cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]LWN.net » 🌐
@lwn@fedi.lwn.net

[?]Peter N. M. Hansteen » 🌐
@pitrh@mastodon.social

yes, this happened:

Apr 8 23:46:59 skapet sshd-session[69515]: Failed none for invalid user Can't locate List/Util.pm in @INC (you may need to install the List from 175.199.67.164 port 51226 ssh2

(and several times more, of course)

Background: "Badness, Enumerated by Robots" nxdomain.no/~peter/badness_enu and links therein

    [?]Aaron Toponce ⚛️:debian: » 🌐
    @atoponce@fosstodon.org

    The and maintainer accounts have been locked out by Microsoft. They are now unable to deliver Windows updates.

    cybernews.com/security/microso

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      Nix privilege escalation security advisory

      lwn.net/Articles/1066813/

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]Peter N. M. Hansteen » 🌐
        @pitrh@mastodon.social

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        Hackers breached the European Commission (The Next Web)

        lwn.net/Articles/1066371/

          [?]Graham Perrin » 🌐
          @grahamperrin@mastodon.bsd.cafe

          @nielsa no, that's not what I'm telling you.

          I prefer to believe that most people will be thoughtful.

          "… a huge number of bugs. I have so many bugs in the Linux kernel that I can't report because I haven't validated them yet. I'm not going to make some open source developer validate bugs that I haven't checked yet. I'm not going to send them potential slop … I now have … several hundred crashes that they haven't seen because I haven't had time to check them. We need to find a way to fix this …"

          – Nicholas Carlini

          Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

          Alt...Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

            [?]doragasu » 🌐
            @doragasu@mastodon.sdf.org

            ➡️ in 2025: Make sure your OS is up to date, use trusted apps from trusted sources, use strong passwords, beware of apps with excessive permission requests, be careful with phishing attempts...
            ➡️ Security in 2026: The most popular app in GitHub requires complete access to your system and personal accounts holding sensitive information, and you must assume your system is compromised 🤦‍♂️

            makes people dumb 🤷‍♂️
            arstechnica.com/security/2026/

              [?]gyptazy » 🌐
              @gyptazy@gyptazy.com

              Adding the new feature to for clusters during Easter is basically: hiding eggs → finding eggs → realizing some eggs are actually critical alerts

              For real, many people asked me for their smaller and mid-sized environments, how to handle remote syslog of their nodes. I had some ideas (some of you may have already found my Rust interpretation of this) but I think having this included in as a centralized management interface makes more sense.

              So, PegaProx comes with an own syslog server (ipv4/ipv6, udp/tcp, encrypted/unencrypted support) and is wired to the interface within the resources tab. Providing a quick overview of all your logs and filter options. The next thing is wiring it to the notification system of PegaProx, allowing automated alerting. Might be nice to quickly identify when the quorum got lost - all built-in into PegaProx!


              A syslog integration (server & frontend audit) for PegaProx for Proxmox based clusters

              Alt...A syslog integration (server & frontend audit) for PegaProx for Proxmox based clusters

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                Paco Hope boosted

                [?]Metin Seven 🎨 » 🌐
                @metin@graphics.social

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                mle✨ boosted

                [?]mle✨ » 🌐
                @mle@infosec.exchange

                Last summer I looked at the Internet exposure of a few devices that have historically been the subject of attacks by Iranian threat actors. Given continued activity in the region, I refreshed that data and took another look at exposures.

                Good news: all four device/software types showed at least a slight decrease in exposures since last June, even if we aren't entirely sure why.

                More details + graphs here: censys.com/blog/ics-iran-part-

                  [?]Hylke Bons 🥜 » 🌐
                  @hbons@mastodon.social

                  if you like this, I'm aiming to provide at least one project with an app icon every week.

                  honoured to have gained around 40 supporters in my first jobless month! ❤️

                  your sponsorship will help me keep this up. :)

                  mastodon.social/@hbons/1161661

                    [?]Wen » 🌐
                    @Wen@mastodon.scot

                    [?]Paco Hope [He/Him] » 🌐
                    @paco@infosec.exchange

                    This article about ‘s CLI is also hysterical (in a making me want to give up and join a commune kind of hysterical) because of the anthropomorphising of the AI.

