Sign in

nop.f(x)

@nopfx.bsky.social
26 followers 75 following 64 posts

0xDEADBEEF

PostsRepliesMedia
Reposted by nop.f(x)
Bailey Townsend 🦀 @pds.dad · 30/12/2025
@lewis.moe this is an insane amount of work you've done in a month. The pds is looking really good tangled.org/lewis.moe/bs...
tangled.org
lewis.moe/bspds-sandbox
PDS software with bells & whistles you didn’t even know you needed. will move this to its own account when ready.
1110814
Reposted by nop.f(x)
Igor Sushko @igorsushko.bsky.social · 20/12/2025
1994-2001: US disarms Ukraine of nuclear warheads & intercontinental ballistic missiles After 9/11: Ukraine sends over 5,000 troops to a "war on another continent" to help the US. 18 die. 2014: Russia invades Ukraine. 2025: US - "It's not our war. It's a war on another continent."
27510247
Reposted by nop.f(x)
Jason Jay Smart @jjsmart.bsky.social · 10/12/2025
🥺 A fresh wall painting now decorates Kyiv’s 🇺🇦 Children’s Hospital. In July 2024, Russia launched a missile strike on children receiving dialysis & chemo. 👉 There can be no peace until Russian war criminals face justice.
18935
Reposted by nop.f(x)
MAKS 26 👀🇺🇦 @maks23.bsky.social · 20/11/2025
🇺🇦🇺🇳 Ukrainians representative at UN Security Council: ▪️ There will never be any recognition, formal or otherwise, of Ukrainian territory temporarily occupied by Russia as Russian. Our land is not for sale. ▪️Ukraine will not accept any limits on its right to self-defense or on the size of AFU.
38653149
nop.f(x) @nopfx.bsky.social · 23/06/2025
Privilege Escalation vulnerability in Motors, a #WordPress theme with more than 22,000 sales. This #vulnerability makes it possible for an unauthenticated attacker to change the password of any user
wordfence.com
000
nop.f(x) @nopfx.bsky.social · 20/06/2025
#cpu #fuzz
lifeasageek.github.io
001
nop.f(x) @nopfx.bsky.social · 18/06/2025
#Veeam has released security updates today to fix several Veeam Backup & Replication (VBR) flaws, including a #RCE. Tracked as #CVE-2025-23121, this security flaw was reported by security researchers at #watchTowr and #CodeWhite, and it only impacts domain-joined installations.
veeam.com
KB4743: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2
Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2
000
Reposted by nop.f(x)
Ioannis Polyzos @ipolyzos.com · 14/06/2025
Ubuntu 25.10's switch to sudo-rs, a Rust-based sudo, shows a profound commitment to enhancing memory safety and system security. This move reflects the growing trend of leveraging Rust. thenewstack.io/ubuntu-25-10... #Ubuntu #Ubuntu2510 #sudoRS #RustLang #MemorySafety #SecureByDesign #Security
thenewstack.io
Ubuntu 25.10 Replaces sudo With a Rust-Based Equivalent
The new sudo-rs is meant to be a near drop-in replacement for sudo, but some of the less secure aspects of sudo will not be supported.
001
Reposted by nop.f(x)
dcvz @dcvz.io · 15/06/2025
🎉 godot-bevy v0.7.0 is out! Release with bug fixes and improvements: ✨ Node Type Markers - Better and more efficient ECS queries ⚡ Fix Timing - Component available in Startup systems 🚀 Performance improvements We also now have a #godotbevy book! 📖 #godotengine #bevyengine #rustlang #gamedev
github.com
Release v0.7.0 · dcvz/godot-bevy
What's Changed Update the README "Basic Usage" section & add simple Node2D movement example by @DragonAxe in #37 feat: add explicit configuration of transform sync mode by @dcvz in #44 feat(docs):...
