Posts
4665
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated

CVE Crowd's search feature is now public!

This means you can now search for vendors, products, package names or CVE numbers and find related posts on the Fediverse and Bluesky - all without signing up anymore.

Previously, I used sign up as an obstacle for bots. But since proved good enough to keep those away, it now also secures search.

I hope this is useful to y'all!

https://cvecrowd.com

0
1
0
OMG did @jerry just update Akkoma so we now have enhanced search? 😍

Thank you!
0
0
2
I'm on this picture and don't like it.
2
9
22
repeated

...If anybody's looking for a person who basically does everything from compiler {backend,frontend} development, GPU driver development, to hardware/firmware security research, let me know.

US only.

5
15
0
repeated

RE: https://mastodon.social/@campuscodi/117128474535423979

Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic "starve it, then declare it ineffective" tactic. 😠

1
1
0
repeated

"You never can tell with bees."

0
2
0
repeated

I want a Firefox extension that knows how to replace every single "N months ago" label with the actual exact timestamp (using patterns for how the data is hidden in tooltips, click-to-expand, etc.).

That shit is SO unhelpful. Like if I'm looking back at git history, I don't care that a change was made roughly 3 months ago. I care whether it was made before or after an email I'm looking at that said something relevant to the change.

21
10
1
repeated

⚠️ A few hours ago, a malicious crate was discovered on crates.​io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted.

For details and how to see if you are impacted, see: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/

3
9
0
[RSS] The benchmarkpocalypse

https://danluu.com/benchpocalypse/
0
1
0
repeated

Microsoft killed my exploit 😢
This Friday on @offby1security I'll talk to @steph3nsims about what why, how and if this is the end for this class of exploit techniques

1
5
0
repeated

I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host. https://trustsig.eu/blog/wasm2c-tableflip-unchecked-calloc/

0
2
0
repeated

Just published “Vulnerability Analysis of CVE 2025 22226 Information Disclosure Due to OOB Read in VMwares HGFS” by Alex Zaviyalov the first vulnerability in an ITW VMWare guest to host escape chain 👇

https://www.nccgroup.com/media/1mzfvyzl/nccgroup_cve-2025-22226.pdf

1
2
0
repeated

We have achieved kernel code execution via the IDT under Windows 11 with VBS/HVCI/kCET enabled.

Read the technical write-up here: https://exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11

0
3
0
TIL when the Windows `copy` command is called with one directory argument it copies all files from that directory to CWD.

This was unexpected.
0
1
2
I'm inclined to draw a Petri net, please send help!
0
0
0
repeated

If I gambled on both NFTs and the metaverse to the tune of millions and millions of dollars and even renamed my company accordingly I would be so canceled I’d be farming potatoes, but people are still quoting Zuck AI predictions on my daily news feed.

8
5
0
repeated
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

Doing a presentation tomorrow on our utter dependence on US technology and specifically how we 100% picked US tools/support for cybersecurity as well. We are SO fucking fucked.

2
2
0
repeated

Can someone explain to me why AI companies are not being investigated for hacking other companies?

In the country I am living in, authorities HAVE TO investigate when they get to know about a crime - even without a criminal complaint (because generally people who were e.g. murdered cannot complain any more...).

Is the US justice system already so broken that this doesn't work any more?

1
2
1
Show older