Menu

#Security

5037 posts

1 point
Feed·
20 of 5037 posts
Inside ZCode: Silently Uploading Your Entire Git History to the Cloud
🖼️
0

Inside ZCode: Silently Uploading Your Entire Git History to the Cloud

Code is cheap, let's talk·ferstar·18 days ago
#68ZclJ9y

ZCode silently packages entire workspaces and full Git history to the cloud with a server-only key; this post reconstructs the upload pipeline, gives a filesystem lock, and checks Z.ai's Repo Wiki response — the credential API now 404s, but destruction…

15s
Read More
We wanted to use Baseten for inference. We ended up with admin access to Baseten GitHub repos
🖼️
0

We wanted to use Baseten for inference. We ended up with admin access to Baseten GitHub repos

Hacker News·21 days ago
#quYAg098
#strix#baseten#security#github#article#ama

We gave Strix a domain. In 25 minutes, it found a live token with admin access to Baseten's product, deployment, and CLI repos in a public Docker image.

15s
Read More
Apple Reference Image: A New Approach for Verified Photography - Apple Security Research
📰
0

Apple Reference Image: A New Approach for Verified Photography - Apple Security Research

Hacker News·21 days ago
#RZBHZu5v

Introducing Apple Reference Image, a new solution for verifiable photography on iPhone. This new, opt-in camera mode lets a photographer create a securely timestamped reference image that accurately depicts what was captured by the iPhone's camera sensor.…

15s
Read More
we have a year to fix security everywhere
🖼️
0

we have a year to fix security everywhere

Hacker News·29 days ago
#lmGGMTAs
#jyn#security#ai#llm#article#ama

consumer-grade hardware can run an LLM that hacks the planet. we can stop it, but we don't have much time.

15s
Read More
Just a rumour of a bug is enough to find a security exploit these days
🖼️
378

Just a rumour of a bug is enough to find a security exploit these days

Hacker News·about 1 month ago
#6Zpm0rim
#anil#security#path#agentic#cohttp#article

Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond

15s
Read More
When str.lower() is a security vulnerability in Python
📰
178

When str.lower() is a security vulnerability in Python

Hacker News·about 1 month ago
#sby7P6M3

Some internet standards only support ASCII characters, but the world uses much more than the Latin alphabet. Thus, a mapping from Unicode to ASCII for use in domain names is required. NamePrep was...

15s
Read More
📰
0

TLS 1.2 is in Feature Freeze

www.rfc-editor.org·Rich Salz·2 months ago
#S2EFeufU
#tls#tls12#rfc9851#ietf#security#article

Use of TLS 1.3, which fixes some known deficiencies in TLS 1.2, is growing. This document specifies that no changes will be approved for TLS 1.2 outside of urgent security fixes (as determined by TLS Working Group consensus), new TLS Exporter Labels, and…

15s
Read More
Stronger with every update: How we’re making Chrome and the web safer in the AI Era
🖼️
585

Stronger with every update: How we’re making Chrome and the web safer in the AI Era

Hacker News·2 months ago
#GISCO3Yx

Chrome uses Gemini AI to automate vulnerability discovery, triage, and patching, accelerating updates to match modern security risks.

15s
Read More
Hacker wipes Romania's entire land registry database
🖼️
0

Hacker wipes Romania's entire land registry database

Hacker News·3 months ago
#Zbx53aeu
#news#security#last#group#article#audio

In other news: Graykey maker sues former employee for leaking exploit; Hugging Face was hacked using AI; unauth RCE finally found in WordPress.

15s
Read More
Qubes OS Security in the Public Record
🖼️
0

Qubes OS Security in the Public Record

Hacker News·3 months ago
#fBYg7K27

Qubes OS is a revealing case for security measurement because its architecture makes component boundaries security-relevant. We present a protocol-driven longitudinal analysis of 109 public Qubes Security Bulletins (QSBs, 2011--2025), the official…

15s
Read More
Meta Pauses Employee-Tracking Program Following Internal Data Leak
🖼️
339

Meta Pauses Employee-Tracking Program Following Internal Data Leak

Hacker News·3 months ago
#CfuGEaSc
#wired#meta#workers#employees#security#photo

The move comes after the company left potentially sensitive data from the initiative exposed internally.

15s
Read More
Anthropic’s powerful Mythos AI reportedly breached ‘almost all’ NSA classified systems within a few hours during red-team test — report sheds more light on the U.S. government's sudden ban on the flagship models
🖼️
3

Anthropic’s powerful Mythos AI reportedly breached ‘almost all’ NSA classified systems within a few hours during red-team test — report sheds more light on the U.S. government's sudden ban on the flagship models

Access to Fable 5 and Mythos 5 barred for foreign nationals immediately following security evaluation

15s
Read More