Dennis "D.C." Dietrich
dcdietrich.bsky.social
Dennis "D.C." Dietrich
@dcdietrich.bsky.social
"Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the #npm registry in a new Shai-Hulud supply-chain campaign." #ShaiHulud #trojan #CyberAttack #SupplyChainAttack #CyberCrime
www.bleepingcomputer.com/news/securit...
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign.
www.bleepingcomputer.com
November 24, 2025 at 5:30 PM
I guess @rachelappel.bsky.social doesn’t want to be disturbed. :)
November 23, 2025 at 10:55 PM
Reposted by Dennis "D.C." Dietrich
authors you have the chance to do the funniest thing right now
AI advocates have warned that if every author in the class action filed a claim, it would "financially ruin" the entire industry.
Authors celebrate “historic” settlement coming soon in Anthropic class action
Advocates fear such settlements will “financially ruin” the AI industry.
arstechnica.com
November 18, 2025 at 4:35 AM
"Azure was hit by the 'largest-ever' cloud-based distributed denial of service (DDoS) attack, originating from the #Aisuru #botnet and measuring 15.72 terabits per second (Tbps), according to #Microsoft." #Azure #DDoS #CyberAttack #CyberSecurity
www.theregister.com/2025/11/17/b...
'Largest-ever' cloud DDoS attack pummels Azure
: Aisuru botnet strikes again, bigger and badder
www.theregister.com
November 18, 2025 at 6:47 PM
Reposted by Dennis "D.C." Dietrich
I'm amused. Exclamation mark.
November 18, 2025 at 1:58 PM
Reposted by Dennis "D.C." Dietrich
RIP Rebecca Heineman @burgerbecky.bsky.social, game developer pioneer and legend. Grateful we got to chat last year at San Francisco GDC. It was much too short.
November 18, 2025 at 3:54 PM
Hmm. Maybe it's time to buy a TEAC W-1200 (and an Audio-Technica AT-LP120XUSB while I'm at it). Yeah, in terms of raw quality, cassettes suck, but even though I haven't used any in decades, I always liked the format. Two words: mix tapes!
#RetroAudio #HiFi #CompactCassette
revox.com/us/blog/deta...
Cooperation between National Audio Company Inc. and Revox Group
New: Exclusive audio cassette production at the Revox Manufacture in Villingen, Germany Villingen, September 2025 –  The US-based National…
revox.com
November 16, 2025 at 5:07 PM
Reposted by Dennis "D.C." Dietrich
A man has been found guilty of writing a stream of consciousness novel. He is about to start a 4 year sentence.
November 12, 2025 at 7:37 PM
Reposted by Dennis "D.C." Dietrich
With 80% of modern #apps built on third-party #code, supply chain #security has become critical. Don't miss
@niels.fennec.dev "Beyond Trust: Building Community-Driven Security Analysis for Your .NET Software Supply Chain" at #NDCManchester!

ndcmanchester.com/agenda/beyon...
Beyond Trust: Building Community-Driven Security Analysis for Your .NET Software Supply Chain | NDC Manchester 2025
With 80% of modern applications built on third-party code, supply chain security has become critical. Traditional security tools like OpenSSF Security Scorecard provide surface-level metrics, but fail...
ndcmanchester.com
November 6, 2025 at 3:26 PM
Reposted by Dennis "D.C." Dietrich
Noticed the shift in AI coverage lately? The hype’s fading, replaced by quiet worry about a bubble.

But we've seen this before ... twice. In my @ndcconferences.com keynote, I explore what past AI hype cycles reveal about today’s boom.

www.youtube.com/watch?v=x5s_...
Keynote: AI is having its moment ... again - Jodie Burchell - NDC Copenhagen 2025
YouTube video by NDC Conferences
www.youtube.com
November 6, 2025 at 10:15 AM
Just wanted to share my first ever 100% organic selfie!
November 1, 2025 at 1:16 PM
Reposted by Dennis "D.C." Dietrich
Chatbots — LLMs — do not know facts and are not designed to be able to accurately answer factual questions. They are designed to find and mimic patterns of words, probabilistically. When they’re “right” it’s because correct things are often written down, so those patterns are frequent. That’s all.
June 19, 2025 at 11:21 AM
Reposted by Dennis "D.C." Dietrich
I just heard a new term I'm going to be using in the future: Slopsplaining:

