Lobster Roll

All Programming (General) 3774 Systems / Low-Level / OS 2950 Programming Languages / CS Theory 2127 Data / Databases / Infrastructure 1761 AI / Machine Learning 1524 Web Development 1308 Security / Privacy 1009 Culture / Philosophy / History / Reading 962 Productivity / Career / Business 731 Gaming / Retro Computing 538 Maker / DIY / Hardware 516 Design / UX / Visualization 491 Science / Math / Physics 428 Apple / macOS / iOS 355 Internet / Digital Culture 162 Health / Fitness / Lifestyle 14 Crypto / Blockchain 4

Security / Privacy

The RCE that AMD won't fix (mrbruh.com)
CSRF protection in Phoenix with Sec-Fetch-Site (mediremi.com)
Recent trends in the work of the Django Security Team (djangoproject.com)
Recreating Epstein PDFs from raw encoded attachments (neosmart.net)
I prefer to pass secrets between programs through standard input (utcc.utoronto.ca)
Mobile carriers can get your GPS location (an.dywa.ng)
GDPR Enforcement Is Broken (nikolak.com)
Django security releases issued: 6.0.2, 5.2.11, and 4.2.28 (djangoproject.com)
WhatsApp Encryption, a Lawsuit, and a Lot of Noise (blog.cryptographyengineering.com)
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit (rapid7.com)
oss-security - [kubernetes] Multiple issues in ingress-nginx (openwall.com)
MaliciousCorgi: The Cute-Looking AI Extensions Leaking Code from 1.5 Million Developers (koi.ai)
Notepad++ Hijacked by State-Sponsored Hackers (notepad-plus-plus.org)
Inside Lodash’s Security Reset and Maintenance Reboot (socket.dev)
archive.today is directing a DDOS attack against my blog (gyrovague.com)
Trustworthy Technology (aol.codeberg.page)
Ingress NGINX: Statement from the Kubernetes Steering and Security Response Committees (kubernetes.io)
Google Disrupts Large Residential Proxy Network (cloud.google.com)
Solving Fossil's ASCII art CAPTCHA in 171 characters (blog.nns.ee)
Beta testing of WebUSBUnpinner - a tool to investigate platform worker's privacy and rights violations (reversing.works)
Opinionated GitHub Action for generating high-quality SBOMs (github.com)
ARM MTE Performance in Practice (Extended Version) (arxiv.org)
I still don't understand this SYN attack, but now I can block it easily (boston.conman.org)
"a bootstrap chain for NixOS which builds the whole system from a small hand-auditable binary seed" (chaos.social)
Barev - XMPP flavoured p2p protocol (discourse.imfreedom.org)
zlib-rs: a stable API and 30M downloads (trifectatech.org)
Microsoft obeys court orders to provide Windows BitLocker recovery keys (windowscentral.com)
SITF: The First Threat Framework for SDLC Infrastructure (wiz.io)
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission (grahamhelton.com)
The end of the curl bug-bounty (daniel.haxx.se)