So, hard pill to swallow, but I think there are a class of AI enthusiasts who got that way because computing fundamentally failed them, for whom getting a computer to do anything _for them_ not being a whole-ass bullshit ordeal still deserve our empathy and solidarity. We, computer-people we, can’t escape responsibility for abandoning user empowerment in favour of corporate consolidation and vending machine interfaces decades ago, now that we’re reaping the whirlwind of mechanized capitalism.
Chamilo LMS was put under the microscope 🔬 by @coiffeur0x90 and Sean Matthews
11 vulnerabilities. multiple attack surfaces. Our new research dives into the vulnerable code paths and exploitation primitives to achieve unauthenticated RCE.
🔗 https://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html
With Mastodon's new Collections feature (i.e. "starter packs"), I made a Cyber Threat Intelligence Collection:
https://infosec.exchange/collections/117120621715888849
Feel free to share with anyone getting started here on Mastodon, if they need some accounts to build out their feed. Note that Mastodon Collections currently have no "Follow All" button: this is by design.
"how would you rate the phone app?" YOU'RE FUCKING INFRASTRUCTURE
this shit is as nonsensical as svchost asking you to rate it
product managers are absolutely cuckoo
Happy "Oracle has lost more than 60% of its value since the peak one year ago" to all those who celebrate
DEVCORE CONFERENCE 2027 | CFP is open
#Redteam, #VulnerabilityDiscovery, #Physicalsecurity, firmware and hardware RE, #AI attack surfaces. Bring the research that starts from a hacker's view.
Deadline: Oct 11, 2026, 23:59 GMT+8
https://sessionize.com/devcoreconference2027/
"Because if I know one thing for a fact, it is that I deeply love this island."
The latest and penultimate page of the first chapter of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/
I really recommending reading this.
In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada.
It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this.
Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier.
This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc
Krebs himself, and several other security researchers, have already confirmed they're in the data leak.
tl;dr gah damn dawg this company is going to be sued into oblivion
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Dawg, they got Pete Hegseth in the data breach. It's available for sale for $100
https://bird.makeup/users/vxunderground/statuses/2094961551807545493
We've been thinking about a lot about the language design of expressing lifetime restrictions and dependencies for non-escapable types in Swift, and I put all that into a long and somewhat rambling design paper which folks might find interesting.