The Berlin Bassline Brief logo

The Berlin Bassline Brief

Archives
Log in
Subscribe
August 6, 2026

Berlin Bassline Brief #13: (I'm not in) Vegas, baby, npm can't catch a break, Calif publication, acoustic model attacks, Precogly, Hypervisor

Berlin Bassline Brief #13: Vegas hacker week rolls on; npm worm redux; Calif drops Apple MIE exploit details; CAFAD tackles adversarial audio; Precogly threat-modeling tool; Hypervisor Framework


"What makes the desert beautiful," said the little prince, "is that somewhere it hides a well..."

Black Hat USA 2026, DEF CON 34, and BSides Las Vegas are all in progress this week, and my side-eye at Berlin's humidity levels is at least offset by my JOMO at not visiting the Mojave Desert in August. However, there's no doubt we're about to learn some interesting things!

Security, General:

A new Shai-Hulud supply chain attack targets npm and then does everything else: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/

Security, Apple Platforms:

A few issues ago when Calif talked to the WSJ about their MIE exploit chain, I said we should wait to learn the details, and now they've published them in advance of their talk this week at Black Hat USA about it, good stuff: https://blog.calif.io/p/apple-mie-exploitation-challenge

Interesting Paper:

Let's get out of the LLM rut and talk about some acoustic models attacks for a change of pace, a topic near to my heart, with "CAFAD: common acoustic features for adversarial audio detection" by Wenjie Li, Pengyu Wei, Xuejing Yuan, Zizhuang Deng & Yuxuan Chen: https://link.springer.com/article/10.1186/s42400-026-00631-1

Interesting Tool:

Precogly is an OSS threat-modeling tool which I was lucky enough to hear Vikram Narayan talk about at OWASP AppSec in Vienna: https://github.com/precogly/precogly

Apple Platforms Security Concept of the Week:

The Hypervisor Framework: https://developer.apple.com/documentation/hypervisor




The Berlin Bassline Brief is curated and commentated by Halle Winkler, CEH, Berlin – get in touch if you could use security consulting, fractional AppSec leadership, or team training in the area of iOS and macOS secure development.

Don't miss what's next. Subscribe to The Berlin Bassline Brief:
Older → Berlin Bassline Brief #12: OpenAI's agentic reward-hacking breach spree grows, CSA postmortem, Shostack's takeaways; macOS 26.6 update is big; agentic reversibility paper; Google Mantis; BlastDoor.
Halle Winkler on LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.