Posts
4648
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated

Journalists have tracked down two employees of Kremlin disinformation group Rybar to villas near Berlin, Germany, with the two living comfortably and safe in the decadent EU they villainize each day

https://correctiv.org/aktuelles/russland-ukraine-2/2026/09/24/russischer-kriegskanal-rybar-operiert-von-berlin-aus/

https://istories.media/news/2026/09/24/rabotayushchie-na-z-kanal-ribar-propagandisti-dolmatov-i-chashchukhin-rezidenti-germanii/

1
5
0
@hackaday "Probably the easiest way is to use a known-good and clearly labeled reference magnet. Same poles repel, and opposites attract. But if that’s not available, a simple magnetic compass can help."

So instead of using a clearly labeled reference, you suggest using a clearly labeled reference, got it!
0
0
1
repeated

But I gotta hand it to AI labs that "WE MUST BE STOPPED AT ANY COST OR WE'RE GOING TO KILL YOU ALL" is one of the most original marketing pitches I've heard in my life

3
10
0
repeated
repeated

Any UNIX socket protocols that would be fun to add probes for, anyone?

1
2
0
repeated
Edited yesterday

When I drive a car without a valid driver's license, proof of insurance or tag/license plate, I get stopped by the police, my car will be towed and I can either walk home or might end up in jail and face severe fines, a probation period and loss of my driver's license.

When Microsoft runs 45 gas turbines without a state permit, they get 45 days to fix it and a $1.07M fine (which is petty cash for an operation this size) and don't even have to power down the turbines.

https://www.theguardian.com/environment/2026/sep/25/new-jersey-fines-datacenter-unpermitted-generators

3
18
0
repeated

🚨 Companies are being urged to shut down their NetScaler instances immediately due to multiple unpatched Citrix NetScaler RCE vulnerabilities.

Source: https://x.com/watchtowrcyber/status/2103891689857228803

0
4
0
Edited yesterday
DNS errors again. systemd-resolved once again reports 0 errors (in fact, 0 log messages).

From my professional experience I know this means the network is probably fucked. It was.

But why is it so hard to put `error("network is fucked");` in #systemd?

https://blog.netherlabs.nl/articles/2006/09/08/the-perfect-error-message
0
0
1
repeated

For details on how the 8087 calculates tangents by using the CORDIC algorithm combined with polynomials, see my latest article:
https://www.righto.com/2026/09/8087-tangent-cordic.html

1
3
0
repeated
@freddy @raptor I took that as a joke :) unfortunately last time I checked you also qualify as human, which is a problem in this situation, and would make bots perfect candidates
1
0
0
An old friend is ashamed of speaking English with people but want to practice. Any pro/cons of using an educational chatbot for this?

At first I find this a pretty good use case for language models.
3
0
2
repeated

vertex shaders per cryptographic proof

1
1
0
That's right, the right answer for this questions is: 3!

By first pressing the down arrow you remove the selection (which you didn't put there) from the address bar text. The two downs are needed to reach C:\Users\Public.

"2 or 3" would be also acceptable, because if you don't just click the address bar, but start to type in it, there is no selection to remove.

https://infosec.place/objects/85dfac07-d1d6-412b-832c-897be5be860b
0
0
1
repeated

We have posted the YouTube playlist for Trusted Computing 1103: Advanced TPM Usage by Dimi Tomov in partnership with the TCG. Now anyone wishing to download the videos for offline viewing can find all their URLs here:
https://www.youtube.com/playlist?list=PLUFkSN0XLZ-l-hmC2f0f0WHh5tm76LyTj

But as always the best experience is at the full class at https://ost2.fyi/TC1103

0
2
0
@freddy Not sure I'll be able to have the original trigger now that a media proxy got introduced (don't know if it works retroactively).

But I have an idea for a repro, adding then deleting an <img> to the document. I guess what makes debugging this difficult is that you need a point-in-time document snapshot to see the true source. Even seeing the <img> may not be meaningful without e.g. it's surrounding <div> with the post content.
0
0
0
repeated

It seems that Avast managed to settle the lawsuits related to their data abuse in both US and UK. While in the former they agreed to pay a fairly moderate fine, UK let them off the hook even easier. They are offering two years of free software to eligible UK users which is, quite frankly, a joke. It costs Avast exactly nothing, it allows them to email past users on a legal basis and gives them a chance to win them back. Really, who agreed to that?

0
3
0
repeated
Edited 2 days ago

Interesting Git repos of the week:

Strategy:

* https://github.com/SoShinySoChrome/human-incident-response-framework - tackling the human side of IR

Threats:

* https://github.com/Mickinthemiddle/CLOAK - deception techniques used by operators

Detection:

* https://github.com/Chick3nHawk01/Open_Source-CTI-Tooling - open source CTI tooling

Bugs:

* https://github.com/suce0155/CVE-2026-32996 - a backup route for LPE

Exploitation:

* https://github.com/cloudflare/security-audit-skill - more skills for your 🤖
* https://github.com/almounah/silph - another tool to steal your memories
* https://github.com/TheZeroSlave/WPE - like Burp but for non-HTTP Windows traffic (HT @Ichinin for the reminder)
* https://github.com/interference-security/echomirage - if you remember shade/DOA... someone has saved a copy of Echo Mirage, another Windows MITM testing tool
* https://github.com/Mafifrizi/ARES - someone has been going through adding my AD attacks (credited nicely :)) on Linux to its repertoire
* https://github.com/IoTS-P/Akiba - batch processing Ghidra
* https://github.com/vulncheck-oss/initial-access-community - some nice ideas on initial access from @albinolobster and friends

Hard hacks:

* https://github.com/GlasgowEmbedded/glasgow - it's always nice in Glasgow with @whitequark
* https://github.com/xiaobor123/vuls-find-VxWorks - VxWorks until it doesn't
* https://github.com/xiaobor123/vul-finds - more cute bugs

Data:

* https://github.com/cisco-ai-defense/aibom - AI usage needs to be transparent... and if not, well, some of us will be looking for it in any event 🤖

Cryptography:

* https://github.com/nationwide-group-oss/cryptoptic - time to start taking PQC seriously

Development:

* https://github.com/ItzLevvie/dind - HT to @GossiTheDog for pointing it out, but run Windows inside of GitHub

Nerd:

* https://github.com/sure-fire/derbypi - some neat extensions for Pis from @surefire

, ,

0
4
0
Show older