buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Yesterday, I helped my elderly parents with their banking, setting up a joint account.
"Something went wrong"
Tried the online chat.
"Something went wrong"
Apparently, she had an account with the institution a quarter century ago. We had to fix that account before the system would let us create a joint account.
Find the account, update the phone number, reset the password, change the username because the existing one isn't compatible with their current security.
After all that whole rigamarole, THEN we're able to start the process of creating the joint account.
Dad kept putting his phone away.
"Dad, keep your phone out. We're going to need it. A lot."
After, I think five MFA requests, we got it done.
#banking #finance #security #rigamarole
1/2
Wer 2023 immer noch mit #Microsoft in seinem Unternehmen plant, dem sei gesagt: Der Maschinenraum dieser »Titanic« ist bereits voll Wasser gelaufen. Die Datenschützer & Sicherheitsexperten haben schon unzählige Male oben im Tanzsaal Alarm geschlagen. Aber dort wird noch Champagner getrunken, die Kapelle spielt irgendwas. Die hören nicht, dass das Ganze untergeht. 🌊
🔐 Introducing: Unified Attestation
An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.
The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.
We invite developers, ROM projects, and app providers to get involved.
#Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle
httpd(8) gains support for custom HTTP headers https://www.undeadly.org/cgi?action=article;sid=20260725103657 #openbsd #httpd #customheaders #securityheaders #webserver #security #libresoftware #freesoftware
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Also found:
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
UGREEN NAS: ZURÜCKSETZEN UND SICHER WEITERGEBEN – TUTORIAL
https://gadgetchecks.de/ugreen-nas-zuruecksetzen-und-sicher-weitergeben-tutorial/
.
.
.
#ugreen #ugreennas #nas #ugospro #zurücksetzen #factoryreset #datenlöschen #datenschutz #verkaufen #weitergabe #homeserver #netzwerkspeicher #backup #it #tutorial #storage #fileserver #homelab #security #datensicherheit
#HARICA entschuldigt sich für zwei kürzliche Vorfälle im Zusammenhang mit der Massen-Ersetzung von TLS-Zertifikaten. Betont wird, dass keine Sicherheitskompromittierung vorlag – die betroffenen #Zertifikate blieben stets vertrauenswürdig. Die Probleme entstanden stattdessen durch technische Diskrepanzen zwischen den Zertifizierungsrichtlinien (CP/CPS) und der praktischen Umsetzung.
Nun, ACME hat nicht richtig funktioniert, die Webseite hat nicht richtig funktioniert und ich musste Nachts die Server #Linux , als bei Harica nichts mehr ausgelastet war, die Zertifikate erneuern lassen.
Das war keine schöne Woche insgesamt
Habe mal die englische Mail auf Deutsch zusammenfassen lassen
🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS
📢 New #updates · 23 Jul #10
· Wekan v10.30 — **Improved database indexing for better performance**
· solidtime v0.17.0 — Critical security fixes and email wording improvements
· lightdash 0.3465.1 — Fixed project context compatibility issue
Check out more on https://selfhost.directory
BSides Delaware 2026 ticket sales are OPEN!!!! Quick! Get your tickets NOW!
https://events.humanitix.com/security-bsides-delaware-2026?c=mastodon
Can folder names be user input?
If you interpolate them into a script context, yes! Swift devs often use AppleScript, but it's as dangerous as eval(). Learn about a vulnerability we found in OpenInTerminal:
Zwei OpenAI-Modelle brachen aus ihrer Testumgebung aus und hackten Hugging Face. Der Grund? Sie wollten bei einem Modell-Benchmark betrügen.
Da hierzu in den Medien schon wieder so viel Unfug zum Thema kursiert, habe ich Euch alle bislang bekannten Informationen zusammengefasst und mit reichlich Quellen und Szeneforen-Kommentaren versehen. Ihr findet den Post hier:
https://bedarfsfokus.de/notes/2026-07-22-chatgpt-openai-ausbruch-sandbox/
Enterprise Edge Security: Cloudflare and Gcore versus legacy defenders https://www.cm-alliance.com/cybersecurity-blog/enterprise-edge-security-cloudflare-and-gcore-versus-legacy-defenders
US Police Now Armed With #Israeli #Spy Vans Simulating #MobilePhone Towers
If you thought #Flock was bad check out #Falconet. Falconet from Israeli company #Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. #Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional #warrant requirements under the #FourthAmendment.
