Posts
3537
Following
721
Followers
1583
"I'm interested in all kinds of astronomy."
repeated

TIL: H. P. Lovecraft, on the 'proper' pronunciation of 'Cthulhu':

The name of the hellish entity was invented by beings whose vocal organs were not like man's, hence it has no relation to the human speech equipment. The syllables were determined by a physiological equipment wholly unlike ours, hence could never be uttered perfectly by human throats ... The actual sound -- as nearly as any human organs could imitate it or human letters record it -- may be taken as something like Khlûl'-hloo, with the first syllable pronounced gutturally and very thickly. The u is about like that in full; and the first syllable is not unlike klul in sound, hence the h represents the guttural thickness.

(Not your usual pronunciation note -- the equivalent of "you kinda can't get there from here, but if you have to try, here's now")

0
1
1
repeated

TrendAI Zero Day Initiative

More video highlights from Ireland Day 2, the InfoSect (@infosectcbr) group exploits the Sonos. https://youtube.com/shorts/UGp-HVRP5mU?feature=share

0
1
0
repeated

TrendAI Zero Day Initiative

More video highlights from Ireland Day 2. This one has Corentin Bayet (@OnlyTheDuck) going from the QNAP QHora-322 to the QNAP TS-464 in a SOHO Smashup. https://youtube.com/shorts/LhHk03l4vm8?feature=share

0
1
0
How we program multicores - Joe Armstrong

https://www.youtube.com/watch?v=bo5WL5IQAd0
0
0
1
repeated

TrendAI Zero Day Initiative

Compass Security (@compasssecurity) ran into a collision in their attempt against the Ubiquiti AI bullet. Their exploit still wins them $3,750 and 1.5 Master of Pwn points.

0
1
0
#music #metal
Show content
0
0
0
repeated

Critical 0-day Vulnerability in Fortinet FortiManager (CERT-EU Security Advisory 2024-113)

On October 23, 2024, Fortinet released a security advisory addressing a critical 0-day vulnerability in its FortiManager product. If exploited, a remote unauthenticated attacker could execute arbitrary code or commands on the affected device.
It is strongly recommended to apply the update. When not possible, it is recommended to apply the workarounds. In all cases, it is recommended to search for evidence of a potential compromise.

https://www.cert.europa.eu/publications/security-advisories/2024-113/

0
1
0
repeated

TrendAI Zero Day Initiative

In another video highlight from Day 2 of , team Viettel takes on the Sonos speaker: https://youtube.com/shorts/DUWfgz1Mm6w?feature=share

0
1
0
Blog status: 2595 words, 5 more to a Blue Box...
0
0
0
repeated
repeated

Around 100 new games were added to the program reconstruction section of the Decompilation Wiki:
https://decompilation.wiki/applications/program-reconstruction/

On that note, the Wiki is always looking for more writers who want to contribute tutorials, explanations, or categorizations of any topic in the Wiki :).

0
1
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality SAMPLE out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1955

CVE-2024-0121
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality LD instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2012

CVE-2024-0117
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality out-of-bounds read vulnerability due to excessive loop iteration

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2013

CVE-2024-0118
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality STORE_STRUCTURED instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2014

CVE-2024-0120
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality MOV instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2015

CVE-2024-0119
0
1
0
repeated

TrendAI Zero Day Initiative

Unfortunately, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) could not get his exploit of the TrueNAS Mini X working within the time allotted.

0
1
0
repeated

TrendAI Zero Day Initiative

Sadly, the Neodyme (@neodyme) team could not get their exploit of the Lexmark CX331adwe printer working within the time allotted.

0
1
0
repeated

TrendAI Zero Day Initiative

We have another collision. The DEVCORE Research Team (@d3vc0r3) successfully exploited the Lorex 2K camera, but they used a bug previously seen in the contest. They still earn $3,750 and 1.5 Master of Pwn points.

0
1
0
repeated

I thought I understood the extent to which the broad availability of mobile location data has exacerbated countless privacy and security challenges. That is, until I was invited along with four other publications to be a virtual observer in a 2-weeek test run of Babel Street, a service that lets users draw a digital polygon around nearly any location on a map of the world, and view a time-lapse history of the mobile devices seen coming in and out of the area.

The issue isn't that there's some dodgy company offering this as a poorly-vetted service: It's that *anyone* willing to spend a little money can now build this capability themselves.

I'll be updating this story with links to reporting from other publications also invited, including 404 Media, Haaretz, NOTUS, and The New York Times. All of these stories will make clear that mobile location data is set to massively complicate several hot-button issues, from the tracking of suspected illegal immigrants or women seeking abortions, to harassing public servants who are already in the crosshairs over baseless conspiracy theories and increasingly hostile political rhetoric against government employees.

https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/

16
23
1
Show older