Thousands of consumer routers hacked by Russia's military https://arstechni.ca/hwVk #credentials #Security #hacking #routers #Biz&IT #Policy #DNS
Thousands of consumer routers hacked by Russia's military

End-of-life routers in homes and small offices hacked in 120 countries.

Ars Technica

@ctietze store the secret in a safe place (derived from TPM2, /var/lib/systemd/credential.secret, …) and pass it along to the service using systemd's credentials capabilities:
https://systemd.io/CREDENTIALS/

#systemd #security #credentials

Credentials

Paul Couvert (@itsPaulAi)

에이전트가 외부 도구와 안전하게 연결될 수 있다는 점을 강조한다. 한 부분이 침해돼도 자격 증명이 안전하게 분리되어 있어 OpenClaw, Codex 등은 접근할 수 없고 유출 위험이 줄어든다고 설명한다.

https://x.com/itsPaulAi/status/2041527637818917344

#agent #security #tooling #credentials #sandbox

Paul Couvert (@itsPaulAi) on X

Joke aside I'm glad to see that you can connect your agent to external tools securely Because if one part is compromised, your credentials are safe. OpenClaw, Codex, etc. don't have access to them... So they can't leak!

X (formerly Twitter)
Ah, yes, because the world has been eagerly awaiting yet another #sandbox tool that promises to revolutionize...well, everything! 🙄 Zerobox, the #lightweight hero here to save us from the unbearable burden of unrestricted commands! 🌟 Now we can finally sleep soundly knowing our #credentials are safe from the evils of the #command line! 🛡️
https://github.com/afshinm/zerobox #tools #security #line #HackerNews #ngated
GitHub - afshinm/zerobox: Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls. - afshinm/zerobox

GitHub

Popular #LiteLLM #PyPI package #backdoored to steal #credentials , auth #tokens

The #TeamPCP #hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI & claiming to have stolen data from hundreds of thousands of devices during the attack.

LiteLLM is an open-source #Python library that serves as a gateway to multiple large language model ( #LLM ) providers via a single #API.
#privacy #security #supplychain

https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/

Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack

The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack.

BleepingComputer

Lukasz Olejnik (@lukOlejnik)

AI 소프트웨어 인프라에서 중요한 도구인 LiteLLM이 침해된 것으로 보이며, 환경변수와 SSH 키, AWS/GCP/Azure 자격증명 등 민감 정보가 유출된 악성 페이로드가 포함됐다. AI 개발 인프라 보안상 매우 중요한 사건이다.

https://x.com/lukOlejnik/status/2036719952384622705

#litellm #security #aiinfrastructure #credentials #opensource

Lukasz Olejnik (@lukOlejnik) on X

LiteLLM, an important part of AI software infrastructure, has just been compromised. The payload was a credential stealer that grabbed environment variables, SSH keys, AWS/GCP/Azure credentials, Kubernetes configs, shell history, crypto wallets, and more, then exfiltrated

X (formerly Twitter)

#ICE #Phishing : #Scammers Are Sending 'Support ICE' Emails to Steal #Credentials

Clients of a long-running #email #marketing platform are getting targeted with a #phishing campaign telling them that their emails would begin automatically inserting a “‘Support ICE’ donation button” into every email they send. The strategy suggests that scammers are trying to capitalize on people’s revulsion to ICE by coming up with strategies that would cause users to quickly log into…

https://www.404media.co/ice-phishing-scammers-are-sending-support-ice-emails-to-steal-credentials/

ICE Phishing: Scammers Are Sending 'Support ICE' Emails to Steal Credentials

"As part of our commitment to supporting ICE, we will be adding a ‘Support ICE’ donation button to the footer of every email sent through our platform."

404 Media

Fake Spotify podcast vote phishing targets user login credentials

https://misryoum.com/us/technology-ai/fake-spotify-podcast-vote-phishing-targets-user-login/

NEWYou can now listen to US News Hub MISRYOUM News articles! It started with a simple favor. A friend asked for help voting so he could co-host a major podcast event with Spotify and Google. The first message looked...

#Fake #Spotify #podcast #vote #phishing #targets #user #login #credentials #US_News_Hub #misryoum_com

Fake Spotify podcast vote phishing targets user login credentials

NEWYou can now listen to US News Hub MISRYOUM News articles! It started with a simple favor. A friend asked for help voting so he could co-host a major

US News Hub
🔒💼 Ah, yes, the 4,952-word odyssey from our cryptography-obsessed professor, valiantly defending your #privacy while you fall asleep by page two. Because who doesn't want to spend their #weekend deciphering an 'illustrated primer' on #anonymous credentials? 🙄✨
https://blog.cryptographyengineering.com/2026/03/02/anonymous-credentials-an-illustrated-primer/ #cryptography #credentials #reading #illustrated #primer #HackerNews #ngated
Anonymous credentials: an illustrated primer

This post has been on my back burner for well over a year. This has bothered me, since with every month that goes by, I become more convinced that anonymous authentication the most important topic …

A Few Thoughts on Cryptographic Engineering
#Wayland
كلّ مرّة يزيد حاجة جديدة و هازي المرّة يتحصّل على
#Protocol
جديد لل
Multi-window #Application
https://www.phoronix.com/news/Wayland-Experimental-Zones
#Mesa 26
تتحصّل على تحسين في ال
#RayTracing
https://9to5linux.com/mesa-26-0-open-source-graphics-stack-officially-released-heres-whats-new
#AI #Extension
مزيّفة سرقت المعلومات، ال
#Credentials
متاع 300 ألف مستعمل
https://www.bleepingcomputer.com/news/security/fake-ai-chrome-extensions-with-300k-users-steal-credentials-emails/
و
#System
جديد مقترح لمقاومة ال
#AI #Slop #Contribution
https://github.com/mitchellh/vouch?ref=itsfoss.com
Experimental Zones Protocol Merged To Wayland After 2+ Years, 620+ Comments

After the merge request was opened back in 2023 and after going through 628 comments/activity, merged now to Wayland Protocols is the experimental zones 'xx-zones' implementation for area-limited window positioning.