#flask — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #flask, aggregated by home.social.
-
Как я сделал на Flutter игру для разработчиков. Часть 2
Всем привет! Меня зовут Амир Утеуов , я ML-инженер из Авито . В первой части статьи я поделился тем, что пришлось сделать и учесть для создания собственной игры для разработчиков — DevRush. Суть игры заключается в том, что нужно на время находить иконки языков программирования. Я прошёл путь от создания геймплея и векторной анимации до сборки под Android и iOS. Главная неожиданность ждала в App Store — модераторы отклонили игру из-за иконки Android, посчитав это рекламой конкурента. Но по итогу Авито взял мою игру на стенд Code Fest 2025. В этой части будет о том, как создавался редизайн и что нужно было доработать, чтобы игру можно было использовать на стенде Авито.
-
Как я парсил банковские платёжки всех российских банков на Python: история боли, костылей и XML-матрёшек
Привет, Хабр! (И тебе, случайный бухгалтер, который думает, что «выгрузить из банка» - это нажать одну кнопку. И тебе, 1С-разработчик, который слышит «парсинг PDF» и сразу уходит на больничный. И тебе, Python-разработчик, который уверен, что pip install magic_solution решит любую проблему.) Сегодня расскажу, как мне поставили задачу, от которой у SAP-а ушло, видимо, несколько команд и много времени, а мне дали на это… ну, скажем так, поменьше. Задача звучала элегантно, но всегда есть но, и не одно)) (Спойлер для тех, кому лень читать: я узнал, что Сбербанк формирует WORD-документы с такой XML-вложенностью, что в ней можно заблудиться, ВТБ зачем-то маскирует WORD под RTF, а файл на 10 000 платёжек из 37 мегабайт разворачивается в 1 гигабайт XML. И да, всё по итогу заработало.)
https://habr.com/ru/articles/1025626/
#python #flask #1с #парсинг #pdf #docx #rtf #банки #интеграции #оптимизация
-
Tide is hiring Senior Staff Software Engineer, Agentic Platform
🔧 #java #python #angular #flask #flutter #springboot #aws #cicd #docker #kafka #mysql #postgresql #terraform #seniorengineer
🌎 Serbia
⏰ Full-time
🏢 TideJob details https://jobsfordevelopers.com/jobs/senior-staff-software-engineer-agentic-platform-at-tide-co-apr-16-2026-a79a6f?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
Manychat is hiring Senior Python Engineer (Billing)
🔧 #python #django #flask #api #cicd #docker #nosql #postgresql #seniorengineer
🌎 Amsterdam, Netherlands
⏰ Full-time
🏢 ManychatJob details https://jobsfordevelopers.com/jobs/senior-python-engineer-billing-at-manychat-com-mar-26-2026-ad417f?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
A febbraio abbiamo fatto il primo evento dell’anno di #PyVenice !
🗣️ Due interventi sui #framework del momento, #flask e #django
⚖️ Un confronto tra #python e #javascript, in termini di #ServerSide e #ClientSide rendering
🚀 Come #DjangoNinja ha reso veloce le #REST di Django, mostrando il codice in azione !!!🕖 Noi ci vediamo il 16 aprile 2026, con il #workshop su #n8n ‼️
Info e prenotazioni 👇
https://www.meetup.com/pyvenice/events/312919609/
💾 NON mancate ! -
Как я сделал новостной агрегатор с MCP‑сервером, AI‑чатом и Telegram‑ботом
28 февраля 2026 года я стоял у окна на 41-м этаже в JBR в Дубае и смотрел, как системы ПВО ОАЭ перехватывают иранские беспилотники прямо над моей головой. Полез в новости — в Google и Яндексе статья двухчасовой давности, Telegram-каналы противоречат друг другу. Когда это происходит где-то далеко, не придаёшь этому значения. Когда ты в центре событий, то хочешь знать оперативную информацию, желательно с push-уведомлениями.
https://habr.com/ru/articles/1010502/
#llm #mcp #flask #telegrambot #rss #deepseek #news_aggregator #tool_calling #python
-
Как я на 8 марта написал AI-Wish-лист по книге «Пять языков любви» — и автоматизировал романтику
Мне 34, из них больше десяти лет я в коммерческой разработке. И примерно столько же я женат. Каждый год 7 марта я ловил себя на мысли, что стою в торговом центре с пустым взглядом, пытаясь угадать с подарком. В этом году я решил подойти к проблеме не как муж в панике, а как инженер. Я прочитал книгу Гэри Чепмена «Пять языков любви», поймал пару инсайтов и за 5 вечеров написал сервис-переводчик для пар. Внутри: Flask, Vanilla JS (да, в 2025 году, и я объясню почему), DeepSeek API для генерации карточек в стиле «Love is…» и алгоритм матчинга, который понимает мою жену лучше, чем я за 10 лет брака. Под катом — история о том, как код помогает чинить баги в коммуникации.
https://habr.com/ru/articles/1007566/
#python #flask #javascript #vanilla_js #deepseek #llm #petпроект #mvp #8_марта #психология
-
Building an ML-Powered Transaction Classifier with Retraining and A/B Testing
Every month I download a CSV from my bank with all our household transactions. Each one needs a category: groceries, fuel, mortgage, subscriptions, insurance.
https://www.hylkerozema.nl/2026/02/26/building-an-ml-powered-transaction-classifier-with-retraining-and-a-b-testing/
#DataScience #MachineLearningEngineering #classification #DataScience #Flask #MachineLearning #MLflow #MLOps #mongodb #NAS #Optuna #Python -
🚀 Se termina el mes, pero todavía estás a tiempo de invertir en tu futuro profesional!
📚 ¿Qué podés aprender en #JuncoTIC?
🐧 GNU/Linux & SysAdmin
🔒 Ciberseguridad & Redes
🐍 Desarrollo Web con Python y Flask.✨ BONUS: cursos gratuitos de introducción a GNU/Linux y a Flask 🎁
⏳ Sólo por 5 días, el tiempo corre!
👉 https://juncotic.com/cursos/
Te esperamos en el aula virtual! 🎓
#Linux #Ciberseguridad #Programación #CursosOnline #SysAdmin #Python #Redes #ssh #iptables #nftables #lpic #flask
-
Se vienen cositas próximamente en el blog y en el canal de YouTube 💪
Intentando aclarar algunos conceptos fundamentales de SSH para poder utilizarlo como un pro y no morir en el intento 🚀
¿Todavía no nos siguen? 👇
▶️ https://www.youtube.com/juncotic?sub_confirmation=1
¡Los esperamos para seguir aprendiendo juntos!
#gnu #linux #ssh #curso #firewall #iptables #nftables #wireshark #redes #tcpip #ciberseguridad #python #flask #shellscripting #juncotic
-
Últimas horas de la promoción de precios mínimos de Febrero! 🔥
No pierdan la oportunidad de mejorar sus perfiles profesionales! 🎓
Pueden encontrar los mejores precios a todos nuestros cursos en nuestro sitio web:
Los esperamos!
Para pagos desde Argentina (transferencia, MercadoPago):
[email protected]#linux #curso #python #flask #wireshark #ssh #iptables #nftables #tcpip #juncotic
-
Invertir en tu conocimiento es la única apuesta segura 🚀
Por los próximos 5 días, todos los cursos de #JuncoTIC están al mejor precio en Udemy!
Si tenés ganas de dominar GNU/Linux, entender cómo funcionan las redes TCP/IP, o desarrollar sitios web con #Python y #Flask, esta es la oportunidad!
👇 Todos los cursos con el descuento acá:
Dudas? Otras formas de pago?
💬 [email protected]#Linux #SysAdmin #IT #python #ssh #nftables #iptables #tcpip #flask #wireshark
-
In Which I Vibe-Code a Personal Library System https://hackaday.com/2025/12/03/in-which-i-vibe-code-a-personal-library-system/ #ArtificialIntelligence #barcodescanner #librarysystem #OriginalArt #SQLAlchemy #vibecoding #Featured #Interest #barcode #ChatGPT #library #flask
-
Nothing new to proper software people of course, but my amateur-self found out about the fetch() - Flash combination, which solved a problem in a much smarter way than I was trying to solve it, and I'm spreading the word to any brethren in amateuristic ignorance:
https://www.tegladwin.com/files/howto/fetchAndFlask.php
(The problem was about API calls to OpenAI taking so long the page timed out, because I was using basic submit-form functionality.)
