⚠️ Github CLI now has telemetry spyware built in:
https://cli.github.com/telemetry
They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.
Run `gh config set telemetry disabled` to disable it.
⚠️ Github CLI now has telemetry spyware built in:
https://cli.github.com/telemetry
They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.
Run `gh config set telemetry disabled` to disable it.
I'd guess FreeBSD's infrastructure is under attack. mailing list manager is super slow, forums have been defaced, what else is going on?
also, no official channel has acknowledged this yet?
tagging @FreeBSDFoundation for lack of a better profile
Every single blueteamer in information security at the moment...
500+ Organizations Now Participating as CVE Numbering Authorities (CNAs)!
As of March 31, 2026, there are 502 CNAs (499 CNAs and 3 CNA-LRs) from 42 countries participating in the CVE Program
Learn more:
https://www.cve.org/Media/News/item/blog/2026/03/31/502-Organizations-Participating-as-CNAs
#cve #cna #vulnerability #vulnerabilitymanagement #informationsecurity #infosec #cybersecurity
attention anybody with substantial experience with Rust and networking: my team is hiring!!
one of few rust jobs I'm aware of that is not web 3.0 horseplop.
fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind.
feel free to reach out for more details and the job posting.
🚨 First the social media ban, now the UK government wants to restrict VPNs 🚨
VPNs are a vital cybersecurity tool for businesses, politicians, journalists and families to protect data and communications.
Banning or requiring digital ID checks before buying VPNs would increase cybercrime risks and expose IP addresses to predators.
https://www.express.co.uk/news/uk/2217934/vpn-ban-table-july-labour
#vpn #socialmediaban #ageverification #ukpolitics #cybersecurity #onlinesafety #ukpol #vpns #ProtectVPNs #privacy #onlinesafetyact
Hello, Mastodon! 👋 We help people take back control of their personal data online, and we're here to connect with others who care about digital privacy.
Help us out: What feeds or accounts should we be following?
#privacy #cybersecurity #infosec #dataprivacy #dataprotection
Your browser could already be part of a botnet thanks to this dangerous Chrome flaw
Your browser may never act suspicious enough to raise concern.
https://www.androidauthority.com/chromium-browser-vulnerability-3669581/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
(aikido.dev) CVE-2026-40175: Axios Critical Vulnerability Claim vs. Real-World Exploitability in Node.js Environments
Critical CVE-2026-40175 in Axios (CVSS 10) involves a multi-stage exploit chain: prototype pollution → CRLF injection → request smuggling → SSRF → AWS IMDSv2 credential theft. However, real-world exploitability in Node.js/Bun/Deno is blocked by runtime-level CRLF header rejection (ERR_INVALID_CHAR).
In brief - CVE-2026-40175 is a critical-rated Axios flaw with a complex exploit chain targeting cloud credentials, but standard Node.js environments mitigate it at runtime. Patch to Axios ≥1.15.0 to address the library-level vulnerability.
Technically - The exploit leverages prototype pollution to inject CRLF sequences into HTTP headers, aiming for request smuggling/SSRF against AWS IMDSv2. Node.js’s http.request() blocks CRLF characters, breaking the chain. Axios failed to sanitize headers independently, requiring a patch. Edge-case exploitation possible only with non-standard adapters bypassing Node’s HTTP client.
Source: https://www.aikido.dev/blog/axios-cve-2026-40175-a-critical-bug-thats-not-exploitable
[#TRADESHOW] #Intersec #Shanghai 2026 – #Security #Equipment and #Technology #Expo will be held from May 7 to 9, 2026, at the National #Exhibition and #Convention #Center (#NECC), Shanghai. #Exhibition connects #international #suppliers with #China’s rapidly #expanding security, #fire #protection, and #safety #technology #markets. #Event integrates #global expertise with #market depth to promote #innovation in #AI, #IoT, #cybersecurity, and #emergency response #systems. https://cnbusinessforum.com/event/intersec-shanghai-2026-security-equipment-and-technology-expo/
New book, released under a Creative Commons BY-NC-ND license: "Don't Get Hacked! Protecting Yourself at Home": https://www.cs.columbia.edu/~smb/homesec/index.html
Retoot for reach!
