dhulliger @ruheabteil.ch · 08/06/2026Shoutout to Mole, our @binary.ninja plugin that made these findings possible. Mole finds interesting execution paths in binaries by performing backward slicing on variables in MLIL SSA form, enabling static taint analysis. Mole: github.com/cyber-defenc... Advisory: certvde.com/en/advisorie...certvde.com MBS: Several security vulnerabilities in the UGW web GUI 032
dhulliger @ruheabteil.ch · 05/06/2026finally seen some real good use of ai www.youtube.com/watch?v=z3pV...youtube.comVibeOS - Fully Hallucinated Operating SystemYouTube video by Zev.3R 010
Reposted by dhulligerAltYellostoneNatPar @altyellonatpark.org · 17/03/2026Life is actually pretty simple 12881231
dhulliger @ruheabteil.ch · 02/03/2026Sad truth youtu.be/T4Upf_B9RLQ?...youtu.beA Day in the Life of an Ensh*ttificatorYouTube video by Forbrukerrådet - Norwegian Consumer Council 000
dhulliger @ruheabteil.ch · 28/01/2026Worth watching! youtu.be/3C1Gnxhfok0?...youtu.be39C3 - A post-American, enshittification-resistant internetYouTube video by media.ccc.de 000
Reposted by dhulligerUkraine Advocate 🇺🇦 @eugenemcparland.eurosky.social · 24/01/2026Are you concerned about your privacy and the power abuse by American tech companies? This website helps you switch to European and open-source alternatives. switch-to.eu/en/switch-to.euSwitch-to.eu - EU alternatives to global servicesA guide to help you switch from non-EU to EU-based digital services and products. 38148
dhulliger @ruheabteil.ch · 25/01/2026Nothing new, but the current political situation in the US just makes it way more of an issue! 001
Reposted by dhulligerheiseonline @heise.de · 23/01/2026In Minnesota wurden Aktivistinnen festgenommen, die Proteste gegen ICE organisiert haben sollen. Von einer hat das Weiße Haus ein Foto manipulieren lassen. #Bildbearbeitungheise.deWeißes Haus verbreitet KI-manipulierte Aufnahme von festgenommener AktivistinIn Minnesota wurden Aktivistinnen festgenommen, die Proteste gegen ICE organisiert haben sollen. Von einer hat das Weiße Haus ein Foto manipulieren lassen. 713865
Reposted by dhulligerMarco Arrigoni / Seichnungen @marcoarrigoni.bsky.social · 18/01/2026Wie jedes Jahr: Hoffen auf Weltverbesserung am @worldeconomicforum.bsky.social 021
Reposted by dhulligerPaige Bailey (webpaige.dev) @dynamicwebpaige.bsky.social · 12/01/2026🧵 Thread on beautiful data centers: MareNostrum 4 (Barcelona SCC): Often called "the most beautiful data center in the world," this facility is housed inside the Torre Girona Chapel, a deconsecrated 19th-century church. When fully installed, it will have a peak performance of 13.9 Petaflops. 715048
Reposted by dhulligerInk Radio @inkradio.bsky.social · 26/12/2025Usually I can’t wait for a sequel but… 10265061354
Reposted by dhulligerDamian Pfammatter @damianpfammatter.bsky.social · 10/12/2025First two unauthenticated RCE CVEs published - Discovered with the help of our #Binja plugin #Mole! 🔗 Advisory: certvde.com/en/advisorie... @ruheabteil.ch 🔗 Mole: github.com/cyber-defenc... More vulnerabilities have been reported - stay tuned for upcoming advisories.certvde.com WAGO: Vulnerabilities in WAGO Industrial-Managed Switches 022
Reposted by dhulligerSocket @socket.dev · 31/10/2025🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from a recent MIT-linked report now drawing widespread criticism. → socket.dev/blog/securit...socket.devSecurity Community Slams MIT-linked Report Claiming AI Power...Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood. 0188
Reposted by dhulligerSpelling Mistakes Cost Lives @darrencullen.bsky.social · 07/08/2025Did a new one 3777072730
dhulliger @ruheabteil.ch · 22/10/2025Earlier that year @damianpfammatter.bsky.social and me had time to play with domotics equipment. Finally the patches and advisories were released: www.certvde.com/en/advisorie...certvde.com Sauter: Multiple vulnerabilities in SAUTER modulo 6 011
Reposted by dhulligerPhrack Zine @phrack.org · 12/09/2025Thanks for the excellent writeup @intel471.bsky.social www.intel471.com/blog/the-phr...intel471.comThe Phrack leak: Examining an APT’s workstationIn August 2025, two anonymous researchers released 9 GB of data from a workstation of a likely advanced persistent threat (APT) group. Here’s an analysis of the data by Intel 471’s Cyber Geopolitical ... 0195
Reposted by dhulligerMicah Lee @micahflee.com · 19/08/2025My DEFCON talk "We are currently clean on OPSEC" now has over 30k views on YouTube, so now more people watched my talk than attended DEFCON itself. If you haven't seen it, please do! The Trump admin's incompetence is mindbogglingly BONKERS www.youtube.com/watch?v=KFYy...youtube.com"We are currently clean on OPSEC": The Signalgate Saga (DEFCON 33)YouTube video by Micah Lee 410535
Reposted by dhulligerBinary Ninja @binary.ninja · 14/08/2025Check out our latest blog post on modeling complex control flow with function-level basic block analysis in Binary Ninja 5.1. From DSPs to Brain***k, this update makes it easier to develop plugins for tricky architectures. binary.ninja/2025/08/12/f... 073
