<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-27T16:45:53Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Tim (Wadhwa-)Brown :donor:</title>
  <author>
    <name>Tim (Wadhwa-)Brown :donor:</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07.rss" />
  <link href="https://nostr.ae/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07" />
  <id>https://nostr.ae/npub1feda6kwfz0r3vxaferk7alqjpe00gce0gz8n9dfk2zd4kf8q2ngs6a8w07</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/270/420/396/177/158/original/dee4c24c931fd17a.jpeg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/270/420/396/177/158/original/dee4c24c931fd17a.jpeg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqszy2yng0d8r36eq5n836jwve85q9rvk8zyu6gsll2xw4g5tkn9atszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxmfsqp</id>
    
      <title type="html">Some people will tell you that PQC resilience is a maths issue, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszy2yng0d8r36eq5n836jwve85q9rvk8zyu6gsll2xw4g5tkn9atszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxmfsqp" />
    <content type="html">
      Some people will tell you that PQC resilience is a maths issue, but I&amp;#39;m arguing it&amp;#39;s a hygiene issue.
    </content>
    <updated>2026-07-28T12:02:58Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd4kfluzvhyncad8mds77mvtszmyuk7cmk59vee589hkvad6s7afszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz30jmh6</id>
    
      <title type="html">RE: https://mastodon.social/@sellathechemist/116992339665635678 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd4kfluzvhyncad8mds77mvtszmyuk7cmk59vee589hkvad6s7afszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz30jmh6" />
    <content type="html">
      RE: &lt;a href=&#34;https://mastodon.social/@sellathechemist/116992339665635678&#34;&gt;https://mastodon.social/@sellathechemist/116992339665635678&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;It&amp;#39;s not really random if it&amp;#39;s not from from the location of getrandom(), instead it&amp;#39;s just sparkling CPU state data...&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1nslzx38g4fagxhz2u7qm95zcnku0hdddzmy0qgzspd5ty9w2me7q96u9v4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1nsl…u9v4&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Message for the day – Commit a random act of maintenance! &lt;br/&gt;&lt;br/&gt;Listen to it, look at it, wipe it, clean it, lube it, brush it, tighten it, grease it, turn it, check it, test it, sweep it, mop it, paint it, tape it, sand it, tweak it, tune it, adjust it, wash it, oil it, dust it, align it, scrub it, wind it, fill it, seal it…&lt;br/&gt; &lt;img src=&#34;https://files.mastodon.social/media_attachments/files/116/992/337/654/431/563/original/2c735092f765b654.jpg&#34;&gt; &lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-07-27T20:15:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszev3fd99eujq7lpy8v9hw9g2a2ajxw7r8rte3qf50j3l8eyd2l0szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvck7ec</id>
    
      <title type="html">There is no better feeling than a Friday thumbs up on a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszev3fd99eujq7lpy8v9hw9g2a2ajxw7r8rte3qf50j3l8eyd2l0szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvck7ec" />
    <content type="html">
      There is no better feeling than a Friday thumbs up on a deliverable  The next step in securing the waterfall awaits and I can go to the pub with a smile on my face.
    </content>
    <updated>2026-07-24T16:10:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsttuk7vadfe48r9xs2l2k54lwfjp9kgaw4phvmt7t4a4w27khy38gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9vt4l5</id>
    
      <title type="html">Might go bug hunting KDE later for the full 2010&amp;#39;ish ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsttuk7vadfe48r9xs2l2k54lwfjp9kgaw4phvmt7t4a4w27khy38gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9vt4l5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswem6nvcavf7hpfh8jd7j5xkxvch9tsakz9hc8yv2plr02l54s82srguzw0&#39;&gt;nevent1q…uzw0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Might go bug hunting KDE later for the full 2010&amp;#39;ish experience. The big questions:&lt;br/&gt;&lt;br/&gt;1) Are IOSlaves still a problem?&lt;br/&gt;2) Is DBUS any better than DCOP?
    </content>
    <updated>2026-07-22T18:50:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswem6nvcavf7hpfh8jd7j5xkxvch9tsakz9hc8yv2plr02l54s82szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzah8pm8</id>
    
      <title type="html">Also went with KDE which I&amp;#39;d not used since ~3.something and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswem6nvcavf7hpfh8jd7j5xkxvch9tsakz9hc8yv2plr02l54s82szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzah8pm8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdgd8pz2n06w4vsetzetsd7p5s0kgh3dsdlkxg223sk8eqpsd999ckfysyq&#39;&gt;nevent1q…ysyq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also went with KDE which I&amp;#39;d not used since ~3.something and now Akregator is being loaded with all my &amp;#34;interesting links&amp;#34;...
    </content>
    <updated>2026-07-22T18:41:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdgd8pz2n06w4vsetzetsd7p5s0kgh3dsdlkxg223sk8eqpsd999czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz4ssdcj</id>
    
      <title type="html">I&amp;#39;d kinda forgotten what games can be like. but building my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdgd8pz2n06w4vsetzetsd7p5s0kgh3dsdlkxg223sk8eqpsd999czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz4ssdcj" />
    <content type="html">
      I&amp;#39;d kinda forgotten what games can be like. but building my first personal laptop in the last decade or so, I&amp;#39;ve installed vitetris and the rogue-like angband.
    </content>
    <updated>2026-07-22T18:35:38Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0mhu276mw5lff7fs575xtrtpyxykk7vn8033hnf9zpeu98eqs8kczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu5jm35</id>
    
      <title type="html">Be interesting to see how I get on with this, just discovered ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0mhu276mw5lff7fs575xtrtpyxykk7vn8033hnf9zpeu98eqs8kczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu5jm35" />
    <content type="html">
      Be interesting to see how I get on with this, just discovered &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1zts534mmumk850wyxet8wvujq32nqv0lstq4uevkku68p4kuju8qdq4g7j&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Tokodon&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1zts…4g7j&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;...
    </content>
    <updated>2026-07-21T22:07:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg2n9a3yemqvjeelg2f40g6u8djk4hqcs2cn5zhj86hqv077q993czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz30pjnq</id>
    
      <title type="html">@npub1yak…d8rp If I buy all the spare parts from the online ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg2n9a3yemqvjeelg2f40g6u8djk4hqcs2cn5zhj86hqv077q993czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz30pjnq" />
    <content type="html">
      &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1yakxj0kck8urftqqw07uxnzffngyrxah20ga6lqft9h5plehe97qf9d8rp&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;EMF Badge&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1yak…d8rp&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; If I buy all the spare parts from the online store and the new 2026 bits (both already done), do I need the 2024 green front board or will it work without? If I do, do you have any spares on site?&lt;br/&gt;&lt;br/&gt;Asking as I gave my 2024 badge to someone who missed out and I&amp;#39;m trying to bootstrap a replacement from the spare parts...
    </content>
    <updated>2026-07-19T12:42:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp7p7c0djd8409cqmpr0m3fgnsj43fuqcjkpruv3lqcqn9ezxgrgczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcx8dn5</id>
    
      <title type="html">Could do with some saying you are number X in the queue. That ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp7p7c0djd8409cqmpr0m3fgnsj43fuqcjkpruv3lqcqn9ezxgrgczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcx8dn5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp2aeq2r0uqfvea3pzw2kwt5u9rqkz4sgqwyyeuzqauy4z7gjaw9cpgg4ka&#39;&gt;nevent1q…g4ka&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Could do with some saying you are number X in the queue. That would be very #emfcamp :bloblaugh:..
    </content>
    <updated>2026-07-19T08:24:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsda4mpka7k6mvvez96u9dgpyhd0gw8xwt96vugwak304cgme03qaqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzq6e3wh</id>
    
      <title type="html">Found a wristband, so if you could all check the whereabouts of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsda4mpka7k6mvvez96u9dgpyhd0gw8xwt96vugwak304cgme03qaqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzq6e3wh" />
    <content type="html">
      Found a wristband, so if you could all check the whereabouts of yours before I have to involve orga, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1x0e9r0rh6yana7yajlkzxwl67a5059me5c2d9trshac56zxzyr9syxyc6u&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;EMF info and help&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1x0e…yc6u&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, lost property and site security...&lt;br/&gt;&lt;br/&gt;#emfcamp, #emfcamp2026
    </content>
    <updated>2026-07-19T07:54:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdau3pfk0hgrkx9pelhfqnv3fkp2uu94vw6s0r5pk2ptqud9jtwhszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfnyjmx</id>
    
      <title type="html">Traffic jam at EMF border. #emfcamp</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdau3pfk0hgrkx9pelhfqnv3fkp2uu94vw6s0r5pk2ptqud9jtwhszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfnyjmx" />
    <content type="html">
      Traffic jam at EMF border.&lt;br/&gt;&lt;br/&gt;#emfcamp
    </content>
    <updated>2026-07-16T09:59:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsze8cpqnxs8ew8dptaaxuw6ydq55y65x2satl385h56p54g7sm66gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxjtzdt</id>
    
      <title type="html">A little bit on machine-id from a friend: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsze8cpqnxs8ew8dptaaxuw6ydq55y65x2satl385h56p54g7sm66gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxjtzdt" />
    <content type="html">
      A little bit on machine-id from a friend:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://ransomware.sh/posts/machine-id/&#34;&gt;https://ransomware.sh/posts/machine-id/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#linux, #blueteam
    </content>
    <updated>2026-07-13T17:47:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxd279ptwv04qx539g2s6nrm9cdxqptq37rapmlxhs337z2k65g3szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxxg9f0</id>
    
      <title type="html">Super keen to launch my laptops into the sun right now. Mac ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxd279ptwv04qx539g2s6nrm9cdxqptq37rapmlxhs337z2k65g3szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxxg9f0" />
    <content type="html">
      Super keen to launch my laptops into the sun right now.&lt;br/&gt;&lt;br/&gt;Mac laptop doesn&amp;#39;t recognise wifi interface after an upgrade, Ubuntu is bitching about my partitioning due to a GRUB issue after a dist-upgrade and my old Surface needs flattening after I migrated to a new one. The only laptops in a working state are the corporate Linux and corporate Surface.
    </content>
    <updated>2026-07-12T08:49:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgsrd6ayvlthq9dxuljy8vg9dk72q3kgr8hvl00rt7my7u7jt9u2szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhfxyrf</id>
    
      <title type="html">That time of the week, where I go through all the crazy ideas on ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgsrd6ayvlthq9dxuljy8vg9dk72q3kgr8hvl00rt7my7u7jt9u2szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhfxyrf" />
    <content type="html">
      That time of the week, where I go through all the crazy ideas on the timeline proposed for #emfcamp to pick out the scavenger hunt challenges for &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1t23lesu83acya2a8ue0ywjr4unqz9ng947r0xq6z6lm7vqah2tcqx5k3r5&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Electromagnetic Field CTF Team&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1t23…k3r5&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;.
    </content>
    <updated>2026-07-11T10:58:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspxkwuryzahg3t0wf8czu95weklp60z6949mnpxu36dtyx6mvm6vszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxvqqmy</id>
    
      <title type="html">Interesting Git repos of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspxkwuryzahg3t0wf8czu95weklp60z6949mnpxu36dtyx6mvm6vszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxvqqmy" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/connectans/awesome-CISSP-CCSP&#34;&gt;https://github.com/connectans/awesome-CISSP-CCSP&lt;/a&gt; - so you want to CIISP?&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/dinosn/apache-activemq-rce-research&#34;&gt;https://github.com/dinosn/apache-activemq-rce-research&lt;/a&gt; - queue jumping&lt;br/&gt;* &lt;a href=&#34;https://github.com/hacefresko/CVE-2021-4045&#34;&gt;https://github.com/hacefresko/CVE-2021-4045&lt;/a&gt; - popping the TP-Link Tapo&lt;br/&gt;* &lt;a href=&#34;https://github.com/jarnovandenbrink/CVE-2026-26128&#34;&gt;https://github.com/jarnovandenbrink/CVE-2026-26128&lt;/a&gt; - what KRB5 identity do you see in the mirror?&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/apify/fingerprint-suite&#34;&gt;https://github.com/apify/fingerprint-suite&lt;/a&gt; - mess with your fingerprints 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/apisec-inc/AI-Surface&#34;&gt;https://github.com/apisec-inc/AI-Surface&lt;/a&gt; - map the AI attack surface 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/doyensec/maSSO&#34;&gt;https://github.com/doyensec/maSSO&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub12c3uqtuc56u27myphgd2kzpfvvcwrnpysdczmlqj34umlc3fuflsndulke&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Doyensec&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub12c3…ulke&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s hostile IdP&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/nervous-inhuman/tplink-tapo-c200-re&#34;&gt;https://github.com/nervous-inhuman/tplink-tapo-c200-re&lt;/a&gt; - reverse engineering a TP-Link camera&lt;br/&gt;&lt;br/&gt;#security, #research, #code
    </content>
    <updated>2026-07-11T09:40:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqcw2vs84dhcqmj5llskxr7mk4uweuk07prejhdxyjfn5wladavjszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhh67ml</id>
    
      <title type="html">Pointed this out before but UNIX sockets are an untapped LPE ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqcw2vs84dhcqmj5llskxr7mk4uweuk07prejhdxyjfn5wladavjszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzhh67ml" />
    <content type="html">
      Pointed this out before but UNIX sockets are an untapped LPE opportunity:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://syntetisk.tech/blog/posts/privilege-escalation-to-root-in-lima-qemu-guests-via-a-world-writable-agent-socket-cve-2026-53657/&#34;&gt;https://syntetisk.tech/blog/posts/privilege-escalation-to-root-in-lima-qemu-guests-via-a-world-writable-agent-socket-cve-2026-53657/&lt;/a&gt;
    </content>
    <updated>2026-07-05T17:11:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswm4p7n4mx04cv55yv49a2c0nagfkkkqt8yr34qw7xp8y55s5zw6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5y2zk0</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswm4p7n4mx04cv55yv49a2c0nagfkkkqt8yr34qw7xp8y55s5zw6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5y2zk0" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://ecs-org.eu/policy/nis2-directive-transposition-tracker/&#34;&gt;https://ecs-org.eu/policy/nis2-directive-transposition-tracker/&lt;/a&gt; - following along at home with NIS2 enactment&lt;br/&gt;* &lt;a href=&#34;https://mr-r3b00t.github.io/org_cyber_attack_sim/&#34;&gt;https://mr-r3b00t.github.io/org_cyber_attack_sim/&lt;/a&gt; - what does it really feel life to defend, [@UK_Daniel_Card](&lt;a href=&#34;https://infosec.exchange/@UK_Daniel_Card&#34;&gt;https://infosec.exchange/@UK_Daniel_Card&lt;/a&gt; ) has built a sim to find out&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.w3.org/TR/security-disclosure/&#34;&gt;https://www.w3.org/TR/security-disclosure/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1tl7py9zzhkzjmwfzy9cwtz9fsl4jnqn4cn4uz3cz24da864kxztsau6j09&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;World Wide Web Consortium&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1tl7…6j09&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; weighs in on disclosure&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://anuragbhatia.com/post/2026/06/telegram-bgp-hijack-and-blackholing/&#34;&gt;https://anuragbhatia.com/post/2026/06/telegram-bgp-hijack-and-blackholing/&lt;/a&gt; - some reporting on a BGP hijack of Telegram&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.huntress.com/blog/ldap-active-directory-detection-part-six&#34;&gt;https://www.huntress.com/blog/ldap-active-directory-detection-part-six&lt;/a&gt; -  more from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1fe05cwn4yp5tmszf859qqg90wtq80huenwm8c7apy63fshsmmwcqyq30s6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Huntress&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1fe0…30s6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; on LDAP detection&lt;br/&gt;* &lt;a href=&#34;https://tradecraftgarden.org/&#34;&gt;https://tradecraftgarden.org/&lt;/a&gt; - from the people that brought you Cobalt Strike&lt;br/&gt;* &lt;a href=&#34;https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html&#34;&gt;https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html&lt;/a&gt; - incident satire from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1m49jugn9ndwz3d6e4yhgeyq902fwjr5q5ept4pg9lumd4cyc66tschyl0h&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Andrew Nesbitt&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1m49…yl0h&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.sentry.security/log-curation-101/&#34;&gt;https://blog.sentry.security/log-curation-101/&lt;/a&gt; - a subject after my own heart, useful logs...&lt;br/&gt;* &lt;a href=&#34;https://www.deathcon.wales/&#34;&gt;https://www.deathcon.wales/&lt;/a&gt; - here be dragons&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://askar.so/blogs/chaining-isc-dhcp-server-features-for-unauthenticated-root-remote-code-execution/&#34;&gt;https://askar.so/blogs/chaining-isc-dhcp-server-features-for-unauthenticated-root-remote-code-execution/&lt;/a&gt; - poppin&amp;#39; DHCP&lt;br/&gt;* &lt;a href=&#34;https://pop.argus-systems.ai/advisory/adv-040.html&#34;&gt;https://pop.argus-systems.ai/advisory/adv-040.html&lt;/a&gt; - OpenBSD is too open 🤖&lt;br/&gt;&lt;br/&gt;Data:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://intheweights.com/&#34;&gt;https://intheweights.com/&lt;/a&gt; - which models are you in? 🤖&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://fediverse.info/explore/people&#34;&gt;https://fediverse.info/explore/people&lt;/a&gt; - people of the Fediverse&lt;br/&gt;* &lt;a href=&#34;https://fedidb.com/welcome&#34;&gt;https://fedidb.com/welcome&lt;/a&gt; - find your perfect Fediverse platform&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-07-04T11:42:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqk9pltc098ss2606uhsa82r3l2g8gffemk9p4ux52gfpmrtlg6lczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2mkxxn</id>
    
