Dear journalists: it's not "AI escaped", it's "AI companies failed to restrict the programs". Programs that did exactly what they were instructed to do. By those companies.
Place the blame where it belongs.
Dear journalists: it's not "AI escaped", it's "AI companies failed to restrict the programs". Programs that did exactly what they were instructed to do. By those companies.
Place the blame where it belongs.
@dalias @mirabilos Most of those (except for the RDS ones) require CONFIG_USER_NS, I think.
Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".
https://www.openwall.com/lists/oss-security/2026/09/08/1
Various exploits/PoCs here:
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research
While I don't know how widespread the use of RDS is, it's the "and 20 more" that kills me. Pretty much assuming shell access == root access at this point.
Hey kids! It's the start of the Fall semester, and I'm again teaching "Advanced Programming in the UNIX Environment".
The syllabus and all course materials including all code examples are available here:
https://stevens.netmeister.org/631/
As usual, we'll be using #NetBSD as our main platform. All video lectures are public and available for free on YouTube:
https://www.youtube.com/playlist?list=PL0qfF8MrJ-jxMfirAdxDs9zIiBg2Wug0z
I'll be posting individual lecture videos and related links in this thread throughout the semester.
So that log4j thing that came in last week... that's just a nothing burger, right?
Claiming it's an RCE in log4j because if you find an endpoint to which you can upload an object and that _then_ de-serializes the attacker controlled data feels like claiming Apache httpd has an RCE because you found a web server configured to accept POSTs to its cgi-bin directory. (If you remember what that is.)
I mean, sure, don't de-serialize attacker controlled data, but that's not news.
Incident: actively exploited CVE
Service team: Not to worry. The EoL'd version we run is *much* older than that, so we're not affected. 🤡
Infosec: 🤦♂️
(This happens far too often.)
‘“The world looks different now than when we co-founded the climate pledge,” said Margaret Callahan, an Amazon spokeswoman.’
Yeah, no kidding. IT’S ON FUCKING FIRE because of soulless sacks of shit and the corporate bullshitters like you.
Climate pledge my ass.
https://www.nytimes.com/2026/08/08/climate/amazon-data-center-texas-pollution.html
Really looking forward to the first large-scale OpenAI / Anthropic API outage, where 85% of the industry will be flopping around trying to remember how to hello-world on their own while execs google "how to write an email".
Here's your weekly batch of Linux local privilege escalation vulnerabilities:
CVE-2026-43499 "GhostLock"
https://nebusec.ai/research/ionstack-part-2/
CVE-2026-46242 "Bad Epoll"
https://github.com/J-jaeyoung/bad-epoll
Enjoy! ✌️
Oh, goodie. KVM Guest-to-Host escape
"Januscape (CVE-2026-53359)" -- https://github.com/V4bel/Januscape
I miss Web 1.0. You click a link, you get to the website, you read the content. What a concept.
So people are totally now using AI models for regular stuff that you can do via shell scripts and cron, because why do something for free when you can burn tokens and at the same time actively forget how to use the normal tools at your disposal?
🤦 🙏 🤦
Now this is some bullshit.
Today: Don't have an "approved" phone? Too bad for you.
Tomorrow: Don't have a Google account? Good bye.
Another nail in the coffin of the Open Web. Those fuckers.
https://thecodersblog.com/google-breaks-recaptcha-for-de-googled-android-users-2026/
https://cybernews.com/privacy/google-qr-code-recaptcha-requires-approved-phone/
Now what the fresh fuck is this, then?
Not today, Satan.
#DirtyFrag status/advisories:
AlmaLinux:
https://almalinux.org/blog/2026-05-07-dirty-frag/
Debian:
https://security-tracker.debian.org/tracker/CVE-2026-43500
https://security-tracker.debian.org/tracker/CVE-2026-43284
Gentoo:
https://bugs.gentoo.org/974307
RedHat:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2026-43284
https://access.redhat.com/security/cve/cve-2026-43284
nothing yet on CVE-2026-43500
Rocky:
https://kb.ciq.com/article/rocky-linux/rl-dirty-frag-mitigation
SUSE / OpenSUSE:
https://www.suse.com/security/cve/CVE-2026-43500.html
https://www.suse.com/security/cve/CVE-2026-43284.html
https://www.suse.com/c/addressing-copy-fail2-aka-dirtyfrag-in-suse-virtualization/
Ubuntu:
https://ubuntu.com/security/CVE-2026-43284
https://ubuntu.com/security/CVE-2026-43500
https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available
AWS:
https://aws.amazon.com/security/security-bulletins/rss/2026-027-aws/
https://explore.alas.aws.amazon.com/CVE-2026-43284.html
The rxrpc module is likely easier for you to block, but if you can't blocklist the ESP kernel modules, note that that exploit path requires the ability to call `unshare(CLONE_NEWUSER | CLONE_NEWNET)`.
That is
```
sysctl -w kernel.unprivileged_userns_clone=1
```
prevents the ESP exploit.
(That also prevents that other silly variant.)
Oh FFS.
#DirtyFrag
https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
"Because the embargo has now been broken, no patches or CVEs exist for these vulnerabilities."
https://www.openwall.com/lists/oss-security/2026/05/07/8
Well, just put that CopyFail incident work on rinse and repeat, I suppose...
*slow clap* to everybody out there doing Anthropic's Marketing Team's job for them. 🍿
"#Mythos discovers 27-year-old bug" is intentionally conflating length of existence of a bug with difficulty of finding it. There is no such correlation.
If software projects and companies performed regular, ongoing, in-depth code audits over and over and missed it, sure, then age would be meaningful, but that is simply not what organizations do.
But sure, it makes for great headlines.
The monetary waste aside, and assuming companies using leaderboards and bonus incentives for token use haven't ever heard (!) of Goodhart's Law, the obliviousness to the environmental impact resulting from "tokenmaxxing" is just obscene.
Encouraging and rewarding employees to do maximum environmental damage is positively evil and journalists should call this out in their coverage every single time.
https://www.nytimes.com/2026/03/20/technology/tokenmaxxing-ai-agents.html
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.