Posts
3358
Following
711
Followers
1579
"I'm interested in all kinds of astronomy."
#Keycloak CVE-2026-1529: "lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access."

https://access.redhat.com/security/cve/cve-2026-1529

#JWT
0
6
8
repeated

Apple says it supports competition, privacy, and repair. AirPods say “not for you.” From EU feature lockouts to batteries you can’t replace, we unpack Apple’s most disposable design at the link below.

https://www.ifixit.com/News/115572/apple-airpods-and-malicious-compliance

2
4
0
Rust Crate: It's very easy to use me, here's a definition: ...

Me: I don't even know how to type half of these characters :S
0
0
1
repeated
New Rapid7 Analysis on AttackerKB topic: CVE-2026-1731

"On February 6, 2026, BeyondTrust published an [advisory](https://www.beyondtrust.com/trust-center/security-advisories/bt26-02) for a new critical command injection vulnerability, [CVE-2026-1731](https://nvd.nist.gov/vuln/detail/CVE-2026-1731), affecting their products Remote Support (RS) and Privileged Remote Access (PRA). ..."

Link: https://attackerkb.com/topics/0e038aee-d044-46cf-8b9e-8f54ca24d80a
0
1
0
repeated

my friend @asciimoo built a thing again \o/ and it's great as always. read his own thoughts on this at https://hister.org/posts/how-i-cut-my-google-search-dependence-in-half/

and engage with the cringe on the orange site at https://news.ycombinator.com/item?id=46959554

1
3
1
@troed

No that I disagree, but I think OP is (at least in part) about scaring away volunteer contributors where nothing vs. something can make a difference. You probably won't start building a sand castle in the dog park.

@chainq
0
0
1
repeated

This multi-part blog series is discussing an undocumented feature of Windows: instrumentation callbacks (ICs).

In part 4 we cover ICs from a more theoretical standpoint. Mainly restrictions on unsetting them, how set ICs can be detected and how new ones can be prevented from being set.

Learn more at https://cirosec.de/en/news/windows-instrumentation-callbacks-part-4/

0
2
0
@troed @chainq One recurring pattern I see with LLM contributions is that code-level abstractions don't make sense. The feature works, all tests pass, but a considerable amount of functionality is at the wrong place. Simplest example is a C project where *technically* it doesn't matter in which file you implement a function, but I've seen the same with Java&classes too. This doesn't matter for machines because they just grep for the function name, but makes human contributions extremely taxing, like living in a mad mans house where the soap is in the fridge and you have to climb a ladder to the attic to find the salt.

I think this can be a valid argument against the LLM push.
1
0
5
repeated

Usenix WOOT Conference on Offensive Technologies verified

The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 4 weeks (March 3, 2026)!

WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused).

Details are available in the Call for Papers:
https://lnkd.in/gK2RGj-h

0
3
0
repeated

It's pretty insane how we live in an age where everything needs to be monetized; every single tear of knowledge must be consecrated to the mighty god of money throught crappy trainings and certificates.

0
1
0
repeated

Annie Rauwerda, creator of Depths of Wikipedia, lives for the internet’s weirdest footnotes.

That includes things like the long-gone Garfield the cat “G-Mail,” 🙀📬 a very real web oddity now preserved only on the .

Internet history is stranger—and more fragile—than it looks.

Read more 👉 https://blog.archive.org/2026/02/05/depths-of-wikipedia-creator-annie-rauwerda-on-fragile-internet-citations/

@annierau @internetarchive

0
2
0
repeated

Additional reason delete Discord account: Just a few months back someone pilfered all of the ID they'd already collected.

So of course they're asking for more of it.

https://arstechnica.com/security/2025/10/discord-says-hackers-stole-government-ids-of-70000-users/

0
6
0
repeated
[RSS] Windows containers network isolation RE

https://safesws.github.io/windows-containers-network-isolation/
0
0
1
[RSS] CVE-2026-2103 - Infor Syteline ERP - Keys Included: No Assembly Required

https://blog.blacklanternsecurity.com/p/cve-2026-2103-infor-syteline-erp
0
0
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

I am losing it at how many of my peers have forgotten what software engineering is. It is not typing in lines of code.

5
11
1
git ass
1
4
4
Show older