Calif Newsletter
Subscribe
Sign in
Home
Visit Calif
MAD Bugs
Archive
About
Latest
Top
Discussions
WeWorm is calling. It's time to answer.
A practical to-do list for collective cyber defense in the age of AI
Sep 11
9
1
1
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
Sep 8
9
August 2026
OEMpocalypse Now
Part 1 of a series that takes an unprivileged Android app to root on Samsung, Xiaomi, and Oppo/OnePlus/Realme devices, with a single strategy.
Aug 31
5
No Country for Old Passwords
Two pre-auth macOS remote root exploits in four hours
Aug 10
13
3
1
The Taking of FreeBSD One Two Three
Three pre-auth remote kernel exploits behind one TCP port that FreeBSD has decided to document rather than fix.
Aug 6
6
The WordPress Chain Massacre
You can outsource the hacking, but not the understanding
Aug 5
5
July 2026
Apple MIE exploitation challenge
Two months ago, we demonstrated the first public bypass of Apple MIE on macOS 26.4.1.
Jul 27
Â
•
Â
Bruce Dang
6
1
Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)
A pure-logic, 100% reliable path from a normal user to SYSTEM
Jul 22
Â
•
Â
r0keb
10
Journey to Root, Episode I: The Maglev King
Hacking Chrome with AI
Jul 17
Â
•
Â
Duc Phan
,Â
Quang Luong
, andÂ
Tuan
13
4
MAD Bugs: My Cousin Vinyl (CVE-2026-50052)
So the story went like this: Squid was bleeding from a 29-year-old heap overread in her default config.
Jul 1
Â
•
Â
Jun Rong
11
2
June 2026
Squidbleed (CVE-2026-47729)
Heartbleed's ancient cousin, hiding in Squid since 1997.
Jun 18
8
5
1
Apple Internals: Swift in the Kernel
A new series reverse-engineering Apple's internals.
Jun 18
Â
•
Â
Josh Maine
25
3
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts