Daniel Stenberg warns of risks in curl project

Daniel Stenberg, creator of the widely used curl program, draws parallels between his project and a cyberattack that nearly succeeded two years ago. In an interview in Huddinge, he stresses the importance of trust in open-source software underpinning the internet. An expert warns he could theoretically shut down half the internet.

In March 2024, Andres Freund, a Microsoft employee, discovered a backdoor in the Xz program inserted by Jia Tan under a pseudonym over several years. Xz is used for data compression on millions of servers. The update was halted at the last moment after Freund raised the alarm, foiling the attack.

Daniel Stenberg, who has developed curl since the mid-1990s, sees similarities with his own project. Curl, a tool for digital data transfer, has been installed about 20 billion times in devices like cars, mobile phones, and helicopters. "It was like an insider. One in the team. I also have people in my project I don't meet daily. No face. Just an online name," Stenberg says.

The project began as a way to fetch currency rates and relies on open source, open to contributions from anyone. Stenberg notes the world has changed since 1990s hacker meetups, but the appeal of sharing persists. "We must do something to protect us from that percentage of users trying to find mischief," he says.

KTH professor Pontus Johnson claims Stenberg could "shut down half the internet." Stenberg responds: "Trust is everything I have here. I can't break it or risk it." He acknowledges a security flaw in open source could have severe consequences but stresses suspicions would undermine its use.

Makala yanayohusiana

Dramatic illustration of a darknet leak of Swedish government IT data by hackers, showing computer screens with source code, passwords, and personal files.
Picha iliyoundwa na AI

Swedish government IT data leaked on darknet

Imeripotiwa na AI Picha iliyoundwa na AI

A hacker group called ByteToBreach has leaked sensitive information from a government IT system on the darknet. The leak includes source code, passwords, and personal data from a platform managed by IT consultant CGI Sweden. Authorities like Cert-SE confirm they are aware of the reports but decline to comment.

The cURL project, a key open-source networking tool, is ending its vulnerability reward program after a flood of low-quality, AI-generated reports overwhelmed its small team. Founder Daniel Stenberg cited the need to protect maintainers' mental health amid the onslaught. The decision takes effect at the end of January 2026.

Imeripotiwa na AI

A new report from Surfshark highlights that internet censorship impacted half the world's population in 2025, affecting 4.6 billion people. The company warns that the situation is set to worsen in 2026. This assessment comes amid growing concerns over digital freedoms globally.

An open-source AI assistant originally called Clawdbot has rapidly gained popularity before undergoing two quick rebrands to OpenClaw due to trademark concerns and online disruptions. Created by developer Peter Steinberger, the tool integrates into messaging apps to automate tasks and remember conversations. Despite security issues and scams, it continues to attract enthusiasts.

Imeripotiwa na AI

Ethereum co-founder Vitalik Buterin has voiced concerns over the European Union's Digital Services Act, warning it could eliminate space for controversial digital ideas. In a recent social media post, he advocated for greater user empowerment instead. This comes amid a surge in privacy-focused cryptocurrencies in 2025.

OpenClaw, an open-source AI project formerly known as Moltbot and Clawdbot, has surged to over 100,000 GitHub stars in less than a week. This execution engine enables AI agents to perform actions like sending emails and managing calendars on users' behalf within chat interfaces. Its rise highlights potential to simplify crypto usability while raising security concerns.

Imeripotiwa na AI

The EU Commission has presented a revised cybersecurity law to better fend off attacks and reduce dependencies on high-risk third countries. In particular focus: Chinese companies like Huawei and ZTE, which are to be effectively excluded from 5G rollout. This follows a recent hacker attack on the Eurail platform.

Alhamisi, 26. Mwezi wa tatu 2026, 21:31:45

Hackers release 93GB of data from crime tips platform

Jumatatu, 23. Mwezi wa tatu 2026, 09:31:59

Researchers uncover leaked API keys on nearly 10,000 websites

Alhamisi, 19. Mwezi wa tatu 2026, 20:22:13

Linux Foundation announces $12.5m for open source security

Alhamisi, 12. Mwezi wa tatu 2026, 10:38:45

Local Governments Promote OpenClaw AI Despite Central Warnings

Jumatano, 11. Mwezi wa pili 2026, 00:43:36

Researchers discover SSHStalker botnet infecting Linux servers

Jumanne, 10. Mwezi wa pili 2026, 19:39:23

New Linux botnet SSHStalker uses IRC for command-and-control

Jumatano, 4. Mwezi wa pili 2026, 19:25:39

Russian hackers exploit Microsoft Office vulnerability days after patch

Jumatano, 14. Mwezi wa kwanza 2026, 15:36:41

China directs firms to halt use of US and Israeli cybersecurity software

Jumamosi, 20. Mwezi wa kumi na mbili 2025, 05:05:16

Hackers steal millions of Pornhub users' data for extortion

Jumanne, 18. Mwezi wa kumi na moja 2025, 04:07:10

Cloudflare outage disrupts X and ChatGPT access

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa