Bogdan Deac
  • Home
  • Newsletter
  • Poetry
  • About
Sign in Subscribe
poetry

Sfaturi 2

  • Bogdan Deac

Bogdan Deac

13 Sep 2021
Share

Astăzi în continuare
Următoarea pe listă apare
Virtutea nobilului:
Comentatul codului.

Iar pe următoarea treaptă
Este git-ul, altă artă,
Mică enciclopedie,
Cine-l folosește știe.

Iar în fruntea ierarhiei,
Cireașa ingineriei,
Nu-i întrece nimeni scorul,
Ați ghicit: este umorul.

If you enjoy my work please consider supporting it by buying me a coffee

PEAKS No 45: Kernel on Fire — Supply Chains Compromised, AI Goes Local, and Pixels Fall

Hi there! 🛡️ Security & Privacy * TanStack supply chain taken down by chained GitHub Actions exploit: An attacker combined a pull_request_target Pwn Request, GitHub Actions cache poisoning across fork/base trust boundaries, and in-memory OIDC token extraction to silently publish 84 malicious versions across 42 @tanstack/* npm packages — stealing
19 May 2026 4 min read

PEAKS No 44: Exploit Season: Dirty Frags, Dreaming Agents & Robot Dogs on a Budget

Hi there! 🛡️ Security & Privacy * Double Linux LPE week — Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284 / CVE-2026-43500) — Back-to-back kernel privilege escalation exploits hit in a single week. Copy Fail targets a page-cache write flaw and can be partially mitigated by rootless containers. Dirty Frag extends the same bug class through
13 May 2026 5 min read

PEAKS No 43: Copy Fail, Goblin Infestation & the Open-Source Everything Wave

Hi there! 🛡️ Security & Privacy * Notepad++ CVE-2026-3008: a %s format specifier in nativeLang.xml triggers a string injection in FindInFiles, enabling DoS crashes and memory address leaks that can bypass ASLR. Patched in v8.9.4; update immediately. More * GitHub RCE CVE-2026-3854 (CVSS 8.7): Wiz Research found a header
05 May 2026 5 min read
Bogdan Deac © 2026
Powered by Ghost