Lobster Roll

All LHN/.

Security / Privacy (2025-09)

RSS

Showing stories from 2025-09. View all

Shellshock (2014, 2025) (dwheeler.com)
Claude in Cyber Competitions (red.anthropic.com)
Supply chain security for the 0.001% (and why it won’t catch on) (blog.viraptor.info)
Testing "exotic" p2p VPN (blog.nommy.moe)
Is IP fragmentation still considered vulnerable? (blog.apnic.net)
Offline translator for Android (github.com)
seL4 2025 Playlist (youtube.com)
go-landlock: A Go library for the Linux Landlock sandboxing feature (github.com)
First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails (koi.security)
Cross-Agent Privilege Escalation: When Agents Free Each Other · (embracethered.com)
crates.io: Malicious crates faster_log and async_println (blog.rust-lang.org)
Race Against Time in the Kernel’s Clockwork (streypaws.github.io)
How MCP Authentication Flaws Enable RCE in Claude Code, Gemini CLI, and More (verialabs.com)
Fifty Years of Open Source Software Supply-Chain Security (cacm.acm.org)
Our plan for a more secure npm supply chain (github.blog)
Phishing attacks with new domains likely to continue (blog.pypi.org)
Using DNS for responding to ACME challenges (hsm.tunnel53.net)
Crypto Miner in hotio/qbittorrent (apogliaghi.com)
Exploring GrapheneOS secure allocator: Hardened Malloc (synacktiv.com)
Linux Kernel Runtime Guard (LKRG) 1.0 (openwall.com)
Kernel Security in the Wild: Side-Channel-Assisted Exploit Techniques, Kernel-Level Defenses, and Real-World Analysis (tugraz.elsevierpure.com)
My Hacking Simulator runs on a Cyberdeck (tiniuc.com)
Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame (bughunters.google.com)
Less is safer: how Obsidian reduces the risk of supply chain attacks (obsidian.md)
Hacking with AI SASTs: An overview of ‘AI Security Engineers’ / ‘LLM Security Scanners’ for Penetration Testers and Security Teams (joshua.hu)
Shai-Hulud, The Most Dangerous NPM Breach In History Affecting CrowdStrike and Hundreds of Popular Packages (koi.security)
Protect your keys with the Secure Enclave (octet-stream.net)
Project Rain:L1TF (bughunters.google.com)
Want to piss off your IT department? Are your links not malicious looking enough? (phishyurl.com)
From suspicion to published curl CVE (daniel.haxx.se)