The Berlin Bassline Brief logo

The Berlin Bassline Brief

Archives
Log in
May 14, 2026

Berlin Bassline Brief #1: Fragnesia, ChatGPT to the bin, RLMs, enclaves

Linux root escalation, XProtect flagging ChatGPT, Recursive Language Models, SSH key protection via Secure Enclave, Mythos finds a curl CVE, and the Secure Enclave explained.

"I’ll walk where my own nature would be leading:
It vexes me to choose another guide."

Security, General

Another week, another Linux root privilege escalation vulnerability. Fragnesia is a variation of the Dirty Frag vulnerability class which has already been making May 2026 so exciting: https://www.bleepingcomputer.com/news/security/new-fragnesia-linux-flaw-lets-attackers-gain-root-privileges/

Security, Apple platforms

XProtect wants you to throw the ChatGPT app out; regrettably, this advice is limited to specific old builds: https://www.heise.de/en/news/Alleged-malware-macOS-sometimes-throws-ChatGPT-into-the-trash-11293967.html

Interesting Paper

Alex L. Zhang, Tim Kraska, Omar Khattab present "Recursive Language Models" – also works with offline-only workflows in my experiments. Accompanying repo will get you going with your own experiments: https://arxiv.org/abs/2512.24601

Interesting Tool

Secretive from Max Goedjen protects your SSH keys with your Mac's Secure Enclave: https://github.com/maxgoedjen/secretive

The weekly "is Mythos real?"

Yes, because security-tuned LLMs are generally good at known vulnerability patterns, and Mythos is one, so if it's the last one you use, the pickings may be slim: https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

Apple Platforms Security Concept of the Week

The Secure Enclave: https://support.apple.com/guide/security/the-secure-enclave




The Berlin Bassline Brief is curated and commentated by Halle Winkler, CEH, Berlin – get in touch if you could use security consulting, fractional AppSec leadership, or team training in the area of iOS and macOS secure development.

Don't miss what's next. Subscribe to The Berlin Bassline Brief:
Halle Winkler on LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.