Posts
4068
Following
730
Followers
1617
"I'm interested in all kinds of astronomy."
repeated

Started to roll my eyes and say "Here, let me Google that for you" and then remembered that Googling it unlikely to yield a correct answer anymore.

4
3
0
[RSS] Measuring LLMs' Impact on N-day Exploits

https://red.anthropic.com/2026/n-days/
0
0
0
repeated

Lorenzo Franceschi-Bicchierai

NEW: WhatsApp said it caught and disrupted a new hacking campaign by NSO Group against its users.

The Meta-owned messaging giant said this phishing campaign violates a court decision that ordered NSO to stop targeting WhatsApp and its users. WhatsApp is seeking to hold NSO in contempt of court because of this violation.    

https://techcrunch.com/2026/06/08/whatsapp-says-it-caught-new-spyware-attacks-linked-to-nso-group-in-violation-of-court-order/

0
2
0
repeated
repeated

Stuck on a problem..... Would really appreciate some help. Over the last four days I have had many coffees and even more headaches from WinRE on a hobby project (long weekend). Basically what I've tried to do is map the state machine for TPM and WinRE. To anyone interested I can provide a 42 page walkthrough of my methodology, thoughts, roadblocks, and current issue. the bootmgrfw lives in physical memory from what I could tell from my RE, so it was easy enough to extract the static start address from the .efi file, but WinRE lives in virtual memory. Long story short, I was able to find that start point after timing the break in a GDB stub (QEMU) when the TianoCore logo was running and then scrape through looking for the public symbol file for winload.efi and then eventually through some searching of memory find the location of the entry after calculating the base taking into account the RVA I had taken from Ghidra previously since at that point I knew it was loaded in memory. I was using that for 6 hours + and after shutting off for the night, I realised when I logged on the next day that it was no longer resolving the function, I have attached before and after. As far as I can tell ASLR is not enabled here. Does anyone know what could have caused that? I can't work it out for the life of me. You can tell its rubbish from the (bad) instruction.

0
3
0
repeated

Agents need better tools for reversing! I'm releasing declib (previously libbs), with a new CLI today that gives agents CLI access to 4 decompilers (IDA, Ghidra, Binja, angr), parity feature support to most MCP (12 features), and the ability to sync those changes across decs!
https://asciinema.org/a/J6jHm77G4a5L0TVZ

1
4
0
repeated

c'mon, Taylor…can we have just one?

2
5
0
repeated

🚨 New advisory by @kruxinator & Christian Hager: Local privilege escalation in @genetec 's deployment (#CVE-2026-25112)
Writable dir + missing binary + SeImpersonatePrivilege = SYSTEM via Rotten Potato 🥔
Patch available. Apply now!
🔗 https://r.sec-consult.com/genetec

0
2
0
repeated
repeated

Shawn Hooper (he/him) 🇨🇦

Happy 31st Birthday to the programming language.

https://en.wikipedia.org/wiki/PHP

0
4
0
repeated

Open Source Security mailing list

X.⁠Org Security Advisory: June 2, 2026 https://www.openwall.com/lists/oss-security/2026/06/02/1
8 issues in X server and Xwayland, all with ZDI-CAN identifiers, one also already has a CVE

0
4
0
@stragu @zbrown It also has a chance that it will be covered in concrete in the very near future, maybe ask the birds first if they are comfy with that.
0
0
0
repeated

Here’s an easter egg in the new Lego Batman that I think all of yourwill REALLY appreciate.

It’s so good, I had to make a video.

5
26
0
#LinkedIn is so full of AdTech that I need to use a dedicated browser to open any post there (otherwise I get stuck at the cookie consent window that I can't close...).

Please don't use LinkedIn as your primary publishing platform, esp. for technical content!
0
3
9
repeated

Greg Linares (Laughing Mantis)

Been telling people about these kinds of hybrid threats and interactions between threat actors and victims for years, and these examples are not reflecting true nation-state efforts or capabilities.

Cyber threats aren't limiting themselves to computers so why are we?
https://bird.makeup/users/jamieantisocial/statuses/2062922881869271522

0
1
0
repeated
Show older