๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ฎ๐ฐ, ๐ฎ๐ฌ๐ฎ๐ฒ
This is why we can't have nice things...
๐ชฒ ๐๐๐ฝ๐๐๐ฒ๐ฟ ๐๐ป๐๐ฒ๐ฟ๐ฝ๐ฟ๐ถ๐๐ฒ ๐๐ฎ๐๐ฒ๐๐ฎ๐
Another great write-up from the elttam team. As always, itโs well explained, with enough details to understand both the issue and the process they followed to get there. I also like this one because it shows how something that looks โonlyโ like user-controlled configuration can become a much bigger issue once it reaches Kubernetes and privileged execution paths.
elttam.com/blog/jupyter-enteโฆ.
๐ค ๐ ๐ฒ๐ฎ๐๐๐ฟ๐ถ๐ป๐ด ๐๐๐ ๐โ ๐ถ๐บ๐ฝ๐ฎ๐ฐ๐ ๐ผ๐ป ๐ก-๐ฑ๐ฎ๐ ๐ฒ๐
๐ฝ๐น๐ผ๐ถ๐๐
How much time do models need to create exploits for N-day vulnerabilities? A really interesting comparison of Anthropic modelsโ efficiency at building exploits for known vulnerabilities. Another signal, if you needed one, that your time-to-patch needs to shrink dramatically.
red.anthropic.com/2026/n-dayโฆ.
๐ ๐๐๐ฝ๐ฎ๐๐๐ถ๐ป๐ด ๐ฎ ๐ฏ ๐น๐ฎ๐๐ฒ๐ฟ ๐ฆ๐ฉ๐ ๐๐ฎ๐ป๐ถ๐๐ถ๐๐ฒ๐ฟ: ๐ฆ๐๐ผ๐ฟ๐ฒ๐ฑ ๐ซ๐ฆ๐ฆ ๐ถ๐ป ๐ ๐ผ๐๐ถ๐น๐น๐ฎ
Some great content that reads like a course in application security: what was happening, why it was wrong, how to fix it, and the impact of the fix. I especially like the part where the sanitizer is called, but the sanitized output is not actually used. Itโs such a good example of why code review is not about spotting the function name you want to see. You need to follow the data and check that the thing being validated or sanitized is the thing that gets stored or rendered.
profile-chi-jade.vercel.app/โฆ.
โ๏ธ ๐๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐๐ผ๐ผ๐ด๐น๐ฒ ๐๐ถ๐๐ต ๐.๐. ๐ณ๐ผ๐ฟ $๐ฑ๐ฌ๐ฌ,๐ฌ๐ฌ๐ฌ
How much time and effort should you invest in a bug bounty target? This post gives a pretty good answer. Itโs not just โuse AI and bugs fall outโ. Itโs more about building a process around a hard target, mapping a huge attack surface, collecting the right inputs, and using AI to help scale parts of the work. A great write-up if youโre interested in how people find vulnerabilities in targets where the easy bugs disappeared a long time ago.
brutecat.com/articles/hackinโฆ.
๐ค ๐ฆ๐๐ฎ๐๐ฒ๐บ๐ฒ๐ป๐ ๐ผ๐ป ๐๐ต๐ฒ ๐จ๐ฆ ๐ด๐ผ๐๐ฒ๐ฟ๐ป๐บ๐ฒ๐ป๐ ๐ฑ๐ถ๐ฟ๐ฒ๐ฐ๐๐ถ๐๐ฒ ๐๐ผ ๐๐๐๐ฝ๐ฒ๐ป๐ฑ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ ๐๐ฎ๐ฏ๐น๐ฒ ๐ฑ ๐ฎ๐ป๐ฑ ๐ ๐๐๐ต๐ผ๐ ๐ฑ
Well, well, well, if it isnโt the consequences of your actions... After marketing Mythos as powerful enough to need special access and safeguards, Anthropic has now been asked to suspend access to Fable and Mythos for foreign nationals, including foreign-national Anthropic employees. They complied by blocking access to all customers. Any geopolitical AI expert probably had a busy weekend.
anthropic.com/news/fable-mytโฆ.
๐๏ธ ๐๐ฎ๐๐ ๐๐ฒ๐ฒ๐ธ @๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ฒ๐ฟ๐๐ฎ๐ฏ
I spent the week working on new content and updating our Security Code Review in Golang for Developers Training (
pentesterlab.com/live-trainiโฆ) for an upcoming private session.