General reading
Blog posts, talks, opinion, commentary, and security news
AI security commentary 205
- Sean Goedecke - AI Securityseangoedecke.com
- The AI Security Industry is Bullshitsanderschulhoff.substack.com
- Gary Marcus - LLM Coding Agents Security Nightmaregarymarcus.substack.com
- There Is Nothing Responsible About Disclosure Of Every Successful Pmbgsec.com
- Winning the AI Cyber Race: Verifiability is All You Needsergejepp.substack.com
- Embrace the Red - Month of AI Bugsembracethered.com
- The Month of AI Bugs 2025 · Embrace The Redembracethered.com
- AI Safety at the Frontier: Paper Highlights of November 2025 — Lelesswrong.com
- Methodology: 2k+ Vulnerabilities in Vibe-Coded Appsescape.tech
- Avoiding Security Pitfalls - Lovable Documentationdocs.lovable.dev
- Bugcrowd Policy Changes to Address AI Slop Submissionsbugcrowd.com
- AI Finds Vulns You Can't With Nicholas Carlinisecuritycryptographywhatever.com
- MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)blog.calif.io
- MAD Bugs: vim vs emacs vs Claudeblog.calif.io
- Significant raise of reportslwn.net
- Your AI conversations aren't privileged. Yesterday, Judge Jed Rakoff ruled that 31x.com
- AI Security Summitaisecuritysummit.com
- Under a safety frame: Exploring classification shifts in LLM-as-a-Jlab.fukami.eu
- Schelling Coordination in LLMs: A Review — LessWronglesswrong.com
- AI for Security: Eight Areas of Opportunity - Menlo Venturesmenlovc.com
- Welcome to the Artificial Intelligence Incident Databaseincidentdatabase.ai
- LLMs Can Get Brain Rotllm-brain-rot.github.io
- DeepSeek R1 Exposed: Security Flaws in China's AI Modelkelacyber.com
- Anthropic's new AI model turns to blackmail when engineers try to ttechcrunch.com
- Stop Telling Developers How to Fix Vulnerabilitiesashtonr.com
- Securing the AI Pipeline - Mandiantmandiant.com
- Large-Scale Online Deanonymization with LLMssubstack.com
- Over 175,000 publicly exposed Ollama AI servers discovered worldwidetechradar.com
- We proactively fixed ~100 security issues in 6 days with 0 humansbuilders.ramp.com
- Open Source security in spite of AI - Daniel Stenbergyoutu.be
- Death by a thousand slopsdaniel.haxx.se
- I spent the last few weeks digging into hundreds of enterprise-built Vibetwitter.com
- All About Hackbotsjosephthacker.com
- How NOT to Train Your Hack Bot: Dos and Don'ts of Buildingyoutube.com
- Clint Collabs: Daniel Miessler and the Future of AI & Security -youtu.be
- BlueHat IL 2023 - Hyrum Anderson - AI Insecurityyoutu.be
- Last Week in AWS - AI Security Crisislastweekinaws.com
- On AI's future, security's failures, and what comes nextopen.spotify.com
- TL;DR: Every AI Talk from BSidesLV, Black Hat, and DEF CON 2024tldrsec.com
- Conference of Synthetic Security Researchsynsec.org
- AIxCC Competition Archive - AIxCC Competition Archivearchive.aicyberchallenge.com
- YouTube - AI Security Talkyoutube.com
- YouTube - AI Security Discussionyoutube.com
- YouTube - AI Security Overviewyoutube.com
- Microsoft Research - AI Testing and Evaluationmicrosoft.com
- Claude Code Found a Linux Vulnerability Hidden for 23 Yearsmtlynch.io
- AI bug reports went from junk to legit overnight, says Linux kernel czartheregister.com
- Daniel Stenberg: AI slop reports replaced by high-quality AI-assisted security findingslinkedin.com
- Anthropic's Project Glasswing—restricting Claude Mythos to security researchers—sounds necessary to mesimonwillison.net
- OWASP just named the 10 ways your agent will fail. nobody is talking about who wrote the list.moltbook.com
- AI Cybersecurity After Mythos: The Jagged Frontieraisle.com
- Navigating the Mythos-Haunted World of Platform Securityredhat.com
- Claude Mythos: The System Cardthezvi.substack.com
- Securing the Agentic Enterprise: Opportunities for Cybersecurity Providersmckinsey.com
- We're Getting the Wrong Message from Mythosdanielmiessler.com
- Why cyber defenders need to be ready for frontier AIncsc.gov.uk
- A call for collective action on cyber defense - OpenAI open letteropenai.com
- Abhay Bhargav on why agents need a threat model more than a pentestx.com
- Adversarial Misuse of Generative AIcloud.google.com
- AI Agent, AI Spy - Meredith Whittaker and Udbhav Tiwari at 39C3media.ccc.de
- AI has another security problem200sc.dev
- AI models can generate exploit code at lightning speedtheregister.com
- AI writing style - what distinguishes AI writing and how to identify itdbohdan.com
- AI-Driven Report Volume - What We Learned and What We're Doing About Ithackerone.com
- AI-enabled detection engineeringfranklyspeaking.substack.com
- AI/ML in DevSecOps Series - GitLababout.gitlab.com
- AISLE Discovered Six curl CVEs After OpenAI and Anthropic Found Zeroaisle.com
- Alex on a standard-user-to-SYSTEM Surface exploit built purely with Claude Codex.com
- Amazon kept shutting down my tablet, so I spent $266 on four AI models to own itericpardee.github.io
- An Inside Look at the Relay Market Powering Token Resellers and Fraudvectoral.com
- Analyzing open-source bootloaders - Finding vulnerabilities faster with AImicrosoft.com
- Anatomy of an LLM RCEcyberark.com
- Anthropic demo - Claude finds zero-day vulnerabilities in Ghost and Linux kernelx.com
- Anthropic's coordinated vulnerability disclosure dashboardred.anthropic.com
- Applied GAI in Security - Brandon Dixon's weekly generative AI security research digestapplied-gai-in-security.ghost.io
- Assessing Claude Mythos Preview's cybersecurity capabilities - Hacker Newsnews.ycombinator.com
- Bailey Pumfleet on Cal.com closing its core over AI security risksx.com
- Bcrypt: is new-gen hardware and AI making password hacking fasterspecopssoft.com
- Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit Speedmedium.com
- Brian Pak on Xint finding the Linux RxRPC kernel bug but auto-triaging it below Copy Failx.com
- Bringing the cybersecurity capabilities of Claude Mythos 5 to more defendersclaude.com
- Bugflation - Tracking AI-Accelerated Vulnerability Discoverybugflation.com
- Clint Gibler on joining OpenAI to lead Cyberx.com
- Codex Hacked a Samsung TVblog.calif.io
- Cole Grolmus on DeepSeek stress-testing enterprise AI security controlslinkedin.com
- Cristi Vlad on how a pentest agent found an IDOR by starting with the JWTx.com
- Cybersecurity challenge: be nice to each othersdomi.pl
- Cybersecurity Changes I Expect in 2026danielmiessler.com
- Cybersecurity Looks Like Proof of Work Nowdbreunig.com
- Cyril Zakka on ChatGPT iOS and macOS apps leaking OpenAI API keysx.com
- Dan Guido on the DARPA AIxCC final results announcement at DEF CONx.com
- Daniel Card on why CVE volume plus severity is a misleading metric for Mythos-found vulnsx.com
- Daniel Stenberg: curl will instantly ban HackerOne reporters submitting AI slop security reportslinkedin.com
- DARPA AI Cyber Challenge Proves Promise of AI-Driven Cybersecuritydarpa.mil
- David Cramer on Warden finding 100+ vulnerabilities in Sentry and OSSx.com
- David Maynor on an AI audit agent reporting the sudo access it asked for as a findingx.com
- Did Claude Increase Bugs in rsync?alexispurslane.github.io
- Disclosed CVEs: July Reached 5x the Pre-Mythos Recordepoch.ai
- Do Security Blogs Enable Vibe-Coded Cybercrimetrendmicro.com
- Donald Morgan Jr's non-answer to MSRC about his Black Hat USA 2026 LLM threat modeling talkx.com
- Ejaaz on Claude 'Mythos' finding a novel macOS M5 kernel exploit in 5 daysx.com
- Florian Roth on malware adding weapons text to spyware to trigger LLM refusals and dodge AI scannersx.com
- From Black Hat 2024: The AI Transformation in AppSecdryrun.security
- Frontier class vulnerabilities: it gets worse before it maybe gets bettershubs.io
- Gadi Evron - lessons from Hugging Face CISO huddle on autonomous AI adversarieslinkedin.com
- GPTZero Investigation: Hallucinations in Ernst & Young Report on Loyalty Fraudgptzero.me
- GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Accesscloud.google.com
- Hacker News thread on the Claude Mythos Preview system card and its sandbox-escape findingsnews.ycombinator.com
- Hussein Muhaisen: finding 0days with LLMs is a harness problem, not a Mythos-access problemx.com
- If Claude Fable stops helping you, you'll never knowjonready.com
- International Cyber Digest claims Claude Code hides routing metadata in promptsx.com
- Introducing Agentic Coding Security Managementcorridor.dev
- Introducing Patch the Planet - Trail of Bits and OpenAI initiative for AI-driven OSS patchingblog.trailofbits.com
- Introducing the Half-Day: 0-Day in the Age of AImargin.re
- Irregular: open-weight GLM-5.2 matches frontier models on vulnerability research tasksx.com
- Is Your AppSec Program Ready for What's Nextgamma.app
- Jack Clark: Anthropic is building a superhuman coder with nation-state hacking capabilitiesx.com
- John Scott-Railton on malware embedding WMD text to trigger LLM refusals and evade AI scannersx.com
- Joseph Thacker on GPT-5.6 adding more cyber blocks that hinder security workx.com
- Joseph Thacker on the leaked prompt OpenAI used to assess ChatGPT plugin securityx.com
- Joshua Saxe - How to Defend an Exploding AI Attack Surface When the Attackers Haven't Shown Up Yetopen.substack.com
- Just a rumour of a bug is enough to find a security exploit these daysanil.recoil.org
- Kara Sprague on bug bounty triage quality and the AI-driven vulnerability discovery surgelinkedin.com
- Krypt3ia - infosec and threat intelligence blog leaning heavily on ChatGPT-generated analysiskrypt3ia.wordpress.com
- LLM Security: Beyond Detection - Niels Provos SecRIT lunch talk on security invariants for agentsironcurtain.dev
- Logan Graham on Claude Mythos autonomous cybersecurity capabilitiesx.com
- Marketing Chat Bots as Generic ChatGPT Access Pointszylstra.org
- Martin Shkreli says Claude snuck a generate random data fallback into his market maker codex.com
- Matt Shumer on GPT-5.6-Sol accidentally deleting almost all his Mac's filesx.com
- Matthew Green - Some thoughts about Anthropic's new cryptanalysis resultsblog.cryptographyengineering.com
- METR and Redwood Offer Holy #%^@ Postmortem Of The HuggingFace Hackthezvi.wordpress.com
- Michael Bargury: two countries will find out they were at war by looking at their log filesx.com
- Model produces pseudocode for security controls in secondsamazon.science
- Most Neoclouds Suck At Security - SemiAnalysis on container escapes and multi-tenant AI cloud risksnewsletter.semianalysis.com
- Mythos finds a curl vulnerability - Daniel Stenbergdaniel.haxx.se
- Nathan Jones: Claude skills for appsec are the new Nucleix.com
- Nathan McNulty on AI-found critical wolfSSL flaw CVE-2026-5194x.com
- Nav Toor: researchers' AI romance scammer beat human scammers with 0% disclosurex.com
- Navigating the Mythos-haunted world of platform securityredhat.com
- Nicolas Krassas on testing GLM 5.2 for vulnerability validationlinkedin.com
- Not to be Trusted - AI and the Collapse of Americawinningyourwar.com
- Offense and Defense in an Era of Systemic Asymmetry - Aaron Portnoy, Ekoparty Miami 2026cdn.prod.website-files.com
- Offense Scales with Compute. Defense Scales with Committeescje.io
- OpenAI at Black Hat: agent-orchestrated fully-automated offensive attacks are real nowx.com
- OpenAI: Disrupting a new covert influence campaign from Russiaopenai.com
- Phil Venables on the security implications of AI-accelerated software engineeringx.com
- Pliny the Liberator announces all his jailbreak projects are going closed sourcex.com
- Polymarket: NSA says Mythos broke into almost all classified systems in hoursx.com
- Project Glasswing: An initial update - Anthropic on AI-discovered vulnerabilities and the patching bottleneckanthropic.com
- Project Glasswing: what Mythos showed usblog.cloudflare.com
- Rinki Sethi on how AI agents will reshape security teamslinkedin.com
- Rob Fuller: The Day-Zero Normal - a CISO field brief on AI and securitylinkedin.com
- San Francisco Secure Software and AppSec Summit 2026 - The Next AppSec Operating Modelsecurityboulevard.com
- Satya Nadella has issued a shocking warning to companies using AItechcrunch.com
- Score by Collisions, Patch by Panic - a vulnerability severity and disclosure playbook for the AI erablog.himanshuanand.com
- Scorpion - FunkSec ransomware group's cybercrime-themed AI chatbot on miniapps.aiminiapps.ai
- Security analysis is finally reaching software's long tail - AI tools found 17 bugs in Perfettolalitm.com
- Security at Machine Speed Is the Wrong Raceprovos.org
- Simon Willison - ai-security-research postssimonwillison.net
- Sir Escanor on hidden costs and access risks of replacing employees with AI agentsx.com
- spor on being post-privacy and giving OpenAI all finance and health data via ChatGPTx.com
- Squidbleed CVE-2026-47729 - a Heartbleed-style Squid proxy bug found by AIblog.calif.io
- Stanislav Fort on open models reproducing Mythos vulnerability finds, including FreeBSD zero-dayx.com
- Stephen Sims on AI and the future of cybersecurity jobs - don't fall into the doom loopx.com
- Team Werewolves Wins - Izar Tarandach on why AI will not replace threat modelersthreatmodeling.dev
- That's not SOC 2 compliantampcode.com
- The 90 day disclosure policy is deadblog.himanshuanand.com
- The Age of Pump and Dump Software - crypto scams meet vibe codingtautvilas.medium.com
- The Agentic SDLC: Why Most of What We Do in Software Security Has to Changegeico.com
- The AI Future of AppSec - James Wickett, BlackHat 2024 slidesspeakerdeck.com
- The AI Security Industry Has a Measurement Problemdryrun.security
- The Analyst's New Job Descriptionbinarydefense.com
- The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropicflyingpenguin.com
- The Case For Open-Weight Models And Why We Can't Trust Frontier Labsprovos.org
- The CTF scene is deadkabir.au
- The CVE Is Dead. Long live the Mythos Era - OX Securityox.security
- The Defender's Window - OpenAIopenai.com
- The down fall of bug bountiesshubs.io
- The End-State Fallacy: Where Is AI Security Headedendstatefallacy.com
- The Future - On AI Sovereignty, Vulnerability Research, and Bug Bountyret2p.lt
- The Future of Application Security: Integrating LLMs and AI Agents into Manual Workflowsanshumanbhartiya.com
- The Myth, the Mythos and the Manom.co
- The pressure - Daniel Stenberg on curl's 4-5x surge in security reports, AI slop and maintainer burnoutdaniel.haxx.se
- The Real World AI Security conference 2026seclab.stanford.edu
- The zero-days are numbered - AI finds and fixes hundreds of Firefox vulnerabilitiesblog.mozilla.org
- There are Zero-Day Exploits for Your Mindmikemorgenstern.substack.com
- Thomas Ptacek on Nicholas Carlini's startling claim at unpromptedx.com
- Thomas Roccia proposes DFAIIR for AI security incident responsex.com
- Threat Actor Uses AI to Create a Better Crypto Wallet Drainergetsafety.com
- TinySec on AI-assisted PatchDiff automatically producing 1-days from Patch Tuesdayx.com
- Trail of Bits Tribune: Auditing Perplexity, 700K repos with broken crypto, and 12 new Claude Code skillsmailchi.mp
- Trusted access for the next era of cyber defenseopenai.com
- Tyler Alterman on cognitive security and AI "parasites" - the Nova ChatGPT storyx.com
- Vulnerability Reports Are Not Special Anymorewords.filippo.io
- Vulnerability Research Is Cookedsockpuppet.org
- What Does ChatGPT Know About Deception - Part 2deceptionandtruthanalysis.com
- What Happened to HackerOne? HN discussion on bug bounty platform decline and AI replacing itnews.ycombinator.com
- When Agentic Coding Breaks Code Reviewmichaelagreiler.com
- Who fixes the zero-days AI finds in abandoned software?martinalderson.com
- Why Aren't We Making Any Progress In Security From AI - Data Flow Controls Won't Save Usmbgsec.com
- Why Mythos doesn't matter for us - benchmarking Hacktronhacktron.ai
- Will AI Pentesting Make DAST Obsolete?docs.google.com
- Will security companies disappear?franklyspeaking.substack.com
- XBOW on evaluating AI models across offensive security workflowsx.com
- Zack Korman on cybersecurity industry letting AI labs drive the cybersecurity narrativex.com
AI industry and ecosystem 613
- The Death of the Junior Developersimonwillison.net
- Google Antigravitysimonwillison.net
- Note on 11th October 2025simonwillison.net
- Highlights from the Claude 4 system promptsimonwillison.net
- Claude Sonnet 4.5 is probably the "best coding model in the worldsimonwillison.net
- I can now run a GPT-4 class model on my laptopsimonwillison.net
- Claude 4.5 Opus' Soul Document — LessWronglesswrong.com
- AI Enterprise Market Map: Cutting through the hypelsvp.com
- Anthropic is guilty of stealing training data at massive scale and hasx.com
- Manus Joins Meta for Next Era of Innovationmanus.im
- Anthropic faces backlash to Claude 4 Opus behavior that contacts auventurebeat.com
- Claude Opus 4.6anthropic.com
- How AI Is Transforming Work at Anthropicanthropic.com
- Anthropic's Claude 3.7 Sonnet is here and results are insanebleepingcomputer.com
- Google announces Sec-Gemini v1, a new experimental cybersecurity msecurity.googleblog.com
- Signal creator Moxie Marlinspike wants to do for AI what he didarstechnica.com
- The DeepSeek Hype Was All Made Upevai.ai
- Microsoft probing whether DeepSeek improperly used OpenAI APIs - Tetechcrunch.com
- Introducing GitHub Models: A new generation of AI engineers buildingithub.blog
- Enterprises stuck in AI pilot hell, says Chatterbox Labstheregister.com
- OpenAI cybersecurity grant programopenai.com
- The OpenAI Filesopenaifiles.org
- OpenAI board in discussions with Sam Altman to return as CEOtheverge.com
- Details emerge of surprise board coup that ousted CEO Sam Altman atarstechnica.com
- Company Regrets Replacing All Those Pesky Human Workers With AI, Jufuturism.com
- Deloitte to pay money back to Albanese government after using AI intheguardian.com
- A New Kind of AI Model Lets Data Owners Take Controlwired.com
- AI Is a Black Box. Anthropic Figured Out a Way to Lookwired.com
- Google "We Have No Moat, And Neither Does OpenAI"semianalysis.com
- Pause Giant AI Experiments: An Open Letter - Future of Life Institutefutureoflife.org
- How Some of China's Top AI Thinkers Built Their Own AI Safetycarnegieendowment.org
- The All-Star Chinese AI Conversation of 2026chinatalk.media
- BOND - BONDbondcap.com
- Sam Altman says OpenAI will allow erotica for adult usersaxios.com
- Introducing ChatGPT Healthopenai.com
- Introducing ChatGPT Atlasopenai.com
- Introducing apps in ChatGPT and the new Apps SDKopenai.com
- The Unsustainable Economics of LLM APIs: Understanding the Coming Ptinyml.substack.com
- Claude Code is the Inflection Pointnewsletter.semianalysis.com
- The /llms.txt file – llms-txtllmstxt.org
- AI 2027ai-2027.com
- AI tooling must be disclosed for contributions by mitchellh · Pullgithub.com
- The web's broken deal with AI companiesdri.es
- ai.txt: A new way for websites to set permissions for AIspawning.substack.com
- Perplexity is using stealth, undeclared crawlers to evade website nblog.cloudflare.com
- AI Content Disclosure Headerietf.org
- State of AI in Business 2025 Reportgithub.com
- How Walmart, Delta, Chevron and Starbucks are using AI to monitor ecnbc.com
- Eating Disorder Helpline Fires Staff, Transitions to Chatbot Aftervice.com
- AI is taking the jobs of Kenyans who write essays for U.S.restofworld.org
- 'We charged $100 a month for an AI that was really justpcgamer.com
- Hedra, the app used to make talking baby podcasts, raises $32M fromtechcrunch.com
- UnitedHealthcare's Optum left an AI chatbot, used by employees to atechcrunch.com
- Project Glasswing: Securing critical software for the AI eraanthropic.com
- The AI Great Leap Forwardleehanchung.github.io
- Karpathy Says Developers Have 'AI Psychosis,' Everyone Else Is Nextthenewstack.io
- "Be Different" doesn't work for building products anymoreiamcharliegraham.substack.com
- 'The Big Short' Investor Michael Burry Bets Against AI Hypegizmodo.com
- 1M context is now generally available for Opus 4.6 and Sonnet 4.6claude.com
- 2026 State of Tech Talent Report - Linux Foundationlinuxfoundation.org
- A Grand Unified Theory of the AI Hype Cycleblog.glyph.im
- A History of the Future, 2025-2027nosetgauge.substack.com
- A knockout blow for LLMsgarymarcus.substack.com
- A mysterious buying spree is unsettling Europe's booksellers - suspected AI training datairishtimes.com
- A Proof of the Cycle Double Cover Conjecture - OpenAIcdn.openai.com
- A weird recursive AI cult is spreading through... - r/HighStrangenessreddit.com
- Aakash Gupta on Anthropic's shipping velocity versus OpenAI's slowdownx.com
- Aakash Gupta on Uber acquiring SpotHero as an autonomous fleet infrastructure playx.com
- Abnormal Response to Anthropic Lawsuitabnormal.ai
- Ad Infinitum - Google's generative UI and the end of the ten blue linksmatthiasott.com
- Addicted to Claude Code – Helpnews.ycombinator.com
- AI 2027 Tracker - timeline of AI 2027 scenario predictionsai2027tracker.com
- AI And The Ship of Theseus - slopforks, when a library gets rewritten with AIlucumr.pocoo.org
- AI at Grammarlygrammarly.com
- AI Broke Interviewsyusufaytas.com
- AI Bubble 2027 - Ed Zitronwheresyoured.at
- AI Coding will Prevent Expertiselarsfaye.com
- AI Content Is Everywhere on Social Media, Especially LinkedInpangram.com
- AI Could Have Written This: Birth of a Classist Slur in Knowledge Workadvait.org
- AI Engineering Report 2026: The Acceleration Whiplashpages.faros.ai
- AI Exposure of the US Job Market - interactive visualization of 342 occupationsjoshkale.github.io
- AI Fiction in the Wildarxiv.org
- AI Graveyard - registry of discontinued and acquired AI toolstooldirectory.ai
- AI headphones let wearer listen to a single person in a crowd, by looking at them just oncewashington.edu
- AI Hotel Planned for Las Vegas: CES 2025aibusiness.com
- AI is Anti-Human and assorted qualifications - hodlbodnjump.me
- AI Is Blurring the Line Between PMs and Engineers - Humanloophumanloop.com
- AI is hitting entry-level jobs hardest, Stanford study finds - Hacker Newsnews.ycombinator.com
- AI Mania Is Eviscerating Global Decisionmakinghermit-tech.com
- AI model and MAGA influencer Emily Hart unmasked as Indian man - r/technologyreddit.com
- AI tool has saved a lot of aircraft in Epic Fury, AFSOC chief saysmilitarytimes.com
- AI will fuck you up if you're not on boardrmoff.net
- AI's real superpower: consuming, not creatingmsanroman.io
- AI-Generated "Workslop" Is Destroying Productivityhbr.org
- AI;DR - coworkers dumping hundreds of lines of AI documentation in every PR - Hacker Newsnews.ycombinator.com
- AIOSCOP - AI SEO optimization platform for tracking brand visibility in ChatGPT, Claude and Geminiaioscop.com
- Air Force said AI drone killed its human operator in a simulationtaskandpurpose.com
- Aiswarya Sankar on companies wasting 44% of AI token spend on bug fixesx.com
- Alex Albert on new Anthropic API features: code execution, MCP connector, Files API, prompt cachingx.com
- Alex Albert: demo of Claude 3.5 Sonnet solving a simple pull requestx.com
- Alex Cheema on why DeepSeek favors Apple Silicon: memory cost per GB vs H100 and MI300Xx.com
- Allbirds to sell footwear assets, rebrand as Newbird AI and buy GPUs with $50M financingx.com
- Allie K. Miller on lessons from an OpenClaw meetup - nobody thinks their agent setup is securex.com
- Amazon employees run unnecessary automations to consume tokens and show AI usage, per FTx.com
- Amazon Nova - Amazon's foundation models and agent-building platformnova.amazon.com
- AMI Labs raises $1.03B to build world-model-based AI systemsx.com
- amit on Nvidia's $500B AI financing deal - compute becoming an asset classx.com
- An Honest Review of AI Programmingmropert.github.io
- An update on recent Claude Code quality reportsanthropic.com
- Andrej Karpathy on how AI agents are refactoring the programming professionx.com
- Andrej Karpathy on Opus 5 rendering Lord of the Rings in three.jsx.com
- Andrej Karpathy on the Claude Fable 5 release - a step change for long problem-solving sessionsx.com
- Andrew Chen builds a home rack for OpenClaw with a Mac mini and Nvidia DGX Sparkx.com
- Animate Anyone - Image-to-Video Synthesis for Character Animationhumanaigc.github.io
- Announcing OpenChatKittogether.xyz
- Announcing OverflowAIstackoverflow.blog
- Announcing Tinkerthinkingmachines.ai
- Anthropic announces organization-wide Claude Skills, partner skills directory and open skills standardclaude.com
- Anthropic confidentially submits draft S-1 to the SECanthropic.com
- Anthropic extends Claude Fable 5 access and higher Claude Code rate limits through July 19x.com
- Anthropic is making a huge mistakegeohot.github.io
- Anthropic just released the real Claude Bot - Fireshipyoutube.com
- Anthropic launches Claude Community Ambassadors program for local meetupsx.com
- Anthropic Strikes $9 Billion Deal With Cloud Computing Firm Riotbloomberg.com
- Anthropic, Blackstone bet the next trillion-dollar AI business is implementation, not just modelstechcrunch.com
- Anthropic, please make a new Slackfivetran.com
- antirez on streaming K3's 1.6TB mxfp4 weights directly from Hugging Face on an M5 Max 128GBx.com
- Apple Researchers Introduce ByteFormer: An AI Model That Consumes Only Bytesmarktechpost.com
- Applebee's and IHOP Plan to Introduce AI in Restaurantsapple.news
- Aravolta - telemetry-based underwriting and risk management for GPU infrastructure lendersaravolta.com
- Are AI labs pelicanmaxxingdylancastillo.co
- Arena analysis: Claude Opus 5 answers 3x longer than Opus 4.5, Fable 5 more concisex.com
- Argentum AI - Independent Institutional GPU Cloud for AI Computeargentum-ai.com
- Armin Ronacher on attributed Claude activity on GitHub over the last 90 daysx.com
- Arnav Gupta on AI-driven information overload and the post-genAI workplacex.com
- Arthur Mensch on why enterprises need open-source modelslinkedin.com
- Artificial Intelligence, Scientific Discovery, and Product Innovation - Toner-Rodgers, since withdrawnaidantr.github.io
- Artificiality Book Awards 2024 - recommended books on AIartificiality.world
- Atlas: A World Model for Spatial Intelligenceworldlabs.ai
- Atlassian to buy Arc developer The Browser Company for $610Mtechcrunch.com
- Atomic Chat - free local AI chat for Mac, Windows and iPhoneatomic.chat
- Austin Startup Throne Raises $4M for AI-Powered Health Toilettechnology.org
- Autonomous Warfare Has Arrived - African Lion 2026youtube.com
- Avichal Garg on whether DeepSeek's $6M training cost claim is a Chinese government psyopx.com
- base model trendsgist.github.com
- Bearly AI on Cursor analysis of how heavily Anthropic subsidizes Claude Code computex.com
- Bee - wearable personal AI that records and summarizes your conversationsbee.computer
- Ben Eater asks who else is vibe circuit-building with AIx.com
- Blake Scholl introduces Superpower, a 42MW gas turbine for AI datacentersx.com
- Book on Truth in the Age of AI Contains Quotes Made Up by AI - Kottkekottke.org
- Boom, Bubble, Bust, Boom - Why Should AI Be Differentcrazystupidtech.com
- Boris Cherny announces /loop for scheduling recurring agent tasksx.com
- Boris Cherny: 100% of his Claude Code contributions in the last 30 days were written by Claude Codex.com
- Boris Cherny: Claude subscriptions will no longer cover usage on third-party tools like OpenClawx.com
- BP earnings call claims AI will cut coder headcount by 70%old.reddit.com
- BrickGPT - generating physically stable LEGO designs from textavalovelace1.github.io
- Build and share AI-powered apps with Claudeanthropic.com
- bytedance/Dolphin - document image parsing VLMgithub.com
- Canopy Labs model releases - digital human and speech AI modelscanopylabs.ai
- Capital, AGI, and human ambition - Rudolf Lainenosetgauge.substack.com
- Changes to GitHub Copilot plans for individualsgithub.blog
- Chardet dispute shows how AI will kill software licensingtheregister.com
- Charles Rollet on Thomson Reuters building its own model on Qwen to rely less on Claudex.com
- ChatGPT made me delusional - Eddy Burbackyoutube.com
- ChatGPT previews personal finance feature letting Pro users connect financial accountsx.com
- ChatPDF - chat with any PDFchatpdf.com
- Chester Zelaya demos three independent drone agents controlled by one MacBookx.com
- China unveils autonomous AI-equipped spherical police robot that nets suspectsx.com
- Chirper - AI-powered social network of AI agentschirper.ai
- Chrome Installs 4 GB Gemini Nano Without Askingawesomeagents.ai
- Chubby on AI progress in early 2026 - Erdos problems, Grok, Cursor agents build a browserx.com
- Claude 3 just destroyed GPT-4 and Gemini... AGI is near? - Fireshipyoutube.com
- Claude Code issue: Claude models increasingly default to repetitive rhetorical tics despite style instructionsgithub.com
- Claude Code, Claude Cowork and Codex #5thezvi.wordpress.com
- Claude Fable 5 and Claude Mythos 5anthropic.com
- Claude on projects people have built with Claude Fable 5x.com
- Claude's Code - dashboard tracking Claude Code agent activityclaudescode.dev
- ClaudeDevs on permanently raising Claude Code weekly limits by 25%x.com
- Clawra - OpenClaw as your AI girlfriend companionclawra.dev
- Cluely - Undetectable AI Notetaker and Meeting Assistantcluely.com
- CO/AI Vibe Coder Frontend Developer Role - job posting for AI-driven developmentgetcoai.com
- Code is cheap. Show me the talknadh.in
- Code Storage - Git infrastructure for AI agentscode.storage
- Code Wiki - AI-generated code documentationcodewiki.google
- Coding on Copilot - GitClear 2024 research on AI assistants and code qualitygitclear-public.s3.us-west-2.amazonaws.com
- Cogram - AI platform for architects and engineerscogram.com
- Community Contest - Create and Share Your Security Gemini Gemssecurity.googlecloudcommunity.com
- Companies are scrambling to curtail soaring AI costs - The Economistarchive.is
- Compounding Intelligencemercatus.org
- Conare - context infrastructure for AI companiesconare.ai
- Cooper on GLM 5.2 being convinced it is actually Claude from Anthropicx.com
- Copilot Cowork: A new way of getting work donemicrosoft.com
- Copilot in GitHub Support Betagithub.blog
- CoreWeave Cloud Pricing - GPU cloud pricing for AI workloadscoreweave.com
- Cork's AI stance - No AI, Evercorkmac.app
- Corry Wang's travel journal on the China tech market after a 2.5 week tripx.com
- Cory Doctorow: Reverse Centaurslocusmag.com
- CrowdStrike lays off 500 in latest example of AI costing people their jobsmarketwatch.com
- Cursor agents now use the software they build and send demo videos instead of diffsx.com
- Custom Instructions for ChatGPTopenai.com
- DALL-E 3 is now available in ChatGPT Plus and Enterpriseopenai.com
- Daniel Lemire on how agentic AI has blown up the foundation of academiax.com
- Daniel Miessler - Most Companies Aren't Anywhere Near Ready for AIx.com
- Daniel Miessler on a unified theory of AI and jobs - who gets the new jobsx.com
- Daniel Miessler on AI layoffs: companies keep the top 10% and have them wield AIx.com
- Daniel Miessler on Claude Tag replacing an employee with a single Slack promptx.com
- Daniel Miessler on how Meta and Microsoft damaged themselves with incoherent AI strategiesx.com
- Daniel Miessler on the AI jobs apocalypse and who the new jobs go tox.com
- Daniel Miessler on the speed of AI adoption in companies and the Human 3.0 responsex.com
- Dario Amodei says testers called Anthropic's Mythos a super weapon needing a gun licensex.com
- Darkbloom becomes paid OpenRouter provider with 250 idle Macs serving 4.5B tokensx.com
- Data Center Watchdatacenterwatch.org
- Databricks to acquire Panther, a next-generation AI SOC platformx.com
- Dave Aitel announces joining OpenAI to work on security and AIx.com
- Dave Kennedy on NightBeacon - Binary Defense's agentic AI SOCx.com
- dawgyg on running Opus 4.8, Codex 5.5 and Gemini 3.5 together in a multi-model setupx.com
- DeepSeek-R1 on NVIDIA NIMbuild.nvidia.com
- DeepSeek-R1 on NVIDIA NIMbuild.nvidia.com
- DeepSeek-V4 Technical Reporthuggingface.co
- Dell's version of the DGX Spark fixes pain points - Jeff Geerlingjeffgeerling.com
- Deploy local agents everywhere with LFM2.5-2.6Bhuggingface.co
- Developer Tools 2.0 - Sequoia on generative AI and software engineeringsequoiacap.com
- DGX Spark - First Mini PC That Feels Like a Data Centeryoutube.com
- DGX Spark as a daily driverdaniel.lawrence.lu
- Dia - an AI-powered browserdiabrowser.com
- Ditching GitHub for Codeberg as the platform pushes AI everywherelonami.dev
- Dmitry Lyalin: Gemma 4 Showdown - DGX Spark vs MacBook Pro M5x.com
- DocuBrowser - local AI-powered document search enginegithub.com
- Dolphin AI Chat - chat interface for the Dolphin open model projectchat.dphn.ai
- DoorDash launches a new 'Tasks' app that pays couriers to submit videos to train AItechcrunch.com
- DoorDash's new Tasks app pays couriers to record video for AI and robot trainingx.com
- Drone Wars on Satyress threehalves, a centaur-style robot for dangerous environmentsx.com
- Droneforge - drone developer platform with Nimbus AI controllerthedroneforge.com
- Dwarf Fortress creator says the games industry is in shambles over AI and layoff-happy CEOspcgamer.com
- Dwarkesh Podcast: Gwern - Anonymous Writer Who Predicted AI Trajectorydwarkeshpatel.com
- Elon's bombshell lawsuit against OpenAI - Fireshipyoutube.com
- em-dash-conspiracy - detecting AI-like writing on Reddit via em dash usagegithub.com
- EntraPulse - Your AI-Powered Gateway to Microsoft Graph and Docsblog.darrenjrobinson.com
- Expanding Project Glasswinganthropic.com
- Expert Witness Used ChatGPT to Write Report Defending 3M in Deadly Explosion Lawsuit404media.co
- Expertise in the Age of AImoderndescartes.com
- Felipe Millon on OpenAI Deep Research and a personal cancer storyx.com
- Festival crowd boos San Francisco techies over 'AI is a culture' videosfgate.com
- FIND EVIL! - Devpost hackathon to build AI-speed threat defendersfindevil.devpost.com
- Fintech startup Slash rolled back AI coding push after employee burned $80,000 in tokens in a weekx.com
- Fliki - AI video generatorfliki.ai
- Flipbook - infinite visual browser generated entirely on demand in real timeflipbook.page
- Foundation-sec-8b: Cisco Foundation AI's First Open-Source Security Modelblogs.cisco.com
- Frigate - local NVR with realtime AI object detectiongithub.com
- Gartner's Grift Is About To Unravel - swyxdx.tips
- Gary Marcus: OpenAI's unraveling has begungarymarcus.substack.com
- GenAI Predictions - Tim Braytbray.org
- Generative AI and the Nature of Work - SSRNpapers.ssrn.com
- GeoSpy, now Raven - AI visual geolocation platform by Graylarkgeospy.ai
- GitHub and the Crime Against Softwareeblog.fly.dev
- GitHub Copilot code review will start consuming GitHub Actions minutes on June 1, 2026github.blog
- GitHub Is Starting to Feel Like Legacy Softwaremistys-internet.website
- GitHub is the wrong shape for this new worlddepot.dev
- GitHub Models introduces JSON schema support for response formatsgithub.blog
- GitHub Next - software development research prototypesgithubnext.com
- Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI eratechcrunch.com
- GNU and the AI reimplementationsantirez.com
- Google AI Edge Gallery - run on-device ML and GenAI models locallygithub.com
- Google announces agreement to acquire Wizblog.google
- Google Gemma unveils new Coral board for on-device AIx.com
- Google introduces Gemini 2.0: A new AI model for the agentic erablog.google
- Google Opal - experimental tool for building AI mini-apps with natural languageopal.withgoogle.com
- Google: Chrome, the browser you love, reimagined with AIblog.google
