Sign in

dragosr

@dragostech.bsky.social
1.7K followers 3.8K following 1.3K posts

Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV

PostsRepliesMedia
dragosr @dragostech.bsky.social · 01/10/2026
Mr. Scruffles goes to CanSecWest...
Mr. Scruffles, a small brown plush cat wearing a CanSecWest-branded lanyard, sits on a conference table at CanSecWest. Behind him, attendees face two projection screens showing a presentation, with a large red CanSecWest banner between them.
160
dragosr @dragostech.bsky.social · 13/09/2026
"Blinding speed" would have to qualify as sarcasm. control_run_pass75.py I'm looking at you.
010
dragosr @dragostech.bsky.social · 13/09/2026
In practice, it's a lot of sequential passes over the same chunks of code. Patience helps.
110
dragosr @dragostech.bsky.social · 13/09/2026
Or installing electric heat pumps.
100
dragosr @dragostech.bsky.social · 12/09/2026
Anyone worried about, or scared of "machine speed" attacks probably hasn't spent any time babysitting an LLM vulnerability discovery and/or verification pipeline. ;-P
262
Reposted by dragosr
The Washington Sun @washingtonsun.com · 09/09/2026
Washington journalism is in a moment of generational change. We're rising to meet it. Welcome to The Washington Sun. washingtonsun.com
47817300
dragosr @dragostech.bsky.social · 08/09/2026
Yes, it's terrible, we can now talk to it and it responds. It understand when we make typos and infers what we wanted to do without throwing errors. It's absolutely horrible now.
010
dragosr @dragostech.bsky.social · 18/08/2026
Also seeking one more panelist for "Who Guards the Guardians?" on safety classifiers, guardrails, and their effect on security research. Promises to be interesting. :-) Image prompt: geoposition CanSecWest 2026 from Vancouver building profile extrapolation, wire-mesh from overlaid targeting reticle
Aerial view of Vancouver’s Coal Harbour skyline and marina, overlaid with a cyan targeting reticle highlighting the Pinnacle Harbourfront hotel. A wireframe magnification panel promotes CanSecWest 2026 at Pinnacle Harbourside, September 30–October 1, with the website secwest.net.
010
dragosr @dragostech.bsky.social · 18/08/2026
New training: reverse engineering with LLMs and Ghidra from Kara Nance, author of the No Starch Ghidra Book (she's also presenting her optical drone tracking work), plus Erlend Oftedal's two-day workshop on building an agentic vuln discovery pipeline. Registration just opened.
Aerial view of Vancouver’s Coal Harbour skyline and marina, overlaid with a cyan targeting reticle highlighting the Pinnacle Harbourfront hotel. A wireframe magnification panel promotes CanSecWest 2026 at Pinnacle Harbourside, September 30–October 1, with the website secwest.net.
110
dragosr @dragostech.bsky.social · 18/08/2026
Last week for CanSecWest submissions. Vancouver, Sept 30 / Oct 1. Keynotes: Bruce Schneier and Katie Moussouris. Sergey Bratus on automated micro-patching. Paper announcements coming to the site as we proceed. CFP and registration: secwest.net 🧵
Aerial view of Vancouver’s Coal Harbour skyline and marina, overlaid with a cyan targeting reticle highlighting the Pinnacle Harbourfront hotel. A wireframe magnification panel promotes CanSecWest 2026 at Pinnacle Harbourside, September 30–October 1, with the website secwest.net.
153
dragosr @dragostech.bsky.social · 31/07/2026
WireGuard powers world’s fastest VPN services. Technology behind Tailscale now goes where UDP can't: WireguardTCP delivers familiar configuration, kernel-native performance, NAT traversal, seamless roaming, with improved throughput, latency, and CPU load improvements over UDP. wireguardtcp.net
wireguardtcp.net
WireguardTCP — WireGuard over TCP
Same encrypted tunnel. A long-lived TCP carrier. Get the source and watch the binary release channels.
050
Reposted by dragosr
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
I’ve been working on a hobby project to crack classical ciphers. The guts of it is to see whether frontier LLMs, given the right tools, can do a good job cracking a broad range of historical ciphers. github.com/matthewdgree...
github.com
GitHub - matthewdgreen/decipher: An AI-enabled application for cracking ciphers
An AI-enabled application for cracking ciphers. Contribute to matthewdgreen/decipher development by creating an account on GitHub.
