Posts
3373
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated

Channeling @Viss

"Go to the cloud, it'll be great"

Microsoft has been reporting an issue since 8:54pm yesterday. The basic summary of the issue is "Teams,. Exchange, Purview, SharePoint, and Universal Print are all broken". So you know - everything you need to use in Office365 to operate on a day to day basis in a Microsoft world.

Copilot is also broken apparently, but we don't like that anyway, right?!

1
2
0
repeated

luna, friend of eggbug

A lot of people don’t know this one weird trick — much like JavaScript, C also lets you perform arithmetic with mixed types:

2
11
1
[RSS] Arbitrary web root file read in Sitecore before v10.4.0 rev. 010422

https://blog.scrt.ch/2024/11/25/arbitrary-web-root-file-read-in-sitecore-before-v10-4-0-rev-010422/
0
0
1
[RSS] Finding vulnerabilities in ClipSp, the driver at the core of Windows' Client License Platform

https://blog.talosintelligence.com/finding-vulnerabilities-in-clipsp-the-driver-at-the-core-of-windows-client-license-platform/
0
0
1
repeated

Dear everyone who owns domains that are *not used for e-mail*, particularly ones that are potential targets for phishing (banks, high-profile names): Could you please configure SPF+DMARC, ideally with p=reject? You may wonder: Why should I configure anything email for a host that isn't used for email? Well... it helps others to identify spam sent with your domain as the sender.

7
9
0
repeated

@0xabad1dea they could have gone the crowdstrike route and just bricked the laptop when processing the unsigned update.

0
1
0
repeated

Good news: The Dell firmware update utility definitely checks whether update executables are signed.

Bad news: Dell is posting unsigned update executables to their website labeled “critical” which then fail to install due to the good news

3
9
0
[RSS] How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review

https://pentesterlab.com/blog/jwt-algorithm-confusion-code-review-lessons
0
4
1
[RSS] Ruby 3.4 Universal RCE Deserialization Gadget Chain

https://nastystereo.com/security/ruby-3.4-deserialization.html
0
2
2
repeated

bsky.app/profile/mrme.bsky.social/post/3lbql2z2uas2f

Trust me, the Chinese hack Spring apps harder than you: https://juejin.cn/post/6972564484720328718

0
1
0
repeated

Revisiting unresolved JetBrains TeamCity issues: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=teamcity

I may be a hater but I'm not lying and to my customers and hiding security issues.

1
1
0
@screaminggoat @dreadpir8robots @todb @h4sh IME CVE issuance is the easiest part: if vendor is a CNA, they will take care of it, most of the process is coordinating technical details and disclosure. If it's MITRE you can get a CVE basically instantly with their online form.

I have to note that AFAIK MITRE is *not* a fallback (they will redirect you to the CNA you just visited), and H1 is *definitely* not a fallback (for a multitude of reasons). FD is a fallback, and so is CERT-CC in some cases.
1
0
2
repeated

social media platform users are going to link offsite. the only question is how obnoxious the platform will make it for them and everyone else.

(For context: Instagram prohibits links in post text. This, plus the incentive to inflate comments, has led to the proliferation of tools where creators instruct their followers to comment with a specific word to receive a link in their DMs— in this case, to a pie crust recipe)

7
10
0
@wdormann Is this the feature implemented by ai.exe, aka. "Artificial Intelligence Host"? That thing caused problems for me before by trying to chat with the mothership:

https://www.reddit.com/r/Office365/comments/ylkip5/comment/j3vjm8w/
0
0
0
repeated

and... fruitless

$1$yMKkNlnT$BDBNp1JZAq1Kyk.CUV4Vd0

Maybe I can nerdsnipe this?

3
3
0
Edited 1 year ago
From Guardian to Gateway: The Hidden Risks of EDR Vulnerabilities - Neodyme
https://neodyme.io/en/blog/wazuh_rce/

/via @tekwizz123

CVE-2024-32038, CVE-2023-50260
#frombsky
0
1
5
@aardrian That's weird, it usually works for me out of the box :( I'm not in the mood of digging into Medium's bullshit, but the link at the top of the article seems to work. Anyway, sorry for the spam!
1
0
0
Show older