Tootfinder

Opt-in global Mastodon full text search. Join the index!

@poppastring@dotnet.social
2025-09-04 14:30:25

Prompt Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous
#security #llm
arxiv.org/abs/2508.12175

@0x663030623472@chaos.social
2025-07-29 10:12:23

#Secure. Or not? This is the question! :) #security #software

Image features information about "Top-notch Security," highlighting enterprise-grade security measures to keep data safe and protected, along with mentions of regular audits and transparent security practices.
A warning message about LumenOne not encrypting user passwords. It states the issue will be resolved in version 1.0.0 and advises users not to leak the "lumenone.db" file.
@mgorny@social.treehouse.systems
2025-08-07 05:43:48

Am I seeing #Django test failures because #Gentoo is up-to-date on #security backports to #Python? Of course.
(I didn't have time to report them yet.)

@chrysn@chaos.social
2025-10-01 09:14:05

While I do maintain that "it's coming from the LAN" is not a good #security boundary, there are services where it is practical (eg. media center volume control), but also fault prone (oups my phone just switched to LTE for power saving – a generally justified thing).
Before I start formalizing how "a device can retain permissions it gets from being local for a few days&quo…

@midtsveen@social.linux.pizza
2025-09-28 21:41:32

You can now find my public #PGP key at my website.
#Security

@paulbusch@mstdn.ca
2025-08-29 18:33:06

Harley is keeping a sharp lookout for sharks while our granddaughter is digging on the beach.
#DogsOfMastadon #BeachLife #Security

@khalidabuhakmeh@mastodon.social
2025-08-21 12:37:06

Hey #dotnet folks and #security wonks, join our #livestream today to learn about FAPI 2.0 and how to enhance security at your organization with the latest specification.
Also, drop in and say h…

@frankel@mastodon.top
2025-07-24 16:25:02

Critical #ContainerRegistry #Security Flaw: How Multi-Architecture Manifests Create Attack Vectors

@joergi@chaos.social
2025-07-24 06:55:56

TIL: Slack messages from private channels aren't private anymore, if someone post it in a public channel :🤯
Then everyone can read it.
I guess it's a feature and not a bug,, but I was really not expecting this!
#privacy #security

Screenshot from slack which says: "This is a message from a private conversation
You can see messages forwarded from any type
of conversation, but won't be able to access the
original message.
From a private conversation on Jul 22nd"
@adelgado@eu.mastodon.green
2025-08-25 06:59:54

I disabled my browser password extension for now #Security

@publicvoit@graz.social
2025-09-26 08:39:22

I'm sending a digitally signed and encrypted #email with somewhat sensitive data to an external party.
His thank-you-answer with the full quote of the while conversation came back signed and unencrypted.
Oh boy. 😔
#PIM

@crell@phpc.social
2025-08-26 19:15:14

Well, that's lovely...
#Security

@michabbb@social.vivaldi.net
2025-07-18 22:21:55

#Livewire v3 Remote Command Execution Vulnerability in Property Update Hydration 🚨🚨🚨
Critical #security #vulnerability in

@UP8@mastodon.social
2025-08-14 16:24:26

🗑️ TapTrap: Animation‑Driven Tapjacking on Android
#android #security

@khalidabuhakmeh@mastodon.social
2025-08-11 16:19:54

Are you worried your #dotnet #security could be more secure? Join us for a #livestream on August 21st, 2025, to discuss FAPI 2.0, its relation to

@ber@social.tchncs.de
2025-09-25 12:33:30

Want to know how to write and distribute #SecurityAdvisories that can be parsed and processed automatically?
Freshly announced are this years workshops for the Common Security Advisory Framework (#CSAF). They will be held in Nuremberg, Germany, November 10th to 12th.
See

@unchartedworlds@scicomm.xyz
2025-09-28 10:53:44
Content warning: systemic solutions vs individual shaming

Good post from @…:
"Trying to address the real issues going on in tech can’t rely on shaming average users for not conforming to an imagined version of reality that doesn’t exist and for not “just” doing things that aren’t really viable in light of everything else they’ve got going on."
#systems #tech #privacy #security

@michabbb@social.vivaldi.net
2025-07-11 00:26:02

#Security Alert: Massive #Laravel APP_KEY leak exposing 600 apps to remote code execution 🚨 #GitGuardian &

