Try the `upki` preview for Ubuntu via @fanf https://lobste.rs/s/981pzy #linux #security
https://jnsgr.uk/2026/07/upki-preview-for-ubuntu/
security
Soatok’s Informal Guide to Threat Models https://lobste.rs/s/gwrlsv #rant #security
https://soatok.blog/2026/06/30/soatoks-informal-guide-to-threat-models/
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) https://lobste.rs/s/0kc445 #linux #security
https://cyberstan.co.uk/fuse-readdir-oob/
Magecart skimmer turns Stripe into a malware command server via @mseri https://lobste.rs/s/evgsx7 #security
https://sansec.io/research/stripe-api-skimmer-infrastructure
Chasing Lightning: Detecting, Characterizing, and Identifying a Powerful Space-Based GNSS Interference Source via @fanf https://lobste.rs/s/qrhqvc #science #security
https://arxiv.org/abs/2606.03673
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy https://lobste.rs/s/k67xnh #privacy #security
https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
Running Python code in a sandbox with MicroPython and WASM https://lobste.rs/s/h22iaq #python #security #wasm
https://simonwillison.net/2026/Jun/6/micropython-in-a-sandbox/
Claude Code Is Steganographically Marking Requests https://lobste.rs/s/qs2sxd #security #vibecoding
https://thereallo.dev/blog/claude-code-prompt-steganography
Fuzzing for fun - unauthenticated denial of service in snac2 https://lobste.rs/s/zjnc5o #c #security
https://nullenvk.pl/posts/02-snac2-json/
The Threat of Residential Proxies via @fanf https://lobste.rs/s/x8qug8 #security
https://www.feistyduck.com/newsletter/issue_138_the_threat_of_residential_proxies
Dancing mad with sandboxing https://lobste.rs/s/fmkvwk #security
https://xeiaso.net/blog/2026/dancing-mad-sandboxing/
This week's net.wars, "The Sutton effect", goes to the 25th Workshop on the Economics of Information Security, where researchers mull the costs of cybersecurity failures: https://netwars.pelicancrossing.net/2026/06/05/the-sutton-effect/ #NetWars #security #economics
Creating a development sandbox with crosvm https://lobste.rs/s/mml3sh #practices #security #virtualization
https://www.erat.org/crosvm.html
the last weeks we saw more and more security issues coming up. Let's talk!
Sorry, a pretty long blog post about this...
https://gyptazy.com/blog/coding-after-ai-are-humans-still-good-enough/
#ai #aicoding #coding #opensource #foss #security #infosec #vulns #developer #devops #engineer #ops #fedi #philosophy
Open Source as Infrastructure: Taking Roads and Bridges literally via @robey https://lobste.rs/s/z2wzap #security #testing
https://nesbitt.io/2026/06/30/taking-roads-and-bridges-literally.html
Integrity on Embedded Linux Devices under the Cyber Resilience Act https://lobste.rs/s/ypba4x #linux #security
https://sigma-star.at/blog/2026/06/integrity-on-embedded-linux-devices-under-the-cyber-resilience-act/
Autocrypt v2 - Post-Quantum and Reliable Deletion https://lobste.rs/s/esy9xh #cryptography #security
https://autocrypt2.org
Vulnerability and malware checks in uv by @yossarian https://lobste.rs/s/mct5rz #python #security
https://astral.sh/blog/uv-audit
Expanding Private Cloud Compute - Apple Security Research https://lobste.rs/s/4xbzbk #ai #privacy #security
https://security.apple.com/blog/expanding-pcc/
Self-hosting email the hard way from your own routable IPv4 block up https://lobste.rs/s/cw7vxa #ml #networking #security
https://anil.recoil.org/notes/recoil-self-hosting-2026
Arbitrary code execution in objdump -g https://lobste.rs/s/sbcasc #security
https://blog.calif.io/p/oobdump-relocation-oriented-programming
For the 2nd time in weeks, Microsoft packages laced with credential stealer https://lobste.rs/s/ryxjww #security
https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 https://lobste.rs/s/uaoe9y #security #web
https://nebusec.ai/research/v8-cve-2026-6307-writeup/
Do excellent vulnerability reports via @andrewnez https://lobste.rs/s/pwr4h7 #security
https://daniel.haxx.se/blog/2026/06/29/do-excellent-vulnerability-reports/
ipv6_frag_escape: Linux LPE - Reliable Jail/Container Escape https://lobste.rs/s/eihlve #devops #security
https://github.com/sgkdev/ipv6_frag_escape