infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] Exploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed

https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/
this post | permalink
Python packages are age-shaming my OS :(
this post | permalink
[RSS] TruffleHog, Fade In and BSAFE Crypto-C vulnerabilities

https://blog.talosintelligence.com/trufflehog-fade-in-and-bsafe-crypto-c-vulnerabilities/
this post | permalink
@Daojoan the best ideas are often simple too though
this post | permalink
Technical tasks where LLMs proved to be incredibly useful for me:

- Fixing bugs in Gradle scripts
- Resolving systemd and Network Manager fights

I see a pattern emerging!
this post | permalink
[RSS] Critical RCE Vulnerability CVE-2025-11953 Puts React Native Developers at Risk

https://jfrog.com/blog/CVE-2025-11953-critical-react-native-community-cli-vulnerability

"The Metro development server [..] binds to external interfaces by default [...] The server%27s /open-url endpoint handles a POST request that includes a user-input value that is passed to the unsafe open() function provided by the open NPM package, which will cause OS command execution."
this post | permalink
[RSS] Four Bytes, One Lie: A SMAP-Free Confidence Trick on Kernel Pointers :: Out of Bounds

https://www.oobs.io/posts/four-bytes-one-lie/

CVE-2025-50168
this post | permalink
@natashenka Link broke :(
this post | permalink
[RSS] BGGP6 Announcement

https://n0.lol/bggp6-announcement/
this post | permalink
[RSS] deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented Harnesses

https://github.com/purseclab/deepSURF
this post | permalink
Next Page