Posts
3368
Following
712
Followers
1580
"I'm interested in all kinds of astronomy."
And the day is not over: Trying to fix some household stuff, I google for parts. First result is a recall notice claiming a dozen incidents with human injury o.O

(The part I was searching for was the cause of the failure too)
1
0
4
repeated

AFL++ v4.32c release - mostly minor bug fixes and improvements, LLVM 20 users should update! https://github.com/AFLplusplus/AFLplusplus/releases/tag/v4.32c -tools

0
7
0
One of my favorite #SmallWeb site is this guy's, who documents disassembling the multitude of things he collected during several decades, while also blogging the nuances of everyday life like what he got fur lunch or finding a dead cockroach:

https://translate.kagi.com/translate/http://www.szetszedtem.hu/1717villanyvasut/apukamevolt.htm
0
2
3
repeated
Edited 9 months ago

Interesting Git repos of the week:

Strategy:

* https://github.com/TalEliyahu/awesome-CISO-maturity-models - modelling your strategy

Detection:

* https://github.com/yevh/TaaC-AI - threat modelling as code
* https://github.com/thalesgroup-cert/Watcher - build your own threat hunting platform with Thales
* https://github.com/microsoft/msticpy - Microsoft's TI tooling

Exploitation:

* https://github.com/specfy/stack-analyser - what's in the stack?

Hardening:

* https://github.com/nistorj/ISR1000 - guestshell on the ISR1000

, ,

0
3
0
I struggled a couple of hours because my sshfs connections kept breaking, that made my browser hang in many different ways (fuse ftw!).

I suspected my router getting bust, but of course I was wrong. The problem - as always - was DNS.
0
1
6
[FD] Microsoft Windows .XRM-MS File / NTLM Information Disclosure Spoofing

https://seclists.org/fulldisclosure/2025/May/0

Just block egress SMB connections already!
0
0
1
repeated

brk, a.k.a. @evanrichter

Don’t forget to patch your tomorrow! (Security related)
https://floss.social/@forgejo/114433179035067022

0
2
0
repeated

I'm proud to announce that myself and @atipriyabajaj have created the Workshop on Software Understanding and Reverse Engineering (SURE), which will be co-located at CCS 2025. https://sure-workshop.org/

Please follow our workshop account @sureworkshop and RT it for visibility :).

0
2
0
repeated

Here's something counterintuitive to non-practitioners: curve P-521 is often less secure in practice than curve P-256.

The latter is more popular, and so better tested. The risk of implementation bugs dwarfs the risk of partial cryptanalysis of ECC, so picking P-521 optimizes for the wrong thing.

5
7
0
[RSS] CVE-2025-21756: Attack of the Vsock

https://hoefler.dev/articles/vsock.html

#linux
0
0
3
repeated

Intel's 386 processor (1985) moved the x86 architecture to 32 bits, but it needed to be backward compatible with earlier 16 and 8-bit processors. As a result, it needed complicated circuitry for its internal registers: six different circuits for 30 registers. Let's look at the silicon circuits. 1/N

1
6
0
BinPool: A Dataset of Vulnerabilities for Binary Security Analysis

https://github.com/SimaArasteh/binpool

/via @exploitsclub
0
0
2
repeated
repeated

🔐 The SLB 9670VQ2.0 FW7.85 SPI TPM module sounds like something your cat would type mid-zoom call — but it's actually a serious piece of security hardware.

This TPM (Trusted Platform Module) chip is used in motherboards and SBCs to store crypto keys, generate true random numbers, and keep your hardware’s trust chain tight, even if the rest of your system isn’t Fort Knox. TPM 2.0 is even a requirement for modern OSes like Windows 11.

1
1
0
TP-Link is CNA now.
2
4
9
repeated

A BIG WELCOME to these 7 CVE Numbering Authority () partners that joined the Program in April!!!

* CTOne
* Insyde Software
* Jaspersoft
* Sandisk
* Spotfire
* The Qt Company
* TP-Link

Join: https://www.cve.org/PartnerInformation/Partner#HowToBecomeAPartner

0
1
0
repeated

How to win my instant support as a customer:

"We have decided not to focus on generative AI features, and instead reinvest heavily in quality assurance for our core products through hiring, training, and process development."

4
14
0
Show older