GitHub Actions needs OIDC audience constraints by @yossarian https://lobste.rs/s/ipt1em #security
https://blog.yossarian.net/2026/08/10/github-actions-needs-oidc-audience-constraints
security
Shipping post-quantum cryptography to Python https://lobste.rs/s/szvtko #cryptography #python #security
https://blog.trailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-python/
432 Linux kernel CVEs published in the last 24 hours https://lobste.rs/s/t2jxyu #linux #security
https://lore.kernel.org/linux-cve-announce/
New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Updated GPG key for signing Firefox and Thunderbird Releases https://lobste.rs/s/vj2erc #security
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
CVE-2026-49176 Exploit Development: WalletService to SYSTEM https://lobste.rs/s/dxhdqx #security #windows
https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
ZOOMSDAY, Zoom Zero-Click Vulnerabilities Via Annotation https://lobste.rs/s/juj7bi #security #vibecoding
https://a.security/blog/asecurity-zoomsday
Adopting Memory-Safety and Fine-Grained Compartmentalisation with CHERI via @fanf https://lobste.rs/s/lt89di #transcript #video #hardware #security
https://www.infoq.com/presentations/cheri-memory-safety-compartmentalization/
Unlocking _everything_ on the CPU with DRAM scrambling https://lobste.rs/s/a4zifd #security
https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
Deadbugz: Currently Active MCP Supply-Chain Campaign https://lobste.rs/s/wjiyxu #security #vibecoding
https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign
What does GitHub’s security team even do? https://lobste.rs/s/jnhyrh #security #vcs
https://orchidfiles.com/github-security-team/
Bypassing Android Hardware Attestation from the Analyst's Chair https://lobste.rs/s/lbaw4d #android #security
https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
Don't #Hang Up On #AI #Scammers. Do THIS Instead. #Kitboga #yt #satire #comedyGold #privacy #security
https://youtu.be/lk3jCuITwcE 🤣🤣🤣🤣🤣🤣
My Homelab Got Hacked - A Postmortem https://lobste.rs/s/ugkhor #devops #security
https://phunky.cafe/my-homelab-got-hacked/
Apple Limits Bug Bounty Submissions After a Barrage of AI Entries https://lobste.rs/s/uyyfhi #security #vibecoding
https://www.pcmag.com/news/apple-limits-bug-bounty-submissions-after-a-barrage-of-ai-entries
Decrypting Flume Water Monitor Traffic via @hibachrach https://lobste.rs/s/g94aro #hardware #security
https://lithostech.com/2026/08/decrypting-flume-water-monitor-traffic/
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles https://lobste.rs/s/pg4toy #security
https://eaton-works.com/2026/07/27/my-eicher-hack/
Apple MIE exploitation challenge https://lobste.rs/s/lz6eoe #mac #security
https://blog.calif.io/p/apple-mie-exploitation-challenge
I found a KVM guest-to-host heap corruption bug and someone else got there first https://lobste.rs/s/octplv #linux #security
https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/
Design flaws in issetugid() (2017) https://lobste.rs/s/6gx5vy #api #c #security #unix
https://gist.github.com/nicowilliams/4daf74a3a0c86848d3cbd9d0cdb5e26e
Bulk AbuseIPDB reporting using command-line tools https://lobste.rs/s/vjds7h #security
https://blog.mbirth.uk/2026/08/30/bulk-abuseipdb-reporting-using-command-line-tools.html
Bastillion 5.1: single-JAR SSH gateway now audits and replays every session https://lobste.rs/s/an2tby #java #release #security
https://github.com/bastillion-io/Bastillion/releases#release-v5.1.0
The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes https://lobste.rs/s/2dc0gb #reversing #security
https://blog.silentsignal.eu/2026/07/28/the-cipher-behind-qsyrupwd-reconstructing-ibm-i-password-hashes/
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident https://lobste.rs/s/pxczeo #security #vibecoding
https://huggingface.co/blog/agent-intrusion-technical-timeline
Proof types in Dart: Using final classes as computational witnesses https://lobste.rs/s/wdo7aj #compilers #security
https://modulovalue.com/blog/proof-types-in-dart/
🐦🔥nemo™🐦⬛ 🇺🇦🍉