soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Fifty Years of Open Source Software Supply-Chain Security https://lobste.rs/s/ga0vwq #programming #security
https://cacm.acm.org/practice/fifty-years-of-open-source-software-supply-chain-security/
Our plan for a more secure npm supply chain https://lobste.rs/s/slysq6 #javascript #security
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
Exploring GrapheneOS secure allocator: Hardened Malloc https://lobste.rs/s/popcyd #android #security
https://www.synacktiv.com/en/publications/exploring-grapheneos-secure-allocator-hardened-malloc
Crypto Miner in hotio/qbittorrent https://lobste.rs/s/6wzpji #security
https://apogliaghi.com/2025/09/crypto-miner-in-hotio/qbittorrent/
Kernel Security in the Wild: Side-Channel-Assisted Exploit Techniques, Kernel-Level Defenses, and Real-World Analysis https://lobste.rs/s/hgcjod #pdf #linux #security
https://tugraz.elsevierpure.com/ws/portalfiles/portal/98775241/main.pdf
Linux Kernel Runtime Guard (LKRG) 1.0 https://lobste.rs/s/trvolm #slides #linux #security
https://www.openwall.com/presentations/NullconBerlin2025-LKRG/
Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame https://lobste.rs/s/sbib09 #security #web
https://bughunters.google.com/blog/6715529872080896/beyond-sandbox-domains-rendering-untrusted-web-content-with-safecontentframe
Less is safer: how Obsidian reduces the risk of supply chain attacks https://lobste.rs/s/oenamh #security
https://obsidian.md/blog/less-is-safer/
Hacking with AI SASTs: An overview of ‘AI Security Engineers’ / ‘LLM Security Scanners’ for Penetration Testers and Security Teams https://lobste.rs/s/vmilfm #practices #security #vibecoding
https://joshua.hu/llm-engineer-review-sast-security-ai-tools-pentesters
Shai-Hulud, The Most Dangerous NPM Breach In History Affecting CrowdStrike and Hundreds of Popular Packages https://lobste.rs/s/rgfgku #nodejs #security
https://www.koi.security/incident/shai-hulud-npm-supply-chain-attack-crowdstrike-tinycolor
Protect your keys with the Secure Enclave https://lobste.rs/s/8kj7sz #transcript #ios #security
https://octet-stream.net/b/scb/2025-09-16-protect-your-keys-with-the-secure-enclave.html
Want to piss off your IT department? Are your links not malicious looking enough? https://lobste.rs/s/zletng #satire #security
https://phishyurl.com
From suspicion to published curl CVE https://lobste.rs/s/y6ptel #devops #security
https://daniel.haxx.se/blog/2025/09/18/from-suspicion-to-published-curl-cve/
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens https://lobste.rs/s/r6td3c #security
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages https://lobste.rs/s/ozicir #javascript #security
https://www.sysdig.com/blog/shai-hulud-the-novel-self-replicating-worm-infecting-hundreds-of-npm-packages
PyPI Token Exfiltration Campaign via GitHub Actions Workflows https://lobste.rs/s/ksefec #python #security
https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/
Linux 6.17 Security: New Kernel Hardening & Mitigation Controls https://lobste.rs/s/7bd5z6 #linux #security
https://www.armosec.io/blog/linux-6-17-security-features/
ctrl/tinycolor and 40+ NPM Packages Compromised https://lobste.rs/s/tbmypi #security
https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised
Security through intentional redundancy https://lobste.rs/s/gwnulr #security #vibecoding
https://commaok.xyz/post/security-through-redundancy/
Protecting Rust against supply chain attacks https://lobste.rs/s/ylbxri #rust #security
https://kerkour.com/rust-supply-chain-attacks
OCSP Service Has Reached End of Life https://lobste.rs/s/7jiz4y #security
https://letsencrypt.org/2025/08/06/ocsp-service-has-reached-end-of-life
On the Security of SSH Client Signatures https://lobste.rs/s/6sig0s #security
https://arxiv.org/abs/2509.09331
a few notes on ratelimiting by @fanf https://lobste.rs/s/kkqhue #security
https://dotat.at/@/2025-09-14-ratelimit.html
Pass: Unix Password Manager https://lobste.rs/s/lmdyti #linux #security
https://www.passwordstore.org/
@blueluma #privacy and #security are inherently intertwined.
There is no legitimate reason to demand any #PII when there's neither legal mandate (i.e. #KYC / #AML) nor risk of fraud (i.e. #prepaid services).
2015: #USA #military strongest #security guarantee for #Europe: basically true. But there's no big threats and USA is unravelling internally politically
2025: "#Ukraine military strongest security guarantee for Europe, #EU's #Kallas says"
No lies detected
Send everything to Ukraine, Europe
Then send some more
Ukraine is fortress Europe. You owe Ukraine your peace and security now
Ukraine will not join #NATO. NATO will join Ukraine
@briankrebs
Here's a gift link (valid til Sept. 12) for the story on oregonlive.com just in case anyone has trouble with the "prove you're a human" page for the archive link
🛡️ Who Owns, Operates, and Develops Your VPN Matters: An analysis of transparency vs. anonymity in the VPN ecosystem, and implications for users
New research: Eight popular, commercial VPN apps operate deceptively and put more than 700 million users at risk of authoritarian surveillance.
GrapheneOS version 2025090300 released:
https://grapheneos.org/releases#2025090300
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/26117-grapheneos-version-2025090300-released
New Privacy Guides article 🔒 🚩
by me:
They all claim:
"Your privacy is important to us."
But how can we know if that's true?
With all the privacy washing and disinformation around, it becomes increasingly difficult to evaluate who we can trust with our data.
There are red flags, and green(ish) flags, we can look for to help us assess who to trust, or not 🚩
https://www.privacyguides.org/articles/2025/09/03/red-and-green-privacy-flags/
#PrivacyGuides #Privacy #Security #PrivacyWashing #SecurityTheater #Disinformation
As "privacy washing" becomes more and more prevalent, being able to distinguish fact from marketing fiction is an essential skill for you to have. Our latest article covers the
red flags and the
green flags you should look out for when evaluating any service.
https://www.privacyguides.org/articles/2025/09/03/red-and-green-privacy-flags/
#PrivacyWashing #RedFlags #Privacy #Security #GreenFlags #Evaluation #RedFlag #GreenFlag #Article #PrivacyGuides
Update. Another lengthy rebuttal to the #Trump #DOE #climate report:
"20+ National Security Leaders and the Center for Climate & Security Critique the US Department of Energy Climate Report."
https://councilonstrategicrisks.org/2025/09/02/20-national-security-leaders-and-the-center-for-climate-security-critique-the-us-department-of-energy-climate-report/
#DefendResearch #Security #Trump #TrumpVResearch #USPol #USPolitics