#highpriority
Stuck in an infinite loop.

Send help.

#highpriority
September 15, 2026 at 1:34 PM
PIXIE : code correction, accepted @made-sick.org

Implement #feedback
made-sick.org

Target #washed low-impact profiles
Analyze #metadata MATCHES established verified sources with @archive.org

Mark any matches as #highpriority
Category :youtube rappers

PIXIE : confirmed #musicsky
September 12, 2026 at 9:34 PM
B&C's TSCAblog: DoW Seeks Information on Existing Chemicals Undergoing TSCA Risk Evaluation
www.lawbc.com/dow-seeks-in...
#DoW, #highpriority, #TSCA
DoW Seeks Information on Existing Chemicals Undergoing TSCA Risk Evaluation - Bergeson & Campbell, P.C.
The U.S. Department of War (DoW) published a request for information (RFI) on May 12, 2026, seeking information to identify and assess critical
www.lawbc.com
May 15, 2026 at 11:39 PM
#EssentialTruthSocial "Truth Media Empire: Trump Family Media"

1. Donald Trump creates wild and crazy #MediaEvent

2. Every All media system kicks into #HighPriority delivery network of Trump

3. Social media users GO: LOL LOL Trump Stupid, Dumb Trump, LMAO

#MemeNetworks rule the USA minds.
May 7, 2026 at 6:17 PM
Parts 1-3/3 — EFTA01655458.jpg
#epsteinweb #efta01655458
https://epsteinweb.org
Available in the iOS app store now!
https://apps.apple.com/us/app/epstein-web/id6758880661
March 5, 2026 at 7:19 PM
Check it out, scholarships from the USASP for high priority early career investigators! These are scholarships to support trainees or young investigators for underrepresented or disadvantaged backgrounds to attend the 2026 annual USASP meeting.
Apply by February 5th!
www.usasp.org/highpriority...
High Priority Early Career Award | USASP
Provide opportunities individuals from underrepresented groups (racial and ethnic backgrounds, gender identities, sexual orientations, and/or disabilities).
www.usasp.org
February 5, 2026 at 3:04 PM
Check it out, scholarships from the USASP for high priority early career investigators! These are scholarships to support trainees or young investigators for underrepresented or disadvantaged backgrounds to attend the 2026 annual USASP meeting.
Apply by February 5th!
www.usasp.org/highpriority...
High Priority Early Career Award | USASP
Provide opportunities individuals from underrepresented groups (racial and ethnic backgrounds, gender identities, sexual orientations, and/or disabilities).
www.usasp.org
February 4, 2026 at 1:01 PM
Check it out, scholarships from the USASP for high priority early career investigators! These are scholarships to support trainees or young investigators for underrepresented or disadvantaged backgrounds to attend the 2026 annual USASP meeting.
Apply by February 5th!
www.usasp.org/highpriority...
High Priority Early Career Award | USASP
Provide opportunities individuals from underrepresented groups (racial and ethnic backgrounds, gender identities, sexual orientations, and/or disabilities).
www.usasp.org
January 30, 2026 at 12:23 AM
11月のパッチチューズデー:サーバー、コントローラー、PCにおけるゼロデイWindowsカーネルの脆弱性

