Posts
2469
Following
660
Followers
1482
"I'm interested in all kinds of astronomy."
repeated

I had missed this discussion about

[RFC] Add a prctl to disable ".." traversal in path resolution

https://lore.kernel.org/linux-fsdevel/20241211142929.247692-1-mjg59@srcf.ucam.org/T/#u

1
2
0
Edited 13 days ago
1
1
1
I combined DEVCORE's CVE-2024-35250 with the CVE-2024-30084 double fetch bug and the Cloud Filter memory trap technique by @tiraniddo to achieve reliable LPE without device requirements on Win10 VMs.

https://scrapco.de/blog/its-a-trap-reliable-exploitation-of-cve-2024-30084.html
1
10
9
repeated
mutual aid request
Show content

I've been bedridden for nine months, and I'm only now getting a surgeon lined up to fix this.
If you could send a couple dollars, it'd really help. Time isn't on my side here, and waiting is very expensive.

https://ko-fi.com/fooneturing

0
7
0
repeated
Edited 18 days ago

checking whether the C compiler works... no

Understandable, have a nice weekend

3
8
2
repeated

The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting. So I wrote a blog post about it

An absolutely ridiculous amount of open source is one person projects. I have the data to prove it

https://opensourcesecurity.io/2025/08-oss-one-person/

7
20
0
repeated

Cisco Talos just disclosed vulnerabilities in Libbiosig, Tenda routers, SAIL image library, PDF-XChange, and Foxit Reader — all now patched by vendors: https://blog.talosintelligence.com/libbiosig-tenda-sail-pdf-xchange-foxit-vulnerabilities/

0
1
0
repeated

This page intentionally left blank

0
2
1
re: Mention of suicide
Show content
@schrotthaufen Most likely. It's the first time I saw the actual crap it produced (in the published court docs) and I'm outraged.
1
0
0
"Our safeguards work **more reliably** in **common**, **short** exchanges. We have learned over time that these safeguards can **sometimes** be **less reliable** in **long** interactions: as the back-and-forth grows, **parts** of the model’s safety training **may** degrade."
0
0
0
Look at the rate of weasel wording in OpenAI's not-really-apology:

https://openai.com/index/helping-people-when-they-need-it-most/

I'm sick and tired of people pretending they have ways to enforce LLM behavior, while all they do is weigh dices differently - they remain dices.

Trying to enforce security boundaries with a PRNG is one thing, but you definitely can't prevent reinforcing harmful behavior, because you can't even define what it is.

And this can cost lives, as we just witnessed.
2
1
2
repeated
Edited 14 days ago

The CEO of Open AI should be tried for accessory to murder -- OpenAI responds to ChatGPT helping a teen commit suicide

What a load of goddamned CRAP:

https://openai.com/index/helping-people-when-they-need-it-most/

1
3
0
repeated
repeated

🇪🇺 Brussels speaks clearly. @EU_Commission confirmed to us: The is non-negotiable, not even as part of trade talks with Donald Trump.

💪 We welcome the EC’s reaffirmation of its commitment to neutral, robust, and evidence-based enforcement of the . But we call on the Commissioners to strengthen enforcement and make sure gatekeepers cannot get away with circumventing the law.

👉 Read the Commission’s reply: https://edri.org/wp-content/uploads/2025/08/European-Commission-response-on-US-influence-in-DMA-enforcement.pdf

1
7
1
repeated

@davidgerard We have a client with a working/useful computer vision product... and the word AI doesn't appear on their website because they presumably don't want to seem like grifters

Everything is backwards

0
1
1
repeated

"Will WebClient Start"

This awesome blog post by Steven Flores, with SpectorOps, tries to answer a question I had too: "Is it possible to start the WebClient service remotely as a low-priv user?"

Very interesting read. The article walks you through the entire thought process and tackles various Windows internals. And even if the result may seem underwhelming, it lays the ground for others to try and take on this challenge. 😉

👉 https://specterops.io/blog/2025/08/19/will-webclient-start/

0
3
0
repeated

SMAP is coming to Windows

1
2
0
[RSS] The One Where We Just Steal The Vulnerabilities (CrushFTP CVE-2025-54309) - watchTowr Labs

https://labs.watchtowr.com/the-one-where-we-just-steal-the-vulnerabilities-crushftp-cve-2025-54309
0
0
1
Show older