experiments with isolation on blue pill https://lobste.rs/s/bbkpzc #assembly #c #hardware #security
https://l0puh.github.io/log/2026/08/04/experiments_with_isolation/
security
On Reading SRAMs in IR Images, and Establishing Bounds on Trust via @cyplo https://lobste.rs/s/oiyknx #hardware #security
https://www.bunniestudios.com/blog/2026/on-reading-srams-in-ir-images-and-establishing-bounds-on-trust/
iSCSI CHAP: Heap Buffer Overflow in the Linux Kernel https://lobste.rs/s/exezj2 #linux #security
https://ahossu.ro/blog/iscsi-chap-base64-overflow
The Newest Instagram "Exploit" is the Goofiest I've Seen https://lobste.rs/s/pmkmil #security #vibecoding
https://www.0xsid.com/blog/meta-account-takeover-fiasco
OpenSSH Key Structure Guide via @bd103 https://lobste.rs/s/lnxdje #security
https://sshref.dev/
New, by me: A number of high-profile and/or valuable Instagram accounts, including those of the Obama White House and the Chief Master Sergeant for the U.S. Space Force, got hacked and defaced with pro-Iran messaging in the past 24h after people figured out that Meta's AI support assistant could be tricked into resetting account passwords.
From the story:
"A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit that appears to have involved using a VPN connection with an IP address that is in or near the target's usual hometown, requesting a password reset for the account, and then choosing to chat with Meta's AI support assistant. From there, the video shows the attacker told the bot to link the account in question to a new email address, after which the bot dutifully sent that address a one-time code that allowed a password reset."
https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
Akrites: Coordinated, confidential vulnerability remediation for the open source software critical infrastructure depends on via @fanf https://lobste.rs/s/x6nv9y #security
https://akrites.org/
AI Agents Enable Adaptive Computer Worms https://lobste.rs/s/qsp10b #ai #security
https://cleverhans.io/worm.html
Ignore DNSSEC if you like MITM attacks via @ggpsv https://lobste.rs/s/pcuxjt #networking #security
https://whynothugo.nl/journal/2026/06/24/ignore-dnssec-if-you-like-mitm-attacks/
Exploiting vulnerabilities in Johnson & Johnson web apps https://lobste.rs/s/rl7aid #security
https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
Codex Discovered a Hidden HTTP/2 Bomb https://lobste.rs/s/cnbztx #security
https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
Full Disclosure: 1-Click GitHub Token Stealing via a VSCode Bug https://lobste.rs/s/fysuyw #security #vscode #web
https://blog.ammaraskar.com/github-token-stealing/
Anatomy of a Failed (Nation-State?) Attack https://lobste.rs/s/j2ua4f #security
https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
A peek into Reddit's anti-spam internals by @rebane2001 https://lobste.rs/s/boap41 #privacy #security
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Golang code review notes II https://lobste.rs/s/d0ixpj #go #security
https://www.elttam.com/blog/golang-code-review-notes-ii
Incident Report: CVE-2026-LGTM https://lobste.rs/s/6q12d7 #satire #security
https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html
A Post-Quantum Future for Let's Encrypt via @fanf https://lobste.rs/s/djguny #security #web
https://letsencrypt.org/2026/06/03/pq-certs.html
Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name via @fanf https://lobste.rs/s/0rtm7s #security
https://mxsasha.eu/posts/meshcore-xss-home-assistant/
Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does https://lobste.rs/s/evydbs #privacy #security
https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/
It's dead, Jim! (UEFI CA expiry) https://lobste.rs/s/xz51yj #linux #security
https://blog.einval.com/2026/06/27#its_dead_jim
Pilcrow's auth book via @andrew_chou https://lobste.rs/s/a9qqxl #book #security #web
https://auth.pilcrowonpaper.com/
The Empty Field That Wasn't: GPS Broadcasts a Numbers Station https://lobste.rs/s/a7v7e5 #security
https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer
exploitarium: A single archive of public exploit PoCs https://lobste.rs/s/4ywqva #security
https://github.com/bikini/exploitarium
Did Claude Increase Bugs in rsync? https://lobste.rs/s/mf5ryi #security #vibecoding
https://alexispurslane.github.io/rsync-analysis/
Januscape: Guest-to-Host Escape in KVM/x86 https://lobste.rs/s/jea4xl #linux #security
https://github.com/V4bel/Januscape