Posts
4440
Following
738
Followers
1657
"I'm interested in all kinds of astronomy."
repeated

Did you read our latest publication?

Our latest advisory covers a critical vulnerability in UNISOC modem firmware that can provide unrestricted read and write access to physical memory, potentially leading to arbitrary code execution with kernel privileges.

At SSD Secure Disclosure, we’re actively looking for baseband vulnerabilities and exploits, particularly high-impact research that can lead to remote code execution or equivalent impact.
Working on baseband security? Let us get you the highest payout available!

Check out our full product scope at https://ssd-disclosure.com/product-index/

0
1
0
repeated

The Gardener's laboratory.

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/

0
2
0
[RSS] Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust

https://bughunters.google.com/blog/scaling-memory-safety
0
1
1
repeated

The legendary Cliff Stoll gave a delightful talk at DEFCON on Stalking The Wily Hacker (40 Years Later) at DEFCON. It's now online. If you've never seen Cliff, a Klein Bottle, or an overhead projector before, rush over to the youtubes and fix that right now: https://www.youtube.com/watch?v=656058JxTM0

1
12
1
repeated

Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here (password: "expmon"):

https://drive.google.com/file/d/140JTizPrejK28bP3kt-iPdS5bRIy5hLr/view?usp=sharing

As shared previously, the crash still affects the latest Adobe Reader, but probably just a null-pointer-dereference issue.
https://bird.makeup/users/haifeili/statuses/2090513692895154536

0
1
0
repeated

just got laid off this morning. so if anyone knows of a position for an experienced researcher please let me know. 🖤

0
7
0
repeated

flock ceo calls for compromise

you heard em, hackers

0
5
0
repeated

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

0
3
0
repeated
Edited 20 hours ago

Know your paradoxes, or how to protect yourself against sentient machines: https://lcamtuf.coredump.cx/blog/paradoxes/

0
2
0
@foone That's enterprise security 101!
1
0
1
repeated

it's the last week of my summer sale -- get 50% a copy of "building git" using code BGAUG2026 at https://shop.jcoglan.com/building-git/

0
2
0
repeated

LAST WEEK to submit — Tokyo CFP closes soon.

We want real, original work: cutting-edge security research, novel exploit techniques, AI and deep technical investigations that actually move the field forward.

0
1
0
repeated
Edited yesterday

Can somebody give me a definition of metamorphism for something that aren't rocks? Specifically in binary code generation, how do you define metamorphism?

1
1
0
repeated

Uh nice Keycloak critical 🔥 how did i miss that one x3

https://github.com/keycloak/keycloak/issues/51833

0
7
0
I should not have to use an LLM to figure out a menu hierarchy.

I should not use an LLM to figure out how to undo the result of a hotkey.

LLMs (and search engines) should not be excuses for shitty #UI.
1
2
2
repeated

So sparc64 is officially a base-clang architecture now. The first bulk as such is just under 2 hours in.

If you ask "base-clang? What?" - OpenBSD has two types of architectures. Those where cc is the old gcc, and those where cc is clang. After a lot of work by kirill@, sparc64 has switched to using clang by default.

2
2
0
repeated

We are pleased to release tmp.0ut 5 Volume!

Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!!

https://tmpout.sh/5/

1
8
0
repeated
Show older