the 90 day disclosure policy is dead https://lobste.rs/s/qxkdgl #security
https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/
security
Malware in Arch Linux AURs now inserting Russian spam into shell configs https://lobste.rs/s/zaejgn #linux #security
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/2YQSHTC27MOKDDKHZTH2BJGTEN2CYC7W/
The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic https://lobste.rs/s/ttvlyt #security #vibecoding
https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/
Why every organization should make it easy to report security flaws via @fanf https://lobste.rs/s/jhwbzf #practices #security
https://this.weekinsecurity.com/why-every-organization-should-make-it-easy-to-report-security-flaws/
I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help? https://lobste.rs/s/xkxbq3 #security #vibecoding
https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free https://lobste.rs/s/wdnet3 #linux #security #vibecoding
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
Robot Dogs Are a Security Nightmare https://lobste.rs/s/6f9o6w #video #security
https://www.youtube.com/watch?v=lA8WuXDXfcI
#Hezbollah exploding #pager trail runs from #Taiwan to #Hungary
A snr Lebanese #security source identified a photograph of the model of the pager, an AR-924.
The source said the #pagers had been modified by #Israel's spy service, #Mossad, "at the production level."
"The Mossad injected a board inside of the device that has explosive material that receives a code. It's very hard to detect it through any means.”
#lebanon #geopolitics
https://www.reuters.com/world/middle-east/israel-planted-explosives-hezbollahs-taiwan-made-pagers-say-sources-2024-09-18/
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations https://lobste.rs/s/suyqvr #security
https://www.security.com/threat-intelligence/fast16-nuclear-sabotage
Load-Bearing Assumptions: the rxrpc case (CVE-2026-43500) and the constraint that was never there https://lobste.rs/s/tuiapt #linux #security
https://www.linkedin.com/pulse/load-bearing-assumptions-rxrpc-case-cve-2026-43500-never-oldani-uzyae
@GrapheneOS is being threatened by French authorities for refusing to add backdoors and they're dealing with coordinated attacks in French media right now. They're pulling out of France entirely, moving all their servers, and fighting off a wave of bullshit one-sided reporting that makes them look like they're helping criminals.
They need us to fight back. Support them however you can, whether that's a dollar, sharing their story, pushing back on the garbage news coverage when you see it, or just telling someone you know about what's happening. All of it matters because they're drowning in attacks from governments and media and bad actors who want them gone.
This is the only Android OS that actually makes me feel like privacy isn't just marketing. They fight for us now they need us to fight for them.
The EU is pushing Chat Control and creating an environment where governments feel empowered to threaten developers into compliance, and if we stay quiet we're letting it happen. Show up for them in whatever way you're able to.
#grapheneos #Privacy #NoBackdoors #encryption #security #chatControl
RE: https://privacysafe.social/@JohnKiriakou/115645609531513341
These classes with me and @JohnKiriakou are 50% OFF for #CyberMonday and beyond! https://ivycyber.com/kiriakou
How my minimal, memory-safe Go rsync steers clear of vulnerabilities https://lobste.rs/s/5y9u93 #go #security
https://michael.stapelberg.ch/posts/2026-05-24-minimal-memory-safe-go-rsync-vulns/
The world isn’t becoming multipolar — it’s becoming "multisphere." Overlapping power, blurred norms and rising coercion are redefining global risk in 2026. https://www.japantimes.co.jp/commentary/2025/12/22/world/strategic-outlook-geopolitics-2026/?utm_medium=Social&utm_source=mastodon #commentary #worldnews #geopolitics #china #us #defense #sanaetakaichi #security #ukraine #europe
AI-generated vulnerability patches require human review https://lobste.rs/s/rkh2ux #security
https://1password.com/blog/why-ai-generated-patches-still-require-human-review
Security Update: Hollo 0.6.19 Released
We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.
This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.
We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.
FieldDetailsCVECVE-2025-68475SeverityHigh (CVSS 7.5)ActionUpgrade to Hollo 0.6.19🔒 Security Release: BotKit 0.3.1
We've released BotKit 0.3.1 with an important security fix.
This update addresses CVE-2025-68475 (High severity, CVSS 7.5), a ReDoS vulnerability in Fedify's HTML parsing that could cause denial of service.
If you're using BotKit 0.3.x, please upgrade to 0.3.1 as soon as possible.
We 90's kids learned early about the consequences of unnoticed phishing mails.
I've noticed a concerning trend of "slop security reports" being sent to open source projects. Here are thoughts about what platforms, reporters, and maintainers can do to push back:
https://sethmlarson.dev/slop-security-reports?utm_campaign=mastodon
An acquaintance is thinking about jailbreaking their iPhone. Not being an Apple user, I haven't followed the topic closely, but I thought this was generally believed to be a bad idea from a security perspective (at least for a primary device).
Unfortunately what I can easily find online are people with no obvious credentials saying it's fine and security companies (who often overblow risks, like the infamous "juicejacking") saying it's bad. I'm hoping the Fediverse might be able to give me a more nuanced or fact-based perspective.
Urgent Warning for Fedi Admins
We've discovered an ongoing Denial-of-Service attack against Misskey-based instances. The attacks exploit a zero-day vulnerability impacting Misskey, Sharkey, IceShrimp, and other related software. Patches are in progress and will be released ASAP. We encourage all admins to update immediately!
Note: this is a different vulnerability from the ones that were recently announced! You should update today and again tomorrow at the scheduled time.
Update: Sharkey version 2024.9.2 has been released with a patch. You can get the update here: https://activitypub.software/TransFem-org/Sharkey/-/releases/2024.9.2
#Misskey #Sharkey #IceShrimp #FediAdmins #Security
No one owes you supply-chain security https://lobste.rs/s/cxwidw #security
https://purplesyringa.moe/blog/no-one-owes-you-supply-chain-security/
Unlocking Encrypted ZFS Volumes with a Passkey https://lobste.rs/s/m9c8st #security
https://withblue.ink/2026/05/09/revaulter-encrypted-zfs-passkey.html
