infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

"Bad programmers worry about the code. Good programmers worry about data structures and their relationships."

Are there any (case-)studies about using LLM's to create data models?
this post | permalink
SEC-T 0x10: Jonas Vestberg - Hello my name is QSECOFR

https://www.youtube.com/watch?v=Zt5AOR5zLhM

Very nice presentation about #IBMi security, including post-exploitation steps and lateral movement via pass-the-hash!
this post | permalink
‘Reasoning’ AI is LYING to you! — or maybe it’s just hallucinating again /by @davidgerard

https://pivot-to-ai.com/2025/04/18/reasoning-ai-is-lying-to-you-or-maybe-its-just-hallucinating-again/
this post | permalink
Hash Resolver Resolve hashed API names by emulating the hashing function in-place using Unicorn Engine + #IDA integration.

https://github.com/moreveal/hash-resolver
this post | permalink
Tracing malloc calls in PCode

https://scribe.rip/@cy1337/tracing-data-flow-with-pcode-f879278d9fc1

#Ghidra #ReverseEngineering
this post | permalink
[RSS] Zero Day Quest 2025: $1.6 million awarded for vulnerability research

https://msrc.microsoft.com/blog/2025/04/zero-day-quest-2025-1.6-million-awarded-for-vulnerability-research/
this post | permalink
[RSS] A First Glimpse of the Starlink User Ternimal

https://www.darknavy.org/blog/a_first_glimpse_of_the_starlink_user_ternimal/
this post | permalink
[RSS] Cybersecurity (Anti)Patterns: Busywork Generators

https://spaceraccoon.dev/cybersecurity-antipatterns-busywork-generators/
this post | permalink
[oss-security] CVE-2025-29953: Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass

https://www.openwall.com/lists/oss-security/2025/04/18/3

"servers could abuse the unbounded deserialization *in the client* to provide malicious responses that may eventually cause arbitrary code execution on the client"

"The project is considering to [...] drop this part of the NMS API altogether."
this post | permalink
@tychotithonus Straight to jail.
this post | permalink
Next Page