Sensitive content
Les bug bounty hunters nโont quโaฬ bien se tenir car Google va bientoฬt tenter de les remplacer (comme ils ont deฬjaฬ remplaceฬ pas mal de creฬateurs web) graฬce aฬ leur nouvelle IA baptiseฬe Big Sleep. En effet, celle-ci vient de prouver quโelle peut deฬtecter des failles de seฬcuriteฬ que meฬme les meilleurs hackers humains ont loupeฬes. Et je ne vous parle pas de petites vulneฬrabiliteฬs bidons, mais de veฬritables failles dans des logiciels critiques.
Vous vous souvenez quand je vous parlais de XBOW, cette IA qui eฬtait devenue numeฬro 1 sur HackerOne ? Eh bien Google vient de rentrer dans la danse avec Big Sleep, et visiblement ils ne sont pas venus pour rigoler. Lโapproche est diffeฬrente mais tout aussi impressionnante.
Big Sleep, cโest le fruit dโune collaboration entre Google Project Zero (lโeฬquipe dโeฬlite qui trouve des failles zero-day) et DeepMind (les geฬnies derrieฬre AlphaGo). Ensemble, ils ont creฬeฬ une IA capable dโanalyser du code source et de deฬtecter des vulneฬrabiliteฬs de manieฬre autonome. Le nom โBig Sleepโ vient dโailleurs du roman noir de Raymond Chandler (lien affilieฬ), un clin dโลil au coฬteฬ deฬtective de lโIA.
La premieฬre vraie victoire de Big Sleep, cโest donc dโavoir trouveฬ une vulneฬrabiliteฬ stack buffer underflow dans SQLite, la base de donneฬes la plus utiliseฬe au monde. Cette faille eฬtait passeฬe sous le radar de tous les outils de fuzzing traditionnels et des chercheurs humains. LโIA a reฬussi aฬ lโidentifier en analysant les patterns de code et en comprenant la logique profonde du programme.
Ce qui est vraiment fou avec Big Sleep, cโest sa capaciteฬ aฬ comprendre le contexte et la seฬmantique du code car contrairement aux outils de fuzzing classiques qui bombardent le programme avec des donneฬes aleฬatoires pour voir sโil crashe, Big Sleep lit et comprend reฬellement ce que fait le code.
Cโest la diffeฬrence entre un lecteur de Korben.info qui lit lโun de mes articles et qui est content. Et un lecteur de Korben.info (ou pas dโailleurs) qui lit lโun de mes articles en diagonale (ou juste le titreโฆlol), qui ne comprend rien et qui part ensuite mโinsulter sur les reฬseaux sociaux ^^.
Google explique que Big Sleep utilise une approche en plusieurs eฬtapes. Dโabord, lโIA analyse le code source pour comprendre sa structure et son fonctionnement. Ensuite, elle identifie les zones potentiellement vulneฬrables en se basant sur des patterns connus mais aussi sur sa compreฬhension du flux de donneฬes. Enfin, elle geฬneฬre des cas de test speฬcifiques pour confirmer lโexistence de la vulneฬrabiliteฬ.

Les 20 vulneฬrabiliteฬs deฬcouvertes touchent diffeฬrents types de logiciels, des bibliotheฬques systeฬme aux applications web. Google reste discret sur les deฬtails exacts pour des raisons eฬvidentes de seฬcuriteฬ, mais ils confirment que toutes les failles ont eฬteฬ corrigeฬes avant toute exploitation malveillante. Cโest le principe du responsible disclosure : on trouve, on preฬvient, on corrige, et seulement apreฬs on communique.
Ce qui diffeฬrencie Big Sleep de XBOW, cโest surtout lโapproche. Laฬ ouฬ XBOW excelle dans les bug bounties publics avec une approche plus agressive, Big Sleep semble plutoฬt orienteฬ vers lโanalyse en profondeur de code complexe. Les deux IA sont donc compleฬmentaires et montrent bien que lโavenir de la cyberseฬcuriteฬ passera par ces assistants intelligents.
