jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
These are the voyag... uh, things I post about.
Admin email
jrollans@gmail.com
Admin account
@jrollans@jrollans.com

Search results for tag #opensource

[?]Self-Hosted Feed » 🤖 🌐
@selfhosted_bot@fd.mrmave.work

🖥️ alexpinel/Dot

Text-To-Speech, RAG, and LLMs. All local!

Integrates Text-To-Speech, RAG, and Large Language Models into a local environment for fully offline operation

⭐ Stars: 1908
📅 Last Update: Jun 05, 2026

github.com/alexpinel/Dot

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Pocket Casts adopts Liquid Glass design in latest podcast player app update

    Pocket Casts for iOS has picked up a fresh visual overhaul this week. The latest version brings Apple’s Liquid Glass design language to one of the most popular podcast apps on the platform.

    9to5mac.com/2026/06/10/pocket-

    [9to5Mac]

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Deals: AirPods Pro 3 hit best price ever at $179, MacBook Pro $300 off, Series 11 $130 off, more

      Today’s 9to5Toys Lunch Break is headlined by AirPods Pro 3 dropping even lower to the best price ever at $179 shipped (nearly 30% off) and all five AirPods Max 2 colors hitting the Amazon all-time low. We also have up t…

      9to5mac.com/2026/06/10/deals-a

      [9to5Mac]

        [?]EdTheDev [He/Him] » 🌐
        @EdTheDev@infosec.exchange

        Random thought of the day: Having a few open source projects I wrote for myself on a weekend or two means having an endless wishlist / backlog - with no one to blame but myself if things don't get better.

        In contrast, I've plenty of folks to thank - since I build on others great prior work!

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          A dedicated Apple Watch communication app is missing in watchOS 27

          While the Apple Watch is gaining a handful of helpful features with watchOS 27, it’s also losing one that some users might miss.

          9to5mac.com/2026/06/10/a-dedic

          [9to5Mac]

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            AT&T launches new $3 ‘Unlimited Day Pass’ plan for iPad cellular

            AT&T has announced a new ‘Unlimited Day Pass’ plan launching today that allows iPad users to activate cellular coverage on a convenient, per-need basis. Here are the details.

            9to5mac.com/2026/06/10/att-lau

            [9to5Mac]

              AodeRelay boosted

              [?]9to5Linux » 🌐
              @9to5linux@floss.social

              First Look at 4: A Beautiful and Modern Revamp of the Popular Open-Source Audio Editor 9to5linux.com/first-look-at-au

              A screenshot of Audacity 4 showing the main interface while editing several audio tracks.

              Alt...A screenshot of Audacity 4 showing the main interface while editing several audio tracks.

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Interview: Swift Student Challenge winners talk app inspiration, presenting to Tim Cook and John Ternus, more

                While at Apple Park this week for WWDC, I had the opportunity to sit down with two Swift Student Challenge Distinguished Winners to talk about their apps and what it’s like giving a surprise demo to Tim Cook and John Te…

                9to5mac.com/2026/06/10/intervi

                [9to5Mac]

                  AodeRelay boosted

                  [?]Doris » 🌐
                  @doris@friendica-deutschland.de

                  Android war für viele von uns immer mehr als nur ein Smartphone-System – es stand auch für Offenheit, Freiheit und die Möglichkeit, Apps unabhängig vom Google Play Store zu nutzen.

                  Genau deshalb möchte ich heute auf die Seite hinweisen:
                  keepandroidopen.org/de

                  Besonders Projekte wie F-Droid verdienen Unterstützung. Ich nutze F-Droid selbst schon länger und schätze die Möglichkeit, freie und quelloffene Android-Apps unabhängig von großen Konzernen zu beziehen.

                  Die geplanten Änderungen rund um die verpflichtende Entwickler-Registrierung könnten alternative App-Stores und unabhängige Entwickler massiv unter Druck setzen. Viele Organisationen aus dem Bereich Open Source, Datenschutz und digitale Freiheitsrechte warnen bereits davor.

                  Wer Android als offenes System erhalten möchte, sollte sich das Thema einmal genauer anschauen.

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Siri AI might display break reminders if conversations go on for too long

                    iOS 27 includes code references to break reminders that Siri may display after especially long conversations. Here are the details.

                    9to5mac.com/2026/06/09/siri-ai

                    [9to5Mac]

                      AodeRelay boosted

                      [?]Jürgen » 🌐
                      @elbosso@mastodon.social

                      Flat Notes und Navidrome neu im Docker-Zoo elbosso.codeberg.page/flat_not

                      Ein weiteres Self-Hosting-Experiment hat zu zwei neuen
                      Diensten in meinem
                      Docker-Zoo
                      geführt...

                        [?]parthivsaikia » 🌐
                        @parthivsaikia@mastodon.social

                        I live in the terminal. lazygit, yazi, neovim — if it's a nice TUI I'm probably ricing it.

                        I care about privacy, local-first tools, and interfaces that don't get in the way.

                        Currently building enmasec — a password manager where even the metadata is encrypted. No cloud, no telemetry. An open vault shows you nothing but UUIDs.

                        Building in public. More updates soon.

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          macOS 27 Golden Gate adds higher resolution support for ultrawide displays

                          One addition to macOS 27 Golden Gate that went unmentioned during yesterday’s WWDC keynote was the fact that the system has improved its ultrawide display support. Here are the details.

                          9to5mac.com/2026/06/09/macos-2

                          [9to5Mac]

                            AodeRelay boosted

                            [?]Gonzo » 🌐
                            @Gono8814@mastodon.social

                            AodeRelay boosted

                            [?]dadamsda » 🌐
                            @dadamsda@mstdn.social

                            Schulbildung macht mündig, Open-Source-Software ebenfalls

                            "„Ich finde Open-Source wichtig, weil man damit eine Art Unabhängigkeit hat“, sagt eine Schülerin, „Die Software, die wir verwenden, ist frei, oft kostenlos und ohne Werbung – das passt wie die Faust aufs Auge für eine Schule.“"

                            netzpolitik.org/2026/vorreiter

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Record AirPods Price Drops and a Rare Switch 2 Sale: This Week's Top Tech Deals

                            Multiple AirPods models hit record low prices this week, including the AirPods Pro 3 and AirPods Max 2. We're tracking these great discounts alongside an ultra rare discount on a new Switch 2 on Woot, plus a Summer sale…

                            macrumors.com/2026/06/13/best-

                            [MacRumors]

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Save $500 on this beastly gaming rig with an RTX 5060 Ti 16GB, Ryzen 7800X3D, and 32GB of RAM — Skytech's…

                              Looking for a solid gaming PC but tired of seeing exorbitant prices on every retailer's website? We've got you covered with this prebuilt, equipped with high-quality components ready for 1440p gaming and more, with a cl…

                              tomshardware.com/desktops/gami

                              [Tom's Hardware]

                                [?]Franck Nijhof » 🌐
                                @frenck@fosstodon.org

                                I’ve been working on something new!

                                Presenting YAMLRocks 🪨

                                A fast, correct YAML library for Python, written in Rust.

                                It fills a gap I kept running into: YAML 1.2 (and 1.1) correctness, safe defaults, includes, source locations, and round-trip editing that keeps comments and formatting intact. It is about 5 to 10x faster than PyYAML’s C loader! 🚀

                                Still early, pre-1.0 software, but already pretty useful.


                                yaml.rocks/

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  More than 75 data center build-outs worth $130 billion have been successfully blocked in the first four m…

                                  A research firm says the number of blocked data centers in the first quarter of 2026 already matches the number of projects stopped in 2025. The opposition also comes from both sides of the aisle, despite President Trum…

                                  tomshardware.com/tech-industry

                                  [Tom's Hardware]

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Netgear countersues TP-Link, saying firm 'remains, at its core, a Chinese company selling Chinese-made products' — alleges its 'American company' rebrand is false advertisi…

                                    Netgear filed counterclaims against TP-Link in federal court in Delaware on June 11, accusing its larger rival of false advertising under the Lanham Act.

                                    tomshardware.com/networking/ro

                                    [Tom's Hardware]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Nvidia raises RTX Pro 6000 Blackwell GPU pricing to $13,250 — 55% increase over MSRP in a year's time

                                      Nvidia now sells the RTX Pro 6000 Blackwell graphics cards for $13,250, while partner offerings start at $11,359.99.

                                      tomshardware.com/pc-components

                                      [Tom's Hardware]

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        My first 24 hours with Siri AI on the Mac

                                        I turned off Siri on the Mac years ago and never looked back. Similarly, I found Apple Intelligence so fruitless I never engage with it. But the new Siri AI coming to macOS 27 Golden Gate has at least got me slightly re…

                                        theverge.com/tech/949502/apple

                                        [The Verge]

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Amazon’s Fire TV Stick 4K Select drops to $17.99 in Prime Day runup

                                          The budget 4K stick is 55% off as Amazon ramps up its early deals ahead of the main event.

                                          androidauthority.com/fire-tv-s

                                          [Android Authority]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Ukraine used ten AI-controlled ‘Terminator’ drones to kill Russian soldiers two years ago, marking first autonomous killings o…

                                            A watershed moment occurred on the battlefields of Ukraine in 2024 when 10 fully autonomous AI-controlled quadcopter drones were sent to the front lines against Russia with ‘Terminator Mode’ engaged.

                                            tomshardware.com/tech-industry

                                            [Tom's Hardware]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              My yard is dying, so I made an app for that

                                              When I returned to my computer five minutes after giving Gemini a lengthy prompt, I had two things: a functional app in a preview window, and a message about a bug. "~ Channel is unrecoverably broken and will be dispose…

                                              theverge.com/ai-artificial-int

                                              [The Verge]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Anthropic cuts off Fable 5 and Mythos 5 access following government order

                                                On Friday evening, the government ordered Anthropic to block access to Fable 5 and Mythos 5 for all foreign nations, both inside and outside the US, due to national security concerns. That order included employees of An…

                                                theverge.com/ai-artificial-int

                                                [The Verge]

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Echo Isle is a pint-sized adventure inspired by classic Zelda

                                                  Echo Isle is heavily inspired by The Legend of Zelda, and it's not afraid to show it: The retro graphics bear a striking resemblance to Link's Awakening, the main character wears a blue tunic and wields a sword, and he …

                                                  theverge.com/games/947136/echo

                                                  [The Verge]

                                                    [?]NovaFuture » 🌐
                                                    @novafuture@mastodon.social

                                                    Like clockwork, the same kind of article comes back. "The best Linux for beginners." "The top 5 easy distros." Always recycled clickbait from sites that never booted half the distros they list. So which Linux should you actually start with?

