Posts
4048
Following
730
Followers
1615
"I'm interested in all kinds of astronomy."
[RSS] Docker Internal (3)

https://u1f383.github.io/linux/2026/06/04/Docker-Internal-3.html

3rd part of the Docker security research series
0
0
0
[RSS] The futex READ_ONCE

https://guysrd.github.io/futex-read-once

Android kernel race condition analysis
0
0
1
@brk A lot depends on your regular use cases for sure. For me static binaries for all platforms and Vim-like syntax that Just Works(tm) for the simple editing tasks is exactly what I'm looking for.
0
0
0
@techokami I'm not sure that's a TUI/GUI issue: I've been struggling with Linux clipboards since forever. Someone suggested to sync different clipboards using clipnotify that works quite well, maybe it'll be useful for you too:

https://github.com/cdown/clipnotify

(I can share the script I use too if needed)
0
0
0
I complained about hexeditors recently. Now I found TeeHee, and I think I'll stick with it on all platforms:

https://sr.ht/~aleksi/teehee/
3
11
22
@malanalysis
- King Louis XIV. rode out around midday...
- UTC, CET or CEST?!
1
0
1
repeated

@cR0w @christopherkunz
Every PoC on GitHub these days needs to be assumed fake until proven otherwise.

1
4
0
repeated

Electromagnetic Field

Our Call for Participation will close on 7 June - if you have a talk, workshop, or performance you'd like to give at EMF, there's still time to submit!

https://www.emfcamp.org/cfp

0
4
0
repeated

Some perspective:

4
7
0
repeated

An 8TB hard drive that was $129.99 a year ago is now $299.99.

Thanks, AI. You're really making the world a better place.

4
2
0
repeated

@christopherkunz
I also tested another PoC and it was even more fake. i.e. it didn't even create a CLDAP structure that made sense.

I get that PoC||GTFO is a thing, but we've clearly entered a phase where it needs to be Verified PoC||GTFO. πŸ€¦β€β™‚οΈ

1
3
0
repeated

I don't get out much these days but here's a talk I gave at the North American OSS Summit recently: https://www.youtube.com/watch?v=ZquMucBZnaQ

1
5
0
#Redis - Security advisory: [CVE‑2026‑23479] [CVE‑2026‑25243] [CVE-2026-25588] [CVE‑2026‑25589] [CVE-2026-23631]

https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/
0
0
0
repeated

For 19 years, GPS satellites have secretly broadcast a β€œnumbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, β€œghost” substrings repeating years apart, and a β€œTEXT” prefix spreading now. https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer

4
14
0
repeated

πŸš€πŽπŸπŸ-𝐁𝐲-𝐎𝐧𝐞 πŸπŸŽπŸπŸ” CFP looking for the research that will shape the conversations, techniques and tooling of tomorrow's offensive security community.
CFP closes on 1 July 2026, 18:00 SGT.
The next great OFF-BY-ONE talk might be yours!
https://cfp.offbyone.sg

0
2
0
repeated

A friend reported a LPE to Microsoft and in the advisory Microsoft fucked it and wrote a wrong description saying the vuln was in MMC.

Consequence: people wasting hundred of dollars on AI trying to analyze the wrong files just to get a fake PoC because AI brainwashed them πŸ˜‚πŸ˜‚πŸ˜‚

"A working PoC" and the AI released a supposed MotW bypass. The real vuln was a LPE to System.

What a clown circus 🀑

2
6
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

One principle I’d like to be enshrined in law:

If you create incentives that reward a behaviour, you can (and will) be charged as an accessory in any case where someone is doing something illegal as a result of optimising for that behaviour. An affirmative defence would need to demonstrate that you had safeguards in place to effectively disincentivise that behaviour.

For example, if you are running a delivery company and you set targets that mean people are paid more if they drive or park illegally, you are automatically charged as an accessory to however many counts of dangerous driving your drivers are charged with. If you are a city councillor and vote to close all of the public toilets so that there’s nowhere for taxi drivers to relieve themselves, you can be charged as an accessory to a few hundred counts of public urination.

2
2
0
repeated

Part 2 of the custom PE resources series: how to embed any binary as a resource in Visual Studio and extract it at runtime.
https://trainsec.net/library/windows-internals/how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource/

0
1
0
Show older