Skip to content
  • 0 Votes
    12 Posts
    0 Views
    mason@partychickens.netM
    @h3artbl33d I'd think about fiction related to these ideas but frankly I dropped my power bills by taking these 1U servers out of service and replacing them with workstations. Still Xeon, still ECC, but less power draw - single power supply, larger fans that can spin slower.
  • 0 Votes
    2 Posts
    0 Views
    h3artbl33d@exquisite.socialH
    If you happen to have wp-cli:Update the core:wp core updateAnd check the admins:wp user list --role=administrator
  • GrapheneOS version 2026071500 released:

    World grapheneos privacy security
    1
    0 Votes
    1 Posts
    0 Views
    grapheneos@grapheneos.socialG
    GrapheneOS version 2026071500 released:https://grapheneos.org/releases#2026071500See the linked release notes for a summary of the improvements over the previous release.Forum discussion thread:https://discuss.grapheneos.org/d/40416-grapheneos-version-2026071500-released#GrapheneOS #privacy #security
  • 0 Votes
    1 Posts
    0 Views
    pitrh@mastodon.socialP
    OpenBSD's pledge(2) and unveil(2) are developer-friendly, study finds https://www.undeadly.org/cgi?action=article;sid=20260708055608 #openbsd #security #pledge #unveil #development #programming
  • RouterOS 7.23.2 release notes:

    World mikrotik routeros networking security
    3
    0 Votes
    3 Posts
    0 Views
    stefano@mastodon.bsd.cafeS
    @lw Schrödinger's patch
  • OpenSSH 10.4/10.4p1 released!

    World openbsd openssh ssh security cryptography
    1
    0 Votes
    1 Posts
    0 Views
    pitrh@mastodon.socialP
    OpenSSH 10.4/10.4p1 released! https://www.undeadly.org/cgi?action=article;sid=20260706190144 #openbsd #openssh #ssh #security #cryptography #secureshell
  • Torvalds attacks IT industry 'security circus'

    World linux openbsd security
    1
    0 Votes
    1 Posts
    39 Views
    CiotBSDC
    Linux creator calls OpenBSD crowd a bunch of "monkeys" and criticizes those who publicize security flaws to gain notoriety. https://www.cnet.com/tech/tech-industry/torvalds-attacks-it-industry-security-circus-1/
  • 1 Votes
    1 Posts
    173 Views
    grahamperrinG
    https://freebsdfoundation.org/blog/freebsd-ai-assisted-vulnerability-discovery-project-launch/ … the key goal of reducing the number of exploitable vulnerabilities in the FreeBSD source code. The 6-month project is being funded by a grant from the Alpha Omega project. The funds will be used to engage FreeBSD Security Team members under fixed-term contracts to find and patch vulnerabilities. The Security Team’s access to publicly available AI models and tokens will be provided free of charge. AI will be used for vulnerability discovery and analysis only, all patches will be manually created. … In GitHub: all-projects/AI-assisted-vulnerability-discovery at main · FreeBSDFoundation/all-projects FreeBSD Receives Funding To Launch AI-Assisted Vulnerability Discovery - Phoronix discussion via https://fosstodon.org/@governa/116755744623083032 @governa@fosstodon.org FreeBSD AI-assisted Vulnerability Discovery Project launch | The FreeBSD Forums Cross-posted to r/freebsd in Reddit.
  • 1 Votes
    1 Posts
    111 Views
    grahamperrinG
    https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA). PDF, 44 pages. Context Open source organisations weigh in on age attestation Availability Noted in Reddit: … easily found with Google – without completing Black Duck's form, which requires a business email address: https://www.google.com/search?q="2026+Open+Source+Security+and+Risk+Analysis+Report"+PDF&udm=14 …
  • [vez.mrks.md]

    FreeBSD freebsd security hardening
    6
    -1 Votes
    6 Posts
    525 Views
    CiotBSDC
    No problem with the vote @grahamperrin said: For what it's worth, I think: don't delete it from BSD Cafe Billboard. It's good to raise awareness of the reputation. I hadn't thought of it that way. Interesting!
  • 0 Votes
    1 Posts
    92 Views
    CiotBSDC
    In the world of open source, trust is our most valuable currency. ONAP is a “collection of individual, semi-standalone network automation functions that provide design, orchestration, observability, and automation of network and edge services for operators, cloud providers, and enterprises” (per ONAP). When we build software that powers global telecommunications, “good enough” isn’t an option… https://openssf.org/blog/2026/05/07/the-road-to-gold-how-cps-set-a-new-standard-for-security-and-quality-in-open-source/
  • 2 Votes
    1 Posts
    111 Views
    CiotBSDC
    ⇒ Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardship (2025/09/23) An Open Letter from the Stewards of Public Open Source Infrastructure Over the past two decades, open source has revolutionized the way software is developed. Every modern application, whether written in Java, JavaScript, Python, Rust, PHP, or beyond, depends on public package registries like Maven Central, PyPI, crates.io, Packagist and open-vsx to retrieve, share, and validate dependencies. These registries have become foundational digital infrastructure – not just for open source, but for the global software supply chain… https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/ ⇒ Open Infrastructure Is Not Free, Part II: The Hidden Cost of Running Package Registries (2026/05/06) The September 2025 Working Together Towards Sustainable Open Source open letter raised the alarm about the economic sustainability of open source package registries, highlighting how rising adoption and the pace of innovation are placing new and growing pressures on open source package registries. Those pressures have only accelerated in the time since the letter, amplified by the adoption of AI coding agents and tools… https://openssf.org/blog/2026/05/06/open-infrastructure-is-not-free-part-ii-the-hidden-cost-of-running-package-registries/
  • 2 Votes
    1 Posts
    228 Views
    grahamperrinG
    https://www.daemonology.net/blog/2026-04-11-20-years-on-AWS-and-never-not-my-job.html I created my first AWS account at 10:31 PM on April 10th, 2006. I had seen the announcement of Amazon S3 and had been thinking vaguely about the problem of secure backups — even though I didn't start Tarsnap until several months later — and the idea of an online storage service appealed to me. The fact that it was a web service made it even more appealing; I had been building web services since 1998, … – 24–30 minutes reading time, according to Firefox. Time well spent, IMHO, especially with security vulnerabilities for various operating systems recently in a spotlight. Also: to Mastodon @cperciva@mastodon.social @stefano and to Lobsters. Background: Colin Percival was, for many years, the FreeBSD Security Officer. He is now the FreeBSD Release Engineering Lead. You can show your appreciation for today's blog post at his shares in Reddit, in Hacker News, or in LinkedIn. A thought: AWS has its heroes. Tarsnap has given 2^18 dollars to open source – for this, and for what's described in today's blog post, it's probably fair to describe Colin as a hero in more ways than one.
  • 1 Votes
    2 Posts
    168 Views
    grahamperrinG
    For convenience, from the toot in Mastodon: https://www.reddit.com/r/freebsd/comments/1sgmi14/claude_mythos_preview_fully_autonomously_finds/ … (plus Linux, OpenBSD, and others) – more concerning than calif.io story with known CVE and human prompting? …" – @bigsneakyduck (Sorry. I imagined that the original mention in Mastodon would have shared the whole of the toot as the opening post here.)