Documentation is lies. Source is an abstraction. Assembly is the truth. Also at social.scriptjunkie.us/ and nostr npub10mx0gx3r2lszrrut8kvr5mt2m8r9ffhn
Correction: Most Authoritarian.
• C-8: Without a court order, govt can cut you off from the internet
• C-9: Criminalizes speech online
• C-22: Keep a year of metadata of everything you do online
• C-34: Requires ID checks to use social media
RSA private keys biased toward 0 bits can be factored by swapping a hard math problem for an easy one: integer factorization becomes polynomial factorization.
We found hundreds of real-world keys vulnerable to this. Many traced to a type mismatch in CompleteFTP (now patched): each 32-bit limb got only 8 bits of randomness. We recovered 603 RSA and 74 DSA private keys. blog.trailofbits.com/2026/06…
Epic OPSEC fail by NSO Group.
@whatsapp recently caught the notorious spyware company hacking across their platform.
(NSO is forbidden from doing this by a US court!)
In their testing, NSO was sending a test image of a soup cup...on a desktop mat with the NSO Group logo.
Making it worse, the image was user-reported to WhatsApp.
Cleanest attribution I've seen in a long time.
I shared this note earlier today with the entire team at Opendoor.
Today we began to say goodbye to our colleagues in India as we wind down our India operations.
Our customers are in America, and that's where our operational work belongs.
AI PCB design vendor apparently threatening @adafruit with CFAA over a reported vuln.
I suspect it's not about the vuln. The vendor is raising money; looks like Adafruit was about to post an expose about their marketing claims. See the end of Exhibit K:
courtlistener.com/docket/734…
On Responsible Security Disclosures and Free Speech
Adafruit has worked with our longtime employment firm and team to make sure there is indemnification for all employees and contractors reporting responsible security disclosures at Adafruit. This is not any different... it only makes it more clear that the bad actors and companies that try to use responsible disclosure as a way to chill free speech will not stop us from publishing facts, or even the answers to an interview with a startup that makes lots of questionable claims.
–Ladyada, pt - Adafruit, June 9, 2026
adafruit.com/flux@BuildWithFlux@FenwickWest
(that is zine, our baby girl)
ALT ladyada holding zine, her and pt's baby girl, in front of a reflow oven on the Adafruit factory floor in the USA, in BROOKLYN. black and white documentary photo, pink hair the only color in the frame. this is what's at stake when legal threats are used to silence security researchers and journalists - a woman owned engineering company in the usa, that has employees with families, people who report facts in good faith. stand up together.
NEW: malware developers added nuclear & biological weapons text to to their spyware.
Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner.
Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky.
When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit.
We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted.
In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation.
H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
(near) Instant dumping of the Bitlocker VMK using @SipeedIO#SLogic16U3 and #ngscopeclient 🥰. Full disclosure: i know nothing about C , filter was fully vibe coded (with a Claude free plan)
Soooo, does Hegseth get an apology for the accusations the “supply chain risk” designation was an overreaction? ;)
Or are we fine with silent sabotage of our code now?
Anthropic sells Fable 5 with blatant false advertising. Tweet text only mentions "Fable 5" as far better. Graphic shows "Mythos 5/Fable 5" as ~2x better on cybersecurity. In reality: Fable 5 completely refuses this work (exploitbench). It's just a lie.
x.com/claudeai/status/206439…
Fable 5 is state-of-the-art on nearly all tested benchmarks, with exceptional performance in software engineering, knowledge work, scientific research, and vision.
The longer and more complex the task, the larger Fable 5’s lead over our other models.
ALT Benchmark table titled Mythos 5 & Fable 5, comparing Claude Mythos 5 and Fable 5 against Claude Mythos Preview, Claude Opus 4.8, GPT 5.5, and Gemini 3.1 Pro.
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use.
Its capabilities exceed those of any model we’ve ever made generally available.