Posts
4665
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated

Insane and inhumane: "YC founder asks desperate job seekers to tattoo themselves for an interview"

https://sfstandard.com/2026/07/30/lemonlime-tattoo-job-interview/

2
6
0
repeated

After a short induced hiatus, it's back...

First up this weekend is interesting talks from :

Threats:

* https://media.ccc.de/v/emf2026-215-1-north-korean-agent-looking-for-a-job - job hunting, .kp style

Exploitation:

* https://media.ccc.de/v/emf2026-93-1-they-forgot-what-happened-last-time - @Rairii's pokes the Redmond beast some more
* https://media.ccc.de/v/emf2026-206-1-breaking-in-to-buildings-with-boobs - a guide to social engineering the physical world

Hard hacks:

* https://media.ccc.de/v/emf2026-57-1-obd-ii-obviously-broken-design-too - getting into ODB-II
* https://savvycan.com/ - CANbus packet parser
* https://media.ccc.de/v/emf2026-56-1-lock-picking-robot - robotic approaches to locks
* https://safetyfic.com/how-to-unlock-tsa007-lock-forgot-combination/ - how to change the code on a TSA combination lock?
* https://www.amazon.co.uk/tsa-key-007-master-luggage/ - want a TSA master key?
* https://lpubelts.com/ - how hard to pick is my lock?
* https://media.ccc.de/v/emf2026-47-1-building-a-tiny-paging-network - build your own pager network with @sammachin

Crypto:

* https://media.ccc.de/v/emf2026-59-1-how-not-to-make-a-random-number-generator - return 42;
* https://en.wikipedia.org/wiki/Euclidean_algorithm - finding the common factor
* https://en.wikipedia.org/wiki/Euler%27s_factorization_method - more on common factors

Data:

* https://media.ccc.de/v/emf2026-88-1-building-a-mostly-local-mildly-judgemental-home-assistant - Mark J Cox takes us on a journey to build your own home assistant ๐Ÿค–

Nerd:

* https://media.ccc.de/v/emf2026-124-1-infrastructure-review - a review of the EMF Camp 2026 infrastructure
* https://media.ccc.de/v/emf2026-230-1-an-sres-guide-to-camping-in-extreme-conditions - vanlife reliability engineering from @donna_156
* https://phones.emfcamp.org/ - the EMF phone book
* https://media.ccc.de/v/emf2026-46-1-the-orphan-source-incident - more about the 2024 orphan source incident
* https://media.ccc.de/v/emf2026-277-1-reverse-engineering-007-nightfire - updating Nightfire via reverse engineering
* https://media.ccc.de/v/emf2026-100-1-automated-game-hacking - parsing and compiling game logic

,

0
3
0
repeated

Genuinely having a great time reading @tara 's exploration of purpose-built business machines (in the vein of the IBM 5280): https://www.tara.sh/posts/2026/2026-07-24_cobolito400_essay/

Honestly her site is one of my favorite little blogs. There's a fully essay behind the post!

As an industry, I know we're not going back, but it's neat reflecting on how different engineers over the decades have thought about _data_ and data portability as a first-class citizen.

1
3
0
[RSS] Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape

http://www.darknavy.org/blog/patch_in_exploit_out_how_deepsec_reconstructed_the_pwn2own_microsoft_edge_sandbox_escape/
0
1
1
repeated

Coldcard devices used predictable RNGs, and apparently this has consequences. ๐Ÿ˜‚

0
2
0
repeated

I'm pleased to announce a new release of the bindings for @HexRaysSA IDA Pro! This release adds compatibility with latest SDK (v9.4), and a couple of bug fixes. Thanks to @raptor and @yegor for their contributions.
https://github.com/idalib-rs/idalib.git

0
4
0
repeated

Happy Sys Admin Appreciation Day to all to who observe it.

0
3
0
repeated

This made us think

0
5
0
repeated

IFIN - The Independent Federated Intelligence Network

Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples.

https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698

0
5
0
repeated

anyone experienced with high-speed (~150m) cabling and possibly also somewhere half-way injecting solar-based PoE? is this a thing?

4
2
0
Anthropic choosing an asshole as the logo for Claude is the most honest marketing move in recent history.
2
0
4
repeated

: three critical in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch!
๐Ÿ‘‡
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

0
3
0
repeated

For the nerds in the back:

Not understanding how your program works is not an excuse for it doing the bad shit it was literally programmed to do.

6
7
0
repeated
Edited 2 months ago

Wiz found a master key that could access every database in Azure's Cosmos DB.

Whoops.

https://nitter.net/yuvalavra/status/2082864672294736324

My present to all of you: Go ahead and think a bit about why such a key even exists. Go ahead...

3
11
0
repeated

bert hubert ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ

AI: Considerations for people who make decisions. There is enormous pressure to deploy AI, and if you believe the LinkedIn thought leadership, you'd think that if you don't get on board NOW you'll be lost forever. Meanwhile other people severely detest AI, so much so that it damages their (worthwhile) arguments against it. Below, thoughts on what to do now, and what things might best be postponed. Finally, some stimulating words on what we actually DO at the office: https://berthub.eu/articles/posts/ai-for-decision-makers/

5
8
0
repeated

This wonderful wallpaper and the Issue cover were created by Vasyl/Joker^NAH^TRSI. Both this and other wallpapers, as well as Issue which just came out, can be downloaded from Paged Out!'s website!

0
1
0
Edited 2 months ago
This feels like kindergarteners making up stories about who fell bigger with their scooters during summer break :P

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
0
0
5
repeated

Reproduced the LPE in 1h 56m on Linux 6.12.96 LTS.

Also managed to get root on Pixel 10 with the latest 2026-07-05 security update.

It was originally submitted by another researcher to Google KernelCTF as exp527 and should qualify for a $101,337 bounty.
https://bird.makeup/users/spendergrsec/statuses/2082627090310938838

0
2
0
Show older