Search
Items tagged with: security
Cyberattacke auf Berliner Verwaltung, Ermittlungen laufen
Die Senatskanzlei berichtet von einem Angriff auf Teile der Verwaltung in der Hauptstadt. Ein Krisenstab ist eingerichtet. Viele Fragen sind offen.
heise.de/news/Cyberattacke-auf…
#Cyberangriff #IT #Journal #Security #news
AI applied to hardening systems might cause US intelligence agencies to lose a large portion of their surveillance capabilities.
Everything is about to “go dark”
I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaini…A Few Thoughts on Cryptographic Engineering
#Hackers On Planet Earth - #HOPE
#HOPE26 will be the seventeenth Hackers On Planet Earth event. It will take place from August 14-16, 2026, at the New Yorker Hotel in #NewYorkCity.
This promises to be a memorable event. It is open to all hackers, makers, tinkerers, experimenters, artists, educators and anyone else with an interest in exploring and improving the world we live in, and sharing knowledge with others.
HOPE is an all-ages event with multiple simultaneous sessions and many other things to do throughout the weekend.
Some of what you can expect:
Speaker sessions
Workshops
Entertainment
Contests
Vendors
Space to socialize
Hands-on learning opportunities
Friendly and supportive conference attendees
#privacy #security
Hackers On Planet Earth - HOPE
HOPE (Hackers On Planet Earth) is an annual conference for hackers, makers, and tech enthusiasts based in New York City.HOPE
#TutaMail and #ProtonMail are by far the world's two best email providers/services for #Anonymity, #Privacy and #Security (#APS).
I have recently (12th August 2026) carried out a thorough research into this as I am planning to migrate to whichever is the best email provider/service for APS and move away and ditch US Big Tech.
Between the two, the one that comes on top depends on what you value most on aggregate. In individual edge terms, here is how they compare:
Tuta Mail: cheaper; more custom domains; more email addresses; more established/robust Post-Quantum (PQ) Security;
ProtonMail:
Terabytes of credentials leaked in massive supply-chain attack
Terabytes of credentials leaked in massive supply-chain attack
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.Dan Goodin (Ars Technica)
Vulnerability-Lookup 6.0.0 released — webhook notifications, local exploit hazard API, and a vulnerability credits index
Modeling Local Exploit Hazard - A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency
This paper presents a local exploit hazard model : a Bayesian framework that converts the global probabilities produced by an exploit likelihood model (ELM), such as the Exploit Prediction Scoring System (EPSS), into a daily exploit hazard rate for a…arXiv.org
Make sure your Flatpak is up to date due to security issues
#Flatpak #Linux #Security #OpenSource
Make sure your Flatpak is up t...
Make sure your Flatpak is up to date due to security issues
Version 1.18.1 and 1.19.0 pre-release rolled out for Flatpak, due to some security issues that were found so it's an essential update for all Linux systems.Liam Squires-Hand (GamingOnLinux)
Hardware backdoors in x86 CPUs
GitHub - xoreaxeaxeax/rosenbridge: Hardware backdoors in x86 CPUs
Hardware backdoors in x86 CPUs. Contribute to xoreaxeaxeax/rosenbridge development by creating an account on GitHub.GitHub
Downfall Attacks
Downfall
Downfall attacks targets a critical weakness found in billions of modern processors used in personal and cloud computers.Downfall Attacks
⚠️Quick tip for the privacy community: remember that duress passwords and decoy PINs can be a double-edged sword. In some jurisdictions, using them during an investigation is treated as destruction of evidence, which may result in separate criminal charges and prison time.
Stay safe by knowing your rights and talking to a local legal professional before setting up these tools!
#software #privacy #security #data #justice #law #hacking #foss #opensource #freesoftware #grapheneos #android #mobile
Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
The hacked digital advertiser was caught serving malicious ads that allowed hackers to steal a victim's cryptocurrency.Zack Whittaker (~this week in security~)
Spider-Man: Brand New Day
Het fulltime bestrijden van misdaad als Spider-Man in een wereld die hem niet meer herinnert – en de druk om zijn oude vrienden zonder hem verder te zien gaan – zet een verandering in gang in Peter Parker die hij misschien niet in de hand heeft.The Movie Database
DPRK says US-led ‘cyber warnings’ aim to tarnish its image
North Korea says US-led ‘cyber warnings’ aim to tarnish its image
North Korea denounces the US and its allies for making unfounded allegations about PyongyangPressTV
The Python Software Foundation is hiring a Security Developer to join @miketheman and I on triaging vulnerability reports and mitigating malware published to PyPI.
If you've got experience with Python, security, and collaborating with open source projects then we'd love to hear from you:
jobs.pyfound.org/apply/ei03ut6…
#python #security #pypi #supplychain #vulnerability
Security Developer - Python Software Foundation - Career Page
Apply to Security Developer at Python Software Foundation in Remote.Python Software Foundation
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure. This attack was very sophisticated, and the resulting document doubles as a crash-course …Simon Willison’s Weblog
🐛 NEW SECURITY CONTENT 🐛
💻 macOS Tahoe 26.6 - 155 bugs fixed
support.apple.com/en-us/128067
💻 macOS Sequoia 15.7.8 - 138 bugs fixed
support.apple.com/en-us/128071
💻 macOS Sonoma 14.8.8 - 127 bugs fixed
support.apple.com/en-us/128072
⌚ watchOS 26.6 - 100 bugs fixed
support.apple.com/en-us/128068
📺 tvOS 26.6 - 100 bugs fixed
support.apple.com/en-us/128069
🥽 visionOS 26.6 - 99 bugs fixed
support.apple.com/en-us/128070
📱 iOS and iPadOS 26.6 - 87 bugs fixed
support.apple.com/en-us/128066
#apple #cybersecurity #infosec #security #ios
About the security content of iOS 26.6 and iPadOS 26.6 - Apple Support
This document describes the security content of iOS 26.6 and iPadOS 26.6.Apple Support
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files.Pierluigi Paganini (Security Affairs)
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
GitHub - berabuddies/redis-poc: RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0. Contribute to berabuddies/redis-poc development by creating an account on GitHub.GitHub
My security camera shipped a GitHub admin token in its login page
My security camera shipped a GitHub admin token in its login page
i dissected some firmware for a Hanwha Wisenet XNP-9300RW and found that it had github admin tokens in it, also miltech is weirdhhh.hn
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: bobdahacker.com/blog/click-to-…
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later.bobdahacker.com
Vulnerability-Lookup 5.5.0 released
Add Rocky Linux OSV feeder by adulau · Pull Request #482 · vulnerability-lookup/vulnerability-lookup
Motivation Ingest OSV advisories published by Rocky Linux's Apollo service where no git repo/dump is available by consuming the Apollo paginated OSV API and mapping records into the existing O...GitHub
DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.
The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.
Your browsing data stays within the EU and is protected from cyber threats without being monetized!
#dns #browser #security #privacy #eu #europe
Official site of the DNS4EU project
Experience DNS4EU, the European security ecosystem led by Whalebone. Access our free Public Service for private browsing or upgrade to DNS4GOV for professional-grade government and critical infrastructure protection.joindns4.eu
