infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] CVE-2026-78902: XSS to RCE in pfSense with one DNS request

https://www.netspi.com/blog/technical-blog/web-application-pentesting/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/
this post | permalink
[RSS] How One Twitch Chat Message Became Code Execution on a Streamer's PC

https://blog.scrt.ch/2026/09/22/how-one-twitch-chat-message-became-code-execution-on-a-streamers-pc/
this post | permalink
Can gzip be a language model?

https://nathan.rs/posts/gzip-lm/
this post | permalink
It's funny how WinDbg's TTD docs[1] emphasizes that PII may appear in dumps, while e.g. docs for crash dump analysis[2] don't.

Based on the observation that behind every warning sign there is a story I suspect that at one point a TTD trace somehow resulted in summoning MS's legal team :)

[1] https://learn.microsoft.com/en-us/windows-hardware/drivers/debuggercmds/time-travel-debugging-overview
[2] https://learn.microsoft.com/en-us/windows/win32/dxtecharts/crash-dump-analysis
this post | permalink
Today's xkcd is especially unhinged, love it!

https://xkcd.com/3301/
this post | permalink
[RSS] Windows Exploitation Techniques: Dangling COM Object Registrations

https://projectzero.google/2026/09/windows-dangling-com.html
this post | permalink
#IBMi could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys

https://www.ibm.com/support/pages/node/7285846

The 90s called and want their dumb obfuscation back!
this post | permalink
@Natasha_Jay I really like Andorra's concept of Transportation via Electric Boogie!
this post | permalink
[RSS] Advisory X41-2026-004: dm-verity can be bypassed in Debian live-boot

https://x41-dsec.de/lab/advisories/x41-2026-004-debian-live-boot/
this post | permalink
[RSS] ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553

https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
this post | permalink
Next Page