Posts
4286
Following
738
Followers
1633
"I'm interested in all kinds of astronomy."
repeated

They AI slopped up a few CVEs on SATURDAY and none of what it describes talks about the actual impact, claims NULL derefs/kernel panics/"corrupted ciphertext results"/"decryption bypass". Pure slop.

1
1
0
repeated
repeated
Edited 12 hours ago

I'm convinced that UI developers are my mortal enemies.

Today's experience: Microsoft Outlook, which I have to assume is popular for some reason.

I go to delete a calendar item that I created for testing. Upon hitting [Delete] on my keyboard, I'm presented with the following dialog.

Which button will continue with the deletion of the item?

  • [➡️ Send]
  • [🗑️ Discard]

If you selected the 🗑️ button to delete the entry, you're a fool like me. Obviously the [➡️ Send] button is the one you click to delete the thing. [🗑️ Discard] obviously means [❌ Cancel] (do nothing).

3
5
0
The year is 2026. Literal trillions are spent in the hope to revolutionize the IT industry.

At the same time children have to deal with OAuth flows, One-Time Passwords and consent prompts to play Minecraft.

We really should stop fetishizing new software and stop for a brief moment to think through how software *should* work so it'd make our lives a bit better.
1
2
2
If only search was considered in Mastodons design...

RE: https://infosec.exchange/@cR0w/116953352499158321
1
0
0
repeated

#3274 - Arthurian Connector

0
5
0
repeated

Today Excel bugged me again to rate it, and when I tried it told me I was ineligible to submit a review.

Once again I am asking for all technology to be cast into the sea immediately or sooner.

1
14
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft Windows NETIO.sys NsipGetAllInformationProviderParameters Information Disclosure Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2443

CVE-2026-50475,CVE-2026-50475,CVE-2026-50475
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Foxit Foxit Reader Javascript checkbox CBF_Widget code execution vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2420

CVE-2026-57256,CVE-2026-57256
0
1
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2426

CVE-2026-58613,CVE-2023-29361,CVE-2026-58613,CVE-2026-58613
0
1
0
[RSS] Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454

https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
0
0
1
[RSS] Defender Internals - AI Assisted EDR Introspection

https://blog.deeb.ch/posts/defender-ai-introspection/
0
0
1
At this point I'm not 100% sure LLMs are not alien psyops against our species (coincidentally I'm in the middle of Three Body Problem)
1
2
11
@schrotthaufen Good news is that Average Joe is probably not interested in hacker blogs or similar "dual-use" content :)
0
0
0
@root The main problem for visibility is mobile. I want a solution where the users don't have to look at domain names at all: how will Aunt Judy know if mybank.foo or my-bank.bar is the right one, esp when even legit providers rely on crappy redirectors for adtech?
0
0
1
@schrotthaufen I like the uBlock idea! I wonder how hard it's to maintain the lists though...
1
0
0
repeated

Remember to boost things you like, even if the post is old!

You are the algorithm here 🫵

10
21
1
I've been thinking a lot about securing online transactions for laypeople.

A major issue seems to be that URLs are 1) often not visible 2) not designed for laypeople, so many of us have no idea who they are communicating with.

I'm looking for a reliable browser extension that can block site access based on domain allow-lists, extensible by country.

Any recommendations?

#security #phishing #scam
2
1
1
repeated

Hacker Summer Camp Watch Week starts Monday!

We’ll be watching classic hacker documentaries, DEF CON talks, and hacker history live on YouTube & Twitch from my 6TB InfoCon archive before heading to Vegas.

You can grab the same archive free at infocon.org or the Data Duplication Village.

0
4
0
Show older