<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-23T18:36:33Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Will Dormann</title>
  <author>
    <name>Will Dormann</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub12xhpqz0ygq7cy87pcyhpf06tgr0yf37uv9mcnzzqeg00n70tca5q0vzxeq.rss" />
  <link href="https://nostr.ae/npub12xhpqz0ygq7cy87pcyhpf06tgr0yf37uv9mcnzzqeg00n70tca5q0vzxeq" />
  <id>https://nostr.ae/npub12xhpqz0ygq7cy87pcyhpf06tgr0yf37uv9mcnzzqeg00n70tca5q0vzxeq</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/243/347/114/375/182/original/481f384cb5fcb03c.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/243/347/114/375/182/original/481f384cb5fcb03c.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqswtvenlr8p8uvddfnawdvxr2hlr3ams33p9x99xzl9m344n43wveqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks74gce8</id>
    
      <title type="html">&amp;gt; This is not anti-science, this is extremely pro-science. … ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswtvenlr8p8uvddfnawdvxr2hlr3ams33p9x99xzl9m344n43wveqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks74gce8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswzz3dx52c4u5l307auuvcmdd47z4kgw7drwjsjpw79qds9vx33egxvvmfm&#39;&gt;nevent1q…vmfm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&amp;gt; This is not anti-science, this is extremely pro-science. … It’s using science that is not conveniently accepted yet.&lt;br/&gt;&lt;br/&gt;AKA **Not science**. 😂
    </content>
    <updated>2026-07-23T12:43:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstjlv2uwncqhrq909sngl0q2zjrm8s20n94tq56g250r400jf3nuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6nez2s</id>
    
      <title type="html">That&amp;#39;s been around since the inception of vulnerabilities ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstjlv2uwncqhrq909sngl0q2zjrm8s20n94tq56g250r400jf3nuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6nez2s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvgce583mew3dtryjqatnau78wqpmf6cgfwa5r45ysvzag9gfmg0q8zj4x9&#39;&gt;nevent1q…j4x9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That&amp;#39;s been around since the inception of vulnerabilities being discussed. &amp;#34;What does this get an attacker that they didn&amp;#39;t already have?&amp;#34; is a question that nobody seems to consider.
    </content>
    <updated>2026-06-28T15:35:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstl3a4hy64k8928udqhmeaery8ush8k35ud5y97zqypysa5mhajkqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksl86sar</id>
    
      <title type="html">OK, I looked at one more, because I had free cycles, and I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstl3a4hy64k8928udqhmeaery8ush8k35ud5y97zqypysa5mhajkqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksl86sar" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsga984edy6culvjr8sscauhen80aggefmg0g4tpm58agj38cvfarqujews5&#39;&gt;nevent1q…ews5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;OK, I looked at one more, because I had free cycles, and I apparently don&amp;#39;t value my own time.&lt;br/&gt;&lt;br/&gt;The imagemagick &amp;#34;vulnerability&amp;#34;:&lt;br/&gt;If you **run imagemagick from a special harness designed to exploit imagemagick**, imagemagick will load an EXE file from the path you specify to the harness.&lt;br/&gt;&lt;br/&gt;How does the exploit work?  It adds a PATH environment variable to the directory where the attacker-provided gswin64c.exe is located, and subsequently executed.&lt;br/&gt;&lt;br/&gt;You can replace &amp;#34;imagemagick&amp;#34; with &amp;amp;lt;anything_else&amp;amp;gt; in this exploit.  This is how Windows works.  If you can set a PATH to an arbitrary directory, Windows will look for things there.&lt;br/&gt;&lt;br/&gt;Anyway, I&amp;#39;m calling it.  This exploitarium repo is pure slop.  But that won&amp;#39;t spread people who don&amp;#39;t bother looking at the contents from spreading the news.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/828/029/355/522/512/original/49a46674c32eb369.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-28T13:44:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsga984edy6culvjr8sscauhen80aggefmg0g4tpm58agj38cvfarqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksdxrsx8</id>
    
      <title type="html">Because I&amp;#39;m slightly masochistic, I looked at the ffmpeg PoC. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsga984edy6culvjr8sscauhen80aggefmg0g4tpm58agj38cvfarqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksdxrsx8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvwd9gds9mku8hnflgc8jxvh3a7rxfzktqsdz26gq4qhwymkav4ksmv2lze&#39;&gt;nevent1q…2lze&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Because I&amp;#39;m slightly masochistic, I looked at the ffmpeg PoC.&lt;br/&gt;&lt;br/&gt;If you **run the compiled C code**, it does indeed create a /tmp/ffmpeg_rasc_exec_demo file as proof of exploitation.&lt;br/&gt;&lt;br/&gt;Does this actually prove anything?  No, not really.  The C program you just ran is a contrived application where instead of giving ffmpeg (libavcodec) an image buffer, it gives it a specially crafted struct:&amp;lt;code&amp;gt;typedef struct DemoChunk {&amp;lt;br&amp;gt;    uint8_t plane[64];&amp;lt;br&amp;gt;    demo_callback cb;&amp;lt;br&amp;gt;    uint8_t palette[1024];&amp;lt;br&amp;gt;} DemoChunk;&amp;lt;br&amp;gt;&amp;lt;/code&amp;gt;&lt;br/&gt;&lt;br/&gt;Which when contrived PoC code runs, lands in code that does &amp;lt;code&amp;gt;    puts(&amp;#34;[callback] hijacked callback reached&amp;#34;);&amp;lt;br&amp;gt;    system(&amp;#34;touch /tmp/ffmpeg_rasc_exec_demo&amp;#34;);&amp;lt;br&amp;gt;&amp;lt;/code&amp;gt;&lt;br/&gt;&lt;br/&gt;Is there a bug in ffmpeg?  Perhaps.&lt;br/&gt;But all this PoC proves is &amp;#34;Contrived harness designed to do &amp;amp;lt;thing&amp;amp;gt; does &amp;amp;lt;thing&amp;amp;gt;.  Does this PoC prove that people in the real world have anything to worry about?  No.  At least not based on this PoC.  If your attack involves the victim running a crafted malicious executable, then fine.  Have it do that you want.  You don&amp;#39;t even need ffmpeg.&lt;br/&gt;&lt;br/&gt;I didn&amp;#39;t think that PoC||GTFO would need clarification about what it means.  Yet here we are.&lt;br/&gt;&lt;br/&gt;I probably won&amp;#39;t look at any more of these, unless a more-masochistic individual has the patience to sift through them and point out what might be of interest.
    </content>
    <updated>2026-06-27T03:57:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvwd9gds9mku8hnflgc8jxvh3a7rxfzktqsdz26gq4qhwymkav4kszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks674stj</id>
    
      <title type="html">Somebody posted a bunch of exploits on GitHub that claim to be ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvwd9gds9mku8hnflgc8jxvh3a7rxfzktqsdz26gq4qhwymkav4kszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks674stj" />
    <content type="html">
      Somebody posted a bunch of exploits on GitHub that claim to be 0days.&lt;br/&gt;&lt;a href=&#34;https://github.com/bikini/exploitarium&#34;&gt;https://github.com/bikini/exploitarium&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Let&amp;#39;s look at the first one: A 7-Zip MotW bypass.&lt;br/&gt;&lt;br/&gt;**Problem #1**: 7-Zip **DOESN&amp;#39;T EVEN WRITE MOTW FOR EXTRACTED FILES BY DEFAULT**.  This doesn&amp;#39;t have a CVE, because [apparently CVE is difficult](&lt;a href=&#34;https://github.com/CVEProject/cve-documents/issues/29&#34;&gt;https://github.com/CVEProject/cve-documents/issues/29&lt;/a&gt; ).&lt;br/&gt;&lt;br/&gt;**Problem #2**: If you are a security-conscious person who enabled writing MotW in 7-Zip extracted files (contratulations!), you might notice that the archive contains a :Zone.Identifier:$DATA (MotW ADS) file in it and recognize shenanigans.&lt;br/&gt;&lt;br/&gt;**Problem #3**: When you extract the file, you will be presented by the following dialog asking if you want to overwrite the ::DATA (primary data stream) of the file.  And if you got this far, you&amp;#39;re a security-conscious person, so you won&amp;#39;t do this.&lt;br/&gt;&lt;br/&gt;If you get past all of those hurdles, and click Yes in the dialog, then yes, you&amp;#39;ll have a file extracted from a RAR that came from the internet that contains an attacker-controlled MotW (that says it didn&amp;#39;t come from the internet).&lt;br/&gt;&lt;br/&gt;Is this a vulnerability?  Sure.  But it both relies on a **non-default** 7-zip configuration, and it also relies on **user interaction** to succeed.  As such, I can&amp;#39;t say that I&amp;#39;m terribly interested in it.&lt;br/&gt;&lt;br/&gt;How about the other 22 exploits in the repo?  I skimmed through a few, and some seem quite contrived (sort of like the 7-zip one), but some may be legit.&lt;br/&gt;&lt;br/&gt;But alas, I don&amp;#39;t have the mental fortitude to sift through it all, based on what I&amp;#39;ve seen.  Maybe somebody else here will.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/819/948/011/919/334/original/9769c2b70237c247.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/819/953/048/972/397/original/49f29bad5378b265.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-27T03:34:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8338ahzzdk35ht5vaaq8fkutjgc488hk2xgjfcse4ah39uvnfsvczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksggngfx</id>
    
      <title type="html">&amp;gt; nearly half I wonder if there&amp;#39;s another common fraction ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8338ahzzdk35ht5vaaq8fkutjgc488hk2xgjfcse4ah39uvnfsvczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksggngfx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstt45jywlcluyh0kjvw9a8u6ey8rx3ajj7rf3rdxq8t6q025lw99q5ag63s&#39;&gt;nevent1q…g63s&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&amp;gt; nearly half&lt;br/&gt;&lt;br/&gt;I wonder if there&amp;#39;s another common fraction that could help to convey the concept of 34%... 🤔&lt;br/&gt;&lt;br/&gt;😂
    </content>
    <updated>2026-06-23T12:50:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgadlprj6g8lstkgsf9ca5xaytsw24m6sxvlh2340z22wajrjrgxszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6xuche</id>
    
      <title type="html">Eh, it sure doesn&amp;#39;t look fixed to me? Also, sfc /scannow ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgadlprj6g8lstkgsf9ca5xaytsw24m6sxvlh2340z22wajrjrgxszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6xuche" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswnshpdg0qyhycs9eg6rklfzz63mffcx9nrhqtdqs8lynpk0tcd5g4m0rds&#39;&gt;nevent1q…0rds&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Eh, it sure doesn&amp;#39;t look fixed to me?&lt;br/&gt;Also, sfc /scannow suggests you&amp;#39;re running it on bare metal as opposed to just reverting to a VM snapshot?  😬&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/726/835/618/170/580/original/1e1380b75079a89f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-10T16:49:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspg9359cerh925wrs8tegvxxq3qargw4907s7qe63waex35jgzlrczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksu0yk56</id>
    
      <title type="html">Ah, so change the named pipe name? 😂 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspg9359cerh925wrs8tegvxxq3qargw4907s7qe63waex35jgzlrczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksu0yk56" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9mzwagrakanmkfhc8znpwxmzlqvpme7seggakp5ewupets7t04dqmvh72w&#39;&gt;nevent1q…h72w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, so change the named pipe name?   😂&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/726/655/964/467/021/original/6c1d7b19d3249a33.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-10T15:41:35Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg9dkf7kkf77xruy6g0pjee32wmap5fwvwdlcpg8gdpnnzl5nf7uszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksl0rgag</id>
    
      <title type="html">I&amp;#39;m going to go out on a limb here... ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg9dkf7kkf77xruy6g0pjee32wmap5fwvwdlcpg8gdpnnzl5nf7uszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksl0rgag" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsykjsklw6glqelxpfeapeaw0q5wcuqwzxzfcam4lhrxjdav8fqkdsgefcuy&#39;&gt;nevent1q…fcuy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;m going to go out on a limb here...&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/433/829/956/371/original/e357b8b91da492b2.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-04T15:00:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2jwyqgg7mfq4v85vt0697gnrkrpcm49fl3qpvcxlwu22g29y0pxszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks0ru467</id>
    
      <title type="html">https://www.youtube.com/watch?v=aW2LvQUcwqc</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2jwyqgg7mfq4v85vt0697gnrkrpcm49fl3qpvcxlwu22g29y0pxszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks0ru467" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstwfwla5cqgvf2sz4ejkwntws52c7egjckd5led35zsxf5t48sssq7k50d4&#39;&gt;nevent1q…50d4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=aW2LvQUcwqc&#34;&gt;https://www.youtube.com/watch?v=aW2LvQUcwqc&lt;/a&gt;
    </content>
    <updated>2026-06-04T14:28:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst7rfmptgyvxkfphq0xrysk247ud6vk5n9fuwm7m7jm22r09yjd0gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksxh7qdj</id>
    
      <title type="html">I also tested [another ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst7rfmptgyvxkfphq0xrysk247ud6vk5n9fuwm7m7jm22r09yjd0gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksxh7qdj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs28nqlaa6f7snuxuppp3rdhnn6ylfa2y2fne9q70v63x3kt6rxw8syc204a&#39;&gt;nevent1q…204a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I also tested [another PoC](&lt;a href=&#34;https://github.com/hnytgl/CVE-2026-41089&#34;&gt;https://github.com/hnytgl/CVE-2026-41089&lt;/a&gt; ) and it was even more fake.  i.e. it didn&amp;#39;t even create a CLDAP structure that made sense.&lt;br/&gt;&lt;br/&gt;I get that PoC||GTFO is a thing, but we&amp;#39;ve clearly entered a phase where it needs to be Verified PoC||GTFO.  🤦‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/083/358/777/859/original/77e9c8cd6e0af56f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-04T13:31:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs28nqlaa6f7snuxuppp3rdhnn6ylfa2y2fne9q70v63x3kt6rxw8szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7zckwp</id>
    
      <title type="html">Yes, my test environments (unpatched Server 2016, 2022, and 2025) ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs28nqlaa6f7snuxuppp3rdhnn6ylfa2y2fne9q70v63x3kt6rxw8szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7zckwp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstfsxluwu9nvkw3sw5a6ykkju9hs0eucgmzzng3ua6m30yuqratksuxf4y0&#39;&gt;nevent1q…f4y0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yes, my test environments (unpatched Server 2016, 2022, and 2025) all had a maximum DNS suffix of 64 chars.  (Longer isn&amp;#39;t allowed)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/049/575/250/713/original/3ef786e32d2e758c.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/058/641/106/787/original/9d54baff81429e7d.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/066/460/411/287/original/66e42781919dfaa6.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-04T13:23:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspm347q5l3faeqts8xpklxn2ju82kzt3xdm055f7hqeh5mqfwcdgqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6lfw3q</id>
    
      <title type="html">😂 I miss the days when things like this were written by ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspm347q5l3faeqts8xpklxn2ju82kzt3xdm055f7hqeh5mqfwcdgqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks6lfw3q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9dta5eqmhn3fcx57r59erf2z4srlg0ukjgfsyflp8wg8jrgsclwc99dgrl&#39;&gt;nevent1q…dgrl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;😂&lt;br/&gt;&lt;br/&gt;I miss the days when things like this were written by humans, using logic and facts. As opposed to statistically plausible slop.
    </content>
    <updated>2026-06-04T12:44:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdhrtw9hfkr5nz5tzz5k0l78ps2ljfnjjnf5cjq7ucn6yemu9dccgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7ncal2</id>
    
      <title type="html">Yeah, I&amp;#39;ve seen what it claims to do. But either they are ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdhrtw9hfkr5nz5tzz5k0l78ps2ljfnjjnf5cjq7ucn6yemu9dccgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7ncal2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrs8swa7h03g5pmyy7pxlx3u42jcjxdkr4773w34anpffpl8tfcjqlturse&#39;&gt;nevent1q…urse&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah, I&amp;#39;ve seen what it claims to do.&lt;br/&gt;But either they are hand-waving over a critical requirement of what it takes to repro, or it&amp;#39;s fake.
    </content>
    <updated>2026-06-04T12:40:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxkeprtjpn7hvet835nj3g67ax6um8d29nrelwe54s0kj6vy6k97qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks46ehmv</id>
    
      <title type="html">Ah, so you&amp;#39;ve confirmed that it works? With AI and clout ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxkeprtjpn7hvet835nj3g67ax6um8d29nrelwe54s0kj6vy6k97qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks46ehmv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0dw5dvxm0jr74fy9l3rmcqcg3kz3kg0vx7536mrs3a0tl8g46v4qmppdtq&#39;&gt;nevent1q…pdtq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, so you&amp;#39;ve confirmed that it works?&lt;br/&gt;With AI and clout seeking these days, we&amp;#39;ve **long** passed the &amp;#34;PoC exists on Github&amp;#34; thing having any meaning whatsoever. 😂&lt;br/&gt;&lt;br/&gt;Personally, I couldn&amp;#39;t get that one to do anything.
    </content>
    <updated>2026-06-04T12:35:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswplkdhu53jmwav3sytpwrfs848z3yy4z5vt8zj5pqj2a9qk0drrqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkssqm7x7</id>
    
      <title type="html">Reference?</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswplkdhu53jmwav3sytpwrfs848z3yy4z5vt8zj5pqj2a9qk0drrqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkssqm7x7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsde62vjsl2hw0hqlhyd6ykp7dvjngjr5esume5pm970myxfg46ylgj97qx3&#39;&gt;nevent1q…7qx3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Reference?
    </content>
    <updated>2026-06-03T16:18:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr547fez3kr7wl7yh6mrya5xskl6rk73vfymw427wslzx6gpsv6pqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz4d85s</id>
    
      <title type="html">In today&amp;#39;s episode of &amp;#34;CVE is a disaster&amp;#34;: Anthropic ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr547fez3kr7wl7yh6mrya5xskl6rk73vfymw427wslzx6gpsv6pqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz4d85s" />
    <content type="html">
      In today&amp;#39;s episode of &amp;#34;CVE is a disaster&amp;#34;:&lt;br/&gt;&lt;br/&gt;Anthropic has published a [cordinated vulnerability disclosure dashboard](&lt;a href=&#34;https://red.anthropic.com/2026/cvd/&#34;&gt;https://red.anthropic.com/2026/cvd/&lt;/a&gt; ) for their findings.&lt;br/&gt;&lt;br/&gt;Vulnerabilities disclosed: 1596&lt;br/&gt;Vulnerabilities patched: 97&lt;br/&gt;Assigned a CVE or a GHSA: 88&lt;br/&gt;...&lt;br/&gt;**CVE COUNT for 1596 disclosed vulnerabilities: 14**&lt;br/&gt;&lt;br/&gt;If something has an adoption rate of less than 1%, what do you call it?
    </content>
    <updated>2026-05-27T12:32:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8mc3sr7jt4jdlfgva5fn58al8kcf8lgywww7ff2m93kahtgn9m7czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksy5jqwl</id>
    
