438 Followers
152 Following
1.8K Posts
I toot about IT security and iOS jailbreaking.
Red Team.
XSwissHttp

The cat's out of the bag! My latest book, "The Secret Life of Circuits", is available in early access:

https://lcamtuf.coredump.cx/blog/secret/

It's the reference I wish I had when I was starting out. Electrons to embedded systems, 290+ color illustrations and 420+ pages of well-explained theory.

The Secret Life of Circuits

Many of you follow this blog because of the regular features about electronic circuit design.

I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.

I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl

384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:
-----BEGIN RSA PRIVATE KEY-----
MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK
j0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP
LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa
9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09
AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj
7ez94w==
-----END RSA PRIVATE KEY-----

Chasing an Angry Spark

A VM-obfuscated backdoor observed on a single machine in the UK, operated for one year, and vanished without a trace.

This is a fantastic blogpost and one to keep in bookmarks to check again in a year or two to see if it was right or not!

https://leehanchung.github.io/blogs/2026/04/05/the-ai-great-leap-forward/

The AI Great Leap Forward

In 1958, Mao ordered every village to produce steel. The steel was useless. The crops rotted. Today's top-down AI mandates are producing the same pattern: ba...

Han, Not Solo

I can confirm Creative Cloud has added to my /etc/hosts file.

Adobe secretly modifies your hosts file for the stupidest reason: https://www.osnews.com/story/144737/adobe-secretly-modifies-your-hosts-file-for-the-stupidest-reason/

Your session limit is still 5 hours. We've just changed the definition of what an hour is

https://x.com/trq212/status/2037254607001559305

(h/t @davidgerard)

Enough is enough. It's time to pull the 🔌.

After the F-35 drama, the tariff insults, public mockery by Trump of the 🇨🇭 president, the technical inferiority of the Patriot missiles compared to the SAMP/T, 🇬🇱🇨🇦 invasion threats, the Pentagon's theft of European paid weapons destined to Ukraine to make up for the failures in Iran, and now the theft of money from the F-35 payments towards to patriot restocking…

🇨🇭should no longer be buying 🇺🇸 weapons.
Join the petition ✍️: https://gssa.ch/57766/#formular

There is currently an insane spy thriller running in #Hungary ICYMI:

https://www.direkt36.hu/en/titkosszolgalati-nyomasra-tortent-hazkutatas-a-tiszat-segito-informatikusoknal-aztan-kibukott-egy-gyanus-muvelet-a-part-ellen/

A 90min interview with the whistleblower was released too that reveals even more pieces of the puzzle. The whole thing screams for a movie (and long prison sentences).
Inside the covert operation to bring down the party threatening Viktor Orbán’s rule - Direkt36

According to documents obtained by Direkt36, a secret operation was carried out to bring down the IT systems of the Hungarian opposition party Tisza. IT specialists affiliated with the party planned to expose this, but then police officers, pressured by the Hungarian secret services, raided them, apparently on trumped-up charges.

Direkt36 - Direkt36 is a non-profit investigative journalism center with the mission to hold powerful people and institutions accountable.
(no)

A former Trenchant employee told us that when Triangulation was first revealed, other employees at the company believed that at least one of the zero-days caught by Kaspersky “were from us."

Also both Kaspersky and Trenchant seemed to wink at the fact that they both knew.

https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/