Sign in

Matthias

@grambulf.bsky.social
62 followers 175 following 2 posts

InfoSec & shitposting English & german Also infosec.exchange/@grambulf

PostsRepliesMedia
Reposted by Matthias
ᴉpᴉǝH 🐐💕 @summerheidi.bsky.social · 02/10/2026
012
Reposted by Matthias
Elle Cordova @ellecordova.bsky.social · 03/09/2026
Rough Draft vs Final Draft
254116923321
Reposted by Matthias
Razzball @razzball.bsky.social · 07/08/2026
gets incredible air here
256145453363
Reposted by Matthias
DilDog 🅅 @dildog.l0pht.com · 24/07/2026
AI Expert Advice: Make Claude Code work faster by telling it to type with a Dvorak keyboard layout, which is optimized for speed
28715
Reposted by Matthias
Kodo and Sangha! @kodoandsangha.bsky.social · 08/06/2026
We need this whimsy and joy. Absolutely solid beats.
1020774
Reposted by Matthias
Jake Williams @malwarejake.bsky.social · 11/06/2026
I can't wait to have a separate security budget for tokens...
4224
Reposted by Matthias
Ian Coldwater 🧊🚫 @lookitup.baby · 30/05/2026
If your org still hasn’t figured out things like how to patch without production falling over or getting teams to talk to each other, a higher volume of findings will only make those things worse. Before you worry about Mythos, figure out how you’re going to deal with that
313619
Reposted by Matthias
Ian Dees @iandees.bsky.social · 26/05/2026
Recent status: watching someone that works at Zoom take a past due security training about not taking meetings in public spaces while he was on a train going between Copenhagen and Stockholm. He completed his training then had a sales meeting about volume discounts.
A photo of a Dell laptop screen taken between two train seats. The screen has a training video with the text "You never know who's sitting next to you" showing on it. The picture taker is sitting behind the person taking the training, so it's OK.
361859317
Reposted by Matthias
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/05/2026
#Mythos finds a #curl vulnerability yes, as in singular one. daniel.haxx.se/blog/2026/05/11/myth…
daniel.haxx.se
Mythos finds a curl vulnerability
yes, as in singular _one_. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model _Mythos_ is _dangerously good_ at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it. The whole world seemed to lose its marbles. Is this the end of the world as we know it? An amazingly successful marketing stunt for sure. ## My (non-) access Part of the deal with _project Glasswing _was that Anthropic also offered access to their latest AI model to “Open Source projects” via Linux Foundation. Linux Foundation let their project Alpha Omega handle this part, and I was contacted by their representatives. As lead developer of curl I was offered access to the magic model and I graciously accepted the offer. Sure, I’d like to see what it can find in curl. I signed the contract for getting access, but then nothing happened. Weeks went past and I was told there was a hiccup somewhere and access was delayed. Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report. To me, the distinction isn’t that important. It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. Getting the tool to generate a first proper scan and analysis would be great, whoever did it. I happily accepted this offer. (I am purposely leaving out the identity of the individual(s) involved in getting the curl analysis done as it is not the point of this blog post.) ## AI scans of curl Before this first Mythos report, we had already scanned curl with several different very capable AI powered tools (I mean _in addition to_ running a number of “normal” static code analyzers all the time, using the pickiest compiler options and doing fuzzing on it for years etc). Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between _two and three hundred_ bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more. Nowadays we also use tools like GitHub’s Copilot and Augment code to review pull requests, and their remarks and complaints help us to land better code and avoid merging new bugs. I mean, we still merge bugs of course but the PR review bots regularly highlight issues that we fix: our merges would be worse without them. The AI reviews are used _in addition_ to the human reviews. They help us, they don’t replace us. We also see a high volume of high quality security reports flooding in: security researchers now use AI extensively and effectively. Security is a _top_ _priority_ for us in the curl project. We follow every guideline and we do software engineering properly, to reduce the number of flaws in code. Scanning for flaws is just one of many steps to keep this ship safe. You need to search long and hard to find another software project that makes as much or goes further than curl, for software security. Steps involved in keeping curl secure ## May 6, 2026 It was with great anticipation we received the first source code analysis report generated with Mythos. Another chance for us to find areas to improve and bugs to fix. To make an even better curl. This initial scan was made on curl’s git repository and its master branch of a certain recent commit. It counted 178K lines of code analyzed in the src/ and lib/ subdirectories. The analysis details several different approaches and methods it has performed the search, and how it has focused on trying to find which flaws. A fun note in the top of the report says: > curl is one of the most fuzzed and audited C codebases in existence (OSS-Fuzz, Coverity, CodeQL, multiple paid audits). Finding anything in the hot paths (HTTP/1, TLS, URL parsing core) is unlikely. … and it correctly found no problems in those areas. Completely unscientific poll on Mastodon about people’s expectations for Mythos scanning curl ## The size of curl curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece. On average, every single production source code line of curl has been written (and then rewritten) 4.14 times. We have polished on this. Right now, the existing production code in git master that still remains, has been authored by 573 separate individuals. Over time, a total of 1,465 individuals have so far had their proposed changes merged into curl’s git repository. We have published 188 CVEs for curl up until now. curl is installed in over _twenty million instances_. It runs on over _110 operating systems_ and _28 CPU architectures_. It runs in every smart phone, tablet, car, TV, game console and server on earth. ## Five findings became one The report concluded it found **five** “Confirmed security vulnerabilities”. I think using the term _confirmed_ is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take. Five issues felt like nothing as we had expected an extensive list. Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with _one_ confirmed vulnerability. The other four were three false positives (they highlighted shortcomings that are documented in API documentation) and the fourth we deemed “just a bug”. The single confirmed vulnerability is going to end up a _severity low_ CVE planned to get published in sync with our pending next curl release 8.21.0 in late June. The flaw is not going to make anyone grasp for breath. All details of that vulnerability will of course not get public before then, so you need to hold out for details on that. The Mythos report on curl also contained a number of spotted bugs that it concluded were not vulnerabilities, much like any new code analyzer does when you run it on hundreds of thousands of lines of code. All the bugs in the report are being investigated and one bye one we are fixing those that we agree with. All in all about twenty bugs that are described and explained very nicely. Barely any false positives, so I presume they have had a rather high threshold for certainty. curl is certainly getting better thanks to this report, but counted by the volume of issues found, all the previous AI tools we have used have resulted in larger bugfix amounts. This is only natural of course since the first tools we ran had many more and easier bugs to find. As we have fixed issues along the way, finding new ones are slowly becoming harder. Additionally, a bug can be small or big so it’s not always fair to just compare numbers ## Not particularly “dangerous” My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. This is just _one_ source code repository and maybe it is much better on other things. I can only tell and comment on what it found here. ## Still very good But allow me to highlight and reiterate what I have said before: AI powered code analyzers are _significantly_ better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past. All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real. Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others. Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find. ## How AI analyzers differ * They can spot when the comment says something about the code and then conclude that the code does not work as the comment says. * It can check code for platforms and configurations we otherwise cannot run analyzers for * It “knows” details about 3rd party libraries and their APIs so it can detect abuse or bad assumptions. * It “knows” details about protocols curl implements and can question details in the code that seem to violate or contract protocol specifications * They are typically good at summarizing and explaining the flaw, something which can be rather tedious and difficult with old style analyzers. * They can often generate and offer a patch for its found issue (even if the patch usually is not a 100% fix). ## More details from the report **Zero memory-safety vulnerabilities found.** Methodology note: this review is hand-driven analysis using LLM subagents for parallel file reads, with every candidate finding re-verified by direct source inspection in the main session before being recorded. The CVE to variant-hunt mapping was built from curl’s own vuln.json. No automated SAST tooling was used. This outcome is consistent with curl’s status as one of the most heavily fuzzed and audited C codebases. The defensive infrastructure (capped dynbufs everywhere, `curlx_str_number` with explicit max on every numeric parse, `curlx_memdup0` overflow guard, CURL_PRINTF format-string enforcement, per-protocol response-size caps, pingpong 64KB line cap) systematically closes the bug classes that would normally be productive in a codebase this size. Coverage now includes: all minor protocols, all file parsers, all TLS backends’ verify paths, http/1/2/3, ftp full depth, mprintf, x509asn1, doh, all auth mechanisms, content encoding, connection reuse, session cache, CLI tool, platform-specific code, and CI/build supply chain. ## AI finds existing kinds of errors It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before. ## More to find These were absolutely not the last bugs to find or report. Just while I was writing the drafts for this blog post we have received more reports from security researchers about suspected problems. The AI tools will improve further and the researchers can find new and different ways to prompt the existing AIs to make them find more. We have not reached the end of this yet. I hope we can keep getting more curl scans done with Mythos and other AIs, over and over until they truly stop finding new problems. ## Credits Thanks to Anthropic and Alpha Omega for providing the model, the tools and doing the scan for us. Thanks also to the individual who did the scan for us. Much appreciated! Top image by Jin Kim from Pixabay Thanks for flying curl. It’s never dull.
