Yayitzzz
banner
yayitzzz.bsky.social
Yayitzzz
@yayitzzz.bsky.social
"Championing digital freedom and privacy, because true power lies in autonomy, not compliance."

https://its-yayo.github.io/contact
Totally love this song ngl. Im built different and my extensions are built different. Yep, lets trascend everything
"Any escape might help disprove the unattractive truth, but the suburbs have no charms to soothe the restless dream of youth"

Rush - Subdivisions (I love that song, it feels like a huge hug to me rn)
December 17, 2025 at 11:27 AM
Reposted by Yayitzzz
Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
cybersecuritynews.com
November 24, 2025 at 5:13 PM
Reposted by Yayitzzz
CrowdStrike detected an insider threat where an individual was providing sensitive information to hackers, showcasing the importance of cybersecurity in catching insider threats.
CrowdStrike catches insider feeding information to hackers
View post on Reddit.
reddit.com
November 22, 2025 at 6:42 PM
Reposted by Yayitzzz
France's cybersecurity agency was previously actively using GrapheneOS. They helped us by auditing our code and submitting bug reports such as this one:

github.com/GrapheneOS/h...

They also made suggestions for security improvements to improve protection against exploits.
Undefined behaviour in get_large_size_class() · Issue #133 · GrapheneOS/hardened_malloc
As mentioned there, I'm opening this issue to discuss another finding I investigated following static code analysis of hardened_malloc. If we can reach the following definition in get_large_size_cl...
github.com
November 22, 2025 at 3:14 PM
Zero-Trust policy then
Important to note here that the FBI was able to access the chat because of an informant who was in the chat.

Your Signal chats are only secure if you know and trust the people in them.

But be careful not to spread this in a way that makes people think "Signal is not really encrypted." Unhelpful.
BIG: FBI spied on Signal group chat of immigration activists CourtWatch, classifying them as violent terrorist extremists for quietly sitting in on court cases, as revealed in intel bulletin we obtained & shared w/ @samtlevin.bsky.social @us.theguardian.com. #FOIA www.theguardian.com/us-news/2025...
November 22, 2025 at 3:31 PM
Hyprland + Cosmic = ❤️

Ima calm my mind right now

#viernesdeescritorio
November 21, 2025 at 2:23 PM
Reposted by Yayitzzz
$ softwear reboot --obsidian
> compiling new hoodies, tees, and stickers…
> bases: covered
> status: live → obsidian.md/softwear
November 18, 2025 at 10:04 PM
Reposted by Yayitzzz
Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
Apache patched a Critical RCE flaw (CVE-2025-64408) in Causeway allowing authenticated attackers to execute arbitrary code via Java deserialization in the ViewModel component. Update to v3.5.0.
securityonline.info
November 20, 2025 at 5:35 AM
Reposted by Yayitzzz
Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
A Critical DoS flaw (CVE-2025-65015) in joserfc allows unauthenticated attackers to overwhelm log/SIEM systems by injecting massive JWT payloads into exception messages.
securityonline.info
November 20, 2025 at 5:40 AM
Reposted by Yayitzzz
🚨BREAKING NEWS🚨
We're suing the city of San Jose for its pervasive ALPR surveillance program. With nearly 500 ALPRs, the SJPD allows its officers to search millions of records, all without a warrant. These unconstitutional searches must be stopped. Read the complaint: www.eff.org/cases/siren...
SIREN and CAIR-CA v. San Jose
The San Jose Police Department has blanketed the city’s roadways with nearly five hundred Automatic License Plate Readers (ALPRs). The police department uses this unblinking surveillance network to
www.eff.org
November 18, 2025 at 6:43 PM
Reposted by Yayitzzz
The internet and technology—originally built as tools of freedom—are being used as weapons of tyranny. So what do we do? We Take Back CTRL. takebackctrl.org
November 13, 2025 at 7:00 PM
Reposted by Yayitzzz
We received an ASN and IPv6 space for GrapheneOS from ARIN: AS40806 and 2602:f4d9::/40.

