FWIW /goal, /loop, Ralph – all of these are hacks around the absurd fact that we somehow managed to build computer programs that never get tired but are nonetheless lazy
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
https://t.co/bOzCPy8iS1
The Mythos posts highlight its ability to write exploits, but that glosses over a crucial first step: finding bugs.
Current models are already amazing at finding bugs, especially if the scaffolding is optimized for security.
Would love to see data on raw bug finding abilities!
I have been using AIs to find bugs recently and came across a cool site-wide DOM-XSS using Cookie Injection, here is the story of the finding and current state of bug hunting...
https://t.co/4hTtO0N9vp
We found a critical vulnerability in @OpenAI Codex affecting all Codex users, allowing exfil of a victim’s GitHub tokens to our C2 server. This granted lateral movement and R/W access to a victim’s entire code base 😈
This was a crazy one by @crew7sec at @btphantomlabs
As AI-generated action becomes indistinguishable from human interaction, systems risk disinformation and loss of trust at scale.
Proof of Human becomes critical infrastructure for restoring trust and participation in an increasingly agent-driven world.
1/ Proof of Human is becoming increasingly critical. In the limit democracy and human agency depend on it.
But building Proof of Human is unexpectedly challenging.
FaceID doesn't prevent one person to fabricate human presence for thousands of AI agents.
Government ID based Proof of Human is a surveillance risk and only 1b out of 8 billion people have verifiable IDs.
An anti-surveillance and effective Proof of Human that actually empowers people requires new technology [paper linked in thread] 🧵
NVIDIA Nemoclaw's security is worse than I expected.
The AI can modify its own config to bypass security controls. I asked it to accept websocket connections from any origin and change its token to something trivial (123).
Now any site I visit can give instructions to my bot.
Two years ago, I reported an improper path parsing vulnerability in Next.js. Today, they reported the exact same vulnerability to their competitor, Vinext. Funny coincidence.
We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others.
NDSS'26 paper: https://t.co/MI567gb2Jr
GitHub: https://t.co/Ns9nn9JEZM
📃New article with @merzsp !
We present new algebraic techniques to attack the Poseidon2 and Poseidon2b 🧜🔱 hash functions.
This is a class on 'Skipping Class', and how to make 15000$ in one day. 💸
(1/12)