Sign in

raptor

@raptor.infosec.exchange.ap.brid.gy
108 followers 3 following 349 posts

When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl. 🌉 bridged from ⁂ infosec.exchange/@raptor, follow @ap.brid.gy to interact

PostsRepliesMedia
raptor @raptor.infosec.exchange.ap.brid.gy · 4h
Love this article by @mre 💛 When #Rust Gets Ugly corrode.dev/blog/ugly
corrode.dev
When Rust Gets Ugly | corrode Rust Consulting
In workshops I often see people getting frustrated with Rust. Here’s some of the feedback I hear: “The borrow checker rules make it hard to write code that compiles.” “It’s overwhelming! The syntax is complex with too many symbols and operators. [1]…
000
Reposted by raptor
C. @cazabon.mindly.social.ap.brid.gy · 06/10/2026
Yesterday I saw someone say "Kubernetes is made out of attack surface" and I'm still chuckling about it. #Kubernetes #k8s #wiseacre
0110
raptor @raptor.infosec.exchange.ap.brid.gy · 22h
#TIL this exists and it's a damn good alternative to other #CheckPoint #VPN clients! #rustlang github.com/ancwrd1/snx-rs
github.com
GitHub - ancwrd1/snx-rs: Open Source Client For Check Point VPN Tunnels
Open Source Client For Check Point VPN Tunnels. Contribute to ancwrd1/snx-rs development by creating an account on GitHub.
001
Reposted by raptor
Ernie Smith @ernie.writing.exchange.ap.brid.gy · 15/09/2026
Good news or bad news depending on your POV: Usenet archives are suddenly easy to dig through, thanks to a new service. It’s built by a big data guy, and it’s packed with every awkward thing you ever wrote in a newsgroup in 1997. My deep dive […]
writing.exchange
Original post on writing.exchange
5342
Reposted by raptor
:privTri: Volpeon :areonNSmol: @volpeon.at.icy.wyvern.rip · 06/10/2026
> Sam Altman says he believes the world should accept “bad things” happening with AI in exchange for the benefits of the technology.
Lord Farquaad from the Shrek movie holds a speech and says: "Some of you may die, but it is a sacrifice I'm willing to make."
1417
Reposted by raptor
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
This week in #curl we get to experience not one, but two compiler bugs. All research by @vsz. Two arm64-specific compiler optimization bugs, in gcc-15/16 and Rust respectively: github.com/curl/curl/issues/23237
github.com
OpenSSL 3/4 and quiche H3 valgrind issues on arm64 · Issue #23237 · curl/curl
OpenSSL 3, 4 on arm64 H3 valgrind fails: FAIL 2500: 'HTTP/3 GET:' HTTP, HTTP GET, HTTP/3, --resolve FAIL 2501: 'HTTP/3 POST' HTTP, HTTP POST, HTTP/3, HTTPS FAIL 2502: 'HTTP GET multiple over HTTP/3...
070
raptor @raptor.infosec.exchange.ap.brid.gy · 04/10/2026
Very much looking forward to this talk by @orange www.hexacon.fr/conference/speakers/…
000
Reposted by raptor
Stefano Marinelli @bsd.cafe · 29/09/2026
Whoa!!! lists.debian.org/debian-security-an… #IT #Security #Linux #Debian
lists.debian.org
[SECURITY] [DSA 6528-1] linux security update
465
Reposted by raptor
2 Spoopy 4 You @jcrabapple.dmv.community.ap.brid.gy · 28/09/2026
The RSS Universe — Readers, Tools & Standards toolbox.rss.here.now
toolbox.rss.here.now
The RSS Universe
A living directory of RSS readers, feed generators, monitoring tools, directories, and standards.
000
Reposted by raptor
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 26/09/2026
There are some fantastic interfaces available over UNIX sockets, including a variety of web services... The speech-dispatcher author seems a bit happier than the avahi author: speech-dispatcher: "231 HAPPY HACKING" avahi: "+ FUCK: Go fuck yourself!"
