Search
Items tagged with: security
Self-Host Weekly #149: A Few of My Favorite Things
My #favorite apps of 2025, software updates and launches, a spotlight on #wastebin -- a lightweight #pastebin app, and more in this week's #selfhosted recap!
#selfhost #selfhosting #foss #opensource #homelab #newsletter #devops #sysadmin #development #privacy #security #fediverse #software
Self-Host Weekly #149: A Few of My Favorite Things
Bidding wars, mobile bookmarks, and my favorite new self-hosted apps from 2025Ethan Sholly (selfh.st)
GitLab discovers widespread npm supply chain attack
GitLab discovers widespread npm supply chain attack
Malware driving attack includes "dead man's switch" that can harm user data.Michael Henriksen (GitLab)
Vulnerability-Lookup 2.19.0
Vulnerability-Lookup 2.19.0
We’re delighted to announce the release of Vulnerability-Lookup 2.19.0! What’s New GCVE: Global CVE Allocation System We’re pleased to announce the publication of: GCVE-BCP-02 – Practical Guide to Vulnerability Handling and Disclosure, and GCVE-BC…ossbase.org
blog.gslin.org/archives/2025/1…
中國的 NanoKVM 內藏麥克風以及監聽軟體
#aircrack #amixer #arecord #backdoor #china #ip #kvm #linux #mic #micphone #nanokvm #network #security #ssh #tcpdump #wifi
中國的 NanoKVM 內藏麥克風以及監聽軟體
NanoKVM 屬於 IPKVM 類的產品,也就是可以透過網路操作遠端的機器的鍵盤與滑鼠 (有些可以再掛上 USB storage 開機),因為這是突破了物理隔離的限制,這種產品在資安上的問題都會很嚴重。 這次引起注意的是在 NanoKVM 上面發現內藏麥克風以及監聽軟體:「How I discovered a hidden microphone on a Chinese NanoKVM (via)」。 作者抓的照片中有標出麥克風的位置...Gea-Suan Lin (Gea-Suan Lin's BLOG)
Schleswig-Holstein reports €15M yearly savings by replacing Microsoft 365 with LibreOffice across most government workplaces 💶
About 80% of offices have migrated, with a €9M one-time investment planned for 2026 to finish the shift and strengthen open-source tools 🧩
🔗 itsfoss.com/news/german-state-…
#TechNews #OpenSource #Privacy #Security #Government #EU #Data #Sovereignty #IT #PublicSector #Digital #Microsoft #Office #Software #Tech #Cloud #FOSS #Germany #German #LibreOffice
Hurray! This German State Decides to Save €15 Million Each Year By Kicking Out Microsoft for Open Source
Schleswig-Holstein's migration to LibreOffice reaches 80% completion, with a one-time €9 million investment on cards for 2026.Sourav Rudra (It's FOSS)
telefoncek.si/2025/02/2025-02-…
To summarize: the device is riddled with security flaws, originally shipped with default passwords, communicates with servers in China, comes preinstalled with hacking tools, and even includes a built-in microphone - fully equipped for recording audio - without clear mention of it in the documentation. #hardware #security #offrehacked
Be careful, if the product is too secure, the user may be a criminal. This is how some parts of the EU think about security and data protection.
The German #BSI has made 2025 the Year of #Email #Security
Great initiative - and great rating for Tuta ❤️ - your secure email provider from Germany. 🇩🇪
bsi.bund.de/DE/Themen/Kampagne…
Eckpunkte zum E-Mail-Sicherheitsjahr
Das Bundesamt für Sicherheit in der Informationstechnik hat zusammen mit eco – Verband der Internetwirtschaft e.V. und Bitkom e.V. das E-Mail-Sicherheitsjahr 2025 ausgerufen.Bundesamt für Sicherheit in der Informationstechnik
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations of a mercenary spyware company focused on exploit…Amnesty International's Security Lab
Cloudflare's 2025 Q3 DDoS threat report -- including Aisuru, the apex of botnets
Cloudflare mitigates record 29.7 Tbps DDoS attack by the AISURU botnet
Cloudflare blocked a record 29.7 Tbps DDoS attack from the AISURU botnet. The 69-second attack set a new high.Pierluigi Paganini (Security Affairs)
Ouch. CVE rating 10.
react.dev/blog/2025/12/03/crit…
#Security #vulnerabilities #reactjs
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfacesreact.dev
End-of-Year Threat Intelligence Sightings Forecast
EU Funding & Tenders Portal
The Funding and Tenders Portal is the single entry point (the Single Electronic Data Interchange Area) for applicants, contractors and experts in funding programmes and procurements managed by the European Commission.ec.europa.eu
Your offensive-security library, ready to go.