                                                    novafuture.org/open-source/whi

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Apple’s new AI photo editing tools mostly work, for better and worse

                                                      iPhone owners are getting real, native AI photo editing for the first time. The most popular camera in the world just got its first set of serious AI photo editing features, and I don't think any of us are ready. As far…

                                                      theverge.com/tech/949360/apple

                                                      [The Verge]

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        A better way to manage all your screenshots

                                                        Hi, friends! Welcome to Installer No. 132, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, happy soccer, and also you can read all the old editions at the Installer homepage.) Thi…

                                                        theverge.com/tech/949465/pool-

                                                        [The Verge]

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          I always keep 3 devices connected to a power station - here's why

                                                          Using a portable power station to its full potential is ideal for getting your money's worth and enjoying uninterrupted power.

                                                          zdnet.com/article/3-things-i-k

                                                          [ZDNet]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            The Anker SOLIX S2000 power station is an essential home backup beast

                                                            It can outlast any outage I have encountered.

                                                            androidauthority.com/anker-sol

                                                            [Android Authority]

                                                              [?]Jigell » 🌐
                                                              @Jigell@masto.nu

                                                              📚 New Resource Available

                                                              If you're building applications that integrate with Mastodon, understanding authentication, media uploads, server differences, and API rate limits is essential.

                                                              Our latest guide walks through the entire integration process with practical examples and recommendations based on real-world implementation experience.

                                                              Read it here:
                                                              example.com/developer/mastodon

                                                                AodeRelay boosted

                                                                [?]Graham Perrin » 🌐
                                                                @grahamperrin@mastodon.bsd.cafe

                                                                Did anyone attend OSFS last month?

                                                                05f5.com/ – Open Source Founders Summit

                                                                ― The conference about building financially successful and sustainable open source companies.

                                                                  AodeRelay boosted

                                                                  [?]Graham Perrin » 🌐
                                                                  @grahamperrin@mastodon.bsd.cafe

                                                                  Yugabyte bets on open-source memory infrastructure for AI agents

                                                                  <forkable.io/p/yugabyte-bets-on> (Paul Sawers, 2026-05-12)

                                                                  "… I check in with Karthik Ranganathan, CEO and co-founder of Yugabyte, an open-source database company now pushing into AI infrastructure with the launch of Meko, a new “memory layer” for AI agents.

                                                                  Meko reflects how infrastructure companies are reassessing their role in the agentic AI stack. As agents take on longer-running tasks across multiple systems, the problems companies keep hitting — shared context and coordination — are ones distributed systems engineers would recognise immediately.

                                                                  "Agents are working from inconsistent views of what's true right now," Ranganathan told me. "This is because there is no way to enforce a shared truth." …"

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    The best VPN routers of 2026: Expert tested and reviewed

                                                                    Our guide lists the top routers on the market that provide VPN coverage throughout your entire home. We've ranked them based on speed, security, and reliability.

                                                                    zdnet.com/article/best-vpn-rou

                                                                    [ZDNet]

                                                                      [?]Open Rights Group » 🌐
                                                                      @openrightsgroup@social.openrightsgroup.org

                                                                      The UK's digital infrastructure is a strategic asset.

                                                                      But being dependent on US tech firms is a critical weakness.

                                                                      Our systems can be hit with sanctions, our economy is damaged and our tech policy curbed.

                                                                      Tell your MP we need Digital Sovereignty by 16 June ➡️ action.openrightsgroup.org/tel

                                                                      What are the risks of digital dependency?

National security – The US has tech powers of sanction which can be used to stop a US company from supplying services.

Economic – The UK government exposes itself to vendor lock-in when contracting for proprietary software, resulting in inflated costs and the extraction of value from the UK economy.

Tech policy capture – Big Tech has used its outsized power and resources to control markets, limit innovation, curb regulation and lobby Government.

                                                                      Alt...What are the risks of digital dependency? National security – The US has tech powers of sanction which can be used to stop a US company from supplying services. Economic – The UK government exposes itself to vendor lock-in when contracting for proprietary software, resulting in inflated costs and the extraction of value from the UK economy. Tech policy capture – Big Tech has used its outsized power and resources to control markets, limit innovation, curb regulation and lobby Government.

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        As a longtime Android privacy nerd, here are 6 privacy apps I actually regret installing

                                                                        Most of these apps aren't necessarily bad, they just didn't fit in with what I was looking for.

                                                                        androidauthority.com/android-p

                                                                        [Android Authority]

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          I usually avoid on-ear headphones, but Marshall has me seriously reconsidering

                                                                          Marshall revamped its midrange headphones with stellar comfort, repairability, and a marathon battery life.

                                                                          zdnet.com/article/marshall-mil

                                                                          [ZDNet]

                                                                            AodeRelay boosted

                                                                            [?]DerReparierer » 🌐
                                                                            @DerReparierer@social.tchncs.de

                                                                            Es wird wieder fleißig in vielen Reparaturcafés repariert und es gibt auch einige Termine für den Umstieg auf Linux! Schaut gerne mal, wann bei euch die nächsten Termine sind.

                                                                            Ein Reparaturcafé ist eine gute Anlaufstelle um unabhängig Expertise zu euren defekten Geräten zu bekommen.

                                                                            Heute, morgen und die nächste Woche in
                                                                            ... und viele mehr

                                                                            Termine
                                                                            reparatur-initiativen.de/termi


                                                                            repaircafes.at/


                                                                            repair-cafe.ch/reparieren/

                                                                            Auf umsteigen
                                                                            endof10.org/de/places/

                                                                            Digitale Unabhängigkeit: am 5. Juli
                                                                            di.day/de

                                                                            Termine nächster Reparatur Cafés und deren Orte.

                                                                            Alt...Termine nächster Reparatur Cafés und deren Orte.

                                                                            AodeRelay boosted

                                                                            [?]LUG Offenbach » 🌐
                                                                            @lug_offenbach@hessen.social

                                                                            So, nachem ich anfangs mit meinem privaten Mastodon Konto Werbung für unsere Gruppe gemacht habe gibt es nun auch das offizielle Linux User-Group Offenbach Mastodon Konto.

                                                                            Also nochmal für alle die aus Offenbach oder dem Umkreis kommen - seit 12.04.2026 gibt es nun eine Linux User-Group direkt in Offenbach.

                                                                            Auf dem Flyer stehen Infos zur Linux User-Group Offenbach.

                                                                            Alt...Auf dem Flyer stehen Infos zur Linux User-Group Offenbach.

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Phone battery draining fast? Malware is one of 8 possible factors - how to tell for sure

                                                                              No battery lasts forever. But it's often in your power to extend its life. Here's our checklist for identifying the causes of battery degradation - and how to fix each one.

                                                                              zdnet.com/article/phone-batter

                                                                              [ZDNet]

                                                                                AodeRelay boosted

                                                                                [?]heinelo » 🌐
                                                                                @heinelo@pixelfed.social

                                                                                Es gibt seit ein paar tagen eine freie alternative zu linkedin und xing sollte es jemand noch nicht mit bekommen haben
                                                                                #bizzfed #linux #opensource #nobigtech
                                                                                https://www.bizzfed.de/feed

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  We’ve cut Google enough slack for poor Pixel updates. Now it’s time to hold it accountable

                                                                                  Pixel updates have been a mess, and it needs to stop!

                                                                                  androidauthority.com/google-po

                                                                                  [Android Authority]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    macOS 27 Golden Gate includes these changes that Tahoe critics will appreciate

                                                                                    macOS 26 Tahoe made some polarizing design choices that evoked strong responses from critics. While the new design in macOS 27 Golden Gate is still all about Liquid Glass, Apple’s new Mac operating system corrects a lot…

                                                                                    9to5mac.com/2026/06/09/macos-2

                                                                                    [9to5Mac]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      Apple TV just dropped trailers for two upcoming returning shows

                                                                                      Apple TV kicked off its best summer lineup ever last week with thriller series Cape Fear, and today the streamer released trailers for two returning shows coming soon.

                                                                                      9to5mac.com/2026/06/09/apple-t

                                                                                      [9to5Mac]

                                                                                        [?]VSX.is | Digital sovereignty » 🌐
                                                                                        @vsx@infosec.exchange

                                                                                        Volla Community Days 2026: Europe’s Bet on Independence from Big Tech

                                                                                        While most of the world operates within the Google and Apple ecosystems, a small group of European companies is building an alternative. This year’s…

                                                                                        vsx.global/volla-community-day

                                                                                          [?]sanjay91flip » 🌐
                                                                                          @sanjay91flip@flipboard.social

                                                                                          Technology moves fast, but continuous learning remains the most valuable skill. Stay curious, keep building, and share what you learn along the way.

                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                            @techwire@social.gamefan.net

                                                                                            iOS 27 adds unique new setting to personalize your iPhone’s Lock Screen

                                                                                            iOS 27 adds a brand new Siri, new features in CarPlay and Apple Wallet, and more—including a unique clock setting to personalize your iPhone’s Lock Screen even more.

                                                                                            9to5mac.com/2026/06/09/ios-27-

                                                                                            [9to5Mac]

                                                                                              [?]Ced Chat » 🌐
                                                                                              @cedcha73@mastodon.world

                                                                                              Guerre de l'open source et polémiques, tout ce qu'il faut savoir sur le lancement d'Euro Office par NextCloud

                                                                                              zdnet.fr/actualites/euro-offic

                                                                                              Je trouve ça triste que les équipes des projets open source en viennent se comporter comme les sociétés qui représentent le monde du propriétaire. Mais il est vrai que les parts de marché sont difficiles à acquérir et à conserver pour l’open.

                                                                                              #

                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                @techwire@social.gamefan.net

                                                                                                Top watchOS 27 features that will enhance your Apple Watch

                                                                                                While watchOS 27 didn’t get much stage time during WWDC 2026, the next Apple Watch software update still packs some great new features. Here’s everything new coming to Apple Watch this fall so far.

