cfillekes

@cfillekes.bsky.social

https://linktr.ee/cfillekes

FYI there is no "real" reason why Rome "fell." Its power waned for the usual, mundane reasons: widening gap between rich and poor, inability to maintain infrastructure, incompetent leadership, pointless wars, endless persecution of marginalized groups who performed vital labor, etc.

This is Alfie. He is a professional opera singer with some of the best vibrato in the industry. Some have even called him the next Paw-varotti. 13/10 (TT: thelifeofalfiee)

The American Civil Liberties Union of Massachusetts says it’s releasing an online toolkit for attorneys to uncover the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets

A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.

wired.com

Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts

Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts

Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This vulnerability, tracked as CVE-2026-52824, affects Kimai versions 2.57.0 and earlier. The issue has been resolved in Kimai version 2.58.0. Kimai is an open-source time-tracking application widely used by businesses and teams, delivered via Docker containers. The flaw originates from an insecure default value for the application’s APP_SECRET environment variable. The official Docker image included the publicly known value “ change_this_to_something_unique ,” which was intended to be replaced during deployment. However, the Docker startup process did not enforce this requirement or automatically generate a replacement secret. Kimai uses APP_SECRET as Symfony’s kernel secret, a cryptographic value required to create and validate HMAC-signed security tokens. If an installation continues to use the default secret, an attacker can exploit the known cryptographic key to forge tokens that the application might trust. Kimai Docker Vulnerability The GitHub advisory states that the exposed secret could allow attackers to forge several security-sensitive values, including the KIMAI_REMEMBER remember-me cookie, login link signatures, password reset URLs, and CSRF tokens. An attacker with network access to a vulnerable Kimai instance could impersonate a user without needing valid credentials. For an account takeover scenario to occur, the attacker would need knowledge of a target username and the ability to identify the account’s user ID. Kimai user IDs are sequential integers starting at 111, making them relatively predictable in many deployments. The first super administrator account is often assigned ID 111, making these privileged accounts attractive targets. Two-factor authentication (2FA) can mitigate the attack when enabled on the targeted account. However, the advisory warns that accounts without active 2FA could be completely compromised. Since the attack can be executed remotely against an exposed application, organizations that have deployed Kimai using default Docker settings should consider this issue urgent. The vulnerability has been classified as critical and is associated with CWE-1188 , “Initialization of a Resource with an Insecure Default.” Security researcher AzureADTrent reported the issue. A proof of concept was initially provided but later removed to reduce the risk of exploitation. Kimai version 2.58.0 modifies the Docker initialization process to prevent the insecure setup. The upgraded entrypoint generates a random APP_SECRET using bin2hex(random_bytes(32)) if an administrator has not supplied one. The generated secret is stored in /opt/kimai/var/data/.appsecret , and the deployment configuration is written to /opt/kimai/.env.local . According to the GitHub advisory (GHSA-jr9p-4h4j-6c58) , the maintainers removed the hard-coded default secret from the Dockerfile and updated the documentation to recommend using a unique, randomly generated secret. Additionally, Kimai has strengthened login-link entropy in a separate advisory to reduce risks associated with predictable secrets in older configurations. Administrators should immediately upgrade to Kimai version 2.58.0 or later. They should also explicitly set a high-entropy, unique APP_SECRET , rotate credentials and active sessions when feasible, review administrator accounts, and enable two-factor authentication for all privileged users.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts appeared first on Cyber Security News .

cybersecuritynews.com

Everybody in the "climate space" (which means everyone on earth...) needs to understand these mind-blowing figures. Google's "total electricity consumption jumped from 31 terawatt hours (TWh) in 2024 to 43 TWh in 2025." In ONE year. The AI corporate arms race is eating the world.

Ketan Joshi@ketanjoshi.co · last mo.

NEW BLOG FOR YOU Google's energy consumption numbers in their new climate report are mind-blowing. 2 years ago they flipped from linear to exponential growth, and their climate impact is blowing out, too. A WILD testament to the obscene bloat and waste of GenAI: ketanjoshi.co/2026/07/01/g...

a chart showing google's rising energy consumption - huge, and rising faster than ever before

This is Penny. She came up with her own trick. Really hopes you like it, and will repeat it as many times as necessary until you acknowledge that you do. 14/10 (IG: pennycorgipoo)

There’s only one reason JD Vance regrets calling women “childless cat ladies”—his focus groups and polls must show it kills his already weak electoral chances. That vicious, grinning goon never apologizes for anything. This is pure self-interest.

What 80 year old wants a UFC wrestling match for his birthday, especially when one is President during a war they provoked? Is it me? 🤔 DC is safe? I think not.

Bild