security
            Secure AI/ML-Driven Software Development (LFEL1012): Learn to Build Safer Software with AI
            
                    
        
        
                https://openssf.org/blog/2025/10/16/a-new-course-on-secure-ai-ml-driven-software-development/
            
        
                Added 2 weeks ago 
            
                            
            OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code
            
                    
        
        
                https://cybersecuritynews.com/openssh-vulnerability-proxycommand/
            
        
                Added 3 weeks ago 
            
                            
            Introducing CodeMender: an AI agent for code security - Google DeepMind
            
                    
        
        
                https://deepmind.google/discover/blog/introducing-codemender-an-ai-agent-for-code-security/
            
        
                Added 3 weeks ago 
            
                            
            Red Hat data breach escalates as ShinyHunters joins extortion
            
                    
        
        
                https://www.bleepingcomputer.com/news/security/red-hat-data-breach-escalates-as-shinyhunters-joins-extortion/
            
        
                Added 3 weeks ago 
            
                            
            Almost 1 billion Salesforce records stolen, hacker group claims
            
                    
        
        
                https://www.reuters.com/sustainability/boards-policy-regulation/almost-1-billion-salesforce-records-stolen-hacker-group-claims-2025-10-03/
            
        
                Added 3 weeks ago 
            
                            
            Discord customer service data breach leaks user info and scanned photo IDs | The Verge
            
                    
        
        
                https://www.theverge.com/news/792032/discord-customer-service-data-breach-hack
            
        
                Added 3 weeks ago 
            
                            
            From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more
            
                    
        
        
                https://verialabs.com/blog/from-mcp-to-shell/
            
        
                Added 3 weeks ago 
            
                            
            Red Hat confirms security incident after hackers claim GitHub breach
            
                    
        
        
                https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/
            
        
                Added 4 weeks ago 
            
                            
            GitHub - francoismichel/ssh3: SSH3: faster and rich secure shell using HTTP/3, checkout our article here: https://arxiv.org/abs/2312.08396 and our Internet-Draft: https://datatracker.ietf.org/doc/draft-michel-ssh3/
            
                    
        
        
                https://github.com/francoismichel/ssh3
            
        
                Added 1 month ago 
            
                            
            OpenSSF to freeloaders: Open source infra isn't free • The Register
            
                    
        
        
                https://www.theregister.com/2025/09/23/openssf_open_source_infrastructure/
            
        
                Added 1 month ago 
            
                            
            One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - dirkjanm.io
            
                    
        
        
                https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
            
        
                Added 1 month ago 
            
                            
            We all dodged a bullet - Xe Iaso
            
                    
        
        
                https://xeiaso.net/notes/2025/we-dodged-a-bullet/
            
        
                Added 1 month ago 
            
                            
            Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1
            
                    
        
        
                https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/
            
        
                Added 1 month ago 
            
                            
            The Critical Flaw in CVE Scoring
            
                    
        
        
                https://www.darkreading.com/vulnerabilities-threats/critical-flaw-cve-scoring
            
        
                Added 2 months ago 
            
                            
            Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault - Cyata | The Control Plane for Agentic Identity
            
                    
        
        
                https://cyata.ai/blog/cracking-the-vault-how-we-found-zero-day-flaws-in-authentication-identity-and-authorization-in-hashicorp-vault/
            
        
                Added 2 months ago 
            
                            
            Fully Homomorphic Encryption and the Dawn of A Truly Private Internet
            
                    
        
        
                https://bozmen.io/fhe
            
        
                Added 3 months ago 
            
                            
            Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai – Krebs on Security
            
                    
        
        
                https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/
            
        
                Added 3 months ago 
            
                            
            GitHub - Forceu/Gokapi: Lightweight selfhosted Firefox Send alternative without public upload. AWS S3 supported.
            
                    
        
        
                https://github.com/Forceu/Gokapi
            
        
                Added 3 months ago 
            
                            
            @bagder.mastodon.social.ap.brid.gy on Bluesky
            
                    
        
        
                https://bsky.app/profile/bagder.mastodon.social.ap.brid.gy/post/3ltodxecunfy2
            
        
                Added 3 months ago 
            
                            
            China breaks RSA encryption with a quantum computer - Earth.com
            
                    
        
        
                https://www.earth.com/news/china-breaks-rsa-encryption-with-a-quantum-computer-threatening-global-data-security/
            
        
                Added 4 months ago 
            
                            
            Defending the Internet: how Cloudflare blocked a monumental 7.3 Tbps DDoS attack
            
                    
        
        
                https://blog.cloudflare.com/defending-the-internet-how-cloudflare-blocked-a-monumental-7-3-tbps-ddos/
            
        
                Added 4 months ago 
            
                            
            Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositories | Sysdig
            
                    
        
        
                https://sysdig.com/blog/insecure-github-actions-found-in-mitre-splunk-and-other-open-source-repositories/
            
        
                Added 4 months ago 
            
                            
            Google Online Security Blog: On Fire Drills and Phishing Tests
            
                    
        
        
                https://security.googleblog.com/2024/05/on-fire-drills-and-phishing-tests.html
            
        
                Added 4 months ago