89 Followers
75 Following
252 Posts
Cybersecurity "professional" at some well known software company that I do not speak on behalf of.
Websitehttps://www.maclaren.dev

Feeling old. I remember when wifi was hard, hardware was rare, and it seemed like we’d all be building cyberpunk-as-heck mesh networks on openWRT to get around corporate ISPs.

Now hardware is cheap and ubiquitous but we get a particular company’s WiFi solution (Unifi with a controller box and wired backhaul for me) and big corporate entity as fiber ISP because it’s relatively cheap internet.

Microsoft Office 2016 and Office 2019 are no longer receiving software updates, technical support, or bug and security fixes.

Consider migrating to LibreOffice.

Microsoft recommends migrating to a Microsoft 365 subscription.

LibreOffice supports the features that a majority of users need for free.

Website: https://www.libreoffice.org
Mastodon: @libreoffice

4/4

#Microsoft #Office2016 #Office2019 #Office #LibreOffice #Privacy #InfoSec #CyberSecurity #Encryption #FOSS #FreeSoftware #OpenSource

Are you a dumbass like me that has long-lived Kali Linux VMs and used the default partition scheme?

https://www.maclaren.dev/posts/2025-12/bootful/ might be useful for you if you've also had to troubleshoot kernel panics on startup because your boot partition ran out of space...

Troubleshooting a small boot partition

This one will be quick Recently stumbled across an interesting problem… Against recommendations I have multiple long-lived Kali Linux VMs. I use these for CTFs as well as general security research and my day job, so having them always available and set up the way I want is quite valuable to me. This, of course, means I also need to keep them updated. As I update these VMs I of course get updated packages, but I also get updated kernels.

In this blog post, we detail newly discovered authentication bypass vulnerabilities in the ruby-saml library used for single sign-on (SSO) via SAML on the service provider (application) side. Users of ruby-saml should update immediately to version 1.18.0.

https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials

Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

The GitHub Blog

If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292).

https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials

Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

The GitHub Blog
Nice.

$NEWJOB is very exciting but holy shit am I exhausted. Learning so much, so quickly!

To quote the great Z. Brannigan - "The spirit is willing but the flesh is spongy and bruised."

My dog is farting while dream-running and it is awful.