Posts
3905
Following
728
Followers
1600
"I'm interested in all kinds of astronomy."
repeated

Eight years later, I’ve updated my most-starred @github repository with some new @fridadotre scripts, inspired by @spaceraccoonsec's new book “From Day Zero to Zero Day”.

Check it out: https://github.com/0xdea/frida-scripts/

0
3
0
repeated
Edited 8 months ago
1
1
1
I combined DEVCORE's CVE-2024-35250 with the CVE-2024-30084 double fetch bug and the Cloud Filter memory trap technique by @tiraniddo to achieve reliable LPE without device requirements on Win10 VMs.

https://scrapco.de/blog/its-a-trap-reliable-exploitation-of-cve-2024-30084.html
1
9
9
repeated

Alice Averlong🏳️‍⚧️

mutual aid request
Show content

I've been bedridden for nine months, and I'm only now getting a surgeon lined up to fix this.
If you could send a couple dollars, it'd really help. Time isn't on my side here, and waiting is very expensive.

https://ko-fi.com/fooneturing

0
7
0
repeated
Edited 8 months ago

checking whether the C compiler works... no

Understandable, have a nice weekend

3
8
2
repeated

The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting. So I wrote a blog post about it

An absolutely ridiculous amount of open source is one person projects. I have the data to prove it

https://opensourcesecurity.io/2025/08-oss-one-person/

7
15
0
repeated

Cisco Talos just disclosed vulnerabilities in Libbiosig, Tenda routers, SAIL image library, PDF-XChange, and Foxit Reader — all now patched by vendors: https://blog.talosintelligence.com/libbiosig-tenda-sail-pdf-xchange-foxit-vulnerabilities/

0
1
0
repeated

This page intentionally left blank

0
2
1
Look at the rate of weasel wording in OpenAI's not-really-apology:

https://openai.com/index/helping-people-when-they-need-it-most/

I'm sick and tired of people pretending they have ways to enforce LLM behavior, while all they do is weigh dices differently - they remain dices.

Trying to enforce security boundaries with a PRNG is one thing, but you definitely can't prevent reinforcing harmful behavior, because you can't even define what it is.

And this can cost lives, as we just witnessed.
2
0
2
repeated
Edited 8 months ago

The CEO of Open AI should be tried for accessory to murder -- OpenAI responds to ChatGPT helping a teen commit suicide

What a load of goddamned CRAP:

https://openai.com/index/helping-people-when-they-need-it-most/

1
3
0
repeated

🇪🇺 Brussels speaks clearly. @EU_Commission confirmed to us: The is non-negotiable, not even as part of trade talks with Donald Trump.

💪 We welcome the EC’s reaffirmation of its commitment to neutral, robust, and evidence-based enforcement of the . But we call on the Commissioners to strengthen enforcement and make sure gatekeepers cannot get away with circumventing the law.

👉 Read the Commission’s reply: https://edri.org/wp-content/uploads/2025/08/European-Commission-response-on-US-influence-in-DMA-enforcement.pdf

1
7
1
repeated

"Will WebClient Start"

This awesome blog post by Steven Flores, with SpectorOps, tries to answer a question I had too: "Is it possible to start the WebClient service remotely as a low-priv user?"

Very interesting read. The article walks you through the entire thought process and tackles various Windows internals. And even if the result may seem underwhelming, it lays the ground for others to try and take on this challenge. 😉

👉 https://specterops.io/blog/2025/08/19/will-webclient-start/

0
3
0
repeated

SMAP is coming to Windows

1
2
0
[RSS] The One Where We Just Steal The Vulnerabilities (CrushFTP CVE-2025-54309) - watchTowr Labs

https://labs.watchtowr.com/the-one-where-we-just-steal-the-vulnerabilities-crushftp-cve-2025-54309
0
0
1
#suicide #llm
Show content
In a somewhat better world this ChatGPT suicide case should at minimum trigger resignations from OpenAI top brass. This won't happen of course, showing what kind of people we are dealing with there.

And yes, this case is different from finding similar information via search engines, because search engines don't pretend to be people who care about you.
0
0
1
Magical Breakpoints and Where to Find Them
0
0
1
repeated

Total respect for Alyssa Anne Rosenzweig, @lina@vt.social and all the other developers from Asahi Linux for reverse engineering Apples M1 GPU architecture to the point where they surpassed Apple by providing Vulkan support.
That is so unbelievable outstanding!
No one else of all those other senior developers in the whole wide world didn't even bother to try. Meanwhile someone born 2001 (like Alyssa) did – I think the others are mostly in the same age range.
I can only repeat, this is outstanding!
Congratulations and thank you all for your incredible work!!

https://rosenzweig.io/blog/asahi-gpu-part-n.html

0
3
0
Show older