Risky Business Weekly (823): Humans impersonate clawdbots impersonating humans
YouTube video by Risky Business Media
ICYMI: This week's show is up!
@metlstorm.risky.biz and I were joined by our new podcast host @jameswilson.io to talk all about the Notepad++ supply chain compromise and the security angle on the Clawdbot/Moltbook fiasco:
VIDEO: www.youtube.com/watch?v=W5hx...
AUDIO: risky.biz/RB823
04.02.2026 22:38
π 9
π 4
π¬ 2
π 0
Maybe one day our paths will cross π
30.10.2025 04:40
π 1
π 0
π¬ 1
π 0
Found an interesting ruby bug, time to see if it impacts rails. Anyone want to collab?
29.10.2025 08:34
π 1
π 1
π¬ 2
π 0
Notes on the Pentium's microcode circuitry
Most people think of machine instructions as the fundamental steps that a computer performs. However, many processors have another layer of ...
The Pentium's microcode ROM holds 414,720 bits in total: 4608 micro-instructions. For more photos of the Pentium's microcode circuitry along with a detailed explanation, see my latest blog post:
www.righto.com/2025/03/pent...
31.03.2025 17:40
π 29
π 3
π¬ 0
π 0
Thank you! That motivates me to continue writing and sharing!
10.12.2024 11:55
π 1
π 0
π¬ 1
π 0
My latest blog post is live! Check your Ruby on Rails applications for the use of params[:_json]
nastystereo.com/security/rai...
10.12.2024 08:30
π 34
π 14
π¬ 1
π 2
GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin
ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.
Ten years ago, I realised I needed to rewrite ActiveScan++ in Java. After putting it off for so long that artificial intelligence was literally able to do 90% of the work for me, I've done it! It's now available in the BApp store. Report issues and feature requests here ->
github.com/albinowax/Ac...
05.12.2024 15:57
π 42
π 10
π¬ 0
π 0
Security researcher Luke Jahnke has published an escape for SafeMarshal, a new Ruby security gem that can be used to block deserialization attacks
nastystereo.com/security/rub...
05.12.2024 14:03
π 4
π 2
π¬ 0
π 0
Haha it is starting to feel like an advent calendar. But no, just a lot of free time lately. Maybe I need tougher targets, any suggestions?
04.12.2024 06:42
π 1
π 0
π¬ 1
π 0
My latest blog post is live π₯ Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE!
Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation!
nastystereo.com/security/rub...
04.12.2024 04:57
π 19
π 8
π¬ 1
π 0
GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin
ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.
I've just rewritten ActiveScan++ in Java to lay the foundation for some major enhancements. It's not in the BApp store yet but if you'd like to take it for a spin you can grab it here:
github.com/albinowax/Ac...
03.12.2024 12:53
π 47
π 17
π¬ 3
π 0
I hope to write a follow up post that covers the footguns I learnt about for R apps, especially jsonlite::fromJSON ;)
02.12.2024 14:55
π 3
π 0
π¬ 0
π 0
New blog post is up!
Shiny Vulnerabilities in R's Most Popular Web Framework
nastystereo.com/security/r-s...
Turns out the programming language R is used for more than statistics, including web apps!
02.12.2024 14:55
π 12
π 2
π¬ 2
π 0
I think my post showing that Ruby's substring implementation is faulty is a little bit interesting, hoping someone else can chain it with another bug someday to show some true impact: nastystereo.com/security/rub...
01.12.2024 18:29
π 3
π 0
π¬ 0
π 0
research!rsc: Running the βReflections on Trusting Trustβ Compiler
Not sure how I missed that, but we now actually have Ken Thompson's C compiler backdoor code from the classic "Reflections on Trusting Trust". An excellent writeup by @swtch.com - research.swtch.com/nih.
27.11.2024 09:17
π 10
π 3
π¬ 0
π 0
My latest blog post is live! nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
27.11.2024 09:10
π 79
π 29
π¬ 3
π 4
one tip for i3 is to use pypi.org/project/quic...
25.11.2024 06:57
π 0
π 0
π¬ 0
π 0
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby!
It builds on the work of others, including Leonardo Giovanni, @ulldma.bsky.social and @vakzz.bsky.social
nastystereo.com/security/rub...
25.11.2024 05:27
π 15
π 5
π¬ 0
π 0