Posts
4132
Following
733
Followers
1624
"I'm interested in all kinds of astronomy."
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Foxit Reader List Box Calculate Array Use-After-Free Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2365

CVE-2026-3779
0
1
2
repeated

New security advisory in our bug parade: Unauthenticated Remote Code in dormakaba evolo Service.

.NET Remoting is still a thing...

https://mogwailabs.de/en/advisories/mlsa-2026-001/

0
4
0
repeated

Our colleague @mal had another look at OpenOLAT and found a nice RCE (CVE-2026-28228 and CVE-2026-28228). If you're interested, details can be found on our blog https://secfault-security.com/blog/openolat-ssti.html

0
3
0
repeated
repeated

Did anyone got that alleged Vim RCE PoC working? MacOS doesn't seem vulnerable, Ubuntu 22/24, Debian 13, the same... Advisory says <9.2.0272 but doesn't seem like it?

Smells like AI slop hype? Yeah, kinda because most distros don't seem to ship vim with +tabpanel feature. HYPEEEEEEEEEEEEEEEEE

1
1
0
repeated

Instead of using an LLM to write me some boilerplate and basic functionality, frontend etc, why isn’t there a library where I can find all of these?

You know, something structured and shared, again, like a library, for specific purposes, and specific languages, with educational hints from development pros on the best way to do things and maybe some constructive feedback and improvements from other people?

And why were we left to deal with stackexchange instead?

Could this have been, dare I say it: gatekeeping?

1
2
0
Underrated post
3
6
19
repeated

If someone comes to me today preaching about “post-quantum” security issues, I’ll remind them of the current state of security: the npm ecosystem gets abused daily, CI pipelines run left and right with full access to cloud services, so-called security devices like F5 and Ivanti are exposed (and compromised) to the internet, mailboxes get compromised just to change an IBAN in a PDF, and a simple phone call is still enough to get someone to hand over an MFA code.

But yes, by all means, let’s focus on post-quantum threats while handing AI tools SSH access like it’s a feature, not a confession.

2
9
0
repeated
I skim through a lot of articles daily and in this age of slop my signal/noise decisions are heavily influenced by whether the piece is being hosted on a custom domain (showing that the author cares enough to maintain one).
0
1
6
[RSS] Reverse Engineering Crazy Taxi, Part 2

https://wretched.computer/post/crazytaxi2
0
0
0
repeated

Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

2
4
0
"As of March 2026, Alphabet’s market cap is ~$2T while Lockheed Martin’s is ~$120B."

https://martinvol.pe/blog/2026/03/30/how-the-ai-bubble-bursts/
0
1
0
repeated

Anyone knows anything more about this ?

"CVE-2026-31893 describes a serious Tunnelblick vulnerability.

This vulnerability is present in all versions of all Tunnelblick versions 3.3beta26 through 9.0beta01.

Tunnelblick 8.0.1 and 9.0beta02 contain fixes for the vulnerability.

The CVE is expected to be published and this page updated on or before 2026-03-27."

https://tunnelblick.net/CVE-2026-31893.html

1
1
0
repeated

Micropatches released for Arbitrary Registry Key Delete As Local System With Consolidator Scheduled Task (CVE-2025-59512) https://blog.0patch.com/2026/03/micropatches-released-for-arbitrary.html

1
2
0
repeated
Edited 2 months ago

RE: https://social.heise.de/@heiseonlineenglish/116316847500488516

“Oh, we murdered 100 kids? Oh, that's unfortunate.

We just had some stale data in our Palantir Project Maven data lake that was used by our ‘highly accelerated, software-supported targeting process’. We'll clear the cache sometimes.”

3
6
0
repeated

Honesty is not policy.

0
3
0
repeated

“Reverse Engineering the ITE 8910 Keyboard RGB Protocol for OpenRGB” with https://chocapikk.com/posts/2026/reverse-engineering-ite8910-keyboard-rgb/

0
3
0
[RSS] Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)

https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/
0
0
0
repeated

A walkthrough on patching Dell UEFI firmware at the SPI flash level to disable pre-boot DMA protection — bypassing the BIOS password entirely. The interesting part: the UEFI UI still reports the setting as enabled, and TPM measured boot doesn't detect the NVRAM change, so BitLocker unlocks normally. The patch also persists through official Dell BIOS updates. From there it's DMAReaper to kill IOMMU + PCILeech for a SYSTEM shell. Significant measured boot policy gap. https://www.mdsec.co.uk/2026/03/disabling-security-features-in-a-locked-bios/

0
5
0
Show older