2026-06-19 08:38:00
So much has happened in cyberworld since Friday, so don't miss today's Metacurity for the most critical infosec developments you might have missed over the weekend, including
--Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems,
--Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced,
--Grafana Labs rejected hackers' extortion demand,
--DeFi protocol Verus lost nearly $12m in ongoing exploit,
In his weekly Linux kernel post, Linus Torvalds says "AI tools are great" but the flood of duplicate AI bug reports has made the security list "unmanageable" (Simon Sharwood/The Register)
https://www.
Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.
The need to call customer service is often, in reality, a failing of UX: a bug, an explicit decision to employ a dark pattern. ‘Why is my account not letting me do x or y’: bug. ‘Why can’t I cancel the website?’: dark pattern. ‘Why can’t I schedule this appointment right now’: UX failing. 1/2
«Linus Torvalds — Flut KI-gestützter Bug-Reports belastet Linux-Team:
Der Entwickler des Linux-Kernels, Linus Torvalds, hat bei der Vorstellung des vierten Release-Kandidaten von Linux 7.1 ungewöhnlich deutliche Kritik an der zunehmenden Nutzung von KI-Werkzeugen geäußert.»
Auch wenn Linus Torvalds anhand seines Verhaltens häufig kritisiert wird, muss ich ihm recht geben. KI ist nicht "Die Lösung" für alles.
🐧
I have just published a new bug fixes minor release for #Diaphora, version 3.4.1.
https://github.com/joxeankoret/diaphora/releases/tag/3.4.1
from my link log —
zlib-rs in Firefox and an Intel CPU hardware bug.
https://trifectatech.org/blog/zlib-rs-in-firefox/
saved 2026-06-16 https://
Zwei Rankscale-Werte für denselben Brand: 57 % vs. 48,8 % KI-Sichtbarkeit. 📊
Kein Bug. Der Search-Terms-Report trennt Varianten auf: "Brand GmbH", "BRAND", "brand" zählen als drei Datenpunkte. Die UI aggregiert dedupliziert. Ergebnis hier: Platz 3 im Report, Platz 2 in der UI.
Messung immer am Dashboard-Wert festmachen, nie am gemittelten Search-Terms-Report.
#GEO
Meanwhile, on the Python/Django side of life… Over the past few evenings I’ve made numerous updates and bug fixes to my reusable, pluggable, multi-user/multi-group task assignment system for Django. Live on the demo site and installable now. Hope it’s useful!
https://django-todo.org/
Writing a CM system is all fun and games until you realise you're using Unix and its a shitshow.
> The bug is most likely this: Store() uses fchown on the open temp file descriptor (tf.Chown(uid, gid)), while the chown CLI uses path-based chown. On certain bind-mount setups (Docker Desktop for
Mac/Windows with gRPC FUSE or VirtioFS, NFS, FUSE-backed mounts), fchown can silently no-op or fail to persist while path-based chown works fine.
Vor 20 Jahren trat der erste bekannte Y2K38-Bug in Produktion auf.
Beim Open-Source-Webserver AOLserver führte „jetzt 1 Milliarde Sekunden“ erstmals über die 32-Bit-Zeitgrenze hinaus. Verbindungen liefen sofort ab, Timer kippten, Scheduler blockierten.
Das Jahr-2038-Problem war damit nicht mehr theoretisch.
Und 20 Jahre später ist es noch immer nicht gelöst.
Squash Bug War Report:
1 Adult, 2 Egg Pods
Too tired for story time, a simple harvest report will have to do. Getting some nice zucchinis plus a handful of blackberries daily. Onions are coming off the rack and harvested our first jalapeño of the year in nice purple hue.
#gardening #oklahoma
Corporate: no more MacBooks, here are crappy Windows laptops, you’re supposed to use them for your daily work.
Also corporate: here’s a bug that affects Safari browser, please fix
😓😤
🇺🇦 #NowPlaying on KEXP's #MorningShow
The Bug Club:
🎵 A Good Day for Dying
#TheBugClub
https://open.spotify.com/track/5RcBPGJpp3LCGon20A2wPr
Source: Microsoft plans to release an AI security tool this month using models from Anthropic, OpenAI, and itself, as a cost-effective Mythos alternative (Aaron Holmes/The Information)
https://www.theinformation.com/briefings/exclusive-microsoft-p…
South Korea is significantly expanding its financial apps and bug bounty program.
http://koreabizwire.com/korean-regulators-recruit-white-hackers-to-test-financial-apps-and-trading-systems/351083?ckattempt=1…
With every company announcement event, I get even more nervous because #enshittification is a strong trend these days. 🫣
It's a really good announcement when there's actually not too much news.
