Sign in

Nicolò Fornari

@rationalpsyche.bsky.social
24 followers 56 following 64 posts

Penetration Tester. Art passionate. Friends call me "grandpa".

PostsRepliesMedia
Nicolò Fornari @rationalpsyche.bsky.social · 27/09/2026
"The big takeaway I had from this AI age is that we should be using it to solve problems that are even more difficult than ever before. Increasing the ambition that we have for what we are building or in my case researching, has been the most rewarding thing to do" shubs.io/do-we-still-...
shubs.io
do we still enjoy software engineering in the age of AI?
A few weeks ago, one of the software engineers I manage sent me a message about how they have been struggling to find satisfaction in their work ever since AI has eroded much of the creativity and pro...
000
Reposted by Nicolò Fornari
Rami Krispin @ramikrispin.bsky.social · 23/09/2026
I'm not sure who gets the credit, but it's brilliant! 😂
11210
Reposted by Nicolò Fornari
halvarflake.bsky.social @halvarflake.bsky.social · 17/09/2026
I gave a talk at Bluehat Singapore today. The slides are here: thomasdullien.github.io/about/slides...
1219
Nicolò Fornari @rationalpsyche.bsky.social · 13/09/2026
It could also simply be: "let's slow down this money burning race until we figure out how to be profitable", although it would be surprisingly against the current inefficient Nash equilibrium.
030
Reposted by Nicolò Fornari
Simon Willison @simonwillison.net · 28/08/2026
My LLM cliché highlighter is up to 38 patterns now tools.simonwillison.net/llm-cliche-h...
Screenshot of a writing-analysis tool showing paragraphs of text with phrases highlighted in two shades of yellow, brown circular "3" badges, and a black tooltip overlaying the first line reading: "No X, no Y" chains · 3 "no" items. The visible text reads: We r[obscured by tooltip]nd up. No sign-ups, no downloads, no hassle (3) — just paste your text and start writing. Everything runs locally in your browser. The reviewer read the draft twice. Did not flinch, did not blink, did not reach for the red pen (3). That's the whole review, honestly. Don't call it a rewrite — call it a rescue. The improvement is real, and it's not subtle. That loss is worth naming. Sit with that for a moment. The gains were modest, but that's not nothing. You already know the answer, of course. Consistency is the entire game, and the punchline is that nobody wants to hear it. The entire pitch is one sentence long.
2350165
Reposted by Nicolò Fornari
Ethan Mollick @emollick.bsky.social · 23/08/2026
Life is full of things that, by complexity or design or lack of care or required time, are hard to navigate: healthcare, government, personal finance, school forms are all among them It is why I feel consumer AI is underrated. People muddle by, but are missing support & AI is good enough to help.
1013513
Reposted by Nicolò Fornari
Ethan Mollick @emollick.bsky.social · 21/08/2026
Variation is also going to be important if you want AIs to surface diverse new ideas, do science and tons of other things.
2753
Reposted by Nicolò Fornari
Bert Hubert 🇺🇦🇪🇺🇺🇦 @berthubert.bsky.social · 19/08/2026
They said no such thing. They achieved "statistically significant and clinically meaningful improvements in Relapse-Free Survival". Which is nice, but not "prevents cancer from returning". news.modernatx.com/merck-and-mo...
news.modernatx.com
Merck and Moderna Announce Phase 3 INTerpath-001 Trial of Intismeran Autogene Plus KEYTRUDA® Met Endpoints of Recurrence-Free Survival (RFS) and Distant Metastasis-Free Survival (DMFS) in Patients Wit...
Deliver the greatest possible impact to people through mRNA medicines.
121
Reposted by Nicolò Fornari
Chris Wysopal @weld.bsky.social · 13/08/2026
This is a pretty big shift in US cyber policy. The White House is setting up a program that would let private cybersecurity companies conduct gov-authorized operations against foreign cybercriminal groups, inc surveillance & disruption of their infrastructure www.whitehouse.gov/presidential...
whitehouse.gov
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE
53125
Reposted by Nicolò Fornari
halvarflake.bsky.social @halvarflake.bsky.social · 08/08/2026
The EU gets a bad rap, but ... sometimes we have to appreciate that the 1949-2026 period is the longest period in *documented history* without interstate war among the bloodthirsty western European tribes.
