Ubuntu, Fedora, Linux Mint Eye Age Verification Amid California Law Backlash - 9to5Linux
The upcoming California Digital Age Assurance Act law requires OSes to ask users to input their birth date during setup to protect minors.
#linux: Ubuntu, Fedora, Mint Linux are considering adding age verification to Linux due to the upcoming law mandating that OS providers and application developers implement age verification measures to protect minors online. This will have a huge impact:
06.03.2026 09:17
๐ 0
๐ 0
๐ฌ 0
๐ 0
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.
#NPM: If previously attackers hijacked NPM packages to install credential-stealing and data-stealing malware, in this latest hijack of Cline CLI the attackers installed #OpenClaw:
#SoftwareSupplyChainSecurity
๐
23.02.2026 10:07
๐ 1
๐ 0
๐ฌ 0
๐ 0
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflow...
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
#NPM: New Shai-Huludโlike supply chain worm is actively targeting the npm ecosystem with at least 19 malicious npm packages designed to steal developer & CI/CD secrets & automatically spread across repositories & workflows:
#SoftwareSupplyChainSecurity
๐
socket.dev/blog/sandwor...
21.02.2026 23:18
๐ 0
๐ 0
๐ฌ 0
๐ 0
"A swarm of agents! Everywhere!" I was watching a 1983 British spy thriller starring Michael Caine and Laurence Olivier and then I hear this 25 minutes in๐ฎ: ๐
21.02.2026 13:27
๐ 0
๐ 0
๐ฌ 0
๐ 0
Just re-watched Spiderman2 on Netflix (shot in 2004) where Dr Octopus has AI-controlled Claws attached to his body using tentacles, neuro-linked to his brain with a "guardrail" microchip making sure the AI in the claws does not go rogue, and it does... Eerie watching this in 2026:๐ฆ
21.02.2026 11:34
๐ 16
๐ 1
๐ฌ 0
๐ 1
Just re-watched Spiderman2 on Netflix (shot in 2004) where Dr Octopus has AI-controlled Claws attached to his body using tentacles, neuro-linked to his brain with a "guardrail" microchip making sure the AI in the claws does not go rogue, and it does... Eerie watching this in 2026:๐ฆ
21.02.2026 11:34
๐ 16
๐ 1
๐ฌ 0
๐ 1
Join us in Oslo for the OWASP Contributor Workshop. Get hands-on with the projects powering open-source security worldwide. Learn, connect, and start contributing on the spot.
๐ March 6
๐๏ธ Free signup: luma.com/4hp7c8bm
#owasp #NDC #workshop #opensource #appsec #infosec #community
19.02.2026 10:48
๐ 2
๐ 1
๐ฌ 0
๐ 0
Major 'vibe-coding' platform Orchids is easily hacked, researcher finds
Vibe-coding tools - which let people without coding skills create apps using AI - are exploding in popularity.
#AI: Major AI #vibecoding platform's flaws allow BBC reporter to be hacked:
#Orchids platform claims to have a million users, and says it is used by top companies including Google, Uber, and Amazon:
#AISecurity
๐
www.bbc.co.uk/news/article...
15.02.2026 10:59
๐ 3
๐ 0
๐ฌ 0
๐ 0
RCE in Google's AI code editor Antigravity - $10000 Bounty
Hacktron AI Research Team discovered a critical RCE in Googleโs Antigravity IDE that lets attackers take over your system just by opening a malicious website.
#Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
#BugBountyTips
๐
www.hacktron.ai/blog/hacking...
09.02.2026 21:51
๐ 0
๐ 0
๐ฌ 0
๐ 0
Hackers exploit critical React Native Metro bug to breach dev systems
Hackers are targeting developers by exploiting the critical vulnerabilityย CVE-2025-11953 in the Metro serverย for React Native to deliver malicious payloads for Windows and Linux.
#ReactNative: Critical vulnerability in Metro server for #React Native CVE-2025-11953 allows unauthenticated attackers to execute arbitrary OS commands via a POST request is actively exploited - patch now!
#Metro4Shell
#SoftwareSupplyChainSecurity
๐
www.bleepingcomputer.com/news/securit...
04.02.2026 10:12
๐ 0
๐ 0
๐ฌ 0
๐ 0
The number of startups, products and workflows built on #chatGPT-4.x models is huge!
This is your reminder that #OpenAI will be *retiring all* gpt-4.x, o4-mini and some gpt-5 models next week on February 13th, 2026 ๐ฟ:
#AIBOM
๐
help.openai.com/en/a...
03.02.2026 23:22
๐ 0
๐ 0
๐ฌ 0
๐ 0
Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users
State-backed attackers hijacked Notepad++ update traffic via a hosting provider breach, redirecting users to malicious downloads since June 2025.
#Notepad++ Official Update Mechanism Was Hijacked to Deliver Malware.
Notepad++ downloads between September 2 - December 2, 2025 were diverted to malicious servers.
