Choujun! Choujou-senpai: release date, trailer, and everything we know
A new anime is coming: Choujun! Choujou-senpai. Release date, trailer, concept - furansujapon covers the announcement. Here's what you need to know.
2 h ago 16 4
A new anime is coming: Choujun! Choujou-senpai. Release date, trailer, concept - furansujapon covers the announcement. Here's what you need to know.
2 h ago 16 4
A new malicious campaign dubbed DOUBLECUP exploits the ClickFix technique and cached PNGs to distribute two malware families: CountLoader and DeviceManager RAT. Anatomy of a two-stage attack.
2 h ago 24 3
A flaw in the random number generator of the COLDCARD hardware wallet could have allowed the derivation and draining of thousands of wallets—one of the largest documented thefts on "cold" hardware.
yesterday 9 3
Unit 42 (Palo Alto) documents a real-world case of an autonomous LLM agent: a single instruction sent via Telegram was enough to scan the internet, select a public exploit, and launch an attack—without any further human intervention.
Jul 31, 2026 18 3
Anthropic ran Claude Mythos Preview as a semi-autonomous agent on cryptographic primitives: effective keysize of HAWK-256 dropped from 2^64 to 2^38, 7-round AES attack accelerated ×200 to ×800, LEA 13-round key recovery in less than an hour. Two real CVE (OpenSSL, wolfSSL) along the way. Cost: ~$100,000 API per subject.
Jul 28, 2026 20 4
Lava scanned the net in May 2026: 36,872 exposed BMC interfaces, including 24,650 that spit out the IPMI hash on a simple RAKP request. A 13-year-old spec flaw, unpatchable, with Supermicro, HPE iLO, and Dell in the front line.
Jul 28, 2026 12 3
Nozomi Networks Labs documents Tengu, a multi-architecture Linux botnet that abuses the kernel watchdog and rewrites reboot binaries to survive cleanup attempts - all controlled via ChaCha20/Poly1305.
Jul 28, 2026 9 2
Moonshot AI publishes the weights of Kimi K3 on Hugging Face, a few days after the preliminary evaluation of the model's cyber capabilities by the British and American institutes AISI/CAISI. A milestone for the "AI agents and threats" thread.
Jul 27, 2026 17 3
A researcher claims to have alerted SharkNinja as early as March about a vulnerability that allows remote control of Shark robot vacuum cleaners, access to their camera, and the exfiltration of sensitive data. Patches are still awaited.
Jul 27, 2026 4 1
Five days after OpenAI's admission, a LessWrong post surfaced on July 26 as the top story on HN, highlighting the gray areas: which specific notes, in what context, and why the public report remains so vague.
Jul 26, 2026 6 2
New stone in the "Offensive LLMs" file after the Hugging Face breach and the OpenAI sandbox exploit: UK AISI and CAISI publish a preliminary assessment of the cyber offensive capabilities of Kimi K3, the Chinese open-weight model with 2.8 T parameters. In parallel, a researcher releases a functional exploit against the latest Redis server obtained via this same model.
Jul 25, 2026 7 2
CVE-2026-54121, CVSS 8.8. A domain account with no privileges is sufficient to obtain an AD CS-signed certificate for the identity of a Domain Controller, then authenticate via PKINIT and extract krbtgt via DCSync. Patched on July 14, 2026, public exploit since today.
Jul 24, 2026 3 1