Have you checked out our Summer Clearance Sale yet? Select back issues and products are 50% off through July 31st! Get 2024 and older issues of Linux Magazine, @adminmagazine, Special Issues, and select products. Follow the link for the shop for your region/currency.
https://shop.linuxnewmedia.com/shop/category/summer-clearance-79
#Linux #OpenSource #security #FOSS #LibreOffice #hacks #RaspberryPi
security
Cybersecurity challenge: be nice to each other [IMPOSSIBLE] https://lobste.rs/s/jifvgs #culture #rant #security
https://sdomi.pl/weblog/29-please-do-better-thanks/
Smartphone security tip of the week: Do not take screenshots of personal or sensitive data
Certain malicious apps secretly search your screenshots for login data, recovery data or personal information.
Read more about this topic: https://smartphone-dont-spy.de/en/list/do-not-take-screenshots-of-personal-or-sensitive-data
An open call to #Android #developers! The #EuropeanCommission needs help evaluating #GooglePlay's #security claims. I'm going to do what I can. Anyone with knowledge of how app installation, uninstallation, sandboxing, signing, etc. could really help here. If you want to contribute, please reach out!
Don't trust cloud services with your creative work.
#enshittification #privacy #infosec #security #cybersecurity #writing #art
A list of Digital Service Providers located outside the jurisdiction of the United States of America:
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
This is an ongoing group project — so if you have any suggestions, corrections, or new information to share, feel free to reach out!
#USJurisdiction #USA #America #UnitedStates #Privacy #Security
Automate the most repetitive operational task in Proxmox: keeping cluster nodes updated! ProxPatch drains, migrates, patches, and reboots nodes in a controlled rolling fashion — no downtime, no manual intervention.
ProxPatch is written in Rust and fully #opensource.
Website: https://proxpatch.de
GitHub: https://github.com/gyptazy/ProxPatch
#PVE #homelab #enterprise #Debian #PatchManagement #ProxmoxVE #Security #ProxLB #SecurityUpdateManagement #Automation #Rustlang
Just found out that #BeagleIM automatically fetches web links in messages and plays the page's video if there is one.
This is not acceptable behavior!!!
* It's annoying. There isn't any obvious way to stop the video.
* It's insecure. The linked page might attack vulnerabilities in Beagle's video player.
* It exposes the user's IP address to anyone who sends them a message, potentially physically endangering them.
Will uninstall and replace ASAP.
***infosec specialists are needed in the resistance ***
The world needs tech security specialists to run workshops at public libraries for all ages & abilities to remove spyware, AI, reduce surveillance, understand the issues, & for more advanced, move to Linux, degooglefy, etc.
Libraries will pay good wages for these workshops.
If you have these skills, please consider offering them.
#libraries #library #tech #infosec #privacy #security #activism #antifa #resistance
Are you interested in a different kind of security conference?
Then take a look at the Open Security Conference (@OSCo). #osco25 takes place from October 2 to 5 in Rückersbach (Germany near Frankfurt) and registration is still open at https://opensecurityconference.org/.
(this is an English version of the original German thread https://infosec.exchange/@realn2s/114936419689473030)
Why?
The Open Security Conference aims to be diverse and inclusive. This also includes different levels of knowledge and experience.
It is therefore not only for security experts or for people who have (already) worked in the security sector for a long time,
but also for people who are interested in security or want to get into the field.
The #OpenSpace format not only enables expert presentations,
but also non-expert topics or questions as session topics. Sessions are not resticted to presentations, they can be interactive, collaborative, workshops or basically anything else.
Since topics do not have to be submitted months in advance,
but the agenda is created jointly by the participants, hot topics can also be covered.
The conference is non-commercial, i.e. the total costs are shared between the participants (including the organizers).
The costs include accommodation and meals in the conference hotel.
And yes, there are also sponsors who cover part of the costs.
But not everything is different.
There are great keynotes e.g. by @bkastl ("History repeating itself") and Mireia Cano ("Building an AppSec Program from Scratch").
#CyberSecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity
LinkedIn Is Illegally Searching Your Computer
#tech #technology #BigTech #IT #enshittification #microslop #microsoft #LinkedIn #social #media #SocialMedia #data #security #safety #InfoSec #internet #web
[$] California's Digital Age Assurance Act and Linux distributions
A recently enacted law in California imposes an age-verification requirement on operating-system providers beginning next year. The language of the Digital Age Assurance Act does n [...]
https://lwn.net/Articles/1062112/ #LWN #Linux #security #Debian
🔒 Security Update for BotKit Users
We've released #security patch versions BotKit 0.1.2 and 0.2.2 to address CVE-2025-54888, a security #vulnerability discovered in #Fedify. These updates incorporate the latest patched version of Fedify to ensure your bots remain secure.
We strongly recommend all #BotKit users update to the latest patch version immediately. Thank you for keeping the #fediverse safe! 🛡️
We've released #security updates for #Hollo (0.4.12, 0.5.7, and 0.6.6) to address a #vulnerability in the underlying #Fedify framework. These updates incorporate the latest Fedify security patches that fix CVE-2025-54888.
We strongly recommend all Hollo instance administrators update to the latest version for their respective release branch as soon as possible.
Update Instructions:
Railway users: Go to your project dashboard, select your Hollo service, click the three dots menu in deployments, and choose “Redeploy”
Docker users: Pull the latest image with docker pull ghcr.io/fedify-dev/hollo:latest and restart your containers
Manual installations: Run git pull to get the latest code, then pnpm install and restart your service
CLI Authentication, the Right Way by @ABGEO https://lobste.rs/s/nqv7yo #practices #security
https://www.abgeo.dev/blog/cli-authentication-the-right-way/
Backstage access: an unauthenticated SQL injection in Front Gate Tickets https://lobste.rs/s/fplb85 #security
https://ian.sh/frontgate
SQLite Critical CVEs or LLM Slop? https://lobste.rs/s/9nxwpi #security
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
Offensive Cybersecurity Time Horizons https://lobste.rs/s/cwzmdl #security
https://lyptusresearch.org/research/offensive-cyber-time-horizons
Are you waiting for an AI miracle? Big projects usually fail because they're trying to change too much at once. My latest Forbes article shows you a better, faster way...
Focus on micro-transformations. You identify and fix a single small bottleneck and see results in weeks. This builds the trust you need to move toward larger goals later.
🧠 Pick one simple manual task.
⚡ Use one specific model or product for it.
💡 Leverage AI tools you already have in your stack, like Google.
🎓 Recognize your savings immediately.
🔍 Move to the next one.
🔍 Expand to a second team once the first succeeds.
A surgical approach builds the confidence your team needs. You stop waiting for a miracle and start seeing results right away.
#AI #artificialintelligence #leadership #CIO #CTO #CISO #Caio #innovation #business #security #privacy #cloud #infosec #cybersecurity
@RHR_International
@forbes
@Forbes@newsie.social
@forbestechcncl
For real, many people asked me for their smaller and mid-sized environments, how to handle remote syslog of their nodes. I had some ideas (some of you may have already found my Rust interpretation of this) but I think having this included in #PegaProx as a centralized management interface makes more sense.
So, PegaProx comes with an own syslog server (ipv4/ipv6, udp/tcp, encrypted/unencrypted support) and is wired to the interface within the resources tab. Providing a quick overview of all your logs and filter options. The next thing is wiring it to the notification system of PegaProx, allowing automated alerting. Might be nice to quickly identify when the quorum got lost - all built-in into PegaProx!
#easter #development #coding #python #opensource #foss #pve #proxmox #proxmoxve #virtualization #vmware #alternatives #free #logging #security #gyptazy #proxmoxdatacenter #homelab #enterprise
Claude Code Found a Linux Vulnerability Hidden for 23 Years https://lobste.rs/s/lh9rmv #security #vibecoding
https://mtlynch.io/claude-code-found-linux-vulnerability/
How Hard Is It To Open a File? via @PolyWolf https://lobste.rs/s/fbfu56 #security #unix
https://blog.sebastianwick.net/posts/how-hard-is-it-to-open-a-file/
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain https://lobste.rs/s/x79usb #security
https://socket.dev/blog/bitwarden-cli-compromised
My domain got abused on Github Pages https://lobste.rs/s/zsjasr #security
https://meertens.dev/blog/github-enables-domain-abuse/
LinkedIn Is Illegally Searching Your Computer via @kirch https://lobste.rs/s/d5lzvy #security
https://browsergate.eu/

