Posts
2963
Following
697
Followers
1542
"I'm interested in all kinds of astronomy."
repeated

wild how the media has fully given up on using the word “lie” as powerful people just bullshit constantly

it’s always “contradicted earlier statements” or “made claims that do not align with the facts” like girl just say they knowingly made shit up, we all see it

1
10
0
@molly0xfff also, this reply captures the X vibe perfectly:
3
0
12
Edited 9 months ago
This "analysis" by Wallarm - claiming active exploitation of CVE-2025-24813 Tomcat RCE - is wrong in multiple ways (maybe LLM slop?):

https://web.archive.org/web/20250314071219/https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/

There is a PoC on GitHub too now - it improves my findings by directly invoking the session corresponding to the saved object so you don't have to wait for periodic refreshes:

https://github.com/iSee857/CVE-2025-24813-PoC/

This PoC will raise the EPSS score too.

Edit: Wallarm published an update showing that exploit traffic was detected before a PoC was public. Problem is my writeup&PoC was published well before their detection :P
0
2
9
repeated

In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released/

1
5
1
repeated
@molly0xfff Her query may also have non-linear complexity, 60k rows is nothing.
3
0
2
repeated

Kompromisse 🙂

0
5
0
repeated

🚀 We’re working on a new user interface for http://draw.io! 🎨 Check out the details here 👉 https://github.com/jgraph/drawio/discussions/4953 — and let us know what you think! Your feedback will help shape the future of http://draw.io! 💡😊

0
1
0
repeated

Cool stuff for sale on Ebay! "1216428-301 Lockheed Martin Target ECM Combiner Circuit Card Assembly"

https://www.ebay.com/itm/203918329141

1
2
0
repeated

I take it that there are no rules for being a CVE CNA?
Synology is a CNA.
They published a security advisory.
No CVE to be found.

3
3
0
@kagihq @mellow I also switched recently and was curious how kids passwords will be handled. I think the parent e-mail OTP is a great balance between security and usability, it seems you did think this through 👌
0
0
0
@Some_Emo_Chick Wait, I literally heard this argument yesterday but sampled in an old EDM track o.O Will try to dig it up from history...
0
0
1
repeated

“There is significant public interest in knowing when and on what basis the UK government believes that it can compel a private company to undermine the privacy and security of its customers.”

ORG, Big Brother Watch and Index on Censorship call for the Tribunal into the UK government's secret order for Apple to break encryption to be held in public.

The case happens TOMORROW.

Read more ⬇️

https://techcrunch.com/2025/03/13/apples-appeal-against-uks-secret-icloud-backdoor-order-must-be-held-in-public-rights-groups-urge/

1
6
0
Edited 9 months ago
Representing type lattices compactly

https://bernsteinbear.com/blog/lattice-bitset/

"The Cinder JIT compiler does some cool stuff with how they represent types so I’m going to share it with you here. "

("Cinder is Meta's internal performance-oriented production version of CPython.")

/via exploits.club
0
0
2
@wdormann On a more serious note setting a hard deadline for publication can do wonders to the pipeline IME.
0
0
2
@wdormann Just repost your original report to FD, if MSRC can't repro without a video I'm sure bad guys can get no value from it either.
1
0
6
repeated

"Don't make vulnerability reporters angry" is not high on anybody's list, it seems.

5
2
0
repeated

We value your opinion! Please respond to our:

“CVE Data Usage and Satisfaction Survey”
https://forms.office.com/g/hx168RPctg

The CVE Program is requesting feedback from:
* CVE consumers
* Defenders

0
2
0
Show older