18 DRM-free books. $700+ value. Pay what you want (as little as $36).
Includes Black Hat Bash, Serious Cryptography, Practical Malware Analysis, and more.
Support the @eff and level up your lab. Link in bio.
humblebundle.com/books/hacking…
#hacking #books #offensive #security
Humble Tech Book Bundle: Hacking by No Starch
Turn your curiosity about computer hacking into a fast-paced, proven, and practical career with the latest Humble Tech Book Bundle!Humble Bundle
Indien zwingt WhatsApp und Telegram zur permanenten SIM-Bindung
Indiens Telekombehörde DoT verpflichtet Messenger-Dienste zur dauerhaften SIM-Bindung. WhatsApp, Telegram und Signal müssen binnen 90 Tagen umstellen.
heise.de/news/Indien-zwingt-Wh…
#Cybersecurity #Mobiles #Netzpolitik #Security #Signal #SIMKarte #Telegram #WhatsApp #news
Briliant, just brilliant!
Ireland’s "Pause Before You Post" campaign aims to raise awareness about the risks that come with sharing excessive #personalinformation on the #internet.
reddit.com/r/Damnthatsinterest…
#security #OnlineSafety #ThinkBeforeYouPost #DigitalAwareness #PrivacyMatters #StaySafeOnline #CyberSafety #ProtectYourData #InternetAwareness #SafePosting #InfoSecurity #privacy #bigdata #survaillance #socialmedia
Wow, if you search for signal messenger on DuckDuckGo using Chrome, the actual @signalapp web site is the *third* entry following ads for “Signal Private Messenger – Free Download” that leads to the site appmaus.com and “Get Signal Messenger | Install Signal App” that leads to the site filelocations.com.
DuckDuckGo should be held criminally liable for anyone who ends up downloading malware because of this.
CC @Mer__edith
#DuckDuckGo #Signal #adtech #teachingPeopleHowToGetPhished #malware #security #privacy #BigTech
Taking a Curated Look at Black Friday Sales For 2025
A small curated list of Black Friday sales by independent creators or small businesses covering areas of technology, gaming and miscellaneous deals.
adamsdesk.com/posts/black-frid…
#blog #BlackFriday #tech #InfoSec #security #100DaysToOffload @Tutanota @b0rk
oh no, not npm again...
- YouTube
Bekijk je favoriete video's, luister naar de muziek die je leuk vindt, upload originele content en deel alles met vrienden, familie en anderen op YouTube.www.youtube.com
Cato CTRL™ Threat Research: HashJack - Novel Indirect Prompt Injection Against AI Browser Assistants
HashJack - First Known Indirect Prompt Injection | Cato Networks
HashJack hides attacks in URLs using AI prompt injection. Cato CTRL reveals six risks, from phishing to data theft and misinformation.Vitaly Simonovich (Cato Networks)
How Quickly Can AI Crack Your Password?
Are Your Passwords in the Green?
Passwords that felt secure a year ago might not hold up in 2025. Hive Systems’ updated Password Table reveals just how much faster hackers can break into accounts today.Corey Neskey (Hive Systems)
Malicious app developers offering to buy old apps from developers who are no longer active, so they can push malware onto those users
I'm writing a #guide for #cybersecurity:
take a look: wiki.doomsday.site/en/cybersec…
Please feel free to comment your ideas for more tools ...
#security #surfing #internet #browser #firefox #privacy #surveillance #tracking #bigbrother #orwell #online #cyberspace #cybercrime #bigtech #web #www #anonymity
3.5 Billion Accounts: Complete WhatsApp Directory Retrieved and Evaluated
3.5 Billion Accounts: Complete WhatsApp Directory Retrieved and Evaluated
Vienna researchers retrieved all WhatsApp numbers. The 3.5 billion profiles represent the largest data leak in history—and it's worse than you might think.Daniel AJ Sokolov (heise online)
DeepSeek-R1 erzeugt unsicheren Code bei politisch sensiblen Begriffen
Die chinesische KI DeepSeek-R1 erzeugt schlechteren Code, wenn Begriffe wie Falun Gong oder Taiwan im Prompt stehen. Das fanden Sicherheitsforscher heraus.
heise.de/news/DeepSeek-R1-erze…
#DeepSeek #IT #KünstlicheIntelligenz #Programmierung #Security #Sicherheitslücken #Zensur #news
Vulnerability-Lookup 2.18.0 - Integration with Rulezet
feature request - users directory and user profile pages to be accessible only to logged in users.
Perhaps it would be better if the user pages were only available to logged in users. I am talking about the /users/ directory and the /user/username pages For the time being, since I am using apach...matpanel (GitHub)
