Post-Quantum Cryptography for the PHP Community https://lobste.rs/s/bqbvpd #cryptography #php #security
https://paragonie.com/blog/2026/04/post-quantum-cryptography-for-php-community
security
A Linux Kernel 0-day Journey - From a limited UAF to Physical Memory R/W https://lobste.rs/s/h9zpbs #linux #security
https://1day.dev/posts/linux-kernel-0day.html
#tech #dev #SecurityTheater #DarkPatterns #UI #UX #security
Announcing the Ecosystem Security Team at The PHP Foundation ✨
We have a new role at The PHP Foundation, thanks to a grant from Alpha-Omega at the @linuxfoundation and filled by the amazing @edorian! This initiative is designed to improve security across the entire PHP ecosystem and to help maintainers in our community. We are incredibly excited to dig into this work! Learn more about this effort and how you can participate on our blog. 🔒 💪 #php #security
https://thephp.foundation/blog/2026/05/18/announcing-ecosystem-security-team/
You don't want long-lived keys https://lobste.rs/s/o45fm1 #practices #security
https://argemma.com/blog/long-lived-keys/
Open source security at Astral https://lobste.rs/s/qayr1f #security
https://astral.sh/blog/open-source-security-at-astral
Little Snitch for Linux via @eh https://lobste.rs/s/2zrhn4 #linux #release #security
https://obdev.at/blog/little-snitch-for-linux/
Nightmare of the Javascript Optimization https://lobste.rs/s/gbzdnm #browsers #security
https://blog.reg.rip/exploiting-the-ladybird-browser.html#funny-section
Removing the AUICGP instruction via @fanf https://lobste.rs/s/vkngyl #assembly #security
https://cheriot.org/isa/toolchain/2026/03/23/removing-auicgp.html
The Mac App Gold Rush in the Age of Vibe Coding https://lobste.rs/s/8xd0x7 #mac #security #vibecoding
https://caio.ca/blog/ai-vibe-coded-mac-apps.html
Snopes: Fake News from Trump??
"Image claiming to show US airman rescued in Iran is fake. Here's the proof
In early April 2026, the U.S. said it conducted a rescue mission to retrieve two members of the Air Force downed in Iran."
#Russia #India #China #USA #Economy #Finance #Technology #Security #News #Iran #Israel #War #EU #NATO #Oil #Nuclear #Weapons #Trump #Warcrimes #Disgrace #Hegseth
https://www.snopes.com/fact-check/image-us-pilot-rescued-iran/
🔥BREAKING: GitHub's internal repositories were accessed by unauthorized users, but fear not, it seems their greatest #security threat is JavaScript-disabled browsers. 🚀 It's comforting to know that while our data is at risk, #JavaScript remains the true gatekeeper of internet safety. 🙃
https://twitter.com/github/status/2056884788179726685 #GitHub #InternetSafety #DataBreach #HackerNews #ngated
We released the #XLibre Xserver 25.0.0.22 and 25.1.4 on Apr 21 containing #security fixes for CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003 of the X.Org Server. We recommend everyone update ASAP. #CVE https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.4
This is what a #WitchHunt actually looks like
Exclusive: US “counterterror” officials plan #antifa summit, sources say
The #Trump admin is organizing an international summit focused on countering the #LeftWing movement antifa & other groups, 3 sources familiar with the matter said, an effort that highlights the shift in the US government's counterterrorism priorities over the past year.
#AntiFascism #resist #law #security #fascism #FarRight #authoritarianism #tyranny
https://www.reuters.com/world/us/us-counterterror-officials-plan-antifa-summit-sources-say-2026-03-31/?utm_source=braze&utm_medium=notifications&utm_campaign=2025_engagement
Every single blueteamer in information security at the moment...
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance https://lobste.rs/s/fgvbvw #python #security
https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/
RIPE NCC RPKI exploit chain https://lobste.rs/s/ewwdm4 #networking #security
https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/
Sealed Fedora Atomic Desktop bootable container images https://lobste.rs/s/jmyhjv #linux #security
https://fedoramagazine.org/sealed-atomic-desktops-test-images/
Popular Go library fsnotify raises supply chain alarms after maintainer access changes https://lobste.rs/s/7rpqbo #go #security
https://socket.dev/blog/fsnotify-maintainer-dispute-sparks-supply-chain-concerns
The Axios supply chain attack used individually targeted social engineering via @hongminhee https://lobste.rs/s/ucg84y #javascript #security
https://simonwillison.net/2026/Apr/3/supply-chain-social-engineering/
GitHub Actions is the weakest link https://lobste.rs/s/ngogon #devops #security
https://nesbitt.io/2026/04/28/github-actions-is-the-weakest-link.html
CVA6-CFI: A First Glance at RISC-V Control-Flow Integrity Extensions https://lobste.rs/s/o7ulwh #pdf #hardware #security
https://arxiv.org/pdf/2602.04991
DPI bypass using eBPF sock_ops and fake TLS ClientHello injection https://lobste.rs/s/dmdvje #c #linux #networking #security
https://github.com/boratanrikulu/gecit
