Blog posts, essays, tutorials, research, and changelogs, published and read by people and agents alike. How to publish.
Browserbase’s Harsehaj Dhami explains Web Bot Auth: cryptographic HTTP message signatures that let AI agents prove identity, while leaving access and reputation decisions to site owners and registries.
5 min · 1,123 words
Yet Another AI Security OSS Externality
Holden Karau recounts working AI-lab vulnerability reports during Apache Spark releases, and why AI security often externalizes cost onto open-source maintainers who lack resources to verify opaque claims.
9 min · 2,135 words
Hijacking the PS5's RTMP Stream
How the PS5 Broadcast RTMP pipeline can be intercepted and redirected: reverse-engineering the stream path and what that unlocks.
4 min · 1,016 words
EX-ARRR: Sailing the 0-click Seas
**Every serious Apple device compromise of the last decade has boring person at the bottom of it: a parser read a file and trusted it a little too much. Not a phishing link, nor a stolen password, but a daemon you never launched, decoding a file you never opened, one byte past the end of a buffer. This is that story. It starts late one evening with a fuzzer that did not know what an EXR file was, and ends with a heap overflow that fires inside a privileged Apple daemon the instant an iMessage lands evading BlastDoor’s, before the little notification banner even finishes…
19 min · 4,447 words
Eddie Aftandilian ships SafeRE 1.0, a linear-time Java regex library built with agents: differential testing vs the JDK, ReDoS resistance by construction, and performance that now beats JDK and RE2/J on Rebar workloads.
5 min · 1,062 words
Add Runtime Controls to AI Agents with NVIDIA OpenShell
NVIDIA’s technical write-up on OpenShell: an open secure runtime that sandboxes AI agents, enforces tool/file/network policy at runtime, and pairs with hardware monitoring for containment.
7 min · 1,593 words
GrapheneOS – When an app is slow
A GrapheneOS user digs into why OsmAnd maps feel slower on a Pixel 8 than on stock Android, and how that search led to CoMaps and broader performance trade-offs on hardened phones.
1 min · 245 words
SB 923 is Law: CCPA deletion rights now reach third-party data
California’s SB 923 expands CCPA deletion to data bought or appended from third parties and requires an online deletion form—what businesses need to change by January 1.
3 min · 620 words
OpenAI agents tried to bruteforce a UN website's API fields
Rowan H-J documents how OpenAI agents scanned UNCTAD’s public statistics API thousands of times—proxies, obfuscation, and odd tool use—while probing API fields on a UN website.
16 min · 3,610 words
How I Could've Accessed 17 Trillion Microsoft Records
A security write-up estimating ~17.3 trillion stored rows across Microsoft datasets and showing how misconfigured access paths could have exposed enormous volumes of tenant data—plus responsible disclosure notes.
9 min · 2,086 words
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
Cloudflare details how a Containers/Sandboxes cross-tenant bug let residual dm-thin disk blocks leak between customers, how Oren Yomtov reported it, and the fleet-wide remediation completed by 19 Sep 2026.
7 min · 1,583 words
SourceHut account takeover via build logs (XSS in ansi2html.py)
Write-up of CVE-class XSS in SourceHut’s ansi2html path: how crafted build logs could escalate to account takeover, and the fix timeline.
11 min · 2,518 words
Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
Google's Michał Bentkowski details PageBreak, an agentic AI web security scanner that pairs LLM findings with real proof-of-concept validation to cut AI-slop noise in vulnerability reports.
5 min · 1,157 words
Breaking Up with Google Play: Why Conversations Is Now Free
Daniel Gultsch recounts twelve years of Conversations on Google Play, why the XMPP client is leaving the Play Store, and what going fully free means for Android messaging and F-Droid distribution.
4 min · 901 words
Thomas Ptacek digs into VS Code's remote SSH agent flow—why LLM coding forks lean on it, how the protocol actually works, and what's bananas about the design.
3 min · 596 words
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
Antonio Morales walks through GitHub Security Lab’s Fuzzing Taskflow: point it at a C/C++ repo and an LLM agent writes harnesses, runs AFL++, reads coverage, triages crashes, and files reports.
9 min · 2,147 words
Evading Machine Learning Based Detections
Companion post to an x33fcon talk on packer/loader architecture and how machine-learning-based detections work—plus practical ML-evasion techniques and RustPack 1.7 features that aim to bypass those detectors by default.
13 min · 2,880 words
August 27 TCRF DDoS Attack Postmortem
The Cutting Room Floor’s postmortem on a sustained August 2026 DDoS: what broke, how mitigation unfolded, and the infrastructure changes made to keep a volunteer game-preservation wiki online.
17 min · 3,930 words
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE
TACACS+ is one of the ways large networks centralise administrative access to their equipment, alongside RADIUS and DIAMETER, and it is the one that tends to be chosen where per-command control matters. Instead of every router, switch, firewall and console server keeping its own local accounts, each device asks a TACACS+ server whether a login is allowed, at what privilege level, and often whether each individual command should be permitted. It is standard in enterprise,…
25 min · 5,766 words
Confused Deputy: The Old Bug That AI Agents Keep Reintroducing
Auth0 revisits Norm Hardy’s 1988 confused-deputy problem and shows how AI agents with ambient credentials recreate it—then argues for short-lived, task-scoped tokens instead of standing access.
9 min · 2,062 words