need you all to see this deeply indescribable cooking video
I'm very happy to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to DEF CON 34! This research was a huge gamble and the result was glorious, can't wait to share!
Notifications for deleted shouldn't remain in any OS notification database, and we've asked Apple to address this. In the meantime, you can prevent any preview text from your Signal messages from appearing in your notifications. Signal Settings > Notifications > Show “No Name or Content”
NEW: The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database, multiple people present for FBI testimony in a trial told 404 Media.
I feel like we're not addressing the most concerning news from Mythos
> We demonstrate that Shor’s algorithm...can execute with either ≤ 1200 logical qubits and ≤ 90 million Toffoli gates or ≤ 1450 logical qubits and ≤ 70 million Toffoli gates research.google/blog/safegua... quantumai.google/static/site-...
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
Every day we wake up to more of this.
Hadn't realised that the third party review of Twitter's chat protocol had been published and wow github.com/trailofbits/...
github.com
Our digital systems reward belonging over accuracy, with people gaining status by aligning with their group, not by checking facts. Once beliefs become tied to identity, more media literacy won’t shift behaviour, the social rewards run against work against it.
my latest investigation for @consumerreports.org is based on months of reporting and 60+ lab tests of leading protein supplements we found that most protein powders and shakes have more lead in one serving than our experts say is safe to have in a day (🧵) www.consumerreports.org/lead/protein...
Protein Powders and Shakes Contain High Levels of Lead - Consumer Reports
CR tests of 23 popular protein powders and shakes found that most contain high levels of lead.
consumerreports.org
Workday discloses "third-party CRM" breach... most likely their Salesforce account blog.workday.com/en-us/protec...
Protecting You From Social Engineering Campaigns: An Update From Workday
blog.workday.com
Exciting! MLS e2ee messaging with fingerprints in Bluesky bios (to prevent silent bindings) and pre-keys in PDS. Kinda wish the key was published in the DID document though, especially if one day plc.directory will become a tlog. (Basically free KT!) www.germnetwork.com/blog/integra...
Integrating Germ with AT Protocol — Germ Network
End-to-end encrypted Germ DM is now a Bluesky messenger. In this technical post, we introduce the architecture of Germ’s integration with AT Protocol. From the beginning, Germ has been building for an...
germnetwork.com
It’s here! Germ DM is now an #ATProto messenger. Read our full announcement now.
New from 404 Media: we spoke to the researcher who found hackers can remotely trigger brakes on American trains. Says was ignored for years, DHS confirmed. "All of the knowledge to generate the exploit already exists on the internet, AI could even build it for you." www.404media.co/hackers-can-...
Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
“All of the knowledge to generate the exploit already exists on the internet. AI could even build it for you,” the researcher told 404 Media.
404media.co
Just to clear up some misinfo, a BGP hijack was not the cause of Cloudflare DNS going down today. At 21:51 UTC, Cloudflare (AS13335) withdrew both 1.1.1.0/24 and 1.0.0.0/24 for an unknown reason. I suspect AS4755 was always announcing 1.1.1.0/24, when CF went away, it leaked a bit (%2).
Activision has pulled a Call of Duty game after multiple reports of PC players having their computers hacked. An old insecure version of the game was reportedly uploaded to the Microsoft Store 😬 www.theverge.com/news/702255/...
Activision pulls Call of Duty game after PC players are hacked
Call of Duty: Remote Code Execution
theverge.com
Today’s unsigned, unexplained #SCOTUS ruling clearing the way for removals of migrants to third countries without any additional process is a disaster—not just on the merits, but because of the government misbehavior that it not only refuses to punish, but effectively rewards. Me, via “One First”:
161. The Court's Disastrous Ruling in the Third-Country Removal Case
The majority did not just greenlight an especially odious immigration policy without any explanation; it did so in a case in which the government defied the district court—twice—with no consequence.
stevevladeck.com
Here's something I am very excited about: Photosynthesis! 🌱☀️ A proposal to have CAs run transparency logs and make X.509 certificates out of Merkle Tree inclusion proofs. This is similar to how CT would have worked in an ideal world, and it solves the problem of PQC sizes in logs and handshakes.