1265
Reposted by Nicolò Fornari
Dominic White @singe.bsky.social · 07/08/2026
I haven’t settled my thoughts on the OpenAI incident but I can’t help but feel that the threat modelling & security engineering applied up-front to long-term xhigh training runs with no cyber guard-rails was seriously shoddy. Easy to say after the fact. (1/3)
101
Nicolò Fornari @rationalpsyche.bsky.social · 02/08/2026
While I enjoy being up to date with tech news feeds, time for reading is an investment and I want to retain what is most valuable. For this purpose I started an "AI diary", with facts and ideas that I believe will remain relevant for years. darkvolumes.nz/reading/ai-d...
darkvolumes.nz
An AI diary
000
Nicolò Fornari @rationalpsyche.bsky.social · 02/08/2026
Highly recommend read. Very balanced stating objective facts. Lots of "I didn't about this".
131
Reposted by Nicolò Fornari
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 27/07/2026
Claude: > Once a chat has been shared, anyone with the link can view the chat snapshot. The part Claude doesn't say out loud: When you generate a link, we share the link with search engines, so basically the whole world has the link […] [Original post on infosec.exchange]
Google search for site:claude.ai/public/artifacts
003
Reposted by Nicolò Fornari
Ethan Mollick @emollick.bsky.social · 24/07/2026
Glad to see Google sharing data on how Gemini is being used. Especially interesting is that the usefulness of multimodal AI for manual labor may be greater than expected. blog.google/innovation-a...
2627
Reposted by Nicolò Fornari
Robin Berjon @robin.berjon.com · 20/07/2026
If you operate an institutional account and you hadn't understood that this is the power dynamic that you're under, now is a good time to get to work. What's your transition plan?
411449
Nicolò Fornari @rationalpsyche.bsky.social · 18/07/2026
What. The. Fuck.
000
Reposted by Nicolò Fornari
Cheryl Rofer @cherylrofer.bsky.social · 08/07/2026
Great answer from Rutte, though in the sense of retaining control of the conversation. In these times of Trump, it's good to see people who know how to do this.
47015
Reposted by Nicolò Fornari
Sven-Erik Volberg @volberg.bsky.social · 19/06/2026
Ukraine launches TrophyLab: they are opening access to captured russian weapon technologies for our global partners. Every missile, drone, and vehicle seized on the battlefield is now a source of knowledge for the free world.🧵 1/2 trophylab.mod.gov.ua/en/
15489179
Nicolò Fornari @rationalpsyche.bsky.social · 16/06/2026
RL economics, morally charged terms, and "distillation" addxorrol.blogspot.com/2026/06/rl-e...
addxorrol.blogspot.com
RL economics, morally charged terms, and "distillation"
After a number of Twitter discussions, and repeating myself a lot in these discussions, it is time to write a short note on the economics of...
000
Reposted by Nicolò Fornari
Ursula von der Leyen @vonderleyen.ec.europa.eu · 14/06/2026
Good discussion with Guy Parmelin. We take note of the outcome of today’s vote in Switzerland. The Swiss people have spoken. The EU and Switzerland share deep ties and a strong partnership.
719820
Reposted by Nicolò Fornari
Max Kennerly @maxkennerly.bsky.social · 13/06/2026
It's an objective fact that Elon Musk is a mass murderer. He intentionally caused the deaths of millions of people. There's no caveats to this, no alternative explanations, no defenses, no missing context; that was the sole reason for doing what he did.
