Lobster Roll

All Programming (General) 7610 Systems / Low-Level / OS 6145 Programming Languages / CS Theory 4007 Data / Databases / Infrastructure 3614 Web Development 2571 AI / Machine Learning 2257 Security / Privacy 2020 Culture / Philosophy / History / Reading 1959 Productivity / Career / Business 1422 Maker / DIY / Hardware 1172 Gaming / Retro Computing 954 Design / UX / Visualization 860 Science / Math / Physics 791 Apple / macOS / iOS 644 Internet / Digital Culture 313 Health / Fitness / Lifestyle 24 Crypto / Blockchain 10

Security / Privacy

Cyber Resilience Act - Implementation (digital-strategy.ec.europa.eu)
Composing capability security and conflict-free replicated data types (spritely.institute)
Quantifying Information Loss (testingbranch.com)
ACME Challenge for Persistent DNS TXT Record Validation (datatracker.ietf.org)
India orders smartphone makers to preload state-owned cyber safety app (reuters.com)
Decreasing Certificate Lifetimes to 45 Days (letsencrypt.org)
Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers (blog.quarkslab.com)
Landlock-ing Linux (blog.prizrak.me)
Is anyone using Project Hummingbird? (redhat.com)
Fort Knox for your secrets - Manage secrets with encryption or cloud providers (fnox.jdx.dev)
Leak of identity of anonymous reviewers, authors, and area chairs on OpenReview
ML-KEM Mythbusting (keymaterial.net)
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats (blog.pypi.org)
Chat Control: EU lawmakers finally agree on the voluntary scanning of your private chats (techradar.com)
fail2ban RCE (cve.org)
Releasing Packages with a Valet Key: npm, PyPI, and beyond (byk.im)
SecretSpec 0.4.0 (devenv.sh)
Stop Hacklore - An Open Letter (hacklore.org)
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem) (labs.watchtowr.com)
Project Foxhound - on the Scent of Client-Side Web Vulnerabilities (community.sap.com)
Counter Galois Onion: Improved encryption for Tor circuit traffic (blog.torproject.org)
Shai Hulud Strikes Again (aikido.dev)
Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours (helixguard.ai)
Rust for Malware Development (bishopfox.com)
Windows ARM64 Internals: Deconstructing Pointer Authentication (preludesecurity.com)
A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture (stack.int.mov)
We should all be using dependency cooldowns (blog.yossarian.net)
Beyond the cloud: smarter choices for control, security & costs (bevuta.com)
Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models (arxiv.org)
Preventing Abuse of Digital Credentials (w3.org)