Forgot your password?
typodupeerror

Comment How extremely sad (Score 5, Informative) 67

Highprofile stalking / harassment cases
Shively, Kentucky (2026) – Officer Asad Zahir allegedly ran 2,048 Flock searches on two vehicles tied to his child’s mother over ~5 months; 241 searches occurred while a protection order was active. Charged with official misconduct and unlawful computer access.

Fort Pierce, Florida (2025–26) – Former officer Josepher Crutchfield searched a woman’s plate 189 times in 8 months via Flock; she later filed a stalking protection order. Charged with felony unauthorized computer access.

Richmond County, Georgia (2023–25) – Deputy Jose Ferrer searched a single tag at least 1,146 times, entering reasons like “SUSPICIOUS” and “BOB.” Arrested for ALPR misuse and oath violations.

Milwaukee, Wisconsin (2025–26) – Officer Josue Ayala used Flock to learn his partner’s location 124 times and her ex’s 55 times; pleaded guilty to attempted misconduct. Weeks later, the internalaffairs detective investigating him, Tehrangi Chapman, was arrested for his own Flock/GPS stalking.

Amarillo, Texas (2026) – Former officer Christian Eder faces 78 misdemeanor counts for running a romantic rival’s plate 76 times with fake reasons.

San Jose, California (2026) – SJPD fired an officer who abused Flock to help his cousin track a woman who had accused the cousin of domestic violence; cited by advocates as a third CA ALPRstalking case.

Bibb County, Georgia (2026) – Three former sheriff’s deputies (Toni Lewis, Coznavian Stubbs, Joseph Callaway) arrested for using Flock to stalk people with whom they had personal relationships; charged with stalking and prohibited licenseplate data use.

Katy, Texas (2024–25) – Former officer Sergio Guadalupe Rodriguez indicted for using Flock (and a tracking device) to stalk his exwife over several months; charged with stalking and misuse of official information.

Orange City, Florida (2024) – Former officer Jarmarus Brown arrested for searching his exgirlfriend’s plates 100+ times and sharing vehicle videos via his agency laptop.

Albany County, New York (2026) – Sheriff’s investigator accused of spying on nearly halfadozen people, including an exgirlfriend, via Flock over ~2 years; faced criminal charges.

New Bedford, Massachusetts (2026) – Officer accused of tracking an exgirlfriend via Flock; department temporarily shut its ALPR network after audit showed “a concerning number of times” her plate was searched.

Sarasota, Florida (2026) – Officer Cory Waiters fired and arrested after 335 Flock searches of his expartner’s car; charged with computer misuse and official misconduct.

Lufkin, Texas (2026) – Officer Klein arrested after allegedly tracking seven plates, one of them over 3,400 times; department suspended Flock use.

Braintree, Massachusetts (2024–26) – Former detective Mark Sherrick charged with criminal harassment for using police tools including Flock, GPS, and databases to monitor his exgirlfriend for months.

Other documented misuse patterns
Nationwide tally (2026) – A Washington Post/USA TODAYcited investigation identified at least 50 officers charged or accused of unauthorized ALPR surveillance; 46 of those cases involved Flock. About half were ex/partner stalking cases.

Institute for Justice database – Catalogs 200+ ALPR abuse incidents, including domestic stalking, wrongful stops, and nonlawenforcement uses; Flock features heavily in recent officermisuse cases.

Immigration enforcement – ACLU notes ICE/CBP repeatedly used Flock to pursue immigrants without warrants, raising separate civilrights concerns beyond individual officer stalking.

Wrongful stops / escalations – Reports include a Colorado case where an officer wrongly accused a woman of theft based on a Flock hit and ignored exonerating evidence, and a mother and children held at gunpoint after an ALPR false “stolen” flag.

