A Stuxnet source reconstruction appeared on GitHub: what it is and is not
A GitHub repository called Sadpainy/Stuxnet surfaced this week claiming a reconstructed source code of Stuxnet, the worm that damaged Iranian centrifuges and effectively invented the category of cyber-physical weapon. It is written in C, targets Windows XP and Windows 7 only, and comes with the usual educational-use disclaimer. It has 69 stars and a single […]
MikroTrick: pre-auth MikroTik takeover chain under active attack
If you run a MikroTik router with SSH exposed to the internet, patch it now, then check it for compromise. CERT Polska disclosed six RouterOS vulnerabilities on September 5, and two of them chain into what the agency calls MikroTrick: an unauthenticated, full administrative takeover of any device whose SSH service is reachable from public […]
Jellyfin 12.0 drops the 10 and rewrites how playlists work
Jellyfin 12.0 is out, and the version number itself is the story. The project dropped the leading “10” from its scheme, so what would have been 10.12.0 ships as 12.0.0. That sounds cosmetic until you remember that 10.11.0 rewrote the entire library database and still looked, to anyone glancing at a version string, like a […]
Signing TLS Handshakes Inside a TPM: Hardware-Bound Keys in Go
A recent post by Christian Bshaatsbergen walks through a technique more Go developers should know: terminating TLS with a private key that exists only inside a TPM and never touches process memory. The post, Signing TLS handshakes inside a TPM, demonstrates the whole chain with a small library, and the mechanics are worth unpacking. Why […]
Asahi Linux Reaches Official M3 Support
Asahi Linux, the project that reverse engineers Apple silicon for Linux, now officially supports Macs built on the M3, M3 Pro, and M3 Max. The announcement landed on the project blog this week under the title M2 Episode 1, and it carries both good news and the usual honest list of caveats. What works The […]
OpenAI’s Chief Scientist Says No Lab Is Ready to Scale at Full Speed
OpenAI chief scientist Jakub Pachocki published an essay on September 6 called An Alien Mind, and the timing is hard to ignore. Three days earlier, the company shipped GPT-6 Astra, its most capable model yet and the first to cross a Critical threshold on cybersecurity evaluations. Days after that launch, the person who runs research […]
Visualizing Rust’s Vtables: What dyn Trait Really Looks Like in Memory
What is actually inside a trait object? Rust’s dyn Trait is one of those features most developers use daily and few have fully visualised. Sofia Belen’s write-up, Visualizing Rust’s Vtables, does the dissection, and it is a good read for anyone coming to Rust from C++ who keeps trying to map one language onto the […]
Azure Firewall Auto-Learn SNAT Routes Is Generally Available
The SNAT problem that needed solving Here is a scenario that plays out in half the hybrid networks I have seen: traffic from Azure toward an on-premises range that is not one of the standard private ranges silently gets source-NATted by Azure Firewall. The on-prem firewall sees an unexpected source IP, a policy match fails, […]
AKS Artifact Streaming Reaches General Availability
Pulling images is the slow part nobody budgets for If you have ever watched a scale-out event on AKS with one eye on the pod list, you know the pattern: the scheduler places pods in seconds, then everything sits in ContainerCreating while each node drags a multi-gigabyte image out of Azure Container Registry. Your autoscaler […]
Azure Monitor Auxiliary Logs reach sovereign clouds, and log pricing gets interesting
Azure Monitor’s Auxiliary Logs plan is now generally available in the sovereign clouds, specifically Azure Government (Fairfax) and Microsoft Azure operated by 21Vianet (Mooncake). The September 1 update closes a gap that has mattered to anyone running compliance or audit logging for public-sector or regulated workloads, and it caps a year of quiet expansion for […]
Chrome’s sixth zero-day of 2026: CVE-2026-85046 exploited in the wild
Google shipped an emergency Chrome Stable update on September 3 and confirmed that one of the twelve bugs it patched is already being exploited in the wild. The flaw, CVE-2026-85046, is a type confusion vulnerability in V8 with a CVSS score of 8.8. It is the sixth actively exploited Chrome zero-day of 2026, and all […]
Azure Multicloud Interconnect: Microsoft and AWS finally wired the clouds together
Microsoft and AWS announced a joint service this week that neither company would have shipped five years ago: a managed private connection between the two clouds, provisioned from both portals, operated by both providers. Azure Multicloud Interconnect is in public preview now, with AWS as the first supported partner, and it replaces what has historically […]