Posts
2754
Following
681
Followers
1504
"I'm interested in all kinds of astronomy."
repeated

From bit flip to RCE in Ollama! 🦙

Our latest blog post explains how a file parsing bug led to an interesting out-of-bounds write primitive. Learn how it could have been exploited in Ollama, a tool to run LLMs locally:

https://www.sonarsource.com/blog/ollama-remote-code-execution-securing-the-code-that-runs-llms/?utm_medium=social&utm_source=twitter&utm_campaign=research&utm_content=blog-ollama-vuln-251104-&utm_term=---&s_category=Organic&s_source=Social%20Media&s_origin=social

1
6
0
repeated
repeated

OH: "You're in his DMs. I'm in his VMs. We're not the same."

1
8
0
repeated
@tmr232 See also Anthropics latest about putting an MCP in your MCP, aka. "innovation, bitches!": https://www.anthropic.com/engineering/code-execution-with-mcp
0
0
1
@tmr232 @joxean Infact I'm playing with it rn because tree-sitter query CLI doesn't seem to support structured output...
1
0
0
@joxean Oh OK, I'm still learning, but this usually accumulates in some tips&tricks so I'll keep that in mind!
1
0
0
On the other hand ast-grep's pattern/rule syntax is **not** compatible with Semgrep's :(
1
0
1
I almost got brain aneurysm thinking that the query syntax of tree-sitter and ast-grep differ.

Fortunately that's not the case, but - contrary to Internet wisdom - query syntax is not compatible between languages (parsers).

Also, ast-grep's Playground is insanely useful:

https://ast-grep.github.io/playground.html
1
1
1
[RSS] One-Click Memory Corruption in Alibaba's UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data

https://www.interruptlabs.co.uk/articles/one-click-memory-corruption-in-alibabas-uc-browser-exploiting-patch-gap-v8-vulnerabilities-to-steal-your-data
0
1
0
repeated

‼️ Meet Ryan Clifford Goldberg, a Digital Forensics and Incident Response manager at Sygnia, he is one of three insiders accused of cybercrimes. He allegedly conducted cyberattacks using ALPHV BlackCat ransomware.

Goldberg and two other insiders ran ransomware operations since 2023 while employed at cybersecurity firms. After an FBI visit, Goldberg confessed. He now faces up to 50 years in prison.

0
1
0
@joern Right, that's why I xposted quickly from the other site while on the bus :) boosted your post now!
0
0
1
repeated
RCE in "json" mode of JsonPlusSerializer · Advisory · langchain-ai/langgraph · GitHub
https://github.com/langchain-ai/langgraph/security/advisories/GHSA-wwqv-p2pp-99h5
1
0
0
repeated
Edited 12 days ago
Kaitai Struct: A Tool For Dealing With Binary Formats - Petr Pucil & Mikhail Yakshin

https://www.youtube.com/watch?v=SC2zIli8MNA

#hacklu2025
0
0
0
repeated

"An eBPF Loophole: Using XDP for Egress Traffic" https://loopholelabs.io/blog/xdp-for-egress-traffic

0
2
0
Show older