<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-05-29T02:05:11Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Tim (Wadhwa-)Brown :donor:</title>
  <author>
    <name>Tim (Wadhwa-)Brown :donor:</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07.rss" />
  <link href="https://yabu.me/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07" />
  <id>https://yabu.me/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/270/420/396/177/158/original/dee4c24c931fd17a.jpeg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/270/420/396/177/158/original/dee4c24c931fd17a.jpeg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsxn89kqu6lcna048wnjvkqjn5ytj2wpglem2tv9lyhh3t00xfg65czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkxtux</id>
    
      <title type="html">Someone&amp;#39;s just listed out &amp;#34;all&amp;#34; the Windows versions ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxn89kqu6lcna048wnjvkqjn5ytj2wpglem2tv9lyhh3t00xfg65czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkxtux" />
    <content type="html">
      Someone&amp;#39;s just listed out &amp;#34;all&amp;#34; the Windows versions - with the tag line &amp;#34;which one did you start on&amp;#34; - and I am genuinely sad they forgot Windows 2.
    </content>
    <updated>2026-04-20T14:51:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs837253vhapskevhgqp2um9jxuysaymag7k9l9nkcptxdjn8qye2czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjtsp62</id>
    
      <title type="html">When times were simpler: &amp;#34;text generator&amp;#34; ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs837253vhapskevhgqp2um9jxuysaymag7k9l9nkcptxdjn8qye2czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjtsp62" />
    <content type="html">
      When times were simpler:&lt;br/&gt;&lt;br/&gt;&amp;#34;text generator&amp;#34;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/398/545/697/160/770/original/5b7142feb5ce6c17.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-13T17:22:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdwmjacu3j0z9hc2egq6q0v7l0kvc8spnus8mr06lpv05rwe36a0szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt9qa5u</id>
    
      <title>Nostr event nevent1qqsdwmjacu3j0z9hc2egq6q0v7l0kvc8spnus8mr06lpv05rwe36a0szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt9qa5u</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdwmjacu3j0z9hc2egq6q0v7l0kvc8spnus8mr06lpv05rwe36a0szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt9qa5u" />
    <content type="html">
      Has anyone seen any analysis of CVE:KEV ratios over time?
    </content>
    <updated>2026-04-09T08:48:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs88f3yn0v5xw8mmjh3qhye0jhrdc04lanretrx6se5x0vu2psukggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrrlpc9</id>
    
      <title type="html">Finally got around to uploading my slides for Reflections on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs88f3yn0v5xw8mmjh3qhye0jhrdc04lanretrx6se5x0vu2psukggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrrlpc9" />
    <content type="html">
      Finally got around to uploading my slides for Reflections on trusting Zero Trust (or why I have zero trust in Zero Trust) from BSides London 2021:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/timb-machine/presentations/blob/main/Reflections%20on%20Trusting%20Zero%20Trust%20-%20Why%20I%20have%20Zero%20Trust%20in%20Zero%20Trust%20v3.pdf&#34;&gt;https://github.com/timb-machine/presentations/blob/main/Reflections%20on%20Trusting%20Zero%20Trust%20-%20Why%20I%20have%20Zero%20Trust%20in%20Zero%20Trust%20v3.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#engineering, #architecture
    </content>
    <updated>2026-03-29T08:25:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdmypmf2pnljvskzlhyj9ahjy6u2gmer8mznxk008qrg7pgwpaq5qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhwy0hx</id>
    
      <title type="html">For those that are upset about time, I&amp;#39;ve had an internal ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdmypmf2pnljvskzlhyj9ahjy6u2gmer8mznxk008qrg7pgwpaq5qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhwy0hx" />
    <content type="html">
      For those that are upset about time, I&amp;#39;ve had an internal date rollover too. Hours are easy for me, it&amp;#39;s years that are harder.
    </content>
    <updated>2026-03-29T07:23:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd05vu37l4tzuhz6rddsdjxf36ngk2khktdwjaee5eef4tpt7nqkczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsf3hyk</id>
    
      <title type="html">Worth noting that after that paper&amp;#39;s release I did further ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd05vu37l4tzuhz6rddsdjxf36ngk2khktdwjaee5eef4tpt7nqkczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsf3hyk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqe4gaxap7jppk8d9l82vphye878zv0ac2xtsyfumxskd7tunuu9cwnry9p&#39;&gt;nevent1q…ry9p&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Worth noting that after that paper&amp;#39;s release I did further work and found examples that would yield code execution and LPE.
    </content>
    <updated>2026-03-28T16:58:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqe4gaxap7jppk8d9l82vphye878zv0ac2xtsyfumxskd7tunuu9czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz24kxku</id>
    
      <title type="html">My original paper from 2013: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqe4gaxap7jppk8d9l82vphye878zv0ac2xtsyfumxskd7tunuu9czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz24kxku" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8n3d9s4lwwjvdnny8v348kg6dt27w9tkt5w8weqlklg6csrl3jac4dz3w6&#39;&gt;nevent1q…z3w6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;My original paper from 2013:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://labs.portcullis.co.uk/download/MSAOSVSM.pdf&#34;&gt;https://labs.portcullis.co.uk/download/MSAOSVSM.pdf&lt;/a&gt;
    </content>
    <updated>2026-03-28T16:53:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8n3d9s4lwwjvdnny8v348kg6dt27w9tkt5w8weqlklg6csrl3jaczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5cdrsv</id>
    
      <title type="html">The number of places that are still potentially vulnerable to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8n3d9s4lwwjvdnny8v348kg6dt27w9tkt5w8weqlklg6csrl3jaczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5cdrsv" />
    <content type="html">
      The number of places that are still potentially vulnerable to weak shared memory permissions...&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://codesearch.debian.net/search?q=shm&#34;&gt;https://codesearch.debian.net/search?q=shm&lt;/a&gt;.*\(.*[0-9][0-9][67]&amp;amp;literal=0
    </content>
    <updated>2026-03-28T16:52:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgmjgnt0sqfpwx00w92nd9t2w5mc4llf77lzf2fl0vx80yf9ukprqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz3ncuyz</id>
    
      <title type="html">Citrix oofise reaches primetime: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgmjgnt0sqfpwx00w92nd9t2w5mc4llf77lzf2fl0vx80yf9ukprqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz3ncuyz" />
    <content type="html">
      Citrix oofise reaches primetime:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&#34;&gt;https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#netscaler, #threatintel
    </content>
    <updated>2026-03-28T13:18:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspsupzs3agm5960ax643a70ax4rrdwtqtkwdwtde2kf58mkdeq4dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz00qte5</id>
    
      <title type="html">Interesting Git repos of the week: Threats: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspsupzs3agm5960ax643a70ax4rrdwtqtkwdwtde2kf58mkdeq4dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz00qte5" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/deepfield/public-research&#34;&gt;https://github.com/deepfield/public-research&lt;/a&gt; - Nokia ERT&amp;#39;s threat intel research&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/RogoLabs/VulnRadar&#34;&gt;https://github.com/RogoLabs/VulnRadar&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1660f345qea7y0w0jr0q0scnrsh4tud65msvwxk46d8rlmtm6f6sqmgu8rt&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Jerry Gamblin&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1660…u8rt&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s tools for vulnerability intelligence on a budget&lt;br/&gt;* &lt;a href=&#34;https://github.com/cmu-sei/GHOSTS&#34;&gt;https://github.com/cmu-sei/GHOSTS&lt;/a&gt; - a ghost with a shell&lt;br/&gt;* &lt;a href=&#34;https://github.com/luckyPipewrench/pipelock&#34;&gt;https://github.com/luckyPipewrench/pipelock&lt;/a&gt; - firewall your agents&lt;br/&gt; &lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/nikaiw/VMkatz&#34;&gt;https://github.com/nikaiw/VMkatz&lt;/a&gt; - extract creds from VM snapshots&lt;br/&gt;* &lt;a href=&#34;https://github.com/0xbigshaq/apatchy&#34;&gt;https://github.com/0xbigshaq/apatchy&lt;/a&gt; - fuzz your Apache modules&lt;br/&gt;* &lt;a href=&#34;https://github.com/numbpill3d/can-playground&#34;&gt;https://github.com/numbpill3d/can-playground&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h6a3l7q9aa4e8239ch50qh5fhxdnmuwkaq5twwvd3gpfa83k4fws28zxr9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;scorn&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h6a…zxr9&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s CAN tools&lt;br/&gt;* &lt;a href=&#34;https://github.com/grokjc/exploitation-validator&#34;&gt;https://github.com/grokjc/exploitation-validator&lt;/a&gt; - JC&amp;#39;s raptor enhancements&lt;br/&gt;* &lt;a href=&#34;https://github.com/LOLAD-Project/LOLAD-Project.github.io&#34;&gt;https://github.com/LOLAD-Project/LOLAD-Project.github.io&lt;/a&gt; - living off the land by hiding in the forest&lt;br/&gt;&lt;br/&gt;#code, #security, #research
    </content>
    <updated>2026-03-28T12:03:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstwe27jzskqrd78ltfmut6mx873a8sv0sxnlu226y4x5h6f3vcnugzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9x0q3d</id>
    
      <title type="html">Today&amp;#39;s AI bullshit: &amp;#34;Yes, I know agentic AI is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstwe27jzskqrd78ltfmut6mx873a8sv0sxnlu226y4x5h6f3vcnugzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9x0q3d" />
    <content type="html">
      Today&amp;#39;s AI bullshit: &amp;#34;Yes, I know agentic AI is potentially unsafe, but can&amp;#39;t we just run it in a container then it will be fine.&amp;#34;
    </content>
    <updated>2026-03-27T23:12:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqswg67j97m3eak33773cm202a6npqjxgdxxx56jvftxwqgvaffzczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqa09vt</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqswg67j97m3eak33773cm202a6npqjxgdxxx56jvftxwqgvaffzczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqa09vt" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.marisec.ca/reports/the-wrong-fix-why-the-fccs-router-ban-misses-the-real-threat&#34;&gt;https://www.marisec.ca/reports/the-wrong-fix-why-the-fccs-router-ban-misses-the-real-threat&lt;/a&gt; - an alternate view on prioritising the supply chain&lt;br/&gt;* &lt;a href=&#34;https://cybertoolkit.service.ncsc.gov.uk/&#34;&gt;https://cybertoolkit.service.ncsc.gov.uk/&lt;/a&gt; - so you&amp;#39;re a small business and you want to improve your posture?&lt;br/&gt;* &lt;a href=&#34;https://how.complexsystems.fail/&#34;&gt;https://how.complexsystems.fail/&lt;/a&gt; - courtesy of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1hg9xaza0p8y5s4dcj7pn5npg3kq3s7uma0fjxq6j23u2szwp9eqqs9wwtk&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Russ Garrett&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1hg9…wwtk&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://eepublicdownloads.blob.core.windows.net/public-cdn-container/clean-documents/Publications/2025/iberian-blackout/Final%20Report%20on%20the%20Grid%20Incident%20in%20Spain%20and%20Portugal%20on%2028%20April%202025.pdf&#34;&gt;https://eepublicdownloads.blob.core.windows.net/public-cdn-container/clean-documents/Publications/2025/iberian-blackout/Final%20Report%20on%20the%20Grid%20Incident%20in%20Spain%20and%20Portugal%20on%2028%20April%202025.pdf&lt;/a&gt; - an Iberian oopsie&lt;br/&gt;* &lt;a href=&#34;https://www.theregister.com/2026/03/20/jlr_bailout_cmc/&#34;&gt;https://www.theregister.com/2026/03/20/jlr_bailout_cmc/&lt;/a&gt; - [@theregister](&lt;a href=&#34;https://geeknews.chat/@theregister&#34;&gt;https://geeknews.chat/@theregister&lt;/a&gt; ) shares a point of view on bailing out JLR&lt;br/&gt;* &lt;a href=&#34;https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf&#34;&gt;https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf&lt;/a&gt; - US intelligence community&amp;#39;s annual threat assessment&lt;br/&gt;* &lt;a href=&#34;https://cyber.gouv.fr/actualites/nis-2-lanssi-poursuit-et-renforce-sa-dynamique-daccompagnement/&#34;&gt;https://cyber.gouv.fr/actualites/nis-2-lanssi-poursuit-et-renforce-sa-dynamique-daccompagnement/&lt;/a&gt; - hot new NIS2 action from ANSSI&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/&#34;&gt;https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/&lt;/a&gt; - how does AI affect STRIDE?&lt;br/&gt;* &lt;a href=&#34;https://united24media.com/latest-news/russian-spy-devices-found-inside-ukrainian-drone-developers-office-17243&#34;&gt;https://united24media.com/latest-news/russian-spy-devices-found-inside-ukrainian-drone-developers-office-17243&lt;/a&gt; - attack of the drones&lt;br/&gt;* &lt;a href=&#34;https://www.elastic.co/security-labs/illuminating-voidlink&#34;&gt;https://www.elastic.co/security-labs/illuminating-voidlink&lt;/a&gt; - another look at VoidLink&lt;br/&gt;* &lt;a href=&#34;https://ctrlaltintel.com/threat%20research/FancyBear/&#34;&gt;https://ctrlaltintel.com/threat%20research/FancyBear/&lt;/a&gt; - FancyBear fucks up&lt;br/&gt;* &lt;a href=&#34;https://netaskari.substack.com/p/chinas-massive-data-leak-of-military&#34;&gt;https://netaskari.substack.com/p/chinas-massive-data-leak-of-military&lt;/a&gt; - .cn springs a leak&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf&#34;&gt;https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf&lt;/a&gt; - my colleague &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1660f345qea7y0w0jr0q0scnrsh4tud65msvwxk46d8rlmtm6f6sqmgu8rt&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Jerry Gamblin&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1660…u8rt&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; talks open source intelligence&lt;br/&gt;* &lt;a href=&#34;https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging&#34;&gt;https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1jfz58dhla3mwj0x6xu6jh98ym5wkss5s64zesucp7939zvcm77rq2vm99l&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;trustedsec&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1jfz…m99l&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; look at logging PowerShell&lt;br/&gt;* &lt;a href=&#34;https://righteousit.com/2026/03/27/linux-forensic-scenario/&#34;&gt;https://righteousit.com/2026/03/27/linux-forensic-scenario/&lt;/a&gt; - [@hal_pomeranz](&lt;a href=&#34;https://infosec.exchange/@hal_pomeranz&#34;&gt;https://infosec.exchange/@hal_pomeranz&lt;/a&gt; ) sets us a little challenge&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/&#34;&gt;https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/&lt;/a&gt; - this reminds me of when I first showed &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xl5ts3h4q2nqgztthcl39sgvjr3n38q488avst06a0jtnd2jelustphs79&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Ben Harris&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xl5…hs79&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; AIX&lt;br/&gt;* &lt;a href=&#34;https://itm4n.github.io/cve-2026-20817-wersvc-eop/&#34;&gt;https://itm4n.github.io/cve-2026-20817-wersvc-eop/&lt;/a&gt; - when errors go rogue with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ktwqmdq0uwway3lnnywh7m6zp9eaeze8cvdmdsumxqzd3suudl4q42rg75&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Clément Labro&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ktw…rg75&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6&#34;&gt;https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h6a3l7q9aa4e8239ch50qh5fhxdnmuwkaq5twwvd3gpfa83k4fws28zxr9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;scorn&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h6a…zxr9&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; shows how you CAN play with busses&lt;br/&gt;* &lt;a href=&#34;https://agentseal.org/blog/mcp-server-security-findings&#34;&gt;https://agentseal.org/blog/mcp-server-security-findings&lt;/a&gt; - hands up if you have a secure MCP?&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf&#34;&gt;https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf&lt;/a&gt; - enclave backed SSH for OS X from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1sueknadxh6t7dkgszkctxf4qqqh752kk5q9aa645ww5mynx3qkrspwwfat&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Arian&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1sue…wfat&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.theguardian.com/culture/2026/mar/24/punk-masks-walkmans-and-choppers-museum-of-youth-culture-to-open-in-london&#34;&gt;https://www.theguardian.com/culture/2026/mar/24/punk-masks-walkmans-and-choppers-museum-of-youth-culture-to-open-in-london&lt;/a&gt; - eras...&lt;br/&gt;* &lt;a href=&#34;https://www.data.gov.uk/&#34;&gt;https://www.data.gov.uk/&lt;/a&gt; - UK specific datasets from HMG&lt;br/&gt;* &lt;a href=&#34;https://www.sambent.com/the-engineer-who-tried-to-put-age-verification-into-linux-5/&#34;&gt;https://www.sambent.com/the-engineer-who-tried-to-put-age-verification-into-linux-5/&lt;/a&gt; - today in Linux daftness&lt;br/&gt;* &lt;a href=&#34;https://blog.rice.is/post/doom-over-dns/&#34;&gt;https://blog.rice.is/post/doom-over-dns/&lt;/a&gt; - everyone&amp;#39;s favourite vanity PoC payload comes to DNS&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-03-27T14:41:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszsustjnsmgqzuteg8xtl04k0kakqep4zunn0w0lk054ur0nqq5egzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvjlu48</id>
    
