Celebrate 10 years of Binary Ninja! For the first time ever, we’re offering a 35% discount! Join us for 10 full days of giveaways including licenses, merch, and more. Huge shoutout to everyone who has been with us since the beginning, and here’s to everything still to come. Join in on the celebration: https://binary.ninja/10years
For decades there's been a conflict between governments wanting to get access to people's private data and people trying to keep them out.
Over the years I've gradually come to the conclusion that the stable "Goldilocks zone", where there's the least likelihood of a major swing that makes things worse for everyone, is *not* the privacy utopia where devices are invulnerable, or a police state where anyone with a badge who asks can root through all your data, or a fictional engineered cryptographic backdoor that''s somehow only exploitable by "the good guys".
Instead, it's the state where devices (especially phones) are breakable, but only through attack vectors that require physical access, have a high per-device cost, and are not 100% reliable. Things like "solder to an internal layer trace on the logic board to glitch it" or "FIB a per-device key out of the SoC then bruteforce the password".
I'm not saying we should be adding deliberate backdoors - quite the opposite, since these are very likely to make entry *too* easy.
But if devices become completely invulnerable, I expect we will see something like chat control turned up to 11 where the pressure to find some way in becomes unbearable and we end up with CALEA-style entry points that turn devices into total spyware with no privacy at all.
So IMO the ideal balance is where there is no viable remote attack vector, trivial drive-by USB etc attacks a la Cellebrite are blocked, but if a government has a phone off a body and are willing to spend $100K+ of lab time to have a >50% chance of breaking into *that one device*, destroying it in the process, without it easily scaling to the next, there's a good chance they can do so.
And this level of difficulty is juuust easy enough that they aren't spending the same money lobbying politicians to make it easy to break into every device belonging to an opposition party or something. They still try of course, they always want more, but they can't claim to congress that the guy who shot senator X will never be caught because they couldn't break the phone they found at the scene.
You know your device was confiscated (or are dead and not around to complain), it's not viable to do to everyone crossing a border or who was in a certain geofenced area, etc. There's no practical way to scale physical attacks to mass surveillance.
My computer just did a blue screen of death and, uh, this is new.
I wasn't watching discovery channel or anything on the computer I have no idea where that's from lol.
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
Good news, web developers: you no longer need fancy animations and 8k video backgrounds just to drain your users’ batteries.
Battery Drainer cuts out the middleman. No visuals, no crypto mining, no useful work required. Just pure depletion.
This Critical Patch Update contains 1449 new security patches across the product families
RE: https://cosocial.ca/@mhoye/116960268208721583
For the uninitiated, Firefox went back to X.
RE: https://infosec.exchange/@patrickcmiller/116963915911110345
Computers don't "act on their own." That's a statement by someone who either doesn't understand how their shit works, is trying to deny responsibility, or likely in this case, both.
🤖 Trojanized Newtonsoft.Json fork on NuGet hides game-rigging code targeting Digitain sportsbook. Package "Newtonsoftt.Json.Net" typosquats the real library and includes logic to rig live betting results.
🔗 https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
#SupplyChain #Malware #ReverseEngineering #CyberSec
HOLY SHIT I FOUND IT
It was called the "ROBOT COLORING BOOK"
It just had some space tanks on the cover. look at how badass this is
Investigation Scenario 🔎
Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation.
No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command?
To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion?