Posts
3932
Following
728
Followers
1602
"I'm interested in all kinds of astronomy."
repeated

The Pentium processor, like many others, implements its instructions in microcode. Each step of an instruction is described by a micro-instruction, stored in the chip in the microcode ROM.
This die photo shows the parts of the Pentium. Let's take a quick look at the microcode ROM...1/N

1
3
0
repeated
Edited 1 year ago

A prominent computer scientist who has spent 20 years publishing academic papers on cryptography, privacy, and cybersecurity has gone incommunicado, had his professor profile, email account, and phone number removed by his employer Indiana University, and had his homes raided by the FBI. No one knows why.

Xiaofeng Wang

https://arstechnica.com/security/2025/03/computer-scientist-goes-silent-after-fbi-raid-and-purging-from-university-website/

7
19
0
repeated

Sufficient time has passed and I'm excited to share a demo and details of a CSRF vulnerability that I discovered in the popular gorilla/csrf library that has been present since its creation 😲 https://patrickod.com/csrf

0
2
0
repeated

🚨 LibAFL 0.15.2 🚨

  • Rust 2024 edition
  • LibAFL_Unicorn
  • Use LibAFL rand types for other crates
  • Allow logging to StatsD
  • LibAFL_QEMU updates like binary-only ASan in Rust 🦀🦀🦀, inputs via StdIn, better snapshots

And so much more:

https://github.com/AFLplusplus/LibAFL/releases/tag/0.15.2

0
5
0
HexShare - Share binaries with byte highlighting

https://hex.pov.sh/
0
1
3
repeated

31 March 2016 | Imre KertĂŠsz (b. 1929), Hungarian Jewish writer & Holocaust Survivor died. His works - including Fateless - draw repeatedly on his experience at . KertĂŠsz won the 2002 Nobel Prize for Literature. https://nobelprize.org/prizes/literature/2002/kertesz/biographical/

0
2
0
repeated
repeated

Re: The Oracle Thing™ this quote from @dangoodin's story seems significant.

On Friday, when I asked Oracle for comment, a spokesperson asked if they could provide a statement that couldn’t be attributed to Oracle in any way. After I declined, the spokesperson said Oracle would have no comment.

https://arstechnica.com/security/2025/03/oracle-is-mum-on-reports-it-has-experienced-2-separate-data-breaches/

0
2
0
repeated

In today's episode of drama in the CVE ecosystem:

The Canonical CNA created CVE-2025-0927 and an associated advisory for a heap overflow in HFS+ in the Linux kernel.

The Linux kernel CNA stripped out the information (like the reporter of Attila SzĂĄsz, useful references, etc) from the CVE entry and added the passive-aggressive:

The Linux kernel CVE team has been assigned CVE-2025-0927 as it was incorrectly created by a different CNA that really should have known better to not have done this.to this issue. [sic]

Also TIL: If you look only at the assignerShortName in a cvelistV5 CVE entry, you might not get the whole picture of whose CVE it technically is. While the Linux kernel rewrote history to claim that they assigned the CVE, that was only done via the cna container's ProviderMetadata shortName value. The top-level [assignerShortName](https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/0xxx/CVE-2025-0927.json#L7) for the entry still shows canonical.

Good times...

1
2
0
In light of recent events, let me re-share a classic:

Mary Ann Davidson - No, You Really Can’t

https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t

#Oracle
0
4
5
repeated

🌪️ We are excited to announce our second keynote speaker!

Join Phuong Nguyen for his thought-provoking session in Seoul on May 29-30! 🔗 typhooncon.com/agenda

0
2
0
repeated

This is a first: https://lore.kernel.org/linux-cve-announce/2025033057-CVE-2025-0927-1436@gregkh/T/#u I guess someone finally told them about the 72 hour deadline.

0
1
0
Edited 1 year ago
[RSS] The Curious Case of CVE-2015-2551 & CVE-2019-9081 - Doom and Gloom! Or not.

https://jericho.blog/2025/03/30/the-curious-case-of-cve-2015-2551-cve-2019-9081-doom-and-gloom-or-not/

My guess here is both CVE's were for deserialization gadget chains (one in JRE, the other in Laravel) which can't be trivially categorized as vulnerabilities (classes do what they are supposed to, only dev decided to YOLO unrelated parts of their code).
1
0
3
Edited 1 year ago
An even better Microsoft Account bypass for Windows 11 has already been discovered

https://www.windowscentral.com/software-apps/windows-11/an-even-better-microsoft-account-bypass-for-windows-11-has-already-been-discovered

Shift+F10 then `start ms-cxh:localonly`
3
118
142
repeated
Edited 1 year ago

🚨 Let’s Encrypt at risk from Trump cuts to OTF: “Let’s Encrypt received around $800,000 in funding from the OTF”

Dear @EUCommission, get your heads out of your arses and let’s find @letsencrypt €1M/year (a rounding error in EU finances) and have them move to the EU.

If Let’s Encrypt is fucked, the web is fucked, and the Small Web is fucked too. So how about we don’t let that happen, yeah?

(In the meanwhile, if the Let’s Encrypt folks want to make a point about how essential they are, it might be an idea to refuse certificates to republican politicians. See how they like their donation systems breaking in real time…)

CC @nlnet @NGIZero@mastodon.xyz

https://mastodon.social/@publictorsten/114223873439053263

20
13
0
The state of affairs is well illustrated by the fact that the video

"Turning children's glue into drinkable alcohol"

has a 1.4M view count currently on YT.

(I know this because it's also in my recommendations for some unfathomable reason)
2
0
3
repeated

New breach: German Doner Kebab had 162k unique email addresses publicly posted to a hacking forum last week. Data also included name, phone and physical addrress. 74% were already in @haveibeenpwned. Read more: https://x.com/DarkWebInformer/status/1905275857159008341

0
3
0
repeated

How not to respond to researchers: A crash course (cross-posting from the hellsite this time 'cause this one deserves it). Sorry to @albinolobster and team for sticking them with the hard part on this one. Being a research CNA is...a joy and a blessing?

https://x.com/Junior_Baines/status/1904940399430426996

0
3
0
Show older