948 Followers
1.6K Following
2.5K Posts
zigzagging my way through cursed code and bugs
bloghttps://swap.gs
Lmao @Hacker0x01 told me the backdoor was known "through internal security assessments" and they're "closing this report as out of scope". But now are pissed I disclosed it. Nobody should use this joke of a platform who put the interests of companies over that of users.

Le programme du SSTIC 2026 a été publié: https://www.sstic.org/2026/programme/

#sstic #sstic2026

SSTIC2026 » Programme du 3 au 5 juin 2026

Looking for someone more articulate than me to discuss the felt "urge" to keep the machine (fuzzer, AI, etc) working; the pressure when the robots are blocked on the human engineer/operator; the stress that comes with it; the (imho very wrong) feeling that there’s a need to be responsive to the machines and how bad management might use it to weaken workers' rights.

Happy to discuss in English or German, but preferably not over social media, because it lacks nuance and context :)

Okay these "Background Security Improvements" are definitely worse than RSRs. They show up at random times in your Settings app, and if you tap anywhere else, they disappear immediately. You can find them again, but they're not under Software Updates where they should be, but under Privacy & Security > Background Security Improvements, which also does not seem to show up in search.

EDIT: HOLY SHIT I have to enable "Automatically Install" in order to even be allowed to download them MANUALLY?! And there's no progress indicator either?? Whoever approved this should be hurled into the sea.

speak next week friends
[RSS] Streamlining Google's OSS VRP: Key Rule Updates

https://bughunters.google.com/blog/ossvrp-rule-updates-2026
Blog: Streamlining Google’s OSS VRP: Key Rule Updates

Read about our updates to the OSS VRP rules which are designed to help us filter out low-quality reports and focus on real-world impact.

just learned that my colleagues rotate VS Code by 1 degree when you leave your laptop unattended

Hey internet. I'm hiring for a vuln researcher/exploit dev/hacker type.

US preferred, UK okay.

Reports to me, in the research engineering team at @runZeroInc.

HMU if you're interested, and then fill out the thing. If you use a name different from the one I know you as, please be clear about that so I can tag the (internal) recruiter with that info.

Listing:

https://www.runzero.com/about/careers/apply/?gh_jid=5829740004

Apply

runZero
Attending #Insomnihack this week? Don't miss our researcher @pspaul breaking down various unsafe patterns attackers can abuse to compromise your GitHub Actions workflows!

Best damn hacking video in decades and it's my dude, Mr @joegrand

https://www.youtube.com/watch?v=MhJoJRqJ0Wc

$75,000,000 Crypto Wallet Bulk Hack

YouTube