Posts
3249
Following
707
Followers
1565
"I'm interested in all kinds of astronomy."
[RSS] Pluralistic: You should be using an RSS reader (16 Oct 2024)

https://pluralistic.net/2024/10/16/keep-it-really-simple-stupid/
0
0
0
repeated

TrendAI Zero Day Initiative

Unfortunately, the Viettel Cyber Security (@vcslab) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.

0
1
0
repeated

CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog
Hot off the press!

  • CVE-2024-37383 (6.1 medium( RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
  • CVE-2024-20481 (5.8 medium) Cisco ASA and FTD Denial-of-Service Vulnerability

0
2
0
repeated

An idea I recently heard on a parenting podcast really resonated with me. Tech has created a generation of people used to instant gratification.

Hungry? Open an app. Want to listen to music? Open an app. Bored? Open an app.

However a lot of needs in life can’t be gratified instantly and we now have many people, both adults and kids, who simply don’t know how to handle that. We now have entire subcultures whose main dysfunction is they can’t just get what they want without work and they’re mad.

4
3
0
[RSS] LibRaw: Uninitialized memory disclosure via LibRaw_buffer_datastream::read

https://github.com/google/security-research/security/advisories/GHSA-cmhf-chvw-6c7j

<3 these :)
0
0
1
[RSS] DTLS ClientHello Race Conditions In WebRTC Implementations

https://packetstormsecurity.com/files/182303/webrtc-hello-race-conditions-paper.pdf
0
0
0
repeated

This is another plus to hosting your own work, by the way. They can still take it up the chain to my service providers, but I don’t have to worry about filing a counterclaim with the webhost because I AM the webhost.

3
6
0
repeated

After I refused a bribe to remove a @web3isgreat post about alleged crypto pyramid scheme co-founder Roman Ziemian, I’ve now received a fraudulent copyright claim aimed at forcing me to take it down

18
18
0
OH: "We had a problem. We thought we'd solve it with the cloud. Now we have a horizontally scalable set of problems."
0
10
21
repeated
@nightwolf Not sure it was this one, but very interesting anyway, thanks!
0
0
1
Edited 1 year ago
Anyone remembers that research about using compromised AV/EDR management consoles as C2 servers?

I remember someone was working on it but I don't remember seeing it released.
1
1
1
repeated

The Irish Data Protection Commission fines LinkedIn €310M over using personal data for behavioral analysis and targeted ads under GDPR, after a 2018 complaint (Ian Curran/The Irish Times)

https://www.irishtimes.com/business/2024/10/24/microsoft-owned-linkedin-fined-310m-by-irish-data-protection-commission/
http://www.techmeme.com/241024/p13#a241024p13

0
3
0
repeated

TrendAI Zero Day Initiative

Our first collision of Day Three: the group from STEALIEN Inc. successfully popped the Lorex camera, but the bug they used had already been demonstrated in the contest. They still earn $3,750 and 1.5 Master of Pwn points.

0
2
0
repeated

It never rains but it pours 🌧️ Mandiant has also released a deep dive into the ongoing exploitation of FortiManager zero-day (CVE-2024-47575) affecting 50+ systems! Check out their analysis here: https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575/

0
2
0
repeated

Here's a picture of the "cash" they printed to confirm their exploit.

0
2
0
repeated

TrendAI Zero Day Initiative

Unfortunately, Sina Kheirkhah (@SinSinology) and Enrique Castillo (@hyprdude) of Summoning Team (@SummoningTeam) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.

0
1
0
Show older