Check it: Sen. Maggie Hassan (D-NH) is demanding answers from CISA and DHS over my reporting this week that a CISA contractor had published on GitHub a number of CISA AWS GovCloud keys and a ton of plaintext passwords, SSH keys, etc. for internal CISA resources.
ICYMI:
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
Alright I better announce this actually. At 8UTC Sunday 10th May ("tomorrow, Sunday morning in Europe") I am speaking to
@bagder of #curl https://curl.se/ https://en.wikipedia.org/wiki/Curl_(software)
about becoming targetted by trillions of dollars of #AI companies #cybersecurity scanning, especially after he rejected their ai-content merge requests. And having to close bug bounties due to #llm spam.
...And what it means for #indie #programming today. #commonLisp #ecl 's 2010 example is curl, and and and.
This dumb password rule is from Getin Bank.
The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.
https://dumbpasswordrules.com/sites/getin-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Xbox is now XBOX
Xbox just allcapsmaxxed: meet XBOX. This isn't a joke, Microsoft appears to be actually rebranding Xbox to XBOX. Asha Sharma, Xbox CEO, ran a poll on X earlier this week, asking fans whether Microsoft should use Xbox or…
https://www.theverge.com/news/931918/microsoft-xbox-rebrand-caps
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
New by me:
Scoop: FulcrumSec Leaks Novo Nordisk Data After $25M Demand Goes Unpaid
#novonordisk #FulcrumSec #hackandleak #infosec #cybersecurity #databreach #intellectualproperty
@campuscodi @dangoodin @zackwhittaker @euroinfosec @amvinfe @briankrebs @lawrenceabrams
NEW by me:
One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.
Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.
Data leaks followed.
#NovoNordisk #FulcrumSec #TheUSERS007 #hackandleak #extortion #AI #databreach #infosec #cybersecurity
@campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe
Japanese chipmaker Rapidus to offer lower wafer pricing than TSMC — 2nm class silicon to be priced around $20,000 on 2027 launch
Japanese chipmaker Rapidus discloses one more aspect of its strategy: to offer lower quotes than TSMC.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
You can now use your #Gmail account in #Proton Mail
Mystery company accidentally blew $500 million on Claude AI in a single month — failed to put usage limit on licenses for employees
A new report cites an AI consultant claiming a client accidentally spent $500,000,000 on Claude in a single month.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
The Great American State Fair cancellations are getting framed as a culture war story. Stop there. The real signal worth tracking is what happens to event infrastructure when organizers face coordinated pressure campaigns online.
Large public gatherings tied to...
Read more: https://steelefortress.com/i10igu
Security #Cybersecurity #ThreatIntel #InfoSec
Rivian says AI makes debate over CarPlay ‘completely obsolete’
Rivian’s chief software officer, Wassym Bensaid, joined Nilay Patel in the latest Decoder interview. And his comments on CarPlay show Rivian continuing to double down on its refusal to support Apple’s platform. more…
https://9to5mac.com/2026/05/28/rivian-says-ai-makes-debate-over-carplay-completely-obsolete/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Raspberry Pi now publishes a Software Bill Of Materials (SBOM) with each PiOS download
and a torrent
and a link to the release notes
and a link to the release archive
and the release date
and a checksum
and the download and install storage sizes
and the architecture, kernel, and upstream release versions
and a list of all compatible hardware
in the same place.
https://www.raspberrypi.com/software/operating-systems/
How is your Enterprise software vendor doing?
#RaspberryPi #PiOS #SBOM #SoftwareBillOfMaterials #InfoSec #InformationSecurity #CyberSecurity
CVSS 10.0 in Google Config Connector — still unpatched.
Any K8s namespace user can become GCP Org Owner with 3 lines of YAML. Google's engineer said "Nice catch!" Then VRP called it "working as intended."
Their defense contradicts their own documentation.
Full writeup + video PoC: https://olearysec.com/research/config-connector-authorization-bypass
#infosec #cloudsecurity #gcp #kubernetes #bugbounty #vulnerability #google #k8s #iam #cybersecurity