A certain Chrome alternative is closing its Mastodon server. For those who are looking for a new instance to move to, might I suggest joinmastodon.org. For the actual how-to of moving, fedi.tips has you covered.
Category: Mastodon News
Mastodon vulnerability – admins must update with urgency
A vulnerability in Mastodon’s origin validation has been discovered. Admins are urged to update to fix this flaw as soon as possible.
With a 9.4 severity score, exploiting CVE-2024-23832 potentially allows attackers to take over Mastodon accounts remotely.
Critical vulnerability in Mastodon is pounced upon by fast-acting admins, The Register
Every Mastodon version prior to 3.5.17 is vulnerable, as are 4.0.x versions before 4.0.13, 4.1.x versions before 4.1.13, and 4.2.x versions before 4.2.5.
“Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account,” the maintainers said in a terse advisory.
Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account, The Hacker News
Devs are keeping the exact details private so that admins have a few weeks to upgrade and patch the problem.
What to know about Threads
Back on Jul 5, 2023, Eugen Rochko wrote about Threads and its intention to use ActivtyPub (thus federating with Mastodon).
What is noteworthy about this launch is that Threads intends to become part of the decentralized social web by using the same standard protocol as Mastodon, ActivityPub. There’s been a lot of speculation around what Threads will be and what it means for Mastodon. We’ve put together some of the most common questions and our responses based on what was launched today.
What to know about Threads, Eugen Rochko, blog.joinmastodon.org