push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
..
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Thank you for calling The Void. All our operators are cursed right now but please hold the line and leave your scream after the tone.
Also:
(not exactly a fan...)
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Interesting Git repos of the week:
Strategy:
Detection:
Bugs:
Exploitation:
Hard hacks:
Nerd:
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Interesting links of the week:
Strategy:
Standards:
Threats:
Detection:
Bugs:
Data:
Nerd:
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Interesting Git repos of the week:
Detection:
Bugs:
Exploitation:
Hard hacks:
Data:
Development:
Nerd:
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
For all the AI hype, I'm absolutely fascinated to see more bug content that focusses on the mass of internal, commercial, compiled code that runs businesses. Most of the disclosures thus far appear to be for open source, where we should assume the models know the code, have seen the bug reports and have access to the patches but that's really not the reality of "interesting" enterprise software.
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Interesting links of the week:
Strategy:
* https://cset.georgetown.edu/article/chinas-pla-challenges-and-competitions/ - analysing .cn PLA strategy
* https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/ - Locked Shield 2026 reporting
* https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board - post-incident review is necessary, ya galah
* https://dukesecurity.ai/incidents - SEC disclosed incidents
* https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference - how .ru trains their spies on fiddling with elections
* https://arxiv.org/abs/2509.00462 - AI, stealing all the jobs
* https://arxiv.org/abs/2604.01637 - but first they need job specs
* https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring - NCSC guidance on DFIR and protective monitoring
* https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ - thought piece from Mozilla on Mythos
* https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities - UK AI Security Institute review of GPT 5.5
* https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ - behind the Mythos curtain with Mozilla
* https://uktl.org.uk/news-events/uktl-ncsc-and-ericsson-strengthen-the-security-of-uk-mobile-networks/ - improving UK telco security
Threats:
* https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html - Trend write up on .cn attacks in Asia
* https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/ - TETRA abuse in the wild
* https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf - new reporting on APT29
* https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf - reporting on Tropic Trooper from BlackHat Asia 2026
* https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/ - attacks on CNI intensify
Detection:
* https://righteousit.com/2026/03/27/linux-forensic-scenario/ - @hal_pomeranz@infosec.exchange's Linux investigation (there are a number of follow on posts)
Bugs:
* https://retr0.zip/blog/cve-2026-31431-copy-fail.html - more on copy.fail
* https://seclists.org/oss-sec/2026/q2/332 - winning a race with Rust
* https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability - more on the FreeBSD dhclient whoopsie
* https://copy.golf/ - copy.fail.golf
* https://visit.suspect.network/reversing-adventures/inadvertent-injections - accidentally injecting shells
Exploitation:
* https://fuzzinglabs.com/exploring-nvidia-linux-drivers-internals-basics-ioctls/ - exploring NVIDIA's LKM attack surface
* https://www.blackhillsinfosec.com/the-p-in-pam-is-for-persistence-linux-persistence-technique/ - @blackhillsinfosec@infosec.exchange discuss persisting in PAM
* https://www.group-ib.com/blog/pluggable-authentication-module/ - why PAM matters
* https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/ - solutions to @trailofbits@infosec.exchange's C challenges
* https://ipurple.team/2026/05/04/cross-session-activation/ - cross session lateral moment in Windows with @netbiosX@infosec.exchange
* https://heyitsas.im/posts/drinking-llms/ - bug hunting the Linux kernel with LLMs
* https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/ - fuzzing Microsoft RPC
Hard hacks:
* https://labs.taszk.io/articles/post/tapocalypse/ - TP-Link whoppers
* https://tantosec.com/blog/2026/04/route-to-root-in-4g-industrial-router/ - hacking a 4G router
Hardening:
* https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/ - @jwildeboer@social.wildeboer.net's approach to beating copy.fail
* https://www.secwest.net/copyfail-mitigation - more on copy.fail mitigations
Nerd:
* https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-problem - be mindful of who you mix with
* https://di.day/en - declare your independence
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Interesting Git repos of the week:
Strategy:
* https://github.com/center-for-threat-informed-defense/attack-flow - mapping ATT&CK flows
Detection:
* https://github.com/timb-machine-mirrors/ddamenova-IRQL.md - KQL for IR
* https://github.com/ridgelinecyberdefence/vanguard - Go toolkit for IR
* https://github.com/SharonBrizinov/Holy-Grail-PCAP - new food for Packet Monkey
* https://github.com/Nextron-Labs/surface-watch - @cyb3rops@infosec.exchange's code to keep an eye on the front door
* https://github.com/keydet89/RegRipper3.0 - @keydet89@infosec.exchange's seminal IR toolkit in Perl
Bugs:
* https://github.com/V4bel/dirtyfrag - more Linux sadness
Exploitation:
* https://github.com/azqzazq1/SunnyDayBPF - imagine that, a kernel that lies
* https://github.com/BlackSnufkin/LitterBox - red teamer's sandbox
* https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper - dump Edge passwords from memory
* https://github.com/her3ticAVI/PAMSkeletonKey - a skeleton key for PAM
* https://github.com/segmentati0nf4ult/linux-pam-backdoor - an earlier version of the same code
* https://github.com/Kudaes/Puzzle - abusing Windows minifilters
* https://github.com/diemoeve/oxide - a new C2 framework
* https://github.com/TwoSevenOneT/DefenderWrite - enumerate AV whitelisted executables for LPE with @TwoSevenOneT@infosec.exchange
Hardening:
* https://github.com/wgnet/wg.copyfail.patch - a nice little eBPF patch for copy.fail
* https://github.com/atgreen/block-copyfail - another eBPF approach to copy.fail from @atgreen@hachyderm.io 🤖
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Citations are nice. Thank you anon.
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Long old week but 5 happy customers, two commuting to renewals makes it all worthwhile. I shall sleep well tonight.
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Provided genuine and nuanced feedback on AI slop on AI slop. Comments all deleted and article published. That'll teach me to spend time making suggestions to improve an article.
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Stumbled into a channel where everyone is replacing themselves with their AI pets and well, if you're the kind that needs an agent to do anything then no wonder you're having trouble installing an agent...
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
The statement "lies, lies and statistics" could have been written by an AI, and now thanks to LLM, it will be.
push(@fediverse, "Adversarial Engineer"); # i hack in Perl
Congratulations to Canonical on poor life choices:
https://seclists.org/oss-sec/2026/q2/332
#threatintel, #non-GNUcoreutils