cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Verified Apps (Privacy Guides) is an app‑signing certificate hash viewer/verifier that checks installed apps or APKs against a crowdsourced DB. MIT • Last update 2026-06-13. Learn more: https://github.com/privacyguides/verified-apps-android/blob/main/README.md 🔐📱 #Security #Android #OpenSource
https://apt.izzysoft.de/fdroid/index/apk/org.privacyguides.verifiedapps
Your Question: Will Bill C-34 Affect Mastodon?
One of the questions we got is whether or not Mastodon is affected by Bill C-34. We'll make an attempt to answer that today.
https://www.freezenet.ca/your-question-will-bill-c-34-affect-mastodon/
#Censorship #News #Privacy #Security #AgeVerification #BillC34 #Canada #Mastodon #OnlineHarms #SocialMedia
GrapheneOS version 2026061800 released:
https://grapheneos.org/releases#2026061800
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/36568-grapheneos-version-2026061800-released
Did you miss #PyConUS this year? 🐍🛡️ Here's a summary of everything security at @pycon US 2026, including the new security talk track, an update from PSF security engineers, and notes from the OSS maintainer security open space.
#Security #OpenSource #SupplyChain #SBOM
https://pyfound.blogspot.com/2026/06/everything-security-at-pycon-us-2026.html
GrapheneOS version 2026061600 released:
https://grapheneos.org/releases#2026061600
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/36483-grapheneos-version-2026061600-released
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
Well that's pretty sneaky. Cybercriminals deployed ransomware on a target's network and disguised their footsteps as MS Teams traffic.
#news #technews #cybersecurity #security #microsoft #crime #cybercrime #ransomware
I'm with Frances Ryan, there is a false distinction drawn by our political class between threats to security that emanate from the global system & those that stem from how UK society is organised.
The argument that we necessarily need to choose between military expenditure & welfare spending (wilfully) misunderstands the *real* threats to the UK population.
Rather we should see the UK's 'security' as including the plight of the population.
#security #politics #welfare
https://www.theguardian.com/commentisfree/2026/jun/16/warfare-v-welfare-britain-spend-benefits-defence-safe
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps.
Mullvad is aware of this issue. It is described in this blog:
https://mullvad.net/en/help/why-wireguard
You can download Loupe here:
https://apps.apple.com/app/id6766152470
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
The security situation with the Arch Linux AUR got a lot worse https://www.gamingonlinux.com/2026/06/the-security-situation-with-the-arch-linux-aur-got-a-lot-worse/
The Arch Linux AUR had over 400 packages compromised with malware https://www.gamingonlinux.com/2026/06/the-arch-linux-aur-had-over-400-packages-compromised-with-malware/
syslogd(8) privileged and non-privileged parts now separate binaries https://www.undeadly.org/cgi?action=article;sid=20260612080210 #openbsd #syslogd #privsep #privelegeseparation #separation #security #logging #development
Government Rolling Age Verification and Online Harms into One Giant Mess
Reports suggest that the Canadian government is introducing a bill that would combine online harms and age verification legislation.
https://www.freezenet.ca/government-rolling-age-verification-and-online-harms-into-one-giant-mess/
#Censorship #News #Privacy #Security #AgeVerification #Canada #FreeSpeech #legislation #OnlineHarms
Dealing with passkeys is kind of hassle for me. Does it get better after a while?
I’m asking because I started selfhosting PocketID and it ONLY has passkeys, no passwords and I have to decide if I keep it or not.
Larson: Are insecure code completions a vulnerability?
https://lwn.net/Articles/1077413/ #LWN #Linux #security #Python
The Arsenal, the sister publication of The Counteroffensive, conducted an #interview with U.S. Senator Ruben Gallego at the Black Sea #Security Forum about #veterans and how they can be supported now and after the war. Watch it at the link! https://www.counteroffensive.news/p/war-threatens-ukraines-checkers-champions
[$] Eliminating long-lived credentials with trusted publishing
Trusted publishing is an authentication mechanism that relies on short-lived credentials to reduce the risk of supply-chain attacks. At the 2026 Open Source Summit North America, M [...]
https://lwn.net/Articles/1076205/ #LWN #Linux #security #Python #Git #OSS
I think I've mentioned this before, but I'm toying around with adding keyboard patterns in my password generator.
The algorithm:
1. Pick a random key.
2. Identify adjacent keys horizontally and vertically.
3. Pick a random adjacent key.
4. Repeat until entropy target is reached.
72-bit examples:
Colemak: 098(){]|}+}[{]\\]|}|}[{{:YU8u
Dvorak: 5$#$p>EJkXKJkUpyp>#2#>pYF
QWERTY: XZxcxzxZXSXsde3>?.?:?>?:"[}+
Workman: _+-0["['I"['iO>oEnFuENfNyn
Do i have someone in my peer group that could give a 4 hrs workshop on target Information Gathering at a company? Ideally based on Kali linux or alike.
Schweizer Rüstungsunternehmen RUAG zahlt Lösegeld an Cybergang
Nachdem die Cybergang Akira bei der RUAG-Tochter Mecanex USA Daten abgezogen hat, hat RUAG ein Lösegeld gezahlt.
UK: Palantir break clause
Cross party committee of MPs has just officially recommended that the government trigger the break clause in #Palantir's #NHS contract.
The report states ...
#corruption #privacy #security #USThreats #USAggression #BigData
[1/2]
Introducing Loupe, our latest privacy app for iOS. Discover what apps can learn about you just by reading data your iPhone already exposes, such as your languages, installed apps, device sensors, and much much more
Loupe is free, private, and open source. Give it a try 👇
https://apps.apple.com/app/id6766152470
Link to source code:

We have completed the update to Mastodon v4.5.11 which contains some security fixes. Protecting our community is paramount to us - so we'd rather not wait until the wee little hours.