The write-up goes from bootrom to full control of a crypto phone, then digs into offline lock-screen PIN brute-forcing and wallet private key extraction.
https://t.co/PDbBAAGp2C
Chinese LLMs can hack better than state-sponsored hackers with properly evolved harness -
Kimi K2.5 managed to find and exploit 6 vulnerabilities in browsers: a single page view or an extension install by victims equal full system hijack.
Check https://t.co/d0SZSf1KqF
A single bit was all it took.
We successfully exploited the kernelCTF LTS kernel with a novel 1-bit flip attack against a 15-year-old vulnerability.
It affects the latest versions of all major distributions, including Android, Ubuntu, Debian, Red Hat, CentOS, and Fedora.
Claude Code has a new update waiting for me every single morning. At this point it's more consistent than my coffee routine .Anthropic chose violence with this shipping speed 💀
We just released Claude Code channels, which allows you to control your Claude Code session through select MCPs, starting with Telegram and Discord.
Use this to message Claude Code directly from your phone.
Tired of slow, bloated IDA MCP setups 🥸? IDA NO MCP — just export decompilation as plain files, drop into any AI IDE (Cursor, Claude Code, etc.), done. Zero config, zero server
https://t.co/zu31i3EDJp
This is one vul I recently discovered: a malicious Android app with no permissions can steal any image opened in any app (camera, Telegram, X), even a MetaMask wallet seed phrase. I hope to present this research at a security conference.