Posts
4090
Following
732
Followers
1618
"I'm interested in all kinds of astronomy."
repeated

So here's the other thing that bothers me about all this. Regardless of the eventual results, this thing they're doing is *incredibly* resource intensive. They routinely spend billions of dollars on training these models, and billions more on operating them. It's not simple to parse out what fraction of that is directly attributable to the massive scale vuln finder/fabricator. But for the sake of argument lets just pick a plausible number, and call it 50-100 million dollars.

What could we have gotten for 50-100 million dollars of sponsorship for security audits? Prior to this, the largest single investment into FOSS security I'm aware of was the 2015 audit of openssl, after the heartbleed incident. It's hard to find precise costs for that, but I found a few sources estimating 1.2 million dollars, and that is arguably the most security critical piece of software in the world.

But suddenly there's 100x more resources available to do this work, now that producing the artifact can be done with stolen labor? Now that they can externalize the cost of false positives onto the already mostly unpaid maintainers of these projects? Even if their claims are true, which we have no reason to believe and very good reason not to, it's still a travesty

1
8
0
repeated

algernon the exhausted, first of his name

German ruling declares Google liable for false answers in AI Overviews

"AI" news are rarely good news, this one is. I hope this becomes an EU-wide thing eventually.

World-wide would be nicer, but I have no hope for the current US admin.

#algernonReviewsHackerNews

0
1
0
repeated

Nightmare Eclipse has released a new exploit: RoguePlanet

It's reportedly not 100% reliable, but it worked on the first attempt for me.

1
4
0
repeated

https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-decade-old-lxd-group-root-re-armed/ reminds me of the time I pointed out that /usr/local/* was writable by the staff group on Debian. Privesc by design.

0
3
0
[RSS] Ghost-Sender - Universal Email Spoofing against Exchange Online

https://labs.infoguard.ch/posts/ghost-sender/
0
0
1
[RSS] Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation

http://blog.quarkslab.com/extending-llvms-bolt-based-binary-analyser-to-validate-stack-variable-initialisation.html
0
1
0
repeated

TrendAI Zero Day Initiative

Edited 2 days ago

Wow. Over 200 CVEs from and another 123 from . It's a record-setting Patch Tuesday, but fear not! @TheDustinChilds has broken the release down and provides the details. Check out the blog athttps://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review

1
2
0
repeated

The “secret” phone museum in Stuttgart hiding inside an underground station had tons of stuff and working demos and wonderful volunteers.

4
4
0
repeated
@cR0w as an (ex) Red Teamer I support fully reput's approach!
0
1
1
repeated

RE: https://infosec.exchange/@reput_io/116720740952715024

We tell you what's demonstrably legitimate: CDNs, cloud ranges, gov registries, SaaS infra, so analysts can dismiss false positives in seconds instead of investigating them for minutes.

That's an interesting approach. tells you about them ( for free ) so you can block them. Different strokes, I guess.

3
2
0
repeated
repeated

command injection vulnerability CVE-2026-42271 that could allow any authenticated user to run arbitrary commands on the host, has been added to the CISA KEV catalog:
👇
https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html

0
2
0
repeated

cryptographic proofs per football field

0
1
0
repeated

In Berlin and no plans on Thursday? Join us at the Mozilla office for a few talks.

https://www.meetup.com/de-de/berlin-mozilla-meetup/events/314623241/

0
1
0
repeated

Out of the 16 pending CVEs:

13 are severity LOW
3 are severity MEDIUM
9 of them are libcurl only (not the tool)
3 are "C mistakes"
2 are younger than six months old
1 is older than 25 years

2
3
0
repeated
repeated

I've been running Follow the Crypto since 2024. Today I'm relaunching it as Tech Influence Watch, expanded to cover AI political spending alongside crypto. They’ve spent more than $400 million this election cycle, and now you can follow it in close to real time.

https://influence.citationneeded.news/

Here’s the full story behind the Tech Influence Watch launch, including what I found while building it and why it matters now: https://www.citationneeded.news/tech-influence-watch/

1
28
0
Show older