7247121
Reposted by Matthias
Chris Paxton @cpaxton.bsky.social · 17/04/2026
We all have days like this
34480712134
Reposted by Matthias
Hans-Böckler-Stiftung @boeckler-stiftung.bsky.social · 07/04/2026
(1/5) Bürgergeldbeziehenden wird oft unterstellt, sie seien faul und arbeitsunwillig. Dabei ist die Gruppe derjenigen, die sich einer Arbeit komplett verweigern, in Wahrheit extrem klein. 👇 📌 Mehr dazu in unserem Impuls-Beitrag:
boeckler.de
Mythos „Totalverweigerer“
Die Vorwürfe halten sich hartnäckig: Arbeitsunwillige würden das Sozialsystem in großem Stil ausnutzen. Doch die Fakten sagen etwas anderes.
24625
Reposted by Matthias
Kashana @kashana.blacksky.app · 07/04/2026
Armageddon is terrible, but our only other option was diversity trainings at work.
1824324010794
Reposted by Matthias
CosmoQuest @cosmoquest.org · 02/04/2026
There are now 10 toilets in Space International Space Station: 4 Crew Dragon Docked at ISS: 1 Soyuz Docked at ISS: 1 Tiangong Space Station: 2 Shenzhou Docked at TSS: 1 Artemis II on way around Moon: 1 This will be the first time a toilet has left low earth orbit!
15456731595
Reposted by Matthias
Carl Quintanilla @carlquintanilla.bsky.social · 27/03/2026
195158544706
Reposted by Matthias
Tabitha Sable @tabbysable.bsky.social · 25/03/2026
🚨 ingress-nginx is now retired 🚨 Stop by the SIG Security booth P-4B at #kubecon #cloudnativecon for a commemorative sticker! We will be there this afternoon and Thursday afternoon. Hope to see you there!
A cackling goose (Branta Hutchinsii) in flight, proclaiming “I migrated off ingress-nginx!”

Does she look joyful? Does she look mischievous? Is she just glad it’s over? Only you know for sure!
2216
Reposted by Matthias
Tabitha Sable @tabbysable.bsky.social · 19/03/2026
By the way, we just published another privilege-escalation CVE in ingress-nginx: github.com/kubernetes/k... 🚨 This will be the final, final release. Please migrate off ingress-nginx as soon as possible. 🚨
github.com
CVE-2026-4342: ingress-nginx comment-based nginx configuration injection · Issue #137893 · kubernetes/kubernetes
CVSS Rating: 8.8 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuratio...
0105
Reposted by Matthias
Zack Whittaker @zackwhittaker.com · 31/12/2025
Are you a security researcher or journalist? We want to hear from you! Please take this survey! DataBreaches.net and myself (at this.weekinsecurity.com) are running this survey to better understand the state of legal demands and criminal threats experienced in cybersecurity. Please share!
forms.gle
Survey about legal and criminal threats experienced by journalists and security researchers
Researchers who try to responsibly disclose leaks, vulnerabilities, and other security breaches or mishaps may face legal threats or lawsuits. Similarly, journalists may find themselves threatened wit...
21925
Reposted by Matthias
Ashley Willis-McNamara @ashley.dev · 02/12/2025
TL;DR Middle management is hard. Caring is required, but the kind of care you provide matters.
ashley.dev
Ashley Willis
The other day I texted my group chat with other leaders outside my organization. The ones I go to when the leadership stuff gets messy and I need perspective fr...
89027
Reposted by Matthias
Kat Traxler @nanook.bsky.social · 11/09/2025
🎉🥳My latest whitepaper has been nearly a year in the making and it’s finally out! 🎉🥳 A huge thanks to the many friends and colleagues that participated in the review process. www.vectra.ai/resources/co... #gcp #aws #msft #NHI #cloudsecurity #multicloud
vectra.ai
Comparing CSP-Managed Machine Identities
Comparing AWS, Google Cloud, and Microsoft CSP-managed machine identities, risks, and security responsibilities.
