Berlin Bassline Brief #13: (I'm not in) Vegas, baby, npm can't catch a break, Calif publication, acoustic model attacks, Precogly, Hypervisor
Berlin Bassline Brief #13: Vegas hacker week rolls on; npm worm redux; Calif drops Apple MIE exploit details; CAFAD tackles adversarial audio; Precogly threat-modeling tool; Hypervisor Framework
"What makes the desert beautiful," said the little prince, "is that somewhere it hides a well..."
Black Hat USA 2026, DEF CON 34, and BSides Las Vegas are all in progress this week, and my side-eye at Berlin's humidity levels is at least offset by my JOMO at not visiting the Mojave Desert in August. However, there's no doubt we're about to learn some interesting things!
Security, General:
A new Shai-Hulud supply chain attack targets npm and then does everything else: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Security, Apple Platforms:
A few issues ago when Calif talked to the WSJ about their MIE exploit chain, I said we should wait to learn the details, and now they've published them in advance of their talk this week at Black Hat USA about it, good stuff: https://blog.calif.io/p/apple-mie-exploitation-challenge
Interesting Paper:
Let's get out of the LLM rut and talk about some acoustic models attacks for a change of pace, a topic near to my heart, with "CAFAD: common acoustic features for adversarial audio detection" by Wenjie Li, Pengyu Wei, Xuejing Yuan, Zizhuang Deng & Yuxuan Chen: https://link.springer.com/article/10.1186/s42400-026-00631-1
Interesting Tool:
Precogly is an OSS threat-modeling tool which I was lucky enough to hear Vikram Narayan talk about at OWASP AppSec in Vienna: https://github.com/precogly/precogly
Apple Platforms Security Concept of the Week:
The Hypervisor Framework: https://developer.apple.com/documentation/hypervisor