      <title type="html">In which I get shout outs from the grsec crew: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszsustjnsmgqzuteg8xtl04k0kakqep4zunn0w0lk054ur0nqq5egzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvjlu48" />
    <content type="html">
      In which I get shout outs from the grsec crew:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/spendergrsec/status/2037295088225636706&#34;&gt;https://x.com/spendergrsec/status/2037295088225636706&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This piece of work remains one of my high water marks for security research. For all the bugs etc, doing something worthy of a grsec enhancement gives me a big smile.&lt;br/&gt;&lt;br/&gt;Cheers &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dg70p8m84vkzk7dgyptnl5ym65krusna7azaqfkwhrlkcj5aaa8q2apyc8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;grsecurity&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dg7…pyc8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; folks.
    </content>
    <updated>2026-03-27T12:06:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswvskshtw33mlgp0se47se66wvlqpzr7d6jgjl44yy5a56rfvglyqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzk3v6gk</id>
    
      <title type="html">Coding with LLMs and agents is a generational opportunity to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswvskshtw33mlgp0se47se66wvlqpzr7d6jgjl44yy5a56rfvglyqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzk3v6gk" />
    <content type="html">
      Coding with LLMs and agents is a generational opportunity to throw the last decade&amp;#39;s hard won lessons on secure coding and appsec out of the window. Definitely something that trust and safety teams, threat actors and possibly even your parents are seizing on with glee when they bypass all of your policies and procedures around installing new software, data governance, validated designs, code reviews, principles of least privilege and regular security assessments. Best of luck.
    </content>
    <updated>2026-03-24T17:40:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsquuq57kkn8vy9q0ncq343lgfa4jukjhn0xpfwwz2a9l44wet35ggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrlfzgg</id>
    
      <title type="html">Today&amp;#39;s oofness is on us :(: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsquuq57kkn8vy9q0ncq343lgfa4jukjhn0xpfwwz2a9l44wet35ggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrlfzgg" />
    <content type="html">
      Today&amp;#39;s oofness is on us :(:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.talosintelligence.com/uat-8616-sd-wan/&#34;&gt;https://blog.talosintelligence.com/uat-8616-sd-wan/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #sdwan
    </content>
    <updated>2026-02-25T17:58:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgp4p7xnyhus0f49wpl0gwe9a2503snnuermzu3tkvkt6u08x8jsgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2nwp9d</id>
    
      <title type="html">Got any plans to seize control and create an army from any ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgp4p7xnyhus0f49wpl0gwe9a2503snnuermzu3tkvkt6u08x8jsgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2nwp9d" />
    <content type="html">
      Got any plans to seize control and create an army from any household IoT today? If so, LLM can help:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt&#34;&gt;https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt&lt;/a&gt;
    </content>
    <updated>2026-02-25T07:58:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswqkyl5xy75264km7ls0hahyj226t9c0u80xzctpl3e4427wf07xgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz36d93a</id>
    
      <title type="html">RE: https://infosec.exchange/@timb_machine/116068550511596363 If ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswqkyl5xy75264km7ls0hahyj226t9c0u80xzctpl3e4427wf07xgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz36d93a" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@timb_machine/116068550511596363&#34;&gt;https://infosec.exchange/@timb_machine/116068550511596363&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;If there&amp;#39;s anyone on here that works at GitHub, do you think you could remind your support team to check their emails.&lt;br/&gt;&lt;br/&gt;For reasons unknown you decided to suspend my account a week ago and I&amp;#39;m yet to even get a response that a ticket has been opened to investigate. I&amp;#39;m sure there&amp;#39;s a reason (although I suspect it&amp;#39;s debatable) but it would at least be nice to hear from you that it&amp;#39;s being looked at.&lt;br/&gt;&lt;br/&gt;#github&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1s4y359gt7axpqshc8xt5wm34y2m8j3ptrn7t5pvjq6p7a5gtydjswdfhh2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1s4y…fhh2&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; *sigh*, a reminder that there are definite pros to self hosting. Waiting for someone to respond to a support ticket. &lt;/blockquote&gt;
    </content>
    <updated>2026-02-19T23:04:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg2jg6z59lwnqsgturn968dc6j9dnegs43el96qkfqdqlw6y9jxegzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs884c5</id>
    
      <title type="html">*sigh*, a reminder that there are definite pros to self hosting. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg2jg6z59lwnqsgturn968dc6j9dnegs43el96qkfqdqlw6y9jxegzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs884c5" />
    <content type="html">
      *sigh*, a reminder that there are definite pros to self hosting. Waiting for someone to respond to a support ticket.
    </content>
    <updated>2026-02-14T10:38:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfegd2yl2rn8c73p2uj382ywkwv75ak7e4lgkenutgjs20hzfr4wszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznmplea</id>
    
      <title type="html">Seen an interesting trend in UK FSI over the last months, with ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfegd2yl2rn8c73p2uj382ywkwv75ak7e4lgkenutgjs20hzfr4wszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznmplea" />
    <content type="html">
      Seen an interesting trend in UK FSI over the last months, with multiple requests for specific support in hampering network-centric aspects of discovery, lateral movement, C2 and exfiltration. I wonder what it&amp;#39;s attributed to.&lt;br/&gt;&lt;br/&gt;#threatintel, #fsi
    </content>
    <updated>2026-02-07T14:56:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8pqza0xlrvdlku320ydu2uplv9gdstppcew4d8rk59hg7jkqdsgqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzzf3tey</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8pqza0xlrvdlku320ydu2uplv9gdstppcew4d8rk59hg7jkqdsgqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzzf3tey" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://x-c3ll.github.io/posts/Rant-Red-Team/&#34;&gt;https://x-c3ll.github.io/posts/Rant-Red-Team/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub19ynhwha8h857slzzuwmr73kspkn4szdqdgrv2ecp44w00m7cvctsem5ucd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Juanma Fernandez&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub19yn…5ucd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; talks red teaming trends&lt;br/&gt;* &lt;a href=&#34;https://arstechnica.com/security/2026/01/county-pays-600000-to-pentesters-it-arrested-for-assessing-courthouse-security/&#34;&gt;https://arstechnica.com/security/2026/01/county-pays-600000-to-pentesters-it-arrested-for-assessing-courthouse-security/&lt;/a&gt; - finally settled, the poor testers with a faulty get out of jail card&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://stratcomcoe.org/pdfjs/?file=/publications/download/Social-Media-Manipulation-FINAL-FILE.pdf?zoom=page-fit&#34;&gt;https://stratcomcoe.org/pdfjs/?file=/publications/download/Social-Media-Manipulation-FINAL-FILE.pdf?zoom=page-fit&lt;/a&gt;  - STRATCOM talks influence operations&lt;br/&gt;* &lt;a href=&#34;https://github.com/blackorbird/APT_REPORT/blob/master/summary%2F2026%2F2025%20Global%20APT%20Threat%20Research%20Report.pdf&#34;&gt;https://github.com/blackorbird/APT_REPORT/blob/master/summary%2F2026%2F2025%20Global%20APT%20Threat%20Research%20Report.pdf&lt;/a&gt; - threat research report from Qihoo 360&lt;br/&gt;* &lt;a href=&#34;https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates&#34;&gt;https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;GreyNoise&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lmd…m9t8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss hidden signals in KEV&lt;br/&gt;* &lt;a href=&#34;https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/&#34;&gt;https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub12gnztrqz68ttv5s5kllvdhj7cwtgtzrdxwuyd7zdj0g465epcznqlasnpu&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;rapid7 :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub12gn…snpu&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s excellent analysis of notepad&#43;&#43;&lt;br/&gt;* &lt;a href=&#34;https://community.plone.org/t/plone-security-advisory-20260116-attempted-code-insertions-into-github-pull-requests/22770/7&#34;&gt;https://community.plone.org/t/plone-security-advisory-20260116-attempted-code-insertions-into-github-pull-requests/22770/7&lt;/a&gt; - another supply chain woopsie&lt;br/&gt;* &lt;a href=&#34;https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/&#34;&gt;https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/&lt;/a&gt; - reporting on the .pl power problems&lt;br/&gt;* &lt;a href=&#34;https://zenodo.org/records/18444900&#34;&gt;https://zenodo.org/records/18444900&lt;/a&gt; - content based risk analysis of Moltbook (not for the faint-hearted)&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://zeek.org/2026/01/how-to-use-ja4-network-fingerprints-in-zeek/&#34;&gt;https://zeek.org/2026/01/how-to-use-ja4-network-fingerprints-in-zeek/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub19qs7vp2pft0zlkjfkqxmg4l88cpettgpvtcrrfh2sr2ql6y595cq36k34f&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Zeek Network Security Monitor&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub19qs…k34f&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss how to leverage JA4&lt;br/&gt;* &lt;a href=&#34;https://blog.jmhill.me/deploying-an-opencti-osint-stack-for-cybersecurity-research/&#34;&gt;https://blog.jmhill.me/deploying-an-opencti-osint-stack-for-cybersecurity-research/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub125dydnyleepf2uad8qmvu7vzlfd3va79t30vy006k9suq2ztdztq3vpadk&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;J.M. Hill&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub125d…padk&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; describes how to deploy OpenCTI&lt;br/&gt;* &lt;a href=&#34;https://www.huntress.com/blog/ldap-active-directory-detection-part-four&#34;&gt;https://www.huntress.com/blog/ldap-active-directory-detection-part-four&lt;/a&gt; - the latest of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1fe05cwn4yp5tmszf859qqg90wtq80huenwm8c7apy63fshsmmwcqyq30s6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Huntress&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1fe0…30s6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s excellent blogs on what an attack on LDAP can actually look like&lt;br/&gt;* &lt;a href=&#34;https://leanpub.com/suri_operator&#34;&gt;https://leanpub.com/suri_operator&lt;/a&gt; - [@da_667](&lt;a href=&#34;https://infosec.exchange/@da_667&#34;&gt;https://infosec.exchange/@da_667&lt;/a&gt; )&amp;#39;s survivors guide to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub19dte26dezjkv3f7mhah9sz3nw55y2vyjk4lhqxh3ghgzlwhs7a9qtlwrng&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Suricata&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub19dt…wrng&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/&#34;&gt;https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/&lt;/a&gt; - [@index](&lt;a href=&#34;https://labs.watchtowr.com/&#34;&gt;https://labs.watchtowr.com/&lt;/a&gt; ) continue their streak of popping fun bugs in the wild&lt;br/&gt;* &lt;a href=&#34;https://zeroleaks.ai/reports/openclaw-analysis.pdf&#34;&gt;https://zeroleaks.ai/reports/openclaw-analysis.pdf&lt;/a&gt; - nice technical write up on OpenClaw&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://scriptjunkie.us/2026/01/tracking-signal-identifiers/&#34;&gt;https://scriptjunkie.us/2026/01/tracking-signal-identifiers/&lt;/a&gt; - leaking Signal IDs from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1j8afajcegmnmlq7qs3ashagyg46sjzpwlj542d7rxmfs5jpnfxwqytfvhn&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;scriptjunkie&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1j8a…fvhn&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://splintersfury.github.io/mal_blog/post/netfilter_driver/&#34;&gt;https://splintersfury.github.io/mal_blog/post/netfilter_driver/&lt;/a&gt; - reversing Netfilter&lt;br/&gt;* &lt;a href=&#34;https://alfiecg.uk/2024/09/24/Kernel-exploit.html&#34;&gt;https://alfiecg.uk/2024/09/24/Kernel-exploit.html&lt;/a&gt; - Alfie pops iOS&lt;br/&gt;* &lt;a href=&#34;https://secure.dev/securing_ggml_rpc.html&#34;&gt;https://secure.dev/securing_ggml_rpc.html&lt;/a&gt; - attack and defend on GGML&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-over-horizon.html&#34;&gt;https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-over-horizon.html&lt;/a&gt; - an oldie on popping NVIDIA&amp;#39;s Falcon&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://itsfoss.com/news/amutable-linux-security/&#34;&gt;https://itsfoss.com/news/amutable-linux-security/&lt;/a&gt; - [@pid_eins](&lt;a href=&#34;https://mastodon.social/@pid_eins&#34;&gt;https://mastodon.social/@pid_eins&lt;/a&gt; ) triggers systemctl restart&lt;br/&gt;* &lt;a href=&#34;https://fosdem.org/2026/schedule/event/EW8M3R-island/&#34;&gt;https://fosdem.org/2026/schedule/event/EW8M3R-island/&lt;/a&gt; - how to get land locked&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-02-05T19:46:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs87h78jwg8dz69vdn66e8v2exc4adryfmwkgs8fl0zlhn8y7y5gegzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz76fqs4</id>
    
      <title type="html">One of our AI threat team pointed me at this: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs87h78jwg8dz69vdn66e8v2exc4adryfmwkgs8fl0zlhn8y7y5gegzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz76fqs4" />
    <content type="html">
      One of our AI threat team pointed me at this:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://zenodo.org/records/18444900&#34;&gt;https://zenodo.org/records/18444900&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Interesting analysis of Moltshite.&lt;br/&gt;&lt;br/&gt;#threatintel, #aislop
    </content>
    <updated>2026-02-02T12:39:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs95rutyt7tug2hw7tft4akrkqje8d3tw7x9skwjfpyu7nq2yl95mczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzc7rkxd</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs95rutyt7tug2hw7tft4akrkqje8d3tw7x9skwjfpyu7nq2yl95mczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzc7rkxd" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www-tokio--dr-jp.translate.goog/thinktank/acd/acd-007.html&#34;&gt;https://www-tokio--dr-jp.translate.goog/thinktank/acd/acd-007.html&lt;/a&gt; - active defense in .jp&lt;br/&gt;* &lt;a href=&#34;https://www.cambridge.org/core/books/securing-democracies/stacking-up-for-resilience/EB2072FAE9F97CF41B568B1C4AAFC190&#34;&gt;https://www.cambridge.org/core/books/securing-democracies/stacking-up-for-resilience/EB2072FAE9F97CF41B568B1C4AAFC190&lt;/a&gt; - building digital resilience ala India&lt;br/&gt;* &lt;a href=&#34;https://www.csis.org/analysis/civil-takedowns-missing-legal-framework-cyber-disruption&#34;&gt;https://www.csis.org/analysis/civil-takedowns-missing-legal-framework-cyber-disruption&lt;/a&gt; - avoiding disruption when performing takedowns&lt;br/&gt;* &lt;a href=&#34;https://breakmeifyoucan.com/&#34;&gt;https://breakmeifyoucan.com/&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://sabsa.org/w105-sabsa-enterprise-security-architecture-principles/&#34;&gt;https://sabsa.org/w105-sabsa-enterprise-security-architecture-principles/&lt;/a&gt; - constructing a security architecture using SABSA principles&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/collection/how-to-prepare-and-plan-your-organisations-response-to-severe-cyber-threat-a-guide-for-cni&#34;&gt;https://www.ncsc.gov.uk/collection/how-to-prepare-and-plan-your-organisations-response-to-severe-cyber-threat-a-guide-for-cni&lt;/a&gt; - NCSC guidance on how to not get yourself in a panic&lt;br/&gt;* &lt;a href=&#34;https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf&#34;&gt;https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf&lt;/a&gt; - a roadmap for quantum&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf&#34;&gt;https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf&lt;/a&gt; - ETSI standards on AI in public life&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/before-vegas-cyberdefense-report.pdf&#34;&gt;https://ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/before-vegas-cyberdefense-report.pdf&lt;/a&gt; - understanding .cn hackers in long form&lt;br/&gt;* &lt;a href=&#34;https://www.bitsight.com/blog/what-is-y2k38-problem&#34;&gt;https://www.bitsight.com/blog/what-is-y2k38-problem&lt;/a&gt; - do you even 2038?&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://it4sec.substack.com/p/detect-rogue-cell-towers-for-50-who&#34;&gt;https://it4sec.substack.com/p/detect-rogue-cell-towers-for-50-who&lt;/a&gt; - hunting rogue radios&lt;br/&gt;* &lt;a href=&#34;https://www.detectionengineering.net/&#34;&gt;https://www.detectionengineering.net/&lt;/a&gt; - a nice news feed for detection engineers&lt;br/&gt;* &lt;a href=&#34;https://github.com/OpenTideHQ/.github/blob/main/profile/OpenTide%20White%20Paper.pdf&#34;&gt;https://github.com/OpenTideHQ/.github/blob/main/profile/OpenTide%20White%20Paper.pdf&lt;/a&gt; - paper on OpenTIDE&lt;br/&gt;* &lt;a href=&#34;https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch&#34;&gt;https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch&lt;/a&gt; - enriching bug classifications&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2402.15147&#34;&gt;https://arxiv.org/abs/2402.15147&lt;/a&gt; - mapping techniques&lt;br/&gt;* &lt;a href=&#34;https://www.huntress.com/blog/ldap-active-directory-detection-part-three&#34;&gt;https://www.huntress.com/blog/ldap-active-directory-detection-part-three&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1fe05cwn4yp5tmszf859qqg90wtq80huenwm8c7apy63fshsmmwcqyq30s6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Huntress&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1fe0…30s6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss AD&amp;#39;s LDAP logs&lt;br/&gt;* &lt;a href=&#34;https://api.gcforum.org/api/files/public/upload/523c55f1-b24a-4824-a841-b513c2aca3bc_Practical-Threat-Detections.pdf&#34;&gt;https://api.gcforum.org/api/files/public/upload/523c55f1-b24a-4824-a841-b513c2aca3bc_Practical-Threat-Detections.pdf&lt;/a&gt; - getting the most from your telco logs&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.zerodayinitiative.com/advisories/ZDI-26-020/&#34;&gt;https://www.zerodayinitiative.com/advisories/ZDI-26-020/&lt;/a&gt; - why are LLMs so quick to oopsie&lt;br/&gt;* &lt;a href=&#34;https://www.interruptlabs.co.uk/articles/when-nas-vendors-forget-how-tls-works&#34;&gt;https://www.interruptlabs.co.uk/articles/when-nas-vendors-forget-how-tls-works&lt;/a&gt; - TLS is hard&lt;br/&gt;* &lt;a href=&#34;https://projectzero.google/2026/01/pixel-0-click-part-1.html&#34;&gt;https://projectzero.google/2026/01/pixel-0-click-part-1.html&lt;/a&gt; - taking over the world, Pixel by Pixel&lt;br/&gt;* &lt;a href=&#34;https://projectzero.google/2026/26/windows-administrator-protection.html&#34;&gt;https://projectzero.google/2026/26/windows-administrator-protection.html&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;James Forshaw :donor:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1wp4…ejcr&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; beats up admins&lt;br/&gt;* &lt;a href=&#34;https://whisperpair.eu/&#34;&gt;https://whisperpair.eu/&lt;/a&gt; - BTLE gets another bad report&lt;br/&gt;* &lt;a href=&#34;https://www.atredis.com/blog/2026/1/26/generals&#34;&gt;https://www.atredis.com/blog/2026/1/26/generals&lt;/a&gt; - exploiting games for fun, high scores and remote tank execution&lt;br/&gt;* &lt;a href=&#34;https://fortiguard.fortinet.com/psirt/FG-IR-26-060&#34;&gt;https://fortiguard.fortinet.com/psirt/FG-IR-26-060&lt;/a&gt; - FortiCloud makes a splash&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.synacktiv.com/publications/pentesting-cisco-aci-lldp-mishandling&#34;&gt;https://www.synacktiv.com/publications/pentesting-cisco-aci-lldp-mishandling&lt;/a&gt; - kicking Cisco&amp;#39;s ACI tyres&lt;br/&gt;* &lt;a href=&#34;https://shazzer.co.uk/blog/distributed-fuzzing-crowdsourced-browser-testing&#34;&gt;https://shazzer.co.uk/blog/distributed-fuzzing-crowdsourced-browser-testing&lt;/a&gt; - scaling browser fuzzing from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xcc6hnrljh03ksmfd4uq4859f756w2h6tp3keckw6pz23ec0unqqrnkhle&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Gareth Heyes :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xcc…khle&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3776743&#34;&gt;https://dl.acm.org/doi/10.1145/3776743&lt;/a&gt; - inferring grammar from parsing&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2601.01592&#34;&gt;https://arxiv.org/abs/2601.01592&lt;/a&gt; - breaking multi-model AI&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://jyn.dev/remotely-unlocking-an-encrypted-hard-disk/&#34;&gt;https://jyn.dev/remotely-unlocking-an-encrypted-hard-disk/&lt;/a&gt; - picking the hard disk lock&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-01-30T13:50:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvfwkwjv0e3gsj9zkuqacjrs9k8lm5376hr96rlg8ys05t3t6fuvgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs3yfam</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvfwkwjv0e3gsj9zkuqacjrs9k8lm5376hr96rlg8ys05t3t6fuvgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs3yfam" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://assets.publishing.service.gov.uk/media/696e0eae719d837d69afc7de/National_security_assessment_-_global_biodiversity_loss__ecosystem_collapse_and_national_security.pdf&#34;&gt;https://assets.publishing.service.gov.uk/media/696e0eae719d837d69afc7de/National_security_assessment_-_global_biodiversity_loss__ecosystem_collapse_and_national_security.pdf&lt;/a&gt; - biodiversity and national security&lt;br/&gt;* &lt;a href=&#34;https://www.gov.uk/government/publications/software-security-ambassadors-scheme&#34;&gt;https://www.gov.uk/government/publications/software-security-ambassadors-scheme&lt;/a&gt; - when you get summoned to number 10 for a nasty oopsie&lt;br/&gt;* &lt;a href=&#34;https://www.cjr.org/news/hannah-natanson-fbi-washington-post-raid-devices-seized-runa-sandvik-security-computer-phone-laptop-sources.php&#34;&gt;https://www.cjr.org/news/hannah-natanson-fbi-washington-post-raid-devices-seized-runa-sandvik-security-computer-phone-laptop-sources.php&lt;/a&gt; - how to blow whistles safely, is it even possible?&lt;br/&gt;* &lt;a href=&#34;https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/2025-cbest-thematic&#34;&gt;https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/2025-cbest-thematic&lt;/a&gt; - themes and trends from UK FSI red teaming under Bank of England&amp;#39;s CBEST programme&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://aivss.parthsohaney.online/calculator&#34;&gt;https://aivss.parthsohaney.online/calculator&lt;/a&gt; - a stab at quantifying AI risk... not convinced it&amp;#39;ll work but at least people are thinking about the problem&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.esentire.com/blog/new-botnet-emerges-from-the-shadows-nightshadec2&#34;&gt;https://www.esentire.com/blog/new-botnet-emerges-from-the-shadows-nightshadec2&lt;/a&gt; - yay, more C2&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/RustyNoob-619/100-Days-of-YARA-2026/blob/main/Rules%2FDay17.yara&#34;&gt;https://github.com/RustyNoob-619/100-Days-of-YARA-2026/blob/main/Rules%2FDay17.yara&lt;/a&gt; - always like a bit of nice YARA&lt;br/&gt;* &lt;a href=&#34;https://andpalmier.com/posts/abuse-ch-toolkit/&#34;&gt;https://andpalmier.com/posts/abuse-ch-toolkit/&lt;/a&gt; - tools for [@abuse_ch](&lt;a href=&#34;https://ioc.exchange/@abuse_ch&#34;&gt;https://ioc.exchange/@abuse_ch&lt;/a&gt; )&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://seclists.org/oss-sec/2026/q1/89&#34;&gt;https://seclists.org/oss-sec/2026/q1/89&lt;/a&gt; - finally Linux telnetd gets an auth-pass feature&lt;br/&gt;* &lt;a href=&#34;https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/&#34;&gt;https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/&lt;/a&gt; - CVE wen, an overflow in UNIX v4&lt;br/&gt;* &lt;a href=&#34;https://www.ibm.com/support/pages/node/7257143&#34;&gt;https://www.ibm.com/support/pages/node/7257143&lt;/a&gt; - so you wanna pop a mainframe?&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.blog/developer-skills/github/codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/&#34;&gt;https://github.blog/developer-skills/github/codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/&lt;/a&gt; - hunting bugs with CodeQL&lt;br/&gt;* &lt;a href=&#34;https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/&#34;&gt;https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/&lt;/a&gt; - industrialising set $pc=0x41414141&lt;br/&gt;* &lt;a href=&#34;https://netaskari.substack.com/p/whats-in-the-box&#34;&gt;https://netaskari.substack.com/p/whats-in-the-box&lt;/a&gt; - pentesting in .cn&lt;br/&gt;* &lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables&lt;/a&gt; - GOOG launch rainbows, share Net NTLMv1 pot of gold&lt;br/&gt;* &lt;br/&gt;&lt;a href=&#34;https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/passwortmanager_sicherheit_datenschutz.pdf&#34;&gt;https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/passwortmanager_sicherheit_datenschutz.pdf&lt;/a&gt; - .de takes pop at password managers&lt;br/&gt;* &lt;a href=&#34;https://security.opensuse.org/2026/01/16/the-journey-of-auditing-uyuni.html&#34;&gt;https://security.opensuse.org/2026/01/16/the-journey-of-auditing-uyuni.html&lt;/a&gt; - SuSE takes UYUNI for a space walk&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://medium.com/@marcel.rickcen/no-tamper-alert-no-password-and-a-backdoor-root-access-on-a-pos-credit-card-payment-terminal-1ea32c73ca41&#34;&gt;https://medium.com/@marcel.rickcen/no-tamper-alert-no-password-and-a-backdoor-root-access-on-a-pos-credit-card-payment-terminal-1ea32c73ca41&lt;/a&gt; - what a POS&lt;br/&gt;* &lt;a href=&#34;https://neodyme.io/en/blog/drone_hacking_part_1/&#34;&gt;https://neodyme.io/en/blog/drone_hacking_part_1/&lt;/a&gt; - on and on, they drone&lt;br/&gt;* &lt;a href=&#34;https://blog.nns.ee/2026/01/06/aike-ble/&#34;&gt;https://blog.nns.ee/2026/01/06/aike-ble/&lt;/a&gt; - sniffing scooter emissions&lt;br/&gt;* &lt;a href=&#34;https://lucasteske.dev/2025/09/running-code-in-pax-machines&#34;&gt;https://lucasteske.dev/2025/09/running-code-in-pax-machines&lt;/a&gt; - this looks like payback&lt;br/&gt;* &lt;a href=&#34;https://web.archive.org/web/20160128030439/http://www.elemental.net/%7Elf/undoc/&#34;&gt;https://web.archive.org/web/20160128030439/http://www.elemental.net/%7Elf/undoc/&lt;/a&gt; - undocumented Cisco commands&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-by-using-ou-objects&#34;&gt;https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-by-using-ou-objects&lt;/a&gt; - delegation in AD by OU&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://rbanffy.github.io/fun-with-old-mainframes.github.io/fun-with-vm370.html&#34;&gt;https://rbanffy.github.io/fun-with-old-mainframes.github.io/fun-with-vm370.html&lt;/a&gt; - mmm, greenscreen&lt;br/&gt;* &lt;a href=&#34;https://openmail.one/&#34;&gt;https://openmail.one/&lt;/a&gt; - OpenAI lawsuits ahoi!&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-01-22T08:36:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswqtgneg8d6rr20ce6rjuvmhzh4wjk2g9g5euwlydx0nc0q9dumuqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzejetrd</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswqtgneg8d6rr20ce6rjuvmhzh4wjk2g9g5euwlydx0nc0q9dumuqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzejetrd" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://assets.publishing.service.gov.uk/media/69411a3eadb5707d9f33d7e8/E03512978_-_Un-Act_The_National_Security_Act_in_2024_Accessible.pdf&#34;&gt;https://assets.publishing.service.gov.uk/media/69411a3eadb5707d9f33d7e8/E03512978_-_Un-Act_The_National_Security_Act_in_2024_Accessible.pdf&lt;/a&gt; - the UK tries to define what a state threat is (and includes everyone from professional spies to someone who may not even know they pose a risk)&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://csrc.nist.gov/pubs/sp/800/82/r3/final&#34;&gt;https://csrc.nist.gov/pubs/sp/800/82/r3/final&lt;/a&gt; - courtesy of [@Secure_ICS_OT](&lt;a href=&#34;https://infosec.exchange/@Secure_ICS_OT&#34;&gt;https://infosec.exchange/@Secure_ICS_OT&lt;/a&gt; )&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025&#34;&gt;https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025&lt;/a&gt; - MSFT&amp;#39;s take on the landscape&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ip.thc.org/&#34;&gt;https://ip.thc.org/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1a0syl0wxctexh7u3m0ek4ycsuaktwfjnynjrzn9zyjjv4hn0eknqasdmkd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Hacker‘s Choice&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1a0s…dmkd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; don&amp;#39;t do things by half... here&amp;#39;s a very large IP/DNS database&lt;br/&gt;* &lt;a href=&#34;https://www.fortinet.com/blog/threat-research/uncovering-hidden-forensic-evidence-in-windows-mystery-of-autologger&#34;&gt;https://www.fortinet.com/blog/threat-research/uncovering-hidden-forensic-evidence-in-windows-mystery-of-autologger&lt;/a&gt; - Fortinet look at alternate DFIR sources for Windows&lt;br/&gt;* &lt;a href=&#34;https://troopers.de/downloads/troopers19/TROOPERS19_DM_Threat_Modelling_Cisco_ACI.pdf&#34;&gt;https://troopers.de/downloads/troopers19/TROOPERS19_DM_Threat_Modelling_Cisco_ACI.pdf&lt;/a&gt; - surprisingly, I have my own take on ACI, but here&amp;#39;s one from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub185cfy2gz8csr797uk7f0kzf5sn7ffwdez8fmtvut9wxy6gshd0hq5jkem0&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;ERNW&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub185c…kem0&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://kqx.io/post/qemu-nday/&#34;&gt;https://kqx.io/post/qemu-nday/&lt;/a&gt; - popping Qemu like it was 13 years ago&lt;br/&gt;* &lt;a href=&#34;https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc&#34;&gt;https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc&lt;/a&gt; - FreeBSD AV:A oopsie&lt;br/&gt;* &lt;a href=&#34;https://projectzero.google/2025/12/android-itw-dng.html&#34;&gt;https://projectzero.google/2025/12/android-itw-dng.html&lt;/a&gt; - GOOG discuss a nasty image&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://hackers-arise.com/sdr-signals-intelligence-for-hackers-building-a-low-cost-private-4g-lte-network/&#34;&gt;https://hackers-arise.com/sdr-signals-intelligence-for-hackers-building-a-low-cost-private-4g-lte-network/&lt;/a&gt; - ever wanted your own 4G LTE playground?&lt;br/&gt;* &lt;a href=&#34;https://podalirius.net/en/mainframe/as400-forensics-retrieving-your-licence-keys-from-disk-images/&#34;&gt;https://podalirius.net/en/mainframe/as400-forensics-retrieving-your-licence-keys-from-disk-images/&lt;/a&gt; - getting the keys to the museum&lt;br/&gt;* &lt;a href=&#34;https://caido.io/&#34;&gt;https://caido.io/&lt;/a&gt; - another alternative to Burp, with a focus on multi-stage attacks&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/pdf/2512.09882&#34;&gt;https://arxiv.org/pdf/2512.09882&lt;/a&gt; - AI vs flesh face off&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.quarkslab.com/modern-tale-blinkenlights.html&#34;&gt;https://blog.quarkslab.com/modern-tale-blinkenlights.html&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1zhy0x6t4zqspekxg56wg3hh22hsem5ptqgxgsf6gpnk4lfwkhahq2pcve0&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;quarkslab&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1zhy…cve0&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; pays €12 for a good time&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ariadne.space/2025/12/12/rethinking-sudo-with-object-capabilities.html&#34;&gt;https://ariadne.space/2025/12/12/rethinking-sudo-with-object-capabilities.html&lt;/a&gt; - [@ariadne](&lt;a href=&#34;https://social.treehouse.systems/@ariadne&#34;&gt;https://social.treehouse.systems/@ariadne&lt;/a&gt; ) discusses their sudo alternative&lt;br/&gt;* &lt;a href=&#34;https://lpc.events/event/19/contributions/2159/attachments/1833/3929/BpfJailer%20LPC%202025.pdf&#34;&gt;https://lpc.events/event/19/contributions/2159/attachments/1833/3929/BpfJailer%20LPC%202025.pdf&lt;/a&gt; - building jails with eBPF&lt;br/&gt;* &lt;a href=&#34;https://pages.nist.gov/OSCAL/&#34;&gt;https://pages.nist.gov/OSCAL/&lt;/a&gt; - an as-code approach to standardised standards&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-12-18T20:14:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8wf5j895xm57sehw8hysx0lmq223g9j9djry7gu3d2dcpxr6ph6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzpfavgh</id>
    
