🔧 AI Nachrichten Trump is giving data centers a pass to pollute(12.09.2026 um 16:41 Uhr)
🔧 AI Nachrichten Anthropic CEO says it’s time to pump the brakes on AI(12.09.2026 um 18:23 Uhr)
🔧 ProgrammierungRust 1.98.1 fixes miscompilation bug(04.09.2026 um 00:49 Uhr)
🔧 ProgrammierungYour frontend observability has an accessibility blind spot(10.09.2026 um 11:00 Uhr)
⚠️ Malware / Trojaner / VirenAnthropic details bad actors’ efforts to misuse its AI for bioweapons(11.09.2026 um 00:35 Uhr)
🔧 AI Nachrichten I spent $4,000 on a robot dog from China(12.09.2026 um 13:00 Uhr)
⚠️ Malware / Trojaner / VirenFrom Hacks to Bioweapons, Claude Misuse Is Now Everywhere(12.09.2026 um 12:30 Uhr)
🔧 AI Nachrichten Trump is giving data centers a pass to pollute(12.09.2026 um 16:41 Uhr)
🔧 AI Nachrichten Anthropic CEO says it’s time to pump the brakes on AI(12.09.2026 um 18:23 Uhr)
🔧 ProgrammierungRust 1.98.1 fixes miscompilation bug(04.09.2026 um 00:49 Uhr)
🔧 ProgrammierungYour frontend observability has an accessibility blind spot(10.09.2026 um 11:00 Uhr)
⚠️ Malware / Trojaner / VirenAnthropic details bad actors’ efforts to misuse its AI for bioweapons(11.09.2026 um 00:35 Uhr)
🔧 AI Nachrichten I spent $4,000 on a robot dog from China(12.09.2026 um 13:00 Uhr)
⚠️ Malware / Trojaner / VirenFrom Hacks to Bioweapons, Claude Misuse Is Now Everywhere(12.09.2026 um 12:30 Uhr)

🕵️ Sicherheitslücken 🕛 vor 3 Std. 3 Min Lesezeit SECURITY-FEED
0

media.ccc.de: MRMCD2026 - The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 202

↗ Quelle (YouTube · media.ccc.de)
🗣️ Stimme:
📺
YouTube · media.ccc.de
152 YouTube-Aufrufe
https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026

In 2025, I found and disclosed a bunch of vulnerabilities in GPG, the most used PGP implementation, and held a talk at 39c3 about it. **Some** of the bugs ended up getting fixed. This talk describes the adventure and aftermath of getting there, shows some novel ones, and talks about the state of security in 2026. May contain zero-days =)

Until May 2025, I liked PGP, and the GNU Privacy Guard. I poked at it in my free time a lot. One day, that suddenly changed, when I flew too close to the sun and ended up uncovering a vulnerability that allows you to easily spoof a PGP signature when opened naively with the GPG tool.

Fast-forward a couple of months, the one vulnerability turned into several independent ones, up to memory corruption in the basic PGP message parser, affecting almost all PGP-related workflows.

I disclosed these a few weeks before 39c3 in December 2025. And while some of the vulnerabilities - like the memory corruption in the message parser - got addressed properly, this was not the case for all of them.

For example, one of the first vulnerabilities I found, that was used for the introduction hook in the 39c3 talk, remains unpatched to this day. Instead of being fixed with code, Werner Koch - the main developer of GnuPG - published a blog post declaring the widely-used feature being "harmful"; while they had weeks in advance, they published this on day one of 39c3, not even giving us time to respond.

Several disgruntled comments followed, but a good portion of the flaws are still not addressed, as I will demonstrate live in the talk. This specific demonstration will not utilize any zero-day vulnerabilities (those come next); we will be showing how much of an issue the footguns (that they refuse to address) at hand really are.

Additionally, I will present a few novel vulnerabilities on GPG. Not quite the bombshells as last time, but some nifty bugs that should never have made it into production in the first place, but to demonstrate the state of the GnuPG codebase.

The talk closes with some general commentary about the state of security and responsible disclosure, and touch on the topic of AI/LLMs in security (with some of the gpg.fail vulnerabilities as examples); what this means for security researchers, ordinary people and software developers (spoiler: neither end users nor security researchers are doomed).

49016 / Lexi Groves

https://talks.mrmcd.net/2026/talk/D3V8QJ/

#mrmcd26 #Security

https://creativecommons.org/licenses/by-sa/4.0/
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
5 Quellen
Rockwell Automation FactoryTalk Activation Manager
2 Quellen
Jetzt patchen! Angreifer attackieren JFrog Artifactory und machen sich zu Admins
2 Quellen
Zero-Day-Lücke StyleSmuggler in Magento und Adobe Commerce wird aktiv ausgenutzt