Harry Sintonen
harrysintonen@infosec.exchange
<p>Infosec consultant at REVƎЯSEC <a href="https://reversec.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">reversec.com</span><span class="invisible"></span></a> - Coding, Research + various other interests</p>
Posts
-
Post #4465792
It appears that AI companies target open source contributors with their marketing spam: "we noticed you contributed to curl/curl — thanks for helping build open source. We're running a small program for Github OSS contributors and would love to invite you. You'll receive $25 in XXXXXXXXX credits to use frontier AI models (this time YYYYY) through a single OpenAI-compatible endpoint." #enshittification
-
Post #4422491
Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape" https://www.openwall.com/lists/oss-security/2026/08/06/3 #CVE_2026_64564 #infosec #cybersecurity
-
Post #4384247
"As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled" 🤦♂️ What exactly did they expect would happen when following such policy? ref: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
-
Post #4383767
"Embargo klo 01:00" ja juttu julkaistu 00:01 - nyt ei kai ihan mennyt niin kuin suunniteltiin. #yleisradio
-
Post #4382803
#Engadget, yes we do have a reason not to watch #Babylon5 from YouTube.
-
Post #4371192
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights: - CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI. - CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). - CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split. - CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check....
-
Post #4352100
Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ #nablencentral #CVE_2026_18577 #infosec #cybersecurity
-
Post #4328493
40 years of #Byterapers: 1986: https://www.youtube.com/watch?v=txaIWaT6zik 2026: https://www.youtube.com/watch?v=TmwjZ33ID5k (Assembly 2026 #democompetition winner) Congratulations on continuing to be awesome! #demoscene
-
Post #4276425
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old. Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream. Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong. I've now reported the issue upstream, which will hopefully eventually lea...
-
Post #4193535
No, the libssh2 vulnerability CVE-2026-55200 isn't end of the world. 1. You need to defeat ASLR to successfully exploit it. The PoC works only when you disable ASLR. In most realistic use cases you need additional off-band infoleak from the app using libssh2. 2. You also must somehow convince the victim to connect to your malicious server, OR compromise some existing server to perform the attack. Calling this a "CRITICAL VULNERABILITY" is dumb.
-
Post #4085374
Back when the "internet" involved expensive phone calls and modems, someone figured out that a video backup system (VBS) could be used to distribute hundreds of megabytes of "backups" between friends by shipping a VHS cassette in a padded envelope. You just needed a VCR (everyone had one), and a small harness that could sample the video signal from the VCR for the software to decode. Interestingly, the Video Backup System website is still up: http://www.hugolyppens.com/VBS....
-
Post #4068323
13 2026-07-24 16:23:31 +0000 error: Corrected error, no action required., CPU 2, bank Unified Memory Controller (bank=17), mcg mcgstatus=0, mci CECC, mca DRAM ECC error. Ext Err Code: 0 Memory Error 'mem-tx: generic read, tx: generic, level: L3/generic', memory_channel=0,csrow=0, mcgcap=0x0000011c, status=0x9c2041000000011b, addr=0x72fb55480, misc=0xd01a000101000000, walltime=0x6a639183, cpuid=0x00a20f10, bank=0x00000011, microcode=0x0a201030 #ECCMemory saving the day.
-
Post #4017660
#openai #huggingface
-
Post #3883160
VESA Monitor Control Command Set (MCCS) standard "Asset Tag" function has a gaping flaw. The key is 16-bit and there is no rate limiting. 🤦♂️
-
Post #3855661
#Amazon #CloudFront seems to having global issues. https://health.aws.amazon.com/health/status
-
Post #3675985
I've started to outright block accounts posting AI slop or parroting AI company PR statements. Life is too short.
