Our CfP is open for only one more week! Do you have a wonderful creation, an art installation, a workshop or a hack that you would like to give a stage? Here is your chance!
https://cfp.why2025.org
@thezdi Fixes for @manf 's Firefox exploit and the one from yesterday have been released
https://www.mozilla.org/en-US/firefox/138.0.4/releasenotes/
https://blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025/
Frida 17 is out 🎉
https://frida.re/news/2025/05/17/frida-17-0-0-released/
a motherboard from my now-previous laptop doesn't boot; the LED blink sequence decodes to "BIOS flash failure". first of all what the heck? that never happens (but the symptoms when it died were consistent with it happening)
anyway, it uses plain SPI, and #GlasgowInterfaceExplorer can now analyze SPI transactions very easily
let's find out
Escaping US Tech Giants Leads European YouTuber to Open Source
https://hackaday.com/2025/05/17/escaping-us-tech-giants-leads-european-youtuber-to-open-source/
A programming language that resembled magical circles.
docs: https://suberic.net/~dmm/projects/mystical/README.html
All sigils: https://suberic.net/~dmm/projects/mystical/docs/operators.html
by @yomikoma
Them: The real threat to reliability is all this complexity in our system!
Me: Wait, so those corrective actions that you proposed in the wake of that last incident, would they *reduce* complexity or *increase* it?
Them: …
Me: …
Pwn2Own Berlin 2025 comes to a close. We awarded $1,078,750 for 28 unique 0-days. Congrats to STAR Labs SG for winning Master of Pwn with $320,000. Thanks to @offensive_con for hosting, and thanks to all who participated. Can't wait to see you next year! #Pwn2Own #P2OBerlin
GLIBC-SA-2025-0002: CVE-2025-4802: glibc: elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH https://www.openwall.com/lists/oss-security/2025/05/17/2
Affects statically linked setuid binaries that call dlopen, including internally to glibc after setlocale or NSS functions such as getaddrinfo
Wrapping up Day Two of #Pwn2Own Berlin 2025. We’ve awarded $695,000 for 20 unique 0-days, with one more day to go!
Dear #Letsencrypt, you helped secure millions and millions of servers, not just web servers. But your announcement at https://letsencrypt.org/2025/05/14/ending-tls-client-authentication/ about ending Ending TLS Client Authentication Certificate Support in 2026 because Google changes their requirements would result in your certificates being unusable for SMTP servers. You are literally risking an email collapse for many mailserver owners just to please Google? Please think again. Please.