      <title type="html">Also note that the [RedSun author noticed that the vulenrability ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8mc3sr7jt4jdlfgva5fn58al8kcf8lgywww7ff2m93kahtgn9m7czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksy5jqwl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspgsglyawfl8kg9xm3ema7drgr06g8tnwd6j6lr6e9annf5ks7t4sdep6h5&#39;&gt;nevent1q…p6h5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also note that the [RedSun author noticed that the vulenrability was fixed, without a CVE](&lt;a href=&#34;https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html&#34;&gt;https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html&lt;/a&gt; )
    </content>
    <updated>2026-05-13T15:41:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvt870d6p34tgaeqkqlp588qw5hskx3cvt9aumxuj2n9695mxa0ggzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks3c5zwu</id>
    
      <title type="html">I suspect that Microsoft pushed out Defender updates that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvt870d6p34tgaeqkqlp588qw5hskx3cvt9aumxuj2n9695mxa0ggzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks3c5zwu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszawj0ekzydvylzephpwqv2w05vx5q9eqwc70e2xstzhs9yzyng5q2zfw3v&#39;&gt;nevent1q…fw3v&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I suspect that Microsoft pushed out Defender updates that mitigate the exploit.&lt;br/&gt;&lt;br/&gt;With current definitions, I&amp;#39;ve not seen RedSun succeed.  No matter how long I wait.&lt;br/&gt;&lt;br/&gt;With old definitions, success is pretty quick.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/230/582/681/814/original/262483d424fd1700.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/231/063/519/567/original/0f68eaf9c05845c3.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-12T15:12:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfn86dfu6xjwn3fqltehghmwpn572xauky5fqux8p4pzhx7t0mrtczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4gmlqk</id>
    
      <title type="html">The 3 recent Linux LPEs are sort of interesting in that each one ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfn86dfu6xjwn3fqltehghmwpn572xauky5fqux8p4pzhx7t0mrtczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4gmlqk" />
    <content type="html">
      The 3 recent Linux LPEs are sort of interesting in that each one took a different path from discovery to disclosure.&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/@wdormann/116489443704631952&amp;#34&#34;&gt;https://infosec.exchange/@wdormann/116489443704631952&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34;&amp;gt;Copy Fail&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;: Publicity stunt where they claim to have done the right thing, yet didn&amp;#39;t bother to tell a single distro vendor, and lied about updates being available.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/@wdormann/116535129483797487&amp;#34&#34;&gt;https://infosec.exchange/@wdormann/116535129483797487&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34;&amp;gt;Dirty Frag&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;: Attempted to do proper coordination, including notifying the &amp;lt;code&amp;gt;linux-distros&amp;lt;/code&amp;gt; mailing list.  But the &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline&amp;#34&#34;&gt;https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;embargo was broken&amp;lt;/a&amp;gt;, so it was disclosed unexpectedly ahead of time.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/@wdormann/116536031268240371&amp;#34&#34;&gt;https://infosec.exchange/@wdormann/116536031268240371&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34;&amp;gt;Copy Fail 2&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;:  &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.openwall.com/lists/oss-security/2026/05/07/12&amp;#34&#34;&gt;https://www.openwall.com/lists/oss-security/2026/05/07/12&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;Discovered as an n-day by looking at kernel commit logs and Spender noticing that it was copyfail-class&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Each path had basically exactly the same outcome (No fixes at publication time).  😂&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1lpqwwkz2ft4zf5823mufsl6j9ce7mltfvqzv8vt0l5jqh23n94tqaps76v&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1lpq…s76v&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; So [CopyFail](&lt;a href=&#34;https://copy.fail/&#34;&gt;https://copy.fail/&lt;/a&gt; ) CVE-2026-31431 is a thing.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/489/442/181/221/777/original/e03a85c201d4361a.png&#34;&gt; &lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-05-08T03:31:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0scn9vhyvnry9dzy0895ysdr2ax7chxcrt9q5zfx05vcnfk8yj2szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszvkydx</id>
    
      <title type="html">Let&amp;#39;s talk about Windows .URL (InternetShortcut) files. Last ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0scn9vhyvnry9dzy0895ysdr2ax7chxcrt9q5zfx05vcnfk8yj2szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszvkydx" />
    <content type="html">
      Let&amp;#39;s talk about Windows .URL (InternetShortcut) files.&lt;br/&gt;&lt;br/&gt;Last year there was discussion about a vulnerability in how Windows handles .URL files. Specifically, when a .URL file specifies a WorkingDirectory directive, an otherwise harmless app being launched would load DLLs from the remote (e.g. WebDAV) server specified. You know, being the current working directory of the app being launched and all.  This vulnerability was being [exploited in the wild](&lt;a href=&#34;https://www.virustotal.com/gui/file/e0a44274d5eb01a0379894bb59b166c1482a23fede1f0ee05e8bf4f7e4e2fcc6&#34;&gt;https://www.virustotal.com/gui/file/e0a44274d5eb01a0379894bb59b166c1482a23fede1f0ee05e8bf4f7e4e2fcc6&lt;/a&gt; ), and it worked well because it bypassed annoying (to attackers) things like SmartScreen.  Sure, it required the victim to click Open on a dialog saying Type: Unknown File Type (😂), but we all know that users are click-happy, so this is fine.  Besides, the file clearly has a .pdf extension, so it should be safe (😂).&lt;br/&gt;&lt;br/&gt;Microsoft recognized the vulnerability and published an [update in the form of CVE-2025-33053](&lt;a href=&#34;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053&#34;&gt;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053&lt;/a&gt; ).&lt;br/&gt;&lt;br/&gt;If we were to believe the [Microsoft documentation at the time](&lt;a href=&#34;https://web.archive.org/web/20250710095434/https://learn.microsoft.com/en-us/windows/win32/lwef/internet-shortcuts&#34;&gt;https://web.archive.org/web/20250710095434/https://learn.microsoft.com/en-us/windows/win32/lwef/internet-shortcuts&lt;/a&gt; ), &lt;br/&gt;&lt;br/&gt;&amp;gt; When the user clicks the icon, the browser is launched and displays the site associated with the shortcut.&lt;br/&gt;&lt;br/&gt;But wait...&lt;br/&gt;How did this .URL file cause a program to be launched?  The URL= parameter specifies a website address to be loaded in the browser.&lt;br/&gt;&lt;br/&gt;Oh, naive child.  Obviously a .URL file can directly point to code on a remote (e.g. WebDAV) server. This technique is also [being exploited ITW as well](&lt;a href=&#34;https://www.virustotal.com/gui/file/93a2d60d1ccfe3e009b1a81951653b559e0cae01c2454244a3a0fbd49a5e4539&#34;&gt;https://www.virustotal.com/gui/file/93a2d60d1ccfe3e009b1a81951653b559e0cae01c2454244a3a0fbd49a5e4539&lt;/a&gt; ).&lt;br/&gt;&lt;br/&gt;I reported this to Microsoft, as this has the **EXACT SAME IMPACT** as CVE-2025-33053.  So if that&amp;#39;s a vulnerability, then this too is a vulnerability, right?  &lt;br/&gt;&lt;br/&gt;Bless your innocent soul.  Per MSRC:&lt;br/&gt;&lt;br/&gt;&amp;gt; When the Shell invokes an app from a remote share, it&amp;#39;s expected that you will see the legacy Windows Security prompt, not the SmartScreen one. SmartScreen Application Reputation (AppRep) evaluation applies to locally downloaded files that bear an Internet Zone mark of the web. It is not meant to apply to execution of files from Network Shares.&lt;br/&gt;&lt;br/&gt;Okie dokie.  I&amp;#39;m sure Windows users surely appreciate this.  But what about the [incorrect documentation](&lt;a href=&#34;https://archive.ph/MgBI8&#34;&gt;https://archive.ph/MgBI8&lt;/a&gt; )?  After my prodding, they [updated the wording](&lt;a href=&#34;https://learn.microsoft.com/en-us/windows/win32/lwef/internet-shortcuts&#34;&gt;https://learn.microsoft.com/en-us/windows/win32/lwef/internet-shortcuts&lt;/a&gt; ):&lt;br/&gt;&lt;br/&gt;&amp;gt; When the user clicks the icon, the URL path is opened by the handler application, typically the user&amp;#39;s default web browser.&lt;br/&gt;&lt;br/&gt;Leaving in the quite misleading first sentence:&lt;br/&gt;&lt;br/&gt;&amp;gt; The Internet shortcut object is used to create desktop shortcuts to Internet sites.&lt;br/&gt;&lt;br/&gt;(An &amp;#34;Internet site&amp;#34; is a web page, right?)&lt;br/&gt;&lt;br/&gt;How can CVE-2025-33053 warrant a CVE, while the behavior I described has the exact same trigger and impact is **not** CVE worthy?  That&amp;#39;s pretty easy.  Microsoft assigns CVEs to **updates**, not **vulnerabilities**.  They are the decider as to what is a vulnerability and what is not.&lt;br/&gt;&lt;br/&gt;What can we do about it?&lt;br/&gt;&lt;br/&gt;At the very least, turn off the Windows feature that hides file extensions, **even if you have the option turned on to see file extensions**.  The disdain that Microsoft has for Windows users is tangible here.  On what planet would I not want to see the actual extension of a file?  Go to HKCU\InternetShortcut and delete the NeverShowExt value.  After this, your pwned.pdf file will reveal its true self as being pwned.pdf.url.&lt;br/&gt;&lt;br/&gt;More powerful protection would be to block the ability to receive .URL files via email, web browsers, etc.  There is no workflow that I can imagine that requires a user to double-click on a .URL file that **came from the internet**.&lt;br/&gt;&lt;br/&gt;Even more powerful than that would be to disassociate .URL files from opening in Windows (thx &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1yg8lnapwc8yyd0m32jcfdp7k28hwmsvtsqc59rsj6d6d0m3mynqs7tccz0&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Taggart&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1yg8…ccz0&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; ).&lt;br/&gt;&lt;br/&gt;This screen recording is a Windows 11 system that has no internet connectivity.  The fact that no warning was displayed that SmartScreen cannot be reached is evidence that SmartScreen is not in play at all.  And that dialog...Do you want to open this file?&lt;br/&gt;&lt;br/&gt;andType: Unknown File Type&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Do you think that users are presented with enough information to make an informed security decision?  Of course not.  But obviously we all know that we can&amp;#39;t rely on users making informed security decisions in general.  Don&amp;#39;t put users in that position.&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/533/712/734/034/973/original/7873081a273e8a42.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2026-05-07T14:53:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyjhnac5zgvw4xk8hxmp45xg5vvxmj83mh9u59cmyu320rpm2r99qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksuldkem</id>
    
