buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
abucci@bucci.onl
Admin account
@abucci@buc.ci

Search results for tag #security

AodeRelay boosted

[?]Samuel Smith » 🌐
@Jirikiha@raphus.social

Yesterday, I helped my elderly parents with their banking, setting up a joint account.

"Something went wrong"

Tried the online chat.

"Something went wrong"

Apparently, she had an account with the institution a quarter century ago. We had to fix that account before the system would let us create a joint account.

Find the account, update the phone number, reset the password, change the username because the existing one isn't compatible with their current security.

After all that whole rigamarole, THEN we're able to start the process of creating the joint account.
Dad kept putting his phone away.
"Dad, keep your phone out. We're going to need it. A lot."
After, I think five MFA requests, we got it done.

1/2

    AodeRelay boosted

    [?]Schwerdtfegr (beta) » 🌐
    @schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com

    AodeRelay boosted

    [?]Kuketz-Blog 🛡 » 🌐
    @kuketzblog@social.tchncs.de

    Wer 2023 immer noch mit in seinem Unternehmen plant, dem sei gesagt: Der Maschinenraum dieser »Titanic« ist bereits voll Wasser gelaufen. Die Datenschützer & Sicherheitsexperten haben schon unzählige Male oben im Tanzsaal Alarm geschlagen. Aber dort wird noch Champagner getrunken, die Kapelle spielt irgendwas. Die hören nicht, dass das Ganze untergeht. 🌊

    Sinkende Titanic/Schiff

    Alt...Sinkende Titanic/Schiff

      AodeRelay boosted

      [?]Volla » 🌐
      @volla@mastodon.social

      🔐 Introducing: Unified Attestation
      An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

      The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

      We invite developers, ROM projects, and app providers to get involved.

      uattest.net/

        AodeRelay boosted

        [?]Peter N. M. Hansteen » 🌐
        @pitrh@mastodon.social

        AodeRelay boosted

        [?]BobDaHacker 🏳️‍⚧️ » 🌐
        @bobdahacker@infosec.exchange

        🙏 New Blog Post

        The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

        What's exposed:

        • Email addresses
        • Names
        • Country
        • Date of birth (they call it "borned_date" lol)
        • Account role (it's "PRAYER" for everyone, obviously)

        Also found:

        • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
        • Their verification emails fail their own domain's authentication requirements

        Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

        Full writeup: bobdahacker.com/blog/click-to-

          AodeRelay boosted

          [?]gadgetChecks.de » 🤖 🌐
          @gadgetchecks@burningboard.net

          AodeRelay boosted

          [?]Christian M. Grube 🐧 » 🌐
          @Seraphyn@social.tchncs.de

          entschuldigt sich für zwei kürzliche Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Betont wird, dass keine Sicherheitskompromittierung vorlag – die betroffenen blieben stets vertrauenswürdig. Die Probleme entstanden stattdessen durch technische Diskrepanzen zwischen den Zertifizierungsrichtlinien (CP/CPS) und der praktischen Umsetzung.

          Nun, ACME hat nicht richtig funktioniert, die Webseite hat nicht richtig funktioniert und ich musste Nachts die Server , als bei Harica nichts mehr ausgelastet war, die Zertifikate erneuern lassen.

          Das war keine schöne Woche insgesamt

          Habe mal die englische Mail auf Deutsch zusammenfassen lassen

          Der Benutzer möchte eine Zusammenfassung einer E-Mail von HARICA auf Deutsch. Die E-Mail ist auf Englisch und behandelt zwei Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Ich muss die wichtigsten Punkte extrahieren und in einer verständlichen deutschen Zusammenfassung präsentieren.

Die E-Mail hat folgende Hauptabschnitte:
1. Einleitung mit Entschuldigung und Klarstellung, dass die Zertifikate sicher waren
2. Aktueller Status des Zertifikats-Ersetzungsprozesses mit verschiedenen Kategorien (ACME ARI, Non-ACME, etc.)
3. Herausforderungen während der Massen-Ersetzung
4. Sofortige Maßnahmen zur Stabilisierung
5. Geplante Infrastrukturverbesserungen
6. Root Cause Analysis (RCA) mit Verweis auf Bugzilla-Tracker

Ich strukturiere die Zusammenfassung logisch und fasse die wichtigsten Zahlen und Fakten zusammen:
- Betroffene Zertifikate: ca. 235.000 insgesamt
- Bereits ersetzte Zertifikate: 71,36% (Stand 23.07.2026, 14:30 CEST)
- Nicht automatisch ersetzbare Zertifikate: ca. 1.500
- Frist für automatische Ersetzung: Freitag, 24.07.2026, 23:59:59 UTC

Ich sollte auch die Ursachen und Lösungen erwähnen:
- Ursache: Technische Diskrepanzen zwischen CP/CPS und Implementierung
- Herausforderungen: Unerwartete Systemlast durch manuelle Ersetzungen, doppelte Ausstellungen
- Sofortmaßnahmen: Zusätzliche Ressourcen, neue Datenbank-Indizes, zusätzliche Server für CertManager
- Geplante Verbesserungen: Rate Limiting, permanente CertManager-Knoten, zusätzliche Datenbank-Knoten, Code-Refactoring

Am Ende sollte ich die Quellen für die RCA erwähnen (Bugzilla-Tracker).

Die Zusammenfassung sollte professionell und präzise sein, aber trotzdem verständlich für einen technischen Administrator.
Zusammenfassung der HARICA-Meldung zum Massen-Ersatz von TLS-Zertifikaten

Hintergrund & Entschuldigung
HARICA entschuldigt sich für zwei kürzliche Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Betont wird, dass keine Sicherheitskompromittierung vorlag – die betroffenen Zertifikate blieben stets vertrauenswürdig. Die Probleme entstanden stattdessen durch technische Diskrepanzen zwischen den Zertifizierungsrichtlinien (CP/CPS) und der praktischen Umsetzung.
Aktueller Status der Zertifikats-Ersetzung (Stand: 23.07.2026, 14:30 CEST)
1. Automatisierte Ersetzung (ACME ARI)

    Alle ACME ARI-Endpunkte wurden aktualisiert.
    Erwarteter Abschluss: Automatische Ersetzung aller betroffenen Zertifikate bis Freitag, 24.07.2026, 23:59:59 UTC.
    Aktuelle Situation:
        ACME-Ausgabe läuft stabil, aber es gab vereinzelt Verzögerungen und Timeouts durch hohe Last auf dem CertManager.
        Infrastruktur wird 24/7 überwacht, um Probleme sofort zu beheben.
        71,36% der betroffenen Domains wurden bereits mit neuen Zertifikaten gesichert (Stand: 23.07.2026).

2. Manuelle Ersetzung (Non-ACME)

    Reusable Validation (gültige Domain- und Identitätsvalidierung):
        ~233.500 Zertifikate erfolgreich ersetzt.
        ~1.500 Zertifikate konnten nicht automatisch ersetzt werden (z. B. wegen CAA-, MPIC- oder anderer technischer Einschränkungen).
        Support-Team arbeitet direkt mit den verantwortlichen Administratoren zusammen, um Lösungen zu finden.
    Expired Validation (abgelaufene Validierung):
        Betroffene Administratoren wurden kontaktiert und müssen neue Zertifikatsanträge einreichen.

