Posts
2711
Following
681
Followers
1505
"I'm interested in all kinds of astronomy."
repeated

What year is this?!
I think I am taking crazy pills!
FWIW: The first ever vulnerability I reported to a vendor was a DNS cache poisoning attack against BIND due its use of predictable query IDs.
I reported it.... in 1996!

https://arstechnica.com/security/2025/10/bind-warns-of-bugs-that-could-bring-dns-cache-attack-back-from-the-dead/

4
6
0
repeated

@evacide

The replies to your posts since the AWS outage have been an amazing source of 'Signal has a flaw and therefore we should ignore the dozens of fundamental design flaws in {other thing} and use it instead' posts.

The mindset of 'X is not perfect, therefore we should use Y, which is strictly worse in almost every way but lacks this one problem of X' never ceases to amaze me.

0
2
0
repeated

Miss anything from Day 2 of Ireland 2025? Join @TheDustinChilds as he recaps what happened and covers some of the highlights of the event.
https://youtu.be/Xz7jjz6xIic

0
2
0
repeated

@remixtures

This follows the Silicon Valley model popularised by Facebook 20 years ago of opting people into consent for things op because they were in other people’s address books and those people consented to sharing personal information. It’s a shame it took regulators so long to stamp on that, it should have been the result of massive fines, possibly followed by fire.

0
3
0
repeated

RT @ednewtonrex
Wait… so users of OpenAI’s Atlas browser can opt-in the web pages they browse - *which belong to other people* - to AI training?

Cool cool

https://openai.com/index/introducing-chatgpt-atlas/

1
2
0
repeated

If you know who did this, or if you know how to set it back, the hotel kindly asks you to do so, respecting the fun achievement unlocked :)
https://infosec.exchange/@xme/115422139879568495

1
3
1
repeated

The new, slightly less patient, Daniel strikes.

11
7
1
repeated

every AI generated pixel, every AI generated token I see makes me want to use the internet less. it makes me want to log off and spend the rest of my days reading books published before 2020. this must be how the paranoid creatives felt in the 2000s when cross-site tracking and the patriot act also pushed them offline. this must be how those creatives who refused to give up their own methods of distribution felt when things like facebook and twitter and youtube monopolized attention through the 2010s and turned the internet into a small collection of walled gardens. I don't know what kind of creative you'd call me, but I cannot abide by the internet being polluted by mushy, merely-probable junk data which is drowning out what had once been a place to find real testimony, real human effort and art whose maxim is to bridge the gap between us. sure there will always be oases, places where human creativity continues to thrive, but I'll forever miss when the entire land was covered in green.

1
5
1
repeated
@da_667 use more sacred oils and incense
0
0
3
repeated

this story is crazy not because someone in the exploit business got a taste of their own medicine, that part should be expected. the crazy thing is that trenchant, widely considered to be one of the “good discerning western exploit shops” was leaking chrome exploits to who knows where.
https://infosec.exchange/@lorenzofb/115412729875549507

1
1
0
repeated

Boom! Rafal Goryl of PixiePoint Security needed two attempts but was able to get his exploit of the Phillips Hue Bridge working. He heads off to the disclosure room to provide all the details.

0
2
0
repeated

You can find all of the results from Day Two of Ireland at https://www.zerodayinitiative.com/blog/2025/10/22/pwn2own-ireland-2025-day-two-results - We'll be updating this blog throughout the day as results become available.

0
2
0
repeated

The new version of the Sanitizer API is now enabled by default in @firefoxnightly!

https://developer.mozilla.org/en-US/docs/Web/API/Sanitizer
https://wicg.github.io/sanitizer-api/

Please give it a try and provide us with feedback.

0
3
0
repeated

OpenAI browser uses Mojo JS bindings, cool implementation.

0
1
0
[RSS] IBM i LIBL Autopwn: Kill the Vulnerability Class

https://blog.silentsignal.eu/2025/10/22/IBM-i-LIBL-Autopwn-Kill-the-Vulnerability-Class/

#IBMi exploits go brrr
0
0
0
repeated

Recapping Day One of Ireland 2025. Join @dustin_childs (and Maude) as he covers the highlights of the first day of the competition. We awarded $522,500 for 34 unique 0-day bugs, and more is to come. https://youtu.be/tiM_StSFvow

0
2
0
repeated

The schedule for r2con2025 is out!
It's online, plenty of awesome talks.

https://radare.org/con/2025/

0
3
0
Show older