Dan

@basic-123.bsky.social

Copy Fail (CVE-2026-31431): the modprobe.d + rmmod recipe everyone is sharing does nothing on RHEL/Alma/Rocky/Oracle. They ship algif_aead built in. On Debian/Ubuntu it auto-loads when anything binds AF_ALG — no default protection. PoC fails on Busybox/Alpine but still vulnerable. Details below.

How to block CVE-2026-31431 (Copy Fail) - secwest.net - secure virtual engagement

How to block CVE-2026-31431 (Copy Fail) — the Linux kernel algif_aead local privilege escalation that poisons setuid binaries via the shared page cache. Fleet-scale module disable, RHEL built-in worka...

secwest.net

This is basically like Mastodon for vulnerability records, except data actually propagates across the whole network instead of staying siloed. Federated vulnerability intelligence, along with legacy CVEs, all map into a shared global index with no single point of failure.

Socket@socket.dev · 5mo ago

🪲 CIRCL's GCVE initiative launched its decentralized publishing ecosystem today alongside Vulnerability-Lookup 4.1.0. Any CNA, CSIRT, or vendor with a disclosure policy can now publish vulnerability data without routing through a central authority. socket.dev/blog/gcve-la...

Turns out you can communicate across containers via 63-bits of available space in a shared lock you acquire on /proc/self/ns/time that all processes have access to. No networking required. The post has a demo of a chat app communicating across unprivileged containers. h4x0r.org/funreliable/

Bild

Illinois Gov. JB Pritzker railed against President Donald Trump for suggesting he would deploy federal forces to Chicago, accusing the administration of “searching for ways to lay the groundwork to circumvent our democracy, militarize our cities and end elections.”

Pritzker tells Trump to stay out of Chicago: ‘You are neither wanted here nor needed here’ | CNN Politics

Illinois Gov. JB. Pritzker on Monday railed against President Donald Trump for suggesting he would deploy federal forces to Chicago, accusing the administration of “searching for ways to lay the groun...

cnn.com

Illinois is launching a first-of-its-kind legal hotline for LGBTQ+ individuals — Illinois Pride Connect. As the only state in the nation that will provide free legal advice to protect the LGBTQ+ community, we'll help fight ignorance with information and cruelty with compassion.

Security firm Trail of Bits has open-sourced Buttercup, a Cyber Reasoning System (CRS) developed for the AIxCC (AI Cyber Challenge). It is designed to find and patch software vulnerabilities in open-source code repositories. blog.trailofbits.com/2025/08/08/b... github.com/trailofbits/...

Buttercup is now open-source!

Now that DARPA’s AI Cyber Challenge (AIxCC) has officially ended, we can finally make Buttercup, our CRS (Cyber Reasoning System), open source!

blog.trailofbits.com

Hello, many new Bluesky followers! I’m a WIRED reporter looking to talk to people about the repercussions of Trump/Musk’s cuts. (In and outside of US) In particular on issues such as child protection, cybercrime, national security, intel sharing I can be reached on Signal: mattburgess.20

QR code for Signal, username: mattburgess.20