vit.am is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
RustNet v1.6.0 is out 🎉
The TUI got a full restyle, plus theme presets (catppuccin-mocha, tokyo-night, gruvbox, nord) and an optional config file. Light terminal backgrounds are finally detected and handled properly.
Under the hood: passive DNS naming for connections without SNI, MAC vendor info for LAN devices, a gateway marker, and response times for DNS, NTP, STUN, ping and friends. Live TCP RTT too.
Unfortunately you sometimes need to do the thing https://lobste.rs/s/ry92nr #philosophy #programming #rust
https://griffinberlste.in/blog/do-the-thing/
Ruff. uv. Polars. Pydantic. Pyrefly. Granian.
Every one of them is written in Rust. The code that used to be C when Python needed speed is increasingly Rust.
Our new course, Up and Running with Rust, is the Python developer's fast track into that world. Every Rust idea is taught next to its Python equivalent: fn vs def, crates vs PyPI, Cargo vs uv, borrow checker vs GC.
You finish by building a Rust extension with PyO3 and calling it from Python.
https://training.talkpython.fm/courses/up-and-running-with-rust
rust-glancer: An alternative LSP for Rust with focus on low memory usage https://lobste.rs/s/am0xtj #rust
https://rust-glancer.github.io/blog/hello-world/
Enabling the next-generation trait solver on nightly | Rust Blog https://lobste.rs/s/3giezs #rust
https://blog.rust-lang.org/2026/08/21/enabling-next-solver-on-nightly/
A uutils coreutils vulnerability in stdbuf uses a world-writable libstdbuf.so via LD_PRELOAD, letting local users execute arbitrary code.
RE: https://infosec.exchange/@catsalad/117132993113278176
let cat = std::ptr::dangling(cat);
#RustCataStructures #rust #RustLang #cat #CatsOfMastodon #ProgrammingHumor #Caturday
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
RE: https://fosstodon.org/@opensuse/117132457275513433
It seems that it's possible to do something for Linux which is not in #rust.
The Rust-based backdoor observed in the supply chain compromise of the `arrayref` Rust crate has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#rust-based-backdoor-observed-in-supply-chain-compromise-of-arrayref-rust-crate
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #macOS #SupplyChain #arrayref
Announcing Rust 1.98.0 https://lobste.rs/s/hbjeir #release #rust
https://blog.rust-lang.org/2026/08/20/Rust-1.98.0/
BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer
In August 2026, an operator published forty typosquatted npm packages mimicking popular libraries like chalk, axios, commander, lodash, react, and typescript. Each package contained an install script that profiles the host and, when detecting Windows or WSL environments, downloads a 22MB Rust-based executable from GitHub. This payload runs entirely in memory without dropping files to disk, targeting cryptocurrency wallets, browser credentials, cookies, and Telegram sessions. The malware uses legitimate services for reconnaissance and exfiltration, making detection and takedown difficult. While npm packages were removed within 84 minutes, the GitHub-hosted payload remained active for an additional 39 hours, and the command-and-control server continued operating. The campaign specifically targets developers using WSL by crossing the boundary between Linux environments and underlying Windows systems.
Pulse ID: 6a8734846b4cc1afd4bde567
Pulse Link: https://otx.alienvault.com/pulse/6a8734846b4cc1afd4bde567
Pulse Author: AlienVault
Created: 2026-08-20 17:08:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #GitHub #InfoSec #Linux #Malware #Mimic #NPM #OTX #OpenThreatExchange #RAT #Rust #Telegram #TypoSquatting #Windows #bot #cryptocurrency #developers #iOS #AlienVault
AmnesiaStealer, an infostealer for macOS machines, has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#amnesiastealer
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #macOS #infostealer #AmnesiaStealer
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Following Black Hat and DEF CON conferences, a threat actor targeted attendees through X direct messages, posing as CoinDesk's VP and Head of Marketing to establish trust under the pretext of conference planning. The campaign employed a malicious Google Apps Script embedded in a Google Doc that presented ClickFix-style instructions and manual download options. The attack delivered different payloads based on the victim's operating system: macOS users received AMOS infostealer, while Windows users were infected with NetSupport RAT, a Ledger wallet implant, and a TLS-intercepting proxy. A secondary lure masqueraded as a DocSend installer to deliver additional payloads. The operation demonstrated sophisticated social engineering by leveraging trusted platforms and post-conference networking expectations.
Pulse ID: 6a85d24a1bf7db5b97a4e9f8
Pulse Link: https://otx.alienvault.com/pulse/6a85d24a1bf7db5b97a4e9f8
Pulse Author: AlienVault
Created: 2026-08-19 15:56:58
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #CyberSecurity #Edge #Google #InfoSec #InfoStealer #Mac #MacOS #Malware #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #Rust #SocialEngineering #TLS #Windows #bot #AlienVault
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Indicators extracted from public reporting. Source: https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns
Pulse ID: 6a877807939f52dc55e5712e
Pulse Link: https://otx.alienvault.com/pulse/6a877807939f52dc55e5712e
Pulse Author: CyberHunter_NL
Created: 2026-08-20 21:56:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #bot #CyberHunter_NL
MirrorMan v0.5.2 is here, and it’s the final release in the 0.5.x family!
