Ссылка
click to show
click to show
Discord competitor Guilded sunsetting
Summary
Discord competitor Guilded is shutting down at the end of 2025.
This follows them loosing a lot of members due after being bought out by Roblox, They forced existing users to make Roblox account and login with Roblox accounts.
Quotes
Quote
While Guilded can continue to be used for the remainder of the year, we encourage you to continue building your community within Roblox.
My thoughts
Its irritating that basically Discord's competition shot itself in the foot by forcing Roblox migrations then a year later shut it down.
Sources
https://devforum.roblox.com/t/update-on-guilded-and-communities/3966775
Ссылка
click to show
click to show
Imgur.com geo-blocks the UK
Summary
The popular image hosting platform Imgur, has decided to geo-block UK users over an investigation by the ICO of the parent company MediaLab.
Quotes
Quote
The popular online image sharing website Imgur.com, which was first founded in 2009 and has been widely used to host viral images, short videos and memes that can be linked to from other sites, appears as if it may have responded to the Government’s new Online Safety Act (OSA) and an ICO investigation by blocking UK
My thoughts
Just more over reaching heavy handed consequences from OSA bill, waiting patiently for Wikipedia to pull the plug so the real disasters can show.
Sources
https://www.ispreview.co.uk/index.php/2025/09/popular-image-sharing-site-imgur-com-blocks-access-to-uk-visitors.html
https://help.imgur.com/hc/en-us/articles/41592665292443-Imgur-access-in-the-United-Kingdom
Ссылка
click to show
click to show
Open Printer: an open source inkjet printer!
Summary
A Paris based organisation called "Open Tools" has announced the development of an open source, repairable and customisable inkjet printer using a Raspberry Pi Zero W as the main board. The project is listed on crowdfunding platform "Crowd Supply", with the funding campaign "launching soon" at the time of writing.
Quotes
Quote
"Open Printer is an open-source, repairable inkjet printer designed for makers, artists, and anyone tired of throwaway hardware." - Open Tools
Quote
"Open Printer can be assembled, customized, and repaired to extend its life. You can easily maintain it and refill cartridges with ink, and its flexible design can adapt to your workspace, working when installed on a wall or placed on a desktop." - Open Tools
Images nabbed from their site:
My thoughts
Is this it? Is this our escape from the inkjet printer hellscape!?
Sources:
Their crowdfunding page:
https://www.crowdsupply.com/open-tools/open-printer
Media Sources:
https://www.hackster.io/news/the-open-printer-is-a-raspberry-pi-zero-w-powered-fully-open-highly-flexible-inkjet-printer-30948a1787cc - hackster.io
https://www.xda-developers.com/open-source-printer-raspberry-pi-zero-w/ - XDA Developers
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Someone is mailing T-Mobile US customers fake notices shaming their online activity
Summary
Over the past few days several T-Mobile customers on Reddit and Discord have reported receiving physical print letters ostensibly from T-Mobile which shame them for technically legal but immoral online conduct including hobby hacking and niche adult content with objectionable characters. The letters look legitimate, and don't carry any of the normal signs of phishing or social engineering, but they are not from T-Mobile and we don't know who sent them or why.
Quotes
Quote
At a cursory glance, this could all seem legitimate. The letter has the official T-Mobile logo at the top, and even finishes by saying to email an official T-Mobile email account.
Nevertheless, it’s all fake.
My thoughts
The whole situation is bizarre. T-Mobile claims they didn't send these letters. While it's possible the PR team and legal team don't know what each other are doing, some of the verbiage doesn't quite add up. Particularly around net neutrality, both not allowing T-Mobile to punish technically legal conduct, but also allowing T-Mobile to block sites they don't like. That's not how net neutrality works. And a legal department would know that.
At the same time, it isn't clear what the point of these letters would be if they were not sent by T-Mobile. My personal hypothesis is that a small group of people have used one of T-Mobile's many data leaks over the past years to get a list of customers and sent these out in the hopes of drawing attention to some kind of cause.
Something like, even though T-Mobile is not doing this today, they or any other ISP could add any time. We've already seen the Steam situation where payment processors bullied Steam into delisting certain adult games. Theoretically, what is to stop your ISP from morally policing your online conduct?
