560 blogs tracked4,974 posts indexed

Search

30 results for “security” · titles, summaries and bodies · ranked by relevance

Security Center 2.0: Act on vulnerabilities in bulk across all your apps (opens on the source site)

Replit is the most secure place to vibe code. Today, we're making it dramatically easier to use the Security Center to understand your security posture across all Replit projects in your business. We’re also making it possible to remediate urgent security holes, such as active critical vulnerabilities on multiple published projects, in seconds. You can reach the Security Center from the Replit Homepage, or your Settings. When you land there, the first thing we want to answer is simple: which of my projects are actually at risk right now? Start with what's urgent At the top of Security Center,…

productexcerpt only · body stays at the source
From the web

Security Turtles All the Way Down (opens on the source site)

An amazing security lapse just occurred: a journalist was accidentally included on a group chat via Signal to discuss sensitive war plans. This was wrong on so many different levels—read the article; it’s one of the msot amazing things I’ve ever read—but what I want to talk about is what “secure” means. Let’s start with what Signal is. It bills itself as a “simple, powerful, and secure messenger”. It works more or less like any other text/voice/video communication platforms, but it’s strongly end-to-end encrypted. But is it really “secure”? That depends on your definition. The first layer up…

excerpt only · body stays at the source
From the web

HTTPS certificate industry phasing out less secure domain validation methods (opens on the source site)

Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical…

excerpt only · body stays at the source
From the web

HTTPS certificate industry phasing out less secure domain validation methods (opens on the source site)

Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical…

excerpt only · body stays at the source
From the web

September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack (opens on the source site)

On September 16, 2026, we faced a zero-day attack targeting one of our servers in Brazil. Our security team detected an attack exploiting a previously undetected vulnerability … The post September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack appeared first on Hostinger Blog.

engineeringexcerpt only · body stays at the source
From the web

Securing Your Email Sending With Python: Authentication and Encryption (opens on the source site)

Email encryption and authentication are modern security techniques that you can use to protect your emails and their content from unauthorized access. Everyone, from individuals to business owners, uses emails for official communication, which may contain sensitive information. Therefore, securing emails is important, especially when cyberattacks like phishing, smishing, etc.

pythonemailexcerpt only · body stays at the source
From the web

Architecting Security for Agentic Capabilities in Chrome (opens on the source site)

Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing. The primary new threat facing all agentic browsers is indirect prompt injection. It can appear in malicious sites,…

chromechrome-securityexcerpt only · body stays at the source
From the web

Architecting Security for Agentic Capabilities in Chrome (opens on the source site)

Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing. The primary new threat facing all agentic browsers is indirect prompt injection. It can appear in malicious sites,…

excerpt only · body stays at the source
From the web

How to keep your Postmark account secure: Best practices guide (opens on the source site)

Your Postmark API tokens are the keys to your email kingdom. One exposed token can mean unauthorized access to your account, potential data breaches, and a whole lot of stress you don't need. The good news? Keeping your account secure doesn't have to be complicated.This guide covers the essential practices that'll help you sleep better at night, knowing your Postmark credentials are locked down tight. Following Industry Standards: OWASP GuidelinesWhen it comes to web application security, you don't have to reinvent the wheel. The Open Web Application Security Project (OWASP) provides…

engineeringexcerpt only · body stays at the source
From the web

Security Caveat: Locked out of my server while traveling (opens on the source site)

I'm still on my self-hosting kick as of late, while also questioning my life choices around hosting my own git forge. The last week or so has included what appears to be a DDoS attack rather than some coordinated scraping effort by a sketchy LLM company. Open source will prevail, even if I'm being stubborn about giving in and setting up Anubis. WordPress has been its own other adventure, but this isn't meant to be a post about those security caveats. I'll save those for another week. The current dilemma is that I'm far from home, ~30 hours away up in Rhode Island. I'm sitting at Audrey's…

excerpt only · body stays at the source
From the web

Securing Software at the Speed of AI (opens on the source site)

Lessons from building an agentic software security strategy at PalantirIntroductionPalantir’s Product Security Team began experimenting with agentic AI across a variety of security workflows over a year ago. By the time Anthropic launched Project Glasswing, we were already using an internal multi-agent review harness with AI security agents focused on different areas of security expertise. Anthropic’s Mythos model and OpenAI’s cyber program helped to accelerate that work.Today, our team has operating capabilities for multi-agent source-code review, analyst-directed vulnerability hunting,…

agentic-softwareinformation-securityexcerpt only · body stays at the source
From the web

Port Scan with Spoofed IP Addresses (opens on the source site)

Or how to make naïve hosters shut down your victim’s server. Do you want to bring down your victim’s game servers? Do they host their game servers on cheap VPSes at hosters who are not that experienced with networking? Is running an actual DoS against the server too expensive and illegal for you? Just grab a server for yourself from a questionable hoster with IP address spoofing allowed on their network. Next run a port scan using nmap (man page) with a spoofed source address (-S or -D for multiple decoys) using your victim’s IP address(es). As the target of the port scan choose a university…

excerpt only · body stays at the source
From the web

Lessons in logging, part 2: mapping your path to a mature security program with logs and audit trails (opens on the source site)

