buherator
buherator@infosec.place
"I'm interested in all kinds of astronomy."
Posts
-
Post #4495389
I thought I'm making up a conspiracy theory around NVIDIA architecting the AI bubble after the crypto bubble bursted. It seems @david_chisnall@infosec.exchange agrees (sort of): RE: https://infosec.exchange/@david_chisnall/117075838205635406
-
Post #4492205
[RSS] 4 jsoup vulnerabilities https://joshua.hu/4-jsoup-vulnerabilities
-
Post #4480085
[RSS] The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
-
Post #4480020
[RSS] 22 CVEs in TeamDavid(R) a "secure" M365 alternative https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
-
Post #4278581
[RSS] LLMs won't break symmetric crypto https://www.bfswa.blog/p/llms-wont-break-symmetric-crypto
-
Post #4269552
[RSS] Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
-
Post #4245307
[RSS] KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
-
Post #4240507
96 degrees in the shaaaaade https://www.youtube.com/watch?v=hwE5gfZlMZY
-
Post #4237247
LLM2Human Clinic https://llm2human.pages.dev/
-
Post #4234676
Serious request: Stop assuming that users have Internet access! #OldManYellsAtCloud
-
Post #4232156
[RSS] XProtectRemediatorDubRobber infoleak on macOS (CVE-2024-40842) https://gergelykalman.com/CVE-2024-40842-xprotectremediatordubrobber-infoleak-on-macos.html
-
Post #4203775
[RSS] Exploiting Titan Quest https://www.synacktiv.com/en/publications/exploiting-titan-quest.html
-
Post #4193251
I like that cargo whips the LLMs butt so I don't have to
-
Post #4189169
Some tracks can't be saved even by a schrantz remix #KylieMinogue
-
Post #4186610
[RSS] ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313 https://horizon3.ai/intelligence/blogs/coldfusion-critical-cves/
-
Post #4185840
HugginFace incident report: https://huggingface.co/blog/agent-intrusion-technical-timeline The report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s :) Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like an URL?). I feel sorry for blue t...
-
Post #4161426
I rarely share podcasts and videos but the latest by LiveOverflow feat. s1r1us about the OpenAI vs. HuggingFace incident is a real good watch and also agrees with some of my earlier points: https://www.youtube.com/watch?v=q2KCrmQz9WE
-
Post #4159262
[RSS] Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/
-
Post #4159224
[RSS] Research: Hacking-adjacent Incident from 1966 https://jericho.blog/2026/07/27/research-hacking-adjacent-incident-from-1966/
-
Post #4158041
[RSS] Random Windows Things Part 1: PreviousMode MitigationRandom Windows Things Part 1: PreviousMode Mitigation https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/
-
Post #4156365
[RSS] Random Windows Things Part 2: Unexpected Clipboard Data BehaviorRandom Windows Things Part 2: Unexpected Clipboard Data Behavior https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
-
Post #4155545
Apple MIE exploitation challenge https://blog.calif.io/p/apple-mie-exploitation-challenge "In this blog, we'll share the details of the two vulnerabilities behind our [MIE bypassing] exploit"
-
Post #4142247
[RSS] From Virtual Share to Physical Shell: Leveraging Windows' Inconsistent Access Control for LPE https://blog.exodusintel.com/2026/07/27/from-virtual-share-to-physical-shell-leveraging-windows-inconsistent-access-control-for-lpe/
-
Post #4131962
Helpful reddit is helpful What is "HH" on ThinkPad logo? https://www.reddit.com/r/thinkpad/comments/o0j9qt/what_is_hh_on_thinkpad_logo_t480s/ #thinkpad
-
Post #4131596
[RSS] 33 Vulnerabilities in cJSON https://joshua.hu/cjson-json-parser-cve-vulnerabilities
-
Post #4070331
An interesting metric of any political system is the distribution of professions of people in power. For years it seemed that only unemployed lawyers and career buttlickers can become popular politicians around here. Now we have a traffic engineer as a minister of transportation who knows the dates to the day when railway sections were closed down and calls engines by their nicknames. And people love him! This gives me some hope.
-
Post #4069032
Is there a list of ways to cut the very connection you are using to manage a server? "A friend" would like to contribute...
-
Post #4068821
You find Anna's Archive via a search engine I find it by randomly typing 2 characters after "annas-archive." We are not the same. (although you've probably visited way less click farms)
-
Post #4061138
[RSS] Confidential Computing on Arm: Architecture & Use Cases https://www.linaro.org/blog/confidential-computing-on-arm-architecture-use-cases/
-
Post #4061089
[RSS] Rustifying Image Codecs in Chromium https://microsoftedge.github.io/edgevr/posts/Rustifying-Image-Codecs-in-Chromium/