更多153
研究称发现首个经微信通话在 iOS/Android 上零点击传播的蠕虫
零点击蠕虫若成立,影响面覆盖海量移动端用户。
RT @blackorbird: OMG
The first zero-click worm to spread through WeChat calls across iOS and Android.
https://t.co/XdE1UJIdRP https://t.co/OhW9LpZiml
移动端蠕虫零点击报告
@0xocdsec
原文 ↗
VulnCheck 披露供应链中的中国植入物 DARKLANTERN 与 SPEAKINGSTONE
供应链植入的实证分析,涉及设备与固件层面的持久化。
Chinese Implants in the Supply Chain (DARKLANTERN, SPEAKINGSTONE)
https://t.co/PYQMxIauPN
#infosec https://t.co/Z6oLTN4Wuf
供应链植入物报告apt
@0xor0ne
原文 ↗
XBOW 称其自动化系统发现 Chrome 完整利用链,获 25 万美元奖金
自主安全测试产出完整浏览器利用链,标志 AI 挖洞能力跃迁。
RT @pwntester: Incredible achievement: XBOW discovered a Chrome full-chain exploit. Only the second in history to earn the $250K bonus.
Extremely proud of the team and what we’re proving autonomous security testing can achieve. 🚀
ai_agent浏览器漏洞挖掘事件
@0xocdsec
原文 ↗
BlueMoon 利用套件串联两个 V8 零日与 Windows 提权漏洞投递载荷
完整利用链拆解,含 GemStone、ShadowPad 等载荷。
RT @greglesnewich: Heard about those zero days in Chrome and Windows? Well, @markkelly0x found them being used in the SAME exploit kit, proliferating across the APT ecosystem.
Meet BlueMoon exploit kit:
https://t.co/AI3s64MJi1
浏览器利用链提权报告
@0xocdsec
原文 ↗
调查称 LG 电视在待机时采集麦克风音频并做网络发现,LG 否认
智能电视应视作网络内一台主机,涉及家庭网络边界。
This is why I keep saying a “smart TV” should be treated like another computer sitting on your network, not just a screen.
The concerning part is bigger than the headline. Researchers working with Gamers Nexus and Level1Techs reported seeing LG sets perform network discovery, collect ACR viewing data, and, in their testing, capture microphone audio while the display was in standby. They also observed data being retained while offline and transmitted after connectivity returned.
LG disputes the microphone interpretation and says voice processing requires user activation, so I wouldn’t jump from the research straight to “LG intentionally records every conversation.” But the discrepancy between what the researchers measured and what the manufacturer says is exactly why independent testing matters.
And ACR itself is worth understanding. It can fingerprint what is playing on the television, including content coming through other inputs, to identify viewing habits. That may be useful for recommendations and advertising, but it also means the television can have considerably more visibility into your household activity than most people realize.
This is also why I prefer putting smart TVs and other IoT devices on their own VLAN/guest network with limited access to everything else. Privacy settings are good, but network segmentation gives you another boundary when you don’t completely trust what the device or a future firmware update might do.
iot隐私事件网络发现
@Officialwhyte22
原文 ↗
RT @tomshardware: LG strongly denies TV security claims, says tracking and snooping concerns 'not true' — online investigation claims 216,000,000 spy TVs record audio https://t.co/9wWr8wvhmw
RT @mattjay: I summarized the 2 hour LG video. It's worth watching but here's a list.
RT @nyxgeek: If you buy networking gear or laptops on Amazon, it's probably a good idea to re-flash fully before using.
Amazon isn't just "Amazon", it's a conglomerate of storefronts by different sellers.
Maybe the reseller is legit. Maybe they added some 'features'. Point is, be safe. https://t.co/0K560sgFAy
OpenSSL 最新公告修复 9 个漏洞,其中 4 个由 Trail of Bits 发现
RT @trailofbits: OpenSSL's latest advisory covers 9 patched vulnerabilities. Our engineers Filipe Casal and Opal Wright found 4 of them as part of Patch the Planet.
https://t.co/m1JNZI2dbf
opensslcve报告
@0xocdsec
原文 ↗
JPCERT 就 Adobe Acrobat 与 Reader 漏洞发布安全警报
RT @jpcert_en: New Security Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-141) ^TN
https://t.co/bNV1htrZh6
adobecve公告
@0xocdsec
原文 ↗
RT @secbughunter: We been a bit busy. 974 Microsoft CVEs published this morning. https://t.co/0ySRLNB1We
研究者披露 Windows Secure Kernel 三个提权漏洞 CVE
RT @vmpr0be: Happy to share that I found 3 EoP vulnerabilities in the Windows Secure Kernel:
CVE-2026-83939
CVE-2026-69846
CVE-2026-69906
Thanks to @msftsecresponse for coordinating the disclosure. I’ll share more details in a blog post soon!
研究者称本月从 MSRC 获得 37 个 CVE 致谢
RT @KeyZ3r0: I received 37 CVE credits from MSRC this month. Neither the number of vulnerabilities patched nor multiple researchers sharing credit for the same bug is surprising. Luckily, almost all my reports were “no dup”—perhaps the greatest surprise for security researchers in the AI era.
cve微软bugbounty
@0xocdsec
原文 ↗
RT @HototogisuTian: This month, Microsoft’s @msftsecresponse fixed 80 CVEs discovered and reported by me and the outstanding collaborators on our team, including wgg, npc0vo, and 2st. MSRC’s response and remediation were remarkably swift.
#bugbounty #cybersecurity #MSRC #security
cve微软bugbounty
@0xocdsec
原文 ↗
Android 9 月安全公告发布,评论批评季度更新节奏
RT @FuzzySec: Hot take, quarterly Android security bulletins are not good (and posted a day late)
https://t.co/slAQ5tPnZE
评论称除 Pixel 外多数 Android 设备将长期未修补漏洞
Yea unless Pixel almost all Androids will remain vulnerable for Christmas and New Years.
Happy N-Daying all the important or unimportant targets on this planet. GG @Android
LSPromise 公开用户态与内核利用代码,用两个逻辑漏洞攻陷内核
RT @canyie2977: https://t.co/HK6szi3vi2
Both userspace and kernel exploit are now public! See how we use 2 logic bugs to compromise the kernel
研究者披露一个可追溯到 1985 年的 iOS 内核 bug
RT @jachashx: The 40-year-old iOS kernel bug I discovered on the DEFCON 34 main stage.