[TLS] Photosynthesis, an update to Merkle Tree Certificates
Photosynthesis combines the Static CT API with the ideas in Merkle Tree Certificates.
mailarchive.ietf.org
this is actually how my cursed Online brain read the post
A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange.
Coinbase breach tied to bribed TaskUs support agents in India
A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange.
bleepingcomputer.com
Most engineers aren’t taught how to write secure code or catch threats after deploy. Detection engineering used to be limited to experts. Now anyone can do it with prompts, Goose, and the Panther MCP server. 💪 block.github.io/goose/blog/2...
Democratizing Detection Engineering at Block: Taking Flight with Goose and Panther MCP
A comprehensive overview of how Block leverages Goose and Panther MCP to democratize and accelerate security detection engineering.
block.github.io
New, by me: Compliance startup Vanta said it's fixing a bug that exposed some customer data to other Vanta customers. One Vanta customer told us that they were notified that some of their data was pulled out of their Vanta instance "into other customers’ instances."
Vanta bug exposed customers' data to other customers | TechCrunch
The compliance company said the customer data exposure was caused by a product change.
techcrunch.com
I'm often asked if I'll redo the 2019 quantum factoring estimate. Denser storage by yokes, smaller magic factories by cultivation, slimmer approx arithmetic by Chevignard et al… surely the cost is lower now? Yes, it's lower now. security.googleblog.com/2025/05/trac... arxiv.org/abs/2505.15917
SCOOP: In Feb, federal agencies "lost" many #FOIA requests but you probably had no idea. It turns out that the FOIAs disappeared due to an "insider threat attack" by 2 employees at a software company who were previously convicted of hacking into the State Dept 🧵 🎁 www.bloomberg.com/news/article...
Probe Found Security Lapses Led to US Contractor’s Data Breach
Failures in cybersecurity practices at a software company that helps federal agencies manage investigations and FOIA requests allowed two convicted hackers to delete databases, according to internal d...
bloomberg.com
New: Docker Hardened Images 🔐 ✅ Non-root by default ✅ SLSA Level 3 compliant ✅ SBOMs, VEX, provenance — all signed ✅ Built-in to Docker Hub 👉 http://spklr.io/63323CAqR #Docker #DevSecOps #SoftwareSupplyChain #Containers #CloudNative #DockerHardenedImages
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server micahflee.com/ddosecrets-p...
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server
This morning, Distributed Denial of Secrets published 410 GB of data hacked from TeleMessage, the Israeli firm that makes modified versions of Signal, WhatsApp, Telegram, and WeChat that centrally arc...
micahflee.com
Here's how the TM SGNL server, which had access to plaintext chat logs from people like Mike Waltz, got hacked in about 20 minutes www.wired.com/story/how-th... (my first article in @wired.com!)
Time to update microcode on your Intel processors (gen >9) new speculative prediction bug lets you capture /etc/shadow with 99% reliability. They didn't make anything like it work on AMD or ARM, yet... comsec.ethz.ch/research/mic... www.intel.com/content/www/... github.com/intel/Intel-...
Branch Privilege Injection: Exploiting Branch Predictor Race Conditions – Computer Security Group
comsec.ethz.ch
Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs. My findings are based on TM SGNL's source code, and they are corroborated by hacked data micahflee.com/despite-misl...
Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs
Despite their misleading marketing, TeleMessage, the company that makes a modified version of Signal used by senior Trump officials, can access plaintext chat logs from its customers. In this post I ...
micahflee.com
TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. “I would say the whole process took about 15-20 minutes,” the hacker said micahflee.com/the-signal-c...
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
micahflee.com