VessOnSecurity

1.5K Followers
52 Following
9.7K Posts

Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance.

PGP keyID: 0x365697c632dd98d9

Check whether a site supports post quantum crypto* https://quantumhello.xyz

* Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768

RE: https://mastodon.social/@campuscodi/116788928037574690

But strcpy() is totally fine, yes?

I asked a clanker to make me a prompt that I can use to generate images of malware, like literal pictures that represent malware such as the ones used in samplepedia, not PE images.

I got a warning for cyber abuse with threats to shut down my account o.O

Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies

Full agent sessions captured on a compromised host turned honeypot offer an unprecedented look at how attackers are using AI in real-world intrusions.

OALABS Research
Not endorsing this (I'm not a rabid anti-AI person and use GenAI for programming tasks a lot) but these points are worth considering:

"Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain":

https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Paradigm Shift’s usbliter8 exploit targets Apple A12 and A13 SecureROM via USB DFU mode, creating an unpatchable hardware risk.

The Hacker News

Don't look now, but it seems Gizmodo's homepage is now serving up a Clickfix attack.

Basics of the Click-Fix exploit, which causes a pasted URL to fetch malware via Windows Powershell.

https://krebsonsecurity.com/2025/03/clickfix-how-to-infect-your-pc-in-three-easy-steps/

#clickfix #gizmodo

Funny out of context quote from a meeting earlier today: "Space law does not happen in a vacuum"