This meeting could have been a blood ritual in the woods.
Thanks to the efforts of @yossarian, @di, Facundo Tuesca and yours truly, we have PEP 740 attestations available on PyPI.
If you use modern pypi-publish with trusted publishing, your dists are signed automatically by default.
https://blog.pypi.org/posts/2024-11-14-pypi-now-supports-digital-attestations/
https://security.googleblog.com/2024/11/new-real-time-protections-on-Android.html
cool, all you need to do is LET GOOGLE FUCKING EAVESDROP ON YOUR PHONECALLS TO TRAIN ITS AI
Security researcher Cristian Cornea authored a fake ransomware builder dubbed Jinn ransomware builder.
It was a fake Builder โ it was actually a payload.
It infected over 100 people on Breached.
https://corneacristian.medium.com/how-i-hacked-100-hackers-5c3c313e8a1a
#Bitdefender's website is tracking me with 27 cookies โ including TikTok. How can anyone trust a company that willingly hands over my privacy to multiple entities? #antivirus
Analyzing Firefox Animation CVE-2024-9680 https://dimitrifourny.github.io/2024/11/14/firefox-animation-cve-2024-9680.html
Wow Intel SGX and Sub-Page Protection exploded at the same time yesterday. The latter is so broken Intel removes it from all future processors. ๐
Remove /dev/null from a host and a surprising number of programs crash and burn. Experienced sysadmins understand that most software requires an uninterruptible supply of nothing.
Full Rapid7 analysis and #exploit PoC (with root shell!) for #FortiManager #CVE202447575 via @stephenfewer ๐ Not a simple project, as it turned out :) https://attackerkb.com/topics/OFBGprmpIE/cve-2024-47575/rapid7-analysis
The Pentium processor had a minor error in the division algorithm. This error cost Intel $475 million to replace the faulty chips. I've tracked down the FDIV error to this circuit on the die:
Me to Matomo:
Your installation instructions guarantee that Windows will be vulnerable to LPE. You should probably fix that.
Matomo:
"Unfortunately we do not consider this as a security issue, because it's actually fully unrelated to Matomo itself."
Great job, folks!