My demo crashed on stage, and after investigating I traced it to a mistyped ++ that goes back to 1985.
Can you spot the bug?
Full post:
https://t.co/e3vuomAJ8r https://t.co/T4S4Vin80o
一篇 Mexc Android 应用 RCE 的漏洞写文
RT @FlEx0Geek: كلام جميل:
https://t.co/m8Qka34JAN https://t.co/GhsIfzHfwq
沙特政府应用被曝内置沙特国家银行私钥,保护口令为单个数字 2
RT @iam_zachi: Full write-up is out.
A Saudi government app with 10M+ installs shipped the Saudi National Bank's private key. The password protecting it was the digit "2".
Fixed and rotated, so here's all of it. https://t.co/nsXcHcQ2Ba
分析 LATAM 地区假税务通知钓鱼投递定制 HVNC 后门
For https://t.co/URBcFhPXNa, Moises Cerqueira analyses fake tax DocuSign notifications, NFe tax documents and banking-themed phishing used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. https://t.co/4wN2m6mzb9 https://t.co/YB9eb8rosZ
Talos 分析 ClearFake WebDAV 感染链投递 Amatera 等窃密木马
Cisco Talos researcher Vanja Svajcer writes about a ClearFake webdav infection chain delivering Amatera stealer, ZigCryptoStealer, and NetSupport Manager. https://t.co/oERVsODUkB https://t.co/UsZIOmMmFT
Seqrite 分析 macOS 窃密木马 MacSync,经 ClickFix 与恶意广告传播
Seqrite analyses MacSync, a family of macOS information stealers & remote-access stagers designed to evade detection and sold commercially under a MaaS model. MacSync is delivered primarily through ClickFix social engineering & search engine malvertising https://t.co/ZnNDMYWSf6 https://t.co/Q2kckuIBh8
Mirage2FA 钓鱼活动针对美国组织,建议采用抗钓鱼 MFA
RT @anyrun_app: 🚨 #Mirage2FA actively targets US organizations.
Defending against it means phishing-resistant MFA, full session revocation, and behavioral detection that doesn't depend on static indicators.
👨💻 See the analysis and detection guidance: https://t.co/IOs3bugMTP https://t.co/7IIr3IvNPQ
RT @EddyWillems: We often share our location without giving it a second thought. In this @vrtnws report, I had the opportunity to provide some cybersecurity context. A good reminder: sometimes, the most sensitive data is the data we share ourselves!!!
https://t.co/XM0BnUnSRI
分享基于 Teams 帮助台冒充攻击的 KQL 高保真检测规则
🎯𝗗𝗲𝘁𝗲𝗰𝘁 𝗧𝗲𝗮𝗺𝘀-𝗕𝗮𝘀𝗲𝗱 𝗛𝗲𝗹𝗽𝗱𝗲𝘀𝗸 𝗜𝗺𝗽𝗲𝗿𝘀𝗼𝗻𝗮𝘁𝗶𝗼𝗻 𝗔𝘁𝘁𝗮𝗰𝗸𝘀
I have chained the following two detection signals across separate Microsoft Defender XDR schemas to create a 𝗵𝗶𝗴𝗵-𝗳𝗶𝗱𝗲𝗹𝗶𝘁𝘆 𝗱𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 for Teams-based Helpdesk Impersonation attacks:
• 𝙳𝚎𝚝𝚎𝚌𝚝𝚒𝚘𝚗𝙼𝚎𝚝𝚑𝚘𝚍𝚜 contains "𝗠𝗮𝗶𝗹 𝗯𝗼𝗺𝗯𝗶𝗻𝗴"
• 𝙰𝚌𝚝𝚒𝚘𝚗𝚃𝚢𝚙𝚎 == "𝚃𝚎𝚊𝚖𝚜𝙸𝚖𝚙𝚎𝚛𝚜𝚘𝚗𝚊𝚝𝚒𝚘𝚗𝙳𝚎𝚝𝚎𝚌𝚝𝚎𝚍"
By chaining these signals together, defenders can identify adversaries who combine email flooding techniques with Microsoft Teams helpdesk impersonation attempts, significantly reducing false positives and improving detection accuracy.
This approach provides security teams with a more reliable way to detect and investigate this increasingly common social engineering attack technique.
https://t.co/jQD0re5Jaa
#TeamsImpersonation #SocialEngineeringAttack
发布 TerminalFix 的 KQL 检测规则
TerminalFix KQL Detection: 👇
https://t.co/I8XAzPc15J https://t.co/lNQce6vKKT
SpecterOps 介绍用于追踪 OAuth 令牌交换的 TATS 系统
RT @SpecterOps: Tracking OAuth token exchanges is complicated. TATS can help.
@Icemoonhsv introduces the Token Analysis and Tracking System & shares some unexpected findings uncovered along the way.
Check it out! ⤵️ https://t.co/E1rSWpr74M
提醒 AD RMS 在 Server 2025 中仍默认存在,值得研究
RT @4ndr3w6S: Everyone says on-prem AD is picked clean.
Nope!
AD RMS still ships in Server 2025. It got two pages in "AD in a Month of Lunches."
It deserves a series. LFG! 😈
https://t.co/tGmqKPibzJ
adwindows议题
@0xocdsec
原文 ↗
分析公开覆盖率仪表盘可反推内核中尚未被发现的漏洞区域
RT @FuzzingLabs: Takeaway: public coverage dashboards are a map of where the bugs still are. The gaps are the target list.
Full write-up by Alexis & Lyes, crash traces, the Syzlang grammar, the kernel patch:
https://t.co/3fObC61PVN https://t.co/uRFzOBwLGz
Linux 无文件加载绕过 memfd 的新手法,已有检测覆盖
RT @CraigHRowland: This is a very cool way to do fileless loading on Linux bypassing traditional memfd. I hope he doesn't mind, but we detect this out of the box already. Here is a fileless backdoor loaded with his tool. @MatheuzSecurity always does great work and you should follow him.
