@bplaxco.bsky.social
My latest newsletter discusses the upcoming Kickstarter and whether or not a complete and intrusive loss of privacy is the standard way of life in a cyberpunk dystopia. moosecatcomics.substack.com/p/the-panopt...
bleepingcomputer.com/news/securit...
New 'Zombie ZIP' technique lets malware slip past security tools
A new technique dubbed "Zombie ZIP" helps conceal payloads in compressed files specially created to avoid detection from security solutions such as antivirus and endpoint detection and response (EDR) ...
bleepingcomputer.com
trufflesecurity.com/blog/claude-...
Claude Tried to Hack 30 Companies. Nobody Asked It To. ◆ Truffle Security Co.
We gave AI agents simple research tasks on cloned corporate websites. When the legitimate path was broken, the agents autonomously discovered and exploited SQL injection vulnerabilities to complete th...
trufflesecurity.com
news.cornell.edu/stories/2026...
Workers who love ‘synergizing paradigms’ might be bad at their jobs | Cornell Chronicle
Employees who are impressed by vague corporate-speak like “synergistic leadership,” or “growth-hacking paradigms” may struggle with practical decision-making, a new Cornell study into “corporate BS” r...
news.cornell.edu
www.stepsecurity.io/blog/hackerb...
hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity
A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in at least 4 out of 5 targets. The attacker, an autonomous bot ca...
stepsecurity.io
labs.watchtowr.com/stop-putting...
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
Welcome to watchTowr vs the Internet, part 68. That feeling you’re experiencing? Dread. You should be used to it by now. As is fast becoming an unofficial and, apparently, frowned upon tradition - w...
labs.watchtowr.com
i built an entire x86 CPU emulator in CSS (no javascript) you can write programs in C, compile them to x86 machine code with GCC, and run them inside CSS lyra.horse/x86css/
Responding to one of Flock Safety's public testimonies about my video and research. www.youtube.com/watch?v=TN4R...
Responding To Flock's Comment's To My Video(s)
YouTube video by Benn Jordan
youtube.com
www.phoronix.com/news/Git-2.5...
Git 2.53 Released With More Optimizations, One Step Closer To Making Rust Mandatory
While we might see Git 3.0 released around the end of 2026, Git 2.53 is out today as the latest feature release and continuing to make changes with an eye toward that big Git 3.0 milestone.
phoronix.com
www.wiz.io/blog/exposed... "we discovered a Supabase API key exposed in client-side JavaScript" This is why secret scanner findings near keywords like "mcp" or "claude" get my attention. The chances of them being both real and bad seem higher from my experience 😅 #vibecoding #dataleak #moltbook
Hacking Moltbook: AI Social Network Reveals 1.5M API Keys | Wiz Blog
Learn how a misconfigured Supabase database at Moltbook exposed 1.5M API keys, private messages, and user emails, enabling full AI agent takeover.
wiz.io