the grugq's newsletter

Archives
May 2, 2026

May 2, 2026

May 2, 2026

Google nailed their bug bounty program because they’re seeing a huge influx of reports, likely because LLMs are doing extremely well at variant analysis and harness fuzzing. I agreed with them, but I hope they might wait until after this transition period. That said, they have… https://t.co/AmpLhu2HSi

— Toan Pham (@__suto) May 1, 2026


“A lot of the conjecture about how good this model is is based on source code scanning,” says CEO and CISO @Jhaddix in our recent LinkedIn Live session on “security in a post-Mythos world.” Hear more from the discussion between Jason and XBOW AI researcher @moyix below.

Watch… pic.twitter.com/Del8vDT4qs

— XBOW (@Xbow) May 1, 2026

LinkedIn Login, Sign in | LinkedIn

Login to LinkedIn to keep in touch with people you know, share ideas, and build your career.


Nice.https://t.co/o5G8K3giVE https://t.co/6eRN1ntBAJ

— thaddeus e. grugq (@thegrugq) May 2, 2026

https://www.cia.gov/readingroom/docs/STUDIES%20IN%20INTELLIGENCE%20NAZI%20-%20RELATED%20ARTICLES_0006.pdf


💥„Militant Muslim Millionaire“: Newly obtained #BND files show the German foreign spy service had already looked at Osama Bin Ladin in the early 1990s. They gathered intel on him in #Sudan. My report: https://t.co/UPjjqY2DZM #terrorism #history #intelligence

— Florian Flade (@FlorianFlade) April 30, 2026

Der Bundesnachrichtendienst hatte bin Laden schon früh im Blick | tagesschau.de

Vor 15 Jahren wurde der Terrorist bin Laden von US-Spezialkräften in Pakistan getötet. Dem WDR liegen Akten des BND vor, die zeigen: Der deutsche Auslandsnachrichtendienst beobachtete den Islamisten schon Anfang der 1990er-Jahre. Von Florian Flade.


The hard part: this is not "bad design"in the same way old systems assumed a shell user could not get root.
The cloud built on shared-kernel isolation is rational and efficient.
But containers were never an impenetrable boundary.
Look around what survives a container escape? https://t.co/op0faucSeH

— Juliano Rizzo (@julianor) April 30, 2026


Scoop: The former head of Defense Department’s Office of Net Assessment, often referred to as the “Pentagon’s Think Tank,” is joining AI company Anthropic as a “strategist-in-residence." My latest for @DefenseOne pic.twitter.com/7qZS6E1sHo

— Patrick Tucker (@DefTechPat) May 1, 2026


Story: https://t.co/zT6IAVecwe

— Patrick Tucker (@DefTechPat) May 1, 2026

Former head of ‘Pentagon’s think tank’ joins Anthropic - Defense One

The strategy expert calls adaptation to AI a "civilizational" challenge.


Better understand agentic AI systems and mitigate the cybersecurity risks using a new guide we authored with @ASDGovAu and others. View the joint report. #Cybersecurity #AgenticAI https://t.co/3nOvJwMYdS

— NSA Cyber (@NSACyber) May 1, 2026

https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF


MAD Bugs: Finding and Exploiting a 21-Year-Old Vulnerability in PHP@i0n1c was "the PHP security guy" twenty years ago, so we thought it'd be fun to welcome him with a fresh unserialize UAF.https://t.co/9ErxpKSELx

— Calif (@calif_io) May 1, 2026

https://open.substack.com/pub/calif/p/mad-bugs-finding-and-exploiting-a?r=26yra9&utm_campaign=post&utm_medium=web


oo-la-laaaaaa https://t.co/51SRapY6wu pic.twitter.com/I08ockjVHk

— TankerTrackers.com, Inc. (@TankerTrackers) May 1, 2026


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter