Search
Items tagged with: Security
Hardware backdoors in x86 CPUs
GitHub - xoreaxeaxeax/rosenbridge: Hardware backdoors in x86 CPUs
Hardware backdoors in x86 CPUs. Contribute to xoreaxeaxeax/rosenbridge development by creating an account on GitHub.GitHub
Downfall Attacks
Downfall
Downfall attacks targets a critical weakness found in billions of modern processors used in personal and cloud computers.Downfall Attacks
⚠️Quick tip for the privacy community: remember that duress passwords and decoy PINs can be a double-edged sword. In some jurisdictions, using them during an investigation is treated as destruction of evidence, which may result in separate criminal charges and prison time.
Stay safe by knowing your rights and talking to a local legal professional before setting up these tools!
#software #privacy #security #data #justice #law #hacking #foss #opensource #freesoftware #grapheneos #android #mobile
Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
The hacked digital advertiser was caught serving malicious ads that allowed hackers to steal a victim's cryptocurrency.Zack Whittaker (~this week in security~)
Spider-Man: Brand New Day
Het fulltime bestrijden van misdaad als Spider-Man in een wereld die hem niet meer herinnert – en de druk om zijn oude vrienden zonder hem verder te zien gaan – zet een verandering in gang in Peter Parker die hij misschien niet in de hand heeft.The Movie Database
DPRK says US-led ‘cyber warnings’ aim to tarnish its image
North Korea says US-led ‘cyber warnings’ aim to tarnish its image
North Korea denounces the US and its allies for making unfounded allegations about PyongyangPressTV
The Python Software Foundation is hiring a Security Developer to join @miketheman and I on triaging vulnerability reports and mitigating malware published to PyPI.
If you've got experience with Python, security, and collaborating with open source projects then we'd love to hear from you:
jobs.pyfound.org/apply/ei03ut6…
#python #security #pypi #supplychain #vulnerability
Security Developer - Python Software Foundation - Career Page
Apply to Security Developer at Python Software Foundation in Remote.Python Software Foundation
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure. This attack was very sophisticated, and the resulting document doubles as a crash-course …Simon Willison’s Weblog
🐛 NEW SECURITY CONTENT 🐛
💻 macOS Tahoe 26.6 - 155 bugs fixed
support.apple.com/en-us/128067
💻 macOS Sequoia 15.7.8 - 138 bugs fixed
support.apple.com/en-us/128071
💻 macOS Sonoma 14.8.8 - 127 bugs fixed
support.apple.com/en-us/128072
⌚ watchOS 26.6 - 100 bugs fixed
support.apple.com/en-us/128068
📺 tvOS 26.6 - 100 bugs fixed
support.apple.com/en-us/128069
🥽 visionOS 26.6 - 99 bugs fixed
support.apple.com/en-us/128070
📱 iOS and iPadOS 26.6 - 87 bugs fixed
support.apple.com/en-us/128066
#apple #cybersecurity #infosec #security #ios
About the security content of iOS 26.6 and iPadOS 26.6 - Apple Support
This document describes the security content of iOS 26.6 and iPadOS 26.6.Apple Support
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files.Pierluigi Paganini (Security Affairs)
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
GitHub - berabuddies/redis-poc: RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0. Contribute to berabuddies/redis-poc development by creating an account on GitHub.GitHub
My security camera shipped a GitHub admin token in its login page
My security camera shipped a GitHub admin token in its login page
i dissected some firmware for a Hanwha Wisenet XNP-9300RW and found that it had github admin tokens in it, also miltech is weirdhhh.hn
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: bobdahacker.com/blog/click-to-…
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later.bobdahacker.com
Vulnerability-Lookup 5.5.0 released
Add Rocky Linux OSV feeder by adulau · Pull Request #482 · vulnerability-lookup/vulnerability-lookup
Motivation Ingest OSV advisories published by Rocky Linux's Apollo service where no git repo/dump is available by consuming the Apollo paginated OSV API and mapping records into the existing O...GitHub
DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.
The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.
Your browsing data stays within the EU and is protected from cyber threats without being monetized!
#dns #browser #security #privacy #eu #europe
Official site of the DNS4EU project
Experience DNS4EU, the European security ecosystem led by Whalebone. Access our free Public Service for private browsing or upgrade to DNS4GOV for professional-grade government and critical infrastructure protection.joindns4.eu
