Bogdan Deac
  • Home
  • Newsletter
  • Poetry
  • About
Sign in Subscribe
poetry

Un mic programator

  • Bogdan Deac

Bogdan Deac

17 Jan 2022
Share

Sunt un mic programator.
De mă iei peste picior
Îți livrez peste un release
Numai bug-uri și cod scris

Cu piciorul, din topor,
Și-ți mai pun și un back door.
Dar de-mi dai cafea festiv,
Brusc, devin inofensiv

Și lucrez fără-ncetare
Cât este ziua de mare
Și presar în toată forma
Codul cu alint aroma.

If you enjoy my work please consider supporting it by buying me a coffee

PEAKS No 45: Kernel on Fire — Supply Chains Compromised, AI Goes Local, and Pixels Fall

Hi there! 🛡️ Security & Privacy * TanStack supply chain taken down by chained GitHub Actions exploit: An attacker combined a pull_request_target Pwn Request, GitHub Actions cache poisoning across fork/base trust boundaries, and in-memory OIDC token extraction to silently publish 84 malicious versions across 42 @tanstack/* npm packages — stealing
19 May 2026 4 min read

PEAKS No 44: Exploit Season: Dirty Frags, Dreaming Agents & Robot Dogs on a Budget

Hi there! 🛡️ Security & Privacy * Double Linux LPE week — Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284 / CVE-2026-43500) — Back-to-back kernel privilege escalation exploits hit in a single week. Copy Fail targets a page-cache write flaw and can be partially mitigated by rootless containers. Dirty Frag extends the same bug class through
13 May 2026 5 min read

PEAKS No 43: Copy Fail, Goblin Infestation & the Open-Source Everything Wave

Hi there! 🛡️ Security & Privacy * Notepad++ CVE-2026-3008: a %s format specifier in nativeLang.xml triggers a string injection in FindInFiles, enabling DoS crashes and memory address leaks that can bypass ASLR. Patched in v8.9.4; update immediately. More * GitHub RCE CVE-2026-3854 (CVSS 8.7): Wiz Research found a header
05 May 2026 5 min read
Bogdan Deac © 2026
Powered by Ghost