ckcbnb

vip
Active for: 1.9y
Peak Tier 2
No content yet
So is it all fake?
Claude Fable 5.1 hit a safety filter, and the conversation was automatically switched to Claude Opus 4.8. Start a new conversation to continue with Claude Fable 5.1, or continue this conversation with Claude Opus 4.8.
SonicWall SMA1000: Pre-authentication SSRF × AMC command injection, with the vendor confirming in-the-wild exploitation CVE-2026-83548 (CVSS 10) + CVE-2026-83549 (7.8) WorkPlace can be used as a pivot to break into AMC, allowing attackers to compromise edge appliances without credentials. Affects 6210 / 7210 / 8200v. SSL VPN on SMA100 and firewalls is not included in this scope. Patch: 12.4.x → 12.4.3-03526 12.5.x →
Moonwell ~$8.7M(official residual ~$9.13M) Thin-liquidity MAMO used as collateral, with the spot price used as the oracle. The supply cap only restricts minting; directly transferring into mMAMO bypasses the cap. The exchange rate increased by approximately 3.7×, then the price was applied on top, and cbBTC / WETH / USDC / wstETH were borrowed. Compound v2 accounting + parameter/oracle design, this entire attack path was broken through in one go. Official post-incident (Anthias /
WELL+2.45%
USDC+0.01%
COMP+2.86%
Burp is getting in on MCP too. DAST 2026.8.2 enables MCP by default. Cursor /Claude can directly launch scans and retrieve vulnerabilities #BurpSuite #MCP #AppSec
Unauthenticated RCE in Next.js 15.5 / 16.3 CVE-2026-75604 + AVIF Image Optimization Both are unauthenticated RCEs. One targets AVIF in Image Optimization, and the other targets self-hosted Windows deployments (Pages + App, with Cache Components not enabled). Linux / macOS are not affected by the second vulnerability. Self-check: npm list next; upgrade 15.x to 15.5.24 and 16.x to 16.3.3 Windows
Auth bypass in JFrog Artifactory CVSS 9.8 CVE-2026-82329 With the default configuration, no login is required, and anyone who can reach it over the network can gain administrator access. If the artifact repository is compromised, the entire software supply chain can be poisoned. Self-check: For self-hosted deployments, check your version and upgrade to the corresponding version: 7.111.21 / 7.117.28 / 7.125.20 7.133.29 / 7.146.38 / 7.161.20 JFrog Cloud has been officially fixed. For self-hosted deployments, do not expose the admin interface to the public internet for now.
I just reserved my Cloudflare Wallet tag: Reserve yours now at
SafeMode on is the solution.
RCE in Fastjson 1.2.83
OpenAI today announced a major update in one go! 🚀 The GPT-5.6 series officially released (Sol / Terra / Luna), while also launching the ChatGPT Work agent + desktop app major upgrade: Core update points: GPT-5.6 family (already live on ChatGPT, Codex, API): Sol (flagship): strongest reasoning + long-duration agentic capabilities + new Ultra sub-agent mode + Max
Recently, I've seen many posts about Claude KYC verification and account bans, and it seems the crackdown has been quite strict. My own account has been active since May with a Pro subscription and hasn't been banned yet, nor have I changed any timezone settings. Here's a brief share of my usage method: ✅ I didn't use any native residential IP; I just use a regular VPN node (200 yuan/year), fixed to one or two nodes for global proxy ✅ Claude
Recently got a Hong Kong version iPhone. After using it for a few days, it's actually pretty good.
Great wealth cannot buy the sun from setting; having nothing does not mean we have no tomorrow.
The market remains indifferent, but my heart is calmer than yesterday. — For myself in the dead of night, and for you who are still chasing.
Just realized, is this the safety color of the new era? #claude #portswigger #burp