Post B5nzJOF4iH682gAP2G by Viss@mastodon.social
 (DIR) More posts by Viss@mastodon.social
 (DIR) Post #B5nzJN1vDgyyHb0NtY by Viss@mastodon.social
       0 likes, 0 repeats
       
       #copyfailjust to chime in on the copyfail thing, while, yes, it is a very big deal, the prerequisite is that you have a shell on the box you wish to exploit. so keep that in mind when doing risk register stuff. attackers will aim for shit like jumpboxes, shared hosting environments, multi-tennancy environments, and places they can get a shell, then move laterally to get you. shops doing yolo devops are gonna get targeted, and I wouldnt be surprised to see openclaw malicious skills too
       
 (DIR) Post #B5nzJNQ1m4GTUMHdT6 by Viss@mastodon.social
       0 likes, 0 repeats
       
       it this exact flavor of bullshit that i worry about whenever someone tries to convince me that keeping a password vault in the cloud is ok.how soon does your vendor patch?do they even know?will they even patch? do they care?because you have given that control surface to them, and they have protected themselves from you by way of using contract language
       
 (DIR) Post #B5nzJNkaXciAW7u3W4 by Viss@mastodon.social
       0 likes, 0 repeats
       
       this is the cost of convenience today in 2026
       
 (DIR) Post #B5nzJNzTeGcZGIrwiu by Viss@mastodon.social
       0 likes, 0 repeats
       
       "but viiihiihiiiiiiss... i dont waaaaaaannuh sysadmin"okay, cool, i hope your vest has plates in it and your helmet is on tight
       
 (DIR) Post #B5nzJOF4iH682gAP2G by Viss@mastodon.social
       0 likes, 0 repeats
       
       right now, every single remote code vuln that will lead to command injection or rce will make this #copyfail thing a very very big deal.so all those qa servers and staging servers and test boxes you think nobody gives a shit about that are just flapping out there in the public, not being logged, not in the siem, not getting alerted on, not getting patched?all those are gonna catch the "oops attackers overwrote sshd to steal creds" disease. or cryptominers. or proxies.
       
 (DIR) Post #B5nzJOc7KbWtC8wnx2 by Viss@mastodon.social
       0 likes, 0 repeats
       
       this is why ive been on a tear about architectural defensive measures, and adversarial defensive measures. because when you build shit from the ground up to be defensively positioned at the architecture layer, this shit is way harder to exploit - purely because its way less accessible. every k8s cluster out there right now with alpine linux rocking kernel 6.7 or whatever is kindling for this thing.
       
 (DIR) Post #B5nzJOwg69yaDuZE00 by Viss@mastodon.social
       0 likes, 0 repeats
       
       having the architecture component sorted ahead of time means this problem goes from a "oh fuck oh fuck oh fuck get everyone out of bed" problem to a "okay, make sure the logging is solid, lets add some detection rules, and lets make sure the patches get inserted the second they land" flavor of issue
       
 (DIR) Post #B5nzJPCd8qjj1O1xrc by Viss@mastodon.social
       0 likes, 0 repeats
       
       yes, i can help, phobos has your back, remember?
       
 (DIR) Post #B5nzJPNGVJF9YN0SRM by Viss@mastodon.social
       0 likes, 0 repeats
       
       this fixed it for me:cat >/etc/modprobe.d/disable-algif-aead.conf <<'EOF'install algif_aead /bin/falseblacklist algif_aeadEOFdepmod -armmod algif_aeadi tested with this:  https://github.com/rootsecdev/cve_2026_31431
       
 (DIR) Post #B5nzJPbndGryHRo45w by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @Viss you don’t need to depmod