      <title type="html">&amp;gt; This issue &amp;gt; **will be**&amp;gt; fixed in upcoming releases ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyjhnac5zgvw4xk8hxmp45xg5vvxmj83mh9u59cmyu320rpm2r99qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksuldkem" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgcttsjx8djj4tnws58zxsc5l4vznzxyttj5tyds99aqq5zqxqamc4wmrgq&#39;&gt;nevent1q…mrgq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&amp;gt; This issue &amp;gt; **will be**&amp;gt;  fixed in upcoming releases of PAN-OS as captured in the table above.&lt;br/&gt;&lt;br/&gt;Sooooooo, exploited ITW I take it?&lt;br/&gt;(Without saying it)
    </content>
    <updated>2026-05-06T13:33:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswlj5ky0lpr7wu47vxhtrrkk5yl6aff7azfh0x5djnsyham9pxpxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkssssgj2</id>
    
      <title type="html">Apparently26.04 is considered a &amp;#34;development release&amp;#34;, so ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswlj5ky0lpr7wu47vxhtrrkk5yl6aff7azfh0x5djnsyham9pxpxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkssssgj2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstjmlj25kfsjue05ykk3eu3tzwudjal985vycyntn2vgymzuv4q9ckgsh7e&#39;&gt;nevent1q…sh7e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Apparently26.04 is considered a &amp;#34;development release&amp;#34;, so you can apparently get it via do-release-upgrade -d&lt;br/&gt;&lt;br/&gt;That is, if Ubuntu&amp;#39;s servers were up.  😂&amp;lt;code&amp;gt;$ sudo do-release-upgrade -d&amp;lt;br&amp;gt;Checking for a new Ubuntu release&amp;lt;br&amp;gt;Could not download the release announcement&amp;lt;br&amp;gt;Please check your internet connection.&amp;lt;br&amp;gt;$&amp;lt;br&amp;gt;&amp;lt;/code&amp;gt;
    </content>
    <updated>2026-05-04T18:18:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszvhl48kqkk304vykvllcamugek0lgrchcurzy8uxdathy3yzn9tczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksksy56v</id>
    
      <title type="html">What went wrong with this case? Theori appear to have only ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszvhl48kqkk304vykvllcamugek0lgrchcurzy8uxdathy3yzn9tczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksksy56v" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz5e6mumndsmrvrz8a0duz9mx6m6cyr5mujcx86v8dx4jrjahyc8q0qnhzu&#39;&gt;nevent1q…nhzu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What went wrong with this case?&lt;br/&gt;&lt;br/&gt;Theori appear to have only contacted the linux kernel devs with the vulnerability, as opposed to going the usual CVD route that includes all of the major Linux distros.&lt;br/&gt;&lt;br/&gt;Why is this a problem?  Since the linux kernel became a CNA, there has been a [flood of CVEs for the Linux kernel](&lt;a href=&#34;https://tuxcare.com/blog/the-linux-kernel-cve-flood-continues-unabated-in-2025/&#34;&gt;https://tuxcare.com/blog/the-linux-kernel-cve-flood-continues-unabated-in-2025/&lt;/a&gt; ).  The Linux kernel devs&amp;#39; arguments is that any given kernel flaw could presumably be leveraged to behave as a vulnerability, and it&amp;#39;s not worth their time to determine &amp;#34;vulnerability&amp;#34; or &amp;#34;not a vulnerability&amp;#34;.  Everything gets a CVE.&lt;br/&gt;&lt;br/&gt;Now the case with copy.fail?  It was indeed reported to the kernel devs.  And it got a CVE.  A single CVE buried in flood of all of the Linux kernel CVEs.&lt;br/&gt;&lt;br/&gt;And it appears that every distro on the planet was blindsided by this proven-exploitable vulnerability because they were not given any warning.  Or even any suggestion to pick this single CVE out of the sea of Linux kernel CVEs as worth cherry picking.&lt;br/&gt;&lt;br/&gt;Much to the chagrin of the Linux devs, RHEL doesn&amp;#39;t use up-to-date Linux kernels.  They cherry pick CVEs to backport to their chosen kernel version.  (e.g. the latest and greates RHEL 10.1 uses 6.12.0, which was released November 17 2024).  And in this world where bad actors like Theori don&amp;#39;t involve vendors in vulnerability coordination, and just about every Linux kernel bug gets a CVE, this workflow fails. Hard.&lt;br/&gt;&lt;br/&gt;Good times...
    </content>
    <updated>2026-04-30T18:37:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz5e6mumndsmrvrz8a0duz9mx6m6cyr5mujcx86v8dx4jrjahyc8qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvz2j4x</id>
    
      <title type="html">If you&amp;#39;re curious about IOCs for copyfail, look in syslog ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz5e6mumndsmrvrz8a0duz9mx6m6cyr5mujcx86v8dx4jrjahyc8qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvz2j4x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsps6n84xst8x7zt6h2je27kdkv7y6u4lmu87aqf8tzsp7kwm8t5zgen6jzj&#39;&gt;nevent1q…6jzj&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re curious about IOCs for copyfail, look in syslog for:NET: Registered PF_ALG protocol family&lt;br/&gt;&lt;br/&gt;for attempts to exploit copyfail on systems that use the vulnerable code as a module. For systems that have the vulnerable code compiled into the kernel, like RHEL, you&amp;#39;ll see this line on every boot.&lt;br/&gt;And at least for this particular flavor of exploit, a wall-clock nearby:process &amp;#39;su&amp;#39; launched &amp;#39;/bin/sh&lt;br/&gt; with NULL argv: empty string added`&lt;br/&gt;is an indication of successful exploitation.&lt;br/&gt;&lt;br/&gt;But it&amp;#39;s worth noting that the &amp;#34;process launched&amp;#34; stuff is merely what the ITW PoC will leave behind.  More clever exploitation may not be as obvious.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/493/963/820/216/458/original/0b40e679216dba90.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-30T13:38:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsps6n84xst8x7zt6h2je27kdkv7y6u4lmu87aqf8tzsp7kwm8t5zgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks3hyg6j</id>
    
      <title type="html">While this vulnerability seems to be discovered using AI ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsps6n84xst8x7zt6h2je27kdkv7y6u4lmu87aqf8tzsp7kwm8t5zgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks3hyg6j" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszg0fggswhyw2slsn9kmh8rqw7y8u47xaxr4jjdeuxr4wvtnlnvwgeg44c0&#39;&gt;nevent1q…44c0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;While this vulnerability seems to be discovered using AI (&amp;#34;Xint Code&amp;#34;), I have to assume that they also let the AI decide how to do the vulnerability coordination as well.&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;&amp;lt;code&amp;gt;major builds are out as of this writing&amp;lt;/code&amp;gt;  😂&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;No distros have official updates for CVE-2026-31431. Fedora 42 and newer have updates, but no official advisory or acknowledgement of CVE-2026-31431. So with them it&amp;#39;s unclear if it&amp;#39;s even intentional. &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://access.redhat.com/security/cve/cve-2026-31431&amp;#34&#34;&gt;https://access.redhat.com/security/cve/cve-2026-31431&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;Red Hat&amp;lt;/a&amp;gt;, &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://ubuntu.com/security/CVE-2026-31431&amp;#34&#34;&gt;https://ubuntu.com/security/CVE-2026-31431&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;Ubuntu&amp;lt;/a&amp;gt;, &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://explore.alas.aws.amazon.com/CVE-2026-31431.html&amp;#34&#34;&gt;https://explore.alas.aws.amazon.com/CVE-2026-31431.html&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;Amazon Linux&amp;lt;/a&amp;gt;, and &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.suse.com/security/cve/CVE-2026-31431.html&amp;#34&#34;&gt;https://www.suse.com/security/cve/CVE-2026-31431.html&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34;&amp;gt;Suse&amp;lt;/a&amp;gt; all have advisories as of now, but &amp;lt;strong&amp;gt;NO&amp;lt;/strong&amp;gt; updates.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;&amp;lt;code&amp;gt;disable the algif_aead module&amp;lt;/code&amp;gt; as a mitigation.  😂&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Bespoke distros like RHEL don&amp;#39;t use a module, it&amp;#39;s compiled into the kernel.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;I can&amp;#39;t figure out what the Xint Code angle is with this copyfail stuff.  On one hand, yes, it is a true vulnerability that affects a **LOT** of Linux distros available.  And they did submit the bug for fixing to the upstream kernel people.&lt;br/&gt;&lt;br/&gt;**BUT** the CVE has only existed for a week.  And **NONE** of the distros **IN THEIR ADVISORY** had updates available at the time that they pulled the trigger for publication of the shiny [copy.fail](&lt;a href=&#34;https://copy.fail/&#34;&gt;https://copy.fail/&lt;/a&gt; ) website.&lt;br/&gt;&lt;br/&gt;I struggle to think of how this even happens.  In all my years of infosec, you&amp;#39;re either on board with doing CVD (e.g. coordinating with the former CERT/CC) or you&amp;#39;re not (dropping 0day).  But this all fits bizarrely in the middle.  The publication gives the **guise** that they did the right thing, (and please use our AI services).  But at the same time, they clearly chose to release the vulnerability details and functional exploit **before** any distro had the ability to properly do anything about it.&lt;br/&gt;&lt;br/&gt;Either these Xint Code people have a hidden agenda or ulterior motive that we aren&amp;#39;t aware of yet.  Or they&amp;#39;re just **really bad** at coordinated vulnerability disclosure.  You pick.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/493/722/586/962/066/original/5bf4d4045d9bf621.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/493/723/221/755/401/original/59717c1351453e9e.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-30T12:46:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszg0fggswhyw2slsn9kmh8rqw7y8u47xaxr4jjdeuxr4wvtnlnvwgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksae0p3w</id>
    
