In case it wasn't posted here already, Project Zero is hiring!
See https://t.co/bA3FT6ZbzH
(please RT for reach - thank you!)
Learned a cool new Linux trick? Know an interesting quirk in a network protocol? Or have something else to share?
Write a 1-page article for the #6 issue of Paged Out! :)
https://pagedout.institute/?page=cfp.php
Soft deadline is Feb 1st.
From over at the Bad Place:
https://gist.github.com/alfarom256/f1342f14dc6a742de7ea4004a1b6d7ed
IObit Malware Fighter has a driver device called IMFForceDelete123.
When you call the only exposed IOCTL to this device, 0x8016E000, along with a specified path, the Windows kernel will delete the specified file/directory. NTFS ACLs don't matter because we're the kernel.
Who is allowed to interact with this device? EVERYONE.
The more software you have on your system, the less secure it is.
The art of programming is the art of organizing complexity, of mastering multitude and avoiding its bastard chaos as effectively as possible.
— E. W. Dijkstra
Backdooring Your Backdoors - Another $20 Domain, More Governments - watchTowr Labs https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/
This is it! Its on!
Save the date and polish your speaking or training skills-> call for papers, workshops, trainings, sponsors and volunteers open!
Submit: https://pretalx.com/bsidesluxembourg-2025/cfp
PS: sponsor package options available on info@bsides.lu!
Please support one of our own! If you ever have been to defcon, needed network security, used MFA, touched HAM radio, etc… dearest cjunkie made your life better one way or another - one of the most awesome human beings I know (and I know tons of them!) https://www.gofundme.com/f/support-marc-rogers-road-to-recovery
High level diff of iOS 18.3 beta 1 vs. iOS 18.3 beta 2 🎉
https://github.com/blacktop/ipsw-diffs/blob/main/18_3_22D5034e__vs_18_3_22D5040d/README.md
Google Chrome security advisory: Stable Channel Update for Desktop
New Google Chrome version 131.0.6778.264/.265 for Windows, Mac and 131.0.6778.264 for Linux includes 4 security fixes, including 1 externally reported: CVE-2025-0291 (high severity) Type Confusion in V8. No mention of exploitation
#google #chrome #vulnerability #cve #infosec #cybersecurity #CVE_2025_0291
Project: golang/go https://github.com/golang/go
File: src/cmd/cgo/ast.go:358 https://github.com/golang/go/blob/refs/tags/go1.23.4/src/cmd/cgo/ast.go#L358
func (f *File) walk(x interface{}, context astContext, visit func(*File, interface{}, astContext))
SVG:
dark https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fcmd%2Fcgo%2Fast.go%23L358&colors=dark
light https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fcmd%2Fcgo%2Fast.go%23L358&colors=light
Project: golang/go https://github.com/golang/go
File: src/runtime/pprof/pprof_test.go:1553 https://github.com/golang/go/blob/refs/tags/go1.23.4/src/runtime/pprof/pprof_test.go#L1553
func containsCountsLabels(prof *profile.Profile, countLabels map[int64]map[string]string) bool
SVG:
dark https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fruntime%2Fpprof%2Fpprof_test.go%23L1553&colors=dark
light https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fruntime%2Fpprof%2Fpprof_test.go%23L1553&colors=light
RULECOMPILE - Undocumented Ghidra decompiler rule language
US adds web and gaming giant Tencent to list of Chinese military companies
This could be the start of a saga to rival TikTok’s troubles, and embroil Tesla and Microsoft The US Department of Defense has added Chinese messaging and gaming Tencent to its list of “Chinese military company”, a designation that won’t necessarily result in a ban but is nonetheless unpleasant.…
#theregister #IT
https://go.theregister.com/feed/www.theregister.com/2025/01/07/tencent_catl_chinese_military_company_list/
I don't dig pit traps and cover them with sticks and a thin layer of leaves nearly as much as I expected; I find a chance to do it barely once a month.
https://xkcd.com/3034/