Bogdan Deac
  • Home
  • Newsletter
  • Poetry
  • About
Sign in Subscribe
poetry

libpcap

  • Bogdan Deac

Bogdan Deac

28 Feb 2022
Share

Nu e om fără greșeală,
Nu e software fără bug,
Vin pachetele-n rafală
Și de timp încerc să trag.

libpcap-ul dă și zbiară:
“Vin într-una, mii si mii,
Buffer-ele dau pe-afară,
Zi un’ să le pun de știi!”

Fibra dă să se topească,
Urlă fan-urile-n cor,
RAM-ul mai mai să plesnească,
De o vacanță mi-e dor

If you enjoy my work please consider supporting it by buying me a coffee

PEAKS No 46: AI Agents, npm Supply Chain Attacks, GitHub Breach, Gemini 3.5

Hi there! 🛡️ Security & Privacy * Mini Shai-Hulud strikes again: A compromised npm maintainer account published 637 malicious versions across 317 packages — including echarts-for-react (3.8M dl/mo) and size-sensor (4.2M dl/mo) — in a 22-minute automated burst. The payload harvests AWS keys, GitHub tokens, Vault secrets, SSH keys, and
26 May 2026 4 min read

PEAKS No 45: Kernel on Fire — Supply Chains Compromised, AI Goes Local, and Pixels Fall

Hi there! 🛡️ Security & Privacy * TanStack supply chain taken down by chained GitHub Actions exploit: An attacker combined a pull_request_target Pwn Request, GitHub Actions cache poisoning across fork/base trust boundaries, and in-memory OIDC token extraction to silently publish 84 malicious versions across 42 @tanstack/* npm packages — stealing
19 May 2026 4 min read

PEAKS No 44: Exploit Season: Dirty Frags, Dreaming Agents & Robot Dogs on a Budget

Hi there! 🛡️ Security & Privacy * Double Linux LPE week — Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284 / CVE-2026-43500) — Back-to-back kernel privilege escalation exploits hit in a single week. Copy Fail targets a page-cache write flaw and can be partially mitigated by rootless containers. Dirty Frag extends the same bug class through
13 May 2026 5 min read
Bogdan Deac © 2026
Powered by Ghost