Posts
2426
Following
592
Followers
1314
"I'm interested in all kinds of astronomy."
repeated

Happy Holidays to my oncall buddies today. I wish you all a quiet and uneventful shift.

0
3
0
I survived #Whamageddon \o/
1
0
3
To avoid sudden dangerous drops of frustration during these peaceful Holidays I'm configuring Postfix.
0
0
3
repeated
What are the online #book stores that are neither a) monopolistic giants built on enshittification nor b) copyright bullies?

If I ask for a unicorn, which ones do at least give authors a more fair share for their work?
4
2
4
repeated

The slides for the keynote our Cristofaro Mune(@pulsoid) has given at @h2hconference
"False Injections: Tales of Physics, Misconceptions and Weird Machines" are now available here:

https://raelize.com/upload/research/2024/2024_H2HC2024_False-Injections-Tales-of-Physics-Misconceptions-and-Weird-Machines.pdf

Enjoy!

0
4
0
repeated
repeated

In light of the Crowdstrike outage over 5 months ago, what specific changes has your organization made to your enterprise security program? What changes to policies, procedures, training, alerting, testing, and your written IRP have you made? Please share!

2
4
0
repeated

European Space Agency's official web shop was hacked as it started to load a piece of JavaScript code that generates a fake Stripe payment page at checkout.

https://www.bleepingcomputer.com/news/security/european-space-agencys-official-store-hacked-to-steal-payment-cards/

0
4
0
Got like 20 new followers overnight at Bsky, what is happening?
1
0
0
repeated
repeated

Maybe we should stop calling them *Notifications* and instead refer to *Interruptions*.

"Working on some stuff so I've turned off interruptions for a while."

"Right on."

10
20
0
repeated

āš” A new remote code execution flaw in Apache Tomcat (CVE-2024-56337) exposes organizations to serious risk.

An uploaded file could turn into malicious JSP codeā€”resulting in remote code execution.

Ā» Affected Versions: Tomcat 9.0.0-M1 to 11.0.1
Ā» Java users: Incorrect configurations = higher risk.
Ā» Severity? CVE-2024-50379 scored a 9.8 on CVSS!

Details here šŸ‘‰ https://thehackernews.com/2024/12/apache-tomcat-vulnerability-cve-2024.html

0
3
0
repeated

Near as I can tell, the activity around the bug,
CVE-2024-53677, is just ham-handed runs of some generalized PoC, and nobody's actually exploiting this yet (since exploitation would be very application/path specific).

Most of the news last week was all "exploitation happening, patch and rewrite everything now!" but not seeing any reports of successful (or even possibly successful) this morning.

Tell me I'm wrong!

(The PoC identified by SANS at https://isc.sans.edu/diary/31520 isn't specific to some particular application -- it's on the user to define upload_endpoint and assumes no auth or session or anything.)

0
2
0
repeated

Using @voooooogel control vector library to backdoor a model so that it introduces command injection vulnerabilities rather than using safer subprocess methods

0
3
0
repeated

Hi all. In order to make the Defensive Security Podcast content a bit more approachable and easier to navigate, I've created a playlist of individual stories/segments we cover here: https://www.youtube.com/playlist?list=PLzHXsgtVDQEq9JiCbwJojE4nd9dRVAT5l

Note: I've only gone back 4 episodes, but will be doing this for all episodes going forward.

Happy holidays!

1
4
0
repeated

Kagi's new video search controls let you replace clickbait thumbnails with real screenshots, customize title formatting, and focus on actual content.

You may find these controls in your search settings.

1
3
0
repeated

I started keeping a log of the serious attempts I've made to use generative AI for things (mostly coding-related). I've been bucketing them as successes or failures, along with the date and models used.

From the past several months, I'm up to 9 failures and 3 successes. I'll share this list some day.

When these systems have been successful, it's pretty neat. However, the successes I've seen have been for easy things, and the failures have mostly been time-sucks for me.

I feel like a heretic saying this (I'm a Principal Machine Learning Engineer), but I am not seeing a net benefit from using generative AI in my own work!

1
2
0
Windows Cloud Files Mini Filter Driver LPE

CVE-2024-30085

https://ssd-disclosure.com/ssd-advisory-cldflt-heap-based-overflow-pe/
0
0
0
Show older