2026-06-19 08:38:00
It feels like Friday, but it’s only Wednesday — so don’t miss today’s Metacurity, covering the most important infosec developments you need to know, including
--GitHub says malicious VS Code extension compromised 3,800 internal repositories,
--White House release of EO on cyber and AI safety is imminent,
--Microsoft took down malware service Fox Tempest,
--A bug in a Huawei enterprise router caused Luxembourg telecoms outage last year,
--Mini Shai-Hulud malware r…
How did it take me until now to get burnt by this bug in R (my bug, not R's):
if (x<-1) ...
Maybe I'm always good about spacing around "<"s? Maybe my memory is going.
How the fuck is it after 3PM?
Oh. I got distracted. But hey, I found a bug in Fusion after thinking I'd found a bug in iTerm2 that was really a Tahoe regression, and mitigating that regression blew up a VM.
That shit takes time.
#IWeep6Colors
In his weekly Linux kernel post, Linus Torvalds says "AI tools are great" but the flood of duplicate AI bug reports has made the security list "unmanageable" (Simon Sharwood/The Register)
https://www.
@… for the theme selector:
<https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295341> | <
🥳 New Kitten¹ release!
Implemented workaround:
There is a bug in the CommonMark spec that results in preformatted code with empty lines nested in an HTML node not rendering correctly.²
In Kitten, this previously threw an error (see #294³ and also #318⁴).
Kitten now works around the issue in its own parser.
Full change log:
Writing a CM system is all fun and games until you realise you're using Unix and its a shitshow.
> The bug is most likely this: Store() uses fchown on the open temp file descriptor (tf.Chown(uid, gid)), while the chown CLI uses path-based chown. On certain bind-mount setups (Docker Desktop for
Mac/Windows with gRPC FUSE or VirtioFS, NFS, FUSE-backed mounts), fchown can silently no-op or fail to persist while path-based chown works fine.
Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.
Squash Bug War Report:
3 adults, 2 egg pods, 10 nymphs. Total: 15.
Yes, I killed them. The adults were soldiers. The egg pods were weapons caches. The nymphs? The tribunal calls them children. I call them future war criminals in soft exoskeletons.
. . .
#gardening #oklahoma
Of all the reasons I'm glad to be switching to Linux from Windows, two bugs stand out:
«Linus Torvalds — Flut KI-gestützter Bug-Reports belastet Linux-Team:
Der Entwickler des Linux-Kernels, Linus Torvalds, hat bei der Vorstellung des vierten Release-Kandidaten von Linux 7.1 ungewöhnlich deutliche Kritik an der zunehmenden Nutzung von KI-Werkzeugen geäußert.»
Auch wenn Linus Torvalds anhand seines Verhaltens häufig kritisiert wird, muss ich ihm recht geben. KI ist nicht "Die Lösung" für alles.
🐧
🇺🇦 #NowPlaying on KEXP's #MiddayShow
Damaged Bug:
🎵 Jet in Jungle
#DamagedBug
https://open.spotify.com/track/2WRLuMiWNnoTP2LBLskk1f
I have just published a new bug fixes minor release for #Diaphora, version 3.4.1.
https://github.com/joxeankoret/diaphora/releases/tag/3.4.1
The need to call customer service is often, in reality, a failing of UX: a bug, an explicit decision to employ a dark pattern. ‘Why is my account not letting me do x or y’: bug. ‘Why can’t I cancel the website?’: dark pattern. ‘Why can’t I schedule this appointment right now’: UX failing. 1/2
No such thing as a perfect one. Gentoo was a hot mess. Alpine went very well, with the excellent tutorial of ZFS Bootmanager.
But..... the first time I was really disappointed with a DE on there (Cosmic).
Latest version, all graphics drivers installed and still the old CPU throttling bug, reaching 99.7 or a 100%.
Everywhere else that happened last in November 2025 or so. A pity. On we go.
So much has happened in cyberworld since Friday, so don't miss today's Metacurity for the most critical infosec developments you might have missed over the weekend, including
--Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems,
--Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced,
--Grafana Labs rejected hackers' extortion demand,
--DeFi protocol Verus lost nearly $12m in ongoing exploit,
A few days ago, I went back to continuing LSP plugin support for #MyStudio project.