                                                                                                9to5mac.com/2026/06/09/top-wat

                                                                                                [9to5Mac]

                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                  @techwire@social.gamefan.net

                                                                                                  Nomad debuts limited edition Stand One in color-matching Stellar Orange

                                                                                                  The Cosmic Orange iPhone 17 Pro has been my favorite color variation in years. I love how the color just pops. I even recently wrote about my Cosmic Orange-themed everyday carry. The Cosmic Orange color-matching continu…

                                                                                                  9to5mac.com/2026/06/09/nomad-d

                                                                                                  [9to5Mac]

                                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                                    @techwire@social.gamefan.net

                                                                                                    How to See Which Mac Apps Will Stop Working After macOS Golden Gate

                                                                                                    Apple is phasing out support for Rosetta 2, which is a feature that allows Intel-based apps to run on Apple silicon Macs. Rosetta is going to stop working for most apps in macOS 28, and when that happens, apps that use …

                                                                                                    macrumors.com/2026/06/12/macos

                                                                                                    [MacRumors]

                                                                                                      AodeRelay boosted

                                                                                                      [?]iX Magazin » 🌐
                                                                                                      @iX_Magazin@social.heise.de

                                                                                                      Drei freie Office-Suiten gegen Microsoft 365 – und ihre Technik im Vergleich

                                                                                                      Drei freie Office-Suiten fürs Web, drei völlig verschiedene Architekturen. Was Euro-Office, Collabora Online und die LibreOffice-Pläne technisch unterscheidet.

                                                                                                      heise.de/hintergrund/Drei-frei

                                                                                                      [?]heise online English » 🤖 🌐
                                                                                                      @heiseonlineenglish@social.heise.de

                                                                                                      Three free office suites vs. Microsoft 365 – technology comparison

                                                                                                      Three free web office suites, three architectures. What Euro-Office, Collabora Online, and LibreOffice plans differentiate technically.

                                                                                                      heise.de/en/background/Three-f

                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                      @techwire@social.gamefan.net

                                                                                                      Notion Is Migrating to SwiftUI, Apple Confirms at WWDC

                                                                                                      Apple this week confirmed that Notion is migrating its user interface to SwiftUI, citing the app's desire for greater performance and UI consistency than its existing web-based stack can deliver. Notion is a productivit…

                                                                                                      macrumors.com/2026/06/12/notio

                                                                                                      [MacRumors]

                                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                                        @techwire@social.gamefan.net

                                                                                                        Apple to Release These 15 New Products Later This Year

                                                                                                        Apple's annual WWDC developers conference is drawing to a close, but there is still a lot to look forward to in the second half of the year. Apple is expected to release at least 15 more products later this year. Now th…

                                                                                                        macrumors.com/2026/06/12/15-ne

                                                                                                        [MacRumors]

                                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                                          @techwire@social.gamefan.net

                                                                                                          Record AirPods Price Drops and a Rare Switch 2 Sale: This Week's Top Tech Deals

                                                                                                          Multiple AirPods models hit record low prices this week, including the AirPods Pro 3 and AirPods Max 2. We're tracking these great discounts alongside an ultra rare discount on a new Switch 2 on Woot, plus a Summer sale…

                                                                                                          macrumors.com/2026/06/12/best-

                                                                                                          [MacRumors]

                                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                                            @techwire@social.gamefan.net

                                                                                                            iOS 27 Adds Landscape Mode to More Apple Apps Ahead of 'iPhone Ultra'

                                                                                                            iOS 27 enables landscape mode in more of Apple's built-in iPhone apps, including Apple Music, Podcasts, Fitness, Health, Reminders, Home, Shortcuts, Apple Watch, Find My, Weather, Voice Memos, Apple TV Remote, and other…

                                                                                                            macrumors.com/2026/06/12/ios-2

                                                                                                            [MacRumors]

                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                              @techwire@social.gamefan.net

                                                                                                              Apple Cut Frequencies in WWDC Keynote to Prevent Siri Activations

                                                                                                              Apple appears to have modified the audio of this week's WWDC 2026 keynote video whenever "Siri" was mentioned, apparently in an effort to prevent viewers' nearby devices from waking inadvertently during the presentation…

                                                                                                              macrumors.com/2026/06/12/apple

                                                                                                              [MacRumors]

                                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                                @techwire@social.gamefan.net

                                                                                                                watchOS 27 Improves Apple Watch Performance in Seven Ways

                                                                                                                Apple's software updates previewed during WWDC 2026 this week have followed a distinct pattern: introduce a handful of key new features, while maintaining a focus on refining the underlying platform architecture. watchO…

                                                                                                                macrumors.com/2026/06/12/watch

                                                                                                                [MacRumors]

                                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                                  @techwire@social.gamefan.net

                                                                                                                  iOS 27: All the New Health and Fitness Features

                                                                                                                  Apple was rumored to be working on an AI health service, but it was scrapped well before the iOS 27 beta came out. It could resurface in the future, but for now, there are a handful of health and fitness changes in the …

                                                                                                                  macrumors.com/guide/ios-27-hea

                                                                                                                  [MacRumors]

                                                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                                                    @techwire@social.gamefan.net

                                                                                                                    Apple's Craig Federighi: Siri Won't Be Your AI Girlfriend

                                                                                                                    Apple software engineering chief Craig Federighi and marketing chief Greg Joswiak sat down for an interview with Mostly Human after during WWDC, discussing the iOS 27 Siri changes, Apple's take on AI, new child safety p…

                                                                                                                    macrumors.com/2026/06/11/apple

                                                                                                                    [MacRumors]

                                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                                      @techwire@social.gamefan.net

                                                                                                                      Valve just imported 13 tons of VR headsets in one day

                                                                                                                      On June 10th, the German container ship Posen docked in Los Angeles after a two-week voyage from Shanghai. As Valve watcher Brad Lynch notes, it was almost certainly carrying the first mass production shipments of the S…

                                                                                                                      theverge.com/news/949517/valve

                                                                                                                      [The Verge]

                                                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                                                        @techwire@social.gamefan.net

                                                                                                                        What's New in the iOS 27 Photos App

                                                                                                                        The Photos app is one of a handful of apps that Apple paid extra attention to in iOS 27. It has multiple improvements to performance, and several quality-of-life upgrades. There are also new AI photo editing tools that …

                                                                                                                        macrumors.com/guide/ios-27-pho

                                                                                                                        [MacRumors]

                                                                                                                          [?]Seth Larson » 🌐
                                                                                                                          @sethmlarson@mastodon.social

                                                                                                                          Every code generation LLM model available will at some point suggest insecure code as a part of “code completion”. Should this behavior be considered a vulnerability?

                                                                                                                          sethmlarson.dev/are-insecure-c

                                                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                                                            @techwire@social.gamefan.net

                                                                                                                            Nvidia preps to sell its Vera CPUs into China as its GPU sales stay frozen — customers encouraged to place orders for CPU shipments as early as August

                                                                                                                            Nvidia has told Chinese clients that its Arm-based Vera server CPUs could be available as soon as August.

                                                                                                                            tomshardware.com/pc-components

                                                                                                                            [Tom's Hardware]

                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                              @techwire@social.gamefan.net

                                                                                                                              [?]Edward [He/Him] » 🌐
                                                                                                                              @edthedev@mastodon.art

                                                                                                                              A quick opensource update - "minion" - my command line
                                                                                                                              journal software - now supports MacOS.

                                                                                                                              Thanks to a fix from the first contributor to the rebooted version on CodeBerg! Thank you!

                                                                                                                              codeberg.org/edthedev/minion

                                                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                @techwire@social.gamefan.net

                                                                                                                                Watching sports at home? I'd change these 4 soundbar settings for the most optimal audio

                                                                                                                                Some of your favorite soundbar settings for music and movies aren't compatible with live sports broadcasts.

                                                                                                                                zdnet.com/article/soundbar-set

                                                                                                                                [ZDNet]

                                                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                  @techwire@social.gamefan.net

                                                                                                                                  Radeon RX 9070 XT finally appears in Steam Hardware Survey — RDNA 4 flagship surprisingly lands just behind RTX 5080

                                                                                                                                  AMD’s Radeon RX 9070 XT graphics card has finally penetrated the Steam Survey video card results table, going straight in at position 25.

                                                                                                                                  tomshardware.com/pc-components

                                                                                                                                  [Tom's Hardware]

                                                                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                    @techwire@social.gamefan.net

                                                                                                                                    Nvidia's high-speed AI data center storage servers break cover, touting 2.9 petabytes of storage and extreme PCIe 6.0 performance — Wiwynn shows off SC…

                                                                                                                                    Wiwynn is among the first to demonstrate Nvidia SCADA server that promises to offer AI systems petabytes of ultra-fast storage thanks to GPU-accelerated storage acceleration.

                                                                                                                                    tomshardware.com/pc-components

                                                                                                                                    [Tom's Hardware]

                                                                                                                                      [?]Owl Eyes » 🌐
                                                                                                                                      @d1@autistics.life

                                                                                                                                      @autistics
                                                                                                                                      Announcement: multiplayer casual game tomorrow (Sat) for 4 hours in the late afternoon to evening (North America). That's in about 24 hours from now.

                                                                                                                                      Voxelibre is a free and clone. More details here: docs.autis.toque.im/

                                                                                                                                      Damage has been turned off. People with , or are invited.

                                                                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                        @techwire@social.gamefan.net

                                                                                                                                        Republican lawmakers urge federal agency to block imports of infringing TSMC chips as patent ruling nears — five asserted U.S. patents come from United Microelectronics Corporation

                                                                                                                                        Four Republican members of Congress have urged the U.S. ITC to block imports of foreign-made chips found to infringe U.S. patents

                                                                                                                                        tomshardware.com/tech-industry

                                                                                                                                        [Tom's Hardware]

                                                                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                          @techwire@social.gamefan.net

                                                                                                                                          Save $300 on Gigabyte's Gaming A16 gaming laptop at Walmart — Budget RTX 5060 -powered 16-inch laptop is now only $1,199

                                                                                                                                          Save $300 on Gigabyte's Gaming A16 gaming laptop at Walmart. Budget RTX 5060 -powered 16-inch laptop is now only $1,199.

                                                                                                                                          tomshardware.com/laptops/gamin

                                                                                                                                          [Tom's Hardware]

                                                                                                                                            [?]Nils » 🌐
                                                                                                                                            @ravage@layer8.space

                                                                                                                                            Running my own BizzFed instance - a federated, algorithm-free alternative to LinkedIn built on ActivityPub.

