We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.
Conversation
Notices
-
Embed this notice
BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 13-May-2026 07:35:08 JST
BrianKrebs
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 13-May-2026 09:52:24 JST
Rich Felker
@briankrebs It's always been that way. The update channel IS the backdoor. And the updates have always been malicious, even if not in the ways infosec dorks recognized as malicious (limited to draining your bank directly, ignoring things like dark patterns, mental health harm, accessibility harm, exfiltrating your data to their servers & later to AI training, harvesting biometrics from your photos, tricking you into signing up for scams/unwanted services, ...)
-
Embed this notice