Mood: Unhackable anti-surveillance tech/stickers from @eff. https://shop.eff.org/ #privacy #security #ElectronicFrontierFoundation #EFF #NowMoreThanEver
security
🎉 Congratulations to Linux Vendor Firmware Service (https://fwupd.org/) (@hughsie) for securing the win in the Security category, sponsored by ControlPlane at the OpenUK Awards 2025!
#openukawards #opensource #security
I have drafted an email critical of the #digitalomnibus proposal in #EU from a wide-reaching privacy, #technology sector protection and #geopolitical risk standpoint.
Read here:
https://nx82858.your-storageshare.de/s/sBFL5CxHY7Yf3XC
Send to EU representatives with this list of emails:
https://nx82858.your-storageshare.de/s/xQogH6dXKifXfS6
If you care about #souvereignty #security and #privacy, please boost and take part in this #campaign !
Not really an #introduction but here we go:
#Freelancing #Privacy and #Security #Coach & #Trainer (#Linux)
Ex #SoftwareDeveloper, #Consultant, #TeamLead, #HeadOfProductDevelopment #HeadOfIT
I care for #privacy #HumanRights #DEI #TransRightsAreHumanRights #Linux #FLOSS #DigitalSelfDefense
See bio for links & websites.
Have you checked out our Summer Clearance Sale yet? Select back issues and products are 50% off through July 31st! Get 2024 and older issues of Linux Magazine, @adminmagazine, Special Issues, and select products. Follow the link for the shop for your region/currency.
https://shop.linuxnewmedia.com/shop/category/summer-clearance-79
#Linux #OpenSource #security #FOSS #LibreOffice #hacks #RaspberryPi
Are you interested in a different kind of security conference?
Then take a look at the Open Security Conference (@OSCo). #osco25 takes place from October 2 to 5 in Rückersbach (Germany near Frankfurt) and registration is still open at https://opensecurityconference.org/.
(this is an English version of the original German thread https://infosec.exchange/@realn2s/114936419689473030)
Why?
The Open Security Conference aims to be diverse and inclusive. This also includes different levels of knowledge and experience.
It is therefore not only for security experts or for people who have (already) worked in the security sector for a long time,
but also for people who are interested in security or want to get into the field.
The #OpenSpace format not only enables expert presentations,
but also non-expert topics or questions as session topics. Sessions are not resticted to presentations, they can be interactive, collaborative, workshops or basically anything else.
Since topics do not have to be submitted months in advance,
but the agenda is created jointly by the participants, hot topics can also be covered.
The conference is non-commercial, i.e. the total costs are shared between the participants (including the organizers).
The costs include accommodation and meals in the conference hotel.
And yes, there are also sponsors who cover part of the costs.
But not everything is different.
There are great keynotes e.g. by @bkastl ("History repeating itself") and Mireia Cano ("Building an AppSec Program from Scratch").
#CyberSecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity
The war on crypto never ends. The war on privacy, civil rights, security and freedom of speech never ends.
This time we are dangerously close to lose. The "Child Sexual Abuse" (CSA) EU regulation proposal, more aptly nicknamed "ChatControl", will be voted AGAIN this October, and many countries who opposed it last year are now undecided. The proposal at its roots aims at allowing authorities to break end-to-end encryption for the usual reason: "because of the children". As a father of two, I am disgusted by this recurring, cheap rhetoric.
What you can do: https://www.patrick-breyer.de/en/posts/chat-control/#WhatYouCanDo
#eu #CSA #CSAM #ChatControl #privacy #security #surveillance #authoritarianism #crypto #cryptography #civilrights
Meine IT Sicherheits-Privatsphäre Übersicht für alle :-)
( 05.08.2025
Die weiterentwicklung von #GalyxOS stagniert
wohl erstmal...)
als PDF:
https://cryptpad.digitalcourage.de/file/#/2/file/Kvo0eIWc8SfCJYXTxujy+YlD
sachliches-Feedback wie immer, erwünscht :-)
#Privatsphäre #Datenschutz #sicherheit
#security
#AppStore
#Kryptografie
#Passwort #PasswortManager #Informationssicherheit #Informationsfreiheit #IFG #Politik #Gaming #gog #Lutris #Android
#Mail #Cloud #Browser #WebBrowser #Verschlüsselung #DNS #VeraCrypt #Fdroid #Messenger #Threema #Signal #Linux #Foss #OpenSource #UnplugTrump #Fediverse #Menschenrechte #Community #LinuxHelden
#GamingonLinux #VPN #GegenRechtsHilfe #FediLZ #Mastodon #Shopping #PreppingforFuture #Prepping #Katastrophenvorsorge #Schutzmaßnahmen #supportyourhinterland #Mobilfunk #NewPipe #uBlock #Medienkompetenz #Facebook #Instagram #Meta #YouTube #Chatkontrolle #überwachung #Matrix #Suchmaschine #Tastatur #2FA #Nichtszuverbergen
🔒 Security Update for BotKit Users
We've released #security patch versions BotKit 0.1.2 and 0.2.2 to address CVE-2025-54888, a security #vulnerability discovered in #Fedify. These updates incorporate the latest patched version of Fedify to ensure your bots remain secure.
We strongly recommend all #BotKit users update to the latest patch version immediately. Thank you for keeping the #fediverse safe! 🛡️
We've released #security updates for #Hollo (0.4.12, 0.5.7, and 0.6.6) to address a #vulnerability in the underlying #Fedify framework. These updates incorporate the latest Fedify security patches that fix CVE-2025-54888.
