Posts
4531
Following
741
Followers
1655
"I'm interested in all kinds of astronomy."
repeated

🚨 New advisory was just published!

A heap buffer overflow in a Windows DCOM service can be leveraged to escalate privileges from a Medium IL standard user to SYSTEM IL, an issue that occurs when attacker-controlled Power Setting data and length are passed to the PSM callback.

This vulnerability earned 3rd place in the Windows LPE category at TyphoonPWN 2026. Read all the details at: https://ssd-disclosure.com/dcom-service-psmserviceexthost-lpe/

0
2
0
repeated

if you have an lg tv

literally throw that shit off your roof

https://www.youtube.com/watch?v=6IFVTcM28KA

3
3
0
repeated

Two hours till my HTTP Terminator talk kicks off at SEC-T! You can catch the livestream at 9:15 UTC:
https://www.youtube.com/watch?v=S6R7cBZDdK4

0
3
0
Made the slop machine do a thing for me that may be useful for others too:

https://github.com/v-p-b/mdsrv

Static webserver that renders #Markdown files and #MermaidJS diagrams for your viewing pleasure. With live updates!

#python #llm
0
2
4
@cure53 do you have Google Ads (or similar) set up? They tend to burn user credits with similar gmail contacts (this user found you, proving our adtech works).
1
0
0
repeated

@zzt Most feature phones are hard to compromise because every time a malware author learns something about how they work, their brains explode.

0
2
0
repeated
repeated
repeated

CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20079

0
1
0
repeated

CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87491

0
1
0
re: #music #hardcore
Show content
@swapgs You know it's a good show when the openers could be the main act! RIP Riley :(
0
0
1
repeated
re: #music #hardcore
Show content
There is also a guy with a landing net at the other side of the stage "catching" stage divers xD
0
0
0
repeated

Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).

Read the full analysis of the exploit chain and post-exploitation tradecraft here: https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
 

0
2
0
#music #hardcore
Show content
Look like a nice recreational event <3

https://www.youtube.com/watch?v=RyNnleNxDIE
2
0
1
Edited yesterday
Default auto-generated CC on YT music videos is a great way to demonstrate how much Google's AI sucks.

Heat.
Heat.
[Music]
1-2-3
0
0
1
repeated
repeated

I miss the days when a toothbrush botnet was the dumbest headline.

2
8
0
repeated

RE: https://mstdn.social/@jukkan/117240247968300759

I just love this:

”Feature #23 is worth noting in isolation. LinkedIn collects the user’s Do Not Track preference, then excludes it from the fingerprint hash (line 9512, excludes: { doNotTrack: true }). They record that you asked not to be tracked. Then they track you.”

1
3
0
Show older