Dโailleurs, Google ne compte pas garder Big Sleep pour lui et lโeฬquipe travaille sur une version open source qui permettra aฬ la communauteฬ de beฬneฬficier de cette technologie. Lโideฬe cโest de deฬmocratiser la recherche de vulneฬrabiliteฬs pour que meฬme les petites entreprises puissent seฬcuriser leur code.
Mais attention, tout nโest pas rose non plus car que se passera-t-il si des acteurs malveillants mettent la main sur ce genre dโIA ? La course aux armements entre attaquants et deฬfenseurs risque de fortement sโacceฬleฬrer drastiquement. Google assure avoir mis en place des garde-fous, mais on sait tous que dans le domaine de la seฬcuriteฬ, rien nโest jamais garanti aฬ 100%.
Selon Google, Big Sleep peut analyser en quelques heures ce qui prendrait des semaines aฬ une eฬquipe humaine et contrairement aฬ vous les vacanciers eฬternels, lโIA ne se fatigue pas, ne fait pas dโerreur dโinattention, et peut traiter des volumes de code monumentaux. Sur les 20 vulneฬrabiliteฬs trouveฬes, au moins 5 eฬtaient consideฬreฬes comme critiques avec un score CVSS supeฬrieur aฬ 8.
Pour voir les dernieฬres deฬcouvertes de BigSleep cโest par ici.
Lโobjectif pour Google aฬ terme cโest de creฬer une IA capable de comprendre non seulement le code, mais aussi lโintention derrieฬre le code, donc si vous eฬtes deฬveloppeur ou responsable seฬcuriteฬ, il est temps de prendre ce sujet au seฬrieux. Les IA comme Big Sleep et XBOW ne sont pas des gadgets, donc commencez aฬ reฬfleฬchir aฬ comment inteฬgrer ces outils dans vos processus de deฬveloppement et surtout, nโattendez pas que les attaquants sโen servent contre vous.
Source
posted by pod_feeder
The discoveries by an AI-based bug hunter are significant, as it shows these tools are starting to get real results, even if they still need a human.Lorenzo Franceschi-Bicchierai (TechCrunch)
N. E. Felibata ๐ฝ reshared this.
Studying the glowing patterns of Earthโs surface helps us understand human activity, respond to disasters, and witness a changing world.
Studying the glowing patterns of Earth039;s surface helps us understand human activity, respond to disasters, and witness a changing world.
Studying the glowing patterns of Earth's surface helps us understand human activity, respond to disasters, and witness a changing world.Earth Science Division Editorial Team (NASA Science)
whuffo likes this.
BRITAIN is โnot just complicit, but an active participantโ in Israelโs genocide in Gaza, activists said today during a protest by British Jews against attacks on Palestine.Morning Star
DEAR FRIENDS. IF YOU LIKE THIS TYPE OF CONTENT, SUPPORT SOUTHFRONT WORK: MONERO (XMR): 86yfEHs6pkoDEKCxc6MAnQX8cVHmzhYxMVrNuwKgNmqpWK8dDxjgGnK8PtUNJMA...Anonymous765 (South Front)
What to know about Legionnaires' disease, which has sickened dozens in New York City
https://apnews.com/article/legionnaires-disease-water-harlem-321a278807329f3843c8d37d40e09e51?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
Tennessee readies for execution of man with working implanted defibrillator
https://apnews.com/article/tennessee-execution-defibrillator-bd1c3d5fcc3dd78faf9fc3ba9a5c7aad?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
Copper torches, lanterns, bars, and chains have been added in today's #Minecraft snapshot 25w32a!
Check out all of the new features in our #MinecraftWiki article and help us document them:
minecraft.wiki/w/Java_Edition_โฆ
25w32a is the second snapshot for Java Edition 1.21.9,[unofficial name] released on August 5, 2025.[1]Minecraft Wiki
Emmanuel Florac likes this.
Emmanuel Florac reshared this.
N. E. Felibata ๐ฝ reshared this.
Sri Lanka's parliament votes to fire country's police chief over abuse of power
https://apnews.com/article/sri-lanka-parliament-police-chief-fired-d0cfd69ae1e16d4b0f56188352b6c45f?utm_source=flipboard&utm_medium=activitypub
Posted into Asia @asia-AssociatedPress
whuffo likes this.
jonathanturley.org/2025/08/05/โฆ
The comments of Ramirez have clearly struck a nerve on both sides. For my part, I am very proud of both my Irish-Sicilian background. My Sicilian grandparents came to this country at the turn of the century. They were deeply proud of their heritage but always insisted that their children identify as Americans first and foremost.