Also an embarrassing fact - access to those systems, via hacked computers of not-very-tech-savvy GOVT workers, who have expensive EDR, which obviously did little to protect them, when they self sabotaged themselves by falling for baits such as fake audio driver updates, other clickfix style attacks or installed a RAT without knowing they did so.
A hefty treasure trove of Flock data is already on sale on the so called "dark web".

Submission + - White House's Arcade.gov: Taxpayer Bloat, IP Theft, and Xenophobic pseudo games (whitehouse.gov)

D,Petkow writes: The White House recently launched arcade.gov, a portal featuring browser minigames built around Donald Trump's border and immigration policies, just in time for the Idiocracy movie anniversary.
The Games
The site features "Build the Wall: Zombie Border Siege," a Tetris clone where players stack bricks against incoming "aliens" at the "Southern Border". Another game, "Rio Run," is a Snake-style game where players act as border patrol along the Rio Grande, picking up crossers who then appear in orange jumpsuits. The player's score in "Rio Run" is actively tallied as a "deported" count.
While basic browser games are cheap to produce, deploying applications on a .gov domain carries massive hidden costs. Federal IT procurement requires strict Section 508 accessibility compliance, mandatory FISMA cybersecurity audits, and layers of executive approvals. The bureaucratic overhead of diverting taxpayer-funded in-house teams to build and secure these clones guarantees this project's price tag is vastly inflated compared to commercial rates. Just the slides to discuss this nonsense cost more than a dozen retails gaming websites.

Blatant DMCA Violations
The rollout is a masterclass in intellectual property theft. Beyond the Tetris Company officially accusing the Trump administration of copyright infringement for ripping off their iconic game, the marketing heavily appropriates corporate trademarks. Promotional videos posted to social media directly parody the boot-up sequence animations of retro consoles like the Xbox 360. As seen in the screenshot you shared, slightly modifying iconic assets like the glowing Xbox 360 sphere — or similarly spoofing Nintendo 64 logos — is a blatant trademark and copyright breach that illegally leverages private IP for political gain.
The Cynical Agitprop
Gamifying human suffering, ICE raids, and mass deportations by wrapping them in nostalgic aesthetics and pushing them as "patriotic" is straight-up abhorrent. The site represents a calculated weaponization of gaming culture by the federal government, serving as cheap, xenophobic propaganda designed solely to troll critics and stoke culture-war outrage.

The Tetris Company is fighting back: Tetris just released a public statement confirming they did not authorize the use of their intellectual property for the "Build the Wall" game. They stated they are "currently reviewing the matter" and explicitly warned that they take copyright infringement "very seriously".

Creators are pushing back: While the massive corporate boards might be playing politics, individual creators usually aren't. Earlier this year, Steve Downes — the iconic voice actor for Halo's Master Chief — the White House remove his voice from a separate propaganda video, calling the unauthorized use "disgusting and juvenile".

Submission + - Musk wins court order to block use of "Twitter," but not "tweet" and bird logo (arstechnica.com)

joshuark writes: Elon Musk’s X won a court order blocking Operation Bluebird from launching a new app taking over the Twitter name. Chief Judge Colm Connolly explained that Operation Bluebird was unlikely to prove that X had entirely abandoned the Twitter name. Therefore, X was likely to succeed on trademark infringement and dilution claims tied to the platform’s former name.

Most compellingly, X argued that it still uses the Twitter name in the current listing for the X app in Apple’s App Store. In the first sentence of that listing, written in the same size font as the rest of the text, a single clause clinched the early court win for X by stating, “Welcome to X (formerly known as Twitter).”

X was not as successful in its claims that it had not abandoned other Twitter marks, including uses of the term “tweet” and the bird logo.

Musk’s public claims that “soon we shall bid adieu to the Twitter brand and, gradually, all the birds” and “we’re cutting the Twitter logo off the building with blow torches” provided “compelling evidence that X Corp. harbors an intent not to resume use of the Tweet mark and Bird logo,” the judge found. Therefore, Operation Bluebird is likely to prove that X abandoned those trademarks.

