Posts
3664
Following
724
Followers
1593
"I'm interested in all kinds of astronomy."
repeated

"AI is giving attackers a huge advantage!"

"Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

11
14
1
Edited 9 days ago
"I traced $2 billion in nonprofit grants and 45 states of lobbying records to figure out who's behind the age verification bills."

https://web.archive.org/web/20260313090844/https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/

https://github.com/upper-up/meta-lobbying-and-other-findings

Spoiler: It's Meta.
0
1
1
repeated

Kagi's Small Web just got a big upgrade! Introducing browser extensions, mobile apps and categories:

https://blog.kagi.com/small-web-updates

3
3
0
repeated

@matildalove "he fed my work into a machine, so I fed him into a machine..."

0
1
0
repeated

RE: https://hachyderm.io/@pheonix/116221805295722939

only exists for two reasons:

- Money
- Info gathering on everyone for reason 1

3
8
0
repeated

Wrote down everything I wish I knew earlier about Python supply chain security. Hash pinning, pip-audit, SBOMs, trusted publishing — the whole thing. Enjoy 🐍🔒https://bernat.tech/posts/securing-python-supply-chain/

4
8
0
repeated

What we get upset about. Cartoon for Dutch newspaper Trouw: https://www.trouw.nl/cartoons/tjeerd-royaards~bcb45712/

3
23
0
@freddy successfully teaching this to a 8yo proves that you really get it ;)
0
0
3
repeated

"There are, of course, an infinity of variations to that single routine."

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/.

1
4
1
Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)

https://seclists.org/oss-sec/2026/q1/300

#NoCVE yet?
0
2
0
[RSS] Archive of classic reverse engineering tutorials (Armadillo, ASProtect, Themida, SoftICE era)

https://github.com/Show0ne/archivo-syxe05-snat
0
0
0
[RSS] Reverse Engineering the undocumented ResetEngine.dll: A C++ tool to programmatically trigger a silent Windows Factory Reset (PBR) bypassing SystemSettings UI.

https://github.com/arielmendoza/Windows-factory-reset-tool
0
0
0
[RSS] I Hacked My Laundry Card. Here's What I Learned.

https://hanzilla.co/blog/laundry-card-hack/
0
0
0
[RSS] Decrypting and Abusing Predefined BIOCs in Palo Alto Cortex XDR

https://labs.infoguard.ch/posts/decrypting-and-abusing_paloalto-cortex-xdr_behavioral-rules_biocs/
0
0
1
[RSS] A Nerd's Life: Weeks of Firmware Teardown to Prove We Were Right

http://blog.quarkslab.com/nerd-life-weeks-firmware-teardown-we-were-right.html
0
5
3
repeated

Jake in the desert

Edited 9 days ago

'An old photo of a very large BBS' posted in 2022, and a writeup about it. https://rachelbythebay.com/w/2022/01/26/swcbbs/

4
3
0
repeated

AFL++ v4.40c release - best performance ever - optimal hidden coverage instrumentation, FrameShift, LLVM 22 support, IJON fixes, a lot of minor and bigger enhancements! https://github.com/AFLplusplus/AFLplusplus/releases/tag/v4.40c

0
2
0
"in the default installation of Ubuntu Server 24.04.3 plus the Postfix mail server, we create a 'fail-open' situation in Sudo" wat :D
1
6
7
repeated

EDIT: See later in thread, it seems like the good news is at least that it's not having auto-merging on, which is where the security risk comes in. I still have other concerns.

Looks like they're also using Claude for PR review https://github.com/systemd/systemd/commit/9a70fdcb741fc62af82427696c05560f4d70e4de

Which probably means systemd is now the most attractive target in FOSS for an AI prompt injection attack to insert a backdoor

EDIT: It does seem that they don't have auto-merging of PRs from the review bot, which is an improvement over the situation (and mitigates the primary security risk, hopefully it stays that way), and AI contributions are asked to be disclosed. That said, it seems like the issue is closed, and they are firmly in the "we will accept AI contributions, as long as disclosed" camp.

10
8
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

Only answer if you have direct and personal experience please. Is there ANY way on IOS (NOT ON ANDROID) to get Signal to help you clean its massive storage? I've manually tried to delete some large things but it is not helping. It is using 11GB and I can't do a thing anymore. Help?

2
2
0
Show older