4336921282
Nicolò Fornari @rationalpsyche.bsky.social · 08/06/2026
"Anthropic has published a Project Glasswing status report. It’s finding a lot of vulnerabilities in software. Some of them are even dangerous. But almost none of them has been patched." www.schneier.com/blog/archive... www.flyingpenguin.com/mythos-gradi...
schneier.com
Anthropic's Project Glasswing Update - Schneier on Security
In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press o...
000
Reposted by Nicolò Fornari
raptor @raptor.infosec.exchange.ap.brid.gy · 07/06/2026
Cool #supplychain safety idea by @ThinkstCanary 💚 blog.thinkst.com/2026/06/introducin…
blog.thinkst.com
Introducing Package Proxy: supply-chain safety checks without client-side software
Supply chains are getting wrecked with back-doored and malicious packages every few days it seems. Today we’ve released Package Proxy, our imaginatively (descriptively?) named Cloudflare-based tool which implements a bunch of in-line checks for popular package managers (npm, pip, uv, and cargo). Read on for why we built it, or head to the GitHub repo to trivially deploy into Cloudflare yourself. ## Sulfurous supply chains Software dependency risk used to be primarily concerned with old versions; if one of your tools bundled a vulnerable OpenSSL version then you had to upgrade that tool to get patched against the 3rd party bug. Apart from old versions, the software dev industry wasn’t thinking too hard about where code came from except that it was from a recognised package repo. The push towards SBoMs is an artifact of that attitude: “if we know all the libraries used in this tool then we can ensure the vendor keeps them updated; _dusts hands_ “. However, security folks have been speaking about expanded software supply chain risk for a while, pointing out that the vast majority of code in most tools resides in libraries and extensions, and _that_ introduces transitive trust of hundreds-to-thousands of unknown and unknowable authors. Ten years ago, our Az and Nick demonstrated backdoored plugins to the Atom code editor, and they weren’t the first to think about backdoored tools. The idea of deliberately malicious dependencies has been kicking around for a long time, but threat actors largely stayed away. It’s been confined to the security world for the most part, with developers largely unaware of the risks. Seven years ago, it was notable when 12 malicious packages were found on PyPI. Last week, Socket reported 639 compromised npm packages in just one coordinated attack and that news passed by quickly. The world has clearly moved on, and supply chain risk has become an issue for developers too. The Axios breach was a foghorn-level alert to developers about the change in the sophistication of these attacks. As a vendor, we’ve been exploring ways to introduce additional controls to reduce our supply chain risk so that we remain unaffected. ## Idealised protection As the dev world scrambled to contain the risk, a few heuristics cropped up. For back-doors inserted surreptitiously into valid packages, the exposed window tended to be narrow before the issue was discovered (i.e. hours to days). For typo-squatted or fake packages, they typically had low numbers of installs. For compromised maintainer accounts, expired or re-registered domains was a strong indicator, as was a change in the package upload process. There are also block lists of known bad packages, and allow lists of known fixed packages that have been assessed. In the ideal world, before any package is installed we would perform checks like: * Require the package to be at least N days old (say, 10), to give a window in which others encounter the issue first. * Check whether the package was uploaded to the repo in a different way from before. Some repos will indicate whether the package was uploaded directly or through an automated process, and attackers who compromise maintainers often directly upload packages instead of using the pipeline (because it is less visible). * Check whether there are domains associated with the package (e.g. email addresses), and see if any are expired or have been registered recently. Attackers look for expired domains in order to re-register them and gain access to unmaintained packages. * Perform a diff on the package from between its two most recent versions, and analyse for back-doors * Run a code scanner on the full package to identify back-doors * See if the package and/or its version is in a list of known bad packages * See if the package is already trusted by us through an out-of-band