Sign in

Frederik

@fre.infosec.exchange.ap.brid.gy
3 followers 0 following 30 posts

studying it sec at TU Darmstadt 🌉 bridged from ⁂ infosec.exchange/@fre, follow @ap.brid.gy to interact

PostsRepliesMedia
Frederik @fre.infosec.exchange.ap.brid.gy · 10/07/2026
> What kind of video would make a given part of your visual brain light up the most? NEvo answers this in silico: it evolves AI-generated videos to maximally drive a target brain region, then uses them to map how visual selectivity becomes increasingly dynamic and social along the lateral stream […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Frederik
Prof. Sam Lawler @sundogplanets.mastodon.social.ap.brid.gy · 10/07/2026
FUCK FUCK FUCK FUCK NOOOOO ca.pcmag.com/news/16760/fcc-approve…
ca.pcmag.com
FCC Approves Reflect Orbital's Giant Mirror Satellite That Astronomers Hate
The FCC says the most controversial aspect of Reflect Orbital's Earendil-1 satellite, the giant mirror, falls out of its purview since the regulator mainly focuses on radio spectrum.
46222338
Frederik @fre.infosec.exchange.ap.brid.gy · 04/07/2026
🚨🚨 eprint.iacr.org/2026/1351 🚨🚨 my first ever academic paper is finally public!!!! exciting stuff Here's a small post giving some introduction to the topic without going into the details: frereit.de/hpcc
Screenshot of the first page of the paper. It shows the title "Hardware Private Cubic Circuits" and two authors "Frederik Reiter and Amir Moradi". The rest of the page is filled by the abstract.
020
Frederik @fre.infosec.exchange.ap.brid.gy · 30/06/2026
Because it came up in conversation at #TROOPERS26 and I realized I tend to infodump about this topic, I wrote down my thoughts and intuitions about how to get malware (such as C2 agents) past AV and EDR software: frereit.de/notes-on-av-evasion don't click on that link expecting new […]
infosec.exchange
Original post on infosec.exchange
000
Frederik @fre.infosec.exchange.ap.brid.gy · 26/06/2026
Golden Egg: 3 Goose: 0 Someone who is good at the economy please help me value this. my family is dying #goose
000
Frederik @fre.infosec.exchange.ap.brid.gy · 26/06/2026
Oh no... What does this mean for the Goose value? #goose #goosevalue
A screenshot of a fake Mastodon post. It reads "New ransom group blost post!", "Group name: anubis", "Post title: Golden Egg factory" and has an attached fake screenshot of the ransomware group's portal showing the ransom note for the Goose factory.
000
Frederik @fre.infosec.exchange.ap.brid.gy · 24/06/2026
blog.quarkslab.com/how-olts-may-hav… Lol, apparently this is still not patched in quite a few places and you can just remote pwn into quite a few ISP networks. How fun.. > We contacted the CERTs and told them we are going to publish on this date, and […]
infosec.exchange
Original post on infosec.exchange
001
Frederik @fre.infosec.exchange.ap.brid.gy · 23/06/2026
RE: infosec.exchange/@fre/1162558094179… Final update on flare.io (combo reseller): They did respond and fulfill my GDPR request. Indeed, they were able to send me a few of my old passwords correlated with service and email. They partially censored the passwords in the GDPR report […]
infosec.exchange
Original post on infosec.exchange
000
Frederik @fre.infosec.exchange.ap.brid.gy · 13/06/2026
friend's MS account got phished, I helped with recovery. Final response from Microsoft (emphasis mine): > Based on this review, we’ve **confirmed that unauthorized access occurred**. > During the investigation, we discovered that the security information on your account had been changed. Due to […]
infosec.exchange
Original post on infosec.exchange
000
Frederik @fre.infosec.exchange.ap.brid.gy · 10/06/2026
Starting a conspiracy that 5-in-1 body wash is forbidden as carry-on because the 5 functionalities are body, face, shampoo, conditioner and bomb.
100
Frederik @fre.infosec.exchange.ap.brid.gy · 22/05/2026
I'm trying to move away from #Spotify to some self-hosted alternative but I'm concerned about discoverability. How do y'all find new #music without an algorithm? Any tips?
002
Frederik @fre.infosec.exchange.ap.brid.gy · 19/03/2026
Today I learned about flare.io, a company that provides other companies with detailed intel about data leaks affecting them. Here's the catch: Unlike @haveibeenpwned or even intelx, they store everything that they can get their hands on. During a live demo, they proudly pulled up all […]
infosec.exchange
Original post on infosec.exchange
100
Frederik @fre.infosec.exchange.ap.brid.gy · 03/02/2026
#Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue. One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and […]
infosec.exchange
Original post on infosec.exchange
010
Frederik @fre.infosec.exchange.ap.brid.gy · 15/01/2026
Today, Mandiant released a NetNTLMv1 Rainbow Table. The rainbow table is relatively small, which increases the lookup time. They say > The release of this dataset allows defenders and researchers to recover keys in under 12 hours using consumer hardware costing less than $600 USD. This seems […]
infosec.exchange
Original post on infosec.exchange
000
Frederik @fre.infosec.exchange.ap.brid.gy · 25/11/2025
The recording of my #TROOPERS25 talk about the #DHL Packstation has finally been published 🎉 youtu.be/WEGVL9Wttsc?si=LIIN6Fq9YSa…
001
Frederik @fre.infosec.exchange.ap.brid.gy · 05/11/2025
Apparently a few weeks ago, example.com was re-designed. I don't know what to do with this information.
A screenshot of example.com in the Internet Archive from the 8th October 2025.
The title of the webpage is "Example Domain" and the text says "This domain is for use in illustrative examples in documents. You may use this domain in literature without prior coordination or asking for permission. More information..."
The text is in a white box on a gray background.A screenshot of example.com in the Internet Archive from the 8th October 2025.
The title of the webpage is "Example Domain" and the text says "This domain is for use in documentation examples without needing permission. Avoid use in operations. Learn more"
The text is on a solid gray background.
020
Frederik @fre.infosec.exchange.ap.brid.gy · 26/09/2025
> Spawn massively parallel process on remote server > laptop fans go crazy, 100% usage on all cores > Wut? > VS Code printing ~20 MiB ASCII from stdout in the integrated terminal used more CPU than the actual process on the remote server Gotta love electron apps
000
Frederik @fre.infosec.exchange.ap.brid.gy · 05/09/2025
#ipv4 is down at vodafone but #ipv6 works without issues. Oh how the turntables
010
Frederik @fre.infosec.exchange.ap.brid.gy · 28/08/2025
Have you ever had a flow state that you, um, you had, your, you- you could, you’ll do, you- you wants, you, you could do so, you- you’ll do, you could- you, you want, you want him to do you so much you could do anything?
000
Frederik @fre.infosec.exchange.ap.brid.gy · 17/07/2025
Had some fun with a #phishing email. After a bunch of redirects, it ends up at hxxps://eso-inzeniring[.]top/quaroundziks.htm which is a Cloudflare Bucket. The HTML spoofs a Webmail Login, and once you enter your information, it uses formsubmit[.]co (a legitimate but weird service as far as I can […]
infosec.exchange
Original post on infosec.exchange
001
Frederik @fre.infosec.exchange.ap.brid.gy · 26/06/2025
Today at #TROOPERS25 I released a reimplementation of a set of protocols used to interact with a DHL #Packstation without using the official app: github.com/frereit/pydhl It's more of a proof of concept than an actual utility, but maybe it's interesting for some.
github.com
GitHub - frereit/pydhl
Contribute to frereit/pydhl development by creating an account on GitHub.
010
Frederik @fre.infosec.exchange.ap.brid.gy · 24/06/2025
Nothing like discovering new facts less than 24 hours before the talk about said facts :ablobcatknitsweats: luckily just an actual confirmation for something we already suspected anyway, so just needed to remove a "likely" from the documentation but still, how fun
010
Frederik @fre.infosec.exchange.ap.brid.gy · 22/06/2025
[long post about weird and guessy crypto question] hi crypto people, I could use a crypto vibe check on some black box crypto: I'm looking at a key encryption mechanisms where some "inner" encryption keys are used to encrypt some data, and then encrypted themselves with a main key and stored […]
infosec.exchange
Original post on infosec.exchange
010
Frederik @fre.infosec.exchange.ap.brid.gy · 14/06/2025
The big Google outage was apparently some kind of null pointer deref: > The issue with this change was that it did not have appropriate error handling nor was it feature flag protected. Without the appropriate error handling, the null pointer caused the binary to crash. Feature flags are used […]
infosec.exchange
Original post on infosec.exchange
100
Frederik @fre.infosec.exchange.ap.brid.gy · 25/04/2025
Just got the email that my proposal for a talk at #TROOPERS25 got accepted!!!! I'm soo excited ahahaha
000