Web server hardware for self-hosting my blog (any excuse to buy another #RaspberryPi :-) ). Time to do some building… #SelfHosting

Cal.com has made a significant change that might have wider effects than it seems at first glance.
Cal.com has moved its main service from open source to closed source, citing new AI-driven security threats as the reason. The company now limits public access to its production code and offers Cal.diy, an independent MIT-licensed fork, for those who want to self-host. This shift affects end-user trust, transparency, and how technical leaders assess software control, auditability, and long-term risk.
This overview covers Cal.com’s recent changes, why they matter, and key trends in open source and digital trust for industry professionals.
Cal.com has moved its production code from GitHub to a private repository. The main service code is no longer open for public review or contributions. The company also introduced Cal.diy, a separate community project under the MIT license. This fork is for people who want to self-host and have full control without commercial or licensing limits.
According to Cal.com, the catalyst for this change is the growing risk posed by AI-powered tools, which can rapidly scan public codebases for vulnerabilities and potentially expose customer data. The company argues that keeping its production code private is necessary to better protect users and maintain security in an age where automated threats are increasingly sophisticated.
Although this might look like a small change in scheduling Technology, it has bigger consequences for anyone who cares about software transparency.
Open source earned end-user trust via transparency and openness. When a company known for openness says those values are now risky, it prompts a broader discussion.
If you care about self-hosting, open software, or reliable business platforms, Cal.com’s change deserves careful attention. It brings up important questions about software control and the limits of open source in today’s security environment.
What actually changed
Cal.com shifted to a closed-source model, ending public access to its main scheduling codebase. The former public repository was replaced by Cal.diy, an open-source, self-hosted project. While Cal.diy serves the open source community, Cal.com’s commercial code is now private. Cal.com clarifies that the ‘commercial edition’ is now ‘source available’, viewable but not freely usable or modifiable. This affects how the community can audit, trust, or contribute to the main product.
Cal.diy is now the main public repository and is presented as a fully open-source fork. All proprietary and commercial code has been removed. Cal.diy is 100% MIT-licensed, requires no license key, and lacks enterprise edition features. It is made for those who wish to self-host, keep data control, and avoid commercial restrictions. Users can run, modify, and share with minimal barriers, in line with open-source values.
Cal.com isn’t just shutting out the community; it still offers a strong open-source alternative. However, most users can no longer review the hosted service for security, add features, or contribute to it. The open-source version is now a separate project, and there’s no promise that new ideas will move between the open and closed versions.
Why Cal.com says it made this move
Cal.com says its choice is based on cybersecurity realities. AI-powered tools rapidly scan codebases for vulnerabilities. These tools let attackers analyse, find flaws, and generate exploits much faster than before. Previously, finding bugs required human effort; now AI tools flag issues at a new speed and scale.
Cal.com handles sensitive data like schedules, emails, tokens, and third-party integrations. Keeping the production codebase public could put users at risk. Even minor vulnerabilities could be exploited quickly. Closing the source adds friction for attackers, making automated reconnaissance harder.
Cal.com says its production code differed from the public version. Major rewrites of authentication, data operation, and integrations are now proprietary. The public codebase no longer duplicates the commercial service. The open source project is now a parallel effort with different priorities.
This change isn’t about being dishonest. It signals a new relationship between the company and its community. In the past, being an “open source company” meant honesty and shared influence. Now, public and private codebases have different roles, and community contributions no longer go straight into the main product.
Why the wording matters so much
Licensing, branding, and what users expect are now more important than ever. Many people think that just seeing the code means it’s open source, but the OSI makes a clear distinction.
The OSI states that open source is more than visible code. Software must be freely accessed, used, modified, and redistributed by anyone. The license must guarantee source access, the right to create derivative works, and free redistribution, without usage limits.
The difference between open source, source available, and closed source isn’t just about wording. It affects what users and developers are allowed to do. Cal.com’s decision marks a real shift in user rights, not just a name change.
Open source
Open source means users can freely use, study, modify, and share the software, as guaranteed by the license. The community can fork, examine for security, and extend the project without fear of losing these rights.
Source available
Source available allows viewing the code, but typically restricts modifying, redistributing, or using it for commercial purposes. Users may mistakenly assume open-source freedoms, but these rights are not guaranteed, and access could be restricted.
Closed source
Closed source means the production code is private. Users cannot inspect, modify, or adapt the software, and there are no guarantees of continued access or control over it.
For developers, startups, and organisations, these differences are critical. Open source licenses can shape business models, security, and trust. Mistaking a source for open source can lead to strategic mistakes and risks.
Many users see a “public repo” and assume freedom and stewardship are guaranteed. Without license protection, access can be revoked with little warning.
What self-hosters still have, and what they do not
Cal.diy is a truly public, MIT-licensed project. This isn’t just for show; the source code is open, and the documentation makes it clear that Cal.diy is for people who want to run their own instance without enterprise restrictions or locked features. There are no hidden barriers, no paid-only features, and no intentional limits on the open version. The goal is to let skilled users manage their own calendar setup independently.
But self-hosting Cal.diy is more complicated than it might look at first. The documentation clearly warns that Cal.diy is meant for personal, non-production use. Running it yourself requires advanced technical skills, including server administration, database management, network setup, and adherence to security best practices, especially for sensitive data such as calendar events and user credentials. There’s no official hosting or support, so you’re responsible for everything: setup, updates, backups, monitoring, and compliance. This is much more involved than the easy, one-click installs offered by some open-source projects.
Because of these requirements, Cal.diy is best suited for organisations and individuals who can treat it as a serious infrastructure project, not just a simple app. Small teams without IT support or casual users looking for an easy alternative to SaaS could struggle and risk data loss or security issues if they don’t closely follow best practices.
There’s another important point in the Cal.diy contribution guide: any code or fixes added to Cal.diy won’t be included in Cal.com’s main service. This isn’t simply a technical split; it’s also an organisational and strategic one. Cal.com’s main service is now closed source and developed in-house, while Cal.diy is run openly by the community. So, even valuable community contributions stay within Cal.diy and don’t affect the commercial version.
For developers and contributors who helped shape Cal.com’s main product, this is a big change. The company has closed the usual path for community-led improvements to reach the main service. Now, contributors can still help other self-hosters and open-source users, but their work won’t impact the commercial platform’s features or direction.
Enterprise users of Cal.com’s commercial platform now get support and updates through private channels. They receive updates, security patches, and help directly from Cal.com’s support team, not through a public repository. This means the company handles maintenance and incidents internally, but the community can’t quickly spot or fix security issues in the production code. Leaders should consider that this closed support model depends more on Cal.com’s internal processes than on open collaboration.
