Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Em :official_verified:
Em :official_verified: boosted
Coywolf
@coywolf@coywolf.social  ·  activity timestamp 7 hours ago

With agentic AI embedded at the OS level, databases storing entire digital lives accessible to malware, tasks whose reliability quickly breaks down at each step, and being opted-in without consent, @signalapp leadership, @Mer__edith and Udbhav Tiwari, are sounding the alarm for the industry to pull back until threats can be mitigated.

https://coywolf.com/news/productivity/signal-president-and-vp-warn-agentic-ai-is-insecure-unreliable-and-a-surveillance-nightmare/

#AI #Privacy #InfoSec

Coywolf

'Signal' President and VP warn agentic AI is insecure, unreliable, and a surveillance nightmare

With agentic AI embedded at the OS level, databases storing entire digital lives accessible to malware, tasks whose reliability quickly breaks down at each step, and being opted-in without consent, Signal leadership is sounding the alarm for the industry to pull back until threats can be mitigated.
⁂
More from
Jon Henshaw
  • Copy link
  • Flag this post
  • Block
Coywolf
@coywolf@coywolf.social  ·  activity timestamp 7 hours ago

With agentic AI embedded at the OS level, databases storing entire digital lives accessible to malware, tasks whose reliability quickly breaks down at each step, and being opted-in without consent, @signalapp leadership, @Mer__edith and Udbhav Tiwari, are sounding the alarm for the industry to pull back until threats can be mitigated.

https://coywolf.com/news/productivity/signal-president-and-vp-warn-agentic-ai-is-insecure-unreliable-and-a-surveillance-nightmare/

#AI #Privacy #InfoSec

Coywolf

'Signal' President and VP warn agentic AI is insecure, unreliable, and a surveillance nightmare

With agentic AI embedded at the OS level, databases storing entire digital lives accessible to malware, tasks whose reliability quickly breaks down at each step, and being opted-in without consent, Signal leadership is sounding the alarm for the industry to pull back until threats can be mitigated.
⁂
More from
Jon Henshaw
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg:// boosted
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
Log in

Gnar 🔥 social

This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.

Gnar 🔥 social: About · Code of conduct · Privacy · Users · Instances
Gnar;🔥 social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login