Posts
4358
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated

New directory traversal CVE!
CVE-2026-15435
IBM - App Connect Enterprise
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

0
2
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

So many POSIX 'RATIONALE' sections can be distilled to:

One vendor did stupid thing A. Another did stupid thing B. We defined this interface to permit both implementations because designing a third thing that's sensible is, sadly, not within our remit and there are existing consumers of both of the stupid APIs.

6
4
0
repeated

"You don't need pentesters anymore." - Every hype cycle, ever.

While the AI debate continues in Vegas, we'll be busy finding the bugs it missed and proving which "findings" were never vulnerabilities in the first place.

Happy Black Hat & DEF CON!

0
1
1
repeated
repeated

sometimes I say "no worries!" when I am at least 33% worries

1
7
0
repeated

Another security position at Mozilla. Help manage our (web) bug bounty program on HackerOne as a Senior Security Engineer https://job-boards.greenhouse.io/mozilla/jobs/8088831 (job posting says Germany, but other countries are eligible, use the job search)

2
2
0
repeated

Check @aleeamini 's post. He has done a remarkable job of analyzing samples from last year's wipe of Iranian banks. I briefly wrote and talked about the operation before, but now that the cat is out of the bag, I guess everyone gets to enjoy the craftsmanship behind it. The blog post covers only the post-exploitation phase and local side of works, jumping from local access to unrestricted firmware and memory. The initial access remains uncovered here, but I strongly believe at least one of the RCEs dell fixed last year was used for gaining initial access to storage devices.

The structure and style of tooling and operation is also very similar and hallmarks of the infamous Predatory Sparrows. Details about this overlap will remain TLP gated though. You might remember a glimpse of that from the wiping attack against Iranian gas stations and fuel distribution system, which also attempted soft-bricking POS devices installed on pumps, combined with partial wipe of mid-level management and relay servers.

One of the most interesting aspects of these wipers used in Iran, which I believe are first of its kind publicly documented as well, are combining software based wipes with physical disruption of operation of device switches. This is mostly an effort to further block attempts to interrupt the wipe operation by physically switching off or restarting the storage device on-site. That alone buys some extra wipe time, before datacenter operators literally pull the plug on machines.

https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/

0
4
0
Edited yesterday
#music #reggae
Show content
96 degrees in the shaaaaade

https://www.youtube.com/watch?v=hwE5gfZlMZY

In the related news: the only nuclear power plant of Hungary is about to shut down because there's not enough water in river Danube
0
0
1
repeated

RE: https://infosec.exchange/@david_chisnall/117007707710681727

“All encryption is end-to-end, if you’re not picky about the ends.” -- Chris Fenner

0
3
1
repeated
repeated

The screensharingd bug that was killed on latest updates, is a pre-auth, contrary to what the company that disclosed it to Apple is writing. This is an amazing bug that allows to pwn any unpatched Mac that has Screen Sharing enabled. If you have it enabled go patch now. If you have old versions for which a 5T company doesn't bother to release patches, good luck!

Releasing a PoC that just allows to download any file from vulnerable machine.

https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/

1
8
0
If you like this post, please consider supporting this GitHub issue:

https://github.com/rust-lang/cargo/issues/16574

#Rust #Cargo
0
0
1
Serious request:

Stop assuming that users have Internet access!

#OldManYellsAtCloud
2
6
8
[RSS] XProtectRemediatorDubRobber infoleak on macOS (CVE-2024-40842)

https://gergelykalman.com/CVE-2024-40842-xprotectremediatordubrobber-infoleak-on-macos.html
0
0
0
repeated
Edited yesterday

I find this compelling, but my economic clue is subprime (pun intended). I would love to read critique on their arguments.

https://www.groundbrkr.com/p/the-second-derivative-why-no-one

0
2
0
repeated
Show older