An attacker has remotely executed code through a JSON parsing library in production.
This unpriv-reachable vuln in the upstream 6.6 LTS was finally fixed yesterday after being publicly triggered in syzkaller over 5300 times since March when it was introduced: https://syzkaller.appspot.com/bug?extid=3ad17e94107dda6b6b03 Since we don't ignore syzkaller results, we fixed it the day it was introduced.
https://bird.makeup/users/spendergrsec/statuses/2074499846887674260
🚨 New advisory was just published!
An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
Enterprise Role Play (ERP), sometimes also Enterprise Resource Play: A unique form of fetish role play.
Unlike more popular fantasies such as boss/secretary focused on power relationships in an office environment, in ERP the business processes themselves are central to the scenario.
ERP participants can create elaborate scenarios involving fictional purchasing departments, legal teams, contract negotiations, and more. Large group ERP scenarios sometimes even extend to the point of renting out vacant space in an office park and acquiring demo licenses of SAP or a competing software package to make the fantasy more realistic, or even traveling to a remote ERP group's dungeon to roleplay a merger or acquisition.
As with more conventional roleplays in the S&M context, consent is critical in ERP. If participants are expected to invest significant real-world money in software licenses, make sure this is agreed upon by everyone in advance. The outcome of all merger scenarios should be pre-briefed; attempted hostile takeovers of another dungeon are extremely frowned upon and can result in participants being banned from future events.
EU Fines Google $1 Billion for DMA Competition Violations, Including Making Search Results More Useful
https://daringfireball.net/linked/2026/07/25/eu-fines-google-1b
Occasional reminder to tip your fedi admin if you can and they want it. They put up with a lot of bullshit around here and some foot some hefty bills.
On Infosec dot Exchange, Jerry has links for donations in his profile:
MSRC is starting well with their "piss off the reporter" strategy.
I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability.
I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.
@cR0w @darfplatypus casual Fridays should be pants optional
RE: https://hachyderm.io/@thomasfuchs/116971063252079748
definitely going to use this to train our AI models on your likeness, nope, not at all.
For the love of Baby Carl Sagan, absolutely do not do this in any circumstances, what the fuck
I kinda wasn't expecting a multi trillion dollar industry to build its marketing campaigns on my tiny niche. Makes sense IMO, 0day have always been pretty easy and false positives don't really matter during the audits... and the entire world has been told 0day are impossible