Sensitive content
Les bug bounty hunters nāont quāaĢ bien se tenir car Google va bientoĢt tenter de les remplacer (comme ils ont deĢjaĢ remplaceĢ pas mal de creĢateurs web) graĢce aĢ leur nouvelle IA baptiseĢe Big Sleep. En effet, celle-ci vient de prouver quāelle peut deĢtecter des failles de seĢcuriteĢ que meĢme les meilleurs hackers humains ont loupeĢes. Et je ne vous parle pas de petites vulneĢrabiliteĢs bidons, mais de veĢritables failles dans des logiciels critiques.
Vous vous souvenez quand je vous parlais de XBOW, cette IA qui eĢtait devenue numeĢro 1 sur HackerOne ? Eh bien Google vient de rentrer dans la danse avec Big Sleep, et visiblement ils ne sont pas venus pour rigoler. Lāapproche est diffeĢrente mais tout aussi impressionnante.
Big Sleep, cāest le fruit dāune collaboration entre Google Project Zero (lāeĢquipe dāeĢlite qui trouve des failles zero-day) et DeepMind (les geĢnies derrieĢre AlphaGo). Ensemble, ils ont creĢeĢ une IA capable dāanalyser du code source et de deĢtecter des vulneĢrabiliteĢs de manieĢre autonome. Le nom āBig Sleepā vient dāailleurs du roman noir de Raymond Chandler (lien affilieĢ), un clin dāÅil au coĢteĢ deĢtective de lāIA.
La premieĢre vraie victoire de Big Sleep, cāest donc dāavoir trouveĢ une vulneĢrabiliteĢ stack buffer underflow dans SQLite, la base de donneĢes la plus utiliseĢe au monde. Cette faille eĢtait passeĢe sous le radar de tous les outils de fuzzing traditionnels et des chercheurs humains. LāIA a reĢussi aĢ lāidentifier en analysant les patterns de code et en comprenant la logique profonde du programme.
Ce qui est vraiment fou avec Big Sleep, cāest sa capaciteĢ aĢ comprendre le contexte et la seĢmantique du code car contrairement aux outils de fuzzing classiques qui bombardent le programme avec des donneĢes aleĢatoires pour voir sāil crashe, Big Sleep lit et comprend reĢellement ce que fait le code.
Cāest la diffeĢrence entre un lecteur de Korben.info qui lit lāun de mes articles et qui est content. Et un lecteur de Korben.info (ou pas dāailleurs) qui lit lāun de mes articles en diagonale (ou juste le titreā¦lol), qui ne comprend rien et qui part ensuite māinsulter sur les reĢseaux sociaux ^^.
Google explique que Big Sleep utilise une approche en plusieurs eĢtapes. Dāabord, lāIA analyse le code source pour comprendre sa structure et son fonctionnement. Ensuite, elle identifie les zones potentiellement vulneĢrables en se basant sur des patterns connus mais aussi sur sa compreĢhension du flux de donneĢes. Enfin, elle geĢneĢre des cas de test speĢcifiques pour confirmer lāexistence de la vulneĢrabiliteĢ.

Les 20 vulneĢrabiliteĢs deĢcouvertes touchent diffeĢrents types de logiciels, des bibliotheĢques systeĢme aux applications web. Google reste discret sur les deĢtails exacts pour des raisons eĢvidentes de seĢcuriteĢ, mais ils confirment que toutes les failles ont eĢteĢ corrigeĢes avant toute exploitation malveillante. Cāest le principe du responsible disclosure : on trouve, on preĢvient, on corrige, et seulement apreĢs on communique.
Ce qui diffeĢrencie Big Sleep de XBOW, cāest surtout lāapproche. LaĢ ouĢ XBOW excelle dans les bug bounties publics avec une approche plus agressive, Big Sleep semble plutoĢt orienteĢ vers lāanalyse en profondeur de code complexe. Les deux IA sont donc compleĢmentaires et montrent bien que lāavenir de la cyberseĢcuriteĢ passera par ces assistants intelligents.
