Posts
4445
Following
738
Followers
1657
"I'm interested in all kinds of astronomy."
repeated

We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.

It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.

Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/

1
6
0
repeated
Edited 17 hours ago

A bit annoyed by tech reporting again. Found two major tech news outlets provide an incorrect explanation of the WebAudio fingerprinting (not you arstechnica. You did good). The thing is mostly prevented in major browsers like Firefox, as explained in this excellent technical analysis https://ritter.vg/blog-webaudio_alibaba.html by @tomrittervg.

Worst part is the article that went straight for FUD and had links for paid articles explaining how to "protect yourself" blergh. I thought better of you heise...

1
1
0
[RSS] Ruby Marshal Kick-off Gadgets - elttam

https://www.elttam.com/blog/ruby-marshal-kick-off-gadgets
0
0
0
repeated

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

https://nvd.nist.gov/vuln/detail/CVE-2026-57909

1
1
0
repeated
@buherator u might like this madness hehe

https://youtu.be/etNTbFZGV8E
1
1
0
@cygnus-xr1 nice work! That thing needs a pilot license...
0
0
0
repeated

Mythos: 0
Aisle: 29

😱

4
3
0
repeated

Did you read our latest publication?

Our latest advisory covers a critical vulnerability in UNISOC modem firmware that can provide unrestricted read and write access to physical memory, potentially leading to arbitrary code execution with kernel privileges.

At SSD Secure Disclosure, we’re actively looking for baseband vulnerabilities and exploits, particularly high-impact research that can lead to remote code execution or equivalent impact.
Working on baseband security? Let us get you the highest payout available!

Check out our full product scope at https://ssd-disclosure.com/product-index/

0
1
0
repeated

The Gardener's laboratory.

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/

1
4
0
[RSS] Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust

https://bughunters.google.com/blog/scaling-memory-safety
0
1
1
repeated

The legendary Cliff Stoll gave a delightful talk at DEFCON on Stalking The Wily Hacker (40 Years Later) at DEFCON. It's now online. If you've never seen Cliff, a Klein Bottle, or an overhead projector before, rush over to the youtubes and fix that right now: https://www.youtube.com/watch?v=656058JxTM0

2
15
1
repeated

Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here (password: "expmon"):

https://drive.google.com/file/d/140JTizPrejK28bP3kt-iPdS5bRIy5hLr/view?usp=sharing

As shared previously, the crash still affects the latest Adobe Reader, but probably just a null-pointer-dereference issue.
https://bird.makeup/users/haifeili/statuses/2090513692895154536

0
1
0
repeated

just got laid off this morning. so if anyone knows of a position for an experienced researcher please let me know. 🖤

0
8
0
repeated

flock ceo calls for compromise

you heard em, hackers

0
5
0
repeated

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

0
3
0
@foone That's enterprise security 101!
1
0
1
repeated

it's the last week of my summer sale -- get 50% a copy of "building git" using code BGAUG2026 at https://shop.jcoglan.com/building-git/

0
2
0
repeated

LAST WEEK to submit — Tokyo CFP closes soon.

We want real, original work: cutting-edge security research, novel exploit techniques, AI and deep technical investigations that actually move the field forward.

0
2
0
Show older