Posts
3906
Following
728
Followers
1600
"I'm interested in all kinds of astronomy."
repeated

Project Zero Bot

New Project Zero issue:

Adobe DNG SDK: integer overflow in dng_pixel_buffer::OptimizeOrder leads to out-of-bounds memory access

https://project-zero.issues.chromium.org/issues/478212931

CVE-2026-27281
0
1
0
repeated

The RCE I've found in LiteLLM (https://x41-dsec.de/lab/advisories/x41-2026-001-litellm/) is a nice example of how AI agents can speed up security research. The issue was found during a project with strict time constraints by me manually. So I had a Nemesis backed AI agent do auto-triage and find a sandbox escape fully automated. After 20 minutes the job was done including a fully working exploit.

0
5
0
repeated

Linus Torvalds, the legend 🔥

6
10
1
repeated
Edited 29 days ago

Getting serious ADHD and building software nobody asked.

checksec for Mach-O
https://github.com/ChiChou/macchk

⚠️ Warning: vibe coded

1
5
0
repeated

Enfys 🏴󠁧󠁢󠁷󠁬󠁳󠁿 🏳️‍⚧ 🔜 Outline

Edited 1 month ago

i released an Atari 2600 demo with some friends at revision this year and managed to win 1st place in the oldskool demo compo! it's been in development for about a year now so was really cool to see it finally out :3
https://demozoo.org/productions/389801/
https://www.youtube.com/watch?v=aEJ0A8Wvdxs

0
2
0
repeated

TrendAI Zero Day Initiative

Inherent flaws in node.js remain unpatched. Bobby Gould and Michael DePlante detail the problem and how the burden of security silently falls on app developers. https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows

0
2
0
repeated
repeated

Another #Hungary and #Russia investigation by #VQuare

  • Budapest systematically weaponized the issue of Hungarian minority rights in Ukraine to stall EU accession negotiations.
  • Péter Szijjártó offered Sergey Lavrov to send EU documents through the Hungarian Embassy in Moscow.
  • Hungary and Slovakia, acting as Kremlin friends in the EU, pushed against restrictions of Russian energy supplies.
  • Budapest also supported the Kremlin’s “achievements” of the Alaska Summit.
  • Leaked audio reveals a strikingly deferential, submissive attitude from Szijjártó toward Lavrov.

https://vsquare.org/kremlin-hotline-how-hungary-coordinates-with-russia-blocking-ukraine-from-the-eu/

0
3
0
repeated

New from 404 Media: Microsoft has terminated an account associated with VeraCrypt, the popular and long-running piece of encryption software. This means can no longer receive updates on Windows, the developer told me. Little explanation given by Microsoft https://www.404media.co/microsoft-abruptly-terminates-veracrypt-account-halting-windows-updates/

3
5
0
repeated

taking pride in my vintage pre-AI CVEs

3
5
1
[RSS] Standardizing Rewards in Google VRP: Introducing Information Tiers and Action Criticality

https://bughunters.google.com/blog/standardizing-rewards-in-google-vrp
0
0
1
repeated

desktop management interface 💽

\o/ VLC in space

@videolan

5
18
0
repeated

It's definitely impressive the LLMs capabilities finding bugs (I was very interested with AIxCC) but let's be honest, bugs were never scarce. There is just a new toy able to scale things faster (although funny how the price is always hidden). So were fuzzers when AFL coverage was introduced. Will it plateau or not that's the question. And will introduction of new bugs crash or not. Interesting times? Sure. End of times? Meh... Time will tell, as usual 🙂

1
3
0
repeated

Keep these monstrosities off our roads 🙅‍♂️

"US carmakers have accused Brussels of keeping their largest pick-up trucks, including the Ford F-150, the Chevy Silverado and the Ram 1500, off European roads”

https://www.ft.com/content/3eb796fd-bcdb-4a9f-89b7-f7d5e692a3cd

https://www.carsized.com/en/cars/compare/renault-twingo-1998-3-door-hatchback-vs-ford-f-350-2016-4-door-pickup-crew-cab/

28
19
0
repeated
Edited 1 month ago

📱 Summer intern wanted!

@exhel and I are looking for someone to help us reverse engineer Android apps this summer @ TU Graz.

→ 20 or 40hrs/week contract
→ Helpful background: Android, reversing, or messaging apps

Send a short motivation statement + CV to lena.heimberger@tugraz.at AND edona.fasllija@tugraz.at

Boosts appreciated! 🙏

0
2
0
repeated

In the 70s they could open Facebook by pressing the Meta key and there were Like and Dislike buttons right on the keyboard.

2
4
0
repeated

Here’s why it’s important to always use r2 from git. In r2land, we follow the law of full disclosure and fix any reported vulnerability within a 24h deadline, as stated in SECURITY.md https://blog.calif.io/p/mad-bugs-discovering-a-0-day-in-zero

0
3
0
repeated

It's so cool that anthropic is setting up a double-sided protection racket where it will profit from the massive token burn of attackers and defenders with a tool specifically designed to generate exploits and their only observable mitigation is a clientside system prompt that sternly warns the LLM to be good and not do malware
https://red.anthropic.com/2026/mythos-preview/

3
10
0
Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS

https://heyitsas.im/posts/cups/

More LLM bugs: CVE-2026-34980 and CVE-2026-34990
0
2
2
repeated

To my security peeps: Was the introduction of widespread fuzzing similar to AI-based bug hunting now, or is this really a different beast?

1
4
0
Show older