Will Dormann
wdormann@infosec.exchange
<p>I play with vulnerabilities and exploits. <br />I used to be <a href="https://twitter.com/wdormann" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">twitter.com/wdormann</span><span class="invisible"></span></a> but Twitter has become unbearable, so here I am.</p>
Posts
-
Post #4455906
Washington Post editor: Maybe we should find a picture of Susan Collins where the fotographer's finger isn't partly covering the camera lens? Their boss: Just ship it.
-
Post #4423031
Over at the bad place, somebody mentioned a "BYOVD" attack that's happening in the wild that's going to be demonstrated at Defcon. We're not in Las Vegas, because all of that nonsense is silly. So let's look at what we've got. The Driver is on VirusTotal. It's made by MOCOMSYS & DRC. Its authentihash of 2a7ed8d0be70e0667aa14e161ae1dc6b7daaeb1438b534d73b1093c0b44d78a2 is (obviously) not on the Microsoft recommended driver block rules list, but it's a...
-
Post #4385182
So, uh, Bugtraq is back?
-
Post #4381715
Saw The Odyssey over the weekend. Was a pretty good example of the type of epic fantasy film. Several people I invited to come along backed out saying that they were waiting to see it on IMAX. Of course I had to be the person to bring up that the closest IMAX screen is 4.5 hours away. (Look up "LieMAX" if you want to read about the nonsense you've been led to believe) If you have an actual IMAX nearby, sure, go ahead and pop for it. If not, then just go see it on a normal scr...
-
Post #4379624
I'm old enough to remember when Google helped you find websites to go to. It was indeed better than HotBot, which was pretty decent. https://www.theringer.com/2026/08/04/tech/google-search-ai-internet
-
Post #4376142
Why would a deer get into tomatoes that are very clearly planted by me, for my own consumption, before they are ripe, bite into them, and then drop them on the ground. Is it an idiot? Or just an asshole? We'll see how this goes...
-
Post #4345241
Last's night entertainment: Puddles Pity Party and Weird Al. They were both spectacular.
-
Post #4344595
A purple tomatillo is apparently a tomatillo with a purple sunburn.
-
Post #4258194
Wiz found a master key that could access every database in Azure's Cosmos DB. #cosmosescape Whoops. https://nitter.net/yuvalavra/status/2082864672294736324
-
Post #4224719
Concern #1: There apparently aren't enough dogs for WeRateDogs to not have to recycle material. Concern #2: Ronnie clearly did something to raise his score from 12 to 13. ๐ค
-
Post #4221551
Apparently on Monday, Apple killed fG!'s bug With any system that has Screen Sharing enabled, it's reported that the vulnerability can allow for remote code execution as root. Apple lists no CVE with such a description. Closest is CVE-2026-43760, which is: An app may be able to access user-sensitive data The navi_the_clown PoC appears to only retrieve files from the target system (root-only is fine).
-
Post #4178808
Anthropic isn't even trying to hide the fact that they only know how to speak spin, with the sole intention of getting investors. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. A not-careful reader (or victim of the telephone game) might conclude that a new way to attack the most widely used symmetric cipher was identified. Round-reduced AES, as opposed to actual AES, isn't used in the real world. I didn't read the article beyon...
-
Post #4164507
Lots of vul collisions in the world of AI-driven vul discovery. Chart taken from a terrible place, so no attribution.
-
Post #4143441
iOS 26.6 is out, with fixes for 91 CVEs.
-
Post #4136122
Claude: Once a chat has been shared, anyone with the link can view the chat snapshot. The part Claude doesn't say out loud: When you generate a link, we share the link with search engines, so basically the whole world has the link. https://www.google.com/search?q=site%3Aclaude.ai%2Fpublic%2Fartifacts
-
Post #4051293
@ai6yr@m.ai6yr.org At some point in the future we will look back at the time when people cooked with open flame indoors with utter disbelief.
