Posts
2502
Following
651
Followers
1473
"I'm interested in all kinds of astronomy."
"[Qualys] discovered a vulnerability in apport [...], and a similar vulnerability in systemd-coredump [...]: a race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump"

https://www.openwall.com/lists/oss-security/2025/05/29/3

CVE-2025-5054 CVE-2025-4598
0
7
5
repeated

Google’s search quality has declined, filled with spam and low-quality results, while it maintains dominance through default placements. Cory Doctorow highlights Kagi as a superior alternative, offering cleaner, more relevant search outcomes. Though it requires a subscription, Kagi provides a user-focused experience that recaptures the efficiency Google once had.

I personally HAPPILY pay for @kagihq.

https://pluralistic.net/2024/04/04/teach-me-how-to-shruggie/#kagi

0
3
0
repeated

SentinelOne still down, approaching three hours. It doesn’t look like they have an official status page so https://sentinelonestatus.com/ is all ya got.

3
2
0
@mcc mathcore/math rock? E.g.: https://www.youtube.com/watch?v=D4-erceTpc8

Edit: or simply Tool...
0
0
0
repeated
New assessment for topic: CVE-2025-41232

Topic description: "Spring Security Aspects may not correctly locate method security annotations on private methods ..."

"On May 19 2025, Spring released an [advisory](https://spring.io/security/cve-2025-41232) warning that Spring Security versions before `6.4.6` were vulnerable to a flaw in how Spring security annotations were identified and processed, that could lead to annotations being ignored on private methods, potentially leading to authorization bypasses on those private methods ..."

Link: https://attackerkb.com/assessments/c3734c78-c018-4e5f-9c70-b5f3c074a411
0
1
0
[RSS] Micropatches Released for Preauth DoS on Windows Deployment Service (CVE-2025-29957)

https://blog.0patch.com/2025/05/micropatches-released-for-preauth-dos.html
0
0
1
repeated

Good bathroom reads.

0
2
1
repeated
Edited 2 months ago

Unfortunately the wiki is very slow today. We are fighting an aggressive web scraper bot. 10,000 of IPs involved. Randomised User-Agent. Ignoring robots.txt

Update: Fixed. We've been able to mitigate the bot traffic.

8
12
0
@nicemicro Yes I also have concerns about how restrictions could be implemented in practice.

Thank you, it's good to see that civilized arguments are still possible online!
0
0
1
@david_chisnall @kenshirriff Just for the record, I find this part of AS/400 history pretty fascinating (from Inside AS/400, by Frank Soltis) :)
0
0
5
@psa @algernon I'm not fully confident that an 8 years old codebase can handle todays mess on the web...
1
0
0
@algernon Are you aware of any recursive mirroring tools? My searches so far only turned up wget (which is severely limited) and ArchiveBox (that doesn't support full mirrors either) :(
3
2
1
@algernon Does Readeck support full domain mirroring? I can't seem to find a definite answer...
1
0
0
repeated

You don't normally pay someone $300M for a "partnership." This is xAI buying access to Telegram's users because it sees their (purportedly secure and private) data and interactions as valuable. https://www.bbc.com/news/articles/cdxvr3n7wlxo

Delete it.

1
4
0
repeated

Looks like @bluehatil talks are online now, so here’s my talk for anyone who wanted to learn about the latest episode of KASLR and couldn’t make it: https://youtu.be/Dk2rLO2LC6I

8
4
0
@david_chisnall @lauriewired @kenshirriff I didn't mean offense towards CHERI (or IBM i), I find all of these concepts really interesting even if some of them didn't turn out to be widely adopted or even useful.
1
0
2
Show older