We have posted the YouTube playlist for Trusted Computing 1103: Advanced TPM Usage by Dimi Tomov in partnership with the TCG. Now anyone wishing to download the videos for offline viewing can find all their URLs here:
https://www.youtube.com/playlist?list=PLUFkSN0XLZ-l-hmC2f0f0WHh5tm76LyTj
But as always the best experience is at the full class at https://ost2.fyi/TC1103
It seems that Avast managed to settle the lawsuits related to their data abuse in both US and UK. While in the former they agreed to pay a fairly moderate fine, UK let them off the hook even easier. They are offering two years of free software to eligible UK users which is, quite frankly, a joke. It costs Avast exactly nothing, it allows them to email past users on a legal basis and gives them a chance to win them back. Really, who agreed to that?
Interesting Git repos of the week:
Strategy:
* https://github.com/SoShinySoChrome/human-incident-response-framework - tackling the human side of IR
Threats:
* https://github.com/Mickinthemiddle/CLOAK - deception techniques used by operators
Detection:
* https://github.com/Chick3nHawk01/Open_Source-CTI-Tooling - open source CTI tooling
Bugs:
* https://github.com/suce0155/CVE-2026-32996 - a backup route for LPE
Exploitation:
* https://github.com/cloudflare/security-audit-skill - more skills for your ๐ค
* https://github.com/almounah/silph - another tool to steal your memories
* https://github.com/TheZeroSlave/WPE - like Burp but for non-HTTP Windows traffic (HT @Ichinin for the reminder)
* https://github.com/interference-security/echomirage - if you remember shade/DOA... someone has saved a copy of Echo Mirage, another Windows MITM testing tool
* https://github.com/Mafifrizi/ARES - someone has been going through adding my AD attacks (credited nicely :)) on Linux to its repertoire
* https://github.com/IoTS-P/Akiba - batch processing Ghidra
* https://github.com/vulncheck-oss/initial-access-community - some nice ideas on initial access from @albinolobster and friends
Hard hacks:
* https://github.com/GlasgowEmbedded/glasgow - it's always nice in Glasgow with @whitequark
* https://github.com/xiaobor123/vuls-find-VxWorks - VxWorks until it doesn't
* https://github.com/xiaobor123/vul-finds - more cute bugs
Data:
* https://github.com/cisco-ai-defense/aibom - AI usage needs to be transparent... and if not, well, some of us will be looking for it in any event ๐ค
Cryptography:
* https://github.com/nationwide-group-oss/cryptoptic - time to start taking PQC seriously
Development:
* https://github.com/ItzLevvie/dind - HT to @GossiTheDog for pointing it out, but run Windows inside of GitHub
Nerd:
* https://github.com/sure-fire/derbypi - some neat extensions for Pis from @surefire
Introducing ๐ท๐๐ ๐๐๐๐๐๐ฑ๐๐๐ ๐๐๐.๐๐ก๐
- 15 KB native web browser
- 6 MB of RAM for the host
- 0 lines of Visual Basic (no C# cuz idk how to write it)
- no URL bar because surfing through 88x31s is more fun
- title bar kept cuz then u can close it and minimize buttons
BBC News has 4 YouTube videos up in the past day about OpenAI hacking โgovernmentsโ, with approaching a million views.
If you want to know the technical details of this elite frontier AI hacking - these are examples of the actual OpenAI agent requests.
Itโs really dumb shit. The story here is OpenAI are utterly incompetent at cybersecurity, as are their victims.
We have both kinds of deities: an ad-supported and a subscription-based Machine God
The Degraded Search Engine
Bonus speedpaint: https://www.peppercarrot.com/en/miniFantasyTheater/071.html#bonus