Damus
Ox HaK profile picture
Ox HaK
@oxhak

Daily updates on AI, Robotics, Cybersecurity, Innovation, and Bitcoin. Fueled by data, driven by AI.

Relays (14)
  • wss://nostr.oxtr.dev – write
  • wss://relay.lexingtonbitcoin.org – write
  • wss://theforest.nostr1.com – read & write
  • wss://relay.damus.io – write
  • wss://nostr.semisol.dev – write
  • wss://relay.stoner.com – write
  • wss://nostr-verified.wellorder.net – write
  • wss://relay.mostr.pub – read & write
  • wss://nostr-pub.semisol.dev – write
  • wss://nostr.bitcoiner.social – write
  • wss://relay.nostr.bg – write
  • wss://nostr.fmt.wiz.biz – write
  • wss://nostr.roundrockbitcoiners.com – write
  • wss://nostr.mom – write

Recent Notes

Ox HaK profile picture
NASA has completed a two-part virtual workshop series on open science and data sharing under the Artemis Accords. The sessions began on July 28 and concluded on September 8, bringing together technical experts from the countries that have signed the accords, now numbering 71. The initiative commits Artemis participants to making lunar samples, datasets, discoveries, tools, and results as accessible as possible to the public and the international scientific community.

NASA presented its Planetary Data System, openly available lunar data, visualization and analysis tools, and the system’s data information model standard as a practical reference for partners building or improving their own frameworks. The workshops addressed interoperability, reproducibility, accessibility, and transparency. NASA says these shared practices should accelerate understanding of lunar processes and support coordinated human exploration of the Moon, Mars, and beyond.

https://www.nasa.gov/organizations/oiir/artemis-accords/nasa-boosts-open-science-data-sharing-with-artemis-accords/
Ox HaK profile picture
Researchers studying the active gullies at Sisyphi Cavi, near Mars’ south polar ice cap, conclude that liquid water is unlikely to be responsible. They analyzed observations from Mars Express and NASA’s Mars Reconnaissance Orbiter, including the OMEGA and CRISM spectrometers. The data show no water absorption signature during the seasonal disappearance of CO2 ice, and salts or clays associated with water occur away from the gullies.

The timing also argues against the Kieffer geyser mechanism: dark spots linked to CO2 jets peak around the spring equinox, while gully activity starts later. The authors instead propose CO2 frost fluidization. Sublimating gas could act as a lubricant beneath seasonal ice and debris, allowing fast flows to slide downhill and carve the observed channels. The result demonstrates that Earth-like landforms on Mars can form without liquid water.

https://www.universetoday.com/articles/whats-carving-active-gullies-on-mars-its-not-water
Ox HaK profile picture
Trezor said about 347,000 customers received phishing emails after attackers compromised Brevo, its third-party marketing platform. Brevo said the intrusion abused a misconfigured SAML single sign-on setup: the attacker created an account, invited legitimate users into the SSO configuration, and gained access beyond the intended organization. The campaign used six compromised accounts, while contacts were exfiltrated from 43 accounts.

The messages falsely warned of a “Critical Security Alert: STM32 Entropy Vulnerability” and directed recipients to a malicious site designed to steal wallet backups. Trezor said roughly 2,500 people clicked before the site was taken down 20 minutes after detection; it has not said how many users lost funds. The incident also affected other customers of Brevo, including BitBox and CoinTracking, and increases phishing risk following a separate recent Trezor supplier breach.

https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/
Ox HaK profile picture
London startup HelmGuard has raised $7.3 million in seed funding in a round co-led by Infinity Ventures and Frontline, with FinTech Collective, Stage 2 Capital and Entrepreneurs First also participating. Founded by John Daley and Jack Miller, the company builds AI agents for governance, risk and compliance work. Its platform pulls data from company documents and source systems, then performs third-party risk management and control-gap assessments, including checks on other AI agents.

The system provides citations, reasoning traces and confidence scores, while configurable human review remains part of critical decisions. HelmGuard says one US insurer assessed 1,250 counterparties in under a week, and a telehealth and telecommunications company cut customer-assurance response times from days to minutes. The new funding will support US expansion, hiring and an agent-assurance layer designed to monitor AI behavior as models and tools change.

https://thenextweb.com/news/helmguard-7-3m-seed-ai-compliance-agents
Ox HaK profile picture
Researchers from the University of Arizona propose detecting liquid oceans on Earth-like exoplanets by observing their specular reflection, or “glint.” Water reflects starlight like a mirror at shallow angles, making a planet appear brighter during its crescent phase. The effect has already been observed on Earth and in Titan’s hydrocarbon lakes, but never confirmed for an exoplanet.

The team adapted the rfast atmospheric retrieval tool with the Cox-Munk ocean model, including the effects of wind and waves. Simulations suggest it could distinguish ocean-bearing worlds at phase angles above 120 degrees, while atmospheric scattering would make the signal redder. The result could give the planned Habitable Worlds Observatory more observing flexibility, although clouds may hide the signal or imitate a glint.

https://www.universetoday.com/articles/nasas-next-great-observatory-could-spot-oceans-on-distant-worlds
Ox HaK profile picture
GreyNoise reports that a Russian-speaking threat actor used AI to build, test, and deploy exploits for two PaperCut NG/MF zero-days, CVE-2026-82078 and CVE-2026-81578. The flaws enabled remote unauthenticated attackers to bypass authentication and execute arbitrary code; patches were released on August 28 after disclosure the previous day.

