Watch This Space: A security research blog.

The Interwebs
Misleading wording, in my opinion. This wasn't the judge making a final ruling but the DoJ filing a brief in support of OpenAI. The case still continues, from my understainding.
SITUATION DETECTED: The US government has sided with OpenAI against the New York Times. The DoJ says training an LLM on copyrighted works does not violate copyright law, and that treating it as infringement would hurt US science, prosperity, and national security.
334
Watch This Space retweeted
i talked to a lot of people who played the defcon ctf finals to understand how llms affected them, both professionally and mentally. i went in hoping to learn that human intuition still mattered. instead, ctfs in their current form as everyone saying is dead, players are forced to operate slot machines because anyone who refuses to token-max loses to those who do. almost everything i learned, including how to learn, came from grinding ctfs. but the pipeline for developing that kind of skill and expertise now seems broken, juniors are rewarded for token-maxxing rather than going through the process of actually understanding things which is quiet sad and ctfs might not produce high quality security researchers any more. this also has serious implications for people who can’t afford tokens. five years ago, i wouldn’t have been able to afford access to something like gpt-5.6, and I would have been locked out of the very competitions that helped me build my career. anyway these are questions i asked if interesting for anyone: did they have fun? almost everyone was unhappy. it has largely become slot-machine operating, if they refuse to use llms, they lose to teams that do. it is not there is no fun at all, playing with friends and competing was all fun just process of solving which is main part and it isn't fun.(please let me know if you had fun) did having a skilled human in the loop still matter? i got mixed answers, but the leaderboard tells a fairly clear story, the top teams aggressively token-maxxed, by pooling gpt accounts and stuff. the #1 team allegedly spent around $50k on tokens xd. how much of the outcome came from human skill versus token-maxxing? its probably 95% token-maxxing and 5% human skill. some challenges, especially visual ones, remain difficult for llms, and human intuition to prompt mattered. but overall, the dominant strategy appears to be throwing more tokens at problems, one interesting observation, people who were better before llms were also better after the llms and they are the ones solving lot of challenges so it seems still 5% operating skill will put u in top and can't be dumb operator. will a new generation of players simply adapt to this new kind of competition? i thought maybe current players are just behaving like boomers who hate every new technology. but unlike previous technology stuff, there doesn’t seem to be much for the human to master here. token-maxxing is literally just token-maxxing. it doesn’t reward human ingenuity, it discourages it, and may eventually atrophies and makes us dumb let me know if i missed something or if you have different opinions
47
128
770
99,387
I might finally write this up.
What's this? Another CVE? Update your Macs. Write-up by the end of this week, maybe.
1
22
11,593
piped.video/FwA3CuJxbk4 Incredible work here by @WIRED and @a_greenberg We need more public disclosures like this. The public should understand how much of the world runs on (likely) vulnerable tech, especially the hidden tech. Full story: wired.com/story/a-device-hid…
1
4
509
Seeing a CEO admit, in writing, that the US government restrictions are "bad news" is honestly refreshing. I have my own complicated feelings on AI, but I specifically believe our current administration cannot be relied on to effectively regulate it.
Good new first: Sol is a smart, efficient, and a significant step forward. It is the same price as GPT-5.5. Also launching in the GPT-5.6 family is Terra, with 5.5-level performance at half the price. Bad news: at the request of the US government, it is launching today in limited preview instead of the open access launch we were planning on. We are working with the government to get to general availability as fast as we can. I think it is quite reasonable to roll out models--especially as they reach significant new levels of capability--in this way. It fits with our long-held strategy of iterative deployment. But this isn't quite the process that we think is optimal. Now we will with the government to attempt to get to a transparent, reliable process for early access, and to ensure that as long as our safeguards work as intended we can release widely. We want to be a reliable, dependable partner that works with all stakeholders, and we also want to live by our mission of benefiting all of humanity. I believe the government shares most of our goals, and that they are overall doing a good job in a very difficult situation. We will work as quickly as we can to get this model in your hands and we hope you will love it.
1
3
308
50% of this tweet is not supported by the actual context I've seen. I hate misinformation.
