Posts
3164
Following
706
Followers
1558
"I'm interested in all kinds of astronomy."
[RSS] Streaming Zero-Fi Shells to Your Smart Speaker

https://blog.ret2.io/2025/06/11/pwn2own-soho-2024-sonos-exploit/
0
1
2
[RSS] Why Was Nvidia Hosting Blogs About 'Brazilian Facesitting Fart Games'?

https://www.404media.co/spam-blogs-ai-slop-domains-wowlazy/

Instant reshare!
0
0
1
repeated

“Localhost tracking” explained. It could cost Meta 32 billion. https://www.zeropartydata.es/p/localhost-tracking-explained-it-could

0
2
0
#hardtechno #music #nudity
Show content
This crowd kicks ass! (It's already established that Jazzy is plain crazy)

https://www.youtube.com/watch?v=R07oELe1aUA
0
1
2
repeated
Edited 7 months ago

"Donald Trump’s director of national intelligence fed the JFK files into an AI program, asking it to see if there was anything that should remain classified, she told a crowd at an Amazon Web Services conference Tuesday"

Is there any way we can convince The Onion to not keep publishing their stuff under different domain names? 🤪

https://www.thedailybeast.com/tulsi-gabbard-admits-to-asking-ai-what-to-classify-in-jfk-files/

1
3
0
repeated

yossarian (1.3.6.1.4.1.55738)

Bypassing GitHub Actions policies in the dumbest way possible

https://blog.yossarian.net/2025/06/11/github-actions-policies-dumb-bypass

1
4
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Adobe Acrobat Reader Font CFF2 PrivateDict vsindex Out-Of-Bounds Read Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2159

CVE-2025-43578
0
1
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Adobe Acrobat Reader Annotation Destroy Use-After-Free Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2170

CVE-2025-43576
0
1
2
[RSS] CVE-2025-33073: A Look in the Mirror - The Reflective Kerberos Relay Attack

https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/
0
1
4
Edited 7 months ago
Fun fact: Microsoft Code Signing PCA 2010 will expire next month 🍿
2
1
5
Edited 7 months ago
It would be so much easier to promote Google alternatives like #Framasoft if there was a usable language chooser on the UI...

https://www.youtube.com/watch?v=pwODwwgE6rA
2
0
2
repeated

Last week, I gave a talk on web browser security research at a student-organized conference. I tried to make the talk reasonably beginner-friendly, so the slides (linked here) could hopefully be useful to someone as a learning resource. https://docs.google.com/presentation/d/1rEPiqV0KBHAI0lVym283OHzYRXNCCuGudmDby1Z1qyc/edit?usp=sharing

1
9
0
repeated

Scumbag Google is at it again and introduces delays when loading a video on YouTube with an active ad blocker. With a nice litter banner on the lower left saying "Experiencing interruptions? Here's why!" with a link to a page telling you to disable ad blockers.

Guess what, you pissheads! It's still faster and less annoying to wait for the delay than actually watching the ads.

3
3
0
repeated
Edited 7 months ago

I finally found the perfect bug to play with wrapwrap and get RCE on Monero forums ablobcatpopcorn

After that, very classic exploitation steps. The only twist is that I didn't expect Laravel to unserialize() session cookies when the session driver is set to Redis (at least this version).

https://swap.gs/posts/monero-forums/

3
8
0
repeated

This Video Can Your (CVE-2025-31200)

https://www.youtube.com/watch?v=nTO3TRBW00E

Besides the clickbaity title, this video is actually a simple and fun initial analysis of the in question.

As a side note, I started watching it on a device with no and damn, YouTube has become so annoying and utterly unusable 😠

0
2
0
I'd like to live through the day when persistent storage will reach the bandwidth to effortlessly handle Windows updates.
1
1
1
repeated
[RSS] Code execution from web browser using URL schemes handled by KDE's KTelnetService and Konsole (CVE-2025-49091)

https://proofnet.de/publikationen/konsole_rce.html
0
0
2
repeated

Apparently, if you have facebook or Instagram installed on your phone, was able to track your browsing habits and link them to your real identity even if you never logged in on the web, used incognito mode or a VPN. I hope Meta gets hit with every fine in the book.

https://www.zeropartydata.es/p/localhost-tracking-explained-it-could

24
28
0
repeated

(CVE-2025-4275) - a trivial bypass for UEFI-compatible firmware based on Insyde , part 1

https://coderush.me/hydroph0bia-part1/

0
2
0
Show older