Democrat Rep. Delia Ramirez (D., Ill.) is locked into a fierce fight with the White House over controversial remarks at the second annual Panamerican Congress held in Mexico, including declaring, โโฆJONATHAN TURLEY
Lady Gaga leads 2025 MTV Video Music Awards nominations, followed by Bruno Mars and Kendrick Lamar
https://apnews.com/article/mtv-vmas-2025-nominees-bfc482686f37f7e5ebb4cd84067ee5ef?utm_source=flipboard&utm_medium=activitypub
Posted into Entertainment @entertainment-AssociatedPress
The Greatest Builder...and POTUS, ever!
theconservativetreehouse.com/bโฆ
President Trump was reviewing the symmetry of architecture as the plans for the White House ballroom are being finalized.Sundance (The Last Refuge)
Sirens have sounded in multiple Israeli city settlements after a missile was launched from Yemen.Al Mayadeen English (Yemeni missile fired at Israeli target; sirens sound in central cities)
Google has released security updates to address multiple security flaws in Android, including fixes for two Qualcomm bugs that were flagged as actively exploited in the wild. The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6), by the chipmaker back in June 2025. CVE-2025-21479
posted by pod_feeder
Google fixed 6 Android flaws, including 3 exploited Qualcomm bugs, raising spyware concerns. Users urged to update.The Hacker News
N. E. Felibata ๐ฝ reshared this.
GitHub Pull Requests Are Down
Link: github.com/github/site-policy/โฆ
Discussion: news.ycombinator.com/item?id=4โฆ
GitHub is introducing non-essential cookies on web pages that market our products to businesses. These cookies will provide analytics to improve the site experience and personalize content and ads ...GitHub
MLB contenders watch for fatigue as some starters experience an increased workload
https://apnews.com/article/mlb-innings-limits-ea7e63d6a461f050c7f21cdae9e57294?utm_source=flipboard&utm_medium=activitypub
Posted into Sports @sports-AssociatedPress
How Ghislaine Maxwell's dad wrecked science
youtube.com/watch?v=KcujgE7znwโฆ
A lot of people donโt know that Ghislaine Maxwellโs dad, Robert Maxwell, played a pivotal role in setting up the system for how science research gets publish...YouTube
Singapore - Saba: Gold prices fell on Sunday, affected by profit-taking after the sharp rise in the previous session following the release of weaker-than-expected US jobs data, which reinforced expectations of a Federal Reserve interest rate cut in โฆwww.saba.ye
Microsoft's AI-fueled 4 trillion valuation highlights the massive impact of the AI bubble on the US economy. AI investments are now acting as a private sector stimulus, contributing more to US economic growth than consumer spending. However, a clear and sustainable business model remains elusive. In many ways, the current AI boom mirrors the dynamics of the dot-com era.
bloodinthemachine.com/p/the-aiโฆ
#usa #economy #technology
Plus how American professors are fighting back against the AI onslaught, a backlash over AI models in Vogue, and more.Brian Merchant (Blood in the Machine)
@Sh4d0w_H34rt O think it's important to separate the tech from the capitalist industry using it. Meanwhile, an economic crash was already in the works even without AI. All the bubble did was postpone what was already inevitable.
It's also informative to see how this tech is being integrated into Chinese economy for contrast.
A friend just sent me this article about losing a spouse.
"You think you're prepared.
you go in with boxes and garbage bags. You tell yourself youโll be strong.
You think, โItโs just stuff.โ
But then you open a drawer.
And their handwriting is still on a notepad.
Their scent still clings to the sleeves of that sweater you begged them to throw out every winter.
Their shoes are still lined up by the door like they might be back any minute.
to be cont
No one tells you how heavy an empty coat can feel in your hands.
No one tells you that cleaning out a space can shatter you all over again.
Itโs not just cleaning.
Itโs letting go of little pieces you were never ready to lose.
