Posts
4621
Following
742
Followers
1659
"I'm interested in all kinds of astronomy."
repeated

Happy announcement: My colleague and me will present a talk at hardwear.io NL 2026, "Vulnerabilities That Get Under Your Skin: Targeting the World’s Best-Selling Infusion Pumps". 100% human-brain VR 😛

1
3
1
repeated

Draw a fish and watch it swim in a tank with everyone else who's drawing them too 🐠🐟🐡

Silly, but also lovely

https://drawafish.com/

2
6
0
If I had a cent for every occasion I had to debug `if let Some(foo)=` moving `foo`, I had 2 cents...

#Rust
0
0
2
@christopherkunz I only ever encountered TACACS at the university, and I've seen shit o.O
1
0
0
repeated

hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪

TIL a recent? Zed update shows you the JSON path to the item you have the cursor at.

0
3
0
repeated
Edited yesterday

poll: in Git, do you ever use any of the references `MERGE_HEAD`, `REBASE_HEAD`, `CHERRY_PICK_HEAD`, `ORIG_HEAD`, `FETCH_HEAD`, or `REVERT_HEAD` etc? (and if so, what do you use them for?)

1% yes, every week or more
13% yes, occasionally
44% no, never
40% no, and I have no idea what they are
7
3
0
repeated

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/

0
3
0
@ancientjames Michael Knight used this during his FLAG debriefings
0
0
1
repeated
repeated

@gregkh on LLMs.

The main point is: DON'T PANIC:!

... At the end 10 bugs fixed, 1hour kernel development...

1
6
0
@ulldma or you could pipe fortune or cowsay? :)
1
0
1
[RSS] ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE

https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce
2
4
6
repeated
Edited 2 days ago

periodic reminder that Wizard Zines has an educational use policy if you want to use them in your university courses! https://wizardzines.com/education/

0
2
0
repeated

RE: https://infosec.exchange/@cR0w/117315299719177302

Important: We have learned that this vulnerability has been exploited.

0
4
0
repeated

Poland's CERT has published its report on MikroTrik, the zero-day campaign that targeted MikroTik routers earlier this month

Praises LLM agents for helping with the research

https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/

0
4
0
My panic!() messages start to degrade to the quality of my commit messages
2
0
1
@dymaxion @kaoudis You are right, and now I think here lies the solution: with pentests you want priorities based on how an external party sees your system. Does this make sense?

(having to think about these things shows how much time passed since I started doing pentesting...)
1
0
0
repeated

It's so good to see this in the MIT Tech Review. Let's hope the message gets through. 🤞Big props to @timnitGebru & @emilymbender for putting such a fine point on things!

"Instead of OpenAI being prosecuted for creating malware that hacked another company, press releases, news outlets, media personalities, and lawmakers refer to “rogue models” as if they acted on their own. Instead of researchers being questioned about their companies’ habit of plagiarizing academics’ work or using customer data to train models without consent, the public’s imagination is redirected to fears about what the future might hold upon the arrival of fictional superintelligent machines."

https://www.technologyreview.com/2026/09/22/1144867/dont-be-fooled-summer-ai-hype/

2
8
0
Show older