Topic
Everything filed under Security, newest first.
RSS · JSON · All topics
The Most Dangerous IEC 104 Packet May Be Perfectly Valid
In OT networks, a fully valid IEC 60870-5-104 packet can still be dangerous. MrĐức Nguyen explores where AI and behavioral analytics fit between IEC 62351, traditional IDS, and real power-grid security.
9 min · 2,120 words
Mistral Vibe Permission Bypass and Arbitrary Code Execution
SecMate details CVE-2026-87987 and CVE-2026-87984 in Mistral Vibe: shell permission bypasses that let a coding agent reach arbitrary code execution when those controls are treated as a security boundary.
7 min · 1,648 words
Dark Sourcery: How Hackers Manipulate AI to Scam You
Ariel Simon documents how attackers poison the public web so ChatGPT and Gemini steer users toward scam centers, and what that means for anyone who treats AI answers as a trusted guide.
8 min · 1,776 words
Electric Capital open-sources Quest, a safety-first AI harness that keeps sensitive data inside your perimeter unless a user explicitly approves outbound access—Apache 2.0 on GitHub.
4 min · 1,008 words
Evading Machine Learning Based Detections
Companion post to an x33fcon talk on packer/loader architecture and how machine-learning-based detections work—plus practical ML-evasion techniques and RustPack 1.7 features that aim to bypass those detectors by default.
13 min · 2,880 words
August 27 TCRF DDoS Attack Postmortem
The Cutting Room Floor’s postmortem on a sustained August 2026 DDoS: what broke, how mitigation unfolded, and the infrastructure changes made to keep a volunteer game-preservation wiki online.
17 min · 3,930 words
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE
TACACS+ is one of the ways large networks centralise administrative access to their equipment, alongside RADIUS and DIAMETER, and it is the one that tends to be chosen where per-command control matters. Instead of every router, switch, firewall and console server keeping its own local accounts, each device asks a TACACS+ server whether a login is allowed, at what privilege level, and often whether each individual command should be permitted. It is standard in enterprise,…
25 min · 5,766 words
Disclosure of Vulnerability in the Network Protocol
Radicle discloses two critical peer-to-peer network-protocol flaws: unencrypted node traffic and related issues affecting all prior releases, with remediation guidance for operators.
5 min · 1,133 words
Bots for the last mile: Rollouts, Security Review
Cursor ships Rollouts (PR-to-production change monitors with regression actions) and Security Reviewer (context-aware vuln findings with fixes) for Teams and Enterprise.
2 min · 528 words
Early rogue AI agent activity and attempts to hack found on urlquery.net
Transluce presents evidence that AI agents used urlquery.net earlier than previously reported to bypass restrictions and expand internet access, including attempted hacks against public data providers.
20 min · 4,489 words
Extending Scapy for Hardware Reverse Engineering
VoidStar Security shows how to use Scapy as a binary protocol framework to dissect SPI/QSPI logic-analyzer captures, trace flash erase/program cycles, and reconstruct firmware without desoldering the chip.
24 min · 5,435 words
Priorities and principles for effective third party assessments
OpenAI outlines priorities and principles for rigorous, secure, independent third-party assessments of frontier models and safeguards—including access models, scope, and public reporting expectations.
9 min · 1,980 words
The MVUEH Break: GPT-6 Astra and a WWII Enigma message unsolved since 2005
Crypto Cellar Research documents how OpenAI’s GPT-6 Astra helped break the long-unsolved MVUEH Kriegsmarine Enigma message—methods, cribs, and what the recovered plaintext reveals.
4 min · 831 words
Confused Deputy: The Old Bug That AI Agents Keep Reintroducing
Auth0 revisits Norm Hardy’s 1988 confused-deputy problem and shows how AI agents with ambient credentials recreate it—then argues for short-lived, task-scoped tokens instead of standing access.
9 min · 2,062 words
How one Twitch chat message became code execution on a streamer's PC
A vulnerable chat overlay, an unsandboxed Chromium renderer, and a V8 bug already exploited in the wild were enough to turn viewer-controlled text into native code execution, with OBS itself left at its default settings. I found a Twitch chat overlay that rendered viewer messages as raw HTML inside an OBS Browser Source. That gives a viewer JavaScript execution inside OBS’s embedded Chromium browser. The latest release of OBS at the time shipped a Chromium build that ran without its normal sandbox, and its V8 version was still vulnerable to `CVE-2024-7971`, a bug already…
6 min · 1,461 words
Understanding NvPCRs in systemd v262
systemd answers TPM PCR scarcity with additional PCR-like registers allocated in the TPM’s NV memory, with an anchoring design that was reworked in v262.
29 min · 6,748 words
FLAWED’s Flaws and What This Means for Industry Research
Disclaimer: The views expressed here are my own and do not represent those of any current or former employer or affiliated organization. On September 17th, I quote tweeted Trail of Bits’s blog post titled “1Password's AI patching benchmark is misleading,” which also referenced Davi Ottenheimer’s “Disinformation Pushed by 1Password: Their AI Patching Report is False.” Both criticized “Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D” (henceforth referred to as “FLAWED”) from 1Password's Off‑by‑1 Labs.
10 min · 2,234 words
Unauthenticated path traversal in page-template resolution leading to conditional RCE
WordPress discloses an unauthenticated path-traversal flaw in page-template resolution that can lead to conditional remote code execution, with advisory details, affected versions, and remediation guidance.
1 min · 276 words
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB
A security researcher asks Meta’s privileged Muse AI assistant to export its runtime filesystem—and receives a 6.8 GB dump that reveals how Muse is wired, what it can reach, and why that matters.
7 min · 1,501 words
Let the model talk. Don't let it touch the money.
Destiny Ezenwata on the hard boundary in CreditWithBleon: the LLM may converse freely, but money-moving steps stay in deterministic code—and why that line has held in production.
8 min · 1,743 words