Mike Siegel

95 Followers
123 Following
584 Posts
I do various offsec stuff.
Githubhttps://github.com/mikesiegel

I already saw how laws like these impacted games like Habitica, where online interaction had to be removed because small, open source companies can't meet legal requirements intended for corporate behemoths.

I wouldn't be surprised if MUDing is probably illegal now in certain jurisdictions because content moderation is simply "don't be a dick".

Here's a good longer piece explaining why age verification solves nothing for children's safety, puts all of us at risk, violates fundamental privacy protections and lets the bad actors, "social" ad platforms off the hook. By @zackwhittaker
https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/
Papers, please: Age verification laws threaten everyone's online security and privacy

Laws that require adults to upload their driver's licenses or passports to access apps, websites, and VPNs will make the entire web less safe.

~this week in security~
I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help?

I pointed Claude Opus at Discord's bundled Chrome (version 138, nine major versions behind upstream) and asked it to build a full V8 exploit chain. The V8 OOB we used was from Chrome 146, the same version Anthropic's own Claude Desktop is running. A week of back and forth, 2.3 billion tokens, $2,283 in API costs, and about ~20 hours of me unsticking it from dead ends. It popped calc.

Hacktron AI

RE: https://fosstodon.org/@iscdotorg/116416426577631380

"MOST OF THESE FALSE POSITIVES CAN BE AVOIDED BY SIMPLY REPRODUCING THE SUPPOSED PROBLEM IN AN ACTUAL SOFTWARE TEST."

Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations — but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

Without donor contact, these machines are useless. :(

I've upcycled ~1,000 older Macs, but T2 era machines will end that. It's controlling, creates e-waste, and will only get worse. #righttorepair matters — Apple couldn't care less.

My colleague Omid and I did a thing.
It's my first Cisco Talos blog ever.
https://blog.talosintelligence.com/the-n8n-n8mare/
The n8n n8mare: How threat actors are misusing AI workflow automation

Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.

Cisco Talos Blog
I have been working on a set of vulnerabilities for 14(!) months, but the end is in sight! Just sent the draft blogs to the vendor for review, got € 3200 in bug bounties, and in two weeks I should be able to publish my attack chain on critical internet infrastructure 🕵️‍♀️

@mikesiegel

Well, I've seen it before, and others have, too, although I wouldn't characterize it as frequent or common. I've occasionally reported on some of these types of things, like this post of mine in 2023: https://databreaches.net/2023/03/19/monti-ransomware-gang-leaks-donut-leaks/

And then, of course, there was the famous LockBit one:
https://databreaches.net/2025/05/08/60k-btc-wallets-tied-to-lockbit-ransomware-gang-leaked/

I would love to see gangs spend so much time attacking each other that they leave everyone else alone, but the only time I've seen anything close to that is all the BreachForum clones who have attacked each other over the past few years.

So the HBO idea: yeah, two kids attacking each other's leak site, fall in love, have a falling out, and one rats out the other to law enforcement? "RaaSurvivor" ??

MONTI ransomware gang leaks Donut Leaks (UPDATED) - DataBreaches.Net

In one of the more intriguing listings of this week, the MONTI ransomware group has added another group, Donut Leaks, to their leak site. The message reads: "st

DataBreaches.Net
Half my timeline is like "GenAI is the tool of Satan and you're a bad person if you use it" and half of it is "GenAI is machine Jesus, TavisO as SaaS, we have solved software security" and I'm just like
TIL JavaScript was made in 10 days. That explains a lot actually.