Posts
2469
Following
660
Followers
1483
"I'm interested in all kinds of astronomy."
#Linux eBPF vulnerabilities incoming (unprivileged eBPF required) + disclosure troubles:

https://www.openwall.com/lists/oss-security/2025/08/03/1
0
3
1
repeated

a 2661 byte program I wrote just won the "Sur Prize" at the International Obfuscated C Code Competition. You can probably guess what it is once I mention that @foone might enjoy it

https://www.youtube.com/watch?v=d2ulsnSTbUQ

4
6
1
[RSS] Exploring possible solutions to the inconsistency in how Windows searches case-insensitively for named resources

https://devblogs.microsoft.com/oldnewthing/20250723-00/?p=111403

Some fun anti-reverse possibilities here :)
0
0
2
repeated
repeated

From a CBS news segment from July of 1985 discussing the busting of various and BBS operators in New Jersey.

Ouch, but also 💀

Will be uploading the entire segment to Internet Archive later today.

2
7
0
repeated

Another day, another conversation with the press team where I explain that I did not give the quote in that story and the whole thing is AI slop. This happens once every few weeks now.

2
14
0
Edited 1 month ago
Why does [ #WinDbg ] show me the wrong function?

https://devblogs.microsoft.com/oldnewthing/20050322-00/?p=36113

TIL about COMDAT folding #compiler optimization!
0
1
1
[RSS] Exploit development for vulnerabilities in Windows over MS-RPC

https://incendium.rocks/posts/Exploit-Development-For-MSRPC/
0
3
5
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Eclipse ThreadX FileX RAM disk driver buffer overflow vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2088
0
2
1
[RSS] Characterizing the Raspberry Pico 2 FI countermeasures - Part 1

https://www.ioactive.com/characterizing-the-raspberry-pico-2-fi-countermeasures-part-1/
0
2
3
repeated

In 1983, Philips produced the first FM radio receiver on a chip, leading to products such as the FM radio wristwatch. Let's look at the tiny silicon die inside this chip and see how it works. 1/N

4
13
0
repeated

New episode is up!
We talked with Nathan Emerick about the Spotify CarThing and it's journey to becoming the DeskThing :D
https://unnamedre.com/episode/75

0
2
0
repeated

Wow, after 25 years of / experience, I learned that you can filter output in .

Press ampersand (&) and enter a regex to show only lines matching the regex.

Press ampersand (&) and then exclamation mark (!) to apply an inverse filter.

6
25
1
repeated

Graham Sutherland / Polynomial

blue cheese (the blue is Cherenkov radiation)

3
2
1
repeated

This is super interesting and isn’t a type of research I’ve seen a lot of before. Great write-up from @albinolobster and team on attacker infrastructure longevity: https://www.vulncheck.com/blog/stillup-stillevil

0
5
0
repeated

"If you only praise last-minute saves, you’ll keep getting last-minute problems. Make sure to recognize the engineer who reduced incidents, the PM who saw the risk a month out, the designer who caught the complexity before it shipped. Make that kind of foresight just as visible and valuable as triage and repair."

— @timcheadle from https://www.timcheadle.com/dont-let-crisis-become-a-compass/

0
6
0
repeated

Related: If you want to tell me you've jailbroken the AI, you better be prepared to tell me how you reverse engineered the ETL, data model and guard rails, not how you clicked on the shiny, shiny and got a shell prompt.

0
2
0
repeated

We released our Fuzzilli-based V8 Sandbox fuzzer: https://github.com/googleprojectzero/fuzzilli/commit/675eccd6b6d0c35ea6c7df24a0a1e513cce45bb3
It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!

0
4
0
Show older