Posts
4641
Following
742
Followers
1661
"I'm interested in all kinds of astronomy."
Can gzip be a language model?

https://nathan.rs/posts/gzip-lm/
0
0
1
repeated
repeated

A first public side-channel attack on the Arm CryptoCell-310.

Our latest blog post walks through the full methodology: EM signal analysis, a collision-correlation attack, and full AES key recovery.

Read it here: https://www.eshard.com/blog/side-channel-analysis-arm-cryptocell-310-aes

0
4
0
repeated

[Commercial, since it involved my company] Two of my friends - Jarosław Jedynak and Michał Leszczyński - are doing a webinar on Kubernetes hacking tomorrow, with live demos and stuff. It's free, but you do have to sign up to hackArcana's newsletter:

https://hackarcana.com/workshop-session/2026-Q4-k8s/intro-webinar

0
2
0
It's funny how WinDbg's TTD docs[1] emphasizes that PII may appear in dumps, while e.g. docs for crash dump analysis[2] don't.

Based on the observation that behind every warning sign there is a story I suspect that at one point a TTD trace somehow resulted in summoning MS's legal team :)

[1] https://learn.microsoft.com/en-us/windows-hardware/drivers/debuggercmds/time-travel-debugging-overview
[2] https://learn.microsoft.com/en-us/windows/win32/dxtecharts/crash-dump-analysis
0
0
0
repeated

📢 Registration for CHERITech'26 is now open!

Join us on 12-13 November 2026 alongside SEMI Europe's SEMICON Europa 2026 at the NextSEMI Arena (Hall B0), Messe München, Germany for two days of talks, technical discussions, and networking focused on CHERI, memory safety, and secure computing.

How to register:

1️⃣ Purchase a valid SEMICON Europa 2026 ticket
2️⃣ Complete the CHERITech'26 registration form

Please note: CHERITech'26 is free to attend for all SEMICON Europa 2026 visitors. However, a valid SEMICON Europa 2026 ticket is required for each day you wish to attend CHERITech'26.

🔗 Register and learn more: https://cheri-alliance.org/events/cheritech26/

0
4
0
Today's xkcd is especially unhinged, love it!

https://xkcd.com/3301/
0
1
3
[RSS] Windows Exploitation Techniques: Dangling COM Object Registrations

https://projectzero.google/2026/09/windows-dangling-com.html
0
1
1
#IBMi could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys

https://www.ibm.com/support/pages/node/7285846

The 90s called and want their dumb obfuscation back!
0
2
9
@Natasha_Jay I really like Andorra's concept of Transportation via Electric Boogie!
0
0
2
[RSS] Advisory X41-2026-004: dm-verity can be bypassed in Debian live-boot

https://x41-dsec.de/lab/advisories/x41-2026-004-debian-live-boot/
0
1
2
[RSS] ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553

https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
0
0
0
repeated
repeated

LittleAlex 🇺🇦🇮🇱🇩🇪🇳🇴

How Much Data Does an Idle Android Phone Send to Google? (72-Hour Packet Benchmark)

https://www.praveentechworld.com/research/degoogle-telemetry-2026

0
3
0
repeated

Allele Security Intelligence

After 6 successful runs of our Introduction to Linux Kernel Exploitation training—across both public and in-company cohorts—and a 100% positive rating from our students, we are offering it for the first time in English!

This is your opportunity to gain hands-on experience with computer architecture, kernel debugging, the Linux kernel, exploit development, and modern mitigation bypasses alongside an instructor doing top-tier vulnerability research.

Here are a few testimonials from our former students:

"I've always wanted to master the Linux kernel, and this course by Anderson and the Allele Security Intelligence team was the perfect opportunity. It expanded my architecture knowledge, sparked my interest in binary exploitation, and completely exceeded my expectations!"

"An exceptional course on computer architecture and the Linux kernel. The clear structure made complex concepts intuitive, and the practical exercises were game-changing for learning how to identify and exploit kernel vulnerabilities."

What sets our training apart:

Direct support: Personalized contact and guidance starting as soon as you enroll.

Cutting-edge content: Up-to-date curriculum drawn from public sources and our own internal security research.

Expert instruction: Taught by an instructor with over 10 years of world-class vulnerability research experience.

Flexible learning: Class recordings uploaded within 24 hours so you never miss a lesson.

Structured & Accessible: Detailed, beginner-friendly documentation that makes complex concepts easy to follow.

Registration is open! We have a Super Early Bird discount available for the first 4 students.

We also offer corporate group packages. If you have any questions or need assistance with the enrollment process, please let us know—we’re happy to help!

Check out the link below for more details and to enroll:

Introduction to Linux Kernel Exploitation – September 2027
https://allelesecurity.com/introduction-to-linux-kernel-exploitation-september-2027/

0
2
0
repeated

Was going to write a couple of posts here about my weekend experiment but decided to make it a bit more permanent so it can be tested by time. If not, just a bit of random (silly) writing practice before those skills are lost forever.

https://reverse.put.as/linesignal/

1
2
0
repeated
repeated

SAML was created in 2002 by merging four rival XML security protocols into one spec. That design still generates vulnerabilities: a canonicalization flaw via XML comments in 2018, XML round-trip bugs in Go's stdlib in 2020, a GitHub Enterprise SAML auth bypass in 2025, and more.

Matt Schwager breaks down 5 design flaws behind the pattern and makes the case for moving to OIDC.

https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/

1
2
0
Show older