Kirill A. Korinsky (kirill@) has added 160MHz channel width support (5GHz) to #OpenBSD's net80211 wireless stack, with the first driver receiving support being iwx(4) for Intel WiFi 6/6E devices.
https://t.co/TtKWT0E0Pr
https://t.co/dUCwBminiX
https://t.co/h6OTn4bQoS
#OpenBSD -current now supports delayed hibernation, after a number of seconds (86400 maximum, or 24 hrs) the machine will wake from S0ix/S3 idle sleep/suspend and hibernate to disk.
https://t.co/Mx0ym7hFT8
By default, it is not enabled. It can be configured in /etc/sysctl.conf.
Back in 2017 I converted tcpdump to the fork+exec model to better take advantage of PIE: https://t.co/ktePHJx2dA
OpenBSD tcpdump has been privsep for ~22 years, its packet parser runs with no privileges, is pledged "stdio" and has no network/filesystem access.
🚨 BREAKING: Someone just rebuilt the entire AI assistant stack in Zig.
It's called NullClaw. The binary is 678 KB. It uses ~1 MB of RAM. It boots in under 2 milliseconds.
No runtime. No VM. No framework. No garbage collector. Just raw Zig.
Here's why this is absurd:
→ OpenClaw needs a $599 Mac Mini and 1 GB+ RAM
→ NanoBot needs 100 MB+ RAM and Python
→ PicoClaw needs 10 MB RAM and Go
NullClaw runs on a $5 board with 1 MB of RAM.
Same functionality. 0.1% of the resources.
Here's what's packed into that 678 KB:
→ 22+ AI providers (OpenAI, Anthropic, Ollama, DeepSeek, Groq, etc.)
→ 13 chat channels (Telegram, Discord, Slack, WhatsApp, iMessage, IRC)
→ 18+ built-in tools
→ Hybrid vector + keyword memory search
→ Multi-layer sandboxing (Landlock, Firejail, Docker)
→ Hardware peripheral support (Arduino, Raspberry Pi, STM32)
→ MCP, subagents, streaming, voice, the full stack
Here's the wildest part:
Every subsystem is a vtable interface. Swap any provider, channel, tool, memory backend, or runtime with a config change. Zero code changes.
It even encrypts your API keys with ChaCha20-Poly1305 by default.
2,738 tests. ~45,000 lines of Zig. Zero dependencies beyond libc.
100% Open Source. MIT License.
@cryptocom Why are you requiring people to put their SSN into a website that's not behind a login to get their tax forms? Why does your email say I can reject this and get a paper copy, but your support personal are refusing me that option? #security
The Ghidra reverse engineering tool/decompiler has returned to #OpenBSD ports!
Thanks to Kurt Miller (kurt@), #Ghidra 12.0.2 is now in -current!
https://t.co/EzMA0x8voz
Ghidra was originally ported to OpenBSD back in 2019, but due to major changes upstream was removed in 2023.
The Conscience of a Hacker, also known as The Hacker Manifesto, turns 40 today!
Written by Loyd "The Mentor" Blankenship, its spirit still resonates with hackers and makers everywhere. A cornerstone of hacker culture.
"My crime is that of curiosity."
Read it here: https://t.co/ZMA4j1QRII
#HackThePlanet #HackerManifesto
Thrilled to welcome the SGNL team to the @CrowdStrike mission.
Adversaries don't break in. They log in. In the era of AI agents, static identity is a vulnerability. Legacy tools weren't designed for machine-speed attacks.
We are redefining identity as a real-time enforcement layer to secure the agentic future.
To the SGNL team: Let's go stop breaches.
Read more: https://t.co/ebusnTgCEf
#CrowdStrike #SGNL #IdentitySecurity
If any of my past work on #OpenBSD, or my highlight posts here has been helpful to you at all, a small recurring monthly donation would help me pay for pizza, rent, & thinkpads (in that order). 🍕💻
THC Release 💥: The world’s largest IP<>Domain database: https://t.co/o4F8M1Pqi1
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.
Updated monthly.
Try: curl https://t.co/5V2xLadmx5
Raw data (187GB): https://t.co/cBZOSAE89K
(The fine work of messede 👌)
Critical Security Vulnerability in React Server Components
CVE-2025-55182 and rated CVSS 10.0
The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of:
react-server-dom-webpack
react-server-dom-parcel
react-server-dom-turbopack
https://t.co/AMlp6yMPSZ
Last week I hosted family for Thanksgiving.
My 12-year-old nephew asked for the WiFi password.
He wanted to play Roblox on his iPad.
I looked at the device.
Unmanaged. No antivirus. No encryption.
I’m an IT Professional. I don't run an open network.
So I didn’t give him the password.
Instead, I spent 45 minutes provisioning a Guest VLAN.
I set up a captive portal.
I throttled the bandwidth down to 56kbps.
Then I blocked all traffic on ports 80 and 443.
He came back crying. He said it wouldn't load.
My sister screamed at me to "just let him play."
I told her that Zero Trust architecture doesn't care about bloodlines.
We didn't have a "fun" Thanksgiving.
But we had a secure perimeter.
You’re welcome for the compliance.
Stealth died 😢 A member of Team-Teso, Phrack staff, and many other groups. A true hacker—perhaps as true as a hacker can ever be. WE MISS YOU. 🩷
More: https://t.co/Jx0JYfrjnG
<stealth> we had joy we had fun we had a rootshell on a sun.
Call for testing by Stefan Sperling, baby steps toward WPA3 support in #OpenBSD, testing required for initial support for PMF (Protected management frames) in iwm/iwx/qwx drivers.
https://t.co/YwvV6Z4pPv
Made possible through sponsorship by NLnet Foundation's NGI0 Commons Fund.
The first AI driven APT espionage campaign has just happened. 🤯
This Anthropic report is a huge turning point for our industry. It’s the first publicly known AI led espionage campaign by an APT group.
They ran intrusion chains at machine speed and breaching around 30 organisations successfully. Around 80 to 90 percent of the operation was handled autonomously, with humans only stepping in for the final pieces.
There were limits though. The AI made mistakes, occasionally hallucinated credentials, and needed human steering for about 10 to 20 percent of the work. But the ceiling is rising fast.
This happened in September 2025. It will keep happening. The next era of cyber will be humans defending against machines.
Manual detection and manual threat hunting will fall behind. We need AI supported defence and safe environments to understand and train against machine speed threats.
Unfortunately for whatever reasons Anthropic did not release any TTPs or any IOCs for us. 💀 so I’m off here just imagining what the intrusions could’ve been like …
https://t.co/KmbmsBXnEx