Posts
3908
Following
728
Followers
1600
"I'm interested in all kinds of astronomy."
repeated
Edited 1 month ago

Hello fedi!

I have an .MVAX file for an MV Silicon chip (unknown model).

Has someone already encountered those? And if yes, is there some documentation, tooling or existing work done of that format?

For the record, the file magic (first 8 bytes) is as follow:
4D 56 B5 58 05 01 13 00

And the end of the file contains the following (no spaces, wrapping is mine):

MVSKeyFileMVBP10<0x90>0xBE>SIMPLEs
<0xD3><0x9A>.<0x90><0xD9>
MVSILICONKEYFL<0x00><0x00>
<0xFF><0xBD><0x00>0x00>

Thanks in advance for your help!!

0
2
0
repeated

Right now, there's a really funny opportunity to burn an Outlook zero day.

0
1
0
repeated
repeated

Yay! @kagihq have provided a URL where you can continue to use their "1996-style" search as your home page.

It's so nice to have a bit of colour and human interaction there. "Small Web" has already become a favourite after just a few days. So many great, mad, creative websites to browse!

https://kagi.com/?year=1996

0
3
0
repeated

Crises precipitate change. That's no reason to induce a crisis, but you'd be a fool to let a crisis go to waste. Donald Trump is the greatest crisis of our young century, and the EU looks set to squander the opportunity, to its own terrible detriment.

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2026/04/04/digital-subjugation/#greenlands-next

1/

6
6
0
repeated
Edited 2 years ago

This is someting I wish I'd realized a lot sooner in life.

0
18
1
repeated
repeated
repeated

Interesting Git repos of the week:

Threats:

* https://github.com/haxrob/BPFDoor-controller-source - yay, BPFDoor source

Detection:

* https://github.com/davidjurgens/hallucinated-reference-finder - how many of those references are horseshit?
* https://github.com/Cybereason-Public/owLSM - kernel based Sigma rules powered by eBPF

Exploitation:

* https://github.com/zh54321/SharePointDumper - dump SharePoint
* https://github.com/Byxs20/Krb5RoastParser - have PCAPs, can cookie
* https://github.com/shellkraft/Anvil - analyse thick clients
* https://github.com/bethgelab/foolbox - mislead that neural network
* https://github.com/Oros42/IMSI-catcher - build your own IMSI catcher
* https://github.com/pullmoll/trusttrust - sample code for Reflections on trusting trust
* https://github.com/ZephrFish/BugBountyTemplates - bug bounty templates
* https://github.com/JoasASantos/Offensivesecurity-Checklists - helpful checklists for pen testing

Hard hacks:

* https://github.com/PentHertz/urh-ng - analyse RF protocols and abuse SDR
* https://github.com/wh1te4ever/super-tart-vphone-writeup - bulld your own virtual iPhone
* https://github.com/34306/vphone-aio - virtual iPhone images

Hardening:

* https://github.com/cisco-ai-defense/defenseclaw - watch where you're sticking that claw

, ,

1
4
0
repeated

Frey (Gender? I hardly know she/her!)

This quote from Apollo 14 astronaut Edgar Mitchell has been in my head the last few days

0
6
0
repeated

docs.rs builds are about to change. If you have crates published on crates.io/docs.rs, I recommend you read this blog post in case you might be impacted by this change: https://blog.rust-lang.org/2026/04/04/docsrs-only-default-targets/

0
4
0
repeated

you ever write code so inefficient they have to update the whole power grid

5
19
0
repeated

My Dad sends me horrible Dad jokes all the time, but sometimes he tells one that hits hard. This is one of those times.

"My favourite time of the year is campaign time. It's the only time I see politicans hang from trees."

1
3
1
repeated
Edited 26 days ago

Tired of reversing the same libc for the 100th time? 👀

Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries.
High-confidence function mapping. Works with any disassembler. By @madsquirrel & Sami.

🔗 https://blog.quarkslab.com/sighthouse-automated-function-identification.html

1
4
0
repeated

🆕 New blog post!

"BitLocker's Little Secrets: The Undocumented FVE API"

A small Windows RE adventure to figure out how to get the status and configuration of a BitLocker protected drive programmatically and without admin privileges.

Now also implemented in PrivescCheck! 🔥

👉 https://itm4n.github.io/bitlocker-little-secrets-the-undocumented-fve-api/

1
7
0
repeated

Project Zero Bot

New Project Zero issue:

vpu driver allocation and free of dmabuf and iova can race causing UAF read

https://project-zero.issues.chromium.org/issues/465824679

CVE-2026-0121
0
1
0
[RSS] Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices

https://www.evilsocket.net/2026/04/02/Mongoose-Preauth-Remote-Code-Execution-and-mTLS-Bypass/
0
3
2
[RSS] Review of AzireVPN and Malwarebytes Privacy VPN

https://x41-dsec.de/security/research/news/2026/04/02/malwarebytes/
0
2
2
Show older