Writing is thinking.
It's not some marginal boring task you can skip. It's the heart of it.
Writing is thinking.
It's not some marginal boring task you can skip. It's the heart of it.
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js
securitylabs.datadoghq.com/articles/cve...
JudΓ€ische Volksfront.gif
initblog.com/2025/abrt-ro...
Great read about exploiting a limited command injection!
WSL stands for Worcestershire Sauce for Linux,
comparison between apple's finder icon and mine. apple's is the split blue and white smiley face, mine is two blue and white anime girls making out
comparison between discord's icon and mine. mine is like a screaming cat on a blue/purple slimy background
comparison between celsys's clip studio paint icon and mine. mine is similar but rotated with some comic styling and pink and blue highlights
comparison between mozilla's firefox icon and mine. mine is similar but looks closer to the old firefox icon and brings back the little arm and gives the fox a cute little smiley face
last week i remembered that macOS lets you set your own icons and that *I* have the power to delegitimize the professionalism of the software that runs on my machine, so here's a thread of the 16 new icons i've made so far
i really forgot how fun it was to just sit down and make art for myself :')
Must-read for fuzzing folks (read: tooling/algorithms/academia) by Addison Crump
addisoncrump.info/research/wha...
Interesting article on the sustainability and profitability of AI companies.
www.wheresyoured.at/costs/
Tldr: they aren't.
It will be interesting to see how Cursor and GH Co-pilot fair over the coming months.
a browser that refuses to connect to websites unless it's hosted on us-east-1
We're updating our bounty program with the top award now set at $2 million for zero-click remote exploit chains. In addition - there are increased awards for proximate wireless attacks, WebKit, and Gatekeeper
security.apple.com/blog/apple...
One the craziest elements about cybersecurity is you have half the industry sat worrying about cyberwar!1! and going on about quantum and AI, then you have you have the operational reality of what is actually happening on the ground - it bares no resemblance, at all, to what people are focused on.
Gebt den Sondierungen noch zwei Wochen und Markus SΓΆder baut uns allen kiffend ne WΓ€rmepumpe ein.
There are two wolves inside of you. If the first acquires lock A and the second acquires lock B, and then the first attempts to acquire lock B while the first attempts to acquire lock A, they will deadlock. Teach your wolves concurrency.
CVSS is dead to us
https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/
#curl
The OSS-Fuzz team is hiring a PhD intern for this summer. Come join us and build something interesting that will have immediate impact on 1000+ open source projects.
www.google.com/about/career...
Also reach out if you have already applied!
r2ai solves my CrackMe in a few seconds. The solution is both elegant and educational.
cryptax.medium.com/cracking-my-...
+ recommended view: www.youtube.com/watch?v=UxE5...
#r2con #radare2 #ai #crackme #ctf
(please re-post for reach - thank you!)
Learned a cool new Linux trick? Know an interesting quirk in a network protocol? Or have something else to share?
Write a 1-page article for the #6 issue of Paged Out! :)
pagedout.institute?page=cfp.php
Soft deadline is Feb 1st.
I am convinced 99% of websites should use magic links + passkeys.
It bypasses all (debatable) portability objections to passkeys, itβs at least as secure as email-based recovery, as fast as a password manager, itβs available to all usersβ¦ and importantly, no passwords!
just a friendly reminder that mars colonization is 100% science fiction.
take mount everest, stack four more mountains of equal size on top of it, and then try to live there.
itβs absolute nonsense.
I got a remarkable for that. Works decently ok.
"The two companies reportedly signed an agreement last year stating OpenAI has only achieved AGI when it develops AI systems that can generate at least $100 billion in profits."
"AGI is when I have heaps of money," is one hell of a position.
techcrunch.com/2024/12/26/m...
I keep putting off my blog post on "random" but I generally feel that platform and SDK developers are failing their users by not using a CSPRNG by default, everywhere.
True crazy real story. Maybe 2019, we had a C Suite exec hacked, threats, etc. All traced back to a car the guy synced his phone with. In Iceland.