Posts
3373
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated
repeated

Writing these words from the first Linux kernel ever booted on x86_64 by a pure Go UEFI bootloader!

Pro debugging technique: listening to CPU noises to attest boot flow progress while Frame Buffer issues made everything dark 😅.

1
6
1
repeated

🔥 The "impossible" XXE in PHP? Not so impossible anymore.

Our researcher Aleksandr Zhurnakov discovered an interesting combination of PHP wrappers and a feature of XML parsing in libxml2 to exploit it.

Read: https://swarm.ptsecurity.com/impossible-xxe-in-php/

0
5
0
repeated

My mom accidentally referred to cryptocurrency as “kleptocurrency” this morning and I think I’m going to call it that from now on! 🤑

7
13
0
repeated

has discovered a zero day exploit abusing -2025-24983 vulnerability in the Windows kernel 🪟 to elevate privileges (). First seen in the wild in March 2023, the exploit was deployed through backdoor on the compromised machines.

The exploit targets Windows 8.1 and Server 2012 R2. The vulnerability affects OSes released before Windows 10 build 1809, including still supported Windows Server 2016. It does not affect more recent Windows OSes such as Windows 11.

The vulnerability is a use after free in Win32k driver. In a certain scenario achieved using the API, the structure gets dereferenced one more time than it should, causing UAF. To reach the vulnerability, a race condition must be won.

The patches were released today. Microsoft advisory with security update details is available here:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24983

0
6
0
repeated

10x the speed and half the memory usage by migrating the TypeScript compiler from TS to Go isn't exactly a ringing TypeScript endorsement.

https://devblogs.microsoft.com/typescript/typescript-native-port/

2
5
1
The only reasonable reaction to this is to unfollow ofc
0
0
6
[RSS] Detecting and Mitigating the Apache Camel Vulnerability CVE-2025-27636

https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations
0
1
5
The Tomcat RCE is pretty fun, fortunately requirements look quite unusual. I'll write this up soonish, but first I have some hardware to fix...
0
0
5
@ra6bit IME pentest can facilitate those things, e.g. I think every pentester has a story when the clients first inventory was compiled because it was needed for pentest scoping. Ofc this is far from ideal, but at least drives things in the right direction
0
0
1
re: uspol
Show content
@wdormann signed, Dwayne Elizondo Mountain Dew Herbert Camacho
0
0
4
repeated

A study of eight AI search engines found they provided incorrect citations of news articles in 60%+ of queries; Grok 3 answered 94% of the queries incorrectly (Columbia Journalism Review)

https://www.cjr.org/tow_center/we-compared-eight-ai-search-engines-theyre-all-bad-at-citing-news.php
http://www.techmeme.com/250310/p28#a250310p28

0
3
0
repeated

Now, I have a little problem: I cannot play it because I don't have a vinyl player anymore since ::checks clock:: the last 2 decades.

Can you recommend me some modern vinyl player with, potentially, USB and Bluetooth support?

0
1
1
repeated
repeated

Still 38 hours left before the WOOT deadline. Who needs tier 1 confs with the inevitable complaints from reviewer 2 who just wishes the hackers would go away? Submit your papers full of fun hacks, chaos and hijinks to the bestest offensive security academic conference and get reviews from people who really appreciate it!

(also pls boost for reach, targeting academics on social media got a lot trickier in this fragmented world 😢)
https://infosec.exchange/@wootsecurity/114140304168415477

0
7
0
Edited 11 months ago
This is the fix commit for CVE-2025-24813, looks pretty straightforward:

https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c

Given Tomcat's downstream supply chain I'd be surprised if this didn't end up in KEV...
1
0
3
Show older