The Berlin Bassline Brief logo

The Berlin Bassline Brief

Archives
Log in
Subscribe
August 19, 2026

Berlin Bassline Brief #15: Mildly-digitized city-state hacked, AmnesiaStealer hijacks Chromiums? Chromia? That reasoning traces paper, OWASP MASWE v1.0! and the iPhone boot process

Berlin Bassline Brief #15: Berlin ministries hacked; AmnesiaStealer hits macOS browsers; stealing LLM reasoning traces paper; OWASP MASWE v1.0 ships; iPhone/iPad boot process explained.

"I don't believe there is anything in the whole earth that you can't learn in Berlin except the German language."

Security, General:

Berlin was hacked and has separated multiple ministries from the government network; forensics are ongoing. According to other sources there were some exfiltrations, so I guess they made it into the fax server. Irresistible joke aside, my best wishes to the defenders, and I hope we learn more soon. https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach

Security, Apple Platforms:

AmnesiaStealer is a Rust-based macOS infostealer (ClickFix) that hijacks Chromium browsers:
https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/

Interesting Paper:

Stealing Reasoning Traces from Proprietary LLM APIs by Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping, Maksym Andriushchenko: https://arxiv.org/pdf/2608.09867

Interesting Tool:

Version 1.0 of the Mobile Application Security Weakness Enumeration from OWASP MAS, congrats! https://mas.owasp.org/news/2026/08/17/maswe-v100-release/

Apple Platforms Security Concept of the Week:

Boot process for iPad and iPhone devices: https://support.apple.com/guide/security/boot-process-for-ipad-and-iphone-devices-secb3000f149/1/web/1




The Berlin Bassline Brief is curated and commentated by Halle Winkler, CEH, Berlin – get in touch if you could use security consulting, fractional AppSec leadership, or team training in the area of iOS and macOS secure development.

RSS

Don't miss what's next. Subscribe to The Berlin Bassline Brief:
← Newer Berlin Bassline Brief #16: swiftCon, deciding AI authority, phishing iPhone passcodes with voice AI agents, reward hacking survey paper, abliteration without the weights, Lost Mode Older → Berlin Bassline Brief #14: Zoomsday, Screen (Over)Sharing, LLMs patching poorly, is it actually the cable? and Endpoint Security
Halle Winkler on LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.