Posts
4527
Following
741
Followers
1655
"I'm interested in all kinds of astronomy."
repeated

Feds: Super sophisticated computer hacking hackers hacked all the utilities!

The actual attackers:

4
15
0
repeated

We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.

It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.

Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/

2
8
0
repeated
Edited 15 days ago

A bit annoyed by tech reporting again. Found two major tech news outlets provide an incorrect explanation of the WebAudio fingerprinting (not you arstechnica. You did good). The thing is mostly prevented in major browsers like Firefox, as explained in this excellent technical analysis https://ritter.vg/blog-webaudio_alibaba.html by @tomrittervg.

Worst part is the article that went straight for FUD and had links for paid articles explaining how to "protect yourself" blergh. I thought better of you heise...

1
1
0
[RSS] Ruby Marshal Kick-off Gadgets - elttam

https://www.elttam.com/blog/ruby-marshal-kick-off-gadgets
0
0
0
repeated
@buherator u might like this madness hehe

https://youtu.be/etNTbFZGV8E
1
1
0
repeated

Mythos: 0
Aisle: 29

😱

5
4
0
repeated

Did you read our latest publication?

Our latest advisory covers a critical vulnerability in UNISOC modem firmware that can provide unrestricted read and write access to physical memory, potentially leading to arbitrary code execution with kernel privileges.

At SSD Secure Disclosure, we’re actively looking for baseband vulnerabilities and exploits, particularly high-impact research that can lead to remote code execution or equivalent impact.
Working on baseband security? Let us get you the highest payout available!

Check out our full product scope at https://ssd-disclosure.com/product-index/

0
1
0
repeated

The Gardener's laboratory.

A new page of my comic Ekphrasis, which you can read for free at https://ekphrasiscomic.neocities.org/

1
4
0
[RSS] Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust

https://bughunters.google.com/blog/scaling-memory-safety
0
1
1
repeated

The legendary Cliff Stoll gave a delightful talk at DEFCON on Stalking The Wily Hacker (40 Years Later) at DEFCON. It's now online. If you've never seen Cliff, a Klein Bottle, or an overhead projector before, rush over to the youtubes and fix that right now: https://www.youtube.com/watch?v=656058JxTM0

2
14
1
repeated

Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here (password: "expmon"):

https://drive.google.com/file/d/140JTizPrejK28bP3kt-iPdS5bRIy5hLr/view?usp=sharing

As shared previously, the crash still affects the latest Adobe Reader, but probably just a null-pointer-dereference issue.
https://bird.makeup/users/haifeili/statuses/2090513692895154536

0
1
0
repeated

just got laid off this morning. so if anyone knows of a position for an experienced researcher please let me know. 🖤

0
8
0
repeated

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

0
3
0
repeated

it's the last week of my summer sale -- get 50% a copy of "building git" using code BGAUG2026 at https://shop.jcoglan.com/building-git/

0
2
0
repeated

LAST WEEK to submit — Tokyo CFP closes soon.

We want real, original work: cutting-edge security research, novel exploit techniques, AI and deep technical investigations that actually move the field forward.

0
2
0
repeated
Edited 17 days ago

Can somebody give me a definition of metamorphism for something that aren't rocks? Specifically in binary code generation, how do you define metamorphism?

1
1
0
repeated

Uh nice Keycloak critical 🔥 how did i miss that one x3

https://github.com/keycloak/keycloak/issues/51833

0
7
0
I should not have to use an LLM to figure out a menu hierarchy.

I should not use an LLM to figure out how to undo the result of a hotkey.

LLMs (and search engines) should not be excuses for shitty #UI.
1
2
2
Show older