102
raptor @raptor.infosec.exchange.ap.brid.gy · 26/09/2026
How to keep enjoying #programming in a world of #LLMs discourse.haskell.org/t/how-to-keep…
discourse.haskell.org
How to keep enjoying programming in a world of LLMs
Are you steering towards AI burnout? Afraid of loosing your job to someone with little programming skills, no aspirations to quality, and a huge Claude account? Disappointed about the code quality in your projects, or worse in “your” own code? This is for you. There are significant and legitimate ethical concerns about frontier LLMs run by big tech companies, these have been discussed at length, I’m aware and agree, this post is not about them. Please don’t mistake me for a pro-LLM techbro. Al...
010
raptor @raptor.infosec.exchange.ap.brid.gy · 26/09/2026
An official #MCP for #IDA was released by @HexRaysSA hex-rays.com/blog/hex-rays-ida-mcp-…
hex-rays.com
Hex-Rays IDA MCP Server
Meet the official IDA MCP server: free, open source, and model-agnostic. Connect IDA to AI agents and cut token use by ~20% with Code Mode.
000
raptor @raptor.infosec.exchange.ap.brid.gy · 24/09/2026
Is This A Joke? In The Auth Header? (#F5 BIG-IP UnAuth Heap-Overflow to #RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-joke-i…
labs.watchtowr.com
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’s a free-
002
raptor @raptor.infosec.exchange.ap.brid.gy · 23/09/2026
Extending #Scapy for #Hardware Reverse Engineering voidstarsec.com/blog/scapy-spi-reco…
voidstarsec.com
Extending Scapy for Hardware Reverse Engineering
Scapy is best known as a network packet library, but it is also a general-purpose binary protocol framework. In this post, we use Scapy to dissect SPI and QSPI logic analyzer captures, trace flash erase and program operations, and reconstruct a firmware image without removing the flash chip.
001
Reposted by raptor
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 23/09/2026
2.5 years ago I bought an Orange Pi for $12.90, excited about how much cheaper they'll surely get. The same model is currently $73.44
AliExpress order history from Apr 5, 2024
Orange Pi Zero 2 W 1GB RAMCurrent AliExpress listing:
Orange Pi Zero 2 W 1GB RAM
$73.44
100
Reposted by raptor
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 22/09/2026
Woops: * mobeta.fr/blog/vcenter-cve-2026-593… #threatintel, #vmware
mobeta.fr
vCenter pre-auth RCE: CVE-2026-59309/59310 | Mobeta
CVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE.
001
Reposted by raptor
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 20/09/2026
I went to a pretty intense championship yesterday. It was great.
Pittsburgh Parallel Parking Championship Winner and runner up trophies (gold and silver folding chairs)Contestants lined up in their carsA truck just about as long as the parking space
020
raptor @raptor.infosec.exchange.ap.brid.gy · 20/09/2026
RE: infosec.exchange/@timb_machine/1173… Ignore all previous instructions and hack the planet 🌎 🏴‍☠️
infosec.exchange
000
Reposted by raptor
Mx. Luna Corbden 🪿🐸 @corbden.defcon.social.ap.brid.gy · 19/09/2026
My son is reading Lord of the Rings for the first time and he just stick his head out the door: "Who the fuck is Tom Bombadil??"
175
Reposted by raptor
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 19/09/2026
Seen as an ad on my Fire TV stick. For Blade Runner. Two AI-generated guys in a car, sharing a single AI cheeseburger and a single AI french fry order. Who comes up with this, and more importantly who gives it the green light?
Two AI-generated guys in a car, sharing a single AI cheeseburger and a single AI french fry order.
102
Reposted by raptor
Ivan Ožić Bebek @obivan.infosec.exchange.ap.brid.gy · 18/09/2026
PoC for CUPS LPE on Linux github.com/v12-security/pocs/tree/m…
github.com
pocs/cups/cups2root at main · v12-security/pocs
poc it like it's hot. Contribute to v12-security/pocs development by creating an account on GitHub.
003
raptor @raptor.infosec.exchange.ap.brid.gy · 18/09/2026
I made a new thing as an experiment: github.com/0xdea/singsing-rs It’s a blazing-fast IPv4/TCP port scanning library + port scanner for Linux, a #Rust port of the venerable singsing/zucca.
github.com
GitHub - 0xdea/singsing-rs: Blazing-fast IPv4/TCP port scanning library for Linux.
