Posts
4364
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated
Edited 8 months ago

EBury SSHD backdoor?? on 400,000 hosts?

Let's fuck around and find out. (Why +s on the .so file???)

Dissect, understand & ridicule. Join the group effort at https://thc.org/ops or SSH straight into the server and check ~/ebury:

ssh -o "SetEnv SECRET=lYQkdQHIuQyTJngVtIskqRLx" root@adm.segfault.net (password is 'segfault')

3
6
0
repeated

Calling for the help of the fediverse!
Help spread the word of our browser extension Consent-O-Matic that helps automate answering those ever-present cookie consent pop-ups.

It's developed by researchers at Aarhus University in Denmark and free to use for Chrome/Edge, Firefox and Safari including for iOS.

Also, it's open source, so if you have a bit of technical skill, you can help us improve the rule set for greater coverage.

https://consentomatic.au.dk

19
36
1
repeated

🚀 radare2-6.0.6 is out! (codename 'siesso’)

That's the first release after which comes with tons of awemazing bug fixes and all the new features presented during the conference!

🔗 https://github.com/radareorg/radare2/releases/tag/6.0.6

See details below 👇

0
3
0
repeated
repeated

BINGO TIME! With CVE-2025-58034, Fortinet secures the crown in my Insecurity Appliance Bingo. This is technically a "high" severity vuln, but since it's being actively exploited and has landed a spot on CISA KEV, I'm admitting it.

https://cku.gt/appbingo25

Reaching a bingo took longer than expected, with FortiNet and Ivanti sitting at 5/6 vulns since about July. But now, there is a well-deserved winner.

I'm now taking new vuln class and vendor suggestions for next year's edition.

3
10
0
Thanks @pancake for the swag!
2
0
4
repeated

Happy Max Headroom Incursion Day to all who celebrate!

11/22/87 never forget

0
3
0
#metal #music
Show content
"We're gonna have the most British Wall of Death - don't worry, it's not a Brexit thing" - These guys are hilariously good xD

Raised By Owls Full Set at Bloodstock 2024

https://www.youtube.com/watch?v=3Shf2h8_yL8
0
0
0
repeated

OTD 1999: announces the Sun Ray thin client. Great blog about its development: https://marcschneider.weebly.com/sun-ray.html

3
8
0
repeated
repeated

This will probably get spread around as misinformation, because people read the titles, not the articles. So let's start with the obvious:

is secure.

Now what everyone didn't read:

> The FBI said the information came from a “sensitive source with excellent access” and introduced the report as a warning about “extremist actors targeting law enforcement officers and federal facilities”.

In other words, the FBI had an informant on the inside. AKA, "a spy".

https://www.theguardian.com/us-news/2025/nov/21/fbi-signal-group-chat-immigration

1
3
1
repeated

not enough people are talking about this gif from the wikipedia article on the falling cat problem

2
6
0
Please help making #TreeSitter Playground better by doing this little experiment:

https://tree-sitter.github.io/tree-sitter/7-playground.html

Write some JS, like `var x=1;`. Enable Query and provide the `(identifier) @foo` pattern in the new Query textbox.

Do you see the code highlighted? (if not, turn on Accessibility, a'la GH issue #1714)
50% Yes, I see the highlight.
50% No, I don't see the highlight
1
0
0
[RSS] exploits.club Weekly(ish) Newsletter 92 - S23 N-Day PoCs, Printer Overflows, DNG OOB Writes, And More

https://blog.exploits.club/exploits-club-weekly-ish-newsletter-92-s23-n-day-pocs-printer-overflows-dng-oob-writes-and-more/
0
0
0
repeated

TrendAI Zero Day Initiative

We have updated the Automotive rules to expand the target scope of the category and to clarify the model of the ChargePointHome Flex model number. Check out the rules at https://www.zerodayinitiative.com/Pwn2OwnAuto2026Rules.html

0
1
0
repeated

CrowdStrike says it caught an insider sharing screenshots taken on internal systems with unnamed threat actors.

https://www.bleepingcomputer.com/news/security/crowdstrike-catches-insider-feeding-information-to-hackers/

0
3
0
[RSS] NSO Group argues WhatsApp injunction threatens existence, future U.S. government work

https://cyberscoop.com/nso-group-whatsapp-injunction-appeal/
0
0
0
Edited 8 months ago
User-friendly GUI: please provide command line parameters in this text box!

Me, knowing that one of the characters will need escaping:
1
2
12
Show older