Whew! They had to swap out the master control board during the attempt, but Hank Chen of InnoEdge Labs successfully demoed their exploit of the Alpitronic HYC50 in Lab Mode. Using screwdrivers during a #Pwn2Own attempt is always crazy to see. He's off to disclose what occurred.
Remember "don't print this email" in signatures that was a bit cringe? It doesn't feel that cringe anymore in retrospect. I'm doing an experiment now with this new email signature :D Anyone doing something similar? Could it catch on?
Today's threads (a thread)
Inside: Google's AI pricing plan; and more!
Archived at: https://pluralistic.net/2026/01/21/cod-marxism/
1/
After auditing the @mullvadnet client applications in 2024, we have recently audited Mullvad VPN's API.
The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.
Five issues were identified, of which only one had a very limited impact on users of the service.
The technical details may be found in our report. https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/
Last December I solved Synacktiv's 2025 Winter Challenge: Quinindrome https://www.synacktiv.com/en/publications/2025-winter-challenge-quinindrome . Here is a 81-byte Linux program which is both a quine (it prints itself when executed) and a palindrome (it is symmetrical)! To learn how I achieved it: https://github.com/fishilico/synacktiv-winter-chall-2025-quinindrome/blob/main/writeup.md
@ekis Meanwhile Amazon is launching a Euro specific AWS, claiming it gives Europeans Digital Sovereignty.
It does not, it's still subject to all the same legal obligations as the US based AWS - Especially the Cloud Act. https://en.wikipedia.org/wiki/CLOUD_Act