launchdaemon

@launchdaemon@infosec.exchange
32 Followers
300 Following
173 Posts
Mostly interested in mobile security/ malware/ reversing, coffee and burritos.
Twitterhttps://twitter.com/launchdaemon

Some users report their Firefox browser is scoffing CPU power

https://www.theregister.com/2025/08/13/firefox_ai_scoffing_power/

You guessed it: looks like it's a so-called AI

<- by me on @theregister

Some users report their Firefox browser is scoffing CPU power

: You guessed it: looks like it's a so-called AI

The Register

Speculative plans in Terraform Cloud can open an attack path.🚨

On a Red Team engagement, we compromised a Terraform token with plan permissions. By adding a custom external data source, we ran code on the Terraform Cloud runner.

That exposed short-lived AWS and GCP credentials, letting us work outside the version control workflow.

Even VCS-backed workspaces do not stop this. The runner still holds the keys during a plan — and that is the risk.

Jack McBride explains the technique and how tighter token scopes and Sentinel allow lists can prevent it.

📌 https://www.pentestpartners.com/security-blog/terraform-token-abuse-speculative-plan/

#CloudSecurity #RedTeam #Terraform #CyberSecurity #DevSecOps #AWS #GCP

Did AI recommend this? In a new digital twist to environmental responsibility, the #UK government is now suggesting people to “Delete old emails and pictures” in data centres to help with the current drought 🤪

This country ... (no words)

https://www.gov.uk/government/news/national-drought-group-meets-to-address-nationally-significant-water-shortfall

Any technical solution that is supposed to block teenagers from anything is not going to work very well, because you are facing an opponent that:

* is smarter than you,
* is very dedicated,
* has a lot of free time,
* has an extensive network of friends,
* faces no serious consequences if caught,
* outnumbers you,
* considers you an immoral crook.

You really, *really* want to have them on your side. That means education rather than control.

OT: I get very annoyed at sites that have cookie plugins that require you to scroll down and down and down, manually rejecting each of the "legitimate interest" vendors sections.

What they call "legitimate interest" is often not my definition of "legitimate interest."

Please use a plugin with a "reject all" for non-essential cookies.

Maybe you think I'll just get tired of scrolling down and will just accept all. But I don't. If your site irritates me on cookies, I just leave.

#advertising #cookies #consent

Finally, a thorough answer and workaround for “why did Ctrl-C stop working in my Mac terminal even though Ctrl-G still works”! I’ve been running into this (infrequently) for years.

https://superuser.com/a/1909498

Ctrl-C not working on MacOS/Zsh

I have a similar problem to Ctrl-C Not working in zsh But it is not the stty setting or the key-bindings. It definitely happened in one terminal, while on others it works. I get: from stty: eol2 = ...

Super User

So this is how Newgrounds is apparently handling age verification RE: UK's Online Safety Act.

Their ultimate solution is... unique.

I noticed someone use ls, but there were icons in the output....? I realized later you could probably do that with dircolors and emoji, but I think that's GNU specific and they were on a mac... how did they do it? 🤔
JD Vance is vacationing soon in the Cotswalds and Scotland, where if there is any justice, no one will give him a break the entire time that shitbag is there in places he denigrated months earlier.