Some version o
Ссылка
click to show
click to show
Discord customer service data breach leaks user info and scanned photo IDs
Summary
Third party service provider got compromised and hackers gained access to a bunch of things, including the ID scan you provided for "age verification".
Quotes
Quote
One of Discord’s third-party customer service providers was compromised by an “unauthorized party,” the company says. The unauthorized party gained access to “information from a limited number of users who had contacted Discord through our Customer Support and/or Trust & Safety teams” and aimed to “extort a financial ransom from Discord.” The unauthorized party “did not gain access to Discord directly.”
Data potentially accessed by the hack includes things like names, usernames, emails, and the last four digits of credit card numbers. The unauthorized party also accessed a “small number” of images of government IDs from “users who had appealed an age determination.”
My thoughts
So much for discord "not putting a target on their back". Any reasonable person couldve seen this coming from a mile away. And as the "hand us over your gov id" plague keeps on spreading this will only get worse...
Sources
https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service
https://www.theverge.com/news/792032/discord-customer-service-data-breach-hack
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Gaming mouse sensors are good enough to be used as a microphone in new exploit paper
Summary
Good mouse sensors (eg. the ones in gaming mice) are sensitive enough to pick up the vibrations of human speech through the surface that the mouse is sitting on. An unprivileged application with access to the high polling rate mouse data can facilitate the exploit - the paper specifically calls out graphics applications and games. The vulnerability uses an audio filtering and AI processing pipeline (which the author's have named Mic-E-Mouse to clean up the captured mouse data and turn it into something understandable to human listeners.
Quotes
Quote
A group of researchers from the University of California, Irvine, have developed a way to use the sensors in high-quality optical mice to capture subtle vibrations and convert them into audible data. According to the abstract of Mic-E-Mouse (full PDF here), the high polling rate and sensitivity of high-performance optical mice pick up acoustic vibrations from the surface where they sit. By running the raw data through signal processing and machine learning techniques, the team could hear what the user was saying through their desk.
source: https://www.tomshardware.com/tech-industry/cyber-security/high-performance-mice-can-be-used-as-a-microphone-to-spy-on-users-thanks-to-ai-mic-e-mouse-technique-uses-mouse-sensors-to-convert-acoustic-vibrations-into-speech
Quote
High-Performance Optical Sensors in Mice expose a critical vulnerability — one where confidential user speech can be leaked.
Attackers can exploit these sensors’ ever-increasing polling rate and sensitivity to emulate a makeshift microphone and covertly eavesdrop on unsuspecting users. We present an attack vector that capitalizes on acoustic vibrations propagated through the user’s work surface, and we show that existing consumer-grade mice can detect these vibrations. However
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Microsoft is removing local accounts workaround in Windows 11 setup
Summary
Microsoft has announced in the latest Microsoft Insider blog post that they will be closing the loopholes that allowed users to bypass the required online Microsoft account when setting up Windows 11. Currently users can skip the online account and complete the Windows 11 setup process with a local user account by using the start ms-cxh:localonly command (bypassnro had already been removed in a previous update). Microsoft has claimed that the bypasses allowed users to skip "critical setup screens" during setup. Users will now be required to complete the Windows 11 setup process with an internet connection and using an online Microsoft account.
Quotes
Quote
Microsoft is cracking down on bypass methods that let Windows 11 installs use a local account, and avoid an internet requirement during the setup process. In a new Windows 11 test build released today, Microsoft says it’s removing known workarounds for creating local accounts as they can apparently cause issues during the setup process.
The changes mean Windows 11 users will need to complete the OOBE screens with an internet connection and Microsoft account in future versions of the OS.
https://www.theverge.com/news/793579/microsoft-windows-11-local-account-bypass-workaround-changes
Quote
Local-only commands removal: We are removing known mechanisms for creating a local account in the Windows Setup experience (OOBE). While these mechanisms were often used to bypass Microsoft account setup, they also inadvertently skip critical setup screens, potentially causing users to exit OOBE with a device that is not fully configured for use. Users will need to complete OOBE with internet and a Microsoft account, to ensure device is setup correctly.
https://blogs.windows.com/windows-insider/2025/10/06/announcing-windows-11-insider-preview-build-26220-67
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Firmware vulnerability allowing for secure boot bypass exploit affects 200K+ Framework Laptops
Summary
Over 200K+ Framework Laptops are susceptible to Secure Boot bypass exploit due to oversight in signed UEFI shells that would allow bad actors to load bootkits that can evade OS-level security controls and persist across OS re-installs. This issue was discovered by firmware security research company Eclypsium, and they already issued a warning to Framework. Framework are yet to comment on the subject but it seems that the patch will arrive in the next BIOS update.
Quotes
Quote
According to firmware security company Eclypsium, the problem stems from including a 'memory modify' (mm) command in legitimately signed UEFI shells that Framework shipped with its systems. The command provides direct read/write access to system memory and is intended for low-level diagnostics and firmware debugging. However, it can also be leveraged to break the Secure Boot trust chain by targeting the gSecurity2 variable, a critical component in the process of verifying the signatures of UEFI modules. The mm command can be abused to overwrite gSecurity2 with NULL, effectively disabling signature verification.
[...] Eclypsium researchers estimates that the problem has impacted roughly 200,000 Framework computers
(BleepingComputer)
Quote
UEFI shells act as pre-boot command-line environments, akin to a supercharged terminal with unrestricted hardware access. Designed for IT pros to diagnose hardware, update firmware, configure settings, or test drivers, they run before the OS loads, granting privileges far beyond typical admin rights. The problem arises from their integration into the Secure Boot chain of trust. Microsoft’s UEFI Certificate Authority serves as the root anchor, signing third-party tools that original equipment manufacturers (OEMs) embed in firmware. Once signed, these she
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Nvidia&TSMC unveils first completed wafer from TSMC's new Arizona Fab
Summary
TSMC and Nvidia did a trial run of the Arizona fab which successfully completed a wafer of Nvidia Blackwell chips.
Quotes
Quote
This is a historic moment for several reasons. It’s the very first time in recent American history that the single most important chip is being manufactured here in the United States by the most advanced fab, by TSMC, here in the United States - Jenson Huang
My thoughts
TSMC's US fabs are moments away from coming online for mass production, as the first trial run of the fab produces its first complete wafer.
Note: No information was released if any of the chips on the wafer are working or even feasible for use.
Sources
https://blogs.nvidia.com/blog/tsmc-blackwell-manufacturing/
https://www.reuters.com/technology/nvidia-tsmc-unveil-first-blackwell-chip-wafer-made-us-axios-reports-2025-10-17
Ссылка
click to show
click to show
Ссылка
click to show
click to show
GPT Atlas: Sam Altman takes chromium, adds OpenAI API, and claims he revolutionized browsing
Summary
I feel a demo video says more than a thousand words.
In this demo from OpenAI, the devs ask a sidebar to look at a recipe and order the ingredients, it takes a lot of typing, and it adds the wrong quantities to the cart (instead of ordering 6 green onions, it orders 6 bounches of green onion).
Quotes
Quote
AI gives us a rare moment to rethink what it means to use the web. Last year, we added search in ChatGPT so you could instantly find timely information from across the internet—and it quickly became one of our most-used features. But your browser is where all of your work, tools, and context come together. A browser built with ChatGPT takes us closer to a true super-assistant that understands your world and helps you achieve your goals.
My thoughts
Sam Altman took chromium, and packaged an OpenAI sidebar hooked to OpenAI APIs, a tab screenshot functionality and click functionality to let the user interact with open tabs. All by chatting with the sidebar.
It's unironically something that I personally am confident I can build with local AI hosting. And looks to me like it would be a terrible user experience.
LLMs are incredible, at a narrow range of tasks. E.g. creating a doxygen comment blocks, creating an example snippet to learn a new library, letting you rewrite a mail or phrase with different styles and emphasis, sentiment analisys, recap/translate a transcript, OCR and so on.
Accurately filling forms without error is NOT one of those tasks, even basic arithmetic is hard because of the temperature, the model can just... count wrong. It's statisticaal in nature, not deterministic. I do use LLMs to generate json structures, but if the number are importants, I need to double check the work, and that negates productivity gains. Deterministic tasks are usual
Ссылка
click to show
click to show
New m5 MacBooks don’t have power adapters!