051
Reposted by Matthias
Ian Coldwater 🧊🚫 @lookitup.baby · 10/08/2025
youtu.be
Keanu Reeves Laughs at the Idea of NFTs - Keanu Reeves The Verge Interview
YouTube video by nemseivideos
315717
Reposted by Matthias
Filippo Valsorda @filippo.abyssdomain.expert · 04/08/2025
Certificate Transparency is meant for browsers and website owners. However, I estimate a majority of clients is only interested in discovering domain names. I am proposing an optional, less secure, 20x more efficient API for those clients. With this, a CT log can probably operate with < 1 Gbps.
groups.google.com
The names tiles Static CT API extension
Certificate Transparency Policy
1355
Reposted by Matthias
Kim Zetter @kimzetter.bsky.social · 21/07/2025
I'll be testifying tomorrow at 10am before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection about Stuxnet and critical infrastructure security. Also on panel will be Rob Lee (Dragos), Tatyana Bolton, and Nate Gleason
homeland.house.gov
Fully Operational: Stuxnet 15 Years Later and the Evolution of Cyber Threats to Critical Infrastructure. – Committee on Homeland Security
3558
Reposted by Matthias
George Takei @georgetakei.bsky.social · 21/07/2025
When I was little, the U.S. military came to our home at gunpoint and took me and my family away. We were imprisoned for years in barbed wire camps simply because we were Japanese American. I have spent my life telling that story, hoping it would never be repeated.
15636838620868
Reposted by Matthias
Sam Jaques @sejaques.bsky.social · 19/06/2025
An out-of-schedule update to my quantum landscape chart: sam-jaques.appspot.com/quantum_land..., prompted by @craiggidney.bsky.social 's new paper: arxiv.org/abs/2505.15917. A startling jump (20x) in how easy quantum factoring can be! Also: much improved web design!
A chart for quantum computers, of number of qubits versus error rate, on a logarithmic scale. Broadly it shows a large gap between current quantum computers in the bottom left, and a curve in the top right of the resources they need to break RSA.
36126
Reposted by Matthias
Stone Cold Jane Austen @abbyhiggs.bsky.social · 22/06/2025
It’s a good thing Congress isn’t alive to see this
8086336414275
Reposted by Matthias
Ned Pyle @nedpyle.com · 19/06/2025
Bluesky is not twitter because we block losers before we even see their sad attention seeking. Think of it as vaccinating your account. Here’s an example: 1. Go to @skywatch.blue 2. Tap Lists and scroll down to MAGA 3. Tap subscribe & then block accounts. 4. All the magas now rot on the vine
The skywatch account lists The maga listThe block accounts button
37320128
Reposted by Matthias
Ashley Willis-McNamara @ashley.dev · 17/06/2025
New blog: I’ll admit, this one’s a bit of a ramble, mostly because I care a lot about how we give feedback, how we receive it, and why it so often feels like an attack (even when it isn’t). TL;DR: Feedback is care, when it’s done with intention. ashley.dev/posts/feedba...
ashley.dev
Ashley Willis
TL;DR This one’s a bit of a ramble because I care a lot about this topic. So here’s the TL;DR for anyone who doesn’t have the energy (or executive function) to ...
811622
Reposted by Matthias
Corey Quinn @quinnypig.com · 17/06/2025
Whoever this “Jenkins” bastard is, they have access to everything! Begin the incident response immediately.
3581
Reposted by Matthias
Corey Quinn @quinnypig.com · 31/05/2025
CUT MY LIST IN TWO PIECES THAT’S HOW YOU START QUICKSORT
131261248
Reposted by Matthias
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/05/2025
My talk, 'Security Champion Worst Practices', from @ndc_conferences, is now available on YouTube! twp.ai/9PRKFn
2203
Reposted by Matthias
Blenster 🅅 @blenster.com · 17/05/2025
The event went smoothly despite the storms; there was a minor power outage. The youth had a great time and the free photo booth was a hit. I see why my friend does this and I hope to join him again. We're still fundraising for the organizers (not ourselves; so far only we have donated) here:
A test photo in a photo booth in front a neon-colored backdrop. I am wearing a black shirt with the test "you will have to go through me" in trans rights colors behind my beard. I am standing slightly off center as we were testing the flashes and placement.
