Elektrine lite

← Feed

Dr. Christopher Kunz

christopherkunz@chaos.social

<p>Security (web, infra, app) nerd, has accepted that VR will never be a mass market, writer @heise Security
<br />All toots are IMHO &amp; not my employer&#39;s opinion. <br />PGP fingerprint: C882 8ED1 7DD1 9011 C088  EA50 5CFA 2EEB 397A CAC1</p>

Posts

  • Post #3858226

    So apparently Mindgard reported a trivial RCE in Cursor (if a repo opened by Cursor includes a git.exe file, that file is executed) in December 2025 (!) via HackerOne, and getting Cursor&#39;s attention required calling them out on LinkedIn. They ghosted Mindgard, prompting them to disclose. This is a 7-month window for attackers. Coordinated Disclosure is dead. Let&#39;s switch back to FD. Who owns securityfocus.com these days? https://mindgard.ai/blog/cursor-0day-when-full-disclosure-become...

  • Post #3826412

    &quot;Software-Update Ursache von IT-Problemen der Berliner Justiz&quot;, titeln wir in der Meldung zum gestrigen Ausfall. Das Update wurde &quot;zurückgenommen&quot;, lässt die Berliner Justizverwaltung mitteilen. Gleichzeitig behebt Microsoft im heutigen Patch 621 CVEs. Cherrypicking bei Updates und selektiver Rollback, weil Legacy-Software nicht mit einem Update klarkommt, wird künftig schlicht nicht mehr funktionieren. Das ist ein simples Rechenexempel. Digitale Resilienz muss bei Update...

  • Post #3805623

    RE: https://chaos.social/@Lilith/116917560042690115 Vor allem, weil &quot;Responsible Disclosure&quot; ein guilt tripping beinhaltet, wie es nur ein Kampfbegriff aus Redmond tun kann...

  • Post #3677068

    As it turns out, Aldi-Nord in Germany is offering mini air coolers (you know, like in this article: https://heise.de/-11346708) from tomorrow. Retail price: 12.99 EUR. Essentially the same device is marketed with aggressive ads for prices between 59.99 and 69.99 EUR (prices vary randomly) by shady businesses. This exact model is available on Alibaba for around 4.50 EUR (minimum order of 5,000) - so Aldi&#39;s still turning a profit, but not ripping customers off. I might even get one.

  • Post #3671532

    So it begins.

  • Post #3666586

    Ein weiterer Grund, warum man der Google-AI-Zusammenfassung kein Stück vertrauen darf: Sie befindet sich bei der Erkennung von Black Hat AIEO auf dem Stand, den SEO etwa im Jahr 2002 hatte. Exhibit A (2026, koloriert). Der angebliche Test ist natürlich Spam auf einer Domain, die sonst reichlich Potenzmittel und weiteren Kram &quot;testet&quot;. Way to go, Google. Way to go. *slow clap*

  • Post #3628348

    Well, this is fun. If you end up on one of the &quot;Airabreeze&quot; or &quot;Jetterix&quot; or the other products marketed by Commerce Core, UAB, and you start filling out the order form, entering an e-mail address or, gods forbid, a phone number, an XHR fires in the background, adding you to Commerce Core&#39;s (or Rara Digital&#39;s) CRM. I just received an e-mail reminder that I haven&#39;t finished my order - and I&#39;ll doubtlessly receive more spam soon. #jetterix #airabreeze #commerce...

  • Post #3622113

    DDosia&#39;s config today looks like the tour schedule for a music group that has seen better days. They&#39;re playing small venues all over Germany, shying away from the big stage.

  • Post #3552212

    Ich habe dem NDR ein paar Infos zu den Wunderkühlern gegeben und daraus wurde folgendes Stück: https://www.ndr.de/ratgeber/verbraucher/fake-klimaanlagen-zu-wucherpreisen-die-grosse-abzocke-bei-hitze,klimaanlagen-100.html

  • Post #3513704

    Der Verfassungsschutzbericht 2025 ist auch online. Man kann da auch schön das Framing mittels toxischer Rhetorik erkennen. Dobrindts Vorwort nennt erst den Linksextremismus und dann &quot;Daneben bleibt der Rechtsextremismus die größte Bedrohung für unsere freiheitliche demokratische Grundordnung.&quot; Das erweckt den Eindruck, dass der Linksextremismus eine ähnlich große Bedrohung der FGDO sei wie der von rechts. Dem ist aber nicht so, wie die Zahlen zeigen. 1/2

  • Post #3510784

    Die Innenministerkonferenz will Indymedia komplett verbieten. Weil wir als Gesellschaft derzeit keine drängenderen Extremismus-Probleme haben. In 85 Seiten der Beschlusssammlung wird kein einziges Mal das Wort &quot;rechtsextrem&quot; erwähnt. Die haben im wahrsten Sinne des Wortes die Schüsse nicht gehört. https://www.innenministerkonferenz.de/IMK/DE/termine/to-beschluesse/2026-06-19_DOK/Freie_Beschl%C3%BCsse.pdf?__blob=publicationFile&amp;v=1

  • Post #3491596

    So this kind of flew under my radar during the hot weekend. It seems that one of the two owners of Mullvad made a € 450K donation to the Örebro party, a populist party with a strong &quot;Sweden for the Swedes&quot; &amp; &quot;we support remigration&quot; sentiment. https://www.flamman.se/techprofil-ger-miljoner-till-orebropartiet/ I&#39;m a little wary of VPN providers supporting populist orgs, to put it diplomatically. I&#39;m wondering if someone has more clue on this party, and their connec...

