Posts
3340
Following
710
Followers
1577
"I'm interested in all kinds of astronomy."
repeated

Earlier this month, we reported a zero-day auth. bypass in the SmarterTools SmarterMail email solution.

Someone has reversed the patch (released on 15th Jan) and begun exploiting it in the wild.

Read our analysis and please, ASSUME BREACH + PATCH NOW.

https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/

0
10
0
repeated

is RFC 9116 compliant

https://curl.se/.well-known/security.txt

https :// curl.se / .well-known / security.txt

5
4
0
[RSS] [reddit] Do any security researchers use Anki or spaced repetition in their workflow?

https://old.reddit.com/r/ExploitDev/comments/1qjjn3q/do_any_security_researchers_use_anki_or_spaced/
0
0
2
[RSS] Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) - watchTowr Labs

https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/
0
1
0
getting things merged into Ghidra

RE: https://chaos.social/@weirdunits/115937461017927780
0
0
1
repeated

TrendAI Zero Day Initiative

Whew! They had to swap out the master control board during the attempt, but Hank Chen of InnoEdge Labs successfully demoed their exploit of the Alpitronic HYC50 in Lab Mode. Using screwdrivers during a attempt is always crazy to see. He's off to disclose what occurred.

0
2
0
@mttaggart @gdupont This whole thing reminds of kids playing war games on the playground. they are playing "revolution" now. they heard revolutions need constitutions, and they happen to have these text writing toys and potato stamps so they worked *really* hard to produce a "constitution" that they can show their shareho^W parents and the enemy kids over at the sandbox.
0
0
1
repeated
@lazyb0y ...until you try to touch it :)
0
0
3
repeated

Remember "don't print this email" in signatures that was a bit cringe? It doesn't feel that cringe anymore in retrospect. I'm doing an experiment now with this new email signature :D Anyone doing something similar? Could it catch on?

13
36
3
repeated

Today's threads (a thread)

Inside: Google's AI pricing plan; and more!

Archived at: https://pluralistic.net/2026/01/21/cod-marxism/

1/

3
3
0
repeated

After auditing the @mullvadnet client applications in 2024, we have recently audited Mullvad VPN's API.
The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.
Five issues were identified, of which only one had a very limited impact on users of the service.

The technical details may be found in our report. https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/

1
6
0
repeated

Last December I solved Synacktiv's 2025 Winter Challenge: Quinindrome https://www.synacktiv.com/en/publications/2025-winter-challenge-quinindrome . Here is a 81-byte Linux program which is both a quine (it prints itself when executed) and a palindrome (it is symmetrical)! To learn how I achieved it: https://github.com/fishilico/synacktiv-winter-chall-2025-quinindrome/blob/main/writeup.md

0
6
0
[RSS] Windows Internals: Check Your Privilege - The Curious Case of ETW's SecurityTrace Flag

https://connormcgarr.github.io/securitytrace-etw-ppl/
0
1
0
I feel I have this instinct to feed programs data that they won't be able to handle.

Unfortunately this is mostly true for tools I'd like to use, not targets I review.
0
3
7
Edited 18 days ago
Humble request for vibe-coders: report your runtime errors!

LLM tends to insert Pokémon exception handlers everywhere, making problems (of which vide-code has a *lot*) hard to even notice.

Slightly related illustration:
3
74
104
Show older