#SoftwareSupplyChainSecurity
๐
02.02.2026 11:20
๐ 0
๐ 0
๐ฌ 0
๐ 0
DNS Based OSINT Techniques for Product and Service Discovery - Rishi C
YouTube video by OWASP London
Many thanks to Rishi C (@rxerium.com) for presenting his talk: "DNS Based #OSINT Techniques for Product and Service Discovery" at our meetup last week.
The video recording of the talk is available to watch ๐บ on the #OWASPLondon YouTube Channel [PLEASE SUBSCRIBE!]:
๐
www.youtube.com/watch?v=lGO3...
25.01.2026 11:25
๐ 2
๐ 3
๐ฌ 0
๐ 0
Time for @owasplondon.bsky.social!!
#OWASPLondon @owasp.org @securestep9.bsky.social
21.01.2026 18:58
๐ 4
๐ 2
๐ฌ 0
๐ 0
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
A 9.8-severity flaw (CVE-2026-24061) in GNU InetUtils telnetd allows remote authentication bypass and root access in versions 1.9.3 to 2.7.
#telnet: Critical telnetd #Vulnerability CVE-2026-24061 Lets Attackers Bypass Login and Gain Root Access on systems running GNU InetUtils since version 1.9.3 up to and including version 2.7.
The vulnerability went unnoticed for nearly 11 years.
๐
22.01.2026 21:50
๐ 5
๐ 3
๐ฌ 2
๐ 0
CVE-2025-68428: Critical Path Traversal in jsPDF | Blog | Endor Labs
Critical path traversal in jsPDF (<= 3.0.4) allows arbitrary file read via Node.js builds. Upgrade to 4.0.0 to remediate CVE-2025-68428.
#jsPDF: Critical Path Traversal Vulnerability (CVE-2025-68428) in jsPDF - a widely-adopted #npm package for generating PDF documents in JavaScript applications allows attackers to read & exfiltrate arbitrary files from the local filesystem:
๐
07.01.2026 17:43
๐ 2
๐ 1
๐ฌ 0
๐ 0
OWASP London Chapter Meetup [IN-PERSON], Wed, Jan 21, 2026, 6:00 PM | Meetup
**This event is kindly sponsored by Nuaware.**
**Raffle prizes are kindly sponsored by GitGuardian and Docker.**
**There is limited seating available for in-person attende
The next OWASP London Chapter in-person Meetup will take place on January 21st, 2026, kindly sponsored by @nuaware_tech with raffle prizes kindly sponsored by @GitGuardian and @Docker
Register to attend this event here:
๐
07.01.2026 12:37
๐ 1
๐ 2
๐ฌ 0
๐ 0
How Trust Wallet Crypto Users Lost $6M+ in a Browser Extension Incident
$6M+ in BTC, ETH, and SOL was lost via a Trust Wallet browser extension incident, prompting an urgent user warning.
#TrustWallet: in a potential supply chain attack TrustWallet browser extension is compromised in the latest update with injected malicious code quietly sending the wallet's seed phrase to malicious domain named "metrics-trustwallet(.)com"- registered only a few days ago
๐
www.ccn.com/education/cr...
26.12.2025 07:52
๐ 1
๐ 0
๐ฌ 0
๐ 0
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB has warned IT admins to immediately patch a high-severity vulnerability that may be exploited in remote code execution (RCE) attacks targeting vulnerable servers.
#MongoDB and MongoDB Server multiple versions are vulnerable to Remote Code Execution (#RCE) #vulnerability CVE-2025-14847 and may be abused by unauthenticated threat actors in low-complexity attacks that don't require user interaction. Patch now!
๐
www.bleepingcomputer.com/news/securit...
26.12.2025 06:47
๐ 5
๐ 2
๐ฌ 0
๐ 1
๐ Big news! Early Bird tickets for OWASP Global AppSec Vienna 2026 are here!
25 years of OWASP โจ Stunning Vienna ๐ฆ๐น World-class training ๐ง & a conference like no other ๐ฅ
Why wait? Register now for early bird pricing: owasp.glueup.com/eve...
#appsec #owasp #cybersecurity #securebydesign
19.12.2025 14:48
๐ 2
๐ 1
๐ฌ 0
๐ 0
If you missed @shehackspurple.bsky.social 's talk "30 Tips for Secure #JavaScript" at the @owasplondon.bsky.social meetup last week - you can watch the recording on the #OWASPLondon YouTube channel [please subscribe!]:
08.12.2025 00:24
๐ 3
๐ 2
๐ฌ 0
๐ 0
Swiss government urges people to ditch Microsoft 365 and others due to lack of proper encryption
Switzerland is worried about data privacy
#Swiss government urges citizens to ditch #Microsoft365 and other #Cloud providers due to lack of proper E2E encryption citing US Cloud Act requirement to hand over data to US authorities, even if itโs stored in Switzerland:
#DataSecurity
๐
www.techradar.com/pro/security...
03.12.2025 08:36
๐ 3
๐ 2
๐ฌ 0
๐ 0