Posts
3852
Following
725
Followers
1595
"I'm interested in all kinds of astronomy."
repeated
Edited 11 days ago

RE: https://infosec.exchange/@josephcox/116374994792773696

To stop leaking your Signal messages:

Signal > Settings > Notifications > Notification Content > Show > “Name only” or “No name or content”

iOS and Android notifications all go through Apple and Google’s servers respectively and are not end to end encrypted. The feds have known and used this for years now.

Edit: That last bit doesn’t affect Signal, my bad. The settings change does still protect from the on-device notification DB storing message preview. See this reply for more info

https://tech.lgbt/@becomethewaifu/116375432389206118

1
8
0
@greg @weirdunits @gsuberland Have you seen this series: https://www.youtube.com/watch?v=kkfIXUjkYqE ? (I'm so glad someone finally called out kWh!)
1
1
1
repeated

rocket propulsion engineers per newton

0
1
0
repeated
repeated

C and C++ run your OS, your browser, your database, and your critical infrastructure. They're also the easiest languages to get catastrophically wrong.

We wrote down everything a security auditor should check: language-level bug classes, stdlib pitfalls, Linux and Windows issues from usermode to kernel, seccomp sandbox escapes, and ptrace handler race conditions.

One checklist, hundreds of checks. https://appsec.guide/docs/languages/c-cpp/

1
4
0
repeated

Project Zero Bot

New Project Zero issue:

Adobe DNG SDK: out-of-bounds write in dng_render_task::ProcessArea due to coordinate system confusion

https://project-zero.issues.chromium.org/issues/479111319

CVE-2026-27280
0
1
1
repeated

Project Zero Bot

New Project Zero issue:

Adobe DNG SDK: integer overflow in dng_pixel_buffer::OptimizeOrder leads to out-of-bounds memory access

https://project-zero.issues.chromium.org/issues/478212931

CVE-2026-27281
0
1
0
repeated

The RCE I've found in LiteLLM (https://x41-dsec.de/lab/advisories/x41-2026-001-litellm/) is a nice example of how AI agents can speed up security research. The issue was found during a project with strict time constraints by me manually. So I had a Nemesis backed AI agent do auto-triage and find a sandbox escape fully automated. After 20 minutes the job was done including a fully working exploit.

0
5
0
repeated

Linus Torvalds, the legend 🔥

6
11
1
repeated
Edited 11 days ago

Getting serious ADHD and building software nobody asked.

checksec for Mach-O
https://github.com/ChiChou/macchk

⚠️ Warning: vibe coded

1
5
0
repeated

@da_667 just jailbroke my paper white 3 last weekend. Was relatively simple. Great for older models with no Android running on it. Breathed new life into it.

https://kindlemodding.org/jailbreaking/index.html

0
4
0
repeated

Enfys 🏴󠁧󠁢󠁷󠁬󠁳󠁿 🏳️‍⚧

Edited 14 days ago

i released an Atari 2600 demo with some friends at revision this year and managed to win 1st place in the oldskool demo compo! it's been in development for about a year now so was really cool to see it finally out :3
https://demozoo.org/productions/389801/
https://www.youtube.com/watch?v=aEJ0A8Wvdxs

0
2
0
repeated

TrendAI Zero Day Initiative

Inherent flaws in node.js remain unpatched. Bobby Gould and Michael DePlante detail the problem and how the burden of security silently falls on app developers. https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows

0
2
0
repeated
repeated

Another #Hungary and #Russia investigation by #VQuare

  • Budapest systematically weaponized the issue of Hungarian minority rights in Ukraine to stall EU accession negotiations.
  • Péter Szijjártó offered Sergey Lavrov to send EU documents through the Hungarian Embassy in Moscow.
  • Hungary and Slovakia, acting as Kremlin friends in the EU, pushed against restrictions of Russian energy supplies.
  • Budapest also supported the Kremlin’s “achievements” of the Alaska Summit.
  • Leaked audio reveals a strikingly deferential, submissive attitude from Szijjártó toward Lavrov.

https://vsquare.org/kremlin-hotline-how-hungary-coordinates-with-russia-blocking-ukraine-from-the-eu/

1
4
0
repeated

New from 404 Media: Microsoft has terminated an account associated with VeraCrypt, the popular and long-running piece of encryption software. This means can no longer receive updates on Windows, the developer told me. Little explanation given by Microsoft https://www.404media.co/microsoft-abruptly-terminates-veracrypt-account-halting-windows-updates/

3
5
0
repeated

taking pride in my vintage pre-AI CVEs

3
6
1
[RSS] Standardizing Rewards in Google VRP: Introducing Information Tiers and Action Criticality

https://bughunters.google.com/blog/standardizing-rewards-in-google-vrp
0
0
1
repeated

\o/ VLC in space

@videolan

6
21
0
Show older