Dāailleurs, Google ne compte pas garder Big Sleep pour lui et lāeĢquipe travaille sur une version open source qui permettra aĢ la communauteĢ de beĢneĢficier de cette technologie. LāideĢe cāest de deĢmocratiser la recherche de vulneĢrabiliteĢs pour que meĢme les petites entreprises puissent seĢcuriser leur code.
Mais attention, tout nāest pas rose non plus car que se passera-t-il si des acteurs malveillants mettent la main sur ce genre dāIA ? La course aux armements entre attaquants et deĢfenseurs risque de fortement sāacceĢleĢrer drastiquement. Google assure avoir mis en place des garde-fous, mais on sait tous que dans le domaine de la seĢcuriteĢ, rien nāest jamais garanti aĢ 100%.
Selon Google, Big Sleep peut analyser en quelques heures ce qui prendrait des semaines aĢ une eĢquipe humaine et contrairement aĢ vous les vacanciers eĢternels, lāIA ne se fatigue pas, ne fait pas dāerreur dāinattention, et peut traiter des volumes de code monumentaux. Sur les 20 vulneĢrabiliteĢs trouveĢes, au moins 5 eĢtaient consideĢreĢes comme critiques avec un score CVSS supeĢrieur aĢ 8.
Pour voir les dernieĢres deĢcouvertes de BigSleep cāest par ici.
Lāobjectif pour Google aĢ terme cāest de creĢer une IA capable de comprendre non seulement le code, mais aussi lāintention derrieĢre le code, donc si vous eĢtes deĢveloppeur ou responsable seĢcuriteĢ, il est temps de prendre ce sujet au seĢrieux. Les IA comme Big Sleep et XBOW ne sont pas des gadgets, donc commencez aĢ reĢfleĢchir aĢ comment inteĢgrer ces outils dans vos processus de deĢveloppement et surtout, nāattendez pas que les attaquants sāen servent contre vous.
Source
posted by pod_feeder
The discoveries by an AI-based bug hunter are significant, as it shows these tools are starting to get real results, even if they still need a human.Lorenzo Franceschi-Bicchierai (TechCrunch)
N. E. Felibata š½ reshared this.
Studying the glowing patterns of Earthās surface helps us understand human activity, respond to disasters, and witness a changing world.
Studying the glowing patterns of Earth039;s surface helps us understand human activity, respond to disasters, and witness a changing world.
Studying the glowing patterns of Earth's surface helps us understand human activity, respond to disasters, and witness a changing world.Earth Science Division Editorial Team (NASA Science)
whuffo likes this.
BRITAIN is ānot just complicit, but an active participantā in Israelās genocide in Gaza, activists said today during a protest by British Jews against attacks on Palestine.Morning Star
DEAR FRIENDS. IF YOU LIKE THIS TYPE OF CONTENT, SUPPORT SOUTHFRONT WORK: MONERO (XMR): 86yfEHs6pkoDEKCxc6MAnQX8cVHmzhYxMVrNuwKgNmqpWK8dDxjgGnK8PtUNJMA...Anonymous765 (South Front)
What to know about Legionnaires' disease, which has sickened dozens in New York City
https://apnews.com/article/legionnaires-disease-water-harlem-321a278807329f3843c8d37d40e09e51?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
Tennessee readies for execution of man with working implanted defibrillator
https://apnews.com/article/tennessee-execution-defibrillator-bd1c3d5fcc3dd78faf9fc3ba9a5c7aad?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
Copper torches, lanterns, bars, and chains have been added in today's #Minecraft snapshot 25w32a!
Check out all of the new features in our #MinecraftWiki article and help us document them:
minecraft.wiki/w/Java_Edition_ā¦
25w32a is the second snapshot for Java Edition 1.21.9,[unofficial name] released on August 5, 2025.[1]Minecraft Wiki
Emmanuel Florac likes this.
Emmanuel Florac reshared this.
