cynicalsecurity 

1.5K Followers
275 Following
9.2K Posts
IT Security, cynically aged. Maths. Some nukes. Four languages. Longing for Symbolics and Connection Machines. Keeper of Ancient Computing Lore. β’Ά
Butterflyplacehttps://bsky.app/profile/cynicalsecurity.bsky.social
Homepagehttp://arrigotriulzi.ch/
First 0day1986

i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with [email protected] or similar.

The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

#infosec

Maglev is canarying at AS8298 IPng Networks - yaay!

First screenshot is nginx-logtail, which aggregates up and slices trending information of all HTTP traffic.

Second screenshot is the vpp-maglev loadbalancer, which distributes (a fraction of) traffic from chbtl2, chlzn1, nlams1, frggh1 to nginx frontends

Third and fourth screenshot is observability with Prometheus and Grafana on how the system is behaving.

Look closely to see a restart of one nginx instance with siblings taking the load!

GCVE is not only designed for distributed vulnerability publication and correlation across multiple sources. It already provides automatic vulnerability classification capabilities through the broader Vulnerability-Lookup ecosystem. In particular, GCVE can rely on VL-AI to automatically estimate vulnerability severity from historical data, giving defenders an immediate first-pass assessment even when no manually curated score is yet available.

#gcve #cve #nist

πŸ”— https://gcve.eu/2026/04/17/automatic-vulnerability-intelligence/

Heads up from naddy@, "The [#OpenBSD] 7.9 release is approaching."

"[...] This is also your final chance to TEST packages before the release."

https://marc.info/?l=openbsd-ports&m=177655653514289&w=2

'Port commits now require approval' - MARC

Approaching 18 years next month that I submitted my first #OpenBSD port.. and it's #tmux​

https://marc.info/?l=openbsd-ports-cvs&m=121226747005033&w=2

'CVS: cvs.openbsd.org: ports' - MARC

NetBSD turns 33 this Sunday! 🚩

To celebrate 33 years of clean code, portability, and zero bloat, Challenging the rest of the fediverse to help hit this year's funding goals.

Also do drop a screenshot of your uptime, uname -a, or a pic of the weirdest hardware you've got running NetBSD right now. (RockPro64 NPF routers or Pi's hooked up to retro CRTs highly encouraged).

Throw some money at the developers keeping the real UNIX alive:

https://www.netbsd.org/donations/

#NetBSD #UNIX #RetroComputing #OpenSource #runbsd #FreeBSD #OpenBSD #Linux

Donations to The NetBSD Foundation

I think it's time for some #OpenBSD #79HYPE β€‹ 

After ~21 years, gcc 3.x has left the building, with the last remaining platform (OpenBSD/luna88k) ported to gcc4.

https://bsd.network/@brynet/115425313813361816

Jonathan Gray (jsg@) has updated the drm graphics drivers (inteldrm/radeondrm/amdgpu) in #OpenBSD 7.9 to Linux 6.18.y/6.18.22 from the 6.12.y longterm support version.

https://bsd.network/@brynet/116201960048161449

https://freshbsd.org/openbsd/src?q=drm&committer[]=jsg

OpenBSD now supports "Delayed hibernation" on amd64: After waiting a number of seconds (up to 24 hrs) the machine will wake from S0ix/S3 idle sleep/suspend and hibernate to disk.

https://bsd.network/@brynet/116217813921273057

The OpenBSD kernel gains a new "parking mutex".. inspired by WebKit.

https://bsd.network/@brynet/115503876824188865

A long standing ACPI issue (boot delay) that has plagued several Intel Mac models has been fixed by jcs@

https://bsd.network/@brynet/115602160298028722

OpenBSD's EFI bootloader now supports loading files from the ESP, making it easier to e.g: copy & bootstrap a ramdisk kernel.

https://bsd.network/@brynet/115630978565153559

Improved support for running OpenBSD as a guest VM on Apple Silicon machines under macOS.

https://bsd.network/@brynet/115899206016337373

OpenBSD/amd64 now supports SMP on up to 255 CPUs, such as on AMD Threadripper/EYPC.

https://bsd.network/@brynet/115899248487624689

OpenBSD iwx(4) now supports additional Intel AX211 WiFi 6/6E models, as well as 160MHz channel support! β€‹

https://bsd.network/@brynet/116210371257002339

https://bsd.network/@brynet/116319563256899912

Important security refinements to both pledge(2) and unveil(2), fixing several early design issues.

https://bsd.network/@brynet/116136000669207850

https://bsd.network/@brynet/116197240853794609

https://bsd.network/@brynet/116217472157803716

Plus lots more to see in 7.9! Stay tuned! β€‹β€‹

Bryan Steele :flan_beard: (@[email protected])

#OpenBSD/luna88k has been switched to gcc4! :flan_thumbs:​ And with that the last GCC3_ARCH is gone! Not with a bang but a whimper.. :flan_smile:​ https://marc.info/?l=openbsd-cvs&m=176124507027163&w=2 https://marc.info/?l=openbsd-cvs&m=176124650328448&w=2

BSD Network
@cynicalsecurity There are some more information in the commit message. https://marc.info/?l=openbsd-cvs&m=177628204122487&w=2
'CVS: cvs.openbsd.org: src' - MARC

Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations β€” but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

Without donor contact, these machines are useless. :(

I've upcycled ~1,000 older Macs, but T2 era machines will end that. It's controlling, creates e-waste, and will only get worse. #righttorepair matters β€” Apple couldn't care less.

I have to say the #OpenBSD patch 031ΒΉ is rather subtle… I wonder how it was discovered.

​

__
ΒΉ https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/031_pgrp.patch.sig