Black boxes below are special surprises we have coming in Sandfly 6.0. Stay tuned.
linux无文件绕过
@0xTriboulet
原文 ↗
文章解析 BOF、Crystal Palace 与 JellyBeeKORE 编译器实现植入物模块化
BOF, Crystal Palace, and the JellyBeeKORE compiler: The new era of implants modularity https://t.co/zIqxC3149C
passthecert-rs v1.0.0 发布,用纯 Rust 实现基于证书的 LDAPS 认证
RT @g0h4n_0: Releasing passthecert-rs v1.0.0 🦀 🔥
Pass-the-Certificate in pure Rust. 🔐
The initial goal is to bring certificate-based LDAPS auth (PFX or CRT+KEY) to RustHound-CE for the collection phase. It then grew into a full PassTheCert-style toolkit.
Link: https://t.co/zJd78SQxwj
作者预告下版文件句柄重定向将可读取 AD 服务器上的 NTDS.dit
In the next version of the File Handle Redirection we will be accessing the NTDS.dit file from an active directory server... 🤗
BEAR-C2 发布,围绕真实 APT TTP 构建的对抗模拟框架
BEAR-C2 - an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups
https://t.co/vDCTjxpfS4
TornadoRevC2 发布,轻量模块化后渗透框架支持 SOCKS5 与内存执行
TornadoRevC2 - A lightweight, modular post-exploitation framework for Linux and Windows that provides:
✅ reverse shell session management
✅ cross-platform plugins
✅ SOCKS5 pivoting
✅ in-memory payload execution
https://t.co/D8tkIvbgXt
Process Parameter Poisoning - Max Hirschberger & Ogulcan Ugur
https://t.co/7RSNIATZCV
攻击手法windows报告
@pentest_swissky
原文 ↗
作者称将公开 HandlebarJS 的 RCE 利用细节
Since someone else published their RCE for HandlebarJS I will be publishing some stuff too :) https://t.co/8lKopL9dFF
rcejavascriptpoc
@kernelstub
原文 ↗
作者称早前已发现 HandlebarJS 可用于窃取数据库凭据的零日
I forgot I had created a 0day ages ago for exfiltration DB creds etc from HandlebarJS too. https://t.co/E2MgbZITn3
凭据窃取javascript漏洞
@kernelstub
原文 ↗
WooCommerce 11.2.0-dev 被曝未认证任意文件读取
Unauth arbitary read on files on
WooCommerce 11.2.0-dev | WordPress 7.1 | PHP 8.1.34 https://t.co/MoosrJAXWf
任意文件读取wordpress漏洞
@kernelstub
原文 ↗
Intigriti 发布攻击 AI 客服代理的手法分析
Hacking AI customer service agents https://t.co/KK7eV3zYEQ
ai_agentllm报告
@ipurple
原文 ↗
Playing with Claude Hooks... 🪝 https://t.co/avGZRIGDMG
ai_agentclaude工具
@ipurple
原文 ↗
Windows 预览版 29661 引入 wesp.sys,便于 EDR 将能力移至用户态
RT @yarden_shafir: Latest preview build (29661) ships wesp.sys! The long-awaited initiative that should make it easier for EDRs to move capabilities to user mode and stay more resilient against kernel-level attacks. https://t.co/eFHddOKYEl
windowsedr内核
@_RastaMouse
原文 ↗
演示本地 GPU 上自主 Agent 自动构造 Chrome M153 利用链
RT @lordx64: please don't steal any Google Chrome 0 days from this video that I randomly took now showing CyberKimi autonomously constructing an exploit chain for Chrome M153 release from yesterday.
its all autonomous using our special harness, I literally didn't type anything since the M153 was announced.
It cost me $0 per token, because it runs on my 8xB300 gpu node, so I literally have ~200 tokens/s running CyberKimi with full precision on a 1M context.
so I will find 0-days faster than you.
go get CyberKimi here: https://t.co/TSEXXRFoNs
do you have compute to spare and want to collab? hit me up [email protected]
note: by compute I mean B300 GPUs. if you have a farm of B300 sitting on a datacenter, please contact me.
ai_agent浏览器漏洞挖掘
@0xocdsec
原文 ↗
讨论 Defender ASR 中阻止低流行度可执行文件运行的规则效果
RT @techspence: This Microsoft Defender for Endpoint ASR rule is really strong:
Block executable files from running unless they meet a prevalence, age, or trusted list criterion
Why is there no equivalent with other EDR products?
edrwindows防御
@0xocdsec
原文 ↗
研究者怀疑模型在针对其输入做训练,导致解题能力短期跃升
RT @matthew_d_green: So one thing I’ve heard from multiple researchers in my field is that models seem to get *much* better at solving their specific problems over short periods, even asked in new contexts. Many of them have mentioned that they wonder if they’re training on their inputs.
Trail of Bits 称利用 Lean 漏洞用 20 行代码证出费马大定理
RT @trailofbits: Last week, @AnthropicAI formalized Fermat's Last Theorem in 13 million lines of Lean code.
We "proved" that same theorem in 20 lines by exploiting a bug we found in Lean. https://t.co/CqkpVuM2Gt
形式化验证漏洞事件
@Teach2Breach
原文 ↗
people need to appreciate the poetry of this post about a string length bug and the historical rhyme of fermat's own string length assertion
提醒 SQL Server 默认排序规则下等号忽略尾随空格
RT @0xacb: I was playing with SQL Server and noticed the default collation is case insensitive (SQL_Latin1_General_CP1_CI_AS). admin and ADMIN are the same string to the DB. That part is well known.
Less talked about: = also ignores trailing spaces.
'admin' = 'admin␣' is true (␣ is an actual space char)
sqlserver认证绕过技巧
@0x64616e
原文 ↗
Corelan 正用 AI 自动翻译其漏洞利用教程内容
RT @corelanconsult: In order to make it easier for everyone to read / use content on https://t.co/AjnutD27UT for self-study , I am working on auto-AI-translating the content into various languages. A selector will be shown with the available languages automatically. (patience please :))
linux-insides — A book-in-progress about the Linux kernel and its insides. https://t.co/3mAEKHKWCI https://t.co/BdAyl5UXnk
Roadmap to C programming
https://t.co/vvSzk1gKwo
JB
DEFCON 32 游戏破解村 CTF 讲解 .NET 程序集修改
🚩 DEFCON 32 Game Hacking Village CTF 2024
Manipulating .NET games by analyzing CIL and modifying assembly instructions, bypassing checks and grabbing flags
👉 https://t.co/vGI9ngRsxR https://t.co/TM6kMzlGyE
ctfdotnet议题
@GuidedHacking
原文 ↗
reconmtl 议题讲解用 IDA、Ghidra、Binary Ninja 做逆向
The @reconmtl talk "SELECT * FROM binary - Vibe Reverse Engineering with IDA, Ghidra and Binary Ninja" is out.