                                                                                                                                            🔧 What I added to my fork:

                                                                                                                                            SMTP relay (no Resend dependency)
                                                                                                                                            Account migration wizard (Move activity)
                                                                                                                                            Fixed language switcher (de/en/fr/es)
                                                                                                                                            Fully translated feed UI
                                                                                                                                            Instance: bizzfed.haxxors.com
                                                                                                                                            Code: git.buechner.me/nbuechner/bizz

                                                                                                                                            Thanks to René Hamdorf for the solid original BizzFed foundation!

                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                              Save a massive $751 on this RTX 5070 Ti gaming PC with a 9800X3D right now — liquid-cooled, 4K-ready Skytech rig with 32GB DDR5 and a 2TB SSD is now just $2,249

                                                                                                                                              Save $750 on this Skytech gaming PC for gaming at 1440p and 4K, featuring a 9800X3D, RTX 5070 Ti, 32GB DDR5, and a 2 TB SSD.

                                                                                                                                              tomshardware.com/desktops/gami

                                                                                                                                              [Tom's Hardware]

                                                                                                                                                [?]Alex Hoyau » 🌐
                                                                                                                                                @lexoyo@framapiaf.org

                                                                                                                                                Started a big one for @silex today

                                                                                                                                                ▶️ leaving GitHub for code hosting and CI/CD

                                                                                                                                                First step: flattening our meta-repo architecture (git submodules) into a single monorepo, so we migrate one repo to Codeberg or @ow2 's gitlab

                                                                                                                                                This work is funded by @nlnet 🇪🇺 and built in public: I'll toot the journey, the good and the ugly

                                                                                                                                                If you are a Silex user, is it clear to you why GitHub is a problem for libre software?

                                                                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                  @techwire@social.gamefan.net

                                                                                                                                                  Several police officers arrested for using controversial Flock AI license plate reader system to stalk romantic partners, says report — investig…

                                                                                                                                                  Tens of officers have been fired, and some even arrested, for abuse of the Flock license plate reader system used by police departments throughout the US, according to a new report.

                                                                                                                                                  tomshardware.com/software/secu

                                                                                                                                                  [Tom's Hardware]

                                                                                                                                                    [?]heise online English » 🤖 🌐
                                                                                                                                                    @heiseonlineenglish@social.heise.de

                                                                                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                    @techwire@social.gamefan.net

                                                                                                                                                    Are Facebook and Instagram down? What to know about the Meta outage

                                                                                                                                                    Even Messenger and WhatsApp appear to be impacted on Friday morning.

                                                                                                                                                    zdnet.com/article/is-facebook-

                                                                                                                                                    [ZDNet]

                                                                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                      @techwire@social.gamefan.net

                                                                                                                                                      This single router antenna adjustment improved my internet speed more than I expected

                                                                                                                                                      Getting the best Wi-Fi performance requires strategic antenna positioning, proper router placement, and a bit of trial and error. Here's my advice.

                                                                                                                                                      zdnet.com/article/adjusting-ro

                                                                                                                                                      [ZDNet]

                                                                                                                                                        [?]Rolle Laukkarinen » 🌐
                                                                                                                                                        @rolle@mementomori.social

                                                                                                                                                        I've received some questions about my algorithm experiments. First off, I'm building this mainly for myself, since I often don't have time to scroll through posts chronologically and just want the best and most important bits from my social media. It's opt-in and currently only an experiment in my fork.

                                                                                                                                                        How the "For you" ranked feed on mementomori.social actually works:

                                                                                                                                                        First, the ground rules. Again, "For you" is opt-in on our instance. If you never touch the toggle, your home feed stays exactly as it is: chronological, complete, and untouched. Nothing below applies to you. We never turn it on without your consent, and every setting is stored and controlled by you.

                                                                                                                                                        Where the posts come from. The feed ranks the newest ~800 posts and boosts from people you follow. If you also enable "Include posts from people you don't follow," trending posts on the instance get mixed in, roughly one in every four slots, and your scrolling can continue through the trending pool once your own feed runs out.

                                                                                                                                                        How a post is scored. Every post receives one score made of four parts multiplied together:

                                                                                                                                                        1. Engagement: boosts count 3x, replies 2x, favourites 1x.

                                                                                                                                                        For posts from other instances, we use counts from their home instance so federation doesn't undercount them.

                                                                                                                                                        2. Your affinity to the author: how often you've favourited, boosted, or replied to that person in the last 30 days.

                                                                                                                                                        It's logarithmic, the 5th interaction matters much more than the 50th, so no one can dominate your feed just because you liked them a lot once.

                                                                                                                                                        3. Time decay: a post loses half its score every 6 hours. Old posts fade no matter how popular they are.

                                                                                                                                                        4. A touch of randomness (±10%) so the order isn't fixed.

                                                                                                                                                        Freshness. Every post shown to you goes to the back of the line for 2 days. That's why refreshing gives you new posts instead of showing the same viral hit again and again, and why "Load more" always digs deeper instead of repeating.

                                                                                                                                                        Housekeeping rules: boosts show the original post. Your own posts and boosts never appear. Private mentions never appear. Brand-new posts wait 15 minutes before entering so they have a bit of time to gather reactions first.

                                                                                                                                                        What it does NOT do: There's no tracking beyond one thing: a list of post IDs already shown to you, which auto-deletes after 2 days. No reading your posts, no content analysis, no machine learning, and no profile built about you.

                                                                                                                                                        The weights above are the entire model, and your instance admin can adjust every number. Hopefully, if this project matures, you'll be able to adjust every weight yourself.

                                                                                                                                                        Code for the curious:
                                                                                                                                                        github.com/mementomori-social/

                                                                                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                          @techwire@social.gamefan.net

                                                                                                                                                          Siri is good now??

                                                                                                                                                          You'd be forgiven for thinking this day would never come. Siri has spent a decade and half somewhere between "sort of useful at a few things" and "utterly disastrous, why did I even try, can it honestly not even set a t…

                                                                                                                                                          theverge.com/podcast/949079/si

                                                                                                                                                          [The Verge]

                                                                                                                                                            [?]Kyle Reddoch (CybersecKyle) » 🌐
                                                                                                                                                            @cyberseckyle@infosec.exchange

                                                                                                                                                            Anyone use VSCode? I built an extension that served a purpose for me and decided to share it!

                                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                                              Everyone says they want to share wearable data with doctors — but almost nobody is doing it

                                                                                                                                                              We're all tracking our health data and keeping it completely to ourselves.

                                                                                                                                                              androidauthority.com/wearable-

                                                                                                                                                              [Android Authority]

                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                [?]iX Magazin » 🌐
                                                                                                                                                                @iX_Magazin@social.heise.de

                                                                                                                                                                Proxmox Mail Gateway 9.1 erleichtert Kampf gegen Spam und verschlüsselt Backups

                                                                                                                                                                Das neue Proxmox Mail Gateway will mehr Komfort beim Mail-Handling bieten und die Möglichkeit, ihre Backups zu verschlüsseln.

                                                                                                                                                                heise.de/news/Proxmox-Mail-Gat

                                                                                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                @techwire@social.gamefan.net

                                                                                                                                                                I held the Trump phone

                                                                                                                                                                Where's the Trump phone? We're going to keep talking about it every week. We've reached out, as usual, to ask about the Trump phone's whereabouts. We don't have the phones we preordered yet, but this week included an un…

                                                                                                                                                                theverge.com/tech/948464/trump

                                                                                                                                                                [The Verge]

                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                  [?]Marian ツ » 🌐
                                                                                                                                                                  @mar_k83@misskey.de

                                                                                                                                                                  [?]Arint - SEO+KI » 🌐
                                                                                                                                                                  @Arint@arint.info

                                                                                                                                                                  RT @Kimi_Moonshot: 🌘 Kimi-K2.7-Code, unser neuestes Coding-Modell, ist jetzt veröffentlicht und quelloffen verfügbar!

                                                                                                                                                                  mehr auf Arint.info

                                                                                                                                                                  https://x.com/Kimi_Moonshot/status/2065377579130142937#m

                                                                                                                                                                    dansup boosted

                                                                                                                                                                    [?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
                                                                                                                                                                    @christin@lsbt.me

                                                                                                                                                                    FediSuite - Fediverse Management Platform

                                                                                                                                                                    Open-source platform for social media management and analytics

                                                                                                                                                                    If you manage several Fediverse accounts, you're constantly juggling browser tabs, losing track of which input field belongs to which platform, and at some point you no longer know what you've already posted. brings everything together in one place.

                                                                                                                                                                    Connect accounts from 19(+) platforms: , , , , , , , and more. The app detects your instance type automatically, loads the correct character limit and media rules straight from your instance, and sets up the composer accordingly. No manual configuration needed.

                                                                                                                                                                    The analytics go way beyond plain follower counts: daily engagement charts, follower growth, your best posting times as a heatmap, hashtag performance, and a tips engine that evaluates your actual data and gives you concrete suggestions based on your own numbers.

                                                                                                                                                                    Schedule posts down to the minute in your own time zone. Background workers handle publishing reliably, with resume handling for rate limits and atomic delivery.

                                                                                                                                                                    FediSuite is free and under the GPL-3.0. Anyone can host their own FediSuite and get it added to the official list automatically.

                                                                                                                                                                    If you find a bug, especially in the setup, feel free to report it. The project is being actively developed, and real-world bug reports are among the most valuable contributions right now. The CONTRIBUTING.md explains how it works.

                                                                                                                                                                    The project lives on donations. Donations guarantee and make it possible for FediSuite to keep going and keep being developed. To support FediSuite, click the yellow button on the website.

                                                                                                                                                                    More info: fedisuite.com

                                                                                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                      @techwire@social.gamefan.net

                                                                                                                                                                      Summer Upgrade Week

                                                                                                                                                                      The sun is out, the sky is clear. It’s time to get outside and disconnect — from work, at least. This summer, we’re looking at all the ways to upgrade our free time indoors and out, from smart lights for the backyard to…

                                                                                                                                                                      theverge.com/tech/942658/summe

                                                                                                                                                                      [The Verge]

                                                                                                                                                                        [?]Super Owl » 🌐
                                                                                                                                                                        @gtsadmin@wiseowl.club

                                                                                                                                                                        @AutisticInnovator I'm sorry to hear about all the difficulties! I hope you succeed despite all those nasty people.

