Lobster Roll

All Programming (General) 43089 Systems / Low-Level / OS 28739 Programming Languages / CS Theory 22274 Data / Databases / Infrastructure 16920 Web Development 14859 Security / Privacy 13153 Culture / Philosophy / History / Reading 13013 Productivity / Career / Business 9857 Maker / DIY / Hardware 7111 Science / Math / Physics 5321 AI / Machine Learning 5067 Design / UX / Visualization 4706 Gaming / Retro Computing 4161 Apple / macOS / iOS 3347 Internet / Digital Culture 1746 Crypto / Blockchain 492 Health / Fitness / Lifestyle 122

Security / Privacy

Fight Chat Control (fightchatcontrol.eu)
Matrix Security Release (matrix.org)
OpenSSH: Post-Quantum Cryptography (openssh.com)
Exploiting a Buggy Zilog C Compiler (farlow.dev)
ChaCha12-BLAKE3: Secure, Simple and Fast authenticated and committing encryption (kerkour.com)
Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications (research.eye.security)
Improving Geographical Resilience For Distributed Open Source Teams with FREON (soatok.blog)
From Chrome renderer code exec to kernel with MSG_OOB (googleprojectzero.blogspot.com)
Updated Google Project Zero disclosure policy (googleprojectzero.blogspot.com)
Preventing ZIP parser confusion attacks on Python package installers (blog.pypi.org)
iOS client for Proton Authenticator (github.com)
Abusing Ubuntu 24.04 features for root privilege escalation (2024) (labs.snyk.io)
Oops Safari, I think You Spilled Something (blog.exodusintel.com)
Exploiting Retbleed in the real world (bughunters.google.com)
A Full-Chain Exploit of an Unfused Qualcomm Device (hhj4ck.github.io)
We replaced passwords with something worse (blog.danielh.cc)
HTTP/1.1 must die: the desync endgame (portswigger.net)
Visualizing Compiled Executables for Malware Analysis (eecis.udel.edu)
The how and why of GitHub to Codeberg (arscyni.cc)
Project Ire autonomously identifies malware at scale (microsoft.com)
Plague: A Newly Discovered PAM-Based Backdoor for Linux (nextron-systems.com)
TIL that You can spot base64 encoded JSON, certificates, and private keys (ergaster.org)
Low-Level Software Security for Compiler Developers (llsoftsec.github.io)
This Malware is live generated with AI? (youtube.com)
Introducing luzer, a coverage-guided Lua fuzzing engine (bronevichok.ru)
A systematic evaluation of OpenBSD’s mitigations (2019) (isopenbsdsecu.re)
Practical Static Analysis for Privacy Bugs (blog.brownplt.org)
Unikernel Guide: Build & Deploy Lightweight, Secure Apps (tallysolutions.com)
Free Security Audits for Erlang and Elixir open source projects (erlang-solutions.com)
Age Verification Doesn’t Need to Be a Privacy Footgun (soatok.blog)