<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Gray haired gray hat. Co-founder Veracode. Former L0pht security researcher. Builds tools to find and fix vulnerabilities in code at scale.</description><link>https://bsky.app/profile/weld.bsky.social</link><title>@weld.bsky.social - Chris Wysopal</title><item><link>https://bsky.app/profile/weld.bsky.social/post/3mlqwox6eg22w</link><pubDate>13 May 2026 18:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mlqwox6eg22w</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3micbmamihk2q</link><description>Phrack call for papers is out! Check out the cool demoscene graphics at phrack.org</description><pubDate>30 Mar 2026 18:19 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3micbmamihk2q</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mhvgagjdbs2d</link><description>I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube.&#xA;&#xA;No fluff, no hype—just real-world AI security from people actually doing the work.&#xA;&#xA;https://www.youtube.com/playlist?list=PLjmt1tu85IhAiVPugOjP-7Cy0Oemi3m7z</description><pubDate>25 Mar 2026 15:37 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mhvgagjdbs2d</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mhavmtdt7c2v</link><description>RCE vulnerability in the Yamaha PSR-E433 synthesizer, discovered by Anna Antonenko, allows exploitation through crafted MIDI files that trigger a hidden firmware backdoor with hardcoded password &#34;#0000&#34;. https://it4sec.substack.com/p/remote-code-execution-rce-in-yamaha</description><pubDate>17 Mar 2026 11:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mhavmtdt7c2v</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mgurh4qtdk2c</link><description>Doesn&#39;t everyone watch Akira on LaserDisc with their figurines?</description><pubDate>12 Mar 2026 16:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mgurh4qtdk2c</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mfugtims6k2r</link><description>🕯️There will be a online memorial for Par 🕯️&#xA;&#xA;Jason Snitker &#34;Parmaster&#34; Memorial Service&#xA;Feb 28, 2026 04:00 PM &#xA;&#xA;Confirmed Speakers:&#xA;&#xA;Par&#39;s Aunt&#xA;Deb Wysopal&#xA;Mudge&#xA;John Lee&#xA;Tom Sloan (former Secret Service)&#xA;&#xA;Registration Link: https://us02web.zoom.us/meeting/register/hYD6OW0URGaIUG5qA18zXw&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>27 Feb 2026 19:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mfugtims6k2r</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mfb643y7gc23</link><description>My wife @debdebdeb.bsky.social and I are heartbroken to share the sad news that our old friend @jasonsnitker.bsky.social AKA Parmaster, has passed away.</description><pubDate>20 Feb 2026 03:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mfb643y7gc23</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mfaf4sr66k2f</link><description>New $10k FULU bug bounty for Ring video doorbells just announced.&#xA;&#xA;https://bounties.fulu.org/bounties/ring-video-doorbells</description><pubDate>19 Feb 2026 20:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mfaf4sr66k2f</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3me72uayeu22h</link><description>This is a new one for me. I&#39;m #8 and #31 on this top 100 list. Do you want Chris the the CTO of Veracode or Chris the security pioneer. 😂&#xA;https://www.futuristsspeakers.com/top-100-cybersecurity-thought-leaders-list/</description><pubDate>06 Feb 2026 13:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3me72uayeu22h</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mdw63jxpyc2g</link><description>Can we all forget about the email disclaimers now?&#xA;&#xA;The information contained in this communication is&#xA;confidential, may be attorney-client privileged, may&#xA;constitute inside information, and is intended only for&#xA;the use of the addressee. It is the property of&#xA;JEE</description><pubDate>03 Feb 2026 01:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mdw63jxpyc2g</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mdoan7e5ck2g</link><description>In order to collect a bug bounty, a researcher was required to sign an NDA to not discuss the vulnerability.&#xA;https://zuernerd.github.io/blog/2026/01/29/molekule-re.html</description><pubDate>30 Jan 2026 21:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mdoan7e5ck2g</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mdizyyjatk2x</link><description>Vulnerability disclosure norms are a control system for incentives. They made vulnerability handling predictable enough to industrialize.&#xA;&#xA;We get more finding, more fixing, and more secure software.</description><pubDate>28 Jan 2026 19:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mdizyyjatk2x</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mdgz44qdec2b</link><description>This looks interesting. Teenage hackers. I was one. I didn’t do this type of thing though.&#xA;&#xA;www.amazon.com/dp/133500193X&#xA;https://www.amazon.com/dp/133500193X</description><pubDate>28 Jan 2026 00:24 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mdgz44qdec2b</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3md47og7ul22h</link><description>ATM jackpotting is still very much alive in 2025.&#xA;&#xA;Two attackers physically opened ATMs, connected a laptop, installed malware, and forced the machines to dump all their cash. DOJ convictions, prison time, restitution, deportation.</description><pubDate>23 Jan 2026 17:23 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3md47og7ul22h</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcxjlqqhxc2o</link><description>This FDA announcement says over 700 people were harmed and 7 people died due to a bug in the Abbot FreeStyle Libre device.&#xA;https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-glucose-monitor-sensor-issue-abbott-diabetes-care</description><pubDate>21 Jan 2026 20:37 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcxjlqqhxc2o</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcx3drnmks2o</link><description>Massachusetts lawmakers introduced bipartisan bills (HD 5563 / SD 3606) to curb abandoned consumer electronics by requiring vendors to disclose software support lifetimes, warn users before end-of-life, and explain lost features and security risks.</description><pubDate>21 Jan 2026 16:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcx3drnmks2o</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcwq22afvs2c</link><description>New from Anthropic. &#xA;&#xA;https://red.anthropic.com/2026/cyber-toolkits-update/</description><pubDate>21 Jan 2026 12:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcwq22afvs2c</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcukmii3ts2o</link><description>Microsoft released NTLMv2 in 1998, no doubt because tools like L0phtCrack were able crack NTLMv1 passwords with the measly computing power then.&#xA;&#xA;NTLMv1 is still in use today! &#xA;&#xA;Mandiant has now released rainbow tables for NTLMv1 that can crack any pw in 12hrs on a $600 computer.</description><pubDate>20 Jan 2026 16:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcukmii3ts2o</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcuied6pzk2o</link><description>UK NCSC: pro-Russian hacktivists are still hammering critical infra &amp; local gov w/DDoS attacks. Low-tech, high impact, disrupting services &amp; costing serious recovery time/money. Shouldn&#39;t critical infra &amp; local gov be able to mitigate these attacks? What do they use? Cloudflare? Akamai? ISPs?</description><pubDate>20 Jan 2026 15:37 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcuied6pzk2o</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mcpo5ddyvc27</link><description>Tell your older relatives to turn personalized ads off everywhere. Scammers target this demographic.</description><pubDate>18 Jan 2026 17:37 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mcpo5ddyvc27</guid></item><item><link>https://bsky.app/profile/weld.bsky.social/post/3mci2tygdkk2d</link><description>“Prompt injection” is the wrong mental model.&#xA;&#xA;LLM attacks increasingly look like malware campaigns, not single exploits. This paper frames them as promptware and maps a 5-stage kill chain: initial access → priv esc → persistence → lateral movement → actions on objective.&#xA;https://arxiv.org/html/2601.09625v1</description><pubDate>15 Jan 2026 17:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:zzxobol7ogdohqi2ce7dir4a/app.bsky.feed.post/3mci2tygdkk2d</guid></item></channel></rss>