Biting the CHERI bullet: Blockers, Enablers and Security Implications of CHERI in Defence
An analysis of CVE-2024-44236 - an RCE in macOS due to the lack of proper validation of “lutAToBType” and “lutBToAType” tag types. Read the details, see the source code review, and get detection guidance at https://www.zerodayinitiative.com/blog/2025/5/7/cve-2024-44236-remote-code-execution-vulnerability-in-apple-macos
Get your macOS 15.4 xnu CodeQL database here! 👩🔬
Also NOW includin the compile_commands.json 🎉
(I also wrote a util for converting the paths github.com/blacktop/ccpaths)
`ccpaths JSON /Users/runner/work/darwin-xnu-build/darwin-xnu-build /path/to/your/xnu`
https://github.com/blacktop/darwin-xnu-build/releases/tag/v15.4
I've been experimenting with improving Binary Ninja's analysis of Objective-C code recently. Having the ability to hide Obj-C runtime reference counting calls, and apply type information based on [super init] and objc_alloc_init calls can dramatically improve the readability (and in some cases even accuracy!) of the decompiled code.
VMware Perpetual License Holders Receive Cease-And-Desist Letters From Broadcom https://yro.slashdot.org/story/25/05/07/1856255/vmware-perpetual-license-holders-receive-cease-and-desist-letters-from-broadcom?utm_source=rss1.0mainlinkanon
only FOUR DAYS left in our spring tea party coding event!
help create a template, theme, or layout for new and seasoned website owners to create their own websites easily!
submissions close may 11!~
#webdev #smallweb #indieweb #codejam #web #webdesign #handmadeweb #coding #codingisart #html #css #internet #neocities #nekoweb #website #personalwebsite #openinternet #foss #opensource
For context: just three days ago CrowdStrike said it delivered "record full year operating cash flow of $1.38 billion and record full year free cash flow of $1.07 billion."
And CEO George Kurtz made $46 million last year.
https://aflcio.org/paywatch/CRWD & https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-reports-fourth-quarter-and-fiscal-year-2025
I’m sorry, but Facebook did more harm to humankind than all NSO-alike spyware vendors of the world altogether. You are fighting into the wrong direction
Next Thursday, May 15 at @NorthSec in Montreal, I will be hosting the workshop "Reconstructing Rust Types: A Practical Guide for Reverse Engineers"! This will be a 3-hour workshop how to approach Rust types and data structures when reversing Rust binaries. See https://nsec.io/session/2025-reconstructing-rust-types-a-practical-guide-for-reverse-engineers.html for more details!
Workshops at NorthSec will be streamed on YouTube Live. My workshop is scheduled for 1300-1600 EDT (UTC-4) on Thursday, May 15 in the Workshop 2 track, in Salle de la Commune. The stream link for all the Thursday Salle de la Commune workshops is here: https://www.youtube.com/watch?v=UwJgS32Q6As&list=PLuUtcRxSUZUrW9scJZqhbiuTBwZBJ-Qic&index=7
Looking forward to seeing folks there! 🦀
(Edited since I can't count days of the week apparently: May 15, which is when my workshop is occurring, is a Thursday, not a Wednesday.)
#rustlang #ReverseEngineering #MalwareAnalysis #NorthSec #infosec #reversing