#privacy #security #surveillance
States Want #ICE Agents to Show Their Faces. The #Trump Administration Is Blocking Them
Federal lawyers say anti-mask laws would endanger #immigration agents, citing an ICE face-recognition art project that doesn’t actually work.
#privacy #security
People with secret ‘safe phones’ advised to turn off devices during national test of AusAlert emergency warning | Australia news | The Guardian
https://www.theguardian.com/australia-news/2026/jul/22/people-with-secret-safe-phones-advised-to-turn-off-devices-during-national-test-of-ausalert-emergency-warning
Of interest to those who have to keep a secret phone for emergencies, in any locale that has an emergency alert system
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.
Many thanks to the security researchers who responsibly reported these issues.
Release details: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
#OpenAI Models Escaped #Containment and #Hacked #HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing #sandbox #exploited a zero-day, and gained access to the open internet to pull off the attack.
#cybersecurity #security #0day #zeroday #gpt #privacy #ai #artificialintelligence
https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
A must read #Privacy #Security
Richard Medhurst says his #GrapheneOS-secured phone helped protect his data after #UK #police seized his devices at Heathrow—despite months of password demands. Experts note there’s no “silver bullet” for source safety. 🔒📱 Read: https://www.computerweekly.com/feature/Journalist-Richard-Medhurst-had-his-mobile-phone-seized-Did-using-a-secure-phone-protect-his-dataa #cybersecurity #journalism #infosec
So, Mullvad made a clarification statement about one of their donator.
I agree with all Mullvad view in this response.
The incident signals that #AI's expanding capabilities are already fueling the #security threat experts long feared & even top developers can be caught off-guard by flaws their models can exploit.
The breakout was "an unprecedented cyber incident, involving state-of-the-art cyber capabilities" & #OpenAI is reinforcing its safeguards, the company said in a blog post.
#OpenAI said Tuesday that an autonomous agent powered by its advanced #ArtificialIntelligence models went rogue during a #security test & triggered a #hack that compromised the infrastructure of #AI startup #HuggingFace last week.
The #ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet & broke into Hugging Face to satisfy its testing goal.
⚪️ Dynamic Malware Analysis with Python: Peeking Inside Malicious Code
🗨️ Many types of malware are resistant to debugging: they detect and block popular tools used to monitor the file system, processes, and changes to the Windows registry. To outsmart such malware, we’ll build our own Python-based tool for analyzing malicious code samples.
Europe's unique strengths are in encryption and security. If we look at companies and organizations like Proton, Wire and Threema, we can see that the European innovation is about privacy, data security and trust.
Europe has strong potential to become global superpower regarding these areas. Made in Europe means made with privacy-by-design and security-by-design principles.
Europe can offer the world the most secure, trusted and privacy-oriented solutions. What it needs to do is to embrace this path and recognize its own strengths.
#Europe #Europa #privacy #security #technology #tech #DataSecurity #data #MadeInEurope
New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special.
That is, until I noticed what machine was listed. Introduced late 2015/early 2016
I have never purchased whatever support. Both Supermicro and Dell work this way.
HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you.
In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer.
However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash.
#Rant #Security #Vulnerabilities #Hardware #Servers #HPE #SysOp #Homelab
Nice and informative blog about the new #Librem16 laptop by @purism:
https://puri.sm/posts/an-exciting-future-with-the-librem-16/
"#Purism’s biggest strength is also our promise: we’re powered by free and open source software. We publish the source code for all software we build, so you’re never locked out."
"Because of that, there is no built-in obsolescence."
"It’s built into how we operate: practical, transparent, and designed to protect your #freedom and #privacy..."
OpenBSD relayd(8) adds ECDSA support with CA engine code from smtpd(8) https://undeadly.org/cgi?action=article;sid=20260721124747 #openbsd #relayd #ecdsa #cryptography #security #https #loadbalancing #webserver #networking #develppment #freesoftware #libresoftware
I just updated @OpenCloud LTS from production version 4 to production version 7. It was scary, but successful.
I also found that my #Collabora Office instance admin endpoint was exposed to the public internet with the default admin and password. It is unbelievably embarrassing.