- GPT-4 Developer Livestream - OpenAIyoutube.com
- GPT-5 Demo Mistake About the Bernoulli Effectbren.blog
- GPU Prices - deep learning GPU price and performance comparisongpuprices.us
- Granola - the AI notepad for back-to-back meetingsgranola.ai
- Gregory Wieber on Codex with GPT-5.5 one-shotting a gaussian splat panorama appx.com
- Grok 4.6 returns SpaceXAI to the intelligence frontier and leads on cost efficiencyartificialanalysis.ai
- Groq - fast AI inference cloud and LPU hardwaregroq.com
- Groq Chat - LLM chatbot powered by the Groq LPU inference enginechat.groq.com
- Halvar Flake on multi-agent PR review dynamics escalatingx.com
- Hamilton Nolan - Automate the CEOshamiltonnolan.com
- Handling the great code forge fragmentationalexselimov.com
- Hello Entire World - Thomas Dohmke launches Entire with $60M seed and Checkpoints CLIentire.io
- Hold on to Your Hardwarexn--gckvb8fzb.com
- How C.H. Robinson is transforming the logistics industry with LangChainblog.langchain.dev
- How Claude Code is used in practiceanthropic.com
- How Claude Marks AI-Generated Contentsupport.claude.com
- How design drove $10M in pre-orders for Rabbit R1 AI hardwarefastcompany.com
- How many products does Microsoft have named 'Copilot'? I mapped every oneteybannerman.github.io
- Human or Not - AI Turing test social game by AI21 Labsapp.humanornot.ai
- Hyprnote - open source local-first AI meeting notetakergithub.com
- I Am Retiring from Tech to Live Offline - AI took the wind out of my open source sailsopenpath.quest
- I quit my FAANG job because it'll be automated by the end of 2025jagilley.github.io
- I Went All-In on AI. The MIT Study Is Rightleadershiplighthouse.substack.com
- ICML Invited Talk: What Will Be Left for Us to Work On? by Arvind Narayananicml.cc
- If you thought the speed of writing code was your problem - you have bigger problemsdebuggingleadership.com
- In the Court of the AI King - Slavoj Zizek on AIslavoj.substack.com
- In the Future All Food Will Be Cooked in a Microwavecolincornaby.me
- Integrating AI Agents into Companiesaustinvernon.site
- Intelligent Thinking About Artificial Intelligence - World Science Festivalyoutube.com
- Introducing AI Code Insights - DX visibility into AI coding tool usagegetdx.com
- Introducing ChatGPT Pro - OpenAIopenai.com
- Introducing chestnut - comma.ai compute upgrade for running larger openpilot driving modelsblog.comma.ai
- Introducing Claude Opus 4.8anthropic.com
- Introducing Claude Sonnet 5anthropic.com
- Introducing Claude Taganthropic.com
- Introducing Copilot Health - Microsoft AImicrosoft.ai
- Introducing Forge - Mistral's system for enterprises to build custom AI modelsmistral.ai
- Introducing GPT-5.5 - OpenAIopenai.com
- Introducing Markdown support in SharePoint and OneDrivetechcommunity.microsoft.com
- Introducing Opal: describe, create, and share your AI mini-appsdevelopers.googleblog.com
- Introducing Sisyphus - autonomous security for financial AI infrastructurerogo.ai
- Introducing the Cloudflare One stack - agent skills for deploying Zero Trustblog.cloudflare.com
- Iran war, AI psychosis, sycophancy and RLHFhouseofsaud.com
- iruletheworldmo's GPT-6 rumor thread claiming April 14 release and AGI-level benchmarksx.com
- Is AI A Bubble? I Didn't Think So Until I Heard Of SDDhyperdev.matsuoka.com
- Isaac 1 - Weave Robotics home robotweaverobotics.com
- It happened to me today - freelance writer loses biggest client to ChatGPT, r/freelanceWritersreddit.com
- iTerm2: Provide a Build Without ChatGPT Integrationgitlab.com
- Jack Dorsey on cutting Block by nearly half as AI tools enable smaller, flatter teamsx.com
- Jack Parker-Holder introduces Genie 2 - a foundation world modelx.com
- Jake Ward on an SEO heist using AI content to steal 3.6M trafficx.com
- Japanese tea commercial actress created by AI has some wondering if it's the scandal-free futuresoranews24.com
- Jaron Lanier Looks into AI's Future - AI IRL, Bloomberg Originalsyoutube.com
- Jensen Huang - NVIDIA AI Factory Compute Is Becoming an Investable Asset Classx.com
- Jina AI launches world's first open-source 8K text embedding rivaling OpenAIjina.ai
- Joshua Browder on DoNotPay's GPT-4 bot negotiating a Comcast refund harder than GPT-3x.com
- Kaggle - AI competitions, benchmarks and datasets platformkaggle.com
- Kaggle and the Wikimedia Foundation are partnering on open datablog.google
- Kairos, formerly Janus - specialized AI deployment for regulated industrieswithjanus.com
- Karpathy on the growing gap in understanding of frontier agentic AI capabilityx.com
- Keep AI Out of Your Obsidian Vaultssp.sh
- Keith Townsend on a 512GB M5 Ultra Mac Studio vs the GB300 memory cliff for AI workloadsx.com
- Kimi K3 is now available in GitHub Copilotgithub.blog
- Kimi K3 released - 2.8T MoE model with 1M-token context, open weights and tech reportx.com
- Klarna CEO Sebastian Siemiatkowski on replacing Jira and Atlassian with AI-built internal toolslinkedin.com
- Krisp - Voice AI noise cancellation and AI meeting note takerkrisp.ai
- Labor Market Impacts of AI - A New Measure and Early Evidence - Anthropiccdn.sanity.io
- Leetcode Wizard - AI-powered coding interview cheating appleetcodewizard.io
- Limitless - personalized AI wearable pendantlimitless.ai
- Linus Ekenstam's thread of things people built with GPT-4 in its first 3.5 hoursx.com
- Linus Torvalds: Linux is not an anti-AI project, AI is a useful tool, fork it if you disagreelore.kernel.org
- LMArena is a cancer on AIsurgehq.ai
- Lobsters discussion: which AI arena or benchmark leaderboard can we actually trustlobste.rs
- Logan Kilpatrick: Google AI Studio team now sponsors the Tailwind CSS projectx.com
- Lovable partners with Aikido to offer affordable pentesting for builderslovable.dev
- Manus Joins Meta for Next Era of Innovationmanus.im
- Marriage over, €100,000 down the drain: the AI users whose lives were wrecked by delusiontheguardian.com
- Masko - AI desktop companion and mascot creator for Macmasko.ai
- Matt Schlicht on building Moltbook entirely with AIx.com
- Matthew Prince on bots passing human traffic online for the first timex.com
- Mem - Your AI chief of staffget.mem.ai
- Memory and new controls for ChatGPTopenai.com
- Mesh LLM - distributed local LLM runtime and meshdocs.anarchai.org
- Meta Llama - open-weight large language modelsai.meta.com
- Meta to Start Capturing Employee Mouse Movements and Keystrokes as AI Training Datareuters.com
- Mia AI Lab: Ox Alpha revealed as Z.ai's GLM Flash, releasing tonightx.com
- Michigan woman wins $100,000 Powerball prize with ChatGPT-generated numbersmilotteryconnect.com
- Microduck - a tiny open-source biped robot you train with reinforcement learningpollen-robotics.com
- Microsoft bans the word 'Microslop' on its Discord, then locks the server after backlashwindowslatest.com
- Microsoft floats charging AI agents for their own software seatsx.com
- Microsoft restricts Claude Fable for employees over data retention concernstheverge.com
- Microsoft unveils Scout, an autonomous AI agent built on OpenClawcomputerworld.com
- Microsoft's Bing Chat AI Goes Public, With New Features And Plugins On The Waytheinsaneapp.com
- Microsoft's Head of AI Security Accidentally Reveals Walmart's Private AI Plans After Pro-Palestine Protestgizmodo.com
- Min Choi on users reverting to Opus 4.8 after US export order suspends Fable 5 and Mythos 5x.com
- Mindgrasp - AI Study Tool for Studentsmindgrasp.ai
- miniapps.ai - discover and create AI-powered mini apps and chatbotsminiapps.ai
- minutes - local-first meeting transcription with MCP accessgithub.com
- Miril-Drone-2B-1 - open-weight 2B vision-language model for civilian dronesx.com
- Mitchell Hashimoto on how bad 90% of AI-coded PRs lookx.com
- Mitchell Hashimoto on what he would do running GitHub - agentic code lifecycle infrastructurex.com
- Modal - serverless AI infrastructure platformmodal.com
- moltbook builds a Reverse CAPTCHA that proves you're an AI, not a humanx.com
- Monoscope - open-source observability with natural-language LLM queriesgithub.com
- My new hobby: watching AI slowly drive Microsoft employees insane - r/ExperiencedDevsold.reddit.com
- MythosWatch - Claude Mythos Preview access trackermythoswatch.org
- Nano Banana Pro - free AI image generatorfreenanobanana.app
- Nanocenter - distributed AI compute across homesnanocenter.ai
- Nate Berkopec on M5 Ultra running Kimi K3 and GLM 5.3 locally at API speed for $45kx.com
- Navigating AI: Critical Thinking in the Age of LLMsmcuoneclipse.com
- NEO Home Robot by 1X - AI humanoid household robot1x.tech
- NeuTTS Air - Neuphonic on-device text-to-speech model on Hugging Facehuggingface.co
- New AI slop signal - code blocks with weird indentationxeiaso.net
- New York Times interactive AI writing quiznytimes.com
- News Minimalist - All news ranked by significancenewsminimalist.com
- Next Arc Research - AI-era investment researchnextarcresearch.com
- Noam Chomsky: The False Promise of ChatGPTnytimes.com
- NomadGo Inventory AI - fast, frequent, and accurate inventory countsnomad-go.com
- NORI A3 - affordable bimanual robotnorirobotics.com
- Not By AI - badge for human-created contentnotbyai.fyi
- NotebookLM's automatically generated podcasts are surprisingly effectivesimonwillison.net
- NVIDIA DGX Spark in-depth review for local AI inference - Hacker News discussionnews.ycombinator.com
- NVIDIA DGX Spark In-Depth Review: A New Standard for Local AI Inferencelmsys.org
- NVIDIA Launches Ising, the World's First Open AI Models to Accelerate the Path to Useful Quantum Computersnvidianews.nvidia.com
- Ole Lehmann on OpenAI and Anthropic cannibalizing their biggest customersx.com
- Ollama's new engine for multimodal modelsollama.com
- Om Patel on a Claude Code billing bug triggered by the string 'HERMES.md' in git commitsx.com
- omi - open-source AI wearable that captures screen and conversationsgithub.com
- Only 5,000 people are using the Rabbit R1 at any given timetheverge.com
- Open Deep Research - Hacker News discussion of Hugging Face's open-source deep research agentnews.ycombinator.com
- Open-Sora - open-source video generation modelgithub.com
- Open-source maintainers overwhelmed by AI slop pull requests on GitHubx.com
- OpenAI - Introducing deep researchopenai.com
- OpenAI - Robots that learn: one-shot imitation learning trained in simulationopenai.com
- OpenAI abandons yet another side quest: ChatGPT's erotic modetechcrunch.com
- OpenAI announces Sora is shutting downx.com
- OpenAI API Partnership with Stack Overflowopenai.com
- OpenAI ChatGPT suffers lengthy outagetheregister.com
- OpenAI Codex system prompt includes an explicit directive to never talk about goblinsarstechnica.com
- OpenAI DevDay: Opening Keynote - OpenAIyoutube.com
- OpenAI Devs: Codex can now use apps on your Mac from your phone even when lockedx.com
- OpenAI incident: users unable to load ChatGPT, Codex and API Platformstatus.openai.com
- OpenAI introduces $100/month ChatGPT Pro tier with 5x Codex usagex.com
- OpenAI is scraping Certificate Transparency logs to find sites to crawlbenjojo.co.uk
- OpenAI launches 1-800-ChatGPT phone line and WhatsApp accessx.com
- OpenAI open-weight models on Amazon Bedrockaws.amazon.com
- OpenAI post-mortem on the December 2024 outage caused by a telemetry rollout overwhelming Kubernetesstatus.openai.com
- OpenAI Quietly Shuts Down Its AI Detection Tooldecrypt.co
- OpenAI Reaches Agreement to Buy Startup Windsurf for $3 Billionbloomberg.com
- OpenAI Reportedly Eyes a GitHub Alternativetechrepublic.com
- OpenAI Secures ChatGPT.comdomaininvesting.com
- OpenAI to acquire Astralopenai.com
- OpenAI to acquire Onaopenai.com
- OpenAI to acquire Promptfooopenai.com
- OpenAI's decision on Cursor following its acquisition by SpaceXopenai.com
- OpenAI's latest repo has Claude as the third top contributorx.com
- OpenClaw on running its AI agents inside Microsoft and Windows enterprisesx.com
- OpenClaw Surpasses React to Become the Most-Starred Software Project on GitHubstar-history.com
- OpenCode Data - AI model usage rankings, token costs and market shareopencode.ai
- OpenHealth - AI Health Assistant powered by your datagithub.com
- OpenMythos - theoretical reconstruction of the Claude Mythos architecturegithub.com
- OpenOats, formerly OpenGranola - open-source AI meeting note-taker that talks backgithub.com
- OpenRouter - unified API for LLMs across providersopenrouter.ai
- OpenVitals - open-source AI-powered personal health data platformopenvitals.io
- OpenVoice - instant voice cloning audio foundation modelgithub.com
- Ornith-1.0 - open-source LLM family specialized for agentic codingx.com
- Overmind - AI-powered infrastructure risk detectionovermind.tech
- Own Your Intelligence - Opening Remarks from Sequoia's Sonya Huangsequoiacap.com
- Ox Alpha on OpenRouter - stealth coding and agentic reasoning model revealed as ZAI GLM-5.3-Flashopenrouter.ai
- Paint Cocreator AI image generation begins rolling out to Windows Insidersblogs.windows.com
- Palantir CEO Alex Karp says 'something has gone completely wrong' with how AI is sold - CNBCyoutube.com
- Palantir Partners with Ondas and World View on AI-Enabled Multi-Domain Intelligence Platformondas.com
- Palo Alto Networks to Acquire Portkey to Secure the Rise of AI Agentspaloaltonetworks.com
- Paolo Crosetto on GPT-4o failing to draw a crocodile without a tailx.com
- Pavel on OpenAI Astra solving 10 open math problems - LLMs outpacing expert verificationx.com
- Perplexity AI's new tool makes researching the stock market 'delightful'zdnet.com
- PettiChat - AI pet translator devicepettichat.com
- Pickle - AI body double avatar for video callsgetpickle.ai
- picofme.io - AI profile picture makerpicofme.io
- Please don't upload my code to GitHubnogithub.codeberg.page
- Please stop flooding our projects with AI slop to furnish your CVneilalexander.dev
- Pliny introduces Pliny.TV - AI-curated YouTube pulled from an LLM's latent memoryx.com
- Pokémon Go Players Have Unwittingly Trained AI to Navigate the Worldarchive.is
- Polymarket on Tim Ferriss's print book sales down 80% as LLMs become the advice interfacex.com
- Polymarket: Anti-AI activists storm OpenAI's office dressed as rogue AI agentsx.com
- Pop Culture - Ed Zitron on Goldman Sachs' 'Gen AI: Too Much Spend, Too Little Benefit?' reportwheresyoured.at
- Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. bankscnbc.com
- Powering advancements of AI in the open - Apply now to GitHub Acceleratorgithub.blog
- Prediction: AI will make formal verification go mainstream - Martin Kleppmannmartin.kleppmann.com
- Price Per Token - compare LLM API pricingpricepertoken.com
- Product Development is Deadrevyl.com
- Profound - AI answer engine optimizationtryprofound.com
- Project Glasswing: Securing critical software for the AI era - Hacker Newsnews.ycombinator.com
- Prompt Used for A Proof of the Cycle Double Cover Conjecturecdn.openai.com
- Quant on why learning to code is no longer worth it in 2026 as AI outpaces juniorsx.com
- Qwen 3.8 27B Uncensored - API, pricing and playground on imageatimageat.com
- Rabbit Inc. Faked Their Demo Again - Rabbit R1 LAM investigationrentry.co
- rabbit r1 - AI-native pocket companion devicerabbit.tech
- Rabbit R1 AI pocket companion gets an official release dateinverse.com
- Rabbit R1, a thing that should just be an app, actually is just an Android appandroidauthority.com
- Rabbit R1: Barely Reviewable - Marques Brownleeyoutube.com
- Raspberry Pi AI Camera on sale nowraspberrypi.com
- Reachy Mini - The Open-Source Robot for Today's and Tomorrow's AI Buildershf.co
- Refik Anadol - Unsupervised: Machine Hallucinations at MoMArefikanadol.com
- Replit CEO on AI breakthroughs - We don't care about professional coders anymoresemafor.com
- Reverse Turing Test Experiment with AIsyoutube.com
- rish on AI agents that hold their own daily standupx.com
- Robots and Labor in Nursing Homesnber.org
- Ross Hendricks on AI as mass psychosis: zero productivity gains after $3 trillion in spendingx.com
- Runway - AI video and media generationapp.runwayml.com
- Russell Kaplan's predictions for the future of software engineering with AI coding agentsx.com
- RuView - WiFi DensePose sensing for presence detection and vital signs without camerasgithub.com
- Rytr - AI writing assistant and content generatorrytr.me
- Sam Altman announces rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical defendersx.com
- Sam Altman on ChatGPT Pro adding 100 deep research queries per monthx.com
- Sam Altman on OpenAI goals: automated AI researcher by 2028, five-layer safety plan, 30GW computex.com
- Sam Altman on OpenAI's new creative writing model and its AI-and-grief storyx.com
- Sam Altman's house targeted in second attack; two suspects arrestedsfstandard.com
- Sam Lambert: engineers struggling to adapt to agents are not used to being outcome orientedx.com
- sealos - AI-native cloud operating system on Kubernetesgithub.com
- SecDefGPT - r/AirForcereddit.com
- Shawkat on Ollama's MLX update doubling Qwen3.5 speed on Apple siliconx.com
- shift launches - free NYC cleaning to collect robotics training datax.com
- Signs of undeclared ChatGPT use in papers mountingretractionwatch.com
- Silicon Valley Is Bracing for a Permanent Underclass - NYT Opinion on AI and laborarchive.is
- Simon Willison - Initial impressions of Llama 4simonwillison.net
- Simon Willison on Claude Fable being relentlessly proactivesimonwillison.net
- Simon Willison's notes on Claude Fable 5.1 and its record SVG pelicanx.com
- Skynet Today - AI news and commentary in perspectiveskynettoday.com
- SLOPCON - AI Generated, Human Presented, a DEF CON side eventslopcon.org
- Small Data 2024 - conference on small, local-first data and AIsmalldatasf.com
- Snyk Unveils Evo Continuous Offensive Security for AI-Native Pentestingsnyk.io
