GeistHaus
log in · sign up
27 pages link to this URL
March 2026: DTLS-SRTP auth bypass, AI vuln research, DVRTC, WebRTC skimmer

19 of 33 WebRTC media servers fail DTLS-SRTP authentication. AI agents are finding hundreds of zero-days in C codebases. Enable Security launches DVRTC for VoIP security training. Plus a WebRTC payment skimmer, PJSIP advisories, FreePBX CVEs, and more.

0 inbound links article en newsletter SIPVicious OSS v0.3.5Asterisk 21.12.2 and certified-22.8-cert2 released with pjproject fixes21.12.2certified-22.8-cert2Original content here.
Scroll trīgintā septem

Arcane curation from the IndieWeb, Fediverse and Cybersecurity realms

1 inbound link article en Scroll trīgintā septemshellsharksinfosecindiewebfediverse
The Future

After 283 episodes, this will be the final episode of the DAY[0] podcast. We started the podcast on a hopeful note in the days following Ghidra's release. Now, to end it off we've got another discussion about how we see the future of vulnerability research and exploit development going. We recorded this episode before all the hype around "Mythos" and Project Glasswing so it doesn't play into our commentary here. Thank you all for the support over the last seven years. Good luck and happy hacking!

AI in 2026 and Beyond

No one needs another AI think piece. I’m writing this for myself. I wish I’d started writing about AI in 2023. This is a cataclysmic shift in the world and I wish I’d preserved my thought process so I could look back on it and see how it changed over time. With that in mind this is written to my future self, and includes what’s going on now and some predictions about what’s coming in the future.

0 inbound links website en
Weakly Link 26/16 - Quantum Mythos Special

A slightly delayed episode of the weakly link. This time, we have a bit of a special outlook on the future in security to do with Quantum and AI. There were a couple of links that really caught my eye and could make a compelling case for usage of the phrase “everchanging landscape…” - stop it Gerald - this is not AI generated! Let’s start with the big announcement: Anthropic announced how their latest Mythos model was so good at vulnerability research that they decided to keep it from the unwashed masses and just give access to select organisations and call it Project Glasswing.

0 inbound links article en posts
Andrew Ayer (@agwa@follow.agwa.name)

@michael Curious what model/harness you're using? I tried to use Claude Code and Opus 4.6 with the prompt in https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/ to audit some s...

0 inbound links article en
May 15, 2026 - Schneier on Security

In this issue: Defense in Depth, Medieval Style Human Trust of AI Agents Mythos and Cybersecurity Is "Satoshi Nakamoto" Really Adam Back? Mexican Surveillance Company ICE Uses Graphite Spyware FBI Extracts Deleted Signal Messages from iPhone Notification Database Hiding Bluetooth Trackers in Mail Medieval Encrypted Letter Decoded What Anthropic’s Mythos Means for the Future of Cybersecurity Claude Mythos Has Found 271 Zero-Days in Firefox Fast16 Malware A Ransomware Negotiator Was Working for a Ransomware Gang Hacking Polymarket DarkSword Malware Rowhammer Attack Against NVIDIA Chips Smart Glasses for the Authorities Insider Betting on Polymarket LLMs and Text-in-Text Steganography Copy.Fail Linux Vulnerability OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities How Dangerous Is Anthropic’s Mythos AI? Upcoming Speaking Engagements

0 inbound links article en
Simon Willison on careers

76 posts tagged ‘careers’.

0 inbound links website en ai 2016generative-ai 1785ai-assisted-programming 381llms 1751quora 1005ai-ethics 301coding-agents 201programming 158startups 190deep-blue 7
Simon Willison on ai-security-research

17 posts tagged ‘ai-security-research’. Using AI tools to help find security vulnerabilities.

0 inbound links website en ai 2016generative-ai 1785llms 1751security 602anthropic 282ai-ethics 301claude 275thomas-ptacek 18openai 418open-source 303
Simon Willison on security

602 posts tagged ‘security’.

0 inbound links website en ai 2016llms 1751generative-ai 1785prompt-injection 147xss 60exfiltration-attacks 43javascript 755csrf 54phishing 54python 1250
Simon Willison on ai-ethics

301 posts tagged ‘ai-ethics’. Ethical concerns related to building and using AI systems.

0 inbound links website en ai 2016generative-ai 1785llms 1751ethics 152ai-misuse 50openai 418chatgpt 196slop 39anthropic 282training-data 63
What Anthropic’s Mythos Means for the Future of Cybersecurity - Schneier on Security

Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Anthropic is not releasing the model to the general public, but instead to a ...

1 inbound link article en AIcybersecurityLLMpatchingvulnerabilities
You didn’t ‘miss the boat’ on AI in cybersecurity

Your career is not obsolete, no matter how many vendors/influencers say so lately. Let’s set up a small homelab and a few open source tools to start using AI tools in your work, outlining all the places we still need cybersecurity expertise for these new problems that accompany this new technology along the way.

0 inbound links article en