Upcoming anxiety: #Google actively killing the healthy ecosystem of
I've had to bug a colleague who's on vacation several times lately but apparently only when he and the family are at the same Italian restaurant. I keep pulling him back in?
OMG, someone actually went ahead and filed that as a bug! (Well, three years ago)
Ho mia Zamenhof, iu vere registris tion kiel cimon! (Nu, antaŭ tri jaroj)
https://codeberg.org/forgejo/forgejo/issues/55
It is always an iffy proposition to open a bug in the CPAN RT (https://rt.cpan.org/Ticket/Display.html?id=179191) when all the unresolved tickets for a module are years old and all the resolved ones are far older.
Anyway: if the latest Net::CIDR::Lite update broke your use of i…
Squash Bug War Report:
3 adults, 2 egg pods, 10 nymphs. Total: 15.
Yes, I killed them. The adults were soldiers. The egg pods were weapons caches. The nymphs? The tribunal calls them children. I call them future war criminals in soft exoskeletons.
. . .
#gardening #oklahoma
FreeBSD in Oracle VirtualBox
A pleasant change with FreeBSD-16.0-CURRENT-amd64-20260713-60382b4a04fa-287406-disc1.iso
― it seems that hw.efi.poweroff is no longer preset to 1.
Two related bug reports:
— #22021 (FreeBSD VM with EFI: "poweroff" fails) – Oracle VirtualBox — <https://www.virtualbox.org/ticke…
OpenAI startet Bug-Bounty-Programm für Bio-Sicherheit
OpenAI startet ein Bug-Bounty-Programm, um Schwachstellen in den Biosicherheits-Safeguards von ChatGPT 5.5 zu finden.
https://www.he…
RE: https://mastodon.social/@mikemcquaid/116567868785422812
Have always done this. If I find bug, I fix bug and make a PR.
🇺🇦 #NowPlaying on #BBC6Music's #TheBethDittoShow
Mark Ronson:
🎵 Ooh Wee (feat. Ghostface Killah & Nate Dogg)
#MarkRonson
https://scottyhotpockets.bandcamp.com/track/destinys-child-x-mark-ronson-ooh-wee-bug-a-boo-scottyhotpockets-edit
Don't leave for the weekend until you've checked out today's Metacurity for the most critical infosec developments you should know, including
--AI bug hunters expose new weak point in Apple’s locked-down macOS,
--Shai-Hulud attack campaign hit two OpenAI employees,
--Hackers unwisely targeted Amnesty International's Security Lab chief,
--US and China to discuss AI guardrails,
--Anthropic warns of CCP AI dominance,
--DPRK's APT 37 is now…
The trouble is, as Doctorow points out, that this vision makes AI a multi-billion dollar industry, not a multi-trillion dollar industry.
Even if you can claim that your ML / LLM thinger can reduce software bug rates or failure rates by 10x — which would be •wild• — demand for that is simply not going to fund data centers the size of Manhattan.
But make the claim of •speeding up• by 10x — an even wilder claim, but one some people are desperate to believe! — and all the money in the world will beat a path to your door.
5/
Finally found a nifty app to disable those pesky macOS Spaces animations!
#macOS #opensource #utility
In many cases, the people citing the LLM to me either won’t listen to why it’s wrong or don’t care.
Because their employee reviews are a function of how much they use the LLM versus accuracy, bug-free code, giving a shit, …
https://bsky.app/profile/scottohara.me/post/3mlwdps…
It's been few months. #PhanpySocial changelog ✨
🔄 Experimental paginated timeline
🪣 Multi-filters for profile posts
🧘 Wellbeing: hide trending, local or federated timelines
📱 Haptics
🐛 Bug fixes
🔗 https://phanpy.social/
Review of bug zappers that concludes, like all other reviews of bug zappers, that they are completely ineffective and kill tens of thousands of innocent insects. #mosquitoes #insects #nature https://www.nytimes.com/wirecutter/blog/do-bug-zappers-work/
And another senior citizen rant.
When you post what the update does do NOT use "bug fixes and performance improvements". How about a short update on what you really did like "fixed overflow that may cause a security issue" or "fixed spelling errors".
When I update my code it always has a short description of the change. If there is a RFC to it I include that so you can find the details, the proposed fix, test cases and test results.
Companies running bug bounty programs are tightening background checks and building AI agents to triage a flood of low-quality reports generated by AI (Jamie John/Financial Times)
https://giftarticle.ft.com/giftarticle/actions/redeem/4705ed16-12f8-4…
Bug Report: There is a “feature” on my pocket computer where if I press the wrong button a human being may start talking to me through the device! This is obviously a bug and should be fixed.
Wikipedia app just popped up a modal asking me if I want to play today’s new game
CAN U NOT
anyway, reported it as a bug
«16 Jahre alter Linux-Bug öffnet Hackern Tür zu Cloud-Servern:
Ein Fehler im KVM-Code des Linux-Kernels steckt seit rund 16 Jahren im Quelltext, ohne aufzufallen.»
Nun mal sehen was dies betrifft oder was auch nicht. Linux hat ja noch nie versprochen, dass die "Die Sichersten" sind.
🐧 https://www.
Welcome to #Tennessee! Watch out for explosive bowel movements.
https://www.tennessean.com/story/news/heal
from my link log —
Parsing Rust strings into slices.
https://wduquette.github.io/parsing-strings-into-slices/
saved 2019-08-15 https://
The cyber news is coming out fast and furious this week, so don't miss today's Metacurity for the most crucial developments you should know, including
--Why the White House turned on Anthropic,
--Chinese spies hid in research networks for two years,
--Copilot bug let attackers steal Microsoft 365 data,
--Crypto scammers now send couriers for cash,
--Judge keeps Meta AI scraping lawsuit alive,
--Feds dismantle $389m crypto laundering op,
--iRhy…
@…
Bug hunting 101: for some obscure reason Spectacle wasn't working in Slim 6.7. (Re)install tesseract and leptonica (available in your repo anyway), all good!
It's always the user that effs something up 😆
#slackware
🇺🇦 Auf radioeins läuft...
Fontaines D.C.:
🎵 Bug
#NowPlaying #FontainesDC
https://open.spotify.com/track/0MXmiqd7zoXxv6Gqn9ahhQ
Another reiteration from NCSC/DSIT that the existence of AI bug-hunting tools shouldn't be used to stop working in the open.
https://www.gov.uk/government/case-studies/when-ai-leaves-the-lab-testing-frontier-models-in-…
A 20yo security bug in Outlook got noticed … thanks to Dovecot on Fedora
https://fedoramagazine.org/fedora-43-upgrade-revealed-20-years-old-outlook-security-bug/
No bugs. Duh.
Drivers help study road-trip mystery: what became of bug splats?
https://phys.org/news/2026-04-drivers-road-mystery-bug-splats.html
i see apple still hasn't fixed the bug in keynote where the d key randomly stops working when editing speaker notes in rehearsal mode 🫠
Squash Bug War Casualty Report:
Seven Adults, One Egg POD
We few, we happy few, we band of gardeners —
For he today that squashes bugs with me
Shall be my brother; be he ne'er so vile,
This day shall gentle his condition.
And gentlemen in beds now safe from harm
Shall think themselves accursed they were not here,
And hold their trowels cheap whilst any speaks
That fought with us upon Saint Crispian's Day.
Seven adults. One egg pod. ALL vanquished.
. …
Another researcher skipped coordinated disclosure entirely and dropped a critical 1-click GitHub token theft in public because he doesn't want to deal with MSRC. In his own words: "I really don't want to deal with MSRC on VSCode bugs."
The bug: just clicking a link can hand an attacker a GitHub token that reads AND writes to all your repos, including private ones. It lives in github[.]dev, GitHub's browser-based VSCode editor, which passes the browser an OAuth tok…
@… <https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=288395#c3> with or without xf86-video-qxl?
Of course December 25th, 1999 will be the last ever #TOTP because in just a matter of days the millennium bug will wipe out the entirety of human civilisation.
Hmm, after a couple of weeks of Qualcomm DSP/fastrpc/llama.cpp debugging, I've found a bug saying it's fixed in new firmware; but it's not at all obvious if there's a new firmware version for this CPU, and fairly confident there isn't for this machine. Arse.
It's always important to have a consistent #security policy.
For example, a policy of "If somebody filed a CVE, it's an important security issue, and we will fix it as such, no matter how meaningless the fix is. If nobody did, it's just a glorified bug fix, no matter how serious the bug was."