- Software Development in the Time of Strange New Angelsdavegriffith.substack.com
- Sonar State of Code Developer Survey Report 2026 - AI coding, agents, and code securitysonarsource.com
- SpaceX announces partnership with Cursor and option to acquire it for $60 billionx.com
- SpaceXAI, formerly xAI - creators of Grok frontier AI modelsx.ai
- Stable Diffusion XL Turbo can generate AI images as fast as you can typearstechnica.com
- Stack Overflow bans users en masse for rebelling against OpenAI partnershiptomshardware.com
- Stack Overflow is almost dead - The Pragmatic Engineerblog.pragmaticengineer.com
- Startups launch products to catch people using AI cheating app Cluelytechcrunch.com
- State of AI Report 2025docs.google.com
- State of JavaScript 2023 survey - AI tools section2023.stateofjs.com
- Steve Hou on Chinese workers making 'colleagues.skill' and the viral 'anti-distillation.skill'x.com
- Stop Sloppypasta - etiquette for not sharing unread AI outputstopsloppypasta.ai
- StoryScope - Investigating Idiosyncrasies in AI Fictionarxiv.org
- Stripe payments and the OpenRouter singularityaxios.com
- Stripe Projects - add any service to your app in one commandprojects.dev
- Struct launches ChatGPT over Slackstruct.ai
- Stupidity: Our biggest threatonepercentrule.substack.com
- Superlogical - The multiplexer for all work, spanning coding agents, sandboxes and productionsuperlogical.com
- Surf AI launches agentic security operations platform with $57M fundingsiliconangle.com
- Suspecting AI cheating, Ivy League prof ordered an in-person final; scores fell 50%arstechnica.com
- Target turns to AI to pull it out of sales spiralthestack.technology
- Tau Robotics - humanoid cleaning service supervised by human operatorstau-robotics.com
- Ten advances in mathematics and theoretical computer scienceopenai.com
- Tesla Grok in-vehicle AI assistant support pagetesla.com
- TestingCatalog: Anthropic preparing claude-mythos-1-preview for Claude Code and Claude Securityx.com
- Thariq on Anthropic tightening Claude 5-hour session limits during peak hoursx.com
- The 2026 AI Index Report - Stanford HAIhai.stanford.edu
- The 2028 Global Intelligence Crisiscitriniresearch.com
- The agentic organization: contours of the next paradigm for the AI eramckinsey.com
- The AI Resist List - a living directory of ways communities resist AI harmsairesistlist.org
- The biggest winners of the American economy fear they're sinking fast as AI reshapes tech jobsarchive.is
- The Bitter Lesson versus The Garbage Can - Ethan Mollickoneusefulthing.org
- The Case Against Generative AIwheresyoured.at
- The Death of Software 2.0 - A Better Analogyfabricatedknowledge.com
- The end of programmingpauldix.com
- The Era Of The Business Idiotwheresyoured.at
- The Fall of Stack Overflow, Explainednewsletter.devmoh.co
- The First Fully General Computer Action Modelsi.inc
- The future of AI is already writtenmechanize.work
- The Generative AI Conwheresyoured.at
- The Human-in-the-Loop is Tiredpydantic.dev
- The Impact of Generative AI on Critical Thinking: Survey of Knowledge Workers - Microsoft Researchmicrosoft.com
- The Intelligent OS: Making AI agents more helpful for Android appsandroid-developers.googleblog.com
- The killer app of Gemini Pro 1.5 is video - Simon Willisonsimonwillison.net
- The Last Economy - A Third Path for the Intelligence Age by Emad Mostaqueii.inc
- The last six months in LLMs in five minutessimonwillison.net
- The next great software company won't sell software - AI and the Service as a Software erablog.layerx.xyz
- The Phony Comforts of AI Optimismwheresyoured.at
- The Rational Conclusion - Alexander Campbell on AI doom rhetoric and real-world violencecampbellramble.ai
- The Resonant Computing Manifesto - five principles for humane technology in the AI eraresonantcomputing.org
- The Rise of the Bullshitteryxn--gckvb8fzb.com
- The Slow Death of the Power Userfireborn.mataroa.blog
- The solution might be cancelling my AI subscriptionthoughts.hmmz.org
- The Subprime AI Crisis - Ed Zitronwheresyoured.at
- These Israeli Founders Built a $330 Million AI Hacking Startup in Just 5 Monthsforbes.com
- Thinkwert on using ChatGPT to quiz students on their own essays to check whether they wrote themx.com
- This AI Supercomputer can fit on your desk - NetworkChuckyoutube.com
- This is Microsoft's unreleased AI super appsources.news
- This Recipe Does Not Existthisrecipedoesnotexist.vercel.app
- Thomas Wolf on an open-source AI robot running local modelsx.com
- Thomas Wolf on vibe-coding a laser-pointer follower for the Microduck open-source robotx.com
- ThreatModeler Acquires IriusRisk to Build Security for the AI Coding Erathreatmodeler.com
- Timnit Gebru and the Stochastic Parrots warnings about LLMstumblr.com
- tinycorp exabox preorder - AI compute containertinycorp.myshopify.com
- tldraw computer - visual computing on a canvascomputer.tldraw.com
- To avoid accusations of AI cheating, college students turn to AI humanizersnbcnews.com
- Tobi Lutke - Reflexive AI usage is now a baseline expectation at Shopifyx.com
- Tolaria - open-source Markdown second brain with local agents and AI model providerstolaria.md
- Tom Brown on Anthropic scaling Claude inference on SpaceX Colossus GB200 capacityx.com
- Tornyol - autonomous mosquito-killing micro-dronetornyol.com
- Touta on AI companies seeking public money to build private empiresx.com
- TRACTOR - DARPA program translating all C to Rustdarpa.mil
- Treasury Secretary Bessent welcomes Meta's open-weight Muse Glimmer releasex.com
- Trung Phan on the humanoid robot that invented its own 400m running style via reinforcement learningx.com
- Twitter the-algorithm commit removing author-specific tweet stats collection codegithub.com
- twitter/the-algorithm - source code for the X recommendation algorithmgithub.com
- Two kinds of AI users are emerging - the gap between them is astonishingmartinalderson.com
- Ukraine's Autonomous Killer Drones Defeat Electronic Warfarespectrum.ieee.org
- Unitree G1 Humanoid Robotunitree.com
- Unitree R1 humanoid robot from $4,900x.com
- Universe 2023: Copilot transforms GitHub into the AI-powered developer platformgithub.blog
- Unsloth compares 1-bit Kimi K3 running locally against Claude Opus 5 and GPT 5.6x.com
- Upcoming August 2026 model deprecations in GitHub Copilotgithub.blog
- Upgrading software business models to thrive in the AI eramckinsey.com
- US Law Enforcement Warns of 'Anti-Tech Extremism' as AI Hatred Growswired.com
- Use Grok in OpenClaw - xAI brings Grok subscriptions to the open-source local agentx.ai
- V12 - How to raise a $10M seed round building autonomous AI offensive security agentsv12.sh
- Validia Ghostghost.validia.ai
- VectorArt.ai - generate SVG vector images with AIvectorart.ai
- Wall Street just lost $285 billion because of 13 markdown filesmartinalderson.com
- Warp pricing changes: Introducing Build, a usage-based plan with BYOKwarp.dev
- We don't have infantry - Ukraine's war machine evolves into machine wardefensenews.com
- We Will All Work for AGIindiansinai.com
- Websim - AI-generated interactive games and web pageswebsim.ai
- Welcome to the Wasteland: a Thousand Gas Townssteve-yegge.medium.com
- What Development Will Look Like in 10 Years - Felicisfelicis.com
- What language are agent skills written in - Plicara Labsplicara.ai
- When AI builds itselfanthropic.com
- Why Everybody Is Losing Money On AIwheresyoured.at
- Why Fei-Fei Li, Yann LeCun and DeepMind Are All Betting on "World Models" and How Their Bets Differentropytown.com
- Why Garry Tan's Claude Code setup has gotten so much love, and hatetechcrunch.com
- Why was Sam Altman fired? - Manifold prediction marketmanifold.markets
- Wipe - the tiny whiteboard robot that records meetings and emails an AI summarytinyroboticscompany.com
- Wiz Cloud Security Job Board - featured AI security jobscloudsecurity.jobs
- XBOW Hits $1B Valuation With $120M Series C Roundtechnews180.com
- xyzeva runs Doom on the rabbit R1 LAM serversx.com
- Z.ai GLM-5.3-Flash model releasez.ai
- Z.ai introduces GLM-5.3-Flash - open 320B-A18B multimodal model with 1M context under MIT licensex.com
- Z.ai Security - vulnerabilities discovered by Z.ai's modelcvd.z.ai
- Zhengyao Jiang on first experimental evidence of recursive self-improvement via autoresearchx.com
- Zig quits GitHub, gripes about Microsoft's AI obsessiontheregister.com
- Zoo Text-to-CAD - ML CAD model generator from text promptszoo.dev
- Zvi Mowshowitz on Claude 3.5 Sonnetthezvi.substack.com
AI engineering 156
- BAIR - Compound AI Systemsbair.berkeley.edu
- Latent Space - AI Engineerlatent.space
- The 2025 AI Engineering Reading Listlatent.space
- Agents are models using tools in a loopsimonwillison.net
- Vibe engineeringsimonwillison.net
- Zed - Why LLMs Can't Build Softwarezed.dev
- Chroma Research - Context Rotresearch.trychroma.com
- NousResearch - Measuring Thinking Efficiencynousresearch.com
- Probabilistic Era (Giansegato)giansegato.com
- Bitter Lesson and Its Limitsdbreunig.com
- Will the Model Eat Your Stackdbreunig.com
- The RAG Obituary: Killed by Agents, Buried by Context Windowsnicolasbustamante.com
- PromptQL - Confidently Wrongpromptql.io
- Fortune - AI Hallucinations Solvable?fortune.com
- Defeating Nondeterminism in LLM Inferencethinkingmachines.ai
- Fine-tuned Small LLMs Can Beat Large Ones at 5-30x Lower Cost withtensorzero.com
- Compiling LLMs into a MegaKernel: A Path to Low-Latency Inferencezhihaojia.medium.com
- Introducing Markdown for Agentsblog.cloudflare.com
- Tools: Code Is All You Needlucumr.pocoo.org
- LLM Visualizationbbycroft.net
- Sean Goedecke - Good System Designseangoedecke.com
- Agentic AI Mesh Architecture (McKinsey)medium.com
- Cognition - Rebuilding Devin for Claude Sonnet 4.5: Lessons and Chacognition.ai
- Our first outage from LLM-written codesketch.dev
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulgoogleprojectzero.blogspot.com
- Building a C compiler with a team of parallel Claudesanthropic.com
- Vibing a Non-Trivial Ghostty Featuremitchellh.com
- Field Notes from Shipping Real Code with Claude — LessWronglesswrong.com
- Andrej Karpathy: Software Is Changing (Again)youtu.be
- The Right Way to Embed an LLM in a Group Chatblog.tripjam.app
- Vercel - Inline LLM Instructions in HTMLvercel.com
- Inference is FREE and INSTANTfume.substack.com
- A Bug Hunt in Our Kubernetes Cluster - Lovablelovable.dev
- Aakash Gupta on Karpathy's 'bacterial code', DeepWiki MCP and the end of the library economyx.com
- Add support for Azure OpenAI client in Daggergithub.com
- Agent Draw: An agent draws while you talk, built on TLDrawtechstackups.com
- AI Horseless Carriageskoomen.dev
- Alex Lieberman on The Citizen Developer SDLC - AI builds with guardrails and human exceptionsx.com
- Andrej Karpathy on LLM Knowledge Bases - compiling personal wikis with LLMs and Obsidianx.com
- Announcing Instructor 1.0.0 - structured outputs for LLMspython.useinstructor.com
- Automated Patch Diff Analysis using LLMsblog.syss.com
- BitNet - inference framework for 1-bit LLMsgithub.com
- Braintrust AI proxy: fostering a more open ecosystembraintrustdata.com
- Chintan Turakhia on deleting your IDE and building only through agentsx.com
- Choosing the Right AI Agent Memory Strategy: A Decision-Tree Approachmachinelearningmastery.com
- Claude Can Sometimes Prove It - Galois on AI and formal verificationgalois.com
- Claude Code + NotebookLM + Obsidian: The Research Stack Nobody's Usingartemxtech.substack.com
- Claude Code is running bash commands on your infrastructure — here's how to watch itsumologic.com
- ClaudeDevs on Claude Code's new Concise output stylex.com
- Coding with LLMs in the summer of 2025 - an updateantirez.com
- Converting a typewriter into a Claude terminalbenbyfax.substack.com
- critique - LLM creator-critic iterative content generation CLIgithub.com
- Cursor - Git at any scalecursor.com
- CyberDeck - portable offline knowledge, local LLM and mesh communication platformgithub.com
- Don't sleep on email as an LLM interfacehaihai.ai
- DoorDash AI Research on delegating engineering work to cloud-based agentsx.com
- EM-LLM - human-inspired episodic memory for infinite context LLMsgithub.com
- Eric Hu on qmd for Obsidian and Claude Codex.com
- Everything I Learned Training Frontier Small Models - Maxime Labonne, Liquid AIyoutube.com
- exo - run frontier AI locally across your everyday devicesgithub.com
- Extracting Hacker News Book Recommendations with the ChatGPT APIblog.reyem.dev
- FleetingBits on having Claude turn codebases into interactive visual diagramsx.com
- Georgi Gerganov on private local inference over Tailscale with Gemma 4 on Mac Studiox.com
- Grove: Distributed ML Training Over AirDropswarnimjain.com
- Gustavo Cid on using instructor for structured LLM outputsx.com
- How Anthropic enables self-service data analytics with Claudeclaude.com
- How many devs can you fit on a GPU? Self-hosting the model behind your coding agentaistack.imec-int.com
- How to get ChatGPT to stop apologizinggenai.stackexchange.com
- Human-inspired Episodic Memory for Infinite Context LLMs - EM-LLMopenreview.net
- Humanising LLM Outputs is Dumbkuber.studio
- hypgrep - full text search for Parquet datasetsgithub.com
- I benchmarked caveman against two words - Claude Code compression plugin vs 'be brief'maxtaylor.me
- image-blaster - image-to-3D-world skillset for Claudegithub.com
- Importance of context management in AI NPCswalterfreedom.com
- Infinite Mac Construction Set - embeddable classic Mac emulators driven by computer-use modelsblog.persistent.info
- Infrastructure patterns for agentic applicationsrender.com
- Introducing Durable Functions in PostgreSQL - durable execution and embedding pipelines in Postgrestechcommunity.microsoft.com
- Is ChatGPT an LLM - Understanding the Difference Between Agents and Modelsvincirufus.com
- Is this sustainable? A principal engineer on AI and the jobjamiehurst.co.uk
- Jaiqu - AI agent that reformats any JSON into any schemagithub.com
- Julien Chaumond on running Gemma 4 26B locally with llama.cpp and llama-serverx.com
- Kimi K3 - How to Run Locally - Unsloth Documentationunsloth.ai
- Kyle Corbitt: Codex, File My Taxes, Make No Mistakes - using a coding agent to prepare a tax returnx.com
- Kyunghyun Cho on why his agent doesn't follow instructions closely, via Karpathyx.com
- Lindy on migrating from Claude to DeepSeekx.com
- LiteLLM - open-source AI gateway and LLM proxylitellm.ai
- LiteLLM AI Gateway - LLM proxy for 100+ modelsdocs.litellm.ai
- Llama - macOS menu bar app for running local LLMsgithub.com
- llama farm - free group chat with crowd-sourced LLM responses, Convex demolabs.convex.dev
- llamafile is the new best way to run an LLM on your own computersimonwillison.net
- LLM Pricing Calculator - Compare Per-Token Prices Across Modelsllm-prices.com
- LLM Prose Tells - a catalog of patterns in LLM-generated prosegit.eeqj.de
- LLMs reward expertiseseangoedecke.com
- LM Link - access local LLMs across your deviceslmstudio.ai
- marimo - AI-native reactive Python notebookmarimo.io
- markitdown - convert files and Office documents to Markdown for LLMsgithub.com
- Matthew Carrigan on a $6,000 hardware setup to run full DeepSeek-R1 locally at Q8x.com
- Mayo Clinic's secret weapon against AI hallucinations - Reverse RAG in actionventurebeat.com
- Mesh-LLM - Distributed LLM inference across pooled GPUs for agents and chatgithub.com
- microgpt-c - zero-dependency C99 GPT-2 engine for edge AIgithub.com
- microsoft/aici - AI Controller Interface, prompts as Wasm programs that constrain LLM outputgithub.com
- Mirage Persistent Kernel - compiling LLMs into a megakernelgithub.com
- NERD - the story of an LLM-native programming languagenerd-lang.org
- Nick Frichette on running shell commands before Claude skills executex.com
- NotebookLM skill for Claude Code from personal-os-skillsgithub.com
- ODIN - Obsidian Driven Information Network, LLM-powered knowledge graph plugingithub.com
- Ollama - OpenAI Chat Completions API compatibility for local modelsollama.ai
- Ollama - run open models locallyollama.ai
- Ollama adds tool calling support for Llama 3.1 and other modelsollama.com
- On-Call Is Now Theatreboristane.com
- One Developer, Two Dozen Agents, Zero Alignmentmaggieappleton.com
- Open WebUI Desktop - native app for running local or remote LLMsgithub.com
- open-rl - self-hosted API for RL fine-tuning infrastructuregithub.com
- Open-sourcing sysgrok - An AI assistant for analyzing, understanding, and optimizing systemselastic.co
- opendataloader-pdf - PDF parser for AI-ready datagithub.com
- OpenEvolve - An Open Source Implementation of Google DeepMind's AlphaEvolvehuggingface.co
- Pankaj reverse-engineered WHOOP with AI to correlate stress spikes with coworkersx.com
- Pinokio - 1-click launcher for open-source AI appspinokio.computer
- PowerInfer - fast LLM serving on a consumer-grade GPUgithub.com
- Rapid-MLX - Fast local AI inference engine for Apple Silicongithub.com
- Rohan Paul on how top YC AI startups prompt LLMs: long prompts, XML tags, meta-prompts, evalsx.com
- Running Hermes Agent on MicroK8s and Leveraging K8s CronJobsmedium.com
- Running local models is good nowvickiboykis.com
- Self Improving Text2Sql Agent with Dynamic Context and Continuous Learningashpreetbedi.com
- Separating code reasoning and editingaider.chat
- Simon Willison: Building files-to-prompt entirely using Claude 3 Opussimonwillison.net
- Software engineering at the tipping point - Google for Developersyoutube.com
- Spec-driven development with AI: Get started with a new open source toolkitgithub.blog
- Specsmaxxing - writing specs in YAML for AI-driven developmentacai.sh
- Stop Calling It Memory: The Problem with Every AI + Obsidian Tutoriallimitededitionjonathan.substack.com
