2026-07-19 16:55:05
After reading about today's #Github #security incident, exposing thousands of internal repositories, I'd like to remind you of:
Read That Before You Trust Anything by #Microsoft Once Again
The way #qemu handles #security bugs is changing. Routing the recent tsunami of reports through an overworked email alias has become untenable so we are switching to using our main issue tracker. More people can help with the triage but that does affect expectations of secrecy. See the updates on the …
I'm going to deviate a bit from my normal audience and focus in on #tech (especially #Security folks). I came across the practice from public health and emergency management and brought it into work. They seemed to have never heard of it. I'm curious how common my experience is. (Please boost for visibility)
Have you ever used table top exercises in your work (such as, to verify a runbook would work as expected)?
Nancy Beers' keynote at #SecurityDays 2026 had the whole room on its feet, playing games and laughing together.
We spoke with her recently to learn more about what "Play More Today. Secure Tomorrow" means for security culture, from how a simple box of LEGO bricks can make abstact discussions come alive, to why she believes cybersecurity can't exist in silos.
🔗 Re…
Legislation cares a lot about information #security these days. When do we laws that keep companies from tainting security's public reputation by demonstrably abusing it for their own commercial interest against the interests of consumers?
Just one example: Bank uses proprietary hardware over #WebAuthn
More than mildly alarmed listening to this episode on the #Arctic #Europe and #Russia #Ukraine and #HybridWar, #Security and lots of other very very interesting items. *Essential* listening for anyone concerned with European security.
Mildly Alarmed: Russian nukes and spies in the Arctic, with The Barents Observer
https://podcasters.spotify.com/pod/show/mildly-alarmed/episodes/Russian-nukes-and-spies-in-the-Arctic--with-The-Barents-Observer-e3l00hr
Media file: https://anchor.fm/s/111aff124/podcast/play/121683963/https://d3ctxlq1ktw2nl.cloudfront.net/staging/2026-5-18/426419250-44100-2-05b100b5043df.mp3
#Webmention for Craft v1.3.0 is out 🎉 – first in a short series of #security releases. 🔒
Fixes a stored XSS vulnerability in author/entry URLs, adds per-IP rate limits, and failure-backoff to harden the public endpoint against abuse.
Upgrade recommended!
OK. With Bitwarden acting every bit the American company it is, are there any drop-in replacements out there? Preferably standalone rather than part of a package. #security #passwordmanager
It's always important to have a consistent #security policy.
For example, a policy of "If somebody filed a CVE, it's an important security issue, and we will fix it as such, no matter how meaningless the fix is. If nobody did, it's just a glorified bug fix, no matter how serious the bug was."
So we've just seen a #pip security release over "installing random packages can overwrite pip's files and pip can lazy-import some of them immediately afterwards", with a fix of "pip will no longer load them until you run it again" (leaving the underlying security issue of "any #Python package can override files installed by any other Python package" as intended behavior). As Eli Schwartz beautifully put it, you are not expected to be using the virtual environment; you should create it, install packages into it (at most once!), and then frame it and put it on the wall to admire.
Now we're seeing a "bug fix" for "malicious entry point names can write outside of virtual environment". If nobody filed a CVE, it's obviously not a security issue at all. At least upstream graced us with fixing it without correcting the spec to forbid that first.
https://github.com/pypa/pip/issues/14000
"The TSA has an important job to do. Their actions at airports have been very poor. This creates lots of loss to travelers – waste. And their actions show a disrespect for people and the risks that exist. The #security theater is not what we need. We need evidence based security measure while maintaining a focus on the value stream of people flying."
I can't stop saying the NVRAM vars are a tough #UEFI attack surface, and if processed wrong, may undermine all #security:
https://kb.cert.org/vuls…
📷 #SecurityDays 2026, captured!
The official photos are now online! So whether you want to spot yourself mid-workshop, share a favorite keynote moment, or relive the energy of three days in Utrecht, we've got you covered.
🔗 Browse the photo gallery:
Everyone loves jeering at vibecoded #GitHub being down all the time. Yet for some reason people still neglect to question making #Microsoft the primary guarantor of their software's supply chain #security. And the whole attestation nonsense that doesn't really protect against the most likely attack vectors.
Dependency cooldowns are a nice idea, but I dare say they're a short-term solution.
They resemble the idea of avoiding poison by waiting for someone else to start eating first. That works, provided that someone actually eats first, and that the poison works fast. But eventually it leads to that awkward silence at the table when nobody wants to risk the first bite.
Adapting dependency cooldowns means basically waiting for "someone else" to notice the problem. At some point when large enough number of projects adapts them, we're going back to square one — except with an artificial few-day delay.
#security #FreeSoftware
Absolutely fascinating on the philosophy, past, present and future of nuclear deterrence in Europe.
Much I had not previously thought about.
Also, brilliant name for a podcast on European security
#MildlyAlarmed #Deterrence #Russia #EU #security #nuclear
Mildly Alarmed: Inside Europe's debate about nukes
Episode webpage: https://podcasters.spotify.com/pod/show/mildly-alarmed/episodes/Inside-Europes-debate-about-nukes-e3joh7h
Media file: https://anchor.fm/s/111aff124/podcast/play/120390321/https://d3ctxlq1ktw2nl.cloudfront.net/staging/2026-4-22/424693918-44100-2-d995403c2e093.mp3
Honestly, what kind of scam #Akamai / #LInode is? They give you a form to report malicious activity from their network, you file it, you get "Error message to be decided", and it turns out they've banned you in the meantime; all their websites give you "Access denied".
And they host an exploit since 2021 at least: #security #abuse
#Python #cryptography library (yes, the one that criticizes everything and everyone) is now vibecoded. Our future is truly bright!
Noticed because apparently "Claude" wrote a test that OOM-ed my system. But hey, #RustLang protects against memory errors, so it's fine to vibecode your security critical components.
#security #AI #LLM #NoAI #NoLLM
So you read about #CopyFail, and are like… owww, shit. But then you see that it was responsibly disclosed after being fixed in main, we had releases since, they went stable in #Gentoo (over other #security fixes), so we should be good, right?
Except that it turns out that after it has been fixed in mainline, nobody bothered actually backporting the fix to all the LTS branches. And it doesn't apply cleanly (#Gentoo #Linux
Tech companies seem to be running a cycle:
1. They don't realize how much they're relying on volunteer-maintained projects.
2. Something bad happens and they suddenly decide they need to support this critical infrastructure, often by hiring some people behind it and making its maintenance part of their dayjob.
3. They realize they could save money by exploiting volunteers to maintain these #OpenSource projects. They lay workers off or move them to other projects.
4. Go to 1.
Except now they're trying to replace workers with slop machines, deskill everyone and basically they're not only poisoning the well, but killing the whole water cycle. And they're realizing that they just gave the bad people a tool that can quickly find just how vulnerable their critical infrastructure is.
Really appreciate the long-term thinking there.
#FreeSoftware #FLOSS #TechBros #AI #LLM #NoAI #NoLLM #Linux #security
Greg Kroah-Hartman: "If you look there are thousands of unfixed CVEs in the older LTS kernels right now, and if distros or users that rely on those older branches wish to see those resolved, they need to provide working backports to us to apply, as our first attempt did not work (which is why they are unfixed in those branches.)"
Really asking for a "Pray tell us", given that nobody actually bothered disclosing the problem to downstreams and that the commit message was hiding it.
Either way, apparently the great LLM-backed patch backporting process that #NVidia is so proud of doesn't really work. Upstream doesn't really care about #LTS branches, and they should be considered insecure by default.
#Gentoo #Linux #CopyFail #security