The two #curl CVEs we publish today are both rated medium and affect QUIC connections when curl is built to use wolfSSL
Hiroki Kurosawa reported both and he is rewarded 2540 USD for each from the curl bug-bounty.
With these two, the total bug-bounty payout from #curl now exceeds 90,000 USD over the last few years.
https://curl.se/docs/bugbounty.html
(thanks to IBB for sponsoring our bug-bounty program!)
The WAPBackMachine works! There are lots of WAP sites in the waybackmachine. It seems that the WBM crawler actually followed links on WAP sites, despite them not being HTML, which means that there is a lot to find if you know where to look!
This is hilarious 😅
A #SouthPark episode got aired with Russian dub "accidentally" in Hungary
Spent way too long figuring out why a payload wouldn't work.
Given the recent data breach and Coinbase’s user agreement that aims to force customers into arbitration rather than individual or class action lawsuits, it’s interesting to read the outcome of a recent arbitration case against Coinbase.
https://www.courtlistener.com/docket/69741499/1/coinbase-inc-v-spilker/
Five of CISA’s six operational divisions and six of its 10 regional offices will have lost top leaders by the end of the month, the agency’s new deputy director, Madhu Gottumukkala, informed employees in an email on Thursday.
https://www.cybersecuritydive.com/news/cisa-senior-official-departures/748992/
On May 20th 2025 a BGP message was propagated that triggered some surprising (to many) behaviors with two major BGP implementations that are often used for carrying internet traffic.
In a new blog post, I will dissect what that message was, and my thoughts on how it happened:
https://blog.benjojo.co.uk/post/bgp-attr-40-junos-arista-session-reset-incident
The DWARF debug format is well-known for debugging executables,
but it is also an effective format for sharing reverse engineering information
across various tools, such as IDA, BinaryNinja, Ghidra, and Radare2.
In this blog post, I introduce a new high-level API in LIEF that allows the
creation of DWARF files. Additionally, I present two plugins designed to export
program information from Ghidra and BinaryNinja into a DWARF file.
https://lief.re/blog/2025-05-27-dwarf-editor/
(Bonus: The blog post includes a DWARF file detailing my reverse engineering work on DroidGuard)
@morgann
> Privacy: DRM saves the day
was not a headline i expected to read
Defcon forums have to be RCE’d once a year, I don’t make the rules!
https://chaos.social/@christopherkunz/114579265339897261