Posts
4321
Following
738
Followers
1639
"I'm interested in all kinds of astronomy."
repeated

An attacker has remotely executed code through a JSON parsing library in production.

https://fearsoff.org/research/fastjson-1-2-83-rce

1
5
0
repeated

This unpriv-reachable vuln in the upstream 6.6 LTS was finally fixed yesterday after being publicly triggered in syzkaller over 5300 times since March when it was introduced: https://syzkaller.appspot.com/bug?extid=3ad17e94107dda6b6b03 Since we don't ignore syzkaller results, we fixed it the day it was introduced.
https://bird.makeup/users/spendergrsec/statuses/2074499846887674260

1
3
0
repeated

🚨 New advisory was just published!

An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/

0
2
0
repeated

Enterprise Role Play (ERP), sometimes also Enterprise Resource Play: A unique form of fetish role play.

Unlike more popular fantasies such as boss/secretary focused on power relationships in an office environment, in ERP the business processes themselves are central to the scenario.

ERP participants can create elaborate scenarios involving fictional purchasing departments, legal teams, contract negotiations, and more. Large group ERP scenarios sometimes even extend to the point of renting out vacant space in an office park and acquiring demo licenses of SAP or a competing software package to make the fantasy more realistic, or even traveling to a remote ERP group's dungeon to roleplay a merger or acquisition.

As with more conventional roleplays in the S&M context, consent is critical in ERP. If participants are expected to invest significant real-world money in software licenses, make sure this is agreed upon by everyone in advance. The outcome of all merger scenarios should be pre-briefed; attempted hostile takeovers of another dungeon are extremely frowned upon and can result in participants being banned from future events.

3
6
0
repeated

If those slop jockeys could read, they'd be very upset

3
15
0
repeated

EU Fines Google $1 Billion for DMA Competition Violations, Including Making Search Results More Useful
https://daringfireball.net/linked/2026/07/25/eu-fines-google-1b

3
1
0
repeated

Occasional reminder to tip your fedi admin if you can and they want it. They put up with a lot of bullshit around here and some foot some hefty bills.

On Infosec dot Exchange, Jerry has links for donations in his profile:

https://infosec.exchange/deck/@jerry

1
4
0
@wdormann What *is* their job though? Incentives are pervese and blurring risk is in many cases the most cost-effective for everyone. If shits hit the fan, they can blame $country or AI (or both).

Somewhat related: who would've predicted that ClickFix will become an actual ItW vector that needs to be mitigated?!
0
0
1
repeated

MSRC is starting well with their "piss off the reporter" strategy.

I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability.

I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.

1
2
0
#hupol #engineering
Show content
An interesting metric of any political system is the distribution of professions of people in power.

For years it seemed that only unemployed lawyers and career buttlickers can become popular politicians around here.

Now we have a traffic engineer as a minister of transportation who knows the dates to the day when railway sections were closed down and calls engines by their nicknames.

And people love him! This gives me some hope.
0
0
6
Is there a list of ways to cut the very connection you are using to manage a server?

"A friend" would like to contribute...
0
1
2
You find Anna's Archive via a search engine

I find it by randomly typing 2 characters after "annas-archive."

We are not the same. (although you've probably visited way less click farms)
0
0
2
repeated
@schrotthaufen @erraggy @cR0w @darfplatypus you can get kilts for handymen (sturdy material, big pockets, hammer holder, etc.) these days!
2
0
2
repeated

@cR0w @darfplatypus casual Fridays should be pants optional

1
3
0
repeated

RE: https://hachyderm.io/@thomasfuchs/116971063252079748

definitely going to use this to train our AI models on your likeness, nope, not at all.

0
2
0
repeated

For the love of Baby Carl Sagan, absolutely do not do this in any circumstances, what the fuck

5
8
0
repeated

I kinda wasn't expecting a multi trillion dollar industry to build its marketing campaigns on my tiny niche. Makes sense IMO, 0day have always been pretty easy and false positives don't really matter during the audits... and the entire world has been told 0day are impossible

1
1
0
Show older