Skip to content

Normal Science

Brain healing
GraphAuthors

A reading list for frontier science

Articles across AI, biotech, forecasting, and emerging tech.

Recommendation GraphExplore who recommends whom across the networkBrowse AuthorsProfiles, influences, and key works
Weekly Digest — Free
Join researchers, founders, and analysts · Unsubscribe anytime

Categories

AllAIForecastingBioTechMetascienceSecurity / OSINTAI SafetyFinanceManufacturingEnergyCryptoStartups

Time

Sort

Yesterday

Cities Are Ditching Flock, Replacing It with Axon License Plate Readers

cdrnsf·15h ago38pts

Rather than get rid of ALPR cameras entirely, many cities and towns are switching to Axon, whose cameras can be mounted to an existing streetlamp, helping them blend into their surroundings.

Canadian Man Pleads Guilty in Snowflake Extortions

BrianKrebs·Krebs on Security·15h ago

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Mo...

This Week

The Coldcard Disaster Gets Worse: The Hack May Have Reached $88.6M

paulpauper·4d ago25pts

Vulnerabilities in Car Anti-Theft Device

Bruce Schneier·Schneier on Security·1d ago

This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

Some Claude Chats Are Searchable on Google

Bruce Schneier·Schneier on Security·2d ago

And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses. What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem: “We give people control over sh...

Older

Google Chrome silently installs a 4 GB AI model on your device without consent

john-doe·3mo ago1591pts

Google Chrome is downloading a 4 GB Gemini Nano model onto users

DNSSEC disruption affecting .de domains – Resolved

warpspin·3mo ago724pts

Current system status. View active incidents or upcoming maintenance. Subscribe to receive status notifications.

Security through obscurity is not bad

mobeigi·3mo ago165pts

Why security through obscurity still matters: not as your only defence, but as a practical layer that raises attacker cost.

US healthcare marketplaces shared citizenship and race data with ad tech giants

ZeidJ·3mo ago457pts

Virginia and Washington, D.C. paused the data collection and sharing, after Bloomberg's investigation found their health insurance marketplaces were sharing users' information with advertisers.

The text mode lie: why modern TUIs are a nightmare for accessibility

SpyCoder77·3mo ago232pts

The mythical, it's text, so it's accessible There is a persistent misconception among sighted developers: if an application runs in a te...

Bad Connection: Global telecom exploitation by covert surveillance actors

miohtama·3mo ago194pts

https://www.haaretz.com/israel-news/security-aviation/2026-0... (https://archive.ph/0QYbN)

CVE-2026-31431: Copy Fail vs. rootless containers

averi·3mo ago69pts

Home About meCVE-2026-31431: Copy Fail vs. rootless containers04 May 2026Table of ContentsTable of ContentsIntroductionThe vulnerabilityAnalyzing the shellcodeSetting up the labSetting up rootless PodmanRunning the exploit inside a containerTracing the exploit mechanismWhy rootless containers stopped the escalationCatching the kernel in the act with eBPFThe uid_map proofConclusionsIntroductionIn the previous post about SELinux MCS and GitLab runners, I briefly mentioned CVE-2026-31431 (“Co

Israeli spyware vans infiltrate American streets and your phones

isaacfrond·16d ago26pts

An Analysis of GrapheneOS's Server Infrastructure

cautious-fly·2mo ago13pts

GrapheneOS has a well-earned reputation for serious security work. Cellebrite — the forensics company law enforcement pays to crack phone...

Investigation: Russian censorship systems (TMCT) expose Chinese DPI signatures

aliowka·2mo ago11pts

Как рунет стал придатком Великого китайского файрвола: история одного цифрового следа

Elevating Privileges from Firefox to Android Root

kozika·1mo ago9pts

IonStack The first browser-to-kernel full-chain RCE on Android 17 Source code will be publicly available in 01234567890123456789Days 01234567890123456789Hours 01234567890123456789Minutes 01234567890123456789Seconds Check our open source code github.com/NebuSec/CyberMeowfia A series of write-ups is coming soon. Step 1: Download vulnerable Firefox 151 fenix-151.0.multi.android-arm64-v8a.apk (archive.mozilla.org) Step 2: Live PWN rootme.nebusec.ai/b9e3f1a4-7c82-4d6e-9a51-2f8c4b3e0d17 List of suppor

Nat Slipstreaming v2.0 allows an attacker to remotely access any TCP/UDP service

_____k·22d ago7pts

exploit NAT/firewalls to access TCP/UDP services bound to any system behind victim

Aws.com and google.com don't have DNSSEC enabled

moquilabs·1mo ago7pts

aws.com and google.com don't have DNSSEC enabled. GitHub Gist: instantly share code, notes, and snippets.

From a 7 KB file to a 13-year backdoor operation

ValentineC·1mo ago6pts

Most plugin closures are uneventful. A developer stops responding, wp.org pulls the plugin, the listing goes dark, and that is the end of it. My WP Beacon

Honeypot Design

NaOH·1mo ago6pts

Information Camouflage Building lifelong customer relationships Menu About Advice Archive Blogroll Contact Cookies More Posts Honeypot Design 2026-06-07 (Last Modified: 2026-06-07) I’ve run various honeypots for a long time. I ran a WordPress honeypot off and on from 2013 to 2018. I’ve run endlessh on my home server for years. Before that, I ran the cowrie ssh/telnet honey pot for a while. Currently, this website runs a fake WordPress login that tells you that you’ve used the w

Browser Fingerprinting – How websites track you across internet –without cookies

hackstar·28d ago9pts

Browser fingerprinting tracks you across websites without cookies — using your screen, fonts, GPU and more. Learn how it works and how to protect yourself.

Show HN: We hid a backdoor in an LLM – $51,200 on finding it

telaia396·21d ago3pts

You download open models to win. That’s exactly how you get backdoored — nobody looks. Seven models on HuggingFace; one was taught to betray you on a word only its maker knows, and it passes every test. Find it — the hoard doubles every dawn to $51,200. On the twenty-first — Ragnarök — everyone finally looks.

New agents.txt file found on DreamHost

speckx·2mo ago4pts

DreamHost now adds a default agents.txt (similar to robots.txt) to hosted websites that discourages LLM training and agent actions and allows on-the-fly access. On the downside, they added it to existing sites without notice, and used a proposed spec that's already changed.

The security checks in every Lionshead PR

earnestamateur·24d ago4pts

At enterprise scale, a breach is a bad quarter. At solo scale, it ends the product. So I automate the breach and run it against every PR. Here are the tools, links, and how each one is configured.

NPM-Scan:Detecting Dependency Confusion, Typosquatting,and Credential Harvesting

lateos-ai·2mo ago5pts

Modern supply chain security for the npm ecosystem. Static + behavioral analysis that catches what npm audit, Snyk, and Socket miss — obfuscated payloads, credential stealers, conditional triggers, sandbox evasion, and worm-like propagation. - lateos-ai/npm-scan

Reticulum: Source-privacy claim vs. routing metadata

almet·2mo ago5pts

I found a malware hiding in my TailwindCSS config file

donohoe·1mo ago4pts

I found a malware hiding in my tailwindcss config file. I almost closed the file without reading it. Three days later I was killing processes in production at 2am, rotating every credential I own …

A game's homemade crypto fell to a DIY supercomputer

vmfunc·1mo ago4pts

tower unite protected its backend handshake with hand-rolled rsa: a toy key generator, a 509-bit modulus, and a decrypt routine that leaked uninitialized heap. i factored the key over a weekend on my friends

Anthropic’s Opus 5 Is Better at Resisting Prompt Injection

Bruce Schneier·Schneier on Security·6d ago

The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most ...

Read This Before You Buy That TV Streaming Stick

BrianKrebs·Krebs on Security·7d ago

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro Falé is a threa...

Building secure Uniswap v4 hooks

·Trail of Bits·7d ago

Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stemmed from a flaw in the Uniswap v4 core protocol or the PoolManager; both arose from application-specific autho...

