Happy "Oracle has lost more than 60% of its value since the peak one year ago" to all those who celebrate
DEVCORE CONFERENCE 2027 | CFP is open
#Redteam, #VulnerabilityDiscovery, #Physicalsecurity, firmware and hardware RE, #AI attack surfaces. Bring the research that starts from a hacker's view.
Deadline: Oct 11, 2026, 23:59 GMT+8
https://sessionize.com/devcoreconference2027/
"Because if I know one thing for a fact, it is that I deeply love this island."
The latest and penultimate page of the first chapter of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/
I really recommending reading this.
In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada.
It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this.
Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier.
This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc
Krebs himself, and several other security researchers, have already confirmed they're in the data leak.
tl;dr gah damn dawg this company is going to be sued into oblivion
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Dawg, they got Pete Hegseth in the data breach. It's available for sale for $100
https://bird.makeup/users/vxunderground/statuses/2094961551807545493
We've been thinking about a lot about the language design of expressing lifetime restrictions and dependencies for non-escapable types in Swift, and I put all that into a long and somewhat rambling design paper which folks might find interesting.
New (public) exploit broker
Our friendly periodic reminder that we need your cat-and-music-gear pictures! Please include your cat's name 😻🎹
#CatsOfMastodon
The articles already published in the Exploiting Reversing series (ERS) are now hosted on a new website:
https://blackstormsecurity.com/research/
Future articles will be published primarily at this new address, and for a time, I will also publish them on my personal blog.
The series will continue with many more articles, which some are coming soon. Stay tuned.
Have an excellent day.
Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929