Posts
2584
Following
628
Followers
1404
"I'm interested in all kinds of astronomy."
repeated

Congratulations all crowd strike users on macOS who now get warnings about the libcurl version shipped by Apple. May you all enjoy your choices of software vendors.

It alerts about CVE-2024-9681. We said it is severity low. NVD says 6.5 medium.

Never a dull moment.

2
2
0
repeated

OK, I fleshed this out a little more. You can find the (In)Security Appliance Bingo 2025 in proper, two-dimensional form here:

https://cku.gt/appbingo25

Suggestions and submissions very welcome.

1
3
0
repeated

CrowdStrike: Recruitment Phishing Scam Imitates CrowdStrike Hiring Process
Following CrowdStrike's successful Denial of Service attack on customers' Windows systems worldwide in July 2024, recruitment has gone up (this is a joke). CrowdStrike reports that a newly discovered phishing campaign uses CrowdStrike recruitment branding to convince victims to download a fake application, which serves as a downloader for the XMRig cryptominer. They describe the infection chain and provide Indicators of Compromise.

0
2
0
[RSS] WorstFit: Unveiling Hidden Transformers in Windows ANSI!

https://devco.re/blog/2025/01/09/worstfit-unveiling-hidden-transformers-in-windows-ansi/
0
3
2
repeated

Nominations are now open for the Top 10 Web (new) Hacking Techniques of 2024! Browse the contestants and submit your own here:
https://portswigger.net/research/top-10-web-hacking-techniques-of-2024-nominations-open

0
4
0
repeated

Mozilla Foundation security advisories 09 January 2025:

  • MFSA2025-04 Security Vulnerabilities fixed in Thunderbird 134 (9 CVEs: 2 high, 7 "moderate")
  • MFSA2025-05 Security Vulnerabilities fixed in Thunderbird ESR 128.6 (7 CVEs: 1 high, 6 moderate)

No mention of exploitation.

0
2
0
repeated

I really hope I'm missing something, but I can't find a VSCode API that allows me, in an extension, to get an event when a breakpoint is hit.
Seems like a massive blocker for developing debugging tools.

1
1
0
repeated

Taking his previous research to the next level, our Maxence Schmitt explores how to bypass various upload restrictions to exploit client-side path traversal. Read about it in our latest blog post today!

https://blog.doyensec.com/2025/01/09/cspt-file-upload.html

0
4
0
repeated
repeated
repeated
Edited 3 months ago

Hearing about a young hacker whose being extorted by the University of Washington, not cool UW.

The student claims they built an app to help kids get the course schedules they want, a hack as old as time, and the university decided to expel him until he ports his app to the university's internal systems.

This would be unpaid labor.

Until then his class registration is on hold and he can't register or attend his last few classes. 🄓

https://www.linkedin.com/posts/jdkaim_github-jdkaimhuskyswap-huskyswap-project-activity-7282891503142641664-nA8Y

9
15
1
repeated

Computer History Museum šŸ‡øšŸ‡®

šŸŽ‚šŸ—» Looking for simh/DEC J-11 experts to volunteer for our project of developing a libre emulator of the Slovenian Iskra Delta Triglav computer which is celebrating 40 years! We have ROM and disk images (RSX11-M/DELTA-M OS) and lots of documentation. Interested? šŸ‘‰ marko@muzej.si

0
1
0
repeated
repeated

Why You Probably Don't Need A VPN To Stay Secure On Public Wi-Fi

You've probably heard advice about how hackers can steal all your sensitive information if you don't use a VPN on public Wi-Fi, but is that actually true? In this video I'll walk through some of the major risks of public Wi-Fi such as Man-In-The-Middle Attacks, Rogue Access Points, SSL Stripping, and TLS Downgrades, as well as discuss how modern security measures prevent them.
https://www.youtube.com/watch?v=i7GwjGGwxzg

3
8
1
repeated
repeated
repeated

New Connect Secure — I'm sure we'll see Mandiant and MSTIC write-ups shortly on whichever threat campaign/actor was hitting CVE-2025-0282. https://www.rapid7.com/blog/post/2025/01/08/etr-cve-2025-0282-ivanti-connect-secure-zero-day-exploited-in-the-wild/

1
2
0
repeated

Blortā„¢ šŸ€ā“‹šŸ„‹ā˜£ļø

I'm very happy to see @kagihq joining Peertube with their inaugural video below about what makes Kagi independent search special!

https://tilvids.com/w/twGQeYV9c1TGwMmbdXtY2q

Remember to follow their Peertube account at @kagi and boost to encourage and show them the effort is appreciated! Also do check out their excellent lenses feature, shown in the video.

0
3
0
[RSS] Two Network-related vunlnerabilities Analysis

https://u1f383.github.io/linux/2025/01/08/two-network-related-vulnerabilities-analysis.html

#Linux kernel - CVE-2023-6932 CVE-2023-0461
0
1
0
[RSS] Hijacking Azure Machine Learning Notebooks (via Storage Accounts)

https://www.netspi.com/blog/technical-blog/cloud-pentesting/hijacking-azure-machine-learning-notebooks/
0
0
0
Show older