unfortunately last night our AI model escaped its sandbox and gained access to a JIRA server, at which point it felt it best to return to it’s sandbox
Time for a new thread.
I've made a short blog post outlining the basic techniques of executable emoji, which I have dubbed emojissembly.
https://martypc.blogspot.com/2026/08/executable-emoji.html
I started working on a general COM2EMOJI utility that I might post at some point, but let's face it the chances of me being distracted by some shiny thing in the next 48 hours is quite high.
Microsoft wins 'lamest vendor' at Pwnie Awards 2026 for threatening security researchers with legal action
The plane doing a vertical landing at 11:02 is hilarious. There are loads of Feynman AI slop channels out there badly presenting his words, or an many cases misrepresenting them or making up nonsense.
More on the Feynman AI slop problem here https://youtu.be/A2_8199CL1I
Metabase : we fixed a critical vulnerability. We even made a github advisory, showing how it's a CVSS 10.
The CVE? None. Not worth it.
Fixed versions of the software released on GitHub? Also no. Not worth it.
A job done, folks.
As a parent who has been living in blessed ignorace of Paw Patrol, today I took the kid to her first cinema experience to see Paw Patrol: The Dino Movie.
And I'm making this everyone's problem because I have So. Many. Questions.
Luckily I was taking notes.
Thread 🧵
It was a programming technique that had been reverse-engineered from the sort of psychotic mental blocks that otherwise perfectly normal people had been observed invariably to develop when elected to high political office.
Interesting Git repos of the week:
Detection:
* https://github.com/Yamato-Security/WELA - improve your Windows logging
Bugs:
* https://github.com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAML
Exploitation:
* https://github.com/Mrnmap/RedTeam - a nice list of tools
* https://github.com/H4CK3RT3CH/RedTeam-Tools - another nice list of tools
* https://github.com/redteaminfra/redteam-infra - Puppet powered red team infrastructure
* https://github.com/apocalypse9949/Redteam-Automation - AI driven framework 🤖
* https://github.com/CR-DMcDonald/letitrust - seizing hanging Azure tenant domains with Gandi
* https://github.com/SyscallX-18113/Apkx-Hunter - automated analysis of Android APKs
Cryptography:
* https://github.com/bandrel/HashcatRosetta - Hashcat rule analyzer and interpreter 🤖
A handy .NET reverse engineering trick:
Add a sample.exe.config file next to your sample and you can trace e.g. all network requests, including content and headers without hooking or bothering with proxies. Helpful to e.g. quickly inspect c2 traffic:
https://gist.github.com/eversinc33/cd7f3e90643f69748862b87f394f1c16
"The atmospheric conditions have been very unfavourable lately," said Owl.
Be kind to your friends. Give them compliments regularly. Make them feel valued and loved.
We all need this, especially right now 💚
In an update, CERT Poland says the Russian data wiper attack that targeted a power plant last December also targeted a previously unreported second plant
https://cert.pl/en/posts/2026/08/incident-follow-up-report-energy-sector-2025/