Yann Masson
@yayamamass.bsky.social
Du coté OPScure de la Force. Infrastructure/Architecture/Hardware/System/Network/Security/Automation. Saltstack, EventDriven, Chaos Engineering, Netbox, Linux, FreeBSD Fan.
C’est qui qui a fuité aujourd’hui ? C’est Revolut bonjourlafuite.eu.org#Revolut-2026...
C’est qui qui a fuité aujourd’hui ?
Une sponso avec Pampers peut-être ?
bonjourlafuite.eu.org
We found a new compression side-channel attack against SSH: if you use port forwarding with terminal sessions, a web attacker+eavesdropper can recover a sudo pwd in a few hundred trials. There is only one compression context for all channels. Accepted at CCS 26, preprint: arxiv.org/abs/2609.07709
Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, t...
arxiv.org
Au détour d’une pétition très anecdotique, que les députés vont examiner, on découvre que toutes les pétitions ne se valent pas à l’Assemblée nationale. Des règles implicites les régissent, comme on vient de le découvrir.
Facturation électronique : une pétition anecdotique qui a les faveurs de la commission des affaires économiques - Projet Arcadie
Au détour d’une pétition que les députés vont examiner, on découvre que toutes les pétitions ne se valent pas à l’Assemblée nationale.
projetarcadie.com
Age Verification for Steam rolls out in Australia requiring a Credit Card #Steam #Valve #Australia #PCGaming #Gaming
Age Verification for Steam rolls out in Australia requiring a Credit Card
Valve have rolled out Age Verification requirements on Steam in Australia, requiring users to keep a Credit Card on their account.
gamingonlinux.com
GOG expand their Preservation Program with more games and now 3D scans of box art too #GOG #DRMFree #Retro #Gaming #PCGaming
GOG expand their Preservation Program with more games and now 3D scans of box art too
Making it easier than ever to backup your DRM-free downloads and make them look cool - the GOG Preservation Program has expanded with some fun stuff.
gamingonlinux.com
How to use multiple Cursors, merged into Neovim nightly, scheduled for release in Neovim 0.13 #Neovim blog.olimorris.com/2026/09/02/m...
How to use multiple cursors in Neovim 0.13
A practical guide to using native multiple cursors or multicursors in Neovim 0.13.
blog.olimorris.com
The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges. #MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability
MikroTrick PoC: RouterOS Admin Rights Exploited In Wild
CERT Polska confirmed active attacks against internet-facing MikroTik RouterOS devices on September 5, 2026. Attackers chain two flaws, named MikroTrick, to seize full control over SSH without a password. This MikroTik RouterOS vulnerability chain is exploited in the wild, and public proof-of-concept exploit code is already available. Why this matters MikroTik routers sit at the edge of countless networks worldwide. So a full takeover exposes every device behind them.
securityonline.info
🏖️🐻 Les Logiciels Libres de l'été, jour 74 : Garage : un stockage objet S3 distribué pensé pour l’auto-hébergement
🚨 We have released a critical security update in all RouterOS release channels. Even though the fixed issue does not affect most home users with default configuration, we still suggest to treat this seriously and upgrade your MikroTik routers and inform other users. To give time to update your […]
Original post on mikrotik.social
mikrotik.social
It's difficult to build very high performance tools in Go. For example, BART would benefit for an helper over net/netip: github.com/golang/go/is.... Unfortunately, the maintainers consistently reject these APIs but Go don't really offer any safe workaround. You can't extend, you can't fork.
proposal: net/netip: add Prefix.ContainsIPv4Unchecked and Prefix.ContainsIPv6Unchecked for hot-path lookups · Issue #81236 · golang/go
Proposal Details Author Karl Gaissmaier Abstract I propose adding two exported, fully inlinable methods to netip.Prefix: ContainsIPv4Unchecked(Addr) bool ContainsIPv6Unchecked(Addr) bool. These met...
github.com
Faut faire la pub de truc GOG qui vendent sans DRM et font en sorte que les jeux restent jouables
Sony says "reasonable consumers" know they don’t own the digital PlayStation games they buy. It argues that it's "not plausible" to suggest that when they buy a digital game they actually believe they're "obtaining ownership" of it. www.videogameschronicle.com/news/sony-sa...
RFC 10001: Operational Guidelines for DNS Transport in Mixed IPv4/IPv6 Environments Vous gérez des serveurs #DNS dans un environnement IPv4 et IPv6 ? Ce #RFC va vous aider. La recommandation : tout serveur DNS doit pouvoir servir les requêtes avec les 2 versions d'IP. www.bortzmeyer.org/10001.html
Blog Stéphane Bortzmeyer: RFC 10001: Operational Guidelines for DNS Transport in Mixed IPv4/IPv6 Environments
bortzmeyer.org
www.tomshardware.com/tech-industr... *étonnant* *sapristi*
Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware
The surveillance seems aimed at the domestic market, but it knocks huge holes in the security of the devices it's found in.
tomshardware.com
Minor update for Akvorado, your beloved flow collector. Among them, a few small fixes, the ability to zoom out, or the support for DB-IP. github.com/akvorado/akv...
