Седмицата (1–6 декември)

Post Syndicated from Надежда Радулова original https://www.toest.bg/sedmitsata-1-6-dekemvri/

Седмицата (1–6 декември)

Първият протест (тогава митинг), в който участвах, беше на 3 декември 1989 г. на колодрума на остров Свобода в Пазарджик, двайсет и три дни след паметния 10 ноември. Бях на 14 години и отидох на митинга заедно с голяма част от класа ми; заведе ни класната ни ръководителка Евелина Трангозова, тогава двайсет и четири годишна учителка по английски и един от първите членове на току-що възстановената Радикалдемократическа партия в града. За мнозина това да заведеш учениците си осмокласници на митинг изглеждаше дръзко и неприемливо политизиране (вероятно и сега би изглеждало така), но аз и до днес съм благодарна на нашата Мис (така наричахме класната), че ме направи съзнателна свидетелка на епохален момент, който щеше да промени пътя на абсолютно всички.

Когато преди няколко дни, на 1 декември, гледах младите хора, изпълнили центъра на София, си помислих, че и сега, както и преди 36 години, исканията на протестиращите се свеждат всъщност до едно и също – свобода (в цялата условност на разбирането ѝ), справедливост, зачитане на правата на всеки… Само дето като че ли някога мечтаехме за бъдеще, в което да напуснем дома си и да видим света, а сега децата-на-света се борят за бъдеще тук, в застрашения си дом. Но и през 1989-та, както и през 2025-та, провокаторите са на линия, спекулациите избиват на повърхността като мръсна пяна и все се намира някоя и друга политическа мутра, която да яхне и осребри чуждия гняв, да си изплете кошницата и да свърши някоя и друга мерзопакост.

Какъв е тогава смисълът от протести, ще попитате, при положение че първо пораснахме, а после остаряхме по площадите с все същите лозунги, мечти и горести. Дали не се оказва, че през цялото време сме протестирали за непостижими неща? И има ли изобщо смисъл да се протестира за непостижимото?

Наскоро ми попадна статия за една от големите екоактивистки от края на ХХ век Джулия Бътърфлай Хил (р. 1974), която между 1997 и 1999 г. живее в продължение на 738 дни на върха на 60-метрова хилядолетна секвоя на име Луна, за да предотврати планираното ѝ отсичане. След две години в обятията на Луна Джулия подписва споразумение с Pacific Lumber Company за запазването на дървото и слиза на земята.

Да, Джулия Хил е късметлийка – защото не всички цели могат да бъдат постигнати в рамките на един човешки живот. И понякога се изискват непомерни усилия и търпение, и вяра – дано младите навреме осъзнаят това: че битката с вятърните мелници, освен да донесе горчивина за сражаващите се, ще задвижи и пренесе енергия и за идващите след тях. И че най-суровата, но и най-важната битка е за онова, което няма да се случи днес и утре, и може би никога, докато сме живи, но ще продължи да има смисъл дълго след нас.

Какви следи оставяме? С действията и бездействията си. С думите и с премълчаванията. Така бихме могли да обобщим и темата на броя ни тази седмица.

От една страна са градовете, които осъзнато и безсъзнателно обитаваме. Да вземем например втория по големина град – Пловдив. Какво се случва с него шест години след като беше Европейска столица на културата с всичките там интелектуални и финансови инвестиции във въпросната титла. Георги Велев анализира днешната ситуация според постигнатото и пропиляното в „Шест години по-късно. Изгуби ли културата в Пловдив своята посока?“.

Оставаме на урбанистична тема със Силвина Фурнаджиева от „Екипът на София“, която в статията „От „на парче“ към ясни цели. Как общината да работи ефективно?“ демонстрира стъпка по стъпка начина един град да се управлява чрез дългосрочна визия.

От темата за градовете минаваме към управлението на „полиса“ и държавата. Какво се случва със съвременната демокрация; пред какви избори и възможности е изправена; струва ли се да се борим за нея, когато средната класа е застрашена, а политическите свободи и правата на гражданите са противопоставени на икономическото им благосъстояние; не губи ли тягата си изобщо идеята за демокрация при нарастващия риск от разрив между САЩ и Европа? Повече по тези въпроси четете в есето на Искрен Иванов „(Не)демократичният световен ред“.

