Posts
3226
Following
706
Followers
1564
"I'm interested in all kinds of astronomy."
repeated

Current temperature of mastodon, twitter et al. ;-)

3
7
1
repeated

bug-bounty stats

(Including 84,260 USD payouts and 15.4% being valid reports.)

https://daniel.haxx.se/blog/2024/10/09/curl-bug-bounty-stats/

0
1
0
[RSS] Ivanti Connect Secure - Authenticated RCE via OpenSSL CRLF Injection (CVE-2024-37404)

https://blog.amberwolf.com/blog/2024/october/cve-2024-37404-ivanti-connect-secure-authenticated-rce-via-openssl-crlf-injection/
0
0
0
repeated

New sensitive breach: "AI girlfriend" site Muah[.]ai had 1.9M email addresses breached last month. Data included AI prompts describing desired images, many sexual in nature and many describing child exploitation. 24% were already in @haveibeenpwned. More: https://www.404media.co/hacked-ai-girlfriend-data-shows-prompts-describing-child-sexual-abuse-2/

0
4
0
repeated
@molly0xfff @cpy @shadow @koen_hufkens Death metal band logos have high resistance against AI text recognition. And OCR. Oh, and human readers.
0
0
2
repeated

TrendAI Zero Day Initiative

It's the spooky season, and and have released their spookiest patches yet. Two bugs from Microsoft are under attack, and one looks strangely familiar. @TheDustinChilds breaks down the release and points out some deployment priorities. https://www.zerodayinitiative.com/blog/2024/10/8/the-october-2024-security-update-review

0
2
0
repeated

Happy from Microsoft: 5 ZERO-DAYS (2 exploited, all of them publicly disclosed)

  • CVE-2024-43573 (6.5 medium) Microsoft Windows MSHTML Platform Spoofing Vulnerability (PUBLICLY DISCLOSED, EXPLOITED)
  • CVE-2024-43572 (7.8 high) Microsoft Management Console Remote Code Execution Vulnerability (PUBLICLY DISCLOSED, EXPLOITED)
  • CVE-2024-43583 (7.8 high) Winlogon Elevation of Privilege Vulnerability (PUBLICLY DISCLOSED)
  • CVE-2024-20659 (7.1 high) Windows Hyper-V Security Feature Bypass Vulnerability (PUBLICLY DISCLOSED)
  • CVE-2024-6197 (8.8 high) Open Source Curl Remote Code Execution Vulnerability (PUBLICLY DISCLOSED)

cc: @goatyell @mttaggart @hrbrmstr @ntkramer @iagox86 @zackwhittaker @dreadpir8robots @TheDustinChilds @neurovagrant @xorhex @campuscodi @briankrebs (remember to remove the mentions to avoid ReplyAll madness)

2
3
0
repeated

We can build the web that we want to see. Watch the recording of my talk from !

https://www.youtube.com/watch?v=MTaeVVAvk-c

5
18
0
@dannycolin asking the important questions \m/
0
0
0
repeated
[RSS] Reversing Tips: (Almost) Automatically renaming functions with Ghidra

https://blog.convisoappsec.com/en/automatically-renaming-functions-with-ghidra/
0
1
1
repeated

In response to my earlier post, some Twitter folks asked why I'm "so afraid of telemetry".

For one, it's because I've seen first-hand what ends up in it. Crash reporting is particularly bad: it's nearly impossible to reliably scrub of sensitive info - URLs, auth tokens, etc.

Worse, a lot of other "telemetry" is deliberately privacy-violating. "Don't worry, we only collect anonymized GPS routes". Except, you know, a buyer of this data can filter by tracks originating from my home.

But above all, I just don't want the mental burden of figuring this out for every piece of software I install, so I hate that it's the new norm.

If you want a peek at how I'm using your software, meaningfully ask, instead of sneaking it in on page 38 of the EULA.

0
8
0
repeated

@alienghic @ai6yr @meganL I read through Ajay Singh Chaudhary's "The Exhausted of the Earth" some months ago.

I got to this part:

"Capital will chew through the biosphere and societies alike in pursuit of an ever more costly maintenance of profitability."

About the same time as I read a piece about OpenAI claiming to want to spend the entire GDP of Japan on burning fuel and making electronic waste.

So I was not able to disagree with that part of his analysis.

1
2
0
Edited 1 year ago
Is it me, or is it actually hard to get the physics angle (as opposed to math/CS) in this year's physics Nobel Prize?
0
2
3
@tmr232 just implement the Windows Hotdog Stand theme and you're done
1
0
1
repeated

TIL: AVX-512 supports an instruction implementing binary logic defined by a 3-input LUT. Sounds super handy.

https://arnaud-carre.github.io/2024-10-06-vpternlogd/

0
1
0
repeated
Show older