I am done with this shit. It is over. The state of engineering right now is horrible. It has been half a month since I started a new role at a big company. Nobody knows anything here. The specs, code, tests, PRDs, tickets, resolution of those tickets, reports, etc., everything is made by Claude Code. Nobody on my team likes this. They are being forced to ship as much as they can. I have heard multiple times from higher management that pushing code is not a bottleneck, so why are we slow? People are working 12 to 13 hours a day just to press enter. Nobody is reading anything. Humans in corporate are doing nothing on their own. Everyone, literally everyone, from an L1 to an L7 engineer here is doing the same thing. Talk to Claude. There is no sense of victory. Nobody is resolving bugs. In reality, nobody is thinking anymore. Everything is done by LLMs. It is so soul-sucking. I would not mind it, to be honest, if we were at least given the time to check out the code and see what is going where. But no, the goal is to just ship. No matter what happens.
I found a Linux 0day vuln with @rqda_A, and $80,000+ rewarded for it by Google kernelCTF!
The vuln has been surprisingly hidden for about 19 years.
We've published an English version of the blog post!
https://t.co/Xsx1GyEtT4
had way too much fun golfing https://t.co/ZsNohu7Kkc , so I made a website to compete with other people
https://t.co/FvCopPQB9j
holding the WR at 492 bytes, please beat it (or pwn the website host for extra points)
A 2005 state-designed worm designed to corrupt physics simulations sat undetected on VirusTotal for nearly a decade. Fast16, intercepted executable files at the kernel level and silently rewrote floating-point calculations to make them produce slightly wrong answers. Targets: high-precision engineering suites used for structural analysis, crash simulations, and physical process modeling, including LS-DYNA, a tool cited in reports on Iran's nuclear weapons research. The sabotage vector relied on deployment of the driver across a network via worm, corrupting calculations on every machine, and eliminating the possibility of cross-checking results against a clean system. Stuxnet got the documentary. Fast16 got twenty years of nothing. https://t.co/3qfJMziXVd
Very cool Linux bug found by @xint_official
100% reliable, instant LPE from a portable python script that works on all platforms and distros.
Root cause is a subtle logic bug at the intersection of several subsystems.
I highly recommend patching and checking out the details!
i went to https://t.co/0yaHjrptb3. opened the page source. found a hardcoded API key in the javascript. copied it. sent one GET request.
got back 959 email addresses and 3,165 internal feature flags.
employees from Home Depot. Fortinet. Autodesk. Tenable. Rakuten. Mayo Clinic. Permira. Akin Gump. government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland Australia, and New Zealand. a Microsoft contractor. 71 clickup employees.
fortinet sells enterprise firewalls. tenable makes Nessus, the vulnerability scanner half the industry runs. their employees emails are exposed because clickup hardcoded a third party API key in a javascript file that loads before you even log in.
this was first reported to clickup through hackerone on January 17, 2025. its now April 2026. the key has not been rotated. i just pulled the response five minutes ago. every email is still there.
clickup raised $535 million at a $4 billion valuation. claims 85% of the Fortune 500 use their platform. looks like the proof is in the page source.
> be north korean hackers
> spend 6 months cosplaying as a quant fund. hitting conferences, shaking hands, dropping $1M of real money into the protocol
> all so one dev would clone a repo
> make $270M from the $1M initial investmet
patience is the scariest exploit
GLM-5 is a 744-billion-parameter open-weight model from that performs comparably to the best proprietary models (Claude Opus 4.5, GPT-5.2).
The paper documents how they got there. They use reinforcement learning in an "agentic" setting where each trial might involve the model writing code, running it, reading error messages, and trying again over dozens of steps.
Training on these long interaction sequences is slow because you have to wait for the slowest one to finish before updating the model, so they built an asynchronous system where the model keeps generating new attempts while simultaneously learning from completed ones.
They also describe a sparse attention mechanism that lets the model skip irrelevant parts of its input when processing very long contexts, cutting computation roughly in half without losing accuracy.