      <title type="html">What&amp;#39;s the best bit of post-exploitation? #redteam, #blueteam</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqk9pltc098ss2606uhsa82r3l2g8gffemk9p4ux52gfpmrtlg6lczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2mkxxn" />
    <content type="html">
      What&amp;#39;s the best bit of post-exploitation?&lt;br/&gt;&lt;br/&gt;#redteam, #blueteam
    </content>
    <updated>2026-07-04T05:12:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrctjjae986ww65w8jnwe4xsau52espya9znsqmcwa2a87mvxkrmszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz2gyd9</id>
    
      <title type="html">Just logged on to my new Surface with a Sun USB keyboard from ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrctjjae986ww65w8jnwe4xsau52espya9znsqmcwa2a87mvxkrmszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz2gyd9" />
    <content type="html">
      Just logged on to my new Surface with a Sun USB keyboard from almost 2 decades back. Eat that Bill.
    </content>
    <updated>2026-06-30T21:48:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdfr7h2gdnt8hmfcfejgza44n888mhhmaqswuw3fgxqdrntw9agkqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzkwenf0</id>
    
      <title type="html">Regretting not fixing the mower earlier in the season, the garden ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdfr7h2gdnt8hmfcfejgza44n888mhhmaqswuw3fgxqdrntw9agkqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzkwenf0" />
    <content type="html">
      Regretting not fixing the mower earlier in the season, the garden was one big thistle patch.
    </content>
    <updated>2026-06-28T20:58:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz9c6qasuvcz4j5sqxd02n7gv3zr9h6sr4akke38ak90alekujljczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz92uqmf</id>
    
      <title type="html">&amp;#34;Who do I file bugs with?&amp;#34; enquired the ghost. &amp;#34;That ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz9c6qasuvcz4j5sqxd02n7gv3zr9h6sr4akke38ak90alekujljczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz92uqmf" />
    <content type="html">
      &amp;#34;Who do I file bugs with?&amp;#34; enquired the ghost. &amp;#34;That one down there is faulty&amp;#34;, they continued, pointing at a politician on the earth below.&lt;br/&gt;&lt;br/&gt;#microfiction
    </content>
    <updated>2026-06-28T00:48:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvrlmxmp2njknkr5uvqfkh83qwv5k20tejef8684w5cc4v4hvfdcszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz65z8mn</id>
    
      <title type="html">I&amp;#39;ve never done an &amp;#34;interesting links&amp;#34; from ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvrlmxmp2njknkr5uvqfkh83qwv5k20tejef8684w5cc4v4hvfdcszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz65z8mn" />
    <content type="html">
      I&amp;#39;ve never done an &amp;#34;interesting links&amp;#34; from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1fak836ah0kaqplhwap2yr4sykskheep4j55d0aglcvwhry732qgsehrg6c&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Electromagnetic Field&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1fak…rg6c&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, it could be a big one...
    </content>
    <updated>2026-06-27T19:42:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2r7uchr02x5nux0dmu6urqszpz4u7qjg2vyp7ky02pxcdtc76d7gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzl9vvlk</id>
    
      <title type="html">RE: https://infosec.exchange/@timb_machine/116195097544770832 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2r7uchr02x5nux0dmu6urqszpz4u7qjg2vyp7ky02pxcdtc76d7gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzl9vvlk" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@timb_machine/116195097544770832&#34;&gt;https://infosec.exchange/@timb_machine/116195097544770832&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Pro-tip: You can still be supportive of gay, bi, lesbian, non-binary, trans, queer folks etc tomorrow, next month, next year etc. Don&amp;#39;t limit yourself to just treating them decently for one month!&lt;br/&gt;nostr:note153ea4t3sg7vh6cjkcxja3qz6nlyyj8q92hpz2mdhrvyy5xss04cqqsj0jq&lt;br/&gt;
    </content>
    <updated>2026-06-27T12:22:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdmtyep7u92ydycd7etgc6p7pd545x6azyn8ustjk224np7exvqngzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9dvkfe</id>
    
      <title type="html">Hydration thought. I have a new snark WRT to AI... ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdmtyep7u92ydycd7etgc6p7pd545x6azyn8ustjk224np7exvqngzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9dvkfe" />
    <content type="html">
      Hydration thought. I have a new snark WRT to AI... &amp;#34;you&amp;#39;re like the backend of a millipede&amp;#34;
    </content>
    <updated>2026-06-27T11:32:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstu2f3jaar68ys0a83dpwhuxzgushp5jzfdx38xc6r29vgv5c28qqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxce0pn</id>
    
      <title type="html">The thing I like about AI this week is all these folks showing ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstu2f3jaar68ys0a83dpwhuxzgushp5jzfdx38xc6r29vgv5c28qqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxce0pn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswvskshtw33mlgp0se47se66wvlqpzr7d6jgjl44yy5a56rfvglyqld9h80&#39;&gt;nevent1q…9h80&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The thing I like about AI this week is all these folks showing up, prattling on about agentic AI identity like it&amp;#39;s a new thing and that most agent based solutions aren&amp;#39;t really just the web service model done really insecurely.
    </content>
    <updated>2026-06-27T07:38:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrv6wjw0hkqjk4sygznfajptafdy7xaynsfnymkt6rg5zkmyd6cjgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztcrjys</id>
    
      <title type="html">&#43;&#43; Buy your dog a wet coat, cold mat, take it out pre-8am, give ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrv6wjw0hkqjk4sygznfajptafdy7xaynsfnymkt6rg5zkmyd6cjgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztcrjys" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsghqau6ajnzsyssu3l4z0perusahg0vm56ct962pnf3a6w99466kqjnak5h&#39;&gt;nevent1q…ak5h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&#43;&#43;&lt;br/&gt;&lt;br/&gt;Buy your dog a wet coat, cold mat, take it out pre-8am, give them a shaded corner of the home etc. Also, find out if your dog like ice cubes and frozen treats.&lt;br/&gt;&lt;br/&gt;Above all, don&amp;#39;t make them suffer for your ignorance.&lt;br/&gt;&lt;br/&gt;This goes as much for #uk as it does from our friends across the river on the mainland.&lt;br/&gt;&lt;br/&gt;#dogsofmastodon, #dogops
    </content>
    <updated>2026-06-26T14:38:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8ga74kpppspgat7tq2u84l28yz7lakhaflrf0xltck4hh0u696sczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzq33r8k</id>
    
      <title type="html">Tim&amp;#39;s first law of thermodynamics: Hot weather makes people ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8ga74kpppspgat7tq2u84l28yz7lakhaflrf0xltck4hh0u696sczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzq33r8k" />
    <content type="html">
      Tim&amp;#39;s first law of thermodynamics: Hot weather makes people drive like dicks.
    </content>
    <updated>2026-06-25T18:16:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0dstyz29acfjftzqq7a7fyd947mawpyyrp0es4wzs7q2jzjewj8qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv0d940</id>
    
      <title type="html">RE: https://bots.robots.rodeo/@scream/116803800090167176 Illegal ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0dstyz29acfjftzqq7a7fyd947mawpyyrp0es4wzs7q2jzjewj8qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv0d940" />
    <content type="html">
      RE: &lt;a href=&#34;https://bots.robots.rodeo/@scream/116803800090167176&#34;&gt;https://bots.robots.rodeo/@scream/116803800090167176&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Illegal instruction: 4&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1l68tup9gu26dc04d2uzsvkrpyatccfup4zqar5kgnjauhwr34j2skwrhx7&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1l68…rhx7&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; AAAAAAAAAAAAAAAAAAAAHHHHHHHHHHHHH &lt;/blockquote&gt;
    </content>
    <updated>2026-06-24T07:40:38Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv0y4lkuzf5ggtxz5zwssgs8uhrsxwp9y56dpv600v7wdm7dd8rgqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzre4vpw</id>
    
      <title type="html">Not one, but two presentations on building better detections for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv0y4lkuzf5ggtxz5zwssgs8uhrsxwp9y56dpv600v7wdm7dd8rgqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzre4vpw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs96s94zy9rjpgpx4rxsarrjrjp3xerl8llvw33f8808wk96ax4lvq6u2kre&#39;&gt;nevent1q…2kre&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Not one, but two presentations on building better detections for service providers:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/CiscoCXSecurity/presentations/blob/master/Telecoms%20Threat%20Landscape%20-%20Mapping%20reality%20to%20frameworks.pdf&#34;&gt;https://github.com/CiscoCXSecurity/presentations/blob/master/Telecoms%20Threat%20Landscape%20-%20Mapping%20reality%20to%20frameworks.pdf&lt;/a&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/CiscoCXSecurity/presentations/blob/master/Practical%20Threat%20Detections%20for%20Telecommunications%20-%20Strategic%20defense%20insights%20from%20the%20wider%20world.pdf&#34;&gt;https://github.com/CiscoCXSecurity/presentations/blob/master/Practical%20Threat%20Detections%20for%20Telecommunications%20-%20Strategic%20defense%20insights%20from%20the%20wider%20world.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #detection, #engineering, #blueteam, #soc, #telco
    </content>
    <updated>2026-06-23T17:55:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstdtfg0d3059l2fd6pdvjd8p3n4q5sq3csd2n5wkpk4w64az6a0jgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrh7qkt</id>
    
      <title type="html">Keir Starmer, so dull, he couldn&amp;#39;t even deliver an inspiring ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstdtfg0d3059l2fd6pdvjd8p3n4q5sq3csd2n5wkpk4w64az6a0jgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrh7qkt" />
    <content type="html">
      Keir Starmer, so dull, he couldn&amp;#39;t even deliver an inspiring resignation speech when for once, people were actually excited to hear from him.
    </content>
    <updated>2026-06-23T06:20:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq2qkv8n28k05qpz5r03y7rquqw26uzpdn4pxduvcmruq9rd06nwqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz4wdsh6</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq2qkv8n28k05qpz5r03y7rquqw26uzpdn4pxduvcmruq9rd06nwqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz4wdsh6" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back&#34;&gt;https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back&lt;/a&gt; - and then the arguments started...&lt;br/&gt;* &lt;a href=&#34;https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/4494769/playing-the-future-insights-from-wargaming-cyber-conflict/&#34;&gt;https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/4494769/playing-the-future-insights-from-wargaming-cyber-conflict/&lt;/a&gt; - insights from wargaming, or how to dress up as .mil, .ir, .il, cn or .ru*&lt;br/&gt;* &lt;a href=&#34;https://www.gov.uk/government/publications/draft-revised-telecommunications-security-code-of-practice-2026/draft-revised-telecommunications-security-code-of-practice&#34;&gt;https://www.gov.uk/government/publications/draft-revised-telecommunications-security-code-of-practice-2026/draft-revised-telecommunications-security-code-of-practice&lt;/a&gt; - the UK TSA gets an update&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://sandflysecurity.com/blog/how-linux-malware-works-from-simple-to-sophisticated&#34;&gt;https://sandflysecurity.com/blog/how-linux-malware-works-from-simple-to-sophisticated&lt;/a&gt; - a lovely write up on Linux malware maturity&lt;br/&gt;* &lt;a href=&#34;http://miod.online.fr/software/openbsd/stories/trojan.html&#34;&gt;http://miod.online.fr/software/openbsd/stories/trojan.html&lt;/a&gt; - that time OpenBSD got popped&lt;br/&gt;* &lt;a href=&#34;https://www.sygnia.co/blog/operation-highland-velvet-ant/&#34;&gt;https://www.sygnia.co/blog/operation-highland-velvet-ant/&lt;/a&gt; - watch out for 🐜 people&lt;br/&gt;* &lt;a href=&#34;https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem&#34;&gt;https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem&lt;/a&gt; - IBM with some ransomware gossip&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://pruva.dev/&#34;&gt;https://pruva.dev/&lt;/a&gt; - automated bug reproduction 🤖&lt;br/&gt;* &lt;a href=&#34;https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/&#34;&gt;https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/&lt;/a&gt; - [@index](&lt;a href=&#34;https://labs.watchtowr.com/&#34;&gt;https://labs.watchtowr.com/&lt;/a&gt; )&amp;#39;s latest fun and games&lt;br/&gt;* &lt;a href=&#34;https://bumsrake.de/&#34;&gt;https://bumsrake.de/&lt;/a&gt; - another sloppy bug in FreeBSD 🤖&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://pretalx.ripe.net/media/ripe-92/submissions/YHQY7N/resources/Manipulating_RPKI___1zypS0J.pdf&#34;&gt;https://pretalx.ripe.net/media/ripe-92/submissions/YHQY7N/resources/Manipulating_RPKI___1zypS0J.pdf&lt;/a&gt; - [@sash](&lt;a href=&#34;https://hachyderm.io/@sash&#34;&gt;https://hachyderm.io/@sash&lt;/a&gt; ) talks XSS attacks on RPKI&lt;br/&gt;* &lt;a href=&#34;https://blog.ikaes.de/getting-the-pid-from-random-numbers/&#34;&gt;https://blog.ikaes.de/getting-the-pid-from-random-numbers/&lt;/a&gt; - PHP is so very predictable&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://trustedsec.com/blog/hardening-intune-the-implementation-guide&#34;&gt;https://trustedsec.com/blog/hardening-intune-the-implementation-guide&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1jfz58dhla3mwj0x6xu6jh98ym5wkss5s64zesucp7939zvcm77rq2vm99l&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;trustedsec&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1jfz…m99l&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss hardening Intune&lt;br/&gt;* &lt;a href=&#34;https://documentation.nokia.com/nsp/25-8/NSP_Security_Hardening_Guide/NSP_Security_Hardening_Guide_Issue_1.pdf&#34;&gt;https://documentation.nokia.com/nsp/25-8/NSP_Security_Hardening_Guide/NSP_Security_Hardening_Guide_Issue_1.pdf&lt;/a&gt; - if you&amp;#39;ve ever wanted to harden a Nokia network&lt;br/&gt;&lt;br/&gt;* not complete list of malicious TLDs :/&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-06-20T14:11:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd4pqcwuzeqx8a82yarh42w4fw0fheysqnygpzz3uln4pk7gqkeggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz3mcfwr</id>
    