Release v2026.8.1 · akvorado/akvorado
💥 console: console.homepage-graph-filter now uses the console filter language instead of SQL 🩹 console: fix completion for DstNetName and the other network attributes 🩹 console: accept again an emp...
github.com
Il y a 29 ans, le 29 août 1997, eu lieu le jour du jugement. SkyNet deviendra conscient et lancera la guerre contre les humains #LaPetiteInfoDuJour
Et dans un petit mois, des millions de factures en lignes grâce à la facturation-passoire-électronique obligatoire !
🔴 Iban, adresses postales, déclarations de salaires… une nouvelle mutuelle victime d’une cyberattaque, 1,2 million d’assurés potentiellement concernés ➡️ https://l.leparisien.fr/9C2x
C’est qui qui a fuité aujourd’hui ? C’est Suez bonjourlafuite.eu.org#Suez-2026-08...
C’est qui qui a fuité aujourd’hui ?
Une sponso avec Pampers peut-être ?
bonjourlafuite.eu.org
🎊 Go 1.27.0 is released! 🗒️ Release notes: https://go.dev/doc/go1.27 📦 Download: https://go.dev/dl/#go1.27.0 #golang
“Go 1.27 is released” by Nicholas Husin, on behalf of the Go team — https://go.dev/blog/go1.27 #golang
Wireblast: a fast and easy-to-use AF_XDP Traffic Generator for Linux, written in Go - On a 100G Mellanox Link it fills the pipe at every frame size, including 138 million packets per second of the smallest frames, from a single process. #Network #Linux toonk.io/wireblast-bu...
Wireblast: a 100Gbs packet generator in Go with AF_XDP
If you’ve followed my blog for a while, you know I love tinkering with packets and making them go fast in software. Today I'm releasing a new tool called wireblast, a blazingly fast network packet…
toonk.io
Le moment est venu de vous faire le petit débrief sur cette mission d'été 2026 qui a été possible grâce à *VOUS* ! (un thread un peu long, et avec des photos malheureusement souvent anonymisées) #Ukraine
Ukraine : la cagnotte de l'été est lancée - grâce à VOUS Objectifs : des matériels essentiels et un véhicule pour l'Ukraine ! www.helloasso.com/associations...
Zapscape Is The Latest Linux Vulnerability For KVM Guest-To-Host Escape, LPE - https://www.phoronix.com/news/Linux-Zapscape-Vulnerability
Zapscape Is The Latest Linux Vulnerability For KVM Guest-To-Host Escape, LPE
Made public earlier today is Zapscape as a guest-to-host escape vulnerability affecting the Linux KVM x86 code for the past six years. This 2020 kernel change to KVM x86 can also be used as a local privilege escalation (LPE) exploit too where /dev/kvm is world-writable on some Linux distributions like RHEL...
phoronix.com
Amazon is investing in a natural-gas-burning power plant, as part of a huge A.I. data center in Texas, that could become the largest single source of climate pollution in the U.S., the company confirmed.
New Amazon Data Center Stokes Worry It Would Be the Most Polluting Power Plant in the U.S.
The tech giant is investing in the natural-gas-burning power plant as part of a huge data center in Texas, even as it pledges to honor climate commitments.
nyti.ms
Proxmox Virtual Environment est disponible officiellement version pour ARM 64 bits avec UEFI. Cette version apporte le support officiel d'arm64, notamment sur NVIDIA Grace Hopper et Vera, avec Debian 13.5, Linux 7.0, QEMU 11.0, LXC 7.0 et ZFS 2.4 ⬇️ forum.proxmox.com/threads/prox...
Proxmox Virtual Environment now available for 64-bit ARM (arm64)!
We are excited to announce the first release of Proxmox Virtual Environment with official support for a second CPU architecture: 64-bit ARM (arm64/aarch64). Until now, Proxmox VE was available for x86...
forum.proxmox.com
IA et reconnaissance faciale : le Royaume-Uni inaugure la police « proactive » La police de Londres a conçu un « projet pilote avec Palantir » pour identifier de manière « proactive » les individus « problématiques » afin d’intervenir « avant que le préjudice ne survienne ». next.ink/249929/ia-et...
IA et reconnaissance faciale : le Royaume-Uni inaugure la police « proactive »
Un système de reconnaissance faciale en temps réel (LFR) déployé dans plusieurs milliers de magasins va alerter la police en temps réel lorsqu’il…
next.ink