Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense.
Host of CanSecWest, and PacSec.
Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF.
VA7MOV
Posts
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh.
CVE-2026-55200 — libssh2 pre-auth heap OOB write, server supplied length runs past heap allocation
Because the trigger sits in the transport layer ahead of full server authentication, network-position attacks (DNS hijack, ARP/BGP, a malicious forward proxy) can deliver the packet even where the client pins host keys, assuming the early-KEX reachability holds.
https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
This kind of hurt my eyes and my brain, and reinforced my opinion that FreeBSD is a softer target amongst OS platforms. It is pretty funny though, and definitely gets some style points for a vulnerability disclosure.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
It's over petrofuel industry, solar has the high ground.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
The Anthropic Fable-5 safety classifiers seem to be written by the OpenAI marketing department.
Pretty much anything I talk to LLMs about gets downgraded.
Nerfed into useless. Worst model release ever?
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
When you leave all the mitigations on, crank up the inference settings to maximum, and run the exploit benchmark to see how close the PoCs can get.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
The thought processes of AI native kids: 9-year old gets a DOCX file from school laptop, wants to read it, doesn't have M365. His first impulse is to use GPT to write a python script to convert it to TXT so he can use VSCode, instead of asking for Word license or searching for converter.
When AI is the path of least resistance.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
🚨 CVE-2026-48710 ("BadHost"): one character in a Host header bypasses path-based auth across most of the internet's Python AI stack.
In Starlette → FastAPI → vLLM, LiteLLM, TGI, MCP servers, agent harnesses. Found by X41 during a vLLM audit.
Patch shipped after 4 months quietly as CVSS 6.5 scoped as a "web framework problem"; but discoverers say critical.
Fix: Starlette 1.0.1.
Scanner: https://badhost.org
Semgrep+CodeQL: https://github.com/x41sec/poc/tree/master/starlette-host-header
Hat Tip: @marver@mastodon.social
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Raelize had Claude Code reproduce an ESP32 Secure Boot V1 bypass via voltage glitching. AI wrote all software: ChipWhisperer Husky control, RK6006 voltage sweeps, PicoScope verification, boot ROM reversing via sub-agent, plus a live dashboard built while glitching. 20k shots, 12.2% bypass rate, 57%+ at two voltage peaks. Two evenings, no human code. Workflow compression is the story.
https://raelize.com/blog/ai-fi-giving-claude-code-glitch-skills-for-bypassing-secure-boot/
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
"Dirty Frag" status update on the clickbait overhype: ESP half (CVE-2026-43284) now patched: mainline f4c50a4034e6, stable backports in 7.0.5 / 6.18.28 / 6.12.87 / 6.6.138 / 6.1.171 / 5.15.205 / 5.10.255. RxRPC half (CVE-2026-43500) still unpatched upstream. AWS now adds ipcomp4/ipcomp6 to the blacklist alongside esp4/esp6/rxrpc, adjacent xfrm code paths, defense in depth or a hint more is coming. AlmaLinux and CloudLinux shipped both fixes. Ubuntu, Debian, RHEL, Amazon still mitigation only.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
My retort for anyone who insists LLMs are just "spicy autocorrect" and can't reason:
Sure, and you're just spicy electrochemistry. If it walks like reasoning, and proves theorems like reasoning, maybe we need to stop calling it a duck shaped Markov chain.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Copy Fail (CVE-2026-31431):
The modprobe.d + rmmod recipe is inadequate. Both populations equally vulnerable; the fix differs.
RHEL/Alma/Rocky/Oracle: compiled in — need initcall_blacklist + reboot.
Ubuntu/Debian: auto-loads on AF_ALG bind — block via modprobe.d install /bin/false.
aarch64, Alpine/busybox: PoC fails. Still vulnerable.
Local root + K8s container escape. Page cache attack; FIM blind.
Mitigation: https://secwest.net/copyfail-mitigation
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Interesting critical analysis of IPv8 Draft...
https://shitwolfymakes.substack.com/p/we-need-to-talk-about-the-ipv8-draft
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
A walkthrough on patching Dell UEFI firmware at the SPI flash level to disable pre-boot DMA protection — bypassing the BIOS password entirely. The interesting part: the UEFI UI still reports the setting as enabled, and TPM measured boot doesn't detect the NVRAM change, so BitLocker unlocks normally. The patch also persists through official Dell BIOS updates. From there it's DMAReaper to kill IOMMU + PCILeech for a SYSTEM shell. Significant measured boot policy gap. https://www.mdsec.co.uk/2026/03/disabling-security-features-in-a-locked-bios/
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Your UEFI firmware can inject a PE binary into Windows on every boot via WPBT (Windows Platform Binary Table). smss.exe extracts it to disk and runs it as SYSTEM. OEMs use this to survive OS reinstalls. Attackers use it the same way.
One registry key tells Windows to ignore the table entirely:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v DisableWpbtExecution /d 1 /t REG_DWORD /f
Won't stop real firmware implants, but kills a whole class of cheap persistence for free.
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
Time to update microcode on your Intel processors (gen >9)...
New speculative prediction bug lets you capture /etc/shadow with 99% reliability. They didn't make anything like it work on AMD or ARM... yet...
https://comsec.ethz.ch/research/microarch/branch-privilege-injection/
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Do security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV
How to inject/spoof positional _audio_ mic arrays remotely using _lasers_.
CanSecWest2025_newtype Presentation:
Cross-Medium Injection: Exploiting Laser Signals to Manipulate Voice-Controlled IoT Devices
Hetian Shi, Tsinghua University
So that positional mic array in your Tesla can be spoofed with lasers to hear "Unlock the Car" and the positional audio microphone array system will think the command is coming from inside the car.
April 24/25 in Vancouver.
https://secwest.net