periodic reminder that Wizard Zines has an educational use policy if you want to use them in your university courses! https://wizardzines.com/education/
RE: https://infosec.exchange/@cR0w/117315299719177302
Important: We have learned that this vulnerability has been exploited.
Poland's CERT has published its report on MikroTrik, the zero-day campaign that targeted MikroTik routers earlier this month
Praises LLM agents for helping with the research
https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/
It's so good to see this in the MIT Tech Review. Let's hope the message gets through. 🤞Big props to @timnitGebru & @emilymbender for putting such a fine point on things!
"Instead of OpenAI being prosecuted for creating malware that hacked another company, press releases, news outlets, media personalities, and lawmakers refer to “rogue models” as if they acted on their own. Instead of researchers being questioned about their companies’ habit of plagiarizing academics’ work or using customer data to train models without consent, the public’s imagination is redirected to fears about what the future might hold upon the arrival of fictional superintelligent machines."
https://www.technologyreview.com/2026/09/22/1144867/dont-be-fooled-summer-ai-hype/
"It is hard to be brave," said Piglet, sniffing slightly, "when you're only a Very Small Animal."
The Irish Presidency of the EU has proposed member states to allow AI companies unfettered access to the data of EU citizens.
According to leaked docs, the proposal would effectively exempt AI companies from any of the GDPR rules and deny EU citizens data protection rights
https://noyb.eu/en/ai-eu-member-states-plan-digital-expropriation-europeans-interest-ai-companies
Everyone ready to vote for the fattest bears? Who are your picks for the 2026 competition?
I'm voting 910!
Veeam Agent LPE PoC https://github.com/suce0155/CVE-2026-32996
A first public side-channel attack on the Arm CryptoCell-310.
Our latest blog post walks through the full methodology: EM signal analysis, a collision-correlation attack, and full AES key recovery.
Read it here: https://www.eshard.com/blog/side-channel-analysis-arm-cryptocell-310-aes
[Commercial, since it involved my company] Two of my friends - Jarosław Jedynak and Michał Leszczyński - are doing a webinar on Kubernetes hacking tomorrow, with live demos and stuff. It's free, but you do have to sign up to hackArcana's newsletter:
https://hackarcana.com/workshop-session/2026-Q4-k8s/intro-webinar
📢 Registration for CHERITech'26 is now open!
Join us on 12-13 November 2026 alongside SEMI Europe's SEMICON Europa 2026 at the NextSEMI Arena (Hall B0), Messe München, Germany for two days of talks, technical discussions, and networking focused on CHERI, memory safety, and secure computing.
How to register:
1️⃣ Purchase a valid SEMICON Europa 2026 ticket
2️⃣ Complete the CHERITech'26 registration form
Please note: CHERITech'26 is free to attend for all SEMICON Europa 2026 visitors. However, a valid SEMICON Europa 2026 ticket is required for each day you wish to attend CHERITech'26.
🔗 Register and learn more: https://cheri-alliance.org/events/cheritech26/