so criiiinge
https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/
CVE-2026-24061: Telnetd RCE as Roothttps://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/
SafeBreach
Root Cause Analysis & PoC Exploit for CVE-2026-24061 | SafeBreach
Learn more about SafeBreach Labs root cause analysis and PoC exploit for critical CVE-2026-24061: Telnetd RCE as Root Vulnerability.
🙈1
https://threadreaderapp.com/thread/2022387879390122049.html
in case you think computers are deterministic
in case you think computers are deterministic
X (formerly Twitter)
LaurieWired (@lauriewired) on X
CPUs are getting worse.
We’ve pushed the silicon so hard that silent data corruptions (SDCs) are no longer a theoretical problem.
Mercurial Cores are terrifying because they don’t hard-fail; they produce rare, but *incorrect* computations!
We’ve pushed the silicon so hard that silent data corruptions (SDCs) are no longer a theoretical problem.
Mercurial Cores are terrifying because they don’t hard-fail; they produce rare, but *incorrect* computations!
😱2
and a bit on the broader changes around making software
https://registerspill.thorstenball.com/p/joy-and-curiosity-74
https://registerspill.thorstenball.com/p/joy-and-curiosity-74
Thorstenball
Joy & Curiosity #74
Interesting & joyful things from the previous week
i wish all papers were written as legible as this one
A Comparative Security Analysis of Three Cloud-based Password Managers
https://eprint.iacr.org/2026/058.pdf
A Comparative Security Analysis of Three Cloud-based Password Managers
https://eprint.iacr.org/2026/058.pdf
❤1
life is stranger than fiction and funnier than comedy (see "title")
https://x.com/summeryue0/status/2025774069124399363
https://x.com/summeryue0/status/2025774069124399363
🤡2🥴2🤣2
Claude's Cycles
ok so it's not just Terence Tao, Donald Knuth is doing vibe research as well
https://www-cs-faculty.stanford.edu/~knuth/papers/claude-cycles.pdf
ok so it's not just Terence Tao, Donald Knuth is doing vibe research as well
https://www-cs-faculty.stanford.edu/~knuth/papers/claude-cycles.pdf
🔥2
far from easily accessible but very impressive still
https://www.ctvnews.ca/vancouver/article/bc-man-cured-of-rare-disease-in-world-first-for-new-gene-editing-technology/
https://www.ctvnews.ca/vancouver/article/bc-man-cured-of-rare-disease-in-world-first-for-new-gene-editing-technology/
CTVNews
B.C. man cured of rare disease in world-first for new gene-editing technology
Ty Sperle says he felt “insane shock” after learning he’d been cured of a rare genetic disease through a clinical trial using a new gene-editing treatment.
⚡1👍1
hypervisor escape exploits are rare and interesting (tweet is just a teaser but we'll see)
https://x.com/osec_io/status/2029643325125390550?s=46
https://x.com/osec_io/status/2029643325125390550?s=46
X (formerly Twitter)
OtterSec (@osec_io) on X
We recently achieved guest-to-host escape by exploiting a QEMU 0day.
We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive.
Writeup coming next…
We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive.
Writeup coming next…
👾2
The Matrix v0.1 ALPHA
(full fruit fly brain simulation plus simplified embodiment by Eon Systems)
Scale it 1000000 times larger to fit the human brain and optimists get immortality, pessimists get digital prison.
https://open.substack.com/pub/theinnermostloop/p/the-first-multi-behavior-brain-upload
(full fruit fly brain simulation plus simplified embodiment by Eon Systems)
Scale it 1000000 times larger to fit the human brain and optimists get immortality, pessimists get digital prison.
https://open.substack.com/pub/theinnermostloop/p/the-first-multi-behavior-brain-upload
Substack
The First Multi-Behavior Brain Upload
The Singularity has belonged exclusively to artificial minds, until now.
🔥1
psychedelics & outdoors potentiate each other's effects & make them longer lasting -- for treatment-resistant depression, in this case
https://pmc.ncbi.nlm.nih.gov/articles/PMC12967759/
https://pmc.ncbi.nlm.nih.gov/articles/PMC12967759/
PubMed Central (PMC)
The combination of exercise and psychedelics for the treatment of major depressive disorder
Upwards of 50% of people do not respond to the primary treatment modalities for major depressive disorder (MDD), which has led to increased attention and use of alternative methods, including exercise and psychedelics. While interventions using ...
🦄1
there's no magic in the world other than one that you can bring
https://fixupx.com/IterIntellectus/status/2032858964858228817?s=20
https://fixupx.com/IterIntellectus/status/2032858964858228817?s=20
FixupX
vittorio (@IterIntellectus)
this is actually insane
> be tech guy in australia
> adopt cancer riddled rescue dog, months to live
> not_going_to_give_you_up.mp4
> pay $3,000 to sequence her tumor DNA
> feed it to ChatGPT and AlphaFold
> zero background in biology
> identify mutated…
> be tech guy in australia
> adopt cancer riddled rescue dog, months to live
> not_going_to_give_you_up.mp4
> pay $3,000 to sequence her tumor DNA
> feed it to ChatGPT and AlphaFold
> zero background in biology
> identify mutated…
⚠️ PSA: LiteLLM 1.82.7, 1.82.8 on PyPI has been hacked and contains code that extracts credentials etc from the machine where it runs then self-replicates
IoCs:
always pin your dependency versions.
IoCs:
File: litellm_init.pth (34,628 bytes) in site-packages/
File: ~/.config/sysmon/sysmon.py
File: ~/.config/systemd/user/sysmon.service
Domain: models.litellm[.]cloud
K8s: node-setup-* pods in kube-systemalways pin your dependency versions.
😱1
cyberpunk is upon us!
tldr: models are becoming better and better hackers, whether you want it or not, and until we find and patch most not-yet-discovered vulns it's gonna be fun times
https://www.youtube.com/watch?v=1sd26pWhfmg
see also: ctf-agent takes 1st place on BSides SF 2026 CTF
https://github.com/verialabs/ctf-agent
tldr: models are becoming better and better hackers, whether you want it or not, and until we find and patch most not-yet-discovered vulns it's gonna be fun times
https://www.youtube.com/watch?v=1sd26pWhfmg
see also: ctf-agent takes 1st place on BSides SF 2026 CTF
https://github.com/verialabs/ctf-agent
YouTube
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
Nicholas Carlini, Research Scientist, Anthropic, speaks at [un]prompted 2026 on: Black-hat LLMs.
Large language models are now capable of automating attacks that were previously only possible by human adversaries. In this talk, I discuss several ways that…
Large language models are now capable of automating attacks that were previously only possible by human adversaries. In this talk, I discuss several ways that…
😱1
PSA: npm axios package has been hacked, unlike LiteLLM if you do frontend you probably DO use it;
npm pins package version by default but at least def dont
bun has
https://x.com/feross/status/2038807290422370479?s=46
npm pins package version by default but at least def dont
npm i axios rn.bun has
minimumReleaseAge; also i've arrived at radical golang-style dependency vendoring via npm pack if I don't foresee them updated oftenhttps://x.com/feross/status/2038807290422370479?s=46
X (formerly Twitter)
Feross (@feross) on X
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer…
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer…
👾1
noninvasive deep brain stimulation! aka computer -> brain side of the interface!
https://www.nature.com/articles/s41467-026-70346-x
https://www.nature.com/articles/s41467-026-70346-x
Nature
Multimodal evidence for hippocampal engagement and modulation by functional connectivity-guided parietal TMS
Nature Communications - Noninvasive hippocampal modulation is key for addressing hippocampal dysfunction. Using multimodal brain recordings, the authors show that personalized connectivity-guided...
🔥2🎉2
i think this can be upgraded all the way to the infinite-context models
https://microsoft.github.io/memento/blogpost/
https://microsoft.github.io/memento/blogpost/
microsoft.github.io
Memento: Teaching LLMs to Manage Their Own Context
Memento teaches language models to manage their own context by segmenting reasoning into blocks, compressing each into a dense memento, and reasoning forward with sharply lower KV cache usage.
❤1
psa: Vercel just had a major security incident; better to consider sensitive env vars in deployments leaked
https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
Vercel
Vercel April 2026 security incident | Vercel Knowledge Base
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems.
😱1
TLDR: No need to beg for the Mythos access, you can find zero-day vulnerabilities with today's open models just fine too.
https://arxiv.org/abs/2604.20801
https://github.com/berabuddies/agentflow
https://arxiv.org/abs/2604.20801
https://github.com/berabuddies/agentflow
arXiv.org
Synthesizing Multi-Agent Harnesses for Vulnerability Discovery
LLM agents have begun to find real security vulnerabilities that human auditors and automated fuzzers missed for decades, in source-available targets where the analyst can build and instrument the...
⚠️ PSA: BitWarden CLI compromised in ongoing supply chain attack campaign
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
👾1