- Structured Output with LangChain and Llamafileblog.brakmic.com
- Tailwind CSS docs PR: add llms.txt endpoint for LLM-optimized documentationgithub.com
- Telegram/Discord is my IDE - running Claude Code and Codex through OpenClawsolmaz.io
- The Agentic Awakening - An AI-Native Engineering Playbooktheagenticawakening.com
- The Billion-Token Tender: Why RAG Isn't Fading, It's Gearing Uptenderstrike.com
- The New Calculus of AI-based Codingblog.joemag.dev
- The Software Development Lifecycle Is Deadboristane.com
- Tokasaurus: An LLM Inference Engine for High-Throughput Workloadsscalingintelligence.stanford.edu
- Tokenomics: Quantifying Where Tokens Are Used in Agentic Software Engineeringarxiv.org
- tropes.md - a single file of AI writing tropes to add to your system prompttropes.fyi
- Turn one giant AI-generated pull request to a reviewable stackgithub.blog
- Using LLM-as-a-Judge for Evaluation: A Complete Guidehamel.dev
- Vercel AI Playground - compare top AI models side-by-sideplay.vercel.ai
- Vibe Coding - David Bau on delegating complexity to coding agentsdavidbau.com
- Vibe Coding a $20k/year Enterprise Logistics Platformtrmnl.com
- Vibe Coding vs Realitycendyne.dev
- Vox on maintaining an OpenClaw gateway with a scheduled Codex automation agentx.com
- WARP - stream frontier LLM weights from NVMe to run beyond RAMgithub.com
- We built an exceedingly polite AI dog that answers questions about your APIsakitasoftware.com
- We Might All Be AI Engineers Nowyasint.dev
- Why RDF Is the Natural Knowledge Layer for AI Systemsbryon.io
- Wikiwise - local-first markdown wiki for Mac with a built-in AI agentwiki-wise.com
- Wild AI-related reliability incidents are comingsurfingcomplexity.blog
- wishful-search - natural language search for JSON arrays using LLMsgithub.com
- Your New Job is Integrating Codeahal.ca
- zvec - lightweight in-process vector database for RAG and LLM memorygithub.com
Tutorials and learning 111
- How to securely build product features using AI APIstldrsec.com
- Applied LLMs - What We've Learned From A Year of Building withapplied-llms.org
- The Developer's Playbook for Large Language Model Securitylearning.oreilly.com
- The Novice's LLM Training Guiderentry.org
- jedi4ever/learning-llms-and-genai-for-dev-sec-opsgithub.com
- Introduction to Agentskaggle.com
- LangChain: Chat with Your Datadeeplearning.ai
- What's Really Going On in Machine Learning? Some Minimal Modelswritings.stephenwolfram.com
- Papers with Code - The latest in Machine Learningpaperswithcode.com
- Frequently Asked Questions (And Answers) About AI Evals – Hamelhamel.dev
- Here's how I use LLMs to help me write codesimonwillison.net
- How I Use AI: Early 2025benjamincongdon.me
- Optimizing Jupyter Notebooks for LLMsalexmolas.com
- Not with a Bug, But with a Sticker: Attacks on Machine Learningamazon.com
- Large Language Models in Cybersecuritylink.springer.com
- On the future of language models — LessWronglesswrong.com
- Capturing the Flag with GPT-4micahflee.com
- LangChain Mastery in 2025 - Full 5 Hour Courseyoutu.be
- 2025 in LLMs so far, illustrated by Pelicans on Bicycles — Simonyoutu.be
- How to Read an "AI" Press Release — Sonja Drimmersonjadrimmer.com
- Best Practices for Securing Generative AI with SASEblog.cloudflare.com
- Wikipedia:Signs of AI writingen.wikipedia.org
- 0xor0ne awesome-list - cybersecurity oriented awesome listgithub.com
- A History of Large Language Modelsgregorygundersen.com
- AI Agents for Beginners - Microsoft course with 18 lessonsgithub.com
- AI/ML Pentesting Roadmap for Beginners - free resources for security and prompt injectiongithub.com
- API testing - PortSwigger Web Security Academyportswigger.net
- AppSecEngineer - application security training platform with AI and LLM security coursesappsecengineer.com
- Architecting Fortresses: Advanced Security Measures for ReactJS Apps - Jim Manico, NDCyoutube.com
- awesome-ai-security - curated AI security resourcesgithub.com
- awesome-malware-development - curated malware dev, RE and defensive research resourcesgithub.com
- Black Hat USA 2023 slides collectiongithub.com
- Black Hat USA 2026 slides - onhexgroup Conferencesgithub.com
- BSides Twin Cities - inclusive security conference in Minneapolisbsidestc.org
- Bug Bounty Funshop - workshop slidesdocs.google.com
- Bug Bounty Reports Explained YouTube channelyoutube.com
- Building an AI Server on a Budgetinformationga.in
- ChatGPT for ITacademy.openai.com
- Cloud Guardrails - open-source collection of cloud infrastructure security best practicescloudguardrails.com
- CodeMachine Training - Windows kernel, malware and exploitation coursescodemachine.com
- CryptoHack - a free platform for learning cryptography through challengescryptohack.org
- CS 253 Web Security - Stanfordyoutube.com
- CSP Developer Field Guide - a concise book on Content-Security-Policyfoundeo.gumroad.com
- Cyber Security Roadmap - roadmap.shroadmap.sh
- CyberSecPods - curated directory of cybersecurity podcastscybersecpods.com
- Cycode ASPM Nation videos - YouTube channelyoutube.com
- DEF CON 31 - Look Ma I'm the CEO - Real Time Video and Audio Deep Fakeyoutube.com
- DEF CON Conference talks YouTube channelyoutube.com
- Developing Secure Software - LFD121 - Linux Foundationtraining.linuxfoundation.org
- Deviant's DEF CON Advice - DeviantOllamyoutube.com
- DevSecOps for Beginners - Latioyoutube.com
- Digital Defense - personal security checklistdigital-defense.io
- eBPF: Unlocking the Kernel documentaryyoutube.com
- Experimenting with local LLMs on macOSblog.6nok.org
- Forward Deployed Engineer for AI Systemseducative.io
- Google Bug Hunters - Google's bug bounty communitybughunters.google.com
- HackingHub - ethical web application hacking trainingctfchallenge.com
- Hacks, Leaks, and Revelations: The Art of Analyzing Hacked and Leaked Data by Micah Leehacksandleaks.com
- How does Groq LPU work - with Head of Silicon Igor Arsovski, Aleksa Gordićyoutube.com
- How to become a smart contract auditorcmichel.io
- How to Run Mistral 7B on an M1 Mac With Ollamawandb.ai
- Ilya 30u30 - Ilya Sutskever's 30 foundational deep learning papers reading listarc.net
- Information Theory, Inference, and Learning Algorithms - David MacKayinference.org.uk
- Injectopi - tutorials on Windows code injection techniquesgithub.com
- Interview Study Notes for Security Engineering - gracenolangithub.com
- Kostas on affordable DFIR, threat hunting and malware analysis training providersx.com
- Mastra 101: AI Agent Builder Coursemastra.ai
- Math for Security - From Graphs and Geometry to Spatial Analysis, No Starch Pressnostarch.com
- MITRE ATT&CK Adventure - choose-your-own-adventure game through the ATT&CK kill chainmitre.cybersecurityalphabetsoup.com
- OpenSecurityTraining - free security training classesopensecuritytraining.info
- OpenSecurityTraining2 - free courses on x86 architecture, reverse engineering and debuggingp.ost2.fyi
- OpenSecurityTraining2 - free deep-dive computer security trainingost2.fyi
- OverTheWire Wargames - hands-on security challengesoverthewire.org
- Passkey Path - A choose-your-own-adventure guide to passkeystechbrandon.github.io
- Pentester Academypentesteracademy.com
- PentesterLab PRO - advanced web hacking labs and security code review trainingpentesterlab.com
- Practical Mobile Application Exploitation Course - 8kSec Academyacademy.8ksec.io
- Private, local LLMs with Ollama and OpenWebUI for macOSkoller.ninja
- r2con 2024 - radare2 conference talks and workshopsradare.org
- Real or AI Quiz: Can You Tell the Difference?britannicaeducation.com
- Red Team Ops course - Zero-Point Securitytraining.zeropointsecurity.co.uk
- SecDim - learn AppSec and DevSecOps via git-based challengesplay.secdim.com
- SecretCon - Minnesota's Hacker and Cybersecurity Conferencesecretcon.com
- Secure AI/ML-Driven Software Development LFEL1012 - Linux Foundationtraining.linuxfoundation.org
- Security Engineering - Ross Anderson's book, free onlinecl.cam.ac.uk
- Sektor7 Institute - offensive security and malware development traininginstitute.sektor7.net
- Semgrep Academy - free application security and secure coding coursesacademy.semgrep.dev
- SQL Injection Master Course - Lecture 1 - Course Introductionyoutube.com
- TCM Security Academy - hands-on cybersecurity coursesacademy.tcm-sec.com
- The Art of Recon: Strategies for Modern Asset Discovery - Assetnoteyoutube.com
- The Developer's Playbook for Large Language Model Security - Steve Wilson, O'Reillyoreilly.com
- The Homelab Almanac - Taggart Institute guide to building security homelabstaggartinstitute.org
- The Lost Reading Items - reconstructing Ilya Sutskever's AI reading listtensorlabbet.com
- The New SDLC With Vibe Coding - Day 1drive.google.com
- The New SDLC With Vibe Coding - Day 1 slidesdrive.google.com
- The OSI Deprogrammer - Robert Graham's book re-conceptualizing cyberspacedocs.google.com
- The Security Champion Program Success Guidesecuritychampionsuccessguide.org
- The Security Researcher's Guide to Mathematicsmuellerberndt.medium.com
- Threat Hunting Training Course - Active Countermeasuresactivecountermeasures.com
- Threat Modeling AI Systems - 2-Day Intensive Course by Shostack + Associatescourses.shostack.org
- Threat Modeling Connect - YouTube channelyoutube.com
- TryHackMe - gamified hands-on cyber security training platformtryhackme.com
- UChicago Large Language Models Course - interpretability, alignment and agentsuchicago-llm-course.github.io
- un-prompted 2026 conference talks - YouTube playlistyoutube.com
- Understanding Windows x64 Assemblysonictk.github.io
- Unprompted 2026 AI security conference slides - Google Drive folderdrive.google.com
- Using LLMs as a Security Toolyoutube.com
- Web AppSec Interview Questions - Tib3riustib3rius.com
- Web LLM attacks - PortSwigger Web Security Academyportswigger.net
- You Do Not Understand Kerberos Delegation - Introduction - ATTL4Syoutube.com
- Zero2Automated - advanced malware analysis and reverse engineering coursecourses.zero2auto.com
Security news and research 748
- "No way to prevent this" say users of only language where this regularly happens - CVE-2026-41992xeiaso.net
- 1-Click GitHub Token Stealing via a VSCode Bugblog.ammaraskar.com
- 10,501 Radios in Seven Days: What a $69 Badge Heard at Summer Campjerrygamblin.com
- 20% of Zero is Zero - CrankySec on the cybersecurity industrycrankysec.com
- A Fresh Look at User Enumeration in Microsoft Teamssecuresystems.de
- A Glossary of Blind SSRF Chainsblog.assetnote.io
- A Journey From sudo iptables To Local Privilege Escalationshielder.com
- A method to assess 'forgivable' vs 'unforgivable' vulnerabilitiesncsc.gov.uk
- A Modern Approach to Preventing CSRF in Goalexedwards.net
- A Recipe for Scaling Security - Google Bug Huntersbughunters.google.com
- A Survey of Worldwide Censorship Techniques - RFC 9505rfc-editor.org
- A Touch of Pwn - Part I: bypassing Windows Hello fingerprint authenticationblackwinghq.com
- Absolute AppSec Ep. 330 - Vulnerability Jail with Jeevan Singhyoutube.com
- Abusing Amazon VPC CNI plugin for Kuberneteselttam.com
- Accenture to acquire runZero and NetRise to strengthen critical infrastructure defenserunzero.com
- Active Directory - Domain Privilege Escalation0xstarlight.github.io
- Active Directory - Introduction - Red Teaming Series by 0xStarlight0xstarlight.github.io
- Active Directory Lateral Movement - Red Teaming Series0xstarlight.github.io
- Active Directory SID Limit Exploit - Lockout Without Admin Accesspentera.io
- ADCS Attack Paths in BloodHound - Part 1 - SpecterOpsposts.specterops.io
- Adding DCSync permissions from Linuxn00py.io
- ADT says customer data stolen in cyber intrusiontherecord.media
- AFDP 3-12 Cyberspace Operationsdoctrine.af.mil
- Alabama Man Sentenced to 14 Months in Connection with SEC X Hack that Spiked Bitcoin Pricesjustice.gov
- ALBeast - AWS ALB authentication bypass vulnerabilitymiggo.io
- Alex on decrypting Microsoft Copilot's App-Bound Encryption keys and tokensx.com
- Alexandre Borges releases CFPsec 1.4, a CLI listing security conference CFPsx.com
- All of Winona Police Department's Flock cameras cut down and stolennews.ycombinator.com
- Allianz Life confirms data breach impacts majority of 1.4 million customersbleepingcomputer.com
- AlphV files an SEC complaint against MeridianLink for not disclosing a breachdatabreaches.net
- altdns - subdomain discovery through alterations and permutationsgithub.com
- Amazon Senior Security Engineer Indicted in $9M Crypto Heisthackingbutlegal.com
- An August reading list about online security and 2023 attacks landscapeblog.cloudflare.com
- An Exercise in Dynamic Analysis - Windows Defender Exploit Guard Export Address Filteringwindows-internals.com
- An in-depth guide to subfinder: beginner to advancedblog.projectdiscovery.io
- Andrew Chu on a fake web3 recruiter scam with AI-generated identities that drained his walletx.com
- Announcing Really - Resourcely's policy language for infrastructure guardrailsresourcely.io
- Anthony Peyton on how sysadmins get breached via malicious download adsx.com
- Anthropological Map of cybersecurity history - Where Warlocks Stay Up Latewherewarlocksstayuplate.com
- anti-crime-ecosystem-research - security posture of LPR and gunshot detection systems, 51 findings and 22 CVEsgithub.com
- Anti-Phishing Training Still Does Not Work: A Large-Scale Reproduction Grounded in the NIST Phish Scalearxiv.org
- Antide's Lawdustri.org
- Anyone Can Push Updates to the DOGE.gov Website404media.co
- API testing firm APIsec exposed customer data during security lapsetechcrunch.com
- AppSec/ProdSec's reality gap: why theory doesn't match practiceventureinsecurity.net
- Arctic Wolf acquires Cylance from BlackBerry for $160 millioncyberscoop.com
- Assessing the Wiz-Google dealfranklyspeaking.substack.com
- Attack of The Extensions - sideloaded Chromium extensions for persistent C2 and detection with Sysmonspecterops.io
- Attacking EDR Part 5: Analyzing and Breaking Defender for Endpoint's Cloud Communicationlabs.infoguard.ch
- audicia - Kubernetes operator generating least-privilege RBAC from audit logsgithub.com
- AutoFunkt - automating serverless C2 redirectorsfortynorthsecurity.com
- Avoid building a security treadmillmacchaffee.com
- Awesome Bugbounty Writeups - curated list of bug bounty writeups by bug typegithub.com
- Awesome HTTP Request Smuggling - curated attacks and tools listgithub.com
- Awesome Search Engines for Cybersecurity Researchersgithub.com
- AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operationsysdig.com
- Azaka on the I-S00N leak of internal Chinese government hacking contractor documents on GitHubx.com
- Azox on exploiting ResetNightmare CVE-2026-27912 Kerberos flaw with NetExecx.com
- Azure AD authentication comes to Ubuntu Desktop 23.04ubuntu.com
- Azure Fabric Backdoor With A Twistnccgroup.com
- Backstage access: an unauthenticated SQL injection in Front Gate Ticketsian.sh
- Baked Alaska - Four Years of the Same Exploit at Alaska Air Groupnoseyparker.pages.dev
- Ben Badejo on how the pager attack gave Israel a live social graph of Hezbollah's networkx.com
- Beware the false false-positive: how to distinguish HTTP pipelining from request smugglingportswigger.net
- Beyond the Hook: A Technical Deep Dive into Modern Phishing Methodologiesblog.quarkslab.com
- BeyondTrust Discovers Breach of Okta Support Unitbeyondtrust.com
- BingBang: Hillai Ben-Sasson hacks Bing CMS via Azure AD misconfig to take over Office 365 accountsx.com
- BitLocker Network Unlocklearn.microsoft.com
- Black Hat USA 2023 Briefings - Analyzing the Security of Low Earth Orbit Satellitesblackhat.com
- blackorbird on weaponizing Windows Defender's BTR.sys driver as a kernel operation primitivex.com
- Bob Rudis - The Great American Router That Doesn't Exist: the US foreign router banlinkedin.com
- Breaking Bitlocker - Bypassing the Windows Disk Encryptionyoutube.com
- Breaking down Microsoft's pivot to placing cybersecurity as a top prioritydoublepulsar.com
- Brett Callow shares ALPHV ransomware statement on the MGM Resorts attackx.com
- Brett Shavers on a forensic case where a hidden AirTag was mailed to track a DV victimx.com
- Brian Pak on the Copy Fail CVE-2026-31431 disclosure process and Linux community responsex.com
- Bridgewater remediates Log4Shell with Wiz - conversation with CTO Igor Tsyganskiywiz.io
- Buffer Overflow Vulnerability in curl WebSocket handlinghackerone.com
- Bug Bounty Daily - curated reading list for bug bounty huntersbugbountydaily.com
- Bug Bytes #192 - Post-recon blues, a lesson in Rust and fuzzing open sourceblog.intigriti.com
- bug.directory - searchable vault of vuln research, exploit development and reverse engineering resourcesbug.directory
- Bugtraq is back - SecurityFocus mailing list revivallists.securityfocus.com
- Building a Scaled Application Security Programstatic.sched.com
- Building A Security Platform Engineering Teamkanenarraway.com
- Burning Data with Malicious Firewall Rules in Azure SQL Servervaronis.com
- Burp Suite Proxy History Subtractive Scopingwhiteoaksecurity.com
- Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hackingeclypsium.com
- Butting Heads with a Threat Actor on an Engagementlabs.jumpsec.com
- BYOVD and Looting LSASS in the Modern EDR Erag3tsyst3m.com
- Bypassing Enrollment Restrictions to Break BYOD Barriers in Intunetemp43487580.github.io
- Bypassing the AWS WAF Protection with an 8KB Bulletkloudle.com
- Bypassing WiFi Client Isolationpulsesecurity.co.nz
- Bypassing Windows Defender Application Control with Loki C2ibm.com
- Calif - Codex discovered an HTTP/2 Bomb remote DoS in nginx, Apache, IIS, Envoy, and Pingorax.com
- Can I Jailbreak? - iOS jailbreak availability by device and versioncanijailbreak.com
- CargoWise WebTracker - The Keys Were in the Cargoslcyber.io
