Upcoming breaking changes for npm v12 https://lobste.rs/s/drkeug #security
https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
security
Some fascinating research out on hacking a Subaru via STARLINK connected vehicle service.
"On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK connected vehicle service that gave us unrestricted targeted access to all vehicles and customer accounts in the United States, Canada, and Japan.
Using the access provided by the vulnerability, an attacker who only knew the victim’s last name and ZIP code, email address, phone number, or license plate could have done the following:
Remotely start, stop, lock, unlock, and retrieve the current location of any vehicle.
Retrieve any vehicle’s complete location history from the past year, accurate to within 5 meters and updated each time the engine starts.
Query and retrieve the personally identifiable information (PII) of any customer, including emergency contacts, authorized users, physical address, billing information (e.g., last 4 digits of credit card, excluding full card number), and vehicle PIN.
Access miscellaneous user data including support call history, previous owners, odometer reading, sales history, and more.
After reporting the vulnerability, the affected system was patched within 24 hours and never exploited maliciously."
Upgrade your systems now!
The xz package has been backdoored
https://archlinux.org/news/the-xz-package-has-been-backdoored/
Hackers can steal 2FA codes and private messages from Android phones. The "Pixnapping" attack is a really clever piece of research. It shows that the theoretical wall between apps on your phone isn't as solid as we'd like to believe. By exploiting a GPU side channel, a malicious app with zero permissions can effectively screenshot other apps, one pixel at a time. It's a reminder that security is a stack, and a vulnerability at the hardware level can undermine everything built on top of it.
TL;DR
👾 A new attack called "Pixnapping" can read visual data from other apps on Android devices.
🔑 It exploits a GPU side-channel leak to steal sensitive info like 2FA codes and messages, pixel by pixel.
⚠️ The scary part: the malicious app required for the attack needs zero special permissions to be granted.
🧠 While complex to pull off, this is a serious proof of concept that challenges the core idea of OS app sandboxing.
https://arstechnica.com/security/2025/10/no-fix-yet-for-attack-that-lets-hackers-pluck-2fa-codes-from-android-phones/
#Android #Cybersecurity #SideChannelAttack #2FA #security #privacy #cloud #infosec
I'm giving another #surveillance detection seminar in our intimate small classroom setting. Sign up for our full course at https://ivycyber.com/product/course-surveillance-defense/
#tech #dev #web #internet #SecurityTheater #cybersecurity #infosec #security
A backdoor in a LinkedIn job offer https://lobste.rs/s/2u1z4w #security
https://roman.pt/posts/linkedin-backdoor/
Hey! Let's talk about #SSH and #security!
If you've ever looked at SSH server logs you know what I'm about to say: Any SSH server connected to the public Internet is getting bombarded by constant attempts to log in. Not just a few of them. A *lot* of them. Sometimes even dozens per second. And this problem is not going away; it is, in fact, getting worse. And attackers' behavior is changing.
The graph attached to this post shows the number of attempted SSH logins per day to one of @cloudlab s clusters over a four-year period. It peaks at about 3.4 million login attempts per day.
This is part of a study we did on our production system, using logs of more than 640 million login attempts, covering more than 1,500 hosts on our side and observing more than 840 thousand incoming IP addresses.
A paper presenting our analysis and a new, highly effective means to block SSH brute force attacks ("Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them") will be presented next week at #NSDI24 by @sachindhke . The full paper is at https://www.flux.utah.edu/paper/singh-nsdi24
Let's dive in. 🧵
AI is Breaking Two Vulnerability Cultures https://lobste.rs/s/kuhmb0 #security #vibecoding
https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures
An exploitable integer overflow in Lix (CVE-2026-44028) https://lobste.rs/s/ebv5qy #nix #security
https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/
Why Nobody Can Verify What Booted Your Server https://lobste.rs/s/uagdwq #security
https://unmitigatedrisk.com/?p=1231
Somehow bot-detecting algorithms have been degrading over time.
