Posts
2588
Following
623
Followers
1381
"I'm interested in all kinds of astronomy."
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Wavlink AC3000 wctrls static login vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2034

CVE-2024-39754
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Wavlink AC3000 login.cgi Unauthenticated Firmware Upload vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2036

CVE-2024-39608
0
1
0
repeated
repeated

Happy from your friends at Fortinet: Authentication bypass in Node.js websocket module
CVE-2024-55591 (CVSSv3.1: 9.8 critical) An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Please note that reports show this is being exploited in the wild.

Indicators of compromise include possible log entries, IP addresses used, and admin accounts created. cc: @GossiTheDog @wdormann @cR0w @briankrebs

#

5
7
0
repeated
repeated

DOOM has now been ported to... a PDF!
(Works in browsers)
https://github.com/ading2210/doompdf

2
18
0
repeated

Micropatches Released for Windows "LDAPNightmare" Denial of Service Vulnerability (CVE-2024-49113)
https://blog.0patch.com/2025/01/micropatches-released-for-windows.html

1
4
0
repeated

Turns out snprintf() in old Windows C runtimes is documented to have the buffer overflow that no other implementations do. 🤔

https://learn.microsoft.com/en-us/cpp/c-runtime-library/reference/snprintf-snprintf-snprintf-l-snwprintf-snwprintf-l?view=msvc-170#remarks

6
5
0
repeated

Threat actors exploit a probable 0-day in exposed management consoles of Fortinet FortiGate firewalls https://www.orangecyberdefense.com/global/blog/cert-news/0-day-in-exposed-management-consoles-of-fortinet-fortigate-firewalls

0
2
0
repeated

TIL \ exists in ASCII literally so that ALGOL could write its Boolean operators in ASCII

https://en.m.wikipedia.org/wiki/ALGOL

5
17
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

OFFIS DCMTK nowindow improper array index validation vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122

CVE-2024-47796
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

OFFIS DCMTK determineMinMax improper array index validation vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2121

CVE-2024-52333
0
1
0
repeated

Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282) - watchTowr Labs https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/

0
2
0
[RSS] An SSRF to LFI Payload for PDF Generators (CVE-2024-34112 and beyond)

https://www.hoyahaxa.com/2025/01/an-ssrf-to-lfi-payload-for-pdf.html
0
0
1
repeated

Does anybody know how to prevent from issuing calls to libc functions like `memset` in this case when compiling C programs? I have tried I don't know how many command line arguments to try to disable it but none worked at all.

Here you have an example program in : https://godbolt.org/z/jheYoPWzj

These are the command line arguments I've tried to disable it:

-ffreestanding -disable-simplify-libcalls -fno-builtin -nostdinc -nostdlib -fno-builtin-memset -nostdlib++ -nostdinc++

Any idea?

2
1
0
repeated

might have to give up the apple watch so I can wear this replicate of the apollo guidance computer instead

https://gizmodo.com/apollo-landing-keypad-shrunken-into-worlds-coolest-calculator-watch-2000541103

6
6
0
repeated

Added the overlay-note-region-name-pending feature to the demo behind a feature-flag.

You can play with them at https://tmr232.github.io/function-graph-overview/?showRegions

Use `cfg-overlay-start: message` and `cfg-overlay-end` comments to denote the start and end of a region.

1
1
0
repeated

In one of the most "on brand" things I could write, here's an interview with Dan Keyworth, Director of Business Technology at McLaren Racing on how how the 2024 F1 World Constructor's Champions keep vast amounts of data and tech secured against cyber threats.

“We’ve got 200 people travelling around the world at any one time to 24 different races who, when they try to do something genuine, may look like they’re a threat to our organization,” says Keyworth.

“We’ve got to learn the different network behaviors they’re using when they’re on the road, for our business to recognize it as normal behavior when typically for other businesses, that’s abnormal behavior."

https://darktrace.com/the-inference/in-conversation-with-dan-keyworth-mclaren-racing

1
2
0
repeated
repeated

mitmproxy mitmproxy 11.1 is out! 🥳

We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings.

On Linux, this is done using eBPF and https://aya-rs.dev/, more details are at https://mitmproxy.org/posts/local-capture/linux/. Super proud of this team effort. 😃

2
7
0
Show older