Posts
4125
Following
733
Followers
1624
"I'm interested in all kinds of astronomy."
[RSS] "Astral-tokio-tar" / "uv" Arbitrary Write Path Traversal Vulnerability

https://github.com/google/security-research/security/advisories/GHSA-9p78-p5g6-gcj8

This is CVE-2025-59825
0
1
0
[RSS] dz6: vim-like hex editor

https://crates.io/crates/dz6
1
2
1
Since yesterdays #AdTech link was received quite positively, I'm sharing again this collection from The Correspondent:

Debunking the science of advertising
https://thecorrespondent.com/collection/the-nonsense-of-online-advertising

The Correspondent was an incredible publication, and as such, turned out to be unsustainable :(
0
1
1
repeated

I have a friend who prefers to stay anonymous who gives this amazing talk in non US (but allied) countries about how long their internet will -really- function if they lose all comms with American data centers and it’s… phew. It’s a thing. Some resilient ones will last a few weeks before certificates expire. But CF is a wrench.

10
14
0
repeated

I want to try switching to Linux.

However, I cannot find a working remote desktop system that allows me to take over the same session that I was using locally so that I can switch back and forth between being at the computer and being remote without having to log out. Blanking/Locking the local screen while I'm connected remotely is also a need.

Basically I need it to work as close to Microsoft's RDP as possible. If anyone can help me with this, you'll convert me to a Linux user.

13
6
0
repeated

Here’s a free scanner for that FortiWeb CVE-2025-64446 I made for you. https://github.com/sensepost/CVE-2025-64446

0
5
0
repeated

Chatting with a friend about Cloudflare's intermittent outages today, they brought up an interesting point: How many organizations have started relying on Cloudflare to do basic security blocking and tackling stuff, like stopping SQL injection attacks at the edge? Maybe your devs were lazy at blocking this stuff in the past b/c CF was the control layer to compensate for that.

You might say well okay but if CF is down, so are the sites relying on them, and that's true. But a lot of organizations will switch CF off during these times to keep their sites and services reachable and running. And my friend's point was that for those organizations, they might want to take a closer look at the traffic they received during this eight-hour outage window or whatever, and I think that's sound advice.

12
10
0
repeated

Wizard Zines is doing another Big Zine Sale again this year on Friday, November 28th! One day only.

here’s a google calendar link for the duration of the sale if you want a reminder: https://wzrd.page/cal (or an ICS link: https://wzrd.page/cal.ics)

0
6
0
repeated

Just dropped: my RECON 2025 talk on Rust library recognition in malware! 🦀

I present RIFT—a tool that tackles one of the trickier problems in modern malware analysis, rust library recognition in malicious software.

https://youtu.be/_JiuYkFzVgg?si=7GAVhfyNOzLjPZnS

Worth a watch if you're into RE or malware research.

0
4
0
repeated

Jordan Maris 🇪🇺 🇺🇦 #NAFO

RE: https://nileane.fr/@nileane/115570855799458529

First it was IoT devices, and now browsers don't work when Cloudflare has an outage. We truly are living in the dumbest timeline.

2
2
0
repeated
Edited 7 months ago

Big day for hardware folks in Europe 🧡

We’re launching Beautiful Boards+, our biggest PCB update yet:
2–8 layers • 5 PCB colours • black/white silkscreen • 35/70 µm copper – all 100% made in Europe.

Our checkout automagically picks Beautiful Boards or Beautiful Boards+ based on your choices.

Try Beautiful Boards+ with your next project: https://aisler.net/en

Thanks for building with us and for helping us make hardware less hard. 🧡

0
4
1
Cloudflare down is another teachable moment to think about your eggs and your baskets.
1
3
11
repeated
Edited 7 months ago

Cloudflare just jumped off a bridge, down globally.

7
6
1
repeated

We're in Tokyo presenting our iOS emulator at the CODE BLUE Conference.

📲 You can still join our early adopter program: https://u.eshard.com/ios-emulation

0
4
1
reasoning_effort = 'none'
0
2
0
repeated

New, by me: Protei, a Russian-founded telecoms provider and supplier of surveillance and web monitoring technologies, was breached, its website defaced, and its servers raided.

"Another DPI/SORM provider bites the dust," read the company's defaced website.

https://techcrunch.com/2025/11/17/surveillance-tech-provider-protei-was-hacked-its-data-stolen-and-its-website-defaced/

1
7
0
Friendly advice for crisis communication:

"Our systems have been under attack for T days" doesn't mean that your system withstood the attack for that long. Hackers don't work with sledgehammers.

It means that you saw the attack but were unable to act on it for T days.

#incidentresponse
0
2
6
repeated

⌨️ Introducing HCLI: The Modern Command-Line Interface for IDA.

Automate workflows, simplify plugin development across platforms, manage licenses and more.

https://hex-rays.com/blog/introducing-hcli

0
4
0
repeated
New assessment for topic: CVE-2025-25257

Topic description: "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. ..."

"In one of our honeypots we observed the following payload being executed: ..."

Link: https://attackerkb.com/assessments/ccb5097e-52f5-411c-b4f6-951b36b166d7
0
1
1
This is a fun one: LLM inference creates a timing side channel that allows identifying sensitive topics by passively intercepting encrypted traffic:

https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/

/via @jonny
0
3
5
Show older