#Microsoft asks users to ignore ' #Antivirus is turned off ' errors
"I have been Foolish and Deluded," said he, "and I am a Bear of No Brain at All."
A 12TB Steam 'Teraleak' Spills More Than a Decade of Lost PC Gaming History https://games.slashdot.org/story/26/08/31/0247220/a-12tb-steam-teraleak-spills-more-than-a-decade-of-lost-pc-gaming-history?utm_source=rss1.0mainlinkanon
Death by a thousand (paper)cuts (also known as WT-2026-0144) brings us back aboard the HellScape Express.
The saga continues… and we'll be back soon.
(We gently, kindly, and calmly suggest pulling PaperCut entirely off the Internet at this point)
Growing up with the phrase “Wikipedia isn’t a valid source,” only to end up in a daily life where everyone says, “Just ask ChatGPT.”
Packing my DIY encryption prototypes for my workshop at @inselchaos. It's a fun tech-related topic that you can explore with low-tech materials.
#inselchaos26 #InselChaos #inselchaos2026 #stemeducation #encryption #papercraft #FediLZ #stem #diy #diy_electronics
Programming is understanding.
- Kristen Nygaard
This is a post about AI.
RE: https://grapheneos.social/@GrapheneOS/117179231167297908
Apple: "We had to work on MTE stability and security improvements for 5 years, but we finally ship it with the iPhone 17 and enable it by default."
Google: "We shipped MTE hardware for 3 years and only academics enabled this optional feature to demonstrate practical attacks against it, so we decided to no longer ship it on the latest Pixels."
New video: Process Memory Map in Code (Part 3).
MemMap now enumerates threads, finds each TEB via NtQueryInformationThread and PHNT, and reads thread stacks with ReadProcessMemory.
Full write-up: https://trainsec.net/library/windows-internals/process-memory-map-in-code-thread-stacks-and-tebs-part-3/
Interesting links of the week:
Strategy:
* https://assets.publishing.service.gov.uk/media/6a50d66b1228eb26a4cab76c/National_Risk_Register_2026.pdf - I rave about the HMG risk register but it's a new year and there is still much to worry about
* https://www.whitehouse.gov/wp-content/uploads/2026/08/NSSTS-082026.pdf - the US strategy for tech supremacy
* https://www.wired.com/story/silicon-valley-doesnt-get-why-you-hate-ai/ - @WIRED makes some great points on AI scepticism
* https://codeberg.org/ethical-foss/open-slopware#operating-systems - slop free software!
* https://ar.al/2025/06/25/web-numbers/ - @aral writes small...
* https://www.linkedin.com/pulse/i-spent-day-learning-wargaming-ive-stopped-thinking-since-nicholls-0wh8e - making incident exercises fun
* https://home.treasury.gov/news/press-releases/sb0616/ - the US continues their great policy of going after activists
* https://web.archive.org/web/20260828071449/https://cavallette.noblogs.org/2026/08/10083/2 - who exactly are noblogs and why you should care...
* https://simonwillison.net/2026/Aug/28/just-a-rumour-of-a-bug/ - more thoughts on bugs 🤖
* https://www.csis.org/analysis/cyberattacks-us-water-sector-and-iran-question-escalation-or-opportunism - more reporting on rain
* https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/ - once you've secured water, BES is next
* https://www.cyber.gc.ca/en/news-events/joint-guidance-isolating-vital-systems - put your OT in a box say ASD and CCCS
* https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai - NCSC drops some guidance on agentic AI 🤖
* https://www.gov.uk/government/statistics/uk-public-survey-of-risk-perception-resilience-and-preparedness-2026 - HMG's report on public perception of risk, resilience and preparedness
* https://ieeexplore.ieee.org/document/11644378 - paper on UK NIS readiness
* https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/ - having spent years, presumably improving encryption, @matthew_d_green is worried that threat actors may go dark
* https://www.cyberleagle.com/2026/08/if-computer-is-not-accountable-who-is.html - @cyberleagle.bsky.social asks the awkward question, "who do we prosecute?"
Standards:
* https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/ - new ETSI standards, in support of EU CRA
Threats:
* https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot - another day, another botnet
* https://securelist.com/honeymyte-coolclient-driver-rootkit/ - another day, another rootkit from @Kaspersky
* https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/ - another one for luck, this time from my friends at @TalosSecurity
* https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ - @citizenlab reporting on global surveillance
* https://www.mdsec.co.uk/2026/08/when-it-snows-it-pours-anatomy-of-a-servicenow-red-team/ - more from MDSec on SNow
* https://insights.bridewell.com/hubfs/Reports/Defending%20Against%20DPRK%20IT%20Workers%20-%20An%20Implementation%20and%20Operational%20Guide.pdf - what to do to avoid meeting a .kp colleague at the water cooler
Detection:
* https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a - SOC lessons from CISA
* https://maldbg.com/interlock-esxi-decryptor-internals - don't pay the ransom
* https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/ - scissors are essential for DFIR
* https://www.elastic.co/security-labs/ai-coding-agent-audit-cursor-hooks - if you don't fully trust your AI, how do you keep an eye on it?
Bugs:
* https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/ - too social network
* https://www.usenix.org/system/files/usenixsecurity26-kim-daewoo.pdf - side channels in vSwitch
* https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ - are the NetScalers still in the room @index?
Exploitation:
* https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf - so, nothing that clever then... 🤖
* https://tmpout.sh/5/ - new @tmpout
* https://exploitation.ashemery.com/ - a nice little course on exploitation
* https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse - replicating CrowdStrike's excellent work on turning EDR into a footgun
* https://smolbox.remyhax.xyz/ - why not play with AI in someone else's container? 🤖
Hard hacks:
* https://boschko.ca/g1-ble-rce/ - thank @boschko, for when the robots rise...
* https://blog.n0p.me/2026/08/2026-08-21-fortitool-fortios-decryption/ - dump FortiOS
* https://www.usenix.org/conference/usenixsecurity26/presentation/anwar - who cares what the date is...
* https://0x434b.dev/breaking-secure-boot-without-breaking-the-crypto/ - untrusted boot from @434b
Data:
* https://datarepublican.com/dsa-explorer/ - if you're in the US, what data are they keeping on you? 🤖
Nerd:
* https://lists.debian.org/debian-vote/2026/08/msg00360.html - @debian sadness 🤖
* https://littlefedi.org/ - @stefano's bit of the Fediverse
* https://eater.net/ - a little bit of light CPU design, just for fun!
watching what's happening to Debian (and Linux, and open source in general)
And on the topic @kenshirriff is posting about, here's my old macro photo of an Ampex core memory module.
It sure is strange just how many actually legitimately criminal terrorist orgs have their shit behind Cloudflare, or host actual pedophile rings on Telegram, but it's Autistici/Inventati that gets taken down.