Space & Security News

New article: “Responsible Disclosure in the Age of AI: A Call for Urgent Action,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remediation. Frontier AI models...

Establishing a successful purple team program requires more than tools and technology. Organizations need to devote time, attention, and resources to critical considerations such as program governance, leadership, and outcomes. Establishing a...

OSSOCDOCS is a project designed to fill a need for robust, freely available, SOC documentation including runbooks and governance. After a decade of building and running Security Operations Centers (SOCs) for dozens of companies, I have...

Traditional formulas of risk assessment applied to cybersecurity simply do not work due to the fundamentally different landscape of cybersecurity. Assessment based on capability breaks due to the proliferation of computation, internet connection,...

About

01/06/2026 16:40

Daddy geek blog… Some informations: No regular posting Sometimes french posts, sometimes franglais posts Code presented is probably only working on my computer Content is licensed under CC-BY-SA 4.0 All opinions or views presented here are mine...

Here is an overview of content I published in May: Blog posts: Update: search-for-compression.py Version 0.0.7 SANS ISC Diary entries: Wireshark 4.6.5 Released YARA-X 1.16.0 Release Wireshark 4.6.6 Released Microsoft Access VBA YARA-X 1.17.0 Release

Introduction This diary provides indicators from an unidentified RAT infection on Wednesday 2026-05-27 that was followed by a malicious NetSupport Manager RAT package. This originated from the SmartApeSG ClickFix campaign. I still don't know the...

Scala Security Audit

31/05/2026 22:00

Introduction Scala is a modern multi-paradigm programming language designed to express common programming patterns in a concise, elegant, and type-safe way. It seamlessly integrates features of object-oriented and functional languages. Over the...

YARA-X's 1.17.0 release brings 5 improvements (several performance improvements) and 1 bugfix. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial...

HTB: Interpreter

30/05/2026 13:45

Interpreter is a Linux box hosting Mirth Connect, a Java-based healthcare integration engine. I’ll exploit an unauthenticated XStream deserialization vulnerability in the Mirth API to get remote code execution and a foothold as the mirth service...

Someone named “Squid” seems to be a “West Country legend.” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Chilling Effects

29/05/2026 11:02

Younger Americans have soured on the second Donald Trump presidency, but they are not protesting it. Despite an unpopular Iran war and an even more unpopular Trump administration, college campus protests nationwide have gone silent. And at many...

Aucun article de sécurité disponible