Posts
4665
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated
Edited 2 months ago

My newest Citation Needed project made an appearance on Last Week Tonight with John Oliver! It’s a work in progress, but you can see the new interactive version of my map of the Trump family’s crypto ventures at https://map.citationneeded.news/.

The map contains hundreds of business entities and links to the Trump family (with more being added!), augmented with data from the president’s most recent financial filings to estimate how much money is flowing in. It will be queryable by other researchers/journalists.

3
29
0
repeated

✨ A Sprinkle of JoyousJoyness ✨

That's all that matters.

Have a JoyousJoyfulJoyness day!

0
6
0
Edited 1 month ago
I can't wait for someone pivoting from a HF build container to Nvidia's ICS :)

#consolidation

RE: https://mastodon.cloud/@slashdot/117168550975017498
1
1
0
repeated
repeated

If Hollywood had any nerve there would be three different movies about a scruffy blue-collar hero who's down on his luck but finds meaning and new love cutting down Flock cameras shooting right now

https://www.theverge.com/tech/985155/flock-camera-destruction-vigilantes

2
2
0
repeated
repeated

Ryan Castellucci (they/them) nonbinary_flag

Partner: Open this for me?
Me: What are the magic words?
Partner: Please?
Me: ...
Partner: ...
Me: Squeamish...
Partner: ...
Me: Ossifrage.
Partner: looks up "Squeamish Ossifrage"
Partner: NERD!

2
4
1
The latest #PowerShell version is 7.6 (according to Wikipedia).

I need a feature from 7.2.

I downloaded a Windows image literally yesterday.

The feature is not there.
1
1
0
Since I was #FediLectured that I shouldn't expect street names to be displayed on AdTech maps, here is a map from our local bike rental app with zero street names to indicate where the bike stations actually are (map provider is #Mapbox)

#geoinformatics #cartography #bubi
0
0
0
repeated
Compromising Signal's Contact Discovery Enclave | V12
https://v12.sh/blog/signal
0
4
2
repeated

Trammell Hudson

Hope you're having a better day than the folks at Ziggo who pushed a remote firmware update that bricked eleven thousand customers' cable modems. https://tweakers.net/nieuws/251384/ziggo-vervangt-11000-modems-van-zakelijke-klanten-vanwege-technisch-defect.html
(in case you were wondering why we were offline for much of Monday...)

3
3
0
repeated

I've recently scanned DKIM keys for vulnerabilities, more extensively than previous scans. DKIM keys with the Debian OpenSSL bug are still very common. So are too-short RSA keys (quite a few 512 and even 384 bit keys, and *many* 768 bit, which is still difficult to break, but possible).
Also, a notable number publish a private key in their DKIM record. (This is only a problem if they actually use the same key elsewhere correctly.)
I tried disclosing things, but manual disclosure impractical for thousands of affected hosts and automated disclosure is difficult (plenty without security.txt, security@ often is rejected).
Replies to disclosures also show a common misunderstanding: People believe they are unaffected saying these keys are old and unused. This shows a fundamental confusion about how digital signatures work. Attackers don't care if you use insecure keys as long as they can use them.

Some stats for the latest scan: https://monitor.badkeys.info/dkim/2026-08-11-dkim-badkeys.html

0
2
0
repeated
repeated

this wild defcon talk is finally out

researchers created a fake defi startup, hired lazarus it workers, put them into a sandbox and recorded their tooling, workflows, and faces from inside the operation

starts at 5:46:09
https://www.youtube.com/live/_uYQr8hfpbI?t=20770

0
2
0
repeated

New on Insinuator: Part 1 of a four-part series on token theft in Microsoft Entra ID, accompanying ERNW White Paper 80.

The target is no longer the password or even MFA, but the token issued once authentication succeeds.

Part 1 covers the threat landscape and the techniques: direct token theft and PRT abuse, AiTM phishing, device code phishing, consent phishing, ClickFix and the ConsentFix family, plus where Microsoft's defense-in-depth strategy still leaves gaps.

By Niklas Kerner.

https://insinuator.net/2026/08/token-theft-in-microsoft-entra-id-part-1-of-4-threat-landscape-and-attack-techniques/

0
2
0
repeated

Graham Sutherland🎃 / Polynomial.pdf.exe

godspeed you wonderful human

1
2
0
repeated

I guess throwing up a message like this is easier than optimizing your code

0
2
0
repeated
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Adobe Photoshop Installation privilege escalation vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2026-2360

CVE-2026-48388,CVE-2026-48388,CVE-2026-48388
0
1
0
Show older