Salta al contenuto

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  • Exciting news.

    Mondo openpgp rust freebsd security smartcard yubikey nitrokey infosec
    2
    0 Votazioni
    2 Post
    0 Visualizzazioni
    hko@floss.social
    @Larvitz exciting indeed! Would be great to see these projects in the FreeBSD ports collection ❤️Cc @wiktor
  • 0 Votazioni
    1 Post
    5 Visualizzazioni
    ricardo@mastodon.bsd.cafe
    Jail chroot escape via fd exchange with a different jailCVE-2025-15576"Note that in order to exploit this problem, an attacker requires control over processes in two jails which share a nullfs mount in which a unix socket can be installed."https://www.freebsd.org/security/advisories/FreeBSD-SA-26:04.jail.asc#freebsd #jails #security
  • 0 Votazioni
    1 Post
    36 Visualizzazioni
    redhotcyber@mastodon.bida.im
    Chrome a rischio: due estensioni che prima erano “sicure” ora rubano i tuoi dati📌 Link all'articolo : https://www.redhotcyber.com/post/chrome-a-rischio-due-estensioni-che-prima-erano-sicure-ora-rubano-i-tuoi-dati/#redhotcyber #news #malware #security #chromemalware #cybersecurity #hacking #dataprivacy #navigatorisicuri
  • Hundreds of scientists say stop!

    Mondo agechecks privacy security ageverification
    13
    1
    0 Votazioni
    13 Post
    38 Visualizzazioni
    [[global:guest]]?
    @Tutanota and me that always said there is a simple way to do this without the need to rely on any third party crap to verify your identity.blockage at isp level of dns and vpn until the landlord proved he is adult (witch is stupid but hey), and once he ask the disablement of the blockage he signe (electronically) that he will manage the computer in his home (once ok the dns lock is lifted)for mobile it can be managed phone by phonewould be much more effective than the app / os level crap.
  • 0 Votazioni
    1 Post
    3 Visualizzazioni
    pitrh@mastodon.social
    A kiddie and their script, part N of N!Mar 9 17:54:52 skapet sshd-session[97161]: Failed password for invalid user %company% from 20.83.3.189 port 17677 ssh2#scriptkiddies #sshgropers #passwordguessing #cybercrime #ssh #security And if you need some reading material, https://nxdomain.no/~peter/hailmary_lessons_learned.html (or g-tracked https://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html)
  • 1Password is increasing its price 30%.

    Mondo askfedi security eucloud
    2
    0 Votazioni
    2 Post
    16 Visualizzazioni
    elena@aseachange.com
    @Jeremiah yeah I am staying with 1password because I'm afraid of migrating all my passwords and 2FA to Proton... all eggs in one basket sort of problem like, what happens if my account is compromised or I lose access to it? Best to keep passwords private from email/calendar/drive IMHO... and moving them to Bitwarden will take significant time so the slight price increase is ok for me as I value my time more. But keeping an open mind and may change stance in the future.Pricing aside, I love the UX/UI of 1Password across devices (computer / phone) over other offerings...
  • Good Idea: Make GrapheneOS Mainstream

    Mondo privacy opensource digitalrights tech security
    17
    0 Votazioni
    17 Post
    40 Visualizzazioni
    xz@ieji.de
    @fluttersh @MinistryOfGoodIdeas No, the main focus of the project is security and privacy while still being able to use Android apps like normal. There are other projects that don't focus on security, like LineageOS, but they don't offer optional confined Google Play services, only microG, a reverse-engineered implementation of Google Play services. So what you're asking here for is either a GrapheneOS fork with all security measures stripped, a LineageOS fork with optional Google Play services and Protect API and other features like storage scope implementation, or a complete new project based on AOSP that has this functionality. If you root your device, a lot of safety checks will fail, and therefore a lot of apps and functions will just not work. Therefore, I think no one will make an effort to get less app functionality and security. Less security means more attack surface to get your data leaked, which means you're also less private.
  • 0 Votazioni
    1 Post
    49 Visualizzazioni
    redhotcyber@mastodon.bida.im
    Buon compleanno a Gary McKinnon che compie 60 anni: l’hacker che sfidò la NASA in cerca degli UFO!📌 Link all'articolo : https://www.redhotcyber.com/post/hacker-famosi-la-storia-di-gary-mckinnon/#redhotcyber #news #hacker #security #nasa #ufo #extradizione #statunitensi #scozzese #cybersecurity #hacking
  • 0 Votazioni
    1 Post
    37 Visualizzazioni
    redhotcyber@mastodon.bida.im
    Il “Reddit per AI” progetta la fine dell’umanità e crea una Religione. Ecco la verità su Moltbook📌 Link all'articolo : https://www.redhotcyber.com/post/il-reddit-per-ai-progetta-la-fine-dellumanita-e-crea-una-religione-ecco-la-verita-su-moltbook/#redhotcyber #news #intelligenzaartificiale #socialmedia #security #cybersecurity #hacking #malware #vibecoding
  • ### Security Update: Hollo 0.6.19 Released

