Bogdan Deac
  • Home
  • Newsletter
  • Poetry
  • About
Sign in Subscribe
poetry

Tic-tac

  • Bogdan Deac

Bogdan Deac

11 Oct 2021
Share

Bate ceasul pe perete,
Scrieți cod, dar fără pete
Fiindcă-n caz că nu v-am zis
Ne apropiem de release.

Tica tic și tica toc
Să nu vă stresați deloc
Însă orice minuțel,
Hai să profităm de el!

Serios, stați liniștiți.
Nu v-am spus să vă grăbiți,
Dar în cruda realitate
Zilele sunt numărate.

If you enjoy my work please consider supporting it by buying me a coffee

PEAKS No 45: Kernel on Fire — Supply Chains Compromised, AI Goes Local, and Pixels Fall

Hi there! 🛡️ Security & Privacy * TanStack supply chain taken down by chained GitHub Actions exploit: An attacker combined a pull_request_target Pwn Request, GitHub Actions cache poisoning across fork/base trust boundaries, and in-memory OIDC token extraction to silently publish 84 malicious versions across 42 @tanstack/* npm packages — stealing
19 May 2026 4 min read

PEAKS No 44: Exploit Season: Dirty Frags, Dreaming Agents & Robot Dogs on a Budget

Hi there! 🛡️ Security & Privacy * Double Linux LPE week — Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284 / CVE-2026-43500) — Back-to-back kernel privilege escalation exploits hit in a single week. Copy Fail targets a page-cache write flaw and can be partially mitigated by rootless containers. Dirty Frag extends the same bug class through
13 May 2026 5 min read

PEAKS No 43: Copy Fail, Goblin Infestation & the Open-Source Everything Wave

Hi there! 🛡️ Security & Privacy * Notepad++ CVE-2026-3008: a %s format specifier in nativeLang.xml triggers a string injection in FindInFiles, enabling DoS crashes and memory address leaks that can bypass ASLR. Patched in v8.9.4; update immediately. More * GitHub RCE CVE-2026-3854 (CVSS 8.7): Wiz Research found a header
05 May 2026 5 min read
Bogdan Deac © 2026
Powered by Ghost