4Dgifts @4dgifts.bsky.social · 09/10/2025Reflective loading of an unsigned Windows driver. This may be useful for red teaming and game cheating, but also to reclaim ownership of your computering device. Yay, you don't need a cloud services account to do it! 030
Reposted by 4DgiftsQuarkslab @quarkslab.bsky.social · 23/09/2025BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪 However, with the right primitives, you can do much more. Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver. 👇 blog.quarkslab.com/exploiting-l... 011
Reposted by 4DgiftsTechCrunch @techcrunch.com · 07/09/2025It's not clear who cut the cables or why.techcrunch.comMicrosoft says Azure affected after cables cut in the Red Sea | TechCrunchIt's not clear who cut the cables or why. 03312
4Dgifts @4dgifts.bsky.social · 05/09/2025Reverse engineering of the patch for a (remote?) code execution vuln recently fixed by Apple, allegedly used in attacks ITW. They "improved bounds checking" at an infinite rate, from 0 to actually checking. This is the kind of simple bug that a fuzzer would catch so it is puzzling that it wasn't. 042
4Dgifts @4dgifts.bsky.social · 05/08/2025What kind of advise is "We don't know what is going on, disable your VPN server" ? Also a 0day is not "a security bug that was discovered and exploited before the vendor could patch the issue". 0day is a vuln that is not publicly known. A known vuln that the vendor did not care to patch isn't 0day. 175
4Dgifts @4dgifts.bsky.social · 06/06/202530+ years in cybersecurity and I still see these vendor-supported private 0day sharing clubs. Vendors that tilt the patch and later demand fair play. We have not learned anything from MAPP have we? 021
Reposted by 4DgiftsNora Bär @norabar.bsky.social · 28/05/2025😍Un equipo de la UBA se ubicó entre los 5 mejores (de más de 100) en el mundial de “satélites enlatados”👇en la final del proyecto CanSat, organizado por la Universidad Nacional de México, con un satélite del tamaño de una lata que ellos mismos diseñaron y fabricaron 👇 37132
Reposted by 4DgiftsMariano Absatz @el.baby · 17/05/2025"(...) esa línea de crédito es extorsiva, y mientras la mantengan siempre China va a poder extorsionar" En cambio, el crédito que el FMI por recomendación de los Estados Unidos le otorga a la Argentina... ¡Caramba! ¡qué coincidencia! 021
Reposted by 4DgiftsMariano Absatz @el.baby · 17/05/2025Estados Unidos en el rol del novio violento y golpeador recomendándole a la novia liberarse de las amigas que la bancan cada vez que la faja www.infobae.com/economia/202...infobae.comLa recomendación a Milei de un funcionario de Trump: “Mientras tenga el swap con China, Argentina no será libre”Mauricio Claver-Carone, enviado especial de Estado Unidos para América Latina, fue entrevistado en exclusiva por Infobae 201
4Dgifts @4dgifts.bsky.social · 10/05/2025This is *significantly* better than Johnny Mnemonic and yet much less known. Recommended! 030
Reposted by 4DgiftsJorge Aliaga @jorgeluisaliaga.bsky.social · 06/05/2025OJO con esta nota. El fondo fiduciario eliminado NO es el FONCYT, que no es un fondo fiduciario. El eliminado es el FONDOTEC, creado por la Ley N° 23.877, de 1990. El FONCYT se creó en 1996 con la @agenciaidiar www.pagina12.com.ar/823318-motos...pagina12.com.arMotosierra sin fin: el Gobierno eliminó definitivamente el FISU y el Fondo Fiduciario para la Promoción Científica | Luego de subejecutarlosEn una nueva muestra de su desprecio por las políticas públicas, el Gobierno de Javier Milei eliminó dos fondos fiduciarios clave: uno destinado a la ciencia y tecnología, y otro a la vivienda. Esta d... 031
Reposted by 4DgiftsEric Geller @ericjgeller.com · 30/04/2025Strange times: CISA employees this morning received a "workforce accountability survey" email requiring them to say whether they were on-site, teleworking, on leave, on travel, or no longer employed at CISA. Then a few hours later, they got another email saying "no response is needed." 33713
