Search
Items tagged with: mastoadmin
The attribution for Mastodon's CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:
"This security issue has been reported by Doyensec in collaboration with Claude and Anthropic Research"
Is this how they say "Mythos" without revealing that Doyensec is one of the undisclosed Project Glasswing members?
github.com/mastodon/mastodon/s…
w.on-t.work/activitypub/may-20… says:
"Doyensec has contacted us on *behalf* of Anthropic".
#security #mastoadmin #mythos #ai #glasswing
LD-Signature Bypass via JSON-LD Named-Graph Restructuring
### Summary Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing attackers t...GitHub
We currently have 913 users, 408 active users (with at least one request, login, post, or reaction within the last 24 hours), 385189 posts, and we federate with 43301 domains.
GitHub - mementomori-social/mastodon: Your self-hosted, globally interconnected microblogging community
Your self-hosted, globally interconnected microblogging community - mementomori-social/mastodonGitHub
Tonight's Mastodon upgrade took a bit longer, because they're making a lot of structural changes and needed to update the nightly theme. I eventually got it right.
We just released Mastodon 4.5.10, 4.4.17, and 4.3.23.
These versions contain several medium and high severity security fixes.
Also, please note that this marks the final Mastodon v4.3 update, this branch is now unsupported. If you are still using it, please move to a newer version as soon as possible.
Full release notes and update instructions are available on the GitHub releases page.
github.com/mastodon/mastodon/r…
Releases · mastodon/mastodon
Your self-hosted, globally interconnected microblogging community - mastodon/mastodonGitHub
RE: cupoftea.social/@Whiskeyomega/…
We've been dealing with the same thing on our invite-only instance. I've been planning to add Cloudflare Turnstile for registrations and maybe a few other mitigations. They're quite sneaky, since the registration reasons often sound totally believable. I've been using this blacklist checker, usually, the email domain is showing up on a blacklist: mxtoolbox.com/blacklists.aspx
#MastoAdmin #Spam #AISlop #AI
Will Phoenix (@Whiskeyomega@cupoftea.social)
Discovered this morning that the spam AI Slop had a human signing up and then inviting the AI Slop as a way to circumvent the Approval sign ups. Finally managed to ban outright the main culprit email system smtp.oneb.Will Phoenix (CupOfTea.Social)
Release 4.0.0-alpha.8.rc · rollecode/mastodon-bird-ui
4.0.0-alpha.8.rc: 2026-05-03 NoteWIP Notice: This is a heavily work-in-progress upcoming version of Mastodon Bird UI. This version is part of the ongoing major rewrite (see issue #172) and is final...GitHub
Mastodon is not going to allow colored badges anymore, but we are going to keep them in our instance. With this rate of deprecation, we can expect even more forks, but that's OK. Luckily, Mastodon is open source.
github.com/mastodon/mastodon/i…
#Mastodon #MastoAdmin #OpenSource
Role badge color from admin settings not applied after the profile redesign in v4.6.0-alpha.6
Steps to reproduce the problem Go to Administration > Roles and edit a role Set a badge color for the role Assign the role to a user and make it highlighted Visit that user's profile page Expected ...rollecode (GitHub)
GitHub - mementomori-social/mastodon: Your self-hosted, globally interconnected microblogging community
Your self-hosted, globally interconnected microblogging community - mementomori-social/mastodonGitHub


