Posts
4392
Following
737
Followers
1650
"I'm interested in all kinds of astronomy."
repeated

What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (Mozilla’s infrastructure is producing lots of builds).

https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/

1
2
0
[RSS] Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux

https://cravaterouge.com/articles/resetnightmare/
0
1
1
@dey The cybersecurity awareness you spread to me starts to itch. It also hurts to pee.

@briankrebs
0
1
3
repeated

The fastest way to get VIP treatment when you land...seriously, how dumb do you have to be to try something like this? This person on Reddit stole my thoughts verbatim: "committing federal crimes from inside a sealed metal tube that lands exactly where the feds are waiting is certainly a strategy."

https://www.reddit.com/r/delta/comments/1vl52vr/dl591_lasatl_arrival_met_by_federal_agents/

24
24
0
repeated
@david_chisnall Yeah, "architecting" is not the best word here...
0
0
1
Edited yesterday
I thought I'm making up a conspiracy theory around NVIDIA deliberately looking for bubbles to inflate - AI turned out to be a great one - after the crypto bubble bursted. It seems @david_chisnall agrees (sort of):

RE: https://infosec.exchange/@david_chisnall/117075838205635406
1
4
3
repeated

Finally, to close out our short tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

0
3
0
I wish California could promote LSD to politicians back in the day as effectively as they do today with AI.
0
0
3
[RSS] 4 jsoup vulnerabilities

https://joshua.hu/4-jsoup-vulnerabilities
0
0
0
Great, YT now put me into the "white girl music better than any pre workout" basket...
0
0
0
Now I feel irresistible urge to listen to Katy Perry o.O

https://www.youtube.com/watch?v=tmlGA_zFtpQ

Brains are weird. (fortunately I'm not alone in case crazy ear worms are an indicator of aneurysm :S)
1
0
0
repeated

Xenotime, Librarian of Æther trans_fedi

Edited yesterday
2
3
0
repeated
repeated

OpenSSH 10.5 has just been released, mostly to fix a handful of security vulnerabilities.

https://www.openssh.org/releasenotes.html#10.5

We plan to move to a more frequent release schedule for as long as this season of LLM-found bugs lasts. More details in the release notes.

2
7
0
The soundtrack of my dream was a Sabaton song about debugging Binary Ninja:

"Debug the Ninja
Binary Ninja
Debug the Ninja
This is the song"

(note: I don't usually listen to Sabaton)
1
0
1
repeated
@phillip Hot take: signups should be disabled at install time by default in almost every software.
0
3
4
repeated

RE: https://social.lol/@phillip/117061432689860232

The postmortem of the hack on my Forgejo instance is here! I had fun investigating and writing it, so I hope y’all enjoy reading about it :)

https://phunky.cafe/my-homelab-got-hacked/

2
7
0
repeated

this program was generated with LLVM assistance
"don't you mean LLM assistance?"
no, i mean i implemented a few examples and left the rest as UB for the compiler to figure out https://gcc.godbolt.org/z/hd5Mhdhev

1
8
0
Show older