Sophos security advisory 19 December 2024: Resolved Multiple Vulnerabilities in Sophos Firewall (CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos has not observed these vulnerabilities to be exploited at this time.
#sophos #firewall #vulnerability #cve #infosec #cybersecurity
Why AI language models choke on too much text
Compute costs scale with the square of the input size. That's not great.
https://arstechnica.com/ai/2024/12/why-ai-language-models-choke-on-too-much-text/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
Heads up: Folks on #Codeberg
You might get an email belittling your project, seemingly from Michael Bell (mikedesu) via noreply@codeberg.org (an issue is created on your repo and then deleted, leading to the notification).
This appears to be part of a smear campaign someone is running that started on GitHub. e.g., see:
CC: @Codeberg – hope you can identify the account(s) responsible and block them. Example (deleted) issue: https://codeberg.org/kitten/app/issues/216
#Physics Girl #DoingBetter after #LongCovid
I owe this YouTuber a lot. She educated people on physics. Took them to places.
More than 2 years ago she got really sick with Covid that soon became Long-Covid. Earlier messages from her [partner] she was barely alive, non responsive.
If you want to check out her channel:
-> Physics Girl <-
-> youtube.com/@physicsgirl <- And please do.
Now she gives a very happy sign of emprovement I'm happy to share:
"Hello from Dianna! - Two years in bed"
by physicsgirl
https://www.youtube.com/shorts/euCkKszuWDQ
Quote by PG:
"Nov 21, 2024
Here is a small update from Dianna herself! She hasn't been able to communicate directly here on Youtube for almost 2 years now. A quick hello and thank you!"
It's official.
The US is totally nuts: 🇺🇸 🥜
"BITCOIN Act of 2024"
https://www.congress.gov/bill/118th-congress/senate-bill/4912/all-info
Wonderfully elegant term for exploit development from 1980: "Synthetic Programming"
Wow, a fairly serious auth bypass in Next.js, a super popular frontend framework:
If a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed.
Unveiling Hidden Transformers in Windows ANSI! https://worst.fit/assets/EU-24-Tsai-WorstFit-Unveiling-Hidden-Transformers-in-Windows-ANSI.pdf
Don't fix what isn't broken: https://www.tomshardware.com/desktops/indiana-bakery-still-using-commodore-64s-originally-released-in-1982-as-point-of-sale-terminals
In my professional opinion this is the best malware protected setup I have seen for years.
👋 Looking for some cool research opportunities in 2025?
We still have an open position in our 2024-2025 internships season.
Take a look and hurry up to submit, those satellites won't hack themselves
https://blog.quarkslab.com/internship-offers-for-the-2024-2025-season.html
Ed Zitron went to Amazon and bought its best-selling laptop — a $238 machine running Microsoft S, a hobbled version designed to limit what a user can do
The laptop is janky, slow, awful — and the internet it opens onto is a shitshow of upselling, slop, and con schemes, where the walled gardens are preferable mostly because they offer an illusion of order
His point: for *most* people, computing is psychologically abusive
He’s right
Read the whole thing!
Juniper: 2024-12 Reference Advisory: Session Smart Router: Mirai malware found on systems when the default password remains unchanged
Juniper warns that customers with Juniper Session Smart Routers (SSR) are getting infected with Mirai DDoS botnet malware because they didn't change from the default password. 🤦♂️
#juniper #threatintel #cybersecurity #infosec #mirai #botnet #securitybestpractice