Posts
4358
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated
Edited 2 months ago

The new CEO of the Wikimedia Foundation worked at J.P. Morgan and Lehman Brothers. The Foundation has now fired a longtime lead developer and disbanded the team whose job was to listen to volunteers. Most of the people they fired were union organizers. Wikipedia’s editors are now threatening to strike. To stand in solidarity with them, sign the petition:

https://en.wikipedia.org/wiki/Wikipedia:Wiki_Workers_United_solidarity

For more, read on!

(1/2)

8
27
1
repeated

Hungary Reverses Decision to Exit International Criminal Court

Hungary withdrew its decision to exit the International Criminal Court, reversing a process initiated by the country’s previous leader, Viktor Orban.

https://www.bloomberg.com/news/articles/2026-05-27/hungary-reverses-decision-to-exit-international-criminal-court

0
10
0
[RSS] Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)

https://www.midnightblue.nl/blog/analyzing-the-taiwan-high-speed-rail-thsr-tetra-cyber-incident-part-1
0
1
1
Edited 2 months ago
[RSS] Docker Internal[s] (1)

https://u1f383.github.io/linux/2026/05/27/Docker-Internal-1.html

"For this year's (2026) Pwn2Own Berlin, I tried to find vulnerabilities in Docekr but came up with nothing. This post simply documents my research on Docker's system implmentation, since it is quite interesting."
0
2
4
Java code can become overly complex due to unnecessary abstractions.

With Rust on the other hand you can simply open up a portal to the Dimension of Pain while trying to implement an interface.
1
1
9
The year is 2026:
- My Windows VM can't handle more than 2 serial ports
- My hexeditor won't run without a GPU
2
1
6
repeated

PRESS RELEASE
Today, our engineering team announced a streamlined editorial workflow powered by the Unix tool sed, enabling instant, consistent replacement of the symbol & with the word “and” across all communications. This improvement strengthens clarity, supports accessibility, and ensures brand‑wide linguistic consistency. By integrating sed into our publishing pipeline, we reaffirm our commitment to precision, efficiency, and high‑quality content delivery.

1
1
0
repeated
Edited 2 months ago

While everyone was on Holiday we scanned a few thousand hosts for (CVE-2026-48710): zero auth required and we found clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 now and check your exposure at https://badhost.org

1
4
0
repeated

We paired time travel debugging with an agent on a noisy 7B-instruction ARM64 Android trace.

In ~10 minutes, it traced the MTProto v2 decryption chain down to AES-IGE and correctly described the execution flow.

Full write-up 👇
https://www.eshard.com/blog/telegram-ttd-trace-analysis

0
2
0
repeated
repeated

Hoshino Lina (星乃リナ) 🩵 3D Yuri Wedding 2026!!!

Holy crap, clang in C++ mode is *evil*!

https://godbolt.org/z/hM7W1WPsE

gcc at least puts a `ud2` in there...

3
2
0
repeated
current status
1
0
1
The epoll uaf

https://guysrd.github.io/epoll-uaf

"That one call fixed a uaf that had been reachable from any unprivileged process for a few years on any Linux / Android running a 6.6 and above kernel with the affected optimization."
0
5
4
repeated

Micropatches released for Windows Shell Link Processing Spoofing Vulnerability (CVE-2026-25185)
https://blog.0patch.com/2026/05/micropatches-released-for-windows-shell.html

1
3
0
repeated
Edited 2 months ago

Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

🔗 https://oxidizeconf.com/sessions/awaiting_exploitation

0
4
0
repeated

hack.lu is celebrating its 20th edition!

There is still time to be part of this special anniversary edition: submit your talk, presentation, workshop, or even a short talk for the Call For Failures.

Twenty editions of sharing, learning and community deserve something memorable. Don’t miss the chance to contribute, this year will be special!

Call-for-Papers Submission Site https://pretalx.com/hack-lu-2026/

CfP Details https://2026.hack.lu/blog/hack.lu-2026-call-for-papers/

@hack_lu @circl

0
4
0
repeated

It's . Have a good one and don't forget your

0
4
0
repeated

‚Torvalds added, in the case of AI-discovered bugs, you need to keep in mind that just "because you found it with AI, 100 other people also found it with AI."‘

There is nothing secret about a bug found by a model. If the software is a target, you can be sure that the bad guys are running continously prompts against it. Without token restrictions.

As a maintainer, this is all hard to manage. But this is happening everywhere. It‘s not your job to save the world from stupidity, vanity and greed.

0
4
0
repeated
Edited 2 months ago

I'm incredibly pleased to announce that the microcode for the Intel 80386 has been decoded.

It was a group effort by a bunch of talented people to extract and correct the physical bits, but the major work of decoding them was done by reenigne - you may know him from such incredible PC demos as 8088 MPH and Area 5150, as well as being the person who decoded the 8088 microcode previously.

Please, check out his writeup.

https://www.reenigne.org/blog/80386-microcode-disassembled/

5
29
2
Show older