<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Interesting links of the week:]]></title><description><![CDATA[<p>Interesting links of the week:</p><p>Strategy:</p><p>* <a href="https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/" rel="nofollow noopener"><span>https://www.</span><span>isc.org/blogs/2026-04-16-How-t</span><span>o-report-a-vulnerability/</span></a> - <span><a href="/user/iscdotorg%40fosstodon.org">@<span>iscdotorg</span></a></span> makes some useful suggestions on reporting vulnerabilities<br />* <a href="https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/" rel="nofollow noopener"><span>https://</span><span>sushegaad.github.io/Claude-Ski</span><span>lls-Governance-Risk-and-Compliance/</span></a> - building a GRC framework with Claude <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f916.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--robot_face" style="height:23px;width:auto;vertical-align:middle" title="🤖" alt="🤖" /><br />* <a href="https://jericho.blog/2026/04/17/nvd-gives-up/" rel="nofollow noopener"><span>https://</span><span>jericho.blog/2026/04/17/nvd-gi</span><span>ves-up/</span></a> - Jericho from <span><a href="https://defcon.social/@attritionorg">@<span>attritionorg</span></a></span> gives us the skinny on the NVD updates<br />* <a href="https://www.usenix.org/system/files/login/articles/login_apr15_12_geer.pdf" rel="nofollow noopener"><span>https://www.</span><span>usenix.org/system/files/login/</span><span>articles/login_apr15_12_geer.pdf</span></a> - Dan Geer predicts...<br />* <a href="https://security.googleblog.com/2025/04/google-launches-sec-gemini-v1-new.html" rel="nofollow noopener"><span>https://</span><span>security.googleblog.com/2025/0</span><span>4/google-launches-sec-gemini-v1-new.html</span></a> - remembering Sec-Gemini v1 hype<br />* <a href="https://init6.com/papers/Day-Zero-Normal-CISO-Brief.pdf" rel="nofollow noopener"><span>https://</span><span>init6.com/papers/Day-Zero-Norm</span><span>al-CISO-Brief.pdf</span></a> - <span><a href="/user/mubix%40infosec.exchange">@<span>mubix</span></a></span> comes with another take on AI and LLM<br />* <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf" rel="nofollow noopener"><span>https://</span><span>labs.cloudsecurityalliance.org</span><span>/wp-content/uploads/2026/04/mythosready-20260413.pdf</span></a> - the Cloud Security Aliance chip in<br />* <a href="https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/" rel="nofollow noopener"><span>https://</span><span>cje.io/2026/04/08/offense-scal</span><span>es-with-compute-defense-scales-with-committees/</span></a> - as does @cje</p><p>Detection:</p><p>* <a href="https://pub.expmon.com/" rel="nofollow noopener"><span>https://</span><span>pub.expmon.com/</span><span></span></a> - Haifei Li's EXPMON<br />* <a href="https://obdev.at/blog/little-snitch-for-linux/" rel="nofollow noopener"><span>https://</span><span>obdev.at/blog/little-snitch-fo</span><span>r-linux/</span></a> - <span><a href="https://mastodon.obdev.at/@littlesnitch">@<span>littlesnitch</span></a></span> comes to Linux</p><p>Bugs:</p><p>* <a href="https://x.com/Gi7w0rm/status/2042370775546482815" rel="nofollow noopener"><span>https://</span><span>x.com/Gi7w0rm/status/204237077</span><span>5546482815</span></a> - more on that spike in Adobe Reader bugs chain<br />* <a href="https://rhisac.org/threat-intelligence/bluehammer-windows-local-privilege-escalation-zero-day-publicly-released/" rel="nofollow noopener"><span>https://</span><span>rhisac.org/threat-intelligence</span><span>/bluehammer-windows-local-privilege-escalation-zero-day-publicly-released/</span></a> - moar on Blue Hammer #1<br />* <a href="https://www.cyderes.com/howler-cell/windows-zero-day-bluehammer" rel="nofollow noopener"><span>https://www.</span><span>cyderes.com/howler-cell/window</span><span>s-zero-day-bluehammer</span></a> - moar on Blue Hammer #2<br />* <a href="https://www.coresecurity.com/blog/analysis-bluehammer-lpe-exploiting-windows-defender-updates" rel="nofollow noopener"><span>https://www.</span><span>coresecurity.com/blog/analysis</span><span>-bluehammer-lpe-exploiting-windows-defender-updates</span></a> - moar on Blue Hammer #3</p><p>Exploitation:</p><p>* <a href="https://www.slideshare.net/slideshow/how-i-use-ai-for-penetration-testing-teri-radichel-2nd-sight-lab-3fb8/286987132" rel="nofollow noopener"><span>https://www.</span><span>slideshare.net/slideshow/how-i</span><span>-use-ai-for-penetration-testing-teri-radichel-2nd-sight-lab-3fb8/286987132</span></a> - <span><a href="/user/teriradichel%40infosec.exchange">@<span>teriradichel</span></a></span></p><p>Hard hacks:</p><p>* <a href="https://hackers-arise.com/scada-ics-hacking-and-security-attacking-the-modbus-protocol-with-rofuzz/" rel="nofollow noopener"><span>https://</span><span>hackers-arise.com/scada-ics-ha</span><span>cking-and-security-attacking-the-modbus-protocol-with-rofuzz/</span></a> - attacking ICS and other OT with rofuzz<br />* <a href="https://medium.com/@theopenshelf/amazon-is-cutting-kindle-store-access-on-pre-2013-kindles-a7b495cb51ee" rel="nofollow noopener"><span>https://</span><span>medium.com/@theopenshelf/amazo</span><span>n-is-cutting-kindle-store-access-on-pre-2013-kindles-a7b495cb51ee</span></a> - Amazon has a Kindle problem and how you can help...</p><p>Development:</p><p>* <a href="https://appsec.guide/docs/languages/c-cpp/lang-c-cpp-bug-classes/" rel="nofollow noopener"><span>https://</span><span>appsec.guide/docs/languages/c-</span><span>cpp/lang-c-cpp-bug-classes/</span></a> - <span><a href="/user/trailofbits%40infosec.exchange">@<span>trailofbits</span></a></span>'s security coding guidance with bits'n'pieces from @gsuberland<br />* <a href="https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/" rel="nofollow noopener"><span>https://</span><span>blog.trailofbits.com/2026/04/0</span><span>9/master-c-and-c-with-our-new-testing-handbook-chapter/</span></a> - <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span>'s accompanying blog post<br />* <a href="https://arxiv.org/html/2603.21852v2" rel="nofollow noopener"><span>https://</span><span>arxiv.org/html/2603.21852v2</span><span></span></a> - all elementary functions from a single operator</p><p>Data:</p><p>* <a href="https://cardcatalogforlife.substack.com/p/google-has-a-secret-reference-desk" rel="nofollow noopener"><span>https://</span><span>cardcatalogforlife.substack.co</span><span>m/p/google-has-a-secret-reference-desk</span></a> - getting more out of GOOG</p><p>It's notable how many of the talking heads on AI and LLM are US based or funded *and* how many of them come from a cloud centric generation of businesses...</p><p><a href="https://infosec.exchange/tags/security" rel="tag">#<span>security</span></a>, <a href="https://infosec.exchange/tags/research" rel="tag">#<span>research</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/79398f6c-9181-4e2c-9f90-84a261baf02b/interesting-links-of-the-week</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 00:37:23 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/79398f6c-9181-4e2c-9f90-84a261baf02b.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Apr 2026 10:23:41 GMT</pubDate><ttl>60</ttl></channel></rss>