Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary https://lobste.rs/s/cvzb9z #ai #security
https://www.magonia.io/research/why-a-decade-of-writing-detection-logic-makes-the-mythos-exploit-numbers-less-scary/
security
First public macOS kernel memory corruption exploit on Apple M5 https://lobste.rs/s/qfbsno #mac #security
https://blog.calif.io/p/first-public-kernel-memory-corruption
Where Have All the Complex Windows Malware and Their Analyses Gone? https://lobste.rs/s/sq70nc #security
https://r136a1.dev/2026/05/07/where-have-all-the-complex-malware-and-their-analyses-gone/
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open https://lobste.rs/s/97laur #privacy #security
https://bobdahacker.com/blog/tldv-hack
HAPPENING NOW: @mikalai presents 3NWeb + @privacysafe 😍 Watch @hopeconf #HOPE2025 #hacking #privacy #security https://www.youtube.com/watch?v=zxgoACKKH30
🤖 Most people still treat AI chatbots like a private confessional, but they aren’t. 😳 Every question is logged, stored, and potentially discoverable, sometimes even after you’ve deleted it. OpenAI, Google, and Anthropic all retain user prompts by default, often under the guise of “memory” or “service improvement.”
And here’s the kicker: a federal court order now forces OpenAI to preserve all ChatGPT conversations, including “Temporary” ones users assumed were erased. So the notion of ephemeral chats is gone. That should change how people think about what they type into these systems.
The bigger issue is that the line between “helpful personalization” and “permanent surveillance record” is blurring fast. What looks convenient today could look like an exposure tomorrow.
TL;DR
⚠️ AI queries are logged
🔐 Deleted chats still saved
🧠 “Memory” is default setting
📂 Court orders enforce retention
https://www.theregister.com/2025/08/18/opinion_column_ai_surveillance/
#AI #Privacy #DataSecurity #Surveillance #FRCP #EDRM #security #privacy #cloud #infosec #cybersecurity #LegalHold
Post-Quantum VPN Based on QUIC https://lobste.rs/s/ewpr4z #cryptography #networking #rust #security
https://github.com/quincy-rs/quincy
minipgp6: A very lean interpretation of modern OpenPGP https://lobste.rs/s/yfuber #cryptography #security
https://codeberg.org/minipgp6/minipgp6
🔐 Thank you for your Gold sponsorship of DjangoCon US 2025!
Their identity provider solutions help secure Django applications.
Glad to have you here in Chicago Sept 8-12!
New Research: A "Verified" GitHub Commit Is NOT Unique https://lobste.rs/s/qlw9wg #programming #security
https://www.internationalcyberdigest.com/new-research-a-verified-github-commit-is-not-unique/
Silent Replacement of Trusted macOS App Executables https://lobste.rs/s/dxaogf #mac #security
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
Come join us at the Open Security Conference!
🗓️ Dates: 2025, October 2-5
📍 Location: Rückersbach, close to Frankfurt am Main, Germany
🌐 Website: https://opensecurityconference.org/
❓ FAQ: https://opensecurityconference.org/faq/
➡️ Register: https://register.opensecurityconference.org/
#osco #osco25 #CyberSecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity #OpenSpace [lisi]
Our devotion to privacy and security has led to these two noticeable features in iOS:
1. Permission prompt to access the clipboard (iOS 14)
2. Option to disable downloading icons in Passwords (iOS 26)
We have contributed to several bug fixes under the hood, but these two features are special because they surface in the UI. We are very proud that millions of users see the result of our work on their devices.
#Apple #privacy #security #infosec #cybersecurity
1/4
...🧵
STOLEN & CONCEALED NATIONAL DEFENSE DOCUMENTS CASE
Remember:
Cannon was deemed *unqualified* by the American Bar Association.
#DoJ filed a rebuke to Cannon, in what I think is a situation most ripe for an appeal to the Eleventh Circuit for her "clear error" and "manifest injustice."
#DoJ:
“She worked on almost no cases. She had very little courtroom experience. To find a case that actually she worked on and that resulted in a published opinion is in itself improbable... “It’s a brilliant maneuver..."
Unqualified #Judge keeps making bizarre rulings clearly favoring the man who appointed her, federal prosecutors have resorted to citing case law that Cannon should know for one major reason: She worked on it herself.
DoJ fired off a quiet shot across the bow at Cannon in a recent court filing—a filing that seeks to block Trump’s latest ploy to morph this criminal case into some kind of wild goose chase.
🧵 1️⃣
#traitor #traitortrump #crime #national #security #threat #DoJ #natsec
Mastodon 再次发布紧急安全更新。
请站长立刻更新。
更新描述为
安全性:修正对远端贴文的检查不足。
https://github.com/mastodon/mastodon/releases/tags/v4.2.7
目前暂时没有公开的安全告知:
https://github.com/mastodon/mastodon/security/advisories/GHSA-jhrq-qvrm-qr36
#Mastodon #MastoAdmin #Security
@board @board@a.gup.pe
RE: https://tech.lgbt/users/ShadowJonathan/statuses/111940983829390502
My new article is out, this time it’s about internet-connected cameras, mostly being marketed as spy cameras. While the cameras themselves are very different, the common factor is the LookCam app used to manage them.
There is already a considerable body of research on these and similar P2P cameras, so it shouldn’t be a surprise that their security is nothing short of horrible. Still, how the developers managed to make all the wrong choices here on every level (firmware, communication protocol, cloud functionality) is quite something.
https://palant.info/2025/09/08/a-look-at-a-p2p-camera-lookcam-app/
Any app on recent Android versions can leak certain traffic https://lobste.rs/s/ulnrmv #android #security
https://mullvad.net/en/blog/any-app-on-recent-android-versions-can-leak-certain-traffic
I’m excited to share my latest article, published in Forbes: Deepfakes And Social Engineering: A Growing Threat To Everyone.
This piece is personal to me because I’ve seen how quickly deepfake technology is moving from novelty to real-world attacks. It’s not just companies at risk—families are being targeted with AI-cloned voices and fake video calls.
In the article, I break down the real cases we’re seeing, why multifactor authentication (MFA) is essential, and what both organizations and individuals like you and me can do to protect ourselves.
In the piece, I cover:
🔍 Real-world scams driven by AI voice and video
🔐 Why multifactor authentication (MFA) is essential
📱 How both organizations and families can verify smarter
🧠 The mindset shift from trusting appearances to verifying identities
Deepfakes aren’t a future problem. They’re here. And the time to prepare is now.
https://www.forbes.com/councils/forbestechcouncil/2025/08/25/deepfakes-and-social-engineering-a-growing-threat-to-everyone/
#Forbes #cybersecurity #deepfakes #MFA #security #privacy #cloud #infosec #AI #leadership
@forbes @Forbes@newsie.social @forbestechcncl
Libinput Hit By Worrying Security Issues With Its Lua Plug-In System https://lobste.rs/s/es2tfh #linux #security
https://www.phoronix.com/news/Libinput-Lua-Security-Issues
Ukraine says it hacked Russia's Ministry of Defense
https://t.me/DIUkraine/3545 #infosec #cybersecurity #security
Securitybaseline.eu via @fs111 https://lobste.rs/s/zbpytx #security
https://securitybaseline.eu/
🤯 LIVE ON SEP 20: We're hosting another #surveillance and counter-surveillance workshop with @JohnKiriakou and @profdiggity
Sign up before it's sold out! 👇
https://ivycyber.com/product/cia-pov-john-kiriakou/
If you got a tip & need anonymity you can message me here. (i don’t respond to corporate flacks on signal)

