Posts
4344
Following
737
Followers
1646
"I'm interested in all kinds of astronomy."
[RSS] Confidential Computing on Arm: Architecture & Use Cases

https://www.linaro.org/blog/confidential-computing-on-arm-architecture-use-cases/
0
0
0
repeated

The man whose codebreaking may have helped to shorten the Second World War by two years met a grim reward: in 1952 Alan Turing was convicted simply for being gay and chemically castrated; a royal pardon came only in 2013, decades after his death

By Space Daily Editorial Team

https://spacedaily.com/m-the-man-whose-codebreaking-may-have-shortened-the-second-world-war-by-two-years-met-a-grim-reward-in-1952-alan-turing-was-convicted-simply-for-being-gay-and-chemically-castrated-a-royal-pardon-came/

More information about Alan Turing:
https://en.wikipedia.org/wiki/Alan_Turing

4
6
0
@VirusBulletin Whoever decided to use shades of $color for chart segments should be fired on the spot.
0
0
0
repeated

Authenticated RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0 https://github.com/berabuddies/redis-poc

0
3
0
repeated

Fun fact:

If you go to report a vulnerability to MSRC that is a missed-fix or a variant of something that Microsoft has already released an update for, you must provide the existing VULN- identifier. Just a CVE isn't enough, for reasons I cannot fathom. (If you tell Microsoft a CVE ID, they themselves can easily see which VULN- ID is associated with it.)

Meaning, only the person who reports a vulnerability to Microsoft is allowed to tell them that the fix wasn't good enough. (The VULN- ID is what you get when you submit a case to MSRC)

Great job, folks. It instills great confidence when your form for receiving vulnerabilities confuses when to use OR with when to use AND. 🤦‍♂️

4
3
0
repeated

There's apparently scammers going round pretending to be Mastodon admins, demanding people "verify their identity".

Do not click on their links, do not give them any info. It is a scam. Genuine Mastodon server admins never demand verification like this.

Here's a guide to how to recognise and avoid various kinds of scams on Mastodon and the wider Fediverse:

➡️ https://fedi.tips/how-to-avoid-scammers-on-mastodon-and-the-fediverse

(Thanks to @amministratore for providing warning about the latest wave of scam posts.)

4
33
0
repeated

Apple has fixed the bug in Hide My Email that linked Hide My Email addresses to your real one, but leaked email addresses could still be in third-party logs: https://easyoptouts.com/guides/apple-hide-my-email-was-leaking-email-addresses

0
3
0
@gsuberland Tampermonkey scripts escaping their containment sounds like a technological breakthrough, prepare a press release!
0
2
8
One more thought on the OAI vs HF thing:

If you are wondering how serious network isolation is at these companies, try to install an arbitrary subset of their tech stack without Internet access. Good, now try to install updates!
0
0
2
@cR0w "at the cost of research velocity while the vulnerabilities are patched."

I've spent enough time in enterprise settings to recognize that this translates to "security is a cost center and we spend as little on it as we legally can". I do love how they manage to also blame due diligence as a cause of not whacking more moles!
1
5
9
repeated

Alesandro Ortiz 🇵🇷🏳️‍🌈

🎶 Here comes another bubble.
The VCs are backing,
Baby let's get cracking. 🎶

Here Comes Another Bubble (2007):
https://www.youtube.com/watch?v=I6IQ_FOCE6I

0
2
0
@nullandnull I need something for one-off diagrams, I don't want to write a formal declaration this time. My best idea so far is to annote the bytes in some GUI that supports this (IIRC 010 does?), and take a screenshot...
1
0
0
repeated

i don’t usually respond to these kinds of emails, but this one made me so fucking mad that i blacked out and regained consciousness with this in my outbox

25
24
3
Dotcom bubble nostalgia in the local pubs restroom
0
4
7
Any recommendations for generating annotated hex dumps for #documentation, optimally (but not necessarily) something like @angealbertini's format dissections:

https://github.com/corkami/formats/blob/master/image/PNGRGB_dissected.png

#ReverseEngineering
1
1
0
RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race
(CVE-2026-64600)

https://www.openwall.com/lists/oss-security/2026/07/22/14

Mythos writes Qualys advisories now FML :P
0
0
0
repeated

Google just had its first negative cash flow quarter ever due to massive AI spending

Google continues to report big quarterly revenue, but its AI spending has skyrocketed.
https://arstechnica.com/google/2026/07/google-just-had-its-first-negative-cash-flow-quarter-ever-due-to-massive-ai-spending/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

9
11
0
repeated

The new UI quality of life improvements are pretty nice, especially jump anywhere and pathfinder. I'm starting to like them!

https://hex-rays.com/blog/ida-9.4-smarter-navigation-and-quality-of-life-improvements

Digging deeper into the SDK now, some recent changes in IDA 9.4 might impact my idalib-based plugins (hopefully in a good way).

0
2
1
repeated

the headlines are near satire at this point

0
2
0
Show older