Posts
4376
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
The soundtrack of my dream was a Sabaton song about debugging Binary Ninja:

"Debug the Ninja
Binary Ninja
Debug the Ninja
This is the song"

(note: I don't usually listen to Sabaton)
0
0
0
repeated
@phillip Hot take: signups should be disabled at install time by default in almost every software.
0
3
4
repeated

RE: https://social.lol/@phillip/117061432689860232

The postmortem of the hack on my Forgejo instance is here! I had fun investigating and writing it, so I hope y’all enjoy reading about it :)

https://phunky.cafe/my-homelab-got-hacked/

2
6
0
repeated

this program was generated with LLVM assistance
"don't you mean LLM assistance?"
no, i mean i implemented a few examples and left the rest as UB for the compiler to figure out https://gcc.godbolt.org/z/hd5Mhdhev

1
8
0
repeated
Edited 10 hours ago

Somebody posted a Windows 11 LPE writeup, with a CVE that doesn't yet exist (CVE-2026-62737).

By poking at kloader's ExecutionContext, we can get kernel mode execution at an arbitrary address.

A stock Windows VM won't have a NIC that uses the NetAdapterCx framework, so will not show as affected. But you can start that service to see it in action.

The PoC has a hard-coded 0xFFFFF80041414141 as an execution target. I'm sure that somebody knowledgeable with Windows kernel stuff can figure out how to modify this to do something useful.

I predict that CVE-2026-62737 will be included in this Patch Tuesday lineup.

0
3
0
repeated

Since Metabase couldn't be bothered, it looks like CISA has assigned CVEs.

0
2
0
repeated
repeated

On Saturday night, one of our CT logs rejected most submissions for 30 minutes.

I just published the post-mortem, and the investigation was... a lot of fun? It involves Go mutex starvation, SQLite WAL behavior, and ZFS record sizes.

I got to SIGKILL a VM 200 times, implement a turnstile (TIL!), and order a Nokia flip phone.

https://groups.google.com/a/chromium.org/d/msgid/ct-policy/b1b5e8a2-b010-4e2a-b8c8-91c1d1b7ca91%40app.fastmail.com

0
1
0
repeated

Beatboxing is one of countless very good example why AI will never be able to replace actual art.
Most (if not all) sounds a beatboxer makes can technically be made by a synthesizer. The arrangement can be the same too.
Yet millions and millions of people enjoy beatboxing a lot more, specifically BECAUSE it comes from humans.

I think this principle can be applied to most forms of art.

So I don't think there's too much need to worry.

0
1
0
repeated
Just accidentally spilled some cold water on my tshirt and decided it's actually better this way.
0
0
0
@scottwilson I'm carefully optimistic about markup getting more traction through tools like Obsidian. You'd write content with desired emphasis, then the recipient will get a rendering that fits their theme/other requirements (e.g. high contrast).
0
0
2
repeated

r2ghidra 6.2.0 is out, and this time the changelog is massive! the decompiler output has been heavily improved in sync with all the new type analysis information we have in r2-6.2.0 (yeah next release will reduce backward compatibility with r2 apis)

https://github.com/radareorg/r2ghidra/releases/tag/6.2.0

1
2
0
Security Vendor's AI Best Practices Labels Critical #Elixir RCE Safe

https://paraxial.io/blog/ai-spam
0
0
0
repeated

pyTGTDeleg abuses the Kerberos delegation mechanism (tgtdeleg trick) to extract a usable forwarded TGT from a domain-joined MSSQL server, using only SA credentials.

https://github.com/ivancabrera02/pyTGTdeleg

0
3
0
repeated

Unfortunately my little art shop is closing down, but that also means everything is 30% off!

If you wanted to snag a piece at some point, or just feel like getting yourself a little something nice to look at, now's the chance

http://wagtails.art/shop

(Cannot ship to the EU, sorry.)

3
6
0
repeated

-Pwnie Awards 2026 winners
-Metabase zero-day used in data theft attacks
-Russian hackers disrupted a second power plant in Poland last year
-Two US law firms pay mega ransoms
-New WordPress RCE
-BdThemes supply chain attack
-Coweta city refuses to pay ransom
-Suisun declares local emergency after cyberattack hits 911 system
-More attacks on US water systems
-Victoria court data leaked on dark web
-Breaches at LeviStrauss, Updoc, Framework

N: https://news.risky.biz/risky-bulletin-pwnie-awards-2026-winners/
P: https://risky.biz/RBNEWS598/

2
4
0
repeated

Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Active Directory vulnerabilities discovered by Shai Laron from Semperis allowing Full Domain Takeover and more.
https://cravaterouge.com/articles/resetnightmare/

0
4
0
[RSS] Closing the Hardware Gap: What QEMU 11.1 Brings to Arm Developers

https://www.linaro.org/blog/closing-the-hardware-gap-what-qemu-11-1-brings-to-arm-developers/
0
0
0
Show older