      <title type="html">Or RHEL. I suspect that some people use that? ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszg0fggswhyw2slsn9kmh8rqw7y8u47xaxr4jjdeuxr4wvtnlnvwgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksae0p3w" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstxphnv5zrzprs7eg3m7ssgvjlhkvu6l65j8vjxju2rkjrxr7cr7grazp6r&#39;&gt;nevent1q…zp6r&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Or RHEL.&lt;br/&gt;I suspect that some people use that?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/489/879/332/883/559/original/6a8c2c61116db7aa.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-29T20:28:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstxphnv5zrzprs7eg3m7ssgvjlhkvu6l65j8vjxju2rkjrxr7cr7gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksngxdx5</id>
    
      <title type="html">If you&amp;#39;re using an obscure distro like &amp;#34;Debian&amp;#34;, you ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstxphnv5zrzprs7eg3m7ssgvjlhkvu6l65j8vjxju2rkjrxr7cr7gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksngxdx5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ss88tp9y463y6r4ga7yc0afzuvldl45kqpxrk9hl6fqt4gej64s82qcx8&#39;&gt;nevent1q…qcx8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re using an obscure distro like &amp;#34;Debian&amp;#34;, you may not have a fix available.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/489/512/203/071/598/original/f31e01d91386113d.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-29T18:55:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ss88tp9y463y6r4ga7yc0afzuvldl45kqpxrk9hl6fqt4gej64szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksarjwws</id>
    
      <title type="html">So [CopyFail](https://copy.fail/ ) CVE-2026-31431 is a thing. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ss88tp9y463y6r4ga7yc0afzuvldl45kqpxrk9hl6fqt4gej64szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksarjwws" />
    <content type="html">
      So [CopyFail](&lt;a href=&#34;https://copy.fail/&#34;&gt;https://copy.fail/&lt;/a&gt; ) CVE-2026-31431 is a thing.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/489/442/181/221/777/original/e03a85c201d4361a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-29T18:37:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstjmlj25kfsjue05ykk3eu3tzwudjal985vycyntn2vgymzuv4q9czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkskv7q5r</id>
    
      <title type="html">Apparently [Ubuntu 26.04 has been ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstjmlj25kfsjue05ykk3eu3tzwudjal985vycyntn2vgymzuv4q9czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkskv7q5r" />
    <content type="html">
      Apparently [Ubuntu 26.04 has been released](&lt;a href=&#34;https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon&#34;&gt;https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon&lt;/a&gt; ).&lt;br/&gt;At least somewhat?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/466/388/705/021/635/original/d5286f9c00cf6475.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-25T16:55:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx74pmlc6w83fjs9dgkxeklkg6vu5qzar66jrt3tq4psj3603cluszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa9vruy</id>
    
      <title type="html">I&amp;#39;ve always known that I&amp;#39;m **terrible** at using websites ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx74pmlc6w83fjs9dgkxeklkg6vu5qzar66jrt3tq4psj3603cluszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa9vruy" />
    <content type="html">
      I&amp;#39;ve always known that I&amp;#39;m **terrible** at using websites (I never know where to click).  But I guess I&amp;#39;ve recently realized that this applies to apps as well.&lt;br/&gt;&lt;br/&gt;Today&amp;#39;s case: Paragon Hard Disk Manager.&lt;br/&gt;&lt;br/&gt;My goal: Mount a backup as a drive letter.&lt;br/&gt;After multiple rounds with support, I convinced them to indicate on a screenshot exactly where it is that I should click.&lt;br/&gt;&lt;br/&gt;I get that I&amp;#39;m possibly being obtuse, but I have **NEVER** in my computing years been drawn to click on a thin **DOTTED LINE** part of an arrow with the expectation of it doing something.&lt;br/&gt;&lt;br/&gt;And no, there was no mouse hover indication that the line had special meaning.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/336/792/652/990/016/original/5582a453244ee4d1.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/336/793/168/296/379/original/df302add1b68d9ba.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/336/801/859/576/328/original/0141f4e9822fc698.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-04-02T19:42:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqpt2te0zqp3qslrlcxmd7cd7fhzdgzxfnv4mxcwhkyq4s5unfuvgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksktrnw0</id>
    
      <title type="html">Call me crazy, but there are times when I think that ChatGPT ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqpt2te0zqp3qslrlcxmd7cd7fhzdgzxfnv4mxcwhkyq4s5unfuvgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksktrnw0" />
    <content type="html">
      Call me crazy, but there are times when I think that ChatGPT sprinkling in knowledge about what I normally ask is... **not** useful.&lt;br/&gt;&lt;br/&gt;This is from a question I asked about grease.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/262/125/391/332/770/original/49ed8ad5a126090f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-20T15:08:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdwkw43kw8g7r6rvdsey6k3tp6ehldx35ysaqup3mpcpsvwfqpfmgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksngds6w</id>
    
      <title type="html">My local hardware store just installed a vending machine out ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdwkw43kw8g7r6rvdsey6k3tp6ehldx35ysaqup3mpcpsvwfqpfmgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksngds6w" />
    <content type="html">
      My local hardware store just installed a vending machine out front of it, in case you need things when they&amp;#39;re closed.&lt;br/&gt;I love it.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/201/699/300/335/899/original/9c33a05602a61b0b.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-09T23:00:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspc3vx46avc2h525c868dzgn9qnnnwgzvg7ttkum6hxmlshjp30kqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksh4xpfx</id>
    
      <title type="html">I already knew that we use nonsense measurement systems here in ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspc3vx46avc2h525c868dzgn9qnnnwgzvg7ttkum6hxmlshjp30kqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksh4xpfx" />
    <content type="html">
      I already knew that we use nonsense measurement systems here in the US. But only recently did I realize that a US gallon is different than a UK gallon.&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/197/055/752/673/643/original/9e6c3c630064a3aa.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2026-03-09T03:19:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv324xea5wa69exlkmwuse6qjtn09j6mqqngaah4dh632lvsy0ukczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksceghhv</id>
    
      <title type="html">Ars Technica [retracted an ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv324xea5wa69exlkmwuse6qjtn09j6mqqngaah4dh632lvsy0ukczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksceghhv" />
    <content type="html">
      Ars Technica [retracted an article](&lt;a href=&#34;https://arstechnica.com/ai/2026/02/after-a-routine-code-rejection-an-ai-agent-published-a-hit-piece-on-someone-by-name/&#34;&gt;https://arstechnica.com/ai/2026/02/after-a-routine-code-rejection-an-ai-agent-published-a-hit-piece-on-someone-by-name/&lt;/a&gt; ) about how AI is making the world worse because...&lt;br/&gt;**the Ars article itself** contained AI-generated quotes in it.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://arstechnica.com/staff/2026/02/editors-note-retraction-of-article-containing-fabricated-quotations/&#34;&gt;https://arstechnica.com/staff/2026/02/editors-note-retraction-of-article-containing-fabricated-quotations/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Welp, we had a decent run, folks.  But it&amp;#39;s time to call it.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/076/049/706/592/161/original/a20b3659e47f7476.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-02-15T18:28:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstzp8huhe4wrgc73ypv0k72pnca437apzssutyjtz8edp28h6n5wczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksle8e2x</id>
    
      <title type="html">When you get a screenshot of an individual window in Windows, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstzp8huhe4wrgc73ypv0k72pnca437apzssutyjtz8edp28h6n5wczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksle8e2x" />
    <content type="html">
      When you get a screenshot of an individual window in Windows, using either Alt &#43; PrtScn or the fancy new Snipping Tool, you also capture the contents of whatever is **behind** the window around the edges.&lt;br/&gt;&lt;br/&gt;Linux doesn&amp;#39;t do this.&lt;br/&gt;macOS doesn&amp;#39;t do this.&lt;br/&gt;Just Windows.&lt;br/&gt;&lt;br/&gt;Why are expectations for how Windows works so low?&lt;br/&gt;Or has Microsoft crafted a world where they are not required to care?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/946/059/945/899/333/original/827cd84b29ab8788.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/946/062/007/795/294/original/c57f226b386b39bd.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-01-23T19:29:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0vdra5ar3704k7829d29p4pajsd8tfyfpj58zmxdk3fff53lrl2qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksedvq58</id>
    
