Posts
4322
Following
738
Followers
1639
"I'm interested in all kinds of astronomy."
[RSS] From Virtual Share to Physical Shell: Leveraging Windows' Inconsistent Access Control for LPE

https://blog.exodusintel.com/2026/07/27/from-virtual-share-to-physical-shell-leveraging-windows-inconsistent-access-control-for-lpe/
0
0
0
repeated

New issue - #9 - of the free @PagedOut zine is here!
90 pages of pure technical awesomeness!
Please help spread the news ❤️

Web: https://pagedout.institute/webview.php?issue=9&page=1
PDF: https://pagedout.institute/download/PagedOut_009.pdf
Wallpaper: https://pagedout.institute/download/PagedOut_009_wallpaper.png
Patreon: https://www.patreon.com/cw/PagedOut

Enjoy!

0
5
0
repeated

How is the Bun rewrite in Rust going? https://lockwood.dev/ai/2026/07/27/how-is-the-bun-rewrite-in-rust-going.html

It seems like if the initial token costs are to believed, the cost is approaching $1m USD, but it's likely, as the article says, that there were a lot of non-reported costs being spent from Anthropic helping the project along and continuous CI/CD.

2
5
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

I see LLMs as a continuation of the Silicon Valley obsession with 'problem solving' and their specific definition.

Back when I was an undergrad, the refrain we heard from big tech recruiters was 'we're not interested in specific skills, we want to hire problems solvers'. This always struck me as odd: everyone in my year could solve problems, it wasn't a rare skill, the difficult thing was identifying the correct problems to solve.

Digging a bit deeper, it turns out that they didn't even want people capable for solving generic problems, they wanted people who had learned a load of problem-solution pairs and would do closest-fit matching. People who would look at a problem and say 'ah, this looks like this well-known problem, the solution is therefore a variation of this well-known solution'. Not people who would create novel solutions but people who could pattern match and apply off-the-shelf solutions with small tweaks.

They wrote books about how to hire people with that skill, all without being explicit that this is what they were looking for.

And now they have machines that can do this: ingest a load of problem-solution pairs and match problems to some space of problems and infer a solution from the nearby solutions.

It's not surprising that they believe this is the same as novelty, because they've spent three decades incentivising their employees to avoid true novelty.

3
6
0
repeated

The @EUCommission has just published guidance documents clarifying how the Cyber Resilience Act affects (among other things) . This is the result of the extensive engagement of many open source community members.

https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation

0
2
0
repeated

About time for me to remind everyone that:

a) there was a TV series version of The Net in 1998

and

b) Tim goddamn Curry played the voice of a mysterious hacker called Sorcerer in it

3
4
0
repeated

Remember, kids:

In proper scientific terms, an attempt to explain observable phenomena is called a "hypothesis".

It is called a "theory" when it fits all the observable facts, and there is no observable evidence to the contrary. We don't call it a "truth" because there's always a chance that it might be overturned by later evidence - but as far as science is concerned, a "theory" is as hard as it gets.

This is often confusing to people who dismiss science they don't like as "it's just a theory". But this distinction should be kept in mind when discussing things like the "Theory of Evolution", "Theory of Relativity", "Global Warming Theory", and "Dead Internet Theory".

4
9
0
repeated

An attacker has remotely executed code through a JSON parsing library in production.

https://fearsoff.org/research/fastjson-1-2-83-rce

1
6
0
repeated

This unpriv-reachable vuln in the upstream 6.6 LTS was finally fixed yesterday after being publicly triggered in syzkaller over 5300 times since March when it was introduced: https://syzkaller.appspot.com/bug?extid=3ad17e94107dda6b6b03 Since we don't ignore syzkaller results, we fixed it the day it was introduced.
https://bird.makeup/users/spendergrsec/statuses/2074499846887674260

1
4
0
repeated

🚨 New advisory was just published!

An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/

0
2
0
repeated

Enterprise Role Play (ERP), sometimes also Enterprise Resource Play: A unique form of fetish role play.

Unlike more popular fantasies such as boss/secretary focused on power relationships in an office environment, in ERP the business processes themselves are central to the scenario.

ERP participants can create elaborate scenarios involving fictional purchasing departments, legal teams, contract negotiations, and more. Large group ERP scenarios sometimes even extend to the point of renting out vacant space in an office park and acquiring demo licenses of SAP or a competing software package to make the fantasy more realistic, or even traveling to a remote ERP group's dungeon to roleplay a merger or acquisition.

As with more conventional roleplays in the S&M context, consent is critical in ERP. If participants are expected to invest significant real-world money in software licenses, make sure this is agreed upon by everyone in advance. The outcome of all merger scenarios should be pre-briefed; attempted hostile takeovers of another dungeon are extremely frowned upon and can result in participants being banned from future events.

3
7
0
repeated

If those slop jockeys could read, they'd be very upset

3
16
0
repeated

EU Fines Google $1 Billion for DMA Competition Violations, Including Making Search Results More Useful
https://daringfireball.net/linked/2026/07/25/eu-fines-google-1b

3
1
0
repeated

Occasional reminder to tip your fedi admin if you can and they want it. They put up with a lot of bullshit around here and some foot some hefty bills.

On Infosec dot Exchange, Jerry has links for donations in his profile:

https://infosec.exchange/deck/@jerry

1
4
0
@wdormann What *is* their job though? Incentives are pervese and blurring risk is in many cases the most cost-effective for everyone. If shits hit the fan, they can blame $country or AI (or both).

Somewhat related: who would've predicted that ClickFix will become an actual ItW vector that needs to be mitigated?!
0
0
1
repeated

MSRC is starting well with their "piss off the reporter" strategy.

I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability.

I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.

1
2
0
#hupol #engineering
Show content
An interesting metric of any political system is the distribution of professions of people in power.

For years it seemed that only unemployed lawyers and career buttlickers can become popular politicians around here.

Now we have a traffic engineer as a minister of transportation who knows the dates to the day when railway sections were closed down and calls engines by their nicknames.

And people love him! This gives me some hope.
0
0
6
Is there a list of ways to cut the very connection you are using to manage a server?

"A friend" would like to contribute...
0
1
2
Show older