@da_667 just jailbroke my paper white 3 last weekend. Was relatively simple. Great for older models with no Android running on it. Breathed new life into it.
i released an Atari 2600 demo with some friends at revision this year and managed to win 1st place in the oldskool demo compo! it's been in development for about a year now so was really cool to see it finally out :3
https://demozoo.org/productions/389801/
https://www.youtube.com/watch?v=aEJ0A8Wvdxs
Inherent flaws in node.js remain unpatched. Bobby Gould and Michael DePlante detail the problem and how the burden of security silently falls on app developers. https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows
RE: https://infosec.exchange/@NowSecure/116251163921885755
Last wednesday I sat down at the #paulsecurityweekly podcast to talk about static analysis with @radareorg and mobile security. The video/audio is now online! https://www.scworld.com/podcast-segment/14644-hacking-ip-kvms-reversing-with-radare2-sergi-alvarez-psw-918
Another #Hungary and #Russia investigation by #VQuare
New from 404 Media: Microsoft has terminated an account associated with VeraCrypt, the popular and long-running piece of encryption software. This means can no longer receive updates on Windows, the developer told me. Little explanation given by Microsoft https://www.404media.co/microsoft-abruptly-terminates-veracrypt-account-halting-windows-updates/
It's definitely impressive the LLMs capabilities finding bugs (I was very interested with AIxCC) but let's be honest, bugs were never scarce. There is just a new toy able to scale things faster (although funny how the price is always hidden). So were fuzzers when AFL coverage was introduced. Will it plateau or not that's the question. And will introduction of new bugs crash or not. Interesting times? Sure. End of times? Meh... Time will tell, as usual 🙂
Keep these monstrosities off our roads 🙅♂️
"US carmakers have accused Brussels of keeping their largest pick-up trucks, including the Ford F-150, the Chevy Silverado and the Ram 1500, off European roads”
https://www.ft.com/content/3eb796fd-bcdb-4a9f-89b7-f7d5e692a3cd
📱 Summer intern wanted!
@exhel and I are looking for someone to help us reverse engineer Android apps this summer @ TU Graz.
→ 20 or 40hrs/week contract
→ Helpful background: Android, reversing, or messaging apps
Send a short motivation statement + CV to lena.heimberger@tugraz.at AND edona.fasllija@tugraz.at
Boosts appreciated! 🙏 #AndroidSecurity #ReverseEngineering #Internship
you know that problem where it's actually in Google's best interests to sabotage their traditional search results to force everyone to use the AI results because then you never leave the site and direct prompt advertising becomes extremely valuable? yeah, it's like that for code, where it's actually in anthropic's best interests for all the code to be entirely unmaintainable and unsecurable except for with LLMs
In the 70s they could open Facebook by pressing the Meta key and there were Like and Dislike buttons right on the keyboard.
radare
Here’s why it’s important to always use r2 from git. In r2land, we follow the law of full disclosure and fix any reported vulnerability within a 24h deadline, as stated in SECURITY.md #radare2 https://blog.calif.io/p/mad-bugs-discovering-a-0-day-in-zero
It's so cool that anthropic is setting up a double-sided protection racket where it will profit from the massive token burn of attackers and defenders with a tool specifically designed to generate exploits and their only observable mitigation is a clientside system prompt that sternly warns the LLM to be good and not do malware
https://red.anthropic.com/2026/mythos-preview/
To my security peeps: Was the introduction of widespread fuzzing similar to AI-based bug hunting now, or is this really a different beast?