Posts
4059
Following
730
Followers
1618
"I'm interested in all kinds of astronomy."
repeated

@christopherkunz
I also tested another PoC and it was even more fake. i.e. it didn't even create a CLDAP structure that made sense.

I get that PoC||GTFO is a thing, but we've clearly entered a phase where it needs to be Verified PoC||GTFO. πŸ€¦β€β™‚οΈ

2
3
0
repeated

I don't get out much these days but here's a talk I gave at the North American OSS Summit recently: https://www.youtube.com/watch?v=ZquMucBZnaQ

1
5
0
#Redis - Security advisory: [CVE‑2026‑23479] [CVE‑2026‑25243] [CVE-2026-25588] [CVE‑2026‑25589] [CVE-2026-23631]

https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/
0
0
0
repeated

For 19 years, GPS satellites have secretly broadcast a β€œnumbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, β€œghost” substrings repeating years apart, and a β€œTEXT” prefix spreading now. https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer

5
14
0
repeated

πŸš€πŽπŸπŸ-𝐁𝐲-𝐎𝐧𝐞 πŸπŸŽπŸπŸ” CFP looking for the research that will shape the conversations, techniques and tooling of tomorrow's offensive security community.
CFP closes on 1 July 2026, 18:00 SGT.
The next great OFF-BY-ONE talk might be yours!
https://cfp.offbyone.sg

0
2
0
repeated

A friend reported a LPE to Microsoft and in the advisory Microsoft fucked it and wrote a wrong description saying the vuln was in MMC.

Consequence: people wasting hundred of dollars on AI trying to analyze the wrong files just to get a fake PoC because AI brainwashed them πŸ˜‚πŸ˜‚πŸ˜‚

"A working PoC" and the AI released a supposed MotW bypass. The real vuln was a LPE to System.

What a clown circus 🀑

2
7
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

One principle I’d like to be enshrined in law:

If you create incentives that reward a behaviour, you can (and will) be charged as an accessory in any case where someone is doing something illegal as a result of optimising for that behaviour. An affirmative defence would need to demonstrate that you had safeguards in place to effectively disincentivise that behaviour.

For example, if you are running a delivery company and you set targets that mean people are paid more if they drive or park illegally, you are automatically charged as an accessory to however many counts of dangerous driving your drivers are charged with. If you are a city councillor and vote to close all of the public toilets so that there’s nowhere for taxi drivers to relieve themselves, you can be charged as an accessory to a few hundred counts of public urination.

2
2
0
repeated

Part 2 of the custom PE resources series: how to embed any binary as a resource in Visual Studio and extract it at runtime.
https://trainsec.net/library/windows-internals/how-to-embed-and-extract-custom-pe-resources-in-c-findresource-loadresource-makeintresource/

0
1
0
repeated

Windows Kernel Programming, Second Edition by Pavel Yosifovich is on sale on Leanpub! Its suggested price is $37.95; get it for $24.21 with this coupon: https://leanpub.com/windowskernelprogrammingsecondedition/c/LeanPublishingDaily20260601 @zodiacon

0
2
0
#RoundCube - Security updates 1.6.16 and 1.7.1 released

https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1

Seems pretty serious!
0
2
2
[RSS] Hacking your PC using your speaker without ever touching it

https://blog.nns.ee/2026/06/03/katana-badusb/
1
4
7
[RSS] Wow64 implementation details

https://winware31.blogspot.com/2026/06/wow64-implementation-details.html

"How is Wow64 implemented in Windows 11 25H2?"
0
0
1
repeated
I have a tinfoil hat theory, which is that personalised ads basically don't work
Show content

So tailoring ads to a broad audience obviously does work. You run ads for gamepads on videogame websites. You run ads for expensive wine in Yacht Owners Monthly.

But the massive surveillance-/ad-tech scheme, which collects ten thousand data points about every device and tries to match them to the perfect product, that basically doesn't do anything. It shows you ads for toilet seats because you've bought a toilet seat. It shows me ads for learning German because my device language is set to English and my IP geolocates to Germany. Neither of these campaigns will result in a sale.

Like. Contrast that with the FurAffinity model. "You pay the people who run this website to display ads. You know what sorts of people will see them because of what our website is like." That's far cheaper, far easier, and far less intrusive than the modern ad-tech approach. And the results it yields are probably *better.*

However, a third of the First World's economy is based on the assumption that this Rube Goldberg machine of espionage and real-time bidding actually does do something, so nobody wants to run the numbers.

3
5
0
repeated
In the latest episode of This is What the Web was Made For:

A dedicated domain for different kinds of railway damages

https://www.raildamage.com

#SmallWeb #Train #railway #tram #metro
0
2
0
repeated

20 years from now someone's Media Studies dissertation is gonna be titled "Parodies of Elon Musk in min-2020s popular culture"

0
1
1
repeated
Edited 3 days ago

Somebody wrote about Bring Your Own RWX Region DLL (BYORWXDLL).

Which, being a post-exploitation technique, is already something not terribly interesting to me personally, being a vulnerability analyst and all.

Stage 1: Realize that the provided script doesn't run, as it has a non-UTF-8 character in it (a 0x97 em dash). Since keyboards don't have an em dash key, this is a clear indicator that the script is AI slop. Also, who publishes something without even first attempting to run the very thing you have provided? πŸ€”

Stage 2: Realize that Intel(R) Extreme Tuning Utility, which comes with Intel graphics drivers by default comes with multiple libraries that have YOLO RWX memory sections.

Personally, BYORWXDLL isn't that terribly interesting to me. If somebody is injecting an arbitrary DLL on your system, they already own your system. However, I will admit that knowing which things on your system by design provide RWX memory sections is probably a good way to flush out the software that you don't want to have on your system.

1
3
0
Should've just asked for one of my heisenbugs...

RE: https://flipboard.social/@ScienceDesk/116686632823824615
0
0
1
Show older