Newsletter: Regulators race to reassure the crypto industry as the its flagship Clarity Act legislation collapses, SBF tries his luck with the Supreme Court, and crypto PACs unleash $30 million against Sherrod Brown.
https://www.citationneeded.news/issue-110/
#crypto #cryptocurrency #USpol #USpolitics #CitationNeededNewsletter
Aaron Swartz was charged on July 14th, 2011 with wire fraud and computer fraud (under the Computer Fraud and Abuse Act). He potentially faced 30 years in jail and a fine of 1 million dollars or more. The theory was that he exceeded authorized access by automated scraping through 4.8 million JSTOR articles.
Contrast with...
AI crawlers crawl trillions of documents, often ignoring any ToS the prohibit automated scraping.
OpenAI downloaded pirated books from Library Genesis and created internal datasets that became the foundation for GPT-3's training.
Meta torrented 80+ TB of data from Anna's Archive for Llama 4. There are records of internal discussions at Meta that the data set was known to be pirated content.
Where is the federal prosecutor to throw charges at OpenAI and Meta? That's right. No charges.
Reddit Is Killing RSS Feeds, Ending Public API Access https://tech.slashdot.org/story/26/09/30/1841213/reddit-is-killing-rss-feeds-ending-public-api-access?utm_source=rss1.0mainlinkanon
New series: implementation security for autonomous defense systems.
Their intelligence runs on embedded hardware in the field, where an adversary can recover a device and study it with no time limit.
What happens if someone can study it without constraints?
🔗Part 1: https://www.eshard.com/blog/autonomous-systems-are-changing-the-defence-threat-model
Hashing several values together is easy to get wrong, and the mistakes can lead to forgeries. TupleHash only works with Keccak. Outside SHA-3, people roll their own multihashing, often insecurely.
We built SequenceHash to fix that for any hash function, with length-suffix encoding and protection against length-extension attack. https://blog.trailofbits.com/2026/10/02/sequencehash-multihashing-for-the-rest-of-us/
In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available.
These are defects (like XSS, SQLi) that keep appearing year after year. Their recurrence is not a technical mystery; it is a business and incentive failure.
The presence of an unforgivable vulnerability signals that customer safety was not treated as a non-negotiable requirement.
Our systems detected a minor irregularity in your account, please shitpost to restore full access.
x86 evolution for segmentation and paging
https://lore.kernel.org/lkml/CAKSQd8WX6xH7=njcGZNNFe8m1xbyhCpX-10cZDw+saWJayWQYA@mail.gmail.com/
We’ve had 22 years of Cybersecurity Awareness Month. People are aware. People know phishing is bad, ransomware exists, and passwords shouldn’t be “password.” Mission Accomplished!
Let's rename it Cybersecurity Readiness Month.
https://semgrep.dev/blog/2026/rename-cybersecurity-awareness-month/
Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.
https://www.cve.org/CVERecord?id=CVE-2024-58388
Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html#pre-auth-lfi
But at least there's a Nuclei template:
Exclusive: Israeli spyware maker Paragon positions itself as more responsible than its competitor NSO Group. But the company's new US CEO says in a candid interview that while they will cut off customers who misuse their spyware they have no ability to detect or investigate customer misuse, nor do they want that ability. Their tools also don't log customer activity by default. Though customers can configure some tools to do logging, Paragon doesn't have ability to force customers to provide those logs if allegations of abuse arise. Paragon says instead that it relies on third parties like Citizen Lab to detect abuse by its customers, and even praises Citizen Lab for uncovering suspected abuse in 2025, yet at the same time the company actively works to prevent Citizen Lab and others from detecting its spyware on infected systems, thus thwarting their ability to uncover abuse. Here's my story:
https://www.wired.com/story/the-secrets-of-the-us-spyware-king/
welp. I have exceeded my disgust tolerance for the week; fuck all this shit
CVE ID: CVE-2026-76504
Vendor: Cisco
Product: Catalyst SD-WAN Manager
Date Added: 2026-09-30
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76504
I still remember the day in 1976 when Gary Kildall typed in "dir" to an "A>" prompt on his hazeltine green-screen character display to show me a directory listing on his 8080-based, eight-bit computer running the first release of CP/M, the first real microcomputer operating system (that Gary wrote). He gave me a shy but proud look and asked what I thought. It seemed miraculous to me, and I was hooked.
Anyway, I just tried to rename a file on my Windows 10 PC and midway through the operation Microsoft deleted the file instead. I guess we've really come a long way since those early days 50 years ago. <sigh>