2.8K Followers
171 Following
209 Posts
Unix Berzerker, Pundit on Risky Business, and retired hacker con organiser (Kiwicon!). Would enjoy the cloud future more if AWS was just one big Solaris box, and we could hilari-shell it via SunRPC. 
Was @metlstorm on Twitter.
Vulnerability Disclosure: JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat – Insinuator.net

As an older tech person, it's legit heartwarming watching the TikTok generation discover why we all hate Oracle.

RE: https://cyberplace.social/@GossiTheDog/115929393014353710

/me blinks

Wait what year is it again?!

I wish watchTowr Labs was on mastodon, their blog posts are always amazing.
Today's about a Fortinet vulnerability:
https://labs.watchtowr.com/should-security-solutions-be-secure-maybe-were-all-wrong-fortinet-fortisiem-pre-auth-command-injection-cve-2025-25256/
Should Security Solutions Be Secure? Maybe We're All Wrong - Fortinet FortiSIEM Pre-Auth Command Injection (CVE-2025-25256)

It’s Friday, but we’re here today with unscheduled content - pushing our previously scheduled shenanigans to next week. Fortinet is no stranger to the watchTowr Labs research team. Today we’re looking at CVE-2025-25256 - a pre-authentication command injection in FortiSIEM that lets an attacker compromise an organization’

watchTowr Labs

https://lists.busybox.net/pipermail/busybox/2025-August/091665.html

I am happy to observe a 30-day embargo to coordinate with downstream distributions. Please let me know if you need more or less time.

🤦‍♀️

[SECURITY] busybox tar: TOCTOU symlink race overwrites arbitrary root file with --overwrite

In the highly unlikely case that @metlstorm or @riskybusiness haven't seen this...

The Apple Watch uses IPSec over Bluetooth?!?! That’s mildly horrifying but also a certain level of genius

https://arxiv.org/pdf/2507.07210