Posts
4386
Following
737
Followers
1650
"I'm interested in all kinds of astronomy."
repeated

Mark Wyner Won’t Comply vm

Discovered while doing ethnographic research for a public library district. I was touring one of their branches when this caught my attention.

It’s genius. Smartest solution I’ve seen for this common problem.

Librarians could save the world if we’d let them. 😉

1
2
0
repeated

PEOPLE/ARNOLD1.GIF

0
1
0
Any recommendations for books on #DistributedComputing?

I'm primariy looking for a best-practices kind of thing to recognize potential problems early and avoid reinventing wheels.

#Bookstodon #FediBooks
0
3
0
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
0
0
2
repeated
repeated

New video: Compiled V8 JavaScript for reversers 🎥

➡️ V8 compilation pipeline
➡️ bytecode caching
➡️ how bytenode abuses caching for protection

https://www.youtube.com/watch?v=YSSCMSMcpeM

0
3
0
repeated

Richard Scarry already summarized everything there is to know about cyber security, about 50 years ago.

0
14
1
repeated

RE: https://fosstodon.org/@frehi/117077677106911268

paging all nerds who run their own mailserveres

1
4
0
repeated

Rogue vSphere server that captures credentials from Veeam Backup & Replication https://github.com/mattmillen15/VeeamThief

1
2
0
repeated
repeated

CVE-2025-7771 — ThrottleStop.sys Arbitrary Physical Memory R/W https://github.com/enessakircolak/CVE-2025-7771

0
2
0
repeated

ETW for Security Research: Providers, Sessions, and Detection Engineering https://idov31.github.io/posts/inside-etw-with-etwsuite

0
2
0
repeated

What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (Mozilla’s infrastructure is producing lots of builds).

https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/

1
2
0
[RSS] Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux

https://cravaterouge.com/articles/resetnightmare/
0
1
1
@dey The cybersecurity awareness you spread to me starts to itch. It also hurts to pee.

@briankrebs
0
1
3
repeated

The fastest way to get VIP treatment when you land...seriously, how dumb do you have to be to try something like this? This person on Reddit stole my thoughts verbatim: "committing federal crimes from inside a sealed metal tube that lands exactly where the feds are waiting is certainly a strategy."

https://www.reddit.com/r/delta/comments/1vl52vr/dl591_lasatl_arrival_met_by_federal_agents/

24
23
0
repeated
@david_chisnall Yeah, "architecting" is not the best word here...
0
0
1
Edited 23 hours ago
I thought I'm making up a conspiracy theory around NVIDIA deliberately looking for bubbles to inflate - AI turned out to be a great one - after the crypto bubble bursted. It seems @david_chisnall agrees (sort of):

RE: https://infosec.exchange/@david_chisnall/117075838205635406
1
4
3
repeated

Finally, to close out our short tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

0
3
0
Show older