      <title type="html">I recently bought something from poshmark.com, for the first ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0vdra5ar3704k7829d29p4pajsd8tfyfpj58zmxdk3fff53lrl2qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksedvq58" />
    <content type="html">
      I recently bought something from poshmark.com, for the first time. While I haven&amp;#39;t heard of them before, I figure with credit card protections as they are in the US, there&amp;#39;s really no harm with giving it a shot.&lt;br/&gt;&lt;br/&gt;Within about **30 minutes** of placing my order, I got a not-very-good phishing email from purchase-orders@loyverse[.]com, claiming to be &amp;#34;Poshmark&amp;#34;.&lt;br/&gt;The first time in my life that I&amp;#39;ve received a phish from somebody claiming to be Poshmark.&lt;br/&gt;&lt;br/&gt;My wonders at this point:&amp;lt;li&amp;gt;Is Poshmark unknowingly leaking the email addresses of people who purchase through their site?&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Is Poshmark knowingly leaking the email addresses of people who purchase through their site?  Sub-wonder: If true, is this publicly known?&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Is the person whose Poshmark listing I purchased from either compromised or malicious?🤔&amp;lt;/li&amp;gt;
    </content>
    <updated>2025-12-31T14:43:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszzd2g9grzsepgqplpyj549pl95umswlq8pcn5t9r2qcqgw5jy4eszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvumdzx</id>
    
      <title type="html">Surely you can come up with a higher contrast font color scheme ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszzd2g9grzsepgqplpyj549pl95umswlq8pcn5t9r2qcqgw5jy4eszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvumdzx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfdgpkk8e560pte0fdela5fhjnvls722hvxywwccusngz63rvg0qgf8hekx&#39;&gt;nevent1q…hekx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Surely you can come up with a higher contrast font color scheme for your articles?&lt;br/&gt;Safari on iPhone here.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/791/871/445/397/841/original/dc15a7ea92019411.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-27T13:56:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfe6w22n3fgwglsn2fsasec4wyxksxfy0fphps724efu9uhvx7dnszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkscjv3mu</id>
    
      <title type="html">Microsoft: &amp;gt; As much as 30% of the company&amp;#39;s code is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfe6w22n3fgwglsn2fsasec4wyxksxfy0fphps724efu9uhvx7dnszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkscjv3mu" />
    <content type="html">
      Microsoft:&lt;br/&gt;&lt;br/&gt;&amp;gt; As much as 30% of the company&amp;#39;s code is written by AI.&lt;br/&gt;&lt;br/&gt;Also Microsoft:&lt;br/&gt;Somehow we managed to make it so that [clicking the x in Task Manager doesn&amp;#39;t close the app](&lt;a href=&#34;https://www.windowslatest.com/2025/10/30/windows-11-kb5067036-issue-task-manager-wont-close-and-duplicates-may-hurt-performance/&#34;&gt;https://www.windowslatest.com/2025/10/30/windows-11-kb5067036-issue-task-manager-wont-close-and-duplicates-may-hurt-performance/&lt;/a&gt; ).  Whoopsie daisy!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/463/758/861/236/645/original/2fff515a1fda37bf.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-30T15:12:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvhlvw2r84wwpz299shzu2hwrzxlaak3ejhcczkgj8q4ns8snehwszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvnsght</id>
    
      <title type="html">I&amp;#39;ve noticed that Gmail is letting a pattern of spam messages ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvhlvw2r84wwpz299shzu2hwrzxlaak3ejhcczkgj8q4ns8snehwszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvnsght" />
    <content type="html">
      I&amp;#39;ve noticed that Gmail is letting a pattern of spam messages through lately (maybe the past month or two?).&lt;br/&gt;&lt;br/&gt;With the subject line of Delivery Status Notification (Failure) and then just a junk email body.&lt;br/&gt;&lt;br/&gt;Just me?  Is using a subject line of Delivery Status Notification (Failure) really all it takes to get past Gmail&amp;#39;s spam filtering?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/453/279/983/177/054/original/b0a6dc6f7a7cb502.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-28T18:48:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsftva72psj8y8xc946cafc9juvz9myv7c6dech4y8tntrkdpfgvzczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks8h9krq</id>
    
      <title type="html">TIL that I can take the part of my post-sauce tomatoes that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsftva72psj8y8xc946cafc9juvz9myv7c6dech4y8tntrkdpfgvzczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks8h9krq" />
    <content type="html">
      TIL that I can take the part of my post-sauce tomatoes that I&amp;#39;d otherwise throw away (the skins), throw them in a spice grinder, and you get delicious tomato powder!mindblown.gif&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/437/080/249/765/993/original/0172c1fa588119e8.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-25T22:08:09Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp4mpuzz3vg07dgptvnvd7mda87z85ajugdq0hnpldmgz08sngl3czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkskwfjpe</id>
    
      <title type="html">I initially had it at 60 and got the error. So I took their ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp4mpuzz3vg07dgptvnvd7mda87z85ajugdq0hnpldmgz08sngl3czypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkskwfjpe" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdklmp305gp2e76qsj99ndh320wzqmttr828zdjfpzc3wmyswc0aqcu4tux&#39;&gt;nevent1q…4tux&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I initially had it at 60 and got the error.&lt;br/&gt;So I took their suggestion of setting it to 59.  😂
    </content>
    <updated>2025-10-22T13:32:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq9wlachteum0chdtv7kq0pxwcnlhk8m3yrn8mwghunulql0jxnngzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkswdcf7c</id>
    
      <title type="html">Never change, Linux. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq9wlachteum0chdtv7kq0pxwcnlhk8m3yrn8mwghunulql0jxnngzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkswdcf7c" />
    <content type="html">
      Never change, Linux.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/418/026/377/254/515/original/c3defadb4ae6a24f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-22T13:22:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxaatk458h5csu8tz5fescztf7qkf5sx5tushu4m22wugk3x4q6sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2jwvec</id>
    
      <title type="html">Do you or somebody you know have a Windows 10 that isn&amp;#39;t fit ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxaatk458h5csu8tz5fescztf7qkf5sx5tushu4m22wugk3x4q6sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2jwvec" />
    <content type="html">
      Do you or somebody you know have a Windows 10 that isn&amp;#39;t fit for a Windows 11 upgrade? (e.g. no TPM)&amp;lt;li&amp;gt;Get a Windows 11 25H2 ISO&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Run &amp;lt;code&amp;gt;setup /product server&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Enjoy your Windows 11 with no coerced Microsoft Account, TPM features, etc.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/389/760/139/297/698/original/a40929b810a7a5bd.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/389/760/525/928/238/original/359b7ab0e60c9842.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-17T13:34:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgtzeru7d09f9vtuvukc549hx2en0m543ldpdqkhv2pehpttcf8fqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksuv7vuz</id>
    
      <title type="html">Three clicks is a lot to expect, I suppose.</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgtzeru7d09f9vtuvukc549hx2en0m543ldpdqkhv2pehpttcf8fqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksuv7vuz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy8j7xm3y3tx22ezfkkgm2a3gag7za7h7ycwclp2e7ntaeedzh5vgc2q454&#39;&gt;nevent1q…q454&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Three clicks is a lot to expect, I suppose.
    </content>
    <updated>2025-10-08T17:19:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9dh3ajahpef93vtfetdzzf4nzeqq0uf03aqqmwa3gqexguxtlzqgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksqn55jw</id>
    
      <title type="html">For some reason, people seem to be spun up about recent changes ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9dh3ajahpef93vtfetdzzf4nzeqq0uf03aqqmwa3gqexguxtlzqgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksqn55jw" />
    <content type="html">
      For some reason, people seem to be spun up about recent changes that allegedly force people to create Microsoft accounts during Windows 11 setup.&lt;br/&gt;&lt;br/&gt;Except, nothing is being forced.&lt;br/&gt;Windows 11 Pro or better:&lt;br/&gt;Just do the usual:&amp;lt;li&amp;gt;Set up for work or school&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Sign-in options&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Domain join instead&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Create local account.&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Windows 11 Home:&lt;br/&gt;Ok, fine. Microsoft has indeed removed the OOBE.CMD batch file. But you know what? You can run the command that a batch file runs without the batch file itself?reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE /v BypassNRO /t REG_DWORD /d 1 /f&lt;br/&gt;&lt;br/&gt;Once you reboot, you&amp;#39;ll have the I don&amp;#39;t have internet link, where you can create a local account.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/339/098/324/820/507/original/0c702edb7cf88c97.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/339/098/336/907/693/original/73f8d637c48da2ec.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/339/098/349/572/219/original/643e0ae19d349b4f.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/339/099/231/060/018/original/d0c84dbe5a016502.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-08T14:52:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs85wgp9az4yjnknalzhkn5nmmuhc3svmy9w6fpnzhlhqgwdp290pqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksleph4z</id>
    
      <title type="html">I approve. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs85wgp9az4yjnknalzhkn5nmmuhc3svmy9w6fpnzhlhqgwdp290pqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksleph4z" />
    <content type="html">
      I approve.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/091/740/267/819/777/original/f82a022d7dde9742.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-25T22:23:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq5uaa7gsas5k5klvdkfad20ldrlz7wus5zdlsnvt5fcyspka9wuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkstpwna5</id>
    