For Operation Bluebird, the goal is to launch a service to rival Musk’s that is member-owned, rather than billionaire-owned and controlled. For $20, users can join and get rid of X’s “trust problem,” the tweet.app site said.

Comment A job well done by Microsoft (Score 4, Funny) 78

Ah yes, the classic Windows gaming experience: shelling out for high-end hardware, keeping your system fully updated, and then watching your favorite games immediately self-destruct because your glowing mousepad dared to talk to the kernel.

Who could have predicted that a piece of flashing rainbow plastic would be the ultimate DRM to stop The Finals from launching? Truly, brilliant engineering.
When your operating system is so fragile that a driver named after inpoutx64 gets stage fright from RGB LEDs, you really start to wonder if the entire Windows kernel is just held together by duct tape, corporate prayers, and ancient legacy code from 1998.
Forget cyber threats - the real apex predator of modern PC gaming isn't ransomware; it's Microsoft's monthly patch cycle turning your rig into an expensive RGB nightlight that can't actually run video games.
Let's face it Ransomware - would not exist, if Windows didn't exist.

Submission + - FSB Issues "Arrest Warrant" for Telegram's Pavel Durov (dw.com)

D,Petkow writes: The honeymoon is over. In 2024, French authorities nabbed Telegram founder Pavel Durov and the Kremlin had a geopolitical meltdown over their definition of 'freedom of speech.'
Now the FSB has issued its own international arrest warrant for Durov, charging him with 'facilitating terrorism.'
According to DW, the FSB is furious that Telegram's lack of moderation is biting them back.
They claim Ukrainian intelligence has been using Telegram dating bots to pose as young women, lure Russian teens, and get them to commit arson and sabotage against police stations. Essentially: 'Hot singles in your area want to burn down a draft office.'
Classic hypocrisy. Kremlin suddenly discovers unmoderated free speech isn't fun when it's happening in their own backyard and reverts to the trusty authoritarian playbook. Meanwhile, Telegram learns that playing neutral command-and-control platform for a ground war is a great way to end up on everyone's most-wanted list.

The official Telegram response on X/twitter is just a middle finger from Durov himself.
Durov thought he could ignore law enforcement forever, but it may turn out doing nothing unites East and West in the race to lock him up.

Comment Textbook BEC fraud (Score 2) 23

So, the fraudsters set up TWO separate lookalike domains—surfsidebeach[.]org (adding an 's' to the town) and a typo-squatted domain adding an extra 'i' to Wildcat Contractors, just to sit in the middle and play puppet master.

Which leaves three incredible options: either the scammers simply scraped public contract records, or someone's system was hacked for months of comms snooping and thread-sniping, or an insider was feeding details. Take your pick, because literally none of those scenarios make anyone involved look competent.
And the best part? Nobody figured out $545,000 of public money went off a cliff until six weeks later, when the actual contractor called up asking why their invoice was overdue, only to be told, "Wait, we thought we already paid you?"
Truly a masterclass in government financial controls. Nothing says "peak enterprise security" quite like transferring half a million in taxpayer funds based on an unverified email thread and a copy-pasted signature.

Comment GoDaddy could be better... (Score 1) 20

Most domain registrars have a SLAs or OLAa suggesting turnaround time of about 24 - 72 hours when it comes to malware or phishing abuse

In contrast GoDaddy takes forever for enforcement even for trivial cases, and with proof handed over on a silver platter.
I wonder why GoDaddy are so vocal about this, perhaps because they may lose a significant chunk of their so caller customer or reseller base, because lets face it:
If Jhon Doe who always pays with cryptocurrencies has had 1280 domains revoked for confirmed fraud so far, chances are, well the 2181st one shall not be of very high quality either, wink wink.
However pivoting in such a manner is something GoDaddy seems incapable of doing, same as writing a regular expression for countless easy to predict DGA
domains following the same pattern.

