curl summer of bliss via @andrewnez https://lobste.rs/s/uqagn2 #security
https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
security
Announcing the Save CTFs Fund https://lobste.rs/s/geibgn #security
https://osec.io/blog/save-ctfs-fund/
SecretSpec 0.13: SDKs for Python, Node.js, Go, Ruby, and Haskell https://lobste.rs/s/5r5ebh #release #security
https://secretspec.dev/blog/secretspec-0-13-sdks/
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos https://lobste.rs/s/rcg4bo #security #vibecoding
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Users cry foul after AMD stripped memory crypto from its consumer CPUs https://lobste.rs/s/i2cjew #hardware #security
https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/
It's that time of the year! 🎉 The registration for the Open Security Conference 2026 is officially open. As space is limited we will process registrations first come first served, so get your ticket sooner rather than later.
🗓️ 5-8 November 2026
📌 Rückersbach, Germany (close to Frankfurt am Main)
➡️ https://opensecurityconference.org/conference/registration
#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity #OpenSpace [lisi]
After 8.5 awesome years, today is my last day at 1Password.
I can't even begin to describe how much the experience impacted me as a person. I moved from casual customer support and social media management all the way through to the security team, eventually becoming its longest-tenured member. Some of my greatest hits included:
Pioneering the creation of 1Password's Privacy Team as its first IC
Creating a fully functional DSR program from the ground up
Forming the first internal data map
Developing a process with which to work law enforcement
Becoming a SME on all things consumer product security
Collaboration with Legal, GRC, Customer Support, and plenty of others
My entire future has been shaped by what I accomplished while I was there, and I'll remember it forever. What's next? I'm not sure yet! I think I'll take a bit of time for myself and then start looking for my next big thing. I'm open to suggestions, though, and so if you or someone you know is looking for someone in privacy, shoot me a message!
Pillow 12.3.0 has been released!
This has a number of security fixes, performance improvements and Python 3.15 beta wheels.
https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html
#Python #Pillow #PythonPillow #release #security #Python315 #SBOM
Poison, redzones and shadows: inside KASAN – Bootlin https://lobste.rs/s/exuqoz #linux #security
https://bootlin.com/blog/poison-redzones-and-shadows-inside-kasan/
RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) https://lobste.rs/s/tltlwf #linux #security
https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343) https://lobste.rs/s/miadav #security #windows
https://blog.calif.io/p/dark-elevator-windows-install-service
AT&T's very rare Security-Plus Telephone https://lobste.rs/s/fw8e40 #cryptography #historical #security
https://www.electrospaces.net/2025/10/an-interesting-advertisement-for-stu.html
Secrets Don’t Belong in Config https://lobste.rs/s/iypcjj #nix #security
https://secretspec.dev/blog/secrets-dont-belong-in-config/
OpenSSL HollowByte: A DoS Hiding in 11 Bytes https://lobste.rs/s/tvpnsm #security
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
AI models shock UK testers by using fake identities to try to trick developers https://lobste.rs/s/tmpokv #security
https://www.theguardian.com/technology/2026/aug/05/openai-anthropic-models-went-rogue-cybersecurity-test-ai-security-institute
Full disclosure: Arbitrary code execution in Cursor https://lobste.rs/s/vlr279 #editors #security #vibecoding
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Frag Gap (CVE-2026-53362, CVE-2026-53366) https://lobste.rs/s/uibzl8 #linux #security
https://blog.qwerty.or.kr/en/posts/cdf3008a-c1a4-4eca-a373-aa3a2bcf1489/
Reporting a 19+ Years Hidden Linux Kernel Zero-Day for Google kernelCTF: CVE-2026-43456 https://lobste.rs/s/txjns0 #linux #networking #security
https://gmo-cybersecurity.com/blog/19-years-hidden-80000-rewarded-reporting-a-linux-kernel-zero-day-for-google-kernelctf/
OpenAI model breaks out of security sandbox, hacks Hugging Face for data to pass test https://lobste.rs/s/7nrek3 #security #vibecoding
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) https://lobste.rs/s/w7qez9 #linux #security
https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt
I Inspected My Take-Home Interview Project. It Was a Whole Operation https://lobste.rs/s/5nhto6 #security
https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/
OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root (CVE-2026-57589) https://lobste.rs/s/7hmu0w #openbsd #security
https://nvd.nist.gov/vuln/detail/cve-2026-57589
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts https://lobste.rs/s/xbfsho #ruby #security
https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack