When I drive a car without a valid driver's license, proof of insurance or tag/license plate, I get stopped by the police, my car will be towed and I can either walk home or might end up in jail and face severe fines, a probation period and loss of my driver's license.
When Microsoft runs 45 gas turbines without a state permit, they get 45 days to fix it and a $1.07M fine (which is petty cash for an operation this size) and don't even have to power down the turbines.
🚨 Companies are being urged to shut down their NetScaler instances immediately due to multiple unpatched Citrix NetScaler RCE vulnerabilities.
Source: https://x.com/watchtowrcyber/status/2103891689857228803
For details on how the 8087 calculates tangents by using the CORDIC algorithm combined with polynomials, see my latest article:
https://www.righto.com/2026/09/8087-tangent-cordic.html
We have posted the YouTube playlist for Trusted Computing 1103: Advanced TPM Usage by Dimi Tomov in partnership with the TCG. Now anyone wishing to download the videos for offline viewing can find all their URLs here:
https://www.youtube.com/playlist?list=PLUFkSN0XLZ-l-hmC2f0f0WHh5tm76LyTj
But as always the best experience is at the full class at https://ost2.fyi/TC1103
It seems that Avast managed to settle the lawsuits related to their data abuse in both US and UK. While in the former they agreed to pay a fairly moderate fine, UK let them off the hook even easier. They are offering two years of free software to eligible UK users which is, quite frankly, a joke. It costs Avast exactly nothing, it allows them to email past users on a legal basis and gives them a chance to win them back. Really, who agreed to that?
Interesting Git repos of the week:
Strategy:
* https://github.com/SoShinySoChrome/human-incident-response-framework - tackling the human side of IR
Threats:
* https://github.com/Mickinthemiddle/CLOAK - deception techniques used by operators
Detection:
* https://github.com/Chick3nHawk01/Open_Source-CTI-Tooling - open source CTI tooling
Bugs:
* https://github.com/suce0155/CVE-2026-32996 - a backup route for LPE
Exploitation:
* https://github.com/cloudflare/security-audit-skill - more skills for your 🤖
* https://github.com/almounah/silph - another tool to steal your memories
* https://github.com/TheZeroSlave/WPE - like Burp but for non-HTTP Windows traffic (HT @Ichinin for the reminder)
* https://github.com/interference-security/echomirage - if you remember shade/DOA... someone has saved a copy of Echo Mirage, another Windows MITM testing tool
* https://github.com/Mafifrizi/ARES - someone has been going through adding my AD attacks (credited nicely :)) on Linux to its repertoire
* https://github.com/IoTS-P/Akiba - batch processing Ghidra
* https://github.com/vulncheck-oss/initial-access-community - some nice ideas on initial access from @albinolobster and friends
Hard hacks:
* https://github.com/GlasgowEmbedded/glasgow - it's always nice in Glasgow with @whitequark
* https://github.com/xiaobor123/vuls-find-VxWorks - VxWorks until it doesn't
* https://github.com/xiaobor123/vul-finds - more cute bugs
Data:
* https://github.com/cisco-ai-defense/aibom - AI usage needs to be transparent... and if not, well, some of us will be looking for it in any event 🤖
Cryptography:
* https://github.com/nationwide-group-oss/cryptoptic - time to start taking PQC seriously
Development:
* https://github.com/ItzLevvie/dind - HT to @GossiTheDog for pointing it out, but run Windows inside of GitHub
Nerd:
* https://github.com/sure-fire/derbypi - some neat extensions for Pis from @surefire
Introducing 𝙷𝚊𝚠𝚔𝚃𝚞𝚊𝚑𝙱𝚛𝚘𝚠𝚜𝚎𝚛.𝚎𝚡𝚎
- 15 KB native web browser
- 6 MB of RAM for the host
- 0 lines of Visual Basic (no C# cuz idk how to write it)
- no URL bar because surfing through 88x31s is more fun
- title bar kept cuz then u can close it and minimize buttons