Disabled system extensions & system policies at build-time.
Disabled & removed the build dependency on legacy AutoConfig functionality (also known as Mission Control Desktop, debuted in Netscape Communicator 4.5... https://www.internetnews.com/enterprise/netscape-unveils-enterprise-management-tools/) to reduce attack surface and reliance on legacy code.
Disabled more unnecessary debugging/development features at build-time.
Explicitly disabled SpiderMonkey performance telemetry at build-time.
Enabled mobile optimizations at build-time.
Updated the onboarding to remove Privacy Policy/Terms of Use references, and replaced the Firefox logo (and certain other elements) with our own.
Removed Swisscows as a default search engine due to concerns regarding false marketing of their VPN and spreading false claims about other services, such as Signal.
Other minor tweaks, fixes, & adjustments.
https://gitlab.com/ironfox-oss/IronFox/-/releases
Disabled & removed the build dependency on legacy AutoConfig functionality (also known as Mission Control Desktop, debuted in Netscape Communicator 4.5... https://www.internetnews.com/enterprise/netscape-unveils-enterprise-management-tools/) to reduce attack surface and reliance on legacy code.
Disabled more unnecessary debugging/development features at build-time.
Explicitly disabled SpiderMonkey performance telemetry at build-time.
Enabled mobile optimizations at build-time.
Updated the onboarding to remove Privacy Policy/Terms of Use references, and replaced the Firefox logo (and certain other elements) with our own.
Removed Swisscows as a default search engine due to concerns regarding false marketing of their VPN and spreading false claims about other services, such as Signal.
Other minor tweaks, fixes, & adjustments.
https://gitlab.com/ironfox-oss/IronFox/-/releases
GitLab
feat: Ensure system extensions + system policies are disabled (a2087a1e) ยท Commits ยท IronFox OSS / IronFox ยท GitLab
Signed-off-by: celenity
Forwarded from cKure
โ โ โ โ โก A proof-of-concept program has been released to demonstrate a so-called monitoring "blind spot" in how some Linux antivirus and other endpoint protection tools use the kernel's io_uring interface.
That interface allows applications to make IO requests without using traditional system calls. That's a problem for security tools that rely on syscall monitoring to detect threats.
https://developers.redhat.com/articles/2023/04/12/why-you-should-use-iouring-network-io
https://www.theregister.com/2025/04/29/linux_io_uring_security_flaw/
That interface allows applications to make IO requests without using traditional system calls. That's a problem for security tools that rely on syscall monitoring to detect threats.
https://developers.redhat.com/articles/2023/04/12/why-you-should-use-iouring-network-io
https://www.theregister.com/2025/04/29/linux_io_uring_security_flaw/
The Register
Watch out for any Linux malware sneakily evading syscall-watching antivirus
: Google dumped io_uring after $1M in bug bounties
Forwarded from Hacker News
Must read for tg user!!! ๐ค๐ก๐๐คฎ
https://tginfo.me/esafety-analysis-en/ telegram will read all messages including private messages
https://tginfo.me/esafety-analysis-en/ telegram will read all messages including private messages
Telegram Info
Some Details About Moderation in Telegram From Australian Regulatorโs Investigation
An excerpt of the most interesting facts from eSafety's investigation into how Telegram moderation works
Forwarded from ATT โข Tech News (Agam)
Microsoft is making Office apps load at startup
Microsoft is introducing "Startup Boost" for Office apps, beginning with Word in mid-May 2025. It will enhance load times by preloading the apps at Windows startup. It is only available for PCs having at least 8GB of RAM and 5GB of free disk space to maintain performance.
The scheduled task will wait for 10 minutes before execution to prevent slowing down Windows on login. After the task executes, the app remains in paused state. It can be disabled via app settings or Task Scheduler. The feature will later extend to other Office apps.
๐ MS365 Message Center
๐งโ๐ป @agamtechtricks
Microsoft is introducing "Startup Boost" for Office apps, beginning with Word in mid-May 2025. It will enhance load times by preloading the apps at Windows startup. It is only available for PCs having at least 8GB of RAM and 5GB of free disk space to maintain performance.
