Sign in

buherator

@buherator.bsky.social
538 followers 269 following 3.7K posts

"I'm interested in all kinds of astronomy." scrapco.de Mostly cross-posting from Fediverse: @buherator@infosec.place

PostsRepliesMedia
buherator @buherator.bsky.social · 10h
FlyDubai crew is pretty badass! Original->
000
buherator @buherator.bsky.social · 22h
[RSS] As a general rule, calling product support while drunk is not recommended devblogs.microsoft.com -> I don't endorse this message: most support calls require at lest a shot and a few cigarettes to maintain sanity. Original->
000
buherator @buherator.bsky.social · 22h
Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries www.vusec.net -> Original->
010
buherator @buherator.bsky.social · 29/09/2026
[RSS] Paint It Blue: Reversing Win32k's Callbacks idov31.github.io -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
I read an article about sleep schedules and thought it would be good idea to put on some of those very neutral YT background music channels. Then I got recommended hate5six on the sidebar so Escuela Grind it is: www.youtube.com -> Original->
010
buherator @buherator.bsky.social · 29/09/2026
[RSS] Sender spoofing in Proton Mail via display-name homograph alonsovidales.github.io -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5 ptswarm.com -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
OpenAI delaying its model launch (and IPO) due to security concerns reminds me of 8yo me delaying the launch of my nerve gas rocket (made of paper and stuff I found in the kitchen, probably inspired by The Rock with Nicholas Cage) for similar reasons. Later we agreed in mutual 1/2
100
buherator @buherator.bsky.social · 28/09/2026
It's that time of the year again... Original->
Alt text TBD, sorry!
001
buherator @buherator.bsky.social · 28/09/2026
[RSS] RCE in OpenCode (GHSA-632h-h47v-g4x4) securitylabs.datadoghq.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Cryptographic mass murder www.bfswa.blog -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Aarch64 Rop Cheatsheet binaryru.in -> Original->
010
buherator @buherator.bsky.social · 28/09/2026
[RSS] Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE starlabs.sg -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass github.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 www.safateam.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev -> Original->
000
buherator @buherator.bsky.social · 27/09/2026
RIP Sexecutioner :,( www.rollingstone.com -> Original->
000
buherator @buherator.bsky.social · 27/09/2026
Original->
Alt text TBD, sorry!
000
buherator @buherator.bsky.social · 26/09/2026
DNS errors again. systemd-resolved once again reports 0 errors (in fact, 0 log messages). Now I know this means the network is probably fucked. It was. But why is it so hard to put `error("network if fucket");` in #systemd? Original->
020
buherator @buherator.bsky.social · 26/09/2026
An old friend is ashamed of speaking English with people but want to practice. Any pro/cons of using an educational chatbot for this? At first I find this a pretty good use case for language models. Original->
000
buherator @buherator.bsky.social · 26/09/2026
That's right, the right answer for this questions is: 3! By first pressing the down arrow you remove the selection (which you didn't put there) from the address bar text. The two downs are needed to reach C:\Users\Public. "2 or 3" would be also acceptable, because if you don't 1/2
Alt text TBD, sorry!
100
buherator @buherator.bsky.social · 25/09/2026
"If it only were that simple." - George Washington Original->
000
buherator @buherator.bsky.social · 25/09/2026
#Windows experts, can you answer this without trying: How many times do you need to press the down arrow to select C:\Users\Public? #UX #UI Original->
Alt text TBD, sorry!
010
buherator @buherator.bsky.social · 25/09/2026
Session timeouts[1] provide great examples of #compliance disconnects from reality: When booking for events it *always* takes *days* to get from registering for an event and getting there to show your QR or whatever. And while an attacker who hijacks your session has 0 benefit 1/3
101
buherator @buherator.bsky.social · 25/09/2026
Re: this one I'm still curious how I could tell which document node triggered a network event (denied, with an img Initiator) I see in dev tools. I can't find the corresponding URL by searching in Inspector, DeepSeek hallucinates all the solutions, maybe @freddy has a tip? 1/2
110
buherator @buherator.bsky.social · 24/09/2026
Umm why does infosec.place "access my device"? /cc @jerry Original->
Alt text TBD, sorry!
010
buherator @buherator.bsky.social · 24/09/2026
Whatever they smoke at #F5, I don't want any of it. Original->
000
buherator @buherator.bsky.social · 24/09/2026
[RSS] Google's PageBreak Project - Real-World Findings bughunters.google.com -> Original->
000
buherator @buherator.bsky.social · 24/09/2026
[RSS] CVE-2024-0244 - A heap buffer overflow in the Canon MF753Cdw printer www.thezdi.com -> Original->
000
buherator @buherator.bsky.social · 24/09/2026
[RSS] Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com -> Original->
000
buherator @buherator.bsky.social · 23/09/2026
If I had a cent for every occasion I had to debug `if let Some(foo)=` moving `foo`, I had 2 cents... #Rust Original->
000
buherator @buherator.bsky.social · 23/09/2026
[RSS] ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE www.elttam.com -> Original->
000
buherator @buherator.bsky.social · 23/09/2026
[RSS] EvilVM: Forth shellcode (2019) web.archive.org -> Original->
010
buherator @buherator.bsky.social · 22/09/2026
My panic!() messages start to degrade to the quality of my commit messages Original->
020
buherator @buherator.bsky.social · 22/09/2026
[RSS] CVE-2026-78902: XSS to RCE in pfSense with one DNS request www.netspi.com -> Original->
000
buherator @buherator.bsky.social · 22/09/2026
[RSS] How One Twitch Chat Message Became Code Execution on a Streamer's PC blog.scrt.ch -> Original->
000
buherator @buherator.bsky.social · 22/09/2026
Can gzip be a language model? nathan.rs -> Original->
010
buherator @buherator.bsky.social · 22/09/2026
It's funny how WinDbg's TTD docs[1] emphasizes that PII may appear in dumps, while e.g. docs for crash dump analysis[2] don't. Based on the observation that behind every warning sign there is a story I suspect that at one point a TTD trace somehow resulted in summoning MS's 1/2
100
buherator @buherator.bsky.social · 22/09/2026
Today's xkcd is especially unhinged, love it! xkcd.com -> Original->
020
buherator @buherator.bsky.social · 21/09/2026
#IBMi could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys www.ibm.com -> The 90s called and want their dumb obfuscation back! Original->
010
buherator @buherator.bsky.social · 21/09/2026
[RSS] Windows Exploitation Techniques: Dangling COM Object Registrations projectzero.google -> Original->
021
buherator @buherator.bsky.social · 21/09/2026
[RSS] ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 minanagehsalalma.github.io -> Original->
000
buherator @buherator.bsky.social · 21/09/2026
[RSS] Advisory X41-2026-004: dm-verity can be bypassed in Debian live-boot x41-dsec.de -> Original->
000
buherator @buherator.bsky.social · 21/09/2026
#Ghidra 12.1.4 is out, changes: github.com -> Original->
010
buherator @buherator.bsky.social · 21/09/2026
"The Golden Rule of AI: Don’t use AI to save yourself time by wasting someone else’s." fs.blog -> Original->
040
buherator @buherator.bsky.social · 21/09/2026
"HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images" heif-heist.com -> Cool finding, but these issues have been around for ages. It's embarassing for all the affected large corps 1/2
110
buherator @buherator.bsky.social · 20/09/2026
Seems like AI companies are not that easygoing when they are on the wrong end of hacking :P threadreaderapp.com -> Original->
000
buherator @buherator.bsky.social · 20/09/2026
[RSS] What Go Taught Us About Java Garbage Collection debugagent.com -> Original->
000
buherator @buherator.bsky.social · 20/09/2026
[RSS] Quarkdown: Turing-complete Markdown typesetting system github.com -> There is a demand for this. Shut up. Original->
020
buherator @buherator.bsky.social · 18/09/2026
The future will be much more embarassing for humanity than Skynet Original->
001