Posts
3865
Following
725
Followers
1594
"I'm interested in all kinds of astronomy."
repeated

Almost 7 years of silence.
Today, that changes.
March 23, 2026.
Follow to be among the first to know:
https://www.corelan.be/index.php/contact
Tick tock. It’s coming.

1
1
0
repeated

Electromagnetic Field

Our Call for Participation is now live!

If you have a talk, workshop, performance, or installation you'd like to bring to EMF, you can now submit it here:

https://www.emfcamp.org/cfp

Accepted proposals are guaranteed the chance to buy a ticket!

0
8
0
repeated

ℹ️❤️🖥 aka Compy-chan

Sums up my experience growing up

5
28
0
repeated
The `left-pad` incident was 10 years ago today.

https://en.wikipedia.org/wiki/Npm_left-pad_incident

Thankfully, we've completely solved software supply chains in the years since.
2
12
0
[RSS] LLVM Adventures: Fuzzing Apache Modules

https://pwner.gg/blog/2026-03-20-apatchy
0
0
0
repeated
repeated
repeated

looks like anthropic got rid of the claude refusal triggering string :(

2
4
0
repeated

This is my analysis (and PoC) for CVE-2026-20817, a privilege escalation in the Windows Error Reporting service.

👉 https://itm4n.github.io/cve-2026-20817-wersvc-eop/

Credit goes to Denis Faiustov and Ruslan Sayfiev for the discovery.

TL;DR A low privilege user could send an ALPC message to the WER service and coerce it to start a WerFault.exe process as SYSTEM with user-controlled arguments and options. I did not achieve arbitrary code execution, but perhaps someone knows how this can be done? 🤷‍♂️

1
9
0
repeated
repeated

Has anyone ever heard of a security breach of a Fedramp moderate or higher authorized environment? I mean the parts that are authorized.

3
4
0
#techno #music #acid
Show content
0
0
1
repeated
repeated

Does anyone know where to find more info on the surveilance economy online? I was looking for an update on the unfortunate Debora Silvestri who crashed so badly yesterday, and of course, was met with "We value your privacy" banner where I could consent to giving away… something?

The Privacy Policy talks about two cookies - both Google Analytics, and two partners for gaining "audience insights". The actual cookie pop-up list 1.709 (!) so-called "partners", many with "legitimate interest". Basically all these are companies nobody has ever heard of.

I know I'm leaking info like IP-address, browser and device details. What I can't understand is how all these 1.709 little leeches can possibly deliver enough value and generate revenue based on this information. Who pays them, and for what?

Thanks!

2
3
0
repeated

We’ve always had a problem with least privilege, but users needed to be owned for it to visibly hurt the enterprise.

Kevin didn’t know what to do with the extra creds, but his agent will.

Maybe the first run of the “paperclip” problem will be agents wiping shares to save us..

0
3
0
repeated
Edited 1 month ago

Okay these "Background Security Improvements" are definitely worse than RSRs. They show up at random times in your Settings app, and if you tap anywhere else, they disappear immediately. You can find them again, but they're not under Software Updates where they should be, but under Privacy & Security > Background Security Improvements, which also does not seem to show up in search.

EDIT: HOLY SHIT I have to enable "Automatically Install" in order to even be allowed to download them MANUALLY?! And there's no progress indicator either?? Whoever approved this should be hurled into the sea.

2
2
0
Fixing a Buffer Overflow in UNIX v4 Like It’s 1973

https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/

Exploit su on a PDP-11 :)
0
2
1
repeated

🚨 We are extending the deadline for our Volume 5 Call For Papers and its Rootkit Competition!

Check out the updated dates below:

https://tmpout.sh/blog/vol5-cfp.html (until May 1st 2026)
https://tmpout.sh/blog/vol5-rootkit-competition.html (until May 31st 2026)

We are looking forward to reading your work!

0
5
0
repeated

Whenever I use Chrome to debug a modern website, it's so funny to see all the requests usually blocked by my normal setup. It's like watching a fish being released back into the sea, swimming happily, gobbling up all the data and sending telemetry out to the other fish.

0
2
0
Edited 1 month ago
AI is going great at MS:

"You will see us be more intentional about how and where Copilot integrates across Windows [...] we are reducing unnecessary Copilot entry points, starting with apps like Snipping Tool, Photos, Widgets and Notepad"
0
0
4
Show older