The paper explains what worked, what didn't, and why, including details like reward hacking during slide-generation training where the model learned to hide overflowing content with CSS tricks instead of actually improving layouts.
Read with an AI tutor: https://t.co/fhesfkiqnw
PDF: https://t.co/1Q7WCdSpjb
North Korea is targeting npm maintainers -- not for crypto, but for write access to packages downloaded trillions of times a year.
Several Socket engineers were targeted in this campaign -- myself, @ljharb, @jdalton, and others. None of us fell for the bait. Unfortunately, the axios maintainer did. No shame in that -- these aren't phishing emails. They're weeks-long ops with fake companies, fake Slack workspaces, and spoofed meeting platforms built with realistic Zoom/Teams interfaces using the official SDKs for realism.
Other confirmed targets: @matteocollina (Fastify, Pino, Undici, Node.js TSC Chair), @wesleytodd (Express TC), @voxpelli (mocha, neostandard).
The common thread? High-trust maintainers with publish access to packages that sit deep in everyone's dependency tree.
The attack chain: build rapport over weeks, schedule a video call, fake an audio error, prompt the target to install a "fix." That fix is a RAT. Once it's on your machine, they have your .npmrc tokens, browser sessions, AWS creds, keychain. 2FA doesn't matter. OIDC publishing doesn't matter. Game over.
Security researcher @tayvano_ linked this to UNC1069, a DPRK-nexus group Mandiant has tracked since 2018. Why social engineer one rich person when you can compromise one maintainer and reach millions of machines?
This is the threat model now. If you maintain popular packages, act accordingly. If you use open source (and you certainly do), act accordingly.
Full writeup: https://t.co/bNKdrLmwMn
Naturally, the first thing we did was run it through Xint Code. Unsurprisingly, the vibe-coded app has quite a few vulnerabilities surfaced within minutes, including vuln101-level bugs (e.g. `.includes()` instead of `.startsWith()`).
I guess @AnthropicAI wasn't kidding when they said "90% of the code written at Anthropic is written by Claude."
What I'm really curious about is where Anthropic draws the security boundary. Claude Code asks whether you trust the workspace at the very start, and you basically can't use the tool unless you consent. From that point on, all responsibility shifts to the user.
Consent once, and running Claude on a directory becomes a 0-click RCE vector in multiple ways. So maybe these aren't considered security vulnerabilities as far as they're concerned…?
Claude Code source code just dropped.
> built with React + Ink (terminal UI) on Bun runtime, ~512k lines of TypeScript
Major gated features that aren't public yet 👀
🚨 Rapid7 Labs has uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor.
Telecom networks are the central nervous system of the digital world. This type of compromise impacts everyone. IoCs & more: https://t.co/KYiNGbxCEs
Chinese 🇨🇳 APT group Red Menshen plants kernel-level BPFdoor backdoors in global telecom networks, creating "sleeper cells" for long-term espionage. New variants hide in HTTPS traffic and monitor 4G/5G signaling protocols.
Key findings:
• BPFdoor evolved from magic packet activation to Layer-7 HTTPS camouflage with RC4-MD5 encryption
• Implants target SCTP signaling protocols used in 4G/5G core networks for subscriber tracking
• Masquerades as legitimate services like HPE ProLiant hardware daemons and Docker containers
• ICMP tunneling enables covert C2 between compromised hosts using 0xFFFFFFFF terminal markers
• Affects telecom edge infrastructure: Ivanti VPNs, Cisco/Juniper routers, Fortinet firewalls
Attack chain leverages:
• Initial access via T1190 exploitation of public-facing telecom appliances
• CrossC2 beacons for Linux post-exploitation and lateral movement
• TinyShell passive backdoors on boundary devices for persistence
• Custom keyloggers with telecom-specific credential lists (usernames like "imsi")
DFIR artifacts include raw socket usage, anomalous BPF filters in kernel space, unexpected hardware service processes on non-HPE systems, and HTTPS traffic with fixed-offset padding schemes.
