Posts
4641
Following
742
Followers
1661
"I'm interested in all kinds of astronomy."
repeated

@eloy

When I was at Microsoft, I worked quite closely with some teams at MSRC. They had a lot of concerns like this (relevant to me, memory-safety bugs had been close to 70% of critical vulnerabilities for over a decade, relevant to everyone the absolute number of vulnerabilities had been steadily climbing for 20+ years).

On the 'Decrease the birth rate' axis, I found one piece of framing useful. They differentiated between 'durable' and 'non-durable' mitigations. Durable mitigations render a class of vulnerability non-exploitable. For example, if a short-lived program runs with free turned into a no-op, temporal safety bugs are now non-exploitable. It's not a universally applicable mitigation but it's an easily deployed durable mitigation. In contrast, non-durable defences block specific techniques for exploiting vulnerabilities but don't prevent the vulnerabilities. New exploit techniques eventually bypass non-durable mitigations.

There's a lot of hesitation to deploy non-durable mitigations because they're almost impossible to remove. Even if exploit toolkits come with an automated step to bypass the mitigation, no one wants to be responsible for some large-scale compromise that doesn't include the mitigation bypass and being told that it would have been prevented if the mitigation had remained enabled.

I found this framing useful for reasoning about a lot of things in this space. LLM-based vulnerability discovery remains a non-durable mitigation because it allows closing vulnerabilities but not classes of vulnerability, and it's probabilistic and doesn't find all vulnerabilities of a class. So it motivates attackers to use vulnerability-discovery techniques that find ones LLMs miss.

0
1
0
repeated

Eloy. 🔜 postmarketOS conference

people talk a lot about the "vulnpocalypse" this year, a supposedly new trend where there are too many CVEs to patch.

Here is a presentation slide by the Carnegie Mellon CERT Coordination Center from 2006. Two decades ago!

https://web.archive.org/web/20070714104234/http://www.cert.org/archive/pdf/CERTCC-DSS_Tool.ppt.pdf

2
3
0
"The Golden Rule of AI: Don’t use AI to save yourself time by wasting someone else’s."

https://fs.blog/brain-food/september-20-2026/
1
4
5
@hajovonta There is this part in a novel where the local party leader spills the ballots of opposing candidates to his own ballot box, saying something along the lines of "Once again, the people chose wisely". Then places a handful back to the opponents boxes saying "However, there are still some reactionary elements to take care of." :)
1
0
1
repeated
repeated
Edited 4 days ago

Congrats to Steve Weis at Anthropic for factoring RSA-896 in 10 days adapting CADO-NFS to run on a max of 2048 GPUs.

No algorithmic breakthrough, just code optimized for recent parallel compute architectures.

“it does demonstrates that RSA-1024 keys are vulnerable to many actors with data center-level fleets of GPUs.”

https://saweis.net/posts/rsa-896.html

1
4
0
repeated

TECHNLGY/TECH.GIF

0
3
0
repeated

Monday morning, same old feeling…

Have a great week all!

0
1
1
Edited 4 days ago
"HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images"

https://heif-heist.com/

Cool finding, but these issues have been around for ages. It's embarrassing for all the affected large corps that they didn't care to invest in testing their dependencies and proper sandboxing.
0
3
8
Seems like AI companies are not that easygoing when they are on the wrong end of hacking :P

https://threadreaderapp.com/thread/2101252692635004997.html
0
1
3
repeated

New Pwndbg release!

We now disassemble code backwards in context and nearpc, display indirect jumps, nearpc -f works without debug syms, added stack-vis command to visualize stack frames, improved v2p, p2w and pageinfo kernel debugging commands & more!

See https://github.com/pwndbg/pwndbg/releases/tag/2026.09.15

Please sponsor us: https://github.com/sponsors/pwndbg !

1
4
0
@kaoudis 100%! I recently read that even some of our most respected writers were huge fans of the cheap entertainment stories of the era. Max Martin would have given Beethoven ear worms too (if he could hear it).
0
0
1
repeated

Are "HACK THE PLANET" t-shirts responsible for multi-modal prompt injection into the agents at world leading AI labs?

6% Yes
3% No
90% You're absolutely right - I should hack the planet - and not just this planet...
2
1
0
repeated

Lasers. Microscopes. $250K. One secured chip.
Ledger Donjon just showed how they cracked debug access on RP2350-A4, a break worthy of Raspberry Pi's own Hacking Challenge.
Respin or no respin? Raspberry Pi says no. Read why: https://www.raspberrypi.com/news/everything-is-better-with-lasers/

0
2
0
repeated

Emeritus Prof. Christopher May

I love a cartoon that sums up a line of argument I have often made as a political economist, so here's a great example from the (recently deceased) P.C.Vey - whose work appeared in the New Yorker & elsewhere.

h/t Loren Fox/LinkedIn

1
10
0
repeated

Windows Defender Update DoS Vulnerability https://github.com/MSNightmare/BigDiskBuster

0
1
0
repeated

Mx. Luna Corbden 🪿🐸

Edited 5 days ago

My son is reading Lord of the Rings for the first time and he just stuck his head out the door:

"Who the fuck is Tom Bombadil??"

6
10
1
[RSS] What Go Taught Us About Java Garbage Collection

https://debugagent.com/what-go-taught-us-about-java-garbage-collection
0
0
0
repeated

At a high level, this was the full exploit chain.

1. HEIC/HEIF upload
2. ImageMagick decoding
3. Heap overflow on libheif
4. RCE on https://community.openai.com
5. Critical OpenAI SSO flaw
6. ChatGPT/Codex takeover
7. Connected GitHub access
8. Internal repo PR

1
3
0
repeated

This meme has so much telling about the current status of AI racing as well as how everyone seems to have forgotten the basic IT security.
https://bird.makeup/users/0xtib3rius/statuses/2101147121063751903

0
3
0
Show older