Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica
The most severe Linux threat to surface in years catches the world flat-footed

CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.

Ars Technica
The Internet Was Weeks Away From Disaster and No One Knew

YouTube
they hacked CSS

Get a 14-day FREE trail of flare at https://go.lowlevel.tv/flare2026 . See if you or your company's data is floating around the dark web.🏫 MY COURSESSign-up...

YouTube

You Have Been LaTeXpOsEd: A Systematic Analysis of Information Leakage in Preprint Archives Using Large Language Models
https://arxiv.org/abs/2510.03761

Research uncovered thousands of personally identifiable information (PII) leaks, GPS-tagged EXIF files, publicly available Google Drive and Dropbox folders, editable private SharePoint links, exposed GitHub and Google credentials, and cloud API keys. They also uncovered confidential author communications, internal disagreements, and conference submission credentials, exposing information that poses serious reputational risks to both researchers and institutions.

(Real-world credential leakages
from comments are manually reviewed and verified)

#netsec #compsec #science #research #arxiv

@fesshole
I guess it's all part of natural selection weeding out the idiots who go with default passwords.
#compsec
@pawanjswal
On a related subject, has anyone else noticed that #Proton seem to be blocking their own Onion address today?!
🤪
#JustSaying #email #ProtonMail #compsec #comsec

I think my mail greylisting saved me from a scam.

I received lot of mails today about accounts someone supposedly created for my mail address on dozens of sites and about as many newsletter subscription confirmation mails.

I also received two mails from PayPal, that a SEPA direct debit mandate had been confirmed. The PayPal mail arrived 8 minutes before the first of the flooded mails and 12 minutes before the last arrived.

Obviously this flood was supposed to hide the PayPal mail.

#compsec

Hmmm ... 🤔

Commercial Vehicle Electronic Logging Device (ELD) Security: Unmasking the Risk of Truck-to-Truck Cyber Worms [PDF] https://www.ndss-symposium.org/wp-content/uploads/vehiclesec2024-47-paper.pdf #paper #compsec #security #malware #ELD

Here we go again... The new #meltdown is called #downfall: https://downfall.page/

#security #compsec