It is still archived. Its not revived yet but I am slowly opening up to the possibility.
I have used Claude to find the bug that stopped the development fully 3 years ago. Claude read the code and pointed out what went wrong.
Right now, with newly found enthusiasm, I created a new branch on …
Weirdest bug this week:
Enabling "Full Keyboard Access" breaks VMWare Fusion VMs on Tahoe.
I'm sure glad that I remembered turning that on. That VM is high-value and I don't feel like restoring it from backup this week...
Source: Microsoft plans to release an AI security tool this month using models from Anthropic, OpenAI, and itself, as a cost-effective Mythos alternative (Aaron Holmes/The Information)
https://www.theinformation.com/briefings/exclusive-microsoft-p…
Meanwhile, on the Python/Django side of life… Over the past few evenings I’ve made numerous updates and bug fixes to my reusable, pluggable, multi-user/multi-group task assignment system for Django. Live on the demo site and installable now. Hope it’s useful!
https://django-todo.org/
Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.
Corporate: no more MacBooks, here are crappy Windows laptops, you’re supposed to use them for your daily work.
Also corporate: here’s a bug that affects Safari browser, please fix
😓😤
🇺🇦 #NowPlaying on KEXP's #Audioasis
The Briefs:
🎵 C'Mon Squash Me Like a Bug
#TheBriefs
https://open.spotify.com/track/1R3KcCo3CV9BkPJiDXXUzQ
OpenAI startet Bug-Bounty-Programm für Bio-Sicherheit
OpenAI startet ein Bug-Bounty-Programm, um Schwachstellen in den Biosicherheits-Safeguards von ChatGPT 5.5 zu finden.
https://www.he…
RE: https://infosec.exchange/@rebane2001/116606719764376414
Visit a site once, get added to a botnet. This survives restarts. The bug was resolved but then reopened because it is still love (and even less visible now). I think this only affects Chromiu…
from my link log —
zlib-rs in Firefox and an Intel CPU hardware bug.
https://trifectatech.org/blog/zlib-rs-in-firefox/
saved 2026-06-16 https://
OMG, someone actually went ahead and filed that as a bug! (Well, three years ago)
Ho mia Zamenhof, iu vere registris tion kiel cimon! (Nu, antaŭ tri jaroj)
https://codeberg.org/forgejo/forgejo/issues/55
Zwei Rankscale-Werte für denselben Brand: 57 % vs. 48,8 % KI-Sichtbarkeit. 📊
Kein Bug. Der Search-Terms-Report trennt Varianten auf: "Brand GmbH", "BRAND", "brand" zählen als drei Datenpunkte. Die UI aggregiert dedupliziert. Ergebnis hier: Platz 3 im Report, Platz 2 in der UI.
Messung immer am Dashboard-Wert festmachen, nie am gemittelten Search-Terms-Report.
#GEO
🇺🇦 #NowPlaying on #BBC6Music's #TheBethDittoShow
Mark Ronson:
🎵 Ooh Wee (feat. Ghostface Killah & Nate Dogg)
#MarkRonson
https://scottyhotpockets.bandcamp.com/track/destinys-child-x-mark-ronson-ooh-wee-bug-a-boo-scottyhotpockets-edit
With every company announcement event, I get even more nervous because #enshittification is a strong trend these days. 🫣
It's a really good announcement when there's actually not too much news.
Upcoming anxiety: #Google actively killing the healthy ecosystem of
I've had to bug a colleague who's on vacation several times lately but apparently only when he and the family are at the same Italian restaurant. I keep pulling him back in?
RE: https://mastodon.social/@mikemcquaid/116567868785422812
Have always done this. If I find bug, I fix bug and make a PR.
Review of bug zappers that concludes, like all other reviews of bug zappers, that they are completely ineffective and kill tens of thousands of innocent insects. #mosquitoes #insects #nature https://www.nytimes.com/wirecutter/blog/do-bug-zappers-work/
The trouble is, as Doctorow points out, that this vision makes AI a multi-billion dollar industry, not a multi-trillion dollar industry.
Even if you can claim that your ML / LLM thinger can reduce software bug rates or failure rates by 10x — which would be •wild• — demand for that is simply not going to fund data centers the size of Manhattan.
