Posts
3932
Following
728
Followers
1602
"I'm interested in all kinds of astronomy."
@wdormann @christopherkunz @jhr77 Vuln mgmt is hard, e.g. how you track patch coverage vs. signature update status? Not that pushing a sig was a bad idea, I'd just expect a KB for this too.
1
0
2
repeated

Babe wake up, new Windows privesc just dropped. . Oh and also Bitlocker bypass https://github.com/Nightmare-Eclipse/GreenPlasma

1
6
0
@wdormann @jhr77 @christopherkunz I don't see a Defender entry in today's update that also points to this being a signature based mitigation
1
0
2
repeated
repeated

TrendAI Zero Day Initiative

He says to blame the delay on jet lag, but @dustin_childs has his full review of the and patches. Nothing under active attack, but a total of 190 CVEs to look at (plus 120+ from Chrome recently!) read the details at https://www.zerodayinitiative.com/blog/2026/5/12/the-may-2026-security-update-review

0
2
0
repeated
repeated

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html Xen advisory posted, should be a kernel fix here any minute now I assume

1
2
0
repeated
@ekuber Having a chopper to call when you go hiking is definitely nice :D I don't quite get how the principles apply here though: in your opinion, for this particular example, would it be right to require all traits by ::new()?
1
0
0
@ekuber Don't get me wrong, I'm positively amazed by rustc messages in general, and this one is no exception. On the other hand I also like to see how I should approach the API I'm about to use, having a map about the code base before I go down a path that just won't work. I feel like relying on the compiler is like periodically calling a hovering helicopter to get out of the woods, instead of having a proper $5 map.
1
0
1
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim

https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
0
2
2
repeated

We are releasing Firefox 150.0.3 today, in order to fix an important security issue. Please take the time to update.

https://www.mozilla.org/en-US/security/advisories/mfsa2026-45/

0
4
0
repeated

@jhr77 @christopherkunz
I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

With current definitions, I've not seen RedSun succeed. No matter how long I wait.

With old definitions, success is pretty quick.

2
2
0
repeated

TinyJoyPad 作った

0
2
0
repeated

LLMs are just the ultimate IP-violation-machines. I love using them for reverse engineering. I picked up so many projects I abandoned in the past because staring at obfuscated code or assembly got boring and tiresome and felt like an endless endeavor that will never be realistically reverse engineered completely anway.

Now I give Opus or whatever other model enough context, datasheets and tests and it starts reversing. Does it hallucinate and is not always correct? Yeah. But who cares? I am not always correct and misunderstand things when manually reversing stuff as well. We all do.

Gradually building more and more context to be able to reason a bit easier about things you didn't understand yet is exactly what an LLM can incrementally help you with. And gathering more and more information helps both me and the LLM to understand the stuff we are looking at a bit better.

It's so awesome.

0
2
1
@stf "might affect cryptology at some future time or (more likely) in some other world." I forgot about this one lol
0
1
2
repeated

just happened, which reminds me of the eurocrypt 35 years ago held in budapest, which an cryptologist was attending and giving a scorching in the internal cryptolog newsletter of the nsa: https://scottaaronson.blog/?p=2059

would be interesting to see the latest cryptolog report on this latest edition...

1
2
0
repeated

TrendAI Zero Day Initiative

In a new feature, @TheDustinChilds takes a look at patches and tries to identify which ones should worry you (since Apple won't). Check it out at https://www.zerodayinitiative.com/blog/2026/5/12/the-apple-macos-security-update-review

0
2
0
repeated

Oh look, it's Patch Tuesday. Again.

0
4
0
repeated

ARE YOU crew on a generation ship? Did your ancestors maroon you between the stars in a life of involuntary servitude, deprivation and a vatslime diet? You may be entitled to compensation. Gliese 1171c Legal Services inc has a centuries long record of successful class action litigation on behalf of crews and cryopassengers. Depose your autopilot this diurn and join our next action. NO WIN NO FEE. Plans for your warp drive follow this message.

0
6
1
Show older