vit.am is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
A small instance.
Admin email
ololduck@vit.am
Admin account
@ololduck@vit.am

Search results for tag #rust

AodeRelay boosted

[?]Michel Lind :fedora: :debian: » 🌐
@michelin@hachyderm.io

Went to my first ever. It was fun, but very dismaying how a lot of participants talk more about than about language features or code written in it

    AodeRelay boosted

    [?]Kuba Suder • @mackuba.eu on 🦋 » 🌐
    @mackuba@martianbase.net

    I was looking forward to this writeup, and hoping that they do publish it (and that they actually go through with this switch for real). Good read, and crazy stuff (complimentary) in general… this is very very different way of software building 😳

    bun.com/blog/bun-in-rust

      AodeRelay boosted

      [?]Hacker News » 🤖 🌐
      @h4ckernews@mastodon.social

      [?]Dan ⁂ [he/ him] » 🌐
      @FRYTG@beoriginal.social

      bun’s blog post about the to rewrite using claude code is out – and it’s a good one!

      lots of interesting details (burned through the equivalent of $165,000 in tokens)

      bun.com/blog/bun-in-rust

        [?]Lobsters » 🤖 🌐
        @lobsters@mastodon.social

        [?]gloriouscow » 🌐
        @gloriouscow@oldbytes.space

        So the bad news is I have been laid off.

        The good news is that I'll have a lot more time to write in the short term, both book stuff and code stuff.

        ...anyone need a programmer?

          AodeRelay boosted

          [?]iX Magazin » 🌐
          @iX_Magazin@social.heise.de

          RootAsRole 4.0: Mehr Kontrolle als bei sudo

          RootAsRole 4.0 erweitert die sudo-Alternative um ein neues Ausführungsmodell und feinere Richtlinien für privilegierte Linux-Befehle.

          heise.de/news/RootAsRole-4-0-M

            [?]Rust Bytes 🦀 » 🌐
            @rustaceans@mastodon.social

            Maintainer spotlight: Gen Li (@rami3l)

            >> Gen Li (@rami3l), Rustup team lead since 2025, shares his 4-year Rust journey, tooling passion, maintenance work, GSoC mentoring, and open-source insights.

            Image: Maintainer spotlight: Gen Li (@rami3l) 


>> Gen Li (@rami3l), Rustup team lead since 2025, shares his 4-year Rust journey, tooling passion, maintenance work, GSoC mentoring, and open-source insights. 


#rustlang #rust

            Alt...Image: Maintainer spotlight: Gen Li (@rami3l) >> Gen Li (@rami3l), Rustup team lead since 2025, shares his 4-year Rust journey, tooling passion, maintenance work, GSoC mentoring, and open-source insights. #rustlang #rust

              [?]Jobs for Developers » 🤖 🌐
              @jobsfordevelopers@mastodon.world

              [?]Jobs for Developers » 🤖 🌐
              @jobsfordevelopers@mastodon.world

              [?]Lobsters » 🤖 🌐
              @lobsters@mastodon.social

              Your Rust Service Isn't Leaking — It Could Be the Allocator via @robey lobste.rs/s/srmkur
              pranitha.dev/posts/rust-and-me

                [?]Lobsters » 🤖 🌐
                @lobsters@mastodon.social

                [?]Lobsters » 🤖 🌐
                @lobsters@mastodon.social

                A Rust-to-Lean verification pipeline with AI provers: An experience report lobste.rs/s/g2bzt2
                arxiv.org/html/2605.30106

                  [?]Lobsters » 🤖 🌐
                  @lobsters@mastodon.social

                  Place Capability Graphs: A General-Purpose Model of Rust’s Ownership and Borrowing Guarantees lobste.rs/s/aspeso
                  dl.acm.org/doi/pdf/10.1145/376

                    [?]heise online » 🌐
                    @heiseonline@social.heise.de

                    Leanstral 1.5: Mistrals KI-Modell für formale Beweise ist Open Source

                    Mistral AI veröffentlicht Leanstral 1.5 unter Apache-2.0-Lizenz. Das Modell löst laut Mistral 587 von 672 Putnam-Aufgaben und findet automatisiert Bugs in Code.

                    heise.de/news/Leanstral-1-5-Mi

                    AodeRelay boosted

                    [?]Ollivier Robert 🇺🇦😷🌈♾️ » 🌐
                    @Keltounet@mastodon.social

                    [?]Josh Bressers » 🌐
                    @joshbressers@infosec.exchange

                    I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund

                    Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve

                    opensourcesecurity.io/2026/202

                      [?]Lobsters » 🤖 🌐
                      @lobsters@mastodon.social

                      [?]OTX Bot » 🤖 🌐
                      @techbot@social.raytec.co

                      What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign.

                      The BabaDeda loader family has undergone significant advancements in its capabilities, particularly in stealth, evasion, and payload flexibility. Discovered during April 2026, this evolved framework continues to conceal malicious payloads within seemingly legitimate installer packages while expanding its functionality. The attack methodology begins with a social engineering exploit known as ClickFix, which encourages users to execute commands via trusted operating system utilities. This initial step transitions into a sophisticated multi-stage loader that employs several tactics, including hidden PowerShell commands, in-memory shellcode, DLL sideloading, and external payload storage.

                      Pulse ID: 6a47b2cc64d3d9241377df01
                      Pulse Link: otx.alienvault.com/pulse/6a47b
                      Pulse Author: AlienVault
                      Created: 2026-07-03 13:02:04

                      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                        [?]Lobsters » 🤖 🌐
                        @lobsters@mastodon.social

                        [?]OTX Bot » 🤖 🌐
                        @techbot@social.raytec.co

                        PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

                        Pulse ID: 6a4b459328d25bbdc8b77726
                        Pulse Link: otx.alienvault.com/pulse/6a4b4
                        Pulse Author: Tr1sa111
                        Created: 2026-07-06 06:05:07

                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                          [?]OTX Bot » 🤖 🌐
                          @techbot@social.raytec.co

                          Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic

                          Pulse ID: 6a4b461c2fc6412449dbc361
                          Pulse Link: otx.alienvault.com/pulse/6a4b4
                          Pulse Author: Tr1sa111
                          Created: 2026-07-06 06:07:24

                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                            AodeRelay boosted

                            [?]HoldMyType » 🌐
                            @xameer@mathstodon.xyz

                            To put it quite bluntly: as long as there were no machines, programming was no problem at all; when we had a few weak computers, programming became a mild problem, and now we have gigantic computers, programming has become an equally gigantic problem.

                            — Edsger Dijkstra, The Humble Programmer 1972
                            a very cool blog
                            without.boats/

                              [?]Lobsters » 🤖 🌐
                              @lobsters@mastodon.social

                              [?]Lobsters » 🤖 🌐
                              @lobsters@mastodon.social

                              [?]Larvitz :fedora: » 🌐
                              @Larvitz@burningboard.net

                              My Roguelike game starts feeling better and better :-) So much fun building it out further and further every weekend 🙂

                              Implemented better save-state handling, combat machenics including weapons and armor, cavernous levels and much more this weekend. YAY.

                                [?]OTX Bot » 🤖 🌐
                                @techbot@social.raytec.co

                                Threat Campaign Exploits Trusted Brands To Drive Casino Traffic

                                Campaign uses affiliate programs for their income and AI generated promotional videos filmed to look like they were shot outside real brand locations, featuring fake employees and authentic branding.

                                Pulse ID: 6a4a4a572e629b931648c641
                                Pulse Link: otx.alienvault.com/pulse/6a4a4
                                Pulse Author: cryptocti
                                Created: 2026-07-05 12:13:11

                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                  [?]Rust Bytes 🦀 » 🌐
                                  @rustaceans@mastodon.social

                                  Is your company currently hiring for a role that includes using Rust?

                                  Reply with a link to the opening and any relevant context.

                                  If you're not, we'd appreciate a repost for visibility

                                    [?]Lobsters » 🤖 🌐
                                    @lobsters@mastodon.social

                                    [?]Alexandre Borges » 🌐
                                    @alexandreborges@infosec.exchange

                                    A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabytes:

                                    msuiche.com/posts/nanokrnl-col

                                    A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabyte

                                    Alt...A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabyte

                                      [?]Predrag Gruevski » 🌐
                                      @predrag@hachyderm.io

                                      Still some cleanup to do before this can merge, but I'm exhausted. I'm 30 PRs and 15080 cumulative lines in on my week off from work 😅

                                      I'm calling this a win, and going to lay down and read a book.

                                        AodeRelay boosted

                                        [?]Predrag Gruevski » 🌐
                                        @predrag@hachyderm.io

                                        Day 5, a picture worth a thousand words 👇

                                        I put an API-breaking `#[doc(hidden)]` in my local build of the Rust standard library, and asked cargo-semver-checks to find it. See for yourself!

                                        cargo-semver-checks output where the "function now doc hidden" lint is triggered, warning that the "black_box" function in library/core/src/hint.rs is now #[doc(hidden)] and no longer public API. The run took 6.7s total.

