Posts
2524
Following
646
Followers
1461
"I'm interested in all kinds of astronomy."
It seems after burning God knows how much money and CO2, OpenAI decided that *maybe* if you want to have anything close to "intelligence" you'll need some reasoning. Can't wait to see how they scale against this problem!
0
0
0
repeated

This is cool. We ported parts of the Windows MDM stack (used by Intune) to Linux!! Now you can use it to EASILY control the configuration and security posture of Linux VMs in Azure.

https://learn.microsoft.com/en-us/azure/osconfig/quickstart-sec-baseline-mc?tabs=azure-cli

0
3
0
repeated

Microsoft is building new Windows security features to prevent another CrowdStrike https://trib.al/otEVx6r

0
2
0
Some exploits are just three curl commands in a trench coat.
1
5
17
repeated

I FOUND IT.
it took nearly four hours, but i found it.

thank you for coming along with me into the mines of my twitter archive to find this gif. dropbox deleted this, and many others when they 'just decided' to delete all locally stored files, making all the stuff you had exist only in the cloud.

i fired them for this, and replaced them with synology drive, that I sync over wireguard.

7
4
0
A colleague just wanted to gift me an InkJet...

https://en.wikipedia.org/wiki/White_elephant
1
0
1
repeated

You asked, and we delivered! Check out the new Microsoft Incident Response Ninja Hub for a compilation of the research and guides that the Microsoft IR team has developed over the years on threat hunting, case studies, and more.

https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/welcome-to-the-microsoft-incident-response-ninja-hub/ba-p/4243594

0
3
1
repeated

For those of you who might like it: Here are the slides from my Alligatorcon talk:
https://gergelykalman.com/the-forgotten-art-of-filesystem-magic-alligatorcon-2024-slides.html

1
6
0
repeated
Edited 9 months ago

Mozilla, reading the room extremely well, seemingly just recently flipped the switch to enable-by-default sponsored weather results from AccuWeather in every new Firefox tab you open. Clicking "Learn more" takes you here, with zero information on if your location is sent to AccuWeather every time you open a new tab: https://support.mozilla.org/en-US/kb/customize-items-on-firefox-new-tab-page

Probably only noticed because I normally have a blank new tab page but this showed up after updating Firefox!

2
15
1
Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078

https://www.crowdfense.com/windows-wi-fi-driver-rce-vulnerability-cve-2024-30078/
0
0
1
repeated
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft High Definition Audio Bus Driver HDAudBus_DMA multiple irp complete requests vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2008
0
1
0
repeated

In part 2 of his series, @chudypb describes the ApprovedApplicationCollection gadget. He also covers a path traversal in the Windows utility extrac32.exe, which allowed him to complete the chain for a full RCE in Exchange and remains unpatched.
https://www.zerodayinitiative.com/blog/2024/9/11/exploiting-exchange-powershell-after-proxynotshell-part-2-approvedapplicationcollection

0
5
0
[RSS] CVR: The Mines of Kakadum

https://bughunters.google.com/blog/6220757425586176/cvr-the-mines-of-kakad-m

Pretty sure I posted the OffensiveCon talk before, but it%27s always nice to have things written up
0
2
3
[RSS] Advisory X41-2024-003: DoS Vulnerability in Chilkat ASN.1 Decoder

https://x41-dsec.de/lab/advisories/x41-2024-003-chilkat-asn1/
0
1
2
[RSS] The case of the string being copied from a mysterious pointer to invalid memory, revisited

https://devblogs.microsoft.com/oldnewthing/20240911-00/?p=110247
0
0
0
[RSS] Avred background: Advances in Reversing Defender Signature Format

https://blog.deeb.ch/posts/avred-update/
0
0
0
[RSS] WordPress.org to require two-factor authentication for plugin developers

https://cyberscoop.com/wordpress-two-factor-authentication-supply-chain/
0
0
1
I just got my hands on @tiraniddo's Windows Security Internals book <3

I ordered it through Blackwell's, that is a UK company but ships @nostarch books to EU too, so you can avoid dealing with customs yourself. Order tracking needs improvement.

https://blackwells.co.uk/bookshop/product/Windows-Security-Internals-by-James-Forshaw/9781718501980
0
0
3
Show older