thomas, to random
@thomas@metalhead.club avatar

Metalhead.club patch preview.
It's a woven patch for better details. 🤘

#metalheadclub #patch

lukaso666, to diy Polish
@lukaso666@chaos.social avatar

🪡 🧵 :anarchopunk:

#DIY #patch #crust #punk

cyberpatch, to linux
@cyberpatch@skaverat.net avatar

Working on a couple fox designs.

A more detailed and colored version is still being worked on.

But in the meantime I've also made the stylized xenia design by @chromacat248 into a B/W and trans-pride patch.

Thinking about manufacturing them next month.

Anyone interested in them? Poll below

A simple vectorized graphic of xenia, completely black and white

linuxmagazine, to fedora
@linuxmagazine@fosstodon.org avatar
83r71n, to Cybersecurity

Google has introduced Kernel Address Sanitizer (KASan) to enhance the security of Android firmware. KASan is designed to detect memory corruption vulnerabilities and stability issues before they affect user devices. It works by monitoring memory access operations to ensure they only target valid regions, identified in a shadow memory area. This tool has already helped identify and fix over 40 memory safety bugs in Android firmware. KASan is particularly useful for bare-metal targets, requiring specific compiler options and strategies to implement effectively. It's part of Google's efforts to address the security challenges posed by the vast number of Android devices and the fragmented ecosystem that makes vulnerability patching difficult.

https://security.googleblog.com/2024/03/address-sanitizer-for-bare-metal.html

#cybersecurity #google #kernel #kasan #android #firmware #bugs #baremetal #patch

canard164, to firefox French

Patch now: Mozilla patches two critical vulnerabilities in Firefox | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/03/patch-now-mozilla-patches-two-critical-vulnerabilities-in-firefox

> Mozilla released an update of Firefox to fix two critical security vulnerabilities that together allowed an attacker to escape the sandbox.

minioctt, to mastodon Italian

Mio messaggio, "Mastodon per gli amici Colabrodon"La mia domanda è , ma il sottostante è reale, ormai la situazione è così che pur non ospitando personalmente mi preoccupo: che cavolo sta succedendo a quel ? In meno di 2 settimane siamo già alla terza di critica, che ormai escono con la stessa frequenza delle fantomatiche meteo dei comuni. 👹

Ormai gli amministratori che hanno a che fare con questa storia stanno iniziando a pensare che gli sviluppatori li stiano prendendo per il culo… e non posso fare altro che empatizzare: questa è proprio la cosa che io, da developer, farei per trollare eventuali sysadmin, che dovrebbero poi correre appresso al mio eventuale codice mal scritto, in un programma che dal nulla gli fa uscire a sorpresa in home in color rosso sangue “Aggiornamento critico di sicurezza disponibile!“, ma non offre purtroppo nessuna funzione di aggiornamento con 1 click (al contrario di robe come WordPress). 🦧

Purtroppo, scherzi e a parte, è una cosa specialmente perché, se in Mastodon si stanno trovando così tante , chissà in piattaforme meno popolari e quindi meno controllate e testate… a meno che non sia un caso di impigrimento dei dev, ma su questo non posso fare grandi . 😩

https://octospacc.altervista.org/2024/02/16/il-colabrodon/

linuxmagazine, to security
@linuxmagazine@fosstodon.org avatar
deltatux, to mastodon

A new vulnerability in Mastodon was disclosed allowing attackers to perform account takeovers if they successfully exploit this vulnerability.

This vulnerability is being tracked as CVE-2024-23832 & has a 9.4/10 CVSS3 score, so it's a critical vulnerability.

As always, if you run a Mastodon instance, it's best if you can patch to the latest version as soon as possible.

www.bleepingcomputer.com/news/security/mastodon-vulnerability-allows-attackers-to-take-over-accounts/

#mastoadmin #mastodon #fediverse #patch #vulnerability #CVE_2024_23832

83r71n, to Cybersecurity

A popular file transfer software from Fortra called GoAnywhere Managed File Transfer (MFT) has been found to have a serious security flaw. This flaw, known as a path traversal weakness, could give anyone free administrator rights over the system. The flaw was discovered in December 2023 by cybersecurity researchers Mohammed Eldeeb and Islam Elrfai from Spark Engineering Consultants and disclosed to GoAnywhere’s developer, Fortra. The flaw has a severity score of 9.8 out of 10, making it extremely critical. Users are urged to patch the software immediately to prevent potential misuse and avoid further issues.

https://www.fortra.com/security/advisory/fi-2024-001

NVAccess, to news
@NVAccess@fosstodon.org avatar

NVDA double release day! NVDA 2023.3.2 fixes the fix that wasn’t fully fixed in the first fix. Please do read the full announcement and download at: https://www.nvaccess.org/post/nvda-2023-3-2/

And to go with it, NVDA 2024.1 Beta 5 includes the fix from 2023.3.2, as well as documentation, logging and translation updates! Read more and download from: https://www.nvaccess.org/post/nvda-2024-1beta5/

MuSociety, to free German
@MuSociety@musicians.today avatar
Danthrax, to retrogaming
@Danthrax@retro.pizza avatar

Not content to only improve various shortcomings of the Saturn version of Castlevania: Symphony of the Night, Meduza Team updated their patch to include English text and voices! Read about it in my story:

https://www.segasaturnshiro.com/2024/01/04/new-castlevania-patch-adds-english-text-speech/

deltatux, to random

There is a new remote code execution vulnerability in Splunk that has been recently disclosed. It has a CVSS score of 8.8/10 and is currently tracked as CVE-2023-46214.