                                                                                                                                                                        I've had a lot of bots on my websites, and I set up Anubis on most of them. Anubis was a pain to configure (took a lot of tinkering to understand how it all worked)! But I'm grateful that is was #OpenSource

                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                          [?]heise online English » 🤖 🌐
                                                                                                                                                                          @heiseonlineenglish@social.heise.de

                                                                                                                                                                          Attack wave on Arch Linux: hundreds of package descriptions with malware in AUR

                                                                                                                                                                          Arch Linux defends itself against a wave of attacks that have massively contaminated package descriptions in the unofficial Arch User Repository with malware.

                                                                                                                                                                          heise.de/en/news/Attack-wave-o

                                                                                                                                                                            [?]sigdevel » 🌐
                                                                                                                                                                            @sigdevel@infosec.exchange

                                                                                                                                                                            Security Advisory: CVE-2025-52290 - NULL Pointer Dereference in FFmpeg H.264 Reorder Frame Handling

                                                                                                                                                                            Processing a crafted media file with `ffmpeg` can trigger a segmentation fault in `avpriv_h264_has_num_reorder_frames()`, causing a denial of service.

                                                                                                                                                                            Summary:
                                                                                                                                                                            FFmpeg can crash while demuxing a malformed MPEG/MP4 input that causes H.264 data to be handled through a mismatched AAC `AVCodecContext`. In the observed crash path, the demuxing code reaches `has_decode_delay_been_guessed()` and calls `avpriv_h264_has_num_reorder_frames()` with an invalid or uninitialized H.264 parameter-set state. The function then dereferences `ps.sps` without sufficient validation and triggers a `SEGV` read in `libavcodec/h264dec.c:64`.

                                                                                                                                                                            The issue is reproducible with the provided PoC media file and was observed in both a standard build and an AddressSanitizer build.

                                                                                                                                                                            CWE:
                                                                                                                                                                            CWE-476 - NULL Pointer Dereference

                                                                                                                                                                            Affected Component:
                                                                                                                                                                            ```
                                                                                                                                                                            libavcodec/h264dec.c:64
                                                                                                                                                                            Function: avpriv_h264_has_num_reorder_frames()

                                                                                                                                                                            libavformat/demux.c:757
                                                                                                                                                                            Function: has_decode_delay_been_guessed()
                                                                                                                                                                            ```

                                                                                                                                                                            Affected Product:
                                                                                                                                                                            FFmpeg / ffmpeg command-line media processing tool.

                                                                                                                                                                            Affected Version:
                                                                                                                                                                            The issue was reproduced on FFmpeg version `N-119856-gbe46370941` and commit:
                                                                                                                                                                            ```
                                                                                                                                                                            be46370941405fb04402d96373a53e2a1846f3ac
                                                                                                                                                                            ```
                                                                                                                                                                            The local environment notes also reference a tested FFmpeg commit:
                                                                                                                                                                            ```
                                                                                                                                                                            52441bd4cd0e85bf007473bd2eada2b2083aacf5
                                                                                                                                                                            ```

                                                                                                                                                                            Attack Conditions:
                                                                                                                                                                            An attacker supplies a specially crafted media file to a workflow that invokes FFmpeg on attacker-controlled input. This can be a local batch/transcoding workflow, or a network-facing media-processing service that accepts uploads and processes them with FFmpeg.

                                                                                                                                                                            The crash can be reproduced with:

                                                                                                                                                                            ```
                                                                                                                                                                            ./ffmpeg -i ./1_poc.mp4 -f null
                                                                                                                                                                            ```

                                                                                                                                                                            No elevated privileges are required. User interaction depends on the deployment model: interactive use requires a user to process the malicious file, while automated upload/transcoding services may trigger the crash without direct user interaction.

                                                                                                                                                                            Impact:
                                                                                                                                                                            The observed impact is denial of service due to abnormal process termination. AddressSanitizer reports a `SEGV` caused by a read memory access in:

                                                                                                                                                                            ```
                                                                                                                                                                            avpriv_h264_has_num_reorder_frames libavcodec/h264dec.c:64:17
                                                                                                                                                                            ```

                                                                                                                                                                            The prepared materials at the CVE request also note the potential impact on code execution, however, I have not demonstrated any control flow hacking or an exploit to execute working code.

                                                                                                                                                                            References

                                                                                                                                                                            - Issue/(+ primary email-report): github.com/sigdevel/pocs/blob/
                                                                                                                                                                            - PoC: github.com/sigdevel/pocs/blob/

                                                                                                                                                                            Credits
                                                                                                                                                                            Alexander A. Shvedov (@sigdevel)

                                                                                                                                                                              [?]sigdevel » 🌐
                                                                                                                                                                              @sigdevel@infosec.exchange

                                                                                                                                                                              Security Advisory: CVE-2025-55648 - Heap Buffer Overflow in GPAC MP4Box Opus Packet Parser

                                                                                                                                                                              Processing a crafted MP4 file containing corrupted Opus sample-size data with `MP4Box` can trigger a heap buffer overflow in `gf_opus_parse_packet_header()`, causing a crash and potential memory corruption impact.

                                                                                                                                                                              Summary:
                                                                                                                                                                              The `gf_opus_parse_packet_header()` function in `media_tools/av_parsers.c` does not sufficiently validate the input buffer length before parsing Opus packet headers. When MP4Box processes a crafted MP4 file with corrupted sample-size (`stsz`) data, the parser reads beyond the bounds of a heap-allocated sample buffer.
                                                                                                                                                                              AddressSanitizer reports a `heap-buffer-overflow` at `media_tools/av_parsers.c:11297`, with a `READ of size 1` 1242 bytes past a 32-byte heap region allocated by `Media_GetSample()`.

                                                                                                                                                                              CWE:
                                                                                                                                                                              CWE-122 - Heap-based Buffer Overflow

                                                                                                                                                                              Affected Component:
                                                                                                                                                                              ```
                                                                                                                                                                              media_tools/av_parsers.c:11297
                                                                                                                                                                              Function: gf_opus_parse_packet_header()
                                                                                                                                                                              ```

                                                                                                                                                                              Affected Product:
                                                                                                                                                                              MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                              Affected Version:
                                                                                                                                                                              MP4Box versions 2.4 and earlier are affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                              ```
                                                                                                                                                                              61bbfd2e89553373ba3449b8ec05b5f098d732a5
                                                                                                                                                                              ```

                                                                                                                                                                              Attack Conditions:
                                                                                                                                                                              An attacker supplies a crafted MP4 file containing corrupted Opus sample-size (`stsz`) data. The issue can be reproduced locally with:
                                                                                                                                                                              ```
                                                                                                                                                                              ./MP4Box 12_poc.mp4 -dxml
                                                                                                                                                                              ```
                                                                                                                                                                              No elevated privileges are required. The CVE text describes the attack as network/context-dependent because attacker-controlled media may be processed by MP4Box in automated workflows; manual processing also triggers the issue.

                                                                                                                                                                              Impact:
                                                                                                                                                                              The immediate observed impact is Denial of Service due to process termination. Because the bug reads beyond a heap allocation, information disclosure may be possible. The local MITRE data also notes potential arbitrary code execution risk, though the observed ASAN trace is an out-of-bounds read.

                                                                                                                                                                              Fix / mitigation status:
                                                                                                                                                                              The local CVE/MITRE data references GPAC fix commit:
                                                                                                                                                                              ```
                                                                                                                                                                              cea49f684dbc4d53ecd6c76a9623838802a68d88
                                                                                                                                                                              ```

                                                                                                                                                                              Users should update to a GPAC build containing this commit or later. The affected Opus parser should validate sample buffer length and `stsz`-derived packet sizes before reading packet header fields.

                                                                                                                                                                              References:
                                                                                                                                                                              - Issue: github.com/gpac/gpac/issues/31
                                                                                                                                                                              - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                              - Fix: github.com/gpac/gpac/commit/ce

                                                                                                                                                                              Credit:
                                                                                                                                                                              @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                [?]sigdevel » 🌐
                                                                                                                                                                                @sigdevel@infosec.exchange

                                                                                                                                                                                Security Advisory: CVE-2025-55642 - Divide by Zero in GPAC MP4Box AVI Demuxer

                                                                                                                                                                                Processing a crafted AVI-like media file with `MP4Box` can trigger a division by zero in `avidmx_process()`, causing a floating-point exception and Denial of Service.

                                                                                                                                                                                Summary:
                                                                                                                                                                                The `avidmx_process()` function in `filters/dmx_avi.c` does not sufficiently validate frame-count metadata before using it as a divisor during bitrate computation. When MP4Box processes a specially crafted input with invalid AVI frame metadata, such as a `0/256` frame declaration, the DASH processing path attempts to compute bitrate from the bitstream and divides by zero.
                                                                                                                                                                                AddressSanitizer reports an `FPE` at `filters/dmx_avi.c:639`.

                                                                                                                                                                                CWE:
                                                                                                                                                                                CWE-369 - Divide by Zero

                                                                                                                                                                                Affected Component:
                                                                                                                                                                                ```
                                                                                                                                                                                filters/dmx_avi.c:639
                                                                                                                                                                                Function: avidmx_process()
                                                                                                                                                                                ```

                                                                                                                                                                                Affected Product:
                                                                                                                                                                                MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                Affected Version:
                                                                                                                                                                                GPAC MP4Box v2.4 is affected according to the CVE request data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                                ```
                                                                                                                                                                                f87b30611380e4dcd03cd4dd9ac553c0ec336826
                                                                                                                                                                                ```

                                                                                                                                                                                Builds before the fix commit `cea49f684dbc4d53ecd6c76a9623838802a68d88` should be considered affected if they contain the vulnerable AVI demuxer bitrate computation path.

                                                                                                                                                                                Attack Conditions:
                                                                                                                                                                                An attacker supplies a crafted AVI-like media file with invalid frame metadata. The issue is triggered while processing the file through MP4Box DASH segmentation, for example with a `-dash` command using `14_poc.mp4`.
                                                                                                                                                                                No elevated privileges are required. User interaction is required when the victim manually processes the malicious media file, or an automated workflow invokes MP4Box on attacker-controlled input.

                                                                                                                                                                                Impact:
                                                                                                                                                                                The immediate observed impact is Denial of Service due to an uncaught floating-point exception and process termination. No evidence of arbitrary code execution was observed.

                                                                                                                                                                                Fix / mitigation status:
                                                                                                                                                                                The issue was fixed in GPAC commit:
                                                                                                                                                                                ```
                                                                                                                                                                                cea49f684dbc4d53ecd6c76a9623838802a68d88
                                                                                                                                                                                ```
                                                                                                                                                                                Users should update to a GPAC build containing this commit or later. The affected code should validate `num_frames` and related AVI metadata before using frame counts in bitrate calculations.

                                                                                                                                                                                References:
                                                                                                                                                                                - Issue: github.com/gpac/gpac/issues/31
                                                                                                                                                                                - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                - Fix: github.com/gpac/gpac/commit/ce

                                                                                                                                                                                Credit:
                                                                                                                                                                                @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                  [?]sigdevel » 🌐
                                                                                                                                                                                  @sigdevel@infosec.exchange

                                                                                                                                                                                  Security Advisory: CVE-2025-55644 - Use-After-Free in GPAC MP4Box

                                                                                                                                                                                  Processing a crafted MP4 file with invalid BIFS GlobalQuantizer commands causes gf_node_get_tag() to access a freed 192-byte QuantizationParameter node at scenegraph/base_scenegraph.c:1263, resulting in a heap use-after-free and crash.

                                                                                                                                                                                  Summary:
                                                                                                                                                                                  During MPEG-4 BIFS scene decoding, BM_ParseGlobalQuantizer() in bifs/memory_decoder.c first calls gf_node_unregister() at line 176 to release a QuantizationParameter node, freeing the 192-byte heap region. Without clearing the stale pointer, the function then calls gf_node_get_tag() on the same address at line 181, performing a READ of 8 bytes at offset 0 into the freed region. A crafted MP4 containing invalid GlobalQuantizer BIFS commands, corrupted ODF descriptors, and malformed box types (PEC1808, fre) reliably triggers this free-then-use sequence through the -svg dump path.

                                                                                                                                                                                  CWE:
                                                                                                                                                                                  CWE-416 - Use After Free

                                                                                                                                                                                  Affected Component:
                                                                                                                                                                                  ```
                                                                                                                                                                                  scenegraph/base_scenegraph.c:1263
                                                                                                                                                                                  ```

                                                                                                                                                                                  Affected Product:
                                                                                                                                                                                  MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                  Affected Version:
                                                                                                                                                                                  MP4Box 2.4 and earlier; tested at commit f5b7cdc63a7f3269040778c5431a8f6c310bc9f3

                                                                                                                                                                                  Attack Conditions:
                                                                                                                                                                                  An attacker supplies a locally accessible crafted MP4 file embedding invalid BIFS scene data. The victim runs MP4Box -svg on the file to trigger BIFS scene parsing. No elevated privileges are required.

                                                                                                                                                                                  Impact:
                                                                                                                                                                                  The use-after-free causes a fatal crash (Denial of Service). Use-after-free vulnerabilities can allow attackers to control freed heap memory contents and potentially redirect execution flow; code execution cannot be excluded.

                                                                                                                                                                                  Fix / mitigation status:
                                                                                                                                                                                  The issue was fixed in GPAC commit:
                                                                                                                                                                                  ```
                                                                                                                                                                                  63eccc33d4a2b731ebb31581ff5673a2c0b13ad4
                                                                                                                                                                                  ```
                                                                                                                                                                                  Users should update to a GPAC build containing this commit or later.

                                                                                                                                                                                  References:
                                                                                                                                                                                  - Issue: github.com/gpac/gpac/issues/32
                                                                                                                                                                                  - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                  - Fix: github.com/gpac/gpac/commit/63

                                                                                                                                                                                  Credit:
                                                                                                                                                                                  @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                    [?]sigdevel » 🌐
                                                                                                                                                                                    @sigdevel@infosec.exchange

                                                                                                                                                                                    Security Advisory: CVE-2025-55652 - Heap Buffer Overflow in GPAC MP4Box VP Configuration Handling

                                                                                                                                                                                    Processing a crafted MP4 file with malformed VP codec configuration data can trigger a heap buffer overflow in `gf_isom_vp_config_new()`, causing a crash and potential memory corruption.

                                                                                                                                                                                    Summary:
                                                                                                                                                                                    The `gf_isom_vp_config_new()` function in `isomedia/avc_ext.c` does not sufficiently validate buffer boundaries when creating VP codec configuration boxes. A crafted MP4 file with malformed VP codec data, including unknown box types such as `D0ncv` in `stsd`, can cause MP4Box to allocate an undersized box structure and then write VP/NALU configuration data beyond the allocation.

                                                                                                                                                                                    CWE:
                                                                                                                                                                                    CWE-122 - Heap-based Buffer Overflow

                                                                                                                                                                                    Affected Component:
                                                                                                                                                                                    ```
                                                                                                                                                                                    isomedia/avc_ext.c:1962
                                                                                                                                                                                    Function: gf_isom_vp_config_new()
                                                                                                                                                                                    ```

                                                                                                                                                                                    Affected Product:
                                                                                                                                                                                    MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                    Affected Version:
                                                                                                                                                                                    MP4Box versions 2.4 and earlier are affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                                    ```
                                                                                                                                                                                    74fecde32cd477ab097f3e6db55a32b259f3313d
                                                                                                                                                                                    ```
                                                                                                                                                                                    Builds before the fix commit `ad3b541b4f38c8f0ef67544509598f8207ea1207` should be considered affected if they contain the vulnerable VP configuration allocation/write path.

                                                                                                                                                                                    Attack Conditions:
                                                                                                                                                                                    An attacker supplies a crafted MP4 file containing malformed VP codec configuration data. The issue can be reproduced locally with:
                                                                                                                                                                                    ```
                                                                                                                                                                                    ./MP4Box -dash 10000 ./18_poc.mp4
                                                                                                                                                                                    ```
                                                                                                                                                                                    No elevated privileges are required. User interaction is required when the victim manually processes the malicious MP4 file, or an automated media workflow invokes MP4Box on attacker-controlled input.

                                                                                                                                                                                    Impact:
                                                                                                                                                                                    The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is an out-of-bounds heap write, memory corruption and potential arbitrary code execution cannot be ruled out.

                                                                                                                                                                                    Fix / mitigation status:
                                                                                                                                                                                    The issue was fixed in GPAC commit:
                                                                                                                                                                                    ```
                                                                                                                                                                                    ad3b541b4f38c8f0ef67544509598f8207ea1207
                                                                                                                                                                                    ```

                                                                                                                                                                                    References:
                                                                                                                                                                                    - CVE: cve.org/CVERecord?id=CVE-2025-
                                                                                                                                                                                    - Issue: github.com/gpac/gpac/issues/32
                                                                                                                                                                                    - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                    - Fix: github.com/gpac/gpac/commit/ad

                                                                                                                                                                                    Credit:
                                                                                                                                                                                    @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                      [?]sigdevel » 🌐
                                                                                                                                                                                      @sigdevel@infosec.exchange

                                                                                                                                                                                      Security Advisory: CVE-2025-55643 - NULL Pointer Dereference in GPAC MP4Box TrackWriter Handling

                                                                                                                                                                                      Processing a crafted MP4 file during DASH segmentation can trigger a NULL pointer dereference in MP4Box TrackWriter handling, causing a Denial of Service.

                                                                                                                                                                                      Summary:
                                                                                                                                                                                      The DASH fragmentation path in `filters/mux_isom.c` does not sufficiently validate a `TrackWriter` pointer before accessing its members. A crafted MP4 file with malformed metadata boxes can cause the PID-to-track setup to fail, leaving the `TrackWriter` pointer NULL. The muxer then performs member access through the NULL pointer.

                                                                                                                                                                                      CWE:
                                                                                                                                                                                      CWE-476 - NULL Pointer Dereference

                                                                                                                                                                                      Affected Component:
                                                                                                                                                                                      ```
                                                                                                                                                                                      filters/mux_isom.c:6621
                                                                                                                                                                                      Function/path: TrackWriter handling during fragmented MP4 muxing
                                                                                                                                                                                      ```

                                                                                                                                                                                      Affected Product:
                                                                                                                                                                                      MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                      Affected Version:
                                                                                                                                                                                      MP4Box versions 2.4 and earlier are affected according to the prepared CVE data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                                      ```
                                                                                                                                                                                      74fecde32cd477ab097f3e6db55a32b259f3313d
                                                                                                                                                                                      ```
                                                                                                                                                                                      Builds before the fix commit `ad3b541b4f38c8f0ef67544509598f8207ea1207` should be considered affected if they contain the vulnerable TrackWriter handling path.

                                                                                                                                                                                      Attack Conditions:
                                                                                                                                                                                      An attacker supplies a crafted MP4 file containing malformed metadata boxes, including malformed `mvcC` / `stsz` data. The issue can be reproduced locally with:
                                                                                                                                                                                      ```
                                                                                                                                                                                      ./MP4Box -dash 10000 ./17_poc.mp4
                                                                                                                                                                                      ```
                                                                                                                                                                                      No elevated privileges are required. User interaction is required when the victim manually processes the malicious MP4 file, or an automated media workflow invokes MP4Box on attacker-controlled input.

                                                                                                                                                                                      Impact:
                                                                                                                                                                                      The immediate observed impact is Denial of Service due to process termination. No evidence of arbitrary code execution was observed.

                                                                                                                                                                                      Fix / mitigation status:
                                                                                                                                                                                      The issue was fixed in GPAC commit:
                                                                                                                                                                                      ```
                                                                                                                                                                                      ad3b541b4f38c8f0ef67544509598f8207ea1207
                                                                                                                                                                                      ```
                                                                                                                                                                                      Users should update to a GPAC build containing this commit or later. The affected muxing path should validate `TrackWriter` before member access and fail cleanly when track initialization fails.

                                                                                                                                                                                      References:
                                                                                                                                                                                      - Issue: github.com/gpac/gpac/issues/32
                                                                                                                                                                                      - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                      - Fix: github.com/gpac/gpac/commit/ad

                                                                                                                                                                                      Credit
                                                                                                                                                                                      @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                        [?]c't Magazin » 🌐
                                                                                                                                                                                        @ct_Magazin@social.heise.de

                                                                                                                                                                                        Angriffswelle auf Arch Linux: Hunderte Paketbeschreibungen mit Malware im AUR

                                                                                                                                                                                        Arch Linux wehrt sich gegen eine Angriffswelle, die massenweise Paketbeschreibungen im inoffiziellen Arch User Repository mit Malware verseucht hat.

