🦞🌯 Lobster Roll

All LHN/.~Ars
RSS

Showing stories from 2025-11. View all

NewestOldestTop ScoredMost Discussed
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats (blog.pypi.org)
Chat Control: EU lawmakers finally agree on the voluntary scanning of your private chats (techradar.com)
Prepared Statements? Prepared to Be Vulnerable (blog.mantrainfosec.com)
Ransomware Attack Disrupts Local Emergency Alert System Across US (securityweek.com)
Show HN: A daily cybersecurity newsletter that's fun to read (threatroad.substack.com)
Hey HN, I got tired of cybersecurity news reading like a compliance manual written by a sleep-deprived lawyer, so I built Threat Road — a daily, 5-minute, plain-English cybersecurity briefing that’s actually fun.<p>Would love your feedback, especially from people who do IR, AppSec, dev, ops, or just...
fail2ban RCE (cve.org)
Releasing Packages with a Valet Key: npm, PyPI, and beyond (byk.im)
Show HN: EnvHush – share .env files securely (E2E-encrypted, self-destructing) (envhush.com)
Solo project, launched yesterday. Goal: make the 2 a.m. “here are the keys” moment not end in a security incident. - Encryption happens entirely in browser (WebCrypto) - Server is a dumb store, never sees key or plaintext - Links expire 1 h – 30 days - Optional password + burn-after-reading - Free t...
New banking malware can stealth-hack your Android phone (androidauthority.com)
Launching the Julia Security Working Group (julialang.org)
Show HN: Local Notes History – Privacy-first Notes manager (anan.guru)
I built a notes history manager that stores everything locally in your browser (IndexedDB). No server, no tracking, no accounts.<p>Features:<p>Search through your notes history Tag and organize notes Version history with visual diffs Optional password encryption Dark&#x2F;sepia themes Export&#x2F;im...
Evaluating Computer-Use Agents on Exploiting Web Application Vulnerabilities (researchgate.net)
RunC vulnerabilities CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 (seclists.org)
Huawei and Chinese Surveillance (schneier.com)
eazypm, npm package to reinstall project dep. with malware scanner (safe-chain) (npmjs.com)
SecretSpec 0.4.0 (devenv.sh)
Cryptology firm cancels elections after losing encryption key (bbc.com)
Counter Galois Onion: Improved encryption for Tor circuit traffic (blog.torproject.org)
Security Flaws in DeepSeek-Generated Code Linked to Political Triggers (crowdstrike.com)
Tor switches to new Counter Galois Onion relay encryption algorithm (bleepingcomputer.com)
CVE-2025-66021: in OWASP Java HTML Sanitizer (nvd.nist.gov)
Proton Meet: Secure, end-to-end encrypted video conferencing (proton.me)
Mass Surveillance Is Powering a New Era of Pretextual Traffic Stops (reason.com)
Ask HN: Have major security breeches been less common lately?
A few years ago, it felt like we had another news story of a major security breech every other day or something. (I&#x27;m exaggerating of course but the stories were a regular occurrence.)<p>It occurred to me today that I couldn&#x27;t remember the last time I&#x27;d seen a story like this.<p><i>Ha...
Stop Hacklore - An Open Letter (hacklore.org)
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem) (labs.watchtowr.com)
When Fake Security Is Mandated Real Security Becomes a Crime (techrights.org)
Counter Galois Onion: Improved encryption for Tor circuit traffic (blog.torproject.org)
Show HN: MCP Security Scanning Tool for CI/CD (smart.mcpshark.sh)
Launching the Julia Security Working Group (julialang.org)