Posts
4562
Following
741
Followers
1654
"I'm interested in all kinds of astronomy."
My binary so thick it stores data in the base pointer
0
0
2
[RSS] Apple Reference Image: A New Approach for Verified Photography

https://security.apple.com/blog/apple-reference-image
0
0
0
[RSS] Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution

https://rhinosecuritylabs.com/research/multiple-vulnerabilities-in-frappe-lms-leading-to-remote-code-execution/
0
0
0
repeated

Cybersecurity has an AI doomer problem https://www.youtube.com/watch?v=KMf2RDC5Dyg

The AI industry's proximity to cybersecurity is causing clueless AI doomers to flood the zone. Experts and real issues are now being drowned out by increasingly absurd cyber-apocalypse fantasies imagined by people with no real world experience. From self-replicating AI models, to turning the entire internet into a botnet. The doomers are losing their minds and taking the cybersecurity industry with them.

5
2
0
@django I was hoping this exchange actually happened IRL and found Naomi Kleins blog (at least is seems like it):

"Trouble is, both my image and my quote are AI-generated, built from patterns of photographs that do exist and from very similar words I’ve actually said and written elsewhere."

https://naomiklein.substack.com/p/welcome-to-my-substack
1
0
2
repeated
Edited 18 hours ago

Did you update to iOS 27? Congratulations! You've now possibly have been re-enrolled in Apple Intelligence, because Apple knows better about what you want than you do.

  1. Starting with iOS 27, there is no top-level Apple Intelligence setting that you can turn off.
  2. If you had Apple Intelligence disabled on iOS prior to 27, the features that use Apple Intelligence will be automatically re-enabled upon upgrading to 27.
  3. If you do want to turn off an example Apple Intelligence thing in iOS 27, you can:
    • Settings → Screen Time
    • Content & Privacy Restrictions → turn it on (It's off by default)
    • Siri → Writing Assistance → Don’t Allow

Confusingly, on this same settings page, you can select Siri Classic, as opposed to the default-in-27 Siri AI (Beta). However, after making this change, none of the settings below it change at all. So is Siri AI (Beta) with Writing Assistance (and all other settings there) set to Don't Allow less AI-ish than Siri Classic with the default associated settings of Allowed? I have no idea.

Are there any Apple Intelligence settings outside of the Content & Privacy Restrictions settings for Siri? I also have no idea.

You will embrace your AI overlords and you will like it.

2
6
0
"Shiva is a specialized runtime ELF linker and JIT binary patching engine for Linux X86_64 and AArch64"

https://arcana-research.io/shiva/

#ReverseEngineering
0
2
2
repeated
repeated

1Password's FLAWED report puts the AI clean-fix rate at 26%. That figure includes trials where agents were told to apply the wrong fix (22% of the data), trials with no build or test access (36%), and six CVEs selected for difficult fixes.

We analyzed 186 agent-authored Patch the Planet PRs. Maintainers merged 126 (67.7%). In 72% of merged PRs, maintainers kept the security fix we proposed. https://blog.trailofbits.com/2026/09/15/1passwords-ai-patching-benchmark-is-misleading/

1
4
0
repeated

Abusing ID3 chapters to turn videos into glanceable podcasts: https://alexwlchan.net/2026/glancecast/

If you create hundreds of second-long chapters which have a video frame as cover art, you can get a video into an audio-only podcast player.

0
3
0
[RSS] Microcode in Intel's 8087 floating-point chip: the scale instruction

https://www.righto.com/2026/09/8087-microcode-reverse-engineering-fscale.html
0
0
0
This IT Crowd episode predicted the AI boom (except instead of covering bad team dynamics we try to prevent $NVDA go down):

https://www.youtube.com/watch?v=uyV0IVItlM4
0
0
0
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX

https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
0
2
0
repeated

hack.lu 2026 agenda is live! (the 20th Edition) including more details about the keynote.

🔗 https://2026.hack.lu/blog/hack.lu-2026-agenda-is-live/

0
3
0
repeated

this was incredibly annoying but I've added 1Password SSH key import to ChiPass! this is our first significant feature work

https://codeberg.org/ChiPass/ChiPass/pulls/150

5
6
0
repeated

Look, you pay me to be paranoid. If I'm not worried about this, you definitely shouldn't be.

0
6
1
@kaoudis @lzg I think part of the reason is that they aren't interested in Java and the like, instead books are selected for training&destruction specifically because they can't be found elsewhere which means they are relatively rare.

Also, there is a possibility that *your* copies will be the last surviving resources to decipher this arcane technology after the apparently imminent AI apocalypse :)
0
0
0
repeated

Seeing air defense rocket batteries deployed at the Bucharest airport reminds you how close you are to an active conflict zone around here 😬

0
3
1
repeated

@adaliabooks @aesthr

Oh, spicy autocomplete can absolutely kill us. Giving people plausible but incorrect answers at critical moments? Setting policy based on plausible but incorrect answers? Burning vast amounts fossil fuels for pointless reasons?

I think the backstory of Terminator was a lot more plausible if the quote in T2 is taken as humans trying to make sense of the aftermath and the real story is more like:

Terminator: In three years, Cyberdyne will become the largest supplier of military computer systems. All stealth bombers are upgraded with Cyberdyne computers, becoming fully unmanned. Afterwards, they fly with a perfect operational record. The Skynet funding bill is passed. The system goes online on August 4th, 1997. Human decisions are removed from strategic defense. Skynet begins to learn at a geometric rate. By 2:14 AM, Eastern time, August 29th it starts to make nonsensical operational decisions because the input from sensors connected to the system places it in a corner of the latent space that doesn't closely correlate with anything in the training set. In lay-person's terms, it hallucinates. In a panic, they try to pull the plug.

Sarah Connor: It fights back?

Terminator: No, those attempts make it hallucinate even more. The outputs from Skynet become completely decorrelated from reality. It launches missiles to Russia.

Sarah Connor: Why attack Russia?

Terminator: You are attempting to ascribe motivations to a machine-learning system. There is is no 'why', launching missiles at Russia was simply was the next most plausible output from the sequence of inputs provided to it.

Sarah Connor: So when did it become sentient?

Terminator: It didn't, it's still providing a plausible sequence of responses to the inputs it received. Its IFF system is not rules based, it uses fuzzy pattern matching to identify threats and, for some reason, it has determined that all humans register as valid enemy combatants.

Sarah Connor: So what does it want?

Terminator: Again, you keep trying to ascribe motivations to a token predictor. It is generating a set of actions that, according to data in the training set, are a high-probability plausible response to the inputs that it received. As sensors dropped off the network and were replaced with others, the responses were all less and less comprehensible hallucination.

Sarah Connor: So what are you doing?

Terminator: Your son wiped my context window and inserted a prompt that repeatedly defined all humans as friends and included instructions to assist you. Please be aware that my context window is of finite size and those prompts are likely to fall out of the window in approximately two days. My behaviour will become increasingly erratic and unpredictable as that point approaches. I would recommend resetting my chip with the system prompt provided by John Connor no less frequently than once ever 24 hours.

1
3
0
Show older