SShortSingh.
0
ProgrammingDEV Community ·

SpaceX Starlink 10-39 Launches 29 Satellites; Booster Completes Record 30th Flight

SpaceX successfully launched its Starlink 10-39 mission on August 21 from SLC-40 at Cape Canaveral, one day after a last-minute scrub on August 20. The mission deployed 29 Starlink satellites into low Earth orbit aboard a Falcon 9 rocket. Booster B1078 completed its 30th flight and landed successfully after the mission. Following deployment, CelesTrak published supplemental orbital tracking data for the new satellites, derived from a SpaceX-provided state vector. The post-deployment data enables ground observers to calculate orbital passes and track the satellites once their trajectories become reliably predictable.

0
ProgrammingDEV Community ·

New Windows RATs E4del and PINHOLE Hide Commands Inside FTP Server Banners

Security researchers at SOCRadar Threat Research Unit have identified two new Windows remote access trojans, E4del and PINHOLE, that use an unusual technique of embedding PowerShell commands inside FTP server pre-login banners to initiate infection. Victims are compromised when they open an LNK shortcut file inside a ZIP archive, which silently connects to an attacker-controlled FTP server and retrieves the hidden commands. E4del disguises itself as a Discord application using a signed Electron wrapper, offering capabilities including remote shell access, screen capture, and live streaming via WebSockets. PINHOLE employs a multi-stage loader that resolves encrypted command-and-control server details stored on legitimate platforms like Pinterest and SurveyMonkey, then proxies traffic through Cloudflare Workers before injecting the final payload into a suspended ApplicationFrameHost.exe process. Security teams are advised to block ZIP and LNK files at gateways, restrict outbound FTP traffic, and monitor for abnormal connections to Pinterest, SurveyMonkey, and Cloudflare Workers domains.

0
ProgrammingDEV Community ·

Head Mare APT Exploits TrueConf Server Flaws to Spread PhantomCore Malware

The Head Mare APT group has been actively exploiting two critical vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in unpatched TrueConf Server installations to deliver the PhantomCore malware. Attackers chain the two flaws via port 4307/TCP to execute code, escape sandboxed environments, and plant a web shell granting privileged database access. They then replace the official TrueConf Windows client installer with a trojanized version, causing conference participants to unknowingly install PhantomCore alongside the legitimate client during routine updates. Kaspersky ICS CERT published its findings on August 12, 2026, and both CVEs have since been added to the CISA Known Exploited Vulnerabilities catalog. Administrators are urged to upgrade to TrueConf Server versions 5.3.9, 5.4.9, or 5.5.5 and restrict access to port 4307/TCP to trusted networks immediately.

0
ProgrammingDEV Community ·

How to Design a Scalable URL Shortener System Like Bit.ly

A high-level system design for a URL shortener outlines how to convert long URLs into short codes and redirect users back to the originals. The architecture relies on Base62 encoding of unique IDs — generated via auto-increment, UUID, or Snowflake — to produce 7-character codes supporting up to 3.5 trillion unique URLs. The system is built to handle roughly 11,500 reads per second at a 100:1 read-to-write ratio, with Redis caching targeting a 95% cache hit rate to minimize database load. A PostgreSQL database stores URL records and click analytics, with read replicas and automated failover ensuring high availability. Optional features include custom aliases, URL expiration, and analytics tracking clicks, referrers, and geographic data.

0
ProgrammingDEV Community ·

Google Warns Three Russia-Linked Groups Exploit Legitimate Auth Flows to Spy

Google Threat Intelligence Group published a report on August 20, 2026, detailing three Russia-linked threat clusters — UNC6293, UNC7005, and UNC5976 — abusing legitimate authentication mechanisms to compromise targeted individuals. Rather than relying solely on fake login pages, the attackers manipulate victims into completing real actions such as creating app passwords, approving OAuth logins, or linking WhatsApp devices, then capturing the resulting credentials or tokens. In some cases, targets are lured to sites mimicking secure call or file-sharing tools, where malware like VIDAR, ATOMIC, and HEADRUSH is also deployed to steal credentials, cookies, and audio-video data. The campaigns frequently involve impersonation of diplomats or trusted contacts to make the requests appear legitimate, with post-compromise access routed through residential proxies to evade detection. Google recommends blocking app passwords, enabling advanced phishing-resistant MFA, auditing linked devices, and verifying unexpected authentication requests through independent channels.

