"Mythos" at Home, and It's Called AISLE via @daveliepmann https://lobste.rs/s/cuh3be #security #vibecoding
https://stanislavfort.substack.com/p/mythos-at-home-and-its-called-aisle
security
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection https://lobste.rs/s/5fw1oe #security #vibecoding
https://0day.click/recipe/2026-05-12-cc-rce/
YellowKey Bitlocker Bypass Vulnerability via @PolyWolf https://lobste.rs/s/aovfvz #security #windows
https://github.com/Nightmare-Eclipse/YellowKey
Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability https://lobste.rs/s/xnoqe8 #security
https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability
Sculpt OS release 26.04 via @RunxiYu https://lobste.rs/s/8gpopi #osdev #release #security
https://genode.org/news/sculpt-os-release-26.04
Passwords suck. Can passkeys replace them? via @dario https://lobste.rs/s/oyo7dd #security
https://kerkour.com/passkeys
Counterterrorism Czar’s Blueprint Targets Leftists, Ignores Far-Right Violence and Heaps Praise on Trump
---
Sebastian Gorka’s anti-terror plan makes no mention of long-established threats posed by far-right militants and instead villainizes the president’s political enemies. “This administration is not paying attention to the data,” one expert said.
https://www.propublica.org/article/trump-counterterrorism-plan-ignores-far-rights-gorka?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post
#News #Terrorism #Trump #USPolitics #Violence #Security #Extremism
Noroboto: Lying fonts and mitigation in Rust https://lobste.rs/s/xsnzi6 #law #rust #security
https://tritium.legal/blog/noroboto
21 Zero-Days in FFmpeg https://lobste.rs/s/ejra5c #security
https://depthfirst.com/research/21-zero-days-in-ffmpeg
The First CVE Wave: Signs That AI-Assisted Vulnerability Discovery Is Reshaping Disclosure Volumes https://lobste.rs/s/xksr2p #security
https://www.vulncheck.com/blog/ai-assisted-vulnerability-discovery
security mitigations ansible role https://lobste.rs/s/f4alia #devops #security
https://git.sig-io.nl/sigio/mitigations
Mini Shai-Hulud - TanStack and more npm packages compromised, with SLSA Build Level 3 provenance attestations https://lobste.rs/s/y1k2qm #security
https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem
Does anyone have recommendations for a Mastodon fork that doesn't require visitors to enable JavaScript to view basic content? The JavaScript dependency is a security risk and user hostile. Visitors should not be required to enable JavaScript when simply visiting a Mastodon server. Plus, the recommendation to use a native app doesn't even work for all Mastodon/ActivityPub instances.
Also, the requirement for JavaScript makes the Mastodon development team seem incompetent. They can't even make a basic web site that doesn't require JavaScript. I could do that when I was in middle school.
>To use the Mastodon web application, please enable JavaScript. Alternatively, try one of the native apps for Mastodon for your platform.
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens via @refi64 https://lobste.rs/s/l9uweb #android #security
https://projectzero.google/2026/05/pixel-10-exploit.html
https://github.com/v12-security/pocs/tree/main/qemu
The worst thing, people are providing pocs before maintainers and upstreams have time to fix.
#qemu #kvm #kubevirt #security #vm #kvm
score by collisions, patch by panic https://lobste.rs/s/pi9gjl #practices #security
https://blog.himanshuanand.com/2026/05/score-by-collisions-patch-by-panic/
CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation https://lobste.rs/s/lwtmzl #security #windows
https://github.com/orinimron123/CVE-2026-40369-EXPLOIT
Cheap smart doorbell allows fleet-wide account takeover and call hijacking by @ABGEO https://lobste.rs/s/yxj57x #hardware #reversing #security
https://www.abgeo.dev/blog/anyone-can-ring-your-doorbell/
Recent Kernel exploits, attack surface reduction, example IPSEC by @hanno https://lobste.rs/s/kep6ok #linux #networking #security
https://www.openwall.com/lists/oss-security/2026/05/16/3
Why people working on software where something serious is at stake would throw out known gradient to use a code generator + testing is beyond my capacity to understand.
https://1password.social/@1password/116580082041363054
#AI #GenAI #GenerativeAI #LLM #VibeCoding #Software #SoftwareDevelopment #tech #dev #security #InfoSec #PasswordManagers
Security is Hard, Y’all https://lobste.rs/s/qoptbx #security
https://textslashplain.com/2026/08/04/security-is-hard-yall/
Debian SE Linux and PinTheft https://lobste.rs/s/jlhsqw #linux #security
https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/
2026-05-20 FreeBSD errata notice and seven security advisories
https://www.reddit.com/r/freebsd/comments/1tjaceg/20260520_freebsd_errata_notice_and_seven_security/
– an overview, including clickable links to CVE records.