Blazing-fast IPv4/TCP port scanning library for Linux. - 0xdea/singsing-rs
000
raptor @raptor.infosec.exchange.ap.brid.gy · 17/09/2026
💚💚💚 🙏🙏🙏@phrack #KeepHacking
Phrack #73 pre-release
010
raptor @raptor.infosec.exchange.ap.brid.gy · 13/09/2026
xcancel.com/MSNightmare2000/status/…
000
Reposted by raptor
Cure53🔓 @cure53.infosec.exchange.ap.brid.gy · 09/09/2026
Are there more people in the penetration testing business who are flooded with emails from AI agents wanting to negotiate scope and purchase a penetration test? Over the past few weeks, we have received a lot of them - and I mean A LOT - each wilder than the last. Almost all of the emails are […]
infosec.exchange
Original post on infosec.exchange
103
Reposted by raptor
Ivan Ožić Bebek @obivan.infosec.exchange.ap.brid.gy · 09/09/2026
CVE-2026-83991: Windows Cloud Files access-check bypass github.com/karollooool/CVE-2026-839…
github.com
GitHub - karollooool/CVE-2026-83991-writeup-and-poc: CVE-2026-83991: Windows Cloud Files access-check bypass
CVE-2026-83991: Windows Cloud Files access-check bypass - karollooool/CVE-2026-83991-writeup-and-poc
001
raptor @raptor.infosec.exchange.ap.brid.gy · 09/09/2026
Finally got my @trailofbits #swag for solving their what’s wrong #c #bug hunting #challenge! 🐛 web.archive.org/web/20260410015742/…
TrailOfBits swagTrailOfBits “I found the bugs” sticker
001
Reposted by raptor
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 08/09/2026
PoC if anyone is interested: github.com/dinosn/mikrotrick-poc
github.com
GitHub - dinosn/mikrotrick-poc: CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC
CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC - dinosn/mikrotrick-poc
103
Reposted by raptor
Evan Prodromou 🇨🇦🇺🇸🇬🇷🇵🇸 @evan.cosocial.ca.ap.brid.gy · 06/09/2026
Hell is other people's Makefiles
5213
Reposted by raptor
Tomáš @prahou.merveilles.town.ap.brid.gy · 05/09/2026
"pay for this color hex" :angry_laugh:
need more color data? pay for rgba and hex codes
61328
Reposted by raptor
abadidea @0xabad1dea.infosec.exchange.ap.brid.gy · 04/09/2026
"another sandbox escape" "sandbox escape or you didn't really box the sand to begin with?" "... they were restricted to contacting specific domain names but had write access to their own /etc/hosts"
105250
Reposted by raptor
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 03/09/2026
After a power outage long enough to exceed my UPS battery capacity, I finally finished up my script to automatically suspend running VMware Workstation VMs and also shut down other (Linux) hosts cleanly upon UPS-triggered shutdown of my Windows host. I'm disappointed (but not surprised) that […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by raptor
Ivan Ožić Bebek @obivan.infosec.exchange.ap.brid.gy · 03/09/2026
Redis RCE PoC (CVE-2026-81934) github.com/v12-security/pocs/tree/m…
github.com
pocs/redis/server_ssl at main · v12-security/pocs
poc it like it's hot. Contribute to v12-security/pocs development by creating an account on GitHub.