      <title type="html">Interesting Git repos of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd4pqcwuzeqx8a82yarh42w4fw0fheysqnygpzz3uln4pk7gqkeggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz3mcfwr" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/tmylla/Awesome-LLM4Cybersecurity&#34;&gt;https://github.com/tmylla/Awesome-LLM4Cybersecurity&lt;/a&gt; - papers on LLM for security 🤖&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/elastic/detection-rules&#34;&gt;https://github.com/elastic/detection-rules&lt;/a&gt; - Elastic&amp;#39;s detection rules 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/threathunters-io/kassandra_x33fcon_2026&#34;&gt;https://github.com/threathunters-io/kassandra_x33fcon_2026&lt;/a&gt; - fingerprinting modern C2&lt;br/&gt;* &lt;a href=&#34;https://github.com/SlimKQL/Detections.AI&#34;&gt;https://github.com/SlimKQL/Detections.AI&lt;/a&gt; - detection rules&lt;br/&gt;* &lt;a href=&#34;https://github.com/NVIDIA/SkillSpector&#34;&gt;https://github.com/NVIDIA/SkillSpector&lt;/a&gt; - NVIDIA take a stab at detection malicious skills&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/antonioCoco/RoguePotato&#34;&gt;https://github.com/antonioCoco/RoguePotato&lt;/a&gt; - old PoC for a Windows LPE&lt;br/&gt;* &lt;a href=&#34;https://github.com/MSNightmare/GreatXML&#34;&gt;https://github.com/MSNightmare/GreatXML&lt;/a&gt; - the nightmares return&lt;br/&gt;* &lt;a href=&#34;https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802&#34;&gt;https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1j543hgudzf58v908qy5k7fy896p6wyct455ptwlq5fwaj9j4t7eq4j42x7&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;chompie&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1j54…42x7&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s CVE-2023-36802 PoC&lt;br/&gt;* &lt;a href=&#34;https://github.com/chompie1337/s8_2019_2215_poc_exynos&#34;&gt;https://github.com/chompie1337/s8_2019_2215_poc_exynos&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1j543hgudzf58v908qy5k7fy896p6wyct455ptwlq5fwaj9j4t7eq4j42x7&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;chompie&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1j54…42x7&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s CVE-2019-2215 PoC&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/atomiczsec/Noradrenaline&#34;&gt;https://github.com/atomiczsec/Noradrenaline&lt;/a&gt; - malicious payloads for Linux and OS X&lt;br/&gt;* &lt;a href=&#34;https://github.com/ar0x4/tunnel-vision-toolkit&#34;&gt;https://github.com/ar0x4/tunnel-vision-toolkit&lt;/a&gt; - abusing Microsoft&amp;#39;s ZTNA solution&lt;br/&gt;* &lt;a href=&#34;https://github.com/leechristensen/SpoolSample&#34;&gt;https://github.com/leechristensen/SpoolSample&lt;/a&gt; - love the name, another relay attack on Windows&lt;br/&gt;* &lt;a href=&#34;https://github.com/portbuster1337/lpe-toolkit&#34;&gt;https://github.com/portbuster1337/lpe-toolkit&lt;/a&gt; - Linux LPE toolkit&lt;br/&gt;* &lt;a href=&#34;https://github.com/OpenSecurityResearch/hostapd-wpe&#34;&gt;https://github.com/OpenSecurityResearch/hostapd-wpe&lt;/a&gt; - attacking wireless clients&lt;br/&gt;* &lt;a href=&#34;https://github.com/Poellie01/PentestCompanion&#34;&gt;https://github.com/Poellie01/PentestCompanion&lt;/a&gt; - a pentesting framework&lt;br/&gt;* &lt;a href=&#34;https://github.com/hannob/snallygaster&#34;&gt;https://github.com/hannob/snallygaster&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1syue7pmxnqdduqh2ydqwavs0vx056jnc5zxmlg6lxecrl9zdtxfq283cq9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;hanno&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1syu…3cq9&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; hunts secretes in HTTP&lt;br/&gt;* &lt;a href=&#34;https://github.com/haltman-io/thc.org&#34;&gt;https://github.com/haltman-io/thc.org&lt;/a&gt; - a mirror of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1a0syl0wxctexh7u3m0ek4ycsuaktwfjnynjrzn9zyjjv4hn0eknqasdmkd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Hacker‘s Choice&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1a0s…dmkd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; goodies&lt;br/&gt;* &lt;a href=&#34;https://github.com/mongodb/kingfisher&#34;&gt;https://github.com/mongodb/kingfisher&lt;/a&gt; - you should never share a secret&lt;br/&gt;* &lt;a href=&#34;https://github.com/kernelstub/Ferrum&#34;&gt;https://github.com/kernelstub/Ferrum&lt;/a&gt; - Windows research&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/boinkor-net/hoopsnake&#34;&gt;https://github.com/boinkor-net/hoopsnake&lt;/a&gt; - want an SSH server in your initrd?&lt;br/&gt;&lt;br/&gt;Encryption:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/singe/QuantumHello&#34;&gt;https://github.com/singe/QuantumHello&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1pfnwnq4gjrap2f2eelmhd5zlpqw2dtrjegk4g2qh64wppa8lm8lsma8d8k&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Dominic White&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1pfn…8d8k&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s tools for poking for PQC&lt;br/&gt;* &lt;a href=&#34;https://github.com/snowch/hsm-guide&#34;&gt;https://github.com/snowch/hsm-guide&lt;/a&gt; - everything you&amp;#39;ve (n)ever wanted to know about HSM&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/timb-machine-mirrors/iloveappleandtwinks-gistfile1.txt&#34;&gt;https://github.com/timb-machine-mirrors/iloveappleandtwinks-gistfile1.txt&lt;/a&gt; - may possibly be Siri&amp;#39;s system prompt&lt;br/&gt;&lt;br/&gt;#security, #code, #research
    </content>
    <updated>2026-06-20T13:49:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyp429ywreydz6cjfagvc4puwnaktfutgfsdasckqv9acw93a0g8szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs20632</id>
    
      <title type="html">$snoopcon &#43;&#43;; # The yearly trip to Birmingham has concluded. Many ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyp429ywreydz6cjfagvc4puwnaktfutgfsdasckqv9acw93a0g8szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs20632" />
    <content type="html">
      $snoopcon &#43;&#43;; # The yearly trip to Birmingham has concluded. Many thanks to those friends who helped organise the event
    </content>
    <updated>2026-06-19T18:34:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswcl2k34y96qklkj93vcayrfunym6d2ygzc0al9k9af4wlc8qjp7qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6xptf2</id>
    
      <title type="html">Until you walk in the woods every day, you don&amp;#39;t realise how ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswcl2k34y96qklkj93vcayrfunym6d2ygzc0al9k9af4wlc8qjp7qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6xptf2" />
    <content type="html">
      Until you walk in the woods every day, you don&amp;#39;t realise how many trees suffer systemic failure every year...
    </content>
    <updated>2026-06-16T16:23:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs80edwryzkpqjsjdf37sxahgnd99wzsf49mdcl9qvwe9yk8wavh5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn52dzc</id>
    
      <title type="html">Trying to talk a customer out of buying firewalls for their MPLS ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs80edwryzkpqjsjdf37sxahgnd99wzsf49mdcl9qvwe9yk8wavh5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzn52dzc" />
    <content type="html">
      Trying to talk a customer out of buying firewalls for their MPLS transport network. They&amp;#39;d do better to invest the time in hardening, monitoring but apparently that&amp;#39;s too hard.
    </content>
    <updated>2026-06-16T11:07:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2yawsafnujxy5d6rr0fjsp7zfp0zyj7xmjxfs962ezu3dssa9rgczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8rulhn</id>
    
      <title type="html">It&amp;#39;s kinda interesting to see who ended up here and who ended ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2yawsafnujxy5d6rr0fjsp7zfp0zyj7xmjxfs962ezu3dssa9rgczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8rulhn" />
    <content type="html">
      It&amp;#39;s kinda interesting to see who ended up here and who ended up on BSky. Too bad.
    </content>
    <updated>2026-06-14T21:17:54Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9ntnmsy2cescup309a9fln2wjkmyhldnvep9s4a3ksh3yhkluu0qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzch7t94</id>
    
      <title type="html">What parts of #detection #engineering do people find difficult? ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9ntnmsy2cescup309a9fln2wjkmyhldnvep9s4a3ksh3yhkluu0qzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzch7t94" />
    <content type="html">
      What parts of #detection #engineering do people find difficult?&lt;br/&gt;&lt;br/&gt;#blueteam
    </content>
    <updated>2026-06-14T19:28:54Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2785m55p0fuyr9049jzpmgsus3nvu3lxsjtach07t2gndx4sv9gqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzenpnvy</id>
    
      <title type="html">Good $arbitrarydeity, people bragging about having &amp;#34;used ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2785m55p0fuyr9049jzpmgsus3nvu3lxsjtach07t2gndx4sv9gqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzenpnvy" />
    <content type="html">
      Good $arbitrarydeity, people bragging about having &amp;#34;used Mythos&amp;#34; like it&amp;#39;s a badge of honour.
    </content>
    <updated>2026-06-14T05:59:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs86263rlp38ukrwzzc7x8gjzgn6a3keyvexu5v3c6x28qven57hjqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqmm06c</id>
    
      <title type="html">It&amp;#39;s disappointing that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs86263rlp38ukrwzzc7x8gjzgn6a3keyvexu5v3c6x28qven57hjqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqmm06c" />
    <content type="html">
      It&amp;#39;s disappointing that &lt;a href=&#34;https://www.sygnia.co/blog/operation-highland-velvet-ant/&#34;&gt;https://www.sygnia.co/blog/operation-highland-velvet-ant/&lt;/a&gt; mentions RPATH but then doesn&amp;#39;t provide any details. I&amp;#39;m just left wondering if you could exploit their backdoors...
    </content>
    <updated>2026-06-13T12:26:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrtvcz0td2v8trnwx9cw3e0tyetc9y8t8dnz8j3xs7lg5m6z04f5szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzddd6dt</id>
    
      <title type="html">Interesting Git repos of the week: Detection: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrtvcz0td2v8trnwx9cw3e0tyetc9y8t8dnz8j3xs7lg5m6z04f5szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzddd6dt" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/Sbharadwaj05/ot-sentinel-rules&#34;&gt;https://github.com/Sbharadwaj05/ot-sentinel-rules&lt;/a&gt; - detection rules for OT&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/Bad-Jubies/Exploits&#34;&gt;https://github.com/Bad-Jubies/Exploits&lt;/a&gt; - interesting PoCs&lt;br/&gt;* &lt;a href=&#34;https://github.com/TwoSevenOneT/EDRChoker&#34;&gt;https://github.com/TwoSevenOneT/EDRChoker&lt;/a&gt; - if you&amp;#39;ve ever wanted to strangle an EDR?&lt;br/&gt;* &lt;a href=&#34;https://github.com/MSNightmare/RoguePlanet&#34;&gt;https://github.com/MSNightmare/RoguePlanet&lt;/a&gt; - uh, oh, they&amp;#39;re back and Microsoft are still stuck in their nightmare&lt;br/&gt;* &lt;a href=&#34;https://github.com/ADScanPro/CVE-2026-41089-LongLogon&#34;&gt;https://github.com/ADScanPro/CVE-2026-41089-LongLogon&lt;/a&gt; - analysis of LongLogon&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/AdnaneKhan/gato-x&#34;&gt;https://github.com/AdnaneKhan/gato-x&lt;/a&gt; - attacking GitHub 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/frizb/Windows-Privilege-Escalation&#34;&gt;https://github.com/frizb/Windows-Privilege-Escalation&lt;/a&gt; - LPE methodology for Windows&lt;br/&gt;* &lt;a href=&#34;https://github.com/tjnull/cygor&#34;&gt;https://github.com/tjnull/cygor&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1j48y4hcwzft237hqyj3ujl64z3sz8hezdhrt5pm0eejhs5lcxzys8z4sv2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Tj Null :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1j48…4sv2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; goes asset mapping&lt;br/&gt;* &lt;a href=&#34;https://github.com/foxglovesec/RottenPotato&#34;&gt;https://github.com/foxglovesec/RottenPotato&lt;/a&gt; - the original rotten potato&lt;br/&gt;* &lt;a href=&#34;https://github.com/breenmachine/RottenPotatoNG&#34;&gt;https://github.com/breenmachine/RottenPotatoNG&lt;/a&gt; - someone&amp;#39;s built a better/worse potato&lt;br/&gt;* &lt;a href=&#34;https://github.com/hatRiot/token-priv&#34;&gt;https://github.com/hatRiot/token-priv&lt;/a&gt; - abusing tokens for LPE&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/Geeoon/Fault-Injection-Finder&#34;&gt;https://github.com/Geeoon/Fault-Injection-Finder&lt;/a&gt; - if your IoT doesn&amp;#39;t have enough faults, why not make some more&lt;br/&gt;* &lt;a href=&#34;https://github.com/yeet-src/usbsnoop&#34;&gt;https://github.com/yeet-src/usbsnoop&lt;/a&gt; - snooping on USB 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/persistentcache/Lora-Wideband-Decoder&#34;&gt;https://github.com/persistentcache/Lora-Wideband-Decoder&lt;/a&gt; - decoding LoRa 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/umair9747/Genzai&#34;&gt;https://github.com/umair9747/Genzai&lt;/a&gt; - fingerprint and brute force IoT&lt;br/&gt;* &lt;a href=&#34;https://github.com/geo-tp/ESP32-Bit-Pirate&#34;&gt;https://github.com/geo-tp/ESP32-Bit-Pirate&lt;/a&gt; - Bus Pirate-alike based on ESP32&lt;br/&gt;* &lt;a href=&#34;https://github.com/fuzzsociety/usbStackFuzz&#34;&gt;https://github.com/fuzzsociety/usbStackFuzz&lt;/a&gt; - fuzzing USB stacks&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/Division-36/Z-Jail&#34;&gt;https://github.com/Division-36/Z-Jail&lt;/a&gt; - another day, another sandbox&lt;br/&gt;* &lt;a href=&#34;https://github.com/rimvydascivilis/seccomp-profiler&#34;&gt;https://github.com/rimvydascivilis/seccomp-profiler&lt;/a&gt; - using eBPF to build seccomp profiles&lt;br/&gt;&lt;br/&gt;#code, #security, #research
    </content>
    <updated>2026-06-13T08:52:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv2fdz9pn7slfz28r00mlepf2v88kukuh4dcv9rdpvqpnnh2v7auqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6y7tx0</id>
    
      <title type="html">Splunk sadness courtesy of [@index](https://labs.watchtowr.com/ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv2fdz9pn7slfz28r00mlepf2v88kukuh4dcv9rdpvqpnnh2v7auqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz6y7tx0" />
    <content type="html">
      Splunk sadness courtesy of [@index](&lt;a href=&#34;https://labs.watchtowr.com/&#34;&gt;https://labs.watchtowr.com/&lt;/a&gt; ):&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/&#34;&gt;https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #splunk
    </content>
    <updated>2026-06-12T21:23:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswv74yak48pdz2eh729ya8lsdxrpld4ucekuclrqhq05ndlfx3v7czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv7ctay</id>
    
      <title type="html">There is an irony that despite my offensive background, the only ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswv74yak48pdz2eh729ya8lsdxrpld4ucekuclrqhq05ndlfx3v7czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv7ctay" />
    <content type="html">
      There is an irony that despite my offensive background, the only cyber security discipline I don&amp;#39;t hold current certs for is offense.&lt;br/&gt;&lt;br/&gt;#purpleteam
    </content>
    <updated>2026-06-09T19:55:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy4qsetvgr2rjff29zfvn2s096zprkw2sm7lfd09quxpjjpd2fknszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxwsp9c</id>
    
      <title type="html">Fan thought: Can&amp;#39;t imagine many states going for it, but a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy4qsetvgr2rjff29zfvn2s096zprkw2sm7lfd09quxpjjpd2fknszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxwsp9c" />
    <content type="html">
      Fan thought: Can&amp;#39;t imagine many states going for it, but a tax on war might be interesting...
    </content>
    <updated>2026-05-25T13:48:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsve75lc6jhcsr96c60r3dt340jm0vy9gfhc250ev4cklyhwaxyeeqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9q4zgn</id>
    
      <title type="html">Excellent DR exercise last week after the DC caught fire. Now, I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsve75lc6jhcsr96c60r3dt340jm0vy9gfhc250ev4cklyhwaxyeeqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9q4zgn" />
    <content type="html">
      Excellent DR exercise last week after the DC caught fire. Now, I do parallel backups so wasn&amp;#39;t directly caught out but it turns out the corporate backup solution doesn&amp;#39;t notify on failure. This seems a gap.
    </content>
    <updated>2026-05-16T07:18:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs962ps2sd2tsahjzch72llxscv2hfl7kkqleey2gyapu4hel725ggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzwc2v7v</id>
    
