Posts
3686
Following
724
Followers
1595
"I'm interested in all kinds of astronomy."
When I become dictator I'll establish an authority that will check every EDM track for "is one of my many chat programs blimping?" sounds.
0
0
3
repeated
repeated

RE: https://mastodon.art/@lurnoise/114993216415771245

Hi! You should hire me for stuff, not only do I draw pretty neatly but I'm also very kind and easy to work with and always hit the deadlines <3

0
2
1
repeated

What You Need to Know: Windows Admin Center Remote Privilege Escalation (CVE-2026-26119) https://www.semperis.com/blog/what-you-need-to-know-windows-admin-center-remote-privilege-escalation-cve-2026-26119/

0
2
0
@pancake I think we are talking about different things (please provide a link or stg if I misunderstand). When I just launch claude it can and will write at random FS paths for example, because the process has the privileges to do so. Can it do the same if I launch it in a regular old container where the project directory is mounted (it will have access to everything inside the mount ofc but not my whole ~)?
1
0
0
@pancake I get that this is a stronger isolation layer, but why is that necessary? Do agents randomly perform container escapes?

Simplicity is definitely a plus, but that wouldn't require VMs either.
1
0
1
@pancake How is this different from simply bind mounting your project dir?
1
0
1
[RSS] Windows stack limit checking retrospective: Alpha AXP

https://devblogs.microsoft.com/oldnewthing/20260318-00/?p=112146
0
1
0
repeated

Almost 7 years of silence.
Today, that changes.
March 23, 2026.
Follow to be among the first to know:
https://www.corelan.be/index.php/contact
Tick tock. It’s coming.

0
1
0
repeated

Our Call for Participation is now live!

If you have a talk, workshop, performance, or installation you'd like to bring to EMF, you can now submit it here:

https://www.emfcamp.org/cfp

Accepted proposals are guaranteed the chance to buy a ticket!

0
8
0
repeated

@fluffykittycat

I refer to this as the Oracle problem. In the early ‘90s, if you were using a database to manage things like payroll and inventory, you needed a big server. Paying for an expensive database was a good idea because you really needed to get the last bit of efficiency out of the system.

By the early 2000s, your company’s database might have doubled in size (7% annual growth), but computers were 64x faster for the same price. Now you could (and a lot of companies did, but shouldn’t) handle the same workload in Access on a moderately good desktop. Another decade later and they could buy three cheap Arm SBCs for under $100 and set up Postgres with replication and handle the same workload without noticeably spiking the CPU usage. Not only did the hardware cost drop to almost nothing, the cost of an expensive database went from a rounding error in the accounting to the vast majority of the cost.

0
1
1
repeated

ℹ️❤️🖥 aka Compy-chan

Sums up my experience growing up

4
29
0
repeated
The `left-pad` incident was 10 years ago today.

https://en.wikipedia.org/wiki/Npm_left-pad_incident

Thankfully, we've completely solved software supply chains in the years since.
2
12
0
[RSS] LLVM Adventures: Fuzzing Apache Modules

https://pwner.gg/blog/2026-03-20-apatchy
0
0
0
repeated
repeated
repeated

looks like anthropic got rid of the claude refusal triggering string :(

2
5
0
repeated

This is my analysis (and PoC) for CVE-2026-20817, a privilege escalation in the Windows Error Reporting service.

👉 https://itm4n.github.io/cve-2026-20817-wersvc-eop/

Credit goes to Denis Faiustov and Ruslan Sayfiev for the discovery.

TL;DR A low privilege user could send an ALPC message to the WER service and coerce it to start a WerFault.exe process as SYSTEM with user-controlled arguments and options. I did not achieve arbitrary code execution, but perhaps someone knows how this can be done? 🤷‍♂️

0
6
0
Show older