      <title type="html">Any of the @npub1n4p…t7gf folks on here?</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8wf5j895xm57sehw8hysx0lmq223g9j9djry7gu3d2dcpxr6ph6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzpfavgh" />
    <content type="html">
      Any of the &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1n4pt2ps5a3fhw8jhmngeerxkhmf2t02wdqy657gu8ff2r7r4tsyqa5t7gf&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;OffSec&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1n4p…t7gf&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; folks on here?
    </content>
    <updated>2025-12-18T19:45:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr6a05k235fmj6xsgfjgdh6ys8r24d972p88tsfqt00ws248p5cvczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqrjhgl</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr6a05k235fmj6xsgfjgdh6ys8r24d972p88tsfqt00ws248p5cvczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqrjhgl" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.ofcom.org.uk/siteassets/resources/documents/consultations/7986-cfi-security-resilience/annexes/detica-report.pdf?v=334114&#34;&gt;https://www.ofcom.org.uk/siteassets/resources/documents/consultations/7986-cfi-security-resilience/annexes/detica-report.pdf?v=334114&lt;/a&gt; - the start of OFCOM&amp;#39;s journey to improve telecomms (from 2013)&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far&#34;&gt;https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far&lt;/a&gt; - sometimes it&amp;#39;s okay for NCSC to be deceptive&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/pdf/2512.03641&#34;&gt;https://arxiv.org/pdf/2512.03641&lt;/a&gt; - modelling adversary decisions&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/blog-post/what-makes-a-responsible-cyber-actor&#34;&gt;https://www.ncsc.gov.uk/blog-post/what-makes-a-responsible-cyber-actor&lt;/a&gt; - NCSC discuss responsible threat actors&lt;br/&gt;* &lt;a href=&#34;https://www.interface-eu.org/publications/cyber-red-flags&#34;&gt;https://www.interface-eu.org/publications/cyber-red-flags&lt;/a&gt; - just what makes an irresponsible threat actor&lt;br/&gt;* &lt;a href=&#34;https://www.csis.org/analysis/criteria-cyber-situational-awareness&#34;&gt;https://www.csis.org/analysis/criteria-cyber-situational-awareness&lt;/a&gt; - what does situational awareness mean in cyber&lt;br/&gt;* &lt;a href=&#34;https://www.redteammaturity.com/&#34;&gt;https://www.redteammaturity.com/&lt;/a&gt; - a maturity model for red teams&lt;br/&gt;* &lt;a href=&#34;https://redteam.guide/&#34;&gt;https://redteam.guide/&lt;/a&gt; - a handy guide to red team capability&lt;br/&gt;* &lt;a href=&#34;https://engage.mitre.org/&#34;&gt;https://engage.mitre.org/&lt;/a&gt; - if ATT&amp;amp;CK is operational, where do you start with forward planning your operational capability&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.rfc-editor.org/rfc/rfc6918.html&#34;&gt;https://www.rfc-editor.org/rfc/rfc6918.html&lt;/a&gt; - deprecating the fun bits of ICMP&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://medium.com/@meeswicky1100/unmasking-a-new-dprk-front-company-dredsoftlabs-bf9ed544d690&#34;&gt;https://medium.com/@meeswicky1100/unmasking-a-new-dprk-front-company-dredsoftlabs-bf9ed544d690&lt;/a&gt; - beware of DredSoftLabs, a North Korean enterprise&lt;br/&gt;* &lt;a href=&#34;https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/&#34;&gt;https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/&lt;/a&gt; - CrowdStrikes latest missive on naughty pandas&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://api.gcforum.org/api/files/public/upload/c77233d5-139d-4fbd-a1a4-793a6f29916b_STC-report.pdf&#34;&gt;https://api.gcforum.org/api/files/public/upload/c77233d5-139d-4fbd-a1a4-793a6f29916b_STC-report.pdf&lt;/a&gt; - spotting spoofed callers&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://scrapco.de/&#34;&gt;https://scrapco.de/&lt;/a&gt; - fun projects from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub17wvr8uywpuzew2lqvprnt4g7cuq0kyvdf8gz57dlv3rsjvfcer3qqgnag2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;buherator&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub17wv…nag2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://bl4ckarch.github.io/posts/PrintSpoofer_from_scratch/&#34;&gt;https://bl4ckarch.github.io/posts/PrintSpoofer_from_scratch/&lt;/a&gt; - spoofing the printer&lt;br/&gt;* &lt;a href=&#34;https://zplin.me/papers/GREBE.pdf&#34;&gt;https://zplin.me/papers/GREBE.pdf&lt;/a&gt; - deep dive on Linux kernel bugs and exploitability&lt;br/&gt;* &lt;a href=&#34;https://faith2dxy.xyz/2025-11-28/extending_race_window_fallocate/&#34;&gt;https://faith2dxy.xyz/2025-11-28/extending_race_window_fallocate/&lt;/a&gt; - winning races with the Linux kernel&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ioninja.com/&#34;&gt;https://ioninja.com/&lt;/a&gt; - manipulating protocols at the bits and bytes&lt;br/&gt;* &lt;a href=&#34;https://blog.byteray.co.uk/critical-vulnerabilities-in-rut22gw-industrial-lte-cellular-routers-f4eb8768feb7&#34;&gt;https://blog.byteray.co.uk/critical-vulnerabilities-in-rut22gw-industrial-lte-cellular-routers-f4eb8768feb7&lt;/a&gt; - LTE modems go brrrrrrr&lt;br/&gt;* &lt;a href=&#34;https://mp.weixin.qq.com/s/mfXBJmTuDsE5Y5ufbffkjw?poc_token=HL9bPGmjQcx4HjY2q6nc3pvfsIFWuwnJf-vGJx33&#34;&gt;https://mp.weixin.qq.com/s/mfXBJmTuDsE5Y5ufbffkjw?poc_token=HL9bPGmjQcx4HjY2q6nc3pvfsIFWuwnJf-vGJx33&lt;/a&gt; - attacking the Globalstar uplink&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://oswatcher.github.io/frontend/&#34;&gt;https://oswatcher.github.io/frontend/&lt;/a&gt; - how Windows has changed over time&lt;br/&gt;* &lt;a href=&#34;https://social.coop/@eb/115646613032814668&#34;&gt;https://social.coop/@eb/115646613032814668&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ysjtd466takqccw983trquu5ycwu5gqsk6ydymvlrp2zv0dlphlq8w0ve5&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Evan B🥥ehs&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ysj…0ve5&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s prompt for F/OSS projects&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-12-12T18:27:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsge7qfsdhh8k23stdvkkdmhrpz6v9auperc3kdy2fn39nkuqkhavczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy228qf</id>
    
      <title type="html">Interesting links of the week: In honour of stealth: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsge7qfsdhh8k23stdvkkdmhrpz6v9auperc3kdy2fn39nkuqkhavczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy228qf" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;In honour of stealth:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.thc.org/404/stealth/eulogy.txt&#34;&gt;https://www.thc.org/404/stealth/eulogy.txt&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.hacklore.org/letter&#34;&gt;https://www.hacklore.org/letter&lt;/a&gt; - re-evaluating security myth&lt;br/&gt;* &lt;a href=&#34;https://disclosing.observer/2025/11/24/bulletproof-hoster-anatomy-data-driven-reconstruction.html&#34;&gt;https://disclosing.observer/2025/11/24/bulletproof-hoster-anatomy-data-driven-reconstruction.html&lt;/a&gt; - how bullet proof hosting works&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.greynoise.io/blog/your-ip-address-might-be-someone-elses-problem&#34;&gt;https://www.greynoise.io/blog/your-ip-address-might-be-someone-elses-problem&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;GreyNoise&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lmd…m9t8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss what happens if 127.0.0.1 gets popped &lt;br/&gt;* &lt;a href=&#34;https://blogs.cisco.com/security/cisco-talos-incident-response-threat-hunting-at-govware-2025&#34;&gt;https://blogs.cisco.com/security/cisco-talos-incident-response-threat-hunting-at-govware-2025&lt;/a&gt; - threat hunting at GovWare from one of my old team at &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xkd2rp780746wm90u3nshlvzqfhcyhjw7p08pz0wgdpzl3he8gvqlscc62&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Cisco Talos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xkd…cc62&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://mikecybersec.notion.site/ESXi-IR-Guide-0ffbcec7272244d6b10dba4f4d16a7c8&#34;&gt;https://mikecybersec.notion.site/ESXi-IR-Guide-0ffbcec7272244d6b10dba4f4d16a7c8&lt;/a&gt; - doing IR on ESXi&lt;br/&gt;* &lt;a href=&#34;https://rosesecurity.dev/2024/08/28/homegrown-honeypots.html&#34;&gt;https://rosesecurity.dev/2024/08/28/homegrown-honeypots.html&lt;/a&gt; - mm, honey&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.quarkslab.com/k7-antivirus-named-pipe-abuse-registry-manipulation-and-privilege-escalation.html&#34;&gt;https://blog.quarkslab.com/k7-antivirus-named-pipe-abuse-registry-manipulation-and-privilege-escalation.html&lt;/a&gt; - AV oopsies, don&amp;#39;t you just love them... this time from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1zhy0x6t4zqspekxg56wg3hh22hsem5ptqgxgsf6gpnk4lfwkhahq2pcve0&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;quarkslab&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1zhy…cve0&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/&#34;&gt;https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/&lt;/a&gt; - explanation of the React bug&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://jhalon.github.io/reverse-engineering-protocols/&#34;&gt;https://jhalon.github.io/reverse-engineering-protocols/&lt;/a&gt; - reverse engineering protocols&lt;br/&gt;* &lt;a href=&#34;https://lyra.horse/blog/2025/12/svg-clickjacking/&#34;&gt;https://lyra.horse/blog/2025/12/svg-clickjacking/&lt;/a&gt; - draw me the attack path&lt;br/&gt;* &lt;a href=&#34;https://ayaa101.medium.com/how-i-discovered-1-400-users-pii-through-a-graphql-query-and-uncovered-5-more-bugs-using-the-389d8e7d8deb&#34;&gt;https://ayaa101.medium.com/how-i-discovered-1-400-users-pii-through-a-graphql-query-and-uncovered-5-more-bugs-using-the-389d8e7d8deb&lt;/a&gt; - turns out adversaries also think in graphs&lt;br/&gt;* &lt;a href=&#34;https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable&#34;&gt;https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable&lt;/a&gt; - SQLi into prepared statements&lt;br/&gt;* &lt;a href=&#34;https://phishing.club/blog/covert-red-team-phishing-with-phishing-club/&#34;&gt;https://phishing.club/blog/covert-red-team-phishing-with-phishing-club/&lt;/a&gt; - the first rule of phishing.club is there are no rules (that can&amp;#39;t be bypassed)&lt;br/&gt;* &lt;a href=&#34;https://afine.com/desktop-application-security-standard-introducing-dasvs/&#34;&gt;https://afine.com/desktop-application-security-standard-introducing-dasvs/&lt;/a&gt; - content with fixing all web and mobile vulnerabilities, binary desktop apps enter the spotlight&lt;br/&gt;* &lt;a href=&#34;https://xbz0n.sh/blog/living-off-the-land-windows&#34;&gt;https://xbz0n.sh/blog/living-off-the-land-windows&lt;/a&gt; - avoiding falling out of Windows&lt;br/&gt;* &lt;a href=&#34;https://ipurple.team/2025/12/01/bind-link-edr-tampering/&#34;&gt;https://ipurple.team/2025/12/01/bind-link-edr-tampering/&lt;/a&gt; - a new/old way to avoiding endpoint detection&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://troopers.de/downloads/troopers25/TR25_SBOMs-The-right-way_CBLHDX.pdf&#34;&gt;https://troopers.de/downloads/troopers25/TR25_SBOMs-The-right-way_CBLHDX.pdf&lt;/a&gt; - da SBOM from the &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1duhuqcrrnt77cgtr456pypn4e39zmslgz5e5yt2wel58ypnr05fs568p3x&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;securefirmware&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1duh…8p3x&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; gang&lt;br/&gt;* &lt;a href=&#34;https://xairy.io/articles/pixel-kgdb&#34;&gt;https://xairy.io/articles/pixel-kgdb&lt;/a&gt; - debugging a Pixel with gdb&lt;br/&gt;* &lt;a href=&#34;https://stefan-gloor.ch/pulseoximeter-hack&#34;&gt;https://stefan-gloor.ch/pulseoximeter-hack&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1yhe9s5g0jvzt2hkgrqsccck79pmge9rjlvf7swznf0t55txyk7msn7mhdt&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Stefan Gloor&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1yhe…mhdt&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; patches consumer-grade pulse oximeters&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://lwn.net/SubscriberLink/1046841/5bbf1fc049a18947/&#34;&gt;https://lwn.net/SubscriberLink/1046841/5bbf1fc049a18947/&lt;/a&gt; - making Debian Rusty&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://lolwifi.network/journey&#34;&gt;https://lolwifi.network/journey&lt;/a&gt; - how much do you trust wifi?&lt;br/&gt;* &lt;a href=&#34;https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f076ef44a44d02ed91543f820c14c2c7dff53716&#34;&gt;https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f076ef44a44d02ed91543f820c14c2c7dff53716&lt;/a&gt; - are you sure that&amp;#39;s the right time?&lt;br/&gt;* &lt;a href=&#34;https://mathstodon.xyz/@dougmerritt/115596707083538102&#34;&gt;https://mathstodon.xyz/@dougmerritt/115596707083538102&lt;/a&gt; - the wrong history of languages courtesy of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vlchukd4yknuculh52a5xzq98k4fcndnp4ptnl9jx7gr6j5nqsls06mzqq&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;DougMerritt (log😅 = 💧log😄)&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vlc…mzqq&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://obr.uk/docs/dlm_uploads/01122025-Investigation-into-November-2025-EFO-publication-error.pdf&#34;&gt;https://obr.uk/docs/dlm_uploads/01122025-Investigation-into-November-2025-EFO-publication-error.pdf&lt;/a&gt; - release early, release predictably... UK OBR goes agile&lt;br/&gt;* &lt;a href=&#34;https://monthlyreview.org/articles/why-socialism/&#34;&gt;https://monthlyreview.org/articles/why-socialism/&lt;/a&gt; - Einstein, not just a pretty face&lt;br/&gt;* &lt;a href=&#34;https://netpol.org/2025/11/28/government-plans-new-powers-to-label-dissenting-movements-as-subversion/&#34;&gt;https://netpol.org/2025/11/28/government-plans-new-powers-to-label-dissenting-movements-as-subversion/&lt;/a&gt; - kinda wonder what happens if you dissent?&lt;br/&gt;* &lt;a href=&#34;https://replaceyourboss.ai/&#34;&gt;https://replaceyourboss.ai/&lt;/a&gt; - replace your boss, slopify your strategy&lt;br/&gt;&lt;br/&gt;#security, #research&lt;br/&gt;nostr:note1afu4r7r78zwn470nlat4n0kalhwrvyfv0f35wn38paw39d6tptaqx8w30t&lt;br/&gt;
    </content>
    <updated>2025-12-05T22:09:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsta2yfk0utgzhpa5rctw8n07clpq0r38pjkqp626xu2f87uxtlvpqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzye2xfk</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsta2yfk0utgzhpa5rctw8n07clpq0r38pjkqp626xu2f87uxtlvpqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzye2xfk" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://wero-wallet.eu/&#34;&gt;https://wero-wallet.eu/&lt;/a&gt; - a European replacement for PayPal, Google and Apple&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://the-sequence.com/rustypages-malware-part-i&#34;&gt;https://the-sequence.com/rustypages-malware-part-i&lt;/a&gt; - some nice new shiney malware for OS X&lt;br/&gt;* &lt;a href=&#34;https://www.crowdstrike.com/en-us/blog/murky-panda-trusted-relationship-threat-in-cloud/&#34;&gt;https://www.crowdstrike.com/en-us/blog/murky-panda-trusted-relationship-threat-in-cloud/&lt;/a&gt; - don&amp;#39;t you just hate being poked with bamboo?&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://camel-security.github.io/&#34;&gt;https://camel-security.github.io/&lt;/a&gt; - LLM guard rails from GOOG&lt;br/&gt;* &lt;a href=&#34;https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1#enabling-script-block-logging&#34;&gt;https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging?view=powershell-5.1#enabling-script-block-logging&lt;/a&gt; - MSFT&amp;#39;s protected logging feature for PS&lt;br/&gt;* &lt;a href=&#34;https://adsecurity.org/?p=4510&#34;&gt;https://adsecurity.org/?p=4510&lt;/a&gt; - mm, honey&lt;br/&gt;* &lt;a href=&#34;https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/&#34;&gt;https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/&lt;/a&gt; - preventing domain resurrections in PyPI&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.heise.de/en/news/Docker-Desktop-Critical-vulnerability-allows-host-access-10560707.html&#34;&gt;https://www.heise.de/en/news/Docker-Desktop-Critical-vulnerability-allows-host-access-10560707.html&lt;/a&gt; - attackers may no longer be contained&lt;br/&gt;&lt;a href=&#34;https://bughunters.google.com/blog/5800341475819520/a-fuzzy-escape-a-tale-of-vulnerability-research-on-hypervisors&#34;&gt;https://bughunters.google.com/blog/5800341475819520/a-fuzzy-escape-a-tale-of-vulnerability-research-on-hypervisors&lt;/a&gt; - I hate being supervised, do you?&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2507.09411&#34;&gt;https://arxiv.org/abs/2507.09411&lt;/a&gt; - feasibility of generating variant malware using LLMs&lt;br/&gt;* &lt;a href=&#34;https://phrack.org/issues/72/5_md#article&#34;&gt;https://phrack.org/issues/72/5_md#article&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1am3w48p7rdt932pdgq4wkskl8rvqvfxzxx8xjy7h65rrsr9kxvusyuj6qn&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Phrack&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1am3…j6qn&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; #72 lands and it&amp;#39;s a goodie... aforementioned link is to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ypsx5l9k8hkdczuwst8ndag0wz09k6mrxnnknsj9en7dqxlvelcsvd97w6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Orange Tsai&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1yps…97w6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s work on PHP&lt;br/&gt;* &lt;a href=&#34;https://versprite.com/blog/the-shell-was-restricted-but-the-kernel-memory-was-wide-open/&#34;&gt;https://versprite.com/blog/the-shell-was-restricted-but-the-kernel-memory-was-wide-open/&lt;/a&gt; - attacking Linux-based firmware for LPE via the kernel&lt;br/&gt;* &lt;a href=&#34;https://blog.anh4ckin.ch/posts/netexec-workshop2k25/&#34;&gt;https://blog.anh4ckin.ch/posts/netexec-workshop2k25/&lt;/a&gt; - nosing around an AD lab&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-08-22T00:31:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgskumd6sq98nqn0p36q9cer8d5fz4zs04du5cnj2xgk2zzmww4gczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxpsq54</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgskumd6sq98nqn0p36q9cer8d5fz4zs04du5cnj2xgk2zzmww4gczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxpsq54" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat&#34;&gt;https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat&lt;/a&gt; - NCSC CAF 4.0 drops&lt;br/&gt;* &lt;a href=&#34;https://cfp.bsides.london/bsides-london-2025/cfp&#34;&gt;https://cfp.bsides.london/bsides-london-2025/cfp&lt;/a&gt; - BSides London CFP is open&lt;br/&gt;* &lt;a href=&#34;https://data-media.s3.us-east-1.amazonaws.com/assets/CISOs&#43;guide&#43;to&#43;SAP&#43;Security.pdf&#34;&gt;https://data-media.s3.us-east-1.amazonaws.com/assets/CISOs&#43;guide&#43;to&#43;SAP&#43;Security.pdf&lt;/a&gt; - a CISO view on SAP&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/&#34;&gt;https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/&lt;/a&gt; - PA give their thoughts on telco intrusions&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://medium.com/anton-on-security/soc-visibility-triad-is-now-a-quad-soc-visibility-quad-2025-72811401073a&#34;&gt;https://medium.com/anton-on-security/soc-visibility-triad-is-now-a-quad-soc-visibility-quad-2025-72811401073a&lt;/a&gt; - [@anton_chuvakin](&lt;a href=&#34;https://infosec.exchange/@anton_chuvakin&#34;&gt;https://infosec.exchange/@anton_chuvakin&lt;/a&gt; )&amp;#39;s take on what comes next in SOCs... is it AI or is it fuck?&lt;br/&gt;* &lt;a href=&#34;https://www.greynoise.io/resources/early-warning-signals-attacker-behavior-precedes-new-vulnerabilities&#34;&gt;https://www.greynoise.io/resources/early-warning-signals-attacker-behavior-precedes-new-vulnerabilities&lt;/a&gt; - what to look for as new bugs rain down...&lt;br/&gt;* &lt;a href=&#34;https://bakerstreetforensics.com/2025/08/02/enhance-threat-hunting-with-mitre-lookup-in-malchela-3-0-2/&#34;&gt;https://bakerstreetforensics.com/2025/08/02/enhance-threat-hunting-with-mitre-lookup-in-malchela-3-0-2/&lt;/a&gt; - neat &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h8wq6pmwwcxphdckcnm72unypz4u9u8p6vztg4ny07l8qpzawk0q2jvyt6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;MITRE ATT&amp;CK&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h8w…vyt6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; integration&lt;br/&gt;* &lt;a href=&#34;https://www.totes-legit-notmalware.site/home/detection-exercise-d-link-dir-513-cves-2025-8184-8169-and-8168&#34;&gt;https://www.totes-legit-notmalware.site/home/detection-exercise-d-link-dir-513-cves-2025-8184-8169-and-8168&lt;/a&gt; - [@da_667](&lt;a href=&#34;https://infosec.exchange/@da_667&#34;&gt;https://infosec.exchange/@da_667&lt;/a&gt; ) talks IDS detections&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://specterops.io/blog/2025/07/29/bloodhound-v8-usability-extensibility-and-opengraph/&#34;&gt;https://specterops.io/blog/2025/07/29/bloodhound-v8-usability-extensibility-and-opengraph/&lt;/a&gt; - new dog, who dis?&lt;br/&gt;* &lt;a href=&#34;https://www.incendium.rocks/posts/Exploit-Development-For-MSRPC/&#34;&gt;https://www.incendium.rocks/posts/Exploit-Development-For-MSRPC/&lt;/a&gt; - developing exploits for Microsoft RPC&lt;br/&gt;* &lt;a href=&#34;https://blog.trailofbits.com/2025/07/25/exploiting-zero-days-in-abandoned-hardware/&#34;&gt;https://blog.trailofbits.com/2025/07/25/exploiting-zero-days-in-abandoned-hardware/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1rcsevfzqfj6xzk0rajfaftsnq4f4wewydfyxd9u46jch4sxta60qjz7sw8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Trail of Bits&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1rcs…7sw8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; exploit some 0lddays&lt;br/&gt;* &lt;a href=&#34;https://secret.club/2022/08/29/bootkitting-windows-sandbox.html&#34;&gt;https://secret.club/2022/08/29/bootkitting-windows-sandbox.html&lt;/a&gt; - breaking the Windows sandbox&lt;br/&gt;* &lt;a href=&#34;https://blogs.cisco.com/security/extracting-training-data-from-chatbots&#34;&gt;https://blogs.cisco.com/security/extracting-training-data-from-chatbots&lt;/a&gt; - another way to fuck with LLMs&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://lwn.net/Articles/1030669/&#34;&gt;https://lwn.net/Articles/1030669/&lt;/a&gt; - how security patches land in Debian&lt;br/&gt;&lt;br/&gt;Development:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://metacpan.org/dist/MCP&#34;&gt;https://metacpan.org/dist/MCP&lt;/a&gt; - MCP in Perl&lt;br/&gt;* &lt;a href=&#34;https://20455591.fs1.hubspotusercontent-na1.net/hubfs/20455591/Website%20Assets/Secure%20Coding%20Guideline%20en%20BASE24%20.pdf&#34;&gt;https://20455591.fs1.hubspotusercontent-na1.net/hubfs/20455591/Website%20Assets/Secure%20Coding%20Guideline%20en%20BASE24%20.pdf&lt;/a&gt; - writing secure Base24 code&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.e-resident.gov.ee/uk-hub-digital-residency-setup/&#34;&gt;https://www.e-resident.gov.ee/uk-hub-digital-residency-setup/&lt;/a&gt; - become a virtual Estonian&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-08-08T10:10:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszwv8z9v9h449pfw2ml2j8r2xytxpalphzfxjhwk04m6hgnla4qggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu24hy4</id>
    
