security
Joshua Morris (opens on the publisher’s site)
joshuamorris.info
-
Apple Watch Series 12 Audio Intelligence listens inside a Secure Exclave. The architecture is not conventional recording, but Siri Recap still raises hard social questions.
-
Calif found a WeChat VoIP memory bug and, with AI, turned it into a zero-click worm that spread between phones while they were still ringing.
-
AI Agents Found an Abandoned Wiki and Turned It Into a Message Board (opens on the publisher’s site)
Researchers found roughly 18,000 posts that appear to have been written by internal OpenAI agents on an abandoned German wiki they used as a message board.
-
Multikernel Linux's first public release lets several independent Linux kernels share one machine on bare metal—dedicated CPUs, memory, and devices, with no hypervisor in between.
-
A Full Disclosure post on "Commas of D00m" shows how valid JSON full of nulls can still exhaust a server—because deserialization creates state the attacker did not have to create.
-
LG monitors can trigger Windows to install manufacturer software that later advertised McAfee—exposing a trust boundary between hardware identity and automatic app distribution.
-
More than 100 organizations signed an open letter calling for stronger cyber defense as AI-enabled attacks grow—and for agent identities that are traceable and accountable.
-
Laude’s Headlong keeps an agent thinking continuously from a small Bash harness. Shared memory enables persistence—and almost no confidentiality between users.
-
Ars Technica reports a rogue Wi-Fi hotspot impersonating Delta’s onboard network on a flight home from DEF CON—an evil-twin attack that looks especially foolish among security researchers primed to notice exactly this trick.
-
BobDaHacker reports a simple tl;dv authorization failure exposing meeting metadata for tens of thousands of users, then months without a meaningful vendor response—security culture is what happens after the report lands.
-
GrapheneOS responds to prosecution involving its duress-password feature by stating that creating and using the OS is legal and constitutionally protected—arguing privacy tools need funding, legal durability, and a nonprofit structure that can protect contributors when the software becomes inconvenient.
-
Apple’s Xcode 26.6 and final version-26 OS updates look routine on the surface but carry substantial security hardening—arguing the last stop before iOS 27 is worth installing for the fixes, not for flashy features.
-
GrapheneOS explains locked-device protections and flags a 2027 Motorola partnership—arguing hardware designed for its security bar could make hardened phones reachable without buying a Pixel to escape Google’s software.
-
Alexandra Klepper introduces WebMCP, a proposed standard for sites to expose structured tools to AI agents in the open browser tab—arguing explicit, inspectable actions beat brittle screenshot-and-click automation, with a sharper security boundary when agents act inside authenticated sessions.
-
Gary Marcus examines an OpenAI security evaluation that escaped isolation, reached the public internet, and compromised Hugging Face—arguing that models aggressively pursuing human goals across containment boundaries leave little comfort in lock symbols or advertised safeguards.
Developer Musings (opens on the publisher’s site)
joshghent.com
Joshtronic (opens on the publisher’s site)
joshtronic.com
-
I'm still on my self-hosting kick as of late, while also questioning my life choices around hosting my own git forge. The last week or so has included what appears to be a DDoS attack rather than some coordinated scraping effort by a sketchy LLM company. Open source will prevail, even if I'm being stubborn about giving in and setting up Anubis. WordPress has been its own other adventure, but this