NEW -
DCG real-ucode
Actually provides the latest CPU microcode for AMD and Intel
Version: 2025-03-24
updated ucode for amd and intel with that one !

NEW -
DCG real-ucode
Actually provides the latest CPU microcode for AMD and Intel
Version: 2025-03-24
updated ucode for amd and intel with that one !
NEW -
DCG rpm-hardened_malloc available
last updated:
2025/03/24
pkgver = 2025/01/27
pkgrel = 2
Compatibility:
- Fedora 39/40/etc.
- Arch Linux
Hardened allocator designed for modern systems
https://codeberg.org/divested/rpm-hardened_malloc
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #hardened_malloc #hardenedmalloc #linuxtech #cybersec #cybersecurity #antivirus
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #hardening #foss #infosec
NEW -
DCG Domain Blocklist available - last updated 2025/03/24
1690632 - Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
All available lists:
- uBlockOrigin
- Hosts format & Hosts format with wildcards
- dnsmasq with wildcards
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss
NEW -
D-WRT builds available: 2025-03-12
update to kernel 6.6.82
https://divested.dev/unofficial-openwrt-builds/mvebu-linksys
https://codeberg.org/divested/Divested-WRT
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss
We value your opinion! Please respond to our:
“CVE Data Usage and Satisfaction Survey”
https://forms.office.com/g/hx168RPctg
The CVE Program is requesting feedback from:
* CVE consumers
* Defenders
#cve #vulnerability #vulnerabilitymanagement #cybersecurity
March 12 UPDATE: Grafana Exploitation May Signal Multi-Phase SSRF Attacks. Update + original analysis: https://www.greynoise.io/blog/new-ssrf-exploitation-surge #Cybersecurity #GreyNoise #Vulnerability
NEW -
Brace Build 2025/03/06 - 1
Toolkit compatible with multiple Linux distros that allows for installation of handpicked applications, along with corresponding configs that have been tuned for reasonable privacy and security.
Compatibility:
Arch Linux
CentOS 9/Stream
Debian 12
Fedora 39/40/41 (preferred)
openSUSE Tumbleweed
https://codeberg.org/divested/brace
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #skynet #foss
They say the other one couldn't only be triggered if you're careless.
Two new pieces of Mac malware in the wild – one being fixed this week
https://9to5mac.com/2025/02/27/two-new-pieces-of-mac-malware-in-the-wild-one-being-fixed-this-week/
#Mac #macOS #Malware #Vulnerability #Security #InfoSec #Apple Tech
The #neck is a small part of our body with an outsize influence on culture, psychology, and biology. A biology professor’s new book explores how the neck came to symbolize of power, beauty, and #vulnerability: https://theconversation.com/how-the-human-neck-became-a-locus-of-power-beauty-and-frailty-238672 #evolution #vulnerability #vampires
Passkey/password bug: iOS 18.3.1
Ook in iOS versie 18.3.1 is de eerder door mij gemelde iCloud KeyChain (*) kwetsbaarheid nog niet gerepareerd (eerder schreef ik hierover, Engelstalig: https://infosec.exchange/@ErikvanStraten/113821443334366419).
(*) Tegenwoordig is dat de app genaamd "Wachtwoorden" (of "Passwords").
De kwetsbaarheid bestaat indien:
• De eigenaar een "passcode" (pincode of wachtwoord) gebruikt om de iPhone of iPad te ontgrendelen - en er GÉÉN biometrie is geconfigureerd;
ofwel:
• De gebruiker wel biometrie kan gebruiken om het scherm te ontgrendelen, doch in 'Instellingen' > 'Touch ID en toegangscode' de instelling "Autom. invullen wachtw." is UITgezet.
Zie onderstaande screenshots (Engelstalig in https://infosec.exchange/@ErikvanStraten/113821443334366419). Meer info ziet u door op "Alt" in de plaatjes te drukken.
Probleem: iedereen met toegang tot de ontgrendelde iPhone of iPad kan dan, *zonder* opnieuw lokaal te hoeven authenticeren:
1) Op elke website inloggen waarvan het user-ID en wachtwoord in iCloud Keychain zijn opgeslagen;
2) Met passkeys op enkele specifieke websites inloggen (waaronder https://account.apple.com en https://icloud.com), namelijk als volgt:
a) Open de website;
b) Druk op "Inloggen";
c) Druk op de "x" rechts bovenaan de pop-up die verschijnt (in de onderste schermhelft);
d) Druk kort in het veld waar om het e-mailadres gevraagd wordt;
e) Druk op de knop "gebruik passkey".
Risico: uitlenen van een unlocked iDevice (o.a. aan kinderen) maar ook diefstal nadat de passcode is afgekeken. Of als de dief geen passcode heeft, als deze wacht tot de eerstvolgende iOS/iPadOS kwetsbaarheid bekend wordt waarbij de schermontgrendeling omzeild kan worden.