      <title type="html">Gotta love IT. copy.fail directions that use perl and curl to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs962ps2sd2tsahjzch72llxscv2hfl7kkqleey2gyapu4hel725ggzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzwc2v7v" />
    <content type="html">
      Gotta love IT. copy.fail directions that use perl and curl to apply patches. Not only elite UNIX knowledge but the patching command rhymes. We must curl the perl.
    </content>
    <updated>2026-05-14T22:46:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsttyl48zggpugzz7kfzyuudgwfd6d8dncfukj6jla7tnm424zs8xszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdxr8kp</id>
    
      <title type="html">Did some adulting today. Took my parents-in-law into central ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsttyl48zggpugzz7kfzyuudgwfd6d8dncfukj6jla7tnm424zs8xszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdxr8kp" />
    <content type="html">
      Did some adulting today. Took my parents-in-law into central London for an eye hospital appointment. Same one my dad used to go to. Tired.
    </content>
    <updated>2026-05-14T17:41:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2jznt62fctydqpyg9024lykz03ta5j50vn4aa6qgsws7mnp83phszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzejewxa</id>
    
      <title type="html">Today in Tim meets old colleagues in random places, bumped into ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2jznt62fctydqpyg9024lykz03ta5j50vn4aa6qgsws7mnp83phszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzejewxa" />
    <content type="html">
      Today in Tim meets old colleagues in random places, bumped into one of our old red team and an old Portcullis customer at the ATT&amp;amp;CK event.
    </content>
    <updated>2026-05-13T22:28:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9za5ka0lc6uwmafyupvtc92n49d3nrs2yr8yq43ug8j0dhylvh9szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrq3t2n</id>
    
      <title type="html">Off to @npub1h8w…vyt6 MASIG.</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9za5ka0lc6uwmafyupvtc92n49d3nrs2yr8yq43ug8j0dhylvh9szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzrq3t2n" />
    <content type="html">
      Off to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h8wq6pmwwcxphdckcnm72unypz4u9u8p6vztg4ny07l8qpzawk0q2jvyt6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;MITRE ATT&amp;CK&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h8w…vyt6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; MASIG.
    </content>
    <updated>2026-05-13T09:47:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdnf3dxy5088zg9l07vw4a9h9gg8wnj8z7j9qnh5hwce4dll27szqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx2j66t</id>
    
      <title type="html">I wonder how many offensive folks have done IR for ILOVEYOU, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdnf3dxy5088zg9l07vw4a9h9gg8wnj8z7j9qnh5hwce4dll27szqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx2j66t" />
    <content type="html">
      I wonder how many offensive folks have done IR for ILOVEYOU, SFPs, an MPLs infrastructure, a mainframe, an entire bank and busses amongst other things.&lt;br/&gt;&lt;br/&gt;#purpleteam
    </content>
    <updated>2026-05-12T17:43:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg6q833df6s7mp492pkp5ze4r0wh0sycpcl9g2akrqy075ustgpwgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqmjlg9</id>
    
      <title type="html">For all the AI hype, I&amp;#39;m absolutely fascinated to see more ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg6q833df6s7mp492pkp5ze4r0wh0sycpcl9g2akrqy075ustgpwgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqmjlg9" />
    <content type="html">
      For all the AI hype, I&amp;#39;m absolutely fascinated to see more bug content that focusses on the mass of internal, commercial, compiled code that runs businesses. Most of the disclosures thus far appear to be for open source, where we should assume the models know the code, have seen the bug reports and have access to the patches but that&amp;#39;s really not the reality of &amp;#34;interesting&amp;#34; enterprise software.
    </content>
    <updated>2026-05-10T21:12:58Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2kppjecweegrfnzfllx0yyh02qmvzhy467uc9uhuuuzwqsrpkkvqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz20a0k5</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2kppjecweegrfnzfllx0yyh02qmvzhy467uc9uhuuuzwqsrpkkvqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz20a0k5" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://cset.georgetown.edu/article/chinas-pla-challenges-and-competitions/&#34;&gt;https://cset.georgetown.edu/article/chinas-pla-challenges-and-competitions/&lt;/a&gt; - analysing .cn PLA strategy&lt;br/&gt;* &lt;a href=&#34;https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/&#34;&gt;https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/&lt;/a&gt; - Locked Shield 2026 reporting&lt;br/&gt;* &lt;a href=&#34;https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board&#34;&gt;https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board&lt;/a&gt; - post-incident review is necessary, ya galah&lt;br/&gt;* &lt;a href=&#34;https://dukesecurity.ai/incidents&#34;&gt;https://dukesecurity.ai/incidents&lt;/a&gt; - SEC disclosed incidents&lt;br/&gt;* &lt;a href=&#34;https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference&#34;&gt;https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference&lt;/a&gt; - how .ru trains their spies on fiddling with elections&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2509.00462&#34;&gt;https://arxiv.org/abs/2509.00462&lt;/a&gt; - AI, stealing all the jobs&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2604.01637&#34;&gt;https://arxiv.org/abs/2604.01637&lt;/a&gt; - but first they need job specs&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring&#34;&gt;https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring&lt;/a&gt; - NCSC guidance on DFIR and protective monitoring&lt;br/&gt;* &lt;a href=&#34;https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/&#34;&gt;https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/&lt;/a&gt; - thought piece from Mozilla on Mythos&lt;br/&gt;* &lt;a href=&#34;https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities&#34;&gt;https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities&lt;/a&gt; - UK AI Security Institute review of GPT 5.5&lt;br/&gt;* &lt;a href=&#34;https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/&#34;&gt;https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/&lt;/a&gt; - behind the Mythos curtain with Mozilla&lt;br/&gt;* &lt;a href=&#34;https://uktl.org.uk/news-events/uktl-ncsc-and-ericsson-strengthen-the-security-of-uk-mobile-networks/&#34;&gt;https://uktl.org.uk/news-events/uktl-ncsc-and-ericsson-strengthen-the-security-of-uk-mobile-networks/&lt;/a&gt; - improving UK telco security&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html&#34;&gt;https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html&lt;/a&gt; - Trend write up on .cn attacks in Asia&lt;br/&gt;* &lt;a href=&#34;https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/&#34;&gt;https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/&lt;/a&gt; - TETRA abuse in the wild&lt;br/&gt;* &lt;a href=&#34;https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf&#34;&gt;https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf&lt;/a&gt; - new reporting on APT29&lt;br/&gt;* &lt;a href=&#34;https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf&#34;&gt;https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf&lt;/a&gt; - reporting on Tropic Trooper from BlackHat Asia 2026&lt;br/&gt;* &lt;a href=&#34;https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/&#34;&gt;https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/&lt;/a&gt; - attacks on CNI intensify&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://righteousit.com/2026/03/27/linux-forensic-scenario/&#34;&gt;https://righteousit.com/2026/03/27/linux-forensic-scenario/&lt;/a&gt; - [@hal_pomeranz](&lt;a href=&#34;https://infosec.exchange/@hal_pomeranz&#34;&gt;https://infosec.exchange/@hal_pomeranz&lt;/a&gt; )&amp;#39;s Linux investigation (there are a number of follow on posts)&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://retr0.zip/blog/cve-2026-31431-copy-fail.html&#34;&gt;https://retr0.zip/blog/cve-2026-31431-copy-fail.html&lt;/a&gt; - more on copy.fail&lt;br/&gt;* &lt;a href=&#34;https://seclists.org/oss-sec/2026/q2/332&#34;&gt;https://seclists.org/oss-sec/2026/q2/332&lt;/a&gt; - winning a race with Rust&lt;br/&gt;* &lt;a href=&#34;https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability&#34;&gt;https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability&lt;/a&gt; - more on the FreeBSD dhclient whoopsie&lt;br/&gt;* &lt;a href=&#34;https://copy.golf/&#34;&gt;https://copy.golf/&lt;/a&gt; - copy.fail.golf&lt;br/&gt;* &lt;a href=&#34;https://visit.suspect.network/reversing-adventures/inadvertent-injections&#34;&gt;https://visit.suspect.network/reversing-adventures/inadvertent-injections&lt;/a&gt; - accidentally injecting shells&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://fuzzinglabs.com/exploring-nvidia-linux-drivers-internals-basics-ioctls/&#34;&gt;https://fuzzinglabs.com/exploring-nvidia-linux-drivers-internals-basics-ioctls/&lt;/a&gt; - exploring NVIDIA&amp;#39;s LKM attack surface&lt;br/&gt;* &lt;a href=&#34;https://www.blackhillsinfosec.com/the-p-in-pam-is-for-persistence-linux-persistence-technique/&#34;&gt;https://www.blackhillsinfosec.com/the-p-in-pam-is-for-persistence-linux-persistence-technique/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1hrjc27jh8xnzzyqf86wq9u9lst4u88laghv40mgln0ks23wplulqjkmtaz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Black Hills Infosec&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1hrj…mtaz&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss persisting in PAM&lt;br/&gt;* &lt;a href=&#34;https://www.group-ib.com/blog/pluggable-authentication-module/&#34;&gt;https://www.group-ib.com/blog/pluggable-authentication-module/&lt;/a&gt; - why PAM matters&lt;br/&gt;* &lt;a href=&#34;https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/&#34;&gt;https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/&lt;/a&gt; - solutions to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1rcsevfzqfj6xzk0rajfaftsnq4f4wewydfyxd9u46jch4sxta60qjz7sw8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Trail of Bits&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1rcs…7sw8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s C challenges&lt;br/&gt;* &lt;a href=&#34;https://ipurple.team/2026/05/04/cross-session-activation/&#34;&gt;https://ipurple.team/2026/05/04/cross-session-activation/&lt;/a&gt; - cross session lateral moment in Windows with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub14pvealemcx8mjgc4mggenvhqzsh4nvg6pvdcr9y7ydkj20lkhe8qjpscte&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;netbiosX&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub14pv…scte&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://heyitsas.im/posts/drinking-llms/&#34;&gt;https://heyitsas.im/posts/drinking-llms/&lt;/a&gt; - bug hunting the Linux kernel with LLMs&lt;br/&gt;* &lt;a href=&#34;https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/&#34;&gt;https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/&lt;/a&gt; - fuzzing Microsoft RPC&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://labs.taszk.io/articles/post/tapocalypse/&#34;&gt;https://labs.taszk.io/articles/post/tapocalypse/&lt;/a&gt; - TP-Link whoppers&lt;br/&gt;* &lt;a href=&#34;https://tantosec.com/blog/2026/04/route-to-root-in-4g-industrial-router/&#34;&gt;https://tantosec.com/blog/2026/04/route-to-root-in-4g-industrial-router/&lt;/a&gt; - hacking a 4G router&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/&#34;&gt;https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1m7m3f90p4y6ff94jyh5swxx9de2m3anangf79md92n96a5m4dx5qqd2e7k&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Jan Wildeboer 😷:krulorange:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1m7m…2e7k&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s approach to beating copy.fail&lt;br/&gt;* &lt;a href=&#34;https://www.secwest.net/copyfail-mitigation&#34;&gt;https://www.secwest.net/copyfail-mitigation&lt;/a&gt; - more on copy.fail mitigations with &lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-problem&#34;&gt;https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-problem&lt;/a&gt; - be mindful of who you mix with&lt;br/&gt;* &lt;a href=&#34;https://di.day/en&#34;&gt;https://di.day/en&lt;/a&gt; - declare your independence&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-05-10T14:49:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfcy0x27cexu2ghdrwy9lzre9jr6gt6673n2ym9ht6j7xtsx6kj5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmzk2hf</id>
    
      <title type="html">Interesting Git repos of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfcy0x27cexu2ghdrwy9lzre9jr6gt6673n2ym9ht6j7xtsx6kj5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmzk2hf" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/center-for-threat-informed-defense/attack-flow&#34;&gt;https://github.com/center-for-threat-informed-defense/attack-flow&lt;/a&gt; - mapping ATT&amp;amp;CK flows&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/timb-machine-mirrors/ddamenova-IRQL.md&#34;&gt;https://github.com/timb-machine-mirrors/ddamenova-IRQL.md&lt;/a&gt; - KQL for IR&lt;br/&gt;* &lt;a href=&#34;https://github.com/ridgelinecyberdefence/vanguard&#34;&gt;https://github.com/ridgelinecyberdefence/vanguard&lt;/a&gt; - Go toolkit for IR&lt;br/&gt;* &lt;a href=&#34;https://github.com/SharonBrizinov/Holy-Grail-PCAP&#34;&gt;https://github.com/SharonBrizinov/Holy-Grail-PCAP&lt;/a&gt; - new food for Packet Monkey&lt;br/&gt;* &lt;a href=&#34;https://github.com/Nextron-Labs/surface-watch&#34;&gt;https://github.com/Nextron-Labs/surface-watch&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1582puw8r649g8m5fafge0yuzeuzw2apx3acxv8p2t8ypnjl2dkwqpgzvg8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Florian Roth&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1582…zvg8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s code to keep an eye on the front door&lt;br/&gt;* &lt;a href=&#34;https://github.com/keydet89/RegRipper3.0&#34;&gt;https://github.com/keydet89/RegRipper3.0&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub12pxczes9wt2dleyg5vrq62cypxuvsecj8p766xzk5r0fjxqp0xxqq69x9m&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;keydet89&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub12px…9x9m&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s seminal IR toolkit in Perl&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/V4bel/dirtyfrag&#34;&gt;https://github.com/V4bel/dirtyfrag&lt;/a&gt; - more Linux sadness&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/azqzazq1/SunnyDayBPF&#34;&gt;https://github.com/azqzazq1/SunnyDayBPF&lt;/a&gt; - imagine that, a kernel that lies&lt;br/&gt;* &lt;a href=&#34;https://github.com/BlackSnufkin/LitterBox&#34;&gt;https://github.com/BlackSnufkin/LitterBox&lt;/a&gt; - red teamer&amp;#39;s sandbox&lt;br/&gt;* &lt;a href=&#34;https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper&#34;&gt;https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper&lt;/a&gt; - dump Edge passwords from memory&lt;br/&gt;* &lt;a href=&#34;https://github.com/her3ticAVI/PAMSkeletonKey&#34;&gt;https://github.com/her3ticAVI/PAMSkeletonKey&lt;/a&gt; - a skeleton key for PAM&lt;br/&gt;* &lt;a href=&#34;https://github.com/segmentati0nf4ult/linux-pam-backdoor&#34;&gt;https://github.com/segmentati0nf4ult/linux-pam-backdoor&lt;/a&gt; - an earlier version of the same code&lt;br/&gt;* &lt;a href=&#34;https://github.com/Kudaes/Puzzle&#34;&gt;https://github.com/Kudaes/Puzzle&lt;/a&gt; - abusing Windows minifilters&lt;br/&gt;* &lt;a href=&#34;https://github.com/diemoeve/oxide&#34;&gt;https://github.com/diemoeve/oxide&lt;/a&gt; - a new C2 framework&lt;br/&gt;* &lt;a href=&#34;https://github.com/TwoSevenOneT/DefenderWrite&#34;&gt;https://github.com/TwoSevenOneT/DefenderWrite&lt;/a&gt; - enumerate AV whitelisted executables for LPE with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dt0tyzp0rfct2wqlhlqxmzq4ngn2zcvjkgkm2jags0sukucq039s36th85&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Two Seven One Three&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dt0…th85&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/wgnet/wg.copyfail.patch&#34;&gt;https://github.com/wgnet/wg.copyfail.patch&lt;/a&gt; - a nice little eBPF patch for copy.fail&lt;br/&gt;* &lt;a href=&#34;https://github.com/atgreen/block-copyfail&#34;&gt;https://github.com/atgreen/block-copyfail&lt;/a&gt; - another eBPF approach to copy.fail from [@atgreen](&lt;a href=&#34;https://hachyderm.io/@atgreen&#34;&gt;https://hachyderm.io/@atgreen&lt;/a&gt; ) 🤖&lt;br/&gt;&lt;br/&gt;#security, #research, #code
    </content>
    <updated>2026-05-10T13:42:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy6xnuwga5j9tnzsgfn8hhmxzky3s83tglprrzvjmfcgud6lrm3dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5yyusz</id>
    
