

the band-aid is sloughing off and yet ipv6 is still not a native option in my area.
fixate on what you think you know… you’re missing what you don’t though.


the band-aid is sloughing off and yet ipv6 is still not a native option in my area.


drones are cheap.


you know the ecosystem is FUBAR when this is your (and my) very first thought when a vuln pops up.


a security site that (kinda) demands JS shields down? sigh… anyway here is the article for those that prefer to not do silly things…
Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 and 1.4.5, carrying fixes for seven security flaws along with smaller hardening changes.
Most of the patched bugs sit in the code that unpacks and parses executable formats, the part of a scanner built to handle hostile input. CVE-2026-20213 is an integer overflow in the PE rebuild size calculation that a malformed Aspack-packed file can trigger, leading to a heap buffer overflow write. The related CVE-2026-20214 covers an FSG unpacker loop underflow that can write past the section array during a scan of a crafted PE file. Both reach far back through the codebase, with the FSG issue present in builds dating to 2004.
CVE-2026-20217 rounds out the PE group. A bug in the PESpin unpacker cleanup path could free pointers into the scanned file buffer and crash the scanner. That flaw has lived in the code since 2005. Archive and image format bugs
Three more fixes address archive and disk-image handling. CVE-2026-20215 is a 7z parser substream count overflow that can under-allocate parser metadata arrays and then write past them when reading a crafted archive. CVE-2026-20243 covers ALZ parser size handling errors that can make malformed ALZ archives panic, abort the scanner, or skip expected scan-limit handling. CVE-2026-20216 is an InstallShield archive extraction limit bypass that can write far more temporary data than intended and drain temporary storage.
The last parsing flaw, CVE-2026-20244, sits in the 32-bit DMG parser. A short mish stripe table could pass validation and crash the scanner. This one affects only 32-bit builds, going back to version 0.98.1, and leaves 64-bit builds untouched. Quarantine race condition
The releases also harden the quarantine actions in clamscan, clamdscan, and clamonacc against time-of-check/time-of-use races. Under unsafe quarantine directory settings, those races could redirect files as the scanner copied, moved, or removed them. Hiroki Imai of Ricerca Security, Inc. reported the issue.
Version 1.5.3 adds a few items beyond 1.4.5. It upgrades the Rust tar dependency to resolve two RUSTSEC advisories and moves the Rust openssl dependency past CVE-2026-41676. Metadata preclass scans now run before the final scan verdict. A ClamOnAcc fix addresses hash bucket list corruption when two watched paths land in the same bucket. Both releases raise the minimum CMake version to 3.17 to repair Linux builds that link static dependencies against libcurl v8.21.0.
The release files are available on the GitHub release page, and through Docker Hub in Alpine and Debian containers.


dont discount the utility of running containers in an abstracted Hardware Virtual Machine (HVM) away from your physical hardware. it expands your testing surfaces and sandboxes immeasurably.


“It has seen its job as explaining why we cannot instead of showing how we can, and that old way of thinking will lose on Tuesday. And frankly, it will lose in South Carolina and New Hampshire. It will fall short of 270 electoral votes, because the party of the past will not be what leads us into the future.”
the man is legitimately on fire.


the reflecting pool is definitely brawndo



little wins and small victories is very low volume, but wonderful to see pop up in your feed.


one of the better articles on this issue. the usual obvious propaganda is useless. this is somewhat thoughtful.


and how has, literally, anything he has been doing for the past 12+ years not been focused on ensuring that there is a deep, substantial, robust pool of people to do exactly that?


yeah. and thats such a pity, because the video is absolutely worth a watch.


honestly, I have always had pretty decent experiences with non-oem lead-acid batteries. my local battery place has a decent supply and longevity is roughly the same as the oem ones (3-4 years). I have never had any issues (type or frequency) that were not also an issue with oem batteries.
almost no UPS mfcr makes their own batteries, so if you strip off the labeling from the oem ones, you may even find an exact replacement.
edit: another advantage of a local place is the core-return rebate and disposal of your old batteries.


the attack should only have insight into the abstracted storage provided by the browser, so your idea of a virtual device that spits out random timing results is probably reasonable.
the issue is that timing being random, in and of itself, is a potential fingerprint when combined with other data from your browser - unless everyone is doing it as well.
all I can say is I give thanks for noscript every single day.
the original arch from hell.


thats a pretty astute observation. still, narrowly missing a “state-level charlie kirk” because the fascists are just fucking bad at the job is not the type of comfort I hope for.


this looks like a state charge. trump (theoretically) has no control over state pardons.


You shouldn’t be getting downvoted.
agreed. a tad snarky, but it was an honest opinion. lemmy will grow and communities will fill out.
one thing that may help are clients that allow community aggregation into meta communities. this would allow users to be presented with a themed superfeed of similar communities across many instances. easiest done at the client level (no protocol changes needed), but could be extended to communities using meta tags or moderator inclusion into meta communities with protocol help. protocol support would also allow meta communities to be presented via the web interface.
perhaps this has already been done in some clients. if implemented thoughtfully it could be interesting and perhaps even useful.


HAHA HaHa haha… * cry *


the latest colonization of prior human effort. I am not absolutely against LLMs and a push towards actual AI, but all financial proceeds from this effort must be shared equally and globally.
however, human nature being what it is, we will almost certainly empower the very worst outcome - because… of course!
edit: word
are you able to give additional info on the DNS issue you had?