Posts
3988
Following
731
Followers
1608
"I'm interested in all kinds of astronomy."
#music #acid
Show content
Fun set for #Saturday by one of my favorite Hungarian DJs

https://www.mixcloud.com/titusz-bicskei/
0
0
0
repeated

Cry and sob hysterically at every occasion, especially when confronted by government clerks.

0
4
0
"Insanity is doing the same thing over and over again and expecting different results"

Einstein obviously didn't have to work with LLMs
1
2
1
repeated

A hefty root cause analysis of Secure Firewall Management Center (FMC) RCE CVE-2026-20079 out now from our exploit dev team. The bug's a CVSS 10, but there are significant prerequisites for exploitation that limit real-world exploitability https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079

0
2
0
repeated

AI, a few thoughts, observations about AI & security vulns.
My standard line about AI is "there's a lot I'm uncertain about". But let's be clear, there's a lot I don't like & I'm probably biased towards the "here's how spectacularly AI failed once again" news (of which there are plenty) or at least the "it's not as impressive as it may look".
Yet, I don't want to close my eyes if I see things that clearly don't fit my biases. And I know a thing or two about security vulnerabilities.🧵

1
2
0
Took me a while to discover the automatic tab arrangement/containerization feature of Sidebery - best thing since silced bread!

https://addons.mozilla.org/en-US/firefox/addon/sidebery/

Right click on tab -> Configure site
0
0
0
repeated

you know

multiple people now have said that the thing they like about LLMs is that they don't have to deal with feeling embarrassed or humiliated by bringing questions to others that the others will judge them for.

which like

y'all.

this is a classic "solving a people problem with tech and having horrible side effects as a result" situation

and perhaps y'all ought to be less fucking toxic and judgemental to your coworkers.

fuck.

0
4
0
repeated

Rust 1.94.1 has been released.

This point release fixes a few regressions that slipped into in Rust 1.94.0: an internal compiler error in Clippy, a small security issue in Cargo, and two issues in the standard library.

See the blog post for details: https://blog.rust-lang.org/2026/03/26/1.94.1-release/

0
3
0
#ICS #OT crowd: I'm looking for "Production Line Design for Dummies"-type resources. I'm primarily interested in high-level best practices, rules of thumb for making industrial processes work reliably, ELI5 level is sufficient. Let's say I want to build a lemonade factory for my teddy bear!

Any recommendations?
1
0
1
repeated

I discovered a race-based vulnerability class in the Linux kernel: "Out-of-Cancel"

A structural flaw where cancel_work_sync() is used as a barrier for object lifetime management, causing UAF across multiple networking subsystems.

I wrote an exploit for CVE-2026-23239 (espintcp). It interleaves Delayed ACK timers, NET_RX softirqs, timerfd hardirqs, workqueue scheduling, and CFS scheduler manipulation to hit a ~Xµs race window.

Blog: https://v4bel.github.io/linux/2026/03/23/ooc.html

This is the race scenario diagram 😁:

1
5
0
repeated

Lorenzo Franceschi-Bicchierai

NEW: Here's everything you need to know about the new iPhone hacking tool DarkSword.

What is DarkSword? How does it work? Where did it come from? How did it leak online? What can you do about it?

We break it all down in this explainer.

http://techcrunch.com/2026/03/26/a-major-hacking-tool-has-leaked-online-putting-millions-of-iphones-at-risk-heres-what-you-need-to-know/

0
3
0
repeated
repeated
Edited 2 months ago

Vibe Security Radar: Real CVEs where AI-generated code introduced the vulnerability.

https://vibe-radar-ten.vercel.app/

EDIT: forget that, it's slop:

> If the primary model fails, a Claude Agent SDK fallback with independent repository access retries the investigation.

sigh

2
2
0
repeated

We analyzed the Coruna exploit kit and found intriguing code overlaps with Operation Triangulation https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/

0
5
0
repeated

📱 1-click RCE in the YTDLnis Android app!

On Android, turning file writes into RCE is usually quite hard, but here the app had a nice gadget for us. Check out the details in our latest blog post:

https://www.sonarsource.com/blog/ytdlnis-argument-injection-rce?utm_medium=social&utm_source=mastodon&utm_campaign=research&utm_content=social-ytdlnis-rce-260324-&utm_term=---&s_category=Organic&s_source=Social%20Media&s_origin=social

0
3
0
repeated
Edited 2 months ago

Sometimes I wonder… I come from two Milanese industrialist families who worked hard to keep their factories going (and failed in one case due to, literally, natural causes aka a dam disaster) and, reading the responses to my LinkedIn post about salary dumping in Ticino, I cannot reconcile it with anything I have ever heard from my parents or grandparents.

This bizarre concept that it is the workers and the international treaties which somehow "force" the companies to use cheap labour is spectacular.

Of course my families tried to run a profit but, in one case, literally financed one of the most skilled workers to set up their own shop and become a supplier with a guaranteed 5-yr 100% purchase cover before they could work alone (their family is still in business!), the other spent literally almost all their fortune to provide for the worker families hit by the disaster.

I should add that my grandfather's idea of "owner luxury" was going on holiday in Rimini for two weeks, having a large apartment in a new development towards Milan Linate airport, and driving an Alfa Romeo Alfetta, not "two yachts, three Ferrari, five villas." That might explain things...

Having said this I was brought up in a left-wing family and the only comment when I said I was an Ⓐ was "perhaps too much?" which is fair :)

1
2
0
There is currently an insane spy thriller running in #Hungary ICYMI:

https://www.direkt36.hu/en/titkosszolgalati-nyomasra-tortent-hazkutatas-a-tiszat-segito-informatikusoknal-aztan-kibukott-egy-gyanus-muvelet-a-part-ellen/

A 90min interview with the whistleblower was released too that reveals even more pieces of the puzzle. The whole thing screams for a movie (and long prison sentences).
4
17
10
repeated

okay I can finally show off these things- Sun SPOTs, weird little java on metal microcontrollers from 2005/2006!

http://nug.only9fans.com/penny/SunSPOTs/

4
4
0
Show older