cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Tom Sellers »
@TomSellers@infosec.exchange

Hey folks, if you run Redis you should be aware of a CVSS 10 vuln, CVE-2025-49844, which is a lua related RCE. Redis have release a patch for this and 3 other CVEs. According to Wiz, this vuln has existed for 13 years. That means forks such as Valkey may also be impacted. Valkey has also released updates to address the same CVEs.

Redis: runzero.com/blog/redis/

Valkey: runzero.com/blog/valkey/

-2025-49844

    [?]ティージェーグレェ »
    @teajaygrey@snac.bsd.cafe

    I submitted a Pull Request to update MacPorts' OpenSSH to 10.1p1 here:

    https://github.com/macports/macports-ports/pull/28592

    GitHub Continuous Integration checks passed OK!

    Alas, the agent.patch that iamGavinJ had created, doesn't apply cleanly, in large part because ssh-agent.c has been reworked significantly with this release.

    Subsequently, I closed this previous Pull Request: https://github.com/macports/macports-ports/pull/28592 not because I didn't want to restore that functionality to launchd, but because it will require more effort than I can give such things at this time.

    But, check out these improvements to ssh-agent from the OpenSSH 10.1 release notes:

    "ssh-agent(1)](https://man.openbsd.org/ssh-agent.1), sshd(8): move agent listener sockets from /tmp to
    under ~/.ssh/agent for both ssh-agent(1) and forwarded sockets
    in sshd(8).

    This ensures processes that have restricted filesystem access
    that includes /tmp do not ambiently have the ability to use keys
    in an agent.

    Moving the default directory has the consequence that the OS will
    no longer clean up stale agent sockets, so ssh-agent now gains
    this ability.

    To support $HOME on NFS, the socket path includes a truncated
    hash of the hostname. ssh-agent will, by default, only clean up
    sockets from the same hostname.

    ssh-agent(1) gains some new flags: -U suppresses the automatic
    cleanup of stale sockets when it starts. -u forces a cleanup
    without keeping a running agent, -uu forces a cleanup that ignores
    the hostname. -T makes ssh-agent put the socket back in /tmp."

    Anyway, I updated this as well:

    https://trac.macports.org/ticket/72482

    I should probably actually close this ticket now that I think of it (fingers crossed that adding that to the PR is sufficient, since I forgot to add that note to the commit message as is typically preferred: https://trac.macports.org/ticket/73084).


      [?]gyptazy »
      @gyptazy@gyptazy.com

      Automated Security Patch Management for clusters? The next major feature of comes with automated node patching on Proxmox clusters! This becomes real with the upcoming version 1.2.0!


      ProxLB with upcoming new major features for Proxmox based clusters

      Alt...ProxLB with upcoming new major features for Proxmox based clusters

        [?]נאריש זשלאָב מענטש »
        @dukepaaron@babka.social

        "The violence has put local community members in the area on edge just days before the anniversary of the -led attacks on , which triggered the ongoing war in .

        “I’m always aware, wherever I am, thinking about my ,” Michele Bat-Or told KOMO News.

        A reported rise in globally after Oct. 7, 2023, has left local Jewish people, like Bat-Or, feeling at risk.

        “I usually wear a necklace, and I changed to a different symbol,” she continued, “That feels a little bit too unsafe to wear a Jewish star around my neck.”

        komonews.com/news/local/seattl

          [?]Peter N. M. Hansteen »
          @pitrh@mastodon.social

          Chewie boosted

          [?]knoppix »
          @knoppix95@mastodon.social

          🇬🇧 UK govt demands access to British Apple users' data, reigniting its privacy dispute with Apple 🔐

          Apple pulled Advanced Data Protection from UK iCloud, calling the move "gravely disappointing" ⚠️

          Critics warn secret orders threaten global security 🕵️

          🧑‍⚖️ Legal hearing set for Jan 2026

          🔗 bbc.com/news/articles/c740r0m4

            Wen boosted

            [?]Reoneas »
            @Reoneas@social.tchncs.de

            🗳

            [?]GeneralX ⏳ »
            @generalx@freeradical.zone

            Tor Browser: how much do you use it?