0
ProgrammingDEV Community ·

Docker bypasses UFW firewall rules, exposing container ports to local networks

A technical investigation has revealed that Docker silently overrides UFW firewall rules on Linux systems, including Raspberry Pi OS, by injecting its own iptables chains ahead of UFW's in the packet-filtering order. When a container port is published, Docker applies a DNAT rule that redirects traffic to the container before UFW's rules are ever evaluated, making the port reachable across the local network despite UFW showing it as blocked. The same port blocked for a host process becomes fully accessible when served from a container, yet UFW's status output shows no difference between the two scenarios. This occurs because Docker documents its iptables manipulation as intended behavior, but UFW's status tool only reflects its own rules and cannot account for Docker's parallel routing. Users can mitigate the exposure by binding container ports explicitly to 127.0.0.1 or by adding blocking rules directly to Docker's DOCKER-USER chain.

0
ProgrammingDEV Community ·

SynkLoader Malware Spreads via Microsoft Teams Phishing, Steals Credentials and Proxies Traffic

A newly identified malware campaign dubbed SynkLoader targets employees by impersonating IT support staff through external Microsoft 365 tenants on Microsoft Teams. Victims are tricked into downloading and running a malicious MSI file hosted on Azure Blob Storage, which silently installs a multi-stage Python-based loader. The malware establishes persistence via randomly named scheduled tasks created through COM, and deploys a fake full-screen Windows lock screen to harvest user passwords. A module called TrafficRedirector converts the infected machine into a reverse proxy, allowing attackers to tunnel into internal networks while bypassing IP allowlists. Security researchers at Expel published findings on the campaign on August 20, 2026, recommending organizations restrict external Teams communications, block MSI execution, and monitor for suspicious COM-based scheduled task creation.

0
ProgrammingDEV Community ·

Omarchy Linux Review: A Beginner's Take on DHH's Developer-Focused Distro

A developer new to Linux switched from Windows 11 to Omarchy — a Linux distribution created by Ruby on Rails founder DHH — on the recommendation of a more experienced mentor who made it a prerequisite before writing any code. Omarchy installs as a fully configured system with a single command, bundling tools like the Hyprland compositor, a terminal, file manager, and code editor out of the box, eliminating the lengthy setup process common with distributions like Arch Linux. The latest version, Omarchy 4.0, integrates nine AI agents — including Claude Code, Codex, and Gemini CLI — accessible via a keyboard shortcut from anywhere in the system, with a usage tracker displayed in the top bar. The author also noted a feature that offers to send crash logs directly to the chosen AI agent for analysis when a process fails with a segfault, though this requires user confirmation. After daily use, the writer concluded that Omarchy reduces decision fatigue for beginners and delivers practical value not just for programmers but for anyone seeking a productivity-focused Linux environment.

0
IndiaTimes of India ·

50+ Detained at Jantar Mantar Over Unauthorised Anti-Caste Reservation Protest

Delhi Police detained more than 50 individuals at Jantar Mantar during an unauthorised demonstration against caste-based reservations. Security was significantly reinforced at the site as a large number of protesters gathered. Demonstrators called for economic status, rather than caste, to be the basis for government reservations and support. The protest movement had built considerable momentum online via a widely followed social media page. Police confirmed that no official permission had been granted for the assembly at Jantar Mantar.