-
🎬 ¡Semana de edición! 🎞️
🎧 Mejorando los audios de las clases del nuevo curso de #nftables de JuncoTIC.com !
✨ Siempre intentando entregar la mejor calidad para nuestros alumnos 🙂
📤 Y ya empezando a subir las clases a la plataforma 🚀
🔜 ¡Pronto más novedades del lanzamiento!
#gnu #linux #learning #juncotic #educacion #softwarelibre #opensource #freesoftware #sysadmin #devops #curso #networking #lpic #tcpip #wireshark #python #flask #ssh #iptables #scripting #bash #firewalls
-
Buenos días #fediverso! #TZAG
Les comento que esta semana tenemos todos los #cursos de #juncotic en #descuento para seguidores! 🔥
Pueden acceder a cada #curso al mejor precio de #udemy hasta fin de mes.
Todos los enlaces de descuento acá: 👇
Ojalá les sirva y lo puedan aprovechar!
La #oferta es por tiempo limitado ⌛
Cualquier duda sobre el acceso, contenido, u otras formas de pago me escriben! 💬
#gnu #linux #ssh #firewall #python #flask #wireshark #scripting #lpic
-
Buenos días #fediverso! #TZAG
Les comento que esta semana tenemos todos los #cursos de #juncotic en #descuento para seguidores! 🔥
Pueden acceder a cada #curso al mejor precio de #udemy hasta fin de mes.
Todos los enlaces de descuento acá: 👇
Ojalá les sirva y lo puedan aprovechar!
La #oferta es por tiempo limitado ⌛
Cualquier duda sobre el acceso, contenido, u otras formas de pago me escriben! 💬
#gnu #linux #ssh #firewall #python #flask #wireshark #scripting #lpic
-
Buenos días #fediverso! #TZAG
Les comento que esta semana tenemos todos los #cursos de #juncotic en #descuento para seguidores! 🔥
Pueden acceder a cada #curso al mejor precio de #udemy hasta fin de mes.
Todos los enlaces de descuento acá: 👇
Ojalá les sirva y lo puedan aprovechar!
La #oferta es por tiempo limitado ⌛
Cualquier duda sobre el acceso, contenido, u otras formas de pago me escriben! 💬
#gnu #linux #ssh #firewall #python #flask #wireshark #scripting #lpic
-
Buenos días #fediverso! #TZAG
Les comento que esta semana tenemos todos los #cursos de #juncotic en #descuento para seguidores! 🔥
Pueden acceder a cada #curso al mejor precio de #udemy hasta fin de mes.
Todos los enlaces de descuento acá: 👇
Ojalá les sirva y lo puedan aprovechar!
La #oferta es por tiempo limitado ⌛
Cualquier duda sobre el acceso, contenido, u otras formas de pago me escriben! 💬
#gnu #linux #ssh #firewall #python #flask #wireshark #scripting #lpic
-
RBACX — универсальный RBAC/ABAC-движок авторизации для Python
RBACX — авторизация без боли в Python-проектах Когда доступ «размазан» по вьюхам и миддлварам, ревью и тесты превращаются в квест - появляется мотивация все это унифицировать. Я написал RBACX — лёгкий движок, где правила описываются декларативно (JSON/YAML), а проверка прав — это один понятный вызов. В статье показываю, как собрать из него аккуратный PDP для микросервисов и монолитов. Я последние два года пишу бэкенд в стартапе MindUp — это мой первый пост на Хабре, и первая библиотека. Буду рад вопросам и критике. Если тема авторизации болит так же, как у меня, загляните!
https://habr.com/ru/articles/950080/
#python #rbacx #RBAC #ABAC #fastapi #authorization #django #flask #litestar #accesscontrol
-
https://www.walknews.com/1040513/ Cultured quail, Brazil nuts and more #abstract #AnimalCell #artificial #awe #backgrounds #bacterium #biotechnology #Brazil #BuiltStructure #cell #CellCulture #circle #concepts #continuity #curve #dishware #disposable #equipment #flask #futuristic #HealthcareAndMedicine #HumanCell #HumanHand #ideas #laboratory #majestic #MedicineAndScience #nanotechnology #pattern #plastic #plate #ProtectiveGlove #research #Science #StemCell #Technology #vial #ブラジル
-
https://www.wacoca.com/news/2635850/ Cultured quail, Brazil nuts and more #abstract #AnimalCell #Artificial #awe #backgrounds #bacterium #biotechnology #Brazil #BuiltStructure #cell #CellCulture #circle #concepts #continuity #curve #dishware #disposable #EQUIPMENT #flask #futuristic #HealthcareAndMedicine #HumanCell #HumanHand #ideas #Laboratory #Majestic #MedicineAndScience #nanotechnology #pattern #Plastic #plate #ProtectiveGlove #Research #science #StemCell #technology #vial #ブラジル
-
От консоли к веб-интерфейсу: создание инсталлятора ALD Pro с Flask и Python
Программисты делятся на два типа: те, кто автоматизирует установку ALD Pro, и те, кто ещё не понял, сколько времени они теряют. Когда-то я вручную прописывал DNS, как средневековый монах переписывающий манускрипты, но потом осознал, что компьютеры должны работать вместо нас. В этой статье — мой путь от консольных скриптов, которые пугали коллег, до веб-интерфейса, где даже бухгалтер (почти) разберётся.
https://habr.com/ru/articles/930698/
#ald pro #astralinux #python3 #web #flask #api #automation #linux
-
Hoy aprendí sobre el algoritmo de hash #bcrypt, basado en el cifrador de bloques #Blowfish, revisando un artículo de @andrea_navarro sobre extensiones de #Flask... particularmente sobre las extensiones de seguridad.
Y acabo de descubrir que es uno de los algoritmos soportados para la creación de passwords en GNU/Linux :D
Habrá que hacer algunos experimentos.
#gnu #linux #cryptography #criptografía #ciberseguridad #infosec #encrypt #hash #python #flask
-
Professionnellement, je commence doucement à me projeter dans l'après CDD, c'est à dire au printemps-été 2026.
J'aimerais aller vers #ClermontFerrand pour me rapprocher de gens que j'aime.Donc si vous êtes dans un service public, une association ou une SCOP du coin qui recherche ou est susceptible de chercher un géomaticien, n'hésitez pas à me faire signe.
#PGSQL #RStats #Python #Flask #QGIS #ecologie #leaflet #geoserver #SIG #logicielLibre
-
APScheduler + requests 遇到 OSError: [Errno 24] Too many open files 的問題
#apscheduler #bug #code #collection #flask #gc #gunicorn #pypy #pypy3 #python #requests #source #urllib #urllib3 #workaround
-
While trudging through my day-to-day activities, I had an inspiration about how to implement local #API access for #AWS #APIGateway code using #Python #LambdaFunctions for back-end logic, by overriding #FastAPI and #Flask #decorators.
https://goblinfish-code.blogspot.com/2025/06/local-aws-api-gateway-development-with.html
-
Female Figure with a Flask in her Hand
Alexandre de Riquer
(Calaf, 1856 - Palma, 1920)#femalefigure #flask
#temperaoncanvas
#alexandrederiquer#mnac
#art #artmuseum
#museunacionaldartdecatalunya
#museunacional
#nationalmuseumofart
#nationalpalacemuseum #barcelona #spain -
Как сократить время ответа в 2 раза, добавив одну строку кода
Okko – один из крупнейших онлайн-кинотеатров в России c нагрузкой в несколько тысяч запросов в секунду, в котором персональные рекомендации занимают важное место. Для улучшения пользовательского опыта нужно не только предоставить качественные рекомендации, но и обеспечить быстрый доступ к ним. В этой статье мы поделимся: 1. Описанием, как мы использовали инструменты Jaeger и Grafana для выявления узких мест в производительности, что привело к выявлению критических проблем со сборщиком мусора; 2. Анализом влияния различных настроек сборщика мусора на время ответа, что позволило сократить его вдвое для 99% запросов; 3. Когда и почему стоит рассматривать изменение стандартных настроек сборщика мусора (на примере нашего случая).
https://habr.com/ru/companies/okko/articles/853406/
#Python #garbage_collector #perfomance #flask #latency #okko
-
If you use #PyCharm Pro and have a REST API, you *must* check out the Endpoints tool window.
