We have a year to fix security everywhere
GLM 5.3-flash released last week, and that means Project Glasswing and Daybreak are running out of time. Cheap models capable of dangerous hacking are now available to anyone, without the normal safeguards for refusing malicious actions. We need to fix vulnerabilities across the industry so that we aren’t caught unawares. And for one of the […]
The NX bit is not just about security
September 4, 2026 Guest post Lobsters While I’m taking a short break from low-level programming, here’s a story by a friend of mine, Sonya, about debugging a seemingly impossible bug in ARM code. This bug hunting saga started several months ago. While developing a bare-metal hypervisor on ARM64 for postmarketOS, I hit a strange bug: […]
SeL4 security proofs now complete on AArch64

Proofcraft News – 2026 Proofcraft seL4 security proofs now complete on AArch64 After completing the proofs of functional correctness and integrity, Proofcraft has now established the proof that seL4 enforces confidentiality on AArch64, providing a formal mathematical proof that the kernel prevents an application running on top of seL4 from learning information without authorisation. Thanks […]
FIPS 140-3 is not a security guarantee, and auditors know it
A sales engineer at one of the major HSM vendors told me recently that over 90 percent of their customers who buy FIPS-enabled HSMs run them with FIPS mode disabled. They pay a premium for the certificate, then switch off the configuration it describes. By the end of this article you will understand why that […]
Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]
Download PDF
My security camera shipped a GitHub admin token in its login page

i have been thinking a bit more about security cameras again, because of AXIS starting to push more for every one of their cameras to be able to easily run linux applications on them, they’re far more serious targets in an enterprise environment and need to be managed as such for vulnerabilities and credential management […]
Security Envelope Pattern collection – S.E.C.R.E.T
Security Envelope Pattern collection | S.E.C.R.E.T. The Society for the Exploration of Confidential Repetitive Envelope Tints WELCOME TO
Security through obscurity is not bad
Escaping the crowded echo chamber I was recently reading a post by a user on a web development forum. This user, whom we’ll call Mini, was asking the community whether it was worth using JavaScript obfuscation for some of the scripts running on their website. Their main goal was to make it harder for data-scraping […]
AI Slop vs. OSS Security

03 Nov, 2025 Author’s Note I have spent the better part of a decade in the bug bounty industry, and my perspective on this industry is shaped by this experience. The first five years were spent as a bug hunter and vulnerability researcher, where I developed an intimate understanding of what it takes to find, […]
X.org Security Advisory: multiple security issues X.Org X server and Xwayland
X.Org Security Advisory: multiple security issues X.Org X server and Xwayland Olivier Fourdan ofourdan at redhat.com Tue Oct 28 13:22:18 UTC 2025 ====================================================================== X.Org Security Advisory: October 28, 2025 Issues in X.Org X server prior to 21.1.18 and Xwayland prior to 24.1.8 ====================================================================== Multiple issues have been found in the X server and Xwayland implementations […]