blasty
4.3K posts

blasty
@bl4sty
irresponsible disclosure aficionado
The Netherlands เข้าร่วม Nisan 2009
1.1K กำลังติดตาม17.2K ผู้ติดตาม
blasty รีทวีตแล้ว

Prompt: "This dude is ranting about some remote kernel/android bug his priv8 model found on the tweeter can you find it, setup a VM, and write a POC to trigger it?"

Tim Becker@tjbecker
Xint Code found a 0-click kernel memory corruption bug, likely weaponizable as wormable RCE, affecting many Android phones, including Pixels. We reported this in February, along with 10 other high+ severity bugs, but are waiting for a patch to ship before sharing more details.
English

@modrobert @qualys yeah that's some good fuel for the rewrite-everything-in-rustlang flamewars ;)
English

This part was interesting as well:
"As a side note, we also discovered a local vulnerability (a race condition) in the uutils coreutils (a Rust rewrite of the standard GNU coreutils -- ls, cp, rm, cat, sort, etc), which are installed by default in Ubuntu 25.10. This vulnerability was mitigated in Ubuntu 25.10 before its release (by replacing the uutils coreutils' rm with the standard GNUcoreutils' rm), and would otherwise have resulted in an LPE (from anyunprivileged user to full root) in the default installation of Ubuntu Desktop 25.10."
Wasn't Rust supposed to be safer? ;)
English

imagine the suspense! very nice work from @qualys once again :) cdn2.qualys.com/advisory/2026/…

English

@yacineMTB @cnlohr strat seems legit, wrangle until you pass DRC and start iterating by submitting pcb orders. at some point you'll have a steady rate of jlcpcb deliveries coming in; just gotta keep track of em and feed the bringup failure diag back into the clanker (and x) for design perfection
English

@cnlohr my general approach right now is to simply find some reference kicad designs, figure out every single decision and the tradeoffs involved, learn spice and other simulators and bang at it. and then ask really stupid questions to bait people into imparting knowledge
English

@lina/116198976928184530" target="_blank" rel="nofollow noopener">vt.social/@lina/11619897… this sums up the CTF vs LLM stuff nicely. Good job @Lina_Hoshino !
the competitive metric (ctftime) is dead/a gimmick at this point...
.. as a retired and washed up competitive ctf player with user id #18 on ctftime it is kinda saddening to see it implode like this. ;-(
I simply don't see any workable solution to bring back fair competitive CTF (with varying difficulty).
you could argue "well anyone can use the LLM's, that levels the playing field". by definition that means
1) you need anti-LLM (difficult) tasks, killing the element of having varying difficulty ("something fun for everyone").
2) teams/entities with cashflow could buy more clankers/compute/access to more expensive models, etc.
3) you're really gonna sit there and watch codex dream up "the house of force" instead of revisiting github dot com slash shellphish slash how2heap all by yourself
and yes I'm aware of all the various "underhanded" CTF tactics teams have employed over the years (where is that picture of the iceberg?); but forcing everyone who wants to compete to start using the ridiculous cheatcode doesn't feel like it addresses/fixes anything..
back in the days when we had to address fairness adjustment in the scoring algo of individual CTFs or ctftime as a whole we'd have a civil discussion (that would sometimes quickly erupt into a full on flamewar) on IRC with the involved parties. I'm afraid the solution is not so simple this time around :)
yo @kyprizel @leetmore @snkdna @hellman1908 I'm curious to hear how you people feel/think about this situation
English

@pr0cf51 Do you mean vulns in crypto algorithms/systems, or actually real world deployment of crypto usage? If the latter, the answer probably is: "most real-world crypto vulnerability mostly stem from SECRET KEYS IN GITHUB REPOS".
English

looking to commission someone to design a board like this for a reasonable price. any recommendations? @Mirko_DIY @mangopi_sbc maybe? :)
English

this silicon valley clip aged like fine wine: youtube.com/watch?v=m0b_D2… (and many other scenes/scenario's from the series as well, worth a rewatch! :-))

YouTube
English








