Posts
3865
Following
726
Followers
1594
"I'm interested in all kinds of astronomy."
Command injection in a qmail fork (not the original!) - CVE-2026-41113:

"On the wire, a DNS label is just a length byte followed by up to 63 arbitrary bytes; RFC 1035 lets you put nearly anything in there, and most recursive resolvers will happily pass it through."

https://blog.calif.io/p/we-asked-claude-to-audit-sagredos

#LLM
1
1
1
repeated

Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks:
https://atos.net/wp-content/uploads/2026/04/atos-byovd-article.pdf

0
2
0
repeated

Happy Bicycle Day to all who celebrate! On this date in 1943, Albert Hofman took the LSD off the shelf that synthesized five years previously, ingested 0.25 milligrams and then rode his bicycle on the first LSD trip.

https://en.wikipedia.org/wiki/History_of_lysergic_acid_diethylamide#%22Bicycle_Day%22

0
3
0
@PurpleJillybeans There are pretty good Java decompilers out there (e.g. jd-gui), so you don't have to mess with the bytecode.
0
0
2
repeated
repeated
Edited 4 days ago

The folks at iTerm2 figured out a way to get arbitrary code execution as the result of cat <file>, which is... impressive?

3
8
0
repeated
repeated

i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

18
53
3
repeated

RE: https://chaos.social/@icing/116435790527643905

This is quickly becoming a new trend ... "look, if I totally destroy internals by abusing a private function, something bad can happen"

4
2
0
repeated
repeated

joernchen :cute_dumpster_fire:

Thanks so much to everyone who showed up on the weekend in Berlin to say goodbye to FX.

“Burning bridges where we can” - this is the original Phenoelit slogan. Yet, while FX for sure burned some network bridges, he did quite the opposite for the hacking community. FX built bridges between people wherever he could. He created something way bigger than himself which we all are part of.

Each one who joined us in Berlin carries a piece of his legacy. You were there because he left something with you. We know there are many who couldn't make it in person, and they too carry his spirit with them.

FX is gone.
But the spirit lives on.

0
9
0
[RSS] Slowburn: Looking through AMD Platform Configuration Blobs infrastructure

https://swarm.ptsecurity.com/slowburn-looking-through-amd-platform-configuration-blobs-infrastructure/
0
0
1
repeated

@alex the AI datacenter scraping situation is getting really bad. I think there are some that appear to now be routing through residential proxy networks to evade IP bans. Not sure if that's what you're seeing.

1
2
0
repeated

Useful explainer on the latest Citrix shenanigans, including verifying exposure and hunting/forensics recommendations

https://www.picussecurity.com/resource/blog/cve-2026-3055-cve-2026-4368-inside-the-netscaler-citrixbleed-3-memory-overread

0
2
0
repeated

NetScaler is doing it again. Third time in three years we're patching memory leaks that hand attackers your session tokens on a plate. CISA's already got it on the emergency list. If you run one, stop reading this and patch now.

https://cybersec.picussecurity.com/s/cve-2026-3055-cve-2026-4368-inside-the-netscaler-citrixbleed-3-memory-overread-26799

0
3
0
repeated

A Tennessee man who hacked the US Supreme Court was sentenced to twelve months of probation.

Nicholas Moore hacked the US' highest court in 2023 and leaked documents on an Instagram account named @ihackthegovernment.

https://www.courtlistener.com/docket/72124298/united-states-v-moore/

0
1
0
repeated

ABSTRACT/RAGEKID2.GIF

0
1
0
repeated

I finally managed to write something about my recently deceased dear friend Felix 'Fx' Lindner.

https://phenoelit.de/fx.html#Halvar

1
12
0
repeated

Abstract verbalizations about personal liberty, freedom of the press, and so on, will not be convincing in most parts of the world.

0
1
0
repeated

AIs have been finding bugs and vulnerabilities in for some time.

Is it work to fix those? Yes.

Has someone paid for this? Partially (wolfSSL and @sovtechfund)

Are the AIs annoying? Yes, very.

Could humans find the same bugs? Yes, if they‘d somehow avoid being bored to death through it.

Was there something „heartbleed“ like? No.

Were there lots of C mistakes? No, logic bugs mostly.

Do AIs run out of steam? Yes. After a while a model stops finding things. Findings differ per model.

2
6
0
Show older