🦞🌯 Lobster Roll

All LHN/.~Ars
RSS
NewestOldestTop ScoredMost Discussed
WireGuardClient is Transport Encryption not a VPN (github.com)
TruthLayer – Real-time AI hallucination firewall on AWS (builder.aws.com)
RCE in Your Test Suite: How AI Agent Skills Bypass Every Skill Security Scanner (gecko.security)
Cybercrime isn't just a cover for Iran's government goons (theregister.com)
Cyberpunk 2077 on RTX 5080M (on power) vs. M5 Max (on battery) (twitter.com)
Ballot SMC015v2: Allow mDL for authentication of individual identity (cabforum.org)
Whistleblower claims ex-DOGE member says he took Social Security data to new job (washingtonpost.com)
DHS Ousts CBP Privacy Officers Who Questioned 'Illegal' Orders (wired.com)
Swiss e-voting pilot can't count 2,048 ballots after decryption failure (theregister.com)
Simple End-to-end encrypted file sharing for iOS (stash-app.xyz)
Infrastructure Vulnerabilities and White-Label Abuse: Is Opnex a Scam?
In the current digital finance landscape, fraudulent entities are becoming increasingly adept at using mature technical tools (like MetaTrader 5) to manufacture credit endorsements for their illicit operations. Today, we dissect OPNEX from a network infrastructure, information security, and architec...
China Restricts OpenClaw as Security Fears Grow (operator.io)
Jumping VPN: session-centric architecture – multipath and failover demos (github.com)
Ask HN: Agencies/MSPs, how do you manage VPN access across many clients?
Hi HN,<p>we&#x27;re a software development agency with several clients scattered across Europe. Due to the nature of our products many require to connect to the client&#x27;s VPN to offer assistance and perform maintenance. Most times we can&#x27;t install our own VPN.<p>This has led to some of our ...
Ask HN: Is there a market for a security-audited Claude Code skills newsletter?
I&#x27;ve been using Claude Code heavily and kept running into the same frustration: there are thousands of skills out there but no reliable way to know if they&#x27;re any good or safe to install. Snyk&#x27;s ToxicSkills research found 36.82% of publicly available skills contain security flaws, 13....
OWASP Top Agents and AI Vulnerabilities (blog.alexewerlof.com)
CVE-2026-3288: K8s ingress-nginx path injection via rewrite-target annotation (nvd.nist.gov)
The Global Vulnerability Intelligence Platform with Olle E. Johansson (opensourcesecurity.io)
Tecto: An Opaque, Encrypted Token Protocol as an Alternative to JWT (github.com)
Cybertruck Tried to Drive 'Straight Off an Overpass' Attorney Claims (404media.co)
Log4j – Addressing AI-slop in security reports (github.com)
DOGE employee stole Social Security data and put it on a thumb drive (techcrunch.com)
Needle in the haystack: LLMs for vulnerability research (devansh.bearblog.dev)
Show HN: Rampart – Open-source firewall for AI agents (v0.8) (rampart.sh)
Apple's Privacy Is a Lie (youtube.com)
Whistleblower claims ex-DOGE member says he took Social Security data to new job (washingtonpost.com)
Fixing request smuggling vulnerabilities in Pingora OSS deployments (blog.cloudflare.com)
Remote MCP Servers: Hosting, Authentication and Best Practices (kapa.ai)
Show HN: Aegis – A security-first programming language for AI agents (github.com)
How are you using local LLMs for code? (esp. security/IP protection)
What models, text editors, and hardware is effective?<p>What is your corporate&#x2F;company context?