infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

Why is it that every time I touch an analysis tool I find a blocker bug, but when I touch the target I actually want to analyze...

https://www.youtube.com/watch?v=4G6QDNC4jPs
this post | permalink
@VoltPaperScissors @marove @VVoidCamp We're going to have so much fun with this (and not just with kids)! Thank you!
this post | permalink
@Aurimas @tychotithonus At least you don't have to deal with this in case of CrowdStrike :)
this post | permalink
@tychotithonus I think this dilemma is equivalent to the USGOV vs. Kaspersky case. After some point you have to trust your supply chain. If that's not reasonable, you cut ties.

(I know this is not an answer, but my gut tells me this isn't really a technical problem to solve)
this post | permalink
@bascule Or at least buy a CO detector! I also lost a friend to that shit...
this post | permalink
@cR0w Also considering the recent activity around the Linux kernel...
this post | permalink
I'm tired enough to read "CVE Nürnberg Authority" and think that vulnerability management took a quite radical turn
this post | permalink
SEC Consult SA-20250226-0 :: Multiple vulnerabilities in Siemens A8000 CP-8050 & CP-8031 PLC

https://seclists.org/fulldisclosure/2025/Feb/19

- Firmware Downgrade (CVE-2024-39601)
- Firmware Update Decryption via Secure Element Oracle (CVE-2024-53832)
this post | permalink
[RSS] Taking the relaying capabilities of multicast poisoning to the next level: tricking Windows SMB clients into falling back to WebDav

https://www.synacktiv.com/en/publications/taking-the-relaying-capabilities-of-multicast-poisoning-to-the-next-level-tricking
this post | permalink
[RSS] A Deep Dive into JS Trusted Types Violations

https://bughunters.google.com/blog/5850786553528320/a-deep-dive-into-js-trusted-types-violations
this post | permalink
Next Page