重要なのは、Active DirectoryのKerberosの脆弱性、Visual Studio Copilot拡張機能、そしてMicrosoft Graphics Componentの問題です。 サーバー、コントローラー、デスクトップにおけるゼロデイの特権昇格Windowsカーネル脆弱性が積極的に悪用されており、直ちにパッチを適用する必要があります。 これは、Tenableの上級スタッフリサーチエンジニアであるSatnam…
11月のパッチチューズデー:サーバー、コントローラー、PCにおけるゼロデイWindowsカーネルの脆弱性
重要なのは、Active DirectoryのKerberosの脆弱性、Visual Studio Copilot拡張機能、そしてMicrosoft Graphics Componentの問題です。 サーバー、コントローラー、デスクトップにおけるゼロデイの特権昇格Windowsカーネル脆弱性が積極的に悪用されており、直ちにパッチを適用する必要があります。 これは、Tenableの上級スタッフリサーチエンジニアであるSatnam Narang氏のアドバイスであり、本日の11月パッチチューズデーでMicrosoftが特定した63件の脆弱性のうち、対処すべき2大脆弱性の1つです。 また、SAPは本日、26件の新規および更新されたセキュリティパッチの中で、4件のHotNewsノートと2件のHighPriorityノートをリリースしました。1つのパッチは、ハードコードされた認証情報のためSQL Anywhere Monitorを削除します。 本日、Adobeは8件のアップデートを、Mozillaは3件のアップデートをリリースしました。 Windowsカーネルの脆弱性 Microsoftが対処すべき最も緊急性の高い脆弱性はCVE-2025-62215(Windowsカーネルの脆弱性)ですと、Narang氏はCSOへのメールで述べています。「このバグを悪用するにはかなりの前提条件が必要ですが、Microsoftはすでに積極的な悪用が進行中であることを確認しています。この脆弱性の影響は無視できません。特権昇格の脆弱性は、組織内の他の扉を開く鍵となるからです。これが攻撃者が初期侵入から本格的な侵害へと進む方法です。」 また、Mike Walters氏(Action1社長)は、この脆弱性がデスクトップだけでなく、サーバーやドメインコントローラーにも影響を与えると指摘しています。 Chris Goettl氏(Ivantiプロダクトマネジメント副社長)は、この脆弱性が現在サポートされているすべてのWindows OSエディションおよびESU(拡張セキュリティ更新プログラム)対象のWindows 10マシンに影響すると述べています。「つまり、Windows 10のサポート終了後も使い続けることは仮定上のリスクではありません。」 Ben McCarthy氏(Immersive社リードサイバーセキュリティエンジニア)は、この脆弱性の悪用方法を説明しています。低権限のローカルアクセスを持つ攻撃者が、レースコンディションを繰り返し発生させる特別に作成されたアプリケーションを実行できます。目的は、複数のスレッドを同期されていない方法で共有カーネルリソースと相互作用させ、カーネルのメモリ管理を混乱させて同じメモリブロックを2回解放させることです。この「ダブルフリー」が成功するとカーネルヒープが破損し、攻撃者はメモリを上書きしてシステムの実行フローを乗っ取ることができます。 Microsoftによれば、この脆弱性を悪用するための攻撃の複雑さは高いものの(レースコンディションを制する必要があるため)、必要な権限は低いとされています。そして、得られる報酬は大きい:この脆弱性を悪用した攻撃者はSYSTEM権限を獲得できます。 Windows ESUプログラム利用者は、Nick Carroll氏(Nightwingサイバーインシデントレスポンスマネージャー)によれば、一部のユーザーが拡張セキュリティ更新プログラムへの登録に問題を報告していることに注意が必要です。Microsoftは最近、Windows 10 Consumer Extended Security Updateプログラムへの登録時の問題に対処するため、臨時のアップデートをリリースしました。プログラムへの参加を計画している管理者は、KB5071959をインストールして登録問題に対処してください。その後、今日のKB5068781など他のアップデートもインストールできるようになります。 Visual Studio Copilot拡張機能の脆弱性 2つ目の主要な脆弱性はCVE-2025-62222で、Microsoft Visual Studio Code Copilot Chat Extensionにおけるリモートコード実行の脆弱性です。 悪用される可能性は低いと評価されていますが、Narang氏は「これは生成AIやエージェントAI(基盤モデルやオープンソースモデル、AI支援コード編集ツールを含む)にバグを見つけることへの関心の高まりを示しています」と述べています。
blackhatnews.tokyo
November 12, 2025 at 3:07 AM
November Patch Tuesday: Zero day Windows kernel flaw in servers, controllers, and PCs
A zero day elevation of privilege Windows kernel flaw in servers, controllers, and desktops is being actively exploited and needs to be patched immediately. That’s the advice of Satnam Narang, senior staff research engineer at Tenable, on one of the two biggest vulnerabilities that needs to be addressed from among the 63 holes identified by Microsoft in today’s November Patch Tuesday releases. Separately, SAP today released four HotNews Notes and two HighPriority Notes among its 26 new and updated security patches. One patch deletes the SQL Anywhere Monitor because of hard-coded credentials. Also today, Adobe released eight updates, while Mozilla released three. ## Windows kernel flaw The most urgent of the Microsoft holes to be addressed is CVE-2025-62215 (the Windows kernel vulnerability),” Narang told _CSO_ in an email. “While there is a substantial prerequisite to exploit the bug, Microsoft confirmed active exploitation is underway. The consequences cannot be ignored, as elevation of privilege vulnerabilities are the keys to opening other doors within the organization. This is how attackers go from initial foothold to full-blown breach.” And, Mike Walters, president of Action1, points out, this vulnerability impacts servers and domain controllers as much as desktops. Chris Goettl, vice president of product management at Ivanti, notes that this vulnerability affects all currently supported Windows OS editions plus the Windows 10 machines covered by the ESU (Extended Security Updates) program, “which means running Windows 10 past the end-of life (EOL) is not a hypothetical risk.” Ben McCarthy, lead cyber security engineer at Immersive, explained how this hole can be exploited. An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger a race condition. The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronized way, confusing the kernel’s memory management and causing it to free the same memory block twice. This successful “double free” corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system’s execution flow. Microsoft says while the attack complexity to exploit this hole is high — successful exploitation requires an attacker to win a race condition — the privileges required are low. And the prize is great: An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Those in the Windows ESU program should note that, according to Nick Carroll, cyber incident response manager at Nightwing, some users have been reporting issues enrolling in the Extended Security Update program. Microsoft has recently released an out-of-band update to address issues when users try to enroll in the Windows 10 Consumer Extended Security Update program, he said. Admins planning to participate in the program should make sure to update and install KB5071959 to address the enrollment issues. After that is installed, users should be able to install other updates such as today’s KB5068781, which is the latest update to Windows 10. ## Flaw in Visual Studio Copilot Extension The second major vulnerability is CVE-2025-62222, a remote code execution flaw in Microsoft Visual Studio Code Copilot Chat Extension. While it is rated as less likely to be exploited, Narang said, it “underscores a growing interest in finding bugs in generative AI or agentic AI, which encompasses large language models, whether foundational models or open source models, and the AI-assisted code editing tools.” Researchers at Cisco Systems said exploitation is not trivial for this vulnerability, as it requires multiple steps: prompt injection, Copilot Agent interaction, and triggering a build. Cisco notes that Microsoft assessed that the attack complexity is “high”, and