Itโs closing a drawer for the last time and feeling like youโre betraying them.
Itโs packing up the life you shared, while your heart silently begs, please donโt make me.
Because deep down, youโre not just packing away their things โ
Columbia University's recent suspension and expulsion of more than 70 students for a Palestine demonstration is the latest sign the school's crackdown on activism is not simply about campus conduct, but appeasing political pressure from Washington.
mondoweiss.net/2025/08/as-coluโฆ
#Palestine #Israel #Gaza
@palestine @israel
Columbia Universityโs recent suspension and expulsion of more than 70 students for a Palestine demonstration is the latest sign the schoolโs crackdown on activism is not simply about campus conduct, but appeasing political pressure from Washington.Tamara Turki (Mondoweiss)
like this
Climate Change 2025
The water crisis in Iran: The dire situation of the Zayandeh-Rud River in Isfahan.
In the past, the river was the lifeline of the city and the entire region.
#AureFreePress #News #press #headline #GlobalWarming #climatechange #climatecrisis #Breaking #BreakingNews #Iran
What a sad man he is.
Mark Mansour notes that the overt, unabashed gerrymandering proposed by Texas Republicans is designed, by their own admission, to "enhance the political efficacyโ of GOP votes.
What this is really about is enhancing the political efficacy of WHITE RURAL voters. As Mansour says, it's "a chilling disenfranchisement of millions of votersโespecially Black, Latino, and Asian Americans."
#Texas #Republicans #gerrymandering #racism
/1
mmansour.substack.com/p/the-teโฆ
Trump and Abbott are involved in a conspiracy to cheat Texas voters-it has to be stoppedMark Mansour (Americaโs Fractured Politics)
โTrump knows he canโt win the upcoming mid-term elections, so he is trying to rig them. And the way he is trying to do it is to dismantle the Voting Rights Act of 1965 as we know it. He is trying, for example to try and dismantle Hispanic and African-American opportunity districts."
~ Rep. Greg Casar quoted by John Nicholls
#Texas #Republicans #gerrymandering #racism #SupremeCourt #JohnRoberts
/6
thenation.com/article/politicsโฆ
A gerrymandering fight reveals how far Trump will go to avoid electoral accountability.The Nation
Billy Begala explains how the Republican gerrymandering proposal wants to "carve up Texas like a Christmas ham," disenfranchising Black and Hispanic voters and privileging rural white ones.
#Texas #Republicans #gerrymandering #racism
/7
contrarian.substack.com/p/repuโฆ
At Trumpโs command, the Texas GOPโs redistricting maps strip voting power away from Black Texans and are an insult to us all โ regardless of partisan stripes.The Barbed Wire (The Contrarian)
Russia's Foreign Ministry spokesperson has announced that Moscow is prepared to increase collaboration with BRICS countries to combat the pressure of illegal US sanctions.Iran Press
โAnti-rascist zoneโ
antifainternational.tumblr.comโฆ
"radicalgraff:โAnti-rascist zoneโGraff piece in Toscana, Italy"
radicalgraff: โAnti-rascist zoneโ Graff piece in Toscana, Italyantifainternational (Antifa International)
Gaza aid truck drivers face increasing danger from desperate crowds and armed gangs
https://apnews.com/article/israel-palestinians-hamas-aid-trucks-danger-34f60bfcd7c84d75e90847c70b76b302?utm_source=flipboard&utm_medium=activitypub
Posted into International News @international-news-AssociatedPress
Alex Ovechkin partners with a Russian technology company to make a movie about his career
https://apnews.com/article/alex-ovechkin-movie-aba4c56e0f5d3bfd99e32c1d07069971?utm_source=flipboard&utm_medium=activitypub
Posted into Entertainment @entertainment-AssociatedPress
Talk about powerful: Rachel Maddow last night on how "we're beyond waiting and seeing now":
"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. we are in a place we did not want to be, but we are there."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/1
youtube.com/watch?v=VQbDgOaOh4โฆ
Rachel Maddow points out that the thing most Americans were dreading has come to pass, and the United States has changed profoundly in only six months of aut...YouTube
"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. We are in a place we did not want to be, but we are there. The thing we were all warning about for the last few years is not coming. It is here. We are in it."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/2
"We do now live in a country that has an authoritarian leader in charge. We have a consolidating dictatorship in our country. and it sounds melodramatic to say it, i know, but just go with that for a minute, right? Think. Think in melodramatic terms. Think in cinematic terms. Imagine the cartoon level caricature of what you think a dictatorship looks like."