            Never:5
            Occasionally:2
            Often:3
            Tor Browser is my default browser:1
              Rocketman boosted

              [?]Thomas Fricke (he/his) »
              @thomasfricke@23.social

              The lethal trifecta for s: private data, untrusted content, and external communication
              simonwillison.net/2025/Jun/16/

                [?]Wen »
                @Wen@mastodon.scot

                [?]Peter N. M. Hansteen »
                @pitrh@mastodon.social

                [?]Michel Lind :fedora: :debian: »
                @michelin@hachyderm.io

                Recording is out for our @centos Proposed Updates SIG talk at @allsystemsgo !

                Tune in here if you couldn't make it in person

                youtu.be/r8FWdGweVrc?si=5XdIRM

                cfp.all-systems-go.io/all-syst

                TL;DR we maintain a new repo for updates intended for upstreaming to CentOS Stream, so if you deploy CentOS Stream in production you can get access to updates earlier without diverging from Stream long term.

                  Gina boosted

                  [?]knoppix »
                  @knoppix95@mastodon.social

                  🇦🇹 Austria's Armed Forces have replaced MS Office with LibreOffice on 16,000+ workstations 📄

                  This shift began in 2020 to avoid mandatory cloud reliance ☁️
                  Their goal? Digital sovereignty—not cost saving 🔒
                  They even contributed 5+ person-years of code 🛠️
                  EU trend toward open-source grows 🇪🇺

                  @libreoffice
                  @itsfoss

                  🔗 news.itsfoss.com/austrian-forc

                    Adrianna Tan boosted

                    [?]Spoooky Kagan MacTane (he/him) »
                    @kagan@wandering.shop

                    In retrospect, I'm frankly surprised it took so long for someone to name a worm "Shai-Hulud". I should have been waiting for it for years; it seems so obvious in hindsight.

                      mle✨ boosted

                      [?]mle✨ »
                      @mle@infosec.exchange

                      I recently found some cryptocurrency phishing pages–there's nothing really unusual about that, those are pretty common.

                      But I stumbled on these because of their weird robots.txt files, which caused me to briefly question everything I know about the 30-year-old web standard that is robots.txt. Why? Well, specifically these lines in the files:

                      Disallow: /add_web_phish.php
                      Disallow: /en-us/report
                      Disallow: /report
                      Disallow: /phish.report

                      "add_web_phish.php" is the PhishTank reporting URL. The other endpoints are also phish site reporting endpoints of Netcraft, ESET, etc.

                      ...this isn't how robots.txt works. Like, at all. And that's not the only thing that points to the relative inexperience of the actor behind these pages.

                      Read more:

                      censys.com/blog/disallow-secur

                      Dark mode screenshot of GitHub search results for the strange robots.txt file

                      Alt...Dark mode screenshot of GitHub search results for the strange robots.txt file

                        [?]Tommaso Gagliardoni »
                        @tomgag@infosec.exchange

                        We have to stop the Google/Apple mobile duopoly. And we have to stop the marching enshittification of society. More concretely, we have to fight back against Google's attempt to lock-down the whole Android ecosystem.

                        f-droid.org/2025/09/29/google-

                        This is something that any sane regulatory body should forbid.

                          [?]Neil Craig »
                          @tdp_org@mastodon.social

                          > 'You'll never need to work again': Criminals offer reporter money to hack BBC

                          bbc.co.uk/news/articles/c3w5n9

                            [?]Michel Lind :fedora: :debian: »
                            @michelin@hachyderm.io

                            Super early morning flight for ! For my last international of the year (before I try to not complicate my international move situation by having too much travel) I will be co-presenting, with Davide Cavalca, the @centos and how we use it to handle critical issues (including ) and how you can do it too!




                              [?]KB »
                              @decembr14@mastodon.scot

                              1.6 million and climbing.

                              Not that any government ever takes any notice of any of these petitions, but signing it at least makes me feel like I'm trying something. Letter to (unfortunately rigidly loyal Labour) MP next...

