Posts
2866
Following
689
Followers
1510
"I'm interested in all kinds of astronomy."
"You should be able to talk to your PC"[1]

^ This is a fundamental misunderstanding that reminds me (again) of one of my favorite failed experiments of '90s internet: the online 3D shopping center.[2]

C-levels of the time spared no expense to build a complete VRML model of a shoping center in the browser, where you could walk around, take the escalator for a better view on the virtual fountain or even rent a virtual space for your goods.

What the inventors didn't understand is that of course people don't go to the mall to use the escalator, but to buy stuff.

Online banking, shopping, etc. became popular even over phone-based services because people realized that clicking on stuff is more effective than talking (and walking).

Chatbots are the 3D escalators of todays technology.

[1] https://www.theverge.com/report/822443/microsoft-windows-copilot-vision-ai-assistant-pc-voice-controls-impressions
[2] https://web.archive.org/web/20070610120220/https://index.hu/tech/net/plaza0607/
0
0
2
repeated
a new "modern" run dialog is being implemented and what the fuck is this
1
6
1
repeated
repeated

Since I started to analyze -2025-55182 (, ) at work today, I decided to publish my analysis findings so far, given all the fuzz about the vulnerability: https://github.com/msanft/CVE-2025-55182

Feel free to contribute to the search for a proper RCE sink!

1
5
0
I completely missed that @kaitai v0.11 was finally released with serialization support:

https://kaitai.io/news/2025/09/07/kaitai-struct-v0.11-released.html

This is huge and it's great to see that @nlnet money goes to the right places!
1
1
3
repeated

The ChatGPT outage the other day made me wonder if we will see DDoS crews hold AI services for ransom. Many of them have deep pockets and being down a day or two would hurt.

4
5
0
repeated

Lorenzo Franceschi-Bicchierai

NEW: Staffers at notorious spyware maker Intellexa had live remote access to their customers' surveillance systems.

This allowed them to see the personal data of targets hacked with Intellexa's spyware Predator, according to new research based on a leaked training video.

Needless to say, this is bad for several reasons.

http://techcrunch.com/2025/12/04/sanctioned-spyware-maker-intellexa-had-direct-access-to-government-espionage-victims-researchers-say/

1
6
0
repeated

Project Zero Bot

New Project Zero issue:

Samsung: QuramDng TrimBounds Opcode leads to out-of-bounds reads

https://project-zero.issues.chromium.org/issues/443793212

CVE-2025-21074
0
1
0
repeated

Project Zero Bot

New Project Zero issue:

Samsung: QuramDng invalid LossyJpeg component assumption, leading to out-of-bounds write

https://project-zero.issues.chromium.org/issues/444346510

CVE-2025-21075
0
1
0
repeated
Edited 7 hours ago

Workforce shortage: a developer changed career to mine stone for Great Leader after infecting his own machine for testing, turning your operation into an online version of the imperialist video game Uplink.

https://www.hudsonrock.com/northkorean

0
2
0
This PoC looks convincing enough (I didn't test though!):

https://github.com/msanft/CVE-2025-55182

CVE-2025-55182
0
0
0
repeated
repeated
repeated
@synnfynn nah, no SELinux, and with a brilliant move I now just log to the console :)
0
0
1
I'm writing this network thing and there are always problems that you only recognize during implementation - this is why it's so enlightening to implement stuff.

What I didn't expect is getting stuck because I can't write to a damn log file as root...
1
0
2
repeated

AI Warning: Google has been caught A/B testing replacing real article headlines with AI-generated substitutes, which are of course sometimes wildly misleading/against journalistic ethics. If you see a blatantly horrible headline in a news aggregator, check whether the site's own page matches before blaming the site! https://www.pcgamer.com/software/ai/googles-toying-with-nonsense-ai-made-headlines-on-articles-like-ours-in-the-discover-feed-so-please-dont-blame-me-for-clickbait-like-bg3-players-exploit-children/

7
23
1
Show older