Lobster Roll

All Programming (General) 3776 Systems / Low-Level / OS 2953 Programming Languages / CS Theory 2127 Data / Databases / Infrastructure 1763 AI / Machine Learning 1526 Web Development 1309 Security / Privacy 1010 Culture / Philosophy / History / Reading 962 Productivity / Career / Business 732 Gaming / Retro Computing 538 Maker / DIY / Hardware 516 Design / UX / Visualization 491 Science / Math / Physics 428 Apple / macOS / iOS 355 Internet / Digital Culture 162 Health / Fitness / Lifestyle 14 Crypto / Blockchain 4

Security / Privacy

Security Issues with Electronic Invoices (invoice.secvuln.info)
Building Trustworthy AI Agents (schneier.com)
Rethinking sudo with object capabilities (ariadne.space)
Denial of Service and Source Code Exposure in React Server Components (react.dev)
Over 10,000 Docker Hub images found leaking credentials, auth keys (bleepingcomputer.com)
The story of Propolice (miod.online.fr)
Maybe we don't need a server (lecaro.me)
The Fragile Lock: Novel Bypasses For SAML Authentication (portswigger.net)
RFC 9180 Hybrid Public Key Encryption (rfc-editor.org)
Stop Breaking TLS (markround.com)
Fear of the Walking Zig: The Security Audit Gap (generativeai.pub)
10 Years of Let's Encrypt Certificates (letsencrypt.org)
jail.nix - Easily wrap your nix derivation in bubblewrap jails (git.sr.ht)
Offline cybersecurity AI using RAG + local LLM (Python, FAISS, Llama 3.1) (gitlab.com)
Disagreements over post-quantum encryption for TLS (lwn.net)
Addressing Linux's Missing PKI Infrastructure (discourse.ubuntu.com)
potential security breach in syncthing-fork (mastodon.pirateparty.be)
IDEsaster: A Novel Vulnerability Class in AI IDEs (maccarita.com)
Why the Sanitizer API is just `setHTML()` (frederikbraun.de)
Defeating Prompt Injections by Design (arxiv.org)
GitHub Actions Has a Package Manager, and It Might Be the Worst (nesbitt.io)
CVE-2023-20078 technical analysis: Identifying and triggering a command injection vulnerability in Cisco IP phones (ibm.com)
A struct sockaddr sequel (lwn.net)
The Minnesota Model: What the Digital Fair Repair Act Means for Your Home Network Security (richardcallaby.com)
Coupongogo: Remote-Controlled Crypto Stealer Targeting Developers on GitHub (rastersec.com)
Unredacted Magazine Issue 008 SEP 2025 (unredactedmagazine.com)
What is a Package Manager? (nesbitt.io)
SVG Filters - Clickjacking 2.0 (lyra.horse)
ACME, a brief history of one of the protocols which has changed the Internet Security (blog.brocas.org)
Critical Security Vulnerability in React Server Components (react.dev)