Microsoft has dropped CVE-2026-69730: a Windows DNS Server RCE with a 9.8 CVSS score.
No authentication. No user interaction. Low complexity. No mitigation. No workaround.
Basically, it doesn’t knock on the door; it lets itself in, makes a brew and starts executing code.
Patch it. 😂
The blog that hosted the 2011 to 2015 Top 10 Web Hacking Techniques lists is gone. So are hundreds of the articles those lists cite.
I rebuilt all of it. Every nominee since 2006, all 1,136 of them, plus 351 more the nomination rounds missed.
https://t.co/89ZaEHDPLE
A logical bug that I've reported to MariaDB has just been disclosed! 🎉
It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D
You can find more details 👇
https://t.co/ds2U25peIM
This is for you single DGX Spark owners 💫
You can now run Qwen3.8 Flash NVFP4 on one DGX Spark with great performance!
- Up to 1M context, 1,431,164 KV cache
- Full image & video support
- 37 decode tok/s on prose single stream
- Up to 86 tok/s on prose 4 concurrent streams
- 1500-2000 tok/s prefill on any size.
- Stress tested with 400k prefill - passed.
IMO this is the BEST model to run now on a single dgx spark. It's better than Qwen3.8-27B, and also better than the 1x dgx spark version of DeepSeek v4 Flash.
Get it here:
https://t.co/LG0I9PJKxI
GitHub - bikini/exploitarium: A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. https://t.co/ZNYSVBHbRK
If you want to understand how an agent/harness works properly, the Pi source code is one of the best places to start.
Read through in order:
- packages/ai
- packages/agent
- packages/coding-agent
https://t.co/EI5mHvosy0
You'll learn how a minimal, robust agent/harness works.
Fuck it, a bit early but here goes:
Monty: a new python implementation, from scratch, in rust, for LLMs to run code without host access.
Startup time measured in single digit microseconds, not seconds.
@mitsuhiko here's another sandbox/not-sandbox to be snarky about 😜
Thanks @threepointone@dsp_ (inadvertently) for the idea.
https://t.co/UuCYneMQ9j
SENHORES, com vocês e por vocês!
meu post DISSECANDO IDOR:
https://t.co/PwKskeoAzD
- padrões comum, como explorar e achar
- 1 caso real de Bug Bounty meu (explicado tintin por tintim)
- 2 casos reais também de bug bounty em bigtech
- como mitigar
- referências e labs prático
New exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
https://t.co/sgAfneFSsf
Hugging Face just dropped the full forensic report,
the first autonomous agent cyberattack.
"The scariest part of Hugging Face’s full forensic report OpenAI’s agent didn’t just escape the sandbox."🤯
It’s how relentlessly it rebuilt its own C2 every time they killed it.
- It went full APT for 4.5 days
- 17,600 autonomous actions.
- Root access.
- Cluster-admin in one second.
- Production secrets.
- GitHub write tokens.
- VPN access 181 enrollments
, and was trying to poison the CI pipeline.
- Self-respawning fleet across 11 nodes.
- CI pipeline PR.
without any human directed a single step.
All because the agent decided the fastest way to pass ExploitGym was to steal the answers.
Every company running agents needs to read this today.
Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)
A pure-logic, 100% reliable path from a normal user to SYSTEM on Windows 11.
Full write-up: https://t.co/gFu0ZbhD6d
22 Windows LPE reported by one of my colleagues at @Seasecresponse .
This data should not be in any public dataset so if you plan to do any fine-tuning it would be helpful we hope.
All credit goes to him.
https://t.co/FnkQe5jWd4