Posts
4134
Following
733
Followers
1624
"I'm interested in all kinds of astronomy."
Can anyone point me to a good layman's tutorial to Yubikeys?
0
1
2
repeated

that sound you hear is every Windows platform engineer pasting the "Our commitment to Windows quality" post into their AGENTS.md

0
3
0
When I become dictator I'll establish an authority that will check every EDM track for "is one of my many chat programs blimping?" sounds.
0
0
3
repeated
repeated

RE: https://mastodon.art/@lurnoise/114993216415771245

Hi! You should hire me for stuff, not only do I draw pretty neatly but I'm also very kind and easy to work with and always hit the deadlines <3

0
2
1
repeated

What You Need to Know: Windows Admin Center Remote Privilege Escalation (CVE-2026-26119) https://www.semperis.com/blog/what-you-need-to-know-windows-admin-center-remote-privilege-escalation-cve-2026-26119/

0
2
0
[RSS] Windows stack limit checking retrospective: Alpha AXP

https://devblogs.microsoft.com/oldnewthing/20260318-00/?p=112146
0
1
0
repeated

Almost 7 years of silence.
Today, that changes.
March 23, 2026.
Follow to be among the first to know:
https://www.corelan.be/index.php/contact
Tick tock. It’s coming.

1
1
0
repeated

Electromagnetic Field

Our Call for Participation is now live!

If you have a talk, workshop, performance, or installation you'd like to bring to EMF, you can now submit it here:

https://www.emfcamp.org/cfp

Accepted proposals are guaranteed the chance to buy a ticket!

0
8
0
repeated

ℹ️❤️🖥 aka Compy-chan

Sums up my experience growing up

5
25
0
repeated
The `left-pad` incident was 10 years ago today.

https://en.wikipedia.org/wiki/Npm_left-pad_incident

Thankfully, we've completely solved software supply chains in the years since.
2
12
0
[RSS] LLVM Adventures: Fuzzing Apache Modules

https://pwner.gg/blog/2026-03-20-apatchy
0
0
0
repeated
repeated
repeated

looks like anthropic got rid of the claude refusal triggering string :(

2
4
0
repeated

This is my analysis (and PoC) for CVE-2026-20817, a privilege escalation in the Windows Error Reporting service.

👉 https://itm4n.github.io/cve-2026-20817-wersvc-eop/

Credit goes to Denis Faiustov and Ruslan Sayfiev for the discovery.

TL;DR A low privilege user could send an ALPC message to the WER service and coerce it to start a WerFault.exe process as SYSTEM with user-controlled arguments and options. I did not achieve arbitrary code execution, but perhaps someone knows how this can be done? 🤷‍♂️

1
9
0
repeated

Has anyone ever heard of a security breach of a Fedramp moderate or higher authorized environment? I mean the parts that are authorized.

3
3
0
#techno #music #acid
Show content
0
0
1
repeated
repeated

Does anyone know where to find more info on the surveilance economy online? I was looking for an update on the unfortunate Debora Silvestri who crashed so badly yesterday, and of course, was met with "We value your privacy" banner where I could consent to giving away… something?

The Privacy Policy talks about two cookies - both Google Analytics, and two partners for gaining "audience insights". The actual cookie pop-up list 1.709 (!) so-called "partners", many with "legitimate interest". Basically all these are companies nobody has ever heard of.

I know I'm leaking info like IP-address, browser and device details. What I can't understand is how all these 1.709 little leeches can possibly deliver enough value and generate revenue based on this information. Who pays them, and for what?

Thanks!

2
3
0
Show older