Hey folks, a headhunter got a hold of me recently for a senior-level role at Hudson River Trading.
The position is for Security Operations-type stuff, and it appears to be a somewhat senior position.
Downside is that its hybrid, with at least two days a week in the office, and the office, from what I can tell is at 3 world trade center.
Their job openings have the salary range in the description, and from what I saw, one of the perks states that they cover your healthcare premium.
If you think you can fit the bill, go take a look:
Additionally, here is a direct link to the dude who directed me to the position:
https://www.linkedin.com/in/aaron-wescott-b552ba182/
Wasn't a good fit for me, as I'm not really in a position nor do I have any desire to move back to the east coast, but maybe it'll be a better fit for you instead. Best of luck.
50 years on and space travel has become the techno utopia we have always wanted, as summed up in this quote from NASA's Artemis II livestream
Crises precipitate change. That's no reason to induce a crisis, but you'd be a fool to let a crisis go to waste. Donald Trump is the greatest crisis of our young century, and the EU looks set to squander the opportunity, to its own terrible detriment.
--
If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2026/04/04/digital-subjugation/#greenlands-next
1/
This is someting I wish I'd realized a lot sooner in life.
High level diff of iOS 26.5 beta1 vs. iOS 26.5 beta1 (v2) 🎉
https://github.com/blacktop/ipsw-diffs/blob/main/26_5_23F5043g__vs_26_5_23F5043k/README.md
Interesting Git repos of the week:
Threats:
* https://github.com/haxrob/BPFDoor-controller-source - yay, BPFDoor source
Detection:
* https://github.com/davidjurgens/hallucinated-reference-finder - how many of those references are horseshit?
* https://github.com/Cybereason-Public/owLSM - kernel based Sigma rules powered by eBPF
Exploitation:
* https://github.com/zh54321/SharePointDumper - dump SharePoint
* https://github.com/Byxs20/Krb5RoastParser - have PCAPs, can cookie
* https://github.com/shellkraft/Anvil - analyse thick clients
* https://github.com/bethgelab/foolbox - mislead that neural network
* https://github.com/Oros42/IMSI-catcher - build your own IMSI catcher
* https://github.com/pullmoll/trusttrust - sample code for Reflections on trusting trust
* https://github.com/ZephrFish/BugBountyTemplates - bug bounty templates
* https://github.com/JoasASantos/Offensivesecurity-Checklists - helpful checklists for pen testing
Hard hacks:
* https://github.com/PentHertz/urh-ng - analyse RF protocols and abuse SDR
* https://github.com/wh1te4ever/super-tart-vphone-writeup - bulld your own virtual iPhone
* https://github.com/34306/vphone-aio - virtual iPhone images
Hardening:
* https://github.com/cisco-ai-defense/defenseclaw - watch where you're sticking that claw
This quote from Apollo 14 astronaut Edgar Mitchell has been in my head the last few days
docs.rs builds are about to change. If you have crates published on crates.io/docs.rs, I recommend you read this blog post in case you might be impacted by this change: https://blog.rust-lang.org/2026/04/04/docsrs-only-default-targets/
you ever write code so inefficient they have to update the whole power grid
My Dad sends me horrible Dad jokes all the time, but sometimes he tells one that hits hard. This is one of those times.
"My favourite time of the year is campaign time. It's the only time I see politicans hang from trees."
Tired of reversing the same libc for the 100th time? 👀
Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries.
High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami.
🔗 https://blog.quarkslab.com/sighthouse-automated-function-identification.html
🆕 New blog post!
"BitLocker's Little Secrets: The Undocumented FVE API"
A small Windows RE adventure to figure out how to get the status and configuration of a BitLocker protected drive programmatically and without admin privileges.
Now also implemented in PrivescCheck! 🔥
👉 https://itm4n.github.io/bitlocker-little-secrets-the-undocumented-fve-api/
Node.js pauses bug bounty program after a funding lapse
They were sponsored by IBB, a program funded by Microsoft, Meta, Adobe, and a bunch of other tech giants
Unclear what happened there
https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties