It’s hilarious that they made a huge deal about the cyber capabilities for months and then when they rolled it out, they’ve blocked the actual utility of the model by prohibiting cyber use 🤣
And yes this includes trusted testers. Like, what was the point in even releasing it?
Anthropic expects people to use their cyber models for looking up food recipes or what?
Sales Team: "Hey, look, our model can find and do XXXX!"
Safety Team: "HEY, YOU LOOKED UP XXXX, YOU'RE FLAGGED!"
"Not a happy marriage." @jsnover on why .NET and Windows have never gotten along.
This clip has Bill Gates' obsession, the Longhorn disaster, Dave Cutler's backup tapes, and the day Notepad ballooned from 15KB to 15MB.
TIL that Pacino's character in Heat is, canonically, a cocaine addict; the cocaine stuff didn't make the edit, so Pacino is just insane for no reason in the final cut.
Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector
In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE..
includes PoCs and yara rule to help you find other affected s/w
blog.amberwolf.com/blog/2026…
here's my writeup for the latest Netskope LPE
this was a fun bypass of CVE-2025-0309, and highlights an interesting cloud-based attack surface :)
blog.amberwolf.com/blog/2026…
Finishing off the week with a writeup of CVE-2025-0309 - Netskope Windows Client LPE
This was one of the bugs we demo’d in our DEF CON #ZeroTrustTotalBust talk.
Also releasing a NachoVPN plugin and our 🆙skope PoC. Details on the @AmberWolfSec blog:
blog.amberwolf.com/blog/2025…