Reposted by 4DgiftsQuarkslab @quarkslab.bsky.social · 08/04/2025There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jérémy Jourdois explains it here: blog.quarkslab.com/aosp_ota_sig...blog.quarkslab.comA small bug in the signature verification of AOSP OTA packagesA signature verification bypass in a function that verifies the integrity of ZIP archives in the AOSP framework 045
4Dgifts @4dgifts.bsky.social · 28/03/2025PARA PARA PARA VOS ME ESTAS DICIENDO DE QUE PATRISSIA BULLREICH ES UNA ZURDA? 100
4Dgifts @4dgifts.bsky.social · 27/03/2025beware of how this plays out.. as in "we cannot do it unless a backdoor is installed..." etc 000
4Dgifts @4dgifts.bsky.social · 26/03/2025Agrego que cerraron estaciones d ela línea D durante 3 meses no de sabe para qué carajos. La frecuencia de trenes sigue siendo una mierda, esta llenos todo el tiempo y cada dos por tres se quedan parados varios minutos en los túneles. Solo hicieron boludeces cosméticas 100
Reposted by 4DgiftsChrononaut @chrononaut.bsky.social · 23/03/2025Pope Francis made a brief statement from the hospital balcony: 7279581121
4Dgifts @4dgifts.bsky.social · 17/03/2025Saw this on the other site but I should comment here: Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991. You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns 096
Reposted by 4DgiftsKatie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 17/03/2025Excellent Zoolander reference by @wdormann.bsky.social in his video. You know where to find us if you need help @msftsecresponse.bsky.social 🌺 @lutasecurity.bsky.social 🌺 2207
4Dgifts @4dgifts.bsky.social · 11/03/2025A deep dive into phishing I guess there is a pun in there but child[0|1] have banned dad jokes. sorry 000
Reposted by 4Dgiftsjosé b @melquiadess.bsky.social · 07/03/2025Hace meses la CoNaIn recomendó al gobierno adelantar el refuerzo de la triple viral para prevenir un brote de sarampión. No lo hicieron. No hay ninguna campaña oficial de difusión. Siguen sumándose casos confirmados de la enfermedad MÁS CONTAGIOSA QUE EXISTE, la mitad de los chicos no está vacunado. 23831
Reposted by 4Dgiftse.w. niedermeyer @niedermeyer.online · 07/03/2025Tesla somehow sold 8,600 new vehicles in a single weekend, just before Canada's federal EV rebate expired. Definitely no funny business going on here! Canadians just love Elon Musk, and all that he stands for! www.ctvnews.ca/video/2025/0...ctvnews.caCTV National News: A suspicious spike in Tesla sales in CanadaThere was a suspicious spike in Tesla sales in Canada ahead of the deadline for a federal rebate program for EVs. Adrian Ghobrial investigates. 2031459
4Dgifts @4dgifts.bsky.social · 06/03/2025Today is the 88th anniversary of the birth of one of the most courageous and inspiring women of our era. Happy Birthday Valentina! 040
Reposted by 4DgiftsJake Williams @malwarejake.bsky.social · 06/03/2025At this point, it feels like Altman is hallucinating more than his AI models... 4211
Reposted by 4DgiftsEvan Sutton @evansutton.bsky.social · 27/02/2025Air traffic controllers are required by law to retire at 56. It is a high-stress, high-intensity job that requires intense focus. The retirement rules are there to keep us all safe. This fucking guy has no clue what's he's doing. 447171154355
4Dgifts @4dgifts.bsky.social · 27/02/2025"This is the first all-female flight crew since Valentina Tereshkova’s solo spaceflight in 1963" Valentina will be 88 years old in a week. All of New Shepard's 11 minute rides to space put together come remotely close to what she did solo at 26. ❤️ Still inspiring! www.blueorigin.com/es-MX/news/n...blueorigin.comBlue Origin Announces Crew For New Shepard’s 31st Mission | Blue OriginNew Shepard’s 11th human flight, NS-31, will launch this spring with Aisha Bowe, Amanda Nguyen, Gayle King, Katy Perry, Kerianne Flynn, and Lauren Sánchez. 000
