cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
OpenBSD's pledge(2) and unveil(2) are developer-friendly, study finds https://www.undeadly.org/cgi?action=article;sid=20260708055608 #openbsd #security #pledge #unveil #development #programming
Security and Privacy by Design
Get a truly #trustworthy #messenger without hidden #agendas or #backdoors: #chats, #contact lists, and groups are managed in a #decentralized manner directly on the involved devices – no #data is stored on a server.
This way, your communication remains #private and fully under your control at all times.
RouterOS 7.23.2 release notes:
!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
so... we fixed a security vulnerability, but we're not going to tell you what it is, so you have no idea how urgent this update is or how exposed you are or if you're even affected at all.
thanks, i guess?
(rumour has it this is a memory disclosure or potential RCE in pptp/l2tp/ppoe...)
OpenSSH 10.4/10.4p1 released! https://www.undeadly.org/cgi?action=article;sid=20260706190144 #openbsd #openssh #ssh #security #cryptography #secureshell
🔑 DNSSEC is now enabled for media.metalhead.club as well!
Previously this has only been the case for metalhead.club, but not for media resources, because the zone files for my CDN are hosted on external name servers.
https://dnsviz.net/d/media.metalhead.club/dnssec/
Lets hope my config change does not cause any issues with the service 😅
Whereas DirtyClone exploits a kernel module (which can be tackled by unloading and blocking it), Bad Epoll (CVE-2026-46242) does not.
#FRANCE, #UK AND #OMAN AGREE TO ENSURE #SECURITY IN #HORMUZ #STRAIT: On July 3, French #President #Macron and UK #PrimeMinister #Starmer issued a joint #statement announcing an #agreement with Oman, in which the three countries will work together to ensure safe #transit through the #StraitOfHormuz .
https://www.gov.uk/government/news/joint-statement-on-the-strait-of-hormuz-3-july-2026
#Security question: Why no service shows you a list of currently logged in sessions right after login? In my head, this would address so much bigger security space than the “automatic session timeout” theatre:
- User is in control
- User can spot and question deviations
- No thing is taking decision on behalf of user
- Waaaaaaay better UX
MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
@MissConstrue@mefi.social
Ok, to start, let me define "#stenography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
[$] Secure Boot certificate expiration is here
Linux users who have Secure Boot enabled on their systems rely on certificates issued by Microsoft to verify the software used to boot a system is trusted by the user. One of those [...]
https://lwn.net/Articles/1079808/ #LWN #Linux #security #Debian #RedHat
#Trump admin plans to withhold homeland #security #funding to force #states into #election changes
The Trump admin is threatening to withhold tens of millions of dollars in federal homeland security funds from states unless they adopt a sweeping set of election changes, according to multiple sources & internal documents obtained by CNN.
#law #US #Constitution #VotingRights #TrumpCoup #midterms #BigLie #MafiaState #WhiteSupremacy
https://www.cnn.com/2026/06/22/politics/homeland-security-grants-election-changes?cid=ios_app
RE: https://todon.eu/@MediaActivist/116840199440233179
“It’s time for people to have control over their own tech, not governments and corporations. Worker-owned, The People's Tech will help you and your organisation choose #technology at the intersection of #privacy, #security, #sustainability AND #inclusivity. Stay tuned!” ~ @thepeoplestech
I only now notice that my "What has (can) the EU Cyber Resilience Act done (do) for you?" article, in its tracked incarnation https://bsdly.blogspot.com/2026/06/what-has-can-eu-cyber-resilience-act.html made it onto @vermaden's Valuable news: https://vermaden.wordpress.com/2026/06/29/valuable-news-2026-06-29/ #cra #cybersecurity #cyberresilience #development #security #freesoftware #libresoftware #openbsd #netbsd #freebsd #bsdcan #eurobsdcon
Holy crap.
"Nearly a million passports and photo IDs from multiple countries were exposed across unprotected public URLs, accessible to anyone with a link. The documents remained discoverable this way for months, according to reporting by The Verge, before being taken offline."
Original article: https://www.theverge.com/tech/947157/passports-data-breach-cannabis-club-systems-nefos-puffpal
Via an extensive series of links starting at https://mastodon.social/@Gargron/116828220896988835
#news #technology #TechNews #AgeVerification #security #leak
The doom of cyber security is not about companies get breached by AI.
But, if the one who should be protected (the citizen) no longer own the rights of their own in digital world , and being watched 24 hours 7 days.
In that age, infosec is no longer about "protecting people", but it shifted to "protecting interest".
How to update reverse proxy with zero downtime? A new one in parallel and switch a port on the router.
After I have been postponing the #nginxproxymanager migration to a new/latest version, today I finally did it.
With too many changes along the way I didn't want to risk it. 50 hosts to manually move over, I took the time to clean up some old and unused records.
Running now the latest, single #docker #container setup.
#selfhosting #selfhosted #homelab #security #network #synology
🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇
🚨 They are bringing back #ChatControl 🚨
Metsola doesn't understand that no means no.
Discussion is scheduled for Monday, so act now: https://fightchatcontrol.eu/
Linux Foundation and leading orgs launch Akrites to protect open source from AI threats https://www.gamingonlinux.com/2026/06/linux-foundation-and-leading-orgs-launch-akrites-to-protect-open-source-from-ai-threats/
Securing Verifiable Credentials for a world of agentic AI https://substrate.dougbelshaw.com/securing-verifiable-credentials-ai
#idea #VerifiableCredentials #OpenBadges #DigitalBadges #microcredentials #privacy #security
Great coverage from @lwn of the PSF PyPI Safety & Security Engineer @miketheman's talk on Trusted Publishing at Open Source Summit. 36% of @pypi uploads now use Trusted Publishing. Is yours one of them?
Tick box to prove you're not a bot
Pick all the images of a fire hydrant
Now pick all the images of a motorcycle
Now pick all the images of a bus
Now pick all the images of a motorcycle again
Now pick all the images of traffic lights
Enter your email and password
We've sent you a one-time code
Where I am working has a 3 month password change policy and they send daily reminders 2 weeks before the current one expires.
I always wait until the last day to change my password as changing it early feels wasteful and I want to get the maximum use from each password before discarding it.
I have pointed out to IT that recent recommendations are not to have a periodic password expiry as it encourages poor user security practices but it fell on deaf ears.
The Python Security Response Team patched an authentication bypass in the python.org release management API in under 48 hours. No evidence of exploitation, all artifacts verified.
Check out the full writeup 👇
https://pyfound.blogspot.com/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org.html
Watch PSF PyPI Safety & Security Engineer @miketheman's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos.
strncpy() has been removed from the #Linux kernel. All former callers have +been migrated to safer alternatives. strncpy() is major source of bugs. The replacements are listed now.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3746ccbb0a97bed3c06ccde6b880013b1dddc1
FYI, this is starting from Linux kernel v7.2 but it was the need of the hour.
Think Of The Children: How To Force #RealID For All Internet Traffic (2023)
OR ... How to trick billions into voluntarily self #censorship and Real ID #tracking
Preface: Recently some states and a country have been implementing a centralized commercial database that will be required to upload state ID's and other documents to prove one is an #adult when logging into adult websites. And this is how it starts.
#privacy #security #ageverification #children #agecheck #identity #verification #verify #thinkofthechildren #surveillance
https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Children/