Lima becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept Lima as a CNCF incubating project. Lima enables secure, isolated environments for running cloud native and AI workloads. What is Lima? Where Does It Fit in… ⌘ Read more
ProcessOne: On Signal Protocol and Post-Quantum Ratchets
Signal improved its protocol to prepare encrypted messaging for the quantum era.
They call the improvement “Triple Ratchet” (or SPQR = Signal Post-Quantum Ratchet).
[Signal Protocol and Post-Quantum Ratchets\ \ We are excited to announce a significant advancement in the security … ⌘ Read more
@bender@twtxt.net yeah it wasn’t so much of a browser thing, more of a security/abuse thing. If you upload large media, we downsize/downscale it, etc.
**The Authorization Circus: Where Security Was the Main Clown **
Free Link 🎈
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/the-authorization-circus-where-security-was-the-main-clown-f4b84ca9356f?source=rss—-7b … ⌘ Read more
French lawmakers vote to tax American retirees who freely benefit from social security ⌘ Read more
Bank of America Faces Lawsuit Over Alleged Unpaid Time for Windows Bootup, Logins, and Security Token Requests
A former Business Analyst reportedly filed a class action lawsuit claiming that for years, hundreds of remote employees at Bank of America first had to boot up complex computer systems before their paid work began, reports Human Resources Director magazine:
… ⌘ Read more
Most DevSecOps Advice Is Useless without Context—Here’s What Actually Works
Generic DevSecOps advice may sound good on paper, but it often fails in practice because it ignores team context, workflow, and environment-specific needs. Overloaded controls, broad policies, and misapplied tools disrupt the flow of development. And once flow breaks, security measures are the first to get bypassed. The way forward isn’t more rules but smarter… ⌘ Read more
US Congressional Budget Office Hit By Suspected Foreign Cyberattack
An anonymous reader quotes a report from BleepingComputer: The U.S. Congressional Budget Office (CBO) confirms it suffered a cybersecurity incident after a suspected foreign hacker breached its network, potentially exposing sensitive data. In a statement shared with BleepingComputer, CBO spokesperson Caitlin Emma confirmed the “security incid … ⌘ Read more
US flight cancellations accelerate as airlines comply with government shutdown order
JOSH FUNK and RIO YAMAT, Reporters - Associated Press
_Stephan: I just got an email from a reader who has spent two days trying to get out of Chicago, but her flight has been canceled again and again. I have been warned not to fly because I would have to go through a security check and publishing SR may cause me to be detained, so I don’t have any person … ⌘ Read more
Cloud Native Computing Foundation Announces Graduation of Crossplane
Graduation marks Crossplane’s readiness for widespread use and its evolution from a control plane framework to groundwork for intelligent, secure, and scalable cloud operations and platform engineering Key Highlights: SAN FRANCISCO, Calif. – November 6, 2025… ⌘ Read more
Grinn GenioBoard Offers MediaTek Genio 700 SoM, Dual M.2 Expansion, and CRA-Ready Security
Grinn has unveiled the GenioBoard, a compact single-board computer aimed at accelerating development of embedded and AI-enabled systems. It integrates the company’s GenioSOM-510 and GenioSOM-700 modules built on MediaTek’s Genio processor family, combining multiple Arm Cortex-A cores with an integrated GPU and NPU for edge inference applications. Powered by the Medi … ⌘ Read more
The Louvre’s Video Surveillance Password Was ‘Louvre’
A bungled October 18 heist that saw $102 million of crown jewels stolen from the Louvre in broad daylight has exposed years of lax security at the national art museum. From trivial passwords like ‘LOUVRE’ to decades-old, unsupported systems and easy rooftop access, the job was made surprisingly easy. PC Gamer reports: As Rogue cofounder and former Polygon arch-jester Cass … ⌘ Read more
Danish Authorities In Rush To Close Security Loophole In Chinese Electric Buses
An anonymous reader quotes a report from the Guardian: Authorities in Denmark are urgently studying how to close an apparent security loophole in hundreds of Chinese-made electric buses that enables them to be remotely deactivated. The investigation comes after transport authorities in Norway, where the Yutong buses ar … ⌘ Read more
iOS 18.7.2 & iPadOS 18.7.2 Security Updates Released
iOS 18.7.2 and iPadOS 18.7.2 are available for iPhone and iPad users who are not running iOS 26 and who do not want to install iOS 26.1 update onto their devices. The iOS 18.7.2 and iPadOS 18.7.2 updates are security releases and do not include any new features or changes. Separately, iOS 26.1, iPadOS 26.1, … Read More ⌘ Read more
Louvre heist suspect is social media star and former museum security guard, reports say ⌘ Read more
oss-security - runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881
Comments ⌘ Read more
MacOS Sequoia 15.7.2 & MacOS Sonoma 14.8.2 Updates Released
MacOS Sequoia 15.7.2 and macOS Sonoma 14.8.2 are available as software updates for Mac users who are not running the macOS Tahoe operating system. Safari 26.1 is also available as an update for these versions of MacOS. These are security updates for macOS Sonoma and Sequoia, and the updates do not include new features or … [Read More](https://osxdaily.com/2025/11/04/macos-sequoia-15-7-2-macos-sonoma-14-8-2-updat … ⌘ Read more
Turris Omnia NG Introduced with OpenWRT-Derived OS, Wi-Fi 7, and 10 Gbps Networking