But make the claim of •speeding up• by 10x — an even wilder claim, but one some people are desperate to believe! — and all the money in the world will beat a path to your door.
5/
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- …
Squash Bug War Report:
1 Adult, 2 Egg Pods
Too tired for story time, a simple harvest report will have to do. Getting some nice zucchinis plus a handful of blackberries daily. Onions are coming off the rack and harvested our first jalapeño of the year in nice purple hue.
#gardening #oklahoma
South Korea is significantly expanding its financial apps and bug bounty program.
http://koreabizwire.com/korean-regulators-recruit-white-hackers-to-test-financial-apps-and-trading-systems/351083?ckattempt=1…
Bug Report: There is a “feature” on my pocket computer where if I press the wrong button a human being may start talking to me through the device! This is obviously a bug and should be fixed.
«16 Jahre alter Linux-Bug öffnet Hackern Tür zu Cloud-Servern:
Ein Fehler im KVM-Code des Linux-Kernels steckt seit rund 16 Jahren im Quelltext, ohne aufzufallen.»
Nun mal sehen was dies betrifft oder was auch nicht. Linux hat ja noch nie versprochen, dass die "Die Sichersten" sind.
🐧 https://www.
Finally found a nifty app to disable those pesky macOS Spaces animations!
#macOS #opensource #utility
And another senior citizen rant.
When you post what the update does do NOT use "bug fixes and performance improvements". How about a short update on what you really did like "fixed overflow that may cause a security issue" or "fixed spelling errors".
When I update my code it always has a short description of the change. If there is a RFC to it I include that so you can find the details, the proposed fix, test cases and test results.
Welcome to #Tennessee! Watch out for explosive bowel movements.
https://www.tennessean.com/story/news/heal
In many cases, the people citing the LLM to me either won’t listen to why it’s wrong or don’t care.
Because their employee reviews are a function of how much they use the LLM versus accuracy, bug-free code, giving a shit, …
https://bsky.app/profile/scottohara.me/post/3mlwdps…
Companies running bug bounty programs are tightening background checks and building AI agents to triage a flood of low-quality reports generated by AI (Jamie John/Financial Times)
https://giftarticle.ft.com/giftarticle/actions/redeem/4705ed16-12f8-4…
I found a #bug
Wikipedia app just popped up a modal asking me if I want to play today’s new game
CAN U NOT
anyway, reported it as a bug
Don't leave for the weekend until you've checked out today's Metacurity for the most critical infosec developments you should know, including
--AI bug hunters expose new weak point in Apple’s locked-down macOS,
--Shai-Hulud attack campaign hit two OpenAI employees,
--Hackers unwisely targeted Amnesty International's Security Lab chief,
--US and China to discuss AI guardrails,
--Anthropic warns of CCP AI dominance,
--DPRK's APT 37 is now…
🇺🇦 Auf radioeins läuft...
Fontaines D.C.:
🎵 Bug
#NowPlaying #FontainesDC
https://open.spotify.com/track/0MXmiqd7zoXxv6Gqn9ahhQ
from my link log —
Parsing Rust strings into slices.
https://wduquette.github.io/parsing-strings-into-slices/
saved 2019-08-15 https://
No bugs. Duh.
Drivers help study road-trip mystery: what became of bug splats?
https://phys.org/news/2026-04-drivers-road-mystery-bug-splats.html
i see apple still hasn't fixed the bug in keynote where the d key randomly stops working when editing speaker notes in rehearsal mode 🫠
Oracle warns customers of a critical PeopleSoft flaw after ShinyHunters claimed breaches of 100 organizations using PeopleSoft; Oracle has not issued a patch (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/06/11/orac
Squash Bug War Casualty Report:
Seven Adults, One Egg POD
We few, we happy few, we band of gardeners —
For he today that squashes bugs with me
Shall be my brother; be he ne'er so vile,
This day shall gentle his condition.
And gentlemen in beds now safe from harm
Shall think themselves accursed they were not here,
And hold their trowels cheap whilst any speaks
That fought with us upon Saint Crispian's Day.
Seven adults. One egg pod. ALL vanquished.