N. E. Felibata š½ reshared this.
Sri Lanka's parliament votes to fire country's police chief over abuse of power
https://apnews.com/article/sri-lanka-parliament-police-chief-fired-d0cfd69ae1e16d4b0f56188352b6c45f?utm_source=flipboard&utm_medium=activitypub
Posted into Asia @asia-AssociatedPress
whuffo likes this.
jonathanturley.org/2025/08/05/ā¦
The comments of Ramirez have clearly struck a nerve on both sides. For my part, I am very proud of both my Irish-Sicilian background. My Sicilian grandparents came to this country at the turn of the century. They were deeply proud of their heritage but always insisted that their children identify as Americans first and foremost.
Democrat Rep. Delia Ramirez (D., Ill.) is locked into a fierce fight with the White House over controversial remarks at the second annual Panamerican Congress held in Mexico, including declaring, āā¦JONATHAN TURLEY
Lady Gaga leads 2025 MTV Video Music Awards nominations, followed by Bruno Mars and Kendrick Lamar
https://apnews.com/article/mtv-vmas-2025-nominees-bfc482686f37f7e5ebb4cd84067ee5ef?utm_source=flipboard&utm_medium=activitypub
Posted into Entertainment @entertainment-AssociatedPress
The Greatest Builder...and POTUS, ever!
theconservativetreehouse.com/bā¦
President Trump was reviewing the symmetry of architecture as the plans for the White House ballroom are being finalized.Sundance (The Last Refuge)
Sirens have sounded in multiple Israeli city settlements after a missile was launched from Yemen.Al Mayadeen English (Yemeni missile fired at Israeli target; sirens sound in central cities)
Google has released security updates to address multiple security flaws in Android, including fixes for two Qualcomm bugs that were flagged as actively exploited in the wild. The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6), by the chipmaker back in June 2025. CVE-2025-21479
posted by pod_feeder
Google fixed 6 Android flaws, including 3 exploited Qualcomm bugs, raising spyware concerns. Users urged to update.The Hacker News
N. E. Felibata š½ reshared this.
GitHub Pull Requests Are Down
Link: github.com/github/site-policy/ā¦
Discussion: news.ycombinator.com/item?id=4ā¦
GitHub is introducing non-essential cookies on web pages that market our products to businesses. These cookies will provide analytics to improve the site experience and personalize content and ads ...GitHub
MLB contenders watch for fatigue as some starters experience an increased workload
https://apnews.com/article/mlb-innings-limits-ea7e63d6a461f050c7f21cdae9e57294?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
How Ghislaine Maxwell's dad wrecked science
youtube.com/watch?v=KcujgE7znwā¦
A lot of people donāt know that Ghislaine Maxwellās dad, Robert Maxwell, played a pivotal role in setting up the system for how science research gets publish...YouTube
Singapore - Saba: Gold prices fell on Sunday, affected by profit-taking after the sharp rise in the previous session following the release of weaker-than-expected US jobs data, which reinforced expectations of a Federal Reserve interest rate cut in ā¦www.saba.ye
Microsoft's AI-fueled 4 trillion valuation highlights the massive impact of the AI bubble on the US economy. AI investments are now acting as a private sector stimulus, contributing more to US economic growth than consumer spending. However, a clear and sustainable business model remains elusive. In many ways, the current AI boom mirrors the dynamics of the dot-com era.
bloodinthemachine.com/p/the-aiā¦
#usa #economy #technology
Plus how American professors are fighting back against the AI onslaught, a backlash over AI models in Vogue, and more.Brian Merchant (Blood in the Machine)
@Sh4d0w_H34rt O think it's important to separate the tech from the capitalist industry using it. Meanwhile, an economic crash was already in the works even without AI. All the bubble did was postpone what was already inevitable.
It's also informative to see how this tech is being integrated into Chinese economy for contrast.
A friend just sent me this article about losing a spouse.
"You think you're prepared.
you go in with boxes and garbage bags. You tell yourself youāll be strong.
You think, āItās just stuff.ā
But then you open a drawer.
And their handwriting is still on a notepad.
Their scent still clings to the sleeves of that sweater you begged them to throw out every winter.
Their shoes are still lined up by the door like they might be back any minute.
to be cont
No one tells you how heavy an empty coat can feel in your hands.
No one tells you that cleaning out a space can shatter you all over again.
Itās not just cleaning.
Itās letting go of little pieces you were never ready to lose.
