Google Play is changing how Android apps access your contacts and location

Google’s new set of Google Play policy updates and account transfer feature strengthen user privacy and protect businesses from fraud. Google is also expanding features for managing new contact and location policy changes to support a smoother, more pr… Continue reading Google Play is changing how Android apps access your contacts and location

Tails 7.6.2 patches vulnerability that could expose saved files

The Tails Project released Tails v7.6.2, an emergency release of the popular open source secure portable operating system. What is Tails? Tails, which is based on Debian GNU/Linux, is aimed at users who want to preserve their online privacy and anonymi… Continue reading Tails 7.6.2 patches vulnerability that could expose saved files

OpenAI updates Agents SDK, adds sandbox for safer code execution

OpenAI’s updated Agents SDK helps developers build agents that inspect files, run commands, edit code, and handle tasks within controlled sandbox environments. The update provides standardized infrastructure for OpenAI models, a model-native harness th… Continue reading OpenAI updates Agents SDK, adds sandbox for safer code execution

Product showcase: Ente Auth encrypts, backs up, and syncs 2FA

Two-factor authentication (2FA) is an essential layer of protection for online accounts, and Ente Auth makes it easier to manage securely across devices. Ente Auth is a free, open-source authenticator app designed to generate and store one-time passcod… Continue reading Product showcase: Ente Auth encrypts, backs up, and syncs 2FA

Wi-Fi roaming security practices for access network providers and identity providers

Public Wi-Fi roaming networks carry authentication credentials across multiple administrative boundaries, and the protocols governing that process vary widely in their security properties. The Wireless Broadband Alliance published a set of guidelines t… Continue reading Wi-Fi roaming security practices for access network providers and identity providers

Raspberry Pi OS 6.2 disables passwordless sudo by default

Raspberry Pi OS 6.2, based on the Trixie version, introduces small changes, bug fixes, and disables passwordless sudo by default for new installations. Screenshot of password prompt (Source: Raspberry Pi) “We continually review the security of Raspberr… Continue reading Raspberry Pi OS 6.2 disables passwordless sudo by default

What changed in nginx 1.30.0 and what it means for your upstream config

nginx 1.30.0 brings together features accumulated across the 1.29.x mainline series. The release covers a broad range of changes, from protocol support additions to security-relevant fixes and new configuration options. Keepalive to upstreams is now on… Continue reading What changed in nginx 1.30.0 and what it means for your upstream config

Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab

Misconfigured source code management platforms remain a common entry point in software supply chain attacks, and organizations often lack visibility into which settings put them at risk. Legitify, an open-source tool from Legit Security, addresses that… Continue reading Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab

OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support

OpenSSL 4.0.0 removes several long-deprecated features, adds support for Encrypted Client Hello, and introduces API-level changes that will require code updates for applications built against older versions. SSLv3, SSLv2 client hello, and engines are g… Continue reading OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support