Posts
2916
Following
693
Followers
1518
"I'm interested in all kinds of astronomy."
@kimzetter I didn't say you said that. The article have this line though:

"As federal agencies, *under the direction of DOGE*, continue to fire thousands of workers"

Also I read phrases like:
- "driven out"
- "pushed out"
- "sidelined" (in the Politico article)

I'm curious how this all looks in practice, incl. what formal authority DOGE has (e.g. can they formally direct agencies to do things?). Based on previous discussions my current understanding is that DOGE has no formal power, while people with actual power (e.g. management in agencies) make dumb decisions because DOGE looked them the wrong way.

I hope I am wrong. Based on the general quality of your reporting I hope you could explain the situation better or point me to some good resource.
1
0
0
@kimzetter could you EIL5 (or give link(s)) what DOGE specifically does to get ppl fired? AFAICT they can't make HR decisions on Pentagons behalf, right?
1
0
0
repeated

Cure53 πŸ³οΈβ€πŸŒˆ

Small change to HTML with massive impact on eliminating mXSS attacks

https://github.com/whatwg/html/commit/e21bd3b4a94bfdbc23d863128e0b207be9821a0f

0
3
0
repeated

...and now the video of my talk "Finding and Exploiting 20-year-old bugs in Web Browsers" is live too https://www.youtube.com/watch?v=U1kc7fcF5Ao

2
7
0
repeated

🚨 New advisory was just published! 🚨

Multiple vulnerabilities were discovered in Foscam X5. These vulnerabilities allow a remote attacker to trigger code execution vulnerabilities in the product: https://ssd-disclosure.com/ssd-advisory-multiple-foscam-x5-vulnerabilities/

0
2
0
repeated
Edited 5 months ago

We found a vulnerability in AMD CPUs that lets us load arbitrary microcode!
The recording of our OffensiveCon presentation is live at https://youtu.be/sUFDKTaCQEk
Slides at http://entrysign.top

0
3
0
[RSS] Telegram Gave Authorities Data on More than 20,000 Users

https://www.404media.co/telegram-gave-authorities-data-on-more-than-20-000-users/
0
0
1
[RSS] Remembering The ISP That David Bowie Ran For Eight Years

https://hackaday.com/2025/05/19/remembering-the-isp-that-david-bowie-ran-for-eight-years/
0
1
2
repeated

Discovery: The "copilot" bot user that Microsoft will soon be flooding your github repos with garbage content from is implemented in some sort of special way that exempts it from the "block" feature you would normally be able to block other users/bots with

https://github.com/orgs/community/discussions/159749

29
19
0
#EU reaction as OrbΓ‘n is about to kill independent press and civil society in #Hungary

https://youtu.be/UIPSvIz9NDs?si=Sbe2wHqsHkqPtjm6&t=40
0
0
0
repeated

Microsoft takes Windows Subsystem for Linux open source after nearly a decade
WSL has also recently added official support for both Fedora and Arch distros.
https://arstechnica.com/gadgets/2025/05/microsoft-takes-windows-subsystem-for-linux-open-source-after-nearly-a-decade/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

3
8
0
repeated

"Go Cryptography Security Audit" by Roland Shoemaker β€” https://go.dev/blog/tob-crypto-audit

0
3
0
CVE-2024-11182 also seems like a stored XSS: "attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag" - The '90s called and they want their webmail bugs back!!

RE: https://mastodon.social/@cisakevtracker/114535806650652126
0
0
1
I found that CVE-2024-27443 doesn't qualify for XSS Reflections as it seems to be a stored XSS. Pretty neat vuln though!

https://github.com/v-p-b/xss-reflections

RE: https://mastodon.social/@cisakevtracker/114535804613431399
0
0
1
@cR0w I wish I was ignorant enough to think these are exaggerations...
0
0
1
repeated

I have been following the INFOSEC industry and am ready to begin my startup. Any investors here interested? Here's my business plan.

6
2
0
[RSS] Security Bulletin: IBM i is vulnerable to a machine-in-the-middle attack due to mishandling error codes when verifying the host key by OpenSSH. [CVE-2025-26465]

https://www.ibm.com/support/pages/node/7233399?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSKWKM&mynp=OCSSC5L9&mynp=OCSSB23CE&mync=A&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSKWKM-OCSSC5L9-OCSSB23CE-_-A

#IBMi
0
0
0
repeated

Cure53 πŸ³οΈβ€πŸŒˆ

Edited 1 month ago

DOMPurify 3.2.6 has been released with several smaller fixes and improvements, thanks to all who contributed πŸ’•

https://github.com/cure53/DOMPurify/releases/tag/3.2.6

Hopefully this will also help with the CI/CD issues that arose after the fake CVE was posted last week.

0
3
0
Show older