Posts
3543
Following
722
Followers
1584
"I'm interested in all kinds of astronomy."
repeated

🚨 New advisory was just published!

A critical vulnerability in UNISOC modem firmware allows one User Equipment (UE) to remotely attack another over the cellular network. By sending specially crafted malformed SDP within SIP signaling messages, an attacker can trigger memory corruption in the target modem, potentially leading to remote execution of arbitrary native code on the victim device: https://ssd-disclosure.com/unisoc-t612-rce/

0
2
0
@Sandfish6811 I can't dive deeper into this rn, but the linked GHSA confirms the essence of the vulnerability and the way it was introduced.

I checked and you are right that the hash is not sent back during auth, I'll probably leave a comment about this on /r/ so they can clarify.
1
0
0
repeated

CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

0
2
0
[RSS] Breaking Pingora: HTTP Request Smuggling & Cache Poisoning in Cloudflare's Reverse Proxy

https://xclow3n.github.io/post/6
0
1
1
[RSS] How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit

https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass
1
1
0
repeated

The exact moment software went downhill was when changed away from this.

0
4
0
repeated
repeated

Lorenzo Franceschi-Bicchierai

NEW: A former DOGE employee allegedly stole Americans' personal data from two large databases at the Social Security Administration, according to a new report.

The former employee allegedly put the databases on a thumb drive and wanted to use them at their new contractor job.

https://techcrunch.com/2026/03/10/doge-employee-stole-social-security-data-and-put-it-on-a-thumb-drive-report-says/

1
3
0
repeated
repeated

We are following this story very closely and send our best wishes for recovery to Jello, multi-year HOPE speaker & keynote. https://www.kqed.org/arts/13987466/punk-legend-jello-biafra-hospitalized-after-stroke

0
2
0
repeated
Edited 15 hours ago

If I were to recommend one cryptography book for implementors in 2026, would it be:

(Edit, would love your comments as to why.)

20% Cryptography Engineering
60% Serious Cryptography
10% Real World Cryptography
10% something else (see comments)
0
2
0
repeated

In re: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

I see people in here being smug about an OPSEC failure, and other people pointing out that "we only respond to local law enforcement requests" is a much bigger set than you might think, but it's all focused on what the individual can do to protect their privacy and anonymity against nosy state actors.

Most of the solutions proposed are either very insecure (mailing cash) or sufficiently technically complex to be out of the skill set of the average computer user.

1
1
0
repeated
repeated

I just got back home from @REverseConf . I had an amazing time, and I want to thank the organisers and all the people I met! The talks went great, and I was honoured to be part of the process of choosing and refining them. If you are thinking about where to submit next year, I highly recommend this event, in beautiful Orlando!

2
3
0
repeated

@aesthr sometimes I use makefiles as a way to create parallel shell scripts with proper tracking of exit codes.

0
1
1
repeated

New bugfix release: 2.7.12. More information and full changelog at https://keepassxc.org/blog/2026-03-10-2.7.12-released/

2
2
0
repeated

The Shape of Paris, a balletic short film of skateboarder Andy Anderson zooming, grinding, spinning, and floating around Paris in the summertime. "This is the cleanest footage I've ever seen. The cinematography and color grading is insane." https://kottke.org/26/03/the-shape-of-paris

0
2
0
repeated

Let's play slop or not! Here's the input:

https://hackerone.com/reports/3595753

95% slop
4% not slop
0
2
0
repeated

RE: https://chaos.social/@bitsoffreedom/116204497093736465

🥳 Court victory against Meta 🎉

Today, a Dutch judge ruled in favour of EDRi member @bitsoffreedom of Freedom in the appeal vs. Meta.

Facebook and Instagram users will be free to choose how information appears in their feed - and not be forced into algorithmic timelines - will remain intact.

But the fight isn’t over as Meta is still ignoring these rules in other European countries.

💪 We will keep pushing to make sure the law is respected everywhere.

More details ➡️ https://www.bitsoffreedom.nl/2026/03/10/court-again-rules-in-favor-of-bits-of-freedom-freedom-of-choice-for-instagram-and-facebook-users-remains-intact/

0
8
0
Show older