
Paying $20/month for AI in 2026 is what owning a smartphone in 2009 was.
Patrick Flanigan
1.1K posts

@pflanigan
Infosec, cybersecurity

Paying $20/month for AI in 2026 is what owning a smartphone in 2009 was.

💥 Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io

What can we infer from this?







We're seeing a shift at #RSAC, and it's one the community needs to push harder. People are tired of the gimmicks and sales pitches. It's time to demand that vendors bring real tradecraft, technical insights, and actual researchers to the floor.





The open source supply chain is collapsing in on itself. Trivy gets compromised → LiteLLM gets compromised → credentials from tens of thousands of environments end up in attacker hands → and those credentials lead to the next compromise. We are stuck in a loop.





