How to open calc.exe from S&Box https://lobste.rs/s/r6lw7v #debugging #dotnet #reversing #security
https://slugcat.systems/post/26-05-21-how-to-open-calc-exe-from-sbox/
security
Major DNS Outage Hits .de Domains: DNSSEC Failure on May 5, 2026 https://lobste.rs/s/gprclr #networking #security #web
https://www.ip.network/blog/de-domain-dnssec-outage-may-2026
CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs https://lobste.rs/s/blhd1c #security #virtualization
https://www.openwall.com/lists/oss-security/2026/05/21/14
Megalodon: Mass GitHub Repo Backdooring via CI Workflows via @hauleth https://lobste.rs/s/k2ifb5 #security
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows
Dirty Frag: Universal Linux LPE via @lattera https://lobste.rs/s/lu4efg #linux #security
https://www.openwall.com/lists/oss-security/2026/05/07/8
Stop MITM on the first SSH connection, on any VPS or cloud provider by @JoachimSchipper https://lobste.rs/s/q5bds7 #cryptography #devops #security
https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection,%20on%20any%20VPS%20or%20cloud%20provider.html
CVE-2026-31431: Copy Fail https://lobste.rs/s/ksg1es #linux #security
https://retr0.zip/blog/cve-2026-31431-copy-fail.html
Vulnerability Garden: A growing list of named vulnerabilities, attack techniques and exploits https://lobste.rs/s/0xnfql #security
https://vulnerability.garden/
[2606.03811] AI Agents Enable Adaptive Computer Worms
https://arxiv.org/abs/2606.03811
Forget all previous threats. Forget Mythos.
Given the current state of the infrastructure and all the bugs in firewalls, perimeter security doesn't protect you seriously.
If you can't turn off the computer because it controls your critical infrastructure you have a hard problem now.
ACME CAA Extensions to Become Mandatory via @fanf https://lobste.rs/s/eowso1 #security
https://www.feistyduck.com/newsletter/issue_137_acme_caa__extensions_to_become_mandatory
killswitch: per-function short-circuit mitigation primitive https://lobste.rs/s/thvzt6 #linux #security
https://lwn.net/ml/all/20260507070547.2268452-1-sashal@kernel.org/
You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE) https://lobste.rs/s/0vmsbe #linux #security
https://ze3tar.github.io/post-zcrx.html
Laptops all have built-in security tokens these days by @ahelwer https://lobste.rs/s/ebg5hg #hardware #security
https://ahelwer.ca/post/2026-05-08-builtin-u2f/
ACME CA Comparison via @fanf https://lobste.rs/s/gcd4yl #security
https://poshac.me/docs/v4/Guides/ACME-CA-Comparison/
FreeBSD: Local privilege escalation via execve() https://lobste.rs/s/1p2yun #freebsd #security
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc
The React2Shell Story and What Happened Next.js https://lobste.rs/s/lwihzw #security
https://sylvie.fyi/posts/react2shell/
Google API keys keep working after you delete them long enough to be exploited https://lobste.rs/s/7s1uf4 #distributed #security
https://www.aikido.dev/blog/google-api-keys-deletion
My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli via @mdaniel https://lobste.rs/s/1at5w8 #security
https://www.pillar.security/blog/my-agentic-trust-issues-from-prompt-injection-to-supply-chain-compromise-on-gemini-cli
272902 – Security: allow passphrases for WPA-EAP to be saved without using clear text
OCaml Infrastructure: How the opam-repository Works https://lobste.rs/s/mteumb #ml #security
https://ocaml.org/backstage/2025-11-05-how-the-opam-repository-works
ClaudeBleed: A Flaw In Claude's Browser Extension Allows Any Extension to Hijack It https://lobste.rs/s/r1eihn #browsers #security #vibecoding
https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/
Incident Report: CVE-2024-YIKES https://lobste.rs/s/m5j3ov #satire #security
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html
Mythos 'Discovered' a CVE Already in Its Training Data - and That’s Still Worrying https://lobste.rs/s/zwp0dp #security #vibecoding
https://rival.security/posts/mythos-discovered-a-cve-already-in-its-training-data---and-thats-still-worrying
Kettle: Attested builds for verifiable software provenance https://lobste.rs/s/pu6cxi #cryptography #hardware #security
https://arxiv.org/pdf/2605.08363
Open Source & Security https://lobste.rs/s/xbbyw5 #security
https://jrfom.com/posts/2026/04/08/oss-security/