Welcome to volume thirty-six of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week the open web is in its endgame, and threat actors have an absolute field day. So stop everything else you’re doing and get scrollin’!
IndieWeb
The web is being eaten alive. Some say we’re in the endgame now. If you’re thinking it’s us (humans) vs. machines, think again. Rather, it’s humanity and the “good” web versus the billionaries and tech overlords that seek to wield power over it all.
Despair may be in abundance both IRL and on the web these days, but there is good to be found, and to be built. As much of the web continues to enshittify, and be assimilated, you still have the power to build something of your own on the ‘net and call it home. It doesn’t have to be pretty, it doesn’t need to be serious (though it could be), it just needs to be a place for you.
In the end your li’l website might stink, but it can still be pretty cute! 🧡
Small Web Finds and Features
Some web finds of the week ⬇️
- I’m no fan of “AI”, but this is kinda funny: deathbyclawd 💀
- Get lost in the cyberhole 🕳️
- This site is powered by the sun. Now that’s awesome. ☀️ 😎
- Check out Over/Under #59 featuring Michał “rysiek” Woźniak — one of my favorite bloggers on the web! 👨💻
Cybersecurity
Threat actors are having a particularly successful, and very media-heavy week…
- Google’s Threat Intelligence Group (GTIG) has the scoop on the “DarkSword” iOS-compromising exploit chain.
- TeamPCP has been absolutely wrecking folk’s supply chains.
- Citrix is bleeding once more, and WatchTowr is tired of it.
- NTLM relay attacks are once again in vogue.
And now for the cyber-hodgepodge. Let’s get listy…
- Daniel wisely suggests we verify and skip the “trust” step completely.
- DVRTC is a new purposefully-vulnerable environment for learning about VoIP and WebRTC security. Neat!
- Want a real page turner for your weekend reads? NIST’s got you with SP 800-81r3 (the Secure Domain Name System Deployment Guide).
- Microsoft’s got thoughts on threat modeling AI applications. I’m sure they do… 😒
- Here’s a funny thread on ransomware.
Thanks for reading Scrolls! Time for me to get back to exploring the vast cosmos of the web 🔭


