🦞🌯 Lobster Roll

All LHN/.~Ars
RSS
NewestOldestTop ScoredMost Discussed
I built a scanner to find common vulnerabilities in AI-generated apps (securemyvibes.com)
A Meta AI security researcher said an OpenClaw agent ran amok on her inbox (techcrunch.com)
We audited both MCP SDKs – three classes of boundary-crossing vulnerabilities
MCP (Model Context Protocol) has 77k+ stars and is becoming the standard way AI agents connect to tools. We audited both official SDKs (TypeScript and Python) at the source code level and found three classes of boundary-crossing vulnerabilities.<p>All three confirmed with live PoC exploits using the...
Addressing your questions about the Cyber Resilience Act (fsfe.org)
When we say "security", what do we mean? (2023) (kellyshortridge.com)
OpenClaw and Agent Execution Firewall (github.com)
framedeck: A Framework mainboard based Cyberdeck (2022) (github.com)
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 (hacks.mozilla.org)
Show HN: PDP – A 'robots.txt' protocol for AI prompt privacy (github.com)
Mercari's Phishing-Resistant Accounts with Passkey (engineering.mercari.com)
Vulnerability as a Service (herman.bearblog.dev)
Show HN: Mqvpn – Open-source multipath QUIC VPN (github.com)
The IETF has specs for IP-over-HTTP&#x2F;3 (MASQUE CONNECT-IP, RFC 9484) and Multipath QUIC, but no open-source implementation combines both. I implemented MASQUE CONNECT-IP on XQUIC (which already had Multipath QUIC), and wrote a new multipath scheduler designed for QUIC Datagrams, then built a V...
Show HN: A ground up TLS 1.3 client written in C (github.com)
Diesel Vortex: Inside the Russian cybercrime group targeting US and EU freight (haveibeensquatted.com)
Spotify Update on Developer Access and Platform Security (developer.spotify.com)
Show HN: VVMList – Vulnerable VMs organized by attack techniques (vvmlist.github.io)
Hi HN,<p>I built VVMList for cybersecurity learners to easily find specific techniques used on specific machines.<p>A few years ago, I originally created VVMList to track the machines I completed and the techniques I used to solve them. After some time, I semi-abandoned the project.<p>At the end of ...
Meta executive warned Facebook Messenger encryption plan was 'so irresponsible' (reuters.com)
How to Organize Safely in the Age of Surveillance (wired.com)
Show HN: We scanned 500 ClawHub skills for security risks – 10% were dangerous
We built tork-scan, a free open-source CLI that checks AI agent skills (MCP tools) for 19 security risk patterns — reverse shells, credential harvesting, base64 payloads, eval(), C2 domains, and more.<p>We pointed it at 500 ClawHub skills. Results:<p>- 200 (40%) SAFE (90-100) - 150 (30%) CAUTION (70...
Huntarr - Your passwords and your entire arr stack's API keys are exposed to anyone on your network, or worse, the internet (reddit.com)
Google, Apple start testing encrypted RCS on Android and iOS 26.4 (9to5google.com)
'Starkiller' Phishing Service Proxies Real Login Pages, MFA (krebsonsecurity.com)
Get to Know OpenClaw Security (get-to-know-openclaw-security-model.vercel.app)
NIST Seeking Public Comment on AI Agent Security (Deadline: March 9, 2026) (federalregister.gov)
Global regulators say AI image tools don't get a free pass on privacy rules (theregister.com)
It's Official: The Cybertruck Is More Explosive Than the Ford Pinto (fuelarc.com)
Signed, Sealed, Stolen: How We Patched Critical Vulnerabilities Under Fire [video] (youtube.com)
Signed, Sealed, Stolen: How We Patched Critical Vulnerabilities Under Fire (youtube.com)
Slides: https://fosdem.org/2026/events/attachments/ETMLM8-signed_sealed_stolen_how_we_patched_critical_vulnerabilities_under_fire/slides/267683/slides-ex_msapjhv.pdf
CrowdStrike Plummets. Why a New AI Tool Is Crushing Cybersecurity Stocks (barrons.com)
Mississippi medical center closes all clinics after ransomware attack (bleepingcomputer.com)