CipherCue measured CDNs for 44,143 tracked European companies and found 89.6% of those using a CDN sit behind Cloudflare (country shares range ~79%–95.6%), highlighting high market concentration and the systemic outage risk when a single front-door provider has incidents. The analysis is based on HTTP/DNS fingerprinting of a cohort skewed to small/mid companies, detects CDNs via response headers (with caveats such as CloudFront/AWS ambiguity), and is not a representative sample of all firms.
The paper generalizes Ken Thompson's trusting‑trust attack beyond compilers by constructing a complete attack that manipulates finished ELF binaries (specifically GNU strip) to implant a payload that propagates across rebuilds. They demonstrate the attack in the NixOS bootstrap: a single tampered strip seeds a payload that survives dependency pruning and backdoors nearly every binary in a built graphical installer, enabling arbitrary malicious behavior across the distribution.
A GitHub repository offering a reconstructed, educational source-code recreation of the Stuxnet worm for static analysis and defensive research; it reproduces original modules, propagation methods, rootkits, and the PLC-targeting payload that manipulated Siemens Step 7/S7 PLCs. The project includes build instructions, analysis guidance, and legal disclaimers emphasizing academic/non-malicious use.
The author warns that LinkedIn posts generated by LLMs are stylistically obvious, reduce authenticity, and drive readers away; LLMs are useful as tools for brainstorming and editing but shouldn’t replace your own voice.