infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

#Windows 11 has this nifty "desktop" icon on the taskbar. It's impossible to figure out what the icon is for unless you click it but I digress.

When you click the thing, the minified versions of the windows on the current desktop are arranged on top of the desktop, but the icons etc. underneath are still clearly visible.

Guess what happens when you click on an icon visible on the desktop, not one of the little windows? That's right, the little window closest to the click gets the focus!

I remember, when the intuitive #UI of Windows 3.1 where you could click things to do stuff with them (and not their closest neighbor) was all the rage...
this post | permalink
[RSS] Technical Analysis of WhatsApp Zero-Click Exploit

https://www.courtlistener.com/docket/16395340/741/45/whatsapp-inc-v-nso-group-technologies-limited/

From court documents
this post | permalink
Back in the day when I found an string during #reverseengineering that looked like some trademark, I could use a search engine and find the statically linked library, some API docs, etc.

Now I either get results from some obscure "AI" company SEO spamming or a random character from some even more obscure manga with unreasonably detailed fan wiki pages.
this post | permalink
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5

https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
this post | permalink
[RSS] Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)

http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html
this post | permalink
[RSS] Probabilistic analysis of MTE tagging schemes

https://dustri.org/b/probabilistic-analysis-of-mte-tagging-schemes.html
this post | permalink
[RSS] From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities

https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/
this post | permalink
[RSS] A Mere Mortal's Introduction to JIT Vulnerabilities in JavaScript Engines

https://trustfoundry.net/blog/jit-vulnerabilities-javascript-engines
this post | permalink
I recently learned to distinguish rabbits from hares (from a shitpost ofc) and now I feel slightly offended because my emoji keyboard shows a rabbit but it clearly renders as a hare in the app. 🐇
this post | permalink
"This 3-day training focuses on macOS Vulnerability Research (VR) for beginner to intermediate students. While intermediate topics will be discussed, the course focuses on bringing security researchers up to speed with macOS’s unique protections and vulnerabilities"

Great content from my friends, now in Budapest:

https://macosvuln.training
this post | permalink
Next Page