cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
httpd(8) gains support for custom HTTP headers https://www.undeadly.org/cgi?action=article;sid=20260725103657 #openbsd #httpd #customheaders #securityheaders #webserver #security #libresoftware #freesoftware
Google now support account recovery with AI and your face. What could possibly go wrong? Google having my face is not just bad enough but chances are high that selfie video may not work in edge cases or network down etc.
https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Also found:
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
PyPI now rejects new files after 14 days
https://lwn.net/Articles/1084218/ #LWN #Linux #security #Python
A Device Hidden in #Cars Across the US Leaves Them #Vulnerable to #Hacking and Paralysis. Patch It Now
#Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
#privacy #security
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special.
That is, until I noticed what machine was listed. Introduced late 2015/early 2016
I have never purchased whatever support. Both Supermicro and Dell work this way.
HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you
In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer.
However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash
#Rant #Security #Vulnerabilities #Hardware #Servers #HPE #SysOp #Homelab
OpenBSD relayd(8) adds ECDSA support with CA engine code from smtpd(8) https://undeadly.org/cgi?action=article;sid=20260721124747 #openbsd #relayd #ecdsa #cryptography #security #https #loadbalancing #webserver #networking #develppment #freesoftware #libresoftware
When building a multi-factor authentication system for clients, backups codes should be generated just in case the user does not have their second factor with them.
The backup codes should all be one-time use of course, but how do you store them on the backend? What is best practice here? What is a real-world threat model?
#passwords #security #cybersecurity
| Store plaintext to be viewed later: | 1 |
| Encrypt with key in TPM to be viewed later: | 3 |
| Hash with a password hashing function (bcrypt): | 17 |
Closed
The best compliment I could’ve ever received! Why don’t you artist types ever describe technology in technical terms? How do I know if you are correct or not! My reply? That’s the whole point! Here’s a little hint! I did that on purpose to make all the tech nerds squirm ! How to make portable Passkeys, Sightless Scribbles https://sightlessscribbles.com/posts/how-to-make-portable-passkeys/ #Passkey #Security #Technology
Looks like nextcloud.com has been hacked (now down).
https://www.reddit.com/r/NextCloud/comments/1v0wxw7/nextcloudcom_cloudbox/
WordPress has an actively abused SQL injection in the core in versions =<7.0.1. You should update to 7.0.2 as soon as humanly possible. Sites are already exploited.
Check whether the site has admin users that you don't recognize
More info: patchstack
Note: it has been a long time since there was a nasty vuln like this in the WP core.
Does your website have a security.txt file to let security researchers know how to responsibly contact you regarding security vulnerabilities on your site?
https://shawnhooper.ca/2026/07/18/rfc-9116-security-txt/ #securityAsking various #AI bots to generate 10 #passwords, then using #Vim syntax highlighting to match different character classes to visually identify patterns.
The prompt is exactly "Generate 10 passwords". I did not elaborate further or otherwise restrict the bot in what to generate.
Aside from the #security risks of servers generating secrets for you, I think it's obvious that these lack quality entropy.
Just use the password generator that ships with your password manager.
GrapheneOS version 2026071500 released:
https://grapheneos.org/releases#2026071500
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/40416-grapheneos-version-2026071500-released
Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog)
https://lwn.net/Articles/1083076/ #LWN #Linux #security #SUSE
g2k26 Hackathon Report: Job Snijders (job@) on rpki-client(8) progress https://www.undeadly.org/cgi?action=article;sid=20260714094547 #openbsd #rpkiclient #pki #bgp #routing #security #hackathon #development #freesoftware #libresoftware
#FacialRecognition in #UK Shops Will Soon Instantly Alert #Police About Offenders
#ai #privacy #surveillance #security #biometrics
For those who have been following the Israeli company’s Pegasus product being used to spy on journalists and politicians around the world, this might amuse. A podcast from Australia’s ABC. I might disagree with some of their conclusions, but it is a very fun listen.
https://www.abc.net.au/listen/programs/if-youre-listening/criminals-if-you-re-listening/106885272
#Podcast #ABC #Australia #Pegasus #Security #Privacy #Palentir
GrapheneOS version 2026071100 released:
https://grapheneos.org/releases#2026071100
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/39301-grapheneos-version-2026071100-released
[$] An update on the scraper situation
Our article "Fighting the AI scraper bot scourge", published in early 2025, discussed the problem of widespread scraping of web sites in search of training data for large language [...]
A few implementations of collecting mouse entropy for secure randomness generation.
https://gist.github.com/atoponce/aab1532438dd047d73567edccc3ecf93
xorg-server 21.1.24 and xwayland 24.1.13 released to fix more security issues https://www.gamingonlinux.com/2026/07/xorg-server-21-1-24-and-xwayland-24-1-13-released-to-fix-more-security-issues/