🚨 Companies are being urged to shut down their NetScaler instances immediately due to multiple unpatched Citrix NetScaler RCE vulnerabilities.
Source: https://x.com/watchtowrcyber/status/2103891689857228803
For details on how the 8087 calculates tangents by using the CORDIC algorithm combined with polynomials, see my latest article:
https://www.righto.com/2026/09/8087-tangent-cordic.html
We have posted the YouTube playlist for Trusted Computing 1103: Advanced TPM Usage by Dimi Tomov in partnership with the TCG. Now anyone wishing to download the videos for offline viewing can find all their URLs here:
https://www.youtube.com/playlist?list=PLUFkSN0XLZ-l-hmC2f0f0WHh5tm76LyTj
But as always the best experience is at the full class at https://ost2.fyi/TC1103
It seems that Avast managed to settle the lawsuits related to their data abuse in both US and UK. While in the former they agreed to pay a fairly moderate fine, UK let them off the hook even easier. They are offering two years of free software to eligible UK users which is, quite frankly, a joke. It costs Avast exactly nothing, it allows them to email past users on a legal basis and gives them a chance to win them back. Really, who agreed to that?
Interesting Git repos of the week:
Strategy:
* https://github.com/SoShinySoChrome/human-incident-response-framework - tackling the human side of IR
Threats:
* https://github.com/Mickinthemiddle/CLOAK - deception techniques used by operators
Detection:
* https://github.com/Chick3nHawk01/Open_Source-CTI-Tooling - open source CTI tooling
Bugs:
* https://github.com/suce0155/CVE-2026-32996 - a backup route for LPE
Exploitation:
* https://github.com/cloudflare/security-audit-skill - more skills for your 🤖
* https://github.com/almounah/silph - another tool to steal your memories
* https://github.com/TheZeroSlave/WPE - like Burp but for non-HTTP Windows traffic (HT @Ichinin for the reminder)
* https://github.com/interference-security/echomirage - if you remember shade/DOA... someone has saved a copy of Echo Mirage, another Windows MITM testing tool
* https://github.com/Mafifrizi/ARES - someone has been going through adding my AD attacks (credited nicely :)) on Linux to its repertoire
* https://github.com/IoTS-P/Akiba - batch processing Ghidra
* https://github.com/vulncheck-oss/initial-access-community - some nice ideas on initial access from @albinolobster and friends
Hard hacks:
* https://github.com/GlasgowEmbedded/glasgow - it's always nice in Glasgow with @whitequark
* https://github.com/xiaobor123/vuls-find-VxWorks - VxWorks until it doesn't
* https://github.com/xiaobor123/vul-finds - more cute bugs
Data:
* https://github.com/cisco-ai-defense/aibom - AI usage needs to be transparent... and if not, well, some of us will be looking for it in any event 🤖
Cryptography:
* https://github.com/nationwide-group-oss/cryptoptic - time to start taking PQC seriously
Development:
* https://github.com/ItzLevvie/dind - HT to @GossiTheDog for pointing it out, but run Windows inside of GitHub
Nerd:
* https://github.com/sure-fire/derbypi - some neat extensions for Pis from @surefire
Introducing 𝙷𝚊𝚠𝚔𝚃𝚞𝚊𝚑𝙱𝚛𝚘𝚠𝚜𝚎𝚛.𝚎𝚡𝚎
- 15 KB native web browser
- 6 MB of RAM for the host
- 0 lines of Visual Basic (no C# cuz idk how to write it)
- no URL bar because surfing through 88x31s is more fun
- title bar kept cuz then u can close it and minimize buttons