It shows all of your project's endpoints in one place, along with documentation, schema info, etc!
https://www.jetbrains.com/help/pycharm/django-endpoints.html
https://www.jetbrains.com/help/pycharm/endpoints-tool-window.html
#DRF #Django #DjangoRestFramework #REST #API #Flask #PyCharm #JetBrains #WebDevelopment
-
Programming Jan-April 2024
This year started off pretty light when it came to programming because I’ve been addicted to the video game Against the Storm since last winter. But I eventually started working again on various projects – some old and some new. I didn’t do any programming in January, so we’ll start in February.
February and March
Over these two months I worked on my replacement for web access to my Taskwarrior TODO list because Inthe.am had shut down. In February I got the podman containers set up – one to run the taskd server and one to run the website I’d coded up in Flask. In March I had to write some rudimentary Javascript to get the website to highlight the selected tab (Overdue, Today, This Month, etc). The rest of the interactivity on the site works using HTMX, letting me focus on Python instead of Javascript, but I just wasn’t able to get that part of the site to work without a tiny bit of Javascript. I also added some fixes because the date/time widget assumes UTC. Of course, now that I have it all working correctly and get lots of use for it (especially when I’m at work and I want to quickly get something out of my brain’s short-term buffer), Taskwarrior went to 3.0 which completely changes the way the program works, the API, and the way syncing works. I think in the end it’ll be for the best, but it’s annoying that I need to figure this out. That may involve finally learning how to use PyO3 to interact with Rust or re-writing part of my backend in Rust. We’ll have to see where that goes.
April
Things really picked up in April, programming-wise. First off, I had to upgrade the dependencies in my Amortization program. This will segue into the next topic in a second, but essentially every time I upgrade Fedora, I get a new version of Python. This means I have to redo my virtual environment. So when I tried to run this program again, I had to pip install my requirements and since some of the packages were no longer available on PyPi as wheels, it tried to compile. When that failed, I upgraded the dependencies.
As I’ve mentioned before, because of the virtual environment annoyances, I’ve decided to rewrite all my cron utilities in a compiled language. If it’s a utility I have running via cron, it’s something I want to work all the time. I don’t want to have to run around recreating virtual environments (something I don’t mind for a program I’m going to run occasionally – see previous paragraph). So I rewrote my NASA background downloading program in Go. This was a real breeze. It truly is a pretty easy language to work with – a hybrid of C and Python in my humble opinion. I also used the opportunity to learn how to use Go’s new(ish) SLOG package.
I also took a few days to update the one project I know for a fact is used by other people besides myself, Extra Life Donation Tracker, to use PyQt6. It was an annoying couple days figuring out what has changed since PyQt5. Or rather, to be more specific, the Qt devs did a great job documenting what had changed, but seeing how that translated to what I needed to fix for pyinstaller to make an exe for my Windows users took a few days.
As I mentioned a couple days ago, I’ve started learning Rust. Just as I did with Python when I first learned it, I started with a project-based book: Command-Line Rust. However, while I was getting a good feel for the language, the author wasn’t quite explaining some concepts early enough (to my mind) like when to use a double colon vs a dot to access a function/method. So I started also reading The Rust Programming Language (2018 version) (link is to the newer 2021 edition). There I learned that (using Python terms) double colon is a static method (would belong to the class as a whole) while dot is a method on an instance of the “class”. While I probably could say the same thing about modern C++ or C, I think Rust is actually a good stepping-stone on the path that goes Python->Go->Hard Systems language. As a newer language with less baggage, it seems to be a child of Haskell and C, with functional programming being a first class way of programming in Rust. (I may be speaking out of my butt since I’m only a week or so into learning the language, but that’s my first impression).