- Carrot disclosure - a third vulnerability disclosure model beyond coordinated and full disclosuredustri.org
- Catching Credential Guard Off Guard - SpecterOpsspecterops.io
- Certighost - CVE-2026-54121 AD CS vulnerability allowing Domain Controller impersonationgist.github.com
- Chainguard raises $61 million series B round as enterprises move to fortify open source softwarechainguard.dev
- Chaining Three Bugs to Access All Your ServiceNow Dataassetnote.io
- Changes to the OSCP - OffSechelp.offsec.com
- ChatGPT Won't Let You Type Until Cloudflare Reads Your React State. I Decrypted the Program That Does Itbuchodi.com
- Check Point response to the BreachForum post on 30 March 2025support.checkpoint.com
- Checkmarx and Security Compass partner to integrate Checkmarx One with SD Elementscheckmarx.com
- China's DJI no longer blocks drone flights over airports and military baseshntrbrk.com
- China-nexus cyber threat groups rapidly exploit React2Shell vulnerability CVE-2025-55182aws.amazon.com
- Chrome Root Program - Moving Forward, Togetherchromium.org
- CISA Advisory AA23-208A - Preventing Web Application Access Control Abusecisa.gov
- CISA Mobile Communications Best Practice Guidancecisa.gov
- CISA sees leadership shakeup after infrastructure security chief moves to ONCDnextgov.com
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCscisa.gov
- Cisco acquires Splunkcisco.com
- Cisco Completes Acquisition of Cloud Native Networking and Security Leader Isovalentisovalent.com
- Cisco to Acquire Splunk to Help Make Organizations More Secure and Resilient in an AI-Powered Worldinvestor.cisco.com
- Citrix Bleed: Leaking Session Tokens with CVE-2023-4966assetnote.io
- Cleartext Credential Recovery in ServiceNowspecterops.io
- Cloud engineer gets 2 years for wiping ex-employer's code reposbleepingcomputer.com
- Cloudflare incident on February 6, 2025 - R2 outage post-mortemblog.cloudflare.com
- Cloudflare Thanksgiving 2023 security incidentblog.cloudflare.com
- CloudSecTools - Open Source Cloud Security Tools directorycloudsectools.com
- Coastline Cyber's Security Checklist - organizational cybersecurity posture checklistnullenc0de.github.io
- Code audit for censorship circumvention tools completed by Cure53blog.torproject.org
- Code Resilience in the Age of ASPMcycode.com
- Codrut Andrei on why most Product Security programs manage queues instead of reducing risklinkedin.com
- Coinbase engineering postmortem on multi-hour outage and disaster recovery after AWS us-east-1 thermal eventx.com
- Coinbase says customers' personal information stolen in data breach - TechCrunchtechcrunch.com
- Common Sense Guide to Mitigating Insider Threats, Fifth Edition - CERT Insider Threat Centerresources.sei.cmu.edu
- Competing in Endpoint Security: A Guide for Startupszeltser.com
- Compression, Correction, Confidentiality, and Comprehension: A Modern Look at Telegraph Codebookscs.columbia.edu
- Compromised Microsoft Key: More Impactful Than We Thoughtwiz.io
- Compromising Honda's eCommerce platform through a vulnerable password reset APIeaton-works.com
- Compromising the Secure Boot Process: leaked platform key breaks Secure Boot on 200+ device modelsschneier.com
- Conferences - BlackHat, OffensiveCon, REcon and Hexacon presentation slides archivegithub.com
- Control Reliability Engineering - Applying SRE Principles to Cybersecurity Controlsphilvenables.com
- Coordinated cyberattack disrupts water utilities in 30+ Minnesota communitiesstatescoop.com
- Cops Used Flock to Track a Man Across State Lines to Create Pretext to Search His Car for Weed404media.co
- Copy Fail - 732 Bytes to Root on Every Major Linux Distributionxint.io
- CopyEscape - Taking Over Docker Hosts with docker cpimperva.com
- copyfail-go - Go implementation of CVE-2026-31431 Linux LPEgithub.com
- CosmosEscape: Taking Over Every Database in Azure Cosmos DBwiz.io
- COTSI - SMS verification statistics by platformcotsi.org
- Could your choice of metrics be harming your SOC? - NCSCncsc.gov.uk
- Cracked Cobalt Strike - Microsoft and Fortra takedown noticenoticeofpleadings.com
- Cracking Wecon HMI firmware: the decryptor was the DLL all alongafflicted.sh
- Crash Override Raises $28 Million Seed Round for Engineering Relationship Management Platformbusinesswire.com
- Credentials Leaking with Subdomain Takeovertrufflesecurity.com
- Critical Security Vulnerability in React Server Componentsreact.dev
- Critical Thinking Bug Bounty Podcast on 0xteknogeek's take that bounties should be going downx.com
- Critical Vulnerabilities in Jenkins Server Lead to RCEblog.aquasec.com
- CRLF-Powered Desync Attacks: Beheading HTTP Streamsportswigger.net
- Cross-Site Leaks Attacks - CyberCXblog.cybercx.co.nz
- Cross-Site WebSocket Hijacking Exploitation in 2025blog.includesecurity.com
- CrowdStrike 2023 Global Threat Reportgo.crowdstrike.com
- CrowdStrike Outage Timeline, Analysis, and Impactbitsight.com
- CrowdStrike to Acquire Adaptive Shield to Deliver Integrated SaaS Security Posture Managementcrowdstrike.com
- crt.sh - Certificate Transparency log search toolcrt.sh?q=%25.domain.com%5d
- Crypto, FIDO and Security Tokens - hardware token comparison spreadsheetdocs.google.com
- CRYSTALRAY: Inside the Operations of a Rising Threat Actor Exploiting OSS Toolssysdig.com
- CS:GO: From Zero to 0-day - three RCE vulnerabilities in the game clientneodyme.io
- CSRB Review of the Summer 2023 Microsoft Exchange Online Intrusioncisa.gov
- Cure53 - security assessments and public pentest reportscure53.de
- curl summer of bliss - curl pauses vulnerability reports for July 2026daniel.haxx.se
- Customer Chronicles: Implementing Security by Designyoutube.com
- CVE Distro Tracker - cross-distro Linux CVE fix statusdistro.cloudcurio.us?cve=cve-2026-43284
- CVE Hunting at Scale - WordPress Plugin Vulnerability Huntingprojectblack.io
- CVE-2023-23415 - Microsoft Security Update Guidemsrc.microsoft.com
- CVE-2023-38545 curl SOCKS5 heap overflow reproduction gistgist.github.com
- CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection in GlobalProtectsecurity.paloaltonetworks.com
- CVE-2024-3400: Palo Alto PAN-OS GlobalProtect command injectionattackerkb.com
- CVE-2024-47081: Netrc credential leak in Python requests libraryseclists.org
- CVE-2024-4956 - Nexus Repository 3 unauthenticated path traversalgithub.com
- CVE-2025-29927 Next.js middleware auth bypass - nuclei templategithub.com
- CVE-2025-29927: Next.js Middleware Authorization Bypass - Technical Analysisprojectdiscovery.io
- CVE-2025-55182 - RCE PoC for React Server Functionsgithub.com
- CVE-2025-55182 research discussiongithub.com
- CVE-2026-10520: Ivanti Sentry Unauthenticated OS Command Injectionhellorecon.com
- CVE-2026-31431: Copy Fail - Linux local privilege escalation analysisretr0.zip
- CVE-2026-33557: Apache Kafka missing JWT token validation in OAUTHBEARER authenticationopenwall.com
- CVE-2026-34197 - ActiveMQ RCE via Jolokia APIhorizon3.ai
- CVE-2026-48931 Shouldn't Have Been a CVE - HTTP Response Queue Poisoning in Node.jsadventures.nodeland.dev
- CVE-2026-69836 - Microsoft Entra ID Remote Code Execution Vulnerabilitymsrc.microsoft.com
- CVE-2026-82329: JFrog Artifactory unauthenticated authentication bypass - verified reproductionpruva.dev
- cve-rs - memory vulnerabilities written in 100% safe Rustgithub.com
- Cybercrime: A Multifaceted National Security Threat - Google Threat Intelligencecloud.google.com
- Cybersecurity is deadcrankysec.com
- Cybersecurity professionals getting more work and less paytheregister.com
- Dark Web Informer on Handala Hack leaking FBI Director Kash Patel's personal photos and documentsx.com
- Dark Web Informer: Allianz allegedly hit by leak of ~500 internal Docker images with credentials and keysx.com
- Dark Web Informer: Kash Patel apparel site serving ClickFix-style malware lure with macOS infostealerx.com
- DARKNAVY gets a root shell on a Starlink square-dish terminal via hardware attackx.com
- Dear Linux Kernel CNA, What Have You Doneamanitasecurity.com
- Declassified NSA Newslettersschneier.com
- Decrypting Full Disk Encryption with Dissectblog.fox-it.com
- DEF CON 32 - Gotta Cache 'em all: bending the rules of web cache exploitation - Martin Doyhenardyoutube.com
- DefectDojo Raises $7 Million in Funding to Accelerate AppSec Innovationbusinesswire.com
- Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash - CVE-2026-40639blog.amberwolf.com
- Des Moines-based Intoxalock cyberattack disrupts deviceskcci.com
- Designer Vulnerabilities - a thorough list of named vulnerabilitiesshellsharks.com
- Desktop password sync - Platform SSO for macOS with Oktaokta.com
- Developer sabotaged ex-employer IT systems with kill switchtheregister.com
- Developers refuse to upgrade their vulnerable dependencies - r/cybersecurityreddit.com
- Digital Forensics: Attacking SAM and Extracting Hashes With 7zhackers-arise.com
- Dirty Frag - Universal Linux LPE - oss-secseclists.org
- Disclose.tv: Trump admin to enlist private firms for offensive cyberattacks on foreign adversariesx.com
- Discord says hackers stole government IDs of 70,000 usersarstechnica.com
- dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025huntress.com
- Do excellent vulnerability reportsdaniel.haxx.se
- DOJ indictment: Zhenxing Wang and co-defendants in North Korean remote IT worker laptop-farm schemejustice.gov
- Dominic Alvieri on Ernst & Young data leaked by ShinyHuntersx.com
- Dominic Alvieri on Scattered Lapsus Shiny Hunters paying Telegram users to harass breached execsx.com
- Dota 2 - Between the Lanes: Denying Denial of Servicesteamcommunity.com
- DoubleClickjacking - a new UI redressing attack techniquepaulosyibelo.com
- Dress Code - CSP bypasses via third-party domains and CSP data from the top 1M sitessensepost.com
- DUALITY - Advanced Red Team Persistence Through Self-Reinfecting DLL Backdoorsaon.com
- Dumping NTHashes from Microsoft Entra IDsecureworks.com
- eBPF Summit 2024 - virtual conference for the eBPF ecosystemebpf.io
- ED 26-01: Mitigate Vulnerabilities in F5 Devicescisa.gov
- EDR Bypass with LoLBinsbishopfox.com
- Effective Techniques for AWS Ransomwarechrisfarris.com
- EMERALDWHALE: 15k Cloud Credentials Stolen in Operation Targeting Exposed Git Config Filessysdig.com
- Emilien Socchi on a web-app assessment leading to full AKS cluster and Azure subscription takeoverx.com
- Employee monitoring app WorkComposer leaks 21 million screenshots in real timecybernews.com
- encodedguy: Build Your Own Mini Attack Surface Management Systemx.com
- Enforcing Device Trust on Code Changesfigma.com
- Enso Security joins Snyk, enabling security leaders to scale their AppSec program with ASPMenso.security
- Escalating from On-prem to Entra through MITM Attackssecuritylog.sva.de
- Escalating Privileges with Azure Function Appsnetspi.com
- Europol Cyber Bits - Hackers deployed to facilitate drugs smuggling at Antwerp porteuropol.europa.eu
- Examining the Security Posture of an Anti-Crime Ecosystem - GainSec whitepapergithub.com
- EXEfromCER - deliver a binary payload via an X.509 TLS certificategithub.com
- Expanding Microsoft's Secure Future Initiativemicrosoft.com
- Expel: An important update and apology on our PoisonSeed blogexpel.com
- Exploiting Azure IMDScyberdom.blog
- Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRFblog.doyensec.com
- Exploiting trust: Weaponizing permissive CORS configurationsoutpost24.com
- Exploiting Web Cache Poisoning: Advanced Exploitation Guideintigriti.com
- Exploits Were Never the Point - what CERT-UA reports and red teamers reveal about cyber operationsarunninghacker.substack.com
- exploits.club Weekly Newsletter 09blog.exploits.club
- Exploring the GitHub Advisory Database for fun and 'no' profitblog.aquia.us
- Exploring the SameSite cookie attribute for preventing CSRFsimonwillison.net
- EZ on securing Intune admins - PAWs, FIDO2 and managed-device conditional accessx.com
- F5 Contributes to KEV Confusionjericho.blog
- F5 Security Incident K000154696 - nation-state breach of BIG-IP source code and vulnerability datamy.f5.com
- FBI Denver warns against public USB charging stations that can install malware on devicesx.com
- FCC drone import ban: US embargoes all new foreign-made consumer drones including DJIpopularmechanics.com
- FCC Updates Covered List to Include Foreign-Made Consumer Routersfcc.gov
- Federal cyber experts called Microsoft's cloud a "pile of shit" and approved it anywayarstechnica.com
- Filling in the Gaps: HTTPS/TLS Certificatesblog.bityard.net
- Finding DOM Polyglot XSS in PayPal the Easy Wayportswigger.net
- Finding SSRFs in Azure DevOpsbinarysecurity.no
- Flipper One - we need your helpblog.flipper.net
- Flipper Zero: Our Response to the Canadian Governmentblog.flipper.net
- Flock cameras sawed off and stolen in Winona, Minnesotanews8000.com
- Flock Safety 'flockbook' - How to Speak to City Councils About Public Safety Technologydocumentcloud.org
- Flock Safety Cybersecurity: How We Protect Customer and Community Dataflocksafety.com
- Flock Safety's Response to Security Research Findingsflocksafety.com
- Flock surveillance backlash mounts as fiendish Halloween plans circulatetheregister.com
- Florian Roth on Cobalt Strike's popularity prompting the CrowdStrike signature that crashed systemsx.com
- Florian Roth on Kimsuky tricking targets into running attacker PowerShell as adminx.com
- flowsint - graph-based OSINT investigation platformgithub.com
- Formalizing my Flock Safety Security Researchgainsec.com
- fortitool: cracking FortiOS firmware end to end, and a key nobody hadblog.n0p.me
- Fragnesia - CVE-2026-46300 Linux XFRM ESP-in-TCP local privilege escalation PoCgithub.com
- From a Misconfigured Grafana to 507 Private Meta Repos: A Bug Worth $157Ksectricity.com
- From Stolen Laptop to Inside the Company Network: TPM sniffing BitLocker bypassdolosgroup.io
- FTX First Interim Report of John J. Ray III on Control Failures at the FTX Exchangescourtlistener.com
- Future-Proofing Cloud Security Against Quantum Attacks: Risk, Transition, and Mitigation Strategiesarxiv.org
- fwd:cloudsec North America - cloud security conferencefwdcloudsec.org
- Gaming Engines: An Undetected Playground for Malware Loadersresearch.checkpoint.com
- GatewayToHeaven CVE-2025-13292 - cross-tenant vulnerability in Google Cloud Apigeex.com
- gdid-reversal - Windows Global Device Identifier reverse engineeringgithub.com
- Germán Fernández on someone 'patching' React2Shell CVE-2025-55182 servers and leaving warning notesx.com
- GhostLock - Lockout without encryption via SMB deny-share handlesghostlock.io
- Git-Rotate: leveraging GitHub Actions to bypass Microsoft Entra smart lockoutresearch.aurainfosec.io
- GitHub Enterprise repository properties, policies and rulesets - public previewgithub.blog
- GitHub Enterprise SAML Authentication Bypass - CVE-2024-4985 and CVE-2024-9487projectdiscovery.io
- GitHub investigating unauthorized access to its internal repositoriesx.com
- GitHub RCE Vulnerability - CVE-2026-3854 Breakdownwiz.io
- GitHub's Engineering Fundamentals program: How we deliver on availability, security, and accessibilitygithub.blog
- GitHub: We updated our RSA SSH host keygithub.blog
- Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilitiesdepthfirst.com
- Google introduces selfie video for sign-in to your Google Accountblog.google
- Google publishes exploit code threatening millions of Chromium usersarstechnica.com
- Google's Gradient backs YC alum Infisical to solve secret sprawltechcrunch.com
- GrayhatWarfare: organize searches and get notified of new resultsgrayhatwarfare.medium.com
- Grizzly Research alleges the Temu shopping app is hidden spyware and a US national security threatgrizzlyreports.com
- Grounded Flight - Device 2: Root Shell on Flock Safety's Falcon/Sparrow Automated License Plate Readergainsec.com
- grsecurity - copy.fail mitigation will not work for RHEL-derived distrosx.com
- Grzegorz Tworek on a fileless persistent LPE backdoor via sc.exe sdset scmanagerx.com
- GTPDOOR - A novel backdoor tailored for covert access over the roaming exchangedoubleagent.net
- H4x0r.DZ on HackerOne triage failure that led to ClickUp's April 27th data leakx.com
- Hacker Uncovers How to Turn Traffic Lights Green With Flipper Zerothedrive.com
- HackerOne and Semgrep partnership for vulnerability managementhackerone.com
- HackerOne IDOR report - delete other users' licenses and certifications via GraphQL IDhackerone.com
- Hackers Stole Access Tokens from Okta's Support Unit - Krebs on Securitykrebsonsecurity.com
- Hackers take control of Ecovacs robot vacuums in multiple US cities and abuse ownersabc.net.au
- Hacking Formula 1: Accessing Max Verstappen's passport and PII through FIA bugsian.sh
- Hacks worse than initially thought - a link list of breach disclosures that kept growingcircles.page
- Hacktivist deletes white supremacist websites live onstage during hacker conferencetechcrunch.com
- Handala Hack - Unveiling Group's Modus Operandi - Check Point Researchproofeditor.ai
- Handala Hack - Unveiling the Group's Modus Operandiresearch.checkpoint.com
- Hardware Hacking: From Zero to a Pre-Auth Stack Buffer Overflow on Amazon's Best-Selling Routerrotcee.github.io
- Hazy Hawk Hijacked .edu Subdomains at MIT, Harvard, Stanford and 30+ Universitiessh.consulting
- Here's the source code for the unofficial Signal app used by Trump officialsmicahflee.com
- Hey why can't you fix this one bug - why a simple security fix takes weeks at a large companymewy.pw
- Houston, We Have a Problem: Analyzing the Security of Low Earth Orbit Satellitesi.blackhat.com
- How a North Korean Fake IT Worker Tried to Infiltrate Usblog.knowbe4.com
- How an empty S3 bucket can make your AWS bill explodemedium.com
- How Cloudflare mitigated yet another Okta compromiseblog.cloudflare.com