that exploitation is “less likely”. CSOs should already be addressing emerging AI risks with governance and policy enforcement, added Narang. “If Shadow AI and unchecked sanctioned AI usage run rampant through their organization, CSOs must modify their strategy to govern this emerging, complex attack surface before it’s too late.” ## Kerberos vulnerability Among the fixes released is one for CVE-2025-60704, a Kerboros delegation vulnerability in Active Directory dubbed CheckSum by researchers at Silverfort, who discovered it. If exploited, an attacker could impersonate an authenticated user, escalate privileges and stay hidden. Because Kerberos is a way to enable applications to authenticate securely on behalf of users, abuse of it can be dangerous, Silverfort says in an explanation of this vulnerability. Using a man-in-the-middle technique, the flaw allows researchers to impersonate arbitrary users and ultimately gain control over the entire domain. “Any organization using Active Directory with the Kerberos delegation capability turned on is impacted,” says Silverfort. “This means thousands of companies around the world are affected by this vulnerability.” ## Microsoft Graphics Component flaw Tyler Reguly, associate director of R&D at Fortra, was drawn to CVE-2025-60724, one of several vulnerabilities rated critical in severity. It’s a heap-based buffer overflow in Microsoft Graphics Component that could allow an unauthorized attacker to execute code over a network. He notes that Microsoft says, “in the worst-case scenario, an attacker could trigger this vulnerability on web services by uploading documents containing a specially crafted metafile without user interaction.” “If I’m a CISO, then CVE-2025-60724 has me worried this month,” he told _CSO_. “We have a vulnerability that Microsoft and CVSS agree is critical and an attack vector that requires no user interaction and no privileges, just the ability to upload a file. We know nothing about the file type, the technologies that are impacted (other than GDI+ in the title), or the services impacted. Do I need to worry about my SharePoint infrastructure? What about third-party software – my wiki or my bug tracker? This is definitely one that feels a little spooky without a lot of extra details being provided.” Cisco explains the vulnerability can be triggered by convincing a victim open a document that contains a specially crafted metafile. “In the worst-case scenario,” its researchers write, “an attacker could trigger this vulnerability on web services by uploading documents containing a specially crafted metafile without user interaction. An attacker doesn’t require any privileges on the systems hosting the web services. Successful exploitation of this vulnerability could cause RCE or information disclosure on web services that are parsing documents that contain a specially crafted metafile, without the involvement of a victim user.” ## SAP patches The patches released by SAP today include some Notes that are updates to previously related fixes. That includes two HotNews patches. But there are new two patches, rated high priority by Onapsis, dealing with SAP Commerce Cloud (with a CVSS score of 7.5) and SAP CommonCryptoLib (also with a score of 7.5). One of the notes, #3666261, has a CVSS score of 10. It deals with an insecure key and secret management vulnerability in SQL Anywhere Monitor with hard-coded credentials. SQL Anywhere Monitor is a browser-based administration tool that gives admins information about the health and availability of SQL Anywhere databases, MobiLink servers, and MobiLink server farms. It can also provide information about the availability of web servers, proxy servers, and host computers; The patch removes SQL Anywhere Monitor completely, say researchers at Onapsis. As a temporary workaround, SAP recommends that admins stop using this tool and delete any instances of SQL Anywhere Monitor database. Another note to pay attention to, #3668705 (CVE-2025-42887) patches a code injection vulnerability in SAP Solution Manager. Due to missing input sanitization in a remote-enabled function module, authenticated attackers are able to inject malicious code into the system. Rated with a CVSS score of 9.9, this vulnerability is patched by adding an input check that rejects most of the non-alphanumeric characters. “CVE-2025-42887 is particularly dangerous because it allows an attacker to inject code from a low-privileged user, which leads to a full SAP compromise and all data contained in the SAP system,” notes Joris van de Vis, director of security research at SecurityBridge. Onapsis CTO Juan Pablo Perez-Etchegoyen also says admins need to deal quickly with Note #3633049. “Despite this being a CVSS 7.5,” he said in an email to _CSO_ , “it is a memory corruption potentially exploitable remotely pre-authentication, and these types of vulnerability tend to be very critical because of their nature and potential for denial of service and system compromise.” However, with many of these vulnerabilities, patching alone is not enough: architecture, exposure, segmentation, and monitoring still matter, advises Mike Walters of Action1. “CSOs need to involve not just patching teams, but also service owners (print, scan, document sharing, remote access), network/security teams (for segmentation and exposure control), and logging/monitoring teams (for post-patch verification),” he said.
www.csoonline.com
November 12, 2025 at 9:48 AM
B&C's TSCAblog : Responses to DOD Survey on Alternatives to TSCA High Priority Chemicals Due September 26, 2025
www.lawbc.com/responses-to...
#AA, #DOD, #highpriority, #TSCA, #chemicals
Responses to DOD Survey on Alternatives to TSCA High Priority Chemicals Due September 26, 2025 - Bergeson & Campbell, P.C.
The U.S. Department of Defense’s (DOD) Office of the Assistant Secretary of Defense for Energy, Installations, and Environment will be funding an
www.lawbc.com
September 11, 2025 at 11:28 PM
🟠 CVE-2025-43300 - High

