infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

Officially lost track of Linux page cache LPE's - see also: "cache invalidation and naming things":

https://github.com/v12-security/pocs/tree/main/fragnesia

This is CVE-2026-46300
this post | permalink
@icing Don't give them ideas!
this post | permalink
[RSS] Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.

https://blog.trailofbits.com/2026/05/12/go-fuzzing-was-missing-half-the-toolkit.-we-forked-the-toolchain-to-fix-it./
this post | permalink
[RSS] Exploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgrade

https://www.synacktiv.com/en/publications/exploiting-the-tesla-wall-connector-from-its-charge-port-connector-part-2-bypassing.html
this post | permalink
@wdormann @christopherkunz @jhr77 Vuln mgmt is hard, e.g. how you track patch coverage vs. signature update status? Not that pushing a sig was a bad idea, I'd just expect a KB for this too.
this post | permalink
@wdormann @jhr77 @christopherkunz I don't see a Defender entry in today's update that also points to this being a signature based mitigation
this post | permalink
@ekuber Having a chopper to call when you go hiking is definitely nice :D I don't quite get how the principles apply here though: in your opinion, for this particular example, would it be right to require all traits by ::new()?
this post | permalink
@ekuber Don't get me wrong, I'm positively amazed by rustc messages in general, and this one is no exception. On the other hand I also like to see how I should approach the API I'm about to use, having a map about the code base before I go down a path that just won't work. I feel like relying on the compiler is like periodically calling a hovering helicopter to get out of the woods, instead of having a proper $5 map.
this post | permalink
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim

https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
this post | permalink
@stf "might affect cryptology at some future time or (more likely) in some other world." I forgot about this one lol
this post | permalink
Next Page