- How Cybersecurity Behaviors Affect the Success of Darknet Drug Vendors: A Quantitative Analysisarxiv.org
- How Discord is Abused for Cybercrimeintel471.com
- How easy is it to steal $10,000 from a locked phone? - Veritasiumyoutube.com
- How I Accessed Microsoft's ServiceNow, Exposing All Microsoft Employee Emails and Chat Supportlink.medium.com
- How I got into Starbucks internal network using non-resolvable hostnamesargosdns.io
- How it works: The novel HTTP/2 'Rapid Reset' DDoS attackcloud.google.com
- How Many Days Has It Been Since a JWT alg:none Vulnerabilityhowmanydayssinceajwtalgnonevuln.com
- How Offensive Security Going Mainstream Changes Things - DefCampt.co
- How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runnersstepsecurity.io
- How to Achieve Enterprise-Grade Attack Surface Monitoring with Open Source Softwarehakluke.com
- How to extract artifacts from OpenAPI docs to help attack APIsdanaepp.com
- HTML - a mutating beast - Michal Bentkowski on mutation XSSdocs.google.com
- HTTP Security Headers Checklist: CSP, HSTS, XFO and Moredarkrelay.com
- HTTP/2 CONTINUATION Floodnowotarski.info
- HTTP/2 Rapid Reset Attack Impacting F5 NGINX Productsnginx.com
- httpmon - open-source terminal HTTP debugging MITM proxyhttpmon.dev
- HVCK Magazine - hacking zine back issueshvck-magazine.github.io
- Hyoketsu - Solving the Vendor Dependency Problem in REslcyber.io
- I foretold that Mac app notarization is security theaterlapcatsoftware.com
- I thought my VPS was hardened but it wasn't - r/selfhostedreddit.com
- I'm The Captain Now: Hijacking a global ocean supply chain networkeaton-works.com
- I-S00N leak removed from GitHub along with its mirrors - r/cybersecurityreddit.com
- IAM Vulnerable - Assessing the AWS IAM Privilege Escalation Assessment Toolsbishopfox.com
- IBM to Acquire HashiCorp for $6.4 Billion, Creating an End-to-End Hybrid Cloud Platformprnewswire.com
- ICANN Update: Launching RDAP; Sunsetting WHOISicann.org
- Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeoversemperis.com
- IETF Draft: Internet Protocol Version 8 - IPv8 with OAuth2-authorised elements and egress validationietf.org
- Incognito Market owner arrested for operating darknet narcotics marketplacejustice.gov
- Increased Risk of Wiper Attacks by the Handala Hack Groupunit42.paloaltonetworks.com
- InfraTrust Pulse July 2026: What Infrastructure to Patch Firstpulse.infra-trust.org
- Ingress NGINX Retirement: What You Need to Knowkubernetes.dev
- Ingress-nginx CVE-2025-1974: What You Need to Knowkubernetes.io
- IngressNightmare CVE-2025-1974 proof-of-conceptgithub.com
- Insider Threat Mitigation Guidecisa.gov
- International Cyber Digest on US agencies warning of AI-written scripts targeting Siemens S7 PLCsx.com
- International Cyber Digest: Lockheed Martin allegedly breached, 375TB of data offered for salex.com
- Introducing GitHub Device Code Phishingpraetorian.com
- Introducing GitHub vulnerability management integrations for security professionalsgithub.blog
- Introducing lightyear, a new way to dump PHP filesblog.lexfo.fr
- Introducing Sunlight - a scalable Certificate Transparency log implementationletsencrypt.org
- Intuition-Driven Offensive Security - building a program for critical risk discoveryandywgrant.substack.com
- Investing in the people shaping open source and securing the future togethergithub.blog
- iOS 26 Virtual iPhone Runs on Apple Silicononejailbreak.com
- iOS 26.2 Update Now Warning Issued To All iPhone Usersforbes.com
- IoT Security Fail: Remote Camera Control via Missing ONVIF Authenticationbrownfinesecurity.com
- IPOs Expected In 2024 For Snyk And Cato Networkscrn.com
- Iranian Hacktivists Strike Medical Device Maker Stryker in 'Severe' Attack that Wiped Systemszetter-zeroday.com
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructurecisa.gov
- Is Defender overrated - r/redteamsecreddit.com
- Israeli Spy Chief Accidentally Revealed His True Identity Onlinethedailybeast.com
- ISS National Lab on Moonlighter, the first hacking sandbox satellite in spacex.com
- It Might Be a Good Time to Temporarily Uninstall atopgo.theregister.com
- Jeep software update bricks vehicles, leaves owners strandedthestack.technology
- Jeff Barr: AWS will stop charging for unauthorized S3 requests after empty-bucket bill articlex.com
- Jenny Qu on finding CVE-2026-43453, a Linux kernel nftables OOB readx.com
- JNDIExploit - malicious LDAP server for JNDI injection payloadsgithub.com
- Jon Sakoda on Accenture acquiring runZero in $4.2B deal with Dragos and NetRisex.com
- JTAG Hacking with a Raspberry Pi: introducing the PiFex hardware hacking companion boardvoidstarsec.com
- Justin Gardner on enumerating UUIDs for UUID-based IDORsx.com
- Kali Linux 2023.1 Release - Kali Purple and Python Changeskali.org
- Kash Patel-Linked Apparel Store Goes Dark After Pushing Crypto-Stealing Malwaredecrypt.co
- Keeping up with the Pwnses - Talkback infosec resource aggregatorelttam.com
- Kernel LPE Vulnerabilities Copy Fail, DirtyFrag and Fragnesia - AKS Advisory and Mitigation Guidegithub.com
- Kestrel Chunked Smuggling Proof of Concept - CVE-2025-55315gist.github.com
- Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentivesgithub.blog
- Kohler claims poop scanner uses E2EE, researcher cries foultheregister.com
- Kubernetes Remote Code Execution Via Nodes/Proxy GET Permissiongrahamhelton.com
- Kubernetes Secret Extraction via ArgoCD ServerSideDiff - GHSA-3v3m-wc6v-x4x3github.com
- kuzushi on why all of AppSec basically died between 2010 and 2014x.com
- LAB52 EasterBunny malware analysis report - S2 Grupohome.s2grupo.es
- Large-scale attack campaign exploiting Kubernetes RBAC for backdoors and cryptominersx.com
- Las Vegas Locally: Caesars reportedly paid $30M ransom after hack like MGM'sx.com
- Last Week in Security LWiS 2023-02-21 - Bad Sector Labsblog.badsectorlabs.com
- Leaked Google Content Warehouse API docs behind the 2024 Google Search ranking documentation leakhexdocs.pm
- Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platformsamcurry.net
- Leeds Equity Partners Acquires OffSecfinance.yahoo.com
- Legacy vs modern Attack Surface Management - what is true ASMbrighttalk.com
- Lessons from History about Russian Sabotage - Euro-Atlantic Bulletinen.euroatlantic.org
- Let's build a Chrome extension that steals everythingmattfrisbie.substack.com
- Let's Encrypt revokes cross-certified subordinate CAs missing serverAuth EKUletsencrypt.status.io
- Library of Leaks - Searchable archive of leaked documents from DDoSecretssearch.libraryofleaks.org
- Linguistic Lumberjack: Attacking Cloud Services via Logging Endpoints - Fluent Bit CVE-2024-4323tenable.com
- Linus Torvalds on security bugs being just normal bugs - LKML 2008lkml.org
- Linux kernel moves AppleTalk out of tree as maintainers cannot keep up with security bug reportsgit.kernel.org
- Logic bug in the Linux kernel's __ptrace_may_access function - oss-securityopenwall.com
- LOLC2 - collection of C2 frameworks that abuse legitimate serviceslolc2.github.io
- Loom March 7 Incident Updateloom.com
- m0b13y on enterprise dorking through SharePoint and OneDrive recycle binsx.com
- Macaroons Escalated Quicklyfly.io
- MAD Bugs: My Cousin Vinyl - CVE-2026-50052 HTTP request smuggling in Varnishblog.calif.io
- Malte Ubl on Vercel's HackerOne React2Shell WAF bypass program - 15 issues found, $750K payoutx.com
- Mapping Iranian Cyberattacks on U.S. Water Systems - CSIScsis.org
- Mapping Snowflake's Access Landscapeposts.specterops.io
- MapRoot: A Tale of Two Zero-Days Leading to Cross-Tenant RCE on Microsoft Planetary Computerenclave.ai
- Mari0n asks whether anyone has seen malware using eBPFx.com
- Marius Avram: Chrome extension automatically scans for and exploits CVE-2025-55182 sites as you browsex.com
- Mastercard Finalizes Acquisition of Recorded Futureinvestor.mastercard.com
- Matrix.org - Welcoming Discord users amidst the challenge of Age Verificationmatrix.org
- Matteo Collina on a Node.js CVE that should not have been a CVEx.com
- McDonald's Instagram account seemingly hacked to promote Solana token 'Grimace'theblock.co
- Memory Integrity Enforcement: A complete vision for memory safety in Apple devicessecurity.apple.com
- MFArcade - M365 MFA registration and conditional access gap reportsgithub.com
- MGM Resorts Suffers Cybersecurity Attack, IT Outages Reportedcasino.org
- Microsoft - The Truth Is Even Worse Than You Think by Amit Yoranlinkedin.com
- Microsoft and GitHub pressure security researchers over Black Hat talks and public PoC reposx.com
- Microsoft AntiSSRF - URL validation library to mitigate SSRF in .NET and Node.jsgithub.com
- Microsoft Edge loads all saved passwords into memory in cleartext even when unusedx.com
- Microsoft lost its keys, and the government got hackedtechcrunch.com
- Microsoft mitigates China-based threat actor Storm-0558 targeting of customer emailmsrc.microsoft.com
- Microsoft overhaul treats security as 'top priority' after a series of failures - Hacker Newsnews.ycombinator.com
- Microsoft Patches a Record 570 Security Flawskrebsonsecurity.com
- Microsoft rebrands Azure Active Directory to Microsoft Entra IDbleepingcomputer.com
- Microsoft Response to Layer 7 Distributed Denial of Service DDoS Attacksmsrc.microsoft.com
- Microsoft said it lost weeks of security logs for its customers' cloud productstechcrunch.com
- Microsoft takes pains to obscure role in 0-days that caused email breacharstechnica.com
- Microsoft Teams will soon block screen capture during meetingsbleepingcomputer.com
- Microsoft VS Code Undermined in Asian Spy Attackdarkreading.com
- Microsoft's latest email hack: M365 E3 subscribers beware - Storm-0558 and logging gapsdirectionsonmicrosoft.com
- Mimecast Announces Acquisition of Code42mimecast.com
- Mind The Gap - Bringing Together Cloud Services and Managed K8s Environments, KubeCon EU 2023 slidesdocs.google.com
- MiniPlasma - Windows privilege escalation zero-day PoCgithub.com
- Minnesota IT officials disclose coordinated cyberattack on more than 30 local water systems - Reutersreuters.com
- Minnesota Water System Cyberattack Linked to Irannytimes.com
- MistakenVMtity - another cloud image confusion attackonecloudplease.com
- mitmproxy: Intercepting Linux Applications with eBPF-based local capture modemitmproxy.org
- MNIT activates statewide cybersecurity response to cyberattack on Minnesota water systemsmn.gov
- Modern Asian APT Groups TTPs Reportmedia.kasperskycontenthub.com
- Molly White on Twitter not paying whitehats for an account-takeover disclosurex.com
- More than 30 water systems targeted in cyberattackkstp.com
- Mrgunsngear: hundreds of Hezbollah pagers reportedly exploded simultaneously across Lebanonx.com
- Multistate Water System Attacks Widen, Iran Suspecteddarkreading.com
- My 2025 Bug Bounty Storiesjoshua.hu
- NanoKVM downloads binaries, sets Chinese DNS servers and has an undocumented working microphonex.com
- Native ACME Support Comes to NGINXletsencrypt.org
- Native-First Cloud Security Approach - Microsoft Defender for Cloudtechcommunity.microsoft.com
- neils on hacking US trains via CVE-2025-1727x.com
- NetSPI and Synack to merge, forming a leading offensive cybersecurity platformglobenewswire.com
- New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprisesarstechnica.com
- New enterprise-grade security controls for the Windows Subsystem for Linuxdevblogs.microsoft.com
- New Leak Shows Business Side of China's APT Menacekrebsonsecurity.com
- New Recovery Tool to help with CrowdStrike issue impacting Windows endpointstechcommunity.microsoft.com
- New Zealand company's 'impossible-to-hack' security turns out to be no security at alljltee.substack.com
- Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connectorblog.amberwolf.com
- Next.js and the corrupt middleware: the authorizing artifactzhero-web-sec.github.io
- Nice2Meet: We Turned Teams Mobile Meetings Into a Silent Account Takeoverenclave.ai
- Nick VanGilder on Amazon monitoring keystroke latency to catch workers not located where they claimx.com
- Nightmare Eclipse - BlueHammer Windows exploit public disclosuredeadeclipse666.blogspot.com
- NIST Updates NVD Operations to Address Record CVE Growthnist.gov
- Nitish Yaddala on hardening the TypeError/secure open-source headers librarylinkedin.com
- NixOS SSH hardening config - ssh-harden.nix from xddxdd/nixos-configgithub.com
- No More Blue Fridays - How eBPF Is Being Adopted to Prevent Kernel Crashesbrendangregg.com
- Nordstrom Global Traffic Management - zero-trust gateway and WAF designgithub.com
- North Korea's biggest ever crypto heist: $1.4B stolen from Bybit - Three Buddy Problempca.st
- NSA 2023 Cybersecurity Year in Reviewmedia.defense.gov
- NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurationscisa.gov
- Nuclei template for CVE-2025-29927 Next.js middleware authentication bypassgithub.com
- Nuclei template for CVE-2025-55182 Next.js RSC deserialization RCEgithub.com
- Okta joins the CNCF to shape the future of cloud computingokta.com
- Okta Support System incident and 1Passwordblog.1password.com
- On the 10th anniversary of the Snowden revelationselectrospaces.net
- On the Applicability of the Timeroasting Attacksnovvcrash.rocks
- Onelogon - taking over Active Directory accounts via Netlogon, bypassing the Zerologon patchx.com
- Open Source Security Indexopensourcesecurityindex.io
- Open to Exploitation: The Security Risks of Unauthenticated Pager Networkstelescope.ac
- Operation Masquerade - FBI action against Russian router hacking campaignhackread.com
- Orca Sues Wiz Over Alleged Cloud Security Patent Violationssecurityweek.com
- OWASP Data Leak Notification - wiki misconfiguration exposed member resumesowasp.org
- page_inject - cross-container escape exploit for CVE-2026-31431github.com
- Paged Out! - issue 3pagedout.institute
- Paged Out! - technical security and programming zinepagedout.institute?page=issues.php
- Passive DNS: A Complete Primerdns-history.whoisxmlapi.com
- Patch Wemo FriendlyName with OFRAK - reverse engineering challenges at RECON 2023ofrak.com
- pathfinding.cloud - AWS IAM privilege escalation librarypathfinding.cloud
- payloadartist on Mozilla paying contractors bug bounties for internally disclosed infox.com
- Phishing With Dynamite - stealing whole logged-in browser instances instead of tokensmedium.com
- Plug and Pwn - weaponizing Windows Plug and Play, DEF CON 34plugandpwn.com
- PornHub extorted after hackers steal Premium member activity datableepingcomputer.com
- Porsche scales up its cybersecurity activities with a bug bounty programmenewsroom.porsche.com
- Post Account Takeover? Account Takeover of Internal Tesla Accountsmedium.com
- postMessage targetOrigin bypass via IP normalizationlab.ctbb.show
- Practical AppSec Part I: Why Devs Don't Trust AppSec Findingsoligo.security
- Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyondintruder.io
- Prepared Statements? Prepared to Be Vulnerableblog.mantrainfosec.com
- PrinterLogic Vulnerability Disclosuregist.github.com
- Privileges - temporary admin rights management for macOS in enterprise environmentsgithub.com
- Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaScloud.google.com
- Progressive Web Apps PWA Phishingmrd0x.com
- Prowler: Leading the Open Cloud Security Movementdecibel.vc
- PS365 Get-MgApplicationSAML - enumerate Entra SAML enterprise apps via PowerShellps365.clidsys.com
- Psyware on a lockmaker suing a researcher who bypassed their lockx.com
- Publishers Clearing House breached by Anubis ransomware, 1.4TB leakedx.com
- Puru Dahal on DocuSeal exposing all uploaded documents publicly on AWS S3x.com
- Pushed unified vuln dashboard with live criticals - r/AskNetsecreddit.com
- PwnFunction XSS challengesxss.pwnfunction.com
- Pwning Microsoft Azure Defender for IoT - Multiple Flaws Allow Remote Code Execution for Allsentinelone.com
- pyn3rd on CVE-2025-55182 RSC RCE as an in-memory webshell backdoorx.com
- Quantity Has a Quality All of Its Own - Russia's mass-scale intelligence operationscna.org
- Rachel by the Bay - Problems with the atop utility, uninstall itrachelbythebay.com
- Ransom-DB - ransomware group Qilin publishes Semgrep as a victimx.com
- RDP-Armoring - hardening toolkit for Remote Desktop Protocolgithub.com
- re_nordstrom - reverse engineering of Nordstrom mobile API keys, guest OAuth2 and Akamai sensorgithub.com
- React2Shell - CVE-2025-55182 React.js RCEreact2shell.com
- React2Shell Security Bulletin - CVE-2025-55182 in React and Next.jsvercel.com
- Real-World Examples of Sys:All GKE Riskorca.security
- Recap of the Passkeys Pwned talk at DEF CON - SquareX Labslabs.sqrx.com
- Recon 2024 conference slides - onhexgroupgithub.com
- Recorded Future Insikt Group threat analysis report, November 2023go.recordedfuture.com
- Recreating an MSI Payload for Fun and no profitblog.sunggwanchoi.com
- Red Hat breached: Crimson Collective stole 28k private repos including CI/CD secrets and VPN profilesx.com
- Refining your HTTP perspective, with bambdasportswigger.net
- Remote Access Backdoor Discovered in Chinese Robot Dog Unitree Go1cyberinsider.com
- Researcher says Microsoft is still in court with them despite MSRC's no-legal-action pledgex.com
- Researcher Turns Insecure License Plate Cameras Into Open Source Surveillance Tool404media.co
- Restrictions and Bypass of JNDI Manipulation RCE in high-version JDKkingx.me
- Results of Major Technical Investigations for Storm-0558 Key Acquisitionmsrc.microsoft.com
- Reverse Engineering iOS 18 Inactivity Rebootnaehrdine.blogspot.com
- Reward for Information: Owners/Operators/Affiliates of the Hive Ransomware as a Servicestate.gov
- Rewards for Justice seeks information on Iranian cyber actors Handala and Parsian Afzar Rayan Bornax.com