This is a troubling trend because people who aren't using the anointed access points of the internet struggle more and more to connect and interact. Large entities like CloudFlare choke off more and more avenues of access in the name of "security", enforcing digital checkpoints without any accountability to anyone.
#dev #tech #web #bot #DarkPattern #security #infosec #cybersecurity #checkpoint
some people were saying #linux is insecure, even less than Windows
where do these claims come from? are they true? what can we users do? #security #cybersecurity
Time travel without borders via @hugoarnal https://lobste.rs/s/gz9o6e #nix #security
https://guix.gnu.org/en/blog/2026/time-travel-without-borders/
Rewriting Every Syscall in a Linux Binary at Load Time https://lobste.rs/s/66cgid #linux #security
https://substack.com/home/post/p-194037971
If you are the tech-savvy person within your family or friends group
:
Never ever shame someone for coming to you for advice after being the victim of a scam, malware, or for using an unsecure product.
If you do this,
they might never come back to you later. They might just feel so ashamed they will just stay alone with their tech problems.
Instead, always tell them:
1. It was a good idea to come to you with this. Be empathetic with them 💚
2. Give them advice on how to minimize the damage now. Actionable advice 🚑
3. Help them harden their security for now and for the future. Recommend better products to them. But be careful not to overwhelm them with advice. One step at the time 🔒
4. Talk to them with respect and empathy. Tell them how the people who abused their trust are horrible and anyone can fall for the right scam. Remind them there are things to do to reduce the risks of being victimized again in the future, and help them slowly implementing these 💪
5. Be thankful they trusted you with this. It means they think highly of you 🥰
🇦🇹 Austria's Armed Forces have replaced MS Office with LibreOffice on 16,000+ workstations 📄
This shift began in 2020 to avoid mandatory cloud reliance ☁️
Their goal? Digital sovereignty—not cost saving 🔒
They even contributed 5+ person-years of code 🛠️
EU trend toward open-source grows 🇪🇺
🔗 https://news.itsfoss.com/austrian-forces-ditch-microsoft-office/
#TechNews #LibreOffice #Linux #OpenSource #Privacy #FOSS #Security #Europe #EU #Microsoft #Cloud #DigitalSovereignty #Government #Defense #Innovation #Technology
Security update: Hollo 0.6.12 is now available
We've released #Hollo 0.6.12 to fix a critical privacy #vulnerability where direct messages were being exposed in the replies section of public posts. Please update your instances immediately to ensure your private conversations remain private.
went down to the hotel lobby to retrieve my dinner delivery in a yoga outfit + snuggly cardigan + face mask.
some men with #RSAC2024 lanyards exited the elevator as I re-entered; they turned back to look at me and one said (very loudly, very pointedly staring at me) to the other, “I was like, did you hire me a hooker?”
if you are a man attending #rsac, please shut that kind of shit down when your peers do it. let’s not let insecurity rule our #security industry.
A Network Allow-List Won't Stop Exfiltration https://lobste.rs/s/obnccl #ai #linux #security #vibecoding
https://www.dergraf.org/notes/canister-egress-proxy-dlp/
ssh-keysign-pwn: Read root-owned files as an unprivileged user https://lobste.rs/s/wskhre #linux #security
https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/
I have drafted an email critical of the #digitalomnibus proposal in #EU from a wide-reaching privacy, #technology sector protection and #geopolitical risk standpoint.
Read here:
https://nx82858.your-storageshare.de/s/sBFL5CxHY7Yf3XC
Send to EU representatives with this list of emails:
https://nx82858.your-storageshare.de/s/xQogH6dXKifXfS6
If you care about #souvereignty #security and #privacy, please boost and take part in this #campaign !
What is your favorite app for
Multifactor Authentication, and why do you like it most? 2️⃣✌️👀
Plastic Flowers to Protect the Hive https://lobste.rs/s/lwjndk #nodejs #python #security #vibecoding
https://phildini.dev/slopsquatting-for-good