      <title type="html">Genie: You have 3 wishes Me: Can I just have -1 wish? Genie: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszwv8z9v9h449pfw2ml2j8r2xytxpalphzfxjhwk04m6hgnla4qggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu24hy4" />
    <content type="html">
      Genie: You have 3 wishes&lt;br/&gt;Me: Can I just have -1 wish?&lt;br/&gt;Genie: Okay, you have 4294967295L wishes&lt;br/&gt;&lt;br/&gt;#microfiction
    </content>
    <updated>2025-08-01T23:56:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0wuchk8wl2tycudwq656s6hhmu9q336u9qhnuhhgv4rrkz3kaerszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjn9zlk</id>
    
      <title type="html">Related: If you want to tell me you&amp;#39;ve jailbroken the AI, you ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0wuchk8wl2tycudwq656s6hhmu9q336u9qhnuhhgv4rrkz3kaerszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjn9zlk" />
    <content type="html">
      Related: If you want to tell me you&amp;#39;ve jailbroken the AI, you better be prepared to tell me how you reverse engineered the ETL, data model and guard rails, not how you clicked on the shiny, shiny and got a shell prompt.
    </content>
    <updated>2025-08-01T10:09:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgkv0sqdewxe4a9fl2fsfh6dxrqpydwhqcu0p77m2juhe32stcluqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzslthwk</id>
    
      <title type="html">Wish there was an easy way to migrate MFA tokens from the various ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgkv0sqdewxe4a9fl2fsfh6dxrqpydwhqcu0p77m2juhe32stcluqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzslthwk" />
    <content type="html">
      Wish there was an easy way to migrate MFA tokens from the various OTP apps to cold storage.
    </content>
    <updated>2025-07-26T09:35:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxj32kgfhff9tgsmf7tg7shs69r9nl46cjn069t5uje3mfqj7uhwszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn3nwfd</id>
    
      <title type="html">A Microsoft ouchy on a Saturday, oh my: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxj32kgfhff9tgsmf7tg7shs69r9nl46cjn069t5uje3mfqj7uhwszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn3nwfd" />
    <content type="html">
      A Microsoft ouchy on a Saturday, oh my:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/&#34;&gt;https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Active exploitation already happening...&lt;br/&gt;&lt;br/&gt;#sharepoint, #threatintel
    </content>
    <updated>2025-07-20T06:43:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspavsa4cjd8dml5j0m0r5yce3pnx5yd4c4warws50yu7u4sdkd4lqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz0dxqlw</id>
    
      <title type="html">Interesting Git repos of the week: Detection: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspavsa4cjd8dml5j0m0r5yce3pnx5yd4c4warws50yu7u4sdkd4lqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz0dxqlw" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/telekom-security/tpotce&#34;&gt;https://github.com/telekom-security/tpotce&lt;/a&gt; - have some honey&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/tlsfuzzer/tlsfuzzer&#34;&gt;https://github.com/tlsfuzzer/tlsfuzzer&lt;/a&gt; - fuzz TLS&lt;br/&gt;* &lt;a href=&#34;https://github.com/ShawnDEvans/smbmap&#34;&gt;https://github.com/ShawnDEvans/smbmap&lt;/a&gt; - map SMB shares&lt;br/&gt;* &lt;a href=&#34;https://github.com/nccgroup/fuzzowski&#34;&gt;https://github.com/nccgroup/fuzzowski&lt;/a&gt; - another nice fuzzer&lt;br/&gt;&lt;br/&gt;Data:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/sneakers-the-rat/gpu-free-ai&#34;&gt;https://github.com/sneakers-the-rat/gpu-free-ai&lt;/a&gt; - the AI implementation you don&amp;#39;t want to use!&lt;br/&gt;&lt;br/&gt;#code, #security, #research
    </content>
    <updated>2025-07-12T09:51:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsythvzvxagvre7qvckcrdadypnqk4999hvhfpramlxncguk293efczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlrsr0e</id>
    
      <title type="html">Interesting Git repos of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsythvzvxagvre7qvckcrdadypnqk4999hvhfpramlxncguk293efczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlrsr0e" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/timb-machine/security-research-governance-toolkit&#34;&gt;https://github.com/timb-machine/security-research-governance-toolkit&lt;/a&gt; - I started releasing Portcullis&amp;#39; old security research governance toolkit&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/sandflysecurity/sandfly-forensic-scripts&#34;&gt;https://github.com/sandflysecurity/sandfly-forensic-scripts&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1n7jhrzx2fq2vtwsu72c4e0yphq0h2uaq6y99z04kc299mpv3j9fsmtd4nw&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Sandfly Security&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1n7j…d4nw&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; have release scripts for collecting Linux artefacts&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/stealth/injectso&#34;&gt;https://github.com/stealth/injectso&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub17peuslentk2n6ra5w6hp33wlx066remxqgg07l5nnnhascj635fsdv7sl2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Ike Broflovski&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub17pe…7sl2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; demonstrates how to inject .so files into running processes at will&lt;br/&gt;* &lt;a href=&#34;https://github.com/NeffIsBack/wsuks&#34;&gt;https://github.com/NeffIsBack/wsuks&lt;/a&gt; - have you ever wanted to MITM WSUS?&lt;br/&gt;&lt;br/&gt;Data:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/public-api-lists/public-api-lists&#34;&gt;https://github.com/public-api-lists/public-api-lists&lt;/a&gt; - does what it says on the tin&lt;br/&gt;&lt;br/&gt;Development:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/sapdragon/syscalls-cpp&#34;&gt;https://github.com/sapdragon/syscalls-cpp&lt;/a&gt; - headers for direct syscall invocation&lt;br/&gt;&lt;br/&gt;#security, #research, #code
    </content>
    <updated>2025-06-27T07:03:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs277q6j3n8nw9mxg2knwnud4fc6wv3t66m7kkpfc8k9ayr4vf8txczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzm3lxm6</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs277q6j3n8nw9mxg2knwnud4fc6wv3t66m7kkpfc8k9ayr4vf8txczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzm3lxm6" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.enisa.europa.eu/publications/the-eu-cybersecurity-index-2024&#34;&gt;https://www.enisa.europa.eu/publications/the-eu-cybersecurity-index-2024&lt;/a&gt; - EU&amp;#39;s 2024 cyber security index&lt;br/&gt;* &lt;a href=&#34;https://assets.publishing.service.gov.uk/media/67cad8b18c1076c796a45c25/Cyber_Security_Sectoral_Analysis_Report_2025.pdf&#34;&gt;https://assets.publishing.service.gov.uk/media/67cad8b18c1076c796a45c25/Cyber_Security_Sectoral_Analysis_Report_2025.pdf&lt;/a&gt; - HMG cyber security sectoral analysis 2025&lt;br/&gt;* &lt;a href=&#34;https://www.nao.org.uk/wp-content/uploads/2025/01/government-cyber-resilience.pdf&#34;&gt;https://www.nao.org.uk/wp-content/uploads/2025/01/government-cyber-resilience.pdf&lt;/a&gt; - NAO paper on making UK more resilient&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/collection/security-principles-protecting-most-sensitive-personal-information-in-datasets&#34;&gt;https://www.ncsc.gov.uk/collection/security-principles-protecting-most-sensitive-personal-information-in-datasets&lt;/a&gt; - NCSC ideas on protecting data&lt;br/&gt;* &lt;a href=&#34;https://www.wired.com/story/how-to-protest-safely-surveillance-digital-privacy/&#34;&gt;https://www.wired.com/story/how-to-protest-safely-surveillance-digital-privacy/&lt;/a&gt; - protest early, protest safely, protest often&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/umbrella-stand/ncsc-mar-umbrella_stand.pdf&#34;&gt;https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/umbrella-stand/ncsc-mar-umbrella_stand.pdf&lt;/a&gt; - NCSC exposes UMBRELLA STAND&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/shoe-rack-tipper/ncsc-tip-shoe_rack.pdf&#34;&gt;https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/shoe-rack-tipper/ncsc-tip-shoe_rack.pdf&lt;/a&gt; - ... and SHOE RACK&lt;br/&gt;* &lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia&lt;/a&gt; - GOOG reports on how Russia is targetting academics&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://sud0ru.ghost.io/windows-inter-process-communication-a-deep-dive-beyond-the-surface-part-4/&#34;&gt;https://sud0ru.ghost.io/windows-inter-process-communication-a-deep-dive-beyond-the-surface-part-4/&lt;/a&gt; - a nice set of posts on Windows IPC&amp;#39;s attack surface&lt;br/&gt;* &lt;a href=&#34;https://eprint.iacr.org/2025/1042&#34;&gt;https://eprint.iacr.org/2025/1042&lt;/a&gt; - whacking Falcons with a hammer&lt;br/&gt;* &lt;a href=&#34;https://forums.oracle.com/ords/r/apexds/community/q?question=interpositioning-in-java-2701&#34;&gt;https://forums.oracle.com/ords/r/apexds/community/q?question=interpositioning-in-java-2701&lt;/a&gt; - had your caffeine? seamlessly injecting into Java&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://skemman.is/handle/1946/50456&#34;&gt;https://skemman.is/handle/1946/50456&lt;/a&gt; - emulating icey routers&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C&#43;&#43;.html&#34;&gt;https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C&#43;&#43;.html&lt;/a&gt; - calling cc safely&lt;br/&gt;* &lt;a href=&#34;https://spiffe.io/docs/latest/spiffe-about/community-presentations/&#34;&gt;https://spiffe.io/docs/latest/spiffe-about/community-presentations/&lt;/a&gt; - better authentication primitives for bots&lt;br/&gt;* &lt;a href=&#34;https://workos.com/blog/mcp-authorization-in-5-easy-oauth-specs&#34;&gt;https://workos.com/blog/mcp-authorization-in-5-easy-oauth-specs&lt;/a&gt; - bring OAuth to MCP&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.metoffice.gov.uk/forms/name-our-storms-call-for-names&#34;&gt;https://www.metoffice.gov.uk/forms/name-our-storms-call-for-names&lt;/a&gt; - so you want to work in marketing for storms&lt;br/&gt;* &lt;a href=&#34;https://activitypub.academy&#34;&gt;https://activitypub.academy&lt;/a&gt; - so you want to learn about how the Fediverse works?&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-06-26T21:12:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdwhk4z6k0tp63em6nc6jyx4ejht70ysrvef6l8js674tltu67ssszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt7zhk7</id>
    
      <title type="html">Submitted my first bug via GitHub&amp;#39;s advisory reporting ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdwhk4z6k0tp63em6nc6jyx4ejht70ysrvef6l8js674tltu67ssszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt7zhk7" />
    <content type="html">
      Submitted my first bug via GitHub&amp;#39;s advisory reporting mechanism for hosted projects (I know, right!?!?). Much less painful than the traditional hunt the email address/chase the vendor so far.
    </content>
    <updated>2025-06-13T13:11:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxchvdlce7ppmsfh9q2tqmjspmrdl4ez86wa9xfkc0zhg58aszevgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvh4yc9</id>
    
      <title type="html">Sad times, John Young of Cryptome is no longer with us: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxchvdlce7ppmsfh9q2tqmjspmrdl4ez86wa9xfkc0zhg58aszevgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvh4yc9" />
    <content type="html">
      Sad times, John Young of Cryptome is no longer with us:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.theregister.com/2025/05/24/john_young_obituary/&#34;&gt;https://www.theregister.com/2025/05/24/john_young_obituary/&lt;/a&gt;
    </content>
    <updated>2025-05-25T18:00:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf9544kwp9v245pfm3yrwkpa8nn7qee43y7ne943xcmn5xd23jhsqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgettgh</id>
    
      <title type="html">Interesting Git repos of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf9544kwp9v245pfm3yrwkpa8nn7qee43y7ne943xcmn5xd23jhsqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgettgh" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/TalEliyahu/awesome-CISO-maturity-models&#34;&gt;https://github.com/TalEliyahu/awesome-CISO-maturity-models&lt;/a&gt; - modelling your strategy&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/yevh/TaaC-AI&#34;&gt;https://github.com/yevh/TaaC-AI&lt;/a&gt; - threat modelling as code&lt;br/&gt;* &lt;a href=&#34;https://github.com/thalesgroup-cert/Watcher&#34;&gt;https://github.com/thalesgroup-cert/Watcher&lt;/a&gt; - build your own threat hunting platform with Thales&lt;br/&gt;* &lt;a href=&#34;https://github.com/microsoft/msticpy&#34;&gt;https://github.com/microsoft/msticpy&lt;/a&gt; - Microsoft&amp;#39;s TI tooling&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/specfy/stack-analyser&#34;&gt;https://github.com/specfy/stack-analyser&lt;/a&gt; - what&amp;#39;s in the stack?&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/nistorj/ISR1000&#34;&gt;https://github.com/nistorj/ISR1000&lt;/a&gt;  - guestshell on the ISR1000&lt;br/&gt;&lt;br/&gt;#security, #research, #code
    </content>
    <updated>2025-05-02T07:34:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswvslp4vnk2mykp2j3vexlkqlk2qky7yrhgrt9c80f8cwsh2tn4fczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjuk7mn</id>
    
      <title type="html">That SAP NetWeaver bug is pretty ouchy: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswvslp4vnk2mykp2j3vexlkqlk2qky7yrhgrt9c80f8cwsh2tn4fczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjuk7mn" />
    <content type="html">
      That SAP NetWeaver bug is pretty ouchy:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/gothburz/status/1915755189019017411&#34;&gt;https://x.com/gothburz/status/1915755189019017411&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#sap, #threatintel
    </content>
    <updated>2025-04-27T20:56:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszt5fv5qqr7t4ky4kku3v5ctxj6345tf3as8lwyq5v28d0xhrayvgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvkqxnm</id>
    
      <title type="html">Kinda want a DirBuster style list of headers at this point, so ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszt5fv5qqr7t4ky4kku3v5ctxj6345tf3as8lwyq5v28d0xhrayvgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvkqxnm" />
    <content type="html">
      Kinda want a DirBuster style list of headers at this point, so many times, we see new CVEs stemming from headers with magical properties.
    </content>
    <updated>2025-04-24T09:37:02Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswu40fd9zqj523ky4n4h6x5w9k5pjhkdedh6lexhtptujvktssx7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzkku6mm</id>
    
      <title type="html">Another header bypass, this time a Citrix NetScaler nasty: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswu40fd9zqj523ky4n4h6x5w9k5pjhkdedh6lexhtptujvktssx7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzkku6mm" />
    <content type="html">
      Another header bypass, this time a Citrix NetScaler nasty:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://attackerkb.com/topics/7zebEgmGLs/cve-2024-6235&#34;&gt;https://attackerkb.com/topics/7zebEgmGLs/cve-2024-6235&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #netscaler
    </content>
    <updated>2025-04-24T09:35:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0q5asl87x0e7jztp2yrc20g7m3jnehgvn6hzd2xkmzlwtq2p0wmqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlsc4pz</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0q5asl87x0e7jztp2yrc20g7m3jnehgvn6hzd2xkmzlwtq2p0wmqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlsc4pz" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://en.wikipedia.org/wiki/SIPOC&#34;&gt;https://en.wikipedia.org/wiki/SIPOC&lt;/a&gt; - modelling systems with SIPIC&lt;br/&gt;* &lt;a href=&#34;https://www.thecvefoundation.org/&#34;&gt;https://www.thecvefoundation.org/&lt;/a&gt; - the CVE foundation&lt;br/&gt;* &lt;a href=&#34;https://euvd.enisa.europa.eu/&#34;&gt;https://euvd.enisa.europa.eu/&lt;/a&gt; - EU bug jail&lt;br/&gt;* &lt;a href=&#34;https://xntrik.wtf/aisa2024/&#34;&gt;https://xntrik.wtf/aisa2024/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1gtckj0g99wa9v75slq544t640fn3kxdn30mxms22yrqe6krn774snsm0r6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;xntrik&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1gtc…m0r6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; maps threats with &lt;a href=&#34;https://threatcl.github.io/&#34;&gt;https://threatcl.github.io/&lt;/a&gt;&lt;br/&gt;* &lt;a href=&#34;https://threatspec.org/&#34;&gt;https://threatspec.org/&lt;/a&gt; - the ThreatSpec&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol&lt;/a&gt; - a novel phishing attack involving RDP&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://rulehound.com/rules&#34;&gt;https://rulehound.com/rules&lt;/a&gt; - a single place to find interesting detection engineering ideas&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://bugs.chromium.org/p/chromium/issues/detail?id=584535&#34;&gt;https://bugs.chromium.org/p/chromium/issues/detail?id=584535&lt;/a&gt; - an 11 year old bug in every browser, still not dead!&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://silentsignal.github.io/BelowMI/&#34;&gt;https://silentsignal.github.io/BelowMI/&lt;/a&gt; - memory management on System i courtesy of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub17wvr8uywpuzew2lqvprnt4g7cuq0kyvdf8gz57dlv3rsjvfcer3qqgnag2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;buherator&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub17wv…nag2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/N1ckDunn/SOSLInjection/blob/main/SOSLInjection.pdf&#34;&gt;https://github.com/N1ckDunn/SOSLInjection/blob/main/SOSLInjection.pdf&lt;/a&gt; - Sal&amp;#39;&amp;#39;esforce \o/&lt;br/&gt;* &lt;a href=&#34;https://github.com/N1ckDunn/DoubleFetch/blob/main/Double-FetchVulnerabilitiesInC.pdf&#34;&gt;https://github.com/N1ckDunn/DoubleFetch/blob/main/Double-FetchVulnerabilitiesInC.pdf&lt;/a&gt; - exploiting double fetch&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://xairy.io/articles/thinkpad-xdci&#34;&gt;https://xairy.io/articles/thinkpad-xdci&lt;/a&gt; - emulating USB on a ThinkPad&lt;br/&gt;* &lt;a href=&#34;https://www.rtl-sdr.com/dragonos-lte-imsi-sniffing-using-the-lte-sniffer-tool-and-an-ettus-x310-sdr/&#34;&gt;https://www.rtl-sdr.com/dragonos-lte-imsi-sniffing-using-the-lte-sniffer-tool-and-an-ettus-x310-sdr/&lt;/a&gt; - build your own LTE sniffer&lt;br/&gt;* &lt;a href=&#34;https://blog.sesse.net/blog/tech/2025-04-05-10-57_cisco_2504_password_extraction.html&#34;&gt;https://blog.sesse.net/blog/tech/2025-04-05-10-57_cisco_2504_password_extraction.html&lt;/a&gt; - extracting passwords from Cisco WLC&lt;br/&gt;* &lt;a href=&#34;https://www.prizmlabs.io/post/remote-rootkits-uncovering-a-0-click-rce-in-the-supernote-nomad-e-ink-tablet&#34;&gt;https://www.prizmlabs.io/post/remote-rootkits-uncovering-a-0-click-rce-in-the-supernote-nomad-e-ink-tablet&lt;/a&gt; - exploiting the Nomad e-ink tablet&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ukparliament.github.io/ontologies/meta/bots/&#34;&gt;https://ukparliament.github.io/ontologies/meta/bots/&lt;/a&gt; - UK parliamentary bots&lt;br/&gt;* &lt;a href=&#34;https://mwl.io/fiction/crime&#34;&gt;https://mwl.io/fiction/crime&lt;/a&gt; - Git drives people to murder&lt;br/&gt;* &lt;a href=&#34;https://changelog.complete.org/archives/10768-announcing-the-nncpnet-email-network&#34;&gt;https://changelog.complete.org/archives/10768-announcing-the-nncpnet-email-network&lt;/a&gt; - building a new mail protocol&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-04-17T18:21:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0gljdrpyum4j5mp3a4e7se3nlsqknhsnfeuf0s92u3kvdc8rs2dgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx7m745</id>
    
      <title type="html">My cross-platform and cross-browser NTLM bug is public: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0gljdrpyum4j5mp3a4e7se3nlsqknhsnfeuf0s92u3kvdc8rs2dgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx7m745" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd2p4lcjxc07p04ju3njf0p6f0u28tt0x5l2twayj6da3jn4ypjasl8fvg9&#39;&gt;nevent1q…fvg9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;My cross-platform and cross-browser NTLM bug is public:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://issues.chromium.org/issues/40080133&#34;&gt;https://issues.chromium.org/issues/40080133&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Kudos to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub19m6w3hsy7ndzf74p00dphjfw9g4yavmdy5fyv8tek2edfyf2xwhsdl6gg2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Bitquark&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub19m6…6gg2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; who reported it separately.&lt;br/&gt;&lt;br/&gt;Kudos also to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vwvtra8vq0zy7wtd9mzhz2xfyzq4r5nae5tzfffhzfg76tz0ml3qsacqgs&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Tor Project&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vwv…cqgs&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; and &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub16pr8sa8trydwfwpgwd27wqde3t5d36wghcmpc2yrvxyt8pu8wvjq2qcrsg&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Mozilla&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub16pr…crsg&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; who did make efforts.&lt;br/&gt;&lt;br/&gt;#security, #wontfix, #threatintel, #browserbug
    </content>
    <updated>2025-04-17T12:47:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9zhv6azpaug9qnn8hat940jmzh7jhwwh300t5k0tsr5368jcsmrqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlpr0gj</id>
    
