Posts
2962
Following
697
Followers
1542
"I'm interested in all kinds of astronomy."
repeated

We're programmers. Programmers are, in their hearts, architects, and the first thing they want to do when they get to a site is to bulldoze the place flat and build something grand. We're not excited by incremental renovation: tinkering, improving, planting flower beds.

— Joel Spolsky

1
1
0
repeated

Hello and welcome to this week's installment of !

The guest of today is the TIBPAL16R4 by TI, a programmable array logic chip made with bipolar logic. The die has 2 metal layers, its maskwork produced in 1985. A short thread follows.

More info and hi-res pano at: https://siliconpr0n.org/archive/doku.php?id=infosecdj:ti:tibpal16r4

3
6
0
repeated

It’s disheartening to see AI reactionism lead my community to a 180° on copyright.

Everyone is merrily attacking LibGen now. If it didn’t exist, big tech companies would still find training data, it just wouldn’t be accessible to regular people.

3
9
0
Edited 9 months ago
[RSS] Discourse Backup Disclosure: Rails/nginx send_file Quirk

https://projectdiscovery.io/blog/discourse-backup-disclosure-rails-send_file-quirk

This is CVE-2024-53991
0
1
2
[RSS] Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses

https://swarm.ptsecurity.com/last-barrier-destroyed-or-compromise-of-fuse-encryption-key-for-intel-security-fuses/
0
3
2
repeated

TIL of the bad.horse traceroute

4
10
1
repeated

Rejoice! 🎉

My idalib-based vulnerability research tools are now fully compatible with Windows 🪟

Please test them and report any bugs 🪲

https://security.humanativaspa.it/streamlining-vulnerability-research-with-ida-pro-and-rust/

(PS. Ya like my GPT writing style? 🚀)

0
3
0
repeated
repeated

she is all of us

8
7
0
repeated
repeated

Ryan Castellucci (they/them) nonbinary_flag

"But Ryan, the C preprocessor isn't a programming language!"

Skill issue.

1
6
1
repeated

Lorenzo Franceschi-Bicchierai

The official website of zero-day broker Zerodium has been updated in December of last year. There are no price lists nor any information anymore, just an email and a PGP public key.

🤔

If you know what's happening there...let me know.

https://zerodium.com

2
2
0
@cR0w something something Steven Segal?
0
0
2
repeated

Project Zero Bot

New Project Zero issue:

msm_npu: Race between npu_host_unload_network and npu_host_exec_network_v2 leads to memory corruption

https://project-zero.issues.chromium.org/issues/380081941

CVE-2025-21424
0
1
0
[oss-security] [kubernetes] CVE-2024-7598: Network restriction bypass via race condition during namespace termination

https://seclists.org/oss-sec/2025/q1/234

"The order in which objects are deleted
during namespace termination is not defined, and it is possible for network
policies to be deleted before the pods that they protect." whoops :)
0
0
1
@nbourdais @cR0w @greynoise It'd be actually interesting to see the distribution of HTTP response codes if that data is collected, because it is a straightforward signal for one of the requirements (read-only=false).
0
0
1
@mcc @oblomov This sounds fun, you should get some VC funding!
0
0
1
@cR0w @greynoise "GreyNoise observed exploitation attempts as early as March 11" -> Please note that PoC was publicly available since that way:

https://scrapco.de/blog/analysis-of-cve-2025-24813-apache-tomcat-path-equivalence-rce.html

Also note that even with HTTP response data it's not straightforward to conclude that:
- file based session management was configured
- there were useful gadget chains available
1
1
2
@oblomov @mcc VibeLang? As in execution order depends on how the interpreter feels and all errors are handled somehow just to keep the thing going :)
1
1
1
Up-to-date fork of Sourcetrail:

https://github.com/petermost/Sourcetrail

h/t @brk
0
2
1
Show older