longing for the day when computers are advanced enough to handle 65k bytes of plaintext
NEW: Earlier this month, two hackers published their findings in Phrack magazine after hacking into the computer of a North Korean government hacker. Now, in speaking with @lorenzofb, the hackers explain why they went public — even though their breach was probably illegal.
lol the xz backdoor lives on in docker images https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images
🐘
⚠️#Docker: If you are using Docker for Desktop you need to update it TODAY to v4.44.3. Critical CVE-2025-9074 #vulnerability in previous versions allows malicious containers to access host system:
👇
https://www.heise.de/en/news/Docker-Desktop-Critical-vulnerability-allows-host-access-10560707.html
Anyone happens to know if there's any easy trick to bypass an Incapsula "security firewall" that thinks downloading with curl/wget is an attack to be prevented? (It's not just the user agent, I tried that.)
rsync: 6 CVEs https://www.openwall.com/lists/oss-security/2025/01/14/3
Two independent groups of researchers identified a total of 6 CVEs in rsync. In the most severe CVE (affects rsync 3.2.7+), an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code.
Time to upgrade #ApacheTika to 3.2.2.
XXE in XFA parsing up through version 3.2.1
https://lists.apache.org/thread/8xn3rqy6kz5b3l1t83kcofkw0w4mmj1w
Git 2.51: Preparing for the future with SHA-256 https://www.helpnetsecurity.com/2025/08/19/git-2-51-sha-256/
Ever seen two responses to one request? That's just pipelining... or is it? I've just published "Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling" https://portswigger.net/research/how-to-distinguish-http-pipelining-from-request-smuggling
UK drops demand for backdoor into Apple encryption https://www.theverge.com/news/761240/uk-apple-us-encryption-back-door-demands-dropped
"Ukraine gives award to foreign vigilantes for hacks on Russia" https://www.bbc.com/news/technology-68722542
ehhh...