151 Followers
139 Following
2.5K Posts

Just another Linux hacker

Constantly struggling to hide my affection of hacker subculture and memes behind the veil of corporate professionalism.
Father of 2, master of none.

Interested in #MotorSport, #F1, #VintageCars, #VideoGames, #InfoSec, #OpenHAB, #HomeAutomation, #Linux, #OSS.

Thoughts and opinions are my own.
I am not a bot (that I'm aware of).

I wrote a thing about a thing.

Specifically, Finding Vulnerabilities with Crassus – A Case Study with ESET.

I created Crassus on a whim a few years ago, and it's interesting to see that it still can find things.

It's also interesting (disappointing) that reporting vulnerabilities to vendors is still as painful as ever.

title text: This xkcd.com update introduces a variety of new reading modes which can be activated through the menu.

desktop link: https://xkcd.com/3227
mobile link: https://m.xkcd.com/3227
explainxkcd: https://www.explainxkcd.com/wiki/index.php/3227

"Many a frustrated user has sworn they'll launch Microsoft Outlook into space, but NASA has actually done it – on a journey around the Moon, where it's now causing problems for astronauts."

I know not everyone loves The Register, but the above paragraph is an example of why I've kept reading them for decades.

(from https://www.theregister.com/2026/04/02/artemis_astronauts_microsoft_outlook_broken/)

Artemis II astronaut: 'I have two Microsoft Outlooks, and neither one of those are working'

: In space no one can hear you scream, at Microsoft

The Register

LinkedIn Is Illegally Searching Your Computer. Microsoft is running one of the largest corporate espionage operations in modern history https://browsergate.eu/

Is there anything Microsoft is not doing these days?

LinkedIn Is Illegally Searching Your Computer

Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm. The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.

BrowserGate
Probably going to get a viral blog out of this experience, I'm trying to report a 4tb exposed cloud bucket to a company using their responsible disclosure programme... but they replaced the people with a GenAI ticket system that refuses to discuss the case as it thinks exploring open buckets is unethical and against its rules.

OK. This is cool. Keeping this open in a tab until they’re back.

https://artemistracker.com/
#nasa #artemis

Artemis II Mission Tracker

🚀 2 days until Artemis II launch window opens! Track NASA's mission to the Moon in real-time 3D. Launch: Apr 1, 2026.

Artemis Tracker
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud https://isc.sans.edu/diary/32856
Close enough.