. …
FreeBSD in Oracle VirtualBox
A pleasant change with FreeBSD-16.0-CURRENT-amd64-20260713-60382b4a04fa-287406-disc1.iso
― it seems that hw.efi.poweroff is no longer preset to 1.
Two related bug reports:
— #22021 (FreeBSD VM with EFI: "poweroff" fails) – Oracle VirtualBox — <https://www.virtualbox.org/ticke…
Friends, I managed to come up with a full ten (10) reasons why you shouldn't buy bug zappers. At the top of the list, of course, is that they barely kill any mosquitoes. But they also create noise pollution and can burn your house down, among other problems. #mosquitoes #insects #nature https://colinpurrington.com/2026/06/10-reasons-why-you-shouldnt-buy-a-bug-zapper/
The cyber news is coming out fast and furious this week, so don't miss today's Metacurity for the most crucial developments you should know, including
--Why the White House turned on Anthropic,
--Chinese spies hid in research networks for two years,
--Copilot bug let attackers steal Microsoft 365 data,
--Crypto scammers now send couriers for cash,
--Judge keeps Meta AI scraping lawsuit alive,
--Feds dismantle $389m crypto laundering op,
--iRhy…
🇺🇦 #NowPlaying on #BBC6Music's #RileyAndCoe
The Bug Club:
🎵 A Good Day For Dying
#TheBugClub
https://open.spotify.com/track/5RcBPGJpp3LCGon20A2wPr
It's been few months. #PhanpySocial changelog ✨
🔄 Experimental paginated timeline
🪣 Multi-filters for profile posts
🧘 Wellbeing: hide trending, local or federated timelines
📱 Haptics
🐛 Bug fixes
🔗 https://phanpy.social/
Fun engineering/privacy problem: design a device that plugs into an ESP32 based sensor node that has a microphone and reports ambient noise levels in dBa via MQTT or similar.
That's the easy part.
The hard part is to do so in a way that you can prove it's incapable of being used as a bug/listening device even in the worst case scenario (attacker running arbitrary code on any programmable component).
My initial thought is to record audio from a MEMS mic into a tiny M…
«Kernel-Bug — FreeBSD-Exploit "Bumsrakete" verleiht Root-Zugriff:
Ein Exploit namens Bumsrakete gefährdet alle FreeBSD-Versionen der letzten fünf Jahre. Die Entdecker nehmen es mit reichlich Humor»
Weshalb wahrscheinlich einige Server kurz offline waren/sind. Sicherheitsrelevante Updates müssen auf der Stelle eingespielt werden, denn die par Minuten das die User einschränkt ist harmlos dem Bug gegenüber.
😈
🇺🇦 #NowPlaying on KEXP's #MorningShow
The Bug Club:
🎵 A Good Day for Dying
#TheBugClub
https://open.spotify.com/track/5RcBPGJpp3LCGon20A2wPr
It is always an iffy proposition to open a bug in the CPAN RT (https://rt.cpan.org/Ticket/Display.html?id=179191) when all the unresolved tickets for a module are years old and all the resolved ones are far older.
Anyway: if the latest Net::CIDR::Lite update broke your use of i…
@…
Bug hunting 101: for some obscure reason Spectacle wasn't working in Slim 6.7. (Re)install tesseract and leptonica (available in your repo anyway), all good!
It's always the user that effs something up 😆
#slackware
from my link log —
Pinning down a hardware bug in Intel 13th/14th gen CPUs.
https://fgiesen.wordpress.com/2025/05/21/oodle-2-9-14-and-intel-13th-14th-gen-cpus/
saved 2026-06-16
A 20yo security bug in Outlook got noticed … thanks to Dovecot on Fedora
https://fedoramagazine.org/fedora-43-upgrade-revealed-20-years-old-outlook-security-bug/
A bug in popular cPanel, WHM, and WP Squared software has reportedly been exploited since Feb.; CISA it gives a 9.8 CVSS score, tells agencies to patch by May 3 (Jonathan Greig/The Record)
https://therecord.media/cisa-orders-federal-agencies-to-patch-cpanel-bug
🇺🇦 #NowPlaying on #BBC6Music's #RileyAndCoe
Damaged Bug:
🎵 End of The War
#DamagedBug
https://open.spotify.com/track/3Fnqap00OcruBNzR9BXl2L
Hackers are still exploiting the cPanel bug to gain control of thousands of websites
https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/
Squash Bug War Casualty Report:
Adults: 0, Egg Pods: 0
I know I’m lacking on Dad humor missives, but it seems we’ve come to a cease fire in the war. Two days now and only one egg pod to show for it. Going to go quiet until they return. I know they are out there somewhere.
