<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[The attribution for Mastodon&#x27;s CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:]]></title><description><![CDATA[<p>The attribution for Mastodon's CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:</p><p>"This security issue has been reported by Doyensec in collaboration with Claude and Anthropic Research"</p><p>Is this how they say "Mythos" without revealing that Doyensec is one of the undisclosed Project Glasswing members?</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://github.com/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73" title="LD-Signature Bypass via JSON-LD Named-Graph Restructuring">
<img src="https://opengraph.githubassets.com/c2f3238e9ef74066f23d4f22882bf9e63a50850f4d4103f078e1f03e872c765a/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://github.com/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73">
LD-Signature Bypass via JSON-LD Named-Graph Restructuring
</a>
</h5>
<p class="card-text line-clamp-3">GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.</p>
</div>
<a href="https://github.com/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://github.githubassets.com/favicons/favicon.svg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">GitHub <span class="text-secondary">(github.com)</span></p>
</a>
</div><p></p><p><a href="https://w.on-t.work/activitypub/may-2026-vulnerability" rel="nofollow noopener"><span>https://</span><span>w.on-t.work/activitypub/may-20</span><span>26-vulnerability</span></a> says:</p><p>"Doyensec has contacted us on *behalf* of Anthropic".<br /><a href="https://freeradical.zone/tags/security" rel="tag">#<span>security</span></a> <a href="https://freeradical.zone/tags/mastoadmin" rel="tag">#<span>mastoadmin</span></a> <a href="https://freeradical.zone/tags/mythos" rel="tag">#<span>mythos</span></a> <a href="https://freeradical.zone/tags/ai" rel="tag">#<span>ai</span></a> <a href="https://freeradical.zone/tags/glasswing" rel="tag">#<span>glasswing</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/d0d82ea7-460e-41db-b71d-8c4f002eced1/the-attribution-for-mastodon-s-cve-2026-46349-cvss-5.3-retracted-boost-reissuance-is-interestingly-reported-as</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 07:18:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/d0d82ea7-460e-41db-b71d-8c4f002eced1.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 24 May 2026 15:19:11 GMT</pubDate><ttl>60</ttl></channel></rss>