The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD: blog.calif.io/p/the-taking...
BMCs make such good targets because they live in the org gap nobody owns. not quite the server team, not the network team, not security, so they sit on firmware nobody has touched in years. the access is almost a side effect of the ownership hole.
Hello Las Vegas (and hackers following along at home)! I'm excited to share the first batch of our Out-of-Band / Baseboard Management Controller research at Black Hat USA today and DEFCON 34 this weekend. Read an exclusive by Ars Technica at: arstechnica.com/security/202...
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world's biggest manufacturers are a security mess.
arstechnica.com
Skipping Black Hat and DEFCON this year? Consider presenting at BSides Hanoi instead. Now in its second year, the conference takes place on August 5th, 2026, and a few more talk slots are still open - but the submission deadline is today. Apply here: www.bsideshanoi.net/en/call-for-...
Call for Paper - BSides Hanoi 2026
Submit your proposal for BSides Hanoi 2026 NoHuman.
buff.ly
We know vulnerability reports are not like ordinary issues. But why? It comes down to needing the scarce insight and temporary confidentiality to protect users. However, now that LLMs can find more or less the same bugs for everyone, none of that matters, and vuln reports are not special anymore.
Vulnerability Reports Are Not Special Anymore
We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?
words.filippo.io
My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: arstechnica.com/security/202...
How a USB-connected speaker can infect a PC without ever being touched
Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability.
arstechnica.com
ATX Go is TONIGHT (a week early this month): Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go. www.meetup.com/atxgolang/ev...
ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
meetup.com
ATX Go is a week early this month, tomorrow night! Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go: www.meetup.com/atxgolang/ev...
ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
meetup.com
🚨 New runZero 4.9: We got you, defenders! 📈 Interactive attack path mapping 👁️ Multi-homed detection 🗺️ 2D/3D topology maps 🧠 Deep OT intel + field-level discovery ✅ Protocol exposures 🔥 Risk prioritization 💻 UI/UX enhancements 👉️ Release details at: www.runzero.com/blog/runzero... #OTsecurity
Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future: sockpuppet.org/blog/2026/03...
Vulnerability Research Is Cooked — Quarrelsome
For the last two years, technologists have ominously predicted that AI coding agents will be responsible for a deluge of security vulnerabilities. They were right! Just, not for the reasons they…
sockpuppet.org
Up next on #runZeroDay at 12:30 PM PT – Force multiplied: Community-powered vuln detection. Our guest is Rishiraj Sharma from ProjectDiscovery. Don’t miss a minute! Watch it live at: www.runzero.com/rsac-live-20...
Joseph Menn, renowned journalist & author of "The Cult of the Dead Cow," joins us for a special book signing event at RSAC! runZero and Mallory are thrilled to co-host a private book signing with renowned investigative journalist Joseph Menn during RSA: www.runzero.com/joseph-menn-...
Joseph Menn Book Signing
Complete security visibility across IT, OT, IoT, cloud, mobile, and remote assets.
runzero.com
Join author Caroline Wong for the release of "The AI Cybersecurity Handbook" at RSAC! runZero and Mallory are thrilled to co-host a private book signing with the AI cybersecurity strategist Caroline Wong during RSA Conference 2026! www.runzero.com/caroline-won...
Caroline Wong Book Signing
Complete security visibility across IT, OT, IoT, cloud, mobile, and remote assets.
runzero.com
#RSAC session today at 10:50 AM PT – Preparing for AI Vulnerability Exploitation: Preventing Cataclysm. 👀 Don’t miss this panel featuring @runzero.com’s CEO @hdm.io, @argv.bsky.social (Google), and @gadievron.bsky.social (Knostic). 🗓️ TODAY at 10:50 AM PT
AI vulnerability discovery is here. Don’t miss the #RSAC 2026 session-Preparing for AI Vulnerability Exploitation: Preventing Cataclysm-featuring our CEO @hdm.io, Google’s @argv.bsky.social & Knostic’s @gadievron.bsky.social. 🗓️ Mon, Mar 23 @ 10:50 AM PT path.rsaconference.com/flow/rsac/us...
"The @phrack CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :)" phrack.org (via @richinseattle)
PHRACK CALL FOR PAPERS
phrack.org
The Phrack Staff is on the latest episode of the DarknetDiaries episode! darknetdiaries.com/episode/170/
Phrack – Darknet Diaries
Phrack is legendary. It is the oldest, and arguably the most prestigious, underground hacking magazine in the world. It started in 1985 and is still running today. In this episode we interview the Phr...
darknetdiaries.com
Huh -- this week, the FBI uploaded 35 pages on Phrack to its FOIA Library vault.fbi.gov/phrack/phrac...
Phrack (Final)
vault.fbi.gov
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises: arstechnica.com/security/202... AirSnitch resets WiFi security back to the bad-old-days of ARP spoofing and trivial MITM.
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises
That guest network you set up for your neighbors may not be as secure as you think.
arstechnica.com
Hello Austin Go hackers! Tonight (2026-02-11) is our next ATX Golang meetup, located in Station Austin (aka Capital Factory ). We will have pizza, drinks, and various short talks and discussions related to the Go ecosystem: www.meetup.com/atxgolang/ev...
ATX Golang Meetup - February 2026, Wed, Feb 11, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
meetup.com
runZero users get a new feature today (including Community Edition) - recurring internet speed tests for all deployed Explorers! This (very optional) capability lets you identify backhaul/connectivity issues for sites that you can't physically get to: www.runzero.com/blog/interne...
Run Internet speed tests from runZero Explorers
Get an early signal into usability before you scan. Measure internet connectivity via runZero Explorers to remove uncertainty, with audit logs included.
runzero.com
It's time for our first ATX Gopher meetup of the year! If you are in Austin and write Go code (or would like to start), please join us at 6:30pm at Station Austin (co-located with Capital Factory). Charles and I will be providing pizza and drinks as usual: www.meetup.com/atxgolang/ev...
ATX Golang Meetup - January 2026, Wed, Jan 14, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
meetup.com
🎧 We collected some of our favorite podcasts of 2025 featuring @hdm.io for you to enjoy. 📺 So go ahead and get yourself some coffee (or hot cocoa!) & watch here: www.runzero.com/blog/fun-pod...
Exposure is everywhere now — cloud, SaaS, IoT, shadow IT, unmanaged vendors. Replay the SC Media webcast with @sawaba.bsky.social, @hdm.io & @todb.hugesuccess.org to learn why continuous discovery matters & how attackers exploit what you can’t see. 👉 www.runzero.com/resources/as...
🎙️ The Hacker's Cache: Kyser Clark talks with Metasploit creator @hdm.io on why CVEs won’t save you in 2025. They get into non-CVE vulns, hidden SSH risks, attacker innovation, AI’s impact, and why exposing version numbers can improve security. 👉 www.runzero.com/resources/wh...
On the latest Risky Biz, @patrick.risky.biz, and @hdm.io talk about visualizing the attack surface with runZeroHound, why you can't synthesize what runZero delivers, & how we are leveraging AI to help predict risks and scan smarter. 📺 Watch the full interview: www.runzero.com/resources/ri...
📺 Live webcast Dec 3 with SC Media! Your attack surface doesn’t end at the firewall. Join @hdm.io, @todb.hugesuccess.org, and @sawaba.bsky.social to learn how continuous discovery + attack path mapping keeps you ahead. 👉 www.scworld.com/cybercast/at...
scworld.com