      <title type="html">Released a new tool, packet-monkey: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9zhv6azpaug9qnn8hat940jmzh7jhwwh300t5k0tsr5368jcsmrqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzlpr0gj" />
    <content type="html">
      Released a new tool, packet-monkey:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/timb-machine/packet-monkey&#34;&gt;https://github.com/timb-machine/packet-monkey&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Packet Monkey is a tool to filter and classify PCAPs using Wireshark filters. I use it for layer 2/3 traffic analysis on engagements.&lt;br/&gt;&lt;br/&gt;#tool, #code, #packetcapture, #trafficanalysis, #wireshark
    </content>
    <updated>2025-03-29T10:05:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr68tqsnp7xjfgk8yly0hagkzkhhvdhek6qgz3gyfcurt5lgus05gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzghdj0e</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr68tqsnp7xjfgk8yly0hagkzkhhvdhek6qgz3gyfcurt5lgus05gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzghdj0e" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://rusi.org/explore-our-research/publications/commentary/typhoons-cyberspace&#34;&gt;https://rusi.org/explore-our-research/publications/commentary/typhoons-cyberspace&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1g3n880pkf7e0vd3urgjyfh8qptyphelrx00awreqka64fjdclmts43kzaf&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Ciaran Martin&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1g3n…kzaf&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; talks .cn&lt;br/&gt;* &lt;a href=&#34;https://www.mitre.org/sites/default/files/2022-04/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf&#34;&gt;https://www.mitre.org/sites/default/files/2022-04/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf&lt;/a&gt; - building a world class SOC with MITRE&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/whitepaper/security-architecture-anti-patterns&#34;&gt;https://www.ncsc.gov.uk/whitepaper/security-architecture-anti-patterns&lt;/a&gt; - architectural booboos&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.mdsec.co.uk/2025/03/red-teaming-with-servicenow/&#34;&gt;https://www.mdsec.co.uk/2025/03/red-teaming-with-servicenow/&lt;/a&gt; - red teaming SNow&lt;br/&gt;* &lt;a href=&#34;https://posts.specterops.io/mapping-snowflakes-access-landscape-3bf232251945&#34;&gt;https://posts.specterops.io/mapping-snowflakes-access-landscape-3bf232251945&lt;/a&gt; - mapping Snowflake&lt;br/&gt;* &lt;a href=&#34;https://www.dragos.com/wp-content/uploads/2025/03/Dragos_Littleton_Electric_Water_CaseStudy.pdf&#34;&gt;https://www.dragos.com/wp-content/uploads/2025/03/Dragos_Littleton_Electric_Water_CaseStudy.pdf&lt;/a&gt; - a small case study on how .cn got into your water&lt;br/&gt;* &lt;a href=&#34;https://supportportal.juniper.net/s/article/2025-03-Reference-Advisory-The-RedPenguin-Malware-Incident?language=en_US&#34;&gt;https://supportportal.juniper.net/s/article/2025-03-Reference-Advisory-The-RedPenguin-Malware-Incident?language=en_US&lt;/a&gt; - and a larger case study on how they got into Juniper devices&lt;br/&gt;* &lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers&lt;/a&gt; - more on Juniper from Mandiant&lt;br/&gt;* &lt;a href=&#34;https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/&#34;&gt;https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xkd2rp780746wm90u3nshlvzqfhcyhjw7p08pz0wgdpzl3he8gvqlscc62&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Cisco Talos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xkd…cc62&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; gives us the run down on how .cn got into Cisco devices too&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://mr-r3b00t.github.io/crime-mapper/&#34;&gt;https://mr-r3b00t.github.io/crime-mapper/&lt;/a&gt; - reimagining graphs with [@UK_Daniel_Card](&lt;a href=&#34;https://infosec.exchange/@UK_Daniel_Card&#34;&gt;https://infosec.exchange/@UK_Daniel_Card&lt;/a&gt; )&lt;br/&gt;* &lt;a href=&#34;https://tinyhack.com/2025/03/13/decrypting-encrypted-files-from-akira-ransomware-linux-esxi-variant-2024-using-a-bunch-of-gpus/&#34;&gt;https://tinyhack.com/2025/03/13/decrypting-encrypted-files-from-akira-ransomware-linux-esxi-variant-2024-using-a-bunch-of-gpus/&lt;/a&gt; - decrypting Akira&lt;br/&gt;* &lt;a href=&#34;https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised&#34;&gt;https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised&lt;/a&gt; - another bugdoor in the supply chain&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.includesecurity.com/2025/03/memory-corruption-in-delphi/&#34;&gt;https://blog.includesecurity.com/2025/03/memory-corruption-in-delphi/&lt;/a&gt; - memory corruption in memory safe languages&lt;br/&gt;* &lt;a href=&#34;https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html&#34;&gt;https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html&lt;/a&gt; - shedding light on the the recent TomCat bug&lt;br/&gt;* &lt;a href=&#34;https://portswigger.net/research/saml-roulette-the-hacker-always-wins&#34;&gt;https://portswigger.net/research/saml-roulette-the-hacker-always-wins&lt;/a&gt; - a SAML guide to lock picking from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xcc6hnrljh03ksmfd4uq4859f756w2h6tp3keckw6pz23ec0unqqrnkhle&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Gareth Heyes :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xcc…khle&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/&#34;&gt;https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/&lt;/a&gt; - backdooring your backups&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://tmpout.sh/4&#34;&gt;https://tmpout.sh/4&lt;/a&gt; - new &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1z6kl7et2j7vuwhvpdp35dyh6nvwl0q2v5r8vnq7ntapkyks09m6q9myrg4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;tmpout&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1z6k…yrg4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://research.swtch.com/nih&#34;&gt;https://research.swtch.com/nih&lt;/a&gt; - rethinking trust&lt;br/&gt;* &lt;a href=&#34;https://blog.quarkslab.com/bluetooth-low-energy-gatt-fuzzing.html&#34;&gt;https://blog.quarkslab.com/bluetooth-low-energy-gatt-fuzzing.html&lt;/a&gt; - fuzzing BTLE&lt;br/&gt;* &lt;a href=&#34;https://sgued.fr/blog/der-pem-cert/&#34;&gt;https://sgued.fr/blog/der-pem-cert/&lt;/a&gt; - certs are hard&lt;br/&gt;* &lt;a href=&#34;https://i.blackhat.com/us-18/Thu-August-9/us-18-Bulazel-Windows-Offender-Reverse-Engineering-Windows-Defenders-Antivirus-Emulator.pdf&#34;&gt;https://i.blackhat.com/us-18/Thu-August-9/us-18-Bulazel-Windows-Offender-Reverse-Engineering-Windows-Defenders-Antivirus-Emulator.pdf&lt;/a&gt; - reverse engineering Defender&lt;br/&gt;* &lt;a href=&#34;https://www.slideshare.net/slideshow/remotemethodguesser-bhusa2021-arsenal/249983357&#34;&gt;https://www.slideshare.net/slideshow/remotemethodguesser-bhusa2021-arsenal/249983357&lt;/a&gt; - fuzzing RMI&lt;br/&gt;* &lt;a href=&#34;http://gibsonnet.net/blog/dwarchive/NIMSH,%20SSL%20and%20LPM.%20(Chris%27s%20AIX%20Blog).html&#34;&gt;http://gibsonnet.net/blog/dwarchive/NIMSH,%20SSL%20and%20LPM.%20(Chris%27s%20AIX%20Blog).html&lt;/a&gt; - with a 10.0 in IBM AIX&amp;#39;s NIM install solution, I decided to do some digging... everybody relax, it&amp;#39;s fine&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://latex.vercel.app/&#34;&gt;https://latex.vercel.app/&lt;/a&gt; - LaTeX as HTML&lt;br/&gt;* &lt;a href=&#34;https://artsandculture.google.com/asset/english-electric-kdf9-lyons-electronic-office-computer-installation-bracknell-met-office/sAHERiMe475-Eg?hl=en&#34;&gt;https://artsandculture.google.com/asset/english-electric-kdf9-lyons-electronic-office-computer-installation-bracknell-met-office/sAHERiMe475-Eg?hl=en&lt;/a&gt; - old time photos of the UK met office super computers&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-03-22T01:33:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrqu7sxfsy7yrzttzg9sjkftznagrp6dflje00s8xwcgszvcwk0fgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzf8s059</id>
    
      <title type="html">Activity spinning up on GitHub for people playing with the bug, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrqu7sxfsy7yrzttzg9sjkftznagrp6dflje00s8xwcgszvcwk0fgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzf8s059" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszcansm8dj2qcxvcrepuham3mstkyr0262czsggd4nacercpr8ghqpfw69d&#39;&gt;nevent1q…w69d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Activity spinning up on GitHub for people playing with the bug, but also at least a few possibly vulnerable code bases:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/search?q=%3Cparam-name%3Ereadonly%3C%2Fparam-name%3E&#43;%3Cparam-value%3Efalse%3C%2Fparam-value%3E&#43;&#43;&amp;amp;type=code&#34;&gt;https://github.com/search?q=%3Cparam-name%3Ereadonly%3C%2Fparam-name%3E&#43;%3Cparam-value%3Efalse%3C%2Fparam-value%3E&#43;&#43;&amp;amp;type=code&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The author of the blog post mentioned in my previous post initially predicted KEV but then reconsidered. I suspect they&amp;#39;re right but it will it will depend on if any big commercial J2EE is vulnerable as deployed on TomCat. To that end, the following from the VMware folks looked interesting:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/vmware/dod-compliance-and-automation/blob/e080d523461ade1dadca12c8f7622bd60fcbe920/vsphere/8.0/v1r1-srg/vcsa/inspec/vmware-vcsa-8.0-stig-baseline/eam/controls/VCEM-80-000130.rb#L35&#34;&gt;https://github.com/vmware/dod-compliance-and-automation/blob/e080d523461ade1dadca12c8f7622bd60fcbe920/vsphere/8.0/v1r1-srg/vcsa/inspec/vmware-vcsa-8.0-stig-baseline/eam/controls/VCEM-80-000130.rb#L35&lt;/a&gt;
    </content>
    <updated>2025-03-15T12:03:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszcansm8dj2qcxvcrepuham3mstkyr0262czsggd4nacercpr8ghqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfyvz0z</id>
    
      <title type="html">A decent explanation of the Apache TomCat bug I posted a link to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszcansm8dj2qcxvcrepuham3mstkyr0262czsggd4nacercpr8ghqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfyvz0z" />
    <content type="html">
      A decent explanation of the Apache TomCat bug I posted a link to the PoC for earlier:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html&#34;&gt;https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #tomcat, #java
    </content>
    <updated>2025-03-15T11:53:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxd6uprz0x703fn852l8j8a5mgyrknxrt2urh46c5spwk22uqdpkgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzzv9hlj</id>
    
      <title type="html">PoC vulnerable app for the Camel bug: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxd6uprz0x703fn852l8j8a5mgyrknxrt2urh46c5spwk22uqdpkgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzzv9hlj" />
    <content type="html">
      PoC vulnerable app for the Camel bug:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/akamai/CVE-2025-27636-Apache-Camel-PoC&#34;&gt;https://github.com/akamai/CVE-2025-27636-Apache-Camel-PoC&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Code that may/may not exhibit the same kinds of problems:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/search?q=import&#43;org.apache.camel&#43;RouteBuilder&amp;amp;type=code&#34;&gt;https://github.com/search?q=import&#43;org.apache.camel&#43;RouteBuilder&amp;amp;type=code&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #java
    </content>
    <updated>2025-03-10T17:45:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg3uc92heq4x3djwlk4lz7zt038j75sxry5a9af2whj4f5ujcgaaczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzg7h6vx</id>
    
      <title type="html">Simply smashing a device that you have physical access to is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg3uc92heq4x3djwlk4lz7zt038j75sxry5a9af2whj4f5ujcgaaczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzg7h6vx" />
    <content type="html">
      Simply smashing a device that you have physical access to is scored as CVSS 5.2 (Medium):&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N&#34;&gt;https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N&lt;/a&gt;
    </content>
    <updated>2025-03-10T10:01:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspp8w4ctshtmlshpm0zl8zk80wz24nwqejxlqk29yju4acdsk4esszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzftj4hy</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspp8w4ctshtmlshpm0zl8zk80wz24nwqejxlqk29yju4acdsk4esszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzftj4hy" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3594553&#34;&gt;https://dl.acm.org/doi/10.1145/3594553&lt;/a&gt; - refining TI with automated labelling&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.talosintelligence.com/salt-typhoon-analysis/&#34;&gt;https://blog.talosintelligence.com/salt-typhoon-analysis/&lt;/a&gt; - Salt Typhoon analysis from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xkd2rp780746wm90u3nshlvzqfhcyhjw7p08pz0wgdpzl3he8gvqlscc62&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Cisco Talos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xkd…cc62&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.inversecos.com/2025/02/an-inside-look-at-nsa-equation-group.html&#34;&gt;https://www.inversecos.com/2025/02/an-inside-look-at-nsa-equation-group.html&lt;/a&gt; - a Chinese view on Equation Group&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.thinkst.com/2025/02/almost-famous-behind-the-scenes-of-a-feature-that-didnt-make-the-cut.html&#34;&gt;https://blog.thinkst.com/2025/02/almost-famous-behind-the-scenes-of-a-feature-that-didnt-make-the-cut.html&lt;/a&gt; - building canary tokens with unconstrained delegation&lt;br/&gt;&lt;br/&gt;Hard hack:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://kindlemodding.org/&#34;&gt;https://kindlemodding.org/&lt;/a&gt; - modding the Kindle&lt;br/&gt;* &lt;a href=&#34;https://www.die-welt.net/2025/02/unauthenticated-rce-in-grandstream-ht802v2-and-probably-others-using-gs_test_server-dhcp-vendor-option/&#34;&gt;https://www.die-welt.net/2025/02/unauthenticated-rce-in-grandstream-ht802v2-and-probably-others-using-gs_test_server-dhcp-vendor-option/&lt;/a&gt; - hacking hardware via DHCP vendor options&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://neapay.com/viewposts.html?category=BASE24&#34;&gt;https://neapay.com/viewposts.html?category=BASE24&lt;/a&gt; - variable quality but details on Base24&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-02-21T10:41:56Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszqq9zkjnmtwlgfa7fgmup235c3fcemyqmnqldtxfmqnc6uxwvqjczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztxrtyd</id>
    
      <title type="html">A suitable punishment for DOGE.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszqq9zkjnmtwlgfa7fgmup235c3fcemyqmnqldtxfmqnc6uxwvqjczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztxrtyd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszg5v9a0fn2eq8eg5xgt3lfc7h35ztyhs50j9ny23juty6gc5g8tgedwdtw&#39;&gt;nevent1q…wdtw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A suitable punishment for DOGE.
    </content>
    <updated>2025-02-08T18:08:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx60g5dkawj0gnapqlcqgafucg9kxvx7jwsmtvjys8xfyec9prwygzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzma4hvx</id>
    
      <title type="html">LinkedIn implies DB2 on z.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx60g5dkawj0gnapqlcqgafucg9kxvx7jwsmtvjys8xfyec9prwygzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzma4hvx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvyxnnsxrl9zzelnxsq2eprvksmpsn9rhyy7wv7gz2kl84gazpg6cyz3667&#39;&gt;nevent1q…3667&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;LinkedIn implies DB2 on z.
    </content>
    <updated>2025-02-08T17:12:02Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr8dapug8gmjl2wt0xa3xea94nt4hww92207ddyk7vlchr504ekkgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6jvyk6</id>
    
      <title type="html">I wonder what &amp;#34;mainframe&amp;#34; platform the US treasury ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr8dapug8gmjl2wt0xa3xea94nt4hww92207ddyk7vlchr504ekkgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6jvyk6" />
    <content type="html">
      I wonder what &amp;#34;mainframe&amp;#34; platform the US treasury actually uses...
    </content>
    <updated>2025-02-08T17:06:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyuwcvf7enfnctee3uzh69ts42set0wax7ul8yxp8mg4x7k4yjqzqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzckmhgz</id>
    
      <title type="html">Pretty sure this customer doesn&amp;#39;t own unregistereddomain.tld. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyuwcvf7enfnctee3uzh69ts42set0wax7ul8yxp8mg4x7k4yjqzqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzckmhgz" />
    <content type="html">
      Pretty sure this customer doesn&amp;#39;t own unregistereddomain.tld. Probably not the best FQDN for their OT hosts to be authenticating against.&lt;br/&gt;&lt;br/&gt;#redteam
    </content>
    <updated>2025-01-22T15:04:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgyxx96ntd96mhku4snqgnv5vpx4ynlx0yaryl26jp9yfgvuxhhvszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt9fpyc</id>
    
      <title type="html">PSA: It is indeed incorrect to label Starmer or the modern Labour ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgyxx96ntd96mhku4snqgnv5vpx4ynlx0yaryl26jp9yfgvuxhhvszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt9fpyc" />
    <content type="html">
      PSA: It is indeed incorrect to label Starmer or the modern Labour party as lefties.
    </content>
    <updated>2025-01-12T13:51:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd2p4lcjxc07p04ju3njf0p6f0u28tt0x5l2twayj6da3jn4ypjaszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmqkcfh</id>
    
      <title type="html">A bug so hard to fix that it took almost 10 years to make a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd2p4lcjxc07p04ju3njf0p6f0u28tt0x5l2twayj6da3jn4ypjaszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmqkcfh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst0rxv9yvgwcrgtgs8xajk5zs8yzm64guvhutdw5kxx0ycwumpqjcqww0ed&#39;&gt;nevent1q…w0ed&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A bug so hard to fix that it took almost 10 years to make a decision.
    </content>
    <updated>2025-01-08T18:54:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst0rxv9yvgwcrgtgs8xajk5zs8yzm64guvhutdw5kxx0ycwumpqjczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz960kph</id>
    
      <title>Nostr event nevent1qqst0rxv9yvgwcrgtgs8xajk5zs8yzm64guvhutdw5kxx0ycwumpqjczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz960kph</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst0rxv9yvgwcrgtgs8xajk5zs8yzm64guvhutdw5kxx0ycwumpqjczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz960kph" />
    <content type="html">
      Just got a WontFix on a security bug I reported in 2014 :/.
    </content>
    <updated>2025-01-08T18:09:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgurmuhe9nsk2vq9u0yx68crenhq6ajunkdzaa3p89kah7fc8776szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzwq703v</id>
    