Summary
The new MacBook Pros (M5) don’t come with a power adapter you have to add it at additional cost.
Quotes
Quote
Apple M5 chip with 10-core CPU, 10-core GPU, 16-core Neural Engine
16GB unified memory
512GB SSD storage
No power adapter
Three Thunderbolt 4 ports, HDMI port, SDXC card slot, headphone jack, MagSafe 3 port
My thoughts
Am I the only person who thinks this is a bit mad, while I’m not a fan of doing this with phones, it’s less of an issue with a low power device, but with a laptop it’s more important to have its own PSU.
Sources
https://www.apple.com/uk/shop/buy-mac/macbook-pro/14-inch-space-black-standard-display-apple-m5-chip-with-10-core-cpu-and-10-core-gpu-16gb-memory-512gb#
Ссылка
click to show
click to show
Eight Sleep mattress doesn't work without AWS, and don't expect to sleep if it's offline...
Summary
Apparently Eight Sleep uses AWS for their cloud service, and the large outage on Monday caused their services to go down (1). Unfortunately that meant for some users that the cooling stopped working (2) or their bed apparently couldn't be adjusted anymore (3)
https://www.golem.de/news/durch-aws-ausfall-smarte-matratzenauflagen-rauben-nutzern-den-schlaf-2510-201413.html (German)
Quotes
Quote
Translation from article:
An outage at the cloud provider AWS (Amazon Web Services) on Monday had far-reaching effects on countless online services. Eight Sleep, a manufacturer of smart mattress toppers, was also affected. The toppers are supposed to improve sleep quality. However, during the AWS outage, the opposite happened for many users.
Original:
Ein Ausfall beim Cloudanbieter AWS (Amazon Web Services) hatte am Montag weitreichende Auswirkungen auf unzählige Dienste im Netz. Auch das Unternehmen Eight Sleep, ein Hersteller smarter Matratzenauflagen, war betroffen. Eigentlich sollen die Auflagen die Schlafqualität verbessern. Während des AWS-Ausfalls passierte jedoch bei vielen Anwendern das Gegenteil davon.
My thoughts
I know LTT dropped them for sponsoring and called out their issues with the subscription models before, but since they where features I figured this would be something that they might touch on during the WAN show.
This just shows again how bad any 'smart' device is that doesn't have at least a minimal functionality when offline. People keep thinking the internet is always there and that the cloud is always there. But our infrastructure is a lot less resilient than people think. A simple small mistake can lead to massive outages that have much farther reaches than one imagines. Even if your service doesn't run on <insert your large cloud provider of choice> there's a good c
Ссылка
click to show
click to show
Another PSN account of a top trophy hunter stolen for ransom
Summary
After last year's story of one of the top PSN trophy hunters, Hakoom, retiring from PSN after his account was supposedly stolen by a PSN customer support employee, yet another top trophy hunter got their account stolen. This time it was dav1d_123, number #1 hunter according to PSNProfiles leaderboard.
Quotes
Quote
On October 7, David's PSN account was compromised despite his account being secured by Authy 2FA. He never received any email that his security info had been changed.
(...)
The attacker ("Zzyuj", formerly "dav1d_123") reveals "it's possible to get access to any user just by knowing the [public] username". He claims you just need to keep calling PS Support until someone believes your story. He attributes it to Sony outsourcing PS Support to less developed countries, but frankly, I don't want any country's PS Support to have this much power. Bad actors can exist anywhere, as you'll see next.
My thoughts
Reading up on this makes me remember the last LTT hack - there was a clear way forward, a recognizable threat that could've been prevented, and ultimately somebody inside LTT had to mess up first. In case of PSN, as an owner of the account, you don't even know how and when your account can be stolen, and there's really nothing that can prevent it. You can set your account to private, remove all your PSN friends, and you can still be vulnerable to take over.
And what's worst, Sony doesn't seem to care. Recognizable players are getting hacked, banned and nothing changed, at least since last years hack on Hakoom.
Noise was already made around these stories, and doesn't seem like that helped, but maybe getting it onto even a bigger stage will.