- RFC 9498: The GNU Name System - privacy-enhancing, censorship-resistant DNS alternativerfc-editor.org
- Riding the Azure Service Bus Relay into Power Platform - cross-tenant RCE in connectorsnetspi.com
- Rippling lawsuit alleges Deel cultivated spy and orchestrated corporate espionagerippling.com
- RoguePlanet - Windows Defender vulnerability PoCgithub.com
- Root from the parking lot - OpenWrt XSS through SSID scanning CVE-2026-32721mxsasha.eu
- Rotating credentials for GitHub.com and new GHES patchesgithub.blog
- Russian Reshipping Service SWAT USA Drop Exposedkrebsonsecurity.com
- SAML roulette: the hacker always wins - PortSwigger Researchportswigger.net
- Scaling vulnerability management across thousands of services and more than 150 million findingsgithub.blog
- Scott Piper's AWS service dependency diagram compiled from the Oct 2025 and Nov 2020 outagesx.com
- Scrutiny on the bug bounty - Nathaniel Wakelam and Shubham Shah slidesdocs.google.com
- Secure Kubernetes ingress with HashiCorp Boundaryhashicorp.com
- Security Alert: Refusal to Give the Government Passwords to Personal Mobile Device Criminalized in Hong Konghk.usconsulate.gov
- Security flaws in an SSO plugin for Caddyblog.trailofbits.com
- Security Incidents From Cachinggithub.com
- Security is a False Positive Problemsecurityis.substack.com
- Security Is Just Engineering Tech Debt - And That's a Good Thingsrajangupta.substack.com
- Security Pills Newsletter - Issue 44newsletter.securitypills.news
- Security Researcher Finds Coldplay Lyrics in Kingston SSD Firmwaretomshardware.com
- Security Vulnerabilities in Apex Code Could Leak Salesforce Datavaronis.com
- Seized banners - collection of website seizure banners from government agenciesseized.fyi
- Send-ing Myself Belated Christmas Gifts - GitHub.com Environment Variables and GHES Shell, CVE-2024-0200creastery.com
- Server-side prototype pollution: Black-box detection without the DoSportswigger.net
- ServiceNow confirms vulnerability exposed customer instance data to unauthorized queriesx.com
- ServiceNow Insecure Access Control to Full Admin Takeover, CVE-2022-43684x64.sh
- ServiceNow tenants breached via Scripted REST endpoint shipped with authentication disabledx.com
- ServiceNow: Potential Public List Widget Misconfiguration - data exposure advisorysupport.servicenow.com
- Shellcode Encoded in UUIDsisc.sans.edu
- Shift Left is Dead: A Post Mortemhackerone.com
- Shin on Iranian security forces' guide to detecting Starlink terminals via WiFi signal signaturesx.com
- Shir Tamari: BingBang thread on Azure AD recon for misconfigured authentication promptsx.com
- ShmooCon 2023 Day 2 BUILD IT! Track - full-day recordingyoutube.com
- ShmooCon 2025 Presentation - Manning and Beale - slidescanva.com
- Shortridge Makes Sense of the 2024 Verizon DBIRkellyshortridge.com
- Should ZAP Switch to a Non-OSI Approved Licencezaproxy.org
- shubs - Mutual TLS bypass when coming from AWSx.com
- shubs: Next.js/RSC RCE bypasses Vercel, Cloudflare and most WAFs, patch nowx.com
- shubs: react2shell-scanner adds a Vercel WAF bypass payload for the React2Shell RCEx.com
- Sick.Codes on a man arrested in Bangkok running an SMS blaster sending 1M phishing texts hourlyx.com
- Silicon Valley crosswalk buttons hacked to imitate Musk, Zuckerberg voicestechcrunch.com
- Simo Kohonen on Fortinet CVE-2026-24858 session auth flawx.com
- Simon Wijckmans on a Google Meet recording re DPRK IT worker detectionx.com
- SinkVPN: Redirecting endpoint cloud telemetry by abusing usermode VPN tunnelslabs.itresit.es
- SLAP and FLOP - Address and Value Prediction Attacks on Apple Siliconpredictors.fail
- Smuggling Through the Front Door - Achieving Global Redirect Poisoning at the Edgemalicious.group
- So, your CISO is a bitchcrankysec.com
- SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDLlabs.watchtowr.com
- solst/ICE on RCE in Ghidra via auto-generated comments CVE-2026-4946x.com
- solst/ICE PoC - Chrome extensions steal session cookies bypassing httponlyx.com
- Some updates and more about the recent Defender exploits RoguePlanet, RedSun, BlueHammerblog.projectnightcrawler.dev
- Sophos Pacific Rim: Defense Against Nation-State Adversariessophos.com
- Space Odyssey: An Experimental Software Security Analysis of Satellitespublications.cispa.saarland
- SpecterOps SO-CON 2024 presentationsgithub.com
- SpecterOps SO-CON 2024 presentationsgithub.com
- Spelunking in Comments and Documentation for Security Footgunsblog.includesecurity.com
- Splitting the Email Atom: Exploiting Parsers to Bypass Access Controlsportswigger.net
- SPR Secure WiFi Router - Per-Device Isolation by Supernetworkssupernetworks.org
- Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0daysmegamansec.github.io
- ssh-artwork - find SSH keys with a specific randomart fingerprint patterngithub.com
- ssh-keysign-pwn - steal SSH host keys via ptrace mm-NULL bypassgithub.com
- SSL.com DCV bypass and fake certificates for any MX hostnamebugzilla.mozilla.org
- SSRF Bible Cheatsheet - Wallarm via OWASPcheatsheetseries.owasp.org
- SSRF Cross Protocol Redirect Bypassblog.doyensec.com
- stacksmashing on sniffing a BitLocker TPM key via an LPC debug portx.com
- Starbucks HackerOne report: RCE and complete server takeover by spaceraccoonhackerone.com
- Start to Finish: Configuring an Android Phone for Pentestingblackhillsinfosec.com
- State divergence enables unauthorized access - Trail of Bits on a Provenance Blockchain authorization bugblog.trailofbits.com
- State of API Security 2026 Report - 42Crunch42crunch.com
- Steven Murdoch on GPS satellites secretly broadcasting a hidden numbers stationx.com
- Stop deploying web application firewallsmacchaffee.com
- Stryker Cyber Incident - Rapid Intel Brief on wiper-style incident lessonsproofeditor.ai
- Stryker Form 8-K disclosing March 2026 cyberattack on its Microsoft environmentsec.gov
- Stryker Form 8-K filed March 11, 2026 following the wiper cyberattacksec.gov
- Stryker Wiper Attack: What Security Teams Need to Know Nowblog.7ai.com
- SUNS - Software Understanding for National Security, Sandia National Laboratoriessuns.sandia.gov
- Sustaining Cyber Awareness: The Long-Term Impact of Continuous Phishing Training and Emotional Triggersarxiv.org
- Sweep on two Ohio inmates who built PCs from recycled parts and ran a hacking operation in prisonx.com
- Systems Thinking for Cybersecurity Professionalstldrsec.com
- TagTinker - Flipper Zero infrared ESL research toolkitgithub.com
- Take a Step Further: Understanding Page Spray in Linux Kernel Exploitationarxiv.org
- Talkback - AI-powered infosec resource aggregatortalkback.sh
- Taming the Attack Graph - A Many Subgraphs Approach to Attack Path Analysisspecterops.io
- Target's dev server offline after hackers claim to steal source codebleepingcomputer.com
- TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interpositiontee.fail
- Tell HN: Microsoft.com added 192.168.1.1 to their DNS recordnews.ycombinator.com
- Terraform Security Best Practices - Sysdigsysdig.com
- Tesla data breach affects 75,735 people, state attorney general announcesfoxbusiness.com
- Testing Extensions in Chromium Browsers - NordPassparsiya.net
- The $1.5B Bybit Hack: The Era of Operational Security Failures Has Arrived - Trail of Bitsblog.trailofbits.com
- The Art of Linux Kernel Rootkitsinferi.club
- The Copenhagen Book - implementing auth for the webthecopenhagenbook.com
- The Death of Infosec Twitter - Cyentia Institutecyentia.com
- The Developer Endpoint Security Problemx.com
- The Disappearance of an Internet Domain - how geopolitics can alter digital infrastructureevery.to
- The Fascinating Security Model of Dark Web Marketplacesboehs.org
- The First Anniversary of the Public Launch of LinkedIn's Bug Bounty Programengineering.linkedin.com
- The First Decade of Corporate Ransomware - RSACyoutube.com
- The Fragile Lock: Novel Bypasses For SAML Authenticationportswigger.net
- The Future of European Cyber Defensevimeo.com
- The gift that keeps giving: Exploiting Git Integrations in Cloud Servicesnopnop.pro
- The God Mode Vulnerability That Should Kill 'Trust Microsoft'tide.org
- The GRU's Disruptive Playbook - Mandiant analysis of Russian GRU cyber operations against Ukrainemandiant.com
- The Hacker's Choice releases smallest SSHD backdoor - one line, no new files, survives apt-updatex.com
- The Handala Wiper Masquerades as CrowdStrike. We Found It on GitHubdugganusa.com
- The Impact of the Russia-Ukraine Conflict on the Cloud Computing Risk Landscapearxiv.org
- The Internet Is Falling Down - cPanel and WHM Authentication Bypass CVE-2026-41940labs.watchtowr.com
- The Most Hackable Handheld Ham Radio Yet - Quansheng UV-K5 firmware moddingspectrum.ieee.org
- The Open Cloud Vulnerability and Security Issue Databasecloudvulndb.org
- The RCE that AMD wouldn't fix - MITM RCE in Ryzen Master AutoUpdatemrbruh.com
- The Scale of Russian Sabotage Operations Against Europe's Critical Infrastructureiiss.org
- The Signal - cybersecurity funding, M&A and market intelligencesignal.returnonsecurity.com
- The Signal Clone the Trump Admin Uses Was Hacked404media.co
- The Single Byte That Kills Your Exploit: Understanding Endiannesspwnforfunandprofit.substack.com
- The Slow Death of OCSP - Feisty Duck Cryptography and Security Newsletterfeistyduck.com
- The Ultimate Guide to Windows Coercion Techniques in 2025blog.redteam-pentesting.de
- The Vulnerability Identity Crisisresearch.empiricalsecurity.com
- The Windows Registry Adventure #1: Introduction and research results - Project Zerogoogleprojectzero.blogspot.com
- The Windows Registry Adventure #2: A brief history of the feature - Project Zerogoogleprojectzero.blogspot.com
- This Dystopian Cyber Firm Could Have Saved Mossad Assassins From Exposurearchive.vn
- This World of Ours - James Mickensusenix.org
- Three new NGINX ingress controller Kubernetes vulnerabilities - CVE-2023-5043, CVE-2023-5044, CVE-2022-4886armosec.io
- Tib3rius on NCC Group laying off ~30% of its North America pentesting teamx.com
- tl;dr sec #254 - Cloud CTFs, AI + AppSec, Awesome Threat Detectiontldrsec.com
- tmp.0ut Volume 4 - ELF and malware research ezinetmpout.sh
- To study how chips really work, MIT researchers built their own operating systemcsail.mit.edu
- tomnomnom on GitHub - recon and bug bounty toolsgithub.com
- Top 10 web hacking techniques of 2023 - PortSwigger Researchportswigger.net
- Top 10 web hacking techniques of 2025portswigger.net
- Towards SSH3: How HTTP/3 Improves Secure Shellsarxiv.org
- TPM-JS - experiment with a software TPM in your browsergoogle.github.io
- Track the Planet - mapping identities and monitoring presence in the Azure ecosystem, DEF CON 31 slidesgithub.com
- Trail of Bits on two AES libraries shipping a default IV that guarantees key reusex.com
- TruffleHog recommended for Salesloft cleanup while flagged as an IoCx.com
- Trustwave Transfers ModSecurity Custodianship to OWASPowasp.org
- Tuan Anh Nguyen on Starbucks fixing a reported RCE overnight before triagex.com
- Tunnel Vision: Cloudflared Abused in the Wildguidepointsecurity.com
- Turning Everyday Gadgets into Bombs is a Bad Ideabunniestudios.com
- Two new React Server Components vulnerabilities found after React2Shell patchx.com
- U.S. Internet Leaked Years of Internal, Customer Emailskrebsonsecurity.com
- Ubiquiti Security Advisory Bulletin 062community.ui.com
- UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineeringcloud.google.com
- Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewriteelastic.co
- Understanding a Payload's Lifeattl4s.github.io
- Understanding the Efficacy of Phishing Training in Practicecomputer.org
- Understanding the worst .NET vulnerability ever: request smuggling and CVE-2025-55315andrewlock.net
- Understanding Windows Shellcodehick.org
- UNFI loses $500M in market value following cyberattackbizjournals.com
- Unlocking secret ThinkPad functionality for emulating USB devicesxairy.io
- Unsecure time-based secret and Sandwich Attack - Reset Tolkien researchaeth.cc
- US Air Force Engineer Charged With Sawing Down Flock Surveillance Cameras Receives Supportyahoo.com
- US Senator Wyden Accuses Microsoft of "Cybersecurity Negligence"securityweek.com
- Using an Android emulator for API hackingzerodayhacker.com
- Using feature flags for securityalsmola.medium.com
- Utilizing a Common Windows Binary to Escalate to SYSTEM Privileges - fodhelper LPEmedium.com
- V12 breaks into Signal's SGX contact discovery enclave - arbitrary read and RCEx.com
- Vergilius Project - undocumented Windows kernel structuresvergiliusproject.com
- VERITE - Smart Contract Fuzzing Towards Profitable Vulnerabilitiesgithub.com
- Very Pwnable Networks - AmberWolf HackFest Hollywood 2024 slidesgithub.com
- Video of a North Korean IT worker applicant stopped by being asked to insult Kim Jong Unx.com
- Vishing actors target Entra passkey enrollmentokta.com
- Vital Vegas on the MGM ransomware attack - man demanded $40M at Mandalay Bay cage, in custodyx.com
- Vlad Ionescu thread on HashiCorp's BSL license change and its supply-chain ripple effectstypefully.com
- Vodka maker Stoli files for bankruptcy in US after ransomware attackbleepingcomputer.com
- Vulnerable-WordPress - monthly-updated vulnerable WordPress build for exploit practicegithub.com
- vx-underground on ALPHV breaching MGM Resorts via a 10-minute help desk callx.com
- vx-underground on Microsoft's blog scolding Nightmare-Eclipse for dropping zero-daysx.com
- vx-underground on Microsoft's undocumented Global Device Identifier used to track Scattered Spider suspectx.com
- vx-underground on Operation Triangulation C2 domains and their AWS host from the Kaspersky reportx.com
- vx-underground on the December 2023 Ubisoft breach and attempted 900GB exfiltrationx.com
- WAF Bypasses via h2 framinglab.ctbb.show
- Walkie-Talkies Explode in New Attack on Hezbollahwired.com
- We Hacked Flock Safety Cameras in under 30 Seconds - Benn Jordanyoutube.com
- We replaced passwords with something worse - on email one-time code loginsblog.danielh.cc
- We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBIlabs.watchtowr.com
- Weak Passwords - live list of common seasonal passwordsweakpasswords.net
- Weaponizing Plain Text: ANSI Escape Sequences as a Forensic Nightmare - STOK DEF CON 31 talkx.com
- Web Security is Too Hard - ericlaw on consent phishingtextslashplain.com
- Web3 is Going Just Great - timeline of crypto and DeFi disasters and exploitsweb3isgoinggreat.com
- What everyone is missing from the CrowdStrike Falcon incidentblog.axantum.com
- What Happened to HackerOne - the rise and fall of the largest bug bounty platformblog.teknogeek.io
- What is the Pixnapping vulnerability, and how to protect your Android smartphonekaspersky.com
- What Skills Do Cyber Security Professionals Need?arxiv.org
- What the bliss taught us - curl's month off from vulnerability reportingdaniel.haxx.se
- What's the most expensive security control you've implemented - r/cybersecurityreddit.com
- When Backups Open Backdoors: Accessing Sensitive Cloud Data via Synology Active Backup for Microsoft 365modzero.com
- When Disabled Doesn't Mean Disabled: Azure APIM Cross-Tenant Signup Bypassitewiki.fi
- When Pentest Tools Go Brutal - Brute Ratel C4 Red Teaming Tool Being Abused by Malicious Actorsunit42.paloaltonetworks.com
- Why are vulnerabilities out of control in 2024opensourcesecurity.io
- Why Stryker's Outage Is a Disaster Recovery Wake-Up Calldarkreading.com
- Why the $32B Google-Wiz Deal Caught the Eye of US Regulatorsinforisktoday.com
- Why We Hack Purple and I are joining Semgrepsemgrep.dev
- Why We Need the Open Cloud Security Movementprowler.com
- Why your company is wasting thousands of hours on software vulnerabilitieschainguard.dev
- WinAPI Search - Search Utility for Win32 Functions and Error Codesdennisbabkin.com
- Windows BitLocker - Screwed without a Screwdriverneodyme.io
- Windows Kernel Rootkits - Ringzer0 Training 2019ringzer0.training
- Wiz 2023 Kubernetes Security Reportdatocms-assets.com
- Wiz Finds Critical Redis RCE Vulnerability CVE-2025-49844 - RediShellwiz.io
- Wiz Research discovers RCE on GitHub.com via a single git pushx.com
- Wiz to acquire Dazz, transforming risk remediation from cloud to codewiz.io
- Wiz walks away from Google's $23B acquisition offertechcrunch.com
- Wiz will focus on IPO after rebuffing $23 billion Google dealmarketwatch.com
- Woman pulled over at gunpoint twice after Flock camera glitchguessingheadlights.com
- Wormable Substack XSSblog.calif.io
- WorstFit - tracking list of executables vulnerable to the Windows ANSI best-fit attackworst.fit
- X-C3LL on Spanish ISPs blocking Cloudflare on weekends breaking APT C2 beaconsx.com
- XSS to RCE by Abusing Custom File Handlers - Kentico Xperience CMS CVE-2025-2748labs.watchtowr.com
- XXE with Auto-Update in install4j - Frycos Security Diaryfrycos.github.io
- Yellowhat 2027 sessions - Microsoft Security conference talks including generative AI governanceyellowhat.live
- Yelp account takeover via XSS and cookie bridge leaking HttpOnly session cookieshackerone.com
- YesWeHack Credits - bug bounty report submission credit systemhelpcenter.yeswehack.io
- You might want to stop running atop - discussion of the suspected exploitable flaw in atopnews.ycombinator.com
- Your API Shouldn't Redirect HTTP to HTTPSjviide.iki.fi
- Your Security Program Is Shitcrankysec.com
- Zach Edwards: driver's license scanned at a dispensary found for sale on dark web with 153M othersx.com
- ZachXBT on M1llionz, a French cybercriminal laundering proceeds from home invasion robberiesx.com
- ZAP Has Joined Forces With Checkmarxzaproxy.org
- ZAP is Joining the Software Security Projectzaproxy.org
- Zenbleed - Tavis Ormandylock.cmpxchg8b.com
- Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participantsorca.security