Defense in Depth: A Practical Guide to Python Supply Chain Security https://lobste.rs/s/ghsneu #python #security
https://bernat.tech/posts/securing-python-supply-chain/
security
AGED FIVE, I GOT FAR ENOUGH
AWAY TO SEE 💎
When I was about five years old, I spent two years in a children’s sanatorium.
At the time, I had no idea what that would mean for the rest of my life. Looking back now, I think it was one of the great turning points of my childhood.
And strangely enough, I am grateful for it.
For two years, I was removed from my family and placed somewhere else entirely. Other adults. Other children. Other routines. Other ways of being. It gave me something I could not possibly have named at five.
DISTANCE.
When I eventually returned home, I had already discovered something enormously important. My family was not the whole world. I could stand outside it and see it.
And what I saw, increasingly, was that there was very little about my family that felt real or loving. In fact, I think I experienced more genuine warmth with some of the nurses and children at the sanatorium than I ever did at home. There was family in the biological sense. But I don’t think there was much family in the deeper sense at all.
Years later, at about fifteen, I told my parents I was homosexual.
That was the end of home.
I didn’t leave after a teenage argument and come back a few weeks later. There was nowhere to come back to. I had left because I had to. And when I left, it was over.
I sometimes watch films about people who grow up in brutal, loveless families and later become terribly damaged adults. Psychopaths. Serial killers. People whose childhoods seem almost designed to produce catastrophe. And occasionally I recognise something.
NOT WHAT THEY BECAME.
The beginning. The absence. The emotional coldness. And the fear. The strange knowledge, very young, that whatever happened next, you were largely on your own.
There was my sister.
For a long time, I think I allowed myself to believe that because she was still there, some part of the family remained. But even that relationship eventually forced me to look again. Sometimes the hardest thing is not losing a family. It is realising that what you thought you had may never really have been there. And yet something else was there.
Some capacity to stand outside it. To see it without having to pretend it was something else. Perhaps that began in the sanatorium. At five years old, without knowing it, I got far enough away to see. I learned that the family I had been born into was not the measure of reality.
And for that, strangely enough, I am truly grateful.
@3goodthings @DigitalCoup @meditation @economics_that_works @startrek
#Childhood #Family #LGBTQ #Survival #Perspective #LifeStory #love #security #grateful #warmth #pride
Never forget this:
All it takes is a single tantrum.
Here's where you can sign up for Proton email, calendar, VPN, etc...
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) https://lobste.rs/s/xxmuqx #linux #security #vibecoding
https://heyitsas.im/posts/drinking-llms/
Stalking the Wily Hacker: 40 years later https://lobste.rs/s/r77bda #video #person #security
https://youtu.be/656058JxTM0
Signal Shot: a project to verify the Signal protocol and its Rust implementation using Lean https://lobste.rs/s/jnl6e7 #cryptography #formalmethods #security #vibecoding
https://leodemoura.github.io/blog/2026-4-20-signal-shot-the-platform-is-ready/
CVE-2026-48710: A Maintainer's Perspective https://lobste.rs/s/xvdvko #python #security
https://marcelotryle.com/blog/2026/05/28/cve-2026-48710-a-maintainers-perspective/
https://github.com/macports/macports-ports/pull/32895
GitHub Continuous Integration checks passed OK!
It's up to someone else with commit access to merge it.
#ZMap #MacPorts #NetworkScanning #Security #infosec #OpenSource
GraalVM JavaScript Sandboxing https://lobste.rs/s/ygbtbm #java #javascript #plt #security
https://www.graalvm.org/latest/security-guide/sandboxing/
Fooling around with encrypted reasoning blobs https://lobste.rs/s/5lmciv #security #vibecoding
https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/
We're pleased to announce that #Hollo has been included in the Nivenly Fediverse Security Fund program!
The @nivenly Foundation has launched a security bounty fund to support contributors who identify and help fix #security vulnerabilities in popular #fediverse software. Both Hollo and @fedify are among the selected projects that meet their responsible security disclosure requirements.
This program will run from April–September 2025, with bounties of $250–$500 USD for high and critical security vulnerabilities.
We're honored to be recognized alongside other established fediverse projects like Mastodon, Misskey, and Lemmy. This further encourages our commitment to maintaining strong security practices.
If you're interested in contributing to Hollo's security, please follow our responsible disclosure process outlined in our SECURITY.md file.
Learn more about the program:
https://nivenly.org/blog/2025/04/01/nivenly-fediverse-security-fund/
Command Execution via Drag-and-Drop in Terminal Emulators https://lobste.rs/s/mfy7oi #security
https://sdushantha.github.io/post/drop-it-like-its-hot
CISA Admin Leaked AWS GovCloud Keys on Github via @kngl https://lobste.rs/s/vypafm #security
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
Humiliating IIS servers for fun and jail time https://lobste.rs/s/uqoo16 #security
https://mll.sh/humiliating-iis-servers-for-fun-and-jail-time/
The Futility of Lava Lamps: What Random Really Means https://lobste.rs/s/obxoph #cryptography #security
https://loup-vaillant.fr/articles/lava-lamps-and-randomness
Emacs Arbitrary Code Execution Returns https://lobste.rs/s/jdjb2a #emacs #security
https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html
#tech #dev #security #cybersecurity #InfoSec #Vercel #breach #OAuth #AI
On (not) using “cryptographic hashes” for hash table keys by @RunxiYu@social.treehouse.systems https://lobste.rs/s/0u4fin #security
https://runxiyu.org/comp/ch4ht/
AI has another security problem https://lobste.rs/s/5vufp0 #security #vibecoding
http://200sc.dev/posts/ai-security-apr-2026/
Less than a month after 6.7, suckless pushed a security fix and bumped
the version. That's pretty rare for dwm.
If you noticed Telegram's image previews shaking in 6.7, that's why
a wrong return value check broke atom property reading entirely.
Patch: https://git.suckless.org/dwm/commit/a9aa0d8ffbb548b0b1f9f755557aef2482c0f820.html
Six lines changed.
Update your build.
#dwm #suckless #security #linux
Your Container Is Not a Sandbox via @jryans https://lobste.rs/s/bznmaf #security #virtualization
https://emirb.github.io/blog/microvm-2026/
C8s: A Confidential Kubernetes Architecture https://lobste.rs/s/a2mdys #cryptography #hardware #security #virtualization
https://arxiv.org/abs/2604.26974
New Privacy Guides article 🔐
by me:
If you are an Apple user looking for a free, open-source, and privacy-focused password manager, KeePassium is a fantastic option.
KeePassium offers synchronization options, but allows you to keep your password database offline by default.
It's also KeePass-compatible, which makes migrating from or to any other KeePass-compatible apps easy.
Check the full review here: https://www.privacyguides.org/articles/2025/05/13/keepassium-review/
#PrivacyGuides #Security #Privacy #Password #PasswordManager #KeePass #KeePassium
Pillow 12.1.1 has been released!
This is a security release, addressing an issue in Pillow >= 10.3.0, so upgrade soon!
https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html
#Python #Pillow #PythonPillow #release #security
