Posts
2487
Following
654
Followers
1479
"I'm interested in all kinds of astronomy."
[RSS] Micropatches Released for SCF File NTLM Hash Disclosure Vulnerability (No CVE)

https://blog.0patch.com/2025/03/micropatches-released-for-scf-file-ntlm.html
0
0
1
repeated

Hey did you know

1. It is Bandcamp Friday* I didn't know if they'd do Bandcamp Friday after last year but they're doing it. This means if you buy music on Bandcamp in the next 11 hours the artist gets a higher % than normal and the weird company that bought Bandcamp gets jack

2. ~ Lena Raine, who you may know as the composer from Celeste, dropped a new album today ~

https://radicaldreamland.bandcamp.com/album/earthblade-across-the-bounds-of-fate

---

* https://isitbandcampfriday.com/

1
4
0
repeated

Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post:
https://sensepost.com/blog/2025/diving-into-ad-cs-exploring-some-common-error-messages/

0
4
0
repeated

I’m not saying you definitely have to go to @bluehatil this year, I’m just letting you know it’s free, by the beach and I’ll be there dropping kernel pointers to anyone who asks nicely

4
3
0
repeated

This year I am joining the Black Hat USA review board as a guest reviewer. It's awesome to be part of such an industry defining event and help give back to the community 🫶

Since I learned English as a second language (ESL) myself, I understand how stressful it can be to work on CFPs. It's not just about the technical details, you also have to consider formatting, wording, and overall clarity. If anyone wants some structural feedback on their submissions, my DMs are open as always 🙇‍♂️

1
2
0
repeated
Edited 5 months ago

Fuck.

will soon be completely unusable instead of mostly unusable(paid results).

This is a real problem.

" you can't just scroll down in AI Mode to see organic results. … refine your search or ask follow-up questions."

https://arstechnica.com/google/2025/03/google-is-expanding-ai-overviews-and-testing-ai-only-search-results/

3
3
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

Edited 5 months ago

Wow the AutoCHERI report makes me not want to get into a car ever again:

The few memory issues that were detected by CHERI hardware (exceptions) required a detailed analysis of the error conditions to understand and address the them, which took significantly more time than is normally spent using conventional tools. CHERI’s increased demand on exception management needs a higher level of development effort and expertise, rather than enabling less experienced engineers to adopt it for embedded and safety-critical systems development.

If automotive vendors are employing developers who find it hard to debug memory-safety issues when the hardware tells you the precise instruction that triggers the bug (and a debugger stops at exactly that point showing you where in the bug exists in the source code), they must be really scraping the bottom of the barrel.

Odd that this is the exact opposite of the experience that everyone else has had developing on CHERI platforms.

3
7
0
repeated

Retro MS DOS Coding - Recreating the Iconic Award BIOS Screen
Because why not, it looks simpler than it really is and we’ll get to fall down a rabbit hole trying to draw the Energy Star logo.
https://ncot.uk/videos/retro-ms-dos-coding---recreating-the-iconic-award-bios-screen/

0
3
0
repeated

Google Mandiant has identified several macOS malware variants compiled for x86-64 architecture. This choice of architecture is most likely due to more relaxed execution policies for x86-64 binaries running under Rosetta 2. https://cloud.google.com/blog/topics/threat-intelligence/rosetta2-artifacts-macos-intrusions?linkId=13291352

0
2
0
[RSS] PostgreSQL: Privilege Escalation Vulnerability via pg_cron

https://github.com/google/security-research/security/advisories/GHSA-j8p5-79jf-g575
0
2
6
I got badly nerd sniped by Qualys:

Dreams in #CodeQL - Quest for the Perfect GOTO

https://scrapco.de/blog/dreams-in-codeql-quest-for-the-perfect-goto.html
0
2
6
repeated
Edited 5 months ago

A team of archivists have recreated the CDC (Centers for Disease Control and Prevention) website from just before it was purged by US President Donald Trump, hosting it in Europe!

https://restoredcdc.org/www.cdc.gov/

0
8
0
repeated
repeated

CRTs are particle accelerators built for videogames. I need you to understand this!!!

0
7
0
repeated

Solid comments from @rgb_lights' testimony 🔥

0
3
0
repeated

The BlackHat call for papers is now open and we'd love to have your submission 😍 I am leading the Reverse Engineering track, and would be extra pleased to see your work at this year's con! If you have questions or would like a pre-review, let me know!
https://www.blackhat.com/call-for-papers.html

1
6
0
repeated

Project Zero Bot

New Project Zero issue:

Firefox: use-after-free in txMozillaXSLTProcessor

https://project-zero.issues.chromium.org/issues/383558273

CVE-2025-1009
0
1
1
repeated

🗞️ We just resumed sending out our newsletter!

You'll get some YouTube content and other big news to come.

Register! https://rev.ng/newsletter-subscribe

0
2
0
repeated

🔴 New video: "Deobfuscation with rev.ng"

Check it out: https://www.youtube.com/watch?v=oBfxa9xv24A

0
3
0
Show older