There is currently a Wikipedia edit war on the Great Lakes Wikipedia pages because everything is so stupid
becojo
@becojo.com
securing the computers | gifs https://becojo.tumblr.com
The new “⚠️Seems like AI slop” button on LinkedIn is sending me into orbit lmao
You shouldn’t trust Trusted Publishing https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing #python #security #oss
Every code generation LLM model available will at some point suggest insecure code as a part of “code completion”. Should this behavior be considered a vulnerability? #security #opensource #programming sethmlarson.dev/are-insecure...
Are insecure code completions a vulnerability?
Three months ago I saw that PyCharm shipped with a “Full Line Completion” plugin that “uses a local deep learning model to suggest entire lines of code”. These suggestions manifest as whole-line su...
sethmlarson.dev
If you're worried about AI data centers, Congress is taking notice — not by passing any laws, but by spying on critics through its new intelligence bureau: www.kenklippenstein.com/p/exclusive-...
Exclusive: New Intel Bureau Eyes AI Data Center Critics
Congress has its own CIA and it’s sounding the alarm about anti-AI grievances
kenklippenstein.com
I well recall the online debates where the majority of debaters opined that zero traffic deaths is an utopian goal and would require methods that would kill Helsinki, if not bring about totalitarian communism
“Helsinki hasn’t registered a single traffic-related fatality in the past year…Citing data that shows the risk of pedestrian fatality is cut in half by reducing a car’s speed from 40 to 30km/hr, city officials imposed the lower limit in most of Helsinki’s residential areas and city center in 2021.”
What so many have experienced personally has been confirmed by a new study: AI has been a disaster for working artists.
The AI-inflected crisis artists are facing, in 4 charts
An alarming new study reveals the dire impact AI is having on artists' livelihoods. It does offer some hope, too.
bloodinthemachine.com
… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
wiz.io
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. We’ll continue updating our coverage as more details are confirmed. socket.dev/blog/bitward...
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
socket.dev
TIL the Raspberry Pi firmware supports the storage of ECDSA private keys which allows the user-space to sign data. I ported rpifwcrypto in Go to add the ability to sign ES256 JWT tokens and export public keys as JWKS or PEM to authenticate with external services. github.com/ezoidc/go-rp...
GitHub - ezoidc/go-rpi-crypto: Pure Go library and CLI to access the Raspberry Pi's firmware cryptographic functions
Pure Go library and CLI to access the Raspberry Pi's firmware cryptographic functions - ezoidc/go-rpi-crypto
github.com
New from 404 Media: CBP tapped into the online advertising ecosystem to track peoples' movements, according to an internal DHS document. Shows for the first time DHS tracked phones via process for putting ads in ordinary apps—video games, fitness apps, many more www.404media.co/cbp-tapped-i...
CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements
An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar t...
404media.co
Even the internet's favorite dog account calls out Ring video cameras what they are: Mass surveillance.
we need to talk about that Ring Super Bowl ad
Notepad++ have published an update to fix the software being hijacked by threat actors remotely: notepad-plus-plus.org/news/v889-re... This was being abused by threat actors in China, a blog from mine from a week ago: doublepulsar.com/small-number...
Notepad++ v8.8.9 release: Vulnerability-fix | Notepad++
notepad-plus-plus.org
New blog post: Don't fall into the anti-AI hype. antirez.com/news/158
New: DHS is lying to you. At least four videos show what really happened when ICE shot a woman in Minneapolis. Shots clearly fired while vehicle already turning away from the officer. But DHS lied. Trump lied. Noem lied. Even judges have catalogued DHS' serial lying www.404media.co/dhs-is-lying...
DHS Is Lying To You About ICE Shooting a Woman
At least four videos show what really happened when ICE shot a woman in Minneapolis on Wednesday. DHS has established itself as an agency that cannot be trusted to live in or present reality.
404media.co
After 404 Media's months-long reporting and pressure from lawmakers, the data broker owned by the U.S.’s major airlines will now shut down a program in which it sold access to hundreds of millions of flight records to the government and let agencies track peoples’ movements without a warrant.
Airlines Will Shut Down Program That Sold Your Flights Records to Government
The move comes after intense pressure from lawmakers and 404 Media’s months-long reporting about the airline industry's data selling practices.
404media.co
New from 404 Media: IRS accessed a massive database of Americans flights without a warrant. Shows where and when someone flew, the credit card used. Hundreds of millions records; the airlines sell this data to the government through a broker they own www.404media.co/irs-accessed...
Argument injection (and RCE) in three distinct AI agents blog.trailofbits.com/2025/10/22/p...
Prompt injection to RCE in AI agents
We bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.
blog.trailofbits.com
"an agent is simply an LLM call in a loop" sure and a web server is just accept(2) in a loop
Identifying birds using the Merlin Bird ID is real life Pokémon.
My writeup for @northsec.io CTF 2025's "Containers" reverse track: merkletr.ee/ctf/2025/nse...
NorthSec 2025: Containers
merkletr.ee
If there's one thing I've learned about covering cybersecurity over the past decade or so, is that the cybersecurity community (the fixers and breakers) and the cybersecurity industry (profits above all else) are two very, very different things.