Harry Sintonen
harrysintonen@infosec.exchange
<p>Infosec consultant at REVƎЯSEC <a href="https://reversec.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">reversec.com</span><span class="invisible"></span></a> - Coding, Research + various other interests</p>
Posts
-
View post
We Finns do love our salty liquorice... https://www.saarioinen.fi/tuotteet/salmiakkimaksalaatikko-350g/?lang=en
-
View post
#Debian [DSA 6528-1] linux kernel #security update has fixes to 1313 CVEs. https://lists.debian.org/debian-security-announce/2026/msg00441.html
-
View post
I've been quite happy with #Strongbox password manager. I migrated years ago from 1Password when they dropped functionality I needed and revoked the lifetime subscription.
-
View post
I spent nearly six hours tracking down a bug that was caused by not blocking signals correctly. As a result, signal processing could occur in the middle of a critical section. To make matters worse, the crash would only occur much later when the desync from the earlier overlapping execution would result in use-after-free and crash. The crash would not occur every time since it was timing-dependent - the signal would need to hit a relatively small window to trigger the issue. Figuring out the ro...
-
View post
It appears that AI companies target open source contributors with their marketing spam: "we noticed you contributed to curl/curl — thanks for helping build open source. We're running a small program for Github OSS contributors and would love to invite you. You'll receive $25 in XXXXXXXXX credits to use frontier AI models (this time YYYYY) through a single OpenAI-compatible endpoint." #enshittification
-
View post
Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape" https://www.openwall.com/lists/oss-security/2026/08/06/3 #CVE_2026_64564 #infosec #cybersecurity
-
View post
"As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled" 🤦♂️ What exactly did they expect would happen when following such policy? ref: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
-
View post
"Embargo klo 01:00" ja juttu julkaistu 00:01 - nyt ei kai ihan mennyt niin kuin suunniteltiin. #yleisradio
-
View post
#Engadget, yes we do have a reason not to watch #Babylon5 from YouTube.
-
View post
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights: - CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI. - CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). - CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split. - CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check....
-
View post
Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ #nablencentral #CVE_2026_18577 #infosec #cybersecurity
-
View post
40 years of #Byterapers: 1986: https://www.youtube.com/watch?v=txaIWaT6zik 2026: https://www.youtube.com/watch?v=TmwjZ33ID5k (Assembly 2026 #democompetition winner) Congratulations on continuing to be awesome! #demoscene
-
View post
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old. Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream. Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong. I've now reported the issue upstream, which will hopefully eventually lea...
-
View post
No, the libssh2 vulnerability CVE-2026-55200 isn't end of the world. 1. You need to defeat ASLR to successfully exploit it. The PoC works only when you disable ASLR. In most realistic use cases you need additional off-band infoleak from the app using libssh2. 2. You also must somehow convince the victim to connect to your malicious server, OR compromise some existing server to perform the attack. Calling this a "CRITICAL VULNERABILITY" is dumb.
-
View post
Back when the "internet" involved expensive phone calls and modems, someone figured out that a video backup system (VBS) could be used to distribute hundreds of megabytes of "backups" between friends by shipping a VHS cassette in a padded envelope. You just needed a VCR (everyone had one), and a small harness that could sample the video signal from the VCR for the software to decode. Interestingly, the Video Backup System website is still up: http://www.hugolyppens.com/VBS....
-
View post
13 2026-07-24 16:23:31 +0000 error: Corrected error, no action required., CPU 2, bank Unified Memory Controller (bank=17), mcg mcgstatus=0, mci CECC, mca DRAM ECC error. Ext Err Code: 0 Memory Error 'mem-tx: generic read, tx: generic, level: L3/generic', memory_channel=0,csrow=0, mcgcap=0x0000011c, status=0x9c2041000000011b, addr=0x72fb55480, misc=0xd01a000101000000, walltime=0x6a639183, cpuid=0x00a20f10, bank=0x00000011, microcode=0x0a201030 #ECCMemory saving the day.
-
View post
#openai #huggingface
-
View post
VESA Monitor Control Command Set (MCCS) standard "Asset Tag" function has a gaping flaw. The key is 16-bit and there is no rate limiting. 🤦♂️
-
View post
#Amazon #CloudFront seems to having global issues. https://health.aws.amazon.com/health/status
-
View post
I've started to outright block accounts posting AI slop or parroting AI company PR statements. Life is too short.
- View post
-
View post
Risto Mikael Riihimäki, owner of Rent ja Kalusto Oy, has been sentenced to three years and 8 months in prison for a aggravated regulatory offence. The company delivered 135 trucks and 29 trailers to Russia, circumventing the EU sanctions. In court, the company claimed that the items were destined for Kazakhstan or Turkey, but Finnish officials were able to recover the communications between Riihimäki and his Russian contacts, making it clear where the items were really destined. The company was...
-
View post
I hate it when I'm right about these things. https://www.euronews.com/my-europe/2026/06/26/eu-countries-move-to-revive-temporary-message-scanning-regime-but-it-could-backfire https://infosec.exchange/@harrysintonen/115383111569608066 #stopchatcontrol #privacy
-
View post
I have consistently refused to engage AI in any tasks that require mental effort. Intuitively, I felt that it leads to laziness and eventual deterioration of problem-solving skills. I still consistently challenge myself by solving already solved problems - not because they haven't been solved well already - but in order to maintain my skills. I can only recommend this approach. https://www.nature.com/articles/d41586-026-01947-1
-
View post
Heads up to anyone using #AMD CPUs in a setting where Transparent Secure Memory Encryption (TSME) is critical: AMD has disabled this feature for consumer AMD products as of the latest AGESA updates. The feature is now only available for "PRO" CPU variants. https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/ #enshittification
-
View post
I, for one, hail our EU overlords for staying their ground and not bending over to Apple. This EU regulation did not come as a surprise to anyone, and definitely not to Apple. Yet they decided to go all knee-jerky about it. Food for thought: If you cannot implement an AI feature in an interoperable and safe manner, it likely should not be implemented at all.
-
View post
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions. #CVE_2026_45447
-
View post
As it happens, we still use CVS in our operating system project (there are reasons for doing this, but migration to git would indeed make sense). While working on our project, we occasionally have to do a full checkout of the whole codebase, which is several gigabytes. Over time, this operation has gotten very, very, very slow - I mean &quot;2+ hours to perform a checkout&quot; slow. This was getting quite ridiculous. Even though it&#39;s CVS, it shouldn&#39;t crawl like this....
-
View post
Vulnerabilities found from #curl: #Mythos: 1 Me: 30 - https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ - https://sintonen.fi/advisories/
-
View post
I&#39;ve tried to report a security vulnerability to @signalapp for months now (first attempt was 2025-11-23 to the official security-at email address). I haven&#39;t gotten any response from them, even after repeated attempts. This is highly frustrating. Is there a way to reach them? I don&#39;t need any kind of special treatment, just someone acknowledging that the message has been received would be okay. #signalapp