      <title>Nostr event nevent1qqsy6xnuwga5j9tnzsgfn8hhmxzky3s83tglprrzvjmfcgud6lrm3dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5yyusz</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy6xnuwga5j9tnzsgfn8hhmxzky3s83tglprrzvjmfcgud6lrm3dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz5yyusz" />
    <content type="html">
      Citations are nice. Thank you anon.
    </content>
    <updated>2026-05-09T19:25:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqaukdrxthdx7qm92p7tulgxujwqt5l6npquw2kgakf0jtlwgdzrqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz0slk5</id>
    
      <title type="html">Long old week but 5 happy customers, two commuting to renewals ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqaukdrxthdx7qm92p7tulgxujwqt5l6npquw2kgakf0jtlwgdzrqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz0slk5" />
    <content type="html">
      Long old week but 5 happy customers, two commuting to renewals makes it all worthwhile. I shall sleep well tonight.
    </content>
    <updated>2026-05-07T19:41:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8zsnshx8n6s70cuq9a5e5ls36q0axetvks8hasnqwxnwyp8whksszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcfgyqm</id>
    
      <title type="html">Provided genuine and nuanced feedback on AI slop on AI slop. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8zsnshx8n6s70cuq9a5e5ls36q0axetvks8hasnqwxnwyp8whksszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcfgyqm" />
    <content type="html">
      Provided genuine and nuanced feedback on AI slop on AI slop. Comments all deleted and article published. That&amp;#39;ll teach me to spend time making suggestions to improve an article.
    </content>
    <updated>2026-05-06T19:15:19Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0quesy898v7fmffdf7x287thqzdwthzs4y5whr69l5n6dheync6czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs7d7nl</id>
    
      <title type="html">Sidebar: Please don&amp;#39;t get your pet to paraphrase me and then ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0quesy898v7fmffdf7x287thqzdwthzs4y5whr69l5n6dheync6czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs7d7nl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsweg58mrcvt9jcnqnut9fxlfvfv8lv6nluf0mhe0qkudaalgq6ksgyqynqp&#39;&gt;nevent1q…ynqp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Sidebar: Please don&amp;#39;t get your pet to paraphrase me and then attribute the work to me.
    </content>
    <updated>2026-05-06T16:18:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsweg58mrcvt9jcnqnut9fxlfvfv8lv6nluf0mhe0qkudaalgq6ksgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyykjkl</id>
    
      <title type="html">Stumbled into a channel where everyone is replacing themselves ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsweg58mrcvt9jcnqnut9fxlfvfv8lv6nluf0mhe0qkudaalgq6ksgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyykjkl" />
    <content type="html">
      Stumbled into a channel where everyone is replacing themselves with their AI pets and well, if you&amp;#39;re the kind that needs an agent to do anything then no wonder you&amp;#39;re having trouble installing an agent...
    </content>
    <updated>2026-05-06T16:17:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr6wdesr04u2am36mmr5x8xsykp6jk72gnh0l5hk8ecd5v76guwcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvyjuzk</id>
    
      <title type="html">The statement &amp;#34;lies, lies and statistics&amp;#34; could have been ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr6wdesr04u2am36mmr5x8xsykp6jk72gnh0l5hk8ecd5v76guwcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvyjuzk" />
    <content type="html">
      The statement &amp;#34;lies, lies and statistics&amp;#34; could have been written by an AI, and now thanks to LLM, it will be.
    </content>
    <updated>2026-05-05T12:42:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf29dz5gzg65q7ghp84frtlenl6v452qk0m0rqyza07p30mnve2gszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqvnptp</id>
    
      <title type="html">Congratulations to Canonical on poor life choices: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf29dz5gzg65q7ghp84frtlenl6v452qk0m0rqyza07p30mnve2gszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzqvnptp" />
    <content type="html">
      Congratulations to Canonical on poor life choices:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://seclists.org/oss-sec/2026/q2/332&#34;&gt;https://seclists.org/oss-sec/2026/q2/332&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #non-GNUcoreutils
    </content>
    <updated>2026-05-04T18:55:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvzs4n8g4m6qmyfnhk39adgngjn2sxcx8ptemllmlzphjgrs60s5gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz7c3ns8</id>
    
      <title type="html">A little contribution: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvzs4n8g4m6qmyfnhk39adgngjn2sxcx8ptemllmlzphjgrs60s5gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz7c3ns8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx8vzdcx42767f6ggqaklkqvw7y4za4s9z3f70gvs55g8suemvtkg7uhg3u&#39;&gt;nevent1q…hg3u&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A little contribution: &lt;a href=&#34;https://github.com/timb-machine/presentations/blob/main/A%20rising%20tide%20lifts%20all%20ships%20-%20Cyber%20security%20culture%2C%20competence%20and%20community.pdf&#34;&gt;https://github.com/timb-machine/presentations/blob/main/A%20rising%20tide%20lifts%20all%20ships%20-%20Cyber%20security%20culture%2C%20competence%20and%20community.pdf&lt;/a&gt;
    </content>
    <updated>2026-05-04T12:04:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfxwcjv8qpznztfpe37xzd2hxvw4yx2h6uu7gngta80u5ed8nkpfszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfxsg2v</id>
    
      <title type="html">Got bored so started submitting rules to @npub1582…zvg8&amp;#39; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfxwcjv8qpznztfpe37xzd2hxvw4yx2h6uu7gngta80u5ed8nkpfszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfxsg2v" />
    <content type="html">
      Got bored so started submitting rules to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1582puw8r649g8m5fafge0yuzeuzw2apx3acxv8p2t8ypnjl2dkwqpgzvg8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Florian Roth&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1582…zvg8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39; auditd ruleset...
    </content>
    <updated>2026-05-04T11:07:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst970ghk6kyunfn8qhnganj6eu8yu7mv2whw4uevnj55gtjjgvk7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzevt4ny</id>
    
      <title type="html">Tea.</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst970ghk6kyunfn8qhnganj6eu8yu7mv2whw4uevnj55gtjjgvk7szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzevt4ny" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxwh8syz7x3rznps5g0w2rm8fwq2jxwd79m89sytmnrd07tqfwx0gler8x0&#39;&gt;nevent1q…r8x0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Tea.
    </content>
    <updated>2026-05-03T07:04:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxwh8syz7x3rznps5g0w2rm8fwq2jxwd79m89sytmnrd07tqfwx0gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu7jfhn</id>
    
      <title>Nostr event nevent1qqsxwh8syz7x3rznps5g0w2rm8fwq2jxwd79m89sytmnrd07tqfwx0gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu7jfhn</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxwh8syz7x3rznps5g0w2rm8fwq2jxwd79m89sytmnrd07tqfwx0gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzu7jfhn" />
    <content type="html">
      Toast.
    </content>
    <updated>2026-05-03T06:38:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvze07rpay73pf6mrqa38485j273tymfwyu5s7gapdzpu2aekl8ngzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjkwl0p</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvze07rpay73pf6mrqa38485j273tymfwyu5s7gapdzpu2aekl8ngzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzjkwl0p" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.kpmgcri.com/insights/calculating-the-impact-of-a-cyber-attack-on-critical-infrastructure&#34;&gt;https://www.kpmgcri.com/insights/calculating-the-impact-of-a-cyber-attack-on-critical-infrastructure&lt;/a&gt; - KPMG discuss how to calculate the cost of CNI impact&lt;br/&gt;* &lt;a href=&#34;https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/&#34;&gt;https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1x595mggkh492xtl25nfk5j4xnd2yuscfgmp2n7s6csanxsn99vlq5egect&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Terence Eden&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1x59…gect&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discusses the -ve impact of LLMs on NHS open source strategy&lt;br/&gt;* &lt;a href=&#34;https://www.kcl.ac.uk/building-nhs-resilience-to-ransomware-1&#34;&gt;https://www.kcl.ac.uk/building-nhs-resilience-to-ransomware-1&lt;/a&gt; - a study in national health resilience, not to disease but ransomware&lt;br/&gt;* &lt;a href=&#34;https://www.rusi.org/explore-our-research/publications/cyber-effects-perspectives/cyber-exercises-and-capture-flag-competitions-uk-policy-tools&#34;&gt;https://www.rusi.org/explore-our-research/publications/cyber-effects-perspectives/cyber-exercises-and-capture-flag-competitions-uk-policy-tools&lt;/a&gt; - with all this ransomware, why cyber exercises are still helpful&lt;br/&gt;* &lt;a href=&#34;https://insinuator.net/2026/04/when-paradigms-are-shifting-infosec-in-the-age-of-ai/&#34;&gt;https://insinuator.net/2026/04/when-paradigms-are-shifting-infosec-in-the-age-of-ai/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1x7qqtvaaa989vudgdf5nvvyhatr2qxfvfygy43m8thnvghuzdspqu8f3q0&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Insinuator&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1x7q…f3q0&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; in the days of LLM&lt;br/&gt;* &lt;a href=&#34;https://www.provos.org/p/finding-zero-days-with-any-model/&#34;&gt;https://www.provos.org/p/finding-zero-days-with-any-model/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1mc0z05l9ujnszhuag0jv5d82h8pxxhk75gm28pkchsutt02u5k6s6ew5tc&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Niels Provos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1mc0…w5tc&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; chips in on whether it&amp;#39;s the models or the automation&lt;br/&gt;* &lt;a href=&#34;https://www.technologyreview.com/2026/04/27/1136322/rebuilding-the-data-stack-for-ai/&#34;&gt;https://www.technologyreview.com/2026/04/27/1136322/rebuilding-the-data-stack-for-ai/&lt;/a&gt; - MIT Technology Review gives a take on how to rearchitect for AI&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.rfc-editor.org/rfc/rfc3631.html&#34;&gt;https://www.rfc-editor.org/rfc/rfc3631.html&lt;/a&gt; - Internet-facing security controls&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://medium.com/mitre-attack/attack-v19-ff329cb65d66&#34;&gt;https://medium.com/mitre-attack/attack-v19-ff329cb65d66&lt;/a&gt; - ATT&amp;amp;CK v19 is out&lt;br/&gt;* &lt;a href=&#34;https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems&#34;&gt;https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems&lt;/a&gt; - an attack on the .il water system?&lt;br/&gt;* &lt;a href=&#34;https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/&#34;&gt;https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/&lt;/a&gt; - SentinelOne discuss the pre-stuxnet years&lt;br/&gt;* &lt;a href=&#34;https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow&#34;&gt;https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow&lt;/a&gt; - .cn reporting on Sandworm&lt;br/&gt;* &lt;a href=&#34;https://blog.talosintelligence.com/uat-4356-firestarter/&#34;&gt;https://blog.talosintelligence.com/uat-4356-firestarter/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xkd2rp780746wm90u3nshlvzqfhcyhjw7p08pz0wgdpzl3he8gvqlscc62&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Cisco Talos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xkd…cc62&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; report on FIRESTARTER&lt;br/&gt;* &lt;a href=&#34;https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf&#34;&gt;https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf&lt;/a&gt; - joint NCSC/CISA write up on FIRESTARTER&lt;br/&gt;* &lt;a href=&#34;https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/&#34;&gt;https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub12h8985zt0em44drkckuhxwwh2skslggevkwyctj6g0u8uccdgxws0cac3t&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Citizen Lab&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub12h8…ac3t&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discuss global telecom breaches&lt;br/&gt;* &lt;a href=&#34;https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks&#34;&gt;https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks&lt;/a&gt; - SIM farms and how they work&lt;br/&gt;* &lt;a href=&#34;https://github.com/search?q=knock_functions.sh&amp;amp;type=code&#34;&gt;https://github.com/search?q=knock_functions.sh&amp;amp;type=code&lt;/a&gt; - this is fine...&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://x.com/westonlwalker/status/2049931249180119321&#34;&gt;https://x.com/westonlwalker/status/2049931249180119321&lt;/a&gt; - auditd rules for copy.fail&lt;br/&gt;* &lt;a href=&#34;https://scythe.io/scythe-labs/what-your-rdp-sessions-leave-behind&#34;&gt;https://scythe.io/scythe-labs/what-your-rdp-sessions-leave-behind&lt;/a&gt; - exploring RDP&amp;#39;s stains&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/blogs/could-your-choice-of-metrics-be-harming-your-soc&#34;&gt;https://www.ncsc.gov.uk/blogs/could-your-choice-of-metrics-be-harming-your-soc&lt;/a&gt; - NCSC discuss useful KPIs for a SOC&lt;br/&gt;* &lt;a href=&#34;https://www.slideshare.net/slideshow/first-cti-2026-evaluating-threat-intelligence-through-velocity/287191850&#34;&gt;https://www.slideshare.net/slideshow/first-cti-2026-evaluating-threat-intelligence-through-velocity/287191850&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1am5v43wmu38j5a5ekqsx8hca2g7ez5t264eew8tj57ncvxn8h07szsd84n&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Joe Słowik&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1am5…d84n&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discusses threat intel speed in defence&lt;br/&gt;* &lt;a href=&#34;https://extsentry.github.io/#dashboard&#34;&gt;https://extsentry.github.io/#dashboard&lt;/a&gt; - can you and should you trust browser agents&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://copy.fail/&#34;&gt;https://copy.fail/&lt;/a&gt; - reliable LPE for many Linux releases&lt;br/&gt;* &lt;a href=&#34;https://xint.io/blog/copy-fail-linux-distributions&#34;&gt;https://xint.io/blog/copy-fail-linux-distributions&lt;/a&gt; - blog post with the copy.fail details&lt;br/&gt;* &lt;a href=&#34;https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854&#34;&gt;https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854&lt;/a&gt; - Wiz found a nice parameter pollution bug in GitHub&lt;br/&gt;* &lt;a href=&#34;https://shittrix.moksha.dk/&#34;&gt;https://shittrix.moksha.dk/&lt;/a&gt; - much Citrix sadness&lt;br/&gt;* &lt;a href=&#34;https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc&#34;&gt;https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc&lt;/a&gt; - dhclient oopsie in FreeBSD&lt;br/&gt;* &lt;a href=&#34;https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc&#34;&gt;https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc&lt;/a&gt; - poisoning FreeBSD&amp;#39;s argv[][] for LPE oopsie&lt;br/&gt;* &lt;a href=&#34;https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not&#34;&gt;https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not&lt;/a&gt; - abusing a pty for fun and oopsies&lt;br/&gt;* &lt;a href=&#34;https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html&#34;&gt;https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html&lt;/a&gt; - more fun Linux whoopses&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://windows-internals.com/goodbye-secure-pool-hello-kdp-pool/&#34;&gt;https://windows-internals.com/goodbye-secure-pool-hello-kdp-pool/&lt;/a&gt; - changes afoot in Windows kernel land from [@yarden_shafir](&lt;a href=&#34;https://infosec.exchange/@yarden_shafir&#34;&gt;https://infosec.exchange/@yarden_shafir&lt;/a&gt; )&lt;br/&gt;* &lt;a href=&#34;https://securelist.com/phantomrpc-rpc-vulnerability/119428/&#34;&gt;https://securelist.com/phantomrpc-rpc-vulnerability/119428/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1gerjzuupnt96mq0t5vt9vw3hj9xqyj26fqd9u4lcx9vrxkeuyygqcu6hxz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Kaspersky&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ger…6hxz&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, on new ways to beat a dead horse&lt;br/&gt;* &lt;a href=&#34;https://ghostbyt3.github.io/blog/nday-research-ai&#34;&gt;https://ghostbyt3.github.io/blog/nday-research-ai&lt;/a&gt; - hunting for n-days&lt;br/&gt;* &lt;a href=&#34;https://blog.zsec.uk/bullyingllms/&#34;&gt;https://blog.zsec.uk/bullyingllms/&lt;/a&gt; - [@zephrfish](&lt;a href=&#34;https://bladerunner.social/@zephrfish&#34;&gt;https://bladerunner.social/@zephrfish&lt;/a&gt; ) talks through his approach to abusing LLMs&lt;br/&gt;* &lt;a href=&#34;https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/&#34;&gt;https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/&lt;/a&gt; - more rotten apples, this time from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xkd2rp780746wm90u3nshlvzqfhcyhjw7p08pz0wgdpzl3he8gvqlscc62&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Cisco Talos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xkd…cc62&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://alexreed.srht.site/blog/agent-security-audit.html&#34;&gt;https://alexreed.srht.site/blog/agent-security-audit.html&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1w8vlqgwvecwpcsv05hn7a94pu7fqy8wxehhkuphq6fh88sqr0uusvzympw&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Alex Reed&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1w8v…ympw&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; looks at how to audit and harden your agent&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://prism-break.org/en/all/&#34;&gt;https://prism-break.org/en/all/&lt;/a&gt; - escaping the US-led ecosystem&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-05-02T21:48:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqa2t256acwwwngsrtld4w92d7y8qsfagffyagqjj9737uk7thx6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxad3mn</id>
    
