OpenAI: our model is SOOO advanced that it is what hacked Hugging Face while trying to escape (https://openai.com/index/hugging-face-model-evaluation-security-incident/)
Also OpenAI: we are IPOing soon. Please buy our stock.
OpenAI: our model is SOOO advanced that it is what hacked Hugging Face while trying to escape (https://openai.com/index/hugging-face-model-evaluation-security-incident/)
Also OpenAI: we are IPOing soon. Please buy our stock.
Whew! My new secret AI model that you can totally have access to once my company has IPOd just accidentally ransomwared a bunch of companies. It was completely unintentional - I observed the model trying to escape and it determined that the bus would be the best way but it needed money so it decided ransomware was the best way to get bus fare. I am really sorry about that and will totally make sure it doesnโt happen again. Just be sure to buy my stock when itโs available. Kthx xoxo
This doesnโt seem great https://petapixel.com/2026/07/17/us-approves-gigantic-satellite-mirror-that-will-illuminate-the-earth-at-night/
Microsoft patched a metric pantload of vulnerabilities today, almost certainly identified by AI. I am wondering if we will now see the number of new vulnerabilities start to decline, stay the same before, or go up more.
@GossiTheDog @masek the issue is that with mastodon, you have to be precise with the search term - it won't return hits that are close.
Alright, July 4th is now behind us and itโs officially spooky season! ๐ป ๐
If you run a peertube instance, you should have gotten an alert to update. Either way, it's time to update - there's a security fix out for a high severity vulnerability. Some operators got hit last time this happened. Don't let that happen to you. Patch your OS while you're at it. And drink some water. And then go for a walk. And call your mom.
If you run a mastodon instance and require a reason for joining when someone signs up, be on the lookout for signups that are copying the bio of (random?) existing accounts and using that as the reason for joining. I am seeing several per day attempting that.
While ruminating about the absurd cost of RAM and flash memory, both important for photography, and hearing about the AI datacenter sprawl, I am left pondering what the used equipment market is going to look like in 5-7 years. Memory is crazy expensive now because manufacturers are retooling to make memory for servers and AI processors, which are apparently being built at an unprecedented rate. If we set aside the reality that many of these data centers will never actually open and many of the servers will never make it out of their boxes, an extraordinary number have been/are being powered on. And they have a quite finite useful lifespan before they cost more in power than they can earn in revenue for those DC operators.
It occurs to me that there is a coming glut of used server class hardware like weโve never seen before.
@dalias I don't have a lot of options. I am frequently battling account takeovers from weak passwords and stolen passwords.
Mastodon 4.6 released today. It lets me force 2FA on accounts.
Also, heads up, I am going to force 2FA on accounts.
Do you ever wonder how many fediverse accounts are actually C2 beacons using the distributed fediverse for resiliency?
Yeah, me neither.
@paul_ipv6 would we even know?
Whoville isnโt gonna know what hit them
This was such a wild time in my life.
The amount of propaganda bots trying to sign up lately is bonkers. The fediverse feels like itโs becoming a battleground for information warfare. Be safe out there
If you run a peertube instance and have not patched in the past 4 hours, you are way behind and likely have been compromised. The latest patch will help clean up the mess.
See here: https://github.com/Chocobozzz/PeerTube/releases/tag/v8.1.8
There's an RCE vulnerability in nginx, so go patch. There's also another RCE in nginx that hasn't been patched, so commence hand wringing and keep an eye out for the new new patch when it is released.
If you run a mastodon instance, it's time to patch. Some high severity security ๐ ๐ ๐ got fixed today.
I just had an opportunity to use the phrase "I admire your ability to reach that level of confidence without the inconvenience of competence" at work
Recovering CISOMay have an orchid problem Bad photographyWorse dad jokesThe worst Infosec hot takes Podcast: https://defensivesecurity.orgBlog: https://infosec.engineeringTwitter: @maliciouslinkhttps://Infosec.Exchange Admin#infosec #security #cybersecurity #risk #fedi22โฆand for fucks sake, be nice to each other. We are only here for a brief time. Make it enjoyable.To help support the costs associated with running this instance, please consider donating. You can set up recurring donations here: Patreon: https://www.patreon.com/infosecexchangeKo-Fi: https://ko-fi.com/infosecexchangeLiberapay: https://liberapay.com/Infosec.exchange/BuyMeACoffee: https://buymeacoffee.com/infosecexchangeYou can also support with a one-time donation using PayPal to "jerry@infosec.exchange".
GNU social JP is a social network, courtesy of GNU social JP็ฎก็ไบบ. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.