Posts
2514
Following
649
Followers
1467
"I'm interested in all kinds of astronomy."
[RSS] Bin2Wrong: Fuzzing Binary Decompilers

https://github.com/FuturesLab/Bin2Wrong
0
0
2
repeated

Micropatches Released for "WSPCoerce" Coerced Authentication via Windows Search Protocol (NO CVE/WONTFIX) https://blog.0patch.com/2025/07/micropatches-released-for-wspcoerce.html

1
3
0
[RSS] exploits.club Weekly Newsletter 79 - Lenovo LPEs, WhatsApp Vulns, Forgotten Syzkaller Bugs, And More

https://blog.exploits.club/exploits-club-weekly-newsletter-79-lenovo-lpes-whatsapp-vulns-forgotten-syzkaller-bugs-and-more/
0
0
1
repeated

In a rare move, CISA gave federal agencies just one day to patch Citrix Netscaler bug CVE-2025-5777

Patch ASAP

https://therecord.media/cisa-orders-agencies-patch-citrix-bleed-2

0
4
0
repeated

Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) - watchTowr Labs https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257

0
3
0
repeated

It has officially begun. The CRA info request counter is no longer at zero.

25
18
0
repeated

It makes me laugh/cry that we spent decades trying to get the software industry to internalise that it takes far more effort to support & maintain systems than it does to write them in the first place, and yet seemingly every trendy development in the last 5-10 years has been about making that initial stage faster & sloppier at the expense of everything else

5
11
0
repeated
repeated

No notes.

3
21
0
repeated

🎞️ A developer managed to reverse pixelation in video using FFmpeg, GIMP and edge detection - no AI involved.

By analyzing motion and edges across frames, they could reconstruct original content from blurred areas.

It’s a reminder: pixelation is visual, not secure.

🛠️ Code & demo: https://github.com/KoKuToru/de-pixelate_gaV-O6NPWrI

1
14
0
repeated

, aficionados, enjoyers, browsers: lend me your ears! i need help with a big push to get the word out about for GOOD INTERNET magazine's autumn issue! a digital AND physical magazine that ships all over the world, run & contributed to by volunteers! (‼️)

in case you're unaware, GOOD INTERNET covers a lot of different aspects of the : unplugging from the corporate web, fighting , migrating from data-harvesting corpo social media, creating your own personal website, using code and website-building as an art form, federation, and creating websites for fun. the aim is to be approachable for beginners and enjoyable for seasoned travelers!

you don't have to be a professional or a smartypants to write about all the good things happening on "this side" of the web. the idea here is to spread the word about and share thoughts, independent web projects, services, methods, sites, meet-ups, and celebrate the non-corporate web together while making it easier for us to partake and unplug from .

📏 looking for 1,000- to 4,000-word articles aimed at website owners and hobbyists, digital (and traditional) , culture enthusiasts, nerds, expatriates, & anyone who wants to unplug from the corporate-owned .

⏲️ the deadline is AUGUST 22, 2025 ⏲️

ℹ️ more info here: https://goodinternetmagazine.com/contact/

3
3
0
repeated

Jurisdiction Is Nearly Irrelevant to the Security of Encrypted Messaging Apps

Every time I lightly touch on this point, I always get someone who insists on arguing with me about it, so I thought it would be worth making a dedicated, singular-focused blog post about this topic without worrying too much about tertiary matters. Here's the TL;DR: If you actually built your cryptography properly, you shouldn't give a shit which country hosts the ciphertext for your…

http://soatok.blog/2025/07/09/jurisdiction-is-nearly-irrelevant-to-the-security-of-encrypted-messaging-apps/

12
4
0
repeated

Exploit Wednesday is underway. Unconfirmed PoC for CVE-2025-49677:

https://attackerkb.com/topics/ERsooKem2E/cve-2025-49677

1
3
0
repeated

If you have a machine with PKEY support and somewhat recent Linux kernel you can now play around with hardware support for the V8 sandbox. When active, JS + Wasm code has no write permissions outside the sandbox address space. To enable, simply set `v8_enable_sandbox_hardware_support = true` at build time.

It's not (yet) meant for production use, but should offer a preliminary look at where things might be heading. See https://crbug.com/350324877 for more details.

Feedback welcome! :)

0
3
0
repeated

More links to information about the IBM Power11, that was announced yesterday.
💙
https://www.rpgpgm.com/2025/07/more-details-about-power11.html

0
1
0
New by Security Explorations:

"eSIM Security - We broke security of Kigen eUICC card with GSMA consumer certificates installed into it."

https://security-explorations.com/esim-security.html
0
1
3
repeated

🔓⏫ After compromising every endpoint within an organization, our “Caught in the FortiNet” blog series comes to an end with one more thing.
Read more about FortiClient's XPC mistake that allows local privilege escalation to root on macOS:

https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-3-3?utm_medium=social&utm_source=mastodon&utm_campaign=research&utm_content=blog-caught-in-the-fortinet-080725-&utm_term=&s_category=Organic&s_source=Social%20Media&s_origin=social

0
7
0
[RSS] Privilege Escalation Using TPQMAssistant.exe on Lenovo

https://trustedsec.com/blog/cve-2025-1729-privilege-escalation-using-tpqmassistant-exe
0
0
1
repeated

The patches may be late, but 130 new CVEs from , there's still plenty to talk about. Join @TheDustinChilds as he covers the release and point out why it's a bad month to be a SQL Server admin. https://www.zerodayinitiative.com/blog/2025/7/8/the-july-2025-security-update-review

0
2
0
repeated

has (finally!) released their updates for July. 13 bulletins addressing 60 CVEs in various products. Nothing is listed as under active attack. The patch blog has bee updated with all the details. https://www.zerodayinitiative.com/blog/2025/7/8/the-july-2025-security-update-review

0
2
0
Show older