DirtySlide - root on macOS from one missing bounds check https://lobste.rs/s/27vr6v #mac #security
https://gracecondition.github.io/posts/dirtyslide/
security
Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing https://lobste.rs/s/agkcmz #security #windows
https://www.ghacks.net/2026/07/12/microsoft-confirms-windows-gdid-device-identifier-that-cannot-be-disabled-documented-in-fbi-case-filing/
A Filtering engine and DB for unpropagated kernel security patches https://lobste.rs/s/pfz6dj #linux #release #security
https://patchless.natey.sh
Opaque, Interoperable Passkey Records https://lobste.rs/s/boyu9x #cryptography #security
https://words.filippo.io/passkey-record/
SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare in release 3.10 https://lobste.rs/s/h2qy4t #linux #security
https://security.opensuse.org/2026/07/15/selinux-seunshare.html
Signing TLS handshakes inside a TPM via @fs111 https://lobste.rs/s/vospwq #go #security
https://bschaatsbergen.com/posts/go-tpm-tls/
wp2shell: Pre Authentication RCE in WordPress Core https://lobste.rs/s/aipvbn #security #web
https://wp2shell.com/
Amnesty International (@amnesty) Security Lab just released their most complete breakdown of the Pegasus spyware.
If you have time, go give it a read
You can't bug fix your way out of the vulnpocalypse https://lobste.rs/s/nkrgcp #security
https://alexgaynor.net/2026/jul/15/you-cant-bugfix-your-way-out-of-the-vulnpocalypse/
PyPI releases now reject new files after 14 days https://lobste.rs/s/53g8f7 #python #security
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/
Securing DNSSEC Keys via Threshold ECDSA From Generic MPC (2019) https://lobste.rs/s/e9jl9m #cryptography #security
https://eprint.iacr.org/2019/889
PACT: Anonymous Credentials for the Web – Mozilla Hacks https://lobste.rs/s/6pdyiy #privacy #security
https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/
I believe at this stage CloudFlare provides security in a way analogous to how a protection racket provides security.
#CloudFlare #security #cybersecurity #infosec #web
Journey to Root, Episode I: The Maglev King https://lobste.rs/s/i0mnxl #security #vibecoding
https://blog.calif.io/p/journey-to-root-episode-i-the-maglev
tmp.0ut volume 5 via @eh https://lobste.rs/s/xiwynb #reversing #security
https://tmpout.sh/5/
reaction: A daemon that scans program outputs for repeated patterns, and takes action via @fanf https://lobste.rs/s/zzdc8x #security
https://framagit.org/ppom/reaction
Integrated Sensing and Communication (ISAC) https://lobste.rs/s/35dq6x #privacy #security
https://www.ericsson.com/en/6g/isac
Unauthenticated RCE in Motorola's MR2600 Router https://lobste.rs/s/s1jwea #security
https://mrbruh.com/motorola/
How Far Behind the Frontier are Leading Open Weight Models on Cyber? https://lobste.rs/s/vrcctk #security #vibecoding
https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber
Easy Sandboxing on Linux with Bubblewrap https://lobste.rs/s/stehhb #linux #security
https://bxt.rs/blog/easy-sandboxing-on-linux-with-bubblewrap/
7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors https://lobste.rs/s/bper0d #security #vibecoding
https://www.pillar.security/blog/the-week-of-sandbox-escapes
Switching Password Managers in 2026 https://lobste.rs/s/ikzvtv #practices #security
https://rmondello.com/2026/09/07/switching-password-managers-2026/
I accidentally logged hundreds of thousands of phone calls to military bases via @taavi https://lobste.rs/s/dyswyz #security
https://lina.sh/blog/hijacking-e164-arpa
A researcher bought noreply.net. Companies started sending him secrets https://lobste.rs/s/exgfc0 #privacy #security
https://arstechnica.com/security/2026/08/a-researcher-bought-noreply-net-companies-started-sending-him-secrets/