Posts
3488
Following
717
Followers
1583
"I'm interested in all kinds of astronomy."
repeated

*long drag on cigarette* Kid, this is Mastodon. We're all the algorithm here. You. Me. Everybody. Now get out there and boost somebody's bullshit.

3
14
0
@tmr232

"- Didn't you have ads in the 20th century?

- Well, sure, but not in our commit messages. Only on TV and radio. And in magazines and movies and at ball games, on buses and milk cartons and T-shirts and bananas and written on the sky. But not in commit messages. No, sir-ee!"
0
0
1
repeated
repeated

Team member @sigabrt was able to bypass Apache FOP Postscript escaping to reach GhostScript engine.

https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html

0
2
0
repeated

In case anyone was still under the assumption that US Big Tech and the Trump regime aren't one and the same:

The US has ordered its diplomats to lobby against EU attempts to regulate US tech companies ๐Ÿšจ

We need ethical open alternatives.

https://www.reuters.com/sustainability/boards-policy-regulation/us-orders-diplomats-fight-data-sovereignty-initiatives-2026-02-25/

3
7
0
[RSS] From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)

https://boschko.ca/unitree-go2-rce/
0
2
1
repeated

Michael Kohl ๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡น๐Ÿ‡ญ

Edited 6 days ago

A tale in 3 pictures. In which our hero wonders if he can and doesn't stop to ask if he should.

4
25
1
[RSS] Building a Custom Architecture and Platform: Part 2

https://binary.ninja/2026/02/26/quark-platform-part-2.html

#BinaryNinja
0
0
1
[RSS] Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain

https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/
0
1
1
[RSS] Intego X9: Why your macOS antivirus should not trust PIDs

http://blog.quarkslab.com/intego_lpe_macos_2.html
0
1
3
repeated

Updated breach: Attackers have released another 1M records from Dutch telco Odido, adding 371k more unique email addresses to the breach. The data is consistent with the first dump, with further releases threatened. More: https://haveibeenpwned.com/Breach/Odido

1
5
0
repeated

My final blog related to admin protection is up. https://projectzero.google/2026/02/gphfh-deep-dive.html I go into a bit of history of the interesting GetProcessHandleFromHwnd API, how it ended up allow you to bypass protected process restrictions and how it's now "fixed".

1
7
0
Former General Manager [L3Harris Trenchant] Sentenced to 87 Months for Selling Stolen [0day] to Russian Broker

https://www.justice.gov/opa/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade
0
1
1
repeated

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

17
40
1
@freddy I wouldn't mind getting notified that I need a restart and loosing data *when I finally decide I'm ready*, but in the current situation the browser just stops working during active use because an update executed in the background.
0
0
0
repeated

Assn for Computing Machinery

Today, letโ€™s remember Charles Thacker, who was born on this day in 1943. Thacker received the in 2009 for the pioneering design and realization of the first modern personal computer -- the Alto at Xerox PARC -- and seminal inventions and contributions to local area networks (including the Ethernet), multiprocessor workstations, snooping cache coherence protocols, and tablet personal computers.

Read more about him, here: https://amturing.acm.org/award_winners/thacker_1336106.cfm

0
3
0
@freddy I browse in private mode for various reasons (not all security/privacy related) so it doesn't work (as it shouldn't).

Now I would link that thread where there are users with this very same problem but y'know, I just had to restart my browser so I don't have the link anymore :)

Now I get that my setup is still counts as strange but this behavior *guarantees* regular users run away screaming regardless if they can restore or not.
1
0
0
Show older