Bucketsquatting is finally dead

The way CTRL-C in Postgres CLI cancels queries is incredibly hack-y

From virtio-snd 0-Day to Hypervisor Escape: Exploiting QEMU with an Uncontrolled Heap Overflow

OpenClaw is a security nightmare dressed up as a daydream

A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils CVE-2026-32746)

US Cybersecurity Adds Exploited VMware Aria Operations To KEV Catalog

Attempts to post the latest Trivy security incident have been marked [dead]

Semi-retirement, or, really, changing my relationship with the BSDs

First (?) hacked Emacs package

Trivy Compromised a Second Time - Malicious v0.69.4 Release

FCC Bans Imports of New Foreign-Made Routers, Citing Security Concerns

seccomp — Unsafe at any speed (2022)

Catching malicious contributions in open source repos

Closure of Hormuz is 'greatest global energy security threat in history'

Magic Link Pitfalls

NetBird - Open Source Zero Trust Networking

A GitHub Issue Title Compromised 4k Developer Machines

H&R Block tax software installs a TLS root certificate with bundled private key

Hardening Firefox with Anthropic's Red Team

You can't always fix it

Hardening Firefox with Anthropic's Red Team

Node.js — Developing a minimally HashDoS resistant, yet quickly reversible integer hash for V8

SSH Certificates and Git Signing

Full-Source Binary Seed Bootstrap of the Guix System (2023)

NTLM and SMB go opt-in in curl

Hacking the Xbox One

Perfect types with `setHTML()`

A Linux distribution designed to eliminate single points of failure

The first AI agent worm is months away, if that

My PostgreSQL database got nuked lol

More →