Lobster Roll

All Programming (General) 8177 Systems / Low-Level / OS 6631 Programming Languages / CS Theory 4253 Data / Databases / Infrastructure 3847 Web Development 2761 AI / Machine Learning 2325 Security / Privacy 2166 Culture / Philosophy / History / Reading 2105 Productivity / Career / Business 1501 Maker / DIY / Hardware 1281 Gaming / Retro Computing 995 Design / UX / Visualization 915 Science / Math / Physics 837 Apple / macOS / iOS 697 Internet / Digital Culture 332 Health / Fitness / Lifestyle 24 Crypto / Blockchain 10

Security / Privacy

oss-security - runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 (openwall.com)
Defeating KASLR by Doing Nothing at All (googleprojectzero.blogspot.com)
RDSEED Failure on AMD “Zen 5” Processors (amd.com)
CHERIoT 1.0 Released (cheriot.org)
Notes by djb on using Fil-C (cr.yp.to)
Attacking macOS XPC helpers: Protocol reverse engineering and interface analysis (tonygo.tech)
X.Org Security Advisory: multiple security issues X.Org X server and Xwayland (lists.x.org)
The Tailscale Fall Update in under 8 minutes (youtube.com)
Ten years of joeblu.com (joeblu.com)
Hacking India’s largest automaker: Tata Motors (eaton-works.com)
Fix your FODs (garnix.io)
Introducing Aardvark: OpenAI’s agentic security researcher (openai.com)
Language Models are Injective and Hence Invertible (arxiv.org)
NPM flooded with malicious packages downloaded more than 86,000 times (arstechnica.com)
Introducing fnox: A secret manager that pairs well with mise (fnox.jdx.dev)
I'm Independently Verifying Go's Reproducible Builds (agwa.name)
HTTPS by default (security.googleblog.com)
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition (tee.fail)
filepizza: Peer-to-peer file transfers in your browser (github.com)
What We Talk About When We Talk About Sideloading (f-droid.org)
Firefox Security & Privacy Newsletter 2025 Q3 (attackanddefense.dev)
Why IP address truncation fails at anonymization (00f.net)
When 'perfect' code fails (marma.dev)
Encryption using SSH Keys with age in Linux (ittavern.com)
Sandbox Your Program Using FreeBSD's Capsicum (m.youtube.com)
An Overview of Attestations in CI (github.com)
An analysis of iBoot’s Image4 parser (amarioguy.github.io)
NewPipe is turning 10 (newpipe.net)
Date bug affects Ubuntu 25.10 automatic updates (lwn.net)
Object-capability Programming in Javascript (youtube.com)