This post is the second in a series about logging and audit trails from a security perspective. For the first post in the series, see Lessons in Logging: Chopping Down Security Risks Using Audit Trails If you’re looking to level up your security practices, logging is a good place to focus your attention. Just as logging is a core pillar of observability, comprehensive audit trails are a core pillar of a strong security program. Logs and audit trails are separate but overlapping concepts, and most companies can improve their security posture by investing in this area.

excerpt only · body stays at the source
From the web

Frequently Asked Questions about FHE (opens on the source site)

I work on homomorphic encryption (HE or FHE for “fully” homomorphic encryption) and I have written a lot about it on this blog (see the relevant tag). This article is a collection of short answers to questions I see on various threads and news aggregators discussing FHE. Facts If a service uses FHE and can respond to encrypted queries, can’t the service see your query? How is it possible to operate on encrypted data without seeing it?

excerpt only · body stays at the source
From the web

Lessons in logging: chopping down security risks using audit trails (opens on the source site)

This post is the first in a series about logging and audit trails from a security perspective. For the next post in the series, see Lessons in Logging, Part 2: Mapping Your Path to a Mature Security Program with Logs and Audit Trails At Latacora, we bootstrap security practices. We partner with companies that frequently have minimally developed security programs, work with them to figure out the right security practices for their current size, and then help them evolve and scale those practices as their business matures.

excerpt only · body stays at the source
From the web

AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack (opens on the source site)

AI security is an engineering problem. That means defined security requirements, enforceable controls, named owners and evidence that protections work. As AI becomes more capable, the industry must accelerate security engineering, broaden access to defensive tools and share what works faster. Technology Changes, Security Fundamentals Endure The internet and cloud computing changed how software operates, […]

aiagentic-aiexcerpt only · body stays at the source 31 comment on HN (opens the discussion)
From the web

Cultivating a robust and efficient quantum-safe HTTPS (opens on the source site)

Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant…

excerpt only · body stays at the source
From the web

Cultivating a robust and efficient quantum-safe HTTPS (opens on the source site)

Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant…

excerpt only · body stays at the source
From the web

What 50 open source projects taught us about security in the AI era (opens on the source site)

See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog.

maintainersopen-sourceexcerpt only · body stays at the source 41 comment on HN (opens the discussion)
From the web

Bring your security stack into Edge for Business — with support for more partners (opens on the source site)

At a glance Edge for Business security connectors extend your security tools into the browser, so you gain visibility and enforcement where work happens. This update adds new partner integrations, including Cisco Secure Access, The post Bring your security stack into Edge for Business — with support for more partners appeared first on Microsoft Edge Blog.

uncategorizedexcerpt only · body stays at the source
From the web

HTTPS by default (opens on the source site)

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks on a link, the browser ends up where the user intended. When links don't use HTTPS, an attacker can…

excerpt only · body stays at the source
From the web

Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification (opens on the source site)

Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. Supporting Next-Gen Android Features The implications for the future of secure mobile technology are…

excerpt only · body stays at the source
From the web

HTTPS by default (opens on the source site)

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks on a link, the browser ends up where the user intended. When links don't use HTTPS, an attacker can…

excerpt only · body stays at the source
From the web

Hardening with Firejail, Landlock, and bubblewrap (opens on the source site)

Recently I've been looking into securing my laptop a bit. By default, every single program has access to everything: filesystem, network, other programs. First, I started looking into Firejail. It allows specifying paths the program can access, as well as the network and other special things. It's not bad and I used it for a while. What I don't like about Firejail is that it's setuid: it runs as root, sets up the sandbox, then starts the program that is passed as an argument. If there is a problem in Firejail then it can even extend the blast radius. Then I learned about Landlock. It is…

excerpt only · body stays at the source
From the web

Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification (opens on the source site)

Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. Supporting Next-Gen Android Features The implications for the future of secure mobile technology are…

androidandroid-securityexcerpt only · body stays at the source
From the web

GitHub Secure Open Source Fund (opens on the source site)

Mark and Julien recently represented Bootstrap in the second round of the GitHub Secure Open Source Fund this past June. The program is designed to programmatically and financially improve the security and sustainability of open source projects, and we were honored to be a part of it. GitHub brought together open source maintainers, security experts, and ecosystem partners for an intensive, hands-on learning experience. Throughout three weeks, we had a few days of mixed expert-led presentations, collaborative workshops, and dedicated office hours with security specialists. Between sessions,…

excerpt only · body stays at the source
From the web

0Din: A GenAI Bug Bounty Program – Securing Tomorrow’s AI Together (opens on the source site)

As AI continues to evolve, so do the threats against it. As these GenAI systems become more sophisticated and widely adopted, ensuring their security and ethical use becomes paramount. 0Din is a groundbreaking GenAI bug bounty program dedicated specifically to help secure GenAI systems and beyond. In this blog, you'll learn about 0Din, how it works, and how you can participate and make a difference in securing our AI future. The post 0Din: A GenAI Bug Bounty Program – Securing Tomorrow’s AI Together appeared first on Mozilla Hacks - the Web developer blog.

artificial-intelligencefeatured-articleexcerpt only · body stays at the source
From the web

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.