Posts
2727
Following
681
Followers
1505
"I'm interested in all kinds of astronomy."
repeated

Our Windows CTF is coming to Nullcon in Berlin, Sept 4-5 🎯 https://github.com/eshard/TTA-CTF

Play for a chance to win a Binary Ninja license or a Flipper Zero.

0
2
0
repeated

There is a new short domain name for !

https://putty.software/

At present, this is just a "landing page": a nice short name to remember, which will redirect you to the full PuTTY website at the same longer URL where it's always been.

But unlike putty.org or other third-party landing pages, this one is run by us, the actual PuTTY team, and it doesn't have a weird separate agenda of its own.

I intend to move the main PuTTY site over to that domain in the future, and leave just a redirector at the old location. But first I want to get the word out, so that people know which site to trust.

If anyone is still linking to putty.org, here's a place to link to instead. Please spread the word!

3
46
1
Edited 3 months ago
1
3
4
The mess we're in - Lack of downstream fixes in fdk-aac-free AAC media codec:

https://www.openwall.com/lists/oss-security/2025/08/13/9

#FOSS #supplychain
0
1
2
repeated

“Head, shoulders, knees and toes.”

Went from being a fun little kids song to a list of things that hurt.

5
11
0
As much as I despise Spotify's business model getting incredibly good music I'd have never known thrown to my stream constantly is mind-blowing!
1
0
0
repeated

In case I know anyone here who's familiar with the finer details of DNS and particularly DNS amplification attacks and their mitigations, I have some questions.

1
4
0
[RSS] Function-level Basic Block Analysis [in Binary Ninja]

https://binary.ninja/2025/08/12/function-level-basic-block-analysis.html
0
0
3
repeated

Somehow landed on the NetBSD manpage of sleep(1) and they seem to have a rather unique take on what is considered a bug.

6
37
3
repeated

🚨Alleged Sale of Fortinet 0-Day RCE Exploit

• Industry: N/A
• Threat Actor: WISDOM
• Network: Clearnet, Dark Web
• Price: 0.5 BTC

• Details: A threat actor claims to be selling a 0-day remote code execution (RCE) exploit affecting FortiOS VPN versions 7.4 to 7.6. The listing includes a proof of concept (PoC) available to serious buyers with deposit or established reputation.

0
1
0
repeated

I edited my Cross-Site Request Forgery countermeasures research into a stand-alone article, including recommendations reusable by other projects.

tl;dr: no need for tokens or keys, modern browsers tell you if a request is cross-origin!

https://words.filippo.io/csrf?source=Mastodon

1
3
0
repeated
[RSS] From Support Ticket to Zero Day (CVE-2025-8356, CVE-2025-8355 - Xerox FreeFlow Core)

https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/
0
0
0
repeated
repeated

Here's the full writeup of CVE-2025-53773 - Visual Studio & Copilot – Wormable Command Execution via Prompt Injection: https://www.persistent-security.net/post/part-iii-vscode-copilot-wormable-command-execution-via-prompt-injection

Patch now!

1
4
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

I had a great time at the most excellent camp! Here a write-up of my own talks (with links to video & annotated slides), some observations on the tremendously terrible state of security & regulation, and what we could do about it, plus some nice photos!
https://berthub.eu/articles/posts/dna-talks-and-why2025/

1
1
0
Edited 3 months ago
#music
Show content
TIL Amyl and the Sniffers are on Bandcamp, and there goes my allowance...

https://amylandthesniffers.bandcamp.com/
0
0
1
repeated

2001: A Spaced-Out Odyssey (24)

Frame 146,183 of 207,800

0
2
0
Aside of the awesome diagrams that Mermaid.js can generate I'd like to highlight this script that is really helpful when you want to figure out how #decompiler represents different pieces of code:

https://github.com/v-p-b/ghidra-cheat-sheet/blob/main/scripts/dump_clang.py

Sample output:

https://scrapco.de/ghidra-cheat-sheet/decompiler/structure_samples/
0
0
2
To prevent further frustration from forgotten tricks I brain dumped the less-than-obvious stuff that I can remember from #Ghidra development in my brand new Ghidra Dev Cheat Sheet:

https://scrapco.de/ghidra-cheat-sheet/

PR's and suggestions are most welcome!
1
2
3
Show older