







In cryptography and computer security, a man-in-the-middle[a] (MITM) attack, or on-path attack, is a cyberattack where the attacker secretly relays and possibly alters the communications between two parties who believe that they are directly communicating with each other, where in actuality the attacker has inserted themselves between the two user parties.
Download pumping: New npm deception technique for supply chain attacks
Learn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate.

Soatok’s Informal Guide to Threat Models - Dhole Moments
After a long day of exhausting conversations about Hybrid Post-Quantum Cryptography, random jackasses trying to play gotcha with endpoint attacks against end-to-end encrypted messaging apps, and me…

Cato CTRL™ Threat Research: PoC Attack Targeting Atlassian’s Model Context Protocol (MCP) Introduces New “Living off AI” Risk
Stop me if you've heard this one before: A threat actor (acting as an external user) submits a malicious support ticket. An internal user, linked to a tenant, invokes an …
The attacks on Sam Altman are a warning for the AI world
A politician’s home was also attacked after voting to rezone for a data center.

Pro-Iran hackers claim ‘sophisticated’ attack on Bluesky
A pro-Iran hacking group that has been relentlessly targeting American companies with DDoS attacks claims it disrupted Bluesky with what the social media site called a “sophisticated” attack that…

Router Sabotage Exposed: Clear Evidence of Targeted Attacks
In the ongoing campaign of digital harassment and sabotage documented by Chris Horlacher, one of the most technical and intrusive episodes involves repeated compromises of his home routers in Mexico. These incidents directly affected Chris Horlacher’s ability to work, communicate securely, and acces

feynon/intent-router-blueprint
A hybrid LLM intent routing system for secure agent orchestration.
Mercor Breach Linked to LiteLLM Supply-Chain Attack
A LiteLLM supply-chain compromise enabled attackers to harvest credentials and access internal environments at scale at Mercor. The firm was the first to confirm a
mitmproxy - an interactive HTTPS proxy
mitmproxy is your swiss-army knife for debugging, testing, privacy measurements, and penetration testing. It can be used to intercept, inspect, modify and replay web traffic such as HTTP/1, HTTP/2, HTTP/3, WebSockets, or any other SSL/TLS-protected protocols. You can prettify and decode a variety of message types ranging from HTML to Protobuf, intercept specific messages on-the-fly, modify them before they reach their destination, and replay them to a client or server later on.
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
HACKING – A Hacker Manifesto
The apologists for the vectoral interest want to limit the se- mantic productivity of the term “hacker” to a mere crimi- nality, precisely because they fear its more abstract and multiple potential—its class potential. Everywhere one hears rumors of the hacker as the new form of juvenile delinquent, or nihilist vandal, or servant of organized crime. Or, the hacker is presented as a mere harmless subculture, an obsessive garage pursuit with its restrictive styles of appear- ance and codes of conduct. Everywhere the desire to open the virtuality of information, to share data as a gift, to ap- propriate the vector for expression is represented as the object of a moral panic, an excuse for surveillance, and the re- striction of technical knowledge to the “proper authorities.” This is not the first time that the productive classes have faced this ideological blackmail. The hacker now appears in the official organs of the ruling order alongside its earlier ar- chetypes, the organized worker, the rebellious farmer. The hacker is in excellent company
The Server Called Paranoia: Defend Autistici/Inventati
For twenty-five years, an Italian hacker collective has built communications infrastructure designed to survive censorship, surveillance and police raids. On August 26, the United States designated it a terrorist organization. On September 25, the wind-down period ends.

Germ DM x ATProto is Now in Beta — Germ Network
Germ DM is now a Bluesky messenger. We’ve integrated AT Protocol into our iOS app, so E2EE DMs have come to the Atmosphere! Germ DM is the end-to-end encrypted messenger that lets you talk freely—without a your phone number. It’s powered by Messaging Layer Security (MLS) and now connects to your A

The Hacker and the State: Cyber Attacks and the New Nor…
Packed with insider information based on interviews, de…

STOP CSAM Act Threatens Everyone’s Online Safety and Security - Internet Society
The Internet Society calls on the Senate Judiciary Committee to address risks in the STOP CSAM Act that pose an existential threat to the Internet and crucial security technologies that keep children and vulnerable people safe online.

Germ DM is the first client built on the Autonomous Communicator Protocol, our innovative identity layer that sits atop Messaging layer Security. Read more from our co-founder Mark.
Autonomous Communicator (AC) Protocol — Germ Network
www.germnetwork.com