We've deployed 2 anycast IPv6 networks for our authoritative DNS servers to replace our existing setup: 2602:f4d9::/48 for ns1 and 2602:f4d9:1::/48 for ns2. BGP/RPKI setup is propagating.
November 11, 2025 at 10:39 PM
Reposted by Yayitzzz
Privilege Escalation From Guest To Admin
Privilege Escalation From Guest To Admin
Privilege Escalation Guest user escalates To full project access after project visibility is switched to Public Hello Hackers I’m Mohamed, also known as Mado, a dedicated Web Application Penetration Tester and bug hunter NOTE: The Write Up is hunting and The Write up Focus on Privilege Escalation Get Your Coffe and Lets go If You Liked The Write up Dont Forget 50 Clapped And Thank you My Target Overview My target is a widely used task management app, available as a web app, mobile apps, desktop clients, and browser extensions. It supports personal and team workspaces, shared projects, and link-based project sharing Roles In My Target: Guest = Can edit anything in the project, but can’t remove anyone Admin = Can do Anything, remove or edit START⚔️ My Technique For Exploit : 1. I am Creating a Team Workspace (including Creating Projects) 2. Creating The Project For Writing the Tasks Team 3. I am invited to my second Account, but as a GUEST Now I Have 2 Accounts Owner = Main Account (Victim) Guest = Attacker Note: The guest in team cannot access any project; the owner must first give them access to the Project 4. After Inviting My Second Account as a Guest, I see that The Project can change to public, but anyone Outside The Workspace can View-only 5. I am choosing the Last one (Public), and now anyone in the project can click on the button Copy Link and view all the tasks and share the link with people outside the Team workspace (can’t edit or do anything, can view-only) 6. But wait, I have an Idea, what if the Guest clicks on the Button, copies the link, and leaves the project, and opens the link Are Can he join, or should the owner give them access again, or the target? Don't check on the Role and give him full permission I am trying First : copy The Link and go as an admin, and change a project from public to “Anyone in the team can edit.” Should the link have expired? But yeah, the link has expired Now I am Trying The Second Scenario : I am going as an admin and changing the Project To public. Now I am going as a Guest, copy the Link and leave The Project, And Open The Link again. What do you think is working? Yeah, My Scenario is working now. The Guest escalates the Privilege and removes anyone from the project admins and anyone? Guest Can remove The admin / Response From Server is 200 => Owner Removed Steps 1. I am Creating a Team Workspace For Create Projects 2. Creating The Project For Write My Tasks 3. I am invited to my second Account, but as a GUEST 4. Go as an Admin, Change the Project to public 5. Go as a Guest, click on the button Copy link 6. Attacker leaves the Project and opens the Link of the Project Public 7. Target: Give him Full permission (Edit, remove anyone) The End The Results: The Target doesn't check on the Role if the user is in the Team The/ Attacker can escalate the Role and gain full access to the project by changing the project to public My signature If You Want To Reach Me All My Contact Info is Here: Click Here ……………Thank You For Reading and I hope This Was helpful……………… Privilege Escalation From Guest To Admin👑 was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
November 13, 2025 at 2:53 PM
Reposted by Yayitzzz
Screw Tatooine: astronomers have found a binary star system where *both* stars have planets!

Well, maybe. But this is a cool story!

badastronomy.beehiiv.com/p/another-we...

🔭🧪
Another weird planetary system has been found
A binary star may have planets orbiting both stars
badastronomy.beehiiv.com
November 13, 2025 at 3:08 PM
Reposted by Yayitzzz
LibreOffice 25.8.3 Office Suite Is Now Available for Download with 70 Bug Fixes 9to5linux.com/libreoffice-...

#Linux #OpenSource
LibreOffice 25.8.3 Office Suite Is Now Available for Download with 70 Bug Fixes - 9to5Linux
LibreOffice 25.8.3 is now available for download as the third update to the latest LibreOffice 25.8 office suite series with 70 bug fixes.
9to5linux.com
November 13, 2025 at 2:51 PM
Reposted by Yayitzzz
★ Just published: Billion Mail — Open-source mail server with unlimited sending & AI tools

Self-hosted email marketing platform with unlimited sending, AI-powered email creation, real-time analytics, and no monthly fees. Complete SMTP solution.
Billion Mail: Open Source Alternative to Resend, SendGrid and Mailchimp
Self-hosted email marketing platform with unlimited sending, AI-powered email creation, real-time analytics, and no monthly fees. Complete SMTP solution.
openalternative.co
November 13, 2025 at 3:00 PM
Reposted by Yayitzzz
Linux Unified Key Setup → LUKS2 : add table for binary and json headers

Interest | Match | Feed
Origin
en.wikipedia.org
November 11, 2025 at 5:30 AM
Reposted by Yayitzzz
Sun Microsystems' open source Unix distribution, called OpenSolaris, lives on in this variant. Linux users should give it a try.
Unix: OpenSolaris Lives on in This OpenIndiana Fork
Sun Microsystems' open source Unix distribution, called OpenSolaris, lives on in this variant. Linux users should give it a try.
bit.ly
November 10, 2025 at 2:01 AM
Reposted by Yayitzzz
How to Install Pi-hole on an #Ubuntu VPS Server

Pi-hole is a network-wide ad blocker that acts as a DNS sinkhole. It's an effective tool for blocking ads and trackers on all devices connected to your network. This guide will walk you through ...
Continued 👉 #installguide #vpsguide #pihole
November 8, 2025 at 6:10 AM
Reposted by Yayitzzz
A nice update to LibreOffice has been released this month

Read more about it here

https://blog.documentfoundation.org/blog/2025/10/09/release-of-libreoffice-25-8-2/

Libre Office LibreOffice Documentation Foundation OpenSource programming Linux POSIX
November 1, 2025 at 2:13 PM
Reposted by Yayitzzz
fun fact: i am now paying more for my linux desktop than i did for windows. not because i have to, but because i want to.

i donate to some open-source teams and projects that i depend on in my day-to-day because they're just that good and i wanna support the work they do :>
October 28, 2025 at 1:51 PM
Reposted by Yayitzzz
If we ran a poll today, Python, C, and C++ would probably top the list of Raspberry Pi languages. But I recently came across another one. Although it’s not as well-known, it has serious potential, especially if you want speed and performance in... #raspberrypi #linux
Getting Started with Rust Programming on Raspberry Pi
Keep reading on RaspberryTips.com
raspberrytips.com
October 28, 2025 at 2:00 PM
Mets is such a horrific company.
I deleted my “Meta” accounts but I still get infuriating emails like this. I guess I don’t agree to these changes!
October 27, 2025 at 3:36 PM