  • Post #3487167

    Chip hat sich, na sagen wir mal, von meiner kürzlichen Berichterstattung zur Midea Portasplit und zu den Fake-Klimageräten &quot;inspirieren&quot; lassen, im oberen Teil des Artikels aber noch was zu Fakeshops reingerührt. Naja, kann man machen. Die Screenshots zu der massiven Werbekampagne dieser &quot;Klimageräte&quot; sind allerdings extrem on point, die wirken total echt. Und bewegen sich. Und sind klickbar. Halt, warte...

  • Post #2915507

    Für den NDR Kiel habe ich eine Einordnung zum Datenabgriff beim Klinikdienstleister Unimed gegeben. https://www.ndr.de/nachrichten/schleswig-holstein/uksh-cyberangriff-mutmasslich-ein-erpressungsversuch,uksh-146.html

  • Post #2915506

    Na, das wird die Lage sicherlich entspannen. /s

  • Post #2915505

    Kundendienst-Deutsch, Lektion 12: Kundendienst: &amp;quot;Wir brauchen noch mehr Informationen: Tritt das Problem noch immer auf?&amp;quot; Deutsch: &amp;quot;Dieses Ticket kann die nächste Schicht bearbeiten.&amp;quot;

  • Post #2915504

    Flipper One is a chunky boi!

  • Post #2915503

    I wrote a thing about curl and the woefully underfunded open source universe: https://www.heise.de/en/opinion/Comment-Open-source-developers-are-working-themselves-sick-on-AI-bugs-11308553.html @bagder

  • Post #2396471

    Stellt sich heraus: Einem großen US-Techkonzern die Kontrolle über mobile Betriebssysteme UND Websuche UND Formular-Spamschutz anzuvertrauen, kann nach hinten losgehen. Who could have thought? Zum Glück vertrauen wir nicht einem anderen US-Techkonzern die Kontrolle über CDN UND dDoS-Schutz UND Bot-Schutz UND Formular-Spamschutz und Tunnel UND öffentliches DNS-Resolving an, weil: Das wäre ja total unsinnig! #werironiefindetdarfsiebehalten #krautfair

  • Post #2198381

    Sooo... is Copy Fail fixed in the current Debian kernel package? *squints* *squints harder* *gets prescription for reading glasses* *buys reading glasses* *misplaces reading glasses* ...yup. well hidden though.

  • Post #2162390

    OK, I&amp;#39;m officially locked in a time loop. CAs fuck up their stuff, we&amp;#39;re supposed to compile kernels ourselves for maximum security and there&amp;#39;s a new ProFTPd mod_sql vulnerability each week. It&amp;#39;s Groundhog Day again...

  • Post #2148442

    Wenn ihr aus gegebenem Anlass mehr zu DNSSEC wissen wollt: Passwort Folge 37 geht tieeeef ins Detail (Gast: Peter Thomassen von deSEC). https://passwort.podigee.io/37-dnssec-die-dns-security-extensions

  • Post #2119356

    Dass ich im Bayrischen Rundfunk mal Julia Klöckner verteidigen würde, hatte ich nicht auf meiner 2026er Bingokarte. Und doch tat ich es gestern - um den &amp;quot;Signal-Hack&amp;quot; ein wenig einzuordnen. Aus meiner Sicht wichtig: Selbst wenn es politisch opportun erscheint, &amp;quot;höhö die Doofe lässt sich phishen&amp;quot; zu machen, ist das unangebracht. Dass Shaming die Situation rund um Social Engineering verschlimmert, ist schließlich sattsam bekannt. https://www.br.de/nachrichten...

  • Post #2083523

    May the Fourth be with you! What better way to symbolize that... the Red Sun still prevails!

  • Post #2083518

    Good morning everyone! From today, it shall be known that the Red Sun did, in fact, prevail over DNSSEC resolution in the .de zone. This Windows LPE is now giving Liz Truss and her lettuce a run for their money.

  • Post #1812308

    Let&amp;#39;s start the week with a screenshot. The red sun still prevails #redsun #windows11 #lpe #exploit

  • Post #1808989

    April 28, 2026: The red sun still prevails. Not holding my breath for tomorrow, either. Interestingly enough, someone on Github remarked that BlueHammer and RedSun are essentially the same exploit primitive (&quot;Defender blindly follows NTFS Junctions&quot;), so they should be fixable in one big swoop. Alas, RedSun is not yet fixed. I&#39;m also curious if MSRC (seemingly, I didn&#39;t scour each single one of the dozens of LPEs) didn&#39;t give it an own CVE on purpose or by mistake.

  • Post #1286640

    RE: https://social.treehouse.systems/@grawity/116414674970480108 Huh, this is counterintuitive. I don&amp;#39;t really have a solution, but I admire the problem. My only guess would be that the document kind of considers the optical platform &amp;quot;immortal&amp;quot; and only considers uptimes of the layer 3 platforms. And if the DFs from the NREN to PoP A as well as PoP A&amp;#39;s infrastructure offer five 9&amp;#39;s, and there are only three nines at PoP B, reliability of solution 1 is...

  • Post #1286639

    This is how RedSun looks to Defender: It is detected as Virus:DOS/EICAR_Test_File and Defender fails to remove it. This is a Windows 11 system that was patched today.

  • Post #1286638

    Sehr schöner Artikel vom Kollegen Gleich zu den Kostenaspekten der persönlichen Energiewende. Ich habe seine Zahlen mit meiner eigenen Berechnung verglichen und das kommt sich (leider) gut aus. Allein für diesen Artikel lohnt sich ein heise+-Abo. https://www.heise.de/hintergrund/Private-Energiewende-fuer-Skeptiker-Praxisbericht-Wenn-es-nur-ums-Geld-geht-11247011.html