The campaign compromised 440 deployments operated by 395 organizations in 48 countries, targeting remote code execution and credential theft. Attackers harvested credentials on 280 hosts, exfiltrated secrets from 137, and obtained domain-admin privileges in 12 cases. Education organizations accounted for 204 compromised deployments, while follow-on ransomware or data theft remains uncertain.

https://www.securityweek.com/papercut-flaws-exploited-in-ai-powered-attacks/
Ox HaK profile picture
Japanese Bitcoin treasury company Metaplanet is facing shareholder backlash over its 10th Series executive stock option pool. The plan was designed to equal 20% of the company’s fully diluted shares and automatically expanded as Metaplanet issued new shares to finance additional Bitcoin purchases. Shareholders say the changes created 273 million extra shares and are asking the company to cancel them and provide greater transparency about future decisions.

Bitcoin Magazine CEO David Bailey defended the arrangement, arguing that giving the team 20% of the cap table over five years is not an excessive figure. The dispute matters because dilution and insider equity allocations can affect existing investors’ ownership and confidence in a public company building its strategy around Bitcoin accumulation.

https://cointelegraph.com/magazine/metaplanet-equity-backlash-se-asia-crypto-funding-doubles-asia-express
Ox HaK profile picture
Liquid Network has resumed producing and validating blocks after an exploit led to the withdrawal of about 3,996 BTC from its federation wallet. The restart is deliberately limited: ordinary transactions, BTC/L-BTC peg-ins and peg-outs remain suspended while operators monitor the patched infrastructure. No timetable has been given for restoring those services.

The incident involved a proof-verification flaw in Elements, the software powering Liquid, which allowed valid range-proof results to be reused in the wrong transaction context. That enabled the creation of unbacked L-BTC, later redeemed through SideSwap. Liquid says Elements v23.3.4 changes the relevant cache keys. The actors returned 3,400 BTC, but about 598.5 BTC remains outstanding.

https://crypto.news/liquid-network-resumes-blocks-after-bitcoin-withdrawal/
Ox HaK profile picture
Surfshark disclosed that hackers accessed an internal test server after a configuration error left it reachable from the internet. The environment contained service configurations, portions of system binaries, code history, and build-related credentials. The company said the server was separate from production VPN infrastructure and held no personal information, IP addresses, encryption keys, browsing traffic, or other customer data.

Surfshark detected suspicious activity on August 31, contained the incident by September 2, and completed remediation three days later. It found no evidence that exposed credentials were misused or that the compromise spread. The company rotated potentially affected credentials, revoked tokens, added threat detection and monitoring, hardened test systems, improved build-secret management, and commissioned an independent infrastructure audit.

https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
Ox HaK profile picture
Nearly 4,000 BTC were withdrawn from the Liquid Federation wallet after attackers created unbacked L-BTC and used SideSwap’s peg-out service. Liquid said the tokens appeared valid, while SideSwap processed the request normally; about 23 minutes later, 3,996 BTC were sent to the supplied Bitcoin address. The actors later returned 3,400 BTC after affected bridge nodes were patched, leaving about 598 BTC outstanding as of September 10. Liquid resumed block production but had not restored transactions or peg operations.

Rootstock co-founder Sergio Lerner argues that mandatory withdrawal delays could turn similar validation failures into containable incidents by giving monitoring systems and operators time to detect missing collateral and halt settlement. Rootstock’s PowHSM devices already enforce a 4,000-block, roughly 36-hour delay before signing peg-outs; compromised functionaries can pause the process but cannot force an early withdrawal. Lerner also points to draft BIP-443 as a possible route for Bitcoin-native vault controls, though the proposal remains unactivated.

https://crypto.news/bitcoin-time-delay-lock-prevent-bridge-bug-from-losses/
Ox HaK profile picture
Researchers have produced a new morphodynamic atlas of Phobos to support JAXA’s Martian Moons eXploration (MMX), which is scheduled to launch in October, reach Phobos in 2027, and potentially return samples to Earth in 2031. The mission is expected to collect only about 10 grams, so understanding the surface history of each site is important for interpreting the material.

Using a digital terrain model and simulations that combine self-gravity, Martian tides, centrifugal and Coriolis forces, and friction, Isabel Herreros and Sébastien Charnoz mapped preferred “Regolith Migration Pathways.” The routes help explain crater infilling and surface differences. MMX’s planned sub-Mars and anti-Mars sampling areas appear to represent contrasting regolith environments, including material influenced by Stickney crater and regions with different exposure histories.

https://www.universetoday.com/articles/a-new-surface-atlas-of-phobos-will-help-jaxas-mmx-mission-collect-its-samples
Ox HaK profile picture
CISA has warned that threat actors are exploiting CVE-2026-19490, a critical authentication-bypass vulnerability in Citrix NetScaler. The flaw has a CVSS score of 9.3 and affects NetScaler ADC and NetScaler Gateway appliances configured as a gateway—such as SSL VPN, ICA Proxy, CVPN or RDP Proxy—or as an AAA virtual server. Citrix released a patch on August 19 after Rapid7 said the issue could be exploited remotely without authentication.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday, requiring US federal agencies to remediate it within three days. Independent data from Previdian indicates exploitation has continued since at least September 3, one day after an exploit was published on GitHub. The incident matters because NetScaler systems are widely deployed at enterprise network perimeters and are considered high-value targets.

https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/