      <title type="html">I leave for vacation a week ago with Twitter down, and as I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq5uaa7gsas5k5klvdkfad20ldrlz7wus5zdlsnvt5fcyspka9wuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkstpwna5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8ppyvakujfquayr0va9wprlq2pmw6qrtemas6ksee7g74asfv9rgqjvdgt&#39;&gt;nevent1q…vdgt&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I leave for vacation a week ago with Twitter down, and as I return it&amp;#39;s (still/again/🤷‍♂️) down.&lt;br/&gt;Great job, folks!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/563/217/651/895/953/original/1a241080547799f3.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-24T14:13:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8ppyvakujfquayr0va9wprlq2pmw6qrtemas6ksee7g74asfv9rgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksed9guq</id>
    
      <title type="html">Please don&amp;#39;t bother coming back. KTHXBYE ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8ppyvakujfquayr0va9wprlq2pmw6qrtemas6ksee7g74asfv9rgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksed9guq" />
    <content type="html">
      Please don&amp;#39;t bother coming back.&lt;br/&gt;KTHXBYE&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/523/377/317/595/933/original/b792df1bd59374e2.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-17T13:21:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfmnvlcesvlvpf9m7ny23lhqmpze2gh8uqq7x8xdhrtjsl5slevuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksau3e7n</id>
    
      <title type="html">Ooh, another of my NTFS vulnerabilities that I reported **years** ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfmnvlcesvlvpf9m7ny23lhqmpze2gh8uqq7x8xdhrtjsl5slevuczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksau3e7n" />
    <content type="html">
      Ooh, another of my NTFS vulnerabilities that I reported **years** ago was patched today.  🎉&lt;br/&gt;&lt;a href=&#34;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32707&#34;&gt;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32707&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/501/728/289/047/593/original/127d5aa8905234a9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-13T17:35:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxy8r0fs03fhvmfud7l2cys3p8tthes6f9tmzpkpgh6rnvxh558fgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks9gmj44</id>
    
      <title type="html">I&amp;#39;m at a meeting hosted by somebody else where they&amp;#39;re ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxy8r0fs03fhvmfud7l2cys3p8tthes6f9tmzpkpgh6rnvxh558fgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks9gmj44" />
    <content type="html">
      I&amp;#39;m at a meeting hosted by somebody else where they&amp;#39;re using Microsoft Teams, and in the chat I attempted to share an image that is on my laptop.  By clicking the &#43; button and Attach file.&lt;br/&gt;&lt;br/&gt;The result of doing this is that Teams puts the image in **MY COMPANY&amp;#39;S SHAREPOINT SERVER**, and nobody else in Teams can see the image because they **DON&amp;#39;T HAVE AN ACCOUNT** on my company&amp;#39;s SharePoint server.  🤦‍♂️&lt;br/&gt;&lt;br/&gt;Wonders:&lt;br/&gt;1) Has anybody at Microsoft actually tried **using** Teams?&lt;br/&gt;2) Why do people **choose** to use Teams?&lt;br/&gt;&lt;br/&gt;Aside: If you copy an image and press Cmd - V to put the image in the chat, Teams actually... puts the image in the chat.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/501/201/358/592/222/original/03cbbcbea6ab57d9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-13T15:21:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgugdufutmnfhq80w4vvhvzkql220zyswne2h7sazsc3wlhxd766szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks560u2u</id>
    
      <title type="html">It&amp;#39;s fruit update time. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgugdufutmnfhq80w4vvhvzkql220zyswne2h7sazsc3wlhxd766szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks560u2u" />
    <content type="html">
      It&amp;#39;s fruit update time.&lt;br/&gt;&lt;a href=&#34;https://support.apple.com/en-us/100100&#34;&gt;https://support.apple.com/en-us/100100&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/496/091/652/470/910/original/31285c09c3d0fc9c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-12T17:42:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdkcyy07v04kqp6esal3mdgngunu582mazlqj97azazlq2ctt0wegzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszmne2y</id>
    
      <title type="html">You&amp;#39;ve got this. And a tomato is a perfect example of a thing ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdkcyy07v04kqp6esal3mdgngunu582mazlqj97azazlq2ctt0wegzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszmne2y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8532u5p6w9850lc8d0qnq42t7ggteve6uq7l4qdlll3z3vhs50eg8n3aq8&#39;&gt;nevent1q…3aq8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You&amp;#39;ve got this.&lt;br/&gt;And a tomato is a perfect example of a thing that is night and day when it comes to grocery store vs garden. 🎉
    </content>
    <updated>2025-05-09T13:36:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8yzty3csmm2tmp0llphkk3khe279n8x30yag6nw8hfsvh49g725qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksn0vylm</id>
    
      <title type="html">Here are my notes from last season: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8yzty3csmm2tmp0llphkk3khe279n8x30yag6nw8hfsvh49g725qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksn0vylm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsytuv0d73pwslwmtjgld2fkddqgsgsq6340efngu4t90jjzsmvgag0y6k3t&#39;&gt;nevent1q…6k3t&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Here are my notes from last season:&lt;br/&gt;&lt;a href=&#34;https://docs.google.com/document/d/1tOnZuUFsUPCxhaD-cgmQ6h8asci15UATkz7ul6MYad8/edit?usp=drivesdk&#34;&gt;https://docs.google.com/document/d/1tOnZuUFsUPCxhaD-cgmQ6h8asci15UATkz7ul6MYad8/edit?usp=drivesdk&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Tomato-specific I&amp;#39;d say to get some of the blossom rot stop spray. It&amp;#39;s magic. While egg shells sounds like a good idea, I&amp;#39;m not convinced that it does a thing, since calcium isn&amp;#39;t water soluble. (Tomatoes will get soft black spots on the blossom side if they don&amp;#39;t have enough calcium while growing)&lt;br/&gt;&lt;br/&gt;And if you really want to be in touch with the garden, get a soil test kit with those powder capsules. When it comes to the nutrients and pH, you&amp;#39;d never be able to tell with your eyes.&lt;br/&gt;&lt;br/&gt;But in the end, it&amp;#39;s just dirt &#43; water &#43; sun &#43; seeds. How much you put into it is up to you. Nature will take care of the rest. But you **will** get a better bounty with more effort spent. Guaranteed. 😀
    </content>
    <updated>2025-05-09T13:32:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8r950px2jx2dnjvv2tjcz8aeqsllhhpklzntk3ycgdx3w0pxee6qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksxj7x0k</id>
    
      <title type="html">Specifically, out of three seedlings that successfully ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8r950px2jx2dnjvv2tjcz8aeqsllhhpklzntk3ycgdx3w0pxee6qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksxj7x0k" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp2lmnf99ff0klnvxjklzwwgecffvgtf4rex93fgpaqerdjcx9ruq795xk3&#39;&gt;nevent1q…5xk3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Specifically, out of three seedlings that successfully germinated, each of them look exactly like this one. All of their plant friends who received the same treatment are fine.&lt;br/&gt;&lt;br/&gt;Bad batch of seeds maybe?&lt;br/&gt;&lt;br/&gt;/me lifts his skinny fists like antennas to heaven
    </content>
    <updated>2025-05-09T13:16:35Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp2lmnf99ff0klnvxjklzwwgecffvgtf4rex93fgpaqerdjcx9ruqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksgjskej</id>
    
      <title type="html">Last year: Not a single one of my Blue Beech tomato seedlings ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp2lmnf99ff0klnvxjklzwwgecffvgtf4rex93fgpaqerdjcx9ruqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksgjskej" />
    <content type="html">
      Last year: Not a single one of my Blue Beech tomato seedlings survived.&lt;br/&gt;This year:&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/478/041/040/737/214/original/32a57f757a3bfe20.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-09T13:12:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs96jk7s8lvvj9tsds7mdhp6yh0wg9r3vam6hlzjm74rzdq6gcd2sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks8rz0e0</id>
    
      <title type="html">TBH, I&amp;#39;ve never really fully grok&amp;#39;d what Tamper ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs96jk7s8lvvj9tsds7mdhp6yh0wg9r3vam6hlzjm74rzdq6gcd2sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks8rz0e0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrm0v6jjxn86l9z8m9gqgyzurhfyya3m08vj7dgsvaf7s8vyrt4wqk5szm5&#39;&gt;nevent1q…szm5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;TBH, I&amp;#39;ve never really fully grok&amp;#39;d what Tamper Protection actually does.&lt;br/&gt;&lt;br/&gt;Here&amp;#39;s a PoC of a bypass that I found a long time ago.  🤷‍♂️&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/478/007/440/392/968/original/729ad9588b5ff4c3.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2025-05-09T13:03:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd69u7edatahdmd9qqry9xjuwjkjy7emeqjwyem2j0er8vacw3vsqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkshf39uv</id>
    
      <title type="html">No, Tamper Protection does nothing to stop this. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd69u7edatahdmd9qqry9xjuwjkjy7emeqjwyem2j0er8vacw3vsqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkshf39uv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswe77ehy8l4gmvl7n3z9vdf9rhhjca5nhq0q4gwm30tz8dhe5x4vctjnsa8&#39;&gt;nevent1q…nsa8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;No, Tamper Protection does nothing to stop this.&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/475/168/930/570/810/original/2600e081f6982feb.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2025-05-09T01:01:19Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8jmx7vmx6wy5q9vd6vzdchr0um0y57jnkfxaztypzxy3e7vmqn6szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz09ad8</id>
    
