Enjoy
https://github.com/scadastrangelove/rust-in-peace/
A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more.
https://github.com/scadastrangelove/awesome-ai-security-tools
We're running ёprstcon — a community one-day conference
in Moscow on May 26. Open call for anyone whose talk fits
the room — online or offline.
It's all over Reddit, in every Telegram channel. "I built it over the weekend." "It found a 0-day." "It writes better code than me." Screenshots, demos, euphoria, panic.
Back in the late 80s, when we were pushing ASCII characters across endless green terminals in assembly and FOCAL, nobody thought this would turn into a trillion-dollar industry. We just wanted the machine to obey us, not the other way around.
Now it obeys itself. And we're not the ones making the rules anymore. The rules are making us.
Let's unpack this.
The core claim: SDLC is not a cycle. It is a spiral. Each iteration returns to the same phase — design, implementation, verification — but the system changed, the tools changed, and the threat model should have changed with them. Most do not.
https://github.com/scadastrangelove/asamm
What is inside:
President Bramp of the United States stepped before the cameras at 03:17 Washington time.
https://medium.com/p/7016de25ab3e
A black-box scanner sends its prayers into the dark.
Blackhole answers with pages, headers, flows, lies, half-truths, and—when needed—the unpleasant courtesy of ground truth.
Observability is about visibility.
Visibility works both ways. If you can see it, someone else can too.
This post is the polite version of a talk I gave. The impolite version is the repo.
It’s just a friendly UDP oracle telling strangers what your routers are, how old they are, and whether they like to take naps when prodded. Totally fine.
CVE-2025-20352 lives in Cisco IOS/IOS XE’s SNMP stack. Crafted packets + creds = sad router. While everyone argues about advisory footnotes, we do the boring part: find what talks SNMP with default communities and tag what looks at risk.
Nuk‑Nuke
https://github.com/scadastrangelove/nuknuke
A lightning‑fast decoy web‑server that fools vulnerability scanners by feeding them the answers they expect. Inspired by the 90‑s WinNuke prank and written for ProjectDiscovery’s Nuclei, Nuk‑Nuke parses every template under ~/nuclei‑templates, spins up a single‑py server and replies in a way that always triggers a positive match. Ideal for red‑blue exercises, honeynets or throttling noisy pentest pipelines without touching your production code.
More details can be found in recent AISec talks and releases.
The boom of AI brought to the market a set of impressive solutions both on the hardware and software side. On the other hand, massive implementation of AI in various areas brings about problems, and security is one of the greatest concerns.
Кибербезопасность микропроцессорных систем управления на железнодорожном транспорте
Гордейчик Сергей Владимирович
Nice to see Nordex devices featured in SCADA StrangeLove "Too Smart Grid in da Cloud" talk back to 2014 available via SatCOM in 2020.