Posts
2469
Following
660
Followers
1482
"I'm interested in all kinds of astronomy."
repeated

FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970) https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970

0
2
0
repeated

has anyone ever made a man page viewer which shows you a table of contents for the man page so you can easily navigate through the sections?

(please do not tell me about `info`)

6
3
1
repeated
repeated

We've managed to make it through hacker summer camp, and and survived enough to deliver their latest security patches. Join @TheDustinChilds as he breaks down another large Patch Tuesday release. https://www.zerodayinitiative.com/blog/2025/8/12/the-august-2025-security-update-review

0
2
0
repeated

Lorenzo Franceschi-Bicchierai

NEW: Two hackers broke into the computer of a hacker allegedly working for the North Korean spy group known as "Kimsuky."

The hackers then leaked a treasure trove of stolen data, exposing a North Korean spy operation against South Korean targets.

“Kimsuky, you’re not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda. You steal from others and favour your own. You value yourself above the others: You are morally perverted,” the two wrote in their Phrack magazine article. “You hack for all the wrong reasons.”

https://techcrunch.com/2025/08/12/hackers-breach-and-expose-a-major-north-korean-spying-operation/

0
5
0
Oh shit it's Patch Tuesday...
0
0
7
repeated

Just under three weeks until CFP opens for RE//verse 2026! Submissions open September 1st: https://sessionize.com/reverse-2026

And while you’re at it, snag your ticket early before prices go up: https://shop.binary.ninja/collections/re-verse-admissions-requires-sales-tax/products/re-verse-2026-admission

0
2
0
/me @ the How Did This Ever Work?! phase, with the added excitement that the same code in a different script still works

(now that file is a sacred artifact that must be protected by all costs)
0
3
3
repeated

Absolutely jaw-dropping talk by Micah Lee on the blinding national-security incompetence at the highest levels of the Trump regime.

https://micahflee.com/we-are-currently-clean-on-opsec-the-signalgate-saga/

If this had been any Democratic govt, Fox "News" and the entire right-wing media gang would make it the top story for weeks, if not months.

2
7
0
repeated

Micropatches Released for Windows Disk Cleanup Tool Elevation of Privilege Vulnerability (CVE-2025-21420)
https://blog.0patch.com/2025/07/micropatches-for-windows-disk-cleanup.html

1
3
0
repeated

Micropatches Released for Windows Update Service Elevation of Privilege Vulnerability (CVE-2025-48799) https://blog.0patch.com/2025/08/micropatches-released-for-windows.html

1
3
0
repeated
New assessment for topic: CVE-2025-4678

Topic description: "Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection ..."

"This is a similar RCE like [CVE-2024-12971](https://attackerkb.com/topics/BJe14wkMYS/cve-2024-12971) but now in the `chromium_path`directory settings at the Pandora ITSM application ..."

Link: https://attackerkb.com/assessments/cbac9f7f-798e-424f-a010-48ceada60ff7
0
1
1
repeated

Then: UK govt loses mind
Now: Wikipedia loses legal challenge
Next: UK loses Wikipedia access?

This legislation is way, way beyond porn and stated scope. There is no good reason to age gate an encyclopaedia *at national level* under the guise of protecting children.

https://wikimediafoundation.org/news/2025/08/11/wikimedia-foundation-challenges-uk-online-safety-act-regulations/

0
3
0
repeated

"It's the certificates, stupid!"

A quick analysis into the Phrack #72 APT Down code signing certificates. Has South Korea been backdoor pounded for the last two decades?

https://reverse.put.as/2025/08/11/itsthecertificatesstupid/

0
3
0
[FD] Kigen eUICC issue (custom backdoor vs. FW update bug)

https://seclists.org/fulldisclosure/2025/Aug/4

"we suggest Kigen customers to request information pertaining to all secret / shared keys embedded in Kigen eUICC FW and ECASD domain"
0
0
1
repeated

It's totally reasonable to be more cautious these days, but don't let that drive you to have opsec panic attacks that aren't founded in common sense. For example... it makes no sense to be worried someone might figure out you're queer or a leftist if you're too open about your politics while posting... on fediverse, the queer leftist social media platform. They already know, chief.

4
3
0
[RSS] Compiler Bug Causes Compiler Bug: How a 12-Year-Old G++ Bug Took Down Solidity

https://osec.io/blog/2025-08-11-compiler-bug-causes-compiler-bug
4
16
19
repeated
Show older