Lobster Roll

All Programming (General) 24318 Systems / Low-Level / OS 18960 Programming Languages / CS Theory 12488 Data / Databases / Infrastructure 10399 Web Development 7865 Culture / Philosophy / History / Reading 6780 Security / Privacy 6779 Productivity / Career / Business 4818 Maker / DIY / Hardware 4210 AI / Machine Learning 3929 Design / UX / Visualization 2522 Gaming / Retro Computing 2485 Science / Math / Physics 2472 Apple / macOS / iOS 2051 Internet / Digital Culture 970 Crypto / Blockchain 102 Health / Fitness / Lifestyle 64

Security / Privacy

Exploring GrapheneOS secure allocator: Hardened Malloc (synacktiv.com)
Linux Kernel Runtime Guard (LKRG) 1.0 (openwall.com)
Kernel Security in the Wild: Side-Channel-Assisted Exploit Techniques, Kernel-Level Defenses, and Real-World Analysis (tugraz.elsevierpure.com)
My Hacking Simulator runs on a Cyberdeck (tiniuc.com)
Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame (bughunters.google.com)
Less is safer: how Obsidian reduces the risk of supply chain attacks (obsidian.md)
Hacking with AI SASTs: An overview of ‘AI Security Engineers’ / ‘LLM Security Scanners’ for Penetration Testers and Security Teams (joshua.hu)
Shai-Hulud, The Most Dangerous NPM Breach In History Affecting CrowdStrike and Hundreds of Popular Packages (koi.security)
Protect your keys with the Secure Enclave (octet-stream.net)
Project Rain:L1TF (bughunters.google.com)
Want to piss off your IT department? Are your links not malicious looking enough? (phishyurl.com)
From suspicion to published curl CVE (daniel.haxx.se)
How can we sandbox our development machines?
Access logging in 2025 (neugierig.org)
Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages (sysdig.com)
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens (dirkjanm.io)
Firefox DNS privacy: Faster than ever, now on Android (blog.mozilla.org)
PureVPN IPv6 leak (anagogistis.com)
PyPI Token Exfiltration Campaign via GitHub Actions Workflows (blog.pypi.org)
Linux 6.17 Security: New Kernel Hardening & Mitigation Controls (armosec.io)
ctrl/tinycolor and 40+ NPM Packages Compromised (stepsecurity.io)
Security through intentional redundancy (commaok.xyz)
Protecting Rust against supply chain attacks (kerkour.com)
OCSP Service Has Reached End of Life (letsencrypt.org)
On the Security of SSH Client Signatures (arxiv.org)
a few notes on ratelimiting (dotat.at)
Pass: Unix Password Manager (passwordstore.org)
The Internet Coup (interseclab.org)
My first CVE (natkr.com)
Why (special agent) Johnny (still) Can't Encrypt (2011) (mattblaze.org)