- Post #3613426
-
Post #3516486
Risto Mikael Riihimäki, owner of Rent ja Kalusto Oy, has been sentenced to three years and 8 months in prison for a aggravated regulatory offence. The company delivered 135 trucks and 29 trailers to Russia, circumventing the EU sanctions. In court, the company claimed that the items were destined for Kazakhstan or Turkey, but Finnish officials were able to recover the communications between Riihimäki and his Russian contacts, making it clear where the items were really destined. The company was...
-
Post #3452534
I hate it when I'm right about these things. https://www.euronews.com/my-europe/2026/06/26/eu-countries-move-to-revive-temporary-message-scanning-regime-but-it-could-backfire https://infosec.exchange/@harrysintonen/115383111569608066 #stopchatcontrol #privacy
-
Post #3365073
I have consistently refused to engage AI in any tasks that require mental effort. Intuitively, I felt that it leads to laziness and eventual deterioration of problem-solving skills. I still consistently challenge myself by solving already solved problems - not because they haven't been solved well already - but in order to maintain my skills. I can only recommend this approach. https://www.nature.com/articles/d41586-026-01947-1
-
Post #3349195
Heads up to anyone using #AMD CPUs in a setting where Transparent Secure Memory Encryption (TSME) is critical: AMD has disabled this feature for consumer AMD products as of the latest AGESA updates. The feature is now only available for "PRO" CPU variants. https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/ #enshittification
-
Post #3251060
I, for one, hail our EU overlords for staying their ground and not bending over to Apple. This EU regulation did not come as a surprise to anyone, and definitely not to Apple. Yet they decided to go all knee-jerky about it. Food for thought: If you cannot implement an AI feature in an interoperable and safe manner, it likely should not be implemented at all.
-
Post #3238298
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions. #CVE_2026_45447
-
Post #2505356
As it happens, we still use CVS in our operating system project (there are reasons for doing this, but migration to git would indeed make sense). While working on our project, we occasionally have to do a full checkout of the whole codebase, which is several gigabytes. Over time, this operation has gotten very, very, very slow - I mean &quot;2+ hours to perform a checkout&quot; slow. This was getting quite ridiculous. Even though it&#39;s CVS, it shouldn&#39;t crawl like this....
-
Post #2396563
Vulnerabilities found from #curl: #Mythos: 1 Me: 30 - https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ - https://sintonen.fi/advisories/
-
Post #2359118
I&#39;ve tried to report a security vulnerability to @signalapp for months now (first attempt was 2025-11-23 to the official security-at email address). I haven&#39;t gotten any response from them, even after repeated attempts. This is highly frustrating. Is there a way to reach them? I don&#39;t need any kind of special treatment, just someone acknowledging that the message has been received would be okay. #signalapp
-
Post #2173502
Several vulnerabilities in #Apache HTTP Server 2.4 have been fixed in release 2.4.67. The most severe of these are: - CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset - CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr - CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack https://httpd.apache.org/security/vulnerabilities_24.html #CVE_2026_23918 #CVE_2026_24072 #CVE_2026_33006 #infosec #cybersecurity
-
Post #1930994
Los Alamos nuclear secrets &quot;leaked&quot; in LGP-21 magnetic disk memory: https://www.youtube.com/watch?v=IBjh0SaA5dc I guess securely wiping storage media wasn&#39;t a thing eh? #retrocomputing #usagielectric
-
Post #1898725
You can soon travel to Finland over rail - &quot;Finland gains direct rail link to Europe this summer&quot; https://yle.fi/a/74-20220038 (in english) The track gauge in Finland is still different to European standard though, so passengers are required to change trains in Haparanda. #railway #traintravel
-
Post #1835973
Reminder to anyone using #ApacheCamel SCP/SFTP connections: Apache Camel does not perform host identity validation unless you explicitly configure &quot;StrictHostKeyChecking&quot; as &quot;yes&quot;. The default value for &quot;StrictHostKeyChecking&quot; is &quot;no&quot;. If you do not explicitly configure this option as &quot;yes&quot;, the connections are susceptible to meddler in the middle attacks. What is the impact of such insecure configuration?...