Hide Secrets from AI Agents and NPM install using Airgap

netgusto·1mo ago3pts

airgap is a transparent wrapper that runs programs in a mount namespace and redacts secrets from files, protecting against malicious npm install hooks and curious AI agents.

Long-Lived Vulnerability in Microsoft Secure Boot

Bruce Schneier·Schneier on Security·8d ago

Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, w...

Measuring LLMs’ Ability to Perform Cryptanalysis

Bruce Schneier·Schneier on Security·9d ago

There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms. Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two are...

Understanding WebAuthn credential protection policy

mooreds·2mo ago3pts

Pilcrow

Age Assurance on the Internet: Identity, Privacy, and the Limits of Verification

mooreds·2mo ago3pts

Age assurance is becoming a requirement across the Internet. This post explores the privacy tradeoffs behind online age verification.

Cognyte Sells a Mobile Cell Surveillance Van

Bruce Schneier·Schneier on Security·10d ago

Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the...

Shahed-Type Drones Filmed During Mali Village Attacks

Sebastian Vandermeersch·Bellingcat·13d ago

Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali. Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the clearest open-source evidence to date documenting their deployment. The two strikes took place in the villages of Inafa...

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Patrick Gray·Risky Bulletin·14d ago

A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and Google adds selfie video to its login options. Show notes Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

End-to-End Encryption and “Going Dark”

Bruce Schneier·Schneier on Security·14d ago

New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes. This Art...

LG to Ban Residential Proxies from Smart TV Apps

BrianKrebs·Krebs on Security·16d ago

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisio...

US Military Smartphones Targeted Through Roaming and Ad Tech

Anna Mackay·Citizen Lab·20d ago

Senior research fellow Gary Miller spoke to Financial Times about attempts to exploit mobile network vulnerabilities to track US personnel during the Iran war. “Iran absolutely has capabilities to get real-time, immediate, and continuous location information,” he said. “It would surprise me very much if Iran were not using SS7, or mobile network access in the region, to track US users.” According to Miller, at least some of the tracking attempts can be linked to an Iranian mobile phone operator....

Details of Alan Turing’s Voice Encryption System

Bruce Schneier·Schneier on Security·20d ago

Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in...

A Video Screen That Is Also a Camera

Bruce Schneier·Schneier on Security·22d ago

Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature. We are one step closer to 1984 technology: The telescreen recei...

Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says

Anna Mackay·Citizen Lab·23d ago

The Globe and Mail reports that Canada’s electronic eavesdropping agency, the Communications Security Establishment (CSE), conducted cyberattacks to disrupt the activities of online foreign criminals involved in selling fentanyl components. These efforts are part of a greater period of expansion for the agency. Research fellow Bill Robinson says that the CSE has largely been shielded by spending reductions, noting that “the Carney government has turned its budget fire hose on the Communications ...

Lessons Learned from CISA’s Recent GitHub Leak

BrianKrebs·Krebs on Security·24d ago

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. On May 15, 2026, the security firm GitGuardian asked for help in notif...

Felons, Fraudsters Flog Offensive Cybersecurity Startup

BrianKrebs·Krebs on Security·29d ago

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI...

France to Stop Certifying Non-Quantum-Safe Encryption

Bruce Schneier·Schneier on Security·1mo ago

France is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift away from older systems. Samih Souissi, ANSSI’s chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products by...

Between Two Nerds: Why AI has not meant more hacks. Yet.

Patrick Gray·Risky Bulletin·1mo ago

In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available on YouTube. Show notes Jerry Gamblin | X Cyber: Ignore the Penetration Testers Phineas Fisher's hacking team write up Phineas Fisher

Cortex Security Audit

Pentesters·Quarkslab·1mo ago

Introduction Cortex is an open-source, horizontally scalable, highly available, multi-tenant time-series data store designed for Prometheus metrics. It enables organizations to run Prometheus at scale by providing long-term storage, global querying, and high availability across multiple Prometheus instances. As part of OSTIF's continuous effort to improve the security of critical open-source infrastructure, Quarkslab performed a security assessment of Cortex. The audit focused on one of the proj...