šØ noyb has filed complaints against #TikTok and #Grindr. As it turns out, TikTok even tracks you while you're using other apps. For example, TikTok was able to track a personās Grindr usage - which allows it to draw conclusions about his sexual orientation and sex life
š https://noyb.eu/en/tiktok-unlawfully-tracks-your-shopping-habits-and-your-use-dating-apps
Mitre has just published their top 25 most dangerous software vulnerabilities of 2025
How does #CHERIoT stack up against this list?
5, 7, 8, 11, 14, and 16 are deterministically mitigated with just a recompile.
13 will trap, but is recoverable on a per-compartment basis.
15 is trivial to mitigate with compartmentalisation. Phil Day wrote about this 18 months ago.
6 is mitigated by good capability-based filesystem APIs.
25 is mitigated by our software capability model in the RTOS.
1, 2, 3, 9, 10, 12, 22, and 23 and are not normally applicable on embedded platforms.
That leaves you with a lot more spare brainpower to think about avoiding the remaining seven (4, 17, 18, 19, 20, 21, and 24). The impact of many of these is limited in an environment where there is a programmer model that makes implementing the principles of least privilege and intentional use trivial.
With H2HC on hiatus this year, the security community stepped up to create the 307 Temporary Security Conferenceāand we were proud to be part of it!
We presented our research on vulnerabilities in the CAN BCM protocol in the Linux kernel.
Thank you to everyone who watched!
The slides and exploit demos are now available.
Slides
https://allelesecurity.com/wp-content/uploads/2025/12/Presentation_307.pdf
Demo 1: Exploit for UAF read (CAN BCM) to dump shadow file & MySQL root hash.
https://www.youtube.com/watch?v=znTLHc2mXIs
Demo 2: Exploit for UAF read in CAN BCM (CVE-2023-52922) that leaks encoded freelist pointer and slab object addresses
https://www.youtube.com/watch?v=XQ3QlXqn6pI
Memory bugs, such as use-after-free and buffer overflows, are the most exploited vulnerability class; however, AddressSanitizer's 2-4x performance overhead makes it unusable in production.
So, we recommend GWP-ASan, which uses sampling and guard pages to detect memory safety bugs at scale. Learn the technique and how to implement it in your C++ projects using LLVM's scudo allocator:
https://blog.trailofbits.com/2025/12/16/use-gwp-asan-to-detect-exploits-in-production-environments/
I want things that are above my reading level, that's how I get better at reading š¤š
@reading @bookstodon @books @humor@fedigroups.social @humor@lemmy.world @aiop
#ReadingMemes #Memes
#ReadAllTheBooks #Humor #Humour
#Reading #Readers #ReadersOfMastodon #ReadingCommunity
#Book #Books #Novel #Novels #Fiction
#Bookwyrm #Bookworm #Bookstodon #BookLove #FantasyBooks #ReadingLevel #Level
My second blog post regaling tales from my weekend of bugs:
The Cryptax Award H2 2025 is out! (lol)
Best talks, papers, CTF challenges, tools I encountered in the second half of 2025:
https://cryptax.github.io/nomination-2025-h2/
It's a difficult selection, as always, and it is very personal opinion!
Congratulations to those who are listed, and kudos to others :)
THC Release š„: The worldās largest IP<>Domain database: https://ip.thc.org
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.
Updated monthly.
Try: curl https://ip.thc.org/1.1.1.1
Raw data: https://ip.thc.org/docs/bulk-data-access
(The fine work of messede š)
What does everyone think? Need feedback before release tomorrow :)
If you need to get your mood down a few notches, there are some new slop entries to torment yourself with here:
https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d1cd
Training Ticket Shop for #offensivecon26 is now open.
The content of our 2026 trainings is unique and exclusive to OffensiveCon, so donāt miss out.
š„ New this year: Get your training + conference ticket bundle - you have the opportunity to secure a conference ticket before the conference ticket shop opens!
You can also get a training ticket only...
Training tickets: https://www.offensivecon.org/register.html
And the conference ticket shop? Oh, itāll open⦠sometime in the next 5 months. Stay tuned.š