Lobster Roll

All Programming (General) 8176 Systems / Low-Level / OS 6628 Programming Languages / CS Theory 4253 Data / Databases / Infrastructure 3846 Web Development 2759 AI / Machine Learning 2324 Security / Privacy 2166 Culture / Philosophy / History / Reading 2105 Productivity / Career / Business 1501 Maker / DIY / Hardware 1281 Gaming / Retro Computing 995 Design / UX / Visualization 914 Science / Math / Physics 837 Apple / macOS / iOS 697 Internet / Digital Culture 332 Health / Fitness / Lifestyle 24 Crypto / Blockchain 10

Security / Privacy

Inside a global campaign hijacking open-source project identities (fullstory.com)
WhatsApp Census (github.com)
Mind the encryptionroot: How to save your data when ZFS loses its mind (sambowman.tech)
6 years after too much crypto (bfswa.substack.com)
FunkSec – Alleged Top Ransomware Group Powered by AI (research.checkpoint.com)
k-anonymity, the parent of all privacy definitions (desfontain.es)
The Cameras Tracking You = A Security Nightmare (youtube.com)
No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE (modzero.com)
RMPocalypse Attack: How a Catch-22 Breaks AMD SEV-SNP (rmpocalypse.github.io)
Notion + Data Loss / Privacy - Should you be worried about losing or leaking your notes? (hamy.xyz)
MacOS Infection Vector: Using AppleScripts to bypass Gatekeeper (pberba.github.io)
How we avoided side-channels in our new post-quantum Go cryptography libraries (blog.trailofbits.com)
LinkPro: eBPF rootkit analysis (synacktiv.com)
Support the call for Memory Safety incentives in EU cybersecurity policies - Trifecta Tech Foundation (trifectatech.org)
Nation state threat actor used Claude Code to orchestrate cyber attacks (anthropic.com)
Security Architects Need to be Wrong on the Internet (securitydatacommons.substack.com)
Practical Security in Production Hardening the C++ Standard Library at massive scale (queue.acm.org)
Fun-reliable side-channels for cross-container communication (h4x0r.org)
FFmpeg to Google: Fund Us or Stop Sending Bugs (thenewstack.io)
sudo-rs update to address two moderate vulnerabilities (bugs.launchpad.net)
Firefox expands fingerprint protections: advancing towards a more private web (blog.mozilla.org)
Memory Safety for Skeptics (queue.acm.org)
Android security bulletin: November 2025 patch fixes zero-click RCE (source.android.com)
"erase startup-config" isn't enough (alyx.sh)
The state of the Rust dependency ecosystem (00f.net)
Announcing Magika 1.0: now faster, smarter, and rebuilt in Rust (opensource.googleblog.com)
Introduction - OWASP Top 10:2025 RC1 (owasp.org)
Results from Testing Six AI Models on Advanced Security Exploits (blog.kilocode.ai)
On AI Slop vs OSS Security (devansh.bearblog.dev)
A security model for systemd (lwn.net)