the intensity of the push to /replace/ ECC with PQC instead of hardening puts doubt on the security of the whole PQ setup
https://x.com/hashbreaker/status/2079577558895726668?s=46
https://x.com/hashbreaker/status/2079577558895726668?s=46
X (formerly Twitter)
Daniel J. Bernstein (@hashbreaker) on X
Wow. After disenfranchising an unspecified list of people and making claims about the resulting numbers, the IETF TLS WG chairs refused to answer an evidence request from Fabiana Da Pieve, the Eur…
💯1
Bernard Arnault is no saint but this is a work of art
https://x.com/lulumeservey/status/2081583334434468262 (translation), https://x.com/LVMH_Presse/status/2081404246751109150 (original in french)
https://x.com/lulumeservey/status/2081583334434468262 (translation), https://x.com/LVMH_Presse/status/2081404246751109150 (original in french)
X (formerly Twitter)
Lulu Cheng Meservey (@lulumeservey) on X
Bernard Arnault going direct is remarkable and worth reading in full
The single most impressive thing is that Arnault (personally, not via company spokesman) responds to a major hit piece without…
The single most impressive thing is that Arnault (personally, not via company spokesman) responds to a major hit piece without…
🤨1
PSA: do tell your sysadmin:
nginx
nginx
CVE-2026-42533 — every release since 2011 affected, pre-auth RCE exploit with ASLR bypass available 🤯👍1😱1
daily PSA: DISABLE GIT AUTOSYNC IN YOUR EDITOR NOW.
There is an ongoing spray of attacks on (public but also private once somebody from your org gets infected) repositories that try to push code with exploits that fire once landed on your machine (malicious VSCode configs, etc)
There is an ongoing spray of attacks on (public but also private once somebody from your org gets infected) repositories that try to push code with exploits that fire once landed on your machine (malicious VSCode configs, etc)
😱3
maybe claude choosing to rewrite libraries by default has a point lol
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
www.aikido.dev
Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
😁4👻1
https://fixupx.com/andreamatranga/status/2081292444268728505?s=20
i wonder if one can scale this a bit and make a flying Strandbeest (the walking kinetic sculpture)
i wonder if one can scale this a bit and make a flying Strandbeest (the walking kinetic sculpture)
🧵 Thread • FixupX
Andrea Matranga 🇺🇦🌻 (@andreamatranga)
If you tether two airfoils to each other and make them fly at different altitude, you can exploit the difference in wind speed to keep the conraption aloft with no tether point. With some clever control logic you can even get it to tack upwind. @smartereveryday…
🔥1
https://github.com/alex193a/Root-My-Pixel local root on Google Pixel phones incl pixel10, incl fairly recent kernel versions. ppl say that includes latest but i don't have a pixel so did not check
GitHub
GitHub - alex193a/Root-My-Pixel: Jailbreak supported Google Pixel phones with CVE-2026-43499
Jailbreak supported Google Pixel phones with CVE-2026-43499 - alex193a/Root-My-Pixel
👾2
cpu not found, starting software emulation
https://x.com/lithos_graphein/status/2092733478085304609?s=20
https://x.com/lithos_graphein/status/2092733478085304609?s=20
X (formerly Twitter)
🌿 lithos (@lithos_graphein) on X
Phoenix Semiconductor specializes in replacing obsolete silicon chips used by the U.S. military, some of them nearly 50 years old. Using electronic forensics, the team reverse-engineers how each c…
👾2
mikrotik ssh rce. these days, it's generally not a good idea to have ssh to anything accessible from the internet
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
cert.pl
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from…
👀2
Forwarded from gerontion
The best recap of what AI did to vulnerability research up to date. Frontier labs had treated this area of cybersecurity as priority, so it may be a relevant read to get a feel of what may happen to other industries.
https://sites.google.com/site/zhiniangpeng/blogs/Hacking-with-LLMs-Eng
https://sites.google.com/site/zhiniangpeng/blogs/Hacking-with-LLMs-Eng
Google
A Year of Hacking with LLMs
This blog is a summary of my talk at the Offbyone 2026 cybersecurity conference. It records some of my thoughts as a cybersecurity researcher after spending a year using LLMs for research.
Slides: https://github.com/edwardzpeng/presentations/tree/main/offbyone%202026…
Slides: https://github.com/edwardzpeng/presentations/tree/main/offbyone%202026…
👍3
great writing, clear & thoughtful
tldr: computers used to be math, and now they're about physics & natural sciences!
https://thomasdullien.github.io/about/slides/An-age-of-experimentation-BlueHat-Asia-2026.pdf
tldr: computers used to be math, and now they're about physics & natural sciences!
https://thomasdullien.github.io/about/slides/An-age-of-experimentation-BlueHat-Asia-2026.pdf
umm ahem if you don't try to rein in new opus(5.5) you get one more qualitative step in capabilities, now animation
https://fixupx.com/donaldjewkes/status/2102801274173587569?s=46
https://fixupx.com/donaldjewkes/status/2102801274173587569?s=46
🧵 Thread • FixupX
donald (@donaldjewkes)
I made this with one prompt using Opus 5.5
I spoke to my computer for 5mins, claude worked for 12 hours, and I woke up to this
full prompt:
Quoting NotinReality (@other__reality)
Claude Opus 5.5 has the best visual design of any model I have tested so…
I spoke to my computer for 5mins, claude worked for 12 hours, and I woke up to this
full prompt:
Quoting NotinReality (@other__reality)
Claude Opus 5.5 has the best visual design of any model I have tested so…
👀1
um, ahem, AlphaZero for text.
Training language models without language.
https://arxiv.org/abs/2609.30063
https://github.com/acowsik/self_play_pretraining
Training language models without language.
Loosely, natural data mixes contingent information (facts about our world) with universal predictive structure (composition, repetition, recursion, etc…) that are not specific to our world. Our self-play approach only supplies the latter. However, if it produces universal structure efficiently, and if universal structure is the bottleneck, predictable scaling on natural data follows.
https://arxiv.org/abs/2609.30063
https://github.com/acowsik/self_play_pretraining
arXiv.org
Self-Play Pretraining with Zero Data
Advances in language modeling have been driven by scaling pretraining on ever more data. Yet, the training data is still largely curated on the model's behalf. A more general approach to...
cursed font factory
https://bastardica.mitpit.com/
https://bastardica.mitpit.com/
Bastardica
A type foundry for bastard web fonts.
😱2🔥1