58818
Reposted by dragosr
Miska Knapek @miskaknapek.bsky.social · 18/07/2026
Impressive energy storage developments in the Middle East - Saudi Arabia is building a 12 GWH battery park too, in addition to the 11.3 GWH Abu Dhabi Project below. The Abu Dhabi Project takes power from a 5 GW solar plant ( 1GW is about what a nuclear power plant produces. So they got 11.3 hrs)
0197
Reposted by dragosr
J.R. Orci @orci.mastodon.social.ap.brid.gy · 10/07/2026
Flock CEO: "Unfortunately, there’s terrorist organizations like DeFlock whose primary motivation is chaos. They’re closer to Antifa than they are anything else." #privacy #JoinAntifa deflock.org
deflock.org
DeFlock
Find license plate readers (LPRs) near you.
2337
dragosr @dragostech.bsky.social · 24/06/2026
Remember, every data center Azure has been building since 2024 is closed loop, zero water use. Google and AWS don't have as clean a record, but even massive Oracle Stargate is also zero water use. All the big new AI datacenters, essentially have no water use to complain about. It's an old problem.
100
dragosr @dragostech.bsky.social · 24/06/2026
The water charges in most places not drinking whole rivers offsets the additional power charges. I ran the numbers for the new (small) datacenters Telus is building in Vancouver — would mean about $1-2m/per year more cost for evaporative even including more power used for coolers and power savings.
200
dragosr @dragostech.bsky.social · 24/06/2026
Legacy data centers. Not the new ones - excepting Google's seawater cooled experiment in Finland and any other derivatives. The new designs, including any based on Nvidia's AI reference are closed loop.
100
dragosr @dragostech.bsky.social · 24/06/2026
The datacenter design is symbiotic with the design of the Nvidia NLV72 racks. Here is the picture of (currently) world's largest AI center in Wisconsin. It's a lot of fans with radiators recirculating closed loop cooling liquid (non-evaporative) to the building just off camera that has GB300s GPUs.
Aerial view of Microsoft’s Azure Fairwater data center in Wisconsin under construction, showing two long parallel rows of large circular cooling fans that form the facility’s closed-loop GPU cooling system, flanked by white-roofed data center halls with overhead pipe runs connecting them.
000
dragosr @dragostech.bsky.social · 24/06/2026
15,000 golf courses though, and datacenters all in use less than 8% of what they do. Consumptive use (evaporated, not returned to the watershed) is what matters for stress. Data center cooling towers evaporate; golf course irrigation also mostly evaporates so comparable. But Ag water use 80x more!
100
dragosr @dragostech.bsky.social · 24/06/2026
The nuclear industry is also another walking zombie. Won't have the justification to build large grid scale reactor or any beyond small experiments. >$180-225/mWH and 10y builds just can't compete with 2y build Solar dropping below $30 and getting below $50-$70 - cheaper than gas - with 24h battery.
030
dragosr @dragostech.bsky.social · 24/06/2026
PV has been dropping by 50% every two years, and while not dropping so fast it will keep winning. Grid scale battery costs dropped 93% in a decade. US public and gas industry hasn't figured out that Solar won, years ago, and will keep winning. But power companies got the memo, raw economics wins.
Stacked bar chart of U.S. new utility-scale power capacity additions by source, 2023 to 2027. Each bar shows percentage share; total new gigawatts are labeled above. 2023 (actual): solar 46%, battery 16%, wind 15%, gas 20%, 40 GW total. 2024 (actual): solar 63%, battery 21%, wind 10%, gas 5%, 49 GW. 2025 (actual): solar 51%, battery 28%, wind 9%, gas 9%, 53 GW. 2026 (planned): solar 51%, battery 28%, wind 14%, gas 7%, 86 GW. 2027 (projected): solar 46%, battery 28%, wind 12%, gas 12%, 65 GW. Source: EIA Preliminary Monthly Electric Generator Inventory.
440
dragosr @dragostech.bsky.social · 24/06/2026
Internationally solar adoption is happening even faster. US problem is transmission sys not designed for distributed solar. Only reason small amt of more expensive combined cycle gas gets built now is because of weird NIMBY battle between muni, state, fed, and 7 year avg interconnect study delay.
