An article exploring 11 techniques to bypass Java's strong encapsulation of JDK internals, including reflection, agents, bytecode manipulation, and FFM. The post frames library developers as attempting to access restricted JDK components despite JVM protections, demonstrating gaps in Java's encapsulation strategy across JDK versions 11–27.
LuaRocks.org suffered a remote code execution vulnerability exploited between July and August 2026, affecting user credentials and API keys. The vulnerability in rockspec loading allowed arbitrary bytecode execution; the site was rebuilt, all credentials revoked, and users are advised to update passwords, API keys, and two-factor authentication. No evidence of package modification was found.