Posts
4460
Following
738
Followers
1659
"I'm interested in all kinds of astronomy."
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Adobe Photoshop Installation privilege escalation vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2360

CVE-2026-48388,CVE-2026-48388,CVE-2026-48388
0
1
0
repeated
repeated
Edited yesterday

This is the first genuinely operational littleFedi instance.

It has been online since 1st July, is single-user (just me), and runs on a Raspberry Pi Zero W powered by NetBSD, directly on its SD card.

It consumes just under 1W.

Its database is this size:

-rw------- 1 little wheel 109289472 Aug 26 15:14 littlefedi.db

That is, just a little over 100 MB. Yes, MB.

Its average CPU load is extremely low.

It is perfectly usable both from the web interface and from Mastodon API apps.

I have 179 followers and 169 followings, and it doesn't bat an eye.

I promise myself to use it more, and I will.

You don't need Big Tech to communicate with others.

You don't need an expensive data center to exist online.

Because we are people, and the bits are just extensions of our voice.

EDIT: littleFedi allows to transform posts into blog posts, having its own SSG (Static Site Generator). The one generated by this post is reachable by clicking here.

11
32
2
repeated

Meta, mid trial, agrees to settle claims that Facebook and Instagrams harmed children with the owner of the social media platform to pay 29 states more than $16 billion. https://www.reuters.com/world/us/meta-settles-with-us-states-over-social-media-harms-2026-08-26/

2
4
0
repeated
Phallic imagery
Show content

This is the latest Hungarian memorial for the 500th anniversary of the Battle of Mohács against the Ottomans.

Yes. It is real.

Yes. We lost that battle.

6
5
1
repeated

RE: https://ohai.social/@TarkabarkaHolgy/117134297730197472

I am sorry, I have to add an update based on a recent news article:

1. The memorial has been dismantled

2. It was supposed to depict a bird with a helmet, soaring into the sky

3. The design was - surprise, surprise - generated by

4. The mayor claims he didn't see the finished product, because he was taking time off for pink eye

You can't make this stuff up

7
4
0
@gynvael Will the recent announcement about EU prints affect the Lulu shop?
0
0
0
repeated

Quick announcement:

We're putting on-hold most Paged Out! prints for conferences/events in EU due to the EU's Packaging and Packaging Waste Regulation.

For now we need to figure out where exactly do we stand with this legally. We'll post an update once there's some movement.

1
1
0
[RSS] What's in a tag name? JavaScript, apparently

https://portswigger.net/research/whats-in-a-tag-name-javascript-apparently

This should be illegal #xss
1
1
2
repeated

worked for me so far.

2
3
0
repeated

We just got a root shell on a @starlink terminal antenna! To our knowledge, this is the first full exploit of a "square dish" since @lennertwo's attack on the "circular" one in 2021.

@spacex security team has done an amazing job, leaving us no choice but a *hardware attack* to achieve this 👏 The demo below shows what's only possible on actual rooted hardware: reading fuse register contents, accessing hardware-encrypted "file_edr" data, and more.

0
3
0
repeated

Feds: Super sophisticated computer hacking hackers hacked all the utilities!

The actual attackers:

5
18
0
repeated

We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.

It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.

Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/

2
8
0
repeated
Edited 2 days ago

A bit annoyed by tech reporting again. Found two major tech news outlets provide an incorrect explanation of the WebAudio fingerprinting (not you arstechnica. You did good). The thing is mostly prevented in major browsers like Firefox, as explained in this excellent technical analysis https://ritter.vg/blog-webaudio_alibaba.html by @tomrittervg.

Worst part is the article that went straight for FUD and had links for paid articles explaining how to "protect yourself" blergh. I thought better of you heise...

1
1
0
[RSS] Ruby Marshal Kick-off Gadgets - elttam

https://www.elttam.com/blog/ruby-marshal-kick-off-gadgets
0
0
0
repeated

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

https://nvd.nist.gov/vuln/detail/CVE-2026-57909

1
1
0
repeated
@buherator u might like this madness hehe

https://youtu.be/etNTbFZGV8E
1
1
0
@cygnus-xr1 nice work! That thing needs a pilot license...
0
0
0
repeated

Mythos: 0
Aisle: 29

😱

5
4
0
repeated

Did you read our latest publication?

Our latest advisory covers a critical vulnerability in UNISOC modem firmware that can provide unrestricted read and write access to physical memory, potentially leading to arbitrary code execution with kernel privileges.

At SSD Secure Disclosure, we’re actively looking for baseband vulnerabilities and exploits, particularly high-impact research that can lead to remote code execution or equivalent impact.
Working on baseband security? Let us get you the highest payout available!

Check out our full product scope at https://ssd-disclosure.com/product-index/

0
1
0
Show older