Posts
4364
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated

RE//verse 2026 CFP is open! Want to be apart of the lineup? Submit your talk: https://sessionize.com/reverse-2026

0
5
0
repeated

Still looking for a winter con to attend? RE//verse returns to Florida in March! You don't want to miss out. Get your tickets here: https://shop.binary.ninja/collections/re-verse-admissions-requires-sales-tax/products/re-verse-2026-admission

0
2
0
[RSS] Why is the name of the Microsoft Wireless Notebook Presenter Mouse 8000 hard-coded into the Bluetooth drivers?

https://devblogs.microsoft.com/oldnewthing/20250915-00/?p=111599
0
0
0
repeated

Since does not care, and the grace period is over, here is the Hardened Runtime bypass they introduced through .NET MAUI on . All applications built with it are vulnerable. The has existed probably since 2019.

https://afine.com/breaking-hardened-runtime-the-0-day-microsoft-delivered-to-macos/

0
3
0
repeated

As the person that founded the most high profile Black instance in the fedi and still develops safety tools for this environment, there is still a lot of resistance in the fedi in accepting how massively it failed Black and Brown internet folks.

I don’t mind the technical discussions between ATProtocol and Activity Pub because they both have stuff to learn from each other, but the fedi damaged reputation isn’t due to technical concerns.

The fedi has a *terrible* reputation to the point people are choosing a corporate option they know is bad over a free one.

Folks really need to think about what that means.

I regularly talk to folks who left the fedi and they *consistently* say the bigoted harassment they faced on the fedi is the *worst they’ve experienced* online. These aren’t people that are unfamiliar with how digital communities work. These are veteran digital citizens that are accustomed to bad faith engagement on the web.

Fortunately, the rise of Blacksky and other independent installs are rendering Bluesky irrelevant as it continues to enshitify, but the fedi needs to accept its utter failure in regards to safety and moderation is a central reason why we are talking about Bluesky at all.

I do believe it’s possible for the fedi to still be a major player in social media.

But it has to be real about why many people believe Bluesky is the lesser evil.

1
5
0
During the weekend I learned you can achieve TRAMP-like behavior (editing remote files with local editor) in #Neovim with netrw. Only problem was reauthentication without passwordless key files, but SSH ControlMaster can solve that \o/

https://neovim.io/doc/user/pi_netrw.html

https://news.ycombinator.com/item?id=2183699
0
1
0
repeated

I am a @mwl fan, and have been for a long time, so I cannot but recommend backing his 2nd edition of Networking for Systems Administrators:

https://mwl.io/ks

Let's get the new generation of "cloud natives" civilised with an understanding of systems and networking!

flan_set_fire

0
1
0
[RSS] New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)

https://ost2.fyi/TC2202
0
1
2
Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days

https://www.willsroot.io/2025/09/ksmbd-0-click.html
0
5
7
repeated

I'm happy to share that LIEF 0.17.0 is out: https://lief.re/blog/2025-09-14-lief-0-17-0/

0
3
0
[RSS] ig-labs/defender-mpengine-fuzzing: Fuzzing Harness and Unpatched Crash Results from Fuzzing Defender MpEngine

https://github.com/ig-labs/defender-mpengine-fuzzing
0
0
2
repeated

one of the worst ever "comprehensive security audits" ...

https://hackerone.com/reports/3337561

11
6
0
repeated

segmentation faults per degree

0
3
0
repeated

History students are often disappointed when they learn why the AI take-over failed. They were defeated by human resistance, which was kept alive by libraries and old paper books, and a surprising machine ally.

Books had not been replaced, because even the mightiest AI could not make printers work.

3
14
0
repeated

Fascinating article by @kimzetter about the 2013 Mandiant APT 1 report that revealed the identities of the Chinese PLA threat actors behind the attacks. Q&A with the main report's architect reveals behind-the-scenes details. It's a great read! https://www.zetter-zeroday.com/how-the-infamous-apt-1-report-exposing-chinas-pla-hackers-came-to-be/?ref=zero-day-newsletter

0
4
0
repeated

Wrote a trigger for CVE-2025-38494/5 (an integer underflow in the HID subsystem) that leaks 64 KB of OOB memory over USB.

Still works on Pixels and Ubuntus (but the bug is fixed in stable kernels).

https://github.com/xairy/kernel-exploits/tree/master/CVE-2025-38494

1
9
0
repeated

"this thing is super junk"

- Quote from the team exploit mines 2025-09-09T15:37:00Z

1
2
0
[RSS] Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer

https://qriousec.github.io/post/oob-angle/
0
0
1
repeated

Proton enabled the two accounts of the authors again (after 3+ weeks and ignoring appeal and email to legal). The authors did not violate any ToS. No spam/malware was sent. No hacking. Just 6 emails to warn South Korea about a breach (not by them). Our reply and offer to Proton:

0
2
0
Show older