macOS 26.4 has new Terminal popup warning when pasting commands - 9to5Mac https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/
sambowne@infosec.exchange
Posts
-
macOS 26.4 has new Terminal popup warning when pasting commands - 9to5Mac https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/ -
Magento PolyShell: unrestricted file upload in Magento and Adobe Commerce | Sansec https://sansec.io/research/magento-polyshellMagento PolyShell: unrestricted file upload in Magento and Adobe Commerce | Sansec https://sansec.io/research/magento-polyshell
-
The US just pulled the plug on ALL foreign-made Wi-Fi routers - Android AuthorityThe US just pulled the plug on ALL foreign-made Wi-Fi routers - Android Authority
The US just pulled the plug on ALL foreign-made Wi-Fi routers
The US FCC has effectively banned all new consumer-grade Wi-Fi routers from being approved, sold, or imported into the country.
Android Authority (www.androidauthority.com)
-
Attorneys say SFPD may have violated the law during ICE arrest at SFO - Mission LocalAttorneys say SFPD may have violated the law during ICE arrest at SFO - Mission Local
Attorneys say SFPD may have violated the law during ICE arrest at SFO
Attorneys say SFPD may have crossed a legal line when officers surrounded ICE agents during an arrest at the San Francisco airport.
Mission Local (missionlocal.org)
-
Has Iran brought down an ‘unkillable’ US F-35 jet?Has Iran brought down an ‘unkillable’ US F-35 jet? | US-Israel war on Iran News | Al Jazeera https://www.aljazeera.com/news/2026/3/23/has-iran-brought-down-an-unkillable-us-f-35-jet
-
Claude.ai Prompt Injection Vulnerability | Oasis Security https://www.oasis.security/blog/claude-ai-prompt-injection-data-exfiltration-vulnerabilityClaude.ai Prompt Injection Vulnerability | Oasis Security https://www.oasis.security/blog/claude-ai-prompt-injection-data-exfiltration-vulnerability
-
Clawhub Skill Malware Scanners are Worthless https://raxe.ai/labs/radar/radar-2026-002#malicious-or-not-adding-repository-context-to-agent-skill-classificationClawhub Skill Malware Scanners are Worthless https://raxe.ai/labs/radar/radar-2026-002#malicious-or-not-adding-repository-context-to-agent-skill-classification
-
Switzerland adopts SCION: A Secure Alternative to BGP - UBOS https://ubos.tech/news/switzerland-adopts-scion-a-secure-alternative-to-bgp/Switzerland adopts SCION: A Secure Alternative to BGP - UBOS https://ubos.tech/news/switzerland-adopts-scion-a-secure-alternative-to-bgp/
-
WATCH: Sen. Paul asks DHS nominee Mullin if he believes violence can resolve political differences | PBS News https://www.pbs.org/newshour/politics/watch-sen-paul-asks-dhs-nominee-mullin-if-he-believes-violence-can-resolve-political-differencesWATCH: Sen. Paul asks DHS nominee Mullin if he believes violence can resolve political differences | PBS News https://www.pbs.org/newshour/politics/watch-sen-paul-asks-dhs-nominee-mullin-if-he-believes-violence-can-resolve-political-differences
-
Infosec Decoded Season 6 #98: Phone HackingWith sambowne@infosecInfosec Decoded Season 6 #98: Phone Hacking
With sambowne@infosec.exchange and Doug Spindler
Recorded Thu, Mar 19, 2026
https://youtu.be/1phzkifxtak -
A major security flaw could affect 1 in 4 Android phones - here's how to check yours | ZDNET https://www.zdnet.com/article/security-flaw-affects-1-in-4-android-phones-how-to-check-yours/A major security flaw could affect 1 in 4 Android phones - here's how to check yours | ZDNET https://www.zdnet.com/article/security-flaw-affects-1-in-4-android-phones-how-to-check-yours/
-
How to Build a Production-Ready Claude Code Skill | Towards Data Science https://towardsdatascience.com/how-to-build-a-production-ready-claude-code-skill/How to Build a Production-Ready Claude Code Skill | Towards Data Science https://towardsdatascience.com/how-to-build-a-production-ready-claude-code-skill/
-
Threats to Minnesota’s Medicaid funds could set the stage for other states : NPR https://www.npr.org/2026/03/18/nx-s1-5751216/medicaid-minnesota-fraud-explainedThreats to Minnesota’s Medicaid funds could set the stage for other states : NPR https://www.npr.org/2026/03/18/nx-s1-5751216/medicaid-minnesota-fraud-explained
-
Judge throws DOJ attorney out of hearing over its oversight of prosecutions | AP News https://apnews.com/article/new-jersey-justice-department-federal-prosecutors-habba-c6882eeefa9432a349127715f3be7d55Judge throws DOJ attorney out of hearing over its oversight of prosecutions | AP News https://apnews.com/article/new-jersey-justice-department-federal-prosecutors-habba-c6882eeefa9432a349127715f3be7d55
-
Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.htmlUbuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit https://thehackernews.com/2026/03/ubuntu-cve-2026-3888-bug-lets-attackers.html
-
Dick Van Dyke Credits His Longevity to One Habit, And Science Supports It : ScienceAlert https://www.sciencealert.com/dick-van-dyke-credits-his-longevity-to-one-habit-and-science-supports-itDick Van Dyke Credits His Longevity to One Habit, And Science Supports It : ScienceAlert https://www.sciencealert.com/dick-van-dyke-credits-his-longevity-to-one-habit-and-science-supports-it
-
Here’s why I’ve installed a Dead Man's Switch on my home server https://www.androidauthority.com/home-server-dead-man-switch-3648903/Here’s why I’ve installed a Dead Man's Switch on my home server https://www.androidauthority.com/home-server-dead-man-switch-3648903/
-
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.htmlCritical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html
-
CursorJack: weaponizing Deeplinks to exploit Cursor IDE | Proofpoint US https://www.proofpoint.com/us/blog/threat-insight/cursorjack-weaponizing-deeplinks-exploit-cursor-ideCursorJack: weaponizing Deeplinks to exploit Cursor IDE | Proofpoint US https://www.proofpoint.com/us/blog/threat-insight/cursorjack-weaponizing-deeplinks-exploit-cursor-ide
-
Stryker attack wiped tens of thousands of devices, no malware needed https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/Stryker attack wiped tens of thousands of devices, no malware needed https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/