So far my #HomeAssistant instance had been running on the local subnet, behind the #Router's #Firewall and so was inaccessible from outside my house’s network. However, I’ve now got it onto the #Internet. Of course, there are inherent risks and potential problems with this if malicious actors want to crack the system and so I made sure that it’s only accessible as an #Encrypted connection via #HTTPS rather than #HTTP.

#GNU #Linux #FreeSoftware #HAOS

Laravel Lang Compromised with RCE Backdoor Across 700+ Versions

Community-maintained Laravel Lang packages were compromised with remote code execution backdoors affecting over 700 versions across multiple repositories including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. The attack involved coordinated rapid tag publishing on May 22-23, 2026, suggesting organization-level credential compromise. A malicious helpers.php file was automatically executed via Composer's autoloader, deploying a sophisticated cross-platform information stealer. The second-stage payload systematically harvested credentials from cloud infrastructure, Kubernetes, CI/CD systems, browsers, password managers, cryptocurrency wallets, VPN clients, and local configurations. Stolen data was encrypted and exfiltrated to a command-and-control server. The backdoor employed advanced evasion techniques including TLS verification bypass, per-host execution markers, and embedded Windows executables to bypass Chrome encryption protections.

Pulse ID: 6a1187d92cdbfd79095008cd
Pulse Link: https://otx.alienvault.com/pulse/6a1187d92cdbfd79095008cd
Pulse Author: AlienVault
Created: 2026-05-23 10:56:25

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Browser #Chrome #Cloud #CyberSecurity #Encryption #HTTP #InfoSec #OTX #OpenThreatExchange #PHP #Password #RAT #RCE #RemoteCodeExecution #TLS #VPN #Windows #Word #bot #cryptocurrency #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Got D3 rendering the charts. The design isn't set in stone, but I like it so far.

#GoLang #D3 #htmx #templ #HTTP

Working as intended so far. Main app and N probes start up and the app sends out info to each probe so it can go probe the endpoint, collect results, and report it back to the main app.

#GoLang #Docker #BuildInPublic #HTTP

The Programmer’s Fulcrum: 15 May, 2026

This article originally appeared on The Fulcrum.

Welcome to this week’s The Programmer’s Fulcrum.

It’s your weekly curation of the essential news in the Open Media Network and Fediverse development communities with a focus on devastating big tech via Techno Anarchism.

As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional […]

https://newsletter.mobileatom.net/the-programmers-fulcrum-15-may-2026/ #ActivityPub #AI #ATProto #Beehiv #Buttondown #CastLab #Codeberg #CSS #Drupal #Elefeed #Emacs #Ente #FDroid #Faircamp #Fcast #Fedify #FediLab #FediProfile #fediverse #ForgeCMS #Forgejo #freebsd #Ghost #git #GitLab #Holos #HTML #HTTP #IndieWeb #javascript #LibreOffice #Librewolf #Linux #Mastodon #Matrix #MicroBlog #Movim #OMN #pckt #Pica #PostmarketOS #PureBlog #RSS #Silex #Snac #Substack #WebComponents #Webrings #WordPress #xPrivo #xWiki

@Marloezovic Misschien heb je hier ook iets aan?

The protocols no one can take from you:

https://www.terrygodier.com/the-boring-internet

#protocollen #opensource #irc #RSS #http #usenet #XMPP #Gemini

The Boring Internet

The internet you grew up on isn't dying. A commercial veneer glued on top of it is. A visual essay about what actually persists.

Terry Godier
🌘 簡介:Slumber
➤ 打造高效的終端機 HTTP 互動體驗
https://slumber.lucaspickering.me
Slumber 是一款專為開發者打造、基於終端機的 HTTP 客戶端,旨在提升 REST API 互動的效率與便利性。該工具支援 TUI(終端使用者介面)與 CLI(命令列介面)兩種模式,前者適合互動式測試與回應查看,後者則適用於快速請求與自動化腳本編寫。Slumber 的設計核心在於「易用、可配置與易於共享」,所有請求配置皆統一整合於 YAML 格式的檔案中,實現了介面與邏輯的高度一致性。
+ 終於有一款能夠在終端機裡流暢測試 API 的工具了,重點是還支援 YAML 配置,對於 DevOps 工作流程非常友善。
+ TUI 和 CLI 雙模式切換確實靈活,對於需要頻繁寫腳本又想即時檢查 API 回應的人來說,Slumber 的介面設計非常精簡且直觀。
#開發工具 #終端機軟體 #HTTP 客戶端
Introduction - Slumber

Slumber is a TUI (terminal user interface) HTTP client. Define, execute, and share configurable HTTP requests.

Introduction - Slumber

Slumber is a TUI (terminal user interface) HTTP client. Define, execute, and share configurable HTTP requests.

Can we please get rid of :// for denoting protocols?  Like it's fine to still support it, but how come : doesn't suffice? I hate having three forward slashes when I'm accessing a remote or virtual filesystem.

I love you GNOME but admin:/// is a travesty. 

EDIT: Actually, what about > ?  

https>cubhub.social and admin>/home/rusty

mostly because I like Matrix's @user:server.tld and matrix:@user:server.tld would like dumb but matrix>@user:server.tld would be pretty clutch  

#HTTP #GNOME #Linux #MatrixChat