-
Post #4043382
Today's accomplishment: Code execution as NT AUTHORITY\SYSTEM, triggered by playing a music file on Windows. Local environment configuration by a non-admin user required, so this definitely isn't RCE. Just LPE. If MSRC requires me to provide a video of the exploit, that'll force my hand to drop 0day. ๐
-
Post #4020224
Looks like somebody [posted an exploit for CVE-2026-50522] (patched in July)(https://gist.githubusercontent.com/testanull/0868e02d81d57d6c59a91261969f7f81/raw/4d16304047e525057d732401f718e20fa830eb0a/SharePoint%2520SE%2520p2o%2520PoC.ps1) While I can reproduce it on SharePoint Subscription Edition, I didn't get it to work on SharePoint 2016 or 2019. But I could also attribute that to me having no clue how to properly install SharePoint. Here it is tweaked to run calc.exe as the SharePoint...
-
Post #4014304
Have you ever been on , and it decides to refresh what you see, potentially in a way that you'll never again see what you were just reading? Mastodon has got your back.
-
Post #4012628
AI news is exhausting. Huggingface : We tried to defend ourselves, but guardrails prevented us due to "cyber". So we used a Chinese model (Gee, who could have predicted this? ๐) OpenAI: Our models are so powerful, the world isn't ready for them yet (Wink to venture capitalists and government contract makers. ๐) I want off of this ride.
-
Post #3987551
I've been growing tomatoes for years, and today is the first I've heard about the "breaker stage". That is, once the blossom end of a tomato shows its first blush of color, that is the point that it should be harvested. Leaving it on the plant adds nothing to the flavor, encourages the plant to produce fewer tomatoes, and also increases the risk to the tomato on the vine. Is this common knowledge?
-
Post #3985983
Received to : Dear researcher, Our system cannot reach you via your email . Could you provide another email so that we can reply you officially via our system?
-
Post #3976778
I'm convinced that UI developers are my mortal enemies. Today's experience: Microsoft Outlook, which I have to assume is popular for some reason. I go to delete a calendar item that I created, but which has a problem. Upon hitting [Delete] on my keyboard, I'm presented with the following dialog. Which button will continue with the deletion of the item: [โก๏ธ Send][๐๏ธ Discard] If you selected the ๐๏ธ to delete the entry, you're a fool like me. Obviously the [โก๏ธ Send] button is the o...
-
Post #3961481
The repo is about 2 weeks old, and the vulnerability was patched in June. But there's a reliable public exploit for CVE-2026-42980 Per Microsoft, the vulnerability is in Windows NT. ๐คทโโ๏ธ
-
Post #3960607
If you want to attract bees, see if you can get your hands on some mountain mint. I've never seen any plant with more bees on it.
-
Post #3925168
In today's episode of Will doesn't understand why some films get universal acclaim: Project Hail Mary. Starts out Sci Fi, but somehow morphs into a buddy comedy (with an alien) for kids? Also, to go through pains to clearly show how the alien uses echolocation for vision, and then later on we're expected to completely forget that and just believe that it's watching computer screens and projections. How does that even happen? I get it that 3 hours is a long film, but shouldn...
-
Post #3921218
I didn't confirm it, but there's apparently a public exploit for wp2shell (CVE-2026-60137 and CVE-2026-63030) https://warez.sl0p.foo/wp2shell-fast/
-
Post #3897449
Microsoft released 4 new CVEs on Thursday. Maybe Tuesday was full? Thursday is close enough to Tuesday? Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability CVE-2026-56171Windows Backup Service Elevation of Privilege Vulnerability CVE-2026-58598Windows Admin Center Spoofing Vulnerability CVE-2026-58643Windows Terminal Remote Code Execution Vulnerability CVE-2026-59117
-
Post #3896732
If I theoretically have a way for a non-admin Windows user to be able to load an arbitrary already-on-system COM object library (InprocServer32) into a process that has system integrity, that could be argued to be a security boundary bypass. But in the essence of PoC||GTFO, does anybody have any ideas for how this might be useful to an attacker? i.e., is there an object that can be leveraged to lead to privileged code execution?
-
Post #3891903
Do not like.