Mastodon Digest
for the past
scorer
threshold
Posts

Sad trombone for the world's richest shithead. From the WSJ:

"Tesla shares fell 15% on Thursday—erasing $215 billion of market value—after the electric-vehicle maker missed earnings targets and had negative cash flow for the first time in two years. It was part of a wider stock selloff amid fears that big tech companies are overspending on artificial intelligence.
On an earnings call, Musk walked back earlier guidance on the rollout of Tesla’s Robotaxi ride-hailing service, Optimus humanoid robots and an electric semi truck that has been in development for years."

"Shares of SpaceX, which went public at $135 and traded above $225 in the days after its debut, are down nearly 50% from those highs. The stock broke below its initial-public-offering price within weeks and has lost more than $1 trillion in value from its peak."

wsj.com/finance/stocks/reality (paywall)

archive.ph/GmKt1

AWS had a ~one hour outage to US West 2 datacenter, resolved now. Similar to MS outage yesterday and ExpressRoute (MPLS) connectivity, Direct Route connectivity also broke.

AI advice made people three times less accurate but twice as confident, researchers found thenextweb.com/news/ai-advice-

🇳🇱 IJsstadion Thialf (thialf.nl) a été victime d'une cyberattaque autour du 19 juillet 2026.

L'IJsstadion Thialf, un important stade de patinage et lieu d'événements situé à Heerenveen, a récemment été la cible d'une cyberattaque par ransomware. L'attaque a été attribuée au groupe malveillant « The Gentlemen ». Les attaquants ont exigé le paiement d’une rançon en échange de la non-publication sur le dark web de documents internes, d’informations sur les employés et de contrats financiers volés. Malgré cette attaque, l’IJsstadion Thialf a indiqué que son impact avait été minime, les enquêtes informatiques ayant confirmé que les processus opérationnels et les données n’avaient pas été affectés ni mis en danger.

👉 bndestem.nl/binnenland/ijsstad

My 3D world now has collision detection in CSS! If you run into a wall or door it will stop. Open the door and you can go through. This model is unbelievable.

garethheyes.co.uk/

if you want to read a reddit post that causes your brain to fall out

Boosts

🙏 New Blog Post

The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

What's exposed:

  • Email addresses
  • Names
  • Country
  • Date of birth (they call it "borned_date" lol)
  • Account role (it's "PRAYER" for everyone, obviously)

Also found:

  • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
  • Their verification emails fail their own domain's authentication requirements

Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

Full writeup: bobdahacker.com/blog/click-to-