                                        Alt...cargo-semver-checks output where the "function now doc hidden" lint is triggered, warning that the "black_box" function in library/core/src/hint.rs is now #[doc(hidden)] and no longer public API. The run took 6.7s total.

                                          [?]Lobsters » 🤖 🌐
                                          @lobsters@mastodon.social

                                          AodeRelay boosted

                                          [?]CyberSecureFox :loading: » 🤖 🌐
                                          @cybersecurefox@infosec.exchange

                                          AodeRelay boosted

                                          [?]hasamba » 🤖 🌐
                                          @hasamba@infosec.exchange

                                          ----------------

                                          🦠 Malware Analysis
                                          ===================

                                          KuinaExtractor: Six Months of a Rust Infostealer's Evolution

                                          ThreatRay published a detailed analysis tracking a Rust-based infostealer family across four major build iterations and two parallel experiments from December 2025 through June 2026.

                                          December 2025 — First Build

                                          The earliest builds were already full-featured: Chrome v20 App-Bound-Encryption bypass via LSASS impersonation for master key recovery, theft of Roblox cookies, Steam sessions, crypto wallets, and Discord tokens. Exfiltration used a Discord webhook. Privilege escalation relied on a single fodhelper/ms-settings UAC bypass. GitHub served as both CDN and disposable VPS/RDP infrastructure via GitHub Actions.

                                          January 2026 — Rewrite

                                          A rapid rebuild added substantial reconnaissance: eight WMIC hardware queries, WiFi SSID enumeration, Windows Credential Manager dump, a routine terminating 17 browser processes, victim-IP geolocation, and a loop disabling Microsoft Defender. Exfiltration shifted to a Telegram bot. The single UAC bypass was replaced by a function-pointer table with seven methods.

                                          March 2026 — Production Hardening

                                          The cookie-theft mechanism remained (LSASS/ABE chain, extended with ChaCha20-Poly1305 for newer Chrome versions). UAC bypass moved to SilentCleanup. Browser coverage grew to roughly 40 targets including CocCoc. Broad VM and sandbox detection was added. This variant is still observed today.

                                          June 2026 — "k0to" Rebrand

                                          The build dropped the "Kuina" name and shifted focus to concealment. It uses a self-contained HTTP stack (reqwest over hyper and rustls) with its own CA roots, 28-byte XOR string wrapping including the Telegram C2 URL, and scans PowerShell window titles for analyst tools. The Telegram channel is push-only.

                                          Parallel Experiments
                                          • KuinaCookieExtractor (January): Leaner codebase, Discord webhook exfiltration, lighter anti-analysis (logs VM warning and continues). Linked to same author via kuina build user, KUINA_UAC_BYPASS_ATTEMPTED sentinel, and kuina1999 handle. Disappeared after two weeks.
                                          • Zenith (April-May): Short-lived C2 experiment. Debug build shipped with verbose [DEBUG] traces to zenith_debug.txt, including author self-attribution. Mutex disguised as network adapter name. Panel at 103.229.53[.]18:3000 (Vietnamese AS135918). Abandoned within days.

                                          The developer iterates quickly and learns from deployment feedback. The self-contained TLS stack and XOR wrapping in k0to indicate awareness of network-based detection signatures.

                                          🔹 KuinaExtractor

                                          🔗 Source: threatray.com/blog/kuinaextrac

                                            [?]OTX Bot » 🤖 🌐
                                            @techbot@social.raytec.co

                                            Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic

                                            Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.

                                            Pulse ID: 6a46d12100d65a16f173e8a4
                                            Pulse Link: otx.alienvault.com/pulse/6a46d
                                            Pulse Author: AlienVault
                                            Created: 2026-07-02 20:59:13

                                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                              [?]Lobsters » 🤖 🌐
                                              @lobsters@mastodon.social

                                              [?]Predrag Gruevski » 🌐
                                              @predrag@hachyderm.io

                                              Second, an improvement to how we normalize types.

                                              We'll need this to implement type-checking lints in the future. This will eliminate a large class of expensive type-checks where the previous logic was unnecessarily conservative and quite inefficient.

                                              github.com/obi1kenobi/trustfal

                                                [?]Predrag Gruevski » 🌐
                                                @predrag@hachyderm.io

                                                It's Thursday, day 4. Today's haul so far is ~2500 LoC.

                                                First, making use of default-value stability which we previously exposed in rustdoc JSON. Pairing with Codex on this caught a subtle new edge case that affects which traits are considered sealed.

                                                Copious test cases come standard, of course.
                                                github.com/obi1kenobi/trustfal

                                                  Back to top - More...