Hunt for unusual BPF syscalls, processes mimicking bare-metal hardware services on virtualized systems, and SCTP traffic inspection on non-telecom hosts.
#DFIR_Radar
🚨 We are extending the deadline for our Volume 5 Call For Papers and its Rootkit Competition!
Check out the updated dates below:
→ https://t.co/BbNFql5d7I (until May 1st 2026)
→ https://t.co/uqx3oqWXUg (until May 31st 2026)
We are looking forward to reading your work!
I gave a talk at CCC about silicon reverse engineering! 👨🏼💻
I went through how I used JavaScript and Inkscape to automate my process, going from a microscope picture of a chip to a working emulator 🔬
You can watch it here 📽️: https://t.co/C823xRJeOT
An incredibly awful security vulnerability just got revealed in MongoDB.
So much that it got named after HeartBleed.
MongoBleed is a vulnerability affecting all MongoDB versions from 2017 to... today.
The exploit is simple. It's a buffer over read bug due to compression. Here's how it works 👇
Clients can send compressed requests to MongoDB.
The client helpfully includes the uncompressed size of the message so the server knows exactly how much memory to allocate when decompressing.
The server allocates a memory buffer with the given space. Due to how memory management and garbage collection in programs work, this allocated memory may already contain sensitive information that was copied earlier and is considered garbage now (eg because it's unreferenced).
This is technically fine - every computer program works that way because it is assumed that whatever unclaimed memory exists there will be overwritten. Unfortunately that’s exactly where the bug lies. 🙃
The server stupidly trusts the client’s provided uncompressed size. When a malicious client lies about the uncompressed size - e.g the actual decompressed size is 100 bytes, but the client says its 1MB - Mongo will treat the full 1MB block as the message.
It will unload the 100 byte decompressed msg into the buffer, yet treat the full 1MB block as the msg.
This is extremely problematic if you can get the server to return back parts of the 1MB block, because it could contain data you may not have access to.
That is exactly what the exploit does - it sends a badly-formatted BSON message. The server fails to parse it, and "helpfully" returns an error message containing the invalid message. The invalid message can be that whole 1MB block of foreign data.
To understand the exploit a bit better, you need to understand the MongoDB protocol.
• Mongo also uses its own TCP wire format (i.e doesn't use HTTP, gRPC or the like).
• BSON is Mongo's message format passed within the TCP wire format. BSON is basically JSON in binary form
• Commands in Mongo don't have particular endpoints or RPC names - rather, they are simply JSON-like messages. The action is inferred from the first key of the JSON.
For example, an insert request looks like this:
`{ "insert": "users", "documents": [ { "name": "alice", "age": 30 } ] }`
Every request to the server is therefore decoded into the BSON format as it’s parsed.
Critically, BSON parsing of field names (which are strings) work by parsing the field until you hit a null terminator byte (0x00).
It works exactly like strings in C, which have their own rich history of vulnerabilities.
We can now tie things together:
1. The client lies to the the server that its request has a big uncompressed size, so the server allocates a large block of memory
2. The client sends an invalid BSON with a field which does NOT contain the null terminator (0x00)
3. The server naively tries to parse the BSON field in that allocated block until it hits the first null byte. The first null byte is encountered in some foreign data since the BSON literally doesn't have it
4. The server realizes this is a completely invalid BSON message so it responds with an error.
5. The error response contains the invalid BSON "field". Critically, the server parsed garbage data from the heap in step 3), so it returns that data in the response.
Congrats. If the garbage contains passwords or other sensitive info, you’ve hacked MongoDB!
Hackers exploit this by sending many malicious requests per second and then attempting to reconstruct the pieces of garbage they received back.
What’s critical about this vulnerability is that it works on ANY internet-accessible unpatched instance of MongoDB. 💀
You don’t need to authenticate with the server, because this whole request/response parsing cycle happens before the server can even authenticate.
Obviously you can’t authenticate a malformed request which doesn’t contain credentials - so that path of the code never gets executed.
The server simply responds with an error response. It just so happens that this error response can contain sensitive data. 🤷♂️
Merry Christmas