                    What is the most frustrating aspect of LLMs? Many would use the anthropomorphic term “hallucination.” Apparently are bad but “dreams” are good?

                    When a user goes idle or manually tells Anthropic to sleep at the end of a session, the AutoDream system would tell Claude Code that “you are performing a dream—a reflective pass over your memory files.”

                    “Why does my code say that Wonder Woman is running a taco truck downtown and I’m the only person who can save her dog?” Oh. Right. It was dreaming.

                      [?]Paco Hope [He/Him] » 🌐
                      @paco@infosec.exchange

                      We can quit and just go farm potatoes or something. After 25 years of one of the most talked-about tech companies invents a daemon process that

                      makes use of a file-based “memory system” designed to allow for persistent operation across user sessions.

                      Sure. Just store your system instructions in a random text file.

                      Why are we installing endpoint protection on this system?

                      Why do we verify cryptographic signatures on software updates to this system?

                      Why are we building a zero trust security environment?

                      Why do we do scan email to avoid social engineering emails?

                      Our AI-assisted users are gonna YOLO right past all that. And if they can’t get past our controls, this agentic Frankenstein will write itself some markdown and work quietly in the background figuring out how to bypass something the user couldn’t bypass on their own.

                      This is in 2026

                        chfkch :nixos: :rust: boosted

                        [?]Hylke Bons 🥜 » 🌐
                        @hbons@mastodon.social

                        done! drew the rest of the f***ing owl.

                        App icon for BitRitter in the GNOME icon style. A light blue shield with a thick darker blue border. Overlayed is a password field.

                        Alt...App icon for BitRitter in the GNOME icon style. A light blue shield with a thick darker blue border. Overlayed is a password field.

                          [?]Fedora Project » 🌐
                          @fedora@fosstodon.org

                          TLS and SSH rely on Certificate Authorities (CAs) for authentication, but they also present a vector for Man in the Middle attacks. What if you could set up your own CA to reduce your exposure?

                          ➡️ fedoramagazine.org/make-a-priv

                            [?]LWN.net » 🌐
                            @lwn@fedi.lwn.net

                            [?]Rich Stein (he/him) » 🌐
                            @RunRichRun@mastodon.social

                            Great distraction from the Epstein files and the thickening quagmire in Iran — but it's not going to lower gas prices nor help with the midterms:
                            U.S. plans a witch hunt — err... antifa summit.

                            Deflect and distract. 🙁
                            reuters.com/world/us/us-counte
                            h/t @Nonilex
                            masto.ai/@Nonilex/116323980616

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              Vulnerability Research Is Cooked (sockpuppet.org)

                              lwn.net/Articles/1065586/

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                [?]Larvitz :fedora: » 🌐
                                @Larvitz@burningboard.net

                                Running your own identity provider is all fun and games until you're debugging OIDC token flows at 2 AM.

                                If you want to deploy Keycloak 26 the right way - with proper network isolation, no plaintext passwords, and systemd-native declarative configs. I just published a new deep-dive.

                                We're ditching compose files and building a production-ready, daemonless stack using Podman Quadlets and systemd.

                                Read the full guide here: blog.hofstede.it/keycloak-26-o

                                  [?]Liminal witch 🧙‍♀️ Sarah [She/sie/tema] » 🌐
                                  @xgebi@hachyderm.io

                                  6 ★ 2 ↺
                                  Mike Sheward boosted

                                  [?]sam » 🌐
                                  @sam@cablespaghetti.dev

                                  Fediverse, I have a rant I need to get off my chest. Groups in Google Workspace is a security nightmare and has been for years! Why has Google STILL not fixed the glaring problems!?

                                  I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.

                                  This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.

                                  Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.

                                  Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...


                                  Screenshot of the default Google Group settings for team mode

                                  Alt...Screenshot of the default Google Group settings for team mode

                                  Screenshot of the default Google Group settings for public mode

                                  Alt...Screenshot of the default Google Group settings for public mode