I submitted a Pull Request to update MacPorts' LibreSSL to 4.3.2 here:

https://github.com/macports/macports-ports/pull/32865

GitHub Continuous Integration checks passed OK!

It's up to someone else with commit access to merge it.

I also created a submission for undeadly.org though I will leave it up to one of the other editors to check it for any errors and publish it. The HTML validator at least seems to think I did OK (phew!).

#LibreSSL #MacPorts #TLS #TransportLayerSecurity #SSL #SecureSocketsLayer #OpenSSL #OpenSource
libressl: update to 4.3.2 by artkiver · Pull Request #32865 · macports/macports-ports

Description Type(s) bugfix enhancement security fix Tested on macOS 26.5 25F71 arm64 Command Line Tools 26.5.0.0.1777544298 Verification Have you followed our Commit Message Guidelines? ...

GitHub
nginx

nginx

Let's Encrypt support landed on Ubiquiti. Finally!

#acme #letsencrypt #tls #ubiquiti #unifi

https://youtu.be/EvUwr9GUXtg

It's About Time Ubiquiti

YouTube

MTProxy jumper — делаем автоматическое переключение прокси-серверов Telegram

В свете последних новостей вокруг Telegram провела некоторые эксперименты с протоколом MTProxy. Основная идея: сделать ПО, выглядящее для Telegram-клиента как MTProxy-сервер, и осуществляющее дальнейший обмен данными со сторонними MTProxy-серверами. В идеале, эти сторониие серверы должны обнаруживаться автоматически, и переключение между ними тоже должно происходить автоматически.

https://habr.com/ru/articles/1039034/

#Telegram #MTProto #TLS #прокси #DPI #блокировка #MTJumper

Laravel Lang Compromised with RCE Backdoor Across 700+ Versions

Community-maintained Laravel Lang packages were compromised with remote code execution backdoors affecting over 700 versions across multiple repositories including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. The attack involved coordinated rapid tag publishing on May 22-23, 2026, suggesting organization-level credential compromise. A malicious helpers.php file was automatically executed via Composer's autoloader, deploying a sophisticated cross-platform information stealer. The second-stage payload systematically harvested credentials from cloud infrastructure, Kubernetes, CI/CD systems, browsers, password managers, cryptocurrency wallets, VPN clients, and local configurations. Stolen data was encrypted and exfiltrated to a command-and-control server. The backdoor employed advanced evasion techniques including TLS verification bypass, per-host execution markers, and embedded Windows executables to bypass Chrome encryption protections.

Pulse ID: 6a1187d92cdbfd79095008cd
Pulse Link: https://otx.alienvault.com/pulse/6a1187d92cdbfd79095008cd
Pulse Author: AlienVault
Created: 2026-05-23 10:56:25

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Browser #Chrome #Cloud #CyberSecurity #Encryption #HTTP #InfoSec #OTX #OpenThreatExchange #PHP #Password #RAT #RCE #RemoteCodeExecution #TLS #VPN #Windows #Word #bot #cryptocurrency #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

#DHCP, #DNS, #IPv6, #TLS: Ihr seid anstrengend.

#pihole ignoriert nach Update standardmäßig die eigene dnsmasq-Konfiguration. Alle Hosts bekommen zwei IPv6-Gateways: Router und Pi-hole. Ziemlich zufällig wirkend hängen dann Verbindungen.

#Docker Compose-Setup mit #Coolify: Anfragen wechseln zwischen den Umgebungen, weil es kein Docker-Netz pro Umgebung gibt und per DNS-Round-Robin Anfragen zufällig an Apps verteilt werden.

#Traefik aktualisiert Zertifikate auf Basis von 2160 Stunden Gültigkeit (änderbar mit acme.certificatesDuration). #step-ca gibt Zertifikate aus, die 24 Stunden gültig sind (änderbar über authority.claims.{max,default}TLSCertDuration). Kein Wunder, dass das ganze Setup einen Tag später nicht mehr läuft.

Usw. usf.

How to Use Let's Encrypt TLS Certificates on GoDaddy

Learn how to Use Let's Encrypt TLS Certificates on GoDaddy Shared Hosting. Create, deploy, and automatically renew with acme.sh.

Bob's Pages of Travel, Linux, Cybersecurity, and More

Die Telekom hat einen Dienst der sich 'Security OnNet' nennt. Der bricht die Zertifikatskette auf und injected ein eigenes Zertifikat, leitet Netzverkehr über eigene Routen um und blockiert somit bestimmte Seiten.
Haben das nur bemerkt, weil ein Kunde von uns der Mailserver weg geblockt wurde.

Keine Ahnung wie das funktioniert aber schon scary.

Scheinbar zielt der Dienst besonders gerne auf mailcow Dienste.

https://onnet.telekom.de/portal/telekom-de/blocking

#telekom #blocking #tls

Portal