New Pwndbg release!
We now disassemble code backwards in context and nearpc, display indirect jumps, nearpc -f works without debug syms, added stack-vis command to visualize stack frames, improved v2p, p2w and pageinfo kernel debugging commands & more!
See https://github.com/pwndbg/pwndbg/releases/tag/2026.09.15
Please sponsor us: https://github.com/sponsors/pwndbg !
#pwndbg #gdb #lldb #reverseengineering #security #lowlevel #exploitation #pwning
Are "HACK THE PLANET" t-shirts responsible for multi-modal prompt injection into the agents at world leading AI labs?
Lasers. Microscopes. $250K. One secured chip.
Ledger Donjon just showed how they cracked debug access on RP2350-A4, a break worthy of Raspberry Pi's own Hacking Challenge.
Respin or no respin? Raspberry Pi says no. Read why: https://www.raspberrypi.com/news/everything-is-better-with-lasers/
I love a cartoon that sums up a line of argument I have often made as a political economist, so here's a great example from the (recently deceased) P.C.Vey - whose work appeared in the New Yorker & elsewhere.
#economics #regulation #politics
h/t Loren Fox/LinkedIn
Windows Defender Update DoS Vulnerability https://github.com/MSNightmare/BigDiskBuster
My son is reading Lord of the Rings for the first time and he just stuck his head out the door:
"Who the fuck is Tom Bombadil??"
At a high level, this was the full exploit chain.
1. HEIC/HEIF upload
2. ImageMagick decoding
3. Heap overflow on libheif
4. RCE on https://community.openai.com
5. Critical OpenAI SSO flaw
6. ChatGPT/Codex takeover
7. Connected GitHub access
8. Internal repo PR
This meme has so much telling about the current status of AI racing as well as how everyone seems to have forgotten the basic IT security.
https://bird.makeup/users/0xtib3rius/statuses/2101147121063751903
LMAO, can we just issue one giant CVE for the entire Linux kernel
PoC for CUPS LPE on Linux https://github.com/v12-security/pocs/tree/main/cups/cups2root
@buherator i remember reading during the second iraq war, operations led by the british had far fewer friendly fire casualties because they had not just a system for putting a case for a target together, but also researchers trying to rule out the validity of a target (that's a friendly, that's a school, etc)
the americans didn't have that
...then they automated it
and i guess, *now* the stakes are high enough to give them a target offramp, huh
Sweden is also choosing @forgejo for their digitally sovereign government codeplatform, just like the Dutch code.overheid.nl 🥳🥳
https://github.com/diggsweden/ena-kodsamverkansplattform-poc
This is a nice step towards less dependence on US big tech, aka Github.
In my last days at the @BZKopensource I hope to set up a working group with other EU governments, to work towards a federated network of codeplatforms 🇪🇺
#codeplatform #forgejo #ospo #digitalsovereignty #opensource #foss #govtech
Buyers of pervert glasses join the war on pervert glasses: https://www.latimes.com/business/story/2026-09-18/meta-glasses-captured-shared-intimate-images-without-users-consent-lawsuit-claims