My father-in-law is a COBOL programmer on social security and he's basically ready to join ISIS at this point
The BlackHoodie training at @offensive_con deals with compiler backdoors and is sponsored by @hexrayssa what an honor♥️The training takes place May 15th and registration is now open https://blackhoodie.re/Offensivecon2025/
New updates to the Decompilation Wiki by harpend (on GitHub). We have a new in-depth Switch structuring section and a new Loop Reduction section.
https://decompilation.wiki/fundamentals/structuring/schema-based/switch-structuring/
Kagi empowers you to personalize your search results, allowing you to see more of what you prefer, less of what you don't, or block content entirely.
View the top domains that users create personalizations for: https://kagi.com/stats?stat=leaderboard
Another must-watch talk from RE//verse 2025 is live! Zion Basque challenges decompilers to step up their game and introduces a roadmap for a practical solution to solve some of the trickiest compiler behavior's to analyze. Check it out here: https://youtu.be/VP29biKLoSw
Holy shit.
Just wow, wow, holy shit:
Completely rewriting a multi-million line COBOL codebase that has life-or-death consequences for real people in the space of a few months, using gen AI?
I’ve been writing software for 40-some years, and I have to say: this may be, without exaggeration, the stupidest software-related idea I’ve ever heard from leadership.
https://www.wired.com/story/doge-rebuild-social-security-administration-cobol-benefits/
Our crew members @mwulftange & @frycos discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam's blacklist for CVE-2024-40711 & CVE-2025-23120 as well as further entry points following @SinSinology & @chudypb 's blog. Don’t blacklist - replace BinaryFormatter.
Gemini 2.5 "reasoning", no real improvement on river crossings
https://awful.systems/post/3875809
"I think chain of thought / reasoning is a fundamentally dishonest technology. At the end of the day, just like older LLMs it requires that someone solved a similar problem (either online or perhaps in a problem solution pair they generated if they do that to augment the training data)"
“Vulgar Display of Power”
https://tante.cc/2025/03/28/vulgar-display-of-power/
> It is a display of power: You as an artist, an animator, an illustrator, a writer, any creative person are powerless. We will take what we want and do what we want. Because we can.
(ノ`Д´)ノ彡┻━┻
(Days without cleaning up after a "coding assistant" in the prod: 0)
Here are my notes on using a Python virtual environment with IDA Pro:
https://williballenthin.com/post/using-a-virtualenv-for-idapython/
Spent the morning with my amazing friend Diána Laurent. We sat in a café, talked, laughed, plotted a short comic, and she did character sketches for the MCs I came up with. It was inspiring and wonderful. Seeing an artist bring characters to life will always feel like absolute magic to me. ✨️
(AI can suck it. It will never replicate this.)
Alright, let's get the #nakeddiefriday going.
Today's exhibit is AR9281 by Atheros, a very classic Wi-Fi chip found in many devices. Comes in very pink hues. A short thread with highlights follows.
SiPron page: https://siliconpr0n.org/archive/doku.php?id=infosecdj:atheros:ar9281-al1e