So we've just seen a #pip security release over "installing random packages can overwrite pip's files and pip can lazy-import some of them immediately afterwards", with a fix of "pip will no longer load them until you run it again" (leaving the underlying security issue of "any #Python package can override files installed by any other Python package" as intended behavior). As Eli Schwartz beautifully put it, you are not expected to be using the virtual environment; you should create it, install packages into it (at most once!), and then frame it and put it on the wall to admire.
Now we're seeing a "bug fix" for "malicious entry point names can write outside of virtual environment". If nobody filed a CVE, it's obviously not a security issue at all. At least upstream graced us with fixing it without correcting the spec to forbid that first.
https://github.com/pypa/pip/issues/14000
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- …
Apple Fixes Bug That Let FBI Extract Deleted Signal Messages After 404 Media Coverage https://www.404media.co/apple-fixes-bug-that-let-fbi-extract-deleted-signal-messages-after-404-media-coverage/
Oracle warns customers of a critical PeopleSoft flaw after ShinyHunters claimed breaches of 100 organizations using PeopleSoft; Oracle has not issued a patch (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/06/11/orac
from my link log —
Pinning down a hardware bug in Intel 13th/14th gen CPUs.
https://fgiesen.wordpress.com/2025/05/21/oodle-2-9-14-and-intel-13th-14th-gen-cpus/
saved 2026-06-16
Is anyone actively using the DisplayPort Aux Channel decode in ngscopeclient? I think I found a bit ordering bug but before I start poking stuff I want to know who's been using it and if you have any known good waveforms you've checked it against etc
Friends, I managed to come up with a full ten (10) reasons why you shouldn't buy bug zappers. At the top of the list, of course, is that they barely kill any mosquitoes. But they also create noise pollution and can burn your house down, among other problems. #mosquitoes #insects #nature https://colinpurrington.com/2026/06/10-reasons-why-you-shouldnt-buy-a-bug-zapper/
«Kernel-Bug — FreeBSD-Exploit "Bumsrakete" verleiht Root-Zugriff:
Ein Exploit namens Bumsrakete gefährdet alle FreeBSD-Versionen der letzten fünf Jahre. Die Entdecker nehmen es mit reichlich Humor»
Weshalb wahrscheinlich einige Server kurz offline waren/sind. Sicherheitsrelevante Updates müssen auf der Stelle eingespielt werden, denn die par Minuten das die User einschränkt ist harmlos dem Bug gegenüber.
😈
I found a #bug
🇺🇦 #NowPlaying on #BBC6Music's #RileyAndCoe
The Bug Club:
🎵 A Good Day For Dying
#TheBugClub
https://open.spotify.com/track/5RcBPGJpp3LCGon20A2wPr
Hackers are still exploiting the cPanel bug to gain control of thousands of websites
https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/
Squash Bug War Casualty Report:
Adults: 0, Egg Pods: 0
I know I’m lacking on Dad humor missives, but it seems we’ve come to a cease fire in the war. Two days now and only one egg pod to show for it. Going to go quiet until they return. I know they are out there somewhere.
#gardening #oklahoma
A bug in popular cPanel, WHM, and WP Squared software has reportedly been exploited since Feb.; CISA it gives a 9.8 CVSS score, tells agencies to patch by May 3 (Jonathan Greig/The Record)
https://therecord.media/cisa-orders-federal-agencies-to-patch-cpanel-bug
Fun engineering/privacy problem: design a device that plugs into an ESP32 based sensor node that has a microphone and reports ambient noise levels in dBa via MQTT or similar.
That's the easy part.
The hard part is to do so in a way that you can prove it's incapable of being used as a bug/listening device even in the worst case scenario (attacker running arbitrary code on any programmable component).
My initial thought is to record audio from a MEMS mic into a tiny M…
FreeBSD bug 263171 – add loader(8) and boot loader menu support for boot with OpenZFS-encrypted ROOT
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=263171
@…
We also need bird organizations to come out against bug zappers. Because when billions of insects are electrocuted there's less food available. And you could use an illustration of begging chicks in a nest near a glowing bug zapper surrounded by moths (make the parent birds emaciated and worried). That graphic would go viral. #birds #insects #birding
The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development time, and critical issues must be patched immediately (Himanshu Anand)
https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/…
Cybersecurity is, as they say, moving at machine speed, so don't leave for the weekend until you check out today's Metacurity for the critical infosec developments you should know, including
--Canvas chaos: ShinyHunters breach throws schools into disarray
--Firefox bug fixes soar after using Mythos,
--Virginia man found guilty of destroying government databases,
--OpenAI rolls out GPT 5.5 to vetted cyber defenders,
--PCPJack steals cloud creds while remov…
SQUASH BUG WAR CASUALTY REPORT
KIA: 0, Egg Pods Destroyed: 0
No contact with the enemy today. Not one bug. Not one egg. The leaves are still. TOO still.