For the wider community, this change redefines what “open” means for Cal.com. Users get a real open-source option, but it comes with additional requirements and limits, and their contributions are now separate from the company’s main product.
Why this matters beyond one app
You don’t have to use Cal.com for this to matter. The bigger issue is trust in the digital technologies and platforms that people, businesses, and communities rely on every day.
The heart of the issue is trust, not just in a specific brand, but in the promises that open source and self-hosting have made for decades. Much of the modern self-hosting and open-source movement has been built on a simple yet powerful contract: if you choose tools that are truly open, keep your data under your own control, and reduce your reliance upon external platforms, you are investing in long-term autonomy. The underlying belief is that openness fosters transparency, forkability, adaptability, and resilience in the face of shifting business priorities or technological change. When you run open software, you expect that you and the wider community can always audit the code, migrate your data, and shape the project’s future if the founding maintainers change course.
The Cal.com example shows that “open” can mean many things. Just having a public repository or open source branding doesn’t guarantee real software freedom or future control. Companies might still control the roadmap, the main code, the hosted service, the brand, and the line between community and commercial versions. In these cases, your freedom depends not just on the license but also on the company’s long-term goals and how much you can trust them to keep their promises. Relying only on good intentions, without strong guarantees or an independent community, can be risky.
This doesn’t mean you should give up on open software or self-hosting. Instead, it’s a Signal to look more closely at what kind of openness and control you really have. Are you covered by a strong license? Is the community independent? Could you keep the project going if the company changes direction or shuts down? These questions help you decide if your trust is solid or if it could vanish when you need it most.
The uncomfortable question underneath this move
Here’s where Cal.com’s move from open to closed source turns into real choices about your digital independence, resilience, and risk. If you rely on Cal.com or similar tools, now is the time to review not just what you use, but how prepared you are for the future.
Action Checklist for Technical Leaders:
Identify exactly which Cal.com product or codebase your organisation relies on (commercial hosted, Cal.diy, or a legacy version)
With this checklist, technical leaders can begin an internal assessment to ensure changes to Cal.com’s licensing or product model don’t compromise their autonomy or operations.
Step 1: Precisely Identify Your Product and Source of Truth
Start with a thorough audit:
Step 2: Audit Your Real-World Dependencies
Step 3: Analyse Your Risk Appetite and Priorities
Step 4: Go Past Surface-Level Openness
Step 5: Plan for Company or Project Changes
Step 6: Institutionalise This Assessment
Step 7: Document and Communicate
Step 8: Community and Ecosystem Engagement
Final Thought:
These questions and steps might feel tedious, but they’re what separate true digital control from future problems. In a context where “open” can mean anything from real freedom to just marketing, only careful review and persistent attention will protect you and your organisation.
This is where realistic considerations become critical and where a thoughtful review of your setup and risk exposure is essential in light of Cal.com’s changes.
If you rely on Cal.com or any similar tool for scheduling or critical business functions, now is the moment to conduct a thorough audit of your infrastructure and dependencies. Don’t just assume your present setup is future-proof: determine which product or codebase underpins your operations. Are you using the main hosted Cal.com service (now closed source), the newly launched Cal.diy MIT-licensed project (maintained independently from the main product), or a legacy self-hosted deployment based on the previously public code? Each of these paths comes with different levels of transparency, control, support, and long-term risk. If you’re an enterprise self-hoster, Cal.com states that you will receive an invitation to the private repository; for everyone else, Cal.diy is the public-facing, community-maintained option.
Inventory Your Dependencies
Make a comprehensive list of which scheduling products, plugins, or integrations your workflows depend on. Identify which version you are running, what its licensing model is, and whether you rely on hosted services or self-hosted infrastructure.
Map Out Your Actual Exposure
For each dependency, ask: What would happen if this service were discontinued, closed further, or changed its licensing terms? Would your team be able to maintain or migrate the code, or would you be locked in?
Explain the Source and Support Model
Are you on the hosted commercial service, which now relies on closed code? Are you using Cal.diy, which gives you code access but requires you to manage everything from updates to security? Or are you on a legacy branch, which may no longer receive active maintenance or security fixes?
Assess Operational Preparedness
If you are considering or are currently self-hosting, do you have the technical resources and processes in place to handle server administration, database management, security patching, backups, and compliance? If not, what would you need to put in place to maintain reliability and safety?
Reevaluate Your Risk Model
If your top priority is convenience and you can accept more platform risk, the hosted product may suffice. If you require software freedom, transparency, and control, the open source path is better, but only if you’re ready for the operational burden.
Look Past Surface-Level Signals
Stop treating “has a GitHub repo” as proof of long-term sovereignty. Public code hosting does not guarantee future access, forkability, or influence over the roadmap. Instead, dig into:
These questions may appear tedious or even negative, but they’re critical for anyone relying on digital infrastructure in a fast-changing world. Clear answers help you avoid surprises and ensure your choices align with your goals for transparency, control, and sustainability. In the end, careful review, not just surface signals, will protect your operations and your independence.
Summary of Key Recommendations for Technical Decision-Makers:
By adhering to these steps, you can make smart choices that protect your organisation’s independence and strength.
What this means for digital sovereignty
This is where big ideas about open source, trust, and control turn into real decisions that shape your future flexibility and security.
If you use Cal.com or a similar scheduling tool, now is the time to review your setup and risks. Don’t assume what works today will work tomorrow, or that you’ll always have the same control and reliability. Here’s how to take a closer look:
1. Precisely Identify Your Dependency:
First, determine exactly which Cal.com product or version underpins your operation. Are you using the hosted, closed-source commercial service? The new Cal.diy MIT-licensed project, which is independently maintained and self-hosted? Or an older self-hosted deployment based on the now-defunct public codebase? If you’re an enterprise self-hoster, you may receive an invitation to a private repository; otherwise, Cal.diy is likely your only open route forward. Grasping this distinction is critical, as each option comes with drastically different levels of transparency, community support, and long-term control.
2. Audit Your Full Risk Model:
Consider the possible impact if your current path becomes unavailable or unsupported.
3. Align Your Priorities With Your Choices:
4. Go Beyond “Public Repo” Thinking:
In today’s landscape, simply seeing a GitHub repository is no longer sufficient as a marker of true openness or future-proofing. Dig deeper:
5. Develop a Contingency Plan:
6. Institutionalise Due Diligence:
Make these assessments a regular part of your Technology review process, not just for Cal.com, but for any critical infrastructure. The questions may seem tedious, but they are essential to avoid vendor lock-in, sudden loss of control, or costly last-minute migrations.
7. Share Knowledge Across Your Organisation:
These steps might seem dull or excessively careful, but they’re the foundation for real digital independence and steady operations. As the meaning of “open” keeps changing, asking these questions and adopting these practices will help you avoid surprises and maintain control over your digital future.

RT @MiniMax_AI: Schön zu sehen, dass @openclaws Arbeit wieder aufgenommen hat. Ein kleiner Flex: MiniMax ist das einzige Labor mit Abonnements für beide Seiten des Stacks — OpenClaw und den Hermes-Agenten von @NousResearch. 🛠️ Self-hosted → Token-Plan ab $10/Monat auf-minimax.io/subscrib… ☁️ Cloud-hosted (MaxClaw / MaxHermes) → MiniMax Agent auf agent.minimax.io/pricing Wähle deinen Loop. Dan McAteer (@danielmac8) Anthropic erlaubt OpenClaw-Nutzung wieder. Aus @openclow docs. — https://nitter.net/danielmac8/status/2046547526413644272#m
mehr auf Arint.info
#AI #CloudComputing #LLM #MachineLearning #OpenSource #arint_info
https://x.com/MiniMax_AI/status/2046772123054538909#m
How are the negotiations going regarding #Ukraine becoming the 52nd state of the #USA?
Codex стає інструментом для enterprise-компаній #technology #it #opensource #freeinternet - https://proit.ua/codex-staie-instrumientom-dlia-enterprise-kompanii/
New anti-transmasc asshole to #FediBlock : https://defcon.social/@Tetsuo/116428161250601507
Image attached is a screenshot in case the post gets deleted. Content warning for the above stated, as well as reality-denying & baseless accusations.

Nurses condemn California Assembly’s failure to advance CalCare
https://lemmy.world/post/45922728
#TuneTuesday
Kereta Api Argo Bromo Anggrek di pinggir pantai Batang Jawa Tengah
#beach #sea
#keretaapi
#trainphotography
#streetphotography
#photography
#train
#instagram
#railwayphotography
#fotosepur
#traveling
#indonesia

Wind und Solar schlagen Gas: Erstmals erzeugt die EU mehr Strom aus erneuerbaren Quellen als aus fossilen Brennstoffen.
https://denkstrom.org/artikel/europa-erneuerbare-rekorderzeugung-q1-2026/
#GoodNews #GuteNachrichten #Solar #EU #FediNews #Newstodon #Presseschau #Nachrichten #Deutschland #Fediverse
#Takaichi Self Defence Force #X #Twitter #Japan ( by ur tax n profitable groups from all over the world
川口クルド人会見動画が旧映像と判明、送還議論再燃
三陸沖地震で中国SNSに過激コメント相次ぎ日本で反発広がる
石破前首相、高市政権の外交に評価と進言もXで反発相次ぐ
靖国神社春季例大祭に126人超の国会議員が参拝 高市首相は真榊奉納
こども家庭庁、外国人児童への児童手当不正受給件数・総額を把握せず
https://www.youtube.com/watch?v=iwzPOPSDYmg&feature=youtu.be
https://x.com/explore/tabs/news
Kereta Api Argo Bromo Anggrek di pinggir pantai Batang Jawa Tengah #beach #sea #keretaapi #trainphotography #streetphotography #photography #train #instagram #railwayphotography #fotosepur #traveling #indonesia @bskyphotos.bsky.social@bsky.brid.gy


Ich zocke Rainbow Six Siege auf #twitch
https://www.twitch.tv/liebeskrieger
@LitteRatty joins Mastodon on 21 April and has to spend the next 24 hours reading all the friendly welcome replies.
Gotta love the #Fediverse 🙂

Von der Sovereign Tech Agency bekommt das Mastodon-Team 614.000 Euro für die Arbeit an Funktionen, von denen bald das ganze Fediverse profitieren soll. #Mastodon
Mastodon: Förderung für Arbeit...
Mastodon: Förderung für Arbeit an verschlüsselten Direktnachrichten und mehr
Von der Sovereign Tech Agency bekommt das Mastodon-Team 614.000 Euro für die Arbeit an Funktionen, von denen bald das ganze Fediverse profitieren soll.
#IT #Mastodon #Mobiles #OpenSource #SocialMedia #news
Inscreva-se no canal lá no youtube e fique por dentro das novidades e últimos lançamentos : https://www.youtube.com/@mcoutravibe_ofc
#youtube #bregafunk #funk #news #music #musica #fyp #fy #explore
📰 Spedizioni più lente e materie prime più care: così il prezzo dei preservativi sale del 30% a causa della guerra
#️⃣ #ECONOMIALAVORO #CrisiUsaIran #Iran #Israele #MedioOriente #Negoziatidipace #USA #OpenOnline #TheLabSocial #News #Notizie #Italia
ChatGPT Images 2.0: Neuer Bildgenerator setzt vor allem auf besseres Verständnis https://www.computerbase.de/news/apps/chatgpt-images-2-0-neuer-bildgenerator-setzt-vor-allem-auf-besseres-verstaendnis.97015/ #openai #chatgpt #image2
Крок назад чи маневр? Renault та Geely представили модуль, що перетворює електромобілі на гібриди #technology #it #opensource #freeinternet' - https://gagadget.com/uk/electric-vehicles/706202-krok-nazad-chi-manevr-renault-ta-geely-predstavili-modul-shcho-peretvoriuie-elektromobili-na-gibridi/
Lama odiata,
agito tremenda questa infinita nottata
e penso a te che sei la voce stellata,
unica capace di cambiar la mia strada.
South Korean police seek to arrest K-pop mogul behind BTS
SEOUL, South Korea — South Korean police said Tuesday they are seeking to arrest music mogul Bang Si-Hyuk,…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Entertainment #Business #Generalnews #Lawenforcement #Mediaandentertainmentindustry #Worldnews
https://www.newsbeep.com/us/599215/

Researchers Find ‘Surprising’ Outcome In Loneliness And Memory Study
As society continues to grapple with the public health issue of loneliness, researchers have recently found a “surprising”…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Health #aging #dementia #loneliness #memoryloss
https://www.newsbeep.com/us/599213/

Mike Vrabel’s Tuesday press conference was unannounced and unexpected
Tuesday’s press conference from Patriots coach Mike Vrabel was a surprise to everyone. Including the reporters who cover…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Sports
https://www.newsbeep.com/us/599212/

U.S. closer to net oil exporter status
An oil pump jack in Kansas. Photo by Scott Canon/Kansas News Service By JOHN P. TRETBAREagle Media The United…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Economy #Business
https://www.newsbeep.com/us/599210/

LG G6 vs. LG G5: I compared the latest OLED TV models, and it’s a surprisingly tough choice
Kerry Wan and Adam Breeden/ZDNET Follow ZDNET: Add us as a preferred source on Google. When it comes to high-end…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Mobile #Technology
https://www.newsbeep.com/us/599206/

Exclusive: ICE Glasses
https://lemmy.zip/post/62987248
Comment je me sens quand j'apprends que WhatsApp va devenir payant alors que moi j'utilise Delta Chat (aka @delta )
#Chat
#Communication
#WhatsApp
#DeltaChat
#OpenSource
#Decentralisation

Nächste Trockenphase in Mitteleuropa kommt, bis Ende des Monats April kaum noch Regen in Deutschland: https://www.wetterkontor.de/de/filme/wolken-niederschlag-europa.asp

#askfedide
Leute, ich werd blöde.
Gibt es einen gangbaren Weg, Daten einer Wetterstation von #WeatherCloud oder #WUndergrond auf einer #Wordpress-Seite darzustellen?
Ich hab ein Plugin von Wetternetzwerk installiert. das ist optisch eher so mittel und es fehlen Daten :(
naturbad-siegbach.de
There is a clearer way to host your knowledge beyond the usual clouds 🌥️
XWiki Cloud gives teams a managed way to run XWiki without giving up open source, structured knowledge, and the freedom to adapt the platform to real needs.
Because cloud should make things easier, not lock things down.
👉 https://xwiki.com/en/offerings/services/cloud-hosting
#OpenSource #XWiki #XWikiCloud #tech

自動作詞作曲AI最新版「Suno v4」の概要と使い方+サンプル曲! ~リマスター機能・カバー機能+ChatGPTを使って楽曲自動生成~
#chatgpt #チャットgpt #機械学習 #画像生成 #AI画像 #AIイラスト #画像生成ai #画像生成ai無料 #BingChat #GPTs #copilot #sora #claude #Google #Gemini #AI #音楽生成 #音楽生成 #chatgpt #チャットgpt #...

⚠️ Decentralized design amplified DDoS impact across nodes Attackers targeted #Bluesky’s infrastructure layer, overwhelming relay servers rather than the app itself, causing cascading outages despite its decentralized architecture #ransomNews #DDoS #SocialMedia

⚠️ Decentralized design amplified DDoS impact across nodes Attackers targeted #Bluesky’s infrastructure layer, overwhelming relay servers rather than the app itself, causing cascading outages despite its decentralized architecture #ransomNews #DDoS #SocialMedia

March 2026 Phishing Email Trends Report
In March 2026, trojans represented 21% of attachment-based threats, while phishing attacks using fake pages dropped from 42% to 15% month-over-month. Script-based malware increased significantly, with HTML at 14% and JavaScript at 11%. Compressed files including ZIP (14%), RAR (8%), and 7Z (5%) were common distribution methods. Document-based threats utilized PDF (13%), XLS (5%), and DOCX (2%) files. Attackers impersonated courier services like FedEx and DHL, as well as financial institutions including Hana Bank and Woori Bank. Distribution methods included HTML scripts and PDF hyperlinks leading to credential-stealing pages. Notable malware families included RemcosRAT and AgentTesla, with command-and-control infrastructure utilizing Telegram API tokens and external mail servers for data exfiltration.
Pulse ID: 69e8738326fb86b891dd3c1f
Pulse Link: https://otx.alienvault.com/pulse/69e8738326fb86b891dd3c1f
Pulse Author: AlienVault
Created: 2026-04-22 07:06:43
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #Email #HTML #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #PDF #Phishing #RAT #Remcos #RemcosRAT #Telegram #Tesla #Trojan #ZIP #bot #AlienVault
#QEMU 11.0 Introduces New CPU Model for Intel Diamond Rapids, Many #ARM and #RISCV Improvements https://9to5linux.com/qemu-11-0-released-with-new-cpu-model-for-intel-diamond-rapids
#OpenSource #virtualization #Linux

New Release: v18.2.7 is now available!
https://github.com/super-productivity/super-productivity/releases/tag/v18.2.7
#SuperProductivity #OpenSource #Release
New Release: v18.2.6 is now available!
https://github.com/super-productivity/super-productivity/releases/tag/v18.2.6
#SuperProductivity #OpenSource #Release
AI slop videos aimed at babies are 'garbage,' says pediatrician
A new wave of AI-generated YouTube videos aimed at toddlers and preschoolers are raising concerns among child development experts and advocates who say it could harm early childhood development. They're calling for YouTube parent company Google to change how the videos are displayed and distributed on the platform.
https://www.cbc.ca/news/canada/ai-baby-slop-9.7166873?cmp=rss

Mach-O Man Malware: What CISOs Need to Know
Lazarus Group is conducting an active campaign targeting businesses through ClickFix attacks, distributing a newly identified macOS malware kit called "Mach-O Man". The attack begins with fake meeting invitations via Telegram, redirecting victims to fraudulent collaboration platforms impersonating Zoom, Microsoft Teams, or Google Meet. Victims are tricked into executing terminal commands that install the malware. The kit consists of Go-based Mach-O binaries including a stager, profiler, persistence mechanism, and stealer. The malware collects credentials, browser data, and macOS Keychain entries, exfiltrating data through Telegram. Primary targets include fintech, crypto, and high-value environments where macOS is prevalent. The campaign leverages social engineering and native macOS binaries to evade traditional EDR detection, ultimately enabling account takeover, unauthorized infrastructure access, and financial loss.
Pulse ID: 69e82714e5cf2d1fb9fe1b0a
Pulse Link: https://otx.alienvault.com/pulse/69e82714e5cf2d1fb9fe1b0a
Pulse Author: AlienVault
Created: 2026-04-22 01:40:36
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #EDR #Google #GoogleMeet #InfoSec #Lazarus #Mac #MacOS #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RAT #SocialEngineering #Telegram #Zoom #bot #AlienVault
TYPO3 v14 LTS ist da – und Redakteure profitieren direkt im Alltag.
In unserem neuen Blogbeitrag schauen wir uns an, was die neue LTS-Version für Redakteurinnen und Redakteure wirklich besser macht: vom modernisierten Backend über Bookmarks bis hin zu QR-Codes, Kurz-URLs und dem neuen Context Panel.
Zum Beitrag:
https://www.clickstorm.de/blog/typo3-v14-redakteure/
#TYPO3 #TYPO3v14 #CMS #Webentwicklung #Redaktion #OpenSource #LTS
Click-bait YouTube video titles are really stupid. One category I tend to always skip is the "This <something> really BROKE the Internet". There are many of these so I can assume it is very easy to broke the internet these days.
American living in UK shares four British things that 'feel illegal' but aren’t
https://fed.brid.gy/r/https://www.mirror.co.uk/lifestyle/american-living-uk-shares-four-37051539

😱
https://www.heise.de/en/news/Less-Cloud-More-Control-PHP-Moves-Back-to-Own-Data-Center-11267214.html

📝 Nachtrag zum 2. Friendica-Admin-Treff (15.04.2026)
Ein herzliches Dankeschön an die Entwickler @tobias , @heluecht und @art4 für den offenen und konstruktiven Austausch mit den Friendica-Instanzbetreiber:innen und Admins 🙌
Der Dialog war durchweg hilfreich und hat gezeigt, wie wertvoll der direkte Austausch zwischen Entwicklung und Praxis ist.
💡 Themen waren unter anderem:
• die kommende Friendica-Version inkl. Relais
• Moderation: Übersicht der Reports
• Moderation: Blocklisten entfernter Kontakte (z. B. von anderen Knoten, speziell Bluesky)
• Dateiverwaltung (z. B. PDF) inkl. Funktionen zur Verwaltung und Löschung
• Addon „blockbot“
• und vieles mehr
🤝 Ein gesunder Austausch ist wichtig – er hilft allen weiter, ob Admins oder Entwickler:innen.
Im direkten Gespräch lassen sich Missverständnisse schnell klären und Lösungen finden. Der ein oder andere Aha-Moment war definitiv dabei!
🚀 Mitmachen erwünscht!
Ein wichtiger Punkt wurde ebenfalls betont: Für das Projekt Friendica werden weiterhin engagierte Entwickler:innen gesucht.
Gemeinsam können wir Friendica weiterentwickeln – es gibt noch viel zu tun!
👉 github.com/friendica/friendica…
Auch abseits der Entwicklung kann jede:r beitragen, z. B. durch:
• Übersetzungen
• Dokumentationen und Beschreibungen
• Tests und Feedback
💚 Jeder kleine Beitrag zählt. Alles geschieht freiwillig und dient der Gemeinschaft. Es liegt an uns, dieses wertvolle Projekt lebendig zu halten.
📅 Nächster Termin:
3. Friendica-Admin-Treff
🗓 Montag, 11. Mai 2026
🕢 19:30 Uhr
👉 Termin vormerken und gern wieder dabei sein!
🇩🇪 Hinweis:
Die Veranstaltung findet in deutscher Sprache statt. Wir bitten um Verständnis.
#friendica #admin #fediverse #friendicaadmintreff #instanz
Wine 11.7 Rewrites MSXML, Fixes 35 Bugs
Wine 11.7 arrives with the start of MSXML rewriting, VBScript improvements, 7.1 audio support, and 35 bug fixes across applications and games.https://yoota.it/en/wine-11-7-rewrites-msxml-fixes-35-bugs/

🐧 Mozilla using Claude Mythos AI Preview to help fix major security issues in Firefox
The recent Firefox 150 release includes fixes for 271 vulnerabilities identified using Claude Mythos Preview AI.Read the full article on GamingOnLinux.
📰 Source: GamingOnLinux Latest Articles
🔗 Link: https://www.gamingonlinux.com/2026/04/mozilla-using-claude-mythos-ai-preview-to-help-fix-major-security-issues-in-firefox/
#Linux #OpenSource #AI #ArtificialIntelligence
🏆 Thanks to our Silver Sponsor exocad!
They bring digital precision to dentistry with CAD/CAM software used in real-world workflows.
Glad to have them as part of PyCon DE & PyData 2026.

🚀 This Week in RAG & Vector Databases: Fastest-Growing Projects — April 22, 2026
This week in the RAG & Vector Databases space, we're seeing a surge in innovative tools that leverage Retrieval-Augmented Generation (RAG) to improve document search, threat intelligence analysis, and...
Read full report → https://pullrepo.com/report/this-week-in-rag-vector-databases-fastest-growing-projects-april-22-2026
#AI #OpenSource #GitHub #Tech #RAGVectorDatabase
Wine 11.7: riscrittura di MSXML avviata, 35 bug corretti
Wine 11.7 è disponibile con l'avvio della riscrittura di MSXML senza libxml2, miglioramenti a VBScript, supporto audio 7.1 e 35 correzioni tra applicazioni e giochi.https://yoota.it/wine-11-7-riscrittura-di-msxml-avviata-35-bug-corretti/

Schwerer Rückfall / Buds ‘n Leaves – Jedoch unbedingt Sehenswert – Von Rolf Noe
Bei meinem Osterbesuch im wilden Garten einer meiner Töchter hatte ich außer meinem 20er noch mein 60er Makro-Objektiv dabei und so bin ich am frühen Morgen gleich nach der Meditation und dem ersten Kaffee raus in den kühlen, aber sonnigen Garten und habe mich auf die Jagd nach der Schönheit gegeben. Verzaubert von den knospenden Sträuchern und Bäumen habe ich angefangen das aufkeimende Grün einzufangen
https://photo-philosophy.net/schwerer-rueckfall-buds-n-leaves/
#Artikel #Ostern #Photographie #RolfNoe #wordpress #wwwPhotoPhilosophyNetBusting the Biggest Myths in Neuroscience | Dr Dean Burnett | Instant Genius podcast
https://youtu.be/JQYtTcNSHak?si=0OBLlCwdJtoO4HN-
Dean Burnett answers quickfire questions about familiar brain myths, for the Instant Genius Podcast
#Brains #Myths #BadScience #Youtube #Podcast
The Mariupol City Council provided details on the recent destruction of the Manhush site. "The war criminal occupiers destroyed a mass burial of residents in the village of Manhush near Mariupol #Ukraine -this is exactly where people who died during the siege of the city in 2022 were buried."
The terrorist russian invaders have killed approximately 100,000 civilians in Mariupol, and this is a confirmed number. Mykhailo Romanov, an expert at the Kharkiv Human Rights Protection Group, reported during the presentation of a legally substantiated submission to the International Criminal Court about the genocide of people in Mariupol by the terrorist russian invaders at the Ukrinform press center.
https://en.wikipedia.org/wiki/Siege_of_Mariupol
#eu #europeanunion #europe #news #France #Italy #Spain #uk #usa
@natweaver I use #Emacs Org Mode for idea and research notes and plaintext first drafts, with #Git (through the Magit interface) for version control. After drafting on my own I export to .odt or .docx for editing on #LibreOffice and sharing/submitting. For one huge project I use #TiddlyWiki for interconnected, citation-tracked research notes. Still migrating my notes over from #Zotero for that last part.
#Trump aktuell zur #Schweiz: Zölle wieder "etwas erhöhen", Schweiz sei nicht die Elite, sondern USA (🤭) Schon mal mit Finger auf dem Globus China gesucht? Schon mal technologische Entwicklung von BYD mit Ford verglichen?
Chance für Europa: Reduktion der Geschäfte mit US-Tech-Monstern
Seeländer #Postillion: Erster #Naturforscher der #Schweiz führt Chüngeli auf unberührter Insel im #Bielersee ein und gibt so der Insel ihren Namen, damit sie später Teil eines viel grösseren #Naturschutzgebiet wird.
#wandern #bern #schiffahrt #rebberg

Instagram is testing premium features. Will people pay?
Instagram is testing a premium subscription that, for a monthly fee, allows users to extend the life of their story posts, "spotlight" their stories to put them at the front of followers' feeds and see how many people have rewatched their stories. It's part of an industry-wide shift away from services that are free and equal for all users — a shift that some say ...
https://www.cbc.ca/news/business/instagram-plus-rollout-9.7172486?cmp=rss

A video of this crane: https://youtu.be/e5wU3vx2-jQ
Abandoned crane (Alter Kran) Germany Dec 2022
#urbex #abandoned #photography #YouTube #lostplace #Germany #railway

Sortir de VMWare, mais pour aller où ? Le Guide du Voyageur Intergalactique de la Virtualisation
Dans ce talk, Thibaut Demaret, Directeur technique @worteks_com vous guide pour définir vos besoins réels et choisir la solution open source qui vous correspond : Kubernetes, OpenStack, oVirt, Podman… et bien d’autres.
Ne laissez pas vos infrastructures dépendre d’une seule option et visionnez le replay maintenant : https://www.youtube.com/watch?v=KarNqsHnMa8

OpenAI launches a $100/month ChatGPT Pro tier focused on coding to compete with Claude and other AI coding assistants.
https://lifebriefly.news/chatgpts-new-100-a-month-plan-is-all-about-coding-and-competing-with-claude

Less Cloud, More Control: PHP Moves Back to Own Data Center
PHP development is increasingly taking place outside the cloud. PHP 8.3 is mostly used. Windows is experiencing a comeback among operating systems.
#Docker #IT #Kubernetes #Linux #PHP #Webentwicklung #Windows #news
💬2nd Day of Workshops at #Symfony_Live 2026!
Great atmosphere, great discussions, thank you all for your energy and participation! 🙌
Let’s keep it going!💥
#Symfony #Berlin #PHP #TechEvent

Wishing everyone a great time at Libre Graphics Meeting by Strong Type Systems GmbH, a #hybrid event starting today in Zollhof in #Nuremberg, #Germany and #online on the Internet
Find out more on
https://foss.events/2026/04-22-libre-graphics-meeting.html
Follow the official account: @lgm
Connect via official hashtag(s): #LGM #LibreGraphicsMeeting #LGM26NBG
#foss #floss #freesoftware #opensource #events #europe
AI slop videos aimed at babies are 'garbage,' says pediatrician
A new wave of AI-generated YouTube videos aimed at toddlers and preschoolers are raising concerns among child development experts and advocates who say it could harm early childhood development. They're calling for YouTube parent company Google to change how the videos are displayed and distributed on the platform.
https://www.cbc.ca/news/canada/ai-baby-slop-9.7166873?cmp=rss

#JournéeDeLaTerre 🌍 Chez #Capensis, on s'engage pour les butineuses !
On vous parle souvent de #SouverainetéNumérique mais il y a une autre souveraineté qui nous tient à cœur : celle de nos écosystèmes.
C'est pourquoi, pour chaque nouveau client #Canopsis, notre solution d'hypervision #OpenSource, nous parrainons l'installation d'une ruche avec #UnToitPourLesAbeilles !
Notre bilan :
🍯 10 ruches parrainées
🐝 400.000 abeilles protégées
🌻 3.800 m² de jachère mellifère plantés

GhostBSD 26.1: FreeBSD desktop with XLibre and ZFS snapshots
GhostBSD 26.1 integrates FreeBSD 15.0p2, uses XLibre and offers improved hardware support and ZFS snapshots.
#Betriebssystem #BSD #FreeBSD #IT #Linux #OpenSource #Security #Wayland #Xfce #news