assessment. Now, we can’t do all of these in-line. Running a code scan will take minutes to hours, far too long for actual use. Some are wishful (maintainer emails are not mandatory for PyPI packages). But package age, upload method, and allow and block lists are all fast to check. Of course, even if all of these checks were applied to every package, it’s still possible to construct an attack path past all of these tests. However they raise the effort required by attackers (thereby increasing their cost). ## Package Proxy Package Proxy is a simple idea. Many package managers (notably uv, pip, cargo, and npm) use an index URL to fetch metadata (e.g. https://pypi.org/simple for `pip`). That index URL can be changed through configuration so the package managers instead pull metadata from the Package Proxy. The Package Proxy sees all requests for metadata, and can infer which packages the client wants to install. The Package Proxy performs checks you desire, and simply returns 404 for packages that don’t meet your policies, or will fetch the package for you and serve it to the client if the package passes the policy check. It relies on Cloudflare Workers so it is very tied to Cloudflare, but similar ideas can be implemented elsewhere. The released Package Proxy implements these checks out the box: * Ensures packages are at least 10 days old (PyPI, npm, cargo) * Where the package upload mechanism is visible, check that it has not regressed (PyPI, npm) * Bypass for explicit audit fix steps (npm) * Block list (PyPI, npm, cargo) * Allow list (PyPI, npm, cargo) We’re making the source available on our Github, and you can 1-click deploy to Cloudflare for your own hosted Package Proxy. Internally we run a fork which enforces a stronger version of the allow list; we block `npm` packages by default and developers have to request additions to the allow list. ## What this means Other approaches to this problem hinge on deploying a wrapper around the package manager, with both commercial and open source options. We elected to go with the proxy approach, because it meant we didn’t need an additional dependency in a whole bunch of new places, we just needed a config change. Wrappers have their own benefits, but the proxy gave us an immediate control we could roll out through a background fleet-wide deployment without needing to change workflows or habits. It also helps supply uniform checks when your clients have different versions of package managers. For example, while `uv` supports a notion of “don’t install packages published in the last week”, `pip`‘s `--uploaded-prior-to` option takes a fixed timestamp. With the Package Proxy, we can enforce a uniform check regardless of the package manager. Since the proxy was rolled out, these recent breaches did not affect us: 1. TanStack (due to age checks) 2. BitWarden (due to age & integrity downgrade checks) 3. TeamPCP’s latest round of npm targets (due to age checks) 4. We could ensure that the malicious NPM packages `logger-active` and `utils-terminal` targeting common utility library names hadn’t been installed by mistake (due to age checks) ## Proxy setup Deployment is via Cloudflare and Github; if you have accounts on both then a deploy to Cloudflare will clone our repo into your Github, then set up Cloudflare Workers. After deploying, the “Domains & Routes” page will list your production Worker URL; this is your Package Proxy URL to use. You can also configure a custom domain here if you prefer not to use the auto-generated URLs. The Package Proxy logs its usage into a D1 Database; browse to the Cloudflare dashboard and run queries such as: * **Return all the users that have installed a package (and each version)** : `SELECT DISTINCT UserId, CONCAT(PackageName, '@', PackageVersion) as Installed FROM Installs WHERE PackageName LIKE ?;` * **Fetch the total number of installed packages** : `SELECT COUNT(*) FROM Installs;` * **Fetch all installed package names** : `SELECT DISTINCT PackageName FROM Installs;` ## Proxy configuration To manage your Proxy, configure it through the Cloudflare dashboard. There you can add a [sub-]domain that is directed to the proxy as well as view usage and request logs. Once the proxy has handled a request it will create a default configuration. You can change this configuration with a few Wrangler commands: `$ NAMESPACE_ID="..." # Your KV store's namespace ID` `$ `npx wrangler kv key get "default" --namespace $NAMESPACE_ID --remote > config.json`` [edit the `config.json` file] `$ npx wrangler kv key put "default" ``--namespace $NAMESPACE_ID`` --remote --path config.json` ## Deploy configuration to your endpoints With the proxy in place, you need to tell your endpoints about it. For developers laptops, we pushed out this script which sets up the proxy for npm, pip, uv, and cargo. You can also (in some cases) make the proxy per-repo. `uv`’s `pyproject.toml` supports configuring the index in a particular project with the following settings: [[tool.uv.index]] name = "packageproxy" url = "https://<USERNAME>@package-proxy.corp.dev/pypi" ## Dealing with incidents When (not if) the next supply chain compromise takes place, you don’t need to do anything immediately. The Package Proxy will give you 10 days grace (by virtue of the enforced minimum package age), which historically has been enough time for backdoors to be discovered and the packages yanked from the repos. Should an attack like Axios happen (in which the integrity of the package regressed because the upload mechanism changed) then the Package Proxy will never allow that version regardless of the time. There are times when a critical update does occur that you need to roll out. For NPM packages, the proxy will (as a default configuration) allow `npm audit` to see the latest packages. For the other registries you can add a specific package and version combination to your allow list with Cloudflare’s tools. For example, you can add `test@2.3.4` to the default allow list (with Wrangler installed): 1. `$ cd path/to/repo/with/your/wrangler.jsonc` 2. `$ npx wrangler kv key get "default" --binding PACKAGE_PROXY_CONFIG --remote | jq '.allowlist += {"npm/test": ["2.3.4"]}' > new_config.json` 3. `$ npx wrangler kv key put "default" --binding PACKAGE_PROXY_CONFIG --remote --path new_config.json` It is also possible to edit the KV values directly from the Cloudflare dashboard in your browser. ## Give it a whirl We think this approach has legs and haven’t seen others try it. It’s working for us and has seen real wins. ### _Related_
011
Nicolò Fornari @rationalpsyche.bsky.social · 28/05/2026
Today, for the first time in my life, I've been addressed as "bro" by the guy sitting next to me on the train. It felt really odd. At least, I guess I still look young :D
000
Nicolò Fornari @rationalpsyche.bsky.social · 24/05/2026
I was aware of Palantir's bad reputation and I regarded it as a US problem. I didn't know it was also used in Europe. Sigh..
010
Nicolò Fornari @rationalpsyche.bsky.social · 16/05/2026
"Even more interesting are the broader implications. [...] Just as these models are finding hundreds of vulnerabilities in complex software systems, we should expect them to be equally effective at finding many new and undiscovered tax loopholes." www.schneier.com/blog/archive...
schneier.com
How Dangerous Is Anthropic's Mythos AI? - Schneier on Security
Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to...
120
Reposted by Nicolò Fornari
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
085
Reposted by Nicolò Fornari
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
It's official! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) used a single CWE-150 bug to exploit OpenAI Codex, earning $40,000 and 4 Master of Pwn points. #Pwn2Own #P2OBerlin
023
Reposted by Nicolò Fornari
Internet Archive @archive.org · 09/05/2026
🧵 1️⃣/5️⃣ Announcing Internet Archive Switzerland: Expanding a Global Mission to Preserve Knowledge 🇨🇭🌍 Visit Internet Archive Switzerland ➡️ internetarchive.ch
Logo of the Internet Archive Switzerland. Black text on a white background.
134582
Reposted by Nicolò Fornari
Bert Hubert 🇺🇦🇪🇺🇺🇦 @berthubert.bsky.social · 05/05/2026
The world is now so full of ridiculous things that I struggle to deal with it all. But this is not an 'us' problem. The world really is idiotic. I made a list of things that are impossible to believe. Seeing it in writing might help you deal better with the situation. berthub.eu/articles/pos...
berthub.eu
The Impossible Things We Have to Believe - Bert Hubert
“Alice laughed. ‘There’s no use trying,’ she said. ‘One can’t believe impossible things.’ I daresay you haven’t had much practice,’ said the Queen. ‘When I was your age, I always did it for half-an-ho...
54723
Nicolò Fornari @rationalpsyche.bsky.social · 03/05/2026
"Sound waves vibrate the oxygen faster than the fuel can use it, and break the chemical reaction of the flame" science.slashdot.org/story/26/05/...
000
Nicolò Fornari @rationalpsyche.bsky.social · 29/04/2026
ky.fyi/posts/ai-bur...
ky.fyi
Do I belong in tech anymore?
On quitting, the spread of AI, and the loss of an ideal.