Reposted by dhulligerOlaf Hartong @olafhartong.nl · 06/08/2025During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/... Slides available here: github.com/olafhartong/...github.comGitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR 02515
Reposted by dhulligerDavid Buchanan @retr0.id · 31/05/2025cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort() 643975
Reposted by dhulligerJust Jack @just-jack-1.bsky.social · 07/05/2025Linda McMahon, Secretary of Education, sent Harvard a letter. They graded it. Bwahahaha. 21724494312894
Reposted by dhulligersixtyvividtails @sixtyvividtails.bsky.social · 06/05/2025Heard of #ContextJail? It's a nasty new technique: puts target thread into ⓪ deadloop, for as long as you can afford. Requires THREAD_GET_CONTEXT right. The gist? Just spam NtGetContextThread(tgt).😸 Target will be jailed, running nt!PspGetSetContextSpecialApc 🔁. Src & binary in [ALT]. Usecases: ⤵️ 176
dhulliger @ruheabteil.ch · 09/04/2025Someone please show to the orange man.. xkcd.com/3073xkcd.comTariffs 010
Reposted by dhulligerAnge @angealbertini.bsky.social · 01/04/2025The craziest file I made & visualized recently was combining the Doom PDF with a DOS & Windows (EXE & PE) polyglot. It runs Doom on OS from 1993 until today, and Chrome-based PDF viewers! You can make it an HTML/JS polyglot too to run on most browsers! (3/3) 0226
Reposted by dhulligerJared Rizzi @jaredrizzi.bsky.social · 26/03/2025quick guide to Signal's disappearing messages settings 10587136
Reposted by dhulligerWietze @wietzebeukema.nl · 24/03/2025By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi... 13619
Reposted by dhulligerDavid Buchanan @retr0.id · 19/03/2025the most important aspect of kernel development is to make sure your driver freaks the fuck out whenever the system resumes from sleep 3396769
Reposted by dhulligerRastaMouse @rastamouse.me · 05/03/2025[BLOG] I had a series in mind like "Rubeus' Hidden Secrets" or something like that. Basically, highlighting features of the tool that seem less well known. I'm starting off with a basic one for getting crackable hashes from cached service tickets. rastamouse.me/kerberoastin...rastamouse.meKerberoasting w/o the TGS-REQKerberoasting is a technique that allows an attacker to extract the encrypted part of a TGS-REP and brute force it offline to recover the plaintext password of the associated service account. The most... 0186
Reposted by dhulligerhalvarflake.bsky.social @halvarflake.bsky.social · 22/02/2025I gave a day 1 closing keynote at DistrictCon yesterday. Surprisingly, it was a security talk about memory safety. Slides are here: docs.google.com/presentation...docs.google.comMemory SafetyIs this memory safety here in the room with us? Halvar Flake / Thomas Dullien DistrictCon 0 2025 512029
dhulliger @ruheabteil.ch · 13/02/2025Why making responsible disclosure as cumbersome as possible? Did I miss a hidden agenda to go back to full disclosure vulns in random mailing lists? 000
dhulliger @ruheabteil.ch · 02/02/2025youtu.be/6ad4MH7fMLs?...youtu.beProphets of Rage - Unfuck The World (Music Video)YouTube video by ProphetsOfRageVEVO 000
Reposted by dhulligermthcht @mthcht.bsky.social · 31/01/2025Say goodnight to the bad GUIDs ! badguids.github.io 186
Reposted by dhulligerJames Forshaw @tiraniddo.dev · 30/01/2025New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...googleprojectzero.blogspot.comWindows Bug Class: Accessing Trapped COM Objects with IDispatchPosted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ... 26541
Reposted by dhulligerdmnk @dmnk.bsky.social · 28/01/2025Paper is here: www.usenix.org/conference/u... Code at github.com/pr0me/SAFIRE...usenix.orgForming Faster Firmware Fuzzers | USENIXusenix_logo_notag_white 012
Reposted by dhulligerhasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...hshrzd.wordpress.comProcess Hollowing on Windows 11 24H2Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us… 05838
dhulliger @ruheabteil.ch · 27/01/2025A vulnerability reported in September 2022 to Poly apparently got a CVE in 2024 (CVE-2024-27460). Never was informed. After reporting I did countless requests for updates and as the company being bought by HP i lost hope they would publish anything. support.hp.com/us-en/docume... 000
dhulliger @ruheabteil.ch · 16/12/2024Monday tunes youtu.be/vBrazzkIeLA?...youtu.beWhiskey and GinYouTube video by The Killigans - Topic 000
Reposted by dhulligerbeercow.bsky.social @beercow.bsky.social · 14/12/2024Python tool that converts Microsoft Defender Antivirus Signatures (VDM) into YARA rules. github.com/t-tani/defender2yaragithub.comGitHub - t-tani/defender2yara: Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rulesConvert Microsoft Defender Antivirus Signatures (VDM) into YARA rules - t-tani/defender2yara 096