Posts
3447
Following
714
Followers
1581
"I'm interested in all kinds of astronomy."
repeated

Michael Stapelberg ๐Ÿง๐Ÿน๐Ÿ˜บ

PSA: Did you know that itโ€™s **unsafe** to put code diffs into your commit messages?

Like https://github.com/i3/i3/pull/6564 for example

Such diffs will be applied by patch(1) (also git-am(1)) as part of the code change!

This is how a sleep(1) made it into i3 4.25-2 in Debian unstable.

3
47
2
[RSS] Django SQL Injection in RasterField lookup (CVE-2026-1207)

https://vulnerabletarget.com/VT-2026-1207
0
0
0
repeated

Project Zero Bot

New Project Zero issue:

Samsung: QuramDng Warp opcodes out-of-bounds read

https://project-zero.issues.chromium.org/issues/462544562

CVE-2026-20973
0
2
1
[RSS] CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

https://www.thezdi.com/blog/2026/2/4/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall
0
0
1
repeated

When a piece of type gets damaged, it's like a fingerprint that can be used to tie all the work of a printer together, whether or not their name appears on the title page. The Catalog of Distinctive Type is building a database of these fingerprints for Restoration England. https://cdt.library.cmu.edu/

1
11
0
repeated

RE: https://infosec.exchange/@albinowax/116018773839725691

I'm happy to be on the TOP 10 list for the second time, this time with the fun SOAP stuff.

I'm even more happy to see ORM research in 2nd place. I saw it live during BHEU and it was awesome ๐ŸคŸ

0
4
1
repeated

The path to the PS VR2 (part 1) - "Recovery mode" <- yet another case study on how assumptions should always be checked in practice ๐Ÿคท

https://bnuuy.solutions/2026/02/01/ps-vr2-recovery-mode.html

0
2
0
repeated
@algernon TIL about this initiative. Aiming to index things that are "hosted in Europe" tells me there is a fundamental misunderstanding how the web works, very disappointing :(
1
0
0
repeated

A good blog about computer viruses in Soviet times, the KGB and computer security in the USSR.

https://fromcyberia.substack.com/p/how-the-kgb-discovered-computer-viruses

0
1
0
repeated

๐Ÿšจ New advisory was just published!

A flaw that exists within the handling of sch_cake can allow a local user under the CentOS 9 operating system to trigger an use-after-free. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. This vulnerability won first place in the Linux category during the TyphoonPWN 2025 event: https://ssd-disclosure.com/linux-kernel-net-sched-cake-qdisc-use-after-free-lpe/

0
2
0
repeated
Edited 21 days ago
I sat through way too many #pentest interviews where the candidates had no clue about the fundamentals of web security, like the Same-Origin Policy.

If you want to make a career of finding flaws in (web)apps, do yourself a favor and read @b0rk's HTTP zine:

https://wizardzines.com/comics/same-origin-policy/
0
5
7
repeated

While waiting for the upcoming release of 9.3 by @HexRaysSA, I have made some updates and bug fixes to my idalib-based headless IDA rhabdomancer, haruspex, and augur.

Check out the changelogs for all the details and enjoy!

https://hnsecurity.it/blog/streamlining-vulnerability-research-with-the-idalib-rust-bindings-for-ida-9-2/

0
4
1
@xabd Could you ELI5 how this sw (or LinkTree) is different from a HTML(+CSS) page with links on it?
1
0
0
repeated
repeated

@glyph i wrote about it maybe 6 years ago but I'm thinking of revisiting it

the 6-years-ago comics:

- the same origin policy: https://wizardzines.com/comics/same-origin-policy/
- why we have the same origin policy: https://wizardzines.com/comics/why-same-origin-matters/
- cors: https://wizardzines.com/comics/cors/

0
4
0
repeated
@algernon I'm recommending this because of the "how to make using it easy" part. The repos I linked are just examples, the APIs defined by these libraries are the gist.
1
0
1
Show older