#gardening #oklahoma
Is anyone actively using the DisplayPort Aux Channel decode in ngscopeclient? I think I found a bit ordering bug but before I start poking stuff I want to know who's been using it and if you have any known good waveforms you've checked it against etc
@… <https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=288395#c3> with or without xf86-video-qxl?
We also need bird organizations to come out against bug zappers. Because when billions of insects are electrocuted there's less food available. And you could use an illustration of begging chicks in a nest near a glowing bug zapper surrounded by moths (make the parent birds emaciated and worried). That graphic would go viral. #birds #insects #birding
The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development time, and critical issues must be patched immediately (Himanshu Anand)
https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/…
SQUASH BUG WAR CASUALTY REPORT
KIA: 0, Egg Pods Destroyed: 0
No contact with the enemy today. Not one bug. Not one egg. The leaves are still. TOO still.
This is not a victory. This is a TRAP.
#gardening #oklahoma
Cybersecurity is, as they say, moving at machine speed, so don't leave for the weekend until you check out today's Metacurity for the critical infosec developments you should know, including
--Canvas chaos: ShinyHunters breach throws schools into disarray
--Firefox bug fixes soar after using Mythos,
--Virginia man found guilty of destroying government databases,
--OpenAI rolls out GPT 5.5 to vetted cyber defenders,
--PCPJack steals cloud creds while remov…
FreeBSD bug 263171 – add loader(8) and boot loader menu support for boot with OpenZFS-encrypted ROOT
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=263171
@…
Apple fixes a bug that stored notifications for deleted messages on iPhone and iPad, following a report that police used it to extract deleted Signal messages (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/04/22/appl
Google Raises Top Android Bug Bounty to $1.5 Million to Combat AI-Era Threats
https://hothardware.com/news/google-android-bug-bounty-1-point-5-million-ai-era-threats
FreeBSD bug 100782 – [keyboard] Default keymap to support ALT Left, ALT Right console switching
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=100782
@…
Security research firm Calif says it used Mythos to help build a macOS kernel memory corruption exploit circumventing Apple's Memory Integrity Enforcement tech (Robert McMillan/Wall Street Journal)
https://www.wsj.com/tech/ai/anthropic-myth
Squash Bug War Casualty Report: Adults 0, Egg Pods 0.
No enemy contact, but I know they are out there, it’s like they are taunting me . . .
“Hallo, you tiny-brained gardener! You frighten no one! Today we did not come, because we did not feel like it!”
#gardening #oklahoma
Fasten your seat belts because the cyber developments are off the charts this week. Stay ahead of the curve and check out today's Metacurity for the most crucial developments, including
--Anthropic releases Mythos-derived model with cyber guardrails,
--Admin halts AI safety reports amid fight over oversight,
--Microsoft patches record 200 flaws as AI fuels bug discovery,
--Nightmare Eclipse drops fresh Windows zero-day,
--China's hackers target tech firms…
Evening Squash Bug War: Casualty Report
10 adults KIA, 4 egg pods destroyed.
O cursed stinkèd foe, thou crept upon my vine!
But lo — my thumb of justice, swift and firm,
Hath crushed thy copper eggs and broke thy line.
The Union garden stands. Begone, thou bug.
#gardening #oklahoma
@… this bug?
287569 – bsdinstall: restarting installation: Error: No disk(s) present to configure — <https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=2…
To help defenders prioritize patches amid the coming onslaught of bug reports, Anthropic recommends that they rely on a vulnerability framework known as the Exploit Prediction Scoring System (EPSS).
Check out my latest CSO piece on how EPSS works.
Many thanks to Michael Roytman and Ed Bellis of Empirical Security, James Robinson of Netskope, Aaron Weismann of Main Line Health, and Ramy Houssaini of Cloudflare for their insight.
Anthropic bets on EPSS for the coming bug surg…