Claude Code Full Sandbox Escape (CVE-2026-55607)
writeup: https://t.co/kzJ04Fqu4Y
prompt injection -> code execution on the host.
works even in read-only permissions mode + full sandbox
(it could be my Pwn2Own bug, but p2o was weird this year lol)
In the age of AI slop, some of us are still making things by hand, I promise ❤️ Octocat for the new GitHub Copilot App was modeled, rigged, and animated in Blender...
💥 Introducing "Dirty Frag"
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation.
Details:
https://t.co/9nqku4svkY
VERCEL GOT HACKED
ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums
here's why every developer should care:
- they have NPM tokens and GitHub tokens
- Vercel owns Next.js - 6 million weekly downloads
- one malicious push = global supply chain attack
- Vercel confirmed the breach today, April 19
- they literally DMed the hackers on Telegram asking them to stop
rotate your env variables RIGHT NOW
someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo
claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability in its entire, history...
it found the blind SQL injection in 90 minutes, stole the admin api key, then did the exact, same thing to the linux kernel
What a lovely surprise this morning! ☀️Independent detections of similar transients in European plate archives — exactly the kind of cross-validation this field needs. So it’s not just Palomar anymore.
The study was carried out by a retired NASA scientist.
This is how a signal begins to emerge from the noise.
https://t.co/5Gq8HLm0u5
David Grusch has talked to me many times. I have never heard any inconsistency in any set of statements. He has an unusual mind for excruciating details and discusses them with razor sharp precision at all times.
What he is saying is beyond belief. And I believe he is not lying.
God's eye view 24-hour replay of Operation Epic Fury.
The Iran strikes kicked off and I set an AI agent swarm loose to record every OSINT signal I could find before the caches cleared. Built a full 4D reconstruction in WorldView.
I can scrub through minute by minute and watch the whole thing unfold on a 3D globe:
> Airspace clearing over Tehran
> Ground strike coordinates locking in
> Severe GPS interference blinding the region
> EO and SAR satellites making passes over the strike zone
> No-fly zones locking down 9 countries
> Shipping fleets scrambling at the Strait of Hormuz
It's pretty amazing how complete of a picture you can build without "proprietary data fusion" -- one dev with public signals and a love for computer graphics and geospatial intelligence.
Thank you for all the love on my last post. Dropping WorldView in April. This my friends is just the beginning.
It turned out there are many more payloads used in the Notepad++ attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month.
Here are more IPs used in the attack:
45.76.155[.]202
45.32.144[.]255
Read below for many other IoCs! [1/8]
The right using anti 2A terms frequently used by the left is the gayest shit ever. Hearing right wing dudes use “high capacity” “military style” “3 MAGAZINES?!?!” and others to argue is massively massively bad for 2A rights as a whole. Be better. I carry with with 3 mags everyday. I’ve carried at protests, both open carry and concealed.
We just hit a turning point.
Alex Jeffrey Pretti was legally carrying. Holstered. Never touched his weapon.
ICE disarmed him while he was being dogpiled… then mag-dumped him anyway.
This is what’s turning people into leftists.
Not “wokeness.”
State violence.
We hacked the AWS JavaScript SDK, a core library powering the entire @AWScloud ecosystem - including the AWS Console itself 🤯
How did we do it? Just two missing characters was all it took.
This is the story of #CodeBreach 🧵👇
As some of you may know, #CobaltStrike beacons can be detected using ETW. For CCDC our team built and used BeaconHunter to detect and respond to these threats.
Github: https://t.co/NYryallQMI
We were able to kill +210 beacons (~70% automated) and monitor their behavior like...
The FireEye breach isn't really about red team tools or customer data.
It's about possibly stolen confidential intelligence data on high profile threat groups.
I mean, they know more about some actors than most states' intelligence apparatus.