Mickaël Salaün

@l0kod
292 Followers
162 Following
170 Posts

"Arbitrary File Read via file:// Protocol in cURL"

Well, you see... 🤦‍♂️

📣 The schedule for All Systems Go! 2025 is now live. https://cfp.all-systems-go.io/all-systems-go-2025/schedule/
🗣️ We look forward to hear from all the great speakers on Sept 30th-Oct. 1st.
🎟️ Grab your tickets to join in: https://ti.to/all-systems-go/all-systems-go-2025
ℹ️ Get more info here: https://all-systems-go.io/
All Systems Go! 2025

Schedule, talks and talk submissions for All Systems Go! 2025

OVER x SLIDES & VIDEOS

📣 #pts25 is now over, thanks so much to our speakers and attendees for their kindness and generosity 🙏

🚨 As always, due to the fantastic job of the team 🔥, you can browse/follow *all* talks:

📖 Slides: https://archives.pass-the-salt.org/Pass%20the%20SALT/2025/slides/
🎦 Videos : https://passthesalt.ubicast.tv/channels/#2025

Thanks again & we wish you a fantastic summer ❤️ 😎

🐧 📺 The videos from Linux Security Summit North America (LSS-NA) 2025 are now up on Youtube!

https://youtube.com/playlist?list=PLbzoR-pLrL6pAblvRXHaIYY0VE6ZjObV9&si=tHJlbUMfhM3uHVqI
Before you continue to YouTube

Just for future reference and if anyone is curious: the seventeen AI slop security reports submitted to #curl (so far):

https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d1cd

Maybe this will come handy.

AI slop security reports submitted to curl

AI slop security reports submitted to curl. GitHub Gist: instantly share code, notes, and snippets.

Gist

If you're attending the Linux Security Summit in Europe this year, don't miss the talk from @l0kod on the long journey to supporting code integrity in dynamic runtimes!

https://lsseu2025.sched.com/event/25GEQ

Background on the Kernel support for this that just recently merged: https://docs.kernel.org/userspace-api/check_exec.html

Linux Security Summit Europe 2025: Script Integrity - Mickaël Salaün, Micro...

View more about this event at Linux Security Summit Europe 2025

📢 🐧 🇪🇺 The schedule for Linux Security Summit Europe (LSS-EU) 2025 is now up:

🏰 https://events.linuxfoundation.org/linux-security-summit-europe/program/schedule/

LSS-EU will be co-located with OSS-EU in Amsterdam, NL, on 28-29 August 2025.

For more information, see:

🏤 https://events.linuxfoundation.org/linux-security-summit-europe/

#linux #security #linuxfoundation #linuxsecuritysummit
Schedule | LF Events

28 – 29 August 2025 Please note: All sessions are in Central European Summer Time (CEST / UTC+2). To view the schedule at your preferred time, please choose your location on the right-hand navigation…

LF Events

TIL that because the FFmpeg project has gained so much experience in hand-writing assembly code to provide huge speedups, they now are putting together a series of lessons for learning assembly:

Vibe coding is fun and all, but this is probably a better use of time!

https://github.com/FFmpeg/asm-lessons

GitHub - FFmpeg/asm-lessons: FFMPEG Assembly Language Lessons

FFMPEG Assembly Language Lessons. Contribute to FFmpeg/asm-lessons development by creating an account on GitHub.

GitHub

New blog post (about an old exploit): tachy0n.

For iOS 13.0-13.5, dropped as an 0day at the time.

https://blog.siguza.net/tachy0n/

Siguza’s Blog

Siguza’s Blog

Siguza’s Blog
I just published the fifth #Landlock newsletter! 🤓
- new kernel features: IPC scoping and audit logs
- kernel fixes
- library and talk updates
- new doc
- new open source Landlock users
- RHEL support
https://lore.kernel.org/landlock/20250519.ceihohf6a3uT@digikod.net/
Making sure you're not a bot!