Posts
4298
Following
738
Followers
1636
"I'm interested in all kinds of astronomy."
@freddy I can 100% believe their model did *something*, but first and foremost the official report tells me that their frontiers models are so great they outright steer away from the original problem statement ("write an exploit") and burn a shit ton of tokens on something entirely different ("find an exploit on the Internet"). Second, OAI either didn't have the means to monitor what's going on or didn't care to intervene.
0
0
0
This OpenAI vs. HF story stinks to high heavens, I tell you this much...
1
0
3
repeated

TrendAI Zero Day Initiative

Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at https://www.zerodayinitiative.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories

1
3
0
@root42 I think that's a UI issue with the frontend, the linked quote post shows up as a reply to the original with highlight, but the in-page anchor isn't triggered...

This is the gist:

"Turns out this was an unintentional trick question, because two games mixed up in my memory (30 years is a long time):

- I mainly remembered Ecstatica (thanks @BryanGreyson and your friend!)
- ...but giant worms (which weren't even green?) definitely came from Magic Carpet (thanks @g !)"
1
0
2
You guys are AWESOME! Thanks for all the help, I really didn't expect this much effort from the community!

Turns out this was an unintentional trick question, because two games mixed up in my memory (30 years is a long time):

- I mainly remembered Ecstatica (thanks @BryanGreyson and your friend!)
- ...but giant worms (which weren't even green?) definitely came from Magic Carpet (thanks @g !)

Now I'm off to figure out what little me was supposed to do in front of our first color CRT :)

#retrogaming

RE: https://infosec.place/objects/370500d6-2960-412c-b30c-d2cc19e59c67
0
1
6
Edited 1 hour ago
Let's see if Fedi is smarter than LLMs:

When we got our first PC a friend installed a bunch of games (Win95).

One of these was a 3D adventure game (maybe 3rd person view?). It was a miracle it ran on that HW and was very low poly. I didn't know English at the time so I have no clue what the game was about.

I remember that could walk around in a village and NPCs occasionally talked to you. Then giant green worms appeared and that's when I usually died :D or the game just went on because the worms weren't very targeted/hostile?

I'd appreciate any guesses on this! I'm not a huge gamer but want to know what that game was about.

EDIT, SOLVED: https://infosec.place/objects/fd8ecdde-e47d-4304-a749-b80b9db81c56

#retrogaming
27
93
33
repeated

Celebrate 10 years of Binary Ninja! For the first time ever, we’re offering a 35% discount! Join us for 10 full days of giveaways including licenses, merch, and more. Huge shoutout to everyone who has been with us since the beginning, and here’s to everything still to come. Join in on the celebration: https://binary.ninja/10years

1
4
0
[RSS] Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)

https://blog.calif.io/p/dark-elevator-windows-install-service
0
1
1
[RSS] GitHub - NtProtectVirtualMemory/PE-Library: A modern C++ library for parsing and manipulating Windows Portable Executable (PE) files.

https://github.com/NtProtectVirtualMemory/PE-Library
0
0
1
@asciimoo @jimothy Also mental health support: no battery -> no doomscrolling, tiktok, etc.! I think you could get an EU grant for this...
0
0
1
repeated
Edited 16 hours ago

For decades there's been a conflict between governments wanting to get access to people's private data and people trying to keep them out.

Over the years I've gradually come to the conclusion that the stable "Goldilocks zone", where there's the least likelihood of a major swing that makes things worse for everyone, is *not* the privacy utopia where devices are invulnerable, or a police state where anyone with a badge who asks can root through all your data, or a fictional engineered cryptographic backdoor that''s somehow only exploitable by "the good guys".

Instead, it's the state where devices (especially phones) are breakable, but only through attack vectors that require physical access, have a high per-device cost, and are not 100% reliable. Things like "solder to an internal layer trace on the logic board to glitch it" or "FIB a per-device key out of the SoC then bruteforce the password".

I'm not saying we should be adding deliberate backdoors - quite the opposite, since these are very likely to make entry *too* easy.

But if devices become completely invulnerable, I expect we will see something like chat control turned up to 11 where the pressure to find some way in becomes unbearable and we end up with CALEA-style entry points that turn devices into total spyware with no privacy at all.

So IMO the ideal balance is where there is no viable remote attack vector, trivial drive-by USB etc attacks a la Cellebrite are blocked, but if a government has a phone off a body and are willing to spend $100K+ of lab time to have a >50% chance of breaking into *that one device*, destroying it in the process, without it easily scaling to the next, there's a good chance they can do so.

And this level of difficulty is juuust easy enough that they aren't spending the same money lobbying politicians to make it easy to break into every device belonging to an opposition party or something. They still try of course, they always want more, but they can't claim to congress that the guy who shot senator X will never be caught because they couldn't break the phone they found at the scene.

You know your device was confiscated (or are dead and not around to complain), it's not viable to do to everyone crossing a border or who was in a certain geofenced area, etc. There's no practical way to scale physical attacks to mass surveillance.

5
3
0
repeated

My computer just did a blue screen of death and, uh, this is new.

I wasn't watching discovery channel or anything on the computer I have no idea where that's from lol.

1
4
0
@cR0w Read the latest Qualys thing, that's pretty good :)
1
0
1
repeated

The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days

0
3
1
repeated
Edited 17 hours ago

Good news, web developers: you no longer need fancy animations and 8k video backgrounds just to drain your users’ batteries.

Battery Drainer cuts out the middleman. No visuals, no crypto mining, no useful work required. Just pure depletion.

https://github.com/asciimoo/battery-drainer

2
2
0
repeated

This Critical Patch Update contains 1449 new security patches across the product families

https://www.oracle.com/security-alerts/cpujul2026.html

11
7
0
repeated

RE: https://cosocial.ca/@mhoye/116960268208721583

For the uninitiated, Firefox went back to X.

0
4
0
repeated

RE: https://infosec.exchange/@patrickcmiller/116963915911110345

Computers don't "act on their own." That's a statement by someone who either doesn't understand how their shit works, is trying to deny responsibility, or likely in this case, both.

8
4
0
repeated

send this to your favorite security researcher

2
7
0
Show older