Hacker Newsnew | past | comments | ask | show | jobs | submit | somebudyelse's commentslogin

Earliest snapshot from IA is $120. That's almost 3x increase since then. I knew the component shortage was bad but not this bad.

https://web.archive.org/web/20250529094904/https://www.adafr...


Don't think this is anything new? Have seen various cases from years ago where they searched texts to determine if the person was planning on working or visiting.

Edit: the first directive apparently was from 2009: https://www.jdsupra.com/legalnews/new-policy-for-device-sear...


Expanding the scope of it is new.


If you really want to make sure that it's the right thing (because piping to sudo bash is risky), make sure the URL starts with "pastebin", or ends in ".tk", or is an IP address.


To be absolutely positively certain, be sure that the IP address is also in the same /24 as the same net blocks and hosted on the same AS that appear in every DNS based mail RBL possible.


Too soon


Let's see... That's 4 Linux LPEs in the last 10 days?

Copy Fail [1]

Copy Fail 2: Electric Boogaloo [2]

Dirty Frag [3]

And now this...

[1]: https://copy.fail

[2]: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boo...

[3]: https://github.com/V4bel/dirtyfrag


Aren't CF2 and DF the same exploit?


DirtyFrag and CooyFail2 are two exploits of the same bug.

This one is a level less severe.


It looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.


Somewhat similar vein, the school's blocking software would block YouTube and embeds unless they came from Canvas. They were smart enough to disable the HTML editor for posting discussion comments, but forgot that since it was a rich text editor, you could just copy-paste in an embed by putting the code in data:text/html, then copying the element as formatted html.

I also ran the entire DOMPurify sample XSS and managed to find one way to download custom content onto someone's computer.


It looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.


Look for large BTC moves recently?


Ransom paid?


The only permissions on the play store are notifications. On data privacy, it only shows optional email or phone number. Respectfully, I call BS.


As someone who has an MDM-managed device, I beg to differ. Although, this one uses newer style android MDM, which involves factory resetting and doing special things during OOBE. Even if it used the older style, nothing's stopping the app for requesting file access, notification access, etc. and not working until you grant the permissions.


Android has multiple options for MDM - the mess invasive one has a completely separate work profile that should not give the org that kind of access.


Nothing is stopping any app from the Play store to request any particular permission, not just MDM apps, right? And yet, no app can read arbitrary filesystem data including random app data without your device being rooted first.

If anything, one of many MDM purposes is to prevent orgas from enrolling rooted devices in their fleet.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: