new_otters_raft

@new_otters_raft@piefed.ca · Joined ⁨Feb⁩ ⁨2026⁩

Please contact me at @otter@lemmy.ca for any urgent issues.

This is an alt account used for testing and scheduling posts. I intend to retire the previous accounts I used for this purpose ( otters_raft@lemmy.ca and otters_raft@piefed.ca )

profile image: Photo by Kedar Gadge

posted in Technology

Pet owners say smart pet feeder outage led to furry ones going unfed

This feels like bad design

Smart pet-feeder company Petlibro suffered an outage on Tuesday, giving users a harsh reminder of the risks of relying on smart devices.

Petlibro makes pet feeders that connect to Wi-Fi and, for setup with Petlibro’s mobile companion app, Bluetooth. Users can set the feeders to automatically dispense food at scheduled times, which is handy for pet care when the owner is out of the home.

In a statement to The Verge, Petlibro CEO York Wu said this week’s outage was “related to how the Petlibro app communicates with devices through its online servers.”

Some user reports have also conflicted with Petlibro’s claims about offline functionality. As The Verge pointed out, various users online claimed that during the outage, their devices did not perform any scheduled feedings, performed some feedings but not others, or performed feedings late (examples here, here, here, here, and here).

arstechnica.com/gadgets/2026/08/pet-owners-say-smart-pet-feeder-outage-led-to-furry-ones-going-unfed/

posted in Technology

Terabytes of credentials leaked in massive supply-chain attack

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
A cartoon man runs across a white field of ones and zeroes.Ars TechnicaTerabytes of credentials leaked in massive supply-chain attackThe data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Replying to an earlier post

I wouldn’t use this day to day, but what I found cool was:

  • it doesn’t require cables or any additional equipment (including routers, cell towers)
  • it can’t be detected by anything, assuming you toss a blanket over the transfer

The downside is that if you wanted to get it truly offline, you would need to have the an app installed on both devices ahead of time, if I understood it correctly. (Edit: bolded bits are new)

It did lead to some fun discussion in this thread :)

posted in Technology

Decimen Lets You Send Files Through Light, Not a Network

I’m not sure when I’d use this, but its a neat concept

Decimen is an open-source web app that moves files between devices through an animated QR stream, requiring no direct network connection, pairing, account, or native app.

linuxiac.com/decimen-lets-you-send-files-through-light-not-a-network/
Decimen Lets You Send Files Through Light, Not a NetworkLinuxiacDecimen Lets You Send Files Through Light, Not a NetworkDecimen is an open-source web app that moves files between devices through an animated QR stream, requiring no direct network connection, pairing, account, or native app.

posted in Technology

CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

www.privacyguides.org/news/2026/07/31/cisa-releases-guidance-urging-water-treatment-facilities-to-disconnect-equipment-from-the-internet/
Privacy GuidesCISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the InternetCISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.