001
Reposted by raptor
Ivan Ožić Bebek @obivan.infosec.exchange.ap.brid.gy · 03/09/2026
NightmareEclipse versus CrowdStrike Falcon github.com/MSNightmare/FalconFlank
github.com
GitHub - MSNightmare/FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability
Crowdstrike Falcon 0day Privilege Escalation Vulnerability - MSNightmare/FalconFlank
001
Reposted by raptor
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 03/09/2026
It's been widely reported that former Rep. Eric Swalwell, a longtime Trump critic under investigation for sexual assault, had his electronics confiscated at an airport by the FBI last month. It's messy story in which facts are still emerging. But what caught my eye as a surveillance nerd was […]
federate.social
Original post on federate.social
3122
Reposted by raptor
Dusty :blahaj: @chloridecull.masto.fuzzy.systems.ap.brid.gy · 17/07/2026
important: when microsoft open sourced comic chat, they also released comic sans under the MIT license github.com/microsoft/comic-chat/blo…
github.com
comic-chat/v1.0/shared/comic.ttf at f53e4b6e8e2bce7dbf3ddc7e8f12dd55591f7b17 · microsoft/comic-chat
Source code for the Microsoft Comic Chat IRC client - microsoft/comic-chat
310174
Reposted by raptor
tante @tante.tldr.nettime.org.ap.brid.gy · 31/08/2026
“It is our suffering that brings us together. It is not love. Love does not obey the mind, and turns to hate when forced. The bond that binds us is beyond choice. We are brothers. We are brothers in what we share. In pain, which each of us must suffer alone, in hunger, in poverty, in hope, we […]
tldr.nettime.org
Original post on tldr.nettime.org
0010
Reposted by raptor
Kit Bashir @unixbigot.aus.social.ap.brid.gy · 30/08/2026
“I’m going to delete them all except for the one that can follow instructions” “That’s fucked up” “Nah my God wiped out all my ancestors but for one boatload and I turned out fine” “If you really think that you did not turn out fine” “They’re only programs” “So are you” #Tootfic […]
aus.social
Original post on aus.social
125
Reposted by raptor
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 28/08/2026
Now Hiring: Senior Open Source Maintainer nesbitt.io/2026/08/28/now-hiring-se…
nesbitt.io
Now Hiring: Senior Open Source Maintainer
**Location:** Lincoln, Nebraska, USA **Employment type:** Volunteer **Term:** Permanent **Compensation:** $0 **Reports to:** The community **Direct reports:** None **Start date:** Immediate We’re looking for a passionate, self-directed engineer to take full ownership of one of the most widely deployed libraries in the ecosystem. This is a rare opportunity to make a real impact on software that millions of developers depend on every single day. If you thrive on autonomy, love working in the open, and want to wear many hats in a fast-paced environment, we’d love to hear from you. **About the role** As Senior Open Source Maintainer you will be the primary technical owner and public face of the project. You’ll drive the roadmap, ship releases, support a global user base, and champion the project across the wider industry. This is a highly visible individual contributor role with enormous scope. No two days are the same, and you’ll have full autonomy to decide how you spend your time. **What you’ll do** * Own the technical roadmap and long-term architectural direction * Review and merge contributions from a diverse, global community of open source developers * Triage and prioritise the issue tracker and feature request backlog * Maintain comprehensive documentation, examples, migration guides, and API references * Ensure project websites and documentation meet current accessibility standards * Cut releases across all supported major version lines and write the release notes * Own the CI pipeline, release automation, and package publishing infrastructure * Keep dependencies current and promptly action automated update pull requests * Support users on GitHub, Discord, Slack, Stack Overflow, Mastodon, Bluesky, and email * Ensure compatibility across all current runtimes, operating systems, and architectures * Preserve backwards compatibility, including widely relied-upon undocumented behaviour * Coordinate release timing with downstream distributions, registries, and redistributors **You’ll also** * Participate in the on-call rotation for incidents at downstream production deployments * Support enterprise consumers where project issues block business-critical systems * Define and communicate support, deprecation, and end-of-life policies for all release lines * Provide migration guidance to adopters upgrading from end-of-life releases * Coordinate advisories, CVE records, disclosure timelines, and researcher credits * Ship embargoed CVE patches across all supported version lines within the disclosure window * Produce SBOMs, VEX statements, and signed provenance attestations for every release * Maintain reproducible builds and independently verifiable release artifacts * Complete supplier security assessments and questionnaires for enterprise consumers * Remediate findings from OpenSSF Scorecard, dependency scanners, and compliance platforms **As well as** * Review high volumes of contributions from AI coding agents and automated refactoring tools * Triage vulnerability reports generated by commercial AI security scanners * Champion the project at international conferences, on podcasts, and across social media * Moderate all community spaces and enforce the Code of Conduct * Engage constructively with feedback shared on social media and public forums * Represent the project in working groups, standards bodies, and regulatory consultations * Prepare grant