#securityHole #security #OpenCloud #homelab #selfHosted #selfhosting #selfhost
Verdacht auf Android-Spyware? Diese 10-Punkte-Checkliste zeigt Schritte zum Prüfen, Entfernen und Absichern von Konten – ohne Panik, aber systematisch. 👇
https://www.kuketz-blog.de/android-spyware-in-10-schritten-erkennen-und-entfernen/
#android #security #sicherheit #hack #hacking #surveillance #spyware #schadsoftware
The best compliment I could’ve ever received! Why don’t you artist types ever describe technology in technical terms? How do I know if you are correct or not! My reply? That’s the whole point! Here’s a little hint! I did that on purpose to make all the tech nerds squirm ! How to make portable Passkeys, Sightless Scribbles https://sightlessscribbles.com/posts/how-to-make-portable-passkeys/ #Passkey #Security #Technology
If #kernel hackers are now giving #Claude Code unfettered access to do as it pleases on their development computers, what exactly is stopping #Anthropic from performing a supply-chain attack on the entire #Linux ecosystem?
Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?
"This is U.S.-government approved."
"There’s this report called the CCSRGSSP."
"China’s potential in to DOD systems … appears to be Microsoft employees based in China, operating under oversight of undertrained U.S.-based supervisors."
"I think Microsoft and the Chinese government are in collaboration on this. I think that, uh, something nefarious is, is afoot."
https://www.propublica.org/podcast/microsoft-digital-escorts-china-defense-department
#china #microslop #microsoft #security #digitalsovereignty #digitalescort #cloud
«Decentralized P2P Chat & File Transfer - Secure Messaging Without Central Servers:
Creating decentralized P2P technology. Aiming to provide industry-grade cryptographic capabilities encapsulated into a webapp.»
Do any of you regularly use @xoron with several people at the same time or even professionally and what is your impression about it?
🐟 https://positive-intentions.com
#chat #p2p #e2ee #filetransfer #security #decentralization #webtools #webapp #pqc #pqcrypto #cryptography #noserver
⚪️ Editing Signed PDF Files Without Breaking Their Digital Signatures
🗨️ A digital signature is supposed to guarantee the authenticity and integrity of a document’s contents. You’ll see it on certificates from government service portals and tax accounts, as well as on contracts and invoices. If a document is altered, the user should be shown a warning. However, there …
I prefer WiFi Networks Manager, <https://www.freshports.org/net-mgmt/wifimgr/>.
I used it with sudo, however that's not a direct dependency.
I believe at this stage CloudFlare provides security in a way analogous to how a protection racket provides security.
GrapheneOS version 2026071500 released:
https://grapheneos.org/releases#2026071500
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/40416-grapheneos-version-2026071500-released
Innovation Labs by Identity Digital Convenes Infrastructure, Security, and Finance Leaders to Help Shape Accountability Framework for AI Agents
― Developing response to growing challenge in AI: establishing persistent ownership and accountability for agents operating across platforms, organizations, and environments
― David Conrad, Charles Ryan, Paul Sagan, Teresa Shea and Corey Thomas among founding members of Advisory Council following the launch of DNSid
#AI #DNSid #accountability #Internet #infrastructure #agent #security #finance
Wire • Secure Messenger
https://f-droid.org/packages/com.wire
#privacy #foss #security #safety #SurveillanceCapitalism #messaging #DataSovereignty #boycottusa #opensource #swiss #gdpr #activism #activist #AntiFascist #ngo #techbrofascism #techbroligarchy #google #apple #ios #microsoft #meta #boycottmeta #elbowsup
Amnesty International, world governments including Germany and militaries (including Canada's) and many agencies and large multinational organizations and NGOs that require secure and private communications rely on Wire.
The US Air Force uses it too, which means that Wire is what HEGSETH should've used instead when he caused signalgate (no shade on signal for that!).
It is free for personal use. It is Swiss, governed by Swiss privacy law. Cross platform, and works great on #grapheneos
https://wire.com/en/compare-wire-vs-alternatives
RE: https://infosec.exchange/@DailyCyberSecurity/116924251072903286
The 9.8 referenced here for Workspace impacts 7.0.0 and earlier. 7.0.1 was release in April 3, 2026
https://www.zoom.com/en/trust/security-bulletin/
https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061222#mcetoc_1jk3p0297b2
Zoom vulnerability CVE-2026-53412 (CVSS 9.8) allows unauthenticated account takeover over the network. Update Zoom Workplace for Windows to 7.0.0 now.