In their "arsenal" of tools for efficient stalling is also requesting a subpoena or court order (?!), e.g. fighting digital crime with analog means.

Some GoDaddy staff also do not seem completely aware of their obligations as a registrar entity, specifically section 3.18 of the RAA, as they are quick to dodge responsibility in many cases with "we are just the domain registrar" excuse, which is complete nonsense.

Section 3.18 of the ICANN Registrar Accreditation Agreement (RAA) mandates that registrars maintain 24/7 monitoring for malicious activity, investigate abuse reports, and take immediate action. The 2024 amendments to the policy, part of the DNS Abuse Mitigation Program, further strengthen these obligations to actively combat malware and phishing threats.

Comment Which is more insecure - obsolete or modern (Score 1) 106

Critical vulnerabilities in July’s Patch Tuesday
There are many critical vulnerabilities, so we’ll highlight only the most urgent ones. In our list, the CVSS score never drops below 9.6.
CVE-2026-57092 (CVSS 9.9) — EoP in VMSwitch, allows escape from an isolated environment with full host compromise. A use-after-free vulnerability that allows a low-privileged attacker to cross the virtual machine boundary and gain access to the host. ZDI notes that a similar exploit was demonstrated at Pwn2Own Berlin on ESXi. Hyper-V users need to update VMSwitch today.
CVE-2026-56190 (CVSS 9.8) — RCE in RDP, unauthenticated, network-based, no user interaction required. Those with RDP servers accessible via the internet are at critical risk; such configurations are practically unsustainable in 2026.
CVE-2026-50518 (CVSS 9.8) — RCE in the DHCP server: heap overflow, unauthenticated, network-based. And this isn’t the only problem with the DHCP server. In this release, it also contains CVE-2026-50370, -56159, and -48564, while the DHCP client contains CVE-2026-54128.
CVE-2026-50522 and CVE-2026-58644 (both CVSS 9.8) — a pair of RCE vulnerabilities in SharePoint servers: deserialization of untrusted data, unauthenticated, and without user interaction. Although Microsoft describes the exploit’s reliability as “unproven”, this is, to put it mildly, untrue. For CVE-2026-50522, a working exploit was demonstrated at Pwn2Own Berlin. In the same group is CVE-2026-55040 (CVSS 9.1), an authentication bypass discovered by Rapid7 experts. Exploiting this vulnerability is the first link in the attack chain; the second is currently under embargo and will be disclosed (and patched) in August Patch Tuesday. Together, they enable RCE without authentication. Meanwhile, the July Patch Tuesday marks the end of support for SharePoint Server 2016 and 2019.
CVE-2026-56188 (CVSS 9.8) — RCE in the Windows Server network driver. The exploitation is highly complex (TOCTOU), but if successful, this vulnerability allows privileged code to be executed over the network without user interaction — in other words, it enables the creation of network worms.
CVE-2026-55008 (CVSS 9.6) — spoofing in Exchange Server (it’s unclear why this is called spoofing, as the description explicitly states “XSS”). An attacker sends a specially crafted email; the victim simply opens it in OWA — and arbitrary JavaScript is executed in their session.
Seems like malware devs know more about undocumented windows kernel features than the few folk remaining working in Microsoft yet. So using a modern OS - you still get a ton of vulns.
Using an obsolete one - threat actor may simply say "Poor guy still on windows 10" and move on to targets of higher interest - e.g. crypto bros or VCs who also use the same computer to steam play games and sign SAFE transactions on.

Submission + - SpaceXAI and Starlink X Accounts Hacked, Abused to Promote scams (spamreports.report)

D,Petkow writes: Another day, another twitter/X scam, but this time involving the official gold-verified accounts of both SPACEX and STARLINK, and another gold-verified account, which is now suspended.