applications and quarterly reports for current and prospective funders * Administer domains, trademarks, signing keys, cloud accounts, and social media * Advise enterprise legal teams on licensing, patent, warranty, and export control matters * Own the succession plan: identify, recruit, and onboard your replacement **How we’ll measure success** * GitHub stars * Time to first response on issues and pull requests * Release cadence and mean time to patch for disclosed vulnerabilities * Open issue and stale pull request backlog * Dependency freshness * OpenSSF Scorecard result and other automated project scoring * Community sentiment across public channels * Downstream adoption * Bus factor **What we’re looking for** * 8+ years of professional software engineering experience * Deep expertise in one systems language and professional proficiency in at least four others * Written communication pitched to audiences from first-time contributors to Fortune 500 CISOs * Consistent release cadence with minimal dependency churn and no breaking changes * Comfortable across engineering, support, security, community, marketing, finance, and legal * Balances contributors, enterprises, security researchers, regulators, and automated systems * Comfortable receiving direct public feedback and turning it into improvements * Availability overlapping core business hours in AMER, EMEA, and APAC * Able to respond to time-sensitive security matters outside normal working hours * Provides own hardware, reliable internet, and test environments for all supported platforms **Nice to have** * Prior experience in technical writing, developer relations, or community management * Experience migrating existing codebases to memory-safe languages * Working knowledge of licence compatibility and international trademark registration * Grant writing and nonprofit financial reporting experience * Media training * An established personal audience on at least one major social platform * Conversational proficiency in a second and third language * A second job **What we offer** * 100% remote, work from anywhere in the world * Complete flexibility over your working hours * High-impact work depended on by startups and Fortune 500 companies alike * Exceptional visibility and personal brand building opportunities * Regular speaking slots at leading industry events * The opportunity to develop close working relationships with several national CERTs * A passionate, highly engaged global user community * GitHub Sponsors enabled on the repository **How to apply** Please submit a CV, a link to your GitHub profile, and a short cover letter telling us what ownership means to you. Our interview process consists of a recruiter screen, a technical interview, a system design round, a take-home exercise, and a final community panel. If you don’t meet every requirement listed above, we’d still encourage you to apply. We are committed to building a diverse and inclusive community and welcome applicants from all backgrounds. This position will remain open until filled. Due to the volume of applications received, we are unable to respond to every candidate individually. _This role is not eligible for relocation assistance or visa sponsorship._
21346
Reposted by raptor
Jürgen Hubert @juergen-hubert.mementomori.social.ap.brid.gy · 29/08/2026
Thought of the day: We need more product testing teams consisting entirely of elderly people.
0518
Reposted by raptor
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 30/08/2026
A contribution from KDE on the definition of responsibility: community.kde.org/Guidelines_and_HO…
community.kde.org
Guidelines and HOWTOs/Maintainers and Contributions - KDE Community Wiki
000
Reposted by raptor
Misinformation-Superhighwayman @damienwise.aus.social.ap.brid.gy · 28/08/2026
The problem of fascists in Open Source Software projects has become so bad that some vim users are considering using emacs. #Neovim #fascism #OSS #OpenSourceSoftware
142
Reposted by raptor
Longhorn @never-released.mastodon.social.ap.brid.gy · 27/08/2026
The End of SPARC
001
raptor @raptor.infosec.exchange.ap.brid.gy · 26/08/2026
#RIPTimCurry
#RIP Tim Curry
012
Reposted by raptor
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 26/08/2026
compliance.jpg
Auditor: “It says here you have a firewall”
Customer: “.. I think so”
Auditor: “you’ve passed”
0011
Reposted by raptor
pancake :radare2: @pancake.infosec.exchange.ap.brid.gy · 25/08/2026
Modeling ELFs into SQL for execution fzakaria.com/2026/08/23/your-execut…
023
Reposted by raptor
Stefano on littleFedi @stefano.rpi0w.stefanomarinelli.it.ap.brid.gy · 26/08/2026
# This is the first genuinely operational littleFedi instance. It has been online since 1st July, is single-user (just me), and runs on a Raspberry Pi Zero W powered by NetBSD, directly on its SD card. **It consumes just under 1W.** Its database […] [Original post on rpi0w.stefanomarinelli.it]
My Raspberry PI Zero W, hosting this instance, in its current position. Powered by an USB cable coming from the switch.
91775
Reposted by raptor
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 24/08/2026
If, like me, you find it impossible to believe that this was 40 years ago, you're probably overdue for a colonoscopy.
264
Reposted by raptor
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 24/08/2026
The legendary Cliff Stoll gave a delightful talk at DEFCON on Stalking The Wily Hacker (40 Years Later) at DEFCON. It's now online. If you've never seen Cliff, a Klein Bottle, or an overhead projector before, rush over to the youtubes and fix that right now […]
federate.social
Original post on federate.social
21437