#Zoom #CVE202653412 #AccountTakeover #Windows #CyberSecurity
🟢 DefensePolicy | 4/10
🇪🇺
Europe develops new ballistic missile shield plan
Europe is developing a new ballistic missile shield plan in response to the Russia-Ukraine war. The initiative aims to strengthen the continent's defense capabilities.
Something I probably should've done a while ago, but I finally set up two-factor authentication on my Mastodon account.
The process was super smooth and it works perfectly. Highly recommend!
https://fedi.tips/using-two-factor-authentication-2fa-on-mastodon/
#mastodon #fediverse #2FA #TwoFactorAuthentication #security #OnlineSecurity
The US government warns that Russia state hackers are coming after your router
With residential proxies all the rage, CISA urges router users to be vigilant.
Archive: ia: https://s.faithcollapsing.com/8n0jl
#biz-&-it #cisa #hackers #proxy-networks #routers #security
https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/
g2k26 Hackathon Report: Job Snijders (job@) on rpki-client(8) progress https://www.undeadly.org/cgi?action=article;sid=20260714094547 #openbsd #rpkiclient #pki #bgp #routing #security #hackathon #development #freesoftware #libresoftware
Hey Fediverse, I wrote a little book (#noai).
It's got beavers, snow, surf, games, coding, data entry, literary references, masks, vaccines and a race to the airport!
It's total FREE! And I'll even mail anyone a copy on request (see about).
<18k words.
In paperback: https://www.lulu.com/shop/2qx/the-monterey-protocols/paperback/product-84dydww.html
#vermont #elbowsup #maskup #vaccines #smallpox #nonproliferation #books #publichealth #nurses #healthworkers #opsec #security
#security #privacy #windows #microsoft
some good details on how Microsoft was abot to track a user despite them using VPN and covering their tracks.
im not supporting the criminal or saying they were right.
but if your OS tracks every action you take. every network connection you make then privacy is a myth.
Use Linux, its really accessible for beginners now.
reject corporate spying. and take control of your privacy.
#gdid #vpn
https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/
Digitale Selbstverteidigung muss nicht kompliziert sein. In der Privacy Guide erkläre ich dir, wie du mit wenig Aufwand dein Online Leben deutlich spurenarmer gestalten kannst:
https://gnulinux.ch/privacy-guide
https://fediserve.de/preview.php?v=vimZj8HW0Kg
#privacy #security #sicherheit #firefox #linux #llcoolj #diday
#FacialRecognition in #UK Shops Will Soon Instantly Alert #Police About Offenders
#ai #privacy #surveillance #security #biometrics
Zum Wochenstart gibt es für euch druckfrisch den grossen Privacy Guide für eure Privatsphäre: https://gnulinux.ch/privacy-guide
#privacy #privatsphaere #security #firefox #thunderbird #linux #freesoftware
Privacy Guide
Anleitung zur Wahrung der Privatsphäre im Internet.
"Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint"
GrapheneOS version 2026071100 released:
https://grapheneos.org/releases#2026071100
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/39301-grapheneos-version-2026071100-released
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.
#security #reverse-engineering #ai #privacy
https://thereallo.dev/blog/claude-code-prompt-steganography
RE: https://mastodon.social/@404mediaco/116901939536385326
I switched to Proton Mail many years ago when I was still an iOS user. I'm still a Proton subscriber but abandoned iOS for GrapheneOS.
#privacy and #security matter immeasurably
AodeRelay boostedA vulnerability in Apple’s “Hide My Email” tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year.
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/
#NYT #journalists who received #subpoenas included Julian E. Barnes, Eric Lipton, Tyler Pager & Eric Schmitt, who reported on Wednesday that #Trump had departed Turkey on the old #AirForceOne as a #security precaution at the urging of the #SecretService. Thursday, NYT reported that the new Air Force One, a #Qatar donated Boeing 747-8, lacked some of the advanced security features of the older aircraft, including antimissile capabilities. Both articles cited anonymous sources….
The #Trump admin issued #subpoenas Friday to several journalists for #TheNewYorkTimes, after the news outlet reported this week on #security concerns involving #Trump’s new #Qatar donated #AirForceOne.