Itās closing a drawer for the last time and feeling like youāre betraying them.
Itās packing up the life you shared, while your heart silently begs, please donāt make me.
Because deep down, youāre not just packing away their things ā
Columbia University's recent suspension and expulsion of more than 70 students for a Palestine demonstration is the latest sign the school's crackdown on activism is not simply about campus conduct, but appeasing political pressure from Washington.
mondoweiss.net/2025/08/as-coluā¦
#Palestine #Israel #Gaza
@palestine @israel
Columbia Universityās recent suspension and expulsion of more than 70 students for a Palestine demonstration is the latest sign the schoolās crackdown on activism is not simply about campus conduct, but appeasing political pressure from Washington.Tamara Turki (Mondoweiss)
like this
Climate Change 2025
The water crisis in Iran: The dire situation of the Zayandeh-Rud River in Isfahan.
In the past, the river was the lifeline of the city and the entire region.
#AureFreePress #News #press #headline #GlobalWarming #climatechange #climatecrisis #Breaking #BreakingNews #Iran
What a sad man he is.
Mark Mansour notes that the overt, unabashed gerrymandering proposed by Texas Republicans is designed, by their own admission, to "enhance the political efficacyā of GOP votes.
What this is really about is enhancing the political efficacy of WHITE RURAL voters. As Mansour says, it's "a chilling disenfranchisement of millions of votersāespecially Black, Latino, and Asian Americans."
#Texas #Republicans #gerrymandering #racism
/1
mmansour.substack.com/p/the-teā¦
Trump and Abbott are involved in a conspiracy to cheat Texas voters-it has to be stoppedMark Mansour (Americaās Fractured Politics)
āTrump knows he canāt win the upcoming mid-term elections, so he is trying to rig them. And the way he is trying to do it is to dismantle the Voting Rights Act of 1965 as we know it. He is trying, for example to try and dismantle Hispanic and African-American opportunity districts."
~ Rep. Greg Casar quoted by John Nicholls
#Texas #Republicans #gerrymandering #racism #SupremeCourt #JohnRoberts
/6
thenation.com/article/politicsā¦
A gerrymandering fight reveals how far Trump will go to avoid electoral accountability.The Nation
Billy Begala explains how the Republican gerrymandering proposal wants to "carve up Texas like a Christmas ham," disenfranchising Black and Hispanic voters and privileging rural white ones.
#Texas #Republicans #gerrymandering #racism
/7
contrarian.substack.com/p/repuā¦
At Trumpās command, the Texas GOPās redistricting maps strip voting power away from Black Texans and are an insult to us all ā regardless of partisan stripes.The Barbed Wire (The Contrarian)
Russia's Foreign Ministry spokesperson has announced that Moscow is prepared to increase collaboration with BRICS countries to combat the pressure of illegal US sanctions.Iran Press
āAnti-rascist zoneā
antifainternational.tumblr.comā¦
"radicalgraff:āAnti-rascist zoneāGraff piece in Toscana, Italy"
radicalgraff: āAnti-rascist zoneā Graff piece in Toscana, Italyantifainternational (Antifa International)
Gaza aid truck drivers face increasing danger from desperate crowds and armed gangs
https://apnews.com/article/israel-palestinians-hamas-aid-trucks-danger-34f60bfcd7c84d75e90847c70b76b302?utm_source=flipboard&utm_medium=activitypub
Posted into International News @international-news-AssociatedPress
Alex Ovechkin partners with a Russian technology company to make a movie about his career
https://apnews.com/article/alex-ovechkin-movie-aba4c56e0f5d3bfd99e32c1d07069971?utm_source=flipboard&utm_medium=activitypub
Posted into Entertainment @entertainment-AssociatedPress
Talk about powerful: Rachel Maddow last night on how "we're beyond waiting and seeing now":
"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. we are in a place we did not want to be, but we are there."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/1
youtube.com/watch?v=VQbDgOaOh4ā¦
Rachel Maddow points out that the thing most Americans were dreading has come to pass, and the United States has changed profoundly in only six months of aut...YouTube
"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. We are in a place we did not want to be, but we are there. The thing we were all warning about for the last few years is not coming. It is here. We are in it."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/2
"We do now live in a country that has an authoritarian leader in charge. We have a consolidating dictatorship in our country. and it sounds melodramatic to say it, i know, but just go with that for a minute, right? Think. Think in melodramatic terms. Think in cinematic terms. Imagine the cartoon level caricature of what you think a dictatorship looks like."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/3
Sensitive content
TEHRAN ā Protests condemning Israelās devastating war and deliberate starvation campaign in Gaza continue to sweep across the globe, as activists, politicians, and ordinary citizens demand an end to the violence and immediate humanitarian aid.Tehran Times
Trump is creating a task force for the 2028 Olympic Games in Los Angeles
https://apnews.com/article/trump-2028-summer-olympics-task-force-5751b5137a2576d2d6a26cb7bebd89e8?utm_source=flipboard&utm_medium=activitypub
Posted into Politics @politics-AssociatedPress
In 2019, the American Ayatollah (the Supreme Court) said that it was totally fine to gerrymander, as gerrymandered maps could not be reviewed by federal courts (Rucho v. Common Cause).
