Full-stack developer with special interest in cybersecurity. Advocate of a free and safe Internet. Nature admirer and sports enthusiast.
Public Key
npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 Profile Code
nprofile1qqsvragg6cy4muhjr2ks4gvktp9fed60sp873cvpmteqtmxunf6twqqpz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0ds0z5843
Show more details
Published at
2024-02-20T23:10:04Z Event JSON
{
"id": "f97f6fb332ebed960259ba24b592abecc2999effd95ecaf0ab7bfc1c5cf553a4" ,
"pubkey": "c1f508d6095df2f21aad0aa196584a9cb74f804fe8e181daf205ecdc9a74b700" ,
"created_at": 1708470604 ,
"kind": 0 ,
"tags": [],
"content": "{\"name\":\"dethos\",\"about\":\"Full-stack developer with special interest in cybersecurity.\\n\\nAdvocate of a free and safe Internet. Nature admirer and sports enthusiast.\",\"lud16\":\"[email protected] \",\"display_name\":\"Gonçalo Valério\",\"picture\":\"https://m.primal.net/HcUd.jpg\",\"banner\":\"https://m.primal.net/HcUe.jpg\",\"website\":\"https://ovalerio.net\"}" ,
"sig": "d99ce18fc0ebe30584432155b8c8c9df5b8e34a8996f3146bb2ad18b118e46151cee220960eb92a87936a0e18d8b1a52b8900ddacd1e99e7583b643874a90b4a"
}
Last Notes npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Web Security is Too Hard" https://textslashplain.com/2026/08/04/security-is-hard-yall/ Yes, it is, but sometimes people just make it harder than it needs to be. #web #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Massive ChainDrop npm supply-chain attack infects hundreds of packages" https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/ #npm #javascript #supplychain #security #infosec npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Okay, grok has uploaded my entire user directory to xAI's servers." https://xcancel.com/a_green_being/status/2076598897779020159 Yikes! Some sort of containment appears to be essential to run these tools. Only provide them with access to what they need to do the work, nothing else. #ai #grok #security #infosec npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos PlayStation Is Deleting 551 Movies From Customers’ Accounts, Reminding Us Nothing Digital Is Ever Truly Ours" https://kotaku.com/playstation-store-movies-digital-studio-canal-terminator-2000711013 Instead of "buy" and "purchase", companies providing digital content and goods this way should be legally forced to use "rent" or "lease". #digitalgoods #movies #music #software npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos ".gitignore Isn’t the Only Way To Ignore Files in Git" https://nelson.cloud/.gitignore-isnt-the-only-way-to-ignore-files-in-git/ #git npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "GitHub Actions Security Checklist for Supply Chain Attacks" https://corgea.com/learn/github-actions-security-checklist #security #infosec #github #githubactions #supplychain npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "1-Click GitHub Token Stealing via a VSCode Bug" https://blog.ammaraskar.com/github-token-stealing/ #security #infosec #vscode #github #microsoft npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "The Newest Instagram "Exploit" is the Goofiest I've Seen" https://www.0xsid.com/blog/meta-account-takeover-fiasco 😂 😑 😓 #security #infosec #instagram #meta #ai npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Motorola phones have started hijacking the Amazon app to insert affiliate codes" https://9to5google.com/2026/05/25/motorola-amazon-app-hijacking-behavior/ 🤦♂️ #enshittification #crap #motorola #android npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos OpenSUSE Slowroll just landed on my test machine. Looking and behaving good. 👍 Strong candidate to replace my main one in the future. 🦎 #opensuse #slowroll #os #linux npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor" https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor Yikes... if we even needed more reasons to avoid Windows and Microsoft's encryption tools. #security #infosec #windows #bitlocker #microsoft npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Is anyone surprised? 🥸 https://www.theregister.com/2026/05/04/uk_online_safety_act_age_checks_subvert/ #agechecks #ageverification npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Credit Cards Are Vulnerable To Brute Force Kind Attacks" https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #security #creditcards npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos As if you needed more reasons to stop using Windows and other Microsoft products and services. https://www.bleepingcomputer.com/news/microsoft/microsoft-suspends-dev-accounts-for-high-profile-open-source-projects/ #microsoft #opensource #softwaredevelopment npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos A couple of links with tips to help with supply chain security: * https://github.com/lirantal/npm-security-best-practices * https://bernat.tech/posts/securing-python-supply-chain/ #python #javascript #pypi #npm #security #infosec #supplychain npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 6.0.4, 5.2.13, and 4.2.30" https://www.djangoproject.com/weblog/2026/apr/07/security-releases/ #django #python #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Isn't graphene just a special flavour of android? npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "axios Compromised on npm - Malicious Versions Drop Remote Access Trojan" https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Just another Tuesday. Developing software is becoming a riskier business by the day. #npm #javascript #nodejs #security #supplychain npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "End of “Chat Control”: EU Parliament Stops Mass Surveillance in Voting Thriller – Paving the Way for Genuine Child Protection!" https://www.patrick-breyer.de/en/end-of-chat-control-eu-parliament-stops-mass-surveillance-in-voting-thriller-paving-the-way-for-genuine-child-protection/ #eu #chatcontrol npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "A YC-Backed Startup Left Production AWS Keys Public for 5 Months. Their VDP Was Silent." https://benzimmermann.dev/blog/pump-vdp-silence #security #infosec #yc #cybersecurity npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Managing SSH keys with KeePassXC is actually quite nice -------------- It all started with a post on Lobste.rs, someone asking how others manage their SSH keys. It was a question that I had already asked myself multiple times, so I was genuinely interested in reading about what others had to say. There must be a better way than storing them encrypted on your disk and manually inputting the passphrases while loading them to the agent every morning. When KeePassXC […] https://blog.ovalerio.net/archives/3289 #keepassxc #ssh #sshAgent npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Lock the Ghost: In the software world, “remove” is not equal to "gone."" https://www.cert.at/en/blog/2026/3/lock-the-ghost #pypi #dependencies #supplychain #lockfiles #python npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Jazzband is sunsetting. New signups are disabled. Project leads will be contacted before PyCon US 2026 to coordinate transfers." https://jazzband.co/news/2026/03/14/sunsetting-jazzband #python #opensource #jazzband npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Hisense TVs force owners to watch intrusive ads when switching inputs, visiting the home screen, or even changing channels" https://www.tomshardware.com/tech-industry/big-tech/hisense-tvs-force-owners-to-watch-intrusive-ads-when-switching-inputs-visiting-the-home-screen-or-even-changing-channels-practice-infuriates-consumers-brand-denies-wrongdoing This is just garbage. Need to find the brands that still sell actual TVs. #smarttv #hisense #ads npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Replacing tox with UV" https://blog.changs.co.uk/replacing-tox-with-uv.html #python #testing #uv npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Chat Control, mass surveillance, and then... https://mastodon.online/@mullvadnet/116206184902355562 #eu #chatcontrol #mullvad npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "The AWS Console and Terraform Security Gap" https://blog.includesecurity.com/2026/02/the-aws-console-and-terraform-security-gap/ #aws #terraform #opentofu #security #infosec npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos When a vendor doesn't release the software using one of these methods. Curl bash is very common for example. I usually try to find an alternative. npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Claude is an Electron App because we’ve lost native" https://tonsky.me/blog/fall-of-native/ #software npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos I get it using the distro's package manager. That's it. If something is not there, or I need a bleeding edge version, I use flatpak. Overtime I found that this approach works very well for me. npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Google API Keys Weren't Secrets. But then Gemini Changed the Rules." https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules #security #infosec #google npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos ""Made in EU" - it was harder than I thought." https://www.coinerella.com/made-in-eu-it-was-harder-than-i-thought/ By the post content, **still worth it**. #buyfromeu #techstack #cloud #europeanunion #europeanalternatives npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Leaking secrets from the claud" https://ironpeak.be/blog/leaking-secrets-from-the-claud/ #security #ai #agents #softwaredevelopment npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Spying Chrome Extensions: 287 Extensions spying on 37M users" https://qcontinuum.substack.com/p/spying-chrome-extensions-287-extensions-495 Extensions should be few, installed carefully, and reviewed often. #security #privacy #browsers #chrome npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "We should all be using dependency cooldowns" https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns #supplychain #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 6.0.2, 5.2.11, and 4.2.28" https://www.djangoproject.com/weblog/2026/feb/03/security-releases/ #django #python #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Notepad++ Hijacked by State-Sponsored Hackers https://notepad-plus-plus.org/news/hijacked-incident-info-update/ #security #cybersecurity #notepad++ npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "But how to get to that European cloud?" https://berthub.eu/articles/posts/now-how-to-get-that-european-cloud/ #buyfromeu #cloud #europe #tech #sovereignty #digitalsovereignty npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Google confirms 'high-friction' sideloading flow is coming to Android" https://www.androidauthority.com/google-sideloading-android-high-friction-process-3633468/ Time for alternatives to show up. #android #mobile #mobiledev npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "FOSS for digital sovereignty in the EU" https://www.more-magic.net/posts/open-source-in-the-eu.html #eu #europe #foss #opensource #sovereignty #software npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Instagram account takeover via Meta Pixel script abuse" https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html #security #infosec #netsec #meta #instagram npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Claude Cowork Exfiltrates Files" https://www.promptarmor.com/resources/claude-cowork-exfiltrates-files #ai #security #agents #infosec npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "European Commission issues call for evidence on open source" https://lwn.net/Articles/1053107/ #eu #europe #opensource #sovereignty npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Safe Django migrations without server errors" https://www.loopwerk.io/articles/2025/safe-django-db-migrations/ #django #softwaredevelopment npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "A post-American, enshittification-resistant internet" https://media.ccc.de/v/39c3-a-post-american-enshittification-resistant-internet I just had the time to listen to it now. He does indeed have plenty of valid points. #enshittification #internet #europe #openweb #society npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Google will now only release Android source code twice a year" https://www.androidauthority.com/aosp-source-code-schedule-3630018/ And kids, this is just another example of why we need a viable alternative to the existing duopoly. #android #google #mobile #os #opensource npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Bye Bye Big Tech: How I Migrated to an almost All-EU Stack (and saved 500€ per year)" https://www.zeitgeistofbytes.com/p/bye-bye-big-tech-how-i-migrated-to #buyfromeu npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos The books I enjoyed the most in 2025 https://blog.ovalerio.net/archives/3248 #Books npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "MongoBleed explained simply" https://bigdata.2minutestreaming.com/p/mongobleed-explained-simply #security #infosec #netsec #mongodb npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Merry Christmas Day! Have a MongoDB security incident." https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb #security #infosec #netsec #mongodb npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Help my website is too small" https://lukeplant.me.uk/blog/posts/help-my-website-is-too-small/ #funny #bloat #web npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "NPM Package With 56K Downloads Caught Stealing WhatsApp Messages" https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages #security #infosec #nodejs #npm npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Over 10,000 Docker Hub images found leaking credentials, auth keys" https://www.bleepingcomputer.com/news/security/over-10-000-docker-hub-images-found-leaking-credentials-auth-keys/ #security #infosec #dockerhub npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos More app recommendations The good part of having a personal blog is that I can write about whatever comes to my mind. Today I was thinking of how people find the software they use, how many people end up using the same apps because they don’t know any alternatives, and the fact that many creators (especially open-source ones) deserve more recognition. Over the years I already shared some of the software I use, and I’m […] https://blog.ovalerio.net/archives/3212 #apps #software #Technology #tools npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "GitHub Actions Has a Package Manager, and It Might Be the Worst" https://nesbitt.io/2025/12/06/github-actions-package-manager.html #github #githubactions #security #supplychain npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Fairphone open-sources Fairphone 5 and 6 software, and Moments switch https://www.fairphone.com/en/2025/12/04/were-big-fans-of-open-source-buildable-code-at-fairphone-heres-why/ 💪 Nice #fairphone #mobile #eualternatives #opensource npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "When Password FieldsAren’t Enough – Client-Side SecretExposure in PagerDuty Cloud Runbook" https://www.praetorian.com/blog/cve-2025-52493-when-password-fieldsarent-enough-client-side-secretexposure-in-pagerduty-cloud-runbook/ #security #cybersecurity #infosec npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Critical Security Vulnerability in React Server Components" https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components #security #infosec #netsec #reaxtjs #javascript #npm npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Disable network requests when running Pytest" https://blog.pecar.me/disable-network-requets-when-running-pytest #python #pytest npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 5.2.9, 5.1.15, and 4.2.27" https://www.djangoproject.com/weblog/2025/dec/02/security-releases/ * CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL * CVE-2025-64460: Potential denial-of-service vulnerability in XML serializer text extraction #python #django #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours" https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24 #security #infosec #supplychain #cybersecurity #nodejs #npm npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "The privacy nightmare of browser fingerprinting" https://kevinboone.me/fingerprinting.html #privacy #web npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Yes, Steam Machine is optimized for gaming, but it's still your PC. Install your own apps, or even another operating system. Who are we to tell you how to use your computer?" 👏 👏 👏 A breath of fresh air… given the current status of the industry. #steam #steammachine npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "sudo-rs Affected By Multiple Security Vulnerabilities - Impacting Ubuntu 25.10" https://www.phoronix.com/news/sudo-rs-security-ubuntu-25.10 #security #infosec #ubuntu #sudors npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "10 Smart Performance Hacks For Faster Python Code" https://blog.jetbrains.com/pycharm/2025/11/10-smart-performance-hacks-for-faster-python-code/ #python npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "What data do coding agents send, and where to?" https://chasersystems.com/blog/what-data-do-coding-agents-send-and-where-to/ #ai #privacy #telemetry #codingagents npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "7 vulnerabilities in django-allauth enabling account impersonation and token abuse" https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities #security #python #django #django-allauth #infosec #cybersecurity npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Critical RCE Vulnerability CVE-2025-11953 Puts React Native Developers at Risk" https://jfrog.com/blog/CVE-2025-11953-critical-react-native-community-cli-vulnerability/ #security #reactnative #netsec #mobiledev npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 5.2.8, 5.1.14, and 4.2.26" https://www.djangoproject.com/weblog/2025/nov/05/security-releases/ * CVE-2025-64458: Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows * CVE-2025-64459: Potential SQL injection via _connector keyword argument in QuerySet and Q objects #python #django #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Samsung makes ads on $3,499 smart fridges official with upcoming software update" https://arstechnica.com/gadgets/2025/10/samsung-makes-ads-on-3499-smart-fridges-official-with-upcoming-software-update/ Well… Samsung smart products and appliances are officially banned from my home. 🤷♂️ #ads #samsung #iot #smarthome npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "How I Almost Got Hacked By A 'Job Interview'" https://blog.daviddodda.com/how-i-almost-got-hacked-by-a-job-interview #security #cybersecurity #developers #programmers npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Pixnapping Attack" "Anything that is visible when the target app is opened can be stolen by the malicious app using Pixnapping. Chat messages, 2FA codes, email messages, etc. are all vulnerable since they are visible." https://www.pixnapping.com/ #security #cybersecurity #infosec #android npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code" https://www.legitsecurity.com/blog/camoleak-critical-github-copilot-vulnerability-leaks-private-source-code #security #cybersecurity #infosec #github #copilot npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "HTTP/1.1 must die: the desync endgame" https://portswigger.net/research/http1-must-die #security #http #web #cybersecurity npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "What is "good taste" in software engineering?" https://www.seangoedecke.com/taste/ "In other words, most bad taste comes from inflexibility. I will always distrust engineers who justify decisions by saying “it’s best practice”. No engineering decision is “best practice” in all contexts! You have to make the right decision for the specific problem you’re facing." #softwaredevelopment #programming #softwareengineering npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Red Hat confirms security incident after hackers claim GitHub breach" https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/ #redhat #security #cybersecurity npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 5.2.7, 5.1.13, and 4.2.25" https://www.djangoproject.com/weblog/2025/oct/01/security-releases/ #security #python #django npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "... proof-of-concept transparent proxy PyPI mirror that demonstrates how code can be modified inline and pass hash checks" https://dtm.uk/badpie/ #python #pypi #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens" https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/ #security #cybersecurity #infosec #microsoft #entraid npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Self-Replicating Worm Hits 180+ Software Packages" https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/ #security #cybersecurity #infosec #npm #supplychain npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "npm debug and chalk packages compromised" https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised #security #cybersecurity #infosec #supplychain #npm #javascript npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Django security releases issued: 5.2.6, 5.1.12, and 4.2.24" https://www.djangoproject.com/weblog/2025/sep/03/security-releases/ * CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases #security #websec #python #django npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Supply Chain Security Alert: Popular Nx Build System Package Compromised with Data-Stealing Malware" https://www.stepsecurity.io/blog/supply-chain-security-alert-popular-nx-build-system-package-compromised-with-data-stealing-malware #security #cybersecurity #infosec #supplychain #npm #github npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Burner Phone 101" https://rebeccawilliams.info/burner-phone-101/ `` Privacy Tips for All Phones: * Keep device & OS as updated as possible * Strong PIN, not biometrics * Disable cloud backups / use encrypted backups * Install Signal * Enforce strict app permissions (deny mic, camera, location) unless needed * Radios off (GPS/Wi-Fi/Bluetooth) unless needed * Store minimal sensitive data (including photos) `` #security #privacy npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "DOM-based Extension Clickjacking: Your Password Manager Data at Risk" https://marektoth.com/blog/dom-based-extension-clickjacking/ #security #cybersecurity #infosec #passwordmanagers npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "ghrc.io Appears to be Malicious" https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #security #cybersecurity #containers #github npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Copilot Broke Your Audit Log, but Microsoft Won’t Tell You" https://pistachioapp.com/blog/copilot-broke-your-audit-log #security #cybersecurity #microsoft #ai npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "SystemD Service Hardening" https://roguesecurity.dev/blog/systemd-hardening #linux #systemd #security npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "StarDict sends X11 clipboard to remote servers" https://lwn.net/SubscriberLink/1032732/3334850da49689e1/ 😱 A past exploration just came back to my mind: https://blog.ovalerio.net/archives/2346 #security #cybersecurity #linux #x11 npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Smuggling arbitrary data through an emoji" https://paulbutler.org/2025/smuggling-arbitrary-data-through-an-emoji/ #emoji #hiddendata #fun npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault" https://cyata.ai/blog/cracking-the-vault-how-we-found-zero-day-flaws-in-authentication-identity-and-authorization-in-hashicorp-vault/ #security #cybersecurity #infosec #hashicorp #vault npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "We replaced passwords with something worse" https://blog.danielh.cc/blog/passwords #security #passwords #web #authentication npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Sign in with Google in Chrome" https://underpassapp.com/news/2025/7/5.html 🚯 #web #browsers npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos Interesting approach... Probably a better system than the rest. Let's see. npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Python Gotcha: Logging an uncaught exception" https://andrewwegner.com/python-gotcha-logging-uncaught-exception.html #python #programming npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Design Patterns You Should Unlearn in Python-Part1" https://www.lihil.cc/blog/design-patterns-you-should-unlearn-in-python-part1 #python npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "Evolution Mail Users Easily Trackable" https://www.grepular.com/Evolution_Mail_Users_Easily_Trackable #email #evolution #security #privacy npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "CVE-2025-48384: Breaking Git with a carriage return and cloning RCE" https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384 #security #git #rce npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "How to Migrate your Python & Django Projects to uv" https://www.caktusgroup.com/blog/2025/06/11/migrating-python-django-projects-uv/ #python #uv #django npub1c86s34sfthe0yx4dp2sevkz2njm5lqz0arscrkhjqhkdexn5kuqqtlvmv9 dethos "How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets" https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets #git #github #security #infosec