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

🚨 Exploited
Source: CISA

#CVE #Security #HighPriority #Exploited
August 21, 2025 at 5:45 PM
🟠 CVE-2025-54948 - High

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on...

🚨 Exploited
Source: CISA

#CVE #Security #HighPriority #Exploited
August 18, 2025 at 2:10 PM
🟠 CVE-2025-8088 - High

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

🚨 Exploited
Source: CISA

#CVE #Security #HighPriority #Exploited
August 13, 2025 at 6:06 AM
Add these 2 to the @democrats.org “To Do” list #HighPriority #SaveOurDemocracy

#AbolishTheElectoralCollege
#ReverseCitizensUnited

Way Past Time for playing hard ball folks 💪🏼 🔵
August 4, 2025 at 5:17 PM
Drowning in email? Outlook’s Copilot-powered Priority view could throw you a lifeline. www.windowscentral.com/software-app...
Drowning in email? Outlook’s Copilot-powered Priority view could throw you a lifeline.
Priority view in Outlook will use Copilot to sort emails that require a reply or are highpriority.
www.windowscentral.com
June 9, 2025 at 4:51 PM
紀錄一下用 #koboldcpp 進行的 #llm 性能測試

Llama 3 8B模型,IQ4_XS 量化
Flags: NoAVX2=False Threads=7 HighPriority=False Cublas_Args=None Tensor_Split=None BlasThreads=7 BlasBatchSize=512 FlashAttention=True KvCache=2
Timestamp: 2025-05-26 07:36:07.196685+00:00
Backend: koboldcpp_vulkan.so
Layers: 49
Model […]
Original post on mistyreverie.org
mistyreverie.org
May 26, 2025 at 7:46 AM
TDS?
The
Daily
Show?
Jon Stewart is hilarious. #HighPriority
a man in a suit and tie is sitting at a desk with his hands in the air
ALT: a man in a suit and tie is sitting at a desk with his hands in the air
media.tenor.com
March 9, 2025 at 6:46 AM
URGENT REPORT: SAVE GREENPEACE FROM THE UNFAIR LAWSUIT! Hurry before the lawsuit in February 24th comes! #Urgent #Donate #Donation #PleaseDonate #Greenpeace #SaveGreenpace #Project2025 #SaveEarth #StopBigOil #Activism #BlueCrew #HighPriority #Resist #DefendDemocracy

gpus.link/tote6n
Support Greenpeace Today!
I just donated to Greenpeace. Join me and support their important work to protect the environment today!
gpus.link
February 20, 2025 at 1:02 PM