В основата на съвременната ни представа за демокрация неизменно са стояли свободата на словото и наличието на независими медии. В епохата на постистината, фалшивите новини, дезинформацията и пропагандата именно тази част от основата на демокрацията е сериозно разклатена. В анализа си „Има ли надежда за надеждните новини?“ Светла Енчева обръща внимание на нуждата демокрацията да бъде защитена именно чрез медийната свобода, както и на рисковете, които носи капсулирането или изчезването на качествено медийно съдържание. Следващата събота, 13 декември, Светла ще гостува на Владислав Севов във видеопоредицата ни „Тоест разговаряме“. Гледайте я на живо от 16:00 ч. в YouTube Live. Може предварително да ѝ зададете въпрос и да довършите изречението в нашата анкета.

За разлика от Светла, на Е.Т. не може да ѝ задавате въпроси, защото тя вече ви е дала всички отговори в новия епизод, „в който мразим всички“ и „айсиктирдействително!“.

В Sic transit gloria Boyki Емилия Милчева се връща към протеста от началото на седмицата и разнищва брауновото движение вследствие на създалото се в триъгълника на властта напрежение: най-вече хаотичните танцови стъпки на Борисов, който непрестанно настъпва опърпания шлейф на партията си и се препъва в него; и опитите на (п)резидента да се превърне в бенефициер на случващото се по площадите.

За това какви следи ще оставим след себе си и на каква цена, говори и Зорница Христова в последната си за годината колонка „По буквите“, в която на фокус са три книги – на Йорданка Белева, Роб Дън и Джон Бърджър. Апропо заглавието на Роб Дън е „Естествена история на бъдещето“ – чудесен реторически пример за това как миналото не е приключило, а винаги дебне зад ъгъла, определя бъдещите ни ходове, неизбежно предстои.

Завършваме в светлата следа на музиката с интервю на Ина Иванова с хоровата диригентка Яна Делирадева. „Този живот може да се изпее“ – казва Яна с убеденост, която ни е особено необходима днес, когато за пореден път пълним площадите, обединени повече от гняв, отколкото от надежда.

А ако искате да го пеем този живот заедно, подкрепете ни! Вие сте тези, които дават сила и смисъл на гласа ни.

Friday Squid Blogging: Vampire Squid Genome

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/friday-squid-blogging-vampire-squid-genome.html

The vampire squid (Vampyroteuthis infernalis) has the largest cephalopod genome ever sequenced: more than 11 billion base pairs. That’s more than twice as large as the biggest squid genomes.

It’s technically not a squid: “The vampire squid is a fascinating twig tenaciously hanging onto the cephalopod family tree. It’s neither a squid nor an octopus (nor a vampire), but rather the last, lone remnant of an ancient lineage whose other members have long since vanished.”

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Metasploit Wrap-Up 12/05/2025

Post Syndicated from Jack Heysel original https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-12-05-2025

Twonky Auth Bypass, RCEs and RISC-V Reverse Shell Payloads

This was another fantastic week in terms of PR contribution to the Metasploit Framework. Rapid7’s very own Ryan Emmons recently disclosed CVE-2025-13315 and CVE-2025-13316 which exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). The auxiliary module Ryan submitted which exploits both of these CVEs was released this week. Community contributor Valentin Lobsein aka Chocapikk has returned to the PR queue with a welcomed vengeance. Two modules from Chocapikk were landed this week, a Monsta FTP downloadFile Remote Code Execution module along with a WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE. In addition to some awesome module content, community contributor bcoles added Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

New module content (5)

Twonky Server Log Leak Authentication Bypass

Author: remmons-r7

Type: Auxiliary

Pull request: #20709 contributed by remmons-r7 

Path: gather/twonky_authbypass_logleak 

AttackerKB reference: CVE-2025-13316

Description: This module exploits two CVEs: CVE-2025-13315 and CVE-2025-13316. Both CVEs exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). Then, because the module uses hardcoded keys, it decrypts those credentials.