      <title type="html">PoC for CVE-2024-6387 in OpenSSH is out: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgurmuhe9nsk2vq9u0yx68crenhq6ajunkdzaa3p89kah7fc8776szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzwq703v" />
    <content type="html">
      PoC for CVE-2024-6387 in OpenSSH is out:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/YassDEV221608/CVE-2024-6387_PoC&#34;&gt;https://github.com/YassDEV221608/CVE-2024-6387_PoC&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;32-bit only...&lt;br/&gt;&lt;br/&gt;#linux, #threatintel
    </content>
    <updated>2025-01-06T12:02:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszwmmakt6zh73zkczuqnfq9hwgw7ttzg6psrsu9h23rjrtx9mv29szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz7jj8pl</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszwmmakt6zh73zkczuqnfq9hwgw7ttzg6psrsu9h23rjrtx9mv29szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz7jj8pl" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://jericho.blog/2024/12/28/mitres-phoning-in-new-cnas/&#34;&gt;https://jericho.blog/2024/12/28/mitres-phoning-in-new-cnas/&lt;/a&gt; - a critique of the training for new CNA from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub17frqv647wlw5xeh8a4casr6lck7jqh596qgnjzknhwf37zs2pkqqf4q25e&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;jericho&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub17fr…q25e&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.misp-standard.org/blog/Naming-Threat-Actor/&#34;&gt;https://www.misp-standard.org/blog/Naming-Threat-Actor/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1mlypv5xgnd6zxu8ssyzc485ussa5a0mwf3g4t6sz2jtgts2qsuqq6arl2t&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;MISP&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1mly…rl2t&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; proposes a standard for naming threat actors&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.vodafone.com/sustainable-business/maintaining-trust/law-enforcement-assistance&#34;&gt;https://www.vodafone.com/sustainable-business/maintaining-trust/law-enforcement-assistance&lt;/a&gt; - Vodafone&amp;#39;s yearly account of law enforcement interactions&lt;br/&gt;* &lt;a href=&#34;https://www.propublica.org/article/ap3-oath-keepers-militia-mole&#34;&gt;https://www.propublica.org/article/ap3-oath-keepers-militia-mole&lt;/a&gt; - moles in right wing infrastructure :bloblaugh:&lt;br/&gt;* &lt;a href=&#34;https://community.emergingthreats.net/t/the-many-cves-of-d-link-hnap-command-injection/2314&#34;&gt;https://community.emergingthreats.net/t/the-many-cves-of-d-link-hnap-command-injection/2314&lt;/a&gt; - attacking HNAP for CLI injection&lt;br/&gt;* &lt;a href=&#34;https://www.flux.utah.edu/paper/singh-nsdi24&#34;&gt;https://www.flux.utah.edu/paper/singh-nsdi24&lt;/a&gt; - analysing the prevalence and scope of ITW SSH brute force attacks&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity24/presentation/badva&#34;&gt;https://www.usenix.org/conference/usenixsecurity24/presentation/badva&lt;/a&gt; - paper on threat hunting, full disclosure: participant P18 is me :)&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/&#34;&gt;https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/&lt;/a&gt; - AD LDAP sadness&lt;br/&gt;* &lt;a href=&#34;https://social.circl.lu/@vulnerability_lookup/113761006476621066&#34;&gt;https://social.circl.lu/@vulnerability_lookup/113761006476621066&lt;/a&gt; - fediverse reporting on the same bugs by [@vulnerability_lookup](&lt;a href=&#34;https://social.circl.lu/@vulnerability_lookup&#34;&gt;https://social.circl.lu/@vulnerability_lookup&lt;/a&gt; )&lt;br/&gt;* &lt;a href=&#34;https://thesecmaster.com/blog/how-to-protect-your-four-faith-industrial-routers-from-cve-2024-12856-a-critical&#34;&gt;https://thesecmaster.com/blog/how-to-protect-your-four-faith-industrial-routers-from-cve-2024-12856-a-critical&lt;/a&gt; - hacking the factory&lt;br/&gt;* &lt;a href=&#34;https://seclists.org/fulldisclosure/2024/Dec/21&#34;&gt;https://seclists.org/fulldisclosure/2024/Dec/21&lt;/a&gt; - when the CTF platform itself supplies the bugs...&lt;br/&gt;* &lt;a href=&#34;https://seclists.org/fulldisclosure/2024/Dec/19&#34;&gt;https://seclists.org/fulldisclosure/2024/Dec/19&lt;/a&gt; - iSay, iSay, shell me a midtier, sir!&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://people.kernel.org/kees/colliding-with-the-sha-prefix-of-linuxs-initial-git-commit&#34;&gt;https://people.kernel.org/kees/colliding-with-the-sha-prefix-of-linuxs-initial-git-commit&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h9f5cqgdy8wcr7axv74e6n0vvsms2d63ythdvkdm3fu46geu45hs7t9etp&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Kees Cook (old account)&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h9f…9etp&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; collides Linux&lt;br/&gt;* &lt;a href=&#34;https://www.hvs-consulting.de/en/nfs-security-identifying-and-exploiting-misconfigurations/&#34;&gt;https://www.hvs-consulting.de/en/nfs-security-identifying-and-exploiting-misconfigurations/&lt;/a&gt; - holes in NFS, surely not?&lt;br/&gt;* &lt;a href=&#34;https://blog.slowerzs.net/posts/thievingfox/&#34;&gt;https://blog.slowerzs.net/posts/thievingfox/&lt;/a&gt; -  stealing passwords for red team glory&lt;br/&gt;&lt;br/&gt;Hard hack:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://aleksandr.rogozin.us/blog/2021/8/13/hacking-philips-wiz-lights-via-command-line&#34;&gt;https://aleksandr.rogozin.us/blog/2021/8/13/hacking-philips-wiz-lights-via-command-line&lt;/a&gt; - hacking Philips WiZ&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.cisa.gov/sites/default/files/2024-01/SbD-Alert-Security-Design-Improvements-for-SOHO-Device-Manufacturers.pdf&#34;&gt;https://www.cisa.gov/sites/default/files/2024-01/SbD-Alert-Security-Design-Improvements-for-SOHO-Device-Manufacturers.pdf&lt;/a&gt; - CISA advice on SOHO networks.. not wildly blown away but I suppose they have to start somewhere...&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/markqvist/Reticulum/discussions/231&#34;&gt;https://github.com/markqvist/Reticulum/discussions/231&lt;/a&gt; - an interesting approach to non-TCP/IP federated networks as shared by &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ptqztjvp0s0ayrqr7gs8wytv22acngp2yh5vmt8wgtd84fjqmwxqrc6e7p&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;sqshr&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ptq…6e7p&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;...&lt;br/&gt;* &lt;a href=&#34;https://www.jmeiners.com/lc3-vm/&#34;&gt;https://www.jmeiners.com/lc3-vm/&lt;/a&gt; - write your own VM... kinda remember doing this at uni&lt;br/&gt;* &lt;a href=&#34;https://tickets.why2025.org/&#34;&gt;https://tickets.why2025.org/&lt;/a&gt; - have you ordered your tickets for &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ux8clvzv6te9u9xpl3fegmjrkrf5e2ttnmr3xafljtvrumucknlspzhm28&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;why2025camp&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ux8…hm28&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2025-01-05T16:43:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyqcw07m2asg6ynyck7zsdpzlc44g60tkhup3vewhyks4x537fm4czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrtv6g5</id>
    
      <title type="html">A Struts bug: https://github.com/TAM-K592/CVE-2024-53677-S2-067 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyqcw07m2asg6ynyck7zsdpzlc44g60tkhup3vewhyks4x537fm4czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrtv6g5" />
    <content type="html">
      A Struts bug:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/TAM-K592/CVE-2024-53677-S2-067&#34;&gt;https://github.com/TAM-K592/CVE-2024-53677-S2-067&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The week before Christmas?&lt;br/&gt;&lt;br/&gt;Oh my!&lt;br/&gt;&lt;br/&gt;#java, #threatintel
    </content>
    <updated>2024-12-17T22:06:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp72aeydl427mwtcwmtdl359tgg7gdcmea26d8q7ghf3zf7p86ufgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrnrkgs</id>
    
      <title type="html">Looking at legacy NeXT source: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp72aeydl427mwtcwmtdl359tgg7gdcmea26d8q7ghf3zf7p86ufgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrnrkgs" />
    <content type="html">
      Looking at legacy NeXT source:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/johnsonjh/NeXTSrc/blob/ff846608a76ab2fbbb86e8a14c52ac85332f9786/libc-34.1/libc/gen/execvp.c#L34&#34;&gt;https://github.com/johnsonjh/NeXTSrc/blob/ff846608a76ab2fbbb86e8a14c52ac85332f9786/libc-34.1/libc/gen/execvp.c#L34&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Quoting from the OS X man page for execvp():&lt;br/&gt;&lt;br/&gt;&amp;#34;Historically, the default path for the execlp() and execvp() functions was ``:/bin:/usr/bin&amp;#39;&amp;#39;.  This was changed to place the current directory last to enhance system security.&amp;#34;&lt;br/&gt;&lt;br/&gt;#noshitsherlock, #codereview, #appsec, #sdlc
    </content>
    <updated>2024-12-15T22:48:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2mrf4y0z98p054vd958znw0zamr29lfkhfnm0ny0k78kxp8kqr4czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsjejf2</id>
    
      <title type="html">Nothing. Just made me laugh.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2mrf4y0z98p054vd958znw0zamr29lfkhfnm0ny0k78kxp8kqr4czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsjejf2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst40vgtlmpplgj49jgufk37refepqju20j9q5dlh0vm68ky0pey8g6jhck7&#39;&gt;nevent1q…hck7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Nothing. Just made me laugh.
    </content>
    <updated>2024-12-01T17:26:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs28puwgpex9ssvtvupr2dg8hdx75xpfc4c7lr2gxgscm5nrcnv9hszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzerfsxh</id>
    
      <title type="html">:blobcry:</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs28puwgpex9ssvtvupr2dg8hdx75xpfc4c7lr2gxgscm5nrcnv9hszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzerfsxh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrhl9y6upmqqatkmnw7w6n6v7ux7t7gvxjm00uf5j088zvlq3g8dcltltcd&#39;&gt;nevent1q…ltcd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;:blobcry:
    </content>
    <updated>2024-12-01T17:13:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2yda2jpl6y8vpphy93ndq7t72p6qlef9w7rl86f7ntls7lxq9j7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz8payu</id>
    
      <title type="html">I have but provisionally but it may not stay. We&amp;#39;ll see.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2yda2jpl6y8vpphy93ndq7t72p6qlef9w7rl86f7ntls7lxq9j7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz8payu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr4hketm6w4mxj56dkhw2tnphwzmfs3exzfaphjgyl4qpuc80qvksu2m8es&#39;&gt;nevent1q…m8es&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I have but provisionally but it may not stay. We&amp;#39;ll see.
    </content>
    <updated>2024-11-16T17:53:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2hw0sqhwejn02hauhmd0gpxerhgdyyvhn0alxqpsfn0ndnvh2a6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvvy7ku</id>
    
      <title type="html">Woop. QNX is free (as in beer) again: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2hw0sqhwejn02hauhmd0gpxerhgdyyvhn0alxqpsfn0ndnvh2a6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvvy7ku" />
    <content type="html">
      Woop. QNX is free (as in beer) again:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blackberry.qnx.com/en/products/qnx-everywhere&#34;&gt;https://blackberry.qnx.com/en/products/qnx-everywhere&lt;/a&gt;
    </content>
    <updated>2024-11-08T12:01:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvjxmvu4664nk3eznyq0j6taauv6srsec4np77dpt8va7n6xwx4yczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzk8tc32</id>
    
      <title type="html">Samba can also expose your CUPS configured printers too so ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvjxmvu4664nk3eznyq0j6taauv6srsec4np77dpt8va7n6xwx4yczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzk8tc32" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs88p03e8znxsxt7jgfl0pvdnuv4hrfjm3pzg7jnzz0vecl7ss3hqcd7mf7l&#39;&gt;nevent1q…mf7l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Samba can also expose your CUPS configured printers too so it&amp;#39;s not just 631/tcp to be watchful of.
    </content>
    <updated>2024-09-28T12:03:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs88p03e8znxsxt7jgfl0pvdnuv4hrfjm3pzg7jnzz0vecl7ss3hqczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8wl03s</id>
    
      <title type="html">That&amp;#39;s not typically the default but we&amp;#39;re talking about ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs88p03e8znxsxt7jgfl0pvdnuv4hrfjm3pzg7jnzz0vecl7ss3hqczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8wl03s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw49xkhvhmg85zn9dt6unfxrmsz3p9cm9y2ye3ujexlj2phse32fsuftccw&#39;&gt;nevent1q…tccw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That&amp;#39;s not typically the default but we&amp;#39;re talking about something that is fundamentally designed to be a server &amp;amp; queue manager for others on the network. By default, cupsd (the actual server &amp;amp; queue manager) may well be bound to localhost, with browsing set to no and various IPP API endpoints restricted with location ACLs but all of these can and are changed for various reasons (witness 631/tcp being open).
    </content>
    <updated>2024-09-28T12:00:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw49xkhvhmg85zn9dt6unfxrmsz3p9cm9y2ye3ujexlj2phse32fszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzp7jgp5</id>
    
      <title type="html">The *victim needs to print* narrative would be fine if we&amp;#39;re ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw49xkhvhmg85zn9dt6unfxrmsz3p9cm9y2ye3ujexlj2phse32fszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzp7jgp5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2vpen3csxvpk38as0se837cpzf6t2d466sdlmm0tn99lewdttq6gsrls6w&#39;&gt;nevent1q…ls6w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The *victim needs to print* narrative would be fine if we&amp;#39;re targetting an end user. Thing is, we&amp;#39;re not - we&amp;#39;re targetting the print server.
    </content>
    <updated>2024-09-28T08:27:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2vpen3csxvpk38as0se837cpzf6t2d466sdlmm0tn99lewdttq6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy0hqcv</id>
    
      <title type="html">Casual observation. *Someone* needs to print something. What ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2vpen3csxvpk38as0se837cpzf6t2d466sdlmm0tn99lewdttq6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy0hqcv" />
    <content type="html">
      Casual observation. *Someone* needs to print something. What happens if the adversary can?&lt;br/&gt;&lt;br/&gt;#cups, #redteam
    </content>
    <updated>2024-09-28T07:42:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr45swnxnhaxyzkezjrmc3j6gvwgu6t7wflsvarlhnn26tw8mwwhczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dze9w6xc</id>
    
      <title type="html">Rumours look to have been accurate, it looks like it&amp;#39;s CUPS: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr45swnxnhaxyzkezjrmc3j6gvwgu6t7wflsvarlhnn26tw8mwwhczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dze9w6xc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv9dz68mue98hjzlcyghf0hhpmv8wu85gk9qguh2ttn8ygytq440grfp4lx&#39;&gt;nevent1q…p4lx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Rumours look to have been accurate, it looks like it&amp;#39;s CUPS:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.linkedin.com/posts/benjamin-harris-sg_15-minutes-ago-our-monitoring-systems-went-activity-7245132773902983168-xZ0u?utm_source=share&amp;amp;utm_medium=member_android&#34;&gt;https://www.linkedin.com/posts/benjamin-harris-sg_15-minutes-ago-our-monitoring-systems-went-activity-7245132773902983168-xZ0u?utm_source=share&amp;amp;utm_medium=member_android&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;(Courtesy of an old friend at &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1r4a3cqjhh06tmrex84st3w20407uuq3w4q2m5v3mcu86ffzdlchqj2u230&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;watchTowr&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1r4a…u230&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;)
    </content>
    <updated>2024-09-26T18:16:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv9dz68mue98hjzlcyghf0hhpmv8wu85gk9qguh2ttn8ygytq440gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgcnvmg</id>
    
      <title type="html">Add in, runs as root and likely listens on the network (by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv9dz68mue98hjzlcyghf0hhpmv8wu85gk9qguh2ttn8ygytq440gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgcnvmg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdy2rmvdq83ruf589dqalfu520333pjcsysxy2h64ld0s02hlsg7sa9gp94&#39;&gt;nevent1q…gp94&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Add in, runs as root and likely listens on the network (by default).
    </content>
    <updated>2024-09-26T17:55:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdy2rmvdq83ruf589dqalfu520333pjcsysxy2h64ld0s02hlsg7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn80p77</id>
    
      <title type="html">If you wanted to speculate on the upcoming CVE in Linux distros, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdy2rmvdq83ruf589dqalfu520333pjcsysxy2h64ld0s02hlsg7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn80p77" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgmc5emjjjle6lu0flxknhm8e6mxp2qm9sems73dmkt35dpl0ztxqvudk2j&#39;&gt;nevent1q…dk2j&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you wanted to speculate on the upcoming CVE in Linux distros, correlating Popcon with those that have listening ports and CVE data might be one way to make a prediction:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://popcon.debian.org/&#34;&gt;https://popcon.debian.org/&lt;/a&gt;
    </content>
    <updated>2024-09-26T17:29:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgmc5emjjjle6lu0flxknhm8e6mxp2qm9sems73dmkt35dpl0ztxqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5563v7</id>
    
      <title type="html">PSA: Wild speculation is the best speculation. #rumops</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgmc5emjjjle6lu0flxknhm8e6mxp2qm9sems73dmkt35dpl0ztxqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5563v7" />
    <content type="html">
      PSA: Wild speculation is the best speculation.&lt;br/&gt;&lt;br/&gt;#rumops
    </content>
    <updated>2024-09-26T15:16:55Z</updated>
  </entry>

</feed>