Interesting Git repos of the week:
Bugs:
* https://github.com/MSNightmare/FalconFlank - everyone's favourite new source of 0day pops CrowdStrike Falcon
* https://github.com/MSNightmare/HardBreacher - everyone's favourite new source of 0day pops Kaspersky AV
Hard hacks:
* https://github.com/salmg/SIMtrace2-T1-Research - research into SIM cards
* https://github.com/i12bp8/TagTinker - messing with IR on the Flipper Zero
* https://github.com/nickdaria/wyze-bulb-color-pwned - and Nick opened the firmware and set "let there be light..."
* https://github.com/jprx/darwin-vm - the Apple never falls far from the tree
Hardening:
* https://github.com/a13xp0p0v/linux-kernel-defence-map - mapping the Linux kernel attack surface
* https://github.com/ryancdotorg/libclaymore - @ryanc defuses dd
Data:
* https://github.com/going-doer/Paper2Code - generate PoC code from papers 🤖
* https://github.com/adulau/ptrclassify - what's in a name asks @adulau
What happens if a model is repeatedly asked to make a small, localized tweak to an image. In case you were wondering. You can thank me later.
Yes, we can.
PC Gamer: Go grandmaster becomes first human to win series against advanced AI engine in 3-hour match https://www.pcgamer.com/software/ai/go-grandmaster-becomes-first-human-to-win-series-against-advanced-ai-engine-in-3-hour-match/
The fedi isn't like email.
The fedi is like if you triple booked a BDSM meet up, a FSF convention, and a communist workers AGM all in the same German arena.
@osxreverser
teh fuck 🫣
"CVE-2026-67276 - SSH authentication bypass (CVSS: 9.2)
RouterOS did not properly verify public keys used for SSH authentication - in particular, it did not compare the entire RSA public key assigned to a user. An attacker who knew the username and the public modulus of the user's key could craft a different key and log in via SSH without possessing the corresponding private key. The privileges obtained were equivalent to those of the targeted account."
\o/ #klutshnik server now also builds with #zig v0.16 \o/
was quite easy after updating zphinx* before.
https://klutshnik.info - unlike the common tools like pgp and age - is an online threshold data-at-rest crypto system that provides very cheap and efficient key-updates and thus forward secrecy and post-compromise security.
*zphinx is an online threshold password manager far ahead of the competition in terms of security guarantees: https://sphinx.pm
The opposite of mass-destroying books to feed AI is this 1-minute video 📽️ of Charlotte Wainwright restoring and saving old/ancient books ...
(Definitely worth a watch)