Remember the #Gitlab 16.0 vulnerability and the message to patch it asap ?
Well: https://securityonline.info/poc-exploit-released-for-gitlab-cve-2023-2825-vulnerability/
The PoC is here: https://github.com/Occamsec/CVE-2023-2825
New: NSO Group is under new ownership after lenders forced a change of control with plans to keep its controversial spyware business going. Lenders have been working with Omri Lavie, a co-founder of NSO, after foreclosing on the parent company. https://www.wsj.com/articles/israeli-cyber-company-nso-group-has-new-ownership-after-u-s-blacklist-a2cda00a
Technology and defense systems giant Rheinmetall AG has been breached by Black Basta.
Rheinmetall has over 27,000 employees and is in 138 countries.
Oh wow, Stalker and Solaris are just on Youtube for free, officially uploaded by Mosfilm, the original production company. They've got a bunch of other Soviet films up there too.
https://www.youtube.com/watch?v=Q3hBLv-HLEc
https://www.youtube.com/watch?v=Z8ZhQPaw4rE
Twitter’s encrypted DM feature is technically flawed, opt-in, limited to 1-to-1 text-based messages, restricted to a small user base, and generally inferior in just about every way to encrypted apps like Signal and WhatsApp.
And all for just $8 a month. https://www.wired.com/story/twitter-encrypted-dm-signal-whatsapp/
It turns out you can simply serve a file from a domain to use it as your bsky handle.
So this guy is now S3. All of S3.
Hi all! Firefox Attack & Defense is now on Mozilla's Mastodon Instance. Follow us for news about our bug bounty program: How to find bugs and participate more effectively.
We won't post a lot, but we promise a high signal-to-noise ratio.
#introduction
Kindergarten children dropped seeds in the crack of the sidewalk to see what would happen 🤗 https://streetartutopia.com/2023/04/15/kindergarten-children-dropped-seeds-in-the-crack-of-the-sidewalk-to-see-what-would-happen/
Nature is everything 🌱
DOJ actually detected the SolarWinds hack in its network back in May 2020 and Microsoft, Mandiant, SolarWinds all looked at it at the time, but didn't grasp what they were seeing. Six months later Mandiant publicly exposed the campaign. @kimzetter back in WIRED! https://www.wired.com/story/solarwinds-hack-public-disclosure/
Here, I made you a Slack emoji for when you're talking about GenAI
Today is the 30th anniversary of the announcement of the Clipper Chip, an ultimately failed proposal for "key escrow" cryptography that ignited the "crypto wars" of the 1990's.
Want to get into reversing or learn new advanced topics? Here are my favorite tutorials, talks, blog posts and podcasts! #reverseengineering #reversingshorts
https://youtu.be/6N0mk9s0ylU
I finished reading World Wide Waste by Gerry McGovern. I'd consider it essential reading for anyone working with computers!
https://gerrymcgovern.com/books/world-wide-waste/
It's well cited (though I still need to check those citations) & uses maths effectively to make it's point.
That computers + (surveillance) capitalism is actually worse for the environment than the predigital era. That we can and must move slow and fix things, and fund that vital work directly.
Somewhere, someone finally made this and I think it's beautiful