Let's move all of our internal code, pipelines, secrets and tokens for external systems to someone. It's free and everyone does - it must be awesome. Welcome to 2026!
#git #security #vulnerability #github #opensource
POLA Would Have Prevented the Event-Stream Incident (2018) via @jfred https://lobste.rs/s/wu3gry #practices #security
https://agoric.com/blog/technology/pola-would-have-prevented-the-event-stream-incident
Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat https://lobste.rs/s/dns8du #rust #security
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Finding a RCE in my old TP-Link router https://lobste.rs/s/lplm9j #reversing #security
https://mrbruh.com/tplink/
Github: internal repositories have been accessed https://lobste.rs/s/gq8stb #security
https://nitter.net/github/status/2056884788179726685
Copy Fail - From Pod to Host https://lobste.rs/s/iy258n #linux #security
https://xint.io/blog/copy-fail-pod-to-host
Project Glasswing: what Mythos showed us https://lobste.rs/s/ym8s9n #security #vibecoding
https://blog.cloudflare.com/cyber-frontier-models/
Node.js Security Bug Bounty Program Paused Due to Loss of Funding https://lobste.rs/s/s7me2f #nodejs #security
https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties
Grafana Labs GitHub repos breached via TanStack npm supply chain attack via @ABGEO https://lobste.rs/s/fnie3k #javascript #security
https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/
I discovered a large-scale malware distribution on GitHub https://lobste.rs/s/pc7tnx #security
https://orchidfiles.com/github-repositories-distributing-malware/
I Reached Out to the White House Counterterrorism Czar for Comment. He Lashed Out on X.
---
Sebastian Gorka accused a ProPublica reporter of writing a “putrid piece of hackery” about him. Here’s how basic beat reporting led to a broader story about the state of the U.S. counterterrorism mission at a critical moment.
https://www.propublica.org/article/sebastian-gorka-counterterrorism-reporting?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post
#News #WhiteHouse #Government #USPolitics #Security #Journalism
How cross-thread double free detection could work in glibc malloc https://lobste.rs/s/bb8f7o #c #linux #security
https://kallus.org/blog_tcache_key.html
Postmortem: TanStack npm supply-chain compromise https://lobste.rs/s/d8iunk #javascript #security
https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
uutils coreutils CVEs https://lobste.rs/s/juyhsy #rust #security
https://seclists.org/oss-sec/2026/q2/332
Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) https://lobste.rs/s/nwdn3w #linux #security
https://cdn2.qualys.com/advisory/2026/05/20/cve-2026-46333-ptrace.txt
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None https://lobste.rs/s/k8mkgs #security
https://scotthelme.co.uk/xss-is-deadly-for-passkeys-the-hidden-risk-of-attestation-none/
Chromium publishes fixed exploit 4 years later, turns out it's actually unfixed via @hugoarnal https://lobste.rs/s/e7lsqn #browsers #security
https://infosec.exchange/@rebane2001/116606719764376414
How many sandboxed pods can fit in a Pi? https://lobste.rs/s/mu1yfd #performance #security
https://nubificus.co.uk/blog/runtime_benchmarking_rpi/
#GOP offers a ridiculous additional $1B for #WhiteHouse “security”, sparking dispute over #ballroom
#Senate #Republicans maintain their proposal would authorize #security construction, but not the #Trump ballroom. The White House disagrees.
Senate Republicans late Monday proposed $1 billion to pay for new White House security measures, with lawmakers & White House ofcls disagreeing over whether the #legislation would cover Trump’s planned ballroom.
#law #waste #fraud
https://www.washingtonpost.com/politics/2026/05/05/senate-budget-bill-trump-ballroom/
FatGid - FreeBSD 14.x kernel LPE https://lobste.rs/s/yy3xax #freebsd #security
https://fatgid.io/
Secure Boot and CA Rollover - a heads-up for distributions https://lobste.rs/s/qwytbf #linux #security
https://blog.einval.com/2026/05/22#secure_boot_ca_rollover
A Private pkg Repo Behind Mutual TLS https://lobste.rs/s/ggqpxg #devops #freebsd #security
https://oshogbo.com/blog/88/
Dependency cooldowns are unfair; we should use phased rollouts instead https://lobste.rs/s/jyhbzg #practices #security
https://illegalcode.net/rfcs/phased_rollouts.html
How to open calc.exe from S&Box https://lobste.rs/s/r6lw7v #debugging #dotnet #reversing #security
https://slugcat.systems/post/26-05-21-how-to-open-calc-exe-from-sbox/