home.social

Search

1000 results for “infosecdj”

  1. Oh, and I also completed my reverse engineering project of a 8051-derived CPU core, used by Siemens in their . Because that's what I do with my free time, apparently. No other use except educational, really, and all the products using this particular implementation have been out of use for at least a decade now. But it was good practice on reading CMOS.

    codeberg.org/infosecdj/siemens

    Questions, comments, corrections welcome.

  2. *Rummages in the huge bag* Oh for...
    Oh, there we go. Welcome to the everyone!

    Today I got a nice old chip for you, it's the PIC16C715 by Microchip! A "high performance" RISC CPU with a bunch of peripherals, most importantly 2Kw program ROM, 128B RAM, and, would you believe it, an ADC!

    The image is oriented so that pin 1 is on the top edge. Notably, there are way more pads than the 18 pins of the package. I am most intrigued by those at the bottom where port B is.

    Many thanks to @RueNahcMohr for supplying this sample!

    Full-res map: infosecdj.net/map/microchip/pi

  3. Mushroom! Mushroom!

  4. RE: pixelfed.social/p/TheHeartofth

    Yes and no. They will still happily sue YOU for violations of their copyright.

  5. Well, I think I will leave it at that with this one. Hope you enjoyed!

    As always, thanks for reading! And if you liked my work -- just wanted to remind you I'm open for commissions. Hit me up if you need anything decapped, deprocessed, and imaged.

    Until next Friday, stay safe, stay cool.

  6. A whole bunch of SRAM cells here. I wonder what this unit is? Could be the 8-level stack?

  7. The oscillator circuit, with the output pad uhhh... moved slightly down.

  8. The MCLR/VPP pin is quite different from the others, probably because of the need to handle higher voltage.

  9. Parts of the design were obviously hand optimized, whereas others used standard cells. Those are properly huge in comparison.

  10. Some test points were kindly labelled for our reference.

  11. Part of the fabled ADC unit. Look at all them little capacitors!

  12. Some nice decoding action close to the PROM. The PLA seems to have 14 inputs (at the bottom there) -- unsurprisingly matching the instruction bit width.

  13. The program ROM takes a significant part of the die; it is a large array on the left side. Interestingly, the datasheet notes the PC is 13-bit to address 8K, but only 2K x 14 tops is implemented.

    Another peculiarity is, the memory is actually 16 bits wide, as there are 16 column groups of 16 columns each. What happens with the two extra bits?

    Not everything is well with row drivers too. There are 18 (or 36) sub-circuits which doesn't divide 2K evenly. Hmmm.

  14. The second piece of text is mask IDs, but nothing clearly identifying the die as 16C715.

  15. The manufacturer logo with maskwork and copyright years. I wonder what's being copyrighted here, as there is no microcode.

  16. YouTube Alternatives in 2026: Where to Publish, Where to Watch, and What Has Changed

    For most people today, YouTube is an integral part of the Internet. It’s not as if it has no competition.

    vsx.global/youtube-alternative

  17. 2026-W41 — Weekly Threat Roundup

    🔥 Critical vulnerabilities in NetScaler, SonicWall, AhsayCBS, and Atlassian are being actively exploited — patch windows are measured in hours, not days.
    🕵️ Flax Typhoon dismantled: FBI seized 7 domains and disrupted MicroScan/FishHub tools linked to China's Integrity Technology Group.
    🦠 Midnigh…

    threatnoir.com/weekly/2026-w41

    🤖 AI generated summary

  18. 🗞 Probably Fine Daily No. 14

    SonicWall patched on Tuesday. It was being exploited by Friday.

    Today's threat brief, read by AI — with receipts.
    ninjalabz.io/daily/2026-10-11/

    #cybersecurity #threatintel #infosec

  19. Security Tip: Implement Image Signing in your container workflow. 🛡️

    A secure registry is only part of the solution. By signing your images and enforcing verification via admission controllers, you prevent tampered images from reaching production. If the signature doesn't match, the pod doesn't start. This is a vital step for supply chain integrity.

    Track the latest container vulnerabilities at cvedatabase.com

  20. Security Tip: Implement the Principle of Least Privilege in your container environment. 🛡️ Running containers as a root user is a significant risk. If a vulnerability allows for a container breakout, the attacker inherits those root privileges on the host system. Actionable step: Always define a non-root USER in your Dockerfile and ensure your orchestration layer enforces non-privileged execution. Stay informed: cvedatabase.com

  21. ⚠️ CRITICAL: Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

    The GhostAction campaign is actively compromising GitHub maintainer accounts and injecting malicious workflows into thousands of repositories to steal API keys, tokens, and other secrets. If your organization uses dependencies from affected open-source projects, those workflows could exfiltrate you…

    threatnoir.com/focus

    🤖 AI generated summary

  22. ⚠️ CRITICAL: FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

    FortiBleed campaign is actively targeting 86,000+ FortiGate devices worldwide using credential stuffing and password spraying with stolen credentials from previous leaks. Successful compromises result in account lockouts of legitimate admins and device reconfiguration, with confirmed links to INC R…

    threatnoir.com/focus

    🤖 AI generated summary

  23. ⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

    threatnoir.com/focus

    🤖 AI generated summary

  24. Wp-Redirection (UK, open source) holds a Trust Score C with its lone CVE still unpatched at 100%. CVSS 4.3, CWE-352 CSRF. Low severity, but zero fixes shipped. Patch hygiene matters even for small plugins. #cybersecurity #WordPress #infosec valtersit.com/vendors/wp-redir

  25. A developer postmortem: a static host served a 150 KB internal handoff doc, including an admin payment-bypass parameter and notes on an unfixed payment hole, because the publish directory was the repo root. By the author's account it sat exposed for weeks with no alert. Two CDN purges failed, and rotating the bypass value changed little since it was in client-side source.

    tminuslabs.space/serving-secre

  26. First we warn them. They don’t listen. Then we illustrate. They don’t listen. Then the breach happens. They come to us in a panic, asking what they could have done to prevent this and what they can do now that it has happened. This is the sighbersecurity cycle.

  27. Closes TODAY (Oct 9): DOE's RFI on securing the US bulk-power system (EO 14421). Question B-7 asks how vulnerabilities reported by researchers are received, validated, remediated and communicated. Docket DOE-HQ-2026-1123.
    govinfo.gov/content/pkg/FR-202

    RSAC 2027 Call for Submissions closes Oct 15, 11:59 PM PT: rsaconference.com

  28. Security Tip: Move beyond static secrets. 🛡️ Static API keys and credentials are a major target for attackers. If a long-lived key is leaked, the blast radius is indefinite until manual revocation. Actionable step: Use a secrets management tool to automate rotation and transition to short-lived, dynamic credentials where possible. This limits the window of exploitation. Monitor new vulnerabilities and security trends at cvedatabase.com ...

  29. How can an entire industry accept the absurdity of ISO 27001—the self-proclaimed global standard for information security—being locked behind a copyright paywall?

    The argument that "ISO needs copyright to fund its operations" is laughable. Look at the open-source ecosystem. Thousands of critical software projects secure the modern internet daily without selling access to their source code. They rely on sponsorships, foundations, and community backing.

    #infosec #cybersecurity #grc #risk

  30. Security Tip: Implement automated API key rotation. 🛡️ Even with the best hygiene, secrets can leak. Regular rotation reduces the "shelf life" of a stolen credential, significantly limiting an attacker's window of opportunity. Don't rely on manual updates—use a dedicated secrets management tool to automate the lifecycle. Track the latest vulnerabilities and stay secure at cvedatabase.com

Share on Mastodon

Enter the server where you have an account.