Tired of reversing the same libc for the 100th time? 👀
Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries.
High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami.
🔗 https://blog.quarkslab.com/sighthouse-automated-function-identification.html
🆕 New blog post!
"BitLocker's Little Secrets: The Undocumented FVE API"
A small Windows RE adventure to figure out how to get the status and configuration of a BitLocker protected drive programmatically and without admin privileges.
Now also implemented in PrivescCheck! 🔥
👉 https://itm4n.github.io/bitlocker-little-secrets-the-undocumented-fve-api/
Node.js pauses bug bounty program after a funding lapse
They were sponsored by IBB, a program funded by Microsoft, Meta, Adobe, and a bunch of other tech giants
Unclear what happened there
https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties
Here's a fun post for pro- and anti-AI infosec people alike - guess who is going to have to "fix" AI? If you're thinking "not me" well, think again.
https://www.markloveless.net/blog/2026/4/2/the-uncomfortable-effects-of-ai
@drwho @simplenomad Yeah, apparently they got the AV working...
https://www.404media.co/artemis-2-astronauts-microsoft-outlook-livestream/
Spread the word! @phrack CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of PiotrBania with some hopefully inspiring text from phrack staff :)
phrack.org
🎥 New video about QEMU!
This time, Anton walks through the basics of QEMU system mode using a simple bare metal program! ⚙️
The focus is on understanding how QEMU’s high-level control flow works, from guest code to BIOS, and down to device implementation.
🫡 We’re back.
Today, we’re publishing vulnerabilities we discovered, disclosed, and chained to achieve pre-auth RCE against Progress ShareFile.
Enjoy the journey with us, while you sob into your hands 🫠
important update: they fixed the toilet