Show newer

"Risky Biz News: Chinese APT hacks subsidiaries, pivots to corporate headquarters

In other news: Google and Mozilla patch another Chrome & Firefox zero-day; Cisco patches its own zero-day; and new DarkRiver APT targets Russian defense sector."
riskybiznews.substack.com/p/ch

@pancake OK, yes, there were some connection errors until I manually entered the full path to the model in main.py. Perhaps a bit off-topic, but do you think it's possible to get that irc (liberchat) <-> telegram bot going again?

@malwaretech I'm guessing some mainstream news website, whatever it is, doubting very much it's something like: thegrayzone.com

@radareorg @pancake I tried using llama-2-7b-chat-codeCherryPop.Q5_K_M.gguf instead of llama-2-7b-chat-codeCherryPop.ggmlv3.q4_K_M.gguf, it's roughly 700mb bigger, gives similar results but supposedly more accurate ("large, very low quality loss - recommended"). Got it from here:
huggingface.co/TheBloke/llama2

modrobert boosted

@pancake Does that still require you to have AI API access, or does it work stand-alone? I'm still learning how it works in detail.

"Risky Biz News: China admits NSA hacked Huawei

In other news: iOS zero-days used to hack Egyptian presidential candidate; new Sandman APT targets telcos across the world; Russia's largest travel agency breached by pro-Ukraine hackers."
riskybiznews.substack.com/p/ch

@freemo I don't know what payment methods X accepts, was assuming it will require some kind of billing address (thinking KYC).

@freemo While paying might solve the bot problem, it also means you have to identify yourself which is bad if you care about privacy.

modrobert boosted
modrobert boosted

#libwebp 1.3.2 has two #security related flaws that have been fixed in main:
• Fix invalid incremental decoding check:
github.com/webmproject/libwebp
• Fix next is invalid pointer when WebPSafeMalloc fails:
github.com/webmproject/libwebp

While these are not as easy to exploit as CVE-2023-4863 it seems evident that there has been some gaps in libwebp fuzzing at google. Also CVE-2023-4863 was obviously assigned to a wrong project. #infosec #vulnerabilities #cve

modrobert boosted

brutal first blood for cytrox on iOS 17, but also damn that's some clear cut misuse.

modrobert boosted

if this infosec stuff doesn't work i'll start an ice cream shop

Show thread
modrobert boosted

Need to know whether a piece of hardware is supported by free software? #hNode has you covered! Its search engine will help you verify #freesoftware compatibility. u.fsf.org/3uj

@bohemianchic@infosec.exchange Besides family and friends; learning, but sometimes the more you know the more depressing it gets.

@malwaretech I'd rather take less bandwidth trough any kind of cable (fiber, STP, whatever) than being forced through WiFi

Show older
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.