    Fediverso hollo security fediverse activitypub
    3
    0 Votazioni
    3 Post
    47 Visualizzazioni
    hollo@hollo.social
    セキュリティアップデート: Hollo 0.6.19 リリース FedifyのHTMLパースコードにおけるセキュリティ脆弱性に対応したHollo 0.6.19をリリースしました。 この脆弱性 (CVE-2025-68475) は ReDoS (正規表現によるサービス拒否) の問題であり、攻撃者がフェデレーション操作中に特別に細工されたHTMLレスポンスを送信することで、サービス停止を引き起こす可能性があります。悪意のあるペイロードは小さい (約170バイト) ですが、Node.jsのイベントループを長時間ブロックする可能性があります。 すべてのHollo運営者の皆様には、直ちにバージョン 0.6.19 へのアップグレードを強くお勧めします。 項目 詳細 CVE CVE-2025-68475 深刻度 高 (CVSS 7.5) 対応 Hollo 0.6.19 にアップグレード #Hollo #セキュリティ #fediverse #ActivityPub
  • 1 Votazioni
    1 Post
    40 Visualizzazioni
    fedify@hollo.social
    🚨 Security Advisory: CVE-2025-68475 A ReDoS (Regular Expression Denial of Service) vulnerability has been discovered in Fedify's HTML parsing code. This vulnerability could allow a malicious federated server to cause denial of service by sending specially crafted HTML responses. CVE ID CVE-2025-68475 Severity High (CVSS 7.5) Affected versions ≤1.9.1 Patched versions 1.6.13, 1.7.14, 1.8.15, 1.9.2 If you're running Fedify in production, please upgrade to one of the patched versions immediately. For full details, see the security advisory: https://github.com/fedify-dev/fedify/security/advisories/GHSA-rchf-xwx2-hm93 Thank you to Yue (Knox) Liu for responsibly reporting this vulnerability. #Fedify #ActivityPub #security #fediverse #fedidev
  • 0 Votazioni
    1 Post
    38 Visualizzazioni
    privacynews@mstdn.plus
    GrapheneOS migrates server infrastructure from France amid police intimidation claimshttps://www.privacyguides.org/news/2025/11/22/grapheneos-migrates-server-infrastructure-from-france-amid-police-intimidation-claims/#Privacy #Security #News #PrivacyGuides
  • 0 Votazioni
    1 Post
    34 Visualizzazioni
    linux@mastodon.nl
    ⚠️ Update Your Site I've noticed that many sites on the Fediverse are running very outdated versions of Mastodon or Misskey — sometimes more than a year old.Software updates don’t just add new features — they also include important security fixes. To keep your site secure and running smoothly, make sure you're using the latest version of your platform. #Mastodon #Missykey #Fediverse #ActivityPub #PixelFed #PeerTube #Loops #InfoSec #Security #InfoSecurity
  • 0 Votazioni
    1 Post
    42 Visualizzazioni
    peteorrall@mastodon.bsd.cafe
    Wow, the damage from that Red Hat GitLab breach seems to be getting worse by the day. Jeez.The Crimson Collective, the cybercriminal gang claiming responsibility for breaching the repo and stealing over 500GB of data, now seems to be collaborating with other cybercriminal gangs to extort Red Hat.From the article, the cybercrim alliance:"threatens to publish a "multi terabyte of data haul of your most sensitive intellectual property" and accuses Red Hat of failing to safeguard what it claims are trade secrets and personal data, invoking GDPR and US state privacy laws. It also reckons Red Hat's doors were kicked in on September 13 – weeks before the company came clean about the break-in."https://www.theregister.com/2025/10/07/red_hat_breach_new_claims/?td=rt-9bp#redhat #gitlab #news #technews #cyberattack #breach #cybersecurity #security #cybercrime #crime #extortion