Posts
3349
Following
711
Followers
1577
"I'm interested in all kinds of astronomy."
getting things merged into Ghidra

RE: https://chaos.social/@weirdunits/115937461017927780
0
0
1
repeated

TrendAI Zero Day Initiative

Whew! They had to swap out the master control board during the attempt, but Hank Chen of InnoEdge Labs successfully demoed their exploit of the Alpitronic HYC50 in Lab Mode. Using screwdrivers during a attempt is always crazy to see. He's off to disclose what occurred.

0
2
0
repeated
repeated

Remember "don't print this email" in signatures that was a bit cringe? It doesn't feel that cringe anymore in retrospect. I'm doing an experiment now with this new email signature :D Anyone doing something similar? Could it catch on?

13
36
3
repeated

Today's threads (a thread)

Inside: Google's AI pricing plan; and more!

Archived at: https://pluralistic.net/2026/01/21/cod-marxism/

1/

3
3
0
repeated

After auditing the @mullvadnet client applications in 2024, we have recently audited Mullvad VPN's API.
The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.
Five issues were identified, of which only one had a very limited impact on users of the service.

The technical details may be found in our report. https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/

1
6
0
repeated

Last December I solved Synacktiv's 2025 Winter Challenge: Quinindrome https://www.synacktiv.com/en/publications/2025-winter-challenge-quinindrome . Here is a 81-byte Linux program which is both a quine (it prints itself when executed) and a palindrome (it is symmetrical)! To learn how I achieved it: https://github.com/fishilico/synacktiv-winter-chall-2025-quinindrome/blob/main/writeup.md

0
6
0
[RSS] Windows Internals: Check Your Privilege - The Curious Case of ETW's SecurityTrace Flag

https://connormcgarr.github.io/securitytrace-etw-ppl/
0
1
0
I feel I have this instinct to feed programs data that they won't be able to handle.

Unfortunately this is mostly true for tools I'd like to use, not targets I review.
0
3
7
Edited 20 days ago
Humble request for vibe-coders: report your runtime errors!

LLM tends to insert Pokémon exception handlers everywhere, making problems (of which vide-code has a *lot*) hard to even notice.

Slightly related illustration:
3
74
104
I positively surprised that AWS apparently built a separate IAM for their European Sovereign Cloud:

https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/

I can't tell if this whole thing will be good enough, but some key issues seem to be addressed here.
1
0
1
In the shitty state of tech today: Soundcloud!

I want to filter for DJ mixes (long tracks) on the web:

- The mobile app groups sets to a tab when searching, but the web version does not.
- The web version allows you to filter search based on duration, but the official help page doesn't tell you how to do it (you have to do a search, select Tracks then you can filter for duration).
- Neither interfaces allow you to search only artists you follow.

I thought these were solved problems by 2001.
0
0
2
repeated

TrendAI Zero Day Initiative

Looking for all the results from Day One of Automotive 2026? You can find them here https://www.zerodayinitiative.com/blog/2026/1/21/pwn2own-automotive-2026-day-one-results

0
2
0
repeated
0
3
1
repeated

This might be the most difficult CPU to program.

The Intel i860 was useless for general operating systems.

Context switches took ~2,000 cycles.

*You* controlled the floating point pipeline. But, if you’re a genius, it was one of the most powerful chips that existed.

1
1
0
repeated

oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd https://seclists.org/oss-sec/2026/q1/89

0
3
0
repeated

🆕 iOS emulator update: we now have an assistant to support your iOS security investigations.

What do you think? 💬
Our shortlist is still ongoing: https://u.eshard.com/ios-emulation
#

0
2
0
Show older