1266
Reposted by nop.f(x)
WhiteSponge @whitesponge.bsky.social · 15/06/2025
Good video by Stefan Baumgartner on refactoring with Rust! youtu.be/wuBkzT_3CDU?... #rustlang
youtu.be
Refactoring in Rust - Stefan Baumgartner
YouTube video by RustNL
052
Reposted by nop.f(x)
Rust Bytes @rustaceans.bsky.social · 16/06/2025
3. Steve Klabnik attempted to answer the question we have all been asking, “Is Rust faster than C?” steveklabnik.com/writing/is-r...
steveklabnik.com
Is Rust faster than C?
Blog post: Is Rust faster than C? by Steve Klabnik
101
nop.f(x) @nopfx.bsky.social · 05/06/2025
#Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization #CVE-2025-49113
fearsoff.org
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization [CVE-2025-49113]
A deep technical breakdown of CVE-2025-49113, a critical Roundcube vulnerability involving PHP session serialization. Learn how the bug was discovered, exploited, and responsibly disclosed with full P...
020
nop.f(x) @nopfx.bsky.social · 03/06/2025
#cve-2025-4598 #cve-2025-5054
schneier.com
New Linux Vulnerabilities - Schneier on Security
They’re interesting: Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools...
010
nop.f(x) @nopfx.bsky.social · 02/06/2025
#Cisco ##vulnerability affecting Cisco IOS XE Wireless Controller Software version 17.12.03 and earlier. The issue was described as an unauthenticated arbitrary file upload, caused by the presence of a hard-coded JSON Web Token (JWT).
horizon3.ai
Cisco IOS XE WLC File Upload Vuln CVE-2025-20188
Explore how a hard-coded JWT in Cisco IOS XE WLC enables unauthenticated file upload and potential RCE—and how to mitigate it.
000
nop.f(x) @nopfx.bsky.social · 02/06/2025
#vBulletin #rce #NDay
karmainsecurity.com
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
000
nop.f(x) @nopfx.bsky.social · 29/05/2025
#o3 #cve-2025-37899 #smb #zeroday
blog.exploits.club
How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation
In this post I’ll show you how I found a zeroday vulnerability in the Linux kernel using OpenAI’s o3 model. I found the vulnerability with nothing more complicated than the o3 API &#821…
000
Reposted by nop.f(x)
Catalin Cimpanu @campuscodi.risky.biz · 22/05/2025
A Chinese APT (UNC5221) is behind recent attacks exploiting an Ivanti zero-day (CVE-2025-4427) This is a known Chinese APT group that seems to be specialized in Ivanti and other Western enterprise products... they have a long list of past zero-days in their name blog.eclecticiq.com/china-nexus-...
blog.eclecticiq.com
China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier.
072
nop.f(x) @nopfx.bsky.social · 22/05/2025
A new #critical #vulnerability popped up concerning samlify, a widely adopted #Node.js library for implementing #SAML 2.0 Single Sign-On.
endorlabs.com
000
nop.f(x) @nopfx.bsky.social · 21/05/2025
#Motors <= 5.6.67 - Unauthenticated Privilege Escalation Via Password Update/Account Takeover #wordpress #theme
bleepingcomputer.com
Premium WordPress 'Motors' theme vulnerable to admin takeover attacks
A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete contr...
000
nop.f(x) @nopfx.bsky.social · 21/05/2025
Broadcom-owned #VMware on Tuesday rolled out urgent patches for two sets of flaws that expose its flagship infrastructure software to data leakage, command execution and denial-of-service attacks.
securityweek.com
NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch
VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available.
000
nop.f(x) @nopfx.bsky.social · 19/05/2025
A missing authentication for critical function vulnerability [CWE-306] in #FortiOS, #FortiProxy, and #FortiSwitchManager #CVE-2025-22252
fortiguard.com
PSIRT | FortiGuard Labs
None
000
nop.f(x) @nopfx.bsky.social · 16/05/2025
#Google released updates to address 4 issues in its #Chrome web browser, including one for which it said there exists an exploit in the wild.
thehackernews.com
000
nop.f(x) @nopfx.bsky.social · 15/05/2025
#Intel, #AMD and #Arm each published Patch Tuesday security advisories to inform customers about vulnerabilities found recently in their products, including ones related to newly disclosed CPU attacks.
securityweek.com
Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks
Intel, AMD and Arm each published security advisories on Patch Tuesday, including for newly disclosed CPU attacks.