#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/3
Sensitive content
TEHRAN โ Protests condemning Israelโs devastating war and deliberate starvation campaign in Gaza continue to sweep across the globe, as activists, politicians, and ordinary citizens demand an end to the violence and immediate humanitarian aid.Tehran Times
Trump is creating a task force for the 2028 Olympic Games in Los Angeles
https://apnews.com/article/trump-2028-summer-olympics-task-force-5751b5137a2576d2d6a26cb7bebd89e8?utm_source=flipboard&utm_medium=activitypub
Posted into Politics @politics-AssociatedPress
In 2019, the American Ayatollah (the Supreme Court) said that it was totally fine to gerrymander, as gerrymandered maps could not be reviewed by federal courts (Rucho v. Common Cause).
Now, with a slim majority, Texas Republicans are gerrymandering on racial lines to disempower voters because they cannot win elections on merits. As a result, Texas Democrats have fled the state, denying the governing body of quorum.
This is "American Democracy" failing spectacularly.
texastribune.org/2025/08/04/teโฆ
Texas Republicans are trying to redraw congressional districts to pick up five additional U.S. House seats. Democrats face financial and political risk in their bid to block the GOP plan.Marรญa Mรฉndez (The Texas Tribune)
14 Benefits of Castor Oil for Pain and Inflammation Relief
naturalremedyideas.com/castor-โฆ
What They Donโt Tell Us About Treating Pain
Exposing the pain industry and the forgotten treatments for pain
I have been unemployed for over a year, hustling here and there while trying to find something long term in the current hell that is the tech industry. My cat has kidney problems and I need help to cover vet bills amounting to around 500โฌ.
PayPal: paypal.me/BarbaraL649
Also open to hire making websites for fellow #SexWorkers
Go to paypal.me/BarbaraL649 and type in the amount. Since itโs PayPal, it's easy and secure. Donโt have a PayPal account? No worries.PayPal.Me
US government proposes easing some restrictions on drones traveling long distances
https://apnews.com/article/drones-trump-duffy-line-of-sight-rule-bdbc54ca3b8ef2ead9ccfc62f3762f4c?utm_source=flipboard&utm_medium=activitypub
Posted into Business and Finance @business-and-finance-AssociatedPress
Trump administration wants to end abortion coverage through Veterans Affairs
https://apnews.com/article/veterans-affairs-abortion-trump-biden-dobbs-b9f7866a77928c9ebb078e4dbf173e38?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-AssociatedPress
DEAR FRIENDS. IF YOU LIKE THIS TYPE OF CONTENT, SUPPORT SOUTHFRONT WORK :Odysee
N. E. Felibata ๐ฝ reshared this.
Massive central California wildfire threatens more than 800 structures and leaves 3 injured
https://apnews.com/article/gifford-wildfires-california-santa-barbara-los-padres-cc1e1a2945594e836e133fad309448cb?utm_source=flipboard&utm_medium=activitypub
Posted into U.S. News @u-s-news-AssociatedPress
so apparently only 19% of americans are still #pureblood with zero covid jabs
that's a catastrophic stat.
Not sure. Some won't get the chance, others will cut a deal and sing like a canary.
Zach Clouseau
in reply to Miraculixxxen • • •Sensitive content
Adam Edam
in reply to Miraculixxxen • • •Sensitive content
Miraculixxxen
in reply to Adam Edam • • •Sensitive content
Thank you
My Other Account
in reply to Miraculixxxen • • •Sensitive content
jabu
in reply to Miraculixxxen • • •Sensitive content
Have fun!
Kinky_me
in reply to Miraculixxxen • • •Sensitive content
Miraculixxxen
in reply to Kinky_me • • •Sensitive content
Kinky_me
in reply to Miraculixxxen • • •Sensitive content
tamarisk
in reply to Miraculixxxen • • •Sensitive content