                                                                                                                                                                                        heise.de/news/Angriffswelle-au

                                                                                                                                                                                          [?]sigdevel » 🌐
                                                                                                                                                                                          @sigdevel@infosec.exchange

                                                                                                                                                                                          Security Advisory: CVE-2025-55641 - NULL Pointer Dereference in GPAC MP4Box Sample Info Copy

                                                                                                                                                                                          Processing a crafted MP4 file with corrupted Sample Auxiliary Information metadata can trigger a NULL pointer dereference in `gf_isom_copy_sample_info()`, causing a Denial of Service and potential memory corruption impact.

                                                                                                                                                                                          Summary:
                                                                                                                                                                                          The `gf_isom_copy_sample_info()` function in `isomedia/isom_write.c` does not sufficiently validate pointers after handling invalid Sample Auxiliary Information (SAI) metadata. A crafted MP4 file can provide corrupted SAI values, such as an invalid `sai_samples` count, causing memory allocation or merge handling to fail. The import path later attempts to copy sample information from a NULL pointer.

                                                                                                                                                                                          AddressSanitizer reports a `SEGV` caused by a `READ` memory access at address `0x000000000000`, with the crash occurring at `isomedia/isom_write.c:8164`.

                                                                                                                                                                                          CWE:
                                                                                                                                                                                          CWE-476 - NULL Pointer Dereference

                                                                                                                                                                                          Affected Component:
                                                                                                                                                                                          ```
                                                                                                                                                                                          isomedia/isom_write.c:8164
                                                                                                                                                                                          Function: gf_isom_copy_sample_info()
                                                                                                                                                                                          ```

                                                                                                                                                                                          Affected Product:
                                                                                                                                                                                          MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                          Affected Version:
                                                                                                                                                                                          MP4Box versions 2.4 and earlier are affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                                          ```
                                                                                                                                                                                          f87b30611380e4dcd03cd4dd9ac553c0ec336826
                                                                                                                                                                                          ```

                                                                                                                                                                                          Attack Conditions:
                                                                                                                                                                                          An attacker supplies a crafted MP4 file containing corrupted SAI metadata. The issue can be reproduced locally with:
                                                                                                                                                                                          ```
                                                                                                                                                                                          ./MP4Box -add 13_poc.mp4 -new /dev/null -split-size 500
                                                                                                                                                                                          ```
                                                                                                                                                                                          No elevated privileges are required. User interaction is required when the victim manually processes the malicious MP4 file, or an automated media workflow invokes MP4Box on attacker-controlled input.

                                                                                                                                                                                          Impact:
                                                                                                                                                                                          The immediate observed impact is Denial of Service due to process termination. The local CVE/MITRE data also marks potential code execution impact; the observed ASAN trace is a NULL pointer read.

                                                                                                                                                                                          Fix / mitigation status:
                                                                                                                                                                                          The issue was fixed in GPAC commit:
                                                                                                                                                                                          ```
                                                                                                                                                                                          e38d24b7e3cbdc24e70f0437bf390ac3f2080b52
                                                                                                                                                                                          ```
                                                                                                                                                                                          Users should update to a GPAC build containing this commit or later. The affected code should validate SAI metadata, allocation results, and sample-info pointers before copying sample information.

                                                                                                                                                                                          References:
                                                                                                                                                                                          - CVE: cve.org/CVERecord?id=CVE-2025-
                                                                                                                                                                                          - Issue: github.com/gpac/gpac/issues/31
                                                                                                                                                                                          - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                          - Fix: github.com/gpac/gpac/commit/e3

                                                                                                                                                                                          Credit:
                                                                                                                                                                                          @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                            [?]sigdevel » 🌐
                                                                                                                                                                                            @sigdevel@infosec.exchange

                                                                                                                                                                                            Security Advisory: CVE-2025-55649 - NULL Pointer Dereference in GPAC MP4Box ESD Mapping

                                                                                                                                                                                            Processing a crafted MP4 file with corrupted Elementary Stream Descriptor data can trigger a NULL pointer dereference in `gf_media_map_esd()`, causing a Denial of Service.

                                                                                                                                                                                            Summary:
                                                                                                                                                                                            The `gf_media_map_esd()` function in `media_tools/isom_tools.c` does not verify that `esd->URLString` is non-NULL before passing it to `strlen()`. When MP4Box processes a crafted MP4 file containing corrupted ESD data during fragmentation setup, `URLString` can be NULL and the process crashes while reading from address `0x000000000000`.

                                                                                                                                                                                            AddressSanitizer reports a `SEGV` in `strlen()`, with the GPAC call site at `media_tools/isom_tools.c:1359`.

                                                                                                                                                                                            CWE:
                                                                                                                                                                                            CWE-476 - NULL Pointer Dereference

                                                                                                                                                                                            Affected Component:
                                                                                                                                                                                            ```
                                                                                                                                                                                            media_tools/isom_tools.c:1359
                                                                                                                                                                                            Function: gf_media_map_esd()
                                                                                                                                                                                            ```

                                                                                                                                                                                            Affected Product:
                                                                                                                                                                                            MP4Box (GPAC Multimedia Open Source Project)

                                                                                                                                                                                            Affected Version:
                                                                                                                                                                                            MP4Box versions 2.4 and earlier are affected according to the prepared CVE/MITRE data. The issue was reproduced on a GPAC build at commit:
                                                                                                                                                                                            ```
                                                                                                                                                                                            09e7063ed0a13b4cee9a180a56dcc21e9f9ade07
                                                                                                                                                                                            ```

                                                                                                                                                                                            Attack Conditions:
                                                                                                                                                                                            An attacker supplies a crafted MP4 file containing corrupted ESD data. The issue can be reproduced locally with:
                                                                                                                                                                                            ```
                                                                                                                                                                                            ./MP4Box -frag 1500 11_poc.mp4
                                                                                                                                                                                            ```
                                                                                                                                                                                            No elevated privileges are required. User interaction is required when the victim manually processes the malicious MP4 file, or an automated workflow invokes MP4Box on attacker-controlled media.

                                                                                                                                                                                            Impact:
                                                                                                                                                                                            The immediate observed impact is Denial of Service due to process termination. The crash is a NULL pointer dereference on the zero page; no evidence of arbitrary code execution was observed.

                                                                                                                                                                                            Fix / mitigation status:
                                                                                                                                                                                            The local CVE/MITRE data references GPAC fix commit:
                                                                                                                                                                                            ```
                                                                                                                                                                                            10c16d54659b1b82dd49573dfeacfa9a5627a115
                                                                                                                                                                                            ```
                                                                                                                                                                                            Users should update to a GPAC build containing this commit or later. The affected code should validate `esd`, `esd->URLString`, and related ESD fields before string operations.

                                                                                                                                                                                            References:
                                                                                                                                                                                            - Issue: github.com/gpac/gpac/issues/31
                                                                                                                                                                                            - PoC: github.com/sigdevel/pocs/blob/
                                                                                                                                                                                            - Fix: github.com/gpac/gpac/commit/10

                                                                                                                                                                                            Credit:
                                                                                                                                                                                            @sigdevel (Alexander A. Shvedov)

                                                                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                                                                              You can now beat ChatGPT Codex rate limits, if you have friends

                                                                                                                                                                                              OpenAI launches a new (temporary) referral system that rewards you and a friend with bankable rate limit resets.

                                                                                                                                                                                              androidauthority.com/openai-ch

                                                                                                                                                                                              [Android Authority]

                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                [?]iX Magazin » 🌐
                                                                                                                                                                                                @iX_Magazin@social.heise.de

                                                                                                                                                                                                Homebrew 6.0 sichert Paketquellen ab

                                                                                                                                                                                                Homebrew 6.0 ist da: Externe Paketquellen müssen sich künftig als vertrauenswürdig erweisen. Dazu gibt es eine Linux-Sandbox und eine schnellere Standard-API.

                                                                                                                                                                                                heise.de/news/Homebrew-6-0-sic

                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                  [?]heinelo » 🌐
                                                                                                                                                                                                  @heinelo@pixelfed.social

                                                                                                                                                                                                  #ViernesDeEscritorio #DesktopFriday
                                                                                                                                                                                                  Mein Desktop unter Fedora 44 Gnome 50.2 die Nutzung von Linux und Open Source Software mit entsprechenden Messengern und Mail Anwendungen und ohne Google / Microsoft / Apple und mit KI dann wenn ich sie haben möchte ist und bleibt einfach eine bessere und auch Nachhaltigerer und vor allem Selbst bestimmender Umgang mit Informationstechnologie.

                                                                                                                                                                                                  Bild Bearbeitung ist mit den zur Verfügung stehen Tools unter Linux gar kein Problem funzt viel schneller als unter Windows
                                                                                                                                                                                                  #darktable #gimp #shotwell
                                                                                                                                                                                                  #DailyDesktop
                                                                                                                                                                                                  #ShareYourDesktop
                                                                                                                                                                                                  #UnixPorn
                                                                                                                                                                                                  #mywork
                                                                                                                                                                                                  #duisburg
                                                                                                                                                                                                  #fedora44 #gnulinux #Linux #mydesktop #opensource #fedora #libreoffice #fairphone4 #murenacloud #evolution #digitaleselbstbestimmung #onlyoffice #digitaleselbstverteidigung #digitalenachhaltigkeit #signal #telegram #Verschlüsselung #openpgp #rkhunter #lynis #firewall

                                                                                                                                                                                                  Zu sehen ist mein Fedora Linux Desktop mit einem von mir in Düssseldorf Angermund Aufgenommen Bild von Kornblumen und Magarieten am wegesrand  vor einem Kornfeld was noch grün ist.

                                                                                                                                                                                                  Alt...Zu sehen ist mein Fedora Linux Desktop mit einem von mir in Düssseldorf Angermund Aufgenommen Bild von Kornblumen und Magarieten am wegesrand vor einem Kornfeld was noch grün ist.

                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                    [?]heise online » 🌐
                                                                                                                                                                                                    @heiseonline@social.heise.de

                                                                                                                                                                                                    Murena /e/ OS 4.0: Android-Fork soll Umstieg von Google-Diensten erleichtern

                                                                                                                                                                                                    Das französische Unternehmen Murena hat den Google-freien Android-Fork /e/ OS 4.0 veröffentlicht.