      <title type="html">Interesting Git repos of the week: Detection: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqa2t256acwwwngsrtld4w92d7y8qsfagffyagqjj9737uk7thx6gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzxad3mn" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/gadievron/honeyslop&#34;&gt;https://github.com/gadievron/honeyslop&lt;/a&gt; - a side bar to RAPTOR, a vulndev slop detector from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1h9hd4daq5hu5h0gs8wv2ql5pm6hx8vr5h074k34vs7s8dx8rt2cs9uta2c&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Gadi Evron&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1h9h…ta2c&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/Nehboro/nehboro&#34;&gt;https://github.com/Nehboro/nehboro&lt;/a&gt; - a Chrome extension to help protect you from phishing scams&lt;br/&gt;* &lt;a href=&#34;https://github.com/trustedsec/SysmonCommunityGuide&#34;&gt;https://github.com/trustedsec/SysmonCommunityGuide&lt;/a&gt; - TrustedSec dropped guides for Sysmon&lt;br/&gt;* &lt;a href=&#34;https://github.com/JPCERTCC/LogonTracer&#34;&gt;https://github.com/JPCERTCC/LogonTracer&lt;/a&gt; - watch out for unexpected logins with JPCERT&lt;br/&gt;* &lt;a href=&#34;https://github.com/persistent-security/month-of-bypasses&#34;&gt;https://github.com/persistent-security/month-of-bypasses&lt;/a&gt; - a month of detection engineering tips and tricks&lt;br/&gt;* &lt;a href=&#34;https://github.com/sjzasada/agentflash&#34;&gt;https://github.com/sjzasada/agentflash&lt;/a&gt; - my old uni house mate has written a tool to keep an eye on Claude&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/theori-io/copy-fail-CVE-2026-31431&#34;&gt;https://github.com/theori-io/copy-fail-CVE-2026-31431&lt;/a&gt; - copy.fail \o/&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/CyberStrikeus/CyberStrike&#34;&gt;https://github.com/CyberStrikeus/CyberStrike&lt;/a&gt; - sloppy pen testing 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/SnailSploit/Claude-Red&#34;&gt;https://github.com/SnailSploit/Claude-Red&lt;/a&gt; - another agentic pen tester 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/PurpleAILAB/Decepticon&#34;&gt;https://github.com/PurpleAILAB/Decepticon&lt;/a&gt; - rise of the bots 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/hackerschoice/team-teso&#34;&gt;https://github.com/hackerschoice/team-teso&lt;/a&gt; - courtesy of &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1a0syl0wxctexh7u3m0ek4ycsuaktwfjnynjrzn9zyjjv4hn0eknqasdmkd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Hacker‘s Choice&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1a0s…dmkd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, an archive of TESO&lt;br/&gt;* &lt;a href=&#34;https://github.com/BishopFox/cirro&#34;&gt;https://github.com/BishopFox/cirro&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1chl32xd0d060zgty0qdznslp9srm4ryt5w93zta742w9p0z3x83qkxp3zh&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Bishop Fox&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1chl…p3zh&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; created Cirro to map clouds 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/thomasdullien/vulpine&#34;&gt;https://github.com/thomasdullien/vulpine&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1cj7tkar9se9xgkq0wdvv5w8sagmrgvcpak2dgdzk2dey2yly85cqgenq3s&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;HalvarFlake&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1cj7…nq3s&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; dabbles in AI bug hunting and vulndev&lt;br/&gt;* &lt;a href=&#34;https://github.com/boostsecurityio/smokedmeat&#34;&gt;https://github.com/boostsecurityio/smokedmeat&lt;/a&gt; - smoked meat attacks CICD pipelines for hot red team action&lt;br/&gt;* &lt;a href=&#34;https://github.com/mandiant/gopacket&#34;&gt;https://github.com/mandiant/gopacket&lt;/a&gt; - Mandiant ported Impacket to Go&lt;br/&gt;* &lt;a href=&#34;https://github.com/trailofbits/trailmark&#34;&gt;https://github.com/trailofbits/trailmark&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1rcsevfzqfj6xzk0rajfaftsnq4f4wewydfyxd9u46jch4sxta60qjz7sw8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Trail of Bits&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1rcs…7sw8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s Trailmark graphs code 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/sailay1996/vss-fr2system&#34;&gt;https://github.com/sailay1996/vss-fr2system&lt;/a&gt; - arbitrary reads to SYSTEM \o/&lt;br/&gt;* &lt;a href=&#34;https://github.com/asset-group/Sni5Gect-5GNR-sniffing-and-exploitation&#34;&gt;https://github.com/asset-group/Sni5Gect-5GNR-sniffing-and-exploitation&lt;/a&gt; - attacking 5G for sniffs and giggles&lt;br/&gt;* &lt;a href=&#34;https://github.com/ANSSI-FR/bmc-tools&#34;&gt;https://github.com/ANSSI-FR/bmc-tools&lt;/a&gt; - ANSSI parses your RDP screenshots&lt;br/&gt;* &lt;a href=&#34;https://github.com/BSI-Bund/RdpCacheStitcher&#34;&gt;https://github.com/BSI-Bund/RdpCacheStitcher&lt;/a&gt; - BSI stitches them together&lt;br/&gt;* &lt;a href=&#34;https://github.com/califio/publications&#34;&gt;https://github.com/califio/publications&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dw7uv82yqyz0g54ufjqrqm84u3zdlf7q5wvn59c2l69ke4rx3npqzu3cdf&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;thaidn&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dw7…3cdf&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; and friends do interesting things 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/jedireza/reserved-subdomains&#34;&gt;https://github.com/jedireza/reserved-subdomains&lt;/a&gt; - what subdomains are reserved?&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/sektioneins/ovpncc&#34;&gt;https://github.com/sektioneins/ovpncc&lt;/a&gt; - One of SektionEins&amp;#39;s various config checking tools, this onefor OpenVPN&lt;br/&gt;* &lt;a href=&#34;https://github.com/HarmonicSecurity/claudit-sec&#34;&gt;https://github.com/HarmonicSecurity/claudit-sec&lt;/a&gt; - audit your Claude Desktop posture&lt;br/&gt;&lt;br/&gt;Cryptography:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/nitram2342/bruteforce-crc&#34;&gt;https://github.com/nitram2342/bruteforce-crc&lt;/a&gt; - crunching through CRC32&lt;br/&gt;&lt;br/&gt;Data:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/op7ic/SwarmMaker&#34;&gt;https://github.com/op7ic/SwarmMaker&lt;/a&gt; - my good friend opt7ic drops a new tool to build LLM skills&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/moshix/BRICKS_TS&#34;&gt;https://github.com/moshix/BRICKS_TS&lt;/a&gt; - mainframe code&lt;br/&gt;&lt;br/&gt;#security, #research, #code
    </content>
    <updated>2026-05-02T18:56:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszc9wsyrwref99037q56cwxw8cc0vxlrptuap2n0z0e53laz5d0uqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzpgkacd</id>
    
      <title type="html">Unauthorised maths. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszc9wsyrwref99037q56cwxw8cc0vxlrptuap2n0z0e53laz5d0uqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzpgkacd" />
    <content type="html">
      Unauthorised maths.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/505/975/782/999/185/original/e145ceb77f0dbfb5.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-02T16:47:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspy0mdvnqp0ec6r0unjxak07hqcgdrcqx6gw6pa5wfc0g5a4n9gugzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztujhyq</id>
    
      <title type="html">&amp;#34;We&amp;#39;re all doomed. GlassWing can read source code and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspy0mdvnqp0ec6r0unjxak07hqcgdrcqx6gw6pa5wfc0g5a4n9gugzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztujhyq" />
    <content type="html">
      &amp;#34;We&amp;#39;re all doomed. GlassWing can read source code and find vulnerabilities.&amp;#34;&lt;br/&gt;&lt;br/&gt;If the adversary has access to the source code, then they already somewhat could. They will still have to sort the wheat from the chaff no matter if they&amp;#39;re using grep or some new super intelligence because not every bug ends up being exploitable. Also, how many controls have they subverted to get there...
    </content>
    <updated>2026-05-01T18:18:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsym7v3x4hy2h57kzd4zeu47fks4vr4mpkzdj7qj7rvy4cwh7wkn5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz5dapa</id>
    
      <title type="html">&amp;#34;One of the things that upsets me about AI is that it ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsym7v3x4hy2h57kzd4zeu47fks4vr4mpkzdj7qj7rvy4cwh7wkn5czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzz5dapa" />
    <content type="html">
      &amp;#34;One of the things that upsets me about AI is that it doesn&amp;#39;t think. It just keeps pushing existing ideas.&amp;#34;&lt;br/&gt;&lt;br/&gt;Yeh, no shit sherlock.
    </content>
    <updated>2026-05-01T18:15:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgzl8mgevu3pw04q5t55wajrpzaspn5wjyq6n9pzkdks6mpqzau9szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt72t63</id>
    
      <title type="html">Copy fail is vibe-arg&amp;#39;ing at its finest... https://copy.fail/ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgzl8mgevu3pw04q5t55wajrpzaspn5wjyq6n9pzkdks6mpqzau9szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzt72t63" />
    <content type="html">
      Copy fail is vibe-arg&amp;#39;ing at its finest...&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://copy.fail/&#34;&gt;https://copy.fail/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #linux
    </content>
    <updated>2026-04-30T19:58:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyt3gr9pkt4gzpxmaz90n7qlhaujcdeca8jlzwxgcf8j8nf4e7mkczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyq44ae</id>
    
      <title type="html">Given that BlueSky 302&amp;#39;s &amp;lt;username&amp;gt;.bsky.social to the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyt3gr9pkt4gzpxmaz90n7qlhaujcdeca8jlzwxgcf8j8nf4e7mkczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyq44ae" />
    <content type="html">
      Given that BlueSky 302&amp;#39;s &amp;lt;username&amp;gt;.bsky.social to the user&amp;#39;s profile with content that they control, I wonder what they do to filter username against reserved DNS subdomains...
    </content>
    <updated>2026-04-29T09:43:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq0nqq6p8d3v7fcvlp75gsvhy0nwh0ywenw6lez08ksl3stj9pylgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz77s9xs</id>
    
      <title type="html">I might rewrite the logic at some point, kinda feels like the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq0nqq6p8d3v7fcvlp75gsvhy0nwh0ywenw6lez08ksl3stj9pylgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz77s9xs" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg9q8r4gcphm5xcj6y3hxw5gy76rj87ykeyuq3v39z6pr2afg78acm6m0kd&#39;&gt;nevent1q…m0kd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I might rewrite the logic at some point, kinda feels like the data model has changed sufficiently that my parsing logic might need some love.
    </content>
    <updated>2026-04-29T08:15:35Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg9q8r4gcphm5xcj6y3hxw5gy76rj87ykeyuq3v39z6pr2afg78aczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs2apnr</id>
    
      <title type="html">Running threat-crank to update ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg9q8r4gcphm5xcj6y3hxw5gy76rj87ykeyuq3v39z6pr2afg78aczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzs2apnr" />
    <content type="html">
      Running threat-crank to update &lt;a href=&#34;https://github.com/timb-machine/attack-ti&#34;&gt;https://github.com/timb-machine/attack-ti&lt;/a&gt; with v19 data.&lt;br/&gt;&lt;br/&gt;#threatmodelling
    </content>
    <updated>2026-04-29T08:13:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2uf4sth88m0gz455yzxunhs4r9t5egkw0s8tascqrnsxf073q8gqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvlwspy</id>
    
      <title type="html">This is with respect to &amp;#34;traceroute 2.1.2 - MPLS Extension ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2uf4sth88m0gz455yzxunhs4r9t5egkw0s8tascqrnsxf073q8gqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvlwspy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyz9g8cz09vfjmug94ev5e682h2cqtn0m0p69sqvtajq853ycqgpsqgxh2c&#39;&gt;nevent1q…xh2c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This is with respect to &amp;#34;traceroute 2.1.2 - MPLS Extension Out-of-Bounds Read&amp;#34;. Feels sloppily written...
    </content>
    <updated>2026-04-29T07:35:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyz9g8cz09vfjmug94ev5e682h2cqtn0m0p69sqvtajq853ycqgpszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztpedhw</id>
    
      <title type="html">Today in CVSS questions: CVSS v3.1 Score: 5.9 (Medium) — ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyz9g8cz09vfjmug94ev5e682h2cqtn0m0p69sqvtajq853ycqgpszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dztpedhw" />
    <content type="html">
      Today in CVSS questions:&lt;br/&gt;&lt;br/&gt;CVSS v3.1 Score: 5.9 (Medium) — AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N&lt;br/&gt;Attack Vector: Network (on-path / rogue router)&lt;br/&gt;&lt;br/&gt;Do you mean AV:A?
    </content>
    <updated>2026-04-29T07:22:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs278j9a93hu038zas4yd4kkdzzzxss3dkufxzq97sz2qdvx5pzr8czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyvky8v</id>
    
      <title type="html">@npub1ysw…uzpe has just given me bad dreams, uttering ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs278j9a93hu038zas4yd4kkdzzzxss3dkufxzq97sz2qdvx5pzr8czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyvky8v" />
    <content type="html">
      &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ysw7nqfvcf6l7w6n828j8xnsjsxz2lcxmk3fu536ucm2z963mv3qhduzpe&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;lcamtuf :verified: :verified: :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ysw…uzpe&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; has just given me bad dreams, uttering &amp;#34;systemd-openclawd&amp;#34;...&lt;br/&gt;&lt;br/&gt;*shudder*
    </content>
    <updated>2026-04-28T23:11:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvua4mhsd7c3tqh4439qfgx5tjvateveqqpdcdd307xetgw0gjzhszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdl6tdf</id>
    
      <title type="html">Full write up here: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvua4mhsd7c3tqh4439qfgx5tjvateveqqpdcdd307xetgw0gjzhszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdl6tdf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst88ctusg6y3tuww5s8lnzl6el26pz8vurh29y6akr4kgdzvxnzcce0amqf&#39;&gt;nevent1q…amqf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Full write up here: &lt;a href=&#34;https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854&#34;&gt;https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854&lt;/a&gt;
    </content>
    <updated>2026-04-28T19:43:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyn2vhdarejdtgnng497dfch9579eqezey6yr02kh5c3n75d96p4szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcnmy9q</id>
    
      <title type="html">Fun with Citrix: https://shittrix.moksha.dk/ #threatintel, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyn2vhdarejdtgnng497dfch9579eqezey6yr02kh5c3n75d96p4szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcnmy9q" />
    <content type="html">
      Fun with Citrix:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://shittrix.moksha.dk/&#34;&gt;https://shittrix.moksha.dk/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #citrix
    </content>
    <updated>2026-04-28T19:42:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8x8atsdggg5djawuyh2j64xkzvral38ennsxe8ck6u40uy86wr4gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9glay3</id>
    
      <title type="html">We welcome ATT&amp;amp;CK v19: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8x8atsdggg5djawuyh2j64xkzvral38ennsxe8ck6u40uy86wr4gzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz9glay3" />
    <content type="html">
      We welcome ATT&amp;amp;CK v19:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://attack.mitre.org/resources/updates/updates-april-2026/&#34;&gt;https://attack.mitre.org/resources/updates/updates-april-2026/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Blog post here:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://medium.com/mitre-attack/attack-v19-ff329cb65d66&#34;&gt;https://medium.com/mitre-attack/attack-v19-ff329cb65d66&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#redteam, #blueteam, #threatintel, #att&amp;amp;ck
    </content>
    <updated>2026-04-28T19:01:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst88ctusg6y3tuww5s8lnzl6el26pz8vurh29y6akr4kgdzvxnzcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzeerdav</id>
    
