After releasing his PoC for CVE-2024-49138, @ale98 is back with two new articles that provide background on #Windows #CLFS, analyze two distinct #vulnerabilities patched by Microsoft’s KB5048685, and describe how to #exploit them.
https://security.humanativaspa.it/cve-2024-49138-windows-clfs-heap-based-buffer-overflow-analysis-part-1
https://security.humanativaspa.it/cve-2024-49138-windows-clfs-heap-based-buffer-overflow-analysis-part-2
Well, here's the cyberpunk part of the dystopia. Congrats Linux users, you're all criminals now.
Starting on January 19, 2025 Facebook's internal policy makers decided that Linux is malware and labelled groups associated with Linux as being "cybersecurity threats". Any posts mentioning DistroWatch and multiple groups associated with Linux and Linux discussions have either been shut down or had many of their posts removed.
https://distrowatch.com/weekly-mobile.php?issue=20250127#sitenews
@buherator yes, I don't remember where I took the filter from, but it's something like this: https://github.com/gijsdev/ublock-hide-yt-shorts/blob/master/list.txt works on desktop and mobile. keep on rocking 🤘
Via another "crazy security scanner" report, I learn that #libcurl is installed in a #Microsoft Office and/or Teams install on Windows? According to the reddit post, in a normal install.
Does anyone know more?
The reddit page mentioning this: https://www.reddit.com/r/sysadmin/comments/1hx9eib/libcurl_vulnerability_in_office_and_teams/?sort=new
The libcurl mailing list post:
David Sacks and OAI complaining about distillation is extremely rich considering OAI trained in all of Libgen. :-(
Everyone is r*tarded.
OpenAI says it has evidence China’s DeepSeek used its model to train competitor - https://www.ft.com/content/a0dfedd1-5255-4fa9-8ccc-1fe01de87ea6?shareType=nongift via @ft
Sent by Charles Adams from Inyokern, California, U.S.A. on May 20, 1996. https://postcardware.net/?id=43-13
jesus, Google Maps is going to change the names of the Gulf of Mexico and Denali. https://www.theverge.com/2025/1/27/24353450/google-maps-rename-gulf-of-mexico-america-mt-mckinley
Sitting in bed and using my portable data terminal to read about USA billionaire vs China military backed battling AI systems suspected of stealing our data and spying on us is exactly the cyberpunk future I was promised.
A detailed, well-written, and hilarious breakdown of the details of CVE-2024-55591, one of the latest Fortinet fiascos:
You know the drill.
Update your fruit.
At least one of these (CVE-2025-24085) is being used by attackers in the wild.
https://support.apple.com/en-us/100100