The scheduled task will wait for 10 minutes before execution to prevent slowing down Windows on login. After the task executes, the app remains in paused state. It can be disabled via app settings or Task Scheduler. The feature will later extend to other Office apps.
๐ MS365 Message Center
๐งโ๐ป @agamtechtricks
Forwarded from The Hacker News
๐จ AI isnโt just writing your code โ itโs leaking your secrets.
New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.
๐ 1,200+ repos leaked secrets in 2025 alone.
๐ Donโt trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.
๐ 1,200+ repos leaked secrets in 2025 alone.
๐ Donโt trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
Forwarded from The Hacker News
๐ฅ UPDATE - A public PoC exploit is now available for a serious SonicWall SMA exploit chain.
โก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu
CISA has added both to the KEV catalog โ federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.
๐ Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
โก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu
CISA has added both to the KEV catalog โ federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.
๐ Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
Forwarded from The Hacker News
๐ Microsoft goes passwordless by default for all new accounts.
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
Forwarded from XiaomiTime: Xiaomi & HyperOS News (IFTTT)
Xiaomi may be moving towards a Google-free future with HyperOS, potentially collaborating with BBK and Huawei. This shift could redefine the smartphone market and reduce reliance on Google services while building their ecosystem. Stay tuned for updates!
๐ Check More
๐ Check More
XiaomiTime
Is Xiaomi planning a Google-free Android future with HyperOS? - XiaomiTime
There have been rumors in the tech space of a collaboration among three Chinese tech players - Xiaomi, BBK Group (parent company of OPPO, Vivo, and OnePlus),
Forwarded from Hacker News
Forwarded from Hacker News
Krebs on Security
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
A employee at Elon Musk's artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made forโฆ
Forwarded from ๐ฝ๐ผ๐ฝ๐ ๐ข๐๐ฆ | ๐๐ข๐ฆ๐ฆ, ๐๐ถ๐ณ๐ฒ, ๐ ๐ฒ๐บ๐ฒ๐ (รmer)
Weather Doge
Wow, doge weather for Android.
๐ Links:
- Download
- Screenshots
- Features
- Source code
Developer: VersoBit
โ๏ธFriendly reminder:
๐ท Tags: #Android #Utilities
Wow, doge weather for Android.
๐ Links:
- Download
- Screenshots
- Features
- Source code
Developer: VersoBit
โ๏ธFriendly reminder:
If you find it useful, You may star the repo/app, donate to the developer, or perhaps you may also contribute to the development of this project.
๐ท Tags: #Android #Utilities
Forwarded from It's FOSS
The UN is slowly moving away from proprietary solutions.
https://news.itsfoss.com/un-ditches-google-form/
https://news.itsfoss.com/un-ditches-google-form/
It's FOSS
UN Ditches Google for Taking Form Submissions, Opts for an Open Source Solution Instead
The United Nations opts for an open source alternative to Google Forms.
Forwarded from The Hacker News
๐ฅ Automate the chaos. Stay ahead of CVEs.
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
Forwarded from The Hacker News
๐จ TikTok Fined โฌ530M for secretly storing EU user data in China, violating GDPR rules.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
Forwarded from Bones' Tech Garage
How you can use ALL the AI you want from one web interface using Open WebUI and LiteLLM and your own Virtual Private Server:
https://rumble.com/v6sl7mf-i-made-a-roladex-of-ai-that-i-now-use-every-day-open-webui-and-litellm.html
https://rumble.com/v6sl7mf-i-made-a-roladex-of-ai-that-i-now-use-every-day-open-webui-and-litellm.html
Rumble
I made a Roladex of AI that I now use every day! | Open WebUI and LiteLLM
Open WebUI alongside a plugin called LiteLLM allows us to use ALL the AI we want under one umbrella, in one browser tab, on our own private server. In this video I show you the results of following al