

Solar Designer
14.4K posts

@solardiz
@Openwall founder, @oss_security maintainer, @lkrg_org co-author, @CtrlIQ Linux security engineer. RTs don't imply agreement with points of view.






Qualys Threat Research Unit (TRU) discovered CrackArmor: 9 AppArmor flaws impacting 12M+ Linux systems since 2017. These enable root access & container breakouts. Patch your kernels now! Details: bit.ly/4s2c3O4 #Linux #Cybersecurity #CrackArmor"



passwdqc 2.0.3 releases for Unix-like and Windows systems are out, with many minor additions and changes. Leaked password filter files updated to HIBP v8, encoding the 847+ million unique passwords (from billions of accounts) in a 3.5 GB file. openwall.com/lists/announce…



Two AES libraries ship a default IV that guarantees key reuse. 700K+ repos depend on aes-js alone. A developer flagged the problem years ago, but it was never fixed. 🧵

git.kernel.org/pub/scm/linux/… @solardiz maybe relevant for the list




My article about the Munge Heap Buffer Overflow is available here ! blog.lexfo.fr/munge-heap-buf…

📢New 7ASecurity public #securityaudit report 🔒@zlib strengthened through a whitebox security audit by 7ASecurity. 10 findings. 100% fixed. What was uncovered? Read & share your feedback! 🔗7asecurity.com/blog/2026/02/z… #CyberSecurity #opensource #zlib #appsec #infosec



