Every PCB engineer using KiCad should know about CERN's open-source libraries.
CERN has released the same KiCad component libraries used by its electronics engineers for designing scientific instruments and research hardware.
Why it's worth using
• Production-quality symbols & footprints
• Auto-generated from CERN's Altium libraries
• Nightly updates
• Database-driven library management
• Compatible with KiCad 9 and KiCad 10
• Licensed under CERN Open Hardware Licence v2
Perfect for building:
• Embedded Systems
• FPGA Boards
• Robotics
• Industrial Electronics
• Research Hardware
• Custom PCBs
If you use KiCad, this is one of the highest-quality open-source component libraries you can add to your workflow.
GitLab: https://t.co/nzBv8SrA8T
🦋💐What beautiful projects can colorful PCBs create?
The wings have such vivid, realistic colors – it’s basically a work of art!
🎥Video and Designed by @AlexandraCovor
Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security.
This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled, we recommend upgrading to the latest version.
This bug has been patched in the latest Nginx release. We will publish the technical writeup, including the ASLR bypass, on July 18 together with the previous nginx-poolslip writeup.
These two giant tortoises have been fighting each other for over 120 years. According to the zoo, one tortoise stole the other’s food 120 years ago, and from that day on they became enemies. There hasn’t been a single day where they haven’t fought for a while
> you save $50k to build your project
> you hire a team that ships clean code
> you set up a private github repo
> .env in gitignore, secrets in a vault, mfa on every account, tokens rotated quarterly
> you did everything by the book
> then one github employee auto-updates a vs code extension
> 11 minutes
> 3,800 of github's internal repos walk out
in those repos:
> the tools github engineers use to access your account
> the access management code that decides who reads what
> signing keys
> scripts running prod
you did everything right and it still wasn't enough
Github knew for hours, they delayed telling you and they wont be honest in the future. what an amazing run, its been an honor to play around with the cats over the past few months. #teamPCP#github
The Huntress SOC is currently tracking a sophisticated supply chain attack targeting the popular axios npm package. With over 100M+ weekly downloads, the reach is massive, and we’ve seen the attack impacting 135 customer endpoints so far.
🧵 What you need to know:
The rule that allow the Customs and Border Protection officers to search through your luggage without a
warrant does not extend to your electronic devices. Border officers need a warrant signed by a judge if they want to sift through material that personal to look for evidence of a crime.
https://t.co/wcgMzFk5z0
The Trump administration takes a "let's grab everything first and ask questions later approach” to collecting data at U.S. borders, raising concerns about how it’s used, retained, and shared, EFF’s @SairaHussain87 told @radionz. https://t.co/jbHjE7hic4
AI is NOT replacing cybersecurity jobs. Full stop.
I'm so tired of people parroting "AI will replace reverse engineers" and "malware analysis is solved". No. It is not.
I have analyzed hundreds of malware samples using AI. Here's what actually happens:
-> It gives you made-up decryption keys with full confidence
-> It tries to decrypt data that is literally random garbage
-> It misidentifies malware families
-> It misses critical functions
And have you ever tried retrohunting with the YARA rules AI writes across thousands of samples? Go ahead. Watch the false positives roll in. That alone should tell you everything you need to know.
Every single output needs human validation and rigorous review.
AI is a tool, a powerful one. But someone still has to build the MCPs, validate the output, understand the context, catch the hallucinations, and make the actual calls during incident response.
The people saying this stuff loudest have clearly never watched AI confidently hand them completely wrong decrypted data and make them believe it's real.
Stop scaring newcomers out of the field and misleading people with this nonsense. Cybersecurity still needs humans.