A New ASN.1 API for Python
https://blog.trailofbits.com/2025/04/18/sneak-peek-a-new-asn.1-api-for-python/

A New ASN.1 API for Python
https://blog.trailofbits.com/2025/04/18/sneak-peek-a-new-asn.1-api-for-python/
huh #trailofbits did an audit of #simplex - only the "protocol spec" https://github.com/simplex-chat/simplex-chat/blob/stable/docs/SimpleX_Design_Review_2024_Summary_Report_12_08_2024.pdf
quite limited scope. and last time i looked at the spec i lost my appetite, but apparently there have been updates, like addition of sntrup pq kem. so maybe this has improved? still wouldn't use it the supply chain attack surface is begging for a "soon" not an "if". and the global transcript of group chats was out of scope in this audit. so, meh?
A deep dive into Linux’s new mseal syscall
https://blog.trailofbits.com/2024/10/25/a-deep-dive-into-linuxs-new-mseal-syscall/
White House: Use memory-safe programming languages to protect the nation https://www.helpnetsecurity.com/2024/02/27/memory-safe-programming-languages/ #criticalinfrastructure #softwaredevelopment #Horizon3.ai #programming #TrailofBits #government #Don'tmiss #Honeywell #Hotstuff #News #USA
Attackers Could Eavesdrop on AI Conversations on Apple, AMD, Imagination and Qualcomm GPUs – Source: www.techrepublic.com https://ciso2ciso.com/attackers-could-eavesdrop-on-ai-conversations-on-apple-amd-imagination-and-qualcomm-gpus-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #ArtificialIntelligence #SecurityonTechRepublic #SecurityTechRepublic #largelanguagemodels #CyberSecurityNews #appleiphone15 #appleipadair #GenerativeAI #imagination #trailofbits #opensource #Developer #Qualcomm
LeftoverLocals: Apple, AMD und Qualcomm GPUs von Sicherheitslücke betroffen
#ITSicherheit #AMD #Apple #CPUs #HeidyKhlaaf #LeftoverLocals #ProofofConcept #Qualcomm #Sicherheitslücke #TrailofBits https://sc.tarnkappe.info/af0398
CFTC adds execs from Circle, Ava Labs and Fireblocks to tech advisory group
https://cointelegraph.com/news/cftc-adds-execs-from-circle-ava-labs-and-fireblocks-to-tech-advisory-group
#TechnologyAdvisoryCommittee #IncaDigital #TrailofBits #FireBlocks #Abalanche #AvaLabs #TRMLabs #Circle #CFTC
The 2022 #Curl Security Audit by #trailofbits was interesting as I've myself quite a bit of digging into curl internals over the years. While there were many findings, only two of them were considered security vulnerabilities.
2022 security audit: https://daniel.haxx.se/blog/2022/12/21/the-2022-curl-security-audit/
older post about increased CVE activity: https://daniel.haxx.se/blog/2022/08/22/increased-cve-activity-in-curl/
NFT Marketplace Opensea Migrates to Seaport Protocol, Transition to Cut Network Fees by 35%
https://news.bitcoin.com/nft-marketplace-opensea-migrates-to-seaport-protocol-transition-to-cut-network-fees-by-35/
#Non-fungibleToken #SeaportProtocol #Web3Marketplace #Wyvernprotocol #All-timesales #Openzeppelin #TrailofBits #Technology #$31Billion #OpenSource #OpenseaNFT #NFTMarket #Opensea #Seaport #audit #NFTs #Web3 #nft