Posts
2452
Following
555
Followers
1266
A drunken debugger

Heretek of Silent Signal
repeated

New release! 📣

Parents can now shield their children from clickbait and shock value with powerful new video controls that show authentic thumbnails and clean titles.

Full release notes: https://kagi.com/changelog#5108

2
3
0
repeated
New assessment for topic: CVE-2024-47575

Topic description: "A missing authentication for critical function vulnerability in Fortinet's FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. ..."

"The flaw lies in the FortiGate to FortiManager Protocol (FGFM), which is designed for deployment scenarios where NAT traversal is needed ..."

Link: https://attackerkb.com/assessments/89ecce82-7a39-4376-82e1-8f5bfaad47f6
0
1
0
@screaminggoat @hrbrmstr @todb I think while obviously incomplete, @attackerkb is great, and it includes info about active exploitation too. Also cvedetails, yes.
0
0
4
repeated

Gmail account appears to be fine, but the Amazon account has definitely been hijacked. Looks like the attacker texted a link that the neighbor clicked on this morning, and that completed some sort of account ownership transfer. Neighbor assures me they just clicked the link and didn't enter anything. They just landed on an Amazon page that said their account had been successfully transferred to someone else (they have a screenshot of the hijacker's email address).

They've been on the phone with Amazon trying to get it resolved, but if the description is correct it sure seems like there's a vulnerability on Amazon's end here.

At exactly the same time the SMS was sent the neighbor's Gmail account got hit with a firehose of thousands of spam messages persisting for several hours, which is why they thought the Gmail account was hacked (and also why they clicked the Amazon phishing link from the SMS).

Does this sort of thing sound familiar to anyone?

1
1
0
repeated

Video for my talk on DTrace at 21 is now up, though you will miss me in the chat explaining which of the slides are throwing shade at eBPF https://www.youtube.com/watch?v=KjQnB9yB9kQ

1
2
0
repeated

12 Freya it/its𒀭𒈹𒍠𒊩

are there any ex- engineers on fedi who'd be willing to help us with a thing? We're creating a 10 modernisation kit thing with a bunch of modern tools, and honestly having someone give it a look over who worked with Solaris 10 and stuff really colsely would be super helpful

2
3
0
repeated

Because of a conversation I had elsewhere.

2
4
0
@f4grx @recursive @nina_kali_nina Fair point, but FTR I'm actually logged in to YT, have seen that vid before, and I get 0 Tesla crap while using uBO.
1
0
1
@nina_kali_nina @f4grx @recursive Take a look at how to get out the rear seat of a Tesla, it's fucking horrifying: https://www.youtube.com/watch?v=6PbRBbIGnv4
1
0
2
repeated

CVE-2024-26926 Binder n-day analysis.
It is labeled EoP in Android Security Bulletin (Is it really exploitable?)

https://github.com/MaherAzzouzi/LinuxKernel-nday/blob/main/CVE-2024-26926/CVE_2024_26926_Analysis.pdf

0
2
0
repeated

A quick newsletter post on the dehumanization behind Satya Nadella's remarks about copyright law

https://buttondown.com/maiht3k/archive/virtual-employees-and-remixing-machines-devalue/

1
6
0
repeated

That's a wrap for Ireland 2024! Over last 4 days, we awarded $1,066,625 for over 70 0-day bugs. That makes 4 contests in a row that exceeded the million-dollar mark. Congratulations to the Viettel Cyber Security team for winning Master of Pwn with 33 points and $205,000.

0
3
0
Oracle VM VirtualBox 7.0.10 r158379 Escape

https://zeroclick.sh/blog/cve-2023-22098/
0
0
2
Memory Management - Part 1: Virtual memory and Paging concepts

https://blog.reodus.com/posts/memory-management-part1/
0
0
2
repeated

Seasonal Spells for

Toddler's Vicious Snot: This spell initially impacts the member of the party with the lowest HP. It lasts for 2 days. After that it affects all other members of the party, is immune to Healing, and you need a 20+ Con saving throw to recover from it.

Fall Back: This spell interrupts the target's Long Rest one hour too soon. Every time. For about two weeks.

Toddler's Disappearing Accessories: This spell affects hats, gloves, scarves, and boots.

0
1
1
repeated

@djchateau Good thread also with more info (like that some lengthier policy will apparently be posted): https://lore.kernel.org/lkml/e7d548a7fc835f9f3c9cb2e5ed97dfdfa164813f.camel@HansenPartnership.com/ Parent poster's mail is at minimum misleading/disingenuous because they already were aware their employer was on the sanction list...

1
1
0
CVE-2024-9050: NetworkManager-libreswan IPSec VPN plugin local code execution

https://www.openwall.com/lists/oss-security/2024/10/25/1
0
1
0
repeated

The thing where companies make websites for their own executives, who never visit them, instead of their customers, who are forced to.

0
3
0
Show older