When someone who doesn't know anything about a topic offers up unsolicited AI generated slop 'advice' to others.
October 27, 2025 at 9:22 AM
Latest addition to my library. @citizenmatt.bsky.social, thanks for the recommendation!
October 26, 2025 at 9:16 PM
Reposted by Dennis "D.C." Dietrich
Updating my LEGO White House
October 23, 2025 at 2:51 AM
"A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called #GlassWorm that has been installed an estimated 35,800 times."
#CyberSecurity #VSCode #SupplyChainAttack
www.bleepingcomputer.com/news/securit...
Self-spreading GlassWorm malware hits OpenVSX, VS Code registries
A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called GlassWorm that has been installed an estimated ...
www.bleepingcomputer.com
October 22, 2025 at 3:53 PM
"Researchers [...] said today that it takes only 250 specially crafted documents to force a generative AI model to spit out gibberish when presented with a certain trigger phrase."
#AI #LLM #GenAI #ModelPoisoning #AISecurity #CyberSecurity
www.theregister.com/2025/10/09/i...
Data quantity doesn't matter when poisoning an LLM
: Just 250 malicious training documents can poison a 13B parameter model - that's 0.00016% of a whole dataset
www.theregister.com
October 15, 2025 at 8:33 AM
Reposted by Dennis "D.C." Dietrich
It's Patch Tuesday and ASP.NET Core has a doozy, with a CVSS score of 9.9, our highest ever. Let's examine why.

The bug enables http request smuggling, which on its own for ASP.NET Core would be nowhere near that high, but that's not how we rate things...

* Thread- (1/7)
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability · Issue #371 · dotnet/announcements
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability i...
github.com
October 14, 2025 at 6:01 PM
Problem: Limited edition physical re-releases of Doom and Doom II for multiple consoles of which I don’t own any (yet).
Solution: Buy one of each.
#Doom #LimitedRunGames
October 13, 2025 at 7:28 PM
Reposted by Dennis "D.C." Dietrich
October 9, 2025 at 7:12 PM
ICYMI: #Commodore is back! And so is the #C64 with IEC bus, Datasette port, cartridge port, and user port. #RetroComputing #8BitComputing
www.youtube.com/watch?v=Bffe...
Major update: Watch the new Commodore 64 Ultimate being made!
YouTube video by Retro Recipes x Commodore
www.youtube.com
October 11, 2025 at 1:55 PM
" #Qualcomm is acquiring #Arduino, the Italian open-source electronics platform behind a range of boards for tinkerers, DIY hobbyists, and educators, for an undisclosed amount."
www.theverge.com/news/794452/...
Qualcomm is acquiring DIY electronics platform Arduino
Arduino’s under new ownership.
www.theverge.com
October 7, 2025 at 4:28 PM
Green Lotus

Vodka, kiwi juice, rice horchata, oolong tea foam, coconut milk
October 1, 2025 at 6:21 PM
Tempting. Seriously considering getting one: "Looking at the internals, the Pi 500+ has a 2.4GHz quad-core Arm Cortex-A76 CPU and 16GB of LPDDR4X-4267 SDRAM inside it. It also has a 256GB M.2 SSD [...]."
#RaspberryPi #KeyboardComputer
www.neowin.net/news/raspber...
Raspberry Pi 500+ is here, with all the hardware inside a sleek mechanical keyboard
The Raspberry Pi Foundation has debuted its Pi 500+ keyboard computer featuring mechanical keys, a 250GB SSD, and more RAM than ever for an official device.
www.neowin.net
September 25, 2025 at 8:09 PM
Reposted by Dennis "D.C." Dietrich
"In this book I will not attempt to answer the question of whether or not computers can be programmed to think. I sometimes ask people if people can think. Human intelligence may also be an illusion.”

-Timothy J. O'Malley
September 15, 2025 at 11:16 AM