3296
Reposted by Matthias
kat cosgrove @kat.lol · 23/04/2025
Another one in the books! Kubernetes v1.33: Octarine is live. Congratulations to the release team! kubernetes.io/blog/2025/04...
kubernetes.io
Kubernetes v1.33: Octarine
Editors: Agustina Barbetta, Aakanksha Bhende, Udi Hofesh, Ryota Sawada, Sneha Yadav Similar to previous releases, the release of Kubernetes v1.33 introduces new stable, beta, and alpha features. The c...
0348
Reposted by Matthias
Sean Gallagher @thepacketrat.net · 15/04/2025
I’m launching SVE next week: Sean’s Vulnerability Emotes. SVEs will be rated on a scale of 🤨😕☹️😰😱💀☠️
2173
Reposted by Matthias
nixCraft @cyberciti.biz · 02/04/2025
Nginx doesn't actually load balance; it simply convinces backend servers they're handling less traffic through subtle psychological manipulation.
79211
Reposted by Matthias
Daniel A Collier, PhD @dcollier74.bsky.social · 29/03/2025
Truest meme I've seen in a long time
171569210
Reposted by Matthias
Tarah Wheeler @tarah.org · 24/03/2025
Use Signal; use Tor. Wait, not like that.
46410
Reposted by Matthias
Brian Cowdery @batcow.bsky.social · 11/03/2025
Did you know Mortal Kombat is based off of Scandinavian Folkore? It's a Finnish Hymn.
3659
Reposted by Matthias
Courtney Milan @courtneymilan.com · 09/03/2025
No matter what the US does, the rest of the world is going to spend the next twenty years dismantling US power and influence because we are too dangerous and unreliable to maintain it.
13958186
Reposted by Matthias
Camille Fournier @skamille.themanagerswrath.com · 08/03/2025
It's international women's day and that means it's the day I self-promote! I've written a few good books including my most recent on Platform Engineering, check them out here! amzn.to/3QYGaoB
amzn.to
Camille Fournier: books, biography, latest update
Follow Camille Fournier and explore their bibliography from Amazon's Camille Fournier Author Page.
612437
Reposted by Matthias
hakan @hatr.bsky.social · 01/03/2025
If you've been following #BlackBasta (and the recent leak), this thread might be of interest. Last December, out of the blue, a source reached out to me (and, as I was to find out, to @valerymarchive.bsky.social as well) offering to doxx the leader of that ransomware-operation, known as "tramp".
13415
Reposted by Matthias
halvarflake.bsky.social @halvarflake.bsky.social · 02/03/2025
The German debt brake is stupid. Blog post. addxorrol.blogspot.com/2025/03/the-...
addxorrol.blogspot.com
The German debt brake is stupid!
Welcome to one of my political posts. This blog post should rightfully be titled "the German debt brake is stupid, and if you support it, so...
3165
Reposted by Matthias
opfuchs.gay @opfuchs.gay · 23/02/2025
Good thread on the German election today.
023
Reposted by Matthias
Victoria McIntosh @vmcntosh.bsky.social · 20/02/2025
I’m going to spend the weekend downloading every NIST security standard I can get my hands on, aren’t I?
4328
Reposted by Matthias
David Buchanan @retr0.id · 19/02/2025
docs: WARNING do not pass untrusted data to this function!!! devs: hm yeah my users are pretty trustworthy I think
1139428
Matthias @grambulf.bsky.social · 18/02/2025
Funniest software bug is the "Giant Bug" in bumblebee. While the bug itself isn't that interesting, the meme thread is hilarious. github.com/MrMEEE/bumbl...
github.com
GIANT BUG... causing /usr to be deleted... so sorry.... issue #123, i… · MrMEEE/bumblebee-Old-and-abbandoned@a047be8
…ssue #122, issue #121
000
Reposted by Matthias
Elbsides @elbsides.bsky.social · 14/02/2025
Gentle reminder that #Elbsides 2025 conference Call for Papers is open - enlighten the IT Security community with your talk in Hamburg on June 13th and let your abstract swoop down into our inbox: www.elbsides.eu/2025/cfp/ #infosec #cybersecurity #BSides #womenintech #womeninresearch #diversity
013