Skip to main content

Search

Items tagged with: Security


The attribution for Mastodon's CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:

"This security issue has been reported by Doyensec in collaboration with Claude and Anthropic Research"

Is this how they say "Mythos" without revealing that Doyensec is one of the undisclosed Project Glasswing members?

github.com/mastodon/mastodon/s…

w.on-t.work/activitypub/may-20… says:

"Doyensec has contacted us on *behalf* of Anthropic".
#security #mastoadmin #mythos #ai #glasswing


The GitHub Breach Through VS Code Is the One I Warned About



and folks in this thread: At the risk of feeding myself to the lions, may I suggest care? Gutmann's views on QC are funny to watch, but prone to misinterpretation (although I have to say, this slide in particular is... refreshingly sober?)

gagliardoni.net/#20250714_ludd…

#security #cryptography #crypto #qc #quantum #quantumcomputing #drama


Vulnerability-Lookup 4.6.0



ESA and Spain strengthen ties for secure connectivity



RE: techhub.social/@Techmeme/11660…

Remember this whenever you hear claims that your data is secure on some system or other that you do not own and control.

Like all that additional data governments want to gather via the slippery slope of “age verification” in the EU.

The only data that is actually secure on a third party is data you haven’t shared with the third party.

Hence: data minimisation.

Had I mentioned GDMR yet today? Because I feel I might have. But hey, here it is again:

ar.al/2018/11/29/gdmr-this-one…

#data #security #privacy #GDMR #microsoft #github #hack


GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)

bleepingcomputer.com/news/secu…
techmeme.com/260520/p14#a26052…



🔥BREAKING: GitHub's internal repositories were accessed by unauthorized users, but fear not, it seems their greatest #security threat is JavaScript-disabled browsers. 🚀 It's comforting to know that while our data is at risk, #JavaScript remains the true gatekeeper of internet safety. 🙃
twitter.com/github/status/2056… #GitHub #InternetSafety #DataBreach #HackerNews #ngated

(Nitter addon enabled: Twitter links via https://nitter.privacytools.io)


CISA Admin Leaked AWS GovCloud Keys on Github



A partial response to "Piefed has some really bad security bugs that people running this software should be aware of"



RE: mamot.fr/@pluralistic/11660022…

I'm inclined to think @pluralistic has had entirely enough of this bullshit & so should we all...

#AgeVerification #privacy #security #surveillance


"Object permanence": the ability to understand that things still exist, even if you can't see 'em. Kids acquire a thorough sense of object permanence by the age of two. But when it comes to technopolitics, object permanence eludes full-grown lawmakers. These motherfuckers would lose a game of peek-a-boo.

-

If you'd like an essay-formatted version of this thread to read/share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

pluralistic.net/2026/05/19/she…

1/



Thanks to AI, hackers quickly discovered new vulnerabilities such as CopyFail, DirtyFrag, and Fragnesia. They use LLMs to analyse Linux, finding and exploiting the security flaws faster than ever. The expertise required to hack is at an all-time low.

The Fedora Project decided to explain which precautions are being put in place to protect your system:

🌍 fedoramagazine.org/how-fedora-…

#security #opensource #foss #linux #kernel #fedora #redhat #hacking #ai #llm #coding #copyfail #dirtyflag #fragnesia


PSA: open source security considerations in the era of LLMs



Data Poisoning: The Fatal Flaw in Mass Surveillance

How to use data poisoning to trick the algorithm that’s profiling you (and why “personalization” is more fragile than you think)

youtu.be/AJf4SNuDnoI?si=lUk9FD…

Note: For education and defensive awareness only. I’m explaining the concept of data poisoning so teams can recognize risks and build safer systems. I’m not encouraging or providing guidance for misuse. :)

#DataPoisoning #AI #Algorithms #DataMining #DataPrivacy #Security


Internet of #Shit: #AI #Poop Analysis App Offered to Sell Me Database of Its Users' Poops
#privacy #security

404media.co/ai-poop-analysis-a…


Piefed has some really bad security bugs that people running this software should be aware of



Please update your Firefox to 150.0.3. Details why: https://www.mozilla.org/en-US/security/advisories/mfsa2026-45/ Step-by-step instructions: * open your Firefox application * choose/click menu "Firefox" * choose/click menu item "About Firefox" If it says



A worm just ate its way through the NPM registry...