Going back to what I said about rewriting my cron utilities in compiled languages, I may end up rewriting Snap-In-Time, my btrfs snapshot project in Rust. Based on what I did in the first project of Command-Line Rust, it seems like it would be pretty trivial (compared to Go) to retrieve and use the output of system commands (like btrfs sub snap, btrfs sub del, etc). If this happens, it’s probably a few months away.
Speaking of future projects, over at my personal Mastodon account (started before WordPress joined the Fediverse or I might have only used this account as my Fediverse presence) @djotaku I post my top scrobbled artists every week. (Here’s an example) This is another cron utility that I would prefer not to have to be mindful of when I upgrade Python (although, in comparison to the other utilities, it’s also the most trivial). I’m thinking of redoing this one in Go as (as of this point) interacting with a JSON API seems easier than in Rust. I’m basing that from looking on crates.io at the last.fm crates on there. Most of them are older (makes sense since a lot fewer of us still scrobble to last.fm than in its heyday) and none of them covered the endpoints I needed so I’d have to write my own. One last thing – even though many folks aren’t scrobbling anymore, they must be getting information from somewhere (I thought CBS either sold last.fm to Spotify or did a partnership) because this article mentions the researchers using it to analyze song lyrics.
#Amortization #eldonationtracker #ExtraLife #Flask #Go #Golang #HTMX #Javascript #lastFm #NASA #Podman #PyQT #python #QT #rust #Taskwarrior
-
slsa-github-generator v2 now uses upload/download-artifact v4, so I can update those in all the Pallets projects. Turns out the publish workflow for most projects didn't need any changes at all. Only MarkupSafe, with multiple build jobs, needed a little change to use different upload names and combine their downloads. https://github.com/pallets/markupsafe/commit/f4905079ef7573d5c1e8fe1f291f1e353050bc87 #Python #Flask #MarkupSafe #GitHub #SLSA
-
Any #flask gurus out there? Trying to wrap my head around seemingly HTTP spec-violating behaviour, together with the developer of #changedetection.
tl;dr: send_from_directory 304 responses have a body while they shouldn't
-
🚀 Built #Linux & #Windows agents in #Python that send system & network data to a #RaspberryPi on my #homelab. Using #Flask for the frontend, #SQLite for database, and a touch of #javascript for real-time updates. Learning to code with hands-on projects has worked best for me. #ChatGPT & AI has enabled me to finally learn to code. 💻🔧 #CodingAdventures
-
Another week, another newsletter - catch up on the week's infosec news here:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.
#Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.
#FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign
#LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?
The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.
Have a great week ahead folks, I hope this newsletter proves helpful!
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
#infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD
-
Another week, another newsletter - catch up on the week's infosec news here:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.
#Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.
#FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign
#LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?
The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.
Have a great week ahead folks, I hope this newsletter proves helpful!
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
#infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD
-
Another week, another newsletter - catch up on the week's infosec news here:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.
#Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.
#FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign
#LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?
The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.
Have a great week ahead folks, I hope this newsletter proves helpful!
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
#infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD
-
Another week, another newsletter - catch up on the week's infosec news here:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.
#Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.
#FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign
#LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?
The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.
Have a great week ahead folks, I hope this newsletter proves helpful!
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
#infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD
-
Another week, another newsletter - catch up on the week's infosec news here:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.
#Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.
#FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign
#LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?
The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.
Have a great week ahead folks, I hope this newsletter proves helpful!
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-240423-300423
#infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD
-
#ChatGPT is OK at coding. But great as a learning tool for a new library or task. For example: I used it to help migrate a project from #Flask to #FastAPI and add background processing with #rq recently. It helped me select among multiple options and explained the differences.
The first code wasn't quite right but I could ask questions to figure out why and fix the issues. Enough to do on my own next time.
Much faster than reading docs or generic tutorials. -
New video is out on using #html files/templates in #flask application #python
https://youtu.be/Ckvf3USCeTA