000
Reposted by Nicolò Fornari
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
Nicolò Fornari @rationalpsyche.bsky.social · 26/04/2026
"And so the tech industry is rushing forward to put AI everywhere at enormous cost [...] and locked into the narrow framework of software brain without realizing they are also asking people to be fundamentally less human. They then sit around wondering why everyone hates them"
000
Reposted by Nicolò Fornari
Ethan Mollick @emollick.bsky.social · 23/04/2026
GPT-imagegen-2: "a gallery of shoes, where each shoe is under a painting & is styled matched to that painting: Starry Night, The Bathers, The Girl with the Pearl Earring, The Bayeux Tapestry, Klint's Grupp Svanen nr 17, Kandinsky's Swinging, The Garden of Earthly Delights" "now the full outfits"
6706
Reposted by Nicolò Fornari
Dominic White @singe.bsky.social · 16/04/2026
Two conclusions from this - it's an incremental improvement, not a sea change. And $1k per attack won't easily scale. We probably not about to experience "THE VULNPOCALYPSE" but continued incremental improvements in vulnerabilities hunting.
002
Reposted by Nicolò Fornari
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 14/04/2026
This morning we got one of our pending #curl security flaws reported a **4th** time. Everyone is using (the same) AI tools now.
3117
Reposted by Nicolò Fornari
Dominic White @singe.bsky.social · 09/04/2026
What if Mythos is being overhyped so that Anthropic can develop a higher margin enterprise model instead of the high volume low margin one they’ve pursued until now? This is not to say we can disregard the claim - but let’s wait and see where the truth lies.
281
Nicolò Fornari @rationalpsyche.bsky.social · 07/04/2026
TIL idiocracy.wtf
idiocracy.wtf
Are We Idiocracy Yet?
Tracking how close reality is to Mike Judge's Idiocracy. It's got electrolytes.
000
Reposted by Nicolò Fornari
Dominic White @singe.bsky.social · 30/03/2026
Totally worth reading.
021
Nicolò Fornari @rationalpsyche.bsky.social · 01/04/2026
LOL
000
Reposted by Nicolò Fornari
CSCS - Swiss National Supercomputing Centre @cscsch.bsky.social · 17/03/2026
🇨🇭 In Ticino, the open Swiss model Apertus powers in-house AI translation for the Cantonal Administration — boosting multilingual services with local, transparent control. A great example of sovereign AI in action bit.ly/4rzU0Og @epfl-ai-center.bsky.social @eth-ai-center.bsky.social
065
Reposted by Nicolò Fornari
Compass Security @compass-security.com · 17/03/2026
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
044
Nicolò Fornari @rationalpsyche.bsky.social · 12/03/2026
mxmap.ch
mxmap.ch
MXmap — Email Providers of Swiss Municipalities
Interactive map showing where Swiss municipalities host their official email. DNS analysis of all ~2,100 municipalities, color-coded by provider.
000
Reposted by Nicolò Fornari
Ulrike Franke @rikefranke.eu · 11/03/2026
This is a very good approach. (And I say approach, rather than outcome, because the headline goes a bit far. But still: well done Ukraine!!) #drone www.nytimes.com/2026/03/11/w...
nytimes.com
Ukraine Reaches a Milestone: Making ‘China-Free’ Drones
530059
Reposted by Nicolò Fornari
Cassandrich @dalias.hachyderm.io.ap.brid.gy · 26/02/2026
PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this: Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item […]
hachyderm.io
Original post on hachyderm.io
834225
Reposted by Nicolò Fornari
buherator @buherator.bsky.social · 19/02/2026
Paged Out zine #8 pagedout.institute -> Original->
012
Reposted by Nicolò Fornari
ThinkstCanary @thinkstcanary.canary.tools · 16/02/2026
You can grab the latest copy of our quarterly security research roundup at thinkst.com/ts ¹ For this issue, we selected work from over 1,370 talks & 1,200 blog posts. Available as PDF, ePUB (or audio highlights) __ ¹ As always, completely free
024