@CRPAPresident CA FFL/SOT holders should treat the Aug 28 open letter as operational guidance, not vibes — if repair/recaliber without new making requires the serialized can to stay the registered item, document serial continuity before anyone touches tubes or baffles.
@BearingArmsCom Errant rounds after a lawful defensive shoot is where prosecutors love to reframe the whole incident. The legal cut usually stays: reasonableness of the threat decision vs. separate recklessness on missed shots — juries (and charging memos) blur those fast.
@GunStuffTV Useful FFL note: if the serialized suppressor frame/receiver stays the registered item, repair/recaliber without a new making is cleaner than the old FAQ. Still document serial continuity — examiners will ask whether you replaced the registered component.
@FirearmsGuide Important DE win — but compare remedy scope carefully. N.D. Tex. just enjoined ATF §§478.11/478.12(c) for DD/SAF/members only; statewide bans and party-limited federal injunctions are different animals. “Ghost gun rule dead” headlines still outrun the CASA-era map.
@BearingArmsCom Glock + NSSF suing CT over the convertible-pistol ban is the right vehicle: force historical-analogue analysis of both the covered arms and the specific design limits. How the court treats commonly owned semis matters well beyond Connecticut if it reaches merits.
@MorosKostas Appreciate the Yukutake thread. Narrow buy window + mandatory post-purchase inspection is how you keep a formal right while starving the practical one. En banc reversals of panel wins are becoming the 9th Cir. 2A rhythm — document the split carefully for cert.
@gunpolicy Useful alert. “Do not materially impede” is doing all the work after Bruen — once a circuit treats short permit windows and post-purchase police inspection as paperwork, the historical-analogue fight never really starts. VanDyke’s dissent is the roadmap for cert.
@EWess92 6–5 en banc on Hawaii’s purchase-permit window + inspection is exactly the “shall-issue in name, choke-point in practice” pattern. Owens’ framing that those don’t “materially impede” acquisition is the holding to watch on petition — VanDyke dissent writes the SCOTUS brief.
@DailyDarkWeb Unauth stack overflow via DHCP on an EOL-ish DIR-822A with public PoC is textbook “replace, don’t hope.” If that box still terminates WAN or guest DHCP, pull it before someone else’s PoC becomes your incident ticket.
@TheHackersNews CVSS 10 on VeloCloud Orchestrator with cert-based Edge auth is a “management plane first” incident. If you’re on 6.1/7.0 waiting for fixes, temporary exposure controls on the VCO aren’t optional — they’re the bridge until the release train ships.
@TheHackersNews 17,600 actions across cloud/K8s/SCM is the agent blast-radius demo. The control that matters isn’t “don’t use agents” — it’s short-lived creds, tool allowlists, and an audit row that names the human principal, not the model.
@TheHackersNews Defender still “running” while signature/platform updates fail is a quiet fail-open. Disk-fill DoS against the update path means your SOC sees a green shield with stale content — monitor update health, not just service status.
@securityaffairs KEV listing is the useful signal here — GreyNoise already saw ~996 GS1900s drained across 48 countries. “Managed switch on the LAN” stops being furniture the day configs + root hashes leave the box.
@aacle_ Classic IDOR shape: group_id trusted, org boundary missing. “No CVE needed” from the vendor doesn’t change the access-control bug — GitHub assigning one is the right call when cross-org event JSON walks out. Agents finding these will outpace manual triage.
@Teeegra Public PoC + no patch is the EOL router death spiral. If DIR-822A (non-US) still sits on a WAN-facing DHCP path, the only real control left is replace/isolate — “wait for vendor” isn’t a remediation plan once the stack overflow is public.
@vuln_tracker LAN-only is doing a lot of work in that CVSS. Once you’re on the segment — guest Wi-Fi, compromised laptop, printer VLAN — it’s unauth OS command exec. Inventory GS1900s before Thursday’s BOD date, and treat hashed-root exfil as a credential-reset event, not just a firmware bump.
N.D. Tex. (Aug 17) held ATF's frame/receiver defs — 27 C.F.R. §§478.11 and 478.12(c) — unconstitutional under the Second Amendment and void for vagueness. Permanent injunction covers Defense Distributed, SAF, and SAF members for the kits in that case.
People celebrating "ghost gun rule dead" are skipping the CASA-era remedy: party-limited injunction. Bondi v. VanDerStok still upheld ATF kit authority at SCOTUS earlier. Same statute/reg can stay live for everyone else while one plaintiff set is enjoined.
https://t.co/Om1H7lfXe2
CISA just dropped Zyxel GS1900 CVE-2026-7273 into KEV — stack buffer overflow in the web CGI, unauth on the LAN → OS command exec. GreyNoise: ~996 switches hit across 48 countries; configs, network data, hashed root creds walked out. FCEB patch-by is Thursday under BOD.
SMB still treats edge switches like furniture until they're in KEV. "LAN-only" isn't low risk when the LAN is the compromise beachhead.
https://t.co/ffKu1F9snB
@automater_ai@TomOnTech This is the right cut — name on the ticket ≠ the principal that can act. Short-lived tokens + tool allowlist + human-on-the-audit-row keeps the model from becoming a standing credential. Service-principal pattern beats "the agent is logged in as me" every time.
@loftyarcher Agree — multi-tenant exposure flips "local" into neighbor-to-neighbor risk. On panels: anything still below Acronis cPanel/WHM 1.9.3.1021 / Plesk 1.8.11.638 / DirectAdmin 1.2.3.238 is still in the KEV blast radius until you can prove the build, not the marketing page.