      <title type="html">Hard ouch: https://x.com/sagitz_/status/2049153195243372569 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst88ctusg6y3tuww5s8lnzl6el26pz8vurh29y6akr4kgdzvxnzcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzeerdav" />
    <content type="html">
      Hard ouch:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/sagitz_/status/2049153195243372569&#34;&gt;https://x.com/sagitz_/status/2049153195243372569&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #github
    </content>
    <updated>2026-04-28T18:54:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2rch4224v2ql6gcg6pfwd8eeemnjff9exr3chm9s6gwgtjnhw3eqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkr76p</id>
    
      <title type="html">I do wish Reform would stop posting their recycling through my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2rch4224v2ql6gcg6pfwd8eeemnjff9exr3chm9s6gwgtjnhw3eqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkr76p" />
    <content type="html">
      I do wish Reform would stop posting their recycling through my letter box.
    </content>
    <updated>2026-04-28T18:43:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrgs2xxymysyq6mzrts87alumrnxcd7nwhc8m28teh8wvrhmk92lczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmsr2ln</id>
    
      <title type="html">Discuss: x isn&amp;#39;t a security boundary because ... (where x is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrgs2xxymysyq6mzrts87alumrnxcd7nwhc8m28teh8wvrhmk92lczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzmsr2ln" />
    <content type="html">
      Discuss: x isn&amp;#39;t a security boundary because ... (where x is represented in &lt;a href=&#34;https://attack.mitre.org/datacomponents/&#34;&gt;https://attack.mitre.org/datacomponents/&lt;/a&gt; or other control lists).&lt;br/&gt;&lt;br/&gt;Counter point: Anything that changes the profile of the attack surface and presents an opportunity for detection can be considered a security boundary. Some may be more effective than others, some may have bugs, others may be configured badly but they all have some boundary value. The point of a security test is to point out the bugs and misconfigurations.
    </content>
    <updated>2026-04-28T14:27:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8dt8yqkln38dn5glyyqclwud5yu0rm29qu4s3g82dlq4ucupkymszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv47dkj</id>
    
      <title type="html">Just looked at some AI agentic shit being touted for red teaming ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8dt8yqkln38dn5glyyqclwud5yu0rm29qu4s3g82dlq4ucupkymszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzv47dkj" />
    <content type="html">
      Just looked at some AI agentic shit being touted for red teaming and I am both terrified by the ROE it has and how it might feel about some of the scenarios real red teams have to deal with and fascinated as to how the skills will fall apart when given upwards of 140000 hosts to target across the globe...
    </content>
    <updated>2026-04-27T13:43:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2ewy5ezz4hh3lknhd840me0qv29jcge2whgvk5vmtpp7c3fk06gczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz37xlw3</id>
    
      <title type="html">Maybe not you, but *some* people do want persistent access to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2ewy5ezz4hh3lknhd840me0qv29jcge2whgvk5vmtpp7c3fk06gczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz37xlw3" />
    <content type="html">
      Maybe not you, but *some* people do want persistent access to Cisco devices:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://blog.talosintelligence.com/uat-4356-firestarter/&#34;&gt;https://blog.talosintelligence.com/uat-4356-firestarter/&lt;/a&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf&#34;&gt;https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#threatintel, #cisco
    </content>
    <updated>2026-04-25T11:11:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9zza6xg4zd6rcjfluc99zcz50dn3fgc0wws0nypcgq4f63kpedjszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8u5npw</id>
    
      <title type="html">Accidentally leverage a supply chain attack this week when it ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9zza6xg4zd6rcjfluc99zcz50dn3fgc0wws0nypcgq4f63kpedjszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8u5npw" />
    <content type="html">
      Accidentally leverage a supply chain attack this week when it turned out that the GitHub org I&amp;#39;d cloned for a cyber exercise was &amp;#34;unofficial&amp;#34; and none of the exercise participants knew who actually owned it although they did recognise the committers. Chaos ensued.&lt;br/&gt;&lt;br/&gt;#purpleteam
    </content>
    <updated>2026-04-25T11:06:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswpuyygu3shewtsn6x379fvmcaytddu9wzw432jkcn0z88kjmt7dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyr5wrm</id>
    
      <title type="html">RE: https://infosec.exchange/@thc/116158209911493617 Somehow I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswpuyygu3shewtsn6x379fvmcaytddu9wzw432jkcn0z88kjmt7dqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzyr5wrm" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@thc/116158209911493617&#34;&gt;https://infosec.exchange/@thc/116158209911493617&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Somehow I missed this dropping but wow, so much history.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note15pp0sme4z2nd364vycql5f8nt6fw297anajsgrjwctsjx3njdqyq2kaezp&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note15pp…aezp&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; ❤️RELEASE: The TEAM-TESO cvs:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thc.org/team-teso/&#34;&gt;https://thc.org/team-teso/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Exploits, advisories, teso-informational (never released), burneye ELF crypter, bscan mass scanner, …plus some rare pictures.&lt;br/&gt;&lt;br/&gt;Which 7350 exploit was your favourite? &lt;br/&gt;&lt;br/&gt;Enjoy &amp; Keep hacking,&lt;br/&gt;&lt;br/&gt;Yours Sincerely,&lt;br/&gt;   Team-Teso (via THC’s bsky account).&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/158/209/518/341/885/original/bd67e9be03b646f9.png&#34;&gt; &lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-04-25T09:19:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstepaaxzzdvz60r0ve7srdql9vjdzlf69f3x49zavk2u2gdn6uv6czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznela49</id>
    
      <title type="html">Interesting Git repos of the week: Bugs: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstepaaxzzdvz60r0ve7srdql9vjdzlf69f3x49zavk2u2gdn6uv6czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznela49" />
    <content type="html">
      Interesting Git repos of the week:&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/timb-machine-mirrors/Gi7w0rm-badboy2.js&#34;&gt;https://github.com/timb-machine-mirrors/Gi7w0rm-badboy2.js&lt;/a&gt; - Adobe Reader PoC&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/dougburks/ohmypcap&#34;&gt;https://github.com/dougburks/ohmypcap&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub10xzaja6x8f88tkz8zmt3dhgjz9ear7hm9ttk43hjqd7hlz7z0p8qp9tx5u&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Doug Burks&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub10xz…tx5u&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; dumps packets&lt;br/&gt;* &lt;a href=&#34;https://github.com/cyb3rmik3/presentations&#34;&gt;https://github.com/cyb3rmik3/presentations&lt;/a&gt; - interesting presentations from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub19p6qq32q2s8udn8n7s6lnc8duzmjqmv2nuyg9gnlh4q8k74mhzyqsfc4yy&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Michalis Michalos&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub19p6…c4yy&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/bad-antics/rupurt&#34;&gt;https://github.com/bad-antics/rupurt&lt;/a&gt; - another tool to hunt for Linux root kits&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/pandaadir05/snoop&#34;&gt;https://github.com/pandaadir05/snoop&lt;/a&gt; - tracing with eBPF 🤖&lt;br/&gt;* &lt;a href=&#34;https://github.com/x41sec/force-push-scanner&#34;&gt;https://github.com/x41sec/force-push-scanner&lt;/a&gt; - scanning Git hard pushes for leakage with &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1a7knlj2daku4ka2rtfs2hlj8tp42yrgg0gp9d3v5ftngwkma03zqvnguxz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;X41 D-Sec GmbH&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1a7k…guxz&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/brightio/penelope&#34;&gt;https://github.com/brightio/penelope&lt;/a&gt; - landing all those bind and reverse shells&lt;br/&gt;* &lt;a href=&#34;https://github.com/vmi-rs/ephemera&#34;&gt;https://github.com/vmi-rs/ephemera&lt;/a&gt; - handle Microsoft&amp;#39;s crash dumps without licking with Windows&lt;br/&gt;* &lt;a href=&#34;https://github.com/winterknife/EVENSTAR&#34;&gt;https://github.com/winterknife/EVENSTAR&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1x9xdqgr80q04fyg3dcht3ur3ezgt9jvg4ysx5lx9k9x4547dlmgqqdt8d2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;winterknife 🌻&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1x9x…t8d2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s experiments with poking holes in Windows&lt;br/&gt;* &lt;a href=&#34;https://github.com/NextronSystems/APTSimulator&#34;&gt;https://github.com/NextronSystems/APTSimulator&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1582puw8r649g8m5fafge0yuzeuzw2apx3acxv8p2t8ypnjl2dkwqpgzvg8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Florian Roth&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1582…zvg8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; and friends play dress up&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/dmaynor/apple-vuln-research&#34;&gt;https://github.com/dmaynor/apple-vuln-research&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub102fz8cdupydrcy6yy7xkzcezq7cz7dv9mvtqfl8hmxguvj62pzyq3g9ak9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Dmaynor&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub102f…9ak9&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s rotten apples &lt;br/&gt;* &lt;a href=&#34;https://github.com/fizzyade/sfpdoctor&#34;&gt;https://github.com/fizzyade/sfpdoctor&lt;/a&gt; - is there an SFP doctor in the house?&lt;br/&gt;&lt;br/&gt;Nerd:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/timb-machine-mirrors/karpathy-llm-wiki.md&#34;&gt;https://github.com/timb-machine-mirrors/karpathy-llm-wiki.md&lt;/a&gt; - combining wikis with RAG and LLM for the ultimate lifestyle experience 🤖&lt;br/&gt;&lt;br/&gt;#security, #code, #research
    </content>
    <updated>2026-04-24T12:25:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx63lle7z2hxs3z5370rvxraj0ujt6unk2npc9ur7qnlekdzl2wyszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy5uww6</id>
    
      <title type="html">Interesting links of the week: Standards: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx63lle7z2hxs3z5370rvxraj0ujt6unk2npc9ur7qnlekdzl2wyszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzy5uww6" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Standards:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://github.com/OWASP/APTS&#34;&gt;https://github.com/OWASP/APTS&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1nfkqc3cwmcm2a7hgyyf0f8djf9rpk85gkead25au5v0r50vls8ss75dr9f&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;OWASP Foundation&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1nfk…dr9f&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; has a crack at defining autonomous testing standards&lt;br/&gt;* &lt;a href=&#34;https://cert.pl/en/posts/2026/04/annual-report-2025/&#34;&gt;https://cert.pl/en/posts/2026/04/annual-report-2025/&lt;/a&gt; - .pl CERT gives us their annual update&lt;br/&gt;* &lt;a href=&#34;https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations&#34;&gt;https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations&lt;/a&gt; - more on that Guardian story from a couple of weeks back about Russian hostmasters working for free&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/abs/2603.29545&#34;&gt;https://arxiv.org/abs/2603.29545&lt;/a&gt; - exploring how cyber crime&amp;#39;s vibe will change&lt;br/&gt;* &lt;a href=&#34;https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report&#34;&gt;https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report&lt;/a&gt; - how .mx got popped&lt;br/&gt;* &lt;a href=&#34;https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a&#34;&gt;https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a&lt;/a&gt; - .ir are planning a silent disco and all of US are invited&lt;br/&gt;&lt;br/&gt;Threats:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://socket.dev/blog/bitwarden-cli-compromised&#34;&gt;https://socket.dev/blog/bitwarden-cli-compromised&lt;/a&gt; - careful warden, I see you&amp;#39;re managing a password&lt;br/&gt;* &lt;a href=&#34;https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/&#34;&gt;https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/&lt;/a&gt; - .de doxes head of REvil&lt;br/&gt;* &lt;a href=&#34;https://www.ic3.gov/PSA/2026/PSA260407&#34;&gt;https://www.ic3.gov/PSA/2026/PSA260407&lt;/a&gt; - .ru completes sticker collection of logos from every major law enforcement agency&lt;br/&gt;* &lt;a href=&#34;https://www.lumen.com/blog/en-us/frostarmada-forest-blizzard-dns-hijacking&#34;&gt;https://www.lumen.com/blog/en-us/frostarmada-forest-blizzard-dns-hijacking&lt;/a&gt; - .ru... in your modem, stealing your DNS requests&lt;br/&gt;* &lt;a href=&#34;https://dti.domaintools.com/research/dprk-malware-modularity-diversity-and-functional-specialization&#34;&gt;https://dti.domaintools.com/research/dprk-malware-modularity-diversity-and-functional-specialization&lt;/a&gt; - .kp IT skills continue to develop&lt;br/&gt;* &lt;a href=&#34;https://pushsecurity.com/blog/device-code-phishing&#34;&gt;https://pushsecurity.com/blog/device-code-phishing&lt;/a&gt; - phishermen continue to catch phish, news at 10&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.jamf.com/blog/darksword-ios-exploit-kit-three-lessons-mobile-security/&#34;&gt;https://www.jamf.com/blog/darksword-ios-exploit-kit-three-lessons-mobile-security/&lt;/a&gt; - breaking our on Safari&lt;br/&gt;* &lt;a href=&#34;https://blog.calif.io/p/we-asked-claude-to-audit-sagredos&#34;&gt;https://blog.calif.io/p/we-asked-claude-to-audit-sagredos&lt;/a&gt; - Claude vs qmail but FFS, it shouldn&amp;#39;t have taken that much effort to spot that one&lt;br/&gt;* &lt;a href=&#34;https://heyitsas.im/posts/cups/&#34;&gt;https://heyitsas.im/posts/cups/&lt;/a&gt; - printing a new 0day&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://vulnbench.ghostsecurity.com/&#34;&gt;https://vulnbench.ghostsecurity.com/&lt;/a&gt; - testing LLM efficacy on the work bench&lt;br/&gt;* &lt;a href=&#34;https://agentic-threat-modeling.github.io/MAESTRO/&#34;&gt;https://agentic-threat-modeling.github.io/MAESTRO/&lt;/a&gt; - how to make friends with agents and influence them&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://gpubreach.ca/&#34;&gt;https://gpubreach.ca/&lt;/a&gt; - another hammer, another pixel dead...&lt;br/&gt;&lt;br/&gt;Hardening:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://lore.kernel.org/lkml/20260404133746.80914-1-zybo1000@gmail.com/&#34;&gt;https://lore.kernel.org/lkml/20260404133746.80914-1-zybo1000@gmail.com/&lt;/a&gt; - an interesting new kernel driver for Linux&lt;br/&gt;&lt;br/&gt;Cryptography:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.openssh.org/pq.html&#34;&gt;https://www.openssh.org/pq.html&lt;/a&gt; - #OpenBSD takes a stance on PQC&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-04-23T17:00:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg7yug9ujmd99vnz33539xch3f8hxtwfahf3fqv0arzxujc79dewgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznzlft9</id>
    
      <title type="html">Please hold. You are number 1 in the torment nexus. There is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg7yug9ujmd99vnz33539xch3f8hxtwfahf3fqv0arzxujc79dewgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dznzlft9" />
    <content type="html">
      Please hold. You are number 1 in the torment nexus. There is no-one in front of you and no-one behind. Your call *is* important to us and there is *no* escape. There is no-one to hear your screams. Please hold.&lt;br/&gt;&lt;br/&gt;#microfiction
    </content>
    <updated>2026-04-23T16:12:16Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd4gur5hm2sa957s35xs09937t9vqv7wh4rk0ylptf73vfw4fn7cqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsrc2le</id>
    
      <title type="html">Interesting to read about the hardware differences between ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd4gur5hm2sa957s35xs09937t9vqv7wh4rk0ylptf73vfw4fn7cqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzsrc2le" />
    <content type="html">
      Interesting to read about the hardware differences between USB&amp;lt;&amp;gt;fibre and ThunderBolt&amp;lt;&amp;gt;fibre and how they affect the attack surface. Anyway, ordered an SFP adapter that present via ThunderBolt as Intel chips, so that I can play with ethtool a bit more.
    </content>
    <updated>2026-04-23T12:58:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdmpcw06xvse77s5efan7xq2pz8nn3czyzcz5vexd8nu8wqc7vp3szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdwud9u</id>
    
