buherator
buherator@infosec.place
"I'm interested in all kinds of astronomy."
Posts
-
View post
FlyDubai crew is pretty badass!
-
View post
"This 3-day training focuses on macOS Vulnerability Research (VR) for beginner to intermediate students. While intermediate topics will be discussed, the course focuses on bringing security researchers up to speed with macOS’s unique protections and vulnerabilities" Great content from my friends, now in Budapest: https://macosvuln.training
-
View post
I recently learned to distinguish rabbits from hares (from a shitpost ofc) and now I feel slightly offended because my emoji keyboard shows a rabbit but it clearly renders as a hare in the app. 🐇
-
View post
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5 https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
-
View post
An old friend is ashamed of speaking English with people but want to practice. Any pro/cons of using an educational chatbot for this? At first I find this a pretty good use case for language models.
-
View post
That's right, the right answer for this questions is: 3! By first pressing the down arrow you remove the selection (which you didn't put there) from the address bar text. The two downs are needed to reach C:\Users\Public. "2 or 3" would be also acceptable, because if you don't just click the address bar, but start to type in it, there is no selection to remove. https://infosec.place/objects/85dfac07-d1d6-412b-832c-897be5be860b
-
View post
#Windows experts, can you answer this without trying: How many times do you need to press the down arrow to select C:\Users\Public? #UX #UI
-
View post
Session timeouts[1] provide great examples of #compliance disconnects from reality: When booking for events it *always* takes *days* to get from registering for an event and getting there to show your QR or whatever. And while an attacker who hijacks your session has 0 benefit from accessing it for a prolonged time, somehow #security finds it crucial that users are auto logged-out after 30mins. It would take just a *tiny* bit of thinking to avoid making things worse for everyone. [1] https:...
-
View post
Umm why does infosec.place "access my device"? /cc @jerry@infosec.exchange
-
View post
[RSS] Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
-
View post
Today's xkcd is especially unhinged, love it! https://xkcd.com/3301/
-
View post
[RSS] Advisory X41-2026-004: dm-verity can be bypassed in Debian live-boot https://x41-dsec.de/lab/advisories/x41-2026-004-debian-live-boot/
-
View post
Seems like AI companies are not that easygoing when they are on the wrong end of hacking :P https://threadreaderapp.com/thread/2101252692635004997.html
-
View post
[RSS] What Go Taught Us About Java Garbage Collection https://debugagent.com/what-go-taught-us-about-java-garbage-collection
-
View post
Dependency Cooldowns for different package ecosystems https://cooldowns.dev
-
View post
[RSS] Apple Reference Image: A New Approach for Verified Photography https://security.apple.com/blog/apple-reference-image
-
View post
This IT Crowd episode predicted the AI boom (except instead of covering bad team dynamics we try to prevent $NVDA go down): https://www.youtube.com/watch?v=uyV0IVItlM4
-
View post
Some places of #Fedi literally require you to look up the Communist Manifesto. Un-fucking-believable.
-
View post
When you help out at a friends kitchen and take a nice looking knife they're usually like "it's shit, don't use that! use this." then hand you an old piece in seemingly questionable condition that was used to skin bears during The War and is still so sharp you need safety goggles just to look at it. Is this world-wide or just an Eastern-European thing? #cooking
-
View post
FFS Reddit is now using "protecting communities from scrapers" as an excuse to kill RSS. Great job everyone coming up with this BS! https://old.reddit.com/r/modnews/comments/1tq9vxo/protecting_communities_from_scrapers_and_platform/
-
View post
[RSS] Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days http://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html
-
View post
I thought I'm making up a conspiracy theory around NVIDIA architecting the AI bubble after the crypto bubble bursted. It seems @david_chisnall@infosec.exchange agrees (sort of): RE: https://infosec.exchange/@david_chisnall/117075838205635406
-
View post
[RSS] 4 jsoup vulnerabilities https://joshua.hu/4-jsoup-vulnerabilities
-
View post
[RSS] The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
-
View post
[RSS] 22 CVEs in TeamDavid(R) a "secure" M365 alternative https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
-
View post
[RSS] LLMs won't break symmetric crypto https://www.bfswa.blog/p/llms-wont-break-symmetric-crypto
-
View post
[RSS] Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
-
View post
[RSS] KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
-
View post
96 degrees in the shaaaaade https://www.youtube.com/watch?v=hwE5gfZlMZY
-
View post
LLM2Human Clinic https://llm2human.pages.dev/