Posts
3888
Following
728
Followers
1600
"I'm interested in all kinds of astronomy."
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Norton Secure VPN Installation Insecure Operation On Junction Privilege Escalation Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2276

CVE-2025-58074
1
1
0
repeated

"Marketing agencies are pitching influencers deals such as $5,000 per TikTok video to amplify Build American AI’s messaging about how China’s technological rise should be seen as a threat"

https://www.wired.com/story/super-pac-backed-by-openai-and-palantir-is-paying-tiktok-influencers-to-fear-monger-about-china/

0
4
0
[RSS] Lateral Movement via Cross-Session Activation

https://ipurple.team/2026/05/04/cross-session-activation/
0
0
1
repeated

-DigiCert hacked with a malicious screensaver file
-Ransomware negotiators get four years in prison
-Trellix discloses security breach
-Another Russian hacker arrested vacationing in the wrong place
-Secessionist party leaks Albertans personal data
-Fakestortion campaign hits cPanel sites
-Rockstar stock went up after the hack (leaked financials were spectacular)
-Hacker leak exposes Hungarian-Kremlin propaganda coordination

Podcast: https://risky.biz/RBNEWS559/
Newsletter: https://news.risky.biz/risky-bulletin-digicert-hacked-with-a-malicious-screensaver-file/

3
5
0
repeated
repeated

David Chisnall (*Now with 50% more sarcasm!*)

I saw that there’s now a mobile version of Roller Coaster Tycoon (Roller Coaster Tycoon Touch) and I thought it might be fun (one of the Netflix bundled mobile games). A couple of hours of casual play in, it was clear that the game was carefully designed to make it progressively harder and harder to make progress without in-app purchases.

@EUCommission , if you want to actually make things safer online, how about making that kind of predatory practice illegal? Children are particularly vulnerable, but so are a lot of adults. No need for age verification, just an outright ban.

So sad to see a such a respected game series used for this kind of whale farming.

1
3
0
[RSS] Punk, or why I don't stream anymore

https://geohot.github.io//blog/jekyll/update/2026/05/03/punk-or-why-i-dont-stream.html

"What killed the hacker culture I grew up in was spectacle."
0
0
1
[RSS] A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202

https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202
0
1
0
[RSS] Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold

https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold/

CVE-2026-34621, CVE-2026-34622, CVE-2026-34626
0
0
0
[RSS] Discovering Vulnerabilities in Enterprise Audiovisual Hardware

https://spaceraccoon.dev/discovering-vulnerabilities-enterprise-audiovisual-hardware/
0
2
1
[RSS] libghidra - SDK for automating Ghidra from Python, Rust, and C++

https://github.com/0xeb/libghidra

#Ghidra
0
2
3
[RSS] TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere

https://labs.taszk.io/articles/post/tapocalypse/
1
2
2
@wolf480pl @joshbressers @gregkh I don't think a negative externality has to affect *everyone*. We can argue about who are 1st, 2nd, and 3rd parties in this game, but in the end suboptimal vulnerability management (caused by arguably bullshit CVEs) definitely hurt the security of end users who don't have a say about which vendors their service provider choose (not that there are many orgs out there today who can run without Linux, so this demand is a bit unrealistic too).
0
0
0
@gregkh @joshbressers What you are describing is called a "negative externality".
1
0
1
repeated

News shouldn’t disappear. 🕳️

Some publishers are blocking the Wayback Machine, putting the public record at risk. Journalists are speaking out.

Add your name. Stand for preserving the news.

✍️ https://www.savethearchive.com/NewsLeaders

0
8
0
repeated

Detailed report from DigiCert (thanks!) about "a limited number of code signing certificates, few of which were then used to sign malware".

At the beginning a ZIP file with a .scr executable, and some time later 60 revoked Code Signing certificates. https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

0
4
0
repeated

Hungary's pro-Kremlin media gets hacked by WorldLeaks

The leaked data exposes coordination with the Kremlin in anti-Ukraine coverage: https://telex.hu/zacc/2026/04/30/mediaworks-hekkertamadas-memo-zelenszkij-lejaratas-telefonos-segitseg-moszkvabol

Mediaworks threatens lawsuits over coverage of the hacked data: https://hirtv.origo.hu/ahirtvhirei/2026/05/a-mediaworks-kozlemenye

It sues one of the sites that covered the Kremlin ties: https://media1.hu/2026/05/01/mediaworks-buntetofeljelentes-media1-telex-lapszemle-toth-tamas-antal/

h/t @rqm --> https://mastodon.social/@rqm@exquisite.social/116498047329184815

0
3
0
@tj there should be no API for this at all!
0
0
2
Show older