Posts
4364
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated

joernchen :cute_dumpster_fire:

Today I have a more serious topic than usual, please consider reposting for reach:

My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical contact points have failed us unfortunately and he seems stuck in this condition.

We’re based in Berlin, Germany but really any contact with a specialist who would be willing to take on this case we’d be grateful for!

To reach use you can DM me or contact us via Email at unclear.condition@gmail.com

1
19
0
repeated

One of the most effective security controls you can ever invest in, is a decent work computer for your employees.

Yep, it’s a bit more cash up front to get a bit more RAM or a bit more CPU poke, but your job in IT/Security is to get people the gear they need to do their jobs without thinking ‘this would be quicker if I used….’

Because we all know what happens when your VP of Finance decides to prep the W2’s on their kids Alienware gaming desktop full of Minecraft plugins downloaded from every corner of the internet.

2
6
0
repeated

At long last - Phrack 72 has been released online for your reading pleasure!

Check it out: https://phrack.org/

1
19
0
repeated

-=[ PHRACK PROPHILE ON Gera ]=-

https://phrack.org/issues/72/2#article

That’s the whole post…

0
5
1
repeated

Phrack turns 40.
The digital drop is live.
Download it. Archive it. Pass it on.
💾 https://www.phrack.org

1
16
0
Can You Write A Web Server in PURE BASH?! (no socat, no netcat, no external tools) 🍿

https://www.youtube.com/watch?v=L967hYylZuc
1
2
5
repeated

📣 Introducing the IDA Domain API: a new open-source Python API that makes scripting in IDA simpler and more consistent.
https://hex-rays.com/blog/introducing-the-ida-domain-api

0
4
0
repeated

T-Mobile claimed selling location data without consent is legal—judges disagree
T-Mobile can't overturn $92 million fine; AT&T and Verizon verdicts still to come.
https://arstechnica.com/tech-policy/2025/08/t-mobile-claimed-selling-location-data-without-consent-is-legal-judges-disagree/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

3
5
0
repeated

I reverse engineered Lockbit's Linux ESXi variant, also explaining how I did some of the steps! For the fun of it, cause reverse engineering is lots of fun. Enjoy! https://hackandcheese.com/posts/blog1_lockbit/

0
4
0
repeated
repeated
repeated

Project Zero Bot

New Project Zero issue:

Linux >=6.4: epoll: UAF via race between ep_eventpoll_release() and eventpoll_release_file() because mutex_unlock() is not ownership-drop-safe

https://project-zero.issues.chromium.org/issues/430541637

CVE-2025-38349
0
1
0
Edited 11 months ago
ECC.fail: Mounting Rowhammer Attacks on DDR4 Servers with ECC Memory

https://ecc.fail/

Teachning stones to remember things was a mistake.
0
0
2
Elastic Response to Blog ‘EDR 0-Day Vulnerability’

https://discuss.elastic.co/t/elastic-response-to-blog-edr-0-day-vulnerability/381093

"The reports lacked evidence of reproducible exploits. Elastic Security Engineering and our bug bounty triage team completed a thorough analysis trying to reproduce these reports and were unable to do so."
1
2
3
repeated

The FBI has published an evergreen advisory warning about cryptocurrency recovery scammers lurking everywhere. The minute you mention online that you might have lost money to a crypto scam, you will be flooded with come-ons from "recovery experts" who hold out the unlikely promise of recovering your funds -- for a fee.

These scammers prey on people who are understandably frantic after having just suffered a potentially life-altering financial loss, and are desperate for a quick solution. Far too many people who get burned by crypto get victimized a second time by these charlatans. I probably delete a dozen or more comments each week from my blog that are left by these dirtballs.

https://www.ic3.gov/PSA/2025/PSA250813

2
10
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

In the context of the Chatcontrol attempt to get Americans to scan our photos with AI so we can be reported to Europol, the EU has even bigger plans in this direction. And they are honestly (I am told) asking for experts to advise them on these plans. You can apply until September 1st to be part of the expert group:
https://berthub.eu/articles/posts/possible-end-to-end-to-end-come-help/

4
10
0
repeated

A fascinating story about a in the Expat parser

kills: The story behind CVE-2024-8176 / 2.7.0 released, includes security fixes

https://blog.hartwork.org/posts/expat-2-7-0-released/

1
3
0
repeated

Meanwhile, if you abuse the API and don't comply, asan might complain but that's not a security problem.

https://hackerone.com/reports/3302518

2
1
0
repeated

Any fool can write code that a computer can understand. Good programmers write code that humans can understand.

— Martin Fowler

2
5
0
Show older