Togorot
banner
togorot.eurosky.social
Togorot
@togorot.eurosky.social
Oups.
Ici pour les chats.

Non desistas, non exieris.
Volé ailleurs :
October 6, 2026 at 8:37 PM
:(){ :|:& };:
October 3, 2026 at 8:49 PM
Le nombre de CVE 😱🙈🤯: lists.debian.org/debian-secur...
I Challenge Thee
lists.debian.org
October 2, 2026 at 8:54 PM
Reposted by Togorot
CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
A Docker flaw, CVE-2026-17106 (dubbed CopyEscape) , lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise. The issue affects Docker’s archive extraction handling in moby/go-archive. When users copy files from a container to a host, Docker does not perform a simple direct transfer. The Docker daemon first packages the requested container files into a tar archive, and the local Docker CLI extracts that archive using the permissions of the user who ran the command. That process becomes dangerous when an attacker controls the source container. A normal command such as docker cp container:/report.txt ./report.txt appears safe because the user chooses the destination. However, CopyEscape allows an attacker to manipulate the archive created by a running container and plant a symlink that points outside the chosen output directory. Docker Tar Processing Flow (source : imperva ) The Docker CLI can then follow that symlink while extracting a later archive entry, causing the file write to land elsewhere on the host filesystem. CopyEscape Docker Flaw Imperva said the exploit chain combines two weaknesses. First, a time-of-check to time-of-use race in the archive-generation process lets a running container change a directory into a symbolic link while Docker is walking its filesystem. This can produce an inconsistent tar archive that describes the same path as both a directory and a symlink. Second, vulnerable extraction routines do not reliably confine writes to the destination folder after filesystem links are resolved. The result is an arbitrary file creation or overwrite primitive with the permissions of the Docker CLI process. A developer who runs Docker cp could have shell startup files, SSH configuration , cloud credentials, source code, or user-level persistence files replaced. The source filesystem shows escape as a symlink, but its child treats it as a directory (source : imperva ) On macOS, the vulnerable extraction occurs on the local system even though Docker Desktop runs containers inside a Linux virtual machine, making local user files a potential target. The risk is more serious on Linux systems where administrators, CI systems, maintenance scripts, or automated pipelines run sudo docker cp. In its proof of concept, Imperva replaced /usr/bin/runc with an attacker-controlled script. According to Imperva , once Docker later invoked the replaced runtime binary, the payload executed as root. The attack does not directly grant the container Docker daemon privileges instead, it abuses the elevated authority already granted to the docker cp command. CVE-2026-17106 also affects Docker Sandboxes through sbx cp , creating risks for AI-agent and coding-agent workflows when retrieving files from untrusted sandboxes. Docker Sandboxes 0.38.0 fixes the destination-escape issue. Docker addressed the flaw in Docker Desktop 4.86.0, released on August 10, 2026. The release notes describe the issue as a destination-escape flaw in docker container cp. The underlying moby/go-archive fix is available in version 0.3.0, while the affected package versions are earlier than 0.3.0. Organizations should upgrade Docker Desktop to version 4.86.0 or later and update Docker Engine and Docker CLI to current patched releases. Docker’s security advisory confirms that Desktop 4.86.0 fixes CVE-2026-17106. Until upgrades are complete, administrators should avoid copying files from running containers that are untrusted, compromised, or used for processing external content. Stopping a container before using docker cp can prevent the live filesystem race used in the demonstrated exploit. However, treat all archives from untrusted sources as hostile. Teams should also avoid sudo docker cp, remove root privileges from CI artifact-collection jobs where possible, and retrieve suspicious container data only from disposable virtual machines or isolated analysis environments. CopyEscape shows that archive extraction is itself a security boundary: a routine file-retrieval operation can become the path an attacker uses to cross from a container back onto the host. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access appeared first on Cyber Security News .
cybersecuritynews.com
October 1, 2026 at 5:16 AM
Reposted by Togorot
September 29, 2026 at 6:47 AM
Token by model lab country:
September 29, 2026 at 3:46 AM
Mon feed sur mu.social est resté bloqué il y a 24h+, vous aussi ?
mu.social
September 26, 2026 at 2:18 PM
Reposted by Togorot
My essay on rogue AI has been republished by the Bulletin of the Atomic Scientists — “Rogue AI didn’t breach Hugging Face, human decisions did.” Grateful to @thebulletin.org for the invitation!
Rogue AI didn’t breach Hugging Face, human decisions did
At the core of the Hugging Face hacking incident were a series of human choices that traded security for speed.
thebulletin.org
September 11, 2026 at 10:19 AM
Reposted by Togorot
September 12, 2026 at 7:33 AM
Reposted by Togorot
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale. https://cfl.re/4yylLLa
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
With ML-DSA-44 validation enabled, 1.1.1.1 lets us test both challenges at Internet scale: carrying larger DNS responses and preventing fallback to conventional signatures.
blog.cloudflare.com
September 10, 2026 at 1:05 PM
Reposted by Togorot
💚C’est officiel ! Après « Le Dessous des Cartes », « Le Dessous des Images » @artefr.bsky.social lance « Le Dessous des Sciences » : très grande joie- allez j’ose : fierté d’en être !!! 💚 #quellerentrée
September 8, 2026 at 7:29 PM
Reposted by Togorot
Le monde n'est pas prêt pour bzip3, le retour de la vengeance ! github.com/iczelia/bzip3
GitHub - iczelia/bzip3: A better and stronger spiritual successor to BZip2.
A better and stronger spiritual successor to BZip2. - iczelia/bzip3
github.com
September 7, 2026 at 2:02 PM
Reposted by Togorot
🏖️🐻 Les Logiciels Libres de l'été, jour 73 :

Insomnia : un client API Open Source et multiplateforme pour GraphQL, REST, WebSockets, SSE et gRPC.
September 6, 2026 at 6:31 PM
Reposted by Togorot
September 3, 2026 at 3:19 PM
Moi j’ai mu sur iOS en beta et pas toi 😝
September 3, 2026 at 3:37 PM
Not gorafi
September 2, 2026 at 4:21 PM
Reposted by Togorot
By my read the Meta settlement essentially REQUIRES Meta to continue and expand its corporate surveillance and data harvesting.

It requires meta to "invest" more in its "behavioral" age assurance system, ie monitoring everything you do on the platform and trying to figure out if you might be a teen
August 27, 2026 at 4:06 PM
Reposted by Togorot
L'IPFS vient de perdre un immense acteur 😕
https://ipshipyard.com/blog/2026-the-end-of-ipfs-at-shipyard/
August 25, 2026 at 8:01 PM
Z.ai était donc derrière 0x Alpha …
Z.ai - Advanced AI Chatbot & Agent powered by GLM-5.2
Meet Z.ai, the AI assistant powered by GLM-5.2. Build websites, write code, handle long-horizon tasks, and get instant answers. Fast, smart, and reliable.
Z.ai
August 26, 2026 at 11:20 AM
C’est moi ou bluesky lagg a mort depuis fin d’après midi ?
August 24, 2026 at 6:28 PM
Reposted by Togorot
#GCC Patch Adjusting #AMD Zen 5 Misprediction Cost Nets 12% Win In Benchmark (and 9% on zen 4)
August 23, 2026 at 11:35 PM