                              theguardian.com/politics/2025/

                                [?]Peter N. M. Hansteen »
                                @pitrh@mastodon.social

                                [?]Compassionate Crab »
                                @Compassionatecrab@mstdn.social

                                home security cameras are emailing us that we need to install an update or they'll stop working.
                                I have not researched this update, but somehow I know is at hand. We started with before they were bought by Amazon.

                                Any advice from the pros?
                                Maybe we need a new system?

                                  [?]boredsquirrel »
                                  @Rhababerbarbar@tux.social

                                  @celenity

                                  Amazing! Already donated a large-for-me sum to this amazing effort! Thanks for taking up 's legacy and improving it so much further than that!

                                  celenity.dev/donate

                                    s1m0n4 boosted

                                    [?]Martijn :europe: »
                                    @martijnk@mastodon.green

                                    Travelling with Eurostar across the Channel today, as I’ve done many times before. However, it was the first time there was an extra check in between the Belgian passport control and the automated gates: a British official quickly leafing through all the visa pages of my passport!
                                    What is that all about?

                                      [?]Martin Boller :debian: :tux: :freebsd: :windows: :mastodon: »
                                      @itisiboller@infosec.exchange

                                      Need to reshare this as this is happening with EU NIS2 before our eyes right now.

                                      Tommy Lee Jones looking very Tommy Lee Jonesy. Text:

COMPLIANCE

AN EXERCISE IN POINTLESSNESS FOR PEOPLE WHO DON'T WANT TO DO REALSECURITY™

                                      Alt...Tommy Lee Jones looking very Tommy Lee Jonesy. Text: COMPLIANCE AN EXERCISE IN POINTLESSNESS FOR PEOPLE WHO DON'T WANT TO DO REALSECURITY™

                                        [?]chfkch :nixos: :rust: »
                                        @chfkch@ruhr.social

                                        @mre
                                        The hero we need, not the hero we deserve.

                                          [?]Matthias Endler »
                                          @mre@mastodon.social

                                          I once mistyped `serde` as `sedre` and thought, "oh boy, that's a simple mistake to make. What if someone registered the crate and put malicious code in it?"

                                          So I registered the crate and made it fail at compile-time with a hint about the typo. (See here: github.com/mre/sedre/blob/main)

                                          Turns out, a few people make the same mistake every week. That little thing has prevented 1.214 incorrect installations so far. 😎

                                          Posting this in light of blog.rust-lang.org/2025/09/24/

                                          Description of the `sedre` crate on crates.io, mentioning that this is a common typo.

                                          Alt...Description of the `sedre` crate on crates.io, mentioning that this is a common typo.

                                          Download chart for the sedre crate on crates.io, showing between 0 and 8 downloads a day.

                                          Alt...Download chart for the sedre crate on crates.io, showing between 0 and 8 downloads a day.

                                            [?]Fedora Project »
                                            @fedora@fosstodon.org

                                            This guide provides a step-by-step walk-through for integrating a uTrust FIDO2 security key (Identiv uTrust) with Fedora 42 to secure:

                                            * LUKS2 full disk encryption (FDE)
                                            * Graphical login (LightDM + Cinnamon)
                                            * Sudo elevation

                                            Learn more: fedoramagazine.org/integrating

                                              [?]Peter N. M. Hansteen »
                                              @pitrh@mastodon.social

                                              Tomorrow 2025-09-25 at 10:30 CEST, the refreshed "Network Management with the OpenBSD Packet Filter Toolset" events.eurobsdcon.org/2025/tal by yours truly, @stucchimax and Tom Smyth will start at .

                                              We will put the updated slides online just before the session starts.

                                                [?]gtbarry »
                                                @gtbarry@mastodon.social

                                                JLR shutdown extended again as ministers meet suppliers

                                                Jaguar Land Rover has been unable to produce cars since a cyberattack at the end of August and its factories will remain suspended until next month at the earliest.

                                                bbc.com/news/articles/c15kpxnn

                                                  [?]Chad McCullough »
                                                  @cmccullough@polymaths.social

                                                  No, thank you, @1password@1password.social.

                                                  Can someone tell me if @bitwarden is pushing AI in their service offerings? If not, it might be time to move back or, maybe better, just get more serious about using @keepassxc@fosstodon.org.

