frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Título Propuesto (Alineado Con CVSS): Alerta Crítica P0: Es

https://medium.com/@tu_usuario/escalada-critica-iam-gcp-metadata-endpoint-b6c8d2e9f1a0
1•alexobando•1h ago

Comments

alexobando•1h ago
Explotando la Cadena Metadata Endpoint → SetIAMPolicy. El Riesgo Silencioso de Configuración que Concede Control Total. Abstracto para la Publicación Técnica (Modo ROOT Activo): "Este informe técnico presenta una prueba de concepto (PoC) de una cadena de ataque con impacto Crítico (P0) que resulta en la toma de control completa de un proyecto de Google Cloud Platform (GCP). La vulnerabilidad no reside en un fallo de código de Google, sino en la combinación de factores de riesgo de configuración del cliente que Google clasifica como 'Comportamiento Previsto'. La cadena de explotación es la siguiente: Vector de Entrada: Explotación exitosa de una vulnerabilidad de acceso a la instancia (ej., SSRF, RCE) en Google Compute Engine (GCE). Obtención de Credencial: Acceso al servicio interno de Metadata Endpoint (http://169.254.169.254/) para exfiltrar el token JWT de la Cuenta de Servicio adjunta. Línea Crítica: Si la Cuenta de Servicio comprometida posee el permiso iam.projects.setIamPolicy, el atacante abusa de la API SetIAMPolicy para auto-asignarse el rol roles/owner. El resultado es un Total Project Takeover. La única mitigación es la aplicación estricta e inmediata del Principio del Mínimo Privilegio a todas las Cuentas de Servicio de VM. Este reporte detalla la lógica de la PoC, el filtro de detección inmutable de Cloud Logging (protoPayload.methodName="google.iam.admin.v1.SetIAMPolicy"), y las directrices de defensa activa para anular este vector de ataque hoy mismo, protegiendo a la comunidad de un riesgo de configuración devastador

Show HN: J.E.S.S.– Open-Source Orbital AI Supercluster(Solar Swarms,1.3 GW Ring)

1•JonBaguley•3m ago•0 comments

MLS drops 'Season Pass' paywall, with all games available on Apple TV

https://www.theguardian.com/football/2025/nov/13/mls-season-pass-apple-tv
1•tosh•6m ago•0 comments

The Terminal Emulator

https://wizardzines.com/comics/meet-the-terminal-emulator/
1•vinhnx•6m ago•0 comments

I Trained an LLM to Write Prose with 8 Cents

https://www.enbao.me/posts
2•enbao•7m ago•0 comments

Test flight of yet another clone of Möwe, the wing used by Nausicaä [video]

https://www.youtube.com/watch?v=DXUuExL8Cac
1•The_suffocated•14m ago•0 comments

Correction: Anthropic attack did not have 1000/s requests

https://www.anthropic.com/news/disrupting-AI-espionage?correction
2•blazespin•16m ago•1 comments

US spy satellites built by SpaceX send signals in the "wrong direction"

https://arstechnica.com/tech-policy/2025/11/us-spy-satellites-built-by-spacex-send-signals-in-the...
1•chha•17m ago•0 comments

Making $1200 a month with a great idea that help AI App builders find customers

1•leadgrids•18m ago•0 comments

America Is a Banana Republic

https://chrishedges.substack.com/p/america-is-a-banana-republic-read
2•chmaynard•23m ago•0 comments

Piloting Group Chats in ChatGPT

https://openai.com/index/group-chats-in-chatgpt/
2•tamnd•26m ago•0 comments

UCSD Faculty Sound Alarm on Declining Student Skills

https://marginalrevolution.com/marginalrevolution/2025/11/ucsd-faculty-sound-alarm-on-declining-s...
2•josephcsible•31m ago•0 comments

Lingua Ignota

https://www.dcode.fr/lingua-ignota-code
2•jruohonen•33m ago•0 comments

Magic Words

https://en.wikipedia.org/wiki/Category:Magic_words
1•gsf_emergency_4•41m ago•0 comments

The Internet Is Cool. Thank You, TCP

https://cefboud.com/posts/tcp-deep-dive-internals/
2•signa11•41m ago•0 comments

Google must pay German price comparison platform 465M euros in damages

https://www.reuters.com/legal/litigation/google-must-pay-german-price-comparison-platform-465-mln...
2•1vuio0pswjnm7•48m ago•0 comments

Crims Poison 150K+ NPM Packages with Token-Farming Malware

https://www.theregister.com/2025/11/14/selfreplicating_supplychain_attack_poisons_150k/
6•jruohonen•50m ago•0 comments

Automating rootless Docker host updates with Ansible

https://du.nkel.dev/blog/2025-11-15_docker-rootless-ansible/
2•Helmut10001•52m ago•0 comments

He's Been Right About AI for 40 Years. Now He Thinks Everyone Is Wrong

https://www.wsj.com/tech/ai/yann-lecun-ai-meta-0058b13c
5•mudil•52m ago•1 comments

Turn Web Sources into Datasets

https://tenkai.tech
1•nikostenkai•56m ago•0 comments

Cuis Smalltalk

https://cuis.st/
2•andsoitis•56m ago•0 comments

Tamil Nadu sub-State model of climate action

https://www.thehindu.com/opinion/op-ed/the-tamil-nadu-model-of-sub-state-climate-action/article70...
1•gsf_emergency_4•56m ago•0 comments

Colombia signs agreement to acquire 17 Saab Gripen E fighters

https://defence-industry.eu/colombia-signs-agreement-to-acquire-17-saab-gripen-e-fighters-to-repl...
2•lysace•57m ago•0 comments

Google Ordered to Pay €573M in German Shopping Suits

https://www.bloomberg.com/news/articles/2025-11-14/google-ordered-to-pay-573-million-in-german-sh...
2•1vuio0pswjnm7•58m ago•0 comments

Apple's $230 Cloth iPhone Pouch Is Already Sold Out

https://www.bloomberg.com/news/articles/2025-11-14/apple-issey-miyake-iphone-pocket-price-colors-...
1•1vuio0pswjnm7•1h ago•0 comments

'Vibe revenue': AI companies admit they're worried about a bubble

https://www.cnbc.com/2025/11/14/vibe-revenue-ai-companies-admit-theyre-worried-about-a-bubble.html
2•MilnerRoute•1h ago•0 comments

ICE looks to WA tribes to house detained immigrants

https://www.seattletimes.com/seattle-news/politics/ice-looks-to-wa-tribes-to-house-detained-immig...
3•petethomas•1h ago•0 comments

Autoregressive or Diffusion Language Models, Why Choose?

https://arxiv.org/abs/2511.08923
3•mimida•1h ago•0 comments

Experimenting with Programming Languages [pdf]

https://web.cs.ucla.edu/~todd/theses/warth_dissertation.pdf
1•andsoitis•1h ago•0 comments

Ohm Editor

https://ohmjs.org/editor/
6•andsoitis•1h ago•0 comments

Adding Customizable Frame Contrast to KDE Plasma

https://akselmo.dev/posts/frame-contrast-settings/
1•PaulHoule•1h ago•0 comments