36 Followers
59 Following
212 Posts
Bit-slinger, information addict. I toot mainly about mobile sec, RE & exploit dev. 'I am the 😼 who walks by himself, and all places are alike to me.'
Fair warning: I do use my mastodon instance to bookmark pages.
Bloghttps://heapspray.io/
Wieso heisst es "Backlog Grooming" und nicht "Doom Scrolling"?
And now @ipolit and @_az0x_ will show how to use #radare2 searching crypto-related stuff
#r2con2024
A lot of people are suddenly realizing that their orgs or communities need digital security and privacy training. If you are a person with a technical or teaching background and you think you might be the right person to give such a training, you should check out the Security Education Companion for teaching materials and tips: https://www.securityeducationcompanion.org/

So it was "just" #CUPSD #Evilsocket found #RCE in.
Interesting work, but not the shocker announced.

https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

Attacking UNIX Systems via CUPS, Part I

Hello friends, this is the first of two, possibly three (if and when I have time to finish the Windows research) writeups. We will start with targeting GNU/Linux systems with an RCE. As someone who’s

evilsocket
Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk

SolarWinds issues an urgent patch for a critical Web Help Desk vulnerability. Update now to protect against unauthorized remote access.

The Hacker News

Vulnerabilities in Atlassian Products (CERT-EU Security Advisory 2024-021)

On February 20, 2024, Atlassian released a security advisory addressing a high severity vulnerability in Confluence Data Center and Confluence Server that, if exploited, could allow an authenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser. The security advisory also addresses 10 other high severity vulnerabilities which have been fixed in new versions of several Atlassian products.

https://www.cert.europa.eu/publications/security-advisories/2024-021/

Vulnerabilities in Atlassian Products

Vulnerabilities in Atlassian Products

34 years later, a 13-year-old hits the NES Tetris “kill screen” https://arstechnica.com/?p=1993353
34 years later, a 13-year-old hits the NES Tetris “kill screen”

BlueScuti forces the game to crash after 40 minutes and 1,511 lines.

Ars Technica
"Design is invisible..."

▪ [ 4-7 décembre 2023 ] « 🇬🇧 Black Hat Europe (blackhat.com) » -- 🐘​ @[email protected] #europe #uk
▪ [ 8 décembre 2023 ] « 🇺🇸 BSides Philadelphia (bsidesphilly.org) » -- 🐘​ @bsidesphilly #usa
▪ [ 12-14 janvier 2024 ] « 🇺🇸 ShmooCon (shmoocon.org) » -- 🐘​ @ShmooCon #usa
▪ [ 16-17 janvier 2024 ] « 🇺🇸 CactusCon (cactuscon.com) » -- 🐘​ @cactuscon #usa
▪ [ 12 mars 2024 ] « 🇫🇷 JSSI (ossir.org) » -- 🐘​ @ossir #france
▪ [ 25-27 mars 2024 ] « 🇺🇸 VulnCon (first.org) » -- 🐘​ @firstdotorg #usa
▪ [ 4-5 avril 2024 ] « 🇫🇷 THCon (thcon.party) » #france
▪ [ 15-17 avril 2024 ] « 🇩🇪 FIRST-CTI (first.org) » -- 🐘​ @firstdotorg #germany #allemagne
▪ [ 22-26 avril 2024 ] « 🇨🇭 Insomni'hack (insomnihack.ch) » #switzerland #suisse
▪ [ 23-26 avril 2024 ] « 🇫🇷 Botconf (botconf.eu) » -- 🐘​ @botconf #france
▪ [ 27 avril 2024 ] « 🇺🇸 BSides Seattle (bsidesseattle.com) » -- 🐘​ @bsidesseattle #usa
▪ [ 24 mai 2024 ] « 🇫🇷 Sthack (sthack.fr) » #france
▪ [ 5-7 juin 2024 ] « 🇫🇷 SSTIC (sstic.org) » -- 🐘​ @sstic #france
▪ [ 3-5 juillet 2024 ] « 🇫🇷 Pass the SALT (pass-the-salt.org) » -- 🐘​ @passthesaltcon #france
▪ [ 22-25 octobre 2024 ] « 🇱🇺 hack.lu (hack.lu) » -- 🐘​ @hack_lu #luxembourg
▪ [ 2-4 novembre 2024 ] « 🇮🇪 Virus Bulletin Conference (virusbulletin.com) » -- 🐘​ @VirusBulletin
▪ [ 15 novembre 2024 ] « 🇫🇷 GreHack (grehack.fr) » #france
▪ [ ? mai 2025 ] « 🇺🇸 THOTCON (thotcon.org) » -- 🐘​ @thotcon #usa

(。◕‿‿◕。) Thank you, Xavier

#informatique

Xavier «X» Santolaria :verified_paw: :donor: (@[email protected])

📆 Your #infosec events for the remainder of the year, and some already planned and listed for 2024! ✈️ 🥳 Upcoming in December, @[email protected] @bsidesphilly #cybersecurityoutlook https://github.com/xsa/infosec-events/

Infosec Exchange

Look how beautiful it is!!! This is Professor Simon, the trophy for future winners of the CTF!

Designed, printed, sanded, assembled, painted meticulously by @r00tbsd

The antennas are articulated

Can't wait to win now, can you? Just need the brains! ;-)
#capitaineflam #CTF #IoT