Posts
2582
Following
627
Followers
1397
"I'm interested in all kinds of astronomy."
repeated

Project Zero Bot

New Project Zero issue:

Linux >=4.12: USB CDC-ACM: missing size check in acm_ctrl_irq() leads to OOB write

https://project-zero.issues.chromium.org/issues/395107243

CVE-2025-21704
0
2
4
#test
Show content
5 images, let's see how bsky (and my x-poster) handles this...
0
0
0
repeated

Here's the paywall-free version of today's insane must-read: The Atlantic's Jeffrey Goldberg was added to a Signal chat including SECDEF, VPOTUS, and others that discussed the Houthi strikes. In addition to being illegal, it's just dumb. A foreign adversary's dream come true

https://archive.is/JEYep

1
4
0
repeated

@4ttil4sz1a @andreyknvl (and also provided those fixes back to Canonical, though I haven't tracked what was done with them). Crazy that the Linux CNA is issuing CVEs for unsigned crafted kernel modules (which can execute arbitrary code, modify arbitrary data) but not for things that have real exploits.

1
3
0
repeated

@4ttil4sz1a @andreyknvl Was that the reason the CVE got issued by Canonical instead? Our system saw it come through Feb 14th and was flagged as having no upstream commit (while recognizing it affected upstream), we backported Canonical's fix that day and also fixed 10 memory leaks the fix introduced

2
1
0
repeated
repeated

@mcc I mostly take the behaviour of AI scrapers as evidence that this style of machine learning is a form of violation. Like, whether or not it's philosophically or legally theft, AI companies are behaving more like smash-and-run robbers than anyone who believe they have a legitimate claim to the data they take (and take, and take and take...)

0
3
0
#test
Show content
0
3
7
#test
Show content
2
2
12
@freddy an exploit is an exploit (haven't tested it though)
0
0
0
"Safari 1day RCE Exploit, might be patched in iOS 16.5.1/macOS 13.4.1
Confirmed exploit works on macOS 13.3.1, iOS 15.8.2."

https://github.com/wh1te4ever/WebKit-Bug-256172
1
0
0
repeated

current status: scrawling "FUN JIT COMPILER PROBLEM" in sharpie on a big cardboard box, then putting it on my front lawn and seeing who jumps into it

https://www.mattkeeter.com/projects/prospero/

0
5
0
repeated
repeated

Valerie Aurora 🇺🇦

If you are trying to delete your 23andMe data and get an obnoxious reply asking for ID, tell them no, that's what your password is for, and they will do it. And if they then send you an obnoxious reply saying they will delete everything except the stuff they are required to keep by law, check out this article by actual lawyer @AugustB

https://bourniquelaw.com/2024/10/09/data-23-and-me/

0
20
0
[RSS] The case of the critical section that let multiple threads enter a block of code

https://devblogs.microsoft.com/oldnewthing/20250321-00/?p=110984
0
1
4
#music #metal
Show content
0
0
0
repeated

TIL that because the FFmpeg project has gained so much experience in hand-writing assembly code to provide huge speedups, they now are putting together a series of lessons for learning assembly:

Vibe coding is fun and all, but this is probably a better use of time!

https://github.com/FFmpeg/asm-lessons

4
25
0
repeated

We’re adding a new section to @elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our . Get more details here: https://go.es.io/4hdKQCI

0
2
0
repeated
Show older