Posts
4525
Following
741
Followers
1657
"I'm interested in all kinds of astronomy."
repeated

@zzt Most feature phones are hard to compromise because every time a malware author learns something about how they work, their brains explode.

0
2
0
repeated
repeated
repeated

CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20079

0
1
0
repeated

CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87491

0
1
0
re: #music #hardcore
Show content
@swapgs You know it's a good show when the openers could be the main act! RIP Riley :(
0
0
1
repeated
re: #music #hardcore
Show content
There is also a guy with a landing net at the other side of the stage "catching" stage divers xD
0
0
0
repeated

Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).

Read the full analysis of the exploit chain and post-exploitation tradecraft here: https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
 

0
2
0
#music #hardcore
Show content
Look like a nice recreational event <3

https://www.youtube.com/watch?v=RyNnleNxDIE
2
0
1
Edited 3 hours ago
Default auto-generated CC on YT music videos is a great way to demonstrate how much Google's AI sucks.

Heat.
Heat.
[Music]
1-2-3
0
0
1
repeated
repeated

I miss the days when a toothbrush botnet was the dumbest headline.

2
6
0
repeated

RE: https://mstdn.social/@jukkan/117240247968300759

I just love this:

”Feature #23 is worth noting in isolation. LinkedIn collects the user’s Do Not Track preference, then excludes it from the fingerprint hash (line 9512, excludes: { doNotTrack: true }). They record that you asked not to be tracked. Then they track you.”

1
3
0
@eduzsh when you do an LLM "fix", "works for me" is good enough and you don't have to consider any of the contribution requirements (like not introducing bugs at places you don't personally use). so I think it's more likely that people will churn out a bunch of fixes that are slightly wrong in different ways. it is true that while some of the fixes will be fine, they'll never make it back to the project anyway.
0
0
0
repeated

military-grade mental illness

0
3
0
repeated
Edited 7 hours ago

Hey, I am an old school vanilla JS person and want to learn what frontend frameworks do people use these days.

Are there any statistics I could look into? Not looking for engineering advice or suggestions what to use.

I hope to get a better understanding of the engineering practices & workflows and security needs to ensure that our security work in web standards can actually land with the users.

Edit: Specifically, I am interested how people modify/insert HTML :)

1
2
0
repeated
repeated

RE: https://infosec.exchange/@perfect10_bot/117240802834832354

EITW perfect 10 that won't get patched. 🥳

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.

1
2
0
Show older