Lobster Roll

All LHN/.

Security / Privacy (2025-11)

RSS

Showing stories from 2025-11. View all

Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers (blog.quarkslab.com)
Landlock-ing Linux (blog.prizrak.me)
Is anyone using Project Hummingbird? (redhat.com)
Fort Knox for your secrets - Manage secrets with encryption or cloud providers (fnox.jdx.dev)
Leak of identity of anonymous reviewers, authors, and area chairs on OpenReview
https://openreview.net/forum/user|statement_regarding_api_security_incident (As the URL contains a `|` it is being rejected in the URL field).
ML-KEM Mythbusting (keymaterial.net)
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats (blog.pypi.org)
Chat Control: EU lawmakers finally agree on the voluntary scanning of your private chats (techradar.com)
fail2ban RCE (cve.org)
Releasing Packages with a Valet Key: npm, PyPI, and beyond (byk.im)
SecretSpec 0.4.0 (devenv.sh)
Stop Hacklore - An Open Letter (hacklore.org)
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem) (labs.watchtowr.com)
Project Foxhound - on the Scent of Client-Side Web Vulnerabilities (community.sap.com)
Counter Galois Onion: Improved encryption for Tor circuit traffic (blog.torproject.org)
Shai Hulud Strikes Again (aikido.dev)
Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours (helixguard.ai)
Rust for Malware Development (bishopfox.com)
Windows ARM64 Internals: Deconstructing Pointer Authentication (preludesecurity.com)
A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture (stack.int.mov)
We should all be using dependency cooldowns (blog.yossarian.net)
Beyond the cloud: smarter choices for control, security & costs (bevuta.com)
Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models (arxiv.org)
Preventing Abuse of Digital Credentials (w3.org)
Inside a global campaign hijacking open-source project identities (fullstory.com)
WhatsApp Census (github.com)
Mind the encryptionroot: How to save your data when ZFS loses its mind (sambowman.tech)
6 years after too much crypto (bfswa.substack.com)
FunkSec – Alleged Top Ransomware Group Powered by AI (research.checkpoint.com)
k-anonymity, the parent of all privacy definitions (desfontain.es)