The Ig Nobel in Physics has been awarded:
Awarded to James Liao at the University of Florida for a comprehensive, multi-publication investigation into the swimming abilities of a dead trout¹.
It feels rather more relevant than handing a real Nobel to people working for a commercial company in "Artificial Intelligence" (the only way to write it is between quotes).
__
¹ https://www.cell.com/current-biology/fulltext/S0960-9822(22)00709-6
The Council of the EU has adopted the #CRA Cyber Resilience Act yesterday. This will have huge consequences for everyone who ships hardware and software as a product. Almost no actual open source developers face direct regulation (for writing software), but the users of our open source software very much do. The CRA notably suggests that commercial users pony up for improved open source security attestation. It is a big act, but it offers real possibilities for making better software! 1/2
Well that was unexpected for today! The Council of the EU has adopted the #CRA Cyber Resilience Act and we are just a few small steps away from it becoming a European law.
The #defcon32 presentations are now live and availablle for your perusal on the #DEFCON media server, free of all commercials, data capture or pesky algorithms. We suggest clearing some disk space and personal time this weekend to snatch up some of the many, many jewels our speakers dropped in Las Vegas. While you’re on media.defcon.org you can also find the slide decks, a ton of pictures and even the DC32 soundtrack. Enjoy, learn a few things and #passiton.
We’ll be posting the videos on YouTube Monday.
Using Telerik Reporting or Report Server? Patch now to fix 3 RCEs @mwulftange found (CVE-2024-8015, CVE-2024-8014, CVE-2024-8048). Telerik vulns have a history of being exploited by threat actors according to #CISA Details at https://code-white.com/public-vulnerability-list/
Thousands of hackers, technology freaks, artists, and utopians get together in Hamburg to communicate, learn from each other, and party together: #38C3 Call for participation has launched https://www.ccc.de/en/updates/2024/38c3-call-for-participation
Updates from @brewsterkahle about the DDOS attacks on Internet Archive:
Don't you miss the golden era of SQL Injections?
Here Mathieu Farrell (@coiffeur0x90) explains how to feel the thrill again with the aid of Apache Superset, XML and a bit of parsing tickery:
"Bypass Apache Superset restrictions to perform SQL Injections"
https://blog.quarkslab.com/bypass-apache-superset-restrictions-to-perform-sql-injections.html
A step-by-step guide to writing an #iOS #kernel #exploit -< short and to the point!
// by @alfiecg_dev
https://alfiecg.uk/2024/09/24/Kernel-exploit.html
https://github.com/alfiecg24/Vertex
SonicWall security advisory: SonicWall SSL-VPN SMA1000 and Connect Tunnel Windows Client Affected By Multiple Vulnerabilities
There is no evidence that these vulnerabilities are being exploited in the wild and SonicWall SSL VPN SMA 100 series products are not affected by these vulnerabilities. Affected products are SMA1000 Connect Tunnel Windows (32 and 64-bit) Client 12.4.3.271 and earlier versions, SMA1000 Appliance firmware 12.4.3-02676 and earlier versions (Note: This vulnerability does not affect Connect Tunnel Linux and Mac client versions.) Vulnerabilities are patched in SMA1000 Connect Tunnel Windows (32 and 64-bit) Client 12.4.3.281 version and higher, along with SMA1000 Platform Hotfix - 12.4.3-02758. SonicWall strongly advises SSLVPN SMA 1000 series product and Connect Tunnel client users to upgrade to the mentioned fixed-release version.
Dark-mode has arrived to Function-Graph-Overview!
Version 0.0.9 now supports dark-mode and custom color schemes.
https://marketplace.visualstudio.com/items?itemName=tamir-bahar.function-graph-overview
And the demo now includes a scheme-making tool.
It’s been twelve years since I cleverly combined #CybersecurityAwarenessMonth with #BreastCancer awareness month by being diagnosed with stage 2B breast cancer. After a year of scorched-earth treatment, I went into remission, where I’ve been ever since.
Breast-having mammals reading this, please check yourself regularly; it’s how I found mine. Be careful out there.
Palo Alto in 2018:
CVE-2018-10143 - Oops. We'd better fix the "path" parameter for convertCSVtoParquet.php
Palo Alto in 2024:
CVE-2024-9463 - Oops. We'd better fix the "ram" parameter for convertCSVtoParquet.php
Can someone get this thing to work? Is there any other option to spot gaps in padded fields on structs in C programs? https://github.com/arvidn/struct_layout
Mozilla is looking for a Staff Software Engineer (remote US/EU/CA ✨) working on sandboxing, hardening, crash-reporting, performance and integration with native widgets **on Linux**. As a staff-level position this will require strong technical and people skills, experience in C++ on Linux or Android. The team is distributed and amazing. Ask me in DM if you have any questions about Mozilla (I am *not* the hiring manager). Please apply at https://grnh.se/2c3dc0111us