Trail of Bits adds a Rust security testing chapter, covering Miri, property tests, Kani, Clippy, and supply-chain vetting.
trending22
01 02 A post-quantum migration pitch that, sensibly, starts with inventory and CBOMs instead of swapping algorithms in a panic.03 FIPS 140-3 paperwork stops at validation records; the real risk hides in bootloaders, vendor forks, and shipped firmware.04 [tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked? tldrsec.comSecurity newsletter issue on AI vuln hunting, GuardDog 3.0, bug bounty economics, and assorted supply-chain/RAT/jailbreak bits.05 The surprise is not the quantum order, it's that agencies have to migrate real stacks off RSA before Q-Day.06 Can a causally ordered DAG turn supply-chain lies into self-verifying contradiction proofs? This paper says maybe.07 [tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec tldrsec.comPrompt injection, apparently, is role confusion, in a newsletter that also hits PHP hardening and the new MCP spec.08 Even the FBI says TeamPCP turned dev tools into a credential vacuum for cloud keys, SSH, and K8s secrets.09 Your standard cells can be the Trojan, and this paper scores how hard it is to notice before tapeout.10 Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design arxiv.orgHow do you catch stuff that validates but still fails the receiver’s security model? This paper calls it TBSGs and splits it 4 ways.11 Compliance isn't readiness, this post says, and then lists the usual crypto inventory, agility, governance, and vendor gaps.12 Post-quantum migration gets a presidential memo, alongside the usual quantum hype and supply-chain handwaving.13 US agencies are finally moving from PQC slide decks to inventorying systems and baking it into procurement, deadlines help.14 Quantum-safe crypto is now a sovereignty problem, with the usual suspects fretting over vendor lock-in and export controls.15 Security roundup: package proxies, AI-agent canary benchmarks, and OpenAI's Daybreak/Codex updates, plus the usual cloud mess.16 Another PQC explainer, except it treats migration as procurement and ops debt, not just a math paper.17 How transparent is Proton's crypto? This review says, not much: key transparency gaps, weak SRP auth, and sketchy auto-updates.18 Trail of Bits introduces Patch the Planet, a model-assisted security-patching effort for OSS crypto and infra, because humans were busy.19 Quantum and AI threats get the usual treatment here, plus harvest-now-decrypt-later and OCP S.A.F.E./IEC 62443 chatter.20 Rust library for PQ remote attestation and supply-chain verification, with no_std, SLSA binding, and verifier/prover APIs?21 [tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security tldrsec.comWhat did tl;dr sec #332 pick out this week? OpenAI hire, AWS supply-chain advice, OIDC/Lambda abuse, and AI threat notes.22 KPMG's 2026 cyber priorities: AI security, non-human identities, supply-chain risk, and the usual PQC migration slog.