This release is a major stabilization and feature update for Parch Linux MirrorManager. The GUI now has mirror search and filtering, reliability sorting, bulk enable/disable controls, configurable auto-refresh, non-blocking notifications, keyboard shortcuts, and persistent window geometry. Custom repositories can also be removed directly from the GUI.
The CLI has grown significantly too, with mirrorlist backups, cleanup with dry-run support, mirrorlist sync and diff, individual mirror speed testing, export functionality, and shell completions for Bash, Zsh, and Fish.
Under the hood, MirrorMan now has architecture-aware mirror testing, automatic backup rotation, SHA256 verification for BlackArch's `strap.sh`, safer tempfile handling, and recovery from poisoned mutexes to prevent GUI freezes after thread panics.
Packaging also received some love with AppStream metadata, improved desktop keywords, and a Polkit action for cache cleanup.
with this release, MirrorMan 0.5.x reaches its final milestone.
The next chapter starts with 0.6.x.
#ParchLinux #MirrorMan #Rust #GTK #Libadwaita #Pacman #OpenSource
Rewriting in Rust: Performance, Failures, 2026 Reality Check https://lobste.rs/s/bmdiuz #programming #rust
https://blog.jetbrains.com/rust/2026/08/10/rewriting-in-rust/
New.
Socket: Popular Rust Crates Compromised in Build-Time Supply Chain Attack https://socket.dev/blog/popular-rust-crates-compromised @SocketSecurity #infosec #threatresearch #Rust #supplychain #cyberattack
Supply chain attack on arrayref:
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Hackers poison arrayref Rust crate to push infostealer malware
Indicators extracted from public reporting. Source: https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Pulse ID: 6a873f967f0f7e03e5b60196
Pulse Link: https://otx.alienvault.com/pulse/6a873f967f0f7e03e5b60196
Pulse Author: CyberHunter_NL
Created: 2026-08-20 17:55:34
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #RCE #Rust #bot #CyberHunter_NL
This is perhaps one of the craziest #Rust supply chain attacks I’ve ever seen:
The `arrayref` crate, which for whatever reason was somewhat widely used in cryptography libraries (none that I personally work on AFAIK), was changed to depend on a malicious `proc-macro1` crate published by “dtolney” who was impersonating “dtolnay”.
`proc-macro1` contained a malicious build.rs which was effectively RCE and downloaded a malware payload.
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Zellij (Terminal multiplexer) in v0.45.0 released
Why compiling Rust to WebAssembly is slow via @fanf https://lobste.rs/s/vcqcgl #rust #wasm
https://00f.net/2026/08/19/why-compiling-rust-to-webassembly-is-slow/
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
RE: https://infosec.exchange/@catsalad/117122224704448960
extern crate case;use case::Violin;
#RustCataStructures #rust #RustLang #cat #CatsOfMastodon #ProgrammingHumor
Identity Abuse Through Trusted Communication Channels
Indicators extracted from public reporting. Source: https://www.paloaltonetworks.com/unit42
Pulse ID: 6a86dd54a149a153682540ba
Pulse Link: https://otx.alienvault.com/pulse/6a86dd54a149a153682540ba
Pulse Author: CyberHunter_NL
Created: 2026-08-20 10:56:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rust #bot #CyberHunter_NL
Featured Job: Are you fluent in Rust and want to have an impact with your skills? @nlnet is seeking an enthusiastic, security-minded software developer to join its team in Amsterdam. Learn more about this hybrid position on #OSJH
https://opensourcejobhub.com/job/29558/rust-developer-software-engineer-at-nlnet-foundation/?utm_source=smm
#Rust #SoftwareEngineer #developer #OpenSource #security #career #jobs
RE: https://hachyderm.io/@djc/117127279917454362
arrayref is a really popular Rust crate and it seems like the maintainer account has been compromised. The compromised version (arrayref 0.3.10) and its malicious dependency (proc-macro1) are removed from crates.io already.
@ifin advisory: https://discourse.ifin.network/t/rust-packages-compromised-in-typosquat-account-takeover-attack/765
Rust project blog post: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
StepSecurity writeup: https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Rustsec advisory-db entry: https://github.com/rustsec/advisory-db/issues/3161
#rustlang #rust #infosec #supplychain #malware
Relre Relay boostedPSA: arrayref 0.3.10 (maintained by droundy, 54M recent downloads) appears to contain malware.
Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat https://lobste.rs/s/dns8du #rust #security
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
What Zig felt like, coming from Rust https://lobste.rs/s/oaybfe #rust #zig
https://besok.github.io/posts/what-zig-felt-like-coming-from-rust/
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
Reclaim the terminal https://lobste.rs/s/7v1wvd #rust #unix
https://nishantjosh.dev/blogs/reclaim-the-terminal/
📚 MComix-rs: Cititorul de benzi desenate rescris în Rust pentru Linux și Windows!MComix-rs este o rescriere modernă și ultra-rapidă în limbajul Rust a clasicului cititor de benzi desenate și manga MComix, proiectată special pentru a oferi performanță maximă, stabilitate și un consum minim de resurse pe Linux și Windows.✨ Prin ce se remarcă MComix-rs?🚀 Performanță și siguranță cu Rust:• Prin înlocuirea vechii baze de cod în Python/GTK2 cu Rust, MComix-rs oferă timpi de încărcare aproape instanțiali pentru arhive voluminoase, navigare extrem de fluidă între pagini și elimină complet problemele de gestionare a memoriei.📦 Suport complet pentru formate de arhivă:• Deschide nativ toate formatele populare de benzi desenate și manga, precum CBZ, CBR, CBT, CB7, precum și fișiere de arhivă standard (ZIP, RAR, 7z, TAR) sau directoare simple cu imagini.📖 Moduri avansate de citire & Manga:• Include suport pentru afișarea pe două pagini (Double Page Mode), potrivire automată după lățime/înălțime, zoom inteligent și un modul dedicat de citire de la dreapta la stânga (Right-to-Left) ideal pentru manga.💻 Multiplatformă & Interfață curată:• Este conceput să funcționeze impecabil pe distribuțiile Linux (cu integrare nativă pe Wayland și X11) și pe Windows, menținând o interfață minimalistă, personalizabilă și ușor de utilizat prin scurtături de la tastatură.O alegere excelentă pentru pasionații de comics și manga care își doresc un cititor rapid, modern și complet open-source! 🚀#MComix #Rust #Linux #Windows #Comics #Manga #OpenSource #TechNews #LinuxEasy #FOSS
ok so we've been using cargo-vet for a while at Light Squares and we love it - but every time we had to review a batch of dependency updates we wondered how other people actually keeping up with this?
we just published a blog post with some data on it - would be interesting to get some thoughts on that :)
One of the best ways to learn #Rust is to have someone tell you why your perfectly valid code isn't quite idiomatic yet. 💡
This refactoring reminds me of discovering list comprehensions in Python back in the day 😍
🦀 Looking for Rust malware samples to practice analyzing? Our Rust Malware Sample Gallery just received a major update, with 20 new families added! https://github.com/decoderloop/rust-malware-gallery
The Sample Gallery collects links to articles about malware written in Rust, organizes them by malware family, and includes a download link to a publicly available sample for every malware family. This is a resource for any malware analyst who wants to get hands-on with real Rust malware.
The last time the Sample Gallery was updated was almost 2 years ago, in January 2024. Since then, there's been an explosive growth in new Rust malware, including all of the following families that are now in the Sample Gallery:
SPICA, KrustyLoader, RustDoor, SSLoad, Fickle Stealer, Cicada3301 Ransomware, RustyClaw, Embargo Ransomware, RustyAttr, Akira Ransomware (both the Akira_v2 and Megazord variants), Banshee (Rust variant), RALord Ransomware, RustoBot, Tetra Loader, EDDIESTEALER, Myth Stealer, Rustonotto, RustyPages, ChaosBot
This is nearly one new Rust malware family observed in the wild, every month. Rust as a programming language for malware is here to stay!
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing
The Rust ransomware KCVY OSLOCK has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#kcvy-oslock
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #ransomware
A new Rust DDoS Botnet family has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#unnamed-rust-ddos-botnet
This malware family is currently unnamed, but was analyzed in this 2025-11-30 article by Beelzebub: https://beelzebub.ai/blog/rust-ddos-botnet-honeypot-c2-decoding/
(h/t to @cydave ; I learned about the Beelzebub article from his link to it, in his article about setting up a honeypot: https://0dave.ch/posts/flying-whales-in-a-pot-of-honey/)
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #botnet
FunkSec Ransomware (aka FunkLocker) has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#funksec-ransomware
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #ransomware #FunkSec #FunkLocker
RustyWater (aka RUSTRIC, Archer RAT) has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#rustywater
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #MuddyWater
An unnamed Rust-based loader, mimicking a GoToMeeting DLL, has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#rust-based-loader-mimicking-gotomeeting-dll
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing
Marabu Ransomware has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#marabu-ransomware
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #ransomware #Marabu
An unnamed Rust-based keylogger, used by a threat actor named SloppyLemming, has been added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#rust-based-keylogger-used-by-sloppylemming
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #SloppyLemming
A novel banker RAT, named VENON, has beed added to the Rust Malware Sample Gallery: https://github.com/decoderloop/rust-malware-gallery#venon
#rust #rustlang #malware #infosec #ReverseEngineering #MalwareAnalysis #reversing #VENON