                                                  1Password now available in Comet, the AI-powered browser by Perplexity

                                                  https://blog.1password.com/1password-now-available-in-comet-the-ai-browser-by-perplexity/

                                                  #noai #privacy #security

                                                    [?]Nonilex »
                                                    @Nonilex@masto.ai

                                                    Cache of Devices Capable of Crashing Cell Is Found Near

                                                    The discovered more than 100,000 SIM cards & 300 servers, which could disable towers or be used to conduct .


                                                    nytimes.com/2025/09/23/us/poli

                                                      [?]Nonilex »
                                                      @Nonilex@masto.ai

                                                      One official said the network was capable of sending 30 million text messages per minute, anonymously. The official said the agency had never before seen such an extensive operation.

                                                      There is no specific information that the , now dismantled, posed a threat to the conference itself, officials said, speaking on the condition of anonymity to discuss an ongoing investigation. The agency leads the for the meetings this week.

                                                        [?]Nonilex »
                                                        @Nonilex@masto.ai

                                                        Investigators found the SIM cards & servers in August at several locations within a 35-mile radius of the headquarters. The discovery followed a monthslong investigation into what the agency described as anonymous “telephonic threats” made to 3 high-level officials this spring — one official in the & 2 who work at the ..

                                                        The agency did not provide details about the threats made to the 3 officials.…

                                                          [?]Nonilex »
                                                          @Nonilex@masto.ai

                                                          Investigators have been going through the data on SIM cards that were part of the network, including calls, texts & browser history. Matt McCool, the top agent at the Secret Service’s NY field office, said they expected to find that other senior government officials had also been targeted in the operation.

                                                          The agency shared crime scene photos of servers with antennas & SIM cards. In some cases, the servers holding the SIM cards were on floor-to-ceiling shelves.

                                                          A handout photograph provided by the Secret Service showing racks of dismantled communications devices that were part of an anonymous network in the New York region. Credit Secret Service

                                                          Alt...A handout photograph provided by the Secret Service showing racks of dismantled communications devices that were part of an anonymous network in the New York region. Credit Secret Service

                                                            [?]Nonilex »
                                                            @Nonilex@masto.ai

                                                            Anthony J. Ferrante, the global head of the practice at FTI, an international consulting firm, said the operation appeared to be sophisticated & costly.

                                                            “My instinct is this is ,” said Ferrante, who previously served in top cybersecurity positions at the White House & the FBI.

                                                            In addition to jamming the cellular network, he said, such a large amount of equipment near the could be used for .

                                                              [?]Nonilex »
                                                              @Nonilex@masto.ai

                                                              James A. Lewis, a researcher at the Center for European Policy Analysis in Washington, said that only a handful of countries could pull off such an operation, including , & .

                                                              “This is an ongoing investigation, but there’s absolutely no reason to believe we won’t find more of these devices in other cities,” Mr. McCool [great spy name] said.

                                                                [?]Peter N. M. Hansteen »
                                                                @pitrh@mastodon.social

                                                                [?]Peter N. M. Hansteen »
                                                                @pitrh@mastodon.social

                                                                On Thursday, September 25, 2025, Tom Smyth and I will be giving a "Network Management with the OpenBSD Packet Filter Toolset" tutorial events.eurobsdcon.org/2025/tal at in . Register: 2025.eurobsdcon.org/registrati

                                                                  [?]Fedora Project »
                                                                  @fedora@fosstodon.org

                                                                  complyctl is a powerful command-line utility implementing the principles of “ComplianceAsCode” (CaC) with high scalability and adaptability for security compliance!

                                                                  Learn more: fedoramagazine.org/effortless-

                                                                    [?]Peter N. M. Hansteen »
                                                                    @pitrh@mastodon.social

                                                                    In case you missed it earlier, "EU CRA: It's Later Than You Think, Time to Engineer Up!" nxdomain.no/~peter/eu_cra_its_ (also bsdly.blogspot.com/2025/09/eu-) is a call to up your engineering game in time for the Act to introduce the requirement to do so.

                                                                    Written for an introductory workshop.

                                                                      Back to top - More...