Counterterrorism Czar’s Blueprint Targets Leftists, Ignores Far-Right Violence and Heaps Praise on Trump
---

Sebastian Gorka’s anti-terror plan makes no mention of long-established threats posed by far-right militants and instead villainizes the president’s political enemies. “This administration is not paying attention to the data,” one expert said.
propublica.org/article/trump-c…

#News #Terrorism #Trump #USPolitics #Violence #Security #Extremism


#Palantir contractors working for #NHS to receive ‘unlimited #access’ to #patient #data

source: techradar.com/pro/security/pal…

“That means that Palantir #software can only be used to process data precisely in line with the instruction of the #customer. Using the data for anything else would not only be illegal but technically impossible due to granular access controls overseen by the NHS.”


"technically impossible" - #lol 😭

#uk #england #health #bigdata #society #politics #economy #privacy #news #security #cybersecurity #analysis #wtf #omg #cloud


Meta removed E2EE from Instagram DMs today, May 8, ending private encrypted chats and enabling broader message scanning for abuse detection 📩🔓
The change follows global pressure tied to CSAM enforcement, raising transparency and user-control concerns around private communication 🕵️‍♂️⚠️

🔗 indiatoday.in/technology/news/…

#TechNews #Instagram #Facebook #Meta #E2EE #Privacy #Encryption #Messaging #CyberSecurity #WhatsApp #ChatControl #Surveillance #FOSS #Security #SocialMedia #DataPrivacy


Linux Dirtyfrag vulnerability



DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026



#Canadian #election databases use "canary traps"—and they work

In a world awash in high-tech #security tools like #passkeys , quantum-safe algorithms, & public-key #cryptography , it can be refreshing to get back to the simple things... like a good old-fashioned #canary trap.

The canary trap is a simple tool often used to identify #leakers or #doubleagents. To make one, you simply share a document, image, or DB but make tiny changes that are unique to each recipient.

arstechnica.com/tech-policy/20…


#GOP offers a ridiculous additional $1B for #WhiteHouse “security”, sparking dispute over #ballroom

#Senate #Republicans maintain their proposal would authorize #security construction, but not the #Trump ballroom. The White House disagrees.

Senate Republicans late Monday proposed $1 billion to pay for new White House security measures, with lawmakers & White House ofcls disagreeing over whether the #legislation would cover Trump’s planned ballroom.

#law #waste #fraud
washingtonpost.com/politics/20…


I Reached Out to the White House Counterterrorism Czar for Comment. He Lashed Out on X.
---

Sebastian Gorka accused a ProPublica reporter of writing a “putrid piece of hackery” about him. Here’s how basic beat reporting led to a broader story about the state of the U.S. counterterrorism mission at a critical moment.
propublica.org/article/sebasti…

#News #WhiteHouse #Government #USPolitics #Security #Journalism


Vulnerability Report - April 2026



Your face is becoming your password, and you can’t change your face.

Facial recognition systems turn your identity into a permanent digital key. If that data is breached, it’s not just another hack — it’s a lifelong vulnerability that can track you, expose you and be nearly impossible to undo.
theconversation.com/facial-rec…

#tech #security #data

theconversation.com/facial-rec…


Copy Fail — 732 Bytes to Root



Officer shot in bullet-resistant vest at correspondents’ dinner but is expected to be OK, law enforcement official says

The #FBI said the shooter is in & and that its Washington field office is responding to the #shooting.

The suspect is alive & has been transported to a hospital, according to one US official & one law enforcement official.

A #SecretService agent was injured & is in the hospital, a US official said.

#Trump #WHCA #WHCD #security #law


#Trump said that a “shooter has been apprehended” in a post to Truth Social about 30 minutes following a security incident at the White House correspondents’ dinner.

Both Trump & JD #Vance were uninjured in the incident.

Trump to give statement at White House after #shooting incident at correspondents’ dinner

#WHCA #WHCD #security #law