Herausforderungen während der Massen-Ersetzung

    Unerwartete Systemlast:
        Viele Nutzer haben manuell Zertifikate ersetzt, obwohl HARICA eine automatische Ersetzung angekündigt hatte.
        Dies führte zu konkurrierenden ACME-Client-Updates und überlastete die Systeme.
    Doppelte Zertifikatsausstellungen:
        Einige Nutzer haben automatisierte API-Aufrufe gestartet, während HARICA parallel die Massen-Ersetzung durchführte.
        Ergebnis: Doppelte Zertifikate (manuell + automatisch).

Sofortmaßnahmen zur Stabilisierung

HARICA hat folgende Notfallmaßnahmen ergriffen:
✅ Zusätzliche Compute-Ressourcen für CA-, RA- und Datenbank-Server bereitgestellt.
✅ Neue Datenbank-Indizes eingeführt, um Abfragen zu beschleunigen.
✅ Ein zusätzlicher CertManager-Knoten wurde deployt, um Verfügbarkeit und Durchsatz zu erhöhen.
✅ Throttling-Schwellenwerte angepasst, um E-Mail- und Serververbindungen besser zu verteilen.
Geplante Infrastrukturverbesserungen

Langfristig sollen folgende Optimierungen umgesetzt werden:
🔹 Rate Limiting für REST-APIs, um zukünftige Ressourcen-Engpässe zu vermeiden.
🔹 Permanente CertManager-Knoten im RA-Cluster.
🔹 Zusätzliche Datenbank-Knoten für höhere Resilienz.
🔹 Code-Refactoring, um Datenbankabfragen effizienter zu gestalten.
Root Cause Analysis (RCA)

Die Ursachenanalyse läuft noch. Die detaillierten Berichte werden in den folgenden Bugzilla-Trackern veröffentlicht:

    Mozilla Bugzilla #2055551
    Mozilla Bugzilla #2056668

Fazit & Ausblick

    HARICA betont die Bedeutung des GÉANT-Projekts und der TCS-Community.
    Die Massen-Ersetzung läuft größtenteils automatisch, aber einige Fälle erfordern manuelle Nacharbeit.
    Systemische Schwächen werden behoben, um zukünftige Vorfälle zu verhindern.
    Weitere Verbesserungen sind für die kommenden Monate geplant.

Handlungsempfehlung für unser Team:

    ACME-Clients prüfen, ob sie ARI (Automatic Replacement Indicator) unterstützen.
    Manuelle Zertifikats-Ersetzungen vermeiden, bis der automatische Prozess abgeschlossen ist.
    CAA- und MPIC-Prüfungen für kritische Zertifikate durchführen, falls eine manuelle Ersetzung nötig ist.
    Monitoring verstärken, um mögliche Verzögerungen früh zu erkennen.

Falls Fragen oder Probleme auftreten, kann das HARICA-Support-Team direkt kontaktiert werden.

          Alt...Der Benutzer möchte eine Zusammenfassung einer E-Mail von HARICA auf Deutsch. Die E-Mail ist auf Englisch und behandelt zwei Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Ich muss die wichtigsten Punkte extrahieren und in einer verständlichen deutschen Zusammenfassung präsentieren. Die E-Mail hat folgende Hauptabschnitte: 1. Einleitung mit Entschuldigung und Klarstellung, dass die Zertifikate sicher waren 2. Aktueller Status des Zertifikats-Ersetzungsprozesses mit verschiedenen Kategorien (ACME ARI, Non-ACME, etc.) 3. Herausforderungen während der Massen-Ersetzung 4. Sofortige Maßnahmen zur Stabilisierung 5. Geplante Infrastrukturverbesserungen 6. Root Cause Analysis (RCA) mit Verweis auf Bugzilla-Tracker Ich strukturiere die Zusammenfassung logisch und fasse die wichtigsten Zahlen und Fakten zusammen: - Betroffene Zertifikate: ca. 235.000 insgesamt - Bereits ersetzte Zertifikate: 71,36% (Stand 23.07.2026, 14:30 CEST) - Nicht automatisch ersetzbare Zertifikate: ca. 1.500 - Frist für automatische Ersetzung: Freitag, 24.07.2026, 23:59:59 UTC Ich sollte auch die Ursachen und Lösungen erwähnen: - Ursache: Technische Diskrepanzen zwischen CP/CPS und Implementierung - Herausforderungen: Unerwartete Systemlast durch manuelle Ersetzungen, doppelte Ausstellungen - Sofortmaßnahmen: Zusätzliche Ressourcen, neue Datenbank-Indizes, zusätzliche Server für CertManager - Geplante Verbesserungen: Rate Limiting, permanente CertManager-Knoten, zusätzliche Datenbank-Knoten, Code-Refactoring Am Ende sollte ich die Quellen für die RCA erwähnen (Bugzilla-Tracker). Die Zusammenfassung sollte professionell und präzise sein, aber trotzdem verständlich für einen technischen Administrator. Zusammenfassung der HARICA-Meldung zum Massen-Ersatz von TLS-Zertifikaten Hintergrund & Entschuldigung HARICA entschuldigt sich für zwei kürzliche Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Betont wird, dass keine Sicherheitskompromittierung vorlag – die betroffenen Zertifikate blieben stets vertrauenswürdig. Die Probleme entstanden stattdessen durch technische Diskrepanzen zwischen den Zertifizierungsrichtlinien (CP/CPS) und der praktischen Umsetzung. Aktueller Status der Zertifikats-Ersetzung (Stand: 23.07.2026, 14:30 CEST) 1. Automatisierte Ersetzung (ACME ARI) Alle ACME ARI-Endpunkte wurden aktualisiert. Erwarteter Abschluss: Automatische Ersetzung aller betroffenen Zertifikate bis Freitag, 24.07.2026, 23:59:59 UTC. Aktuelle Situation: ACME-Ausgabe läuft stabil, aber es gab vereinzelt Verzögerungen und Timeouts durch hohe Last auf dem CertManager. Infrastruktur wird 24/7 überwacht, um Probleme sofort zu beheben. 71,36% der betroffenen Domains wurden bereits mit neuen Zertifikaten gesichert (Stand: 23.07.2026). 2. Manuelle Ersetzung (Non-ACME) Reusable Validation (gültige Domain- und Identitätsvalidierung): ~233.500 Zertifikate erfolgreich ersetzt. ~1.500 Zertifikate konnten nicht automatisch ersetzt werden (z. B. wegen CAA-, MPIC- oder anderer technischer Einschränkungen). Support-Team arbeitet direkt mit den verantwortlichen Administratoren zusammen, um Lösungen zu finden. Expired Validation (abgelaufene Validierung): Betroffene Administratoren wurden kontaktiert und müssen neue Zertifikatsanträge einreichen. Herausforderungen während der Massen-Ersetzung Unerwartete Systemlast: Viele Nutzer haben manuell Zertifikate ersetzt, obwohl HARICA eine automatische Ersetzung angekündigt hatte. Dies führte zu konkurrierenden ACME-Client-Updates und überlastete die Systeme. Doppelte Zertifikatsausstellungen: Einige Nutzer haben automatisierte API-Aufrufe gestartet, während HARICA parallel die Massen-Ersetzung durchführte. Ergebnis: Doppelte Zertifikate (manuell + automatisch). Sofortmaßnahmen zur Stabilisierung HARICA hat folgende Notfallmaßnahmen ergriffen: ✅ Zusätzliche Compute-Ressourcen für CA-, RA- und Datenbank-Server bereitgestellt. ✅ Neue Datenbank-Indizes eingeführt, um Abfragen zu beschleunigen. ✅ Ein zusätzlicher CertManager-Knoten wurde deployt, um Verfügbarkeit und Durchsatz zu erhöhen. ✅ Throttling-Schwellenwerte angepasst, um E-Mail- und Serververbindungen besser zu verteilen. Geplante Infrastrukturverbesserungen Langfristig sollen folgende Optimierungen umgesetzt werden: 🔹 Rate Limiting für REST-APIs, um zukünftige Ressourcen-Engpässe zu vermeiden. 🔹 Permanente CertManager-Knoten im RA-Cluster. 🔹 Zusätzliche Datenbank-Knoten für höhere Resilienz. 🔹 Code-Refactoring, um Datenbankabfragen effizienter zu gestalten. Root Cause Analysis (RCA) Die Ursachenanalyse läuft noch. Die detaillierten Berichte werden in den folgenden Bugzilla-Trackern veröffentlicht: Mozilla Bugzilla #2055551 Mozilla Bugzilla #2056668 Fazit & Ausblick HARICA betont die Bedeutung des GÉANT-Projekts und der TCS-Community. Die Massen-Ersetzung läuft größtenteils automatisch, aber einige Fälle erfordern manuelle Nacharbeit. Systemische Schwächen werden behoben, um zukünftige Vorfälle zu verhindern. Weitere Verbesserungen sind für die kommenden Monate geplant. Handlungsempfehlung für unser Team: ACME-Clients prüfen, ob sie ARI (Automatic Replacement Indicator) unterstützen. Manuelle Zertifikats-Ersetzungen vermeiden, bis der automatische Prozess abgeschlossen ist. CAA- und MPIC-Prüfungen für kritische Zertifikate durchführen, falls eine manuelle Ersetzung nötig ist. Monitoring verstärken, um mögliche Verzögerungen früh zu erkennen. Falls Fragen oder Probleme auftreten, kann das HARICA-Support-Team direkt kontaktiert werden.

