Posts
3587
Following
723
Followers
1589
"I'm interested in all kinds of astronomy."
repeated

TrendAI Zero Day Initiative

Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing: Trend ZDI researcher Simon Zuckerbraun shows how to go from a crash to a full exploit - & he provides you tools to do the same, including his technique used to get ROP execution. https://www.zerodayinitiative.com/blog/2025/10/6/crafting-a-full-exploit-rce-from-a-crash-in-autodesk-revit-rfa-file-parsing

0
2
0
repeated

Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984) https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984

0
4
0
repeated

We just posted our AttackerKB @rapid7 Analysis for the recent Cisco ASA 0day chain; CVE-2025-20362 and CVE-2025-20333. The auth bypass appears to be a patch bypass of an older 2018 vuln. The buffer overflow is in a Lua endpoint, but unsafe native code operations allow a buffer to be overflowed and memory corruption to occur. Full technical root cause analysis here: https://attackerkb.com/topics/Szq5u0xgUX/cve-2025-20362/rapid7-analysis

1
5
0
[RSS] iOS emulation for security research -- early access now open

https://u.eshard.com/ios-emulator
0
0
1
[RSS] Remembering the end of support for VRML in Internet Explorer

https://devblogs.microsoft.com/oldnewthing/20251007-00/?p=111657
0
0
1
repeated
repeated

I wonder if Microsoft secretly wants everyone to switch to Linux. There are certainly fewer reasons to stick to Windows every day: https://www.theverge.com/news/793579/microsoft-windows-11-local-account-bypass-workaround-changes

10
8
1
@TarkabarkaHolgy lawful evil calls disease control and puts the whole school under quarantine
1
0
2
repeated

I am constantly feeling like parents have to take daily Alignment checks during Autumn Snot Season. Checks are administered by daycare/school staff.

I'm gonna need an alignment chart for this 😄

4
2
1
repeated
repeated

I love people saying AI helps with the bullshit stuff. Nobody asking why the bullshit exists in first place and how to get rid of it LOL

0
1
0
@neurovagrant "But not as fun" -> No kink shaming plz!
0
0
2
Edited 5 months ago
DiffRays - IDA Pro Binary Diffing Engine

https://github.com/pwnfuzz/diffrays
0
0
2
[RSS] Lucid Dreams I: Lucid's First Time #Fuzzing

https://h0mbre.github.io/Lucid_Dreams_1/
0
0
1
repeated

Remember the old days?

Why aren't today's routers made out of wood?

8
4
0
repeated

📣 Germany's close to reversing its opposition to mass surveillance & private message scanning, & backing the Chat Control bill. This could end private comms-& Signal-in the EU.

Time's short and they're counting on obscurity: please let German politicians know how horrifying their reversal would be.

7
21
1
repeated
repeated
Show older