We strongly recommend all Hollo instance administrators update to the latest version for their respective release branch as soon as possible.
Update Instructions:
Railway users: Go to your project dashboard, select your Hollo service, click the three dots menu in deployments, and choose “Redeploy”
Docker users: Pull the latest image with docker pull ghcr.io/fedify-dev/hollo:latest and restart your containers
Manual installations: Run git pull to get the latest code, then pnpm install and restart your service
***infosec specialists are needed in the resistance ***
The world needs tech security specialists to run workshops at public libraries for all ages & abilities to remove spyware, AI, reduce surveillance, understand the issues, & for more advanced, move to Linux, degooglefy, etc.
Libraries will pay good wages for these workshops.
If you have these skills, please consider offering them.
#libraries #library #tech #infosec #privacy #security #activism #antifa #resistance
Following the success (sarcasm!) of my previous post "Battle of IMs", I decided it's time to write another post where I try to articulate in a technical but snarky way my view on the wonderful world of social media, and which one is best among the mainstream and non-mainstream ones. This is a long post, reviewing 14 different "socials".
https://gagliardoni.net/#20250818_battle_of_socials
#socialmedia #social #privacy #selfsovereignty #security #digitalsovereignty #mastodon #nostr #bluesky #ssb #securescuttlebutt #facebook #meta #tiktok #threads #x #twitter #diaspora #friendica #linkedin #xing #instagram
Don't #Hang Up On #AI #Scammers. Do THIS Instead. #Kitboga #yt #satire #comedyGold #privacy #security
https://youtu.be/lk3jCuITwcE 🤣🤣🤣🤣🤣🤣
#captcha #SecurityTheater #infosec #CyberSecurity #security #tech #dev #internet #web
🔒 Security Release: BotKit 0.3.1
We've released BotKit 0.3.1 with an important security fix.
This update addresses CVE-2025-68475 (High severity, CVSS 7.5), a ReDoS vulnerability in Fedify's HTML parsing that could cause denial of service.
If you're using BotKit 0.3.x, please upgrade to 0.3.1 as soon as possible.
Security Update: Hollo 0.6.19 Released
We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.
This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.
We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.
FieldDetailsCVECVE-2025-68475SeverityHigh (CVSS 7.5)ActionUpgrade to Hollo 0.6.19Today, I had the pleasure of meeting @HennaVirkkunen , the #EU Commission Vice President in charge of Tech Sovereignty, #Security & #Democracy, at the invitation of the Austrian Chancellery and Digital State Secretary Alexander Pröll, at their summit on 🇪🇺 #digitalsovereignty
Together with @c3wien, @WikimediaAT, @epicenter_works & @dpgalliance we are calling for open protocols & #interoperability to be strengthened when building public digital infrastructure ✨
#Fedidiplomacy
#Fediforum
Hey Fediverse, I wrote a little book (#noai).
It's got beavers, snow, surf, games, coding, data entry, literary references, masks, vaccines and a race to the airport!
It's total FREE! And I'll even mail anyone a copy on request (see about).
<18k words.
https://2qx.github.io/monterey-protocols
#vermont #elbowsup #maskup #vaccines #smallpox #nonproliferation #books #publichealth #nurses #healthworkers #opsec #security
Somehow bot-detecting algorithms have been degrading over time.
This is a troubling trend because people who aren't using the anointed access points of the internet struggle more and more to connect and interact. Large entities like CloudFlare choke off more and more avenues of access in the name of "security", enforcing digital checkpoints without any accountability to anyone.
#dev #tech #web #bot #DarkPattern #security #infosec #cybersecurity #checkpoint
🇦🇹 Austria's Armed Forces have replaced MS Office with LibreOffice on 16,000+ workstations 📄
This shift began in 2020 to avoid mandatory cloud reliance ☁️
Their goal? Digital sovereignty—not cost saving 🔒
They even contributed 5+ person-years of code 🛠️
EU trend toward open-source grows 🇪🇺
🔗 https://news.itsfoss.com/austrian-forces-ditch-microsoft-office/
#TechNews #LibreOffice #Linux #OpenSource #Privacy #FOSS #Security #Europe #EU #Microsoft #Cloud #DigitalSovereignty #Government #Defense #Innovation #Technology
Counterterrorism Czar’s Blueprint Targets Leftists, Ignores Far-Right Violence and Heaps Praise on Trump
---
Sebastian Gorka’s anti-terror plan makes no mention of long-established threats posed by far-right militants and instead villainizes the president’s political enemies. “This administration is not paying attention to the data,” one expert said.
https://www.propublica.org/article/trump-counterterrorism-plan-ignores-far-rights-gorka?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post
#News #Terrorism #Trump #USPolitics #Violence #Security #Extremism
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Email addresses
Names
Country
Date of birth (they call it "borned_date" lol)
Account role (it's "PRAYER" for everyone, obviously)
Also found:
Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Yes. Yes, you've seen correctly. There's going to be an Open Security Conference 2026! 😍
🗓 Save the dates: November 5-8, 2026. ✅
https://opensecurityconference.org/
#osco #osco26 #CyberSecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity #OpenSpace [lisi]
🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS

🐦🔥nemo™🐦⬛ 🇺🇦🍉