Feds: Super sophisticated computer hacking hackers hacked all the utilities!
The actual attackers:
We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.
It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.
Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
A bit annoyed by tech reporting again. Found two major tech news outlets provide an incorrect explanation of the WebAudio fingerprinting (not you arstechnica. You did good). The thing is mostly prevented in major browsers like Firefox, as explained in this excellent technical analysis https://ritter.vg/blog-webaudio_alibaba.html by @tomrittervg.
Worst part is the article that went straight for FUD and had links for paid articles explaining how to "protect yourself" blergh. I thought better of you heise...
sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.
Did you read our latest publication?
Our latest advisory covers a critical vulnerability in UNISOC modem firmware that can provide unrestricted read and write access to physical memory, potentially leading to arbitrary code execution with kernel privileges.
At SSD Secure Disclosure, we’re actively looking for baseband vulnerabilities and exploits, particularly high-impact research that can lead to remote code execution or equivalent impact.
Working on baseband security? Let us get you the highest payout available!
Check out our full product scope at https://ssd-disclosure.com/product-index/
The Gardener's laboratory.
A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/
The legendary Cliff Stoll gave a delightful talk at DEFCON on Stalking The Wily Hacker (40 Years Later) at DEFCON. It's now online. If you've never seen Cliff, a Klein Bottle, or an overhead projector before, rush over to the youtubes and fix that right now: https://www.youtube.com/watch?v=656058JxTM0
Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here (password: "expmon"):
https://drive.google.com/file/d/140JTizPrejK28bP3kt-iPdS5bRIy5hLr/view?usp=sharing
As shared previously, the crash still affects the latest Adobe Reader, but probably just a null-pointer-dereference issue.
https://bird.makeup/users/haifeili/statuses/2090513692895154536
just got laid off this morning. so if anyone knows of a position for an experienced researcher please let me know. 🖤
flock ceo calls for compromise
you heard em, hackers
Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
it's the last week of my summer sale -- get 50% a copy of "building git" using code BGAUG2026 at https://shop.jcoglan.com/building-git/