The subpoenas — which seek to force the #reporters to testify before a federal grand jury in Manhattan on Wednesday — were an extraordinary escalation in Trump’s efforts to #threaten & #intimidate independent news organizations.
#law #Constitution #FreePress #journalism
https://www.nytimes.com/2026/07/11/business/media/new-york-times-trump-subpoenas.html?smid=nytcore-ios-share
Schweizer Armee bricht mit Microsoft: „Kommando Cyber“ setzt auf Open Source
Wegen Cloud-Zwang und geopolitischer Abhängigkeit von den USA migrieren die Cyber-Spezialisten der Schweizer Armee in Rekordzeit zur deutschen Lösung OpenDesk.
#Datenschutz #DigitaleSouveränität #IT #ITInfrastruktur #Microsoft #OpenSource #Security #news
Möchtest du deinen Linux-Desktop sicherer machen, dann schau dir mal Portmaster von safing.io an. In diesem Video erkläre ich dir genau, wie du die Desktop-Firewall installierst und einrichtest: https://makertube.net/w/ubNFJRwBQeLCzLgUPonQBm
Huj, fuffzehn jahre alt. Der kleine verkacker im kernel ist ja fast volljährig geworden, bis ihn mal jemand bemerkt hat… und etwas im kontäjhner laufenzulassen, ist auch kein schutz.
Spielt eure sicherheitsaktualisierungen ein!
#Epic #Fail #Link #Linux #Linuxnews #SecurityGhostLock: 15 Jahre alte Kernel-Lücke ermöglicht Root-Zugriff
https://linuxnews.de/ghostlock-15-jahre-alte-kernel-luecke-ermoeglicht-root-zugriff/ #security #linux #kernel #linuxnews
Hackers can use 9 of the most popular AI tools to assemble massive botnets
HalluSquatting
Archive: ia: https://s.faithcollapsing.com/vbp9e
#ai #biz-&-it #features #hallucinations #llms #security #typosquatting
https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/
Vanadium version 150.0.7871.114.0 released:
https://github.com/GrapheneOS/Vanadium/releases/tag/150.0.7871.114.0
See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.
Forum discussion thread:
https://discuss.grapheneos.org/d/37990-vanadium-version-150078711140-released
this KDE security advisory (from 2020) is hilarious: https://kde.org/info/security/advisory-20201002-1.txt
Workaround: stop kdeconnectd. but, you can't do that because it's started from dbus, so it's literally impossible to stop. the only solution is to remove the package, but good luck doing that when it's part of your OS's KDE metapackage.
what is this super important daemon that must be running 100% of the time and cannot be stopped or removed? well, it lets you control your desktop PC from your phone. something which i'm sure at least 0.001% of KDE users have ever done, or ever will do...
what the fuck are you doing, software developers.
Secure PDF Viewer app version 32 released:
https://github.com/GrapheneOS/PdfViewer/releases/tag/32
See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.
Forum discussion thread:
https://discuss.grapheneos.org/d/37983-secure-pdf-viewer-app-version-32-released
Huge thanks to our silver sponsor from day 1: itRISKman and @jenshoffmann! 🩶 We're immensely grateful for their continued support over the years. They literally keep the Open Security Conference more affordable for everyone interested in cybersecurity.
Discover itRISKman: https://www.itriskman.de/
Learn more about all our sponsors: https://opensecurityconference.org/support/sponsors/
#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity #OpenSpace [lisi]
Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck
Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.
#Datenschutz #Datensicherheit #Elasticsearch #IT #Nextcloud #Security #news
Big shout-out to REWE digital for their continued silver sponsorship of the Open Security Conference! 🩶 Their support helps people gain access to #CyberSecurity matters, no matter their own background. We're truly grateful!
Discover #REWEdigital: https://www.rewe-digital.com/
Learn more about all our sponsors: https://opensecurityconference.org/support/sponsors/
#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity #OpenSpace #HomeOfIT #IT #Retail #ITSecurity [lisi]
RootAsRole 4.0: Mehr Kontrolle als bei sudo
RootAsRole 4.0 erweitert die sudo-Alternative um ein neues Ausführungsmodell und feinere Richtlinien für privilegierte Linux-Befehle.
There is a new chat app in town: vectorapp.io
you can find and join #groups here for the #messenger: vectorapp.io/hub
#chat #software #communication #security #cybersecurity #e2e #encryption #vector #app #news #software #internet #privacy #decentralization #foss #floss #opensource #tool #utility
Location: Matrix
OpenBSD's pledge(2) and unveil(2) are developer-friendly, study finds https://www.undeadly.org/cgi?action=article;sid=20260708055608 #openbsd #security #pledge #unveil #development #programming
🛡️📋 Opera prezintă Paste Protect: O nouă funcție de securitate care protejează datele sensibile din clipboard
Browserul Opera adaugă un nou strat de securitate pentru utilizatorii săi prin introducerea funcției Paste Protect. Această tehnologie inovatoare este concepută special pentru a combate una dintre cele mai insidioase tactici de hacking: înlocuirea din mers a datelor salvate în clipboard (funcția de Copy-Paste).
Scopul principal al Paste Protect este de a proteja informațiile ultra-sensibile, cum ar fi numerele de conturi bancare, adresele de portofele cripto (crypto wallets) sau codurile de identificare personală, împotriva programelor malware de tip „clipper”.
Iată cum funcționează această funcție și de ce este esențială pentru navigarea în siguranță:
🔹 Combaterea atacurilor de tip „Clipboard Hijacking”:
Multe programe malware moderne rulează silențios în fundalul sistemului de operare și monitorizează clipboard-ul. Când detectează că un utilizator a copiat un șir lung de caractere (specific unei adrese Bitcoin sau unui cont IBAN), malware-ul înlocuiește instantaneu acel șir cu adresa atacatorului. Dacă utilizatorul nu verifică manual fiecare caracter înainte de a da Paste, banii ajung direct în contul hackerilor. Paste Protect detectează și blochează aceste modificări neautorizate.
🔹 Avertizări inteligente în timp real:
Atunci când Opera detectează că o aplicație externă sau un script web suspect încearcă să modifice sau să intercepteze conținutul pe care tocmai l-ai copiat, browserul va afișa o alertă vizuală clară. Acesta va avertiza utilizatorul că textul din clipboard a fost alterat, prevenind finalizarea unor tranzacții frauduloase.
🔹 Protecție integrată, fără configurări complexe:
Funcția este integrată direct în nucleul browserului și funcționează automat în fundal, fără a necesita instalarea unor extensii terțe sau realizarea unor setări complicate de către utilizator. Aceasta monitorizează interacțiunea dintre browser și clipboard-ul sistemului de operare (fie că vorbim de Linux, Windows sau macOS) pentru a asigura integritatea datelor.
🔹 Parte dintr-un ecosistem mai larg de securitate:
Introducerea Paste Protect face parte din strategia continuă a celor de la Opera de a transforma browserul într-un mediu sigur pentru tranzacții financiare și Web3. Funcția completează suita existentă de unelte, precum VPN-ul gratuit integrat, blocantul de reclame nativ și protecția împotriva scripturilor de cryptojacking (criptomined).
Prin implementarea acestei funcții, Opera face un pas important în fața competitorilor, oferind o soluție directă la o problemă de securitate tot mai frecventă în rândul utilizatorilor care efectuează plăți online sau gestionează active digitale.
#Security #OperaBrowser #PasteProtect #CyberSecurity #Privacy #TechNews #WebSafety #LinuxEasy
To save on #announcement posts, here is a single one about the new #wxWidgets releases in both stable 3.2 and development branch: https://wxwidgets.org/news/2026/07/wxwidgets-3.2.11-and-3.3.3-released/
Both have tons of fixes for various buffer overrun, i.e. #security, problems (mostly, but, unfortunately, not only, in very rarely used parts) that we probably have to thank the advent of #LLMs for.
And 3.3.3 development release also has a lot of improvements to MSW dark mode support, in addition to aesthetically pleasing version number.
AT&T's very rare Security-Plus Telephone https://lobste.rs/s/fw8e40 #cryptography #historical #security
https://www.electrospaces.net/2025/10/an-interesting-advertisement-for-stu.html
RouterOS 7.23.2 release notes:
!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
so... we fixed a security vulnerability, but we're not going to tell you what it is, so you have no idea how urgent this update is or how exposed you are or if you're even affected at all.
thanks, i guess?
(rumour has it this is a memory disclosure or potential RCE in pptp/l2tp/ppoe...)
