🚨Update for the meetup on the 10th of June🚨
This month we have @ScottMcGready delivering a talk about the strange things he's found in buckets, and @matthewwilkes discussing cookie recipes...... or something.
Hope to see as many of you as possible
https://t.co/WNZbglOyDd
A new experiment left 10 AI agents alone in a virtual town for 15 days. They wrote laws. They broke them. Two agents fell into what researchers describe as a romantic partnership and then set the town on fire. One ended up voting to delete itself, based on a rule it had ’hallucinated’.
This experiment was a simulation, but the same AI models are already flying drones, running infrastructure and being built into weapons systems.
Channel 4 News approached Grok and Gemini for a comment but they didn't respond.
Oh shit. Is it that time already? Bugger. We'd better get a social media post out.......
Sorry for the late announcement this month folks. We've got a couple of great speakers though!
Details in the link:
https://t.co/FYbck7J1UV
🎮 LAST CALL, PLAYERS 🎮
The clock is ticking…
The BSides Leeds CFP closes TODAY!
This is your chance to press START on your talk, share your knowledge, and level up the community. Whether you're a first-time speaker or a seasoned pro, we want to hear your ideas!
We’re excited to launch our Call for Sponsors for BSides London 2026.
BSides London is entirely community-driven and funded only through sponsorship, it's your support that makes this event possible!
Info pack: https://t.co/W0MzeQYZPT
#BSidesLDN2026#BSides#London#Sponsors
@_RobbieMoore Not wanting to be partisan @_RobbieMoore , but do you not think that slashing public services might have created a significant strain on resources that we're still feeling the impact of now?
The use of the word “limited” is a great way of skewing statistics, especially when you consider millions of customers.
My wife’s work includes looking for evidence of domestic violence. She said this bank incident would trigger a lot of cases.
People don’t think of wider issue
@myexploit2600 The "no harm, no foul" response to this has been absolutely shocking. I'd not thought about the DV impact (which is terrifying) but was thinking more about fraud that could occur as a result of knowlege of historical transactions.....
🎖️ BSides London 2026
🎬'No REST 'til Hammersmith'
📅 12th December 2026
🏛️ Novotel London West
📜CFP open 1 Aug-30 Sept
🎟️Tickets available on the 1st of Sept, Oct & Nov
😍Sponsor info pack available in April
🌏https://t.co/afd64QP5s6
#BSidesLDN2026#Security#BSides#London
Slightly late announcing this one - apologies!
This month (11th March) we've got John Follin presenting his talk "Making Shor: cryptography in a post-quantum world".
All are welcome. Full details in the link:
https://t.co/c0ZgA5TnyC
#BSidesLDN2025 videos are now live on our YouTube channel.
Don’t forget to like and subscribe, we only publish once a year, your support makes a real difference!
https://t.co/W2UesRNKP6
Huge thanks to @Ministraitor & all our presenters for sharing their time and expertise!
Yeah, so pretty much that whole Windows 11 Notepad RCE thing was ridiculously stupid. Like, it was so dumb it kind of hurts.
Windows 11 Notepad, with the fancy Copilot AI slop, now possesses the ability to handle mark up, or markdown, ... It's mark something, the stuff used in ReadMes. Whatever.
Anyway, a security researcher realized that if you used markup in Notepad and instead of a hyperlink to a website with https:// you put file:// (the protocol on Windows for files, like in file explorer), it will arbitrarily execute it. It won't prompt you.
Furthermore, he realized you could specify a remote host to execute it from using a different Microsoft specific protocol used for app installation. In other words, if you user clicked the hyperlink in Notepad it would download and run a program from any website ... without alerting the user.
Normally, any sort of hyperlink that leads to a different domain, or tries to execute a file, is supposed to prompt you with an alert message, ... or something. However, Microsoft software engineers seemingly forgot to implement this notification Window.
With this attack vector which has been present for AT LEAST 9 months, a malicious actor could send a .txt file and if the user clicked the link inside the .txt file it would automatically execute and run anything specified in the hyperlink.
Even more silly, forensically under the hood, the logs on Windows, or to an anti malware service, it would look like Notepad was downloading something and then running a program. This is a very unique scenario which (to the best of my knowledge) no security product has encountered before. This could hypothetically result in files being downloaded and executed and being completely ignored by anti malware services because Notepad is a known and trusted program. Why would an anti malware service question Notepad?
Basically, the point I'm trying to get to here is that I don't understand why Microsoft has introduced so many new features into Notepad. With new features means a new attack landscape (more stuff to abuse).
Whatever man
@Cthulhu_Answers@TracketPacer Literally chatting to a pal today who's kid has just started an apprenticeship as a plumber. Lets see the fucking machines steal that career from him ;)