🚨APPLE ADVERTISES $2 MILLION FOR FINDING SECURITY BUGS.. THEN CALLS YOUR DISCOVERY A "DUPLICATE".. PATCHES IT SILENTLY.. GIVES YOU NOTHING.. AND BANS YOUR APPLE ID IF YOU COMPLAIN.. Two researchers found a critical macOS vulnerability that let attackers steal passwords, encrypted chats, and Safari data through Archive Utility.. Submitted it October 2025.. Apple took 5 months.. Patched it with zero credit.. Zero CVE.. Zero bounty.. Their reason.. "You were not the first person to report this issue".. That's the duplicate loophole.. Apple claims an internal engineer found it first.. But researchers can't verify that.. Apple controls the tracking system.. No audit.. No appeals.. The researcher said it felt like "doing charity work for a $3 trillion company".. Another researcher found apps could access your entire photo library even after you turned off access in settings.. Apple's own page lists that at $50,000.. They reported it.. Apple went silent.. Patched it quietly.. Said it was a duplicate.. $0.. When the researcher blogged about it.. Apple permanently banned their 12-year-old Apple ID.. Apple's brand new Passwords app in iOS 18 was sending data over unencrypted HTTP.. A credential manager transmitting password reset links in plaintext.. Any attacker on the same WiFi could intercept them.. Researchers reported it.. Apple let it sit 3 months.. Patched it quietly.. Said it "didn't meet the impact criteria".. Then there's the FaceTime disaster.. A 14-year-old discovered you could eavesdrop on anyone's iPhone.. Start a FaceTime call.. Add your own number before they answer.. Their microphone turns on.. If they hit the volume button.. Their camera activates too.. His mother spent a week trying to tell Apple.. Emails.. Faxes.. Social media.. Support told her to pay $99 for a developer account to file a bug report.. Apple did nothing until the exploit went viral and millions started eavesdropping on each other.. Then they panicked.. Took FaceTime offline globally.. Congress sent formal letters to Tim Cook demanding answers.. Then there's the researcher who got so fed up being ignored that they hacked Apple's own internal daily security call.. They'd reported a zero-click iMessage vulnerability.. Apple stonewalled them.. So they found another flaw.. Used it to infiltrate the internal FaceTime call where Apple engineers discuss bugs.. And dropped a screenshot proving the exploit live.. The team securing 2.35 billion devices couldn't secure their own meeting.. Apple's response.. A threatening legal letter.. Not a bounty.. A legal threat.. This is why the exploit black market thrives.. A zero-click iPhone exploit sells for $1.5 to $2.5 million on the gray market.. Guaranteed payment.. No bureaucracy.. No "duplicate" risk.. Submitting to Apple means NDAs.. 6-12 months of waiting.. Risk of $0.. Risk of your Apple ID being banned if you speak up.. Those gray market exploits end up with mercenary spyware vendors like NSO Group.. Deployed against journalists and human rights lawyers worldwide.. Apple pushes researchers toward the black market.. Then spends billions defending against the exploits those researchers could have sold them for a fraction of the price.. 2.35 billion devices.. And the company would rather send lawyers than pay what they owe.
4
3
55
8,338
Apple finally published this. I found a bug in `awdd` that exposed `AWDMetadata.bin` and their response was to straight-up remove the daemon entirely. Very interesting!
3
3
48
4,750
This is why I think filesystem security needs more work put into it. macOS is far ahead of the game, but even it has its issues. Restrictions are a tricky thing, but maybe everything running on your machine shouldn't all put files where they can be accessed by every other thing.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks? It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts. This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
2
1
9
2,649
krebsonsecurity.com/2026/05/… A contractor made a public GitHub repo with the name `Private-CISA`. I find that detail a bit humorous, even though this definitely was/is a serious situation.
1
1
356
> We didn’t build the chain alone. Mythos Preview helped[...] This is still memory corruption, and I might still be holding onto logic bugs as less reachable by AI. But I'm growing less and less sure. Great work! Scary work, but great work!
Early this week, we had a meeting at Apple Park in Cupertino. While there, we also shared with Apple our latest vulnerability research report: the first public macOS kernel memory corruption exploit on M5 silicon, surviving MIE. It was laser printed, in honor of our hacker friends. Full story: open.substack.com/pub/calif/…
1
3
712
I genuinely hope this isn't prophetic.
npm config set min-release-age=2d
2
294
As a security person, this caught my attention, and not exactly in a good way.
Break things on purpose. Really.
1
120
Watch This Space retweeted
"Copy Fail exploits a kernel logic flaw where corrupted page‑cache data is never marked dirty, leaving disk files unchanged while the in‑memory version is silently altered. Because the page cache is what processes read, an unprivileged user can corrupt a setuid binary’s cached page and gain root. The shared cache also lets the attack cross container boundaries. The bug, surfaced through AI‑assisted analysis of crypto‑subsystem behavior, is portable, tiny, race‑free, and stealthy, unlike Dirty Cow or Dirty Pipe. It works across major distros and architectures and forms the basis for both local privilege escalation and Kubernetes container escapes." Thank you for the coverage @securityaffairs
1
3
11
2,527
This might be an unpopular take (and I haven't read too far into this), but I feel like focus of copy.fail being a "root LPE with no race" is the most uninteresting angle one can take on this vulnerability. CrackArmor is already comparable on that front. /1
1
790
The page cache corruption vulnerability is vastly more interesting to me, and I wouldn't be surprised if more research finds additional ways to abuse it besides a simple root LPE. /end
139
Watch This Space retweeted
Replying to @buildwithsid
because macOS: - has fewer native frameworks that are more difficult to build ugly software with (WinUI is pretty but no one uses it and the rest are hideous) - handles frameless windows more gracefully (proper rounding/borders/shadows, allows real window controls to be placed where the app requests for them to be) - has developers who actually give a fuck
7
4
256
5,334