Posts
4425
Following
738
Followers
1652
"I'm interested in all kinds of astronomy."
repeated

"I know that my life has always been vertebrated by two desires: the desire to know and the desire to help, to be of use."

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/

0
3
1
[RSS] Escalating All The Privileges With Foxit PDF Reader (CVE-2026-57239)

https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492
0
1
2
[RSS] The Design of Everyday Cryptography

http://dlp.rip/everyday-cryptography
0
0
1
[RSS] Dnsmasq DNS Remote Heap Buffer Overflow

https://blog.exodusintel.com/2026/07/20/dnsmasq-dns-remote-heap-buffer-overflow/

CVE-2026-2291
0
0
0
repeated
Edited 1 month ago

I'm convinced that UI developers are my mortal enemies.

Today's experience: Microsoft Outlook, which I have to assume is popular for some reason.

I go to delete a calendar item that I created for testing. Upon hitting [Delete] on my keyboard, I'm presented with the following dialog.

Which button will continue with the deletion of the item?

  • [➡️ Send]
  • [🗑️ Discard]

If you selected the 🗑️ button to delete the entry, you're a fool like me. Obviously the [➡️ Send] button is the one you click to delete the thing. [🗑️ Discard] obviously means [❌ Cancel] (do nothing).

3
5
0
The year is 2026. Literal trillions are spent in the hope to revolutionize the IT industry.

At the same time children have to deal with OAuth flows, One-Time Passwords and consent prompts to play Minecraft.

We really should stop fetishizing new software and stop for a brief moment to think through how software *should* work so it'd make our lives a bit better.
1
2
2
If only search was considered in Mastodons design...

RE: https://infosec.exchange/@cR0w/116953352499158321
1
0
0
repeated

#3274 - Arthurian Connector

0
5
0
repeated

Today Excel bugged me again to rate it, and when I tried it told me I was ineligible to submit a review.

Once again I am asking for all technology to be cast into the sea immediately or sooner.

1
11
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft Windows NETIO.sys NsipGetAllInformationProviderParameters Information Disclosure Vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2443

CVE-2026-50475,CVE-2026-50475,CVE-2026-50475
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Foxit Foxit Reader Javascript checkbox CBF_Widget code execution vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2420

CVE-2026-57256,CVE-2026-57256
0
1
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2426

CVE-2026-58613,CVE-2023-29361,CVE-2026-58613,CVE-2026-58613
0
1
0
[RSS] Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454

https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
0
0
1
[RSS] Defender Internals - AI Assisted EDR Introspection

https://blog.deeb.ch/posts/defender-ai-introspection/
0
0
1
At this point I'm not 100% sure LLMs are not alien psyops against our species (coincidentally I'm in the middle of Three Body Problem)
1
2
11
repeated

Remember to boost things you like, even if the post is old!

You are the algorithm here 🫵

9
20
1
I've been thinking a lot about securing online transactions for laypeople.

A major issue seems to be that URLs are 1) often not visible 2) not designed for laypeople, so many of us have no idea who they are communicating with.

I'm looking for a reliable browser extension that can block site access based on domain allow-lists, extensible by country.

Any recommendations?

#security #phishing #scam
2
1
1
Show older