4 February 1917 | A Polish Jewish dancer Franciszka Mann was born. She was most probably the woman who on 23 October 1943, inside the undressing room of gas chamber II at Auschwitz II-Birkenau, seized SS man Josef Schillinger’s pistol, shot him & wounded SS man Wilhelm Emmerich.
---
A podcast about this and other cases of resistance at Auschwitz: https://www.auschwitz.org/en/education/e-learning/podcast/different-cases-of-organized-resistance-at-auschwitz/
the guy and his AI found three uses of memcmp() in TLS code and insisted it was a "CRITICAL" side-channel security vulnerability.
A 2-second check of those three uses told us it was not real.
byebye George
Switching away from Hackerone is not a guarantee... Here we go.
Also came across this today. Wasn't already in the ruleset, so I fixed that.
FreePBX Authenticated Command Injection - testconnection SSH functionality.
https://theyhack.me/CVE-2025-64328-FreePBX-Authenticated-Command-Injection/
Patch diffing + RCA for clfs.sys can take awhile.
I gave the diff + binary to a local LLM.
It mapped the UAF path, race condition, all IOCTLs in <20 min
LLMs don't replace the work, they are momentum.
New blog post following the UAF trail of CVE-2025-29824:
https://clearbluejar.github.io/posts/how-llms-feed-your-re-habit-following-the-uaf-trail-in-clfs/
Dirty Ptrace: Exploiting Undocumented Behaviors in Kernel mmap Handlers
Talk by Xingyu Jin and Martijn Bogaard about a new type of logical bugs in kernel driver mmap handlers exploitable via the ptrace functionality.
Authors found multiple Android vendor drivers affected by the issue. They also wrote an exploit for the IMG DXT GPU driver to escalate privileges on Pixel 10.
Video: https://www.youtube.com/watch?v=yAUJFrPjfCI
Slides: https://powerofcommunity.net/2025/slide/x-84592.pdf
Does anybody know, by any rare chance, what #Firefox settings might cause CORS errors? Since last week I'm unable to access, for example, a local #Jellyfin instance with Firefox due to this problem, as it causes a lot of CORS errors (same origin policy).
I have already tried changing "Enhanced Tracking Protection" settings: they are ignored.
I have also already tried creating a new fresh Firefox profile. It works, but as soon as I synchronise it with my Mozilla account, it fails again.
NEW: French Police searched the local X offices as part of a criminal investigation for several crimes, including possession and distribution of child sexual abuse material.
Paris prosecutor's office also announced that it summond Elon Musk and former X CEO Linda Yaccarino for questioning.
A fun quirk of modern languages is variable names aren’t restricted to ASCII.
Most compilers won’t let you use emojis as identifiers in C++, but we *can* be pretty funny (notice cout).
A legitimate use case is replicating scientific paper notation in code.
Open Source security in spite of AI - the recording.
https://daniel.haxx.se/blog/2026/02/03/open-source-security-in-spite-of-ai/