Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted
Last month the Arch Linux User Repository āAURā saw more than 1,500 malicious packages amid a sophisticated malware attack and then also seeing an influx of spam and profanities amid this community/user-maintained repository for the popular Arch Linux distribution. Unfortunately, there is another round of AUR troubles⦠ā Read more
@eldersnake@we.loveprivacy.club Login to https://feeds.twtxt.net/ with your Podās account. Re-create whatever you like. In the end I had to start over, there was too much mess. As you can no doubt imagine, the reason for revamping the feeds service was to thwart SPAM and Junk.
@prologic@twtxt.net Thatās a good way to keep spammers out:
Your browser did not pass the anti-spam check! Please make sure JavaScript is enabled and try again.
It was turned on.
@arne@uplegger.eu Iāve tried Matrix before, it was all good and dandy until servers started getting spammed with stuff no sane human being should see (if you know what I men). So, I took down my server and never looked back.
@balloonfu-sen@yarn.girlonthemoon.xyz Not difficult, Iām just the target of much spam and bots š¢
@balloonfu-sen@yarn.girlonthemoon.xyz The reason for my locking down my own instance here was purely because of spam and bots š¢
Russian Spam and Profanities Are Now Plaguing the Arch Linux AUR
The Arch Linux User Repository āAURā is facing another issue just days after more than 1,500 packages were found carrying malware. According to Phoronix, over 70 AUR packages have reportedly been modified to insert Russian spam and profane messages into usersā shell configuration files. From the report: Nicolas Boichat with his AI/LLM detection bot ⦠ā Read more
Russian Spam & Profanities Are Now Plaguing The Arch Linux AUR
After days of dealing with 1,500+ packages in the Arch Linux AUR containing malware, the latest headache in the Arch Linux User Repository is Russian spam and offensive messages⦠ā Read more
@movq@www.uninformativ.de Hahaha, great timing! :-D I love your article and agree with almost all your points.
On the AI changelog part, though, Iād rather recommend to just not have a changelog at all.
Another important thing for me is the deprecation notice section. What do I need to look out for in the future? Should I start to migrate to another API soon? Even right now? Or does it have time?
While going through these terrible GitHub release pages, I also found these āNew Project Contributorsā sections (yeah, for that, they found the time to make a section) annoying. Donāt get me wrong, sure, credit where credit is due. But come on. Soooooo much space for an inefficiently formatted (and also unsorted) list. At least it was easy enough to skip over it.
And then, there are also these changelogs or rather notice documents in general that are infested with multicolored emojis all over the place. My brainās spam filter kicks in and shoves everything to /dev/null immediately. Itās especially a thing at work.
In my previous work project, we also used the Keep A Changelog Format. That was great. You wouldnāt believe how often I resorted back to that document. At least twice a week, often several times a day. I was very glad that we put in this effort. Of course, writing the changelog took its time, but it was worth every minute and more. Reading a many months old item, it was immediately clear. I was our best customer in that regard.
Now, itās just the same auto shitshow with MR titles in a rolling date-versioned release scheme. Itās just our team who has to deal with that, though. I think Iām the only one who is not a fan of it.
Drug Sites Hijacked Spotifyās Search Ranking Through Fake Podcasts, Report Finds
A joint congressional report describes a spam operation that turned tens of thousands of fake podcasts into search-engine bait for illegal pharmacy and scam sites. ā Read more
Companies Are Using Reddit To Manipulate ChatGPT and Google AI Search
An anonymous reader quotes a report from 404 Media: The moderators of the biohacking subreddit say that peptide and hormone replacement therapy companies have been surreptitiously spamming Reddit in an attempt to get their posts scraped by AI chatbots. The strategy is an effort to systematically manipulate the answers provided by chatbo ⦠ā Read more
How to Block Spam Calls and Spam Texts on iPhone and Android (2026)
Fight the scourge of unsolicited rings and pings from spammers, scammers, and telemarketers. ā Read more
Please donāt spam people looking for employment. Itās just cruel
Earlier I posted in a āWho wants to be hired?ā thread, looking for a place where I could apply my experience in hospitality, food tech and automation.
A couple hours later I received an email:
āHi Ilia,
I saw your comment on the June Whoās Hiring thread. I build production-ready TypeScript and Python systems that integrate LLMs into real workflows, with particular focus on RAG, agent orchestration, and clear blah-blah-blahā
Come on.
I am a forced immigra ⦠ā Read more
Scammers Are Abusing an Internal Microsoft Account to Send Spam Links
āFor months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts,ā TechCrunch reports:
[The scammers] have been able to set up new Microsoft accounts as if they are new customers and use that access to send out ⦠ā Read more
30 WordPress Plugins Turned Into Malware After Ownership Change
Wednesday BleepingComputer reported that more than 30 WordPress plugins āhave been compromised with malicious code that allows unauthorized access to websites running them.ā
A malicious actor planted the backdoor code last year but only recently started pushing it to users via updates, generating spam pages and causing redirects, as per the instruct ⦠ā Read more
Rspamd 4.0 Released For Open-Source Spam Filtering
Rspamd 4.0 is out today as a big update to this powerful open-source spam filtering system⦠ā Read more
Linus Torvalds Drops Old Linux Kconfig Option To Address Tiresome Kernel Log Spam
Following yesterdayās Linux 7.0-rc1 release, Linus Torvalds authored and merged a patch to get rid of the Linux kernelās WARN_ALL_UNSEEDED_RANDOM Kconfig option. While that option was added with good intentions, on some systems it can yield a lot of unnecessary kernel log spam⦠ā Read more
Thereās a Rash of Scam Spam Coming From a Real Microsoft Address
There are reports that a legitimate Microsoft email address ā which Microsoft explicitly says customers should add to their allow list ā is delivering scam spam. ArsTechnica: The emails originate from no-reply-powerbi@microsoft.com, an address tied to Power BI. The Microsoft platform provides analytics and business intelligence from various source ⦠ā Read more
Wow, as I anticipated, this is waaay out of my capabilities to really understand it. But Iām quite happy to just have spotted a mistake in an explanatory comment in section 4.5.2 āThe icode Arrayā. Of course, it should be /e + tc + /i + ni + t\0. Letās hope that my e-mail with the patch actually makes it into Briamās inbox. I fear GMail just hides it in the spam folder.
@lyse@lyse.isobeef.org I even got spam on ICQ, back when ICQ was a thing. I see spam as an innate thing. š
Oh no, spam via Jabber is new for me. Fuck them!
Microsoft Cancels Plans To Rate Limit Exchange Online Bulk Emails
Microsoft has canceled plans to impose a daily limit of 2,000 external recipients on Exchange Online bulk email senders. From a report: The change was announced in April 2024, when Microsoft said that it would add new External Recipient Rate (ERR) limits starting January 2025 to fight spam, with plans to begin enforcing the limit on cloud-hosted ⦠ā Read more
Google To Kill Gmailās POP3 Mail Fetching
Google is quietly killing Gmailās ability to fetch mail from third-party email accounts using POP3, a long-standing feature that has allowed users to consolidate multiple inboxes into a single Gmail interface. The change takes effect this month and also ends Gmailify, the companion feature that applied Gmailās spam filtering and inbox organization to linked third-party accounts.
Google buried ⦠ā Read more
Rob Pike Angered by āAI Slopā Spam Sent By Agent Experiment
āDear Dr. Pike,On this Christmas Day, I wanted to express deep gratitude for your extraordinary contributions to computing over more than four decadesā¦.ā read the email. āWith sincere appreciation,Claude Opus 4.5AI Village.
āIMPORTANT NOTICE: You are interacting with an AI system. All conversations with this AI system are published publicly online by default ⦠ā Read more
@movq@www.uninformativ.de @bender@twtxt.net Iāll also start spamming from my upcoming Vietnam holiday (flying out this Friday) for a couple of soliday weeks š¤£
@bender@twtxt.net Once Advent of Code starts, Iāll start spamming, donāt worry. š
Android shopping list apps disappointed me too many times, so I went back to writing these lists by hand a while ago.
Hereās whatās more fun: Write them in Vim and then print them on the dotmatrix printer. š„³
And, because I can, I use my own font for that, i.e. ImageMagick renders an image file and then a little tool converts that to ESC/P so I can dump it to /dev/usb/lp0.