Monsta FTP downloadFile Remote Code Execution

Authors: Valentin Lobstein [email protected], msutovsky-r7, and watchTowr Labs

Type: Exploit

Pull request: #20718 contributed by Chocapikk 

Path: multi/http/monsta_ftp_downloadfile_rce 

AttackerKB reference: CVE-2025-34299

Description: This add module for CVE-2025-34299. The module exploits a vulnerability in the downloadFile action which allows an attacker to connect to a malicious FTP server and download arbitrary files to arbitrary locations on the Monsta FTP server.

WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE

Authors: Emiliano Versini, Khaled Alenazi (Nxploited), Valentin Lobstein [email protected], and dledda-r7

Type: Exploit

Pull request: #20720 contributed by Chocapikk 

Path: multi/http/wp_ai_engine_mcp_rce 

AttackerKB reference: CVE-2025-11749

Description: This adds a new exploit module for an unauthenticated vulnerability in the WordPress AI Engine plugin, which has over 100,000 active installations. The vulnerability allows an attacker to create an administrator account via the MCP (Model Context Protocol) endpoint without authentication, then upload and execute a malicious plugin to achieve remote code execution. The vulnerability is being tracked as CVE-2025-11749.

Linux Command Shell, Reverse TCP Inline

Authors: bcoles [email protected] and modexp

Type: Payload (Single)

Pull request: #20712 contributed by bcoles 

Path: linux/riscv32le/shell_reverse_tcp

Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

Linux Command Shell, Reverse TCP Inline

Authors: bcoles [email protected] and modexp

Type: Payload (Single)

Pull request: #20712 contributed by bcoles 

Path: linux/riscv64le/shell_reverse_tcp

Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

Enhancements and features (3)

  • #20658 from jheysel-r7 – This adds a number of accuracy enhancements to the ldap_esc_vulnerable_cert_finder module. It also adds a CertificateAuthorityRhost datastore option to the esc_update_ldap_object module so the operator can specify an IP Address explicitly in cases where the hostname cannot be resolved via DNS.
  • #20677 from zeroSteiner – This enables sessions to MSSQL servers that require encryption. These changes add a new MsTds::Channel which leverages Rex’s socket abstraction to facilitate the necessary encapsulation for the TLS negotiation.
  • #20741 from SaiSakthidar – This removes CAIN as an output format for collected hashes.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Ubiquiti USP-PDU-PRO Power Distribution Pro Mini-Review

Post Syndicated from Ryan Smith original https://www.servethehome.com/ubiquiti-usp-pdu-pro-power-distribution-pro-mini-review/

Ubiquiti’s USP-PDU-PRO is a high-end, 2U PDU with 16 outlets plus four USB-C ports for power, as well as network capabilities for individual port monitoring and power cycling

The post Ubiquiti USP-PDU-PRO Power Distribution Pro Mini-Review appeared first on ServeTheHome.

[$] Eventual Rust in CPython

Post Syndicated from daroc original https://lwn.net/Articles/1046933/

Emma Smith and Kirill Podoprigora, two of Python’s core developers, have
opened a
discussion
about including Rust code in CPython, the reference implementation of
the Python programming language. Initially, Rust would only be used for optional
extension modules, but they would like to see Rust become a required dependency
over time. The initial plan was to make Rust required by 2028, but Smith and
Podoprigora indefinitely postponed that goal in response to concerns raised in the discussion.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1049417/

Security updates have been issued by AlmaLinux (buildah, firefox, gimp:2.8, go-toolset:rhel8, ipa, kea, kernel, kernel-rt, pcs, qt6-qtquick3d, qt6-qtsvg, systemd, and valkey), Debian (chromium and unbound), Fedora (alexvsbus, CuraEngine, fcgi, libcoap, python-kdcproxy, texlive-base, timg, and xpdf), Mageia (digikam, darktable, libraw, gnutls, python-django, unbound, webkit2, and xkbcomp), Oracle (bind, firefox, gimp:2.8, haproxy, ipa, java-25-openjdk, kea, kernel, libsoup3, libssh, libtiff, openssl, podman, qt6-qtsvg, squid, systemd, vim, and xorg-x11-server-Xwayland), Slackware (httpd and libpng), SUSE (chromedriver, kernel, and python-mistralclient), and Ubuntu (cups, linux-azure, linux-gcp, linux-gcp, linux-gke, linux-gkeop, linux-ibm-6.8, linux-iot, and mame).