Reposted by 4Dgiftsℵ₁ @aleph1.underground.org · 27/02/2025RIP Gene Hackman. The Conversation (1974) is one of the best security movies. 262
4Dgifts @4dgifts.bsky.social · 26/02/2025I just found this beautiful thing in a drawer.No current device can match its UX/bloat ratio. Not removing the crude Silk web browser was its only sin. Now I must sneakily find the right cable to charge it without wife0 finding put where I keep the secret cable stash 🤞 010
4Dgifts @4dgifts.bsky.social · 26/02/2025Back in the mid 1990s Core Security's 1st gig was a security audit of Argentina's Customs agency. A lottery determined if a container was or wasn't to be inspected by customs agents. We found out the PRNG was seeded with time(NULL) at registration time and thus could predict result of the lottery. 😄 160
4Dgifts @4dgifts.bsky.social · 26/02/2025Spinning this way what amounts to plain censorship is pure, unadulterated Hoebbels-style propaganda. We live in dark times. 010
Reposted by 4DgiftsMarisa Kabas @marisakabas.bsky.social · 26/02/2025This is how i responded to @bsky.app: 1134016862
Reposted by 4DgiftsQuarkslab @quarkslab.bsky.social · 25/02/2025A Plan to Pwn: Reviving a 17 year old bug or winning a race against Project Management? We've got both. Mathieu Farrell shows you how in the "Pwn Everything, Bounce Everywhere, all at once" blog post series. blog.quarkslab.com/pwn-everythi... 022
4Dgifts @4dgifts.bsky.social · 24/02/2025Don't know if you all are aware but back in 2021 Quarkslab worked on an E2E encryption plugin for Mattermost, an open source Slack look-a-like. In my opinion government, corporate users and enterprises should demand that feature in internal chat systems blog.quarkslab.com/mattermost-e...blog.quarkslab.comMattermost End-to-End Encryption PluginThis blog post introduces a plugin that provides end-to-end encryption (E2EE) to Mattermost. 000
4Dgifts @4dgifts.bsky.social · 24/02/2025This is kinda insane. It's very much like a phishing exercise gone wrong www.washingtonpost.com/dc-md-va/202...washingtonpost.comTrump administration tells agencies they can ignore Musk order on email replyThe Office of Personnel Management told HR officials that employees wouldn’t be let go for not replying to an email asking what they did last week. 000
4Dgifts @4dgifts.bsky.social · 22/02/2025it is not an actual chainsaw, it does not work as a chainsaw. That's it. That is the summary of the whole thing. 010
4Dgifts @4dgifts.bsky.social · 21/02/2025Where Warlocks Stay Up Late episode 2 interviews Ralph Logan aka sangfroid (aka "Rafael" aka "El Ralfo" to me) Over the past 25+ years we crossed paths several times, yet the interview gave me new insights & views of him I hadn't known Series shaping up nicely so far www.youtube.com/watch?v=O0Cm...youtube.comEpisode 2: Ralph Logan aka sangfroidYouTube video by Where Warlocks Stay Up Late 022
4Dgifts @4dgifts.bsky.social · 17/02/2025Y la promicionó como un proyecto para invertir en pymes y en la economía Argentina, etc, etc. NO como una memecoin en joda. Osea digamos, es cómplice de la estafa. Si fuera un proyecto de inversión debería existir documentación sobre el plan, para que se usarían los fondos, etc 001
Reposted by 4DgiftsJorge Aliaga @jorgeluisaliaga.bsky.social · 17/02/2025El autor explica que, como nadie verificaba la circulación de nitrato de amonio, que como dice se puede usar para explosivos, lo sacaron > x.com/fedesturze/s...x.comx.com 134
4Dgifts @4dgifts.bsky.social · 14/02/2025This a quick analysis of the "0day" recently fixed by Apple, reportedly being used In The Wild to disable Restrictive Mode on locked iPhone, thus opening a wider attack surface for exploitation. 012
Reposted by 4DgiftsQuarkslab @quarkslab.bsky.social · 13/02/2025AMD published Security Bulletin AMD-SB-7027 addressing CVE-2024-0179 and CVE-2024-21925, the two UEFI SMM vulnerabilities disclosed in our blog post. Data center, desktop, mobile and embedded processors products are affected: www.amd.com/en/resources...amd.com 022