Posts
2458
Following
555
Followers
1263
A drunken debugger

Heretek of Silent Signal
repeated

Why chatbots are terrible for search, and why retrieval augmented generation doesn't fix that: https://buttondown.com/maiht3k/archive/information-literacy-and-chatbots-as-search/ by @emilymbender

0
2
0
repeated

Happy from Citrix:

Please see the advisories for the prerequisites for each vulnerability.

1
1
0
repeated

Microsoft:
The BinaryFormatter type is dangerous and is not recommended for data processing... BinaryFormatter is insecure and can't be made secure.

Citrix:
We have the facts and we're voting Yes for using BinaryFormatter for processing data in our product.

CVE(s) TBD...

https://labs.watchtowr.com/visionaries-at-citrix-have-democratised-remote-network-access-citrix-virtual-apps-and-desktops-cve-unknown/

1
1
0
"Tomorrow, 10am, BinaryFormatter dies."
\o/

https://bsky.app/profile/blowdart.me/post/3lapy5gaou22h
0
1
2
repeated

Micropatches Released for Remote Registry Service Elevation of Privilege Vulnerability (CVE-2024-43532)
https://blog.0patch.com/2024/11/micropatches-released-for-remote.html

1
3
0
repeated

Check out the Snapshot Manager (https://github.com/d0mnik/binja_snapshot_manager), the latest community-plugin (https://github.com/Vector35/community-plugins ). That brings the total plugins in the plugin manager up to 166. How long before we break 200?!

0
2
0
repeated
repeated
New assessment for topic: CVE-2024-9464

Topic description: "An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. ..."

"Note: While this is an authenticated exploit, CVE-2024-5910 affects the same versions and allows an attacker to reset the admin password to allow authentication. ..."

Link: https://attackerkb.com/assessments/911948de-467d-4804-b97d-d943203fae60
0
3
0
repeated

A few weeks ago, I sent my 1985 Swiss Army Knife back to Victorinox for a broken blade replacement.

It came back today, fully repaired, cleaned, polished, lubricated and in a new box.

Total cost: £10 + return postage.

They sent the knife back with an invoice. I didn't have to pay a penny before the job was done.

A product that's been out of production for almost 40 years, repaired at very little cost by the original manufacturer.

I'm stunned. Happy, impressed, grateful and stunned.

8
34
0
repeated

Happy Patch Tuesday to those who celebrate.

1
2
0
repeated

vArmor

vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.

https://github.com/bytedance/vArmor

0
1
0
[RSS] Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight

https://workos.com/blog/ruby-saml-cve-2024-45409
0
1
1
repeated

I will present about file formats at the CCC (ten years after 31c3's "Funky file formats").
https://speakerdeck.com/ange/funky-file-formats-31c3

2
5
0
repeated

Indo-Pacific News - Geo-Politics & Defense

has officially unveiled its new 5th-generation stealth fighter, the J-35A, at the Zhuhai Air Show

Images show a comparison with the US F-35.

The J-35A is a customized copy of the F-35. China hacked a British defence company and stole the F-35 blueprints a number of years ago. This is the result of that.

0
3
0
repeated

We've just released our 2024-Q3 edition of ThinkstScapes: https://thinkst.com/ts

For this issue, we went through ~5000 info-sec research talks, papers, presentations & blogs.

The website includes PDF & ePub links (and a brief audio summary).

As always: completely free...

0
7
0
repeated

Amazon has confirmed a data breach impacting employee data.

The confirmation comes after a hacker claimed to leak data from a bunch of major organizations, including Amazon, which they say is linked to last year's MOVEit mass-hacks

https://techcrunch.com/2024/11/11/amazon-confirms-employee-data-stolen-after-hacker-claims-moveit-breach/

0
5
0
Exploiting KsecDD through Server Silos – SCRT Team Blog
https://blog.scrt.ch/2024/11/11/exploiting-ksecdd-through-server-silos/
0
0
0
SBFT'25 Fuzzing Competition

https://sbft25.github.io/tools/fuzzing

"Unlike previous years, we will favour fuzzers which are better at discovering novel edges and will accept existing fuzzers as submissions"

/by @addison
0
2
2
repeated

Happy to announce the SBFT'25 fuzzing competition! Unlike previous years, we will favour fuzzers which are better at discovering novel edges and will accept existing fuzzers as submissions, so there is no excuse to not join in :^)

Register and find details here:
https://sbft25.github.io/tools/fuzzing

0
2
0
repeated
Show older