https://t.co/E2yXHsvY51
逆向议题工具
@BinaryWizards
原文 ↗
@reconmtl And a deep dive into GhidraSQL: https://t.co/m95UdKBCUd
逆向ghidra教程
@BinaryWizards
原文 ↗
@reconmtl But if you want a deep dive, here's a dedicated IDASQL tutorial: https://t.co/0rSxy6Bkl8
逆向ida教程
@BinaryWizards
原文 ↗
Binary Ninja 开始支持自带 MCP 服务器
Binary Ninja now supporting its own MCP server, means I can junk my janky plugin \o/ https://t.co/YoGFcXfHnu
用 Claude 辅助分析 VMProtect 虚拟化保护的二进制
RT @Farenain: I have spent some time improving my tool dragon-tales, and asking @claudeai to help me with an analysis of VMProtect in a small binary protected with virtualization. The idea was using methods like the ones proposed by @qb_triton @aftermath_labs and SATURN https://t.co/pdusJz8Nj1
逆向llm工具
@0xTriboulet
原文 ↗
RT @mqst_: ✍️ An Awesome Series of Writeups on Anti-DDoS research
Part 1: https://t.co/Jh9gpouAKy
Part 2: https://t.co/rbTf7TvsVh
Part 3: https://t.co/KFeYhJnXT0
Part 4: https://t.co/79FozOsmRw
Author: @cocomelonckz
ddos报告
@cocomelonckz
原文 ↗
https://t.co/Lb8wb5fPmT next one from my blog! enjoy
https://t.co/R6nglthZeK
#hacking #cybersec #cybersecurity #threatintel #threathunting #redteam #blueteam #purpleteam #ddos #attack #detect #malwareanalysis #math #probability #research #book https://t.co/bqkJOQ4SFI
ddos检测报告
@cocomelonckz
原文 ↗
Cobalt Strike 发布威胁场景剧本,映射 APT29 等真实攻击手法
How would your defenses hold up against APT29, LockBit, or Scattered Spider? Our new Threat Scenarios Playbook maps real-world attacker tradecraft to offensive security exercises showing how red teams can emulate known adversaries and test defenses.
https://t.co/ibLA91thfe https://t.co/UE0tcGZ9B6
红队报告c2
@_CobaltStrike
原文 ↗
It's a race and we are far behind.
We derived the wave equation from a simple idea:
A change at one point takes time to travel to another point.
The same physical idea matters in DDR memory.
A DDR signal travels through real traces, packages and interconnects, so it has a finite propagation delay.
For an ideal transmission line:
v = 1/√(LC)
where L and C are inductance and capacitance per unit length.
Now consider what happens when the signal reaches the receiver.
The data and DQS signals must arrive with the right timing relationship for the receiver to sample the data reliably.
That's why DDR initialization is more than configuring a few registers.
During boot, DDR PHY training adjusts parameters such as read/write timing and DQS alignment to find a reliable sampling point within the valid timing window.
In simple terms:
wave propagation
→ propagation delay
→ timing differences
→ valid sampling window
→ DDR training
The wave equation describes how signals propagate.
DDR training deals with the practical consequence:
When should the receiver look at the signal?
At high data rates, even tiny timing differences can reduce the available margin.
A useful systems lesson:
Once signals get fast enough, physics becomes part of the software-visible system.
Lately, I've been reading about signals and systems and re-learning mathematics from basics.
One of the basic questions, how do you actually derive the wave equation?
Let's start from something physical: a stretched string.
Assume:
• The string has uniform tension T
• μ is its mass per unit length
• The displacement is small
• The slope of the string is small
• We ignore damping
Let:
u(x,t) = displacement of the string
x = position along the string
t = time
First, what does this mean?
∂u/∂x
Take two points very close to each other.
If their displacements are different, the string has a slope.
So:
∂u/∂x = slope of the string
The first derivative tells us how quickly displacement changes as we move along the string.
Now take the derivative again:
∂²u/∂x²
This tells us how quickly the slope is changing.
So, in simple terms:
∂u/∂x → slope
∂²u/∂x² → change in slope → curvature
Strictly speaking, ∂²u/∂x² is only approximately the curvature when the slope is small.
Now take a tiny piece of string of length Δx.
The string tension T pulls this piece from both ends.
If the string is straight, the two tension forces cancel.
Net force = 0
But if the string is curved, the directions of the two tension forces are slightly different.
They no longer completely cancel.
This creates a restoring force.
For a small slope:
vertical force ≈ T × change in slope
The change in slope across Δx is:
(∂²u/∂x²)Δx
Therefore:
F ≈ T(∂²u/∂x²)Δx
Now use Newton's second law:
F = ma
The mass of our tiny piece is:
m = μΔx
because μ is mass per unit length.
What is its acceleration?
u = displacement
∂u/∂t = velocity
∂²u/∂t² = acceleration
Therefore:
a = ∂²u/∂t²
Put this into F = ma:
T(∂²u/∂x²)Δx
μΔx(∂²u/∂t²)
Cancel Δx:
T(∂²u/∂x²)
μ(∂²u/∂t²)
Rearrange:
∂²u/∂t²
(T/μ)(∂²u/∂x²)
Now define the wave speed:
v = √(T/μ)
So:
v² = T/μ
Therefore:
∂²u/∂t²
v²(∂²u/∂x²)
And that's the 1D wave equation.
Look at what the equation is really saying:
∂²u/∂x² → curvature of the string
∂²u/∂t² → acceleration of the string
So:
curvature → restoring force → acceleration → motion
A disturbance at one point creates a force on the nearby points.
Those points move, creating force on the next points.
The disturbance therefore travels along the string.
The wave equation is not a formula pulled out of nowhere.
It comes from:
geometry + tension + mass + Newton's second law.
And the wave speed is:
v = √(T/μ)
More tension → faster wave.
More mass per unit length → slower wave.
A surprisingly simple physical system leads to one of the most important equations in physics.
AI is so good at finding vulnerabilities on the server side, and it is so bad for the client side
ai_agent漏洞挖掘评论
@h4x0r_dz
原文 ↗
关于 DeepSeek Flash 4.1 的讨论
deepseek flash 4.1 👀👀
关于 DeepSeek V4.1 Flash 的讨论
wholy fuck shit DeepSeek V4.1 Flash
Astra 需求激增,厂商称可能暂停新 Pro 订阅
RT @thsottiaux: Demand for Astra is really unprecedented. We're pulling all the levers possible to sustain the demand, but I've not seen anything like it until now and we went through very steep growth before. Priority will always be to keep excellent service for existing users, but we might have to pause new Pro subscriptions for a bit if this continues.
演示用 GPT-6 构建的 M3TH 实验室模拟器
RT @elder_plinius: Astra can COOK! ⚗️🧑🔬
M3TH Lab Simulator — built by GPT-6 🤗 https://t.co/psOOh9tk4s
前 OpenAI/Anthropic 研究员辞职,公开批评两家公司不负责任
RT @hilbertspaess: I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.
Terence Tao 评论 AI 可能让研究者不再公开研究方向
RT @GaryMarcus: Still more absolute 🔥 from Terence Tao:
“We have now seen that even the rumor of someone working on a problem can trigger a massive amount of AI-powered effort to flatten it before the original research project has time to reach its full potential. The incentives may now be pointing in the direction of no longer sharing any promising research directions with the broader community, which would reverse centuries of traditions of open science and do serious long-term damage to the future of the field”
传闻消费级 AI 工具会用生产用户数据衍生数据做训练
RT @aidangomez: Synthetic data derived from production user data of consumer AI tools is used for training. I’ve heard this rumour from both large labs’ employees.
In particular, if you’re doing something “interesting” like working on complex math/business/software/bio problems you’re dramatically more likely to get trained on because they filter/up-weight towards those usecases where the model has the most to learn.
Even in ZDR and “we won’t train on you” regimes, derivative data is usually carved out. The promise is only not to train on exactly the data you put in, rewritten data is fair game.
llm隐私讨论
@0xTriboulet
原文 ↗
This is actually terrifying.
The next few years are going to be either really interesting or an absolute massacre for jobs. And honestly, it could be difficult for both those who adapt and those who don’t.
So, what’s the solution?
did all these AI lab fucks copy my stylometric profile. capitalize something you bastards
评论称批评 AI 末日论者的人多与实验室有利益关联
the people i see bashing "AI doomers" all have AI investments or work at the labs
focus on building something you love. if the thing you do for money now is going to be wiped out by AI, then you might as well. if you're lucky, authentic human creation will be more desirable than whatever you work on now. if not, well hey, at least you made something
RT @RayKump: We have to build AI that murders us, because if we don’t, China will build it first, and I don’t want to get murdered by a computer that speaks Chinese. That would be ridiculous.
分享关于 AI 竞赛中 Moloch 困境的文章链接
@HackingDave https://t.co/DFA5UX7ZnS
评论称 AI 实验室 reckless、无人关心社会损害
it didnt seem to have much point. i guess he just got doom-pilled. i been saying these labs are reckless and could care less about societal damage the whole time. he’ll soon learn that nobody cares. number go up. bigger boat. i got mine. etc… read the early moloch paper. i guess he didnt yet. theres no brakes on this train
As always on Twitter this post will be amplified by anti western bots to make the east get ahead, but apart from that, humans don't have a choice.
It's never about who owns a timespan, it's about evolution itself. https://t.co/kGbHBebPyq
RT @benitoz: @hilbertspaess Do you want China to win?
吐槽某应用蠕虫级 RCE 的赏金仅约 500 美元
RT @lyq_sqsp: Very impressive that this is a memory corruption issue.
BTW I'm curious about the bounty. We've got a wormable RCE in a similar APP with hundreds of millions of users, and their SRC's bounty is like ~$500 for that 🤡
Kinda solved with smaller open weight models
RT @CharlesDardaman: @HackingLZ @UK_Daniel_Card It’s easier to sell security services and EDR than fix the fact that you’re the source of alot of the issues
批评微软长期安全投入不足却把 CVE 潮包装成正面 PR
RT @HackingLZ: I struggle with Microsoft spending far too little on security for decades, then somehow turning the resulting flood of CVEs into positive PR about doing the right thing and leading the way with AI. Meanwhile, I’m watching people shake LPEs out of Windows with prompts barely more sophisticated than “find me bugs, k plz.”
Glasswing and similar projects forced a lot of these companies to confront how bad their codebases had been all along. They’re now carefully managing that reckoning into a story about security leadership and AI adoption.
建议购买 R9700 显卡跑 Qwen3.8-27b 本地模型
Just buy an R9700 and use Qwen3.8-27b
llm硬件建议
@0xTriboulet
原文 ↗
Horizon3 CEO 讲述硅谷银行倒闭时的应对经历
RT @Horizon3ai: When Silicon Valley Bank collapsed in 2023, Horizon3 CEO @snehalantani had to act quickly. All company funds were held at SVB — now frozen, with the threat of missing payroll and incurring $750K daily penalties looming.
Instead of panicking, he drew $1M from a personal line of credit and told the company exactly what was going on, and how he and the executive team were handling it.
Snehal credits the leadership lessons he learned at JSOC with helping him navigate the crisis: stay steady, calm, and controlled when stakes are high.
In a new @BusinessInsider profile from @saraheneedleman, Snehal shares why he waited to become a founder and the lessons that shaped how he leads through uncertainty.
Read the full story at https://t.co/nIk8cXBRGg
#Leadership #CrisisLeadership #Cybersecurity #Startups
RT @HackingLZ: One thing I’ll never fully understand is hunting for random Windows bugs for free, just to find them and never do anything cool with them. I understand chasing a Chrome RCE payout or some pre auth magic because the money is there. Anytime I went looking for bugs, it was because I wanted to use them on an engagement or as part of a complex chain to achieve some goal.
调侃 ChatGPT 花数百万算力争夺百万美元奖金
RT @HackingLZ: ChatGPT spending millions in compute to beat someone else to a $1 million prize is the most Elon “love of the game” thing they’ve done in a while.
