Posts
2558
Following
621
Followers
1371
"I'm interested in all kinds of astronomy."
repeated

Microsoft will force install the new Outlook email client on Windows 10 systems starting with next month's security update.

https://www.bleepingcomputer.com/news/microsoft/microsoft-to-force-install-new-outlook-on-windows-10-pcs-in-february/

2
5
0
repeated

Currently working on adding comment-overlays to Function-Graph-Overview.

The idea is to add special begin- and end- comments, and use those to draw overlays on the graph (think C#'s region thingy).

I hope this will make the CFG more viable as a code-understanding tool, as we'll be able to better document our findings.

0
1
0
repeated

AI generated content in a nutshell

(Disclaimer: This has to be one of the worst videos I've ever watched... enjoy)

3
3
0
repeated
repeated

Reviving a Classic: The Journey to Reconstruct F-15 Strike Eagle II's Code

In a remarkable feat of reverse engineering, a hobbyist has successfully reconstructed the executable for the 1989 game F-15 Strike Eagle II, bringing nostalgia and technical prowess together. This mi...

https://news.lavx.hu/article/reviving-a-classic-the-journey-to-reconstruct-f-15-strike-eagle-ii-s-code

0
3
0
repeated

“Why don’t you take some of that ‘go to mars’ money and actually help rather than Monday morning quarterbacking during a live fire?”

The CEO of Watch Duty is bringing the energy that we need to 2025.

https://sfstandard.com/2025/01/09/wildfires-watch-duty-elon-musk-los-angeles/

1
8
0
repeated

Another take on AI that (at least for now) kinda nails it.

4
15
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

Use of AI tools reduces critical thinking abilities. Frank Herbert looks more prophetic every day.

1
3
0
repeated

Exploiting SSTI in a Modern Spring Boot Application (3.3.4) https://modzero.com/en/blog/spring_boot_ssti/

0
2
0
Overview of WebAssembly Type Confusion in JavaScript Engines Exploitation

https://xia0.sh/blog/overview-of-wasm-in-jsengine-exploit?ref=blog.exploits.club
0
0
2
repeated

Project Zero Bot

New Project Zero issue:

Samsung S24: Out of bounds write in APE Decoder

https://project-zero.issues.chromium.org/issues/368695689

CVE-2024-49415
0
1
3
It's not ../, it's a vanilla stack overflow as a result of strncpy with input size.

This company should not exist by now.

https://labs.watchtowr.com/do-secure-by-design-pledges-come-with-stickers-ivanti-connect-secure-rce-cve-2025-0282/
1
2
3
repeated

Our 2025 RE//verse talk schedule is now live! Talks start Friday, but don't forget to check the Thursday schedule and arrive early enough for the kick-off event!

https://re-verse.io/schedule.html?utm_source=mastodon&utm_medium=social&utm_campaign=schedulepub#sz-tab-45716

0
5
0
repeated

One of the most useful skills you get out of doing open source comes from learning to write READMEs.

Being able to describe a piece of software clearly and concisely in terms of
- what is is
- what it does
- how it does it
- why it does it that way
- how you use it
is a superpower that will you will be able to use throughout your career.

2
4
0
repeated

PowerSchool, a provider of K-12 software and cloud solutions, had a breach over the holidays. But not to worry, they paid the cybercriminals who hacked them and they have a video of the crooks deleting the data.

"PowerSchool has received reasonable assurances from the threat actor that the data has been deleted and that no additional copies exist."

Thank goodness the threat actors are so reasonable, right? SMH.

15
5
0
repeated
Big news: a recent copyleft lawsuit we funded and supported has concluded with a very positive result for user rights! The suit, brought by a device owner in Germany, resolved with the purchaser receiving the right to repair, modify, and reinstall LGPLed software on their devices. Check out the details at https://sfconservancy.org/news/2025/jan/09/avm-copyleft-lawsuit-resolved-with-install/
0
10
0
repeated

Congratulations all crowd strike users on macOS who now get warnings about the libcurl version shipped by Apple. May you all enjoy your choices of software vendors.

It alerts about CVE-2024-9681. We said it is severity low. NVD says 6.5 medium.

Never a dull moment.

2
2
0
repeated

OK, I fleshed this out a little more. You can find the (In)Security Appliance Bingo 2025 in proper, two-dimensional form here:

https://cku.gt/appbingo25

Suggestions and submissions very welcome.

1
3
0
repeated

CrowdStrike: Recruitment Phishing Scam Imitates CrowdStrike Hiring Process
Following CrowdStrike's successful Denial of Service attack on customers' Windows systems worldwide in July 2024, recruitment has gone up (this is a joke). CrowdStrike reports that a newly discovered phishing campaign uses CrowdStrike recruitment branding to convince victims to download a fake application, which serves as a downloader for the XMRig cryptominer. They describe the infection chain and provide Indicators of Compromise.

0
2
0
[RSS] WorstFit: Unveiling Hidden Transformers in Windows ANSI!

https://devco.re/blog/2025/01/09/worstfit-unveiling-hidden-transformers-in-windows-ansi/
0
3
2
Show older