150
dragosr @dragostech.bsky.social · 24/06/2026
Closed loop is actually cheaper capex in most locations. And if you are referring to the BS about counting water used by power, US grid is decarbonizing fast, because solar won the LCOE battle. US new power plants >90% solar, battery, small wind, for last 3y and indefinitely as it gets even cheaper.
130
dragosr @dragostech.bsky.social · 24/06/2026
WTF, what's happened to Popehat? This isn't cool at all. @kenwhite.bsky.social
120
Reposted by dragosr
Joseph Menn @joemenn.bsky.social · 24/06/2026
The global nightmare continues.
theguardian.com
Whistleblower investigating Ecuadorian president’s family business was murdered, activists say
Monika Silva Koniuszek died from a blow to the head and strangulation, postmortem found, despite government claim of suicide
12613
dragosr @dragostech.bsky.social · 24/06/2026
New data centers are closed loop cooling. No real water use. All the new Nvidia AI stuff is closed loop too. Water use is mostly a thing at legacy datacenters, and kind of a red herring. Wait till you hear about golf courses...
2471
dragosr @dragostech.bsky.social · 23/06/2026
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write pre-auth so network attacks can deliver the packet even when client pins host keys github.com/bikini/explo... www.linkedin.com/posts/dragos...
linkedin.com
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write   CVE-2026-55200 is a pre-auth out-of-bounds heap write in… | D...
Don't see these that often, malicious server, no auth, no interaction, RCE in ssh. CVE-2026-55200 — libssh2 pre-auth heap OOB write   CVE-2026-55200 is a pre-auth out-of-bounds heap write in libssh2'...
052
dragosr @dragostech.bsky.social · 12/06/2026
github.com/rebane2001/x...
github.com
GitHub - rebane2001/x86CSS: x86CSS is a working CSS-only x86 CPU/emulator/computer. No JavaScript required.
x86CSS is a working CSS-only x86 CPU/emulator/computer. No JavaScript required. - rebane2001/x86CSS
030
dragosr @dragostech.bsky.social · 12/06/2026
I still use it, infrequently, in places where OpenBSD drivers don't work. They have such a weird driver mismatch between the two BSDs, each has drivers working that the other doesn't.
120
dragosr @dragostech.bsky.social · 11/06/2026
This kind of hurt my eyes and my brain, and reinforced my opinion that FreeBSD is a softer target amongst OS platforms. It is pretty funny though, and definitely gets some style points for a vulnerability disclosure. bumsrake.de
bumsrake.de
BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.
BUMSRAKETE is a HUGE, TREMENDOUS, MANY-PEOPLE-ARE-SAYING FreeBSD kTLS-RX page-cache write primitive. The BEST primitive. Some say the best ever.
2177
dragosr @dragostech.bsky.social · 11/06/2026
<obiwan> It's over, petrofuel industry.... Solar has the high ground. </obiwan>
010
dragosr @dragostech.bsky.social · 10/06/2026
The Anthropic Fable-5 safety classifiers seem to be written by the OpenAI marketing department. Pretty much anything I talk to LLMs about gets downgraded. Nerfed into useless. Worst model release ever?
A classic Scooby-Doo meme template set in a dark, stone dungeon filled with cobwebs. Fred stands in the center, pulling a green ghost mask off the villain to reveal an grumpy, elderly man tied to a wooden chair. Velma points at the unmasked villain while Daphne stands next to her. On the left, Shaggy and a frightened Scooby-Doo look on.

White text labels are superimposed over the image: the ghost mask is labeled "Fable-5" and the unmasked villain is labeled "Opus-4.8", implying that the supposedly new or monstrous "Fable-5" is actually just "Opus-4.8" in disguise.
171
Reposted by dragosr
Michael Geist @mgeist.bsky.social · 08/06/2026
The Globe reports that online harms legislation is coming this week that includes a “temporary” social media for kids under 16. My post on why this effectively establishes mandated ID for all Canadians to use social media and AI and it won’t be temporary. www.michaelgeist.ca/2026/06/you-...
michaelgeist.ca
You Can’t Put the Toothpaste Back in the Tube: Why the Government’s Reported “Temporary” Plan for a Kids’ Social Media and AI Chatbot Ban Would Mean Mandated ID for Everyone - Michael Geist
The Globe and Mail reports today that the government will introduce online harms legislation this week that includes a ban on social media for kids under the age of 16. The ban will be framed as a “te...