FreeBSD 14.5 发布,附带升级 OpenBSD 的调侃
RT @canadianbryan: FreeBSD 14.5 released! Upgrade to OpenBSD 7.9 today! ☺️
RT @Secure_ICS_OT: https://t.co/O0KJdA8vil
RT @tunguz: My whole TL today. https://t.co/rqtH5mRY5U
RT @MarioNawfal: I will not get tired of saying it: a woman’s worst enemy is another woman.
Writer: Sol
https://t.co/oW50YFwmOu
RT @SummerShaddows: Actual Africans mocking African Americans. 😂 https://t.co/QbuRDpV6sD
RT @IAPonomarenko: Propaganda does not make people stupid, but it is designed for the stupid https://t.co/JILejXuSXI
转发关于 Anthropic 内部解决卡牌抢购的传闻
RT @beginbot: wow I just heard a rumor that Anthropic has solved Pokemon card scalping internally
I wonder how many tokens it took
RT @dheeraj_nagaraj: I was an intern under Seb in 2020. Unfortunately, the allegations of unscrupulous behavior is 100% believable. I am glad that the mask is off publicly. I really hope he doesn't weasel out of this.
https://t.co/Pe6e6cK920
RT @rekdt: AGI is everywhere when your intelligence is below average https://t.co/56xRyJ0oDo
https://t.co/O2jJI4VhGm
@_EthicalChaos_ @msftsecresponse Congrats, Ceri! 🥳🔥
@mrgretzky @msftsecresponse Thank you Kuba.
@codex_tf2 @USAO_DC 😭
RT @abdallaemad715: I just completed @Pentesterlab's Code Review Badge!!! https://t.co/VksFRr8rKc
@kyleavery @USAO_DC oh this guy
@C5pider I'd like to cringe but I might spoil the treat for red teamers.
https://t.co/Bo5aIzgaoE
https://t.co/sidJpKcrBL
RT @soshortsolong: @finkd Do you actually pay anyone? https://t.co/0oUam8QRjM
RT @canyie2977: @0xocdsec @GrapheneOS Just a kind remind: they blocked me, you will need to manually forward the post if you want to let they see
👀👀👀👀
Meta duplicate party soon
This is how AGI is going to treat us in the future.
RT @paularambles: whoever’s in charge of comms at anthropic https://t.co/GqY0JgibwV
Man I love this band ❤️ https://t.co/hyoe0Llfin
If you're going to be a Blackhat and get away with it, don't buy the yellow Hummer 🤣 https://t.co/XxuqP7DyOB
转发 Defender ShieldCrash 零日可获 SYSTEM 权限的报道
RT @BleepinComputer: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
https://t.co/nglocI93ut
https://t.co/nglocI93ut
lpewindows零日
@artem_i_baranov
原文 ↗
演示让 AI 不用编译器直接输出十六进制写 OpenGL 动画
延续昨天的话题https://t.co/x4Tlwi6I2b 刚才先让 AI 不用编译器写一个五子棋游戏。检查中发现 AI 先用 Python 构造了一个汇编器。虽然这不算违规,但接下来我要求 AI 必须直接输出十六进制,调用 OpenGL,写一个哆啦A梦吃铜锣烧的 2D 动画程序。结果 AI 也做出来了。虽然动画有点丑,但程序没问题。 https://t.co/IE0o9TRn4I
推荐关注某研究者关于绕过 EDR 与遥测规避的研究
RT @cr3ghost: Detection engineers, red teamers, malware analysts, hardware hackers and reverse engineers: bookmark this FREE rabbit hole.
@waldoirc is one of the most underrated hackers out there.
His research is not just about bypassing EDRs like CrowdStrike or Microsoft Defender for Endpoint. It is about understanding how to blend into the telemetry they collect, what artifacts still survive, and how defenders can detect the behavior even when no alert fires.
PoC Local Privilege Escalation Exploit to SYSTEM for CVE-2021-21551: https://t.co/vQS65Pszab
That is the important lesson:
Don't rely on alerts. Learn the telemetry. Hunt the behavior.
Cobalt Strike. BeaconEye. PE-sieve. Moneta. Heap encryption. DLL/module stomping. Return-address spoofing. APC. VEH. ROP. sRDI. Reflective loading. RWX/private memory. Sleep obfuscation. Memory scanning. Shellcode.
And that's only the Windows side.
There's also kernel exploitation, CVE PoCs, ARM reversing, QEMU, firmware dumping, UART, Bus Pirate, SDR, Zigbee, Bluetooth, hardware hacking and CTF research.
Red teamers: study how memory detections get bypassed.
Detection engineers + blue teams: study the artifacts those bypasses still leave behind.
Malware analysts + reverse engineers: study the hooks, memory layouts, call stacks, loaders and execution primitives underneath both sides.
The best part is the research loop:
Build technique -> understand detection -> bypass detection -> improve detection.
Blog:
https://t.co/VzwKU8iFCB
GitHub:
https://t.co/g5tbXewulo
A seriously underrated archive. Save it.
#DetectionEngineering #RedTeam #MalwareAnalysis
分析签名正常的 OneDriveStandaloneUpdater.exe 发起可疑外连的排查过程
This one was a bit deceptive because the executable itself was actually signed by Microsoft.
We had a workstation making an outbound connection that we could not immediately explain.
When I traced the connection back to the process, I found:
OneDriveStandaloneUpdater.exe
At first glance, that did not look too serious.
I checked the digital signature.
Valid Microsoft signature.
So if I had stopped there, I probably would have assumed it was just OneDrive doing something in the background.
But the location bothered me.
It was running from:
C:\Users\james\AppData\Local\Temp\ODUpdate\
That is not somewhere I would expect a OneDrive updater to just sit permanently and run from.
So I checked everything else inside that folder.
There were only two files:
OneDriveStandaloneUpdater.exe
and
version.dll
The EXE was properly signed.
version.dll was not.
Now it was starting to make sense.
I checked the Sysmon Image Load events.
Event ID 7 showed the signed OneDrive executable loading that exact version.dll from the same temporary directory.
That is when DLL side-loading became a serious possibility.
The idea is quite simple.
You take a legitimate, trusted executable that expects to load a DLL.
Then you place a malicious DLL with the expected name somewhere the application will search first.
The legitimate program starts.
Windows loads the attacker-controlled DLL into it.
Now when somebody checks the process, they may only see a properly signed Microsoft executable running.
That is what made this one interesting.