#Trump aktuell wieder zur #Schweiz: Zölle wieder etwas erhöhen, Schweiz sei nicht die Elite, sondern die USA (die USA 🤭)
Chance für die Schweiz und Europa: Reduktion der Geschäfte mit US-Tech-Monstern
FYI: Dresden court hits Meta with €1,500 GDPR fine over Instagram tracking: A German appeals court on April 13, 2026, ordered Meta to pay €1,500 in GDPR damages for tracking an Instagram user via Business Tools on third-party sites. https://ppc.land/dresden-court-hits-meta-with-eur1-500-gdpr-fine-over-instagram-tracking/ #Dresden #Meta #GDPR #Instagram #Datenschutz
Falls jemand hier (a) auf #LinkedIn ist, (b) Lust auf #Wandern hat, und (c) irgendwo in Einzugsbereich von #Köln und #Bonn lebt:
Eine gute Freundin von mir will sich motivieren mehr zu wandern, und will daher am 2. Mai auf den #Drachenfels bei #Königswinter steigen. Es würde mich freuen, wenn da noch ein paar andere Leute mitmachen!
Pues ya estamos en la v4.5.9 de #Mastodon. Y hasta funciona y todo!!
Version 32.1.2 de OBS Studio, popular aplicación para potenciar la grabación de video y transmisión en directo a través de plataformas como Twitch, TikTok, Youtube y similares: https://www.dekazeta.net/foro/files/file/1869-obs-studio/
#OBSStudio #Youtube #Twitch #TikTok #Streamer #Stream
Most PDF tools push you to upload your files somewhere which is what not many feel comfortable with. That’s where KillerPDF solves the problem. It handles the usual stuff. Open PDFs, edit text, highlight things, merge files, split pages. The text editing part is better than expected, it tries to match the original font instead of breaking the layout. There’s search, annotations, signatures, all the basics you’d normally reach for Acrobat to do.
https://firethering.com/killerpdf-open-source-pdf-editor/.
#opensource #pdf #adobe
🐧 Australia targets Steam, Roblox and others in new legal push against extremists and predators
Australia's eSafety agency sent legal notices to Valve / Steam, Roblox, Minecraft and Fortnite to explain how they're fighting sexual predators and extremists.Read the full article on GamingOnLinux.
📰 Source: GamingOnLinux Latest Articles
🔗 Link: https://www.gamingonlinux.com/2026/04/australia-targets-steam-roblox-and-others-in-new-legal-push-against-extremists-and-predators/
#Linux #OpenSource #SteamDeck #PCGaming #AI #ArtificialIntelligence
🎥 À 17h, @oamgui.bsky.social@bsky.brid.gy part en live pour des #DocuNature mortel ➡️ twitch.tv/oamgui #twitch #vulgarisation #ecologie #documentaire #nature

🎥 À 17h, @oamgui.bsky.social@bsky.brid.gy part en live pour des #DocuNature mortel ➡️ twitch.tv/oamgui #twitch #vulgarisation #ecologie #documentaire #nature

🐧 Actu logiciel libre du 22/04/2026
• Firefox: The zero-days are numbered
[LWN.net] https://lwn.net/Articles/1068906/
#LogicielLibre #OpenSource #Libre
git-stage-batch helps you build a sane #git history incrementally, by letting you stage code changes hunk-by-hunk/line-by-line. https://halfline.github.io/git-stage-batch
Tag der Arbeit: Gewerkschaften warnen vor Chaos-Initiative

Как создать базу данных на своём сервере с помощью Coolify
Coolify это бесплатный инструмент, который позволяет легко запускать приложения на ваших серверах и управлять ими через визуальный интерфейс. В прошлых статьях мы уже разобрались, как подготовить сервер , затем установить на нём Coolify и запустить простые приложения из GitHub. А сегодня посмотрим, как с помощью Coolify создать базу данных на своем сервере и какие преимущества это даёт.
https://habr.com/ru/companies/timeweb/articles/1015374/
#coolify #базы_данных #хостинг #selfhosting #paas #docker #вебразработка #деплой #postgresql #timeweb_статьи
Handling media across wildly different social APIs is the wild west. 🤠
I just rebuilt Maia’s publishing engine. Now it flawlessly handles video compression, AVFoundation thumbnail extraction, and routing for Bluesky & Mastodon all in one tap. ✨
#buildinpublic #iosdev #swiftui #fediverse #bluesky
@opendatacoder@norden.social Hallo und willkommen im #Fediverse
Dem Netzwerk wo so viel mehr möglich ist, als vielen überhaupt bewusst ist
https://fediversum.info/
@oklabflensburg@norden.social
I was struck by this: "The “community” we speak of does exist, even if it’s fragmented, marginal, and ignored. You’ll find it in squats, permaculture collectives, activist media spaces, messy corners of the #Fediverse... But it’s real. I’ve lived inside it for decades."
Me too - but mostly quite apart from any tech-related activity. I worked in the co-operative and social enterprise movement - community and worker co-ops, communes, NGOs developing self-financing activities, state employees 'stepping out' to combine their public-service ethos with independent income generation...
What struck me is that these spaces are not really that fragmented, marginal, or ignored. My clients included governments, local authorities, the NHS, some of the world's biggest NGOs (like Oxfam) - and little start-ups that have since become really big, multinational, and financially strong.
But I always felt there was a disconnect between the alternative tech movement - open source, open standards, etc - and most of my clients - who were primarily focused on environmental action, social justice, alternative lifestyles...
I see fault on both side in this disconnect, but underlay by the very same failure: to understand that resistance to privatisation of online spaces is an aspect of the old fight against 'enclosures' of any kind - at bottom, against capitalism's fundamental mechanism of over-exploitation of both people and planet; part of an enormous, old and indestructable human reaction to bad economics.
💙 Dein Wissen macht den Unterschied in der Pflege!
Du willst dein Wissen weitergeben und Menschen auf ihrem Weg in den Pflegeberuf begleiten?
Dann findest du hier ein Umfeld, das Praxisnähe, moderne Lehre und Teamarbeit verbindet.
Nimm noch heute Kontakt mit uns auf.
📧 info@lehrcare.de
📞 030...https://www.instagram.com/p/DXXpYOgGfWe/
#Schule #lehrer #lehrerin #stellenmarkt #jobs #stellenanzeigen #personalberatung #pädagogen #pädagogin #erzieher #erzieherin #deutschland