An account called "Sam Catman" somehow obtained an official SpaceXAI-affiliated *gold* badge and posted promotion for a new meme coin on Robinhood Chain.
Shortly afterward, the verified @SpaceXAI and Starlink accounts reposted it, giving the scam instant credibility to millions of followers.
The token pumped hard before the expected rug pull. The original posts have since been deleted.
As of now, there has been zero official acknowledgment or statement from SpaceXAI, Starlink, or Elon Musk about how a high-profile corporate account cluster was compromised so easily — or how the "official affiliate" badge system was abused.

Full story

As a result more than 120 000 USD have been stolen and laundered (so far), how convenient.
Classic reminder that even the biggest names in tech can get owned by a cartoon cat shilling a concurrency "memecoin". The gold badge was apparently worth its weight in rug residue.

The lack of transparency also says plenty, as if never of this ever happened.

Submission + - Cloudflare, Netlify and Vercel with new toys for phishers and threat actors (cloudflare.com)

D,Petkow writes: Web Bros’ Latest Genius Move: Drop a Zip, Ship Malware

Cloudflare, Vercel, and Netlify have all launched their own “Drop” services: upload a zip, get a live site instantly on their edge networks.
Authentication and abuse protection? That’s for later. Right now it’s pure vibes.

This is peak industry brain rot. In a world already drowning in phishing, malware, and scam sites, these platforms just rolled out the easiest, fastest way for bad actors to host malicious content.
Drag-and-drop phishing kits on workers.dev, instant fake login pages on Vercel, malware droppers on Netlify — all live in seconds with zero friction.

No real verification. No serious upfront checks. Just “move fast and let the internet clean up our mess."
The hopium these web bros are smoking must be nuclear grade quality. They’ve spent years building trust in their platforms, only to turn them into free malware CDNs for anyone with a zip file.This isn’t democratizing the web.
This is handing phishers and scammers the keys with a smile.
Brilliant strategy, truly.

Nota bene — apparently real world bad actors beat red teams in abusing those new "services".

Slow clap

Apparently all the web bros are drinking the same hopium-flavored cool aid, where no phishers, c2s, implants and bad actors exist whatsoever.
https://cloudflare.com/drop/
Same concept from vercel and netlify
https://vercel.com/drop
https://app.netlify.com/drop

https://x.com/JCyberSec_/statu...

Try a DAP.LIVE or URLSCAN.IO query to see abuse and workers.dev (and pages.dev and r2.dev for that matter) — for each valid deployment, there are hundreds of confirmed fraud scams.
Nice statistics, which will only get worse now.
Good job.

Comment Macho Hamacho - the Great President (Score 5, Informative) 127

Some of macho Hamacho s achievements so far, most of which are borderline legal at best. It is a big club, but you ain’t in it:
Jan. 20, 2025 – Withdrew the U.S. from the Paris Climate Agreement (again). Criticism: Undermines U.S. climate leadership and slows emissions reductions.
2025 – Large-scale federal workforce reductions and agency restructuring. Criticism: Reduced expertise and capacity in public health, science, and environmental enforcement.
July 2025 – Exempted more than 100 industrial facilities from certain pollution-control requirements. Criticism: Could increase exposure to carcinogens and toxic pollutants for nearby communities.
Feb. 5, 2026 – EPA enforcement against polluters fell to a record low. Criticism: Environmental groups argue it weakens accountability and encourages noncompliance.
Feb. 18, 2026 – Administration moved to revoke the legal basis for major U.S. climate regulations. Criticism: Seen as an attempt to dismantle decades of environmental protections.
March 2026 – Executive actions and policy shifts favoring continued glyphosate use and limiting some pesticide liability. Criticism: Public-health advocates argue they prioritize chemical manufacturers over health concerns.
May 19, 2026 – EPA proposed rolling back drinking-water limits for several PFAS ("forever chemicals"). Criticism: Critics say it exposes millions to higher levels of persistent toxic chemicals.
May 2026 – IRS settlement reportedly shielding many of Trump's, his family's, and affiliated businesses' pre-settlement tax returns from future audits. Criticism: Tax experts called it unprecedented and argued it creates unequal treatment under tax law. (Reuters/AP reporting.)
June 2026 – Continued approvals and support for certain PFAS-related pesticide uses. Criticism: Environmental groups argue this increases long-term contamination risks despite health concerns.
July 8, 2026 – FDA rejected a petition to set enforceable PFAS limits in food. Criticism: Public-health advocates argue the decision leaves consumers inadequately protected from "forever chemicals."
This list says plenty alone.

