Posts
3598
Following
723
Followers
1590
"I'm interested in all kinds of astronomy."
TFW LLM keeps hallucinating
0
2
8
repeated

Lenovo released all patches for the Vantage vulnerabilities I reported earlier this year. The blog has been updated with write‑ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717.

https://cyllective.com/blog/posts/lenovo-vantage

0
3
0
@joxean Have we tried applying microcode updates?
1
0
4
@dmnk ...that will do unexpected shit at the worst possible times?
0
0
1
This agent could've been 10 lines of Bash.
2
0
4
repeated

🚨 New advisory was just published!

A critical vulnerability in UNISOC modem firmware allows one User Equipment (UE) to remotely attack another over the cellular network. By sending specially crafted malformed SDP within SIP signaling messages, an attacker can trigger memory corruption in the target modem, potentially leading to remote execution of arbitrary native code on the victim device: https://ssd-disclosure.com/unisoc-t612-rce/

0
2
0
@Sandfish6811 I can't dive deeper into this rn, but the linked GHSA confirms the essence of the vulnerability and the way it was introduced.

I checked and you are right that the hash is not sent back during auth, I'll probably leave a comment about this on /r/ so they can clarify.
1
0
0
repeated

CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

0
3
0
[RSS] Breaking Pingora: HTTP Request Smuggling & Cache Poisoning in Cloudflare's Reverse Proxy

https://xclow3n.github.io/post/6
0
3
2
[RSS] How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit

https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass
1
2
0
repeated

The exact moment software went downhill was when changed away from this.

1
6
0
repeated
repeated

Lorenzo Franceschi-Bicchierai

NEW: A former DOGE employee allegedly stole Americans' personal data from two large databases at the Social Security Administration, according to a new report.

The former employee allegedly put the databases on a thumb drive and wanted to use them at their new contractor job.

https://techcrunch.com/2026/03/10/doge-employee-stole-social-security-data-and-put-it-on-a-thumb-drive-report-says/

1
3
0
repeated
repeated

We are following this story very closely and send our best wishes for recovery to Jello, multi-year HOPE speaker & keynote. https://www.kqed.org/arts/13987466/punk-legend-jello-biafra-hospitalized-after-stroke

0
2
0
repeated
Edited 4 days ago

If I were to recommend one cryptography book for implementors in 2026, would it be:

(Edit, would love your comments as to why.)

16% Cryptography Engineering
66% Serious Cryptography
8% Real World Cryptography
8% something else (see comments)
0
3
0
repeated

In re: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

I see people in here being smug about an OPSEC failure, and other people pointing out that "we only respond to local law enforcement requests" is a much bigger set than you might think, but it's all focused on what the individual can do to protect their privacy and anonymity against nosy state actors.

Most of the solutions proposed are either very insecure (mailing cash) or sufficiently technically complex to be out of the skill set of the average computer user.

1
1
0
repeated
Show older