soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
Every week brings another breach, and a pattern underneath them: the more identity a system collects, the more there is to steal. Passports, fingerprints, phone numbers, all sitting in databases waiting to leak.
The fix isn’t better security on all that data. It’s not collecting it in the first place.
Zerion asks for nothing. No phone number, no email, no ID. Nothing to breach because nothing is stored.
zerion.chat
GitHub itself got breached this week. Around 4,000 code repositories taken, and the group behind it says they’ll sell the source rather than ask for ransom.
Even the platform that hosts the world’s code is a single point that can be hit.
It’s exactly why Zerion treats GitHub as a public mirror, not a dependency. The code is GPLv3 and can live anywhere. Nothing critical relies on it staying up.
zerion.chat
cargo-audit flags Rust dependencies with known vulnerabilities. A flagged crate, though, doesn't tell you whether your code calls the vulnerable function.
We added a feature that matches a binary's symbols against the functions named in each advisory. Any matches are labeled "Affected," separating real exposure from advisories that don't apply.
It's live in cargo-audit 0.22.2+. If you're behind, update with `cargo install -f cargo-audit`.
The White House app is being auto-installed on work phones across multiple US agencies, and employees say it cannot be permanently removed. 📱
The app previously faced security scrutiny over data sharing, and workers raised privacy concerns after it appeared on government-issued phones. đź”’
#TechNews #WhiteHouse #Privacy #Security #Government #MobileApps #DataPrivacy #CyberSecurity #Technology #OpenSource #DigitalRights #InfoSec #FOSS #Tech #US #USA #Trump #DonaldTrump
Hey #InfoSec #SysAdmin folks, anybody heard of ShredOS?
Seems like a potentially useful tool, but the website looks sus:
https://shredos.org/
The GitHub repo seems a bit less sus:
https://github.com/PartialVolume/shredos.x86_64
Edit: the website is not affiliated with the project, see replies. Question stands about the tool itself!
New.
Arctic Wolf: Critical Remote Code Execution Vulnerability in libssh2 Client Library Require Urgent Mitigation https://arcticwolf.com/resources/blog/critical-remote-code-execution-vulnerability-in-libssh2-client-library-require-urgent-mitigation/ #infosec #GitHub #vulnerability
"In a recent study, researchers conducted a first-ever patient-level privacy audit to see how easily individual patients could be identified from the underlying data used to train medical AI models."
https://medicalxpress.com/news/2026-06-patient-groups-vulnerable-privacy-medical.html
Original research: https://www.nature.com/articles/s41586-026-10688-0
OpenAI handed us their most cyber-capable models and asked us to work directly with open-source maintainers to Patch the Planet.
We started with 19 projects: cURL, Python, Sigstore, NATS, and more. 50 projects have now joined the initiative. Each get a dedicated team reviewing code, finding vulnerabilities, and writing patches.
More in their blog: https://openai.com/index/patch-the-planet/
Well it finally happened, I got notified that my medical records, which were in the custody of a third party company without my knowledge, were involved in a big medical data breach last year. This breach apparently went back as far as January 2025 but law enforcement prevented notification of victims until now. Absolute fuckery. I am incandescent. 🤬 🤬 🔪 #privacy #infosec
„A Double Threat“: The EU Revives Chat Control 1.0 in the Same Week That Negotiations on Version 2.0 Are Wrapping Up
Last week, I wrote about Monday’s final meeting on the „Chat Control“ regulation. At that time, there was only one outstanding issue on the table. It was…
Chat Control: The Future of Privacy in the EU Will Be Decided on Monday
On Monday, June 29, European Union negotiators will meet. They will discuss a draft regulation on preventing and combating sexual…
https://vsx.global/on-monday-june-29-a-decision-on-chat-control-regulations-may-be-made-in-the-eu/
It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.
(I don’t recall who wrote the words I used in the graphic here or where I originally saw them. I just made it from my paraphrased version.)
New.
"The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go module compromise involving the Verana Blockchain project."
Socket: Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem @SocketSecurity #infosec #threatresearch #GitHub #npm #malware #JavaScript
FYI @ifin
The EU's "Chat Control" regulation reaches its final trilogue on 2026-06-29. Parliament's position excludes E2EE communications from mandatory scanning; several Council governments want to keep broader scanning powers.
What's actually at stake: client-side scanning before encryption defeats E2EE as a guarantee, no matter what happens to the ciphertext afterward.
@moses_izumi @ltning @ju @cwebber @opensourceopenmind
Security isn't, never was, and never will be a product.
I'm glad I don't know what the #infosec industry is like these days.
Even the new name makes me break out in hives: "cyber security"
It reeks of Dunning-Kruger and hollywoodified idiocy.
We're a sponsor of Stanford's Real World AI Security conference, where Sam Judson will present later today on why AI skill scanners fail.
We recently built 4 skills that bypassed every scanner we tested. He'll elaborate on our conclusion that the tools to catch malicious skills don't work.
https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/
A quick informal poll about #MeshTastic at #defcon since #defcon34 is mere weeks away!
There will almost certainly be a large MeshTastic presence at the con again; which device(s) will you be brining? Â Cooking up some shenanigans with @HamRadioVillage and want to make sure we're hitting all the right buttons.
#infosec #cybersecurity #hackersummercamp #hacktheplanet
| Heltec v3/v4: | 5 |
| CardPuter ADV: | 0 |
| seeed Wio Tracker L1: | 3 |
| seeed XIAO nRF: | 1 |
| LilyGo T-Deck: | 4 |
| LilyGo T-Beam: | 1 |
| Rak WisMesh Pocket: | 1 |
| Rak WisMesh Tap: | 1 |
| LilyGo T-Echo: | 0 |
| Other - comment below: | 1 |
Closed