Posts
2700
Following
681
Followers
1504
"I'm interested in all kinds of astronomy."
#music #ExtremeMetal
Show content
I choose very carefully when I listen to Cephalic Carnage because it drags you to places you have to be prepared for.

I'm not a huge fan of remix albums (shitty sound is usually part of the story!) but this one just makes my nose bleed (in a good way):

https://cephaliccarnage.bandcamp.com/album/exploiting-dysfunction-deluxe-25th-anniversary-reissue

You've been warned.
0
0
1
@Viss this should be pretty obvious but seeing some actual data is...wow
0
0
2
repeated

hey more fun ai / search engine privacy nonsense!

looks like chatgpt .. just.. sprays google with stuff from chats? because it thinks it needs to? so private chats get squirted into google and end up as weird searches?

https://arstechnica.com/tech-policy/2025/11/oddest-chatgpt-leaks-yet-cringey-chat-logs-found-in-google-analytics-tool/

2
3
0
repeated
repeated

Anyone have some FortiShit to test something on?

https://x.com/DefusedCyber/status/1986544427121471513

⚠️Actor mass exploiting unknown Fortinet exploit (FortiWeb path traversal / API exploitation) from 107.152.41.19 🇺🇸 ( TZULO )

VirusTotal Detections 0/95 🟢

After the exploit, the actor attempted to login using the newly created username-credential pair 🔐

4
6
0
[RSS] What's That Coming Over The Hill? (Monsta FTP Remote Code Execution CVE-2025-34299)

https://labs.watchtowr.com/whats-that-coming-over-the-hill-monsta-ftp-remote-code-execution-cve-2025-34299/
0
0
1
repeated

"The moment of discovery" does not always exist: the scientist's work is too tenuous, too divided, for the certainty of success to crackle out suddenly in the midst of his laborious toil like a stroke of lightening, dazzling him by its fire.

In: Eve Curie - Madame Curie - Chapter XII (p. 158)

~Marie Curie in 1867.

0
3
0
repeated

Magika 1.0 is released, available in Rust, TypeScript and Python, and supporting more than 200 file types.

Public blog post:
https://opensource.googleblog.com/2025/11/announcing-magika-10-now-faster-smarter.html

Source: https://github.com/google/magika

1
5
0
repeated

From bit flip to RCE in Ollama! 🦙

Our latest blog post explains how a file parsing bug led to an interesting out-of-bounds write primitive. Learn how it could have been exploited in Ollama, a tool to run LLMs locally:

https://www.sonarsource.com/blog/ollama-remote-code-execution-securing-the-code-that-runs-llms/?utm_medium=social&utm_source=twitter&utm_campaign=research&utm_content=blog-ollama-vuln-251104-&utm_term=---&s_category=Organic&s_source=Social%20Media&s_origin=social

1
7
0
repeated
repeated

OH: "You're in his DMs. I'm in his VMs. We're not the same."

1
9
0
repeated
@tmr232 See also Anthropics latest about putting an MCP in your MCP, aka. "innovation, bitches!": https://www.anthropic.com/engineering/code-execution-with-mcp
0
0
1
@tmr232 @joxean Infact I'm playing with it rn because tree-sitter query CLI doesn't seem to support structured output...
1
0
0
@joxean Oh OK, I'm still learning, but this usually accumulates in some tips&tricks so I'll keep that in mind!
1
0
0
On the other hand ast-grep's pattern/rule syntax is **not** compatible with Semgrep's :(
1
0
1
I almost got brain aneurysm thinking that the query syntax of tree-sitter and ast-grep differ.

Fortunately that's not the case, but - contrary to Internet wisdom - query syntax is not compatible between languages (parsers).

Also, ast-grep's Playground is insanely useful:

https://ast-grep.github.io/playground.html
1
1
1
Show older