Posts
3985
Following
730
Followers
1608
"I'm interested in all kinds of astronomy."
repeated

AIs have been finding bugs and vulnerabilities in for some time.

Is it work to fix those? Yes.

Has someone paid for this? Partially (wolfSSL and @sovtechfund)

Are the AIs annoying? Yes, very.

Could humans find the same bugs? Yes, if they‘d somehow avoid being bored to death through it.

Was there something „heartbleed“ like? No.

Were there lots of C mistakes? No, logic bugs mostly.

Do AIs run out of steam? Yes. After a while a model stops finding things. Findings differ per model.

2
5
0
repeated

It’s International Haiku Day apparently and so for today’s poetry offering, here are a few assorted haiku.

1
10
0
[RSS] Virtual Memory Area Management From Red Black Trees To Maple Trees

https://jinjucat.github.io/Virtual-Memory-Area-Management-from-Red-Black-Trees-to-Maple-Trees/
0
0
0
repeated

I've been uploading magazines from , some of which have been removed for reasons I don't understand, to Internet Archive. This is a decent scan of an issue of Hacker Defence (or Hacker Defence Line?) from I think the early to mid 00s.

https://archive.org/details/hacker_defence_unknown

2
4
0
repeated

Micropatches released for Windows Error Reporting Service Elevation of Privilege Vulnerability (CVE-2026-20817)
https://blog.0patch.com/2026/04/micropatches-released-for-windows-error.html

1
2
0
#music #EDM #hardtechno
Show content
This was a fun night :)

https://www.youtube.com/watch?v=6eJubuyFmSA

(The club was of course shut down by our former fascist govt, but hopefully in the future they will focus more on actual criminal crackheads and their dealers instead of ravers)
0
0
5
repeated

The cat's out of the bag! My latest book, "The Secret Life of Circuits", is available in early access:

https://lcamtuf.coredump.cx/blog/secret/

It's the reference I wish I had when I was starting out. Electrons to embedded systems, 290+ color illustrations and 420+ pages of well-explained theory.

9
14
1
repeated

New Post: Debugging - WinDBG(X) Automation & Scripting - Part 1 https://www.corelan.be/index.php/2026/04/17/debugging-windbgx-automation-scripting-part-1/

0
2
0
repeated

RE: https://infosec.exchange/@attackanddefense/116418875523198922

Q1 2026 was a very strong quarter for Firefox Security & Privacy.

some highlights:
- We expanded AI-assisted vulnerability discovery through our collaboration with Anthropic, helping identify and fix a high number of real security issues.
- We shipped the Sanitizer API in Firefox 148, making Firefox the first browser to support this stronger defense against XSS.

More in the newsletter linked below :)

0
3
0
Current stats:

* Bugs found in target: 1
* Bugs found in bug discovery tools: 4
1
2
7
repeated

RE: https://ec.social-network.europa.eu/@EUCommission/116408720976324749

Doesn't work without a Google/Apple-tied device btw. There is absolutely no story for how this would work on a desktop, anything without a Google/Apple account, or open source OS at all either.

11
18
0
I had pretty good experiences with Zed so far, but this is lunacy:

https://github.com/zed-industries/zed/discussions/29395
0
1
3
repeated
Edited 1 month ago

From the same author as BlueHammer we now have RedSun.

This works ~100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server 2019+ with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled. Any system that has cldapi.dll should be affected.

5
12
0
repeated

Join us tomorrow, April 17th @ 4pm ET, for some live pwn! We'll be using Binary Ninja's shell coding compiler, patching binaries to make them easier to debug, analyzing data moving from globals to the stack to the heap, and finishing by popping shells live with pwntools: https://youtube.com/live/VcK4SoeYZiU

0
2
0
repeated
Edited 1 month ago

RE: https://hachyderm.io/@Mara/115373191721487331

Half a year later, I'm *very* excited to report that we got initial funding and have hired our first Rust maintainers!

RustNL's Rust Maintainers Team now has two full time maintainers, one intern, and five part-time maintainers, now stably employed to continue their invaluable maintenance work that is crucial for Rust’s long-term sustainability.

https://rustnl.org/maintainers/

1
3
1
repeated
Edited 1 month ago

Apparently we reached the state of punishment, it's called and on virustotal. Microsoft and Sophos just "blocked" (aka content filter says it's porn... whuat?) a friend's website because the was suspicious of his AI website probably because on PreCrime is flagging it as will-be-malicious-in-the-future.

I want my Internet back.

0
2
0
Edited 1 month ago
Windows: You can execute stuff by double-clicking

Also Windows: PowerShell is the way to script me!

Still Windows: If you double-click a PS script, it'll open a text editor
0
1
2
repeated

Average number of hours between security reports

Material for a pending presentation

2
3
0
repeated

AI Use Appears to Have a “Boiling Frog” Effect on Human Cognition, New Study Warns

"In a new study, researchers claim to provide the first causal evidence that leaning on AI to assist with “reasoning-intensive” cognitive labor — mental tasks ranging from writing to studying to coding to simply brainstorming new ideas — can rapidly impair users’ intellectual ability and willingness to persist despite difficulty."

https://futurism.com/artificial-intelligence/ai-boiling-frog-human-cognition-study

3
9
0
repeated

I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.

I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl

384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:
-----BEGIN RSA PRIVATE KEY-----
MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK
j0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP
LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa
9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09
AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj
7ez94w==
-----END RSA PRIVATE KEY-----

16
38
0
Show older