Posts
3915
Following
728
Followers
1601
"I'm interested in all kinds of astronomy."
repeated

I just realized that @ is a lower case anarchy symbol.

0
7
0
repeated

One of my co-founders went into a paid engagement yesterday and was noodling through a piece on how to prevent upstream teams from making changes to application database schemas that would break analytics pipelines.

They got the attention of the room and then said "one solution is a baseball bat".

There was a moment of uncomprehending silence and then they said "solve at the human layer".

0
4
1
[oss-security] Dropbear SSH 2025.88 fixes CVE-2025-47203

https://seclists.org/oss-sec/2025/q2/116

"Don't allow dbclient hostname arguments to be interpreted by the shell."

Sounds like fun on many embedded devices :) Original announcement:

https://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2025q2/002385.html
0
1
4
[RSS] Dubious security vulnerability: A program does not run correctly if you run it the wrong way, redux

https://devblogs.microsoft.com/oldnewthing/20250512-00/?p=111174
1
1
1
repeated

Lulz...

"Impact: Muting the microphone during a FaceTime call may not result in audio being silenced"

@ https://support.apple.com/en-us/122404

0
4
0
repeated

CVE ID: CVE-2025-47729
Vendor: TeleMessage
Product: TM SGNL
Date Added: 2025-05-12
Vulnerability: TeleMessage TM SGNL Hidden Functionality Vulnerability
Notes: Apply mitigations per vendor instructions. Absent mitigating instructions from the vendor, discontinue use of the product. ; https://nvd.nist.gov/vuln/detail/CVE-2025-47729
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47729

1
1
0
repeated

NOELREPORTS 🇪🇺 🇺🇦

The ICAO Council has ruled that Russia is responsible for downing flight MH17, violating the Chicago Convention by using weapons against a civilian aircraft. 298 innocent lives were lost.

https://www.rijksoverheid.nl/ministeries/ministerie-van-buitenlandse-zaken/nieuws/2025/05/12/icao-raad-russische-federatie-verantwoordelijk-voor-neerhalen-van-vlucht-mh17

0
4
0
repeated
repeated

There was a short period of time in history when people would unironically say "why are you asking me, go ahead and google it."
(See also: LMFGTFY)

And now we are going back to "for the love of god don't google it, ask an expert instead."

2
9
0
repeated

10 Burp extensions I actually use... BUT none of them are in the top 30 most popular in the BApp Store!

I get tired of seeing the same extensions come up in "top 10" lists. Here are some hidden gems you might not have tried... yet. In no particular order.

🧵👇

1
4
0
repeated

TrendAI Zero Day Initiative

In this behind the scenes look at Berlin, Zed and Dustin have run into an interesting problem - no gear! https://youtube.com/shorts/Xj9Du8iuXCw?feature=share

1
4
0
repeated
Edited 1 year ago

We have a CI job to spot unwanted utf8 letters in PRs as we have noticed that GitHub will gladly show the for example (identical) Cyrillic version of a letter next to the Latin version in a diff and it is yes, entirely impossible for a human to spot the diff. I mean the diff is shown, but the significance of it is not.

Changing just a single letter like that in a URL hostname opens up for a world of grief.

12
7
0
repeated

my bank, deutsche bank, is serving a *revoked* tls certificate on their website db.com.

the mind reels at this level of incompetence.

https://www.ssllabs.com/ssltest/analyze.html?d=db.com

0
1
0
repeated
repeated

so i wrote another program for the IBM 1401 computer this past week. i wrote what it does on the card, but can you figure out how it works? the program is

,008015,022029,036043,048056,061066,070074U%U2MM%U2070WU%U2BB048B.048DATA⯒

that last little character is special!

1
3
1
repeated

You noticed how google search became unusably shit a few years ago?
Turns out that was on purpose

20
48
0
repeated

Men will literally build Kubernetes Cluster cluster at home instead of going to therapy ....

8
6
0
repeated
New assessment for topic: CVE-2024-58136

Topic description: "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. ..."

"On the April 9 2025, Yii released an advisory warning that Yii framework versions before `2.0.52` were susceptible to Unsafe Reflection, with this CVE essentially a patch bypass of `CVE-2024-4990` ..."

Link: https://attackerkb.com/assessments/e6d2c5ff-8653-41a3-acf1-882330960fe1
0
1
1
Show older