Posts
2763
Following
681
Followers
1504
"I'm interested in all kinds of astronomy."
repeated
New assessment for topic: CVE-2025-58034

Topic description: "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands. ..."

"Based on writing the [Rapid7 Analysis](https://attackerkb.com/topics/zClpINmLCh/cve-2025-58034/rapid7-analysis), I have rated the exploitability as `Very High`, as exploitation is trivial and reliable ..."

Link: https://attackerkb.com/assessments/c67a510c-5ac5-43a7-affd-7b7655c4b62f
0
1
1
@rebane2001 that booster thing is plain witchcraft.
0
0
0
repeated
repeated
repeated

Postmortem of the Xubuntu.org download site compromise

https://lwn.net/Articles/1047056/

0
3
0
repeated

Sent from San Francisco, California, U.S.A. on December 20, 1995. https://postcardware.net/?id=12-38

0
1
0
repeated
repeated
Edited 9 hours ago

Cloudflare published a very good article explaining how yesterday's outage happened.

https://blog.cloudflare.com/18-november-2025-outage/

I encourage everyone to read it.

I also think people are focusing on that particular unwrap() too much, and not enough on a bigger picture: lack of fallbacks

Without fallbacks at the interfaces between different subsystems, there's nothing to stop an error in one place from cascading throughout the whole infra

Config parsing is not the only place where such fallback was missing

2
3
0
repeated

First fake ticket spotted in the wild. If you see any offers on platforms like Kleinanzeigen or eBay showing a ticket it is a scam - tickets are not issued and no one knows how they will look like. Flag those offers please.

3
15
1
Edited 11 hours ago
Another humble #UX request:

I know dates look ugly, but "last month" is a pretty wide timeframe and when my brain sees "3 weeks ago" it will recall yesterdays dinner and the 1994 World Cup finals with equal probability.

Please display exact dates on frontends!
1
3
3
TIL cURL only supports the lowercase http_proxy environment variable:

https://curl.se/mail/archive-2001-12/0034.html
0
0
0
[RSS] HEX ADVENT 2025: Crack the Advent, Conquer the Threat

https://starlabs.sg/blog/2025/11-hex-advent-2025/
0
0
0
[RSS] "Astral-tokio-tar" / "uv" Arbitrary Write Path Traversal Vulnerability

https://github.com/google/security-research/security/advisories/GHSA-9p78-p5g6-gcj8

This is CVE-2025-59825
0
1
1
[RSS] dz6: vim-like hex editor

https://crates.io/crates/dz6
1
2
1
Since yesterdays #AdTech link was received quite positively, I'm sharing again this collection from The Correspondent:

Debunking the science of advertising
https://thecorrespondent.com/collection/the-nonsense-of-online-advertising

The Correspondent was an incredible publication, and as such, turned out to be unsustainable :(
0
1
1
repeated
repeated

I have a friend who prefers to stay anonymous who gives this amazing talk in non US (but allied) countries about how long their internet will -really- function if they lose all comms with American data centers and it’s… phew. It’s a thing. Some resilient ones will last a few weeks before certificates expire. But CF is a wrench.

11
15
0
repeated

I want to try switching to Linux.

However, I cannot find a working remote desktop system that allows me to take over the same session that I was using locally so that I can switch back and forth between being at the computer and being remote without having to log out. Blanking/Locking the local screen while I'm connected remotely is also a need.

Basically I need it to work as close to Microsoft's RDP as possible. If anyone can help me with this, you'll convert me to a Linux user.

11
8
0
repeated

Here’s a free scanner for that FortiWeb CVE-2025-64446 I made for you. https://github.com/sensepost/CVE-2025-64446

0
6
0
@mariyadelano @rmd1023 @brouhaha @hacks4pancakes this is a great article, pointing out that if someone charges you by their performance while they are also responsible for measuring their own performance, there is a slight chance of fraud
https://thecorrespondent.com/125/the-non-sense-of-online-advertising-when-the-numbers-dont-add-up
0
3
5
Show older