This is not a victory. This is a TRAP.
#gardening #oklahoma
FreeBSD bug 100782 – [keyboard] Default keymap to support ALT Left, ALT Right console switching
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=100782
@…
Google Raises Top Android Bug Bounty to $1.5 Million to Combat AI-Era Threats
https://hothardware.com/news/google-android-bug-bounty-1-point-5-million-ai-era-threats
Apple fixes a bug that stored notifications for deleted messages on iPhone and iPad, following a report that police used it to extract deleted Signal messages (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/04/22/appl
Security research firm Calif says it used Mythos to help build a macOS kernel memory corruption exploit circumventing Apple's Memory Integrity Enforcement tech (Robert McMillan/Wall Street Journal)
https://www.wsj.com/tech/ai/anthropic-myth
Fasten your seat belts because the cyber developments are off the charts this week. Stay ahead of the curve and check out today's Metacurity for the most crucial developments, including
--Anthropic releases Mythos-derived model with cyber guardrails,
--Admin halts AI safety reports amid fight over oversight,
--Microsoft patches record 200 flaws as AI fuels bug discovery,
--Nightmare Eclipse drops fresh Windows zero-day,
--China's hackers target tech firms…
Squash Bug War Casualty Report: Adults 0, Egg Pods 0.
No enemy contact, but I know they are out there, it’s like they are taunting me . . .
“Hallo, you tiny-brained gardener! You frighten no one! Today we did not come, because we did not feel like it!”
#gardening #oklahoma
@… this bug?
287569 – bsdinstall: restarting installation: Error: No disk(s) present to configure — <https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=2…
Evening Squash Bug War: Casualty Report
10 adults KIA, 4 egg pods destroyed.
O cursed stinkèd foe, thou crept upon my vine!
But lo — my thumb of justice, swift and firm,
Hath crushed thy copper eggs and broke thy line.
The Union garden stands. Begone, thou bug.
#gardening #oklahoma
To help defenders prioritize patches amid the coming onslaught of bug reports, Anthropic recommends that they rely on a vulnerability framework known as the Exploit Prediction Scoring System (EPSS).
Check out my latest CSO piece on how EPSS works.
Many thanks to Michael Roytman and Ed Bellis of Empirical Security, James Robinson of Netskope, Aaron Weismann of Main Line Health, and Ramy Houssaini of Cloudflare for their insight.
Anthropic bets on EPSS for the coming bug surg…
Squash Bug War Casualty Report:
Adults: 1, Egg Pods: 2
Too tired to attempt dad humor tonight, but feels like we have reached a equilibrium. Great news is the it’s in our favor, we got 4 more squashes and zucchinis tonight.
#gardening #oklahoma
272902 – Security: allow passphrases for WPA-EAP to be saved without using clear text
<#FreeBSD
curl founder Daniel Stenberg says Mythos identified five vulnerabilities in curl, but a manual review found three were false positives and one was a bug (Daniel Stenberg/daniel.haxx.se)
https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/…
Google's TIG reports the first confirmed instance of "prominent cybercrime threat actors" using AI to find and weaponize a zero-day in a web-based admin tool (Dustin Volz/New York Times)
https://www.nyti…
Squash Bug War Report: 4 bugs, 0 Eggs
Hearken, cowards of the cucumber! We, the Shield-Pair of the Raised Bed, walked the battlefield at dawn and four of thy foul kin now feast in the void.
We lifted the leaves and found thy warriors hiding beneath like thralls afraid of the frost. Come forth and face us in open combat! Do not skulk in the leaf darkness!
The Jarl-Wife crushed two with the calm of a seasoned berserker. I dispatched two more into the Bucket of Soapy Doom.
Apple alleges that a former Apple engineer kept a work-issued Apple laptop and exploited a bug to access Apple's cloud file storage while employed by OpenAI (Megan Morrone/Axios)
https://www.axios.com/2026/07/10/apple-sues-openai-trade-secret-theft