Posts
4530
Following
741
Followers
1655
"I'm interested in all kinds of astronomy."
repeated

RE: https://infosec.exchange/@decoderloop/117248341568750269

Slides for my 2026 talk are now up! A recording will be posted some time after the conference as well, I'll post it when it's up.

0
4
0
@stf well played! Also, took me like 2 minutes to navigate away from this dark pattern orgy of Ali
0
0
1
I want a SMALLER phone.

Thank you for your attention to this matter!
1
0
5
@Viss they got popped again or is this an older story?
1
0
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

Edited yesterday

My latest article for ACM Queue about CHERIoT is live!

This describes the design decisions that we made in designing an aggressively privilege-separated OS with a single address space for embedded systems. It's part of a series of articles about designing single-address-space systems and aims to highlight which parts of CHERIoT are things that are a good idea everywhere and which are a good idea only for embedded systems.

EDIT: Looks as if they mangled the title, it should read 'usable' not 'able'.

EDIT2: And now they have fixed it.

1
5
0
repeated

Project Zero Bot

New Project Zero issue:

PowerVR: PVRSRV_MEMALLOCFLAG_OS_LINUX_PREFER_CMA PMR allocations with a large page size causes page allocator corruption

https://project-zero.issues.chromium.org/issues/512492460

CVE-2026-45200
0
2
2
repeated

Project Zero Bot

New Project Zero issue:

Windows: CrossDevice Dangling COM Registration Incomplete Fix EoP

https://project-zero.issues.chromium.org/issues/538151139

CVE-2026-66804
0
2
0
repeated

Who needs a foldable phone when you can just have a palm pilot

3
6
0
repeated

🍪 Tired of misleading cookie banners? The Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

🥊 Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. Now we need YOUR help to !

👉 To find out how, as well as read the joint open letter, visit the coalition website https://killthecookiebanner.eu

5
11
0
repeated

I’ve made a somewhat complete archive of my publications while at @TalosSecurity . With web archive links and copies where appropriate so it survives CMS changes.
https://blog.29b.net/talos_archives/

1
4
0
repeated

I don’t want a new phone. I want my perfectly good hardware to keep getting updates until it actually stops working. I want replaceable batteries that get recycled. If a company stops giving updates I want to be able to change the OS.

12
22
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequestForMoreProcessing Type Confusion vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2445

CVE-2026-80093,CVE-2026-80093,CVE-2026-80093
0
1
0
repeated

Microsoft Vibe Gaming: an AI to play your games for you

pivot-to-ai.com/2026/09/09/microsoft-vibe-gaming-an-ai-to-play-your-games-for-you

Microsoft isn’t just the company that bought all the game studios so it could run them into the ground — Microsoft Research is hard at work exploring new realms in how to make gaming suck. Welcome to Project Vega! The blog headline is literally: “Vibe…

0
1
0
repeated

Followerpower: there are a bunch of online + offline tools to turn PDFs with only images into searchable PDFs.
Anyone who has tried plenty of them and can give suggestions which one (requirement would be: either online tool or available on linux) gives best results?

1
1
0
repeated

Berlin Senate employee executed a command that a website politely asked him to execute. The page looked like a “verify you are human” check. It instructed to open Windows Terminal/PowerShell, paste a command and press Enter. This is what appears to lead catastrophic results. Attackers hacked the systems and exfiltrated 1.44 million, 5.8 TB. Including personnel records, applications, internal documents, emergency plans and other sensitive material.

6
4
0
repeated
repeated

🚨 New advisory was just published!

A heap buffer overflow in a Windows DCOM service can be leveraged to escalate privileges from a Medium IL standard user to SYSTEM IL, an issue that occurs when attacker-controlled Power Setting data and length are passed to the PSM callback.

This vulnerability earned 3rd place in the Windows LPE category at TyphoonPWN 2026. Read all the details at: https://ssd-disclosure.com/dcom-service-psmserviceexthost-lpe/

0
2
0
repeated

if you have an lg tv

literally throw that shit off your roof

https://www.youtube.com/watch?v=6IFVTcM28KA

3
3
0
repeated

Two hours till my HTTP Terminator talk kicks off at SEC-T! You can catch the livestream at 9:15 UTC:
https://www.youtube.com/watch?v=S6R7cBZDdK4

0
3
0
Made the slop machine do a thing for me that may be useful for others too:

https://github.com/v-p-b/mdsrv

Static webserver that renders #Markdown files and #MermaidJS diagrams for your viewing pleasure. With live updates!

#python #llm
0
2
3
Show older