Posts
3368
Following
712
Followers
1580
"I'm interested in all kinds of astronomy."
repeated

Every project should have a "cursed"-page like that: 😆

"Cursed knowledge we have learned as a result of building that we wish we never knew."
https://immich.app/cursed-knowledge/

🤓

2
6
0
repeated

https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html

Some cool things to note though: (1) the bug was mitigated via finch kill switch (https://developer.chrome.com/docs/web-platform/chrome-finch) one day after the report from TAG (2) we also fixed the V8 Sandbox bypass within 7 days even though it's not yet considered a security boundary.

And I've also updated our V8 Exploit Tracker sheet now: https://docs.google.com/document/d/1njn2dd5_6PB7oZGTmkmoihYnVcJEgRwEFxhHnGoptLk/edit?usp=sharing (see the 2025 tab) :)

1
4
0
repeated

Meta and Yandex are de-anonymizing Android users’ web browsing identifiers
Abuse allows Meta and Yandex to attach persistent identifiers to detailed browsing histories.
https://arstechnica.com/security/2025/06/headline-to-come/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

6
9
0
repeated

How to build a high-performance network fuzzer with LibAFL and libdesock https://lolcads.github.io/posts/2025/05/high_performance_network_fuzzing/

0
2
0
Stats: I collected ~2600 bookmarks during ~30 months, archiving all of them takes about 2 GB of disk space (with #Readeck)
1
1
4
repeated
repeated
New assessment for topic: CVE-2025-48734

Topic description: "Improper Access Control vulnerability in Apache Commons. ..."

"On May 28 2025, Apache posted an [advisory](https://www.openwall.com/lists/oss-security/2025/05/28/6) to the OSS Security mailing list warning that Apache Commons BeanUtils versions 1.x before 1.11.0 and 2.x before 2.0.0-M2 were vulnerable to insecure access to the Java Classloader via exposed enum properties, namely the `declaredClass` property ..."

Link: https://attackerkb.com/assessments/1d98f952-f6f1-475a-8646-74062d040247
0
1
0
repeated
repeated
Edited 8 months ago
0
1
1
"ChatGPT isn't its own, unique problem. It's a symptom of a totalizing cultural paradigm in which passive consumption and regurgitation of content becomes the status quo"

Many strong quotes in this one

#LLM

Teachers Are Not OK
https://www.404media.co/teachers-are-not-ok-ai-chatgpt/
0
4
5
repeated

Lorenzo Franceschi-Bicchierai

We have finished going through the court docs and hearing transcripts from the WhatsApp v. NSO lawsuit.

Here's everything we learned, from how NSO's customers use Pegasus, to the spyware's cost.

https://techcrunch.com/2025/05/30/eight-things-we-learned-from-whatsapp-vs-nso-group-spyware-lawsuit/

0
5
0
repeated
repeated

New blog post!

How I got a Root Shell on a Credit Card terminal

https://stefan-gloor.ch/yomani-hack

5
9
0
[oss-security] Roundcube webmail: Post-Auth RCE via PHP Object Deserialization reported by firs0v /by @hanno

https://www.openwall.com/lists/oss-security/2025/06/02/1

#NoCVE
0
1
1
repeated

I always learn something new from @tomasp . This time, it was the existence of this book.

Can you write a whole book about a program? About a *1-line program*?

Turns out you can, and it is totally worth reading:
https://10print.org/
I can't praise this enough.

0
4
0
Re: NetLock distrust, this ticket is a good starting point to figure out what exactly the compliance issues were:

https://bugzilla.mozilla.org/show_bug.cgi?id=1904041

It's not a nice read with comments like "was comment 20 AI generated?"...
0
0
0
I have no idea why this works now and why it didn't work before...

Praise be the Omnissiah!
1
0
0
Show older