OpenSSH 10.4/10.4p1 released! https://www.undeadly.org/cgi?action=article;sid=20260706190144 #openbsd #openssh #ssh #security #cryptography #secureshell
Scary thought… EU still may introduce chat control!
#ChatControl #Chat #Privacy #Encryption #Security
https://www.heise.de/en/news/Chat-Control-1-0-EU-Council-forces-messenger-scans-via-fast-track-11353659.html
OPNsense-Update beseitigt kritische Rootlücke und weitere Sicherheitsrisiken
Aktuelle Versionen der Open-Source-Firewall-Distribution schließen mehrere Einfallstore. Eine als kritisch bewertete Lücke macht das Update besonders dringlich.
#Firewall #IT #OpenSource #Security #Sicherheitslücken #Updates #news
Dell dichtet PowerProtect Data Domain gegen gefährliche Angriffsszenarien ab
Als „kritisch“ stuft Dell ein bereitgestelltes Update-Paket für mehrere Versionen des PowerProtect DD-Betriebssystems ein. Remote-Angriffe sind möglich.
#Scientists Asked #AI to Impersonate 112 Public Figures. What Happened Next Is a ‘Dire’ Warning
AI #chatbots that were prompted to #impersonate public figures produced responses that people perceived to be more authentic, coherent, and relevant than the real thing, a finding that underscores “a dire need to inform the general public of the potential harm this can have on society,” according to a study published on Wednesday in PLOS One.
#security #plosone #artificialintelligence #deepfake
🟡 Military Mobilization | 6/10
🇮🇶 🇮🇷
30,000 PMF fighters securing funeral of Iran's late Supreme Leader in Najaf and Karbala
Iraq's Popular Mobilization Forces deployed approximately 30,000 fighters to secure funeral ceremonies for Iran's late Supreme Leader in Najaf and Karbala. Command in the Euphrates region confirmed the deployment.
Whereas DirtyClone exploits a kernel module (which can be tackled by unloading and blocking it), Bad Epoll does not.
Beijing Plane Crash Tests China's Security State – FP
https://foreignpolicy.com/2026/06/30/china-plane-crash-beijing-citic-tower-security/
― The highlights this week: Fallout from a fatal plane crash in Beijing ripples through the security state, a Chinese billionaire is sentenced to 30 years in U.S. prison, and Chinese artificial intelligence models close the U.S. lead on cybersecurity. …
Do you feel a tinge of guilt Googling basic information on something because you aren't sure? Well, if it makes you feel any better, the Secret Service was frantically trying to Google where one of the Trump would-be assassin's were when shots rang out in Pennsylvania.
Interesting Git repos of the week:
Strategy:
* https://github.com/mr-r3b00t/ai_usage_mitre_analysis - AI abuse through an ATT&CK lens with @UK_Daniel_Card 🤖
Detection:
* https://github.com/citizenlab/bluecoat-investigations investigating Blue Coat device breaches with @citizenlab
* https://github.com/andreicscs/HoneyWire - F/OSS deception
Bugs:
* https://github.com/sgkdev/ipv6_frag_escape - another Linux LPE
Exploitation:
* https://github.com/x86byte/Obfusk8 - obfuscation library
* https://github.com/bee-san/RustScan - a port scanner in Rust
* https://github.com/t0thkr1s/gpp-decrypt - dumping GPP cpassword
* https://github.com/kernelstub/Nox - attack surface management in Go
* https://github.com/JVBotelho/skewrun - abusing time in AD
* https://github.com/db0109/AI-Red-Team-Scripts-And-Checklist - tips and tricks for red teaming AI 🤖
* https://github.com/jonaslykkegaard9-ops/m - remapping Windows memory
Hard hacks:
* https://github.com/pinkflawd/MIPSReverseEngineeringWorkshop - @pinkflawd's MIPS training
Nerd:
* https://github.com/ripienaar/free-for-dev - free hosting for developers 🤖
* https://github.com/dockur/macos - OS X in Docker
RE: https://infosec.exchange/@mattburgess/116854795161474282
Please do let that sink in. 🤯
And still, many European countries do hire their #spyware services and give that company our taxpayer money and our personal data.
We need to bring them to justice, not fund their crimes! 🤬
https://en.wikipedia.org/wiki/Pegasus_(spyware)
#Europe #EU #Germany #security #Pegasus #Android #iOS #Apple #NSO