Sources
Hakooms official statement:
Dav1d_123 business partners statement on both incidents:
PSN profiles leaderboard: https://psnprofiles.c
Ссылка
click to show
click to show
Amazon releases information about cause of major AWS us-east-1 outage
Summary
A bunch of websites and apps across the world were impacted on Monday when Amazon had a major outage in their us-east-1 region, with services degraded for over 14 hours. A concise chain of events that led to the outage was:
Amazon manages the DNS entries for a bunch of their services using automation, because there are far too many entries, and they change too frequently, to manage manually. Those DNS entries are what allow users to connect to those services.
That automated tooling contained a race condition, which had not been encountered before and which only happens when some services have fallen way behind
That race condition resulted in the main DNS entries for DynamoDB, a popular AWS-managed database (and one that is used internally by a bunch of AWS services), to be deleted in the us-east-1 region
That meant that nobody could connect to DynamoDB in us-east-1, which caused a bunch of websites etc to go down
A bunch of other AWS services and features, including the functionality that is used to provision new EC2 instances, depend on DynamoDB, so they also stopped working
The DNS issue was resolved in just under 3 hours, and DynamoDB was restored
Now, a bunch of the internal AWS services started working again, but had huge amounts of work to do, causing them to fail or have massive backlogs
This resulted in various functionality, including EC2 instance launching, being degraded for several more hours while AWS engineers worked to manage the backlog in the various services
Although this outage only impacted a single region of a single cloud provider, it was the most popular region of the most popular cloud provider, so a bunch of big websites were down or degraded as a result (a small sample includes eight sleep, snapchat, slack, and fortnite).
Quotes
Quote
Right before this event started, o
DDB endpoint, overwriting the newer plan. The check that was made at the start of the plan application process, which ensures that the plan is newer than the previously applied plan, was stale by this time due to the unusually high delays in Enactor processing. Therefore, this did not prevent the older plan from overwriting the newer plan. The second Enactor’s clean-up process then deleted this older plan because it was many generations older than the plan it had just applied. As this plan was deleted, all IP addresses for the regional endpoint were immediately removed. Additionally, because the active plan was deleted, the system was left in an inconsistent state that prevented subsequent plan updates from being applied by any DNS Enactors.
Quote
At 2:25 AM PDT, with the recovery of the DynamoDB APIs, DWFM [the service that manages physical hosts and their capacity for new instances] began to re-establish leases with droplets across the EC2 fleet. Since any droplet without an active lease is not considered a candidate for new EC2 launches, the EC2 APIs were returning “insufficient capacity errors” for new incoming EC2 launch requests. DWFM began the process of reestablishing leases with droplets across the EC2 fleet; however, due to the large number of droplets, efforts to establish new droplet leases took long enough that the work could not be completed before they timed out. Additional work was queued to reattempt establishing the droplet lease. At this point, DWFM had entered a state of congestive collapse and was unable to make forward progress in recovering droplet leases.
Quote
At 5:28 AM PDT, shortly after the recovery of DWFM, Network Manager began propagating updated network configurations to newly launched instances and instances that had been terminated during the event. Since these network propagation events had been delayed by the issue with DWFM, a significant backlog of network state propagations needed t
d there was one critical component that was inadvertently dependent on a single region, but there are also plenty of others who didn't think about that (Amazon generally only encourages spreading across availability zones, which are part of a region, but that would not have helped here). I imagine there will also be a few companies that decide that the cloud isn't worth it after this, and go back to self-hosting, but I also suspect there will be a lot fewer of those companies than some people would like to think - the cloud does have downsides, but it also does bring advantages too, and those advantages are particularly valuable to big companies (changing capex into opex, and requiring less in-house staff).
On the root cause of this issue, Amazon have already listed in the article some of the changes that they will be making to prevent this issue, and others like it, from happening again. However, in an organization as large as AWS, I think these types of outages are going to be inevitable - it's very difficult to eliminate every bug, and once there is a bug it's very difficult to make sure that every service is resilient to extended failures of its dependencies. I do think there are some useful lessons for both Amazon and other companies to learn from this, about avoiding cascading failures, but because these issues are rare, it's too easy to forget it somewhere, and you only need one part of the chain to be impacted for the outage to be widespread and severe.
Sources
https://aws.amazon.com/message/101925/