001
nop.f(x) @nopfx.bsky.social · 15/05/2025
#Siemens, #SchneiderElectric and #PhoenixContact have released #ICS security advisories on the May 2025 Patch Tuesday.
securityweek.com
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact
Industrial giants Siemens, Schneider Electric and Phoenix Contact have released ICS security advisories on the May 2025 Patch Tuesday.
000
nop.f(x) @nopfx.bsky.social · 14/05/2025
#Zoom fixes multiple security bugs, including a #high-risk flaw. Users are urged to update to the latest version released on May 13, 2025. The updates affect both general app versions and Windows-specific builds. For anyone using Zoom, especially on Windows systems, these updates are worth attention
hackread.com
Zoom Fixes High-Risk Flaw in Latest Update
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
nop.f(x) @nopfx.bsky.social · 14/05/2025
Fortinet released security updates to patch a critical #RCE exploited as a #zero-day targeting FortiVoice enterprise phone systems. Vulnerability tracked as #CVE-2025-32756. As the company explains, successful exploitation can allow rce via maliciously crafted HTTP requests.
fortiguard.fortinet.com
PSIRT | FortiGuard Labs
None
000
nop.f(x) @nopfx.bsky.social · 14/05/2025
Today is #Microsoft May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed #zero-day #vulnerabilities www.tripwire.com/state-of-sec...
tripwire.com
May 2025 Patch Tuesday Analysis
This Patch Tuesday Analysis addresses Microsoft’sMay 2025 Security Updates. FIRE is actively working on coverage for these vulnerabilities.
000
nop.f(x) @nopfx.bsky.social · 25/04/2025
#SCADA Schneider Electric Modicon Controllers - Successful exploitation of these vulnerabilities may risk execution of unsolicited command on the PLC, which could result in a loss of availability of the controller. www.cisa.gov/news-events/...
cisa.gov
Schneider Electric Modicon Controllers | CISA
000
Reposted by nop.f(x)
Nicholas Grossman @nicholasgrossman.bsky.social · 21/04/2025
How many foreign intel agencies already have spyware on Hegseth’s wife or brother’s phone? Is that the device they used to access Signal? Have they been offered money? Or sex? What secrets could be used for extortion? These are much more relevant NatSec questions than how many pushups can you do.
1337078
Reposted by nop.f(x)
Тsфdiиg @tsoding.bsky.social · 19/04/2025
Fun Fact: the C operator >>= is officially called the "Shrek Operator". Because it's "Shift Right Equal" a.k.a "Shreq". It was named this way because Dennis Ritchie was a huge fan of the Shrek series.
419010
nop.f(x) @nopfx.bsky.social · 19/04/2025
#CVE-2025-30208 #vite A critical vulnerability allowing unauthorized access to sensitive information via the Vite development server.
000
nop.f(x) @nopfx.bsky.social · 18/04/2025
#elixir #erlang #otp paraxial.io/blog/erlang-...
paraxial.io
What the Critical Erlang SSH Vulnerability Means for Elixir Developers
How to determine if you are vulnerable.
000
nop.f(x) @nopfx.bsky.social · 18/04/2025
#rce #erlang A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
110
Reposted by nop.f(x)
P(aul) Frazee @pfrazee.com · 16/04/2025
If you often say "wow I relate to developers" then I have the perfect job for you Developer Relations role just listed! There's also a bunch of other recent additions on the jobs page bsky.social/about/join
bsky.social
Jobs - Bluesky
View open positions at Bluesky PBC
761148255
Reposted by nop.f(x)
Haskell programming language @haskell.org · 15/04/2025
#Haskell Language Server 2.10.0.0 release announcement! blog.haskell.org/hls-2-10-0-0/ #LSP #FunctionalProgramming
blog.haskell.org
Haskell Language Server 2.10.0.0 release | The Haskell Programming Language's blog
1258
nop.f(x) @nopfx.bsky.social · 16/04/2025
😶 www.theregister.com/2025/04/16/h...
theregister.com
Homeland Security funding for CVE program expires
: Because vulnerability management has nothing to do with national security, right?
