Émilio Gonzalez

168 Followers
266 Following
933 Posts
Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.
Blueskyhttps://bsky.app/profile/res260.bsky.social
PronounsHe/Him
GitHubhttps://github.com/res260
Cooking something 👀

NIST makes it official and basically gives up on enriching CVEs: https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

Will only enrich:

-KEV listed bugs
-bugs in software used by the US govt
-bugs in critical software (see list here/PDF: https://www.nist.gov/system/files/documents/2026/04/15/EO%2014028%20Critical%20FINAL.pdf)

NIST Updates NVD Operations to Address Record CVE Growth

NIST is changing the way it handles cybersecurity vulnerabilities and exposures, or CVEs, listed in its National Vulnerabilit

NIST

RE: https://mstdn.ca/@avilewis/116399341217393544

Did this (a website charging two people different price for the same thing bought at the same time) really happen in Canada? It sounds kinda ridiculous

Pas de restriction sans une façon de vérifier l'âge qui ne permet ni au gouvernement de savoir où tu t'inscris ni au réseaux sociaux d'avoir ton identité réelle. 😡

https://www.lapresse.ca/actualites/politique/2026-04-10/congres-du-plc-a-montreal/les-liberaux-se-prononceront-sur-les-restrictions-d-age-pour-les-reseaux-sociaux.php
#polcan

Congrès du PLC à Montréal Les libéraux se prononceront sur les restrictions d’âge pour les réseaux sociaux

(Montréal) Les membres du Parti libéral du Canada (PLC) devront se pencher sur la question de savoir s’il faut interdire aux enfants et aux jeunes adolescents l’accès aux comptes sur les réseaux sociaux, tels que TikTok, Instagram, Reddit et YouTube.

La Presse
Merci à la CORPIQ (le lobby des propriétaires immobiliers au Québec) de nous rappeler que les propriétaires ne peuvent charger un prix très élevé que quand il manque de logements et que s'il y en a trop, ils sont forcés de baisser le prix demandé. 👀

‼️ Prochain MontréHack: PolyPwn 2026's LabOps Track ‼️

The goal is to write a keygen for a lab management web application compiled to WebAssembly (WASM).

📍 ÉTS, D-4007
📅 Wednesday April 15th 18:00 - 21:00
https://montrehack.ca/2026/04/15/this-wasm-my-kind-of-web-challenge.html

Not gonna lie this shit is so spooky. At the same time this technology is so insanely interesting. There are so many good reasons to criticize AI but we can't deny that the AI companies actually deliver capabilities improvements and have been since the release of chatgpt in 2022.
This can be used to do so much bad stuff and probably so much good stuff too. Again, spooky.

https://red.anthropic.com/2026/mythos-preview
#ai

Claude Mythos Preview \ red.anthropic.com

Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years.

That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.

https://words.filippo.io/crqc-timeline/

A Cryptography Engineer’s Perspective on Quantum Computing Timelines

The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.

🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week.

Multiple high-impact maintainers have all confirmed they were targeted in the same coordinated social engineering campaign that compromised Axios.

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers

Attackers Are Hunting High-Impact Node.js Maintainers in a C...

Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Socket