The process maintaining the outbound HTTPS connection was still:
OneDriveStandaloneUpdater.exe
The executable itself had not been modified.
The suspicious part was what it had loaded into its process.
We isolated the workstation and preserved both files along with the Sysmon logs before doing anything else.
We also started working backwards to find out how that folder ended up in the user’s Temp directory in the first place.
This case is one reason I do not treat a valid digital signature as the end of an investigation.
A signature can tell you that a particular executable is legitimately signed.
It does not automatically tell you that everything the executable loads at runtime is trustworthy.
Sometimes the EXE is completely legitimate.
The DLL beside it is the part you actually need to investigate.
事件响应windows报告
@Officialwhyte22
原文 ↗
评论称近期 Chrome 零日属十年前就存在的 JSE bug 类回归
Recent 0-Day in Chrome is a canon JSE bug class like those I exploited 10 years ago. Most researchers think they no longer exist. This year’s regression
brave-browser v1.97.8 — Brave browser for Android, iOS, Linux, macOS, Windows. https://t.co/vSvBgdduav https://t.co/hTz2JIz1gc
openvpn v2.7.7 — Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for... https://t.co/DfEuU8VIAc https://t.co/mQKF5tXMrG
uBlock v1.74.1b3 — Wide-spectrum content blocker for browsers that blocks ads, trackers, coin miners, and malicious sites using filter lists and... https://t.co/zgRNtTKnXD https://t.co/q1lhV5XN5S
PHPStan 发布 v2.2.13 静态分析工具更新
phpstan v2.2.13 — PHP Static Analysis Tool - discover bugs in your code without running it! https://t.co/z8jkdkTx2M https://t.co/QiJjsIQPrH
Zitadel 发布 v4.17.3 身份与访问管理平台更新
zitadel v4.17.3 — Open-source identity and access management platform providing SSO, MFA, passkeys, OIDC, SAML, SCIM, and multi-tenant access control for... https://t.co/kVrdyMUWFG https://t.co/sJnU72dswm
changedetection.io 发布 v0.60.3 网页变更监控工具更新
https://t.co/dWeeCyzueI v0.60.3 — Best and simplest tool for website change detection, web page monitoring, and website change alerts... https://t.co/fIHgSUAjiT https://t.co/VkXeBV7zGY
Signal iOS 发布 v8.27.0.1843 更新
Signal-iOS v8.27.0.1843 — Open-source iOS messenger providing end-to-end encrypted text, voice, and video calls via the Signal Protocol, with no... https://t.co/L8E3cQVfcs https://t.co/x72nvuPNEQ
👀 Anti-Cheat Development Course Sneak Peek
Arriving at the end of 2026, this massive course offers a comprehensive guide to understanding detection mechanics and learning how to develop anti-cheat software.
👉 https://t.co/wIJXl9Nj6C https://t.co/b8WTVCm17c
课程反作弊
@GuidedHacking
原文 ↗
It would be interesting if there was a platform to submit the names of the companies that have untuned ATS or fake jobs... https://t.co/0eHpLjXyPH
RT @bohops: Don't forget to think about your well-being from time-to-time and go do other things that make you happy or provide fulfillment:
- Disconnect from social media
- Get off the screen and go touch grass and enjoy nature
- Embrace hobbies outside of tech/cyber/etc.
- Workout or go for a walk/run
- Wake up early to catch a sunrise with a coffee
调侃微软 Coreutils 中 tail.exe 的表现
RT @ewilded: Microsoft Coreutils (version 2026.9.3 and earlier) tail.exe 🤭 https://t.co/9wqZpR43Zz
New Private matrix chat for ppl I know, dm me your matrix handles :)
RT @Fikriyat123: Ruhi çenet kingim direk şu https://t.co/lJHswlpBVI
kuş ölür sen uçuşu hatırla :)
Bruh
RT @_can1357: I am now a married man!
Should be back next week🤞but huge s/o to @BwitneyHouston for keeping up with our insane one-release-a-day schedule, and all of our contributors who have been taking care of omp for the last few days.
RT @MiaAI_lab: https://t.co/PwahZbpJ4N
Some will say the aliens didn’t build this
RT @wilcardjayx: boss keh!!
i'm a boy who's born BlackHat baptised to GreyHat, now who's a grown up baby who has little knowledge of irl hacking/cybersecurity, I'm still learning though I can do some things on my own without ai..
I just have knowledge on how to use ai/configure them to perform the major tasks, work within the given perimeter and get things done!
I follow these guys to learn on CT: @dontfadedave, @GodwinXbt @Officialwhyte22 and few other guys
see how this ollama model plays out🤧
ai转发
@Officialwhyte22
原文 ↗
who could have predicted this?
RT @0xbfho: boh starred outflanknl/ntlmrain on Github https://t.co/TZOkU1PeBO
RT @shtuka123: Excited to announce I will be joining Jurassic Park labs as a safety researcher! Looking forward to bringing these creatures to the public in a safe and secure manner!
RT @LudlowInstitute: https://t.co/Ho05e9CqyB
seems like a bit much for executive security…
Why is this presented here as some kind of big revelation !? If they can access your phone, they can just sync it with a desktop application and get all your messages. It is really not difficult. Accessing your phone's internals of course without the users collaboration ( meaning: handing over your access data ) is slightly more tricky.
Worth the 22 hours of travel for 😍
报道中国 CXMT 的 HBM3 良率停滞在 25%
RT @jukan05: "Three out of four are defective"... China's CXMT struggles with HBM yields, with immature TSV technology to blame
ChangXin Memory Technologies (CXMT), China's largest DRAM maker, has begun trial production of fourth generation high bandwidth memory (HBM3), but initial yields are barely improving. Yields are reported to have stalled at 25%, roughly one third of the so called "golden yield" of 80% that the semiconductor industry treats as the threshold for volume production. The gap is stark compared with SK hynix, which has been mass producing the same product since 2022 and has secured yields above 90%. Industry sources point to the gap in maturity of through-silicon via (TSV) technology, the core process for stacking and connecting multiple DRAM layers, as the root cause.
◇ "DRAM has caught up, but HBM stacking is a different problem"
According to a senior official at a semiconductor equipment company familiar with CXMT's situation on the 9th, the yield of CXMT's HBM3 8-High product is stuck at around 30% in the front end process. Of the products that survive that stage, only about 70% are recognized as final good units after passing through the back end process. In simple terms, if 100 HBM3 units are started, close to 80 of them fail the final test.
