Posts
2537
Following
638
Followers
1436
"I'm interested in all kinds of astronomy."
repeated

🚨 New advisory was just published! 🚨

Multiple vulnerabilities were discovered in Foscam X5. These vulnerabilities allow a remote attacker to trigger code execution vulnerabilities in the product: https://ssd-disclosure.com/ssd-advisory-multiple-foscam-x5-vulnerabilities/

0
2
0
repeated

The recording of our OffensiveCon presentation about EntrySign is live at https://youtu.be/sUFDKTaCQEk
Slides at http://entrysign.top

0
3
0
[RSS] Telegram Gave Authorities Data on More than 20,000 Users

https://www.404media.co/telegram-gave-authorities-data-on-more-than-20-000-users/
0
0
1
[RSS] Remembering The ISP That David Bowie Ran For Eight Years

https://hackaday.com/2025/05/19/remembering-the-isp-that-david-bowie-ran-for-eight-years/
0
1
2
repeated

Discovery: The "copilot" bot user that Microsoft will soon be flooding your github repos with garbage content from is implemented in some sort of special way that exempts it from the "block" feature you would normally be able to block other users/bots with

https://github.com/orgs/community/discussions/159749

32
22
0
#EU reaction as Orbán is about to kill independent press and civil society in #Hungary

https://youtu.be/UIPSvIz9NDs?si=Sbe2wHqsHkqPtjm6&t=40
0
1
0
repeated

Microsoft takes Windows Subsystem for Linux open source after nearly a decade
WSL has also recently added official support for both Fedora and Arch distros.
https://arstechnica.com/gadgets/2025/05/microsoft-takes-windows-subsystem-for-linux-open-source-after-nearly-a-decade/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

3
8
0
repeated

"Go Cryptography Security Audit" by Roland Shoemaker — https://go.dev/blog/tob-crypto-audit

0
3
0
CVE-2024-11182 also seems like a stored XSS: "attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag" - The '90s called and they want their webmail bugs back!!

RE: https://mastodon.social/@cisakevtracker/114535806650652126
0
0
1
I found that CVE-2024-27443 doesn't qualify for XSS Reflections as it seems to be a stored XSS. Pretty neat vuln though!

https://github.com/v-p-b/xss-reflections

RE: https://mastodon.social/@cisakevtracker/114535804613431399
0
0
1
repeated

I have been following the INFOSEC industry and am ready to begin my startup. Any investors here interested? Here's my business plan.

7
3
0
[RSS] Security Bulletin: IBM i is vulnerable to a machine-in-the-middle attack due to mishandling error codes when verifying the host key by OpenSSH. [CVE-2025-26465]

https://www.ibm.com/support/pages/node/7233399?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSKWKM&mynp=OCSSC5L9&mynp=OCSSB23CE&mync=A&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSKWKM-OCSSC5L9-OCSSB23CE-_-A

#IBMi
0
0
0
repeated

DOMPurify 3.2.6 has been release with several smaller fixes and improvements, thanks to all who contributed 💕

https://github.com/cure53/DOMPurify/releases/tag/3.2.6

Hopefully this will also help with the CI/CD issues that arose after the fake CVE was posted last week.

0
3
0
repeated

My new blog post 🥳

Improving AFD Socket Visibility for Windows Forensics & Troubleshooting

It discusses the low-level API under Winsock (IOCTLs on \Device\Afd handles) and explores the workings of the new socket inspection feature in System Informer 🔥
https://www.huntandhackett.com/blog/improving_afd_socket_visibility

0
4
0
repeated
repeated

Trend Zero Day Initiative

Pwn2Own Berlin 2025 comes to a close. We awarded $1,078,750 for 28 unique 0-days. Congrats to @starlabs_sg for winning Master of Pwn with $320,000. Thanks to @offensive_con for hosting, and thanks to all who participated. Can't wait to see you next year!

0
2
0
repeated

Last 7 DAYS LEFT to submit to our Off-By-One 2025 CFP!

Got something exciting to share? Now’s your chance to speak at the conference.

⏰ Time is ticking!
http://offbyone.sg/cfp

Let’s make this unforgettable!

0
4
0
repeated

Distributed Denial of Secrets

Telemssage (410 GB)

https://ddosecrets.com/article/telemessage

Thousands of heap dumps taken May 4, 2025 from TeleMessage, which produces software used to archive encrypted messaging apps such as Signal and WhatsApp. Due to PII in the dataset and the inclusion of groups and messages unrelated to government or corporate behavior, the data is currently only being offered to journalists and researchers.

2
8
0
Show older