Posts
4641
Following
742
Followers
1661
"I'm interested in all kinds of astronomy."
repeated

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/

0
3
0
@ancientjames Michael Knight used this during his FLAG debriefings
0
0
1
repeated
repeated

@gregkh on LLMs.

The main point is: DON'T PANIC:!

... At the end 10 bugs fixed, 1hour kernel development...

1
6
0
@ulldma or you could pipe fortune or cowsay? :)
1
0
1
[RSS] ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE

https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce
2
4
6
repeated
Edited 3 days ago

periodic reminder that Wizard Zines has an educational use policy if you want to use them in your university courses! https://wizardzines.com/education/

0
2
0
repeated

RE: https://infosec.exchange/@cR0w/117315299719177302

Important: We have learned that this vulnerability has been exploited.

0
4
0
repeated

Poland's CERT has published its report on MikroTrik, the zero-day campaign that targeted MikroTik routers earlier this month

Praises LLM agents for helping with the research

https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/

0
4
0
My panic!() messages start to degrade to the quality of my commit messages
2
0
1
@dymaxion @kaoudis You are right, and now I think here lies the solution: with pentests you want priorities based on how an external party sees your system. Does this make sense?

(having to think about these things shows how much time passed since I started doing pentesting...)
1
0
0
repeated

It's so good to see this in the MIT Tech Review. Let's hope the message gets through. 🤞Big props to @timnitGebru & @emilymbender for putting such a fine point on things!

"Instead of OpenAI being prosecuted for creating malware that hacked another company, press releases, news outlets, media personalities, and lawmakers refer to “rogue models” as if they acted on their own. Instead of researchers being questioned about their companies’ habit of plagiarizing academics’ work or using customer data to train models without consent, the public’s imagination is redirected to fears about what the future might hold upon the arrival of fictional superintelligent machines."

https://www.technologyreview.com/2026/09/22/1144867/dont-be-fooled-summer-ai-hype/

2
8
0
@dymaxion @kaoudis I guess back in the day this was about workforce distribution? People with pentest skills usually didn't work at places that required them + project distribution didn't justify hiring? There is also a conflict of interest if a person with pentest skills also works on the system under test.
1
0
0
repeated

"It is hard to be brave," said Piglet, sniffing slightly, "when you're only a Very Small Animal."

0
2
0
[RSS] How One Twitch Chat Message Became Code Execution on a Streamer's PC

https://blog.scrt.ch/2026/09/22/how-one-twitch-chat-message-became-code-execution-on-a-streamers-pc/
0
0
1
repeated

The Irish Presidency of the EU has proposed member states to allow AI companies unfettered access to the data of EU citizens.

According to leaked docs, the proposal would effectively exempt AI companies from any of the GDPR rules and deny EU citizens data protection rights

https://noyb.eu/en/ai-eu-member-states-plan-digital-expropriation-europeans-interest-ai-companies

9
8
0
repeated

Everyone ready to vote for the fattest bears? Who are your picks for the 2026 competition?

I'm voting 910!

https://katmaiconservancy.org/fatbearweek

0
3
0
repeated
Show older