And here we go for the 2nd blog post about a vulnerability in Mastodon. It details how HTTP signatures can be bypassed because of an innocuous bug, and how it can lead to the spoofing of Mastodon instances depending on their domain name. Don't worry, infosec.exchange wasn't vulnerable ;)
https://scumjr.github.io/2023/11/07/usurping-mastodon-instances-cve-2023-42451/