Skip to content
tag — disclosure

grep -rl "disclosure" ./articles

#disclosure

16 articles

The anonymous client passes the ownership check by being nobody

2026-09-09Security

Two flaws in FreeIPA and 389 Directory Server are unremarkable on their own. Together they let an unauthenticated client write a token entry with blank ownership, satisfy the check for whether it owns that entry, and attach a Kerberos identity with administrative group membership. Nobody has published how to tell whether it already happened to you.

One researcher dropped three exploits. Only Gen Digital has shipped a fix

2026-09-08Security

PrettyPrague, FalconFlank and GreenSection target Avast's sandbox, CrowdStrike Falcon's macro remediation and NVIDIA's display driver. Gen Digital has patched. CrowdStrike's advice is to turn the affected protection off. NVIDIA is still investigating. And the FalconFlank claim this site called single-source last week now has independent confirmation.

On Daybreak Blue the control is who you are. On a $20 plan it is whether the model says no

2026-09-07AI

Astra began reaching ChatGPT Plus subscribers on 6 September, three days after OpenAI said it was the first model to meet the Critical cybersecurity threshold of its own Preparedness Framework. That was the announced plan and it gates a capability rather than the product — but the safeguard changed from identity verification to a refusal policy, and OpenAI published the refusal rate: 91.5%.

A court seals a record by order. The order did not travel with the backup copy

2026-09-06Security

West Publishing says an intruder sat in Thomson Reuters' cloud from 1 March to 29 June, and that confidential, redacted or sealed court information may have been affected. Thomson Reuters' reassurance is that C-Track had no operational disruption and is safe to keep using — which answers a question nobody asked.

The safety filter read the ciphertext and the sandbox ran the plaintext

2026-08-22AI

Adversa AI encrypted its instructions so guardrails saw only harmless-looking ciphertext, then let the model's own code sandbox decrypt and execute them. It reported the technique to xAI on 3 June, chased twice, got no reply, and published. Grok still falls to it, including zero-click exfiltration through tool use.