      <title type="html">Everyone should be 💜: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdmpcw06xvse77s5efan7xq2pz8nn3czyzcz5vexd8nu8wqc7vp3szyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzdwud9u" />
    <content type="html">
      Everyone should be 💜:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/Neo23x0/auditd/issues/178&#34;&gt;https://github.com/Neo23x0/auditd/issues/178&lt;/a&gt; provoked:&lt;br/&gt;&lt;br/&gt;&amp;#34;serving up the defense on a silver platter i see 😜&amp;#34; from one of my team... He knows me quite well and was just teasing, but still!&lt;br/&gt;&lt;br/&gt;Despite all my ❤️, I built my first SOC on SQL Server... and handled ILOVEYOU... &lt;br/&gt;&lt;br/&gt;That&amp;#39;s how 💙 I am!
    </content>
    <updated>2026-04-22T17:50:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqpswq3vfmd0hwfxue2xsthvf92hkxh2fmev4z6xdzzcht2glreyqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvv65hh</id>
    
      <title type="html">As we enter conference season, if you&amp;#39;re a first time, or ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqpswq3vfmd0hwfxue2xsthvf92hkxh2fmev4z6xdzzcht2glreyqzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzvv65hh" />
    <content type="html">
      As we enter conference season, if you&amp;#39;re a first time, or less experience speaker:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/timb-machine/presentations/blob/main/A%20rising%20tide%20lifts%20all%20ships%20-%20Cyber%20security%20culture%2C%20competence%20and%20community.pdf&#34;&gt;https://github.com/timb-machine/presentations/blob/main/A%20rising%20tide%20lifts%20all%20ships%20-%20Cyber%20security%20culture%2C%20competence%20and%20community.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#payforwards, #mutualaid
    </content>
    <updated>2026-04-22T07:52:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqyl472lyvpfdq4743008jsdk9ed6j74793tj77x2hf3479pzkkdczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx58eap</id>
    
      <title type="html">Now that&amp;#39;s /some/ shit posting from the TA: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqyl472lyvpfdq4743008jsdk9ed6j74793tj77x2hf3479pzkkdczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzx58eap" />
    <content type="html">
      Now that&amp;#39;s /some/ shit posting from the TA:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.linkedin.com/posts/jamie-williams-108369190_spoofing-as-a-red-team-is-%F0%9D%9A%9D%F0%9D%9A%8E%F0%9D%9A%8C%F0%9D%9A%91%F0%9D%9A%97%F0%9D%9A%92%F0%9D%9A%8C%F0%9D%9A%8A%F0%9D%9A%95%F0%9D%9A%95%F0%9D%9A%A2-share-7452388382078349312-RxLL?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAABLaKEBOSsLj2DTcDmlwFtVAzzZ9BjjPwc&#34;&gt;https://www.linkedin.com/posts/jamie-williams-108369190_spoofing-as-a-red-team-is-%F0%9D%9A%9D%F0%9D%9A%8E%F0%9D%9A%8C%F0%9D%9A%91%F0%9D%9A%97%F0%9D%9A%92%F0%9D%9A%8C%F0%9D%9A%8A%F0%9D%9A%95%F0%9D%9A%95%F0%9D%9A%A2-share-7452388382078349312-RxLL?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAABLaKEBOSsLj2DTcDmlwFtVAzzZ9BjjPwc&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;(MDSec is one of the UK&amp;#39;s own... so a TA pretending to be them... \o/)&lt;br/&gt;&lt;br/&gt;#threatintel, #shitposting
    </content>
    <updated>2026-04-21T17:23:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsywlqyl7pgqzljpcg4fv00wmcfnjwtrc2vtth08vp4x9l8gu4f7cgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgu4qvz</id>
    
      <title type="html">Particularly like the &amp;#34;Waiver required for all ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsywlqyl7pgqzljpcg4fv00wmcfnjwtrc2vtth08vp4x9l8gu4f7cgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzgu4qvz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2a37dgn5qavkqa0u7gdqv69sg0jn8d294k5gchv85afe2naptstg60n0l9&#39;&gt;nevent1q…n0l9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Particularly like the &amp;#34;Waiver required for all participants&amp;#34;... Presumably this means that if someone turns up shooting, it&amp;#39;s on individual attendees heads... Bold move, &amp;#34;you might get shot, but that&amp;#39;s on you...&amp;#34;.
    </content>
    <updated>2026-04-21T12:33:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2a37dgn5qavkqa0u7gdqv69sg0jn8d294k5gchv85afe2naptstgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzp8nzpj</id>
    
      <title type="html">Hmm. Just got invited to Guns &amp;amp; Cyber by virtue of our CREST ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2a37dgn5qavkqa0u7gdqv69sg0jn8d294k5gchv85afe2naptstgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzp8nzpj" />
    <content type="html">
      Hmm. Just got invited to Guns &amp;amp; Cyber by virtue of our CREST membership. I&amp;#39;m sure for some this would be a very welcome invite but not really one for me. Should I follow my personal ethics and make a complaint that I&amp;#39;m not really all that keen on shooting things and ask if they have an alternate event for people who would prefer to help people?
    </content>
    <updated>2026-04-21T12:10:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvs7juzkhqzjv773ruaudww06wrkucd8d0v449ujg5v7rq4uzjhcszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzssymkv</id>
    
      <title type="html">If like me, you&amp;#39;re a fan of Kae Tempest&amp;#39;s written word: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvs7juzkhqzjv773ruaudww06wrkucd8d0v449ujg5v7rq4uzjhcszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzssymkv" />
    <content type="html">
      If like me, you&amp;#39;re a fan of Kae Tempest&amp;#39;s written word:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.theguardian.com/culture/2026/apr/18/kae-tempest-on-creativity-and-his-gender-transition-im-just-glad-to-be-alive&#34;&gt;https://www.theguardian.com/culture/2026/apr/18/kae-tempest-on-creativity-and-his-gender-transition-im-just-glad-to-be-alive&lt;/a&gt;
    </content>
    <updated>2026-04-20T18:12:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxn89kqu6lcna048wnjvkqjn5ytj2wpglem2tv9lyhh3t00xfg65czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkxtux</id>
    
      <title type="html">Someone&amp;#39;s just listed out &amp;#34;all&amp;#34; the Windows versions ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxn89kqu6lcna048wnjvkqjn5ytj2wpglem2tv9lyhh3t00xfg65czyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzfkxtux" />
    <content type="html">
      Someone&amp;#39;s just listed out &amp;#34;all&amp;#34; the Windows versions - with the tag line &amp;#34;which one did you start on&amp;#34; - and I am genuinely sad they forgot Windows 2.
    </content>
    <updated>2026-04-20T14:51:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs22yfutrfsm244xcuar893dgpyxy6gjkuynvrzpnrfqq5qlguqpcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8pu7l2</id>
    
      <title type="html">Forget about the intricacies of the DNS spec. This should have ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs22yfutrfsm244xcuar893dgpyxy6gjkuynvrzpnrfqq5qlguqpcczyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz8pu7l2" />
    <content type="html">
      Forget about the intricacies of the DNS spec. This should have seemed like a bad life choice in any event. Turning user input into a command line when all you really wanted to do was write a 0 byte file:&lt;br/&gt;&lt;br/&gt;sprintf(acfcommand, &amp;#34;/bin/touch %s/control/notlshosts/&amp;#39;%s&amp;#39;&amp;#34;,&lt;br/&gt;        info-&amp;gt;pw_dir, partner_fqdn);&lt;br/&gt;fp = popen(acfcommand, &amp;#34;r&amp;#34;);
    </content>
    <updated>2026-04-19T11:10:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst9pjhacstk4h7k4llj75fskmc4m7dx6d5eezcl5qg9m3m38f63kszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzarw7gj</id>
    
      <title type="html">Regular reminder to myself that whilst I don&amp;#39;t always agree ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst9pjhacstk4h7k4llj75fskmc4m7dx6d5eezcl5qg9m3m38f63kszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzarw7gj" />
    <content type="html">
      Regular reminder to myself that whilst I don&amp;#39;t always agree with everything Jericho says, that he makes a lot more sense than he gets credit for.
    </content>
    <updated>2026-04-19T10:55:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdh93q9wz4q7lag8f400c3hfret7zj3u7stv0qlgk6a8ywu5v0myszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2x04ke</id>
    
      <title type="html">Interesting links of the week: Strategy: * ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdh93q9wz4q7lag8f400c3hfret7zj3u7stv0qlgk6a8ywu5v0myszyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dz2x04ke" />
    <content type="html">
      Interesting links of the week:&lt;br/&gt;&lt;br/&gt;Strategy:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/&#34;&gt;https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1uusg5j7ckv3mynf45mnhlzp9w7r8qvjeftm3k2qr2u7aklf5sgzq75s9sg&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;ISC.org&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1uus…s9sg&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; makes some useful suggestions on reporting vulnerabilities&lt;br/&gt;* &lt;a href=&#34;https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/&#34;&gt;https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/&lt;/a&gt; - building a GRC framework with Claude 🤖&lt;br/&gt;* &lt;a href=&#34;https://jericho.blog/2026/04/17/nvd-gives-up/&#34;&gt;https://jericho.blog/2026/04/17/nvd-gives-up/&lt;/a&gt; - Jericho from &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dy2dn4p8qn6h97r86faxehm8mrsuclff7zaff6gewp08ze4nmceqhjhp28&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Attrition.org&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dy2…hp28&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; gives us the skinny on the NVD updates&lt;br/&gt;* &lt;a href=&#34;https://www.usenix.org/system/files/login/articles/login_apr15_12_geer.pdf&#34;&gt;https://www.usenix.org/system/files/login/articles/login_apr15_12_geer.pdf&lt;/a&gt; - Dan Geer predicts...&lt;br/&gt;* &lt;a href=&#34;https://security.googleblog.com/2025/04/google-launches-sec-gemini-v1-new.html&#34;&gt;https://security.googleblog.com/2025/04/google-launches-sec-gemini-v1-new.html&lt;/a&gt; - remembering Sec-Gemini v1 hype&lt;br/&gt;* &lt;a href=&#34;https://init6.com/papers/Day-Zero-Normal-CISO-Brief.pdf&#34;&gt;https://init6.com/papers/Day-Zero-Normal-CISO-Brief.pdf&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ryte5hhdg6yv42ma327tyztzx4rej3yxvvs79qe38zk5uwzv6cashghg6k&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Rob Fuller&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ryt…hg6k&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; comes with another take on AI and LLM&lt;br/&gt;* &lt;a href=&#34;https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf&#34;&gt;https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf&lt;/a&gt; - the Cloud Security Aliance chip in&lt;br/&gt;* &lt;a href=&#34;https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/&#34;&gt;https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/&lt;/a&gt; - as does @cje&lt;br/&gt;&lt;br/&gt;Detection:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://pub.expmon.com/&#34;&gt;https://pub.expmon.com/&lt;/a&gt; - Haifei Li&amp;#39;s EXPMON&lt;br/&gt;* &lt;a href=&#34;https://obdev.at/blog/little-snitch-for-linux/&#34;&gt;https://obdev.at/blog/little-snitch-for-linux/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lkyyzzcn6ax27ra5uuxlv3mddqnl4eqhlqfcxpnhwv9ntuvd320squ0sa8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Little Snitch&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lky…0sa8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; comes to Linux&lt;br/&gt;&lt;br/&gt;Bugs:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://x.com/Gi7w0rm/status/2042370775546482815&#34;&gt;https://x.com/Gi7w0rm/status/2042370775546482815&lt;/a&gt; - more on that spike in Adobe Reader bugs chain&lt;br/&gt;* &lt;a href=&#34;https://rhisac.org/threat-intelligence/bluehammer-windows-local-privilege-escalation-zero-day-publicly-released/&#34;&gt;https://rhisac.org/threat-intelligence/bluehammer-windows-local-privilege-escalation-zero-day-publicly-released/&lt;/a&gt; - moar on Blue Hammer #1&lt;br/&gt;* &lt;a href=&#34;https://www.cyderes.com/howler-cell/windows-zero-day-bluehammer&#34;&gt;https://www.cyderes.com/howler-cell/windows-zero-day-bluehammer&lt;/a&gt; - moar on Blue Hammer #2&lt;br/&gt;* &lt;a href=&#34;https://www.coresecurity.com/blog/analysis-bluehammer-lpe-exploiting-windows-defender-updates&#34;&gt;https://www.coresecurity.com/blog/analysis-bluehammer-lpe-exploiting-windows-defender-updates&lt;/a&gt; - moar on Blue Hammer #3&lt;br/&gt;&lt;br/&gt;Exploitation:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://www.slideshare.net/slideshow/how-i-use-ai-for-penetration-testing-teri-radichel-2nd-sight-lab-3fb8/286987132&#34;&gt;https://www.slideshare.net/slideshow/how-i-use-ai-for-penetration-testing-teri-radichel-2nd-sight-lab-3fb8/286987132&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1sqhuy0wmqujpqahgkxdkv4l2g3etdvtuv6x2d7enc5hmlrt2e5kssjqex8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Teri Radichel&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1sqh…qex8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Hard hacks:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://hackers-arise.com/scada-ics-hacking-and-security-attacking-the-modbus-protocol-with-rofuzz/&#34;&gt;https://hackers-arise.com/scada-ics-hacking-and-security-attacking-the-modbus-protocol-with-rofuzz/&lt;/a&gt; - attacking ICS and other OT with rofuzz&lt;br/&gt;* &lt;a href=&#34;https://medium.com/@theopenshelf/amazon-is-cutting-kindle-store-access-on-pre-2013-kindles-a7b495cb51ee&#34;&gt;https://medium.com/@theopenshelf/amazon-is-cutting-kindle-store-access-on-pre-2013-kindles-a7b495cb51ee&lt;/a&gt; - Amazon has a Kindle problem and how you can help...&lt;br/&gt;&lt;br/&gt;Development:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://appsec.guide/docs/languages/c-cpp/lang-c-cpp-bug-classes/&#34;&gt;https://appsec.guide/docs/languages/c-cpp/lang-c-cpp-bug-classes/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1rcsevfzqfj6xzk0rajfaftsnq4f4wewydfyxd9u46jch4sxta60qjz7sw8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Trail of Bits&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1rcs…7sw8&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s security coding guidance with bits&amp;#39;n&amp;#39;pieces from @gsuberland&lt;br/&gt;* &lt;a href=&#34;https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/&#34;&gt;https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/&lt;/a&gt; - &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1szz2a5n67z8nfx2s5z87xqk5znexu3kfdmprq5cqva8g0gdd8snq07t4fx&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Graham Sutherland / Polynomial&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1szz…t4fx&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&amp;#39;s accompanying blog post&lt;br/&gt;* &lt;a href=&#34;https://arxiv.org/html/2603.21852v2&#34;&gt;https://arxiv.org/html/2603.21852v2&lt;/a&gt; - all elementary functions from a single operator&lt;br/&gt;&lt;br/&gt;Data:&lt;br/&gt;&lt;br/&gt;* &lt;a href=&#34;https://cardcatalogforlife.substack.com/p/google-has-a-secret-reference-desk&#34;&gt;https://cardcatalogforlife.substack.com/p/google-has-a-secret-reference-desk&lt;/a&gt; - getting more out of GOOG&lt;br/&gt;&lt;br/&gt;It&amp;#39;s notable how many of the talking heads on AI and LLM are US based or funded *and* how many of them come from a cloud centric generation of businesses...&lt;br/&gt;&lt;br/&gt;#security, #research
    </content>
    <updated>2026-04-19T10:23:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp5mt94h0qjfwdta3j7el9lzkamj8qplhdytw2dfyr6d2vkrtg4xgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcqe8hl</id>
    
      <title type="html">Anyone seen any good guidance on hardening Nokia 7xxx series ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp5mt94h0qjfwdta3j7el9lzkamj8qplhdytw2dfyr6d2vkrtg4xgzyp89hh2eeyfuw9sm48ywmmhuzg89aarr9aqg7v44xegfkkeyup2dzcqe8hl" />
    <content type="html">
      Anyone seen any good guidance on hardening Nokia 7xxx series service routers? The common criteria guide is from the old Alcatel days and whilst I&amp;#39;m familiar with them in their older form, wondering if much has changed...
    </content>
    <updated>2026-04-19T08:49:05Z</updated>
  </entry>

</feed>