CZ.NIC has launched the Turris Omnia NG router, described as a new open-source device focused on security, performance, and modularity. It features a quad-core processor, Wi-Fi 7 connectivity, and M.2-based expandability, targeting users who require a long-lasting and adaptable networking platform. The Omnia NG is powered by a quad-core ARMv8 processor operating at 2.2 GHz […] ⌘ Read more
MacOS Tahoe 26.1 Update Released for Mac
Apple has released macOS Tahoe 26.1 for all Mac users, being the first major point release software update for macOS Tahoe since it debuted a few months ago. macOS Tahoe 26.1 includes a few new features, some bug fixes, and security patches, making it an important update to install for any Mac user that is … Read More ⌘ Read more
iOS 26.1 Update Released for iPhone & iPad
Apple has released iOS 26.1 for iPhone, and iPadOS 26.1 for iPad. These are the first major point release updates for iOS 26, and offer a few changes, new features, bug fixes, and security enhancements, and are therefore recommended for users running iOS 26 or iPadOS 26. You will find a new toggle for Liquid … Read More ⌘ Read more
Kristi Noem refuses state’s request not to use tear gas near children on Halloween
Carl Gibson, Contributing Writer - Raw Story
Stephan: The defining characteristics of the Trump vassals are their incompetence, their nastiness, and their desire to live the life of the uber-rich, and be protected while doing so from ordinary Americans. No one demonstrates this more openly than Department of Homeland Security Secretary Kristi Noem
 **
Free Link 🎈
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/how-i-m … ⌘ Read more
Securing the software supply chain: How distroless containers defend against npm malware attacks
The wake-up call: npm ‘is’ package compromise In July 2025, the npm package “is”—downloaded millions of times each week—was quietly hijacked. A simple phishing email to its maintainer opened the door for attackers to inject malicious… ⌘ Read more
theCUBE Research economic validation of Docker’s development platform
Docker’s impact on agentic AI, security, developer productivity, costs, ROI An independent study by theCUBE Research To investigate Docker’s impact on developer productivity, software supply chain security, agentic AI development, cost savings, and ROI, TheCUBE Research asked nearly 400 enterprise IT & AppDev leaders from medium to large global enterprises. The industry context is that… ⌘ Read more
$1000 Bounty: GitLab Security Flaw Exposed
How a $1000 Bounty Hunt Revealed a GraphQL Type Check Nightmare Allowing Maintainers to Nuke Repositories
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/1000-bounty-gitlab-security-flaw-exposed-dd30978 … ⌘ Read more
DietPi October 2025 Update Adds Support for NanoPi R3S, R76S, and Reworked Dashboard
The October 18th release of DietPi v9.18 introduces support for new FriendlyELEC single-board computers, a redesigned DietPi-Dashboard with improved security, and the addition of the LazyLibrarian eBook and audiobook manager. The update also includes bug fixes, filesystem improvements, and expanded compatibility for virtual devices DietPi: DietPi is a lightweight, Debian-base … ⌘ Read more
XMPP Interop Testing: Putting NTA 7532 to the Test (Literally)
You might have seen the XMPP Standards Foundation’s open letter to NEN about NTA 7532, the Dutch effort to standardise secure healthcare chat. It’s a good read, and, as it happens, right up our street.
If you’re building a chat system that has to actually talk to someone else’s chat system (and keep doctors happy while doing it), you’ll kno … ⌘ Read more
Python Software Foundation has bigger spine than big tech
Back in January 2025, the Python Software Foundation applied for a $1.5 million grant from the US government’s National Science Foundation, under the Safety, Security, and Privacy of Open Source Ecosystems program, to address structural vulnerabilities in Python and PyPI. After a lot of paperwork, their application was approved, but upon receiving the contractual agreement, the Python Software Foundation decided to b … ⌘ Read more
Ignite Realtime Blog: Helping Dutch Healthcare Speak the Same Language with XMPP
Helping Dutch Healthcare Speak the Same Language with XMPPThe XMPP Standards Foundation (XSF) has put out a call to action: it’s time for the community to help make secure, interoperable chat a reality - especially in healthcare. Here at Ignite Realtime, we’re excited to support this effort. Our projects, … ⌘ Read more
The XMPP Standards Foundation: Towards Secure and Interoperable Healthcare Chat
Supporting the development of the Dutch NTA 7532 standard with lessons from international practice
The XMPP Standards Foundation (XSF) is an independent, non-profit organization that promotes and advances open standards for real-time communication and collaboration. The XSF oversees the development of extensions to the Extensible Messaging and Presence Protocol (XMPP) and fost … ⌘ Read more
Panic as breached details of 183m accounts, including Gmail, emerge
The news isn’t nearly as bad as some online would have you believe, but it’s always a good idea to check your security. ⌘ Read more
How to Connect MCP Servers to Claude Desktop with Docker MCP Toolkit
What if you could turn Claude from a conversational assistant into a development partner that actually does things—safely, securely, and without touching your local machine? If you’ve been exploring Claude Desktop and wondering how to connect it with real developer tools, Docker MCP Toolkit is the missing piece you’ve been looking for. Here’s the reality:… ⌘ Read more