May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨
Thanks for everyone that came to check out our @districtcon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
(No) surprise!
I think we all saw this coming... #Odido didn't remove data when they said they would, which we now know because it leaked out. Some leaked data was from customers who left 10 years ago, while they state they remove it after 2. Only 8 years late. Even the tax office doesn't need it that long...
https://nos.nl/artikel/2602804-odido-overschrijdt-eigen-termijn-bewaren-gegevens
#datalek #privacy #databreach #cybersecurity #dataleak #security #TMobile
RE: https://furry.engineer/@soatok/116082533052740652
ok the ghost vuln is quite funny. the WAF example really sounds like an array is involved there and it would have bet 20 bucks that its a type confusion (because despite it being 2026 its really easy to shoot yourself in the foot if your types get quirky)
but - spoilers - nope, its really just straight up string interpolation into raw sql like in the good ol days lmao. oh well, happens
nono - kernel-enforced capability sandbox for AI agents https://nono.sh
I’ve been working on this for a while, but let’s make it official: I started a little Tumblr-like microblog about software craft and quality!
You can sign up via RSS or a weekly newsletter digest. There’s already almost two months of content in there, if you just want to check it out.
Hope you like it!
Just got this link on my discord - https://www.kickstarter.com/projects/bitman/bootblock-rebels - passing it along because this book looks fun!
The past two months, I've been working on a little pet project, lovingly called OnlyJunk.Fans: hosted iocaine. For free. Because I could, and wanted to.
It's going to officially launch on the 17th of February, in just a few days. But I thought I'll blog about it before the launch, because I won't have time to do so later.
🚨 New advisory was just published!
Source code review of the Novarain/Tassos framework uncovered 3 critical primitives: unauthenticated file read, unauthenticated file deletion, and SQL injection enabling arbitrary DB reads, affecting 5 widely deployed Joomla! Extensions. Chained together, these bugs allow reliable RCE and administrator account takeover on unpatched Joomla! Instances: https://ssd-disclosure.com/joomla-novarain-tassos-framework-vulnerabilities/
@littlealex
This comes across as a pretty idiotic statement as it suggests there is a way to own an F35 in a way you can own an iPhone by jailbreaking it. Just as if these high-bred killing machines would not rely on distributed complex physical logistics and intelligence networks.
https://www.twz.com/air/you-dont-need-a-kill-switch-to-hobble-exported-f-35s
❤️ Thank you to the #Archlinux Wiki maintainers! ❤️
#Maintainers in general, and maintainers of documentation most of the time get way too little recognition for their contributions to #SoftwareFreedom.
ArchWiki is one of the pearls of the internet! That's why I dedicated my this year's #ilovefs post to the #ArchWiki maintainers!