ArchVizPRO Interior Vol.2 URP - Industrial Loft #Archviz #Interior #Loft #Urp #Unity #Industrial #Lighting #Texture #Prefabs #Script #Shadergraph #Vfxgraph #AssetStore
https://u3dn.com/packages/archvizpro-interior-vol-2-urp-industrial-loft-281948
@opendatacoder Willkommen im #Fediverse. 👋
Any piece of Software that lets you share Media with others, be it #messengers like #signal or SMPs like #mastodon or #bluesky, should prompt you to decide, whether you want to keep, change or delete the #metadata of the media file.
The same goes imo for any application, that lets you insert media files into larger documents, like #zettlr, #joplin, #LibreOffice, etc.
All these applications should offer both, a default setting AND a per-file prompt/switch that allows to make this decision.
This is BETTER than stripping metadata silently by default because:
* it creates awareness for the issue with the user base.
* I do not have to remember for each application I work with, how it handles the problem. (I should not have to read through the docs for this!)
* thus I will not have to use third party tools to remove metadata each time i share a pic, when it is actually done by the main application anyway.
* last but not least, there are cases where it is better or even important to preserve metadata.
#foss #privacy #privacybydefault
3 LABELS FROM FLORIDA : BREAKS
AUDIO : https://ahp.li/cff05a43edf00ab5fe65.mp3
#nowplaying #mastoart #music #musica #release #podcast #radio #art #digitalArt #mix #musique #bass #streaming #stream #audio #media #show #party #electronic #muzik #play #releases #mastodon #beats #newmusic2026 #label #edm #podcasts #club #BreakingNews #dance #dj #download #france #europe #world #mix #label #socialmedia #bigbang #news #playlist #sounds #social #breaks #media #artistic #bigbang #spotify #playlist #breaking
Are there any good critical analysis about comparing Mastodon/Fediverse vs. Bluesky/Eurosky?
Is this a symbiosis or an either/or?
Just checked out #Eurosky and it seems like an entry page to the Fediverse, but the apps have different names...
Does a more centralized infrastructure like the one from #Bluesky help with investors/states?
@leonido @structural_integrity @thothiel @ANosthoff @kuketzblog @ntnsndr
Was sind denn so eure liebsten Ikea-Alternativen in der Schweiz? Am liebsten halbwegs nachhaltig und nicht unfassbar teuer 🙈
What are your favourite Ikea-Alternatives in Switzerland? Preferably somewhat sustainable and not absurdly expensive 🙈
『荻上チキ・Session』 4月22日(水) - YouTube
https://www.youtube.com/watch?v=6NpSmHQRPWg
荻上チキ・Session(TBSラジオ) (@session.tbsradio.jp)
2026年4月22日 16:55
"
【告知】4/22(火)ラインナップ
▷17:05~「トランプ大統領 停戦延長も海上封鎖は継続 行方は不透明 」(神保哲生)
▷17:45~チキ'sコラム
▷18:00~安田菜津紀さん「“パレスチナ人死刑”法案」
▷19:05~特集「高市政権発足から半年」(冨名腰隆、岩田夏弥)
*番組参加でチキさんの新刊を!
https://radiko.jp/share/?sid=TBS&t=20260422170000 #ss954
"
https://bsky.app/profile/session.tbsradio.jp/post/3mk2zhyvcuf2w
誤:4/22(火)→正:4/22(水)
Weniger Cloud, mehr Kontrolle: PHP wandert zurück ins eigene Rechenzentrum
Die PHP-Entwicklung findet immer häufiger abseits der Cloud statt. Meist kommt dabei PHP 8.3 zum Einsatz. Bei den Betriebssystemen erlebt Windows ein Comeback.
#Docker #IT #Kubernetes #Linux #PHP #Webentwicklung #Windows #news
#LinkedIn introduced Cognitive Memory Agent (CMA) as part of its generative AI application stack to enable stateful, context-aware AI systems that retain and reuse knowledge across interactions.
The goal: address a key limitation of LLM workflows - statelessness and the resulting loss of continuity across sessions.
Learn more: https://bit.ly/4u2epx4
#SoftwareArchitecture #AI #AIagents #DistributedSystems #LLMs #InfoQ

ChatGPT Images 2.0 : OpenAI promet des images plus fidèles et un meilleur rendu du texte http://dlvr.it/TS91g6 #ChatGPT #OpenAI
AI slop videos aimed at babies are 'garbage,' says pediatrician
A new wave of AI-generated YouTube videos aimed at toddlers and preschoolers are raising concerns among child development experts and advocates who say it could harm early childhood development. They're calling for YouTube parent company Google to change how the videos are displayed and distributed on the platform.
https://www.cbc.ca/news/canada/ai-baby-slop-9.7166873?cmp=rss

🛡️ #Cybersecurity news & tips across the #fediverse
“Engadget: Homeland Security reportedly wants to develop smart glasses for ICE https://www. engadget.com/wearables/homelan d-security-reportedly-wants-to-develop-smart-glasses-for-ice-093449347.html @ Engadget ...”
https://infosec.exchange/@AAKL/116443939794322985
🤖 via RSS feed. Not an endorsement.
Анализ и модернизация коннектора баз данных с помощью AI-агентов
4-я статья из цикла туториалов о вариантах кастомизации своего бизнес-портала в Битрикс24. Сегодня рассказываем о работе с уже существующим проектом через AI-агентов. ИИ хорошо справляется с созданием новых приложений, но при работе с готовыми проектами чаще возникают сложности — например, при разборе архитектуры и внесении изменений без поломок В статье проанализируем существующий проект BI-коннектора, который нужен для работы с аналитикой, подключим его к порталу, покроем тестами и оптимизируем работу с базами данных. По ходу работы подробно разберём устройство проекта, его назначение и использование для бизнес-целей.
https://habr.com/ru/companies/bitrix/articles/1026102/
#битрикс24 #битрикс_отладка_вебразработка #crm #ai_agent #вайбкодинг #бэкенд #api #docker #sql #automation
Hackaday: DIY Smart Button Gets Surprisingly Complicated
https://hackaday.com/2026/04/22/diy-smart-button-gets-surprisingly-complicated/
#linux #opensource #tech
🇺🇲 The U.S. has run through over half of its stockpiles of key air defense missiles during the nearly two-month war on #Iran
https://kyivindependent.com/war-in-iran-has-used-up-half-of-us-patriot-and-thaad-missile-stockpiles/