371 Followers
162 Following
311 Posts
CEO of Secfault Security, looks like a cliché hacker according to Halvar Flake
Companyhttps://secfault-security.com
Birdchanhttps://twitter.com/teh_gerg
Claude 'Jia Tan' Code

Bumsrakete being delivered to the corporate infosec world

#bumsrakete #infosec

Now I have seen it all - https://bumsrake.de/
BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.

BUMSRAKETE is a HUGE, TREMENDOUS, MANY-PEOPLE-ARE-SAYING FreeBSD kTLS-RX page-cache write primitive. The BEST primitive. Some say the best ever.

What idiot called it Go and not errlang?
Look into yourself and ask:

"Why am I still wearing pants?"
@greg @weirdunits @gsuberland Have you seen this series: https://www.youtube.com/watch?v=kkfIXUjkYqE ? (I'm so glad someone finally called out kWh!)
Cursed Units

YouTube
Our colleague @mal had another look at OpenOLAT and found a nice RCE (CVE-2026-28228 and CVE-2026-28228). If you're interested, details can be found on our blog https://secfault-security.com/blog/openolat-ssti.html
Secfault Security - OpenOlat - RCE via Server-side Template Injection (SSTI) and OIDC Auth Bypass

Has anyone tried getting a Windows 11 VM running with tpm 2.0 on #bhyve and #freebsd 15?
Just had a real positive experience with @hetzner customer service. Thanks a ton and keep up the good work!
Fritz Kola macht echt gutes Marketing. Sie schenken Getränke an Anti-G20 Proteste in Hamburg und sponsern den CDU Parteitag ohne dass sie viele Leute aufregen