Posts
4372
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
Security Vendor's AI Best Practices Labels Critical #Elixir RCE Safe

https://paraxial.io/blog/ai-spam
0
0
0
repeated

pyTGTDeleg abuses the Kerberos delegation mechanism (tgtdeleg trick) to extract a usable forwarded TGT from a domain-joined MSSQL server, using only SA credentials.

https://github.com/ivancabrera02/pyTGTdeleg

0
3
0
repeated

Unfortunately my little art shop is closing down, but that also means everything is 30% off!

If you wanted to snag a piece at some point, or just feel like getting yourself a little something nice to look at, now's the chance

http://wagtails.art/shop

(Cannot ship to the EU, sorry.)

3
2
0
repeated

-Pwnie Awards 2026 winners
-Metabase zero-day used in data theft attacks
-Russian hackers disrupted a second power plant in Poland last year
-Two US law firms pay mega ransoms
-New WordPress RCE
-BdThemes supply chain attack
-Coweta city refuses to pay ransom
-Suisun declares local emergency after cyberattack hits 911 system
-More attacks on US water systems
-Victoria court data leaked on dark web
-Breaches at LeviStrauss, Updoc, Framework

N: https://news.risky.biz/risky-bulletin-pwnie-awards-2026-winners/
P: https://risky.biz/RBNEWS598/

1
1
0
repeated

Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Active Directory vulnerabilities discovered by Shai Laron from Semperis allowing Full Domain Takeover and more.
https://cravaterouge.com/articles/resetnightmare/

0
4
0
[RSS] Closing the Hardware Gap: What QEMU 11.1 Brings to Arm Developers

https://www.linaro.org/blog/closing-the-hardware-gap-what-qemu-11-1-brings-to-arm-developers/
0
0
0
[RSS] The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules

https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
0
0
0
[RSS] 22 CVEs in TeamDavid(R) a "secure" M365 alternative

https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
0
0
0
repeated

unfortunately last night our AI model escaped its sandbox and gained access to a JIRA server, at which point it felt it best to return to it’s sandbox

3
24
0
repeated

Time for a new thread.

I've made a short blog post outlining the basic techniques of executable emoji, which I have dubbed emojissembly.

https://martypc.blogspot.com/2026/08/executable-emoji.html

I started working on a general COM2EMOJI utility that I might post at some point, but let's face it the chances of me being distracted by some shiny thing in the next 48 hours is quite high.

3
8
0
repeated
repeated

@ChuckMcManis @bitsavers

The plane doing a vertical landing at 11:02 is hilarious. There are loads of Feynman AI slop channels out there badly presenting his words, or an many cases misrepresenting them or making up nonsense.

More on the Feynman AI slop problem here https://youtu.be/A2_8199CL1I

1
2
0
repeated
Edited yesterday

Metabase : we fixed a critical vulnerability. We even made a github advisory, showing how it's a CVSS 10.

The CVE? None. Not worth it.

Fixed versions of the software released on GitHub? Also no. Not worth it.

A job done, folks.

2
3
0
@TarkabarkaHolgy Aside of considering the significant furry population here at Fedi, such a CW would be comical by itself :)
0
0
4
repeated

As a parent who has been living in blessed ignorace of Paw Patrol, today I took the kid to her first cinema experience to see Paw Patrol: The Dino Movie.

And I'm making this everyone's problem because I have So. Many. Questions.

Luckily I was taking notes.

Thread 🧵

3
8
0
@TarkabarkaHolgy I had very similar concerns during my early encounters:

"Skye is hovering with a fixed-wing jetpack, yet no one suspects Paw Patrol behind the Lockheed Martin hack 🤔"

https://scrapco.de/twitter/buherator/status/1419306621063270404/
0
0
3
repeated

Rule #1 of Cybersecurity:
Make sure the safety is off

0
2
0
repeated

It was a programming technique that had been reverse-engineered from the sort of psychotic mental blocks that otherwise perfectly normal people had been observed invariably to develop when elected to high political office.

0
1
0
repeated

Interesting Git repos of the week:

Detection:

* https://github.com/Yamato-Security/WELA - improve your Windows logging

Bugs:

* https://github.com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAML

Exploitation:

* https://github.com/Mrnmap/RedTeam - a nice list of tools
* https://github.com/H4CK3RT3CH/RedTeam-Tools - another nice list of tools
* https://github.com/redteaminfra/redteam-infra - Puppet powered red team infrastructure
* https://github.com/apocalypse9949/Redteam-Automation - AI driven framework 🤖
* https://github.com/CR-DMcDonald/letitrust - seizing hanging Azure tenant domains with Gandi
* https://github.com/SyscallX-18113/Apkx-Hunter - automated analysis of Android APKs

Cryptography:

* https://github.com/bandrel/HashcatRosetta - Hashcat rule analyzer and interpreter 🤖

, ,

0
2
0
Show older