11 Followers
53 Following
72 Posts

「 Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and later. This flaw (CVE-2026-3888) allows an unprivileged local attacker to escalate privileges to full root access through the interaction of two standard system components: snap-confine and systemd-tmpfiles. 」
https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root

#ubuntu #snap #infosec

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root | Qualys

The Qualys Threat Research Unit has identified a Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and later. This flaw (CVE-2026-3888)…

Qualys

@devuan the issue in question here is caused by Snap, and an improper systemd-tmpfiles configuration.

I get shitting on systemd, but you're quite wrong on this particular issue.

Thank you Open Rights Group (@openrightsgroup) for supporting Keep Android Open at https://keepandroidopen.org/open-letter/#signatories @keepandroidopen #KeepAndroidOpen
An Open Letter to Google regarding Mandatory Developer Registration for Android App Distribution

Open Letter to Google Regarding Mandatory Developer Registration for Third-Party App Distribution

every so often people report errors in the zines (thank you!). Just made a new page with all the errors that have been reported & fixed so far here: https://wizardzines.com/errors/
zine errors

wizard zines
An appropriate T-shirt for today.

allo la lune – ici la terre – répondez !

French acrobat Bastien Dausse created a device that simulates lunar gravity / Tintin
tags : un peu de légèreté, #birds #moon #art

Bad news 😔💔

I am sad to announce today that unfortunately I will not be working with Privacy Guides anymore after the end of this month.

Good news! 🚨  

I will be available for a new position or contract, starting in April!

I am looking for a position or contact for:

✊ Digital rights activist (with a specialty in privacy rights)

🔒 Privacy expert or consultant

 Fediverse and Mastodon advocate

🙌 Managerial position

📰 Tech journalist

💻 Technical writer

💚 Or any other fitting positions

I am especially interested in working with nonprofit organisations, cooperatives, open-source projects, privacy-oriented software companies, or any other organisations working for the public good.

🇨🇦 Remote from Canada

 All the work I produce is guaranteed to be AI-free

Let me know if you hear of any good opportunities!

#FediHire #GetFediHired #Tech #Jobs

@32x33 I fail to understand why wireless headphones need updating. I have this somewhat irrational fear that one day Google Pixel Buds are gonna get a malicious update that deafens me and everyone using them.
Little Fires Everywhere, directed by Nero.
#romaneratvshows

I heard GAYINT is busy building out some weird shit, but until then, here are some more lists that might be handy for some of you.  

Recent IPs seen attacking SSL VPN portals:

https://blog.gayint.org/intel/vpnAttacks20260316.txt

Usernames used in password sprays and brute force attempts on SSL VPN portals:

https://blog.gayint.org/intel/usernames.txt

Passwords used in password sprays and brute force attempts on SSL VPN portals:

https://blog.gayint.org/intel/passwords.txt

#GAYINT