Posts
4672
Following
742
Followers
1663
"I'm interested in all kinds of astronomy."
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5

https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
0
0
0
[RSS] Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)

http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html
0
0
0
[RSS] Probabilistic analysis of MTE tagging schemes

https://dustri.org/b/probabilistic-analysis-of-mte-tagging-schemes.html
0
0
0
[RSS] From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities

https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/
0
0
0
[RSS] A Mere Mortal's Introduction to JIT Vulnerabilities in JavaScript Engines

https://trustfoundry.net/blog/jit-vulnerabilities-javascript-engines
0
0
0
repeated

Language Matters:

The words we use influence how people think. Shifting language shifts mindsets.

"Vulnerability" sounds like weather: unpredictable, nobody's fault. "Product defect" names something a manufacturer built and could have prevented. Keep it only where it's a term of art, like CVE.

7
8
0
repeated

RE: https://mastodon.social/@monkeydom/117382425456803989

yet more examples of the rollout of passkeys being user hostile in that it does not explain anything to users and does things that may have serious consequences without consent

3
5
0
I recently learned to distinguish rabbits from hares (from a shitpost ofc) and now I feel slightly offended because my emoji keyboard shows a rabbit but it clearly renders as a hare in the app. 🐇
0
1
3
repeated

Newsletter: Regulators race to reassure the crypto industry as the its flagship Clarity Act legislation collapses, SBF tries his luck with the Supreme Court, and crypto PACs unleash $30 million against Sherrod Brown.

https://www.citationneeded.news/issue-110/

2
4
0
repeated
2
8
0
repeated

Aaron Swartz was charged on July 14th, 2011 with wire fraud and computer fraud (under the Computer Fraud and Abuse Act). He potentially faced 30 years in jail and a fine of 1 million dollars or more. The theory was that he exceeded authorized access by automated scraping through 4.8 million JSTOR articles.

Contrast with...

AI crawlers crawl trillions of documents, often ignoring any ToS the prohibit automated scraping.

OpenAI downloaded pirated books from Library Genesis and created internal datasets that became the foundation for GPT-3's training.

Meta torrented 80+ TB of data from Anna's Archive for Llama 4. There are records of internal discussions at Meta that the data set was known to be pirated content.

Where is the federal prosecutor to throw charges at OpenAI and Meta? That's right. No charges.

1
9
0
"This 3-day training focuses on macOS Vulnerability Research (VR) for beginner to intermediate students. While intermediate topics will be discussed, the course focuses on bringing security researchers up to speed with macOS’s unique protections and vulnerabilities"

Great content from my friends, now in Budapest:

https://macosvuln.training
0
1
1
repeated
repeated
repeated

New series: implementation security for autonomous defense systems.

Their intelligence runs on embedded hardware in the field, where an adversary can recover a device and study it with no time limit.

What happens if someone can study it without constraints?
🔗Part 1: https://www.eshard.com/blog/autonomous-systems-are-changing-the-defence-threat-model

0
1
0
repeated

Hashing several values together is easy to get wrong, and the mistakes can lead to forgeries. TupleHash only works with Keccak. Outside SHA-3, people roll their own multihashing, often insecurely.

We built SequenceHash to fix that for any hash function, with length-suffix encoding and protection against length-extension attack. https://blog.trailofbits.com/2026/10/02/sequencehash-multihashing-for-the-rest-of-us/

0
2
0
repeated

In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available.

These are defects (like XSS, SQLi) that keep appearing year after year. Their recurrence is not a technical mystery; it is a business and incentive failure.

The presence of an unforgivable vulnerability signals that customer safety was not treated as a non-negotiable requirement.

3
1
0
repeated

Ryan Castellucci (they/them) 🎃 nonbinary_flag

Our systems detected a minor irregularity in your account, please shitpost to restore full access.

9
9
0
repeated
repeated

We’ve had 22 years of Cybersecurity Awareness Month. People are aware. People know phishing is bad, ransomware exists, and passwords shouldn’t be “password.” Mission Accomplished!

Let's rename it Cybersecurity Readiness Month.

https://semgrep.dev/blog/2026/rename-cybersecurity-awareness-month/

3
4
0
Show older