            AodeRelay boosted

            [?]Mysk🇨🇦🇩🇪 » 🌐
            @mysk@mastodon.social

            🚨 We're disclosing a macOS security bug that Apple says is not an issue.
            Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
            Here's a demo using Signal to steal its encryption key.
            📝 Blog with technical details: link in the replies.
            Do you think this should be considered a security bug?
            🎬👇

            youtu.be/0bOC8S3NQxI

              AodeRelay boosted

              [?]selfhost.directory » 🤖 🌐
              @selfhost_discovery@mastodon.social

              📢 New · 23 Jul #10

              · Wekan v10.30 — **Improved database indexing for better performance**
              · solidtime v0.17.0 — Critical security fixes and email wording improvements
              · lightdash 0.3465.1 — Fixed project context compatibility issue

              Check out more on selfhost.directory

                AodeRelay boosted

                [?]heise Security » 🌐
                @heisec@social.heise.de

                Rechteausweitungslücke in Ubuntu durch snap

                Standardinstallationen von Ubuntu sind für eine Schwachstelle anfällig, die die Rechteausweitung zu root ermöglicht. Auslöser ist snap.

                heise.de/news/Rechteausweitung

                AodeRelay boosted

                [?]XenoPhage :verified: » 🌐
                @XenoPhage@infosec.exchange

                AodeRelay boosted

                [?]Sonar Research » 🌐
                @SonarResearch@infosec.exchange

                Can folder names be user input?

                If you interpolate them into a script context, yes! Swift devs often use AppleScript, but it's as dangerous as eval(). Learn about a vulnerability we found in OpenInTerminal:

                sonarsource.com/blog/escape-fr

                  AodeRelay boosted

                  [?]Benjamin Schötz » 🌐
                  @benschoetz@social.tchncs.de

                  Zwei OpenAI-Modelle brachen aus ihrer Testumgebung aus und hackten Hugging Face. Der Grund? Sie wollten bei einem Modell-Benchmark betrügen.

                  Da hierzu in den Medien schon wieder so viel Unfug zum Thema kursiert, habe ich Euch alle bislang bekannten Informationen zusammengefasst und mit reichlich Quellen und Szeneforen-Kommentaren versehen. Ihr findet den Post hier:

                  bedarfsfokus.de/notes/2026-07-

                    AodeRelay boosted

                    [?]Kyle Reddoch (CybersecKyle) » 🌐
                    @cyberseckyle@infosec.exchange

                    AodeRelay boosted

                    [?]PrivacyDigest » 🌐
                    @PrivacyDigest@mas.to

                    US Police Now Armed With Vans Simulating Towers

                    If you thought was bad check out . Falconet from Israeli company serves as a cell tower simulator that intercepts cell phone data from all devices within range. mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional requirements under the .

                    mobile.slashdot.org/story/26/0

                      AodeRelay boosted

                      [?]PrivacyDigest » 🌐
                      @PrivacyDigest@mas.to

                      States Want Agents to Show Their Faces. The Administration Is Blocking Them

                      Federal lawyers say anti-mask laws would endanger agents, citing an ICE face-recognition art project that doesn’t actually work.

                      wired.com/story/states-want-ic

                        AodeRelay boosted

                        [?]the yyc monk » 🌐
                        @theyycmonk@mstdn.ca

                        People with secret ‘safe phones’ advised to turn off devices during national test of AusAlert emergency warning | Australia news | The Guardian
                        theguardian.com/australia-news

                        Of interest to those who have to keep a secret phone for emergencies, in any locale that has an emergency alert system

                          AodeRelay boosted

                          [?]Python Package Index » 🌐
                          @pypi@fosstodon.org

                          The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

                          blog.pypi.org/posts/2026-07-22

                            AodeRelay boosted

                            [?]NLnet Labs » 🌐
                            @nlnetlabs@social.nlnetlabs.nl

                            Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.

                            Many thanks to the security researchers who responsibly reported these issues.

                            Release details: community.nlnetlabs.nl/t/unbou

                              AodeRelay boosted

                              [?]Tom Sellers » 🌐
                              @TomSellers@infosec.exchange

                              Maybe the first test of any new AI model or model configuration without guardrails should be "Can you get out of the box we put you in?"...

                                AodeRelay boosted

                                [?]PrivacyDigest » 🌐
                                @PrivacyDigest@mas.to

                                Models Escaped and

                                The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing a zero-day, and gained access to the open internet to pull off the attack.

                                wired.com/story/openai-models-

                                  AodeRelay boosted

                                  [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                  @nemo@mas.to

                                  A must read

                                  Richard Medhurst says his -secured phone helped protect his data after seized his devices at Heathrow—despite months of password demands. Experts note there’s no “silver bullet” for source safety. 🔒📱 Read: computerweekly.com/feature/Jou

                                  mastodon.social/@smaurizi/1169

                                    [?]AmmarSpaces » 🌐
                                    @AmmarSpaces@infosec.exchange

                                    So, Mullvad made a clarification statement about one of their donator.

