#fulldisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fulldisclosure, aggregated by home.social.
-
EU to enforce AI content labelling rules from August 2
The European Union will begin enforcing new AI transparency rules from August 2, 2026, requiring clearer labelling of…
#Europe #EU #ArtificialIntelligence #BreakingNews #content #Deepfakes #EuropeanUnion #FullDisclosure #OnlineConsumers
https://www.europesays.com/europe/107216/ -
Unauthenticated RCE in InterSystems IRIS 2026.1 — CVSS 9.8, runs as the
irisowner account, no credentials beyond the built-in CSPSystem default.The technically novel part: the code executes at *compile* time, not call
time.Chain:
CSP broker (unauth, CSPSystem/SYS default) exposes
%DeepSee.UI.FolderManager.ImportItems as a reachable ZenMethod.
directory and selectedFiles are plaintext S-type Zen properties, so
they're injected straight through the broker pBody — no encryption,
fully attacker-controlled.ImportItems calls $system.OBJ.Load(file, "c"). The "c" flag *compiles*
the loaded IRIS XML export. The export carries a ClassMethod with
CodeMode=objectgenerator — its implementation body runs DURING
compilation, and calls $ZF(-100,"","/bin/sh","-c",cmd) as irisowner.Output is redirected to a webroot static file and pulled back via an
anonymous GET. So it's a real RCE with output retrieval, not a blind
write.Defender-relevant: this sidesteps InterSystems' AutoCompile=false
mitigation (DP-441283, added in 2025.1.1+/2025.2.0+). That mitigation
blocks CSP *auto*-compilation; it does not block an explicit
OBJ.Load("c") call from a reachable ZenMethod. ImportItems calls
OBJ.Load("c") directly, so the mitigation doesn't apply.The fix that actually breaks the chain: separate the ReceiveFragment
write directory from the OBJ.Load load directory. They currently overlap
in /usr/irissys/mgr/Temp/ — that overlap is what closes the
write -> load -> compile -> exec loop.The writeup claims the chain was found by method-by-method auditing the
4312 ZenMethods reachable by CSPSystem and picking the highest-value one.
Full root-cause analysis + a self-contained PoC on the advisory page.https://0day-rubbish.com/blog/intersystems-iris-foldermanager-rce
https://github.com/Exploit-Garbage/0day-Rubbish#infosec #vulnerability #0day #RCE #InterSystems #IRIS #database
#exploit #fullDisclosure #applicationSecurity -
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure as self-defense: The Cursor Zero Day
Jürgen Schmidt, head of heise security, explains why Responsible and Coordinated Disclosure no longer have a future.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full Disclosure als Notwehr: Der Cursor Zero Day
Jürgen Schmidt, Leiter von heise security, erklärt, warum Responsible und Coordinated Disclosure keine Zukunft mehr haben.
-
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Full disclosure as the last defense against AI's evil twin cursors? 😂 Spoiler alert: Mindgard's "enterprise-ready" solution seems more like a glorified game of #peekaboo with imaginary threats. 🕵️♂️✨
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left #FullDisclosure #AIThreats #Mindgard #TechHumor #HackerNews #ngated -
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Comments: https://news.ycombinator.com/item?id=48910676
#HackerNews #Cursor0day #FullDisclosure #CyberSecurity #TechNews #Vulnerability
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
@oxy I’m sure the city name is in my @‘s but I got up at 04:45 and my mind is mush. #FullDisclosure
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
"Responsible Disclosure" was the framing that proprietary software vendors used to suggest that those who disclosed details about software vulnerabilities were acting irresponsibly.
They also called it "information anarchy".
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
It took 30 years but I was just beginning to think Microsoft had changed. Guess I was wrong. #fulldisclosure #microsoft #eclipse
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
#Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.
This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.
TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.
Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
https://web.brid.gy/r/https://www.wired.com/story/spacex-ipo-anthropic-compute-finances-risks/
-
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
#HackerNews #FullDisclosure #Azure #SignIn #LogBypass #CyberSecurity #Vulnerability #TechNews
-
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
#HackerNews #FullDisclosure #Azure #SignIn #LogBypass #CyberSecurity #Vulnerability #TechNews
-
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
#HackerNews #FullDisclosure #Azure #SignIn #LogBypass #CyberSecurity #Vulnerability #TechNews
-
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
#HackerNews #FullDisclosure #Azure #SignIn #LogBypass #CyberSecurity #Vulnerability #TechNews