(I have so much scrap paper from mail spam lying around that I donāt feel too bad about this. All these sheets would go straight to the bin otherwise.)

@prologic@twtxt.net @movq@www.uninformativ.de Same here, I give each service a dedicated e-mail address. Itās very interesting to see how e-mail addresses are transferred to other actors. Luckily, this only happens rarely. But it does happen. In surprising ways.
Aliases not only help to fight spam, but are also a great way to specify filter rules to sort e-mails.
@prologic@twtxt.net FWIW, I love the idea and I do the same with my email domains. Itās the most effective way to fight spam, IMO. š„³
@bender@twtxt.net I think thatās where it sends the capture verification requests. Itās based on PoW, so it has to perform validation somehow. It actually looks pretty decent as far as a way to prevent spam/abuse of forms on the open web (e.g: Waitlist on SnipMail).
I had a looksie (just to be sure) at the database, and they were thankfully legit test events. But this did spark/trigger me to make sure I have some form of anti-spam measures in place. So I added some per-event / per-rsvp rate-limiting and honeypot(s).
This is Spam Musubi ā Read more
@bender@twtxt.net Is dealing with spam fun though? DDoS attacks? DoS attacks? Scans for all kinds of stupid shit� Malware? Advertising? Tracking? Spying? ..
I finally solved the loading issue in my WIP reader, TwtStrm (and apologies again to anyone that got spammed while I was diagnosing the issue).
After another round of coding this weekend, Iām happy to report that it now renders all the twts (with markdown parsing), complete with localstorage and server-based file caching.
User-Agent header. Instead of the URL, the nick is repeated.
@lyse@lyse.isobeef.org Thanks, I think I fixed it now. Sorry for the spam.
@prologic@twtxt.net I know we wonāt ever convince each other of the otherās favorite addressing scheme. :-D But I wanna address (haha) your concerns:
I donāt see any difference between the two schemes regarding link rot and migration. If the URL changes, both approaches are equally terrible as the feed URL is part of the hashed value and reference of some sort in the location-based scheme. It doesnāt matter.
The same is true for duplication and forks. Even today, the ācannonical URLā has to be chosen to build the hash. Thatās exactly the same with location-based addressing. Why would a mirror only duplicate stuff with location- but not content-based addressing? I really fail to see that. Also, who is using mirrors or relays anyway? I donāt know of any such software to be honest.
If there is a spam feed, I just unfollow it. Done. Not a concern for me at all. Not the slightest bit. And the byte verification is THE source of all broken threads when the conversation start is edited. Yes, this can be viewed as a feature, but how many times was it actually a feature and not more behaving as an anti-feature in terms of user experience?
I donāt get your argument. If the feed in question is offline, one can simply look in local caches and see if there is a message at that particular time, just like looking up a hash. Whereās the difference? Except that the lookup key is longer or compound or whatever depending on the cache format.
Even a new hashing algorithm requires work on clients etc. Itās not that you get some backwards-compatibility for free. It just cannot be backwards-compatible in my opinion, no matter which approach we take. Thatās why I believe some magic time for the switch causes the least amount of trouble. You leave the old world untouched and working.
If these are general concerns, Iām completely with you. But I donāt think that they only apply to location-based addressing. Thatās how I interpreted your message. I could be wrong. Happy to read your explanations. :-)
Here is just a small list of things⢠that Iām aware will break, some quite badly, others in minor ways:
- Link rot & migrations: domain changes, path reshuffles, CDN/mirror use, or moving from txt ā jsonfeed will orphan replies unless every reader implements perfect 301/410 history, which they wonāt.
- Duplication & forks: mirrors/relays produce multiple valid locations for the same post; readers see several āparentsā and split the thread.
- Verification & spam-resistance: content addressing lets you dedupe and verify youāre pointing at exactly the post you meant (hash matches bytes). Location anchors can be replayed or spoofed more easily unless you add signing and canonicalization.
- Offline/cached reading: without the original URL being reachable, readers canāt resolve anchors; with hashes they can match against local caches/archives.
- Ecosystem churn: all existing clients, archives, and tools that assume content-derived IDs need migrations, mapping layers, and fallback logic. Expect long-lived threads to fracture across implementations.
@alexonit@twtxt.alessandrocutolo.it I took it down mostly because of continued abuse and spam:l. I intend to fix I and improve the drive and its sister at Summer point š¤
Apologies if Iāve been spamming anyone out there in twtxt-land today.
Iāve been working on a couple of twtxt-related projects, and one of them is a reader (tentatively called twtstrm) written in JS. I used dummy data for the first few stages of development, but now Iām at the point where I need some real data, and that meant hitting up my actual following list.
Of course, it didnāt help that I had a typo in my If-Modified-Since headers, but all that has since been resolved.
Anyways, if I accidentally spammed you with requests today, I am sorry, and it shouldnāt happen anymore.
We thank you for your patience, and apologize for the inconvenience.
I have a Python script that transforms the original YouTube channel Atom feed into a more useful Atom feed by removing the spam description and replacing it with the video duration, filtering out videos by title, duration, etc. I just updated it to exclude the damn Shorts garbage more efficiently. Finally, YouTube updated their Atom feed generation, so that the video URL contains /short/ if itās of this useless kind. Never thought that they ever actually will improve their Atom feeds. Thank you, much appreciated!
ProcessOne: ejabberd 25.07
Release Highlights:
This release focus on integration in a wider federated network, with support for spam fighting features, better compliance with Matrix network and native support for PubSub Server Information to have your server count as part of the wider XMPP network (for example, you can register your server on XMPP Network Graph).
- **Spam filter ⦠ā Read more
Chromium to use āAIā to combat the spam notifications it helped create
Notifications in Chrome are a useful feature to keep up with updates from your favorite sites. However, we know that some notifications may be spammy or even deceptive. Weāve received reports of notifications diverting you to download suspicious software, tricking you into sharing personal information or asking you to make purchases on potentially fraudulent online store fronts. To defend agai ⦠ā Read more
Definitely open to taking on users šI only have open registrations turned off because of spam accounts and my pod being the most popular amongst spammers š¤£
(#t4cgo2a) Definitely open to taking on users šI only have open registrations turned off because of spam accounts and my pod being the most p ā¦
Definitely open to taking on users šI only have open registrations turned off because of spam accounts and my pod being the most popular amongst spammers 𤣠ā Read more
Gajim: Gajim 2.0.0
Gajim 2.0 is here and it comes with a big upgrade š Gajim migrated its user interface toolkit to GTK 4, which brings performance improvements and sets the ground for great features to follow. Additionally, this release brings improved image previews, better tools for fighting spam, and much more. All of these changes were only possible by touching a lot of Gajimās code base, and we appreciate all the feedback we got from you.
Switching Gajimās major ver ⦠ā Read more
Codeberg Announces āFight Against Far-Rightā
The Git source code hosting organization, in response to anonymous spam, declares war on āRight-Wing Forcesā, encourages others to do the same. ā Read more
reviewing logs this morning and found i have been spammed hard by bots not respecting the robots.txt file. only noticed it because the OpenAI bot was hitting me with a lot of nonsensical requests. here is the list from last month:
- (810) bingbot
- (641) Googlebot
- (624) http://www.google.com/bot.html
- (545) DotBot
- (290) GPTBot
- (106) SemrushBot
- (84) AhrefsBot
- (62) MJ12bot
- (60) BLEXBot
- (55) wpbot
- (37) Amazonbot
- (28) YandexBot
- (22) ClaudeBot
- (19) AwarioBot
- (14) https://domainsbot.com/pandalytics
- (9) https://serpstatbot.com
- (6) t3versionsBot
- (6) archive.org_bot
- (6) Applebot
- (5) http://search.msn.com/msnbot.htm
- (4) http://www.googlebot.com/bot.html
- (4) Googlebot-Mobile
- (4) DuckDuckGo-Favicons-Bot
- (3) https://turnitin.com/robot/crawlerinfo.html
- (3) YandexNews
- (3) ImagesiftBot
- (2) Qwantify-prod
- (1) http://www.google.com/adsbot.html
- (1) http://gais.cs.ccu.edu.tw/robot.php
- (1) YaK
- (1) WBSearchBot
- (1) DataForSeoBot
i have placed some middleware to reject these for now but it is not a full proof solution.