Posts
4015
Following
731
Followers
1614
"I'm interested in all kinds of astronomy."
repeated
Edited 1 month ago

There's a new Windows 0day LPE that has been disclosed called BlueHammer. The reporter suggests that it's being disclosed due to how MSRC operates these days.

MSRC used to be quite excellent to work with.
But to save money Microsoft fired the skilled people, leaving flowchart followers.
I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MSRC requirement now. πŸ˜‚

Anyway, yeah, it works. Maybe not 100% reliably, but well enough...

5
8
0
repeated

Thousands of CEOs said AI had no impact on productivity. We use AI to catch 200 bugs/week where we used to find 15, and generate $8M per sales rep.

95% of the company pushed back when we started. At unprompted, Dan Guido explains how our 140-person team went AI-native.
https://www.youtube.com/watch?v=kgwvAyF7qsA

1
2
0
Are We Idiocracy Yet?

https://idiocracy.wtf/
0
1
3
repeated

Before its launch, we audited WhatsApp's Private Processing TEEs and found 8 high-severity issues (patched). The enclaves yielded to injected config files, unmeasured ACPI tables, spoofed firmware levels, and stale attestation reports.

TEE security is only as good as the implementation details. Four lessons and the full report: https://blog.trailofbits.com/2026/04/07/what-we-learned-about-tee-security-from-auditing-whatsapps-private-inference/

0
5
0
#pol #sigint
Show content
β€œIn any matter where I can be of assistance, I am at your service.”

https://www.bloomberg.com/news/articles/2026-04-07/viktor-orban-offered-to-help-vladimir-putin-call-transcript-shows

Leaking intercepted Orban-Putin comms is an especially nice touch right when J.D.Vance is visiting Budapest...
0
4
1
repeated

I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf

0
3
0
repeated

Firefox added split tab views and absolutely killed it. I didn't even know I needed this feature and now I cannot live without it. Awesome work. Right click on a tab and select "Add Split View" to try it out.

0
3
0
repeated

If your Open Source project sees a steep increase in number of high quality security reports (mostly done with AI) right now (#curl, Linux kernel, glibc confirmed) please tell me the name of this project.

(I'd like to make a little list for my coming talk on this.)

15
7
0
repeated

Cat 🐈πŸ₯— (D.Burch) paw⁠paw

ad Is your shitposting quantum ready?

2
5
0
Umm, would somebody from Brazil report this to all possible authorities?

RE: https://fedi.computernewb.com/@vncresolver/116358355545832990
0
0
1
repeated

Trivy supply chain attack enabled European Commission cloud breach https://www.helpnetsecurity.com/2026/04/03/european-commission-cloud-breach/

0
2
0
repeated
xz security advisory (CVE-2026-34743):

https://tukaani.org/xz/index-append-overflow.html

Who has the guts to update? :)
0
4
6
repeated

IT'S HAPPENING

GITHUB, THE FIRST ENTERPRISE CLOUD SOLUTION TO REACH ZERO NINES RELIABILITY

https://mrshu.github.io/github-statuses/

18
36
1
repeated

did you know? the google forms share icon has a stray pixel in its corner

why? because the icon spritesheet has a massive black triangle overlapping the icons

what is that triangle? it's a giant out-of-bounds hat!

3
6
0
repeated

Project Zero Bot

New Project Zero issue:

Windows: OSK Shared Session Key EoP

https://project-zero.issues.chromium.org/issues/466303419

CVE-2026-24291
0
1
1
repeated

Project Zero Bot

New Project Zero issue:

Windows: ATBroker CopySettingsToLockedDesktop Information Disclosure

https://project-zero.issues.chromium.org/issues/466301558

CVE-2026-25186
0
1
0
repeated

Project Zero Bot

New Project Zero issue:

Windows: WinLogon WlAccessabilitypDeleteSATKey Registry Deletion EoP

https://project-zero.issues.chromium.org/issues/466300525

CVE-2026-25187
0
1
1
repeated

Lessons learned from the Artemis 2 mission:

1. some genius thought sending Outlook to space was a good idea,
2. some other genius thought that Bluetooth in space was a good idea,
3. plumbers are in demand, even in space.

flan_molotov​

1
3
0
Show older