Skip to main content

Search

Items tagged with: Security


The PAM Duress is a module designed to allow users to generate 'duress' passwords that when used in place of their normal password will execute arbitrary scripts.

This functionality could be used to allow someone pressed to give a password under coercion to provide a password that grants access but in the background runs scripts to clean up sensitive data, close connections to other networks to limit lateral movement, and/or to send off a notification or alert (potentially one with detailed information like location, visible wifi hot-spots, a picture from the camera, a link to a stream from the microphone, etc). You could even spawn a process to remove the pam_duress module so the threat actor won't be able to see if the duress module was available.

github.com/nuvious/pam-duress

#security #Linux #Arch #Debian


A Libre Architecture for Verifiable Data Collection and Proof-of-Check Timestamping


Establishing trusted, time-stamped records of system states in distributed environments presents a significant challenge for maintaining accountability and security. Organizations often struggle to produce non-repudiable proof that a specific check was performed or that a system was in a particular state at a precise moment in time. SCANDALE is a libre software solution designed to address this challenge by providing a robust backend architecture for collecting data from distributed probes and storing immutable proofs of those checks. Its core components include a high-performance HTTP API with real-time capabilities, an agent-based backend built on the Smart Python Agent Development Environment (SPADE) for scalable probe management, and a dedicated service for cryptographic timestamping in compliance with RFC 3161. The platform’s primary contribution is its ability to transform operational measurements into cryptographically verifiable evidence, yielding a durable and non-repudiable audit trail.


Vulnerability Report - December 2025





In 2025, the German #BSI launched the Year of #Email #Security recommending Tuta Mail.🇩🇪 ❤️

In 2026, we call for a year on end-to-end encryption in email - so they stop recommending Gmail & Co as well. 🔒

#privacy #security


Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) | Cyera Research Labs



Dozens of Global Companies Hacked via Cloud Credentials from Infostealer Infections & More at Risk



As our company hosts servers, we have a public Security Policy and a security.txt file for ethical hackers to disclose vulnerabilities responsibly: handbook.dude.fi/security-poli…

Because of this, I receive quite a few reports, most of them ineligible. I've also run into some "security experts" getting upset about not receiving a bounty for a non-issue or putting heavy pressure on payments for valid ones. It often feels unfair, like I'm being held hostage.

That's why replies like the one I just received warm my heart so much:

"Thank you very much for the clarification and for taking quick action to remove the DNS record. I appreciate the transparency and the kind offer as well.

I'd prefer to donate the amount to a child support charity instead. You’re very welcome to donate it on my behalf to any such organization of your choice."

Donation made. Thank you, stranger. Kindness costs nothing.

#Security #SysOps #SysAdmin #SecOps


After my assembly #39c3 talk on the topic, here’s a more in-depth analysis on the #security of data and metadata in #XMPP : blog.mathieui.net/xmpp-and-met…

I’m sure I missed a lot of things, but since the only reference on the topic is the - now defunct - infosec handbook website with the "admin in the middle" article, I guess that could be useful to somebody.


Bluetooth Headphone Jacking: A Key to Your Phone



The abducted Venezuelan president, Nicolás #Maduro, & his wife will be flown in a helicopter to Manhattan, acc/to a law enforcement source briefed on the #security plan to bring the Venezuelan leader to the #US. From there, Maduro will be driven to the US’ #DEA NYC headquarters. Then he will be taken by helicopter to the Metropolitan Detention Center in Brooklyn. He is expected to be held there.
#law #Congress #WarPowers #Trump #abduction #Venezuela #oil #sovereignty #WarCrimes #InternationalLaw


The #UN #Security Council will convene an emergency meeting on Monday morning to discuss #US strikes in #Venezuela. #Russia, #China & #Colombia asked for the meeting after Venezuela’s mission to the UN wrote a letter to the Council president requesting the meeting to condemn & stop US strikes on the country. Secy Gen António Guterres is expected to address the #UNSC Monday. He said in a statement earlier that all sides must uphold #InternationalLaw & the #UNcharter.

#law #Trump #abduction #oil


The #Venezuela mission to the #UN has requested an emergency #Security Council [#UNSC] meeting & has asked the Council to condemn the #US military strikes against the country.

Venezuela’s ambassador, Samuel Reinaldo Moncada Acosta, said in a letter to the UNSC president: “The United States of America always uses lies to fabricate wars. It is an international #tyranny imposed with the #propaganda of death: the recent past confirms this.”

#law #Trump #abduction #oil #LandGrab #InternationalLaw


#China strongly condemned the #US strike in #Venezuela & the action against its president, the Foreign Ministry said, adding the Beijing govt was “deeply shocked” & firmly opposed to the operation.

“Such hegemonic acts of the US seriously violate #InternationalLaw & Venezuela’s #sovereignty & threaten #peace & #security in #LatinAmerica & the #Caribbean region,” it said.

#law #Congress #WarPowers #criminal #Trump #abduction #oil #LandGrab #WarCrimes #ExtrajudicialKillings #theft #piracy


The Kimwolf Botnet is Stalking Your Local Network



RE: mastodon.social/@_elena/115802…

➡️ media.ccc.de/v/39c3-a-post-ame… by @pluralistic (@eff)

Seen via @_elena

#FOSS #Internet #AI #Europe #Sovereignty #Security #Copyright #Anticircumvention #Capitalism #Tech #Enshittification #Resistance #Future #Activism #EFF


Feeling major FOMO as many Fedi friends and inspiring people are currently at #39c3. But luckily talk recordings are already available!

🔗 : media.ccc.de/popular/2025

I'm about to start watching @pluralistic's "A post-American, enshittification-resistant internet" 🍿

🔗 : media.ccc.de/v/39c3-a-post-ame…

Wishing everyone a great day! ✨

#resist



Why We Abandoned Matrix: The Dark Truth About User Security and Safety





GrapheneOS version 2025121700 released:

grapheneos.org/releases#202512…

See the linked release notes for a summary of the improvements over the previous release.

Forum discussion thread:

discuss.grapheneos.org/d/29166…

#GrapheneOS #privacy #security


Vulnerability-Lookup 2.20.0



#Privacy & #Security meet Up Hosted by #Monero & @webwipe at PubKey NYC 5pm - 10pm, us hackers be stopping by for a bit!

luma.com/zoc6lubi


Just updated Node Pebble to support latest release version of Let’s Encrypt’s Pebble testing server.

codeberg.org/small-tech/node-p…

Enjoy!

💕

#LetsEncrypt #Pebble #testing #tls #ssl #security #NodeJS #JavaScript


GPU Efficiency in VLAI Model Training



Security content of iOS 26.2 and iPadOS 26.2