

Heather Adkins - Ꜻ - Spes consilium non est
6.5K posts

@argvee
VP Security @Google, Co-Author "Building Secure and Reliable Systems" @r00t0wns, Medieval Historian



A strong and extensive westerly wind burst is forecast near the equator over the coming weeks. It should amplify the warming effects of a Kelvin wave crossing the basin, push warm surface waters eastward into the Niño 3.4 region and elevate chances for a super El Niño this year.

Tomorrow, I will drop Chrome exploit code showing how an attacker can execute arbitrary Javascript within the context of a domain they control.







Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW


Don't just start a company Start a cult




AI will not solve cybersecurity! “With the recent news of folks finding vulnerabilities left and right using LLMs, some folks hope that we'd be able to find every single vulnerability. Today, I hope to shatter that idea” github.com/yo-yo-yo-jbo/v…



A Frontier Airlines plane hit and killed a pedestrian on the runway of the Denver International Airport during takeoff, airport authorities said, sparking an engine fire and forcing passengers to evacuate. apnews.com/article/denver…

There are so many Linux and Windows LPEs that we literally have to turn away researchers with perfectly good exploits, because we just don’t need another one lying around on the shelf. If you must work Windows/Linux, it makes sense to work on RCE primitives instead of LPE

Try out the early alpha of Process Isolation in Chrome 138. chrome://flags/#enable-process-isolation-ui then chrome://settings/system for the switch. Read known issues issues.chromium.org/issues?q=hotli… and report bugs! Especially interested in App-Compat bugs.


Australia's new cyber incident review board will be modeled on the Cyber Safety Review Board established by the Biden administration in 2022, though with a narrower membership drawn largely from critical infrastructure industries therecord.media/australia-laun…