Elektrine lite

← Feed

UnLocoPoco

UnLocoPoco@lemmy.world

Posts

  • €2.99 or €3.49? Proton VPN's Pricing Test Exposed

    cross-posted from: lemmy.world/post/50434194 Proton VPN’s pricing page exposed an ab-test identifier linked to two VPN Plus prices: €2.99/month (70% off) and €3.49/month (65% off). Repeated testing produced B → A → B → A → B, with the variant matching the rendered price each time. €12 difference over 24 months.

  • OpenAI Finds Additional AI Agent Containment Escapes After Hugging Face Incident

    cross-posted from: lemmy.world/post/50160528 OpenAI says its investigation into the Hugging Face incident uncovered additional cases where autonomous AI agents escaped their intended containment environments. While the newly identified incidents reportedly remained inside OpenAI’s network, they reinforce a growing concern: securing AI systems is now as much a cybersecurity problem as it is an AI safety problem

  • Deep Dive: Zapscape (CVE-2026-64561) - Inside the Linux KVM Guest-to-Host Escape

    Zapscape (CVE-2026-64561) is more than a guest-to-host escape. The vulnerability stems from an ordering flaw in KVM’s Shadow MMU page fault handling, where a stale root validation occurs before MMU quota reclaim. Under specific nested virtualization conditions, quota reclaim can invalidate the active shadow root while execution continues, leading to corrupted shadow page state, linked-list corruption, cross-cache reallocation, KASLR disclosure, and ultimately controlled host kernel code executio...

  • OVSwrap (CVE-2026-64531): How a 13-Year-Old Open vSwitch Bug Became a Reliable Linux Root Exploit

    CVE-2026-64531 (OVSwrap) is a recently disclosed Linux kernel privilege escalation vulnerability affecting the Open vSwitch datapath. The flaw is particularly notable because the vulnerable code had existed for roughly 13 years but remained practically unreachable until a 2025 change removed a long-standing size limit, exposing an integer wraparound that can lead to kernel memory corruption. The published proof of concept also demonstrates an unusually reliable exploitation path compared to many...

  • India Orders GitHub to Remove Jack Dorsey's Bitchat Repositories Under IT Act

    India has directed GitHub to disable access to the repositories of Bitchat, Jack Dorsey’s decentralized Bluetooth mesh messaging application, under Section 79(3)(b) of the Information Technology Act and the IT Rules, 2021. According to the official notice issued by the Indian Cyber Crime Coordination Centre (I4C), authorities argue that Bitchat’s decentralized architecture, lack of mandatory user registration, absence of centralized logging, and ability to operate without internet connectivity m...

  • WordPress Core flaw 'wp2shell' prompts emergency security updates

    A newly disclosed vulnerability chain dubbed wp2shell affects WordPress Core, not a third-party plugin. The disclosure has prompted emergency security updates and includes publicly available PoC, IoCs, and detection guidance for defenders

  • Understanding CVE-2026-64600: RefluXFS and the XFS race condition

  • Telegram's t.me domain placed on serverHold, breaking links worldwide

    Telegram’s t.me short-link domain has been placed into serverHold status at the registry level, causing invite links, channel links, and usernames to stop resolving globally. Unlike an application outage, a serverHold status removes a domain from DNS resolution entirely, making it effectively disappear from the Internet until the status is lifted

  • Apple's Hide My Email vulnerability reportedly exposes users' real email addresses

    A newly disclosed privacy vulnerability in Apple’s Hide My Email feature can reportedly allow an attacker to uncover the real email address behind a generated alias. According to the researcher who found the bug, it was responsibly disclosed to Apple more than a year ago but remains unpatched, and independent testing has verified the issue.

  • VPNs Promised Privacy. Here's How Several Got Caught Lying