Posts
3985
Following
730
Followers
1608
"I'm interested in all kinds of astronomy."
repeated
Edited 18 days ago

"That 'responsible disclosure' Thing"

A post with the details of CVE-2026-23918, the double free vulnerability fixed in Apache httpd 2.4.67.


https://eissing.org/icing/posts/responsible-disclosure/

4
6
0
repeated

Oh cool, Ollama on Windows has unpatched vulnerabilities that lead to Ollama downloading unverified updates from a malicious URL if set locally, and also path traversal that leads to arbitrary file write.

Disclosure without patch.

https://www.striga.ai/research/ollama-windows-auto-update-rce

0
4
0
repeated

bert hubert ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ

Edited 19 days ago

The world is now so full of ridiculous things that at least I struggle to deal with it all. But this is not an 'us' problem. The (political) world really is idiotic. I needed to vent a bit, so I made a list of things that are impossible to believe, yet are very much what is happening. Perhaps seeing it in writing will help you deal better with the situation. https://berthub.eu/articles/posts/the-impossible-things-we-have-to-believe/

5
6
0
repeated

This. ๐Ÿ‘‡

3
7
0
repeated

Defender nuked legitimate DigiCert roots as malware because Microsoft shipped detections for a real DigiCert breach without distinguishing root certs from the compromised code-signing ones. Your trust store is one bad signature update away from triage hell.
https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/

0
4
0
repeated

Aaron Toponce โš›๏ธdebian

Google Chrome is silently installing a local LLM on your computer that is 4 gigabytes in size. It's done without consent, it's not visible in the settings, and removing it will reinstall it later.

https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/

5
18
0
repeated
Edited 19 days ago

The existence of a weird proxy economy for AI tokens is very effing cyberpunk, AI issues notwithstanding (or perhaps especially). (Also, China Talk is an *excellent* source for lots of current tech-related goings-on.)

https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in

2
4
0
repeated

To kick off his collaboration with @portswigger as a Burp Suite Ambassador, our Research Lead @apps3c just published the 10th article on the creation of extensions for . Topic: !

https://hnsecurity.it/blog/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-10/

0
3
0
repeated

30 readers took our C/C++ challenge. Some solved the Linux warmup, but nobody cracked the Windows driver bug. Even LLM-assisted submissions came up short.

The walkthrough explains both, including the Windows escalation from local DoS to kernel code execution.

Best 10 submissions are still getting swag. If you won, we'll be in contact.
https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/

1
3
0
repeated
Edited 19 days ago
[RSS] pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI

https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/

+ CVE-2024-3273 analysis (D-Link)
0
0
0
Coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser

https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368

#Nix #Lix

#NoCVE atm
0
0
0
repeated
Edited 19 days ago

AISLE boasts about their AI tooling and CVE-2026-42511:

"Our autonomous AI system found another critical vulnerability in the FreeBSD DHCP stack - an unauthenticated remote code execution vulnerability with root privileges.

This finding is significant not only because RCE as root is about as severe as it gets, but also because FreeBSD was explicitly included in Anthropicโ€™s Mythos announcement, and Mythos did not identify this issue."

2
2
0
[RSS] Recursively fuzzing MS-RPC structures and monitoring using ETW

https://incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/
0
1
1
[RSS] [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation

https://github.com/klemmm/indyresolve
0
2
1
It's 2026 and Windows still can't synchronize time
1
2
0
repeated

Hister: Your own search engine

Hister has joined the

Hister is a general purpose web search engine providing automatic full-text indexing for visited websites.

Follow to be up-to-date with development news, releases and related articles.

0
5
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Norton Secure VPN Installation Insecure Operation On Junction Privilege Escalation Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2276

CVE-2025-58074
1
1
1
[RSS] Lateral Movement via Cross-Session Activation

https://ipurple.team/2026/05/04/cross-session-activation/
0
0
1
repeated
Show older