Lobster Roll

All Programming (General) 31792 Systems / Low-Level / OS 23352 Programming Languages / CS Theory 16527 Data / Databases / Infrastructure 13189 Web Development 10674 Culture / Philosophy / History / Reading 9529 Security / Privacy 9254 Productivity / Career / Business 6734 Maker / DIY / Hardware 5438 AI / Machine Learning 4701 Science / Math / Physics 3415 Design / UX / Visualization 3345 Gaming / Retro Computing 3131 Apple / macOS / iOS 2475 Internet / Digital Culture 1236 Crypto / Blockchain 304 Health / Fitness / Lifestyle 81

Security / Privacy

Why (special agent) Johnny (still) Can't Encrypt (2011) (mattblaze.org)
open-edison: An MCP Gateway to block Simon Willison's Lethal Trifecta (github.com)
Phishing campaign targeting crates.io users (blog.rust-lang.org)
Trail of Bits: Buttercup is now open-source (blog.trailofbits.com)
Team Atlanta (team-atlanta.github.io)
Lessons in Disabling RC4 in Active Directory (syfuhs.net)
VMScape: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments (comsec.ethz.ch)
Kerberoasting (blog.cryptographyengineering.com)
I don’t want AI agents controlling my laptop (sophiebits.com)
Supply chains and watering holes (cryptography.dog)
Memory Integrity Enforcement: A complete vision for memory safety in Apple devices (security.apple.com)
GNU/Linux Sandboxing - A Brief Review (hardenedlinux.org)
Sandboxing Applications with Bubblewrap: A Simple Script (2024) (sloonz.github.io)
We all dodged a bullet (xeiaso.net)
A look at a P2P camera (LookCam app) (palant.info)
Replacing SGX with GitHub Actions: Or how to turn GitHub Actions into a trusted computing oracle (ethanheilman.com)
A Novel Technique for SQL Injection in PDO’s Prepared Statements (slcyber.io)
color npm package compromised (fasterthanli.me)
Anatomy of a billion-download NPM supply-chain attack (jdstaerk.substack.com)
Vibe-coded build system NX gets hacked, steals vibe-coders’ crypto (pivot-to-ai.com)
Ever shared a Spotify link on the internet? Someone you don't know can now message you (androidauthority.com)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack (arxiv.org)
Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more (blog.trailofbits.com)
Addressing the unauthorized issuance of TLS certificates for 1.1.1.1 (blog.cloudflare.com)
A CA Trusted by Microsoft Mis-issued Certificates for 1.1.1.1 in May 2025, According to Logs (arstechnica.com)
Strategically Holding Back Bugs and Patches (rya.nc)
Linux Kernel SMB 0-Day Vulnerability CVE-2025-37899 Uncovered Using ChatGPT o3 (upwind.io)
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes (portswigger.net)
Passkeys and Modern Authentication (lucumr.pocoo.org)
Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel (a13xp0p0v.github.io)