Many people assume that an AI "Share" link is effectively private unless they send it to someone. That's not how the web works. Recently, users discovered that searches like site:claude.ai/share and site:claude.ai/public/artifacts returned publicly shared Claude conversations through search engines. Some indexed pages reportedly contained resumes, company discussions, code, and other sensitive information. Google began removing many results, but the incident highlights an important privacy lesson: once a conversation is published as a public webpage, it can become discoverable

 

cross-posted from: https://lemmy.world/post/49907053

A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available

 

A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) shows just how dangerous certificate-based authentication can become when trust breaks down. Certighost (CVE-2026-54121) allows a low-privileged domain user, under specific conditions, to obtain a certificate for a Domain Controller, authenticate using PKINIT, and perform DCSync to retrieve the krbtgt secret, potentially leading to complete Active Directory compromise. Microsoft patched the flaw in its July 2026 security updates, but a public proof-of-concept is now available

 

India has directed GitHub to disable access to the repositories of Bitchat, Jack Dorsey's decentralized Bluetooth mesh messaging application, under Section 79(3)(b) of the Information Technology Act and the IT Rules, 2021. According to the official notice issued by the Indian Cyber Crime Coordination Centre (I4C), authorities argue that Bitchat's decentralized architecture, lack of mandatory user registration, absence of centralized logging, and ability to operate without internet connectivity make lawful interception and criminal investigations significantly more difficult.

 

Oracle has released its July 2026 Critical Patch Update (CPU), containing 1,449 security patches across numerous product families. The advisory includes fixes for vulnerabilities affecting Oracle Database, Fusion Middleware, E-Business Suite, Java, Communications, and many other products, with Oracle recommending that customers apply updates without delay.

 

CVE-2026-50522 is a critical SharePoint deserialization vulnerability that is now being actively exploited. This article examines the vulnerability in depth, including the exploitation workflow, affected versions, machine-key theft for persistent access, patch analysis, indicators of compromise, and practical mitigation guidance for defenders.

[–] 2 points 5 days ago*

Coming from a samsung user, pixels do fascinate me a lot but seeing battery life and network issues, I step back. Honestly, want to try pixel once but battery life and worse network modem is holding me back. If rumours are to be believed, the next pixel will have a diff chip...not exynos as base...and a better modem ...prolly from mediatek. That'll improve the two aspects. Lets see.

Also about the watch, o no no. Used gw4 and switched to gw6 classic. Man, I LOVE the physical bezel. Digital one is pretty finicky

  • source
  •  

    A recent incident demonstrates how a vulnerability in a perimeter security appliance can become the first step in a much larger intrusion. This article examines the attack progression from PAN-OS GlobalProtect exploitation through credential theft, lateral movement, and eventual Qilin ransomware deployment, along with the published IoCs, attacker TTPs, and defensive recommendat

     

    The latest OpenSSL disclosure, HollowByte, demonstrates how seemingly small flaws in protocol handling can translate into denial-of-service conditions through uncontrolled memory consumption. This article examines the vulnerability's technical root cause, affected releases, attack prerequisites, remediation, and what it means for administrators running Internet-facing TLS services

    [–] [S] 1 point 1 week ago

    But the unfortunate truth is, who will oversee that it's being followed. Time and time again has shown that these agencies have different power on paper and unofficially...take the NSA or the CIA or literally any intelligence agency around the world and you'll find the same pattern

  • source
  • parent
  • context
  • [–] [S] 7 points 1 week ago

    Yup. IdentityDigital has confirmed its due to OFAC compliance. Presumably due to telegram not complying with the takedown order of the channel, registry (IdentityDigital) Was forced to suspend the entire t.me domain for compliance

  • source
  • parent
  • context
  • view more: next ›