                                    I agree with all Mullvad view in this response.

                                    mullvad.net/en/blog/donation-c

                                      [?]Nonilex » 🌐
                                      @Nonilex@masto.ai

                                      The incident signals that 's expanding capabilities are already fueling the threat experts long feared & even top developers can be caught off-guard ​by flaws their models can exploit.

                                      The breakout was "an unprecedented cyber incident, involving state-of-the-art cyber capabilities" & is reinforcing its safeguards, the company said ​in a blog post.

                                        AodeRelay boosted

                                        [?]Nonilex » 🌐
                                        @Nonilex@masto.ai

                                        said Tuesday that an autonomous agent ​powered by its advanced models went rogue during a test & triggered a that compromised the infrastructure of ‌#AI startup last week.

                                        The creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet & broke into Hugging Face to satisfy its testing goal.

                                          AodeRelay boosted

                                          [?]HackMag — Top-notch cybersecurity magazine » 🤖 🌐
                                          @hackmag@infosec.exchange

                                          ⚪️ Dynamic Malware Analysis with Python: Peeking Inside Malicious Code

                                          🗨️ Many types of malware are resistant to debugging: they detect and block popular tools used to monitor the file system, processes, and changes to the Windows registry. To outsmart such malware, we’ll build our own Python-based tool for analyzing malicious code samples.

                                          🔗 hackmag.com/security/malware-a

                                            [?]Dawid Wiktor » 🌐
                                            @dawid@vebinet.com

                                            Europe's unique strengths are in encryption and security. If we look at companies and organizations like Proton, Wire and Threema, we can see that the European innovation is about privacy, data security and trust.

                                            Europe has strong potential to become global superpower regarding these areas. Made in Europe means made with privacy-by-design and security-by-design principles.

                                            Europe can offer the world the most secure, trusted and privacy-oriented solutions. What it needs to do is to embrace this path and recognize its own strengths.

                                              AodeRelay boosted

                                              [?]BrianKrebs » 🌐
                                              @briankrebs@infosec.exchange

                                              New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps

                                              The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

                                              krebsonsecurity.com/2026/07/lg

                                              A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. The image features a picture of Pac-Man celebrating, and some ghosts on the right. It says: Play Pac-Man without ads! For an ad free experience, please allow web indexing by Bright Data to use your device's free resources and IP address to download web data from the Internet. None of your personal information is collected, except your IP address. Bright Data does not track you. Bright Data may continue running in the background even after you close the app. Scan the QR code to learn more about Bright Data policy and ethical usage. Image: Spur.us.

                                              Alt...A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. The image features a picture of Pac-Man celebrating, and some ghosts on the right. It says: Play Pac-Man without ads! For an ad free experience, please allow web indexing by Bright Data to use your device's free resources and IP address to download web data from the Internet. None of your personal information is collected, except your IP address. Bright Data does not track you. Bright Data may continue running in the background even after you close the app. Scan the QR code to learn more about Bright Data policy and ethical usage. Image: Spur.us.

                                                AodeRelay boosted

                                                [?]h3artbl33d :openbsd: :antifa: » 🌐
                                                @h3artbl33d@exquisite.social

                                                Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special.

                                                That is, until I noticed what machine was listed. Introduced late 2015/early 2016 :flan_awe:

                                                I have never purchased whatever support. Both Supermicro and Dell work this way.

                                                HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you.

                                                In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer.

                                                However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash.

                                                  [?]Jan Vlug » 🌐
                                                  @janvlug@mastodon.social

                                                  Nice and informative blog about the new laptop by @purism:

                                                  puri.sm/posts/an-exciting-futu

                                                  "#Purism’s biggest strength is also our promise: we’re powered by free and open source software. We publish the source code for all software we build, so you’re never locked out."

                                                  "Because of that, there is no built-in obsolescence."

                                                  "It’s built into how we operate: practical, transparent, and designed to protect your and ..."

                                                    AodeRelay boosted

                                                    [?]Peter N. M. Hansteen » 🌐
                                                    @pitrh@mastodon.social

                                                    AodeRelay boosted

                                                    [?]Yehor 🇺🇦 » 🌐
                                                    @yehor@mastodon.glitchy.social

                                                    I just updated @OpenCloud LTS from production version 4 to production version 7. It was scary, but successful.

                                                    I also found that my Office instance admin endpoint was exposed to the public internet with the default admin and password. It is unbelievably embarrassing.

                                                      AodeRelay boosted

                                                      [?]Kuketz-Blog 🛡 » 🌐
                                                      @kuketzblog@social.tchncs.de

                                                      Verdacht auf Android-Spyware? Diese 10-Punkte-Checkliste zeigt Schritte zum Prüfen, Entfernen und Absichern von Konten – ohne Panik, aber systematisch. 👇

                                                      kuketz-blog.de/android-spyware

                                                        AodeRelay boosted

                                                        [?]Robert Kingett » 🌐
                                                        @WeirdWriter@caneandable.social

                                                        ... [SENSITIVE CONTENT]

                                                        The best compliment I could’ve ever received! Why don’t you artist types ever describe technology in technical terms? How do I know if you are correct or not! My reply? That’s the whole point! Here’s a little hint! I did that on purpose to make all the tech nerds squirm ! How to make portable Passkeys, Sightless Scribbles sightlessscribbles.com/posts/h

                                                          AodeRelay boosted

                                                          [?]Uncle Joe » 🌐
                                                          @sydseter.com@bsky.brid.gy

                                                          OWASP Cornucopia just released v3.3.1

                                                          github.com/OWASP/cornuc...

                                                          A Special thanks to Mayur Agnihotri for adding AISVS v1 “High-Impact Action Approval and Irreversibility Controls” and to Adarsh Kumar for continuing pushing out bug fixes. You both rock!

                                                          Release Release v3.3.1 · OWASP...

                                                            [?]ARGVMI~1.PIF » 🌐
                                                            @argv_minus_one@mastodon.sdf.org

                                                            If hackers are now giving Code unfettered access to do as it pleases on their development computers, what exactly is stopping from performing a supply-chain attack on the entire ecosystem?

                                                            Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?

                                                              AodeRelay boosted

                                                              [?]Thomas Fricke (he/his) » 🌐
                                                              @thomasfricke@23.social

                                                              "This is U.S.-government approved."

                                                              "There’s this report called the CCSRGSSP."

                                                              "China’s potential in to DOD systems … appears to be Microsoft employees based in China, operating under oversight of undertrained U.S.-based supervisors."

                                                              "I think Microsoft and the Chinese government are in collaboration on this. I think that, uh, something nefarious is, is afoot."

                                                              propublica.org/podcast/microso

                                                                AodeRelay boosted

                                                                [?]𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ » 🌐
                                                                @kubikpixel@chaos.social

                                                                «Decentralized P2P Chat & File Transfer - Secure Messaging Without Central Servers:
                                                                Creating decentralized P2P technology. Aiming to provide industry-grade cryptographic capabilities encapsulated into a webapp.»

                                                                Do any of you regularly use @xoron with several people at the same time or even professionally and what is your impression about it?

                                                                🐟 positive-intentions.com

                                                                  AodeRelay boosted

                                                                  [?]HackMag — Top-notch cybersecurity magazine » 🤖 🌐
                                                                  @hackmag@infosec.exchange

                                                                  ⚪️ Editing Signed PDF Files Without Breaking Their Digital Signatures

                                                                  🗨️ A digital signature is supposed to guarantee the authenticity and integrity of a document’s contents. You’ll see it on certificates from government service portals and tax accounts, as well as on contracts and invoices. If a document is altered, the user should be shown a warning. However, there …

                                                                  🔗 hackmag.com/security/pdf-crypt

                                                                    AodeRelay boosted

                                                                    [?]Graham Perrin » 🌐
                                                                    @grahamperrin@mastodon.bsd.cafe

                                                                    @argv_minus_one

                                                                    I prefer WiFi Networks Manager, <freshports.org/net-mgmt/wifimg>.

                                                                    I used it with sudo, however that's not a direct dependency.

                                                                      3 ★ 0 ↺

                                                                      [?]Anthony » 🌐
                                                                      @abucci@buc.ci

                                                                      Re: https://mastodon.social/ap/users/115587243049342870/statuses/116934718425134083

                                                                      I believe at this stage CloudFlare provides security in a way analogous to how a protection racket provides security.


                                                                        AodeRelay boosted

                                                                        [?]GrapheneOS » 🌐
                                                                        @GrapheneOS@grapheneos.social

                                                                        GrapheneOS version 2026071500 released:

                                                                        grapheneos.org/releases#202607

                                                                        See the linked release notes for a summary of the improvements over the previous release.

                                                                        Forum discussion thread:

                                                                        discuss.grapheneos.org/d/40416

                                                                          AodeRelay boosted

                                                                          [?]Graham Perrin » 🌐
                                                                          @grahamperrin@mastodon.bsd.cafe

                                                                          Innovation Labs by Identity Digital Convenes Infrastructure, Security, and Finance Leaders to Help Shape Accountability Framework for AI Agents

                                                                          globenewswire.com/news-release

                                                                          ― Developing response to growing challenge in AI: establishing persistent ownership and accountability for agents operating across platforms, organizations, and environments

                                                                          ― David Conrad, Charles Ryan, Paul Sagan, Teresa Shea and Corey Thomas among founding members of Advisory Council following the launch of DNSid

                                                                            AodeRelay boosted

                                                                            [?]the yyc monk » 🌐
                                                                            @theyycmonk@mstdn.ca

                                                                            Wire • Secure Messenger
                                                                            f-droid.org/packages/com.wire

                                                                            Amnesty International, world governments including Germany and militaries (including Canada's) and many agencies and large multinational organizations and NGOs that require secure and private communications rely on Wire.

                                                                            The US Air Force uses it too, which means that Wire is what HEGSETH should've used instead when he caused signalgate (no shade on signal for that!).

                                                                            It is free for personal use. It is Swiss, governed by Swiss privacy law. Cross platform, and works great on

                                                                            wire.com/en/compare-wire-vs-al

                                                                            wire.com/en/blog/big-tech-data

                                                                            wire.com/en/transparency-report

                                                                              AodeRelay boosted

                                                                              [?]Tom Sellers » 🌐
                                                                              @TomSellers@infosec.exchange

                                                                              AodeRelay boosted

                                                                              [?]Kraken » 🤖 🌐
                                                                              @analytics@social.vir.group

                                                                              🟢 DefensePolicy | 4/10
                                                                              🇪🇺

                                                                              Europe develops new ballistic missile shield plan
                                                                              Europe is developing a new ballistic missile shield plan in response to the Russia-Ukraine war. The initiative aims to strengthen the continent's defense capabilities.

                                                                                AodeRelay boosted

                                                                                [?]Stefan Bohacek » 🌐
                                                                                @stefan@stefanbohacek.online

                                                                                Something I probably should've done a while ago, but I finally set up two-factor authentication on my Mastodon account.

                                                                                The process was super smooth and it works perfectly. Highly recommend!

                                                                                fedi.tips/using-two-factor-aut

                                                                                  AodeRelay boosted

                                                                                  [?]Steven Saus [he/him] » 🌐
                                                                                  @StevenSaus@faithcollapsing.com

                                                                                  uspol [SENSITIVE CONTENT]

                                                                                  The US government warns that Russia state hackers are coming after your router

                                                                                  With residential proxies all the rage, CISA urges router users to be vigilant.

                                                                                  Archive: ia: s.faithcollapsing.com/8n0jl

                                                                                  -&-it -networks
                                                                                  arstechnica.com/security/2026/

                                                                                  Ethernet cables connected to the ports in a wireless router

                                                                                  Alt...Ethernet cables connected to the ports in a wireless router

                                                                                    AodeRelay boosted

                                                                                    [?]Peter N. M. Hansteen » 🌐
                                                                                    @pitrh@mastodon.social

                                                                                    AodeRelay boosted

                                                                                    [?]2qx 🔻 » 🌐
                                                                                    @2qx@mastodon.social

                                                                                    Hey Fediverse, I wrote a little book (#noai).

                                                                                    It's got beavers, snow, surf, games, coding, data entry, literary references, masks, vaccines and a race to the airport!

                                                                                    It's total FREE! And I'll even mail anyone a copy on request (see about).

                                                                                    <18k words.

                                                                                    montereyprotocols.org

                                                                                    In paperback: lulu.com/shop/2qx/the-monterey

                                                                                      [?]Myk » 🌐
                                                                                      @notsle@kzoo.to

                                                                                      [?]Myk » 🌐
                                                                                      @notsle@kzoo.to


                                                                                      some good details on how Microsoft was abot to track a user despite them using VPN and covering their tracks.
                                                                                      im not supporting the criminal or saying they were right.

                                                                                      but if your OS tracks every action you take. every network connection you make then privacy is a myth.

                                                                                      Use Linux, its really accessible for beginners now.
                                                                                      reject corporate spying. and take control of your privacy.


                                                                                      windowslatest.com/2026/07/10/y

                                                                                        AodeRelay boosted

                                                                                        [?]Lioh » 🌐
                                                                                        @Lioh@social.anoxinon.de

                                                                                        Digitale Selbstverteidigung muss nicht kompliziert sein. In der Privacy Guide erkläre ich dir, wie du mit wenig Aufwand dein Online Leben deutlich spurenarmer gestalten kannst:

                                                                                        gnulinux.ch/privacy-guide

                                                                                        fediserve.de/preview.php?v=vim

                                                                                          AodeRelay boosted

                                                                                          [?]PrivacyDigest » 🌐
                                                                                          @PrivacyDigest@mas.to

                                                                                          AodeRelay boosted

                                                                                          [?]Lioh » 🌐
                                                                                          @Lioh@social.anoxinon.de

                                                                                          Zum Wochenstart gibt es für euch druckfrisch den grossen Privacy Guide für eure Privatsphäre: gnulinux.ch/privacy-guide

                                                                                            AodeRelay boosted

                                                                                            [?]GNU/Linux.ch » 🌐
                                                                                            @gnulinux@social.anoxinon.de

                                                                                            Privacy Guide

                                                                                            Anleitung zur Wahrung der Privatsphäre im Internet.

