







Big Tech routed me to the loading bay. Not because they're evil. Because we built systems that make human contact a malfunction.
Hacking Millions of Modems (and Investigating Who Hacked My Modem)
Two years ago, something very strange happened to me while working from my home network. I was exploiting a blind XXE vulnerability that required an external HTTP server to smuggle out files, so I spun up an AWS box and ran a simple Python webserver to receive the traffic from the vulnerable server.

Connect, protect, and build everywhere
Make employees, applications and networks faster and more secure everywhere, while reducing complexity and cost.
Your Security is My Security
Speaking to the world, I care about how good the security of your machines are.

The Cyber Resilience Act: A Five Alarm Fire
On October 21, 2016, CNN’s website was knocked offline. So was the BBC and Guardian’s. Amazon, Etsy and Shopify too, along with Quora, Reddit, and Twitter – among others. Huge swaths of the internet were taken down by a series of attacks on the DNS provider Dyn. These Distributed Denial of Service (DDoS) attacks were

The Internet Coup: A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes | InterSecLab
This research reveals groundbreaking findings on how Geedge Networks is selling an extensive suite of next-generation digital repression tools to client governments around the world.

The trust boundary moves inward - Sensemaker
GitHub's poisoned-extension breach, Railway's GCP account suspension, and SpaceX's AI-heavy S-1 all point to the same thing: the inside of infrastructure is now the story.
Project Glasswing: what Mythos showed us
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.

Stop Bill C-22!
🚨 Bill C-22 forces every Canadian internet provider, messaging app & cloud service to build surveillance backdoors and store a year of your data. Foreign state hackers exploited similar legislation in the US. Shut the backdoor: https://openmedia.org/StopC22 #BillC22

The Deceptive Complexity of P2P Connections and the Solution We Found
Discover how ARK Builders navigated a maze of p2p network technologies, comparing WebRTC, libp2p, and Iroh to find the perfect fit.

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure. This attack was very sophisticated, and the resulting document doubles as a crash-course …
The AT Protocol's interesting design - LittleBit
Bluesky's backend was made to be more than a social network
Socket - Block zero-day supply chain attacks
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependen...

AI Cybersecurity After Mythos: The Jagged Frontier
Why the moat is the system, not the model

The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
Why does every platform rebuild the same safety tools from scratch, behind closed doors? Our Head of Product @julietshen.bsky.social joined the Won't Fix pod to talk open-source T&S infrastructure, AI vs. human judgment & safety for the decentralized web: youtube.com/watch?v=RxFV7VwxkLs
Won't Fix Episode 9: With Juliet Shen, Cofounder & HOP at ROOST
www.youtube.com