Now, with a slim majority, Texas Republicans are gerrymandering on racial lines to disempower voters because they cannot win elections on merits. As a result, Texas Democrats have fled the state, denying the governing body of quorum.
This is "American Democracy" failing spectacularly.
texastribune.org/2025/08/04/teā¦
Texas Republicans are trying to redraw congressional districts to pick up five additional U.S. House seats. Democrats face financial and political risk in their bid to block the GOP plan.MarĆa MĆ©ndez (The Texas Tribune)
14 Benefits of Castor Oil for Pain and Inflammation Relief
naturalremedyideas.com/castor-ā¦
What They Donāt Tell Us About Treating Pain
Exposing the pain industry and the forgotten treatments for pain
I have been unemployed for over a year, hustling here and there while trying to find something long term in the current hell that is the tech industry. My cat has kidney problems and I need help to cover vet bills amounting to around 500ā¬.
PayPal: paypal.me/BarbaraL649
Also open to hire making websites for fellow #SexWorkers
Go to paypal.me/BarbaraL649 and type in the amount. Since itās PayPal, it's easy and secure. Donāt have a PayPal account? No worries.PayPal.Me
US government proposes easing some restrictions on drones traveling long distances
https://apnews.com/article/drones-trump-duffy-line-of-sight-rule-bdbc54ca3b8ef2ead9ccfc62f3762f4c?utm_source=flipboard&utm_medium=activitypub
Posted into Business and Finance @business-and-finance-AssociatedPress
Trump administration wants to end abortion coverage through Veterans Affairs
https://apnews.com/article/veterans-affairs-abortion-trump-biden-dobbs-b9f7866a77928c9ebb078e4dbf173e38?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
DEAR FRIENDS. IF YOU LIKE THIS TYPE OF CONTENT, SUPPORT SOUTHFRONT WORK :Odysee
N. E. Felibata š½ reshared this.
Massive central California wildfire threatens more than 800 structures and leaves 3 injured
https://apnews.com/article/gifford-wildfires-california-santa-barbara-los-padres-cc1e1a2945594e836e133fad309448cb?utm_source=flipboard&utm_medium=activitypub
Posted into U.S. News @u-s-news-AssociatedPress
so apparently only 19% of americans are still #pureblood with zero covid jabs
that's a catastrophic stat.
Not sure. Some won't get the chance, others will cut a deal and sing like a canary.
Zach Clouseau
in reply to Miraculixxxen • • •Sensitive content
Adam Edam
in reply to Miraculixxxen • • •Sensitive content
Miraculixxxen
in reply to Adam Edam • • •Sensitive content
Thank you
My Other Account
in reply to Miraculixxxen • • •Sensitive content
jabu
in reply to Miraculixxxen • • •Sensitive content
Have fun!
Kinky_me
in reply to Miraculixxxen • • •Sensitive content
Miraculixxxen
in reply to Kinky_me • • •Sensitive content
Kinky_me
in reply to Miraculixxxen • • •Sensitive content
tamarisk
in reply to Miraculixxxen • • •Sensitive content