Elektrine lite

← Feed

@timb_machine@infosec.exchange

2026-03-14 14:22 UTC

Interesting links of the week: Strategy: * https://shkspr.mobi/blog/2026/03/how-can-governments-pay-open-source-maintainers/ - @Edent@mastodon.social discusses government funding of open source * https://zeltser.com/ciso-leadership-lessons - @lennyzeltser@infosec.exchange on being a CISO * https://thecontractor.io/bugcrowd-researcher-philosophy-thoughts/ - JC calls out BugCrowd * https://arxiv.org/abs/2602.20021 - perhaps let's not trust agentic AI just yet? Threats: * https://blog.nviso.eu/2026/03/13/ivanti-epmm-sleeper-shells-not-so-sleepy/ - what really happened when Ivanti EPMM got popped? Detection: * https://www.robopenguins.com/fatal_core_dump/ - interactive fiction in the blue/red team vein from @axlan@mastodon.social * https://www.deathcon.wales/ - here be dragons! * https://www.labs.greynoise.io/grimoire/2026-02-24-whats-that-string/ - @Dio9sys@haunted.computer on why strings matter * https://arxiv.org/abs/2602.22427 - detecting statistical anomalies in the RAG * https://binsec.github.io/assets/publications/papers/2025-icse.pdf - hunting bugdoors with a fuzzer * https://medium.com/@the_abjuri5t/charting-the-iocs-aa1a4bba2863 - more IOC mapping Bugs: * https://www.postgresql.org/support/security/CVE-2026-2005/ - knocking over tables with Postgres * https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem/ - a nice little EoP in Windows 11 Exploitation: * https://ti-kallisti.com/tales/cyber-kill-chain.html - a nice little tale of physical deception from @kallisti@infosec.exchange * https://www.youtube.com/watch?v=jtv90pE-5hg - a nice reminder of Sergey Bratus (TY @claushoumann@mastodon.social) * https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Sicherheit/SiSyPHus/Workpackage8_Powershell.pdf?__blob=publicationFile&v=1 - @ERNW@infosec.exchange analyses PowerShell * https://sud0ru.ghost.io/windows-inter-process-communication-a-deep-dive-beyond-the-surface-part-10/ - peeling back Windows' IPC layers Hard hacks: * https://www.pentestpartners.com/security-blog/taming-the-dragon-reverse-engineering-firmware-with-ghidra/ - a nice easy-mode tutorial on firmware hacking from PTP * https://nextcloud.seemoo.tu-darmstadt.de/s/WrogYCn4TmcAyXA?dir=/&editing=false&openfile=true - reverse engineering the Apple watch protocols * https://blog.benjojo.co.uk/post/sfp-experiment-ultra-long-range-toslink - @benjojo@benjojo.co.uk explorer SFPs * https://www.apalrd.net/posts/2025/network_smartsfp/ - running Linux on an SFP * https://dl.acm.org/doi/pdf/10.1145/3772356.3772427 - cables that think * https://karlquinsland.com/ubiquiti-uacc-sfp-wizard/ - tearing down Ubiqiti SFP Hardening: * https://frederikbraun.de/perfect-types-with-sethtml.html - attempts to beat DOM XSS continue * https://blog.trailofbits.com/2022/11/08/sigstore-code-signing-verification-software-supply-chain/ - harking back to the past, some reminded me about code signing and this @trailofbits@infosec.exchange post #security, #research

Replies (0)

No replies.