11612
dragosr @dragostech.bsky.social · 31/05/2026
When you leave all the mitigations on, crank up the inference settings to maximum, and run the exploit benchmark to see how close the PoCs can get.
Anime mech-style illustration of a confused humanoid murderbot sitting at a cluttered cyberpunk hacking station, one hand on its head as holographic warning screens announce “TOKEN BUDGET EXHAUSTED,” “CONTEXT WINDOW FULL,” “PROMPT TURN CAP REACHED,” and “OUT OF SPACE TO CONTINUE.” The robot is surrounded by half-finished exploit diagrams, terminal errors, sticky notes, ramen, pizza, and a whiteboard attack plan that has stalled at “???” because the AI system limits have been reached.
010
dragosr @dragostech.bsky.social · 28/05/2026
The thought processes of AI native kids: 9-year old gets a DOCX file from school laptop, wants to read it, doesn't have M365. His first impulse is to use GPT to write a python script to convert it to TXT so he can use VSCode, instead of asking for Word. When AI is the path of least resistance.
150
dragosr @dragostech.bsky.social · 26/05/2026
Fix: Starlette 1.0.1. Rebuild every container and bundled artifact. Durable code fix: use request.scope["path"], not request.url.path, for any security decision. Footnote: vendor pushed ~4 months; patch + disclosure landed same day, with downspin. Assume zero exploit dev lead time. 6/6
021
dragosr @dragostech.bsky.social · 26/05/2026
Test a live endpoint with the free online scanner: badhost.org (X41 D-Sec / Persistent Security Industries / Bintech). Scan source with Semgrep + CodeQL rules: github.com/x41sec/poc/tree/master/starlette-host-header Hat Tip to OSTIF.org that sponsored vLLM audit 5/6
badhost.org
BadHost - CVE-2026-48710 Starlette Host-Header Auth Bypass
Scan your Starlette or FastAPI server for CVE-2026-48710 (BadHost): a critical auth bypass via Host header injection affecting MCP servers, LLM proxies, AI agent frameworks, and thousands of Python AS...
111
dragosr @dragostech.bsky.social · 26/05/2026
Why AI infra is disproportionately exposed: FastAPI stacks are routinely deployed direct-to-uvicorn on lab subnets and workstations. No proxy frontend, no incidental mitigation. The exposed endpoints are the high-value ones: admin, key issuance, model load, tool execution. 4/6
101
dragosr @dragostech.bsky.social · 26/05/2026
Exploit primitive: one character. curl -H 'Host: foo' /admin → 403 curl -H 'Host: foo?' /admin → 200 Patch shipped quietly as CVSS 6.5 Moderate; discoverers rate it critical. X41 chains reach auth bypass, SSRF, and RCE in downstream projects. 3/6
101
dragosr @dragostech.bsky.social · 26/05/2026
The bug: Starlette rebuilds request.url by string-concatenating the Host header and re-parsing. No RFC validation. A ? or / in Host shifts the path boundary. Router dispatches the real wire path. Middleware sees the poisoned one. Auth gate bypassed. Huge problem for most AI/LLM stacks. 2/6
101
dragosr @dragostech.bsky.social · 26/05/2026
🚨CVE-2026-48710("BadHost"): one character in a Host header bypasses path-based authorization across most of the Python AI stack. Lives in Starlette, reaches FastAPI and through it: vLLM (where it was discovered), LiteLLM, TGI, MCP servers, agent harnesses, eval dashboards. cc @marver.bsky.social
secwest.net
starlette - secwest.net - secure virtual engagement
242
dragosr @dragostech.bsky.social · 26/05/2026
Exploit primitive: one character. curl -H 'Host: foo' /admin → 403 curl -H 'Host: foo?' /admin → 200 Patch shipped quietly as CVSS 6.5 Moderate; discoverers rate it critical. X41 chains reach auth bypass, SSRF, and RCE in downstream projects.
