RE: https://mastodon.social/@campuscodi/117128474535423979
Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic "starve it, then declare it ineffective" tactic. 😠
PSA: if you have a website or a blog, you can use Google Search Console to turn off the use of your site in AI overviews. You get multiple scary warnings if you try. I was curious what's the actual impact on site traffic, so I turned it off. It went from ~1k AI summaries a day to zero, with no measurable impact on visits to the site.
I want a Firefox extension that knows how to replace every single "N months ago" label with the actual exact timestamp (using patterns for how the data is hidden in tooltips, click-to-expand, etc.).
That shit is SO unhelpful. Like if I'm looking back at git history, I don't care that a change was made roughly 3 months ago. I care whether it was made before or after an email I'm looking at that said something relevant to the change.
⚠️ A few hours ago, a malicious crate was discovered on crates.io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted.
For details and how to see if you are impacted, see: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Microsoft killed my exploit 😢
This Friday on @offby1security I'll talk to @steph3nsims about what why, how and if this is the end for this class of exploit techniques
One day I'll sit around the camp fire and be like "You know grandpa Bas used to this stuff by hand before the em-dashes took over" ... Things like https://github.blog/security/vulnerability-research/now-you-c-me-now-you-dont-part-two-exploiting-the-in-between/ were always less about the bugs themselves and more about how to approach attack surfaces and exploit development as an adventure in creative debugging and ultimately just fun puzzling. Of course, that very same kind of iterative text based feedback loop is perfect for the current fancy text completion revolution. It's just a bit of a shame that the landscape seems to be shifting from "that was so much fun to figure out!" towards "oh wow it was able to figure it out".
I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host. https://trustsig.eu/blog/wasm2c-tableflip-unchecked-calloc/
No perfect 10s this time, but that's a lot of AIX vulns from the other day:
Just published “Vulnerability Analysis of CVE 2025 22226 Information Disclosure Due to OOB Read in VMwares HGFS” by Alex Zaviyalov the first vulnerability in an ITW VMWare guest to host escape chain 👇
https://www.nccgroup.com/media/1mzfvyzl/nccgroup_cve-2025-22226.pdf
We have achieved kernel code execution via the IDT under Windows 11 with VBS/HVCI/kCET enabled.
Read the technical write-up here: https://exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11
#Windows11 #KernelExploit #IDT #VBS #HVCI #kCET #DataOnly #RedTeam #ExploitResearch #WindowsSecurity #infosec #pentest