James Forshaw 

4.3K Followers
160 Following
419 Posts
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc.
Githubhttps://github.com/tyranid
Bloghttps://www.tiraniddo.dev/

Interesting links of the week:

Strategy:

* https://www.marisec.ca/reports/the-wrong-fix-why-the-fccs-router-ban-misses-the-real-threat - an alternate view on prioritising the supply chain
* https://cybertoolkit.service.ncsc.gov.uk/ - so you're a small business and you want to improve your posture?
* https://how.complexsystems.fail/ - courtesy of @russss
* https://eepublicdownloads.blob.core.windows.net/public-cdn-container/clean-documents/Publications/2025/iberian-blackout/Final%20Report%20on%20the%20Grid%20Incident%20in%20Spain%20and%20Portugal%20on%2028%20April%202025.pdf - an Iberian oopsie
* https://www.theregister.com/2026/03/20/jlr_bailout_cmc/ - @theregister shares a point of view on bailing out JLR
* https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf - US intelligence community's annual threat assessment
* https://cyber.gouv.fr/actualites/nis-2-lanssi-poursuit-et-renforce-sa-dynamique-daccompagnement/ - hot new NIS2 action from ANSSI

Threats:

* https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/ - how does AI affect STRIDE?
* https://united24media.com/latest-news/russian-spy-devices-found-inside-ukrainian-drone-developers-office-17243 - attack of the drones
* https://www.elastic.co/security-labs/illuminating-voidlink - another look at VoidLink
* https://ctrlaltintel.com/threat%20research/FancyBear/ - FancyBear fucks up
* https://netaskari.substack.com/p/chinas-massive-data-leak-of-military - .cn springs a leak

Detection:

* https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf - my colleague @jgamblin talks open source intelligence
* https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging - @trustedsec look at logging PowerShell
* https://righteousit.com/2026/03/27/linux-forensic-scenario/ - @hal_pomeranz sets us a little challenge

Bugs:

* https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ - this reminds me of when I first showed @ha888t AIX
* https://itm4n.github.io/cve-2026-20817-wersvc-eop/ - when errors go rogue with @itm4n

Exploitation:

* https://dev.to/numbpill3d/showdev-can-playground-a-local-first-can-bus-analysis-tool-4ap6 - @numbpilled shows how you CAN play with busses
* https://agentseal.org/blog/mcp-server-security-findings - hands up if you have a secure MCP?

Hardening:

* https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf - enclave backed SSH for OS X from @arianvp

Nerd:

* https://www.theguardian.com/culture/2026/mar/24/punk-masks-walkmans-and-choppers-museum-of-youth-culture-to-open-in-london - eras...
* https://www.data.gov.uk/ - UK specific datasets from HMG
* https://www.sambent.com/the-engineer-who-tried-to-put-age-verification-into-linux-5/ - today in Linux daftness
* https://blog.rice.is/post/doom-over-dns/ - everyone's favourite vanity PoC payload comes to DNS

#security, #research

The Wrong Fix: Why the FCC's Router Ban Misses the Real Threat

On March 20th, 2026, the FCC banned the purchase, import and sale of foreign-made routers, citing supply-chain and security concerns. The FCC fails to account for weak credentials and firmware vulnerabilities, which serve as the initial access vectors for Salt, Volt, and Flax Typhoon attacks.

In which I get shout outs from the grsec crew:

https://x.com/spendergrsec/status/2037295088225636706

This piece of work remains one of my high water marks for security research. For all the bugs etc, doing something worthy of a grsec enhancement gives me a big smile.

Cheers @grsecurity folks.

Brad Spengler (@spendergrsec) on X

#grsecurity automatically prevents this vuln via GRKERNSEC_HARDEN_IPC : https://t.co/iy8m12mGAh cc @timb_machine who did the original research that resulted in the feature

X (formerly Twitter)

A thing being repeated across businesses worldwide, including at Microsoft, is C level execs struggling to know why most staff aren’t using Copilot for M365, despite how much it costs.

Because most staff don’t spend all day in Teams meetings reading out PowerPoint slides to people who pretend to care. They have actual jobs. Doing work. Which they know how to do. Because it is their job.

Of course I’m deeply angry that apple chose to prostate themselves to the ineffectual ofcom who should be spending their time enforcing real laws like against GBNews. But I do wonder what happens now with devices if you log off from your unverified apple account. Does it revert to “normal” operation ? Or with 26.4 will it come up by default in kid mode? Can you use an iPhone anymore without ever signing in?

So @xaitax has cracked Microsoft Recall, he's got access to the encrypted database and has automated dumping of screenshots and all text from screenshots.

I've looked at most recent Recall and yep, you can just read the database as a user process. The database also contains all manner of fields which aren't publicly disclosed for tracking the user's activity.

No AV or EDR alerts triggered, world's #1 in infostealer 😅

* you can just read it in plain text

The new Google office in London is looking nice. https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/platform-37-the-ai-exchange/

I especially like how it's super energy efficient and uses low carbon materials while touting the world destroying tech that is AI. A masterclass of green washing.

Platform 37 and The AI Exchange: new spaces for AI innovation and discovery

Google’s newest London building, Platform 37, is named to honor Google DeepMind’s AlphaGo.

Google

RE: https://mas.to/@sphcow/116204059692143351

This is well worth reading if you are submitting to @44CON - CFP is open (2026 Event 17th-18th September, London, UK)

The new macbook neo looks somewhat cute, but, it doesn't come with a PSU? Really? Is this going to be the new normal going forward for laptops? This seems to at least be the case in the UK, checking the US website it comes with a 20W USB-C PSU.

The @revisionparty invitation just dropped! It's been an absolute blast to work with Slipstream on this...

Watch online: https://thegoldendisk.demozoo.org/

The Golden Disk

The invitation for Revision 2026

My final blog related to admin protection is up. https://projectzero.google/2026/02/gphfh-deep-dive.html I go into a bit of history of the interesting GetProcessHandleFromHwnd API, how it ended up allow you to bypass protected process restrictions and how it's now "fixed".
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero

In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...