Posts
3316
Following
710
Followers
1575
"I'm interested in all kinds of astronomy."
TIL In #Proxmox when you *move* a disk, the original one doesn't get deleted but remains attached to the VM as "unused". Space gets only freed up in the original storage when you remove it from the VM.

#ProTip
0
0
1
It seems Windows can't even launch its terminal properly, this issue is open for >5 years:

https://github.com/microsoft/terminal/issues/4750
0
0
2
@bagder People probably pay less attention than you think (this is a general rule of thumb of mine), they may still assume there is monetary reward even without H1. IMO you should give it some time.
1
0
1
repeated

4 February 1917 | A Polish Jewish dancer Franciszka Mann was born. She was most probably the woman who on 23 October 1943, inside the undressing room of gas chamber II at Auschwitz II-Birkenau, seized SS man Josef Schillinger’s pistol, shot him & wounded SS man Wilhelm Emmerich.
---

A podcast about this and other cases of resistance at Auschwitz: https://www.auschwitz.org/en/education/e-learning/podcast/different-cases-of-organized-resistance-at-auschwitz/

0
4
0
repeated

the guy and his AI found three uses of memcmp() in TLS code and insisted it was a "CRITICAL" side-channel security vulnerability.

A 2-second check of those three uses told us it was not real.

byebye George

1
3
1
repeated

Switching away from Hackerone is not a guarantee... Here we go.

3
4
0
repeated

Learning made me a better programmer.

Not because I write Rust at work. Because Rust forced me to think about things I'd been ignoring and I never realized this fact.

1
3
0
repeated
Edited 20 hours ago

Also came across this today. Wasn't already in the ruleset, so I fixed that.

FreePBX Authenticated Command Injection - testconnection SSH functionality.

https://theyhack.me/CVE-2025-64328-FreePBX-Authenticated-Command-Injection/

0
3
0
[RSS] Micropatches released for Microsoft Excel Remote Code Execution Vulnerability (CVE-2025-62203)

https://blog.0patch.com/2026/02/micropatches-released-for-microsoft.html
0
0
2
repeated

Patch diffing + RCA for clfs.sys can take awhile.

I gave the diff + binary to a local LLM.

It mapped the UAF path, race condition, all IOCTLs in <20 min

LLMs don't replace the work, they are momentum.

New blog post following the UAF trail of CVE-2025-29824:

https://clearbluejar.github.io/posts/how-llms-feed-your-re-habit-following-the-uaf-trail-in-clfs/

2
2
1
repeated

Dirty Ptrace: Exploiting Undocumented Behaviors in Kernel mmap Handlers

Talk by Xingyu Jin and Martijn Bogaard about a new type of logical bugs in kernel driver mmap handlers exploitable via the ptrace functionality.

Authors found multiple Android vendor drivers affected by the issue. They also wrote an exploit for the IMG DXT GPU driver to escalate privileges on Pixel 10.

Video: https://www.youtube.com/watch?v=yAUJFrPjfCI
Slides: https://powerofcommunity.net/2025/slide/x-84592.pdf

0
3
0
repeated

Does anybody know, by any rare chance, what settings might cause CORS errors? Since last week I'm unable to access, for example, a local instance with Firefox due to this problem, as it causes a lot of CORS errors (same origin policy).

I have already tried changing "Enhanced Tracking Protection" settings: they are ignored.

I have also already tried creating a new fresh Firefox profile. It works, but as soon as I synchronise it with my Mozilla account, it fails again.

0
1
0
repeated

Lorenzo Franceschi-Bicchierai

NEW: French Police searched the local X offices as part of a criminal investigation for several crimes, including possession and distribution of child sexual abuse material.

Paris prosecutor's office also announced that it summond Elon Musk and former X CEO Linda Yaccarino for questioning.

https://techcrunch.com/2026/02/03/french-police-search-x-office-in-paris-summons-elon-musk-for-questioning/

0
2
0
I _also_ managed to break my IDE, fantastic!
0
0
0
I am SO GOOD at tweaking my Signal settings when the whole service goes down:

https://status.signal.org/

(or did I bring down Signal?)
1
1
2
repeated

A fun quirk of modern languages is variable names aren’t restricted to ASCII.

Most compilers won’t let you use emojis as identifiers in C++, but we *can* be pretty funny (notice cout).

A legitimate use case is replicating scientific paper notation in code.

1
2
0
repeated

Open Source security in spite of AI - the recording.

https://daniel.haxx.se/blog/2026/02/03/open-source-security-in-spite-of-ai/

1
8
0
Show older