Posts
4134
Following
733
Followers
1624
"I'm interested in all kinds of astronomy."
repeated

We’ve always had a problem with least privilege, but users needed to be owned for it to visibly hurt the enterprise.

Kevin didn’t know what to do with the extra creds, but his agent will.

Maybe the first run of the “paperclip” problem will be agents wiping shares to save us..

0
3
0
repeated
Edited 3 months ago

Okay these "Background Security Improvements" are definitely worse than RSRs. They show up at random times in your Settings app, and if you tap anywhere else, they disappear immediately. You can find them again, but they're not under Software Updates where they should be, but under Privacy & Security > Background Security Improvements, which also does not seem to show up in search.

EDIT: HOLY SHIT I have to enable "Automatically Install" in order to even be allowed to download them MANUALLY?! And there's no progress indicator either?? Whoever approved this should be hurled into the sea.

2
2
0
Fixing a Buffer Overflow in UNIX v4 Like It’s 1973

https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/

Exploit su on a PDP-11 :)
0
2
1
repeated

🚨 We are extending the deadline for our Volume 5 Call For Papers and its Rootkit Competition!

Check out the updated dates below:

https://tmpout.sh/blog/vol5-cfp.html (until May 1st 2026)
https://tmpout.sh/blog/vol5-rootkit-competition.html (until May 31st 2026)

We are looking forward to reading your work!

0
4
0
repeated

Whenever I use Chrome to debug a modern website, it's so funny to see all the requests usually blocked by my normal setup. It's like watching a fish being released back into the sea, swimming happily, gobbling up all the data and sending telemetry out to the other fish.

0
2
0
Edited 3 months ago
AI is going great at MS:

"You will see us be more intentional about how and where Copilot integrates across Windows [...] we are reducing unnecessary Copilot entry points, starting with apps like Snipping Tool, Photos, Widgets and Notepad"
0
0
4
To tilt Hungarian election, Russians proposed staging assassination attempt - The Washington Post

https://archive.ph/f8zdV
2
0
2
Great, I finally get myself to learn a Python project management tool then it immediately gets slurped up by OpenAI :P

https://simonw.substack.com/p/thoughts-on-openai-acquiring-astral
0
1
0
Since I read the JPL coding manual I'm always very considerate before introducing an infinite loop.

Then I usually decide that "it's fine, this is not a spaceship" and forget to implement the exit path.
1
1
1
repeated

"Intego X9: Never trust my updates"

Read @coiffeur0x90's research showing how XPC interprocess communications and the update mechanism of the Intego antivirus for MacOS can be abused for local privilege escalation.

https://blog.quarkslab.com/intego_lpe_macos_3.html

0
2
0
repeated

Call me crazy, but there are times when I think that ChatGPT sprinkling in knowledge about what I normally ask is... not useful.

This is from a question I asked about grease.

1
3
1
Chuck Norris didn't die, he just roundhouse kicked all of us into this shit timeline :(

R.I.P.
0
1
6
repeated
Edited 3 months ago

CVE-2026-20963 Sharepoint Insecure Deserialization 8.8/10

Weekend soon. Where @watchTowr blog? Need lolz. I can has?

0
2
0
Edited 3 months ago
Remote development mode in @zed is true killer feature! Previously I highlighted its usefulness for x-platform Rust dev, but now I'm using it instead of devcontainers to develop some not-very-trustworthy Python stuff.

Debugging worked out-of-the-box, I only had some trouble figuring out that LSP is not available until I mark the remote project as Trusted too.
1
1
2
repeated

Today is #iocaine 3.3.0 release day.

I'd like if it included a Grafana dashboard for the built-in script. But I'm yet to build one. It's very similar in shape to NSoE's, mind you... but I'd still need to do some work on it.

I've been postponing this since forever. But this is likely going to be the last 3.x release, I really, really should.

I'll go grind some spoons1, and see if I can manage.


  1. Well, hello there The Pitt S02E11! ↩︎

1
1
0
repeated

"There are repairs to be done, sometimes, both up there and down here."

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/

0
2
1
repeated
repeated

Let Me Explain How a State Actor Could Perform a Denial-of-Service Attack on the Entire UK Government in the Wake of Ofcom “Online Safety Act” Client-Side Scanning
https://alecmuffett.com/article/150401

2
4
0
repeated
repeated

Super weird experience: have 365 installed on iOS connected to an “Enterprise Tenant”.

This morning I get an urgent alert from Copilot 365, I click on it and there’s a web query for “Tell me the latest trends in IT jobs” running which I never asked for.

I stop it and prompt: “I never asked for this”.

Reply: “Sorry for overstepping and running queries without being prompted”

WTF?!?!?

flan_molotov

This is literally a “kill them all with fire, salt the ashes and, for good measure, flood the area.”

1
4
0
Show older