#fulldisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fulldisclosure, aggregated by home.social.
-
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
#HackerNews #FullDisclosure #Azure #SignIn #LogBypass #CyberSecurity #Vulnerability #TechNews
-
Plethore of critical #Linksys MX4200 Wi-Fi router vulnerabilities (that were originally reported to Linksys nearly a year ago!) are still unfixed:
- [SYSS-2025-001] Linksys MX9600/MX4200 - Path Traversal https://seclists.org/fulldisclosure/2026/Feb/10
- [SYSS-2025-002] Linksys MX9600/MX4200 - Missing Authentication for Critical Function https://seclists.org/fulldisclosure/2026/Feb/11
- [SYSS-2025-009] Linksys MX9600/MX4200 - SQL Injection https://seclists.org/fulldisclosure/2026/Feb/12
- [SYSS-2025-010] Linksys MX9600/MX4200 - OS Command Injection https://seclists.org/fulldisclosure/2026/Feb/13
- [SYSS-2025-011] Linksys MX9600/MX4200 - OS Command Injection https://seclists.org/fulldisclosure/2026/Feb/18
- [SYSS-2025-014] Linksys MX4200 - Improper Verification of Source of a Communication Channel
https://seclists.org/fulldisclosure/2026/Feb/19
On first read it might appear that many of these vulnerabilities would only be exploitable by accessing the device non-WAN interface(s) from inside the local network. However, due to the SYSS-2025-014 vulnerability the normally "LAN only RCE" vulnerabilities (SYSS-2025-010 and -011) and SQL injection (SYSS-2025-009) can be performed from the WAN interface (read: the internet). The attacker merely needs to make the connection originate from port 5222 (which is trivial to arrange via local bind before connect).Update: Users of Linksys MX4200 should upgrade to firmware version 2.0.7.216620 or later. While not all of the security issues are fixed, it at least should stop the attacks via the WAN interface (SYSS-2025-014). https://support.linksys.com/kb/article/952-en/
#linksys #fulldisclosure #vulnerability #infosec #cybersecurity
-
Full disclosure in computer security still exists and is complementary to other disclosure models. The evolution of vulnerability disclosure is not linear from full disclosure to responsible disclosure to coordinated disclosure. These models coexist and all need to be taken into account.
You can’t just say “the legal framework will solve it” or “just do coordinated disclosure.” Vendors, researchers, and users are not all rational actors playing the same game.
Vulnerability disclosure is more complex than that, and if you actually want to address the issue, you can’t just say “it doesn’t exist.”
#cve #gcve #vulnerabilitymanagement #cybersecurity #fulldisclosure #vulnerability
-
I gave no idea, zero (0), how they got a high severity CVSS out of missing response headers. I mean, are they important? Sure! Don't you put that on reports, Bill? You bet! 8.3 severity? I'd be laughed out of the readout call.
-
To everyone using #MintLinux:
Please run `sudo passwd` and set a password for your root shell right now!
Failing to do so will keep your system wounderable to a password-less recovery root shell, which's only security measure asking you to press "Enter", nothing else.
I am doing #FullDisclosure of this massive #SecurityBreach right now, as this huge problem is apparently known for years already, but nobody seems to care at @linuxmint
https://forums.linuxmint.com/viewtopic.php?t=363711.
What the...
-
Lisäänpä heti tähän samaan ketjuun, että kyllä, ajan polkupyörällä, vaikka tällä hetkellä en työmatkaa sillä tyypillisesti taitakaan (lähinnä lenkkeilen). Ja ajan autolla, km-määrissä ihan selvästi enemmän kuin pyörillä.
En silti preferoi autoa enkä varsinkaan kaupunki-infra-asioissa. Raivostuttavaa ajaa pyörällä, kun se on vähiten tärkeä liikkumismuoto kaupungin infrassa ja suunnittelussa.
-
CVE-2024-47081: Netrc credential leak in PSF requests library
https://seclists.org/fulldisclosure/2025/Jun/2
#HackerNews #CVE202447081 #NetrcLeak #PSFRequests #Cybersecurity #Vulnerability #FullDisclosure
-
Insolate opens up and brings out the Full Disclosure album, filled with great techno from the shores of Croatia, on her Out Of Place Records label. #music #Techno #insolate #fulldisclosure #outofplace #album #croatia
-
Playing around with #Modyfi, that does support #VariableFonts now. This shrink-wrap modifier seems destined to be used with #ElectricBlue.
#Animating variable fonts has never been so easy!https://app.modyfi.com
(I’m not payed to say that, Daniël tipped me off and they reached out to hime for some collaboration #fulldisclosure) -
Ohh printer RCE. It's all code, baby.
-
They didn't sound fluent, but Bravo Zulu for a good attempt to promote the Cornish language.
#FullDisclosure Although I was raised in Cardiff (from six weeks old), I was born in Rosemundy House in St Agnes.
-
There we go, confirmation of a hard coded user credential in Asus iKVM/IPMI/Redfish.
Is there a better contact than security@?
-
Sooo.. it's an election year.
I post about #politics. If that's not what you want, you should probably unfollow me.
I do not insult people. If you do, I will block you without further discussion. Those are the ground rules. We now return you to our regularly scheduled programming.
-
Full Disclosure: James O’Brien meets James Blunt.
👍🏻