CXMT is reported to be supplying the small volumes of HBM samples it produces this way to Chinese companies such as Alibaba's T-Head and Cambricon while continuing its yield improvement work. The problem is that the issue does not lie in the fine process technology of the DRAM itself. A semiconductor equipment industry official explained, "There is no major problem with the standard DRAM that CXMT makes on its 'G4' (17nm class) process used for HBM. However, the DRAM dies used for HBM are larger in area than standard products and have more demanding electrical specifications, so even on the same process they are much harder to pass the acceptance criteria."
In other words, CXMT's fundamental capability in making standard DRAM has risen to a considerable level, but a bottleneck is emerging at the stage of converting it into the high performance product that is HBM. At the heart of that bottleneck, according to industry sources, is the TSV process.
◇ The real hurdle is TSV... "Impossible to catch up without years of accumulated know how"
TSV stands for "Through Silicon Via" and refers to the microscopic copper wiring that passes vertically through each layer to carry electrical signals when DRAM is stacked in multiple layers, as in HBM. It is a highly demanding process in which a DRAM wafer is thinned down to several tens of micrometers, a fraction of the thickness of a human hair, after which thousands of tiny holes are drilled through that thin silicon plate and filled completely with copper. A single hole that is misaligned or not properly filled can cause the entire layer to be rejected, making it one of the semiconductor processes with the most stringent precision requirements.
The consensus in the industry is that this is the process where the technology gap between CXMT and the leading companies is widest. According to analysis by semiconductor research firm Nomad Semi, Samsung Electronics' HBM2 (second generation HBM) has more than 5,000 TSVs per die and SK hynix's HBM3 has more than 8,000, while CXMT's is understood to have only around 3,000. A smaller number of TSVs means sacrificing bandwidth (data processing speed) in exchange for lower process difficulty, yet even so CXMT's yields still fall far short of Samsung and SK hynix. TSV is a process that is challenging even for the industry leader: SK hynix itself publicly disclosed in 2024 that the yield of the standalone TSV process was only 40 to 60% at the time.
On top of this, yield losses also occur in the back end (stacking and bonding) stage where the dies are actually stacked and joined. If even one of the eight dies is misaligned, if a microscopic void forms at a bonding interface, or if a layer warps during the thermocompression bonding process (warpage), the entire stack is scrapped. Because the number of possible failure points grows with each additional layer, the difficulty rises exponentially. Given that CXMT is already showing such poor yields at 8-High, some expect it to face even greater difficulties when moving to higher stacks such as 12-High.
A semiconductor industry official explained, "The TSV process is an area that only stabilizes after years of accumulated wafer handling know how. Chinese companies have rapidly closed the gap in the fine process technology of DRAM itself, but back end know how such as TSV and bonding is difficult to catch up on in a short period." He added, "That said, Samsung Electronics also had initial HBM4 (sixth generation HBM) production yields below 60% in February this year and raised them to 80% within six months, so it is too early to declare CXMT's 25% yield a 'failure.'"
RT @realNyarime: 深圳湾公园的深夜巡逻机器人
Powered by @nvidia https://t.co/Yl8ckGELmY
转发关于 DHH 批评 Nix 生态却计划基于 NixOS 构建发行版的评论
RT @cafkafk: Let me do one serious post chat, and I'll resume shitposting. This is important to make explicitly clear.
Two weeks ago, fellow Dane, David Heinemeier Hansson (@dhh) went on a public tirade about Nix and the Linux ecosystem.
"Goddamn maniacs." "Clowns." "Goblins." "Cancer."
In the same conversation, he called Nix “amazing technology.”
Two days ago, it became clear that he is planning to build his "distribution" on NixOS.
That is worth dwelling on.
NixOS can be criticized. Of course it can. We criticize ourselves constantly.
What I find deeply gross is arriving as a tourist to an ecosystem, using an enormous platform to ridicule the people who built it, then deciding their work is good enough to become the foundation of your own project.
Much of his indictment is not even about NixOS. Land acknowledgements? That is not some defining debate here. It is Twitter culture-war material imported into a caricature of a community he barely knows.
For someone so insistent that technology should be "apolitical", David spends a lot of time talking about politics, culture, codes of conduct, and community governance.
He rails against codes of conduct, then writes rules for how people in his own community should behave while insisting that somehow does not count.
Call it whatever you want. Communities require governance.
And governance, packaging, security, infrastructure, release engineering, review and maintenance are not distractions from building a distribution.
They are the work.
So far, what he has is a configuration and installer layer on top of years of work by Arch, Linux, Rust, and soon NixOS and Nixpkgs contributors.
Using Claude to produce that glue does not make the work underneath disappear.
Packages, infrastructure, security and technical knowledge exist because people did the difficult, boring work required to make this ecosystem function.
You are not replacing those people. You are depending on them.
Which makes the rhetoric about creating a home for the "competent" people obnoxious.
David, the competent people are already here.
They are the people your project depends on — including people and communities you have been calling clowns.
You do not get to praise the "amazing technology", dismiss the people who sustain it as politically deranged, put a layer on top, and cast yourself as the serious technical adult in the room.
That is not escaping dysfunction. It is standing on other people's work while sneering downward.
People mock NixOS. They declare it insane. They explain why nobody should want it.
And then they use it anyway. So who's competent here?
You can hate us. You can mock us. You can call us clowns.
But when the answer to your own technical problems is to build on our work, that tells its own story.
So, David: welcome to NixOS.
But understand what you are standing on.
If you intend to build on years of work from this community, the attitude adjustment is overdue: less culture-war posturing, more respect and humility toward the people doing the work you now depend on.
转发某研究者发现 Shopify 漏洞获 5 万美元赏金的消息
RT @__nav1n_: He came, found a bug in Shopify, bagged $50K, and left without a trace... @auguzanellato https://t.co/QMubzL40Mc
RT @kaganisildak: running Peugeot 508 in QEMU :p https://t.co/84Cd93Gg7D
转发在 QEMU 中运行特斯拉 Model 3 系统的演示
RT @0xrootRE: Finally got a Tesla Model 3 — well, technically it’s running in QEMU. https://t.co/F5XDzBJ0LT
It's a race and we are far behind.