Lobster Roll

All Programming (General) 3773 Systems / Low-Level / OS 2950 Programming Languages / CS Theory 2127 Data / Databases / Infrastructure 1761 AI / Machine Learning 1523 Web Development 1308 Security / Privacy 1009 Culture / Philosophy / History / Reading 962 Productivity / Career / Business 731 Gaming / Retro Computing 538 Maker / DIY / Hardware 516 Design / UX / Visualization 491 Science / Math / Physics 428 Apple / macOS / iOS 355 Internet / Digital Culture 162 Health / Fitness / Lifestyle 14 Crypto / Blockchain 4

Security / Privacy

Side-Channel Attacks Against LLMs (schneier.com)
What is Messaging Layer Security (MLS)? (messaginglayersecurity.rocks)
How a single typo led to RCE in Firefox (kqx.io)
Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers (eprint.iacr.org)
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach (socket.dev)
GGML GGUF File Format Vulnerabilities (2024) (databricks.com)
Is End-to-End Encryption Optional For Large Groups? (soatok.blog)
How To Add DRM To Your Backend (easy) [2026 WORKING] (maia.crimew.gay)
Hacking a pharmacy to get free prescription drugs and more (eaton-works.com)
An AI Agent Published a Hit Piece on Me – More Things Have Happened (theshamblog.com)
How we allowed remote code execution (but safely) (tumuchdata.club)
Consumer Rights Wiki (consumerrights.wiki)
Lessons from CalyxOS signing process redesign (calyxos.org)
Reports of Telnet’s Death Have Been Greatly Exaggerated (terracenetworks.com)
Re-Identification Risk vs k-Anonymity (testingbranch.com)
Windows Notepad App Remote Code Execution Vulnerability (cve.org)
CVE-2026-1529 - keycloak: unauthorized organization registration via improper invitation token validation (cvefeed.io)
Breaking Down CVE-2026-25049: How TypeScript Types Failed n8n's Security (hetmehta.com)
Hope Is Not a Security Strategy: Why Secure-by-Default Beats Hardening (tuananh.net)
The Day the telnet Died (labs.greynoise.io)
Hard-braking events as indicators of road segment crash risk (research.google)
Discord Launches Teen-by-Default Settings Globally (discord.com)
SecretSpec 0.7: Declarative Secret Generation - devenv (devenv.sh)
Code injections through Git commit messages (mas.to)
Exploiting signed bootloaders to circumvent UEFI Secure Boot (2019) (habr.com)
Going Through Snowden Documents, Part 1 (libroot.org)
ReMemory - Split a recovery key among friends (eljojo.github.io)
A Horrible Conclusion (addisoncrump.info)
Evaluating and mitigating the growing risk of LLM-discovered 0-days (red.anthropic.com)
Using microvm.nix to sandbox Openclaw (buduroiu.com)