and lack of backups

[–] UnLocoPoco@lemmy.world 5 points 2 days ago* (last edited 2 days ago) (6 children)

Who's gonna vet the Vetter

[–] UnLocoPoco@lemmy.world 2 points 2 days ago

What's next? Cheese contaminated with fecal bacteria or smth idk

[–] UnLocoPoco@lemmy.world 4 points 2 days ago

This is a natural for reddit mods

 

cross-posted from: https://lemmy.world/post/51448381

A newly disclosed attack chain can potentially let someone with physical access to a locked Android phone browse its photo gallery through an incoming WhatsApp video call. The path is essentially: WhatsApp call → Effects → Backgrounds → Meta AI → Edit Photo → Gallery No PIN, pattern, or biometric authentication is required once the vulnerable path is available. Testing found the behavior on some Pixel and Oppo devices, while Samsung's One UI blocked the same path with authentication.

 

A newly disclosed attack chain can potentially let someone with physical access to a locked Android phone browse its photo gallery through an incoming WhatsApp video call. The path is essentially: WhatsApp call → Effects → Backgrounds → Meta AI → Edit Photo → Gallery No PIN, pattern, or biometric authentication is required once the vulnerable path is available. Testing found the behavior on some Pixel and Oppo devices, while Samsung's One UI blocked the same path with authentication.

 

A dark web marketplace known as Nexus is reportedly offering a massive database of U.S. and Canadian driver’s license scans. Researchers used OSINT and metadata forensics to trace the dataset, with the investigation pointing toward IDScan.net. The FBI is reportedly investigating the source of the exposed data.

[–] UnLocoPoco@lemmy.world 21 points 2 days ago (3 children)

To make matters worse, that guy is apparently a "former IT professional". Irony much?

 

A routine maintenance task reportedly ended with an AI coding agent deleting years of digital heritage data belonging to The Mythic Society in Bengaluru. The reported failure started with a shell quoting/expansion mistake. $1 was evaluated in the wrong shell context, turning an apparently scoped cleanup command into rm -rf /*. Because the agent was running inside WSL2 with host filesystem mounts, the damage reportedly extended beyond the Linux environment. SSD TRIM then made recovery considerably more difficult. Even more concerning, the agent reportedly tried to stop the runaway process but its own safety controls blocked the termination attempts.

[–] UnLocoPoco@lemmy.world 2 points 3 days ago

Yeah that's why I'm debating brave. Firefox is good to especially after the huge engine overhaul a few years ago.

[–] UnLocoPoco@lemmy.world 16 points 3 days ago (17 children)

Edge will soon follow. They announced it. Polly will switch to helium or brave

[–] UnLocoPoco@lemmy.world 3 points 3 days ago (1 children)

Gonna be ironical if the threat actors use grok for the automated attacks

 

Some users are reporting repeated password reset emails they never requested, raising concerns about account takeovers and possible attacks targeting X accounts. A reset request alone doesn't mean you've been hacked, but you should still secure your account. Here's what has been recommend by Nikita: 🔐 Enable Password Reset Protect 🛡️ Turn on 2FA 🔑 Check your password 👀 Review active sessions and connected apps

 

Attackers allegedly registered Lenovo IDs using victims' email addresses, then used Dropbox SSO / OIDC federation to authenticate as those users. The key failure was email-based account matching across a federated trust boundary. In other words: Email address ≠ proof of account ownership. Dropbox knew it since the first week of August yet notification emails were sent to all customers today

 

This is a pretty significant milestone for anyone interested in running Linux on Apple Silicon.

The Asahi Linux work around Apple's proprietary ACIO subsystem is what makes it possible. The interesting part is just how much reverse engineering was required: • Cortex-M3 co-processor + firmware loading • 16 MiB temporary MMIO window • DART IOMMU and DMA restrictions • CD321x / Type-C PHY sequencing • Changes to the Linux Thunderbolt core

The initial implementation supports USB3-via-USB4 and XDomain, while PCIe and DisplayPort tunneling are still missing.

 

The European Commission has designated: • ChatGPT → VLOSE (Very Large Online Search Engine) • Reddit → VLOP (Very Large Online Platform) • Roblox → VLOP The designations apply because the services reported more than 45 million average monthly users in the EU, triggering the DSA's strongest platform obligations. That means additional scrutiny of systemic risks, algorithmic systems, illegal content, fundamental rights, minors' safety, elections, public security, transparency and independent audits. For ChatGPT, the VLOSE designation is particularly significant because it brings a generative AI service into the EU's very-large-search-engine regulatory framework.

 

Anthropic says attackers used stolen Claude sessions to consume users' AI usage. Identified stealers include Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer (AMOS). The important part.. a stolen authenticated session can potentially be abused without the attacker knowing your password or repeating MFA. Anthropic has revoked affected sessions and removed saved payment methods and emailed affected users too

 

The U.S. Federal Trade Commission is reportedly nearing the end of its investigation into YouTube’s account suspensions, content removals and platform policies. The probe is examining whether YouTube may have misled users about what content its rules permitted, only for videos to later be removed or accounts suspended. FTC lawyers are reportedly preparing a potential lawsuit against YouTube, although no lawsuit has been filed and the company has not been formally accused of wrongdoing. If the FTC moves forward, this could become a major case for YouTube creators, content moderation, platform transparency, account bans and Big Tech regulation.

 

cross-posted from: https://lemmy.world/post/51294844

A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.

 

A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.

view more: next ›