pretty fun stuff in here :)
https://hackaday.com/2025/11/18/congratulations-to-the-2025-component-abuse-challenge-winners/
Sent from San Francisco, California, U.S.A. on December 20, 1995. https://postcardware.net/?id=12-38
RCE in Apache Causeway.
https://lists.apache.org/thread/rjlg4spqhmgy1xgq9wq5h2tfnq4pm70b
Cloudflare published a very good article explaining how yesterday's outage happened.
https://blog.cloudflare.com/18-november-2025-outage/
I encourage everyone to read it.
I also think people are focusing on that particular unwrap() too much, and not enough on a bigger picture: lack of fallbacks
Without fallbacks at the interfaces between different subsystems, there's nothing to stop an error in one place from cascading throughout the whole infra
Config parsing is not the only place where such fallback was missing
First #39C3 fake ticket spotted in the wild. If you see any offers on platforms like Kleinanzeigen or eBay showing a ticket it is a scam - tickets are not issued and no one knows how they will look like. Flag those offers please.
I have a friend who prefers to stay anonymous who gives this amazing talk in non US (but allied) countries about how long their internet will -really- function if they lose all comms with American data centers and it’s… phew. It’s a thing. Some resilient ones will last a few weeks before certificates expire. But CF is a wrench.
I want to try switching to Linux.
However, I cannot find a working remote desktop system that allows me to take over the same session that I was using locally so that I can switch back and forth between being at the computer and being remote without having to log out. Blanking/Locking the local screen while I'm connected remotely is also a need.
Basically I need it to work as close to Microsoft's RDP as possible. If anyone can help me with this, you'll convert me to a Linux user.
Here’s a free scanner for that FortiWeb CVE-2025-64446 I made for you. https://github.com/sensepost/CVE-2025-64446