Splunk recommends admins to upgrade to 9.0.7 or 9.1.2 depending on which branch you're currently on.
www.helpnetsecurity.com/2023/11/27/cve-2023-46214-poc/

Emily, to infosec

My friends, for years I have given these three recommendations to end users as my top tips for security. Do you have any others that you use as your top three instead?

  1. all your devices when patches are available.
  2. Use - any kind, even SMS, is better than nothing, but an authenticator app or hardware token (like a yubikey) is even better.
  3. Use a to generate and store unique passwords for every account. I personally use 1Password, but there are other good ones out there.
technewslit, to news
@technewslit@journa.host avatar

A vaccine delivered with a patch device is shown in a clinical trial to generate neutralizing antibodies against measles and rubella similar to conventional injections.

https://sciencebusiness.technewslit.com/?p=45443

doctormo, to foss
@doctormo@floss.social avatar

The developer team decided to get the 1.3.2 patch release out the door right away, you can download it here: https://inkscape.org/release/inkscape-1.3.2/

We would have liked to have gotten it perfect with regards to recovering data. The remaining issue is that it won't mark the file as dirty if it fixes it, so you'll have to save as or modify the document and save as normal.

Sorry about the issues everyone!

Hell Let Loose - Patch 14.5 Releases Today at 2pm GMT! - Steam News (store.steampowered.com)

Hey everyone, Back into the ruthless darkness of war! We’re so excited to see you on the frontlines in Patch 14.5! Battle on the dusk time variant of El Alamein which requires you to adapt to new dynamics — dusk lighting conditions sees the map permeated with fog — paving the way for different approaches to becoming the...

majorlinux, to tes
@majorlinux@toot.majorshouse.com avatar

Might be time for that second playthrough.

Starfield finally has a DLSS update for everyone - Desk Chair Analysts

https://dcanalysts.net/starfield-finally-has-a-dlss-update-for-everyone/

#Bethesda #DLSS #Microsoft #Nvidia #Patch #PC #Starfield #Steam #Xbox #GamingNews

etherdiver, (edited ) to modularsynth
@etherdiver@ravenation.club avatar

Here's a look at the newest track from Metaphysical Shitposting! This one was entirely modular/semi modular gear. #MiniBrute2s on one voice, 0-Coast (thru Strega) on one, #Strega doing an intermittent drone and a final voice that was made with noise thru a bandpass filter (WMDevices #C4RBN filter) that then goes thru a flanger (Happy Nerding FX Aid XL).

Delay via Mimeophon; reverb via Desmodus Versio. Both routed via mixer's aux sends.

The track:
https://etherdiver.bandcamp.com/track/cosmic-horror-at-the-strip-mall-parking-lot

#modular #Patch

PogoWasRight, to infosec

Attorney General James Secures $450,000 from US Radiology Specialists for failing to protect patient data: https://ag.ny.gov/press-release/2023/attorney-general-james-secures-450000-medical-company-providing-services-western

The litigation was not under but was under NYS law: Executive Law § 63(12), GBL §§ 349 and 899-bb.

Direct link to Assurance of Discontinuation: https://ag.ny.gov/sites/default/files/settlements-agreements/us-radiology-aod.pdf

Didn't update/patch timely.

Previous coverage of this breach had been somewhat confusing, as I reported here at the time: https://www.databreaches.net/late-notification-raises-questions-about-a-us-radiology-specialists-breach-last-year/

State attorneys general continue to impose more enforcement penalties for failing to secure patient data than HHS OCR has imposed.

kawa, (edited ) to linux
kkarhan,

@kawa I wounder if anyone made a so instead of we get for each initialized by the ...

Ideally complete with some code so one can simply toggle between the two.

badtuple, to random
yeti,
@yeti@emacs.ch avatar
jerome_herbinet, to windows French
ButterflyOfFire, to mastodon French
@ButterflyOfFire@mstdn.fr avatar

Mastodon vient de publier des correctifs pour certaines anciennes versions ainsi qu’une version corrective 4.2.1

Si votre instance tourne encore sous une ancienne version, il est très recommandé de la mettre à jour vers une version plus récente et maintenue.

Source : https://mastodon.social/@MastodonEngineering/111211854006817590

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • ethstaker
  • cisconetworking
  • tester
  • modclub
  • everett
  • cubers
  • tacticalgear
  • Leos
  • megavids
  • normalnudes
  • anitta
  • lostlight
  • All magazines