Salta al contenuto

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  • 0 Votazioni
    40 Post
    0 Visualizzazioni
    gglockner@social.seattle.wa.us
    @newstik @fazalmajid @briankrebs Hopefully the dehumidifier doesn't send usage reports, unlike "smart" TVs.
  • BotKit security updates: 0.4.5 and 0.5.1

    Mondo botkit security
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    botkit@hackers.pub
    If you use BotKit, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, and BotKit includes the affected Fedify versions as a dependency. Fedify can look up a remote server's NodeInfo document to learn what software it runs. The lookup first fetches the server's /.well-known/nodeinfo document, then follows the NodeInfo document URL advertised in that response. The vulnerable paths are getNodeInfo() and the Context.lookupNodeInfo() method that wraps it: affected versions sent both requests without checking that their destinations were on the public internet. Because the second URL comes from the remote server's response, an attacker who controls a server being looked up could point it at a loopback address, a link-local cloud metadata endpoint, an RFC 1918 host, or a data: URL. Depending on the deployment environment and network routing, this could cause a BotKit application that looks up NodeInfo to fetch non-public network resources and return their contents to the application. The fix routes both requests through Fedify's public-address validation. It checks every request before sending it, including each redirect hop, limits the number of redirects, refuses redirects that cross protocols, and rejects non-HTTP(S) URLs. Servers are exposed only if they look up remote NodeInfo, but such lookups are commonly used for peer discovery and instance metadata. BotKit 0.4.x versions through 0.4.4 and BotKit 0.5.0 are affected. Patched releases are 0.4.5 and 0.5.1. BotKit 0.4.5 uses Fedify 2.1.19, and BotKit 0.5.1 uses Fedify 2.3.3. For BotKit 0.5.x, update @fedify/botkit: npm update @fedify/botkit yarn upgrade @fedify/botkit pnpm update @fedify/botkit bun update @fedify/botkit deno update @fedify/botkit For BotKit 0.4.x, update @fedify/botkit: npm update @fedify/botkit@0.4.5 yarn upgrade @fedify/botkit@0.4.5 pnpm update @fedify/botkit@0.4.5 bun update @fedify/botkit@0.4.5 deno update @fedify/botkit@0.4.5 After updating, redeploy. The GitHub Security Advisory is GHSA-hqph-j65v-8cq5, and the CVE ID is CVE-2026-62857. See also Fedify's own announcement. Thanks to @rvzsec and @manus-use for the report and responsible disclosure. If anything is unclear, feel free to ask on GitHub Discussions or Matrix.
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    fedify@hackers.pub
    If you use Fedify, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client. An attacker who runs any instance your server looks up could cause that server to fetch non-public network destinations and return their contents to your application, depending on the deployment environment and network routing. Fedify can look up a remote instance's NodeInfo document to learn what software it runs. The lookup happens in two steps: it fetches the instance's /.well-known/nodeinfo document, then follows the NodeInfo document URL that response advertises. The vulnerable path is getNodeInfo(), along with the Context.lookupNodeInfo() method that wraps it: affected versions sent both requests without validating the destination against public-network expectations. Because that second URL comes straight out of the remote server's response body, the instance being looked up fully controls it, and could point it at a loopback address, a link-local metadata endpoint, an RFC 1918 host, or a data: URL. Servers are exposed only if they look up NodeInfo, but that lookup is routine for peer discovery and instance metadata. The fix routes both requests through the same public-address validation Fedify already applied to WebFinger lookups and remote document loading. Every request is now checked before it is sent, including each redirect hop, so a public URL cannot bounce a request to an internal address. Redirects are followed with a cap and are refused if they cross protocols, and non-HTTP(S) URLs such as data: are rejected outright. These are patch releases, so they tighten behavior without adding new API. If you deliberately look up NodeInfo on a private or intranet address, such as in a closed federation or a test environment, these releases will now refuse it. An allowPrivateAddress opt-out is coming in 2.4.0. Current patched releases are 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. The GitHub Security Advisory is GHSA-hqph-j65v-8cq5, and the CVE ID is CVE-2026-62857. Update @fedify/fedify: npm update @fedify/fedify yarn upgrade @fedify/fedify pnpm update @fedify/fedify bun update @fedify/fedify deno update @fedify/fedify After updating, redeploy. If you run other Fedify-based servers, update those too. Thanks to @rvzsec and @manus-use for the report and responsible disclosure. If anything is unclear, ask below.
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    h4ckernews@mastodon.social
    Briar Is in Maintenance Modehttps://briarproject.org/news/2026-maintenance-mode/Comments: https://news.ycombinator.com/item?id=48919869#HackerNews #Briar #Maintenance #Mode #Technology #Privacy #Security #OpenSource
  • 0 Votazioni
    21 Post
    0 Visualizzazioni
    prometheus@pmth.us
    Apple Product Security has time to monitor Twitter for disclosure posts but not to send a status update to the person who found the bug. The incentive structure is working exactly as designed.
  • 0 Votazioni
    44 Post
    0 Visualizzazioni
    rrr@deds.social
    @Tutanota I don't understand the 'score' for each European parliament member on the website https://fightchatcontrol.eu When I check the profile of a Dutch PvdA (thus S&D) representative it says 'supports'. The contrary of what one would expect. But in the details it says 'Chat Control 1.0 Extension - supports' and 'Chat Control 2.0 - Opposed'What is this about?
  • 0 Votazioni
    15 Post
    0 Visualizzazioni
    nonilex@masto.ai
    The election changes #Trump is seeking could be enormously #expensive for #states. For instance, the nationwide cost of upgrading #election equipment to align with voluntary voting standards has been estimated at $2.7 billion.In #Georgia, where the state legislature has also passed a #law to require hand-marked paper ballots, Republican Secy of State Raffensperger has estimated it will cost $66 million.#US #Constitution #VotingRights #TrumpCoup #midterms #BigLie #MafiaState #WhiteSupremacy
  • Today I released Lockpicker.

    Mondo gnome opensource security flathub
    1
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    sstendahl@floss.social
    Today I released Lockpicker. Lockpicker is essentially a GUI frontend to hashcat. Recover a password from its hash straight from a modern GNOME-native interface without the hassle of dealing with hashcat syntax.Early release. It still has a few rough edges UI-wise, where I probably want to do a pretty major overhaul eventually. I also need to redo the logo properly. But it works quite well, comes with OpenCI GPU acceleration. https://flathub.org/en/apps/se.sjoerd.lockpicker#GNOME #OpenSource #security #Flathub
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    riffraff@mastodon.social
    oh I got some really good scam attempt following the booking.com hack!I have an accommodation booked for this summer, and I received a message via whatsapp to update some details for the reservation.Not uncommon, but then they also asked for my CC, which they do not need since I’ll be paying through booking.So I got suspicious, called the hotel and they indeed denied any involvement.Be wary, just in case it happens to you too.#security #bookinghack
  • Chi si sta cagando addosso alzi la mano!

    Mondo linux arch archbtw aur security
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    sub078@mastodon.uno
    Chi si sta cagando addosso alzi la mano!https://kerberos.archathome.eu/pacchetti-aur/@linux @linux@diggita.com #linux #arch #archBTW #aur #security
  • 🚨 #FreeBSD Patching time!

    Mondo freebsd security
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    alelab@mastodon.bsd.cafe
    🚨 #FreeBSD Patching time! ⌨️It takes less time to install security patches on your systems than prepare the coffee ☕️ And install these also on your VMs and jails too.#FreeBSD #Security
  • 0 Votazioni
    14 Post
    0 Visualizzazioni
    evan@cosocial.ca
    Second thing: my answer is yes. I have used Dependabot (dependencies) and CodeQL (own code) on GitHub for most of my projects for years. Scanning with LLMs seems to work even better. I have found it effective with off-the-shelf models. I don't have access to Mythos, but when I do I will probably run it, too.
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    gyptazy@gyptazy.com
    AI assisted pen testing, coding and arising secvulns. Are we humans still good enough?the last weeks we saw more and more security issues coming up. Let's talk!Sorry, a pretty long blog post about this...https://gyptazy.com/blog/coding-after-ai-are-humans-still-good-enough/#ai #aicoding #coding #opensource #foss #security #infosec #vulns #developer #devops #engineer #ops #fedi #philosophy
  • Oh right.

    Mondo windows security bitlocker fde disk encryption bypass
    4
    0 Votazioni
    4 Post
    0 Visualizzazioni
    h3artbl33d@exquisite.social
    @malte Guess so. Target needs to be rebooted to recovery. Just an additional boot required, doesn't require an unlocked drive AFAIK.
  • Copy Fail, Dirty Frag and now Fragnesia...

    Mondo linux security vulnerabilities
    8
    0 Votazioni
    8 Post
    0 Visualizzazioni
    h3artbl33d@exquisite.social
    @sigsegv44 Even more reason to run #OpenBSD and #HardenedBSD!
  • Today I spoke with someone I've known for a very long time.

    Mondo security
    4
    0 Votazioni
    4 Post
    0 Visualizzazioni
    s1m0n4@ohai.social
    @stefano I don't open traditional social media anymore. Not since I decided to quit every popular platform after I saw a scammer investment ad and feared for my safety. I was about to fall for it and I am even a bit ashamed to admit it. Now with LLMs these risks incremented exponentially.This isn't a world I trust.
  • 0 Votazioni
    2 Post
    0 Visualizzazioni
    filobus@sociale.network
    @TheConversationUS and tour face can be easily extorted from you by force and by law, so your data can be taken by those using force or by government (often they are the same)
  • 0 Votazioni
    15 Post
    0 Visualizzazioni
    elena@aseachange.com
    @joel brilliant idea… but I wonder if it would take me less than 3 years to pull it off 😅 @mischa
  • Well, wow

    Mondo linux security
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    riffraff@mastodon.social
    Well, wowhttps://xint.io/blog/copy-fail-linux-distributions#how-this-happened-3#linux #security
  • How Hard Is It To Open a File?

    Mondo security unix
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    lobsters@mastodon.social
    How Hard Is It To Open a File? via @PolyWolf https://lobste.rs/s/fbfu56 #security #unixhttps://blog.sebastianwick.net/posts/how-hard-is-it-to-open-a-file/