Posts
2346
Following
530
Followers
1242
A drunken debugger

Heretek of Silent Signal
repeated
repeated

(CVE-2024-9680)[1923344][animation]UAF in Animation timelines -> ACE in the content process(exploited ITW), fixed in Firefox 131.0.2, Firefox ESR 128.3.1 & Firefox ESR 115.16.1
https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/#CVE-2024-9680
https://hg.mozilla.org/mozilla-central/rev/0ee07613d0506da465539cfaff1826cdc8bf0384

0
2
0
#music #friday #edm
Show content
'I thought “surely it’s not THAT Rebecca Black.” And so I did some internet browsing and found out “yeah, it’s THAT Rebecca Black.”'

https://www.youtube.com/watch?v=vkcyXB08BBE

It's Friiidaay, Friiiidaaay \o/
0
0
0
repeated

The Ig Nobel in Physics has been awarded:

Awarded to James Liao at the University of Florida for a comprehensive, multi-publication investigation into the swimming abilities of a dead trout¹.

It feels rather more relevant than handing a real Nobel to people working for a commercial company in "Artificial Intelligence" (the only way to write it is between quotes).
__
¹ https://www.cell.com/current-biology/fulltext/S0960-9822(22)00709-6

0
2
0
repeated

Behold government funded weather machines.

1
24
0
repeated

bert hubert 🇺🇦🇪🇺

The Council of the EU has adopted the Cyber Resilience Act yesterday. This will have huge consequences for everyone who ships hardware and software as a product. Almost no actual open source developers face direct regulation (for writing software), but the users of our open source software very much do. The CRA notably suggests that commercial users pony up for improved open source security attestation. It is a big act, but it offers real possibilities for making better software! 1/2

2
5
0
repeated

Well that was unexpected for today! The Council of the EU has adopted the Cyber Resilience Act and we are just a few small steps away from it becoming a European law.

https://www.consilium.europa.eu/en/press/press-releases/2024/10/10/cyber-resilience-act-council-adopts-new-law-on-security-requirements-for-digital-products/

1
2
0
repeated

The presentations are now live and availablle for your perusal on the media server, free of all commercials, data capture or pesky algorithms. We suggest clearing some disk space and personal time this weekend to snatch up some of the many, many jewels our speakers dropped in Las Vegas. While you’re on media.defcon.org you can also find the slide decks, a ton of pictures and even the DC32 soundtrack. Enjoy, learn a few things and .

We’ll be posting the videos on YouTube Monday.

1
7
0
repeated

Using Telerik Reporting or Report Server? Patch now to fix 3 RCEs @mwulftange found (CVE-2024-8015, CVE-2024-8014, CVE-2024-8048). Telerik vulns have a history of being exploited by threat actors according to Details at https://code-white.com/public-vulnerability-list/

0
3
0
repeated

Thousands of hackers, technology freaks, artists, and utopians get together in Hamburg to communicate, learn from each other, and party together: Call for participation has launched https://www.ccc.de/en/updates/2024/38c3-call-for-participation

0
7
0
repeated
Edited 11 days ago

Updates from @brewsterkahle about the DDOS attacks on Internet Archive:

3
28
0
repeated

Use less javascript

4
8
0
repeated

Don't you miss the golden era of SQL Injections?

Here Mathieu Farrell (@coiffeur0x90) explains how to feel the thrill again with the aid of Apache Superset, XML and a bit of parsing tickery:

"Bypass Apache Superset restrictions to perform SQL Injections"

https://blog.quarkslab.com/bypass-apache-superset-restrictions-to-perform-sql-injections.html

1
4
0
repeated

Project Zero Bot

New Project Zero issue:

Linux: fuse_notify_store() marks page uptodate while leaving beyond-EOF parts uninitialized

https://project-zero.issues.chromium.org/issues/42451729

CVE-2024-44947
0
1
1
repeated

Project Zero Bot

New Project Zero issue:

adsprpc: refcount leak leading to UAF in fastrpc_get_process_gids

https://project-zero.issues.chromium.org/issues/42451711

CVE-2024-38402
0
1
0
repeated
repeated

SonicWall security advisory: SonicWall SSL-VPN SMA1000 and Connect Tunnel Windows Client Affected By Multiple Vulnerabilities

  • CVE-2024-45315 (6.1 medium) SonicWALL SMA1000 Connect Tunnel Windows Client Link Following Denial-of-Service Vulnerability
  • CVE-2024-45316 (7.8 high) SonicWALL SMA1000 Connect Tunnel Windows Client Link Following Local Privilege Escalation Vulnerability
  • CVE-2024-45317 (7.2 high) Unauthenticated SMA1000 12.4.x Server-Side Request Forgery (SSRF) Vulnerability

There is no evidence that these vulnerabilities are being exploited in the wild and SonicWall SSL VPN SMA 100 series products are not affected by these vulnerabilities. Affected products are SMA1000 Connect Tunnel Windows (32 and 64-bit) Client 12.4.3.271 and earlier versions, SMA1000 Appliance firmware 12.4.3-02676 and earlier versions (Note: This vulnerability does not affect Connect Tunnel Linux and Mac client versions.) Vulnerabilities are patched in SMA1000 Connect Tunnel Windows (32 and 64-bit) Client 12.4.3.281 version and higher, along with SMA1000 Platform Hotfix - 12.4.3-02758. SonicWall strongly advises SSLVPN SMA 1000 series product and Connect Tunnel client users to upgrade to the mentioned fixed-release version.

0
1
0
repeated

Dark-mode has arrived to Function-Graph-Overview!

Version 0.0.9 now supports dark-mode and custom color schemes.

https://marketplace.visualstudio.com/items?itemName=tamir-bahar.function-graph-overview

And the demo now includes a scheme-making tool.

https://tmr232.github.io/function-graph-overview/

0
1
1
repeated

It’s been twelve years since I cleverly combined with awareness month by being diagnosed with stage 2B breast cancer. After a year of scorched-earth treatment, I went into remission, where I’ve been ever since.

Breast-having mammals reading this, please check yourself regularly; it’s how I found mine. Be careful out there.

2
4
0
SEC Consult SA-20241009-0 :: Local Privilege Escalation via MSI installer in Palo Alto Networks GlobalProtect (CVE-2024-9473)

https://seclists.org/fulldisclosure/2024/Oct/2
0
2
2
Show older