Voices of the Experts: What to Expect from Our Predictions Webinar

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/it-experts-voices-2026-predictions-webinar-teaser

Every year, Rapid7 brings together some of the most experienced minds in cybersecurity to pause, zoom out, and take stock of where the threat landscape is heading. Last year’s predictions webinar sparked lively debate among practitioners, leaders, and researchers alike, and many of those early warnings were proven accurate.

We talked about expanding attack surfaces, the acceleration of zero-day exploitation, and the shifting role of SecOps teams navigating unpredictable regulatory and operational pressure. We explored how AI was beginning to shape attacker behavior and how defenders could prepare for a world where speed and context matter more than ever. Looking back, the real takeaway was not just the predictions themselves. It was how quickly the landscape shifted around them.

This year’s predictions webinar builds on that momentum. The conversation feels different now. Threat actors have adapted. Business environments have tightened. Defenders are operating with more constraints and higher expectations than at any point in recent memory. That is exactly why our experts are once again stepping up to share what they are seeing, what is keeping them curious, and what they believe security teams should be paying closer attention to as we head into 2026.

A panel shaped by diverse vantage points

One of the strengths of this session is the range of perspectives represented on the panel.

Philip Ingram, Former Senior Military Intelligence Officer at Grey Hare Media, brings a global geopolitical lens that connects cyber activity with real-world tensions and state-aligned movements. His vantage point helps translate complex geopolitical signals into practical considerations for security teams.

Raj Samani, SVP and Chief Scientist at Rapid7, offers deep insight into attacker behavior, AI-driven disruption, and the evolving threat landscape. His work tracking threat actor tradecraft and the mechanics of cybercrime economies gives him a unique perspective on how attacks scale and shift over time.

Sabeen Malik, VP of Global Government Affairs and Public Policy at Rapid7, brings a policy and regulatory perspective that is essential for understanding how global mandates and governance trends influence security operations. Her insights shed light on the intersection of cyber risk, legislative pressure, and organizational responsibility.

Together, they create a multi-dimensional picture of what is coming next. Not hype. Not speculation. Instead, grounded observations from experts who see attacker behavior unfold from very different angles.

What we learned from last year 

Last year’s session made one thing clear: the forces shaping cyber risk are not isolated. They are interconnected, and they are accelerating.

We saw that:

  • Attackers were closing the gap between vulnerability disclosure and exploitation.

  • Identity-based compromise continued to outpace traditional malware.

  • Economic and operational pressures made it harder for security teams to keep up.

  • Global events had tangible ripple effects on what attackers chose to target next.

Those insights helped set a realistic direction for 2025. Only twelve months later, the ground has shifted again. AI-assisted exploitation, insider-driven breaches, geopolitical instability, and expanding exposure surfaces are changing both attacker priorities and defender responsibilities.

This webinar is not a rehash. It is a recalibration, grounded in what is actually happening across the threat landscape right now.

Themes our experts will explore

While the predictions themselves will be revealed live during the session, we can share a few of the themes shaping this year’s discussion.

  • How global tensions are redefining cyber risk for private organizations, even those far from the front lines

  • Why identity, behavior, and access are becoming the most reliable early indicators of compromise

  • Where AI is helping and hurting defenders, and how attackers are using automation and tooling to accelerate the earliest stages of intrusion

  • Why context and prioritization are becoming essential as vulnerability volumes and exploitation speeds continue to rise

  • How security teams can get ahead of exposure, not just react to it, through more integrated and risk-aware workflows

These are not abstract conversations. They reflect the real operational and strategic challenges security teams face every day.

Why you will not want to miss it

Whether you are leading a security program or defending in the trenches, this session will help you:

  • Understand the forces shaping attacker strategy
    Identify the signals that matter most for early detection

  • Anticipate the operational pressures teams will face in 2026

  • Prioritize investments, workflows, and practices that support resilience

You will walk away with a clearer sense of where to focus, what to watch for, and how to prepare your team for what comes next, without getting lost in noise or speculation.

Join the conversation

This webinar is one of our most anticipated sessions of the year. If you have not registered yet, now is the perfect time to save your spot and hear directly from the experts shaping the conversation around what 2026 will look like for security teams everywhere.

Register here. 

The collective thoughts of the interwebz