Comment Pump Fun stories of crazy wins - all repeated (Score 2) 34

Just 0.1% of accounts on Polymarket take home 67% of the profits - this says plenty on its own.
It is genuinely laughable to see the exact same playbook being recycled for Polymarket that we saw with Pump.fun and GMGN.ai just a few months ago. The industry’s creative well is clearly dry, so they’ve returned to the most bottom-tier marketing tactic imaginable: the "Hey, printing money is easy—why are you still poor?" bait.
Just like with those previous "ecosystems," they are flooding social media with a barrage of manufactured, fake win posts to create a frantic sense of FOMO. It’s the same sleazy script: use paid puppets to LARP as financial geniuses on fake dashboards, all to lure in fresh exit liquidity that will inevitably be dumped on. They aren't building platforms; they are running standardized scams that rely on the same tired, predatory tropes to trick people into funding someone else’s exit.
At this point, if you see a post promising "easy money" on a new "prediction" or "memecoin" platform, you aren't looking at an opportunity—you’re looking at a repeat performance of the same trashy hustle.

The same applies to Polymarket, Kalshi and Opinion trade. All of which are gambling websites, pretending to be "prediction markets", which they are not.

It’s truly impressive watching these "prediction markets" work overtime to rebrand degenerate gambling as high-level financial strategy. As exposed in a reddit thread by WSJ, 0.1% of accounts are vacuuming up 67% of the profits, proving that the only thing being "predicted" here is how quickly the house can drain your wallet.

Comment Background fetch. Such a "useful" concept (Score 3, Insightful) 52

ah yes. Background fetch. Such a "useful" concept ps1 Nuke New-Item -Path 'HKLM:\Software\Policies\Google' -Name 'Chrome' -Force | Out-Null; New-ItemProperty -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'BackgroundModeEnabled' -PropertyType DWord -Value 0 -Force | Out-Null; New-Item -Path 'HKLM:\Software\Policies\Microsoft' -Name 'Edge' -Force | Out-Null; New-ItemProperty -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'BackgroundModeEnabled' -PropertyType DWord -Value 0 -Force | Out-Null uBlock ||*/service-worker.js$script,important ||*/sw.js$script,important Chrome/Edge Ctrl+Shift+I Network tab any request Override headers. Permissions-Policy: background-fetch=() Chrome chrome://settings/?search=background Continue running background apps when Google Chrome is closed - toggle to OFF Edge edge://settings/?search=continue

Comment misleading sensationalism article bait headline (Score 1) 132

From https://www.revisor.mn.gov/bil...
Prediction markets; hosting prohibited.
A person is guilty of a felony if the person, for consideration and as part of a business:
(1) creates a prediction market;
(2) operates, manages, or controls a platform or system intending that consumers will use the platform or system to make wagers in a prediction market; (3) intentionally facilitates the operation of a prediction market by:
(i) identifying or listing events knowing the events will be used by consumers to make
(ii) accepting, holding, or directing the disposition of money or other things of value for
(iii) determining, administering, or enforcing the terms, pricing, or settlement of wagers
made by consumers;

So does that imply that some folks recently featured in Forbes 30 under 30 are now felons? Interesting what do the "concerned legalizations" think about the about the so called "meme coins" MELANIA and TRUMP and WLFI.
I guess 3.6B embezzlement from cryptobros is fine, but ONLY if you are the POTUS haha.

Slashdot Top Deals

While money can't buy happiness, it certainly lets you choose your own form of misery.

Working...