Posts
3368
Following
712
Followers
1580
"I'm interested in all kinds of astronomy."
Edited 8 months ago
It would be so much easier to promote Google alternatives like #Framasoft if there was a usable language chooser on the UI...

https://www.youtube.com/watch?v=pwODwwgE6rA
2
0
2
repeated

Last week, I gave a talk on web browser security research at a student-organized conference. I tried to make the talk reasonably beginner-friendly, so the slides (linked here) could hopefully be useful to someone as a learning resource. https://docs.google.com/presentation/d/1rEPiqV0KBHAI0lVym283OHzYRXNCCuGudmDby1Z1qyc/edit?usp=sharing

1
9
0
repeated

Scumbag Google is at it again and introduces delays when loading a video on YouTube with an active ad blocker. With a nice litter banner on the lower left saying "Experiencing interruptions? Here's why!" with a link to a page telling you to disable ad blockers.

Guess what, you pissheads! It's still faster and less annoying to wait for the delay than actually watching the ads.

3
3
0
repeated
Edited 8 months ago

I finally found the perfect bug to play with wrapwrap and get RCE on Monero forums ablobcatpopcorn

After that, very classic exploitation steps. The only twist is that I didn't expect Laravel to unserialize() session cookies when the session driver is set to Redis (at least this version).

https://swap.gs/posts/monero-forums/

3
8
0
repeated

This Video Can Your (CVE-2025-31200)

https://www.youtube.com/watch?v=nTO3TRBW00E

Besides the clickbaity title, this video is actually a simple and fun initial analysis of the in question.

As a side note, I started watching it on a device with no and damn, YouTube has become so annoying and utterly unusable 😠

0
2
0
I'd like to live through the day when persistent storage will reach the bandwidth to effortlessly handle Windows updates.
1
1
1
repeated
[RSS] Code execution from web browser using URL schemes handled by KDE's KTelnetService and Konsole (CVE-2025-49091)

https://proofnet.de/publikationen/konsole_rce.html
0
0
2
repeated

Apparently, if you have facebook or Instagram installed on your phone, was able to track your browsing habits and link them to your real identity even if you never logged in on the web, used incognito mode or a VPN. I hope Meta gets hit with every fine in the book.

https://www.zeropartydata.es/p/localhost-tracking-explained-it-could

24
28
0
repeated

(CVE-2025-4275) - a trivial bypass for UEFI-compatible firmware based on Insyde , part 1

https://coderush.me/hydroph0bia-part1/

0
2
0
repeated

With the Kagi for Libraries program, we'll offer free access to Kagi for public library patrons worldwide 📚

If your library is interested or you know a local public library that could benefit, encourage them to apply and help us expand this program:

https://kagi.com/libraries

2
3
0
repeated

TrendAI Zero Day Initiative

It's a mild release from and a record-breaking release from . There's a single 0-day to deal with in WEBDAV and, as always, a few deployment challenges. @TheDustinChilds provides all the details at
https://www.zerodayinitiative.com/blog/2025/6/10/the-june-2025-security-update-review

0
2
0
Edited 8 months ago
[RSS] Getting started with Wirego

http://blog.quarkslab.com/getting-started-with-wirego.html

This looks extremely useful!
0
3
4
repeated
repeated

This was a fun one to discover!
SQL syntax can be ambiguous, and MySQL anticipated this a long time ago. Other SQL dialects stuck to the spec, leading to SQL injection when the right stars align:

@SonarResearch https://infosec.exchange/@SonarResearch/114659742648728633

0
5
0
[RSS] CVE-2025-47934 - Spoofing OpenPGP.js signature verification

https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/
0
0
1
repeated
[RSS] Strong Typing + Debug Information + Decompilation = Heap Analysis for C++

https://core-explorer.github.io/blog/c++/debugging/2025/06/09/snapshot-analysis-for-modern-c++.html
0
0
1
repeated

I've published my 8086 CPU Test suite for emulators.

It contains 646,000 single-step opcode executions with initial and final register and memory states.

https://github.com/SingleStepTests/8086

1
7
0
Show older