infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@DGutie @xabd Thanks, that's exactly why I don't really see the use-case for this. Even considering the 1-click deployment options - if you know those services, you can write 20 lines of HTML (that will not even look like everyone else's linktree).
this post | permalink
[RSS] Pickling the Mailbox: A Deep Dive into CVE-2025-20393

https://starlabs.sg/blog/2026/01-pickling-the-mailbox-a-deep-dive-into-cve-2025-20393/
this post | permalink
[RSS] TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244

https://www.oobs.io/posts/er605-1day-exploit/
this post | permalink
AMD updates installed without signature checking (from an HTTP link, no less)? /via @drwhax

https://mrbruh.com/amd/

Recent report about a nation-state implant that would be useful to exploit this:

https://blog.talosintelligence.com/knife-cutting-the-edge/
this post | permalink
@drwhax Many sw use HTTP updates so they can get through middleboxes. The bigger issue here is the lack of executable authenticode verification.
this post | permalink
@lindsey yes.
this post | permalink
@TarkabarkaHolgy that's actually reasonable, it's modern expectation of modern family logistics that is bonkers
this post | permalink
[RSS] Django SQL Injection in RasterField lookup (CVE-2026-1207)

https://vulnerabletarget.com/VT-2026-1207
this post | permalink
[RSS] CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

https://www.thezdi.com/blog/2026/2/4/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall
this post | permalink
PSA: Nicholas Lemonias is still an asshat.

https://attrition.org/postal/asshats/nicholas_lemonias/
this post | permalink
Next Page