RegPwn was a Windows 0-day that we were using for LPE in our Red Team for a year (discovered by Filip D. In January 2025). Unfortunately it got fixed 🥲
Good bye RegPwn 🫡
An update to our bug bounty policy: https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html
RegPwn - Windows LPE vulnerability (now fixed) https://www.mdsec.co.uk/2026/03/rip-regpwn/
🏴☠️
"AI is giving attackers a huge advantage!"
"Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."
Kagi's Small Web just got a big upgrade! Introducing browser extensions, mobile apps and categories:
@matildalove "he fed my work into a machine, so I fed him into a machine..."
RE: https://hachyderm.io/@pheonix/116221805295722939
#Meta only exists for two reasons:
- Money
- Info gathering on everyone for reason 1
Wrote down everything I wish I knew earlier about Python supply chain security. Hash pinning, pip-audit, SBOMs, trusted publishing — the whole thing. Enjoy 🐍🔒https://bernat.tech/posts/securing-python-supply-chain/
What we get upset about. Cartoon for Dutch newspaper Trouw: https://www.trouw.nl/cartoons/tjeerd-royaards~bcb45712/
"There are, of course, an infinity of variations to that single routine."
A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/.