Posts
3900
Following
728
Followers
1601
"I'm interested in all kinds of astronomy."
[RSS] Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026-7482)

https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama
0
0
2
repeated

Non-technical teams are now shipping production vulns

2
10
0
repeated

Jerry πŸ¦™πŸ’πŸ¦™

Honestly, one of the things I like least about traveling for work is having to wear pants. Seems like we should have moved past this expectation by now

14
5
1
repeated

They'd have got away with it, if it wasn't for those meddling kids.

1
5
0
repeated
repeated
Edited 15 hours ago

"That 'responsible disclosure' Thing"

A post with the details of CVE-2026-23918, the double free vulnerability fixed in Apache httpd 2.4.67.


https://eissing.org/icing/posts/responsible-disclosure/

4
6
0
repeated

@daveaitel @sherrod_im The willful ignorance of latent vulns. It was as if it didn’t exist until a vuln researcher discovered it.

0
4
0
@gsuberland

Remember me to one who lived there.
She once was a true love of mine.
0
0
2
repeated

Oh cool, Ollama on Windows has unpatched vulnerabilities that lead to Ollama downloading unverified updates from a malicious URL if set locally, and also path traversal that leads to arbitrary file write.

Disclosure without patch.

https://www.striga.ai/research/ollama-windows-auto-update-rce

0
4
0
repeated

bert hubert πŸ‡ΊπŸ‡¦πŸ‡ͺπŸ‡ΊπŸ‡ΊπŸ‡¦

Edited yesterday

The world is now so full of ridiculous things that at least I struggle to deal with it all. But this is not an 'us' problem. The (political) world really is idiotic. I needed to vent a bit, so I made a list of things that are impossible to believe, yet are very much what is happening. Perhaps seeing it in writing will help you deal better with the situation. https://berthub.eu/articles/posts/the-impossible-things-we-have-to-believe/

4
5
0
repeated

This. πŸ‘‡

3
7
0
repeated

Defender nuked legitimate DigiCert roots as malware because Microsoft shipped detections for a real DigiCert breach without distinguishing root certs from the compromised code-signing ones. Your trust store is one bad signature update away from triage hell.
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/

0
4
0
repeated

Aaron Toponce βš›οΈdebian

Google Chrome is silently installing a local LLM on your computer that is 4 gigabytes in size. It's done without consent, it's not visible in the settings, and removing it will reinstall it later.

https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/

5
19
0
@stf Given that 1) naming things is hard and 2) you shouldn't reinvent the wheel, you just take the name of a similar project. (and this is how eventually every OSS project becomes "curl")
1
0
1
repeated
Edited yesterday

The existence of a weird proxy economy for AI tokens is very effing cyberpunk, AI issues notwithstanding (or perhaps especially). (Also, China Talk is an *excellent* source for lots of current tech-related goings-on.)

https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in

2
5
0
repeated

@openrightsgroup @torproject

This is the wrong message. Ministers do not care about undermining the open web. They see openness as a bug, not a feature.

The message you need to highlight is that the OSA is handing more control to US tech companies that are under the control of Trump.

0
2
0
repeated

To kick off his collaboration with @portswigger as a Burp Suite Ambassador, our Research Lead @apps3c just published the 10th article on the creation of extensions for . Topic: !

https://hnsecurity.it/blog/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-10/

0
3
0
repeated

30 readers took our C/C++ challenge. Some solved the Linux warmup, but nobody cracked the Windows driver bug. Even LLM-assisted submissions came up short.

The walkthrough explains both, including the Windows escalation from local DoS to kernel code execution.

Best 10 submissions are still getting swag. If you won, we'll be in contact.
https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/

1
3
0
Show older