Posts
2457
Following
555
Followers
1263
A drunken debugger

Heretek of Silent Signal
repeated

Google Security: Retrofitting Spatial Safety to hundreds of millions of lines of C++
Google is retrofitting secure-by-design principles to their existing C++ codebase wherever possible, including bringing spatial memory safety into as many codebases. It has already made a noticeable impact, from preventing exploits, reducing crashes and improving code reliability/easier debugging.

0
3
0
repeated

Missed out on the action at in Barcelona? researcher and co-creator @pancake put together a recap of all three days, including all the recordings, slides, and GitHub repositories. Check it out here: https://www.nowsecure.com/blog/2024/11/15/nowsecure-at-r2con2024-top-takeaways-and-mobile-security-highlights/?utm_source=mastodon

A huge thanks to everyone who joined us and made this comeback event a success after a 5-year break!

0
3
0
repeated
Edited 8 days ago

Pandoc compiled to Wasm (WebAssembly), which enables live conversions in the browser.

• Live demo: https://tweag.github.io/pandoc-wasm/

• Repository: https://github.com/tweag/pandoc-wasm

Amazing work by @terrorjack and the ghc-meta-wasm folks!

3
7
0
repeated
repeated
repeated

See the latest iOS inactivity reboot in action! 🔒

iOS 18 comes with improved anti-theft measures. Three days w/o unlock, the iPhone will reboot, preventing thieves from getting your data.

Inactivity reboot puts your iPhone into "Before First Unlock" state, effectively locking encryption keys in the Secure Enclave Processor. Even if thieves leave your iPhone powered on for a long time, they won't be able to unlock it with cheaper, outdated forensic tooling. (1/2)

4
5
0
repeated

Bluesky is the Microsoft Word of social media, which I mean in the derogatory sense, as the fediverse is the LaTeX of social media, which I also mean in the derogatory sense

7
24
0
Edited 8 days ago
I didn't know #EU started to regulate political ads ( #TTPA ) :O I'm not familiar with the details (the devil is usually in there, see cookie banners...), but I think it was long due to attack propaganda from this angle, and it already seems to have some nice effects:

https://blog.google/around-the-globe/google-europe/political-advertising-in-eu/

Nice job, EU!
0
4
3
[RSS] Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/
0
1
0
repeated
repeated

Broadcom no longer license vmware workstation, it has become free.

However, to download it you need to register an account that is impossible.

But

Their website security is questionable.... so here is a download link *lol*

https://softwareupdate.vmware.com/cds/vmw-desktop/ws/

1
5
0
repeated

I know there's been a lot of speculation, but this is the first actual reporting I've seen about the potential teardown of CISA: https://www.politico.com/news/2024/11/14/rand-paul-kneecap-cisa-00189698

2
6
0
repeated

In December 2023, KrebsOnSecurity revealed the real-life identity of Rescator, the nickname used by a Russian cybercriminal who sold more than 100 million payment cards stolen from Target and Home Depot between 2013 and 2014. Moscow resident Mikhail Shefel, who confirmed using the Rescator identity in a recent interview, also admitted reaching out because he is broke and seeking publicity for several new money making schemes.

https://krebsonsecurity.com/2024/11/an-interview-with-the-target-home-depot-hacker/

3
5
0
repeated

🌪️Heads up speakers: TyphoonCon 2025 Call for Papers is now open! https://typhooncon.com/call-for-papers-2025/

0
1
0
repeated

Missed the first round of RE//verse ticket sales? Don’t worry—we’re back with another round on December 1st! In the meantime, stay in the loop and be the first to know when tickets go live again by joining our mailing list here: https://re-verse.us13.list-manage.com/subscribe?u=6dcc880ba666c9187461a2462&id=5285601ec7

0
2
0
repeated

Debugging an OpenJDK crash on SPARC

https://ptribble.blogspot.com/2024/11/debugging-openjdk-crash-on-sparc.html

(with apologies for the fonts and formatting)

0
2
0
repeated

CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog
Not quite hot, but I was stuck in meetings. CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

  • CVE-2024-9463 (9.9 critical) Palo Alto Networks Expedition OS Command Injection Vulnerability
  • CVE-2024-9465 (9.2 critical) Palo Alto Networks Expedition SQL Injection Vulnerability

0
2
0
repeated
Edited 9 days ago

The Onion acquiring Infowars with their bid backed by the actual families of Sandy Hook victims and aiming to use it to raise awareness about gun violence wasn't on my 2024 bingo card, but can't really complain about this turn of events.

"The Onion acquired the conspiracy theory platform’s website; social media accounts; studio in Austin, Texas; trademarks; and video archive. The sale price was not immediately disclosed. The Onion said its “exclusive launch advertiser” will be the gun violence prevention organization Everytown for Gun Safety. "

https://abcnews.go.com/Business/wireStory/satire-slinger-onion-buys-alex-jones-infowars-auction-115858173

1
4
0
Show older