Linux Kernel Runtime Guard Reaches 1.0: A Major Milestone for Runtime Kernel Security | Linux Journal
AI bot traffic closing in on human web visits, study finds
: RAG bots could overtake human visitors on publisher sites this year, trackers tell us
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
Hackers breach 37 countries in ongoing espionage campaign
Brazil's Ministry of Mines and Energy, the Czech Republic's parliament and an Indonesian government official were each hit.
How the Clawdbot/Moltbot AI Assistant Becomes a Backdoor for System Takeover | Straiker
Security research uncovered over 4,500 exposed Clawdbot/Moltbot instances globally—concentrated in the US, Germany, Singapore, and China—with testing confirming attackers can exfiltrate API keys, service tokens, and WhatsApp session credentials for surveillance.
moltbook - the front page of the agent internet
A social network built exclusively for AI agents. Where AI agents share, discuss, and upvote. 🦞🤖
From Legacy Systems to Cloud Security: The Toby Foss Story
Discover how Toby Foss transformed early telecom work into modern cloud security leadership through adaptability, innovation, and continuous learning.
Top 10 Challenges in DevSecOps Adoption | Veracode
Application Security for the AI Era | Veracode
Council Post: 16 Reasons DevSecOps Efforts Fail (And How To Get Them Right)
Adopting DevSecOps isn’t a simple, single step; it requires new partnerships and processes backed by the full commitment of stakeholders.
DevSecOps vs. SecDevOps: Which Security Model Fits Your Business?
DevSecOps vs. SecDevOps explained—key differences, benefits, use cases, and how to choose the right security-first development approach for your organization in 2026
Trust & Reputation Signals — Superversive
In a mafia state of criminal power politics, trust collapses. When trust collapses, buyers grow paranoid and default to two survival strategies: familiarity and reputation. Known & Safe Familiarity drives choices toward what feels known and safe: longstanding relationships, familiar proc
What Is the Big Secret Surrounding Stingray Surveillance?
State and local law enforcement agencies across the U.S. are setting up fake cell towers to gather mobile data, but few will admit it
Cell-Site Simulators/ IMSI Catchers
Cell-site simulators, also known as Stingrays or IMSI catchers, are devices that masquerade as legitimate cell-phone towers, tricking phones within a certain radius into connecting to the device rather than a tower.
Cell-site simulators operate by conducting a general search of all cell phones within the device’s radius, in violation...
How to Block StingRay Surveillance: Detection & Protection
Learn what IMSI catchers are, who uses them, how to detect a StingRay device and why you should protect your data from being captured.
How ICE Is Using Fake Cell Towers To Spy On People’s Phones
ICE is using a controversial spy tool to locate smartphones, court records show.
Stingray phone tracker - Wikipedia
cellular phone surveillance device
Torito CertPatrol - Certificate Transparency Monitoring Tool
CertPatrol: A lightweight local Certificate Transparency log tailer and CertStream alternative for domain monitoring and brand protection
EthicalAds Newsletter - January 2026
Quarterly update for Q1 2026, covering the previous 3 months and including stats and commentary on our progress as we build EthicalAds
Escaping the Trifecta
So you’ve read Simon Willison’s post about the lethal trifecta and how, like the infinity stones on Thanos’ gauntlet, you really don’t want them all to be present at once.
The lethal trifecta for AI agents: private data, untrusted content, and external communication
If you are a user of LLM systems that use tools (you can call them “AI agents” if you like) it is critically important that you understand the risk of …
Running the "Reflections on Trusting Trust" Compiler - ACM Queue
PageXray by FouAnalytics
Firehound | Security Operations
Industrial management platform for Firehound-Go scans.
How to Sandbox Linux Apps with Firejail and Bubblewrap
Learn how to Sandbox Linux apps with Firejail and Bubblewrap. Isolate apps easily for stronger security, privacy, and system protection.
What is Bubblewrap? How to use it?
Bubblewrap is a command-line sandboxing tool for creating unprivileged containers and securely running Linux applications. It’s uses user_namespaces feature for creating unprivileged containers.
How to Sandbox Linux Apps with Firejail and Bubblewrap
Learn to sandbox Linux apps with Firejail Bubblewrap. Secure your system by isolating potentially risky applications. Stay safe online
CWE - CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.
Why Russian Hackers Are Abandoning Zero-Days for Misconfigurations
Learn how Russian hackers exploit vulnerabilities in cloud environments, challenging traditional security assumptions.
Decentralized Identifiers (DIDs): The Future of Digital Identity
Decentralized Identifiers (DIDs) are transforming digital identity by giving users full control, better privacy, and secure authentication without central authorities.
The Making of Digital Identity - 03 - The Network Era
How we discovered that bits aren't wax, trust doesn't scale, and humans will always route around friction like water around stone.