001
Reposted by nop.f(x)
The Hacker's Choice (1995) @hackerschoice.bsky.social · 15/04/2025
new FEATRUE in bincrypter. LOCK & ENCRYPT a binary to a target host. Will execute differently when uploaded to virustotal.com or any other but the target host. Please don't set BC_LOCK="rm -rf ~/" 🙈 github.com/hackerschoic...
061
Reposted by nop.f(x)
John Hammond @johnhammond.bsky.social · 15/04/2025
I got a chance to try out @Burp_Suite Burp AI, and it's... honestly really cool 😅 Video showcase where we cruise through a web app scan, crawl and audit, and it rips through findings including an explicit UNION SQL injection vulnerability and more 🤩 youtu.be/v-McepNOrTQ
1172
nop.f(x) @nopfx.bsky.social · 14/04/2025
A critical Remote Code Execution ( #RCE ) vulnerability, #CVE-2025-27520 with a CVSSv3 base score of 9.8, has been recently discovered in #BentoM
100
nop.f(x) @nopfx.bsky.social · 13/04/2025
This is what American cease-fire looks like 😡🤬
000
Reposted by nop.f(x)
The Hacker's Choice (1995) @hackerschoice.bsky.social · 09/04/2025
🍿THC member on camera. A first. 😅 30 years of hacking - a perspective and a reflection. 📺 👉 Keep Hacking 👈 The next 30 years of hacking start today. ❤️ thanks @wwsul.bsky.social www.youtube.com/watch?v=sQVL...
youtube.com
Episode 4: Eduart Steiner aka Skyper
YouTube video by Where Warlocks Stay Up Late
094
nop.f(x) @nopfx.bsky.social · 09/04/2025
#Fortinet has released a critical security flaw impacting FortiSwitch that could permit an attacker to make unauthorized password changes. An unverified password change in FortiSwitch GUI may allow unauthenticated attacker to modify admin passwords via a specially crafted request. #CVE-2024-48887
000
Reposted by nop.f(x)
Orhun Parmaksız @orhun.dev · 08/04/2025
Debugging in the terminal isn't difficult anymore 🔥 🛠️ heretek - A gdb TUI dashboard 🐛 Supports viewing registers, hexdump & more! 🚀 Works with remote targets w/o gdbserver 🦀 Written in Rust & built with @ratatui.rs ⭐ GitHub: github.com/wcampbell0x2... #rustlang #ratatui #tui #gdb #debugging
6503
Reposted by nop.f(x)
Rick @rickylongthread.bsky.social · 03/04/2025
NOBEL PRIZE-WINNING ECONOMIST says:
7524801076
Reposted by nop.f(x)
vx-underground (automated mirror) @vxundergroundre.bsky.social · 03/04/2025
Ransomware groups will be raising extortion demands 10% due to Tariffs
05813
nop.f(x) @nopfx.bsky.social · 04/04/2025
#cve CVE-2025-30065: Max severity #RCE #Apache #Parquet, impacting all versions <=1.15.0, looks like problem with deserialisation of untrusted data. #cvss v4 score of 10.0. Fixed release of Apache 1.15.1
010
Reposted by nop.f(x)
Deth Veggie @dethveggie.bsky.social · 03/04/2025
Ohhh.... Oh no. My dude.
14698
nop.f(x) @nopfx.bsky.social · 03/04/2025
Damn🤯
000
Reposted by nop.f(x)
shenetworks @shenet.works · 03/04/2025
So if you get notified of lateral movement inside your network.. you should definitely look into that.. expeditiously
5474