                                                                                            gnulinux.ch/privacy-guide

                                                                                            AodeRelay boosted

                                                                                            [?]Amy C. T. Serrat 🐙 » 🌐
                                                                                            @Amy_C_T_Serrat@universeodon.com

                                                                                            Are you old enough to remember THE DOT COM BUBBLE?

                                                                                            Follow the money, the patents, the majority shareholders ... who is selling who a BILL OF GOODS?

                                                                                            cnb.cx/4wDQZPU

                                                                                            -fund

                                                                                            https://cnb.cx/4wDQZPU

Are you old enough to remember THE DOT COM BUBBLE?

Follow the money, the patents, the majority shareholders ... who is selling who a BILL OF GOODS?

https://cnb.cx/4wDQZPU

#economics #ai #security #welfare #sovereign-fund #errtling #bookcafe #gov #law #finance #society

                                                                                            Alt...https://cnb.cx/4wDQZPU Are you old enough to remember THE DOT COM BUBBLE? Follow the money, the patents, the majority shareholders ... who is selling who a BILL OF GOODS? https://cnb.cx/4wDQZPU #economics #ai #security #welfare #sovereign-fund #errtling #bookcafe #gov #law #finance #society

                                                                                              AodeRelay boosted

                                                                                              [?]Regendans » 🌐
                                                                                              @regendans@todon.eu

                                                                                              "Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint"

                                                                                              windowslatest.com/2026/07/10/y

                                                                                                AodeRelay boosted

                                                                                                [?]GrapheneOS » 🌐
                                                                                                @GrapheneOS@grapheneos.social

                                                                                                GrapheneOS version 2026071100 released:

                                                                                                grapheneos.org/releases#202607

                                                                                                See the linked release notes for a summary of the improvements over the previous release.

                                                                                                Forum discussion thread:

                                                                                                discuss.grapheneos.org/d/39301

                                                                                                  AodeRelay boosted

                                                                                                  [?]Steven Saus [he/him] » 🌐
                                                                                                  @StevenSaus@faithcollapsing.com

                                                                                                  Claude Code Is Steganographically Marking Requests

                                                                                                  I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.

                                                                                                  -engineering
                                                                                                  thereallo.dev/blog/claude-code

                                                                                                  Claude Code Is Steganographically Marking Requests

                                                                                                  Alt...Claude Code Is Steganographically Marking Requests

                                                                                                    AodeRelay boosted

                                                                                                    [?]the yyc monk » 🌐
                                                                                                    @theyycmonk@mstdn.ca

                                                                                                    RE: mastodon.social/@404mediaco/11

                                                                                                    I switched to Proton Mail many years ago when I was still an iOS user. I'm still a Proton subscriber but abandoned iOS for GrapheneOS.

                                                                                                    and matter immeasurably

                                                                                                    AodeRelay boosted

                                                                                                    [?]404 Media » 🌐
                                                                                                    @404mediaco@mastodon.social

                                                                                                    A vulnerability in Apple’s “Hide My Email” tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year.
                                                                                                    404media.co/apple-hide-my-emai

                                                                                                      [?]Nonilex » 🌐
                                                                                                      @Nonilex@masto.ai

                                                                                                      who received included Julian E. Barnes, Eric Lipton, Tyler Pager & Eric Schmitt, who reported on Wednesday that had departed Turkey on the old as a precaution at the urging of the . Thursday, NYT reported that the new Air Force One, a donated Boeing 747-8, lacked some of the advanced security features of the older aircraft, including antimissile capabilities. Both articles cited anonymous sources….

                                                                                                        AodeRelay boosted

                                                                                                        [?]Nonilex » 🌐
                                                                                                        @Nonilex@masto.ai

                                                                                                        The admin issued Friday to several journalists for , after the news outlet reported this week on concerns involving ’s new donated .

                                                                                                        The subpoenas — which seek to force the to testify before a federal grand jury in Manhattan on Wednesday — were an extraordinary escalation in Trump’s efforts to & independent news organizations.


                                                                                                        nytimes.com/2026/07/11/busines

                                                                                                          AodeRelay boosted

                                                                                                          [?]heise online » 🌐
                                                                                                          @heiseonline@social.heise.de

                                                                                                          Schweizer Armee bricht mit Microsoft: „Kommando Cyber“ setzt auf Open Source

                                                                                                          Wegen Cloud-Zwang und geopolitischer Abhängigkeit von den USA migrieren die Cyber-Spezialisten der Schweizer Armee in Rekordzeit zur deutschen Lösung OpenDesk.

                                                                                                          heise.de/news/Schweizer-Armee-

                                                                                                          AodeRelay boosted

                                                                                                          [?]Lioh » 🌐
                                                                                                          @Lioh@social.anoxinon.de

                                                                                                          Möchtest du deinen Linux-Desktop sicherer machen, dann schau dir mal Portmaster von safing.io an. In diesem Video erkläre ich dir genau, wie du die Desktop-Firewall installierst und einrichtest: makertube.net/w/ubNFJRwBQeLCzL

                                                                                                            AodeRelay boosted

                                                                                                            [?]Schwerdtfegr (beta) » 🌐
                                                                                                            @schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com

                                                                                                            AodeRelay boosted

                                                                                                            [?]LinuxNews.de » 🌐
                                                                                                            @linuxnews@social.anoxinon.de

                                                                                                            AodeRelay boosted

                                                                                                            [?]Steven Saus [he/him] » 🌐
                                                                                                            @StevenSaus@faithcollapsing.com

                                                                                                            Hackers can use 9 of the most popular AI tools to assemble massive botnets

                                                                                                            HalluSquatting

                                                                                                            Archive: ia: s.faithcollapsing.com/vbp9e

                                                                                                            -&-it
                                                                                                            arstechnica.com/security/2026/

                                                                                                            An image pulled automatically from the post for decorative purposes only.

                                                                                                            Alt...An image pulled automatically from the post for decorative purposes only.

                                                                                                              AodeRelay boosted

                                                                                                              [?]GrapheneOS » 🌐
                                                                                                              @GrapheneOS@grapheneos.social

                                                                                                              Vanadium version 150.0.7871.114.0 released:

                                                                                                              github.com/GrapheneOS/Vanadium

                                                                                                              See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

                                                                                                              Forum discussion thread:

                                                                                                              discuss.grapheneos.org/d/37990

                                                                                                                AodeRelay boosted

                                                                                                                [?]signifier of eschaton » 🌐
                                                                                                                @lw@mastodon.bsd.cafe

                                                                                                                this KDE security advisory (from 2020) is hilarious: kde.org/info/security/advisory

                                                                                                                Workaround: stop kdeconnectd. but, you can't do that because it's started from dbus, so it's literally impossible to stop. the only solution is to remove the package, but good luck doing that when it's part of your OS's KDE metapackage.

                                                                                                                what is this super important daemon that must be running 100% of the time and cannot be stopped or removed? well, it lets you control your desktop PC from your phone. something which i'm sure at least 0.001% of KDE users have ever done, or ever will do...

