Posts
4659
Following
742
Followers
1661
"I'm interested in all kinds of astronomy."
repeated

New kill chain just dropped

5
12
0
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5

https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
0
0
0
[RSS] Sender spoofing in Proton Mail via display-name homograph

https://alonsovidales.github.io/protonmail-sender-spoofing/
0
0
1
OpenAI delaying its model launch (and IPO) due to security concerns reminds me of 8yo me delaying the launch of my nerve gas rocket (made of paper and stuff I found in the kitchen, probably inspired by The Rock with Nicholas Cage) for similar reasons.

Later we agreed in mutual disarmament with my toy soldiers.
0
0
2
repeated
Edited 18 hours ago

I made a thing: it's called the DNS Museum, and it's because I kept joking at the start of my talk, "Bizarre and Unusual Uses of DNS" that a lot of the things weren't alive anymore - so it was more like a museum of DNS and I was the curator. Anyway, I'm on holiday right now so I finally got around to doing something about that joke.

Consider this a first draft, I have way more notes about other things to add at some point. It's also a little bland, but one thing I'm not is a designer. Let me know about any issues - AI was used to help create the site, but of course I'm responsible for any mistakes. It's on GitHub too, so PRs are welcome.

https://dns.museum

8
10
0
repeated

Some brief thoughts on AI in hacking and optimizing for speed:
https://mahaloz.re/2026/09/28/hack-race.html

A bit is also a response to Flare-On 13.

0
1
0
repeated

RE//verse 2027 is on the way, and you should probably be there! If you know, you know. If you don’t, this is a very good year to fix that. https://re-verse.io/

0
1
0
repeated
repeated

Daphne Preston-Kendal

We trust you have received the usual lecture from the local System Administrator.

pagliacci.jpg

0
6
1
It's that time of the year again...
0
1
4
repeated

For my birthday, my brother-in-law gave me a 4992-digit hex number that, when used as a seed for Python’s random number generator, makes it so that printing a sequence of “random” ASCII characters actually prints a birthday greeting.

I find it rather amazing that this is possible!

This is the program he sent with the seed:

with open("seed.txt", encoding="ascii") as handle:
seed = int(handle.read().strip(), 0)
r = random.Random(seed)
pending = ""
while True:
character = chr(r.randrange(128))
if pending + character == "\x1e\x1f":
break
print(pending, end="")
pending = character
print()

2
10
0
repeated

CVE-2026-88771 - the loaded Citrix footgun went off again, and the screaming noise is back in our ear.

You knew it was coming - enjoy the latest watchTowr Labs blogpost.

https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/

1
10
0
repeated

I know this is going to sound crazy, but what I’d most like in a printer is one where, when I tell it to print something, it prints.

7
6
0
repeated

My second problem with computers and IT is that nearly nobody understands software anymore and I feel so-called AI will make this much worse.

0
2
0
[RSS] Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass

https://github.com/google/security-research/security/advisories/GHSA-wcfm-jp7m-rffh
0
0
1
[RSS] Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE

https://starlabs.sg/blog/2026/09-dirty-cert-cisco-smart-software-managers-silently-patched-rce/
0
0
3
[RSS] CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018

https://daubois.dev/blog/cve-2026-91766-php-http-redirect-credential-leak/
0
0
0
Show older