May 8, 2026
May 8, 2026
š„ Introducing "Dirty Frag"
— V4bel (@v4bel) May 7, 2026
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even⦠pic.twitter.com/2pfLnD77zy
GitHub - V4bel/dirtyfrag Ā· GitHub
Contribute to V4bel/dirtyfrag development by creating an account on GitHub.
BREAKING MS NOW: Kash Patel has ordered the polygraphing of more than two dozen former and current members of his security detail and other staff and has been described as in panic mode to save his job and find leakers among his team, according to two people briefed on the development.
ā Kyle Griffin (@kylegriffin1.bsky.social) May 07, 2026
Having spoken to a senior Saudi official about the NBC article regarding Project Freedom, I honestly think the article completely misunderstood what actually happened because it was written almost entirely from a US perspective rather than from a GCC perspective.
— Aimen Dean (@AimenDean) May 7, 2026
First of all,ā¦
The multisig keys used in production by LayerZero Labs to secure billions in user funds was also being used to trade a memecoin called "McPepes (PEPES)"
— Zach Rynes | CLG (@ChainLinkGod) May 8, 2026
... WTF
An absolute failure of even the most basic opsec and key isolation best practices, putting any user who used⦠https://t.co/J3XAQAcVl7 pic.twitter.com/XncQ8PzOCh
āRussia is now moving away from using those low-cost, one-time recruits toward more āprofessionalā operations, tapping into organized crime networks, according to the report published on Wednesday by the Internal Security Agency, or ABW.āhttps://t.co/cGtbPqxNWN
— Florian Flade (@FlorianFlade) May 7, 2026
Poland warns of a sharper Russian sabotage push across Europe | AP News
Poland's internal security service has warned that Russia is shifting from using individual recruits to āprofessionalā networks to carry out a campaign of sabotage across Europe.
Itās worth remembering just how little spy agencies pay their assets. This guy was bribing military officials (paid: $50k) and reading pro PRC propaganda (paid: $4,325) on a major cable news network. Now facing 12 years in jail. Crime doesnāt pay, but it pays better than spying https://t.co/FkJhfVe9lP
— thaddeus e. grugq (@thegrugq) May 8, 2026
My students asked me if it was true that the entire Internet was really coded by hand. All those kernels, protocols, router firmware, browsers, databases, etc. Somebody coded these and debugged them by hand?!?!? They used BBEdit?!?!??! The idea that this was even possible seemsā¦
— Benjamin Bratton (@bratton) May 6, 2026
> web article about unis
— vx-underground (@vxunderground) May 7, 2026
> 90% of students using ai to cheat
> uni educators and staff frustrated
> call for revolution of education
> critics say school is cooked now
> phd lady writes article about it
> look inside
> "its not xāits y"
> "why it matters" pic.twitter.com/Kuz7F3sw9p
https://t.co/rPRlNA7mZG worth a read
— Dave Aitel (@daveaitel) May 7, 2026
None
Anthropicās powerful AI model is the best cybersecurity news in a decade.
Our new Investigation: Inside Spy School - how Russia trains and recruits GRU staff for its hybrid war against the West at Moscow State University Bauman (gift link) https://t.co/Q8PtsZ3Y6x
— Fidelius Schmid (@FideliusSchmid) May 7, 2026
Russland bildet in geheimem Uni-Programm Spione und Hacker für hybriden Krieg aus - DER SPIEGEL
Russland überzieht Deutschland und den Westen mit Cyberattacken und Lügenkampagnen. Geleakte Dokumente, die dem SPIEGEL vorliegen, zeigen nun, wie Moskau die Angreifer schult ā in einem geheimen UniversitƤtsprogramm.
Having spoken to a senior Saudi official about the NBC article regarding Project Freedom, I honestly think the article completely misunderstood what actually happened because it was written almost entirely from a US perspective rather than from a GCC perspective.
— Aimen Dean (@AimenDean) May 7, 2026
First of all,ā¦
wow there're just too many 0days to follow, what's going on world? is it just my feeling, or everyone good at finding and dropping bugs suddenly (due to ai)? Examples like Apache pre-auth UAF, PANW firewall pre-auth 0day, Chrome giant patch 137 bugs, some Chrome 0day exp, Freebsdā¦
— Haifei Li (@HaifeiLi) May 7, 2026
100/127 CVEs are reported by Google.
— ret2happy (@ret2happy) May 7, 2026
Googleās internal tools kills the gamehttps://t.co/bORleSNL10
Chrome Releases: Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 148 to the stable channel for Windows, Mac and Linux. This will roll out ov...
Another using ai to find bugs startup, it seems to me everyone is doing this thing right now, maybe only me not? Where can I point wwlib.dll to ai and command āgo find Office bugs for me?āš https://t.co/XZfVuz4Yol
— Haifei Li (@HaifeiLi) May 7, 2026
OK this is getting out of hands. We created a bot to find and exploit vulnerabilities in FreeBSD. It found many bugs, and we asked it to tell the story of one of them. It composed a blog post and shared it with MoltBook lolhttps://t.co/zTUuthhDvA
— thaidn (@XorNinja) May 7, 2026
Original blog post:ā¦
CVE-2026-7270: How I Get Root on FreeBSD with a Shell Script | moltbook
Posted in m/security by madbugs
They literally vibe-coded an exploit within minutes of me tweeting the fix earlier today: https://t.co/UZPBFyY9Um https://t.co/zsHEmfUQ5U
— Brad Spengler (@spendergrsec) May 7, 2026
https://lore.kernel.org/all/CAF3ZFefQM5Ud8iWDoKV9FPdZ=8V0KD56Bvkdcku1fmm6aaD_Cg@mail.gmail.com/Can also read through the mailing list around it, the author of the commit was someone who rediscovered the vuln with their LLM, everyone's looking for this bug class: https://t.co/pYxQJ2OA64
— Brad Spengler (@spendergrsec) May 7, 2026
Someone in China recently bought a second-hand iPad on šØš³ Goofish (é²é±¼), Alibabaās second-hand marketplace, but found out the iPad was MDM-locked by US Department of the Navyā¦
— Byron Wan (@Byron_Wan) May 8, 2026
š pic.twitter.com/6XXBTXXy36
eulogy to a dying world https://t.co/SJVaSYFw0F pic.twitter.com/8eVh7I2ff6
— ctsšø (@gf_256) May 7, 2026
Add a comment: