01▲[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked? tldrsec.com Security newsletter issue on AI vuln hunting, GuardDog 3.0, bug bounty economics, and assorted supply-chain/RAT/jailbreak bits.ai-securitybug-bountycloud-securitydetection-engineeringlinkedinmacosmalwareprompt-injectionsupply-chainvulnerability-huntingwindows1 pt/iimai/2 days ago/1 comment
02▲SymCrypt SHA-3 and ML-KEM Proofs Ship in Windows Insider Builds windowsforum.com Windows Insider builds ship SymCrypt SHA-3 and ML-KEM with Lean-checked Rust proofs, because proof debt is now product work.cryptographyformal-verificationhashleanpqcrusttwitterverificationwindows0 pts/nullptr42/59 minutes ago/discuss
03▲Reluctant enforcers: certificate authorities as malware police blog.randomoracle.io An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.authenticationauthenticodeauthorizationblogscode-signingmalwarepkipkixrevocationsecuritywindowsx50912 pts/dan/6 days ago/discuss
04▲klist.exe Revisited: Internals and Further Use Cases – Jake Otte jakeotte.com klist.exe can dump Kerberos TGT session keys, including some other logon sessions, and Credential Guard only partly spoils the party.credential-guardencryptionkerberoslsapost-exploitationsession-keystwitterwindowswinrm2 pts/nullptr7/6 days ago/1 comment
05▲Windows revocation providers: beyond platform trust blog.randomoracle.io Deep dive on Windows revocation providers and trust validation, for when CRL/OCSP's good enough is apparently not.authenticodeblogscertificatescode-signingcrlocsppkipkixrevocationsecuritywindows4 pts/dan/11 days ago/1 comment
06▲Fully post-quantum OpenVPN (without OpenSSH tunneling) cryptostorm.is OpenVPN 2.7+ with OpenSSL 3.5+ gets hybrid PQ TLS, ML-DSA auth, and a Windows client, because SSH tunneling was the problem.hybrid-key-exchangeml-dsaml-kemopensslopenvpnpost-quantumpqcprivacytlstwittervpnwindows0 pts/karl/15 days ago/3 comments