Lobster Roll

All Programming (General) 44210 Systems / Low-Level / OS 29271 Programming Languages / CS Theory 22789 Data / Databases / Infrastructure 17194 Web Development 15434 Security / Privacy 13804 Culture / Philosophy / History / Reading 13227 Productivity / Career / Business 10063 Maker / DIY / Hardware 7332 Science / Math / Physics 5439 AI / Machine Learning 5154 Design / UX / Visualization 4867 Gaming / Retro Computing 4225 Apple / macOS / iOS 3458 Internet / Digital Culture 1953 Crypto / Blockchain 504 Health / Fitness / Lifestyle 125

Security / Privacy

RSS
The how and why of GitHub to Codeberg (arscyni.cc)
Project Ire autonomously identifies malware at scale (microsoft.com)
Plague: A Newly Discovered PAM-Based Backdoor for Linux (nextron-systems.com)
TIL that You can spot base64 encoded JSON, certificates, and private keys (ergaster.org)
Low-Level Software Security for Compiler Developers (llsoftsec.github.io)
This Malware is live generated with AI? (youtube.com)
Introducing luzer, a coverage-guided Lua fuzzing engine (bronevichok.ru)
A systematic evaluation of OpenBSD’s mitigations (2019) (isopenbsdsecu.re)
Practical Static Analysis for Privacy Bugs (blog.brownplt.org)
Unikernel Guide: Build & Deploy Lightweight, Secure Apps (tallysolutions.com)
Free Security Audits for Erlang and Elixir open source projects (erlang-solutions.com)
Age Verification Doesn’t Need to Be a Privacy Footgun (soatok.blog)
We Asked 100+ AI Models to Write Code. Here’s How Many Failed Security Tests (veracode.com)
UserAgent-Switcher: A User-Agent (and "Client HInts") spoofer browser extension (github.com)
PyPI Phishing Attack: Incident Report (blog.pypi.org)
Secure boot certificate rollover is real but probably won't hurt you (mjg59.dreamwidth.org)
What is gVisor? (blog.yelinaung.com)
In search of riches, hackers plant 4G-enabled Raspberry Pi in bank network (arstechnica.com)
Opportunistic Encryption Is Coming to Hickory DNS (memorysafety.org)
How attackers are still phishing "phishing-resistant" authentication (bleepingcomputer.com)
[RFC] Upstream target support for CHERI-enabled architectures (discourse.llvm.org)
Eskil Steenberg – I've had it with the security orthodoxy (youtube.com)
Loading credentials from Bitwarden with direnv (ergaster.org)
Sploitlight: Analyzing a Spotlight-based macOS TCC vulnerability (microsoft.com)
No moar cookies (paretosecurity.com)
Redditor Speculates that EU age verification app to ban any Android system not licensed by Google (reddit.com)
Certificate Transparency - Part 1 (ipng.ch)
OverHAuL: Harnessing Automation for C Libraries with Large Language Models (kchousos.github.io)
An intro to security, with eggs, please (binturo.ng)
copyparty: portable file server with resumable uploads, dedup, WebDAV, and more (github.com)