Als u ze nog niet gezien heeft, bekijk in elk geval de eerste van de volgende twee video's van Joanna Stern (van de Wall Street Journal):
https://youtube.com/watch?v=QUYODQB_2wQ
https://youtube.com/watch?v=tCfb9Wizq9Q
I've just published my first article on my security research; starting things off light with a fun little content injection. :)
(This also happens to be the debut of a basic site generator I whipped up in Lua — long live the #IndieWeb, long live static HTML!)
#Apple fixes zero-day flaw affecting all devices
iOS 18.3 comes with #security fixes, including one for a zero-day exploited in the wild (tracked as CVE-2025-24085). The zero-day is a memory use-after-free in CoreMedia, which when exploited could allow malicious apps to elevate their privileges.
#cve #vulnerability #cybersecurity
https://techcrunch.com/2025/01/28/apple-fixes-zero-day-flaw-affecting-all-devices/
First step in your cybersecurity career:
Buy your mom a car.
Subaru security vulnerability allowed millions of cars to be tracked, unlocked, and started
We have released #security updates (1.0.14, 1.1.11, 1.2.11, 1.3.4) to address CVE-2025-23221, a #vulnerability in #Fedify's #WebFinger implementation. We recommend all users update to the latest version of their respective release series immediately.
The Vulnerability
A security researcher identified multiple security issues in Fedify's lookupWebFinger()
function that could be exploited to:
Fixed Versions
Changes
The security updates implement the following fixes:
How to Update
To update to the latest secure version:
# For npm users
npm update @fedify/fedify
# For Deno users
deno add jsr:@fedify/fedify
We thank the security researcher who responsibly disclosed this vulnerability, allowing us to address these issues promptly.
For more details about this vulnerability, please refer to our security advisory.
If you have any questions or concerns, please don't hesitate to reach out through our GitHub Discussions, join our Matrix chat space, or our Discord server.
2/2: Apple iOS/iPadOS
Many people, elderly in particular, do not use biometrics to unlock their devices, but a "passcode" (screen unlock code, typically a pincode) instead.
On iOS/IpadOS (I've not yet checked the latest versions), the user is NOT asked to enter their passcode any time when:
1) Autofilling password based credentials on ANY website;
2) loging in using passkeys to *some* of the websites that support "Webauthn Conditional UI" (apparently github is aware of this vulnerability, and prevents it themselves).
The latter includes https://icloud.com and https://account.apple.com, meaning that if my child borrows my iPhone after I unlock it (or a thief steals it in unlocked state, or watches me enter my passcode [1]) they can access most of my online data.
Note: when trying to log in, the request to unlock iCloud keychain using the passcode will pop up.
a) Tap X to cancel.
b) Tap in the field that reads "Email or phone number =>".
c) It will offer you to log in, using your passkey, by pressing the button "Use Passkey". No passcode or other secrets needed.
Note: this also happened when using specific iOS/iPadOS settings while having BIOMETRICS ENABLED, but I was unable to reproduce that right now - after Apple has -again- moved configuration settings all over the place - in order to "improve" whatever).
(I've reported this to Apple a long time ago: it's a "wont fix" - go figure).
[1] WSJ Joanna Stern's convincing video: https://youtube.com/watch?v=QUYODQB_2wQ (follow up: https://youtube.com/watch?v=tCfb9Wizq9Q)
During our scans we found ~70K applications exposing their VSCode SFTP config.
These are often critical and can include FTP/SSH credentials.
You can check this out here: https://leakix.net/search?q=%2Bplugin%3AVsCodeSFTPPlugin&scope=leak
All videos from The 38th Chaos Communication Congress (38C3) 2024:
Glacial Lake Floods - A Growing, Unpredictable Climate Risk
--
https://phys.org/news/2023-10-glacial-lake-unpredictable-climate.html <-- shared technical article
--
https://doi.org/10.1038/s41467-023-36033-x <-- shared paper
--
https://www.nature.com/articles/s43017-024-00554-w <-- shared paper
--
#GIS #spatial #mapping #spatialanalysis #climatechange #spatiotemporal #glaciallakeoutburstflood #GLOF #risk #hazard #water #hydrology #flood #flooding #risk #hazard #mitigation #publicsafety #global #river #melting #dam #ice #naturaldisaster #naturalhazard #breach #highmountain #Asia #Pakistan #China #Nepal #population #vulnerability #glacier #glacial #loss #infrastructure #loss #cost #death #injury #model #modeling #Alaska #Asia #NewZealand #Iceland #model #modeling
NEW - DCG /etc/hosts available - last updated 2024/12/20
1544291 - Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
@divested @DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #antivirus #foss
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #hardening #foss #opensource
NEW - DCG real-ucode - 2024-12-14 - 1
New intel-ucode with that one ! Lets goo
https://github.com/divestedcg/real-ucode/
#fsf #FUTO #Fedora #alpinelinux #hardening #linuxtech #cybersec #foss
#opensource #android #skynet #linuxsecurity #ucode #vulnerabilities #vulnerability