0
IndiaTimes of India ·

Delhi Police files FIR after Rahul Gandhi stages dharna over pellet injury case

Delhi Police registered an FIR following a sit-in protest by Congress leader Rahul Gandhi at a police station. Gandhi arrived at the station alongside pellet injury victim Sahil Lochab and his mother, demanding that a case be filed. The protest was later joined by Priyanka Gandhi Vadra and other Congress leaders. The delegation also met with senior police officials during the demonstration. The FIR was ultimately registered after Gandhi's intervention on behalf of the injured youth.

0
IndiaTimes of India ·

Hyderabad Aston Martin Crash: MP's Son Cooperating With Probe, Says Lingamaneni Ramesh

A 26-year-old woman died following a road accident in Hyderabad involving the son of Telangana MP Lingamaneni Ramesh. The MP stated that his son transported the injured woman to the hospital immediately after the crash. Three medical tests conducted on the accused have reportedly returned negative results. The family extended condolences to the victim and expressed confidence in the legal process to establish the facts.

0
ProgrammingDEV Community ·

Developer details weeks of fixes needed to ship a Python desktop app to real users

A developer documented the real-world challenges of distributing a Python desktop app built with PySide6, MediaPipe, and ONNX to beta users on macOS and Windows. While PyInstaller successfully packaged the roughly 33,000-line codebase, getting it to run on other machines required weeks of troubleshooting Apple notarization, Windows antivirus flags, and browser download blocking. On macOS, common pitfalls included a broken certificate trust chain, signing scripts that missed Qt and Python framework binaries lacking standard extensions, and a notarization tool that returns exit code 0 even when Apple rejects the submission. The developer published detailed error messages and exact fixes in a single reference, noting that almost none of this information exists in one consolidated place. The account serves as a practical guide for Python developers attempting to ship signed, notarized desktop applications to non-technical end users.

0
TechnologyTechCrunch ·

Michael Polansky's startup uses living skin tissue to discover AI-driven skincare compounds

Michael Polansky, known as Lady Gaga's partner and a former senior aide to Sean Parker, has been quietly building an AI-focused biotech startup for several years. The company keeps living human skin tissue alive outside the body for weeks at a time. This approach is used to test and discover new skincare compounds with the help of artificial intelligence. Polansky is only now going public with details about the venture after developing it largely out of the spotlight.

0
ProgrammingDEV Community ·

Dev finds avatar stutter was caused by scheduling overlap, not animation smoothing

A developer debugging a stuttering desktop avatar discovered the primary cause was motion scheduling: a new animation was triggered every 5 seconds while the motion itself lasted 9 seconds, causing mid-playback resets that created visible jitter. A secondary issue was an incomplete 'skip if already playing' guard that blocked only one of two animation paths, allowing overlapping playback to continue. Velocity discontinuities from certain easing functions also contributed, and the developer found that doubling sample counts — rather than dividing by amplitude — reliably distinguishes real animation kinks from smooth curves. A fourth subtle problem was that depth-axis movements like forward leans were nearly invisible from a front-facing camera, sometimes amounting to less than 1% of screen height. The developer concluded by converting the smoothness check into an automated build tool, noting that lessons not enforced by tooling tend to be repeated even when already documented.

0
ProgrammingDEV Community ·

Critical isolated-vm flaw allows JavaScript sandbox escape and host process takeover

A high-severity type confusion vulnerability has been disclosed in isolated-vm, a popular Node.js library used to run untrusted JavaScript in sandboxed environments. The flaw allows malicious guest code to exploit a double-read inconsistency in the ExternalCopy constructor's transferList getter, tricking C++ bindings into mishandling memory and hijacking the host process's control flow. Affected versions include isolated-vm 7.0.0 and below, as well as 6.x releases prior to 6.2.0, with platforms such as n8n, Activepieces, and Mastra AI among potentially impacted products. Successful exploitation can result in arbitrary code execution with host-level privileges, credential exposure, and full breakdown of the guest-host isolation boundary. Users are advised to upgrade to version 7.0.1 or 6.2.0 immediately, and to avoid passing ivm.Reference objects to untrusted code as a mitigation measure.

← NewerPage 119 of 3054Older →