Dark mode: ON

Infosec Decoded Season 5 #92: Falling Star

With sambowne@infosec.exchange and Doug Spindler

Recorded Fri, Nov 21, 2025

AI

Stack Overflow is remaking itself into an AI data provider
A number of enterprise customers use its API for training. The data contains questions, answers, and a general reliability score, which informs the AI agent how much each answer can be trusted.
Quantum physicists have shrunk and “de-censored” DeepSeek R1
They managed to cut the size of the AI reasoning model by more than half—and claim it can now answer politically sensitive questions once off limits in Chinese AI systems.

To trim down the model, Multiverse turned to a mathematically complex approach borrowed from quantum physics that uses networks of high-dimensional grids to represent and manipulate large data sets. Using these so-called tensor networks shrinks the size of the model significantly and allows a complex AI system to be expressed more efficiently.

Politics

Trump calls Democrats' message to troops seditious behaviour, punishable by death
President Donald Trump accused six Democratic lawmakers of "seditious behaviour, punishable by death", after they released a video urging US service members to refuse unlawful commands.
President Trump wants Seth Meyers fired. The FCC chair amplified the message
Donald Trump Calls for Jimmy Kimmel to Be Pulled Off ABC After Epstein Jokes: ‘Get the Bum Off the Air!’
Donald Trump Explains Why His Voice Sounds Hoarse in Press Conference: Because 'I Blew My Stack'


HOPE Hacking Conference Banned From University Venue Over Apparent ‘Anti-Police Agenda’ P
Tesla safety driver falls asleep during passenger’s robotaxi ride
Trump revives unpopular Ted Cruz plan to punish states that impose AI laws
President Trump is considering an executive order that would require the federal government to file lawsuits against states with AI laws, and prevent states with AI laws from obtaining broadband funding.

The draft order says the Trump administration “will act to ensure that there is a minimally burdensome national standard—not 50 discordant State ones.”

Alice Guo, Chinese national who ran huge scam centre while Philippines mayor, sentenced to life in prison
Guo, who pretended to be Filipina to become mayor, found guilty of human trafficking after raid on compound where more than 700 people were forced to run scams

Infosec

Microsoft to integrate Sysmon directly into Windows 11, Server 2025
Bonkers Bitcoin heist: 5-star hotels, cash-filled envelopes, vanishing funds
They likely stole the seed phrase off his phone with a camera.
3.5B WhatsApp users' info scooped through enumeration flaw P
The messaging platform allows users to look up others' details by inputting their phone numbers. But there's no rate-limiting, so reseaarchers gathered user details at a rate of over 100 million accounts per hour.

"To our surprise, neither our IP address nor our accounts have been blocked by WhatsApp. Moreover, we did not experience any prohibitive rate-limiting."

After more than a year of nagging, Meta has apparently patched this flaw.

Amazon Inspector detects over 150,000 malicious packages linked to token farming campaign P
This is one of the largest package flooding incidents in open source registry history, and represents a defining moment in supply chain security. Through a combination of advanced rule-based detection and AI, the research team uncovered a self-replicating attack pattern where threat actors automatically generate and publish packages to earn cryptocurrency rewards without user awareness, revealing how the campaign has expanded exponentially since its initial identification.
Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time P
microsoft just opensourced zork
Doubling down on resilient infrastructure
Resilient Infrastructure is a Cisco effort to strengthen network security by increasing default protections, removing legacy insecure features, and introducing advanced security capabilities which reduce the attack surface and enable better detection and response. Simply put, we are making it incredibly obvious when our customers are configuring insecure features that introduce new and unnecessary risks into their networks. Initially, customers will receive increased security warnings that recommend discontinuing the use of any insecure features. In subsequent releases, features will be disabled by default or require additional steps to allow for configuration. Eventually, insecure options will be removed entirely.