Posts
4358
Following
737
Followers
1648
"I'm interested in all kinds of astronomy."
repeated

IFIN - The Independent Federated Intelligence Network

Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples.

https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698

1
5
0
repeated

anyone experienced with high-speed (~150m) cabling and possibly also somewhere half-way injecting solar-based PoE? is this a thing?

3
2
0
[RSS] LLMs won't break symmetric crypto

https://www.bfswa.blog/p/llms-wont-break-symmetric-crypto
0
2
0
Anthropic choosing an asshole as the logo for Claude is the most honest marketing move in recent history.
0
0
2
repeated

Osma A ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡บ๐Ÿ‡ฆ

Somehow, we have ended up in a universe where companies brag about deploying multibillion dollar software systems with an objective to break decades old IT security legislation, and nobody holds their executives to account.
https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/

0
3
0
repeated

: three critical in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch!
๐Ÿ‘‡
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

0
3
0
repeated

For the nerds in the back:

Not understanding how your program works is not an excuse for it doing the bad shit it was literally programmed to do.

6
8
0
@codinghorror CEOs often work for minimal wage for tax reasons around here. But even that case is much better than simply asking your billionaire friends to push literal peanuts your way along with a job contract 2 years before you run for office.
2
0
2
repeated
Edited 11 hours ago

Wiz found a master key that could access every database in Azure's Cosmos DB.

Whoops.

https://nitter.net/yuvalavra/status/2082864672294736324

My present to all of you: Go ahead and think a bit about why such a key even exists. Go ahead...

1
9
0
repeated

bert hubert ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ

AI: Considerations for people who make decisions. There is enormous pressure to deploy AI, and if you believe the LinkedIn thought leadership, you'd think that if you don't get on board NOW you'll be lost forever. Meanwhile other people severely detest AI, so much so that it damages their (worthwhile) arguments against it. Below, thoughts on what to do now, and what things might best be postponed. Finally, some stimulating words on what we actually DO at the office: https://berthub.eu/articles/posts/ai-for-decision-makers/

4
3
0
repeated

This wonderful wallpaper and the Issue cover were created by Vasyl/Joker^NAH^TRSI. Both this and other wallpapers, as well as Issue which just came out, can be downloaded from Paged Out!'s website!

0
1
0
Edited 6 hours ago
This feels like kindergarteners making up stories about who fell bigger with their scooters during summer break :P

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
0
0
5
repeated

Reproduced the LPE in 1h 56m on Linux 6.12.96 LTS.

Also managed to get root on Pixel 10 with the latest 2026-07-05 security update.

It was originally submitted by another researcher to Google KernelCTF as exp527 and should qualify for a $101,337 bounty.
https://bird.makeup/users/spendergrsec/statuses/2082627090310938838

0
2
0
repeated

Fun engineering challenge if anyone has ideas:

The DisplayPort auxiliary channel appears to reuse opcodes for request and completion packets, and uses generally the same framing. This means that, to a first order, if you have a single packet, or a capture that starts in the middle of a long burst of transactions and don't know if you are at an even or odd packet boundary, it is not trivially possible to unambiguously decode the traffic.

Is there a heuristic that you can apply to the first few packets in a capture to determine which one is a request vs a completion and correctly phase the capture?

1
1
0
repeated
Edited 20 hours ago

Slop-coded SPARC64 exploit for Solaris kernel vuln that recently been fixed in Illumos by Dan McDonald:
https://www.illumos.org/issues/18118
https://github.com/illumos/illumos-gate/commit/08292a06bdfa570d21571965b7bd0f053b3aaaa5
No KASLR, no kernel heap NX -- ain't difficult target, heh. I don't have an access to latest 11.4 SRU to check if it was fixed by Oracle on current version, but on 11.3 SRU 36 it still there

0
3
0
repeated

I dunno how many people remember a few months ago when OpenAI made media headlines everywhere for launching Atlas, their AI agent browser... which was going to revolutionise how we use technology and rival Google.

Anyway, neither do OpenAI as they abandoned it and deleted the downloads.

1
8
0
repeated

Natasha mastodon๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡ช

Well played local book store, well played...

0
22
0
repeated

New Pwndbg release!

Added exithandlers cmd, kernel debug improvements + new cmds, support for glibc 2.43 heap dumping, track-heap --where, richer procinfo output (e.g. see those chromium/firefox pipe pairs!) & MORE!

See more at https://github.com/pwndbg/pwndbg/releases/tag/2026.07.29 !

Sponsor us: https://github.com/sponsors/pwndbg !

0
4
0
[RSS] KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)

https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
0
1
2
Show older