@tinoeberl@mastodon.online
2025-08-19 12:54:16

#Schlagzeilen, die ich nicht lesen möchte:
#Security #Hacker #dataleak

IT-Konsolidierung: Netze des Bundes zu alt für Sicherheitsupdates
Der Bundesrechnungshof hat eine Bilanz der IT-Konsolidierung des Bundes gezogen. Trotz Milliardenausgaben gibt es großen Nachholbedarf.
@frankstohl@mastodon.social
2025-07-24 09:03:52

Updates wir jetzt alle Outlook? #cyber #security #internet #BSI

@mgorny@social.treehouse.systems
2025-07-28 19:06:50

Yet another "HIGH severity" vulnerability in #Python.
Once again found in "Library" section of the NEWS, not in "#Security".
cve.org/CVERecord?id=CVE-2025-
github.com/python/cpython/pull

@joergi@chaos.social
2025-09-26 13:40:20

Wir schreiben das Jahr 2025 - und noch immer gibt es solche Sicherheitsbeschränkungen...
#email #security #1und1 #ionos

passwort eingabemaske, alles in rot weil fehler: 
Das Passwort Ist zu lang (69 Zeichen). Bitte
wahlen Sie ein Passwort mit hochstens 40
Zeichen.
passwort eingabemaske, alles in rot weil fehler: 

Falsches Sonderzeichen
Diese verwendeten Sonderzeichen sind
nicht erlaubt: 

Erlaubte Sonderzeichen: äÄöÖüÜ~!@#$%^&*()_-+={}[]|:;,.?/§\
@lilmikesf@c.im
2025-08-11 19:39:25

#UK Police Investigating #Handicapped Entrance #Security Scam At #Wembley After Hundreds Reportedly Gained Entry On Same

@frankstohl@mastodon.social
2025-09-24 15:05:01

New iPhone Air, iPhone 17, and iPhone 17 Pro have an anti-spyware feature #iphone #apple #spyware #security

@mgorny@social.treehouse.systems
2025-09-10 11:45:07

Here are some key takeaways from implementing #PyPI attestations in #Gentoo:
• With OpenPGP, you need to validate the authenticity of a key. With attestations, you need to validate the authenticity of the identity (i.e. know the right GitHub repository). No problem really solved here.
• They verify that the artifact was created by the Continuous Deployment workflow of a given repository. A compromised workflow can produce valid attestations.
• They don't provide sufficient protection against PyPI being compromised. You can't e.g. detect whether new releases weren't hidden.
On the plus side, TOFU is easier here: we don't have to maintain hundreds of key packages, just short URLs on top of ebuilds.
Security-wise, I think PEP 740 itself summarizes it well in the "rationale and motivation" section. To paraphrase, maintainers wanted to create some signatures, and downstreams wanted to verify some signatures, so we gave them some signatures.
#security #Python

@mgorny@social.treehouse.systems
2025-08-24 19:08:49

I've drafted support for verification of #PyPI provenance for #Gentoo.
You know, the new fancy thing that protects against supply chain attacks on PyPI, and verifies that you're using genuine #GitHub artifacts. Because, you know, GitHub repositories and deployment pipelines are an unlikely attack vector. And you definitely don't need to worry about #Microsoft owning the keys, the repositories and the pipelines at all.
#security #Python #SigStore

@mgorny@social.treehouse.systems
2025-08-23 10:26:37

Well, I am complaining about #AI slop introducing some random bugs in a minor userspace project, and in the meantime I learn that #Linux #kernel LTS developers are using AI to backport patches, and creating new vulnerabilities in the process.
Note: the whole thread is quite toxic, so I'd take it with a grain of salt, but still looks like the situation is quite serious.
"You too can crash today's 6.12.43 LTS kernel thanks to a stable maintainer's AI slop."
And apparently this isn't the first time either:
"When AI decided to select a random CPU mitigation patch for backport last month that turned a mitigation into a no-op, nothing was done, it sat unfixed with a report for a month (instead of just immediately reverting it), and they rejected a CVE request for it."
#security #LLM #NVIDIA #Gentoo

@midtsveen@social.linux.pizza
2025-09-14 13:06:33

Do you use #Orbot?
#Android #GrapheneOS #Privacy #Security #Tor #TorBrowser #Google #Apple #iOS
Yes
Yes, but...
No, but...
No