Lobster Roll

All LHN/.

Security / Privacy (2024-09)

RSS

Showing stories from 2024-09. View all

secure.py – Simplify HTTP Security Headers for Python Web Apps (Major Update) (github.com)
Hello everyone, I'm excited to announce a major update to secure.py, a Python library that simplifies adding HTTP security headers to web applications. This release is a complete rewrite, leveraging modern Python 3.10+ features to enhance usability and performance. It supports frameworks like Fla...
Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs (arxiv.org)
Hacking Kia: Remotely Controlling Cars With Just a License Plate (samcurry.net)
You're probably not vulnerable to the CUPS CVE (xeiaso.net)
Attacking UNIX Systems via CUPS, Part I (evilsocket.net)
mir: Module-level RWX permissions for Node.js (github.com)
Eliminating memory safety vulnerabilities at the source (security.googleblog.com)
Mozilla faces a privacy complaint over Firefox's tracking (engadget.com)
Severe Unauthenticated RCE Flaw (CVSS 9.9) in GNU/Linux Systems Awaiting Full Disclosure (securityonline.info)
Eliminating Memory Safety Vulnerabilities at the Source (security.googleblog.com)
Post-OCSP certificate revocation in the Web PKI (seirdy.one)
Awala: The computer network on which humankind can truly rely (awala.network)
Insecurity Through Mandates (michaelwashere.net)
HardenedBSD and Protectli Collaborates for a Censorship- and Surveillance-Resistant Mesh Network (hardenedbsd.org)
Safe Ride into the Dangerzone: Reducing attack surface with gVisor (dangerzone.rocks)
RFC 9446: Reflections on Ten Years Past the Snowden Revelations (2023) (rfc-editor.org)
What's inside the QR code menu at this cafe? (peabee.substack.com)
CensysIO just started actively probing mumble servers (gist.github.com)
<W>2024-09-23 03:27:21.227 1 => <31:CensysIO(-1)> Authenticated <W>2024-09-23 03:27:21.344 1 => <31:CensysIO(-1)> Connection closed: The TLS/SSL connection has been closed [1] How far does Censys actively probe services to where it is more invasive than necessary?
OpenSSH 9.9 released (undeadly.org)
4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways (blog.coffinsec.com)
End-to-End Encryption in Rails with Stimulus and OpenPGP (jensravens.com)
Gaining Access to Anyones Browser without Them Even Visiting a Website (kibty.town)
Visual guide to SSH tunneling and port forwarding (ittavern.com)
Unmasking vulnerabilities in cheap IoT cameras from one Chinese manufacturer (trevorkems.com)
Ruby-SAML pwned by XML signature wrapping attacks (ssoready.com)
Using YouTube to steal your files (lyra.horse)
Integrity Policy Enforcement (IPE) (docs.kernel.org)
Update on an upcoming German broadcasting story about Tor/Onion Services (lists.torproject.org)
Prompt Injections and a demo (frederikbraun.de)
Meet DAVE: Discord’s New End-to-End Encryption for Audio & Video (discord.com)