000
Reposted by dragosr
Michael Geist @mgeist.bsky.social · 21/05/2026
Faced with growing criticism of Bill C-22, CSIS, RCMP, and Public Safety this week tried to make the case for lawful access. My post on why they instead revealed a bill with dangerously disproportionate overreach with real risks of tracking all Canadians. www.michaelgeist.ca/2026/05/the-...
michaelgeist.ca
The Government Tries to Make the Case for Bill C-22: Why Its Own Use Cases Reveal Disproportionate Overreach - Michael Geist
Faced with growing criticism of Bill C-22, the government this week mounted a coordinated defence, with senior officials from CSIS, the RCMP, and Public Safety Canada sitting for on-the-record briefin...
02217
dragosr @dragostech.bsky.social · 16/05/2026
I don't think the authors of this bill have really thought of the implications of not having Signal in Canada. Contact your MP today, before they neuter Canadian technology, and cripple our security.
155
Reposted by dragosr
Alex Andreou @sturdyalex.bsky.social · 16/05/2026
Sneaking a giant screen into the flagshagger march is one of the funniest things @ledbydonkeys.org have ever done. "STAY HYDRATED" 😂🤣😂
342135154166
Reposted by dragosr
David Roberts @volts.wtf · 15/05/2026
Grid-scale batteries are going in an absolutely wild pace. Every whingey objection to renewables you've ever heard is basically solved by batteries. This is happening whether any of the hopeless dipshits running the US want it or not.
canarymedia.com
The world is installing grid batteries at a blistering pace
A total of 112 gigawatts of batteries were deployed around the world in 2025 — 10 times the amount added just four years prior.
723544979
dragosr @dragostech.bsky.social · 11/05/2026
Raelize had LLMs reproduce older ESP32 Secure Boot V1 bypass via voltage glitching in a few days. AI wrote the tooling and built a live dashboard mid-campaign. 20k shots, 12.2% bypass rate. Workflow compression is the story. ESP32 v3 mitigates this. raelize.com/blog/ai-fi-g...
Dark infographic titled "AI-Driven Fault Injection on ESP32 Secure Boot." In the middle, an ESP32 chip is struck by a yellow lightning bolt, representing voltage glitching. A cyan box on the left labeled "AI Agent (Claude Code)" points to the chip, and a green box on the right shows an open lock and "Secure Boot Bypassed." Three large result cards sit below: the initial scan used 1,000 shots and found 1 bypass, the refined timing window used a 1.5-2 us delay and 3-4 us width for a 9.3% hit rate, and the voltage sweep from 2.00-3.00 V across 20,200 shots produced 2,468 bypasses, or 12.2% overall. The footer says AI automated the stack while humans set direction, emphasizing that the attack was known but the engineering effort was reduced.
120
dragosr @dragostech.bsky.social · 11/05/2026
There is someone from HR here... They seem to want to talk to you about your choice of vehicles in your social media posts.
000
dragosr @dragostech.bsky.social · 08/05/2026
"Dirty Frag" clickbait update: ESP (CVE-2026-43284) patched in mainline + stable (7.0.5, 6.18.28, 6.12.87, 6.6.138, 6.1.171). RxRPC (CVE-2026-43500) still unpatched upstream. AWS adds ipcomp4/ipcomp6 to the blacklist alongside esp4/esp6/rxrpc. AlmaLinux shipped both. Ubuntu/Debian mitigation only.
Infographic titled "Dirty Frag: Overhyped" framing the issue as a local Linux kernel privilege-escalation bug, not a remote wormable threat. It explains two exploit paths: ESP/IPsec, which needs a fresh user namespace to gain CAP_NET_ADMIN for XFRM SA registration, and RxRPC, which needs no namespace or extra capability if rxrpc.ko is present. Ubuntu and Debian namespace protections are shown as blocking the ESP path, while RxRPC can still bypass that defense. Other distro trade-offs are summarized, with RHEL-like systems often lacking RxRPC but leaving ESP reachable. Mitigations include blacklisting esp4, esp6, rxrpc, optionally ipcomp4/ipcomp6, using user namespace hardening, and relying on default container seccomp where applicable. Patch status notes ESP fixes in mainline and stable kernels, while RxRPC upstream status is still pending, with some distro-specific patched kernels already shipping.
020
dragosr @dragostech.bsky.social · 02/05/2026
My retort for anyone who insists LLMs are just "spicy autocorrect" and can't reason: Sure, and you're just spicy electrochemistry. If it walks like reasoning, and proves theorems like reasoning, maybe we need to stop calling it a duck shaped Markov chain.
010