NeuroWinter
@neurowinter.com
Reformed #AI & #MLOps tinkerer turned #SRE, now keeping #opensource databases alive. Long-time #AppSec enthusiast, accidental sysadmin, and fueled almost entirely by espresso. Blogging sporadically at NeuroWinter.com
Whats that ? A new post on the Chinese wool farming underground? And this time they are defrauding State owned media, and govt? wow:
Forging the government’s lottery: China’s civic apps run on a shared reward backend with no real secret
Dozens of Chinese city, civic and state-media apps run their points-and-lottery campaigns on a handful of shared B2B SaaS backends. The signing that protects them uses a public salt and a key the…
neurowinter.com
Next post in my Wool series is now live, this time its looking at the scene as a whole, and how to perform OSINT on repos, and how trying to hide your tracks is a singal on its own! neurowinter.com/security/202...
Sixteen strangers and a shared obfuscator: mapping the wool scene
A 16 actor map of a Chinese reward farming scene, built out from a single GitHub repo over a weekend. The operators know GitHub is dangerous and scrub their history religiously, but they defend the pa...
neurowinter.com
JailCTF 2026 Format Write Up A pyjail with no output channel at all. You can only count prompts. `{0[N].__len__}` turns each character into an address, and ASLR moves whole pages, so the last 3 hex digits never move. #ctf #infosec #netsec #jailctf2026 blog.roblab.us/jailctf-2026...
jailCTF 2026: format Write Up
The jail prints nothing and swallows every exception, so all you can measure is how many prompts come back. CPython's one-character string cache is what makes that enough.
blog.roblab.us
Got a cool story? Want to share how you did something cool with GraphQL? Speak at GraphQL Day London! Applications close soon ➡ graphql.org/day/2026/lo...
GraphQL Day @ FOST London — Sep 30-Oct 1 | GraphQL Day 2026
GraphQL Day @ FOST — community-organized GraphQL events at Future of Software Technologies conferences worldwide.
graphql.org
Starting my vacation and seeing if I can leave my phone in "dumb phone" mode all week
Welp heard about the new Kimi K3 model from Moonshot ai. Tried to sign up for it and all their packages are sold out !
Here's an article we published nearly six weeks ago that's suddenly getting reads again: Arch Devs Scramble as 400 AUR Packages Infected With Malware - FOSS Force buff.ly/aj8UKqY
Arch Devs Scramble as 400 AUR Packages Infected With Malware - FOSS Force
Arch User Repository hit by a large-scale malware campaign, with maintainers racing to roll back malicious commits and lock out bad actors.
buff.ly
Well rip. I’ve nearly gotten my #Nitropad set up just the way I like it with salt managing my appvms and templates and now I have a really bad rattling fan that stops often. Tried playing air into it, no luck. I got the tamper evident screws so I can’t even get into it to diagnose:(
I was always sent to primary school with a handkerchief in my pocket. But I don’t think I’ve touched one in years. Does anyone still use them ?!
the iMac G3 remains Peak Computer Design to this day
Fuck off. If anything is "millennial", it's those cool transparent colors our iMacs, Gameboys, and Tamagotchis came in. No fucking millennial likes the house flipper grey. Call it a millennial paint job when I can see through the exterior of a car because it's Glacier Purple like my GBA.
I want to fill all those Comunity libraries with anarchist literature.
My wife and I are sick and miserable. But our cats are so damn happy they get to spend the day in bed with both of us
No thank you ! I don’t want Claude to have full access to impersonate me on 3rd party websites ! 1password.com/blog/1passwo...
1Password for Claude: Give Claude access without giving up your credentials | 1Password
Give Claude access, without giving up control of your secrets. 1Password now enables AI agents to complete tasks requiring credentialed access, while keeping your credentials encrypted, secure, and in...
1password.com
I’ve seen a lot of reporting that these two were the king pins of Scattered Spider, and this is the end of the group. However I find that hard to believe somehow. www.bleepingcomputer.com/news/securit...
Scattered Spider members behind TfL hack get five years in prison
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
bleepingcomputer.com
A suspected crypto scammer has been arrested for stealing $220,000 by hiding malware inside Steam games FBI tracked him through his Uber Eats deliveries
Whats that ? A new post on the Chinese wool farming underground? And this time they are defrauding State owned media, and govt? wow:
Forging the government’s lottery: China’s civic apps run on a shared reward backend with no real secret
Dozens of Chinese city, civic and state-media apps run their points-and-lottery campaigns on a handful of shared B2B SaaS backends. The signing that protects them uses a public salt and a key the…
neurowinter.com
The exact model behind my Qubes OS build and well Qube OS as a whole! a qube per identity minimal Fedora templates and guess what all Salt managed. Let’s hope that helps with my upgrading os woes. #QubesOS #infosec
Highlight from A Hacker's Mind
<p> Compartmentalization (isolation/separation of duties): Smart terrorist organizations divide themselves up into individual cells. Each cell has limited ...
armitagesarchive.com
Super happy to be finally 1 year #sober !! It’s still hard, and some days are still a real slog but it’s better
Here are some of the passages from that article I thought were interesting: armitagesarchive.com/articles/vul...
Vulnerability Reports Are Not Special Anymore
Highlights and excerpts from the article: Vulnerability Reports Are Not Special Anymore.
armitagesarchive.com
Recently read this interesting article. words.filippo.io/vuln-reports/ While we 100% have an issue with an influx of horrible reports, I still belive that each and every even mildly applicable report should be given special attention. It’s the ones that don’t that will split through the cracks.
Vulnerability Reports Are Not Special Anymore
We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?
words.filippo.io
Lesson learnt from this trip to AU. Early morning flights suck. Security doesn’t even open at Auckland airport until 4:30 am. Late night flights suck. Landing near midnight means your next day is ruined