๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ฎ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ
Golang and Weak Skill Scanners
๐ย ๐๐ฒ๐โ๐ ๐๐ฎ๐น๐ธ ๐ฎ๐ฏ๐ผ๐๐ ๐ฒ๐ป๐ฐ๐ฟ๐๐ฝ๐๐ฒ๐ฑ ๐ฟ๐ฒ๐ฎ๐๐ผ๐ป๐ถ๐ป๐ด
A cryptographic look at the encrypted reasoning blobs that get passed back and forth when using the OpenAI and Anthropic APIs. I like this because it does what good security research should do: explain why the mechanism exists, build realistic threat models around it, and then actually test them instead of stopping at speculation:ย
blog.cryptographyengineeringโฆ.
๐ย ๐๐ผ๐น๐ฎ๐ป๐ด ๐ฐ๐ผ๐ฑ๐ฒ ๐ฟ๐ฒ๐๐ถ๐ฒ๐ ๐ป๐ผ๐๐ฒ๐ ๐๐
Once again, elttam delivers! Iโm a huge fan of little programming-language gotchas because they give you an edge as a code reviewer. These are exactly the kinds of details that turn "looks fine" into "wait, what actually happens here?". If youโre writing or reviewing Go, make sure you read this one:ย
elttam.com/blog/golang-code-โฆ.
๐คย ๐ง๐ต๐ฒ ๐๐ผ๐ฟ๐ฟ๐ ๐๐๐ฎ๐๐ฒ ๐ผ๐ณ ๐๐ธ๐ถ๐น๐น ๐ฑ๐ถ๐๐๐ฟ๐ถ๐ฏ๐๐๐ถ๐ผ๐ป
Trail of Bits bypassed multiple scanners with the kind of tricks every supply-chain security person should already be worried about: hidden files, bytecode, prompt injection, and "trust me bro" explanations. The good news is that they published the skills on GitHub, so get ready for vendors to claim they can now detect them all:ย
blog.trailofbits.com/2026/06โฆ.
๐๏ธ ๐๐ฎ๐๐ ๐๐ฒ๐ฒ๐ธ @๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ฒ๐ฟ๐๐ฎ๐ฏ
Last week, we released 5 new labs in ourย JavaScript Sandbox Escape badge (
pentesterlab.com/badges/javaโฆ). Make sure you check them out!