attack-surface

Tag

Cards List
#attack-surface

modulejail: Proactively shrink a Linux host's kernel-module attack surface by blacklisting every module not currently in use

Lobsters Hottest · 2026-05-20 Cached

ModuleJail is a POSIX shell script that shrinks a Linux host's kernel-module attack surface by blacklisting every module not currently in use, helping sysadmins reduce risk from upcoming kernel module vulnerabilities.

0 favorites 0 likes
#attack-surface

Recent Kernel exploits, attack surface reduction, example IPSEC

Lobsters Hottest · 2026-05-16 Cached

Hanno Böck discusses recent kernel exploits affecting the ESP (IPSEC) module and suggests disabling IPSEC-related kernel config options to reduce attack surface, highlighting how many unused kernel modules are loaded by default.

0 favorites 0 likes
#attack-surface

Are AI agents creating a new runtime supply-chain attack surface?

Reddit r/AI_Agents · 2026-05-16

Discusses AI agent security as a runtime supply-chain problem beyond prompt injection, highlighting risks from untrusted data, tools, and feedback loops, and questions how developers enforce boundaries.

0 favorites 0 likes
← Back to home

Submit Feedback