Posts
3165
Following
706
Followers
1560
"I'm interested in all kinds of astronomy."
repeated
Edited 7 months ago
0
1
1
"ChatGPT isn't its own, unique problem. It's a symptom of a totalizing cultural paradigm in which passive consumption and regurgitation of content becomes the status quo"

Many strong quotes in this one

#LLM

Teachers Are Not OK
https://www.404media.co/teachers-are-not-ok-ai-chatgpt/
0
4
5
repeated

Lorenzo Franceschi-Bicchierai

We have finished going through the court docs and hearing transcripts from the WhatsApp v. NSO lawsuit.

Here's everything we learned, from how NSO's customers use Pegasus, to the spyware's cost.

https://techcrunch.com/2025/05/30/eight-things-we-learned-from-whatsapp-vs-nso-group-spyware-lawsuit/

0
5
0
repeated
repeated

New blog post!

How I got a Root Shell on a Credit Card terminal

https://stefan-gloor.ch/yomani-hack

5
9
0
[oss-security] Roundcube webmail: Post-Auth RCE via PHP Object Deserialization reported by firs0v /by @hanno

https://www.openwall.com/lists/oss-security/2025/06/02/1

#NoCVE
0
1
1
repeated

I always learn something new from @tomasp . This time, it was the existence of this book.

Can you write a whole book about a program? About a *1-line program*?

Turns out you can, and it is totally worth reading:
https://10print.org/
I can't praise this enough.

0
4
0
Re: NetLock distrust, this ticket is a good starting point to figure out what exactly the compliance issues were:

https://bugzilla.mozilla.org/show_bug.cgi?id=1904041

It's not a nice read with comments like "was comment 20 AI generated?"...
0
0
0
I have no idea why this works now and why it didn't work before...

Praise be the Omnissiah!
1
0
0
Google Chrome is removing Hungarian CA NetLock from its trust store:

https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html

Stated reason: "a pattern of compliance failures, unmet improvement commitments, and the absence of tangible, measurable progress in response to publicly disclosed incident reports"

I've personally ran into revoked NetLock certs during the past months, the reason for revocation was unclear ("administrative").

NetLock was compromised previously as part of the Stuxnet/Duqu campaign:

https://theintercept.com/2014/11/12/stuxnet/
0
3
2
Hidden Bear: The GRU hackers of Russia’s most notorious kill squad

https://theins.press/en/inv/281731
0
4
3
I don't want to log in with a fucking Microsoft account.

I want to use my fucking serial port.
0
7
27
repeated

Inspirational Skeletor💀

2
3
0
repeated

Data from the domain DNS shows that many European public services rely on proprietary cloud services: https://jurgen.gaeremyn.be/2025/03/08/european-critical-dependencies/

"Querying mail-servers teaches that in some countries, over 70% of all public services rely on this American provider."

Last week, allegedly decided to cancel MS365 services of Chinese universities with a notice of about one week: https://www.scmp.com/tech/tech-war/article/3305889/microsoft-abruptly-cuts-services-chinese-university-genomics-firm

1/2

1
4
0
Has anyone set up kernel debugging with a Windows 11 target with Proxmox (QEMU-KVM)?

This only works with Win10, Win11 doesn't boot for me:

https://forum.proxmox.com/threads/windbg-remote-kernel-debugging-and-proxmox-not-working.163625/

Serial would also be an option if I could make them recognized by guests:

https://forum.proxmox.com/threads/two-windows-guests-communicating-via-serial-console-comn.67588/
0
1
1
repeated

Beating the kCTF PoW with AVX512IFMA for $51k

https://anemato.de/blog/kctf-vdf

0
3
0
A casual player finds a memory corruption in Super Mario allowing arbitrary code execution and speedrunners exploit it *by hand* to warp to the credits screen.

https://www.youtube.com/watch?v=WdadpHLAfdA

#GameHacking is really something else!
0
6
9
repeated

yossarian (1.3.6.1.4.1.55738)

npm is getting trusted publishing soon!

https://github.com/orgs/community/discussions/161015

helping build and design the original version of trusted publishing for PyPI is easily in the top 3 moments of my career so far -- it's really amazing to see it get adopted by RubyGems, Rust (in progress), and now the JS ecosystem.

0
5
0
Had to make a proper GIF of this
0
0
0
Show older