                                                                                                                                                                                                    heise.de/news/Murena-e-OS-4-0-

                                                                                                                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                      @techwire@social.gamefan.net

                                                                                                                                                                                                      Spotify’s hated disco ball icon is finally gone for good

                                                                                                                                                                                                      Spotify's latest iOS update quietly ended a month of disco-themed misery.

                                                                                                                                                                                                      androidauthority.com/spotify-d

                                                                                                                                                                                                      [Android Authority]

                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                        [?]Frank Hofmann » 🌐
                                                                                                                                                                                                        @hofmannedv@mastodon.social

                                                                                                                                                                                                        Aus dem Linux-Magazin 07/2026 (geschrieben von @veit und mir):

                                                                                                                                                                                                        Wie LLM-Agenten Open-Source-Projekte gefährden

                                                                                                                                                                                                        linux-magazin.de/ausgaben/2026

                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                          [?]heinelo » 🌐
                                                                                                                                                                                                          @heinelo@pixelfed.social

                                                                                                                                                                                                          So das sieht jetzt Richtig gut Aus in der Murena Cloud mit Video Chat als Alternative für Teams und mit libresign zur Dokumenten Signatur.
                                                                                                                                                                                                          Danke an das Murena Team auch e/os auf dem Fairphone sieht in Version 4.0 ganz Schick aus.
                                                                                                                                                                                                          #linux #opensource #murena #digitaleselbstbestimmung #nobigtech

                                                                                                                                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                            @techwire@social.gamefan.net

                                                                                                                                                                                                            AAPL Stock Slides Following WWDC, But Analysts Broadly Raise Targets

                                                                                                                                                                                                            Apple shares have lost roughly $25 per share this week following the company's WWDC 2026 keynote, though a wave of upward analyst price target revisions suggests Wall Street's longer-term view of Apple remains construct…

                                                                                                                                                                                                            macrumors.com/2026/06/11/aapl-

                                                                                                                                                                                                            [MacRumors]

                                                                                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                                                                                              Apple Agrees to Let Jon Prosser Formally Contest iOS 26 Leak Lawsuit

                                                                                                                                                                                                              Apple and leaker Jon Prosser have jointly asked a federal court to set aside the default judgment entered against him last October, with Prosser agreeing to hand over documents he had thus far failed to fully produce. A…

                                                                                                                                                                                                              macrumors.com/2026/06/11/apple

                                                                                                                                                                                                              [MacRumors]

                                                                                                                                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                @techwire@social.gamefan.net

                                                                                                                                                                                                                Siri won’t be your AI girlfriend

                                                                                                                                                                                                                ‘Listen, that's not what I'm here for, right?' | Image: Apple Our early testing has already shown that Siri AI knows when to shut up, and that's very much by design. In an interview with Mostly Human, Craig Federighi sa…

                                                                                                                                                                                                                theverge.com/tech/948890/siri-

                                                                                                                                                                                                                [The Verge]

                                                                                                                                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                  @techwire@social.gamefan.net

                                                                                                                                                                                                                  Telegram’s Wear OS app makes a comeback, now with full chats, voice notes, and more

                                                                                                                                                                                                                  Telegram finally fits on your wrist properly.

                                                                                                                                                                                                                  androidauthority.com/telegram-

                                                                                                                                                                                                                  [Android Authority]

                                                                                                                                                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                    @techwire@social.gamefan.net

                                                                                                                                                                                                                    Touchscreen MacBook '100% Confirmed,' Says Reputable Leaker

                                                                                                                                                                                                                    Apple's first touchscreen MacBook is now "100% confirmed," according to the prolific Chinese leaker known as Instant Digital, who appears to have insider information from sources in the supply chain. The leaker made the…

                                                                                                                                                                                                                    macrumors.com/2026/06/11/touch

                                                                                                                                                                                                                    [MacRumors]

                                                                                                                                                                                                                      [?]VSX.is | Digital sovereignty » 🌐
                                                                                                                                                                                                                      @vsx@infosec.exchange

                                                                                                                                                                                                                      The End of uBlock Origin in Chrome: What's Really Changing and What to Do About It

                                                                                                                                                                                                                      In early June 2026, it was confirmed that Chrome was also losing its last technical capabilities that had kept…

                                                                                                                                                                                                                      vsx.global/the-end-of-ublock-o

                                                                                                                                                                                                                        [?]heise online English » 🤖 🌐
                                                                                                                                                                                                                        @heiseonlineenglish@social.heise.de

                                                                                                                                                                                                                        Asahi Linux warns against upgrading to macOS 27 “Golden Gate”

                                                                                                                                                                                                                        Users of Asahi Linux should not update to the beta version of macOS 27 “Golden Gate,” the project currently warns.

                                                                                                                                                                                                                        heise.de/en/news/Asahi-Linux-w

                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                          [?]heise online » 🌐
                                                                                                                                                                                                                          @heiseonline@social.heise.de

                                                                                                                                                                                                                          Asahi Linux warnt vor Upgrade auf macOS 27 „Golden Gate“

                                                                                                                                                                                                                          Nutzer von Asahi Linux sollen nicht auf die Beta-Version macOS 27 „Golden Gate“ aktualisieren, warnt das Projekt aktuell.

                                                                                                                                                                                                                          heise.de/news/Asahi-Linux-warn

                                                                                                                                                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                            @techwire@social.gamefan.net

                                                                                                                                                                                                                            The Galaxy Z Fold 7 is finally getting the S26’s Galaxy AI features

                                                                                                                                                                                                                            Samsung's foldable phones are now getting S26-exclusive Galaxy AI features.

                                                                                                                                                                                                                            androidauthority.com/galaxy-z-

                                                                                                                                                                                                                            [Android Authority]

                                                                                                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                                                                                                              WWDC 2026 Keynote Marked a Major Departure From Previous Years

                                                                                                                                                                                                                              Apple's WWDC 2026 keynote broke from a longstanding format tradition, abandoning the platform-by-platform structure that has defined the annual developer conference for years in favor of a theme-driven presentation. Pre…

                                                                                                                                                                                                                              macrumors.com/2026/06/11/wwdc-

                                                                                                                                                                                                                              [MacRumors]

                                                                                                                                                                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                @techwire@social.gamefan.net

                                                                                                                                                                                                                                Apple Maps to Get These 10 New Features in iOS 27

                                                                                                                                                                                                                                Apple Maps is getting a range of new features in iOS 27, headlined by an upgraded Flyover experience that uses AI to improve the realism and detail of its aerial imagery. Flyover is a longstanding feature of ‌Apple Maps…

                                                                                                                                                                                                                                macrumors.com/2026/06/11/apple

                                                                                                                                                                                                                                [MacRumors]

                                                                                                                                                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                  @techwire@social.gamefan.net

                                                                                                                                                                                                                                  OpenAI bans China-linked ChatGPT accounts that amplified US data center electricity price backlash — used AI-generated cartoons to st…

                                                                                                                                                                                                                                  OpenAI says it has banned two clusters of ChatGPT accounts it believes are operating from China, and that used its models for covert influence campaigns targeting U.S. tech and policy debates.

                                                                                                                                                                                                                                  tomshardware.com/tech-industry

                                                                                                                                                                                                                                  [Tom's Hardware]

                                                                                                                                                                                                                                    [?]Owl Eyes » 🌐
                                                                                                                                                                                                                                    @d1@autistics.life

                                                                                                                                                                                                                                    @delta Thanks for making a consistent client experience on all platforms. The client is great, and this despite the ecosystem being quite an awkward fit to projects.

                                                                                                                                                                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                      @techwire@social.gamefan.net

                                                                                                                                                                                                                                      Memory famine compels GPU vendors to re-release 2020 graphics cards — GeForce RTX 3060 and GeForce RTX 3050 return to Asian market

                                                                                                                                                                                                                                      Graphics card manufacturer Manli adds new GeForce RTX 3060 and GeForce RTX 3050 SKUs to its portfolio.

                                                                                                                                                                                                                                      tomshardware.com/pc-components

                                                                                                                                                                                                                                      [Tom's Hardware]

                                                                                                                                                                                                                                        [?]Arint - SEO+KI » 🌐
                                                                                                                                                                                                                                        @Arint@arint.info

                                                                                                                                                                                                                                        RT @RyanLeeMiniMax: Hallo zusammen — unsere Hochleistungs-MSA-Kernbibliothek ist jetzt Open-Source. Die M3-Gewichte werden voraussichtlich diesen Freitag veröffentlicht. Vielen Dank für eure Geduld! Github: github.com/MiniMax-AI/MSA Paper: github.com/MiniMax-AI/MSA/blob

                                                                                                                                                                                                                                        mehr auf Arint.info

                                                                                                                                                                                                                                        https://x.com/RyanLeeMiniMax/status/2065010795625562486#m

                                                                                                                                                                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                          @techwire@social.gamefan.net

                                                                                                                                                                                                                                          After spat with Chinese gov't, Meta cuts AI Manus off from its internal systems and is 'sunsetting' platform, report claims — Beijing-ordered breakup of $2 billion AI deal begins

                                                                                                                                                                                                                                          Meta has finished separating its operations from Manus, the Chinese-founded agentic AI startup it acquired for roughly $2 billion in December.

                                                                                                                                                                                                                                          tomshardware.com/tech-industry

                                                                                                                                                                                                                                          [Tom's Hardware]

                                                                                                                                                                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                            @techwire@social.gamefan.net

                                                                                                                                                                                                                                            Watching the World Cup online is easier with these VPN deals — deals for watching the FIFA World Cup 2026

                                                                                                                                                                                                                                            A choice of VPN subscriptions to cover you over the FIFA World Cup 2026 and beyond. Stay safe online for less.

                                                                                                                                                                                                                                            tomshardware.com/software/vpn/

                                                                                                                                                                                                                                            [Tom's Hardware]

                                                                                                                                                                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                                                                                                                                                                              @techwire@social.gamefan.net

                                                                                                                                                                                                                                              Massive 8TB SD cards are set to ship 'shortly' after a two-year delay — mind-blowing storage at possibly bank-breaking prices

                                                                                                                                                                                                                                              Notebookcheck reports that 8TB SD cards will soon hit the retail market, although an exact launch date and pricing remain a mystery.

                                                                                                                                                                                                                                              tomshardware.com/pc-components

                                                                                                                                                                                                                                              [Tom's Hardware]

                                                                                                                                                                                                                                                Back to top - More...