Skip to content
TopicTracker
From xeiaso.netView original
TranslationTranslation

"No way to prevent this" say users of only language where this regularly happens

CVE-2026-45447, a heap use-after-free in OpenSSL's PKCS7_verify(), forced urgent patching. The bug is in C, the language behind most memory safety vulnerabilities. C programmers expressed helplessness, calling such flaws unavoidable.

Related stories

  • A U.S. government ban on Anthropic's AI models has sparked debate, but the article argues the restriction was never truly motivated by concerns over a jailbreak exploit. Instead, the decision reflects broader regulatory and policy tensions around AI safety and control.

  • The article argues that US export controls on Fable 5, a cryptographic tool, are weakening domestic cyber defense by limiting access for American researchers and security professionals while foreign adversaries face no such restrictions. The author claims these regulations hinder innovation and leave US infrastructure more vulnerable.

  • U.S. export controls on cybersecurity tools under the Wassenaar Arrangement hinder American cyber defense by restricting security researchers from sharing vulnerability detection tools internationally, weakening collective security.