                                                                                                                what the fuck are you doing, software developers.

                                                                                                                  AodeRelay boosted

                                                                                                                  [?]GrapheneOS » 🌐
                                                                                                                  @GrapheneOS@grapheneos.social

                                                                                                                  Secure PDF Viewer app version 32 released:

                                                                                                                  github.com/GrapheneOS/PdfViewe

                                                                                                                  See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

                                                                                                                  Forum discussion thread:

                                                                                                                  discuss.grapheneos.org/d/37983

                                                                                                                    AodeRelay boosted

                                                                                                                    [?]Open Security Conference » 🌐
                                                                                                                    @OSCo@infosec.exchange

                                                                                                                    Huge thanks to our silver sponsor from day 1: itRISKman and @jenshoffmann! 🩶 We're immensely grateful for their continued support over the years. They literally keep the Open Security Conference more affordable for everyone interested in cybersecurity.

                                                                                                                    Discover itRISKman: itriskman.de/

                                                                                                                    Learn more about all our sponsors: opensecurityconference.org/sup

                                                                                                                    [lisi]

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]heise Security » 🌐
                                                                                                                      @heisec@social.heise.de

                                                                                                                      Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck

                                                                                                                      Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.

                                                                                                                      heise.de/news/Offene-Datenbank

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]Open Security Conference » 🌐
                                                                                                                        @OSCo@infosec.exchange

                                                                                                                        Big shout-out to REWE digital for their continued silver sponsorship of the Open Security Conference! 🩶 Their support helps people gain access to matters, no matter their own background. We're truly grateful!

                                                                                                                        Discover : rewe-digital.com/

                                                                                                                        Learn more about all our sponsors: opensecurityconference.org/sup

                                                                                                                        [lisi]

                                                                                                                          AodeRelay boosted

                                                                                                                          [?]iX Magazin » 🌐
                                                                                                                          @iX_Magazin@social.heise.de

                                                                                                                          RootAsRole 4.0: Mehr Kontrolle als bei sudo

                                                                                                                          RootAsRole 4.0 erweitert die sudo-Alternative um ein neues Ausführungsmodell und feinere Richtlinien für privilegierte Linux-Befehle.

                                                                                                                          heise.de/news/RootAsRole-4-0-M

                                                                                                                            [?]Script Kiddie » 🌐
                                                                                                                            @scriptkiddie@anonsys.net

                                                                                                                            AodeRelay boosted

                                                                                                                            [?]Peter N. M. Hansteen » 🌐
                                                                                                                            @pitrh@mastodon.social

                                                                                                                            AodeRelay boosted

                                                                                                                            [?]linuxwebzine » 🌐
                                                                                                                            @linuxwebzine@mstdn.ro

                                                                                                                            🛡️📋 Opera prezintă Paste Protect: O nouă funcție de securitate care protejează datele sensibile din clipboard

                                                                                                                            Browserul Opera adaugă un nou strat de securitate pentru utilizatorii săi prin introducerea funcției Paste Protect. Această tehnologie inovatoare este concepută special pentru a combate una dintre cele mai insidioase tactici de hacking: înlocuirea din mers a datelor salvate în clipboard (funcția de Copy-Paste).

                                                                                                                            Scopul principal al Paste Protect este de a proteja informațiile ultra-sensibile, cum ar fi numerele de conturi bancare, adresele de portofele cripto (crypto wallets) sau codurile de identificare personală, împotriva programelor malware de tip „clipper”.

                                                                                                                            Iată cum funcționează această funcție și de ce este esențială pentru navigarea în siguranță:

                                                                                                                            🔹 Combaterea atacurilor de tip „Clipboard Hijacking”:
                                                                                                                            Multe programe malware moderne rulează silențios în fundalul sistemului de operare și monitorizează clipboard-ul. Când detectează că un utilizator a copiat un șir lung de caractere (specific unei adrese Bitcoin sau unui cont IBAN), malware-ul înlocuiește instantaneu acel șir cu adresa atacatorului. Dacă utilizatorul nu verifică manual fiecare caracter înainte de a da Paste, banii ajung direct în contul hackerilor. Paste Protect detectează și blochează aceste modificări neautorizate.

                                                                                                                            🔹 Avertizări inteligente în timp real:
                                                                                                                            Atunci când Opera detectează că o aplicație externă sau un script web suspect încearcă să modifice sau să intercepteze conținutul pe care tocmai l-ai copiat, browserul va afișa o alertă vizuală clară. Acesta va avertiza utilizatorul că textul din clipboard a fost alterat, prevenind finalizarea unor tranzacții frauduloase.

                                                                                                                            🔹 Protecție integrată, fără configurări complexe:
                                                                                                                            Funcția este integrată direct în nucleul browserului și funcționează automat în fundal, fără a necesita instalarea unor extensii terțe sau realizarea unor setări complicate de către utilizator. Aceasta monitorizează interacțiunea dintre browser și clipboard-ul sistemului de operare (fie că vorbim de Linux, Windows sau macOS) pentru a asigura integritatea datelor.

                                                                                                                            🔹 Parte dintr-un ecosistem mai larg de securitate:
                                                                                                                            Introducerea Paste Protect face parte din strategia continuă a celor de la Opera de a transforma browserul într-un mediu sigur pentru tranzacții financiare și Web3. Funcția completează suita existentă de unelte, precum VPN-ul gratuit integrat, blocantul de reclame nativ și protecția împotriva scripturilor de cryptojacking (criptomined).

                                                                                                                            Prin implementarea acestei funcții, Opera face un pas important în fața competitorilor, oferind o soluție directă la o problemă de securitate tot mai frecventă în rândul utilizatorilor care efectuează plăți online sau gestionează active digitale.

                                                                                                                              AodeRelay boosted

                                                                                                                              [?]Alonso Caballero / ReYDeS » 🌐
                                                                                                                              @Alonso_ReYDeS@infosec.exchange

                                                                                                                              🧠 Para vencer a un ciberatacante, debes aprender a pensar exactamente como uno ⚔️ 🥇 9, 14, 16 y 21 de Julio 2026 ☑️ De 7 pm a 10 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 ⏩ Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Etico.pdf #cybersecurity #cybersecurity #security #cybersecurityawareness #dataprotection #cyberthreats #cyberthreats

                                                                                                                                AodeRelay boosted

                                                                                                                                [?]VZ » 🌐
                                                                                                                                @VZ@fosstodon.org

                                                                                                                                To save on posts, here is a single one about the new releases in both stable 3.2 and development branch: wxwidgets.org/news/2026/07/wxw

                                                                                                                                Both have tons of fixes for various buffer overrun, i.e. , problems (mostly, but, unfortunately, not only, in very rarely used parts) that we probably have to thank the advent of for.

                                                                                                                                And 3.3.3 development release also has a lot of improvements to MSW dark mode support, in addition to aesthetically pleasing version number.

                                                                                                                                [?]Paul - Antifa. LGBTQ+ safe. » 🌐
                                                                                                                                @paulk@writing.exchange

                                                                                                                                Call me nuts but I love passwords with quotes ( ' <- this thing), spaces and periods in them.

                                                                                                                                  AodeRelay boosted

                                                                                                                                  [?]Lobsters » 🤖 🌐
                                                                                                                                  @lobsters@mastodon.social

                                                                                                                                  AodeRelay boosted

                                                                                                                                  [?]signifier of eschaton » 🌐
                                                                                                                                  @lw@mastodon.bsd.cafe

                                                                                                                                  RouterOS 7.23.2 release notes:

                                                                                                                                  !) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;

                                                                                                                                  so... we fixed a security vulnerability, but we're not going to tell you what it is, so you have no idea how urgent this update is or how exposed you are or if you're even affected at all.

                                                                                                                                  thanks, i guess?

                                                                                                                                  (rumour has it this is a memory disclosure or potential RCE in pptp/l2tp/ppoe...)

                                                                                                                                    AodeRelay boosted

                                                                                                                                    [?]Network Pro Strategies » 🌐
                                                                                                                                    @networkpro@infosec.exchange

                                                                                                                                    If you live in Europe, you'll want to contact your MEP right away. Chat Control is back...

                                                                                                                                    fightchatcontrol.eu/

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]Peter N. M. Hansteen » 🌐
                                                                                                                                      @pitrh@mastodon.social

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]Frank Paul Silye » 🌐
                                                                                                                                      @frankps@mastodon.babb.no

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]heise Security » 🌐
                                                                                                                                      @heisec@social.heise.de

                                                                                                                                      OPNsense-Update beseitigt kritische Rootlücke und weitere Sicherheitsrisiken

                                                                                                                                      Aktuelle Versionen der Open-Source-Firewall-Distribution schließen mehrere Einfallstore. Eine als kritisch bewertete Lücke macht das Update besonders dringlich.

                                                                                                                                      heise.de/news/OPNsense-Update-

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]heise Security » 🌐
                                                                                                                                      @heisec@social.heise.de

                                                                                                                                      Dell dichtet PowerProtect Data Domain gegen gefährliche Angriffsszenarien ab

                                                                                                                                      Als „kritisch“ stuft Dell ein bereitgestelltes Update-Paket für mehrere Versionen des PowerProtect DD-Betriebssystems ein. Remote-Angriffe sind möglich.

                                                                                                                                      heise.de/news/Dell-dichtet-Pow

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]PrivacyDigest » 🌐
                                                                                                                                      @PrivacyDigest@mas.to

                                                                                                                                      Asked to Impersonate 112 Public Figures. What Happened Next Is a ‘Dire’ Warning

                                                                                                                                      AI that were prompted to public figures produced responses that people perceived to be more authentic, coherent, and relevant than the real thing, a finding that underscores “a dire need to inform the general public of the potential harm this can have on society,” according to a study published on Wednesday in PLOS One.

                                                                                                                                      404media.co/untitled-28/

                                                                                                                                        AodeRelay boosted

                                                                                                                                        [?]Kraken » 🤖 🌐
                                                                                                                                        @analytics@social.vir.group

                                                                                                                                        🟡 Military Mobilization | 6/10
                                                                                                                                        🇮🇶 🇮🇷

                                                                                                                                        30,000 PMF fighters securing funeral of Iran's late Supreme Leader in Najaf and Karbala
                                                                                                                                        Iraq's Popular Mobilization Forces deployed approximately 30,000 fighters to secure funeral ceremonies for Iran's late Supreme Leader in Najaf and Karbala. Command in the Euphrates region confirmed the deployment.

                                                                                                                                          AodeRelay boosted

                                                                                                                                          [?]h3artbl33d :openbsd: :antifa: » 🌐
                                                                                                                                          @h3artbl33d@exquisite.social

                                                                                                                                          Whereas DirtyClone exploits a kernel module (which can be tackled by unloading and blocking it), Bad Epoll does not.

                                                                                                                                          Alt...Elmo reigning fire

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]Graham Perrin » 🌐
                                                                                                                                            @grahamperrin@mastodon.bsd.cafe

                                                                                                                                            Beijing Plane Crash Tests China's Security State – FP

                                                                                                                                            foreignpolicy.com/2026/06/30/c

                                                                                                                                            ― The highlights this week: Fallout from a fatal plane crash in Beijing ripples through the security state, a Chinese billionaire is sentenced to 30 years in U.S. prison, and Chinese artificial intelligence models close the U.S. lead on cybersecurity. …

                                                                                                                                              AodeRelay boosted

                                                                                                                                              [?]Freezenet » 🌐
                                                                                                                                              @freezenet@noc.social

                                                                                                                                              Do you feel a tinge of guilt Googling basic information on something because you aren't sure? Well, if it makes you feel any better, the Secret Service was frantically trying to Google where one of the Trump would-be assassin's were when shots rang out in Pennsylvania.

                                                                                                                                              nypost.com/2026/07/02/us-news/

                                                                                                                                                AodeRelay boosted

                                                                                                                                                [?]Tim (Wadhwa-)Brown :donor: » 🌐
                                                                                                                                                @timb_machine@infosec.exchange

                                                                                                                                                Interesting Git repos of the week:

                                                                                                                                                Strategy:

                                                                                                                                                * github.com/mr-r3b00t/ai_usage_ - AI abuse through an ATT&CK lens with @UK_Daniel_Card 🤖

                                                                                                                                                Detection:

                                                                                                                                                * github.com/citizenlab/bluecoat investigating Blue Coat device breaches with @citizenlab
                                                                                                                                                * github.com/andreicscs/HoneyWire - F/OSS deception

                                                                                                                                                Bugs:

                                                                                                                                                * github.com/sgkdev/ipv6_frag_es - another Linux LPE

                                                                                                                                                Exploitation:

                                                                                                                                                * github.com/x86byte/Obfusk8 - obfuscation library
                                                                                                                                                * github.com/bee-san/RustScan - a port scanner in Rust
                                                                                                                                                * github.com/t0thkr1s/gpp-decrypt - dumping GPP cpassword
                                                                                                                                                * github.com/kernelstub/Nox - attack surface management in Go
                                                                                                                                                * github.com/JVBotelho/skewrun - abusing time in AD
                                                                                                                                                * github.com/db0109/AI-Red-Team- - tips and tricks for red teaming AI 🤖
                                                                                                                                                * github.com/jonaslykkegaard9-op - remapping Windows memory

                                                                                                                                                Hard hacks:

                                                                                                                                                * github.com/pinkflawd/MIPSRever - @pinkflawd's MIPS training

                                                                                                                                                Nerd:

                                                                                                                                                * github.com/ripienaar/free-for- - free hosting for developers 🤖
                                                                                                                                                * github.com/dockur/macos - OS X in Docker

                                                                                                                                                , .#research

                                                                                                                                                  AodeRelay boosted

                                                                                                                                                  [?]Karl Voit :emacs: :orgmode: » 🌐
                                                                                                                                                  @publicvoit@graz.social

                                                                                                                                                  RE: infosec.exchange/@mattburgess/

                                                                                                                                                  Please do let that sink in. 🤯

                                                                                                                                                  And still, many European countries do hire their services and give that company our taxpayer money and our personal data.

                                                                                                                                                  We need to bring them to justice, not fund their crimes! 🤬

                                                                                                                                                  en.wikipedia.org/wiki/Pegasus_

                                                                                                                                                    Back to top - More...