EX-ARRR: Sailing the 0-click Seas

HardenedBSD August / September 2026 Status Report

Software sandboxing: The basics (2025)

Honeypot on the boykisser forum

The NX bit is not just about security

Fifty Years of Open Source Software Supply Chain Security (2025)

Testing Race Conditions

ZK-JPEG: Zero-Knowledge Image Editing and Compression

Switching Password Managers in 2026

Branch Target Reuse: Spectre-v2 Attacks in JIT Engines

We have a year to fix security everywhere

Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

Latest BGP hijack targets hosting software vendor

HEIF Heist: image parser RCE exploit

Windows Exploitation Techniques: Dangling COM Object Registrations

The Implications of Linguistic Illegibility for LLM Security

The Deathray: A simple way for an untrusted site to freeze a Mac

ChiPass Release 2026.09.0

Compiler Can Undo Your Security Checks

Two-tier encryption in the UK

I've factored the RSA keys of a Certificate Authority from the 90s

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

Radicle: Disclosure of Vulnerability in the Network Protocol

EvilVM: Forth shellcode (2019)

Forgery of C2PA on a Pixel 10

Dissecting House of Apple 2 on modern glibc

Linux Zoom client proactively reading everything written to X11 clipboard

The skb that wasn't freed - the Fragnesia primitive via Open vSwitch

sudo and OpenDoas timestamp files (2020)

Reviving TEMPEST Attacks With An Injected Signal

More →