      <title type="html">Neat way to disable Windows Defender (or possibly other AV ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8jmx7vmx6wy5q9vd6vzdchr0um0y57jnkfxaztypzxy3e7vmqn6szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz09ad8" />
    <content type="html">
      Neat way to disable Windows Defender (or possibly other AV products)...&lt;br/&gt;&lt;br/&gt;Register a no-op AV product in the Windows Security Center (WSC).  This action is protected by an NDA that AV vendors sign, and, well...&lt;br/&gt;&lt;br/&gt;Anyway, yeah, admin users can do admin things. Don&amp;#39;t forget that.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/es3n1n/defendnot&#34;&gt;https://github.com/es3n1n/defendnot&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/474/016/191/416/836/original/c1cc0ab02f3454bc.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-08T20:08:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdtz96nxluh8l9665y9srjw86346sjmx4k95qsrck9qc4xexzxuzgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks93wc5c</id>
    
      <title type="html">I&amp;#39;ll admit that even with the [updated explicit instructions ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdtz96nxluh8l9665y9srjw86346sjmx4k95qsrck9qc4xexzxuzgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks93wc5c" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgcu8uqwjsrneyj63f0xfw8nrcteg3zs0vcp87kdpcsy4a7qvfz9svuqgcf&#39;&gt;nevent1q…qgcf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;ll admit that even with the [updated explicit instructions on how to get Commvault updates](&lt;a href=&#34;https://documentation.commvault.com/11.38/essential/downloading_software_on_demand.html&#34;&gt;https://documentation.commvault.com/11.38/essential/downloading_software_on_demand.html&lt;/a&gt; ), I fail to see how one can get these mythical SP38-CU25-434 and SP38-CU25-438 optional updates.&lt;br/&gt;&lt;br/&gt;When I first go to &amp;#34;Download or copy software&amp;#34;, Commvault tells me that I&amp;#39;m Up-to-date&lt;br/&gt;&lt;br/&gt;If I **manually** force a download of Latest Fixes for Current Release: 11.38.25, I get an installer that specifies:&amp;lt;code&amp;gt;[Image Information]&amp;lt;br&amp;gt;Version=11.80.380.0&amp;lt;br&amp;gt;ServicePack=38&amp;lt;br&amp;gt;SPTranID=6988515&amp;lt;br&amp;gt;UnixTime=1732240991&amp;lt;br&amp;gt;RevisionNumber=1352&amp;lt;br&amp;gt;Tip=1&amp;lt;br&amp;gt;ReducedMedia=1&amp;lt;br&amp;gt;&amp;lt;/code&amp;gt;&lt;br/&gt;&lt;br/&gt;And if I run this installer and even reboot for good measure, the system is still vulnerable.  And the jar that contains the vulnerable code, cv-ac-common.jar has not changed from my original 11.38.25 vulnerable system.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m not particularly good with computers, so hopefully Commvault sysadmins in the real world are better at this than I am.  But I&amp;#39;ll admit that even with explicit instructions, I have no idea how to get the updates that protect me against CVE-2025-34028.🤷‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/464/625/502/384/086/original/45466ea5816f3fef.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/464/626/098/201/251/original/1e08cf8bfc350eb5.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-07T04:37:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgcu8uqwjsrneyj63f0xfw8nrcteg3zs0vcp87kdpcsy4a7qvfz9szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksavda2f</id>
    
      <title type="html">Oh, wow. Only after pestering the Commvault PSIRT did they update ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgcu8uqwjsrneyj63f0xfw8nrcteg3zs0vcp87kdpcsy4a7qvfz9szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksavda2f" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxe8mgh7wpwh4kdz6v3ly4f24v8r7r6zma64jycgc9qfhlcnzcqcctaneyu&#39;&gt;nevent1q…neyu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oh, wow.&lt;br/&gt;&lt;br/&gt;Only after pestering the Commvault PSIRT did they update the language of their advisory.&lt;br/&gt;&lt;br/&gt;While it **still** incorrectly says that 11.38.0 - 11.38.19 are affected and that 11.38.20 is resolved (it is not), the&amp;#39;ve added a section below this misinformation to convey the actual state of the world:&lt;br/&gt;&lt;br/&gt;11.38.20 is only patched if it has the SP38-CU20-433 **and** SP38-CU20-436 **additional** updates installed.&lt;br/&gt;&lt;br/&gt;And 11.38.25 is only patched if it has the SP38-CU25-434 **and** SP38-CU25-438 **additional** updates installed.&lt;br/&gt;&lt;br/&gt;I cannot think of a behavior that is more vindictive to their customers to botch language in an advisory so bad, and **also** to not bother bumping release versions for the fixes for a CVSS 10 EITW vulnerability.  🤦‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/464/450/506/092/601/original/f3c0de7a8753837f.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/464/451/116/329/288/original/814b4ab3c55bf412.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-07T03:35:35Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxe8mgh7wpwh4kdz6v3ly4f24v8r7r6zma64jycgc9qfhlcnzcqcczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksaux5ye</id>
    
      <title type="html">Now that I have a local copy of the Commvault VM so that I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxe8mgh7wpwh4kdz6v3ly4f24v8r7r6zma64jycgc9qfhlcnzcqcczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksaux5ye" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs87k85n3e7uder7ch2kejhj9svthk2aq2h59atux0yftfvg8qs6zqmau4q4&#39;&gt;nevent1q…u4q4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Now that I have a local copy of the Commvault VM so that I don&amp;#39;t burn truckloads of Azure dollars, I can look at things at my leisure.&lt;br/&gt;&lt;br/&gt;**AND**, it seems that the VM that I have is 11.38.25, which contains the fix for CVE-2025-34028.&lt;br/&gt;&lt;br/&gt;**EXCEPT** the exploit for CVE-2025-34028 still works against it.  🤦‍♂️&lt;br/&gt;&lt;br/&gt;Commvault claims that 11.38.20 **and** 11.38.25 fixes the watchTowr-reported CVE-2025-34028 vulnerability. (Aside: How is it even possible that **two** different versions in the same product line are the ones that fix a single vulnerability?)  watchTowr [discovered the bug in 11.38.20](&lt;a href=&#34;https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/&#34;&gt;https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/&lt;/a&gt; ).&lt;br/&gt;&lt;br/&gt;I trust watchTowr, so I don&amp;#39;t believe Commvault&amp;#39;s statement that 11.38.20 fixes the vulnerability that watchTowr found in 11.38.20.&lt;br/&gt;&lt;br/&gt;I also trust the PoC that I just ran against 11.38.25, so I don&amp;#39;t believe Commvault&amp;#39;s statement that 11.38.25 fixes the vulnerability that watchTowr found in 11.38.20.&lt;br/&gt;&lt;br/&gt;Yes, I have trust issues.  😕&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/458/901/003/124/252/original/4d7dcf947b77b06c.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/458/903/072/597/218/original/bc949823bc70c827.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/458/905/102/553/591/original/8249341a63d86457.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-06T04:06:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs87k85n3e7uder7ch2kejhj9svthk2aq2h59atux0yftfvg8qs6zqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2qagev</id>
    
      <title type="html">After successfully touching grass and beginning to write up ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs87k85n3e7uder7ch2kejhj9svthk2aq2h59atux0yftfvg8qs6zqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2qagev" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv09eey7n8uvgwqpwlk3hadnllszesyhkz35kcf82jwvvgvr7fyrcnjmkfc&#39;&gt;nevent1q…mkfc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;After successfully touching grass and beginning to write up CVE-2025-34028...&lt;br/&gt;&lt;br/&gt;CVE-2025-34028 is a path traversal vulnerability. And yes, the path traversal allows for an unauthenticated attacker to plant files in arbitrary locations.  And presumably Commvault has fixed the path traversal part.&lt;br/&gt;&lt;br/&gt;**BUT**, what about the fact that deployCCPackage() is reachable **by design** (by way of deployServiceCommcell.do being explicitly listed in authSkipRules.xml)?&lt;br/&gt;&lt;br/&gt;Directory traversal aside, in what world does the ability for an unauthenticated client to deploy a Command Center package make sense, whatever that means?  🤔
    </content>
    <updated>2025-05-01T18:55:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszv26cft604malu9jhtag4av4skpwwvdhcqekhx6kxhgea5ndkejgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksh49lqy</id>
    
      <title type="html">Thanks. Yes, you can still RDP in with the old password after the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszv26cft604malu9jhtag4av4skpwwvdhcqekhx6kxhgea5ndkejgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksh49lqy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszj4ntfqayg0r3sk7k3efueh3a89dqv0w45ajctp287srushg90kgls65tp&#39;&gt;nevent1q…65tp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Thanks.&lt;br/&gt;Yes, you can still RDP in with the old password after the account has been switched to passwordless.  No Microsoft Authenticator required.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/433/133/528/491/341/original/085a25003a5ee86b.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/433/137/940/672/639/original/69b69794726d790b.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-01T14:52:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd9xnxn7xwc35x78w4umrtm048537klwx0xv7qfq3g9a9lf7klpeqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksv853gt</id>
    
      <title type="html">Not sure what you mean... My hotmail account **is** passwordless? ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd9xnxn7xwc35x78w4umrtm048537klwx0xv7qfq3g9a9lf7klpeqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksv853gt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8hlnq6zsex2uf7eyfcy3706qjkl9ps07wj49p08dgqzmwfg4t5gsz9s38l&#39;&gt;nevent1q…s38l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Not sure what you mean...&lt;br/&gt;My hotmail account **is** passwordless?  (Locally it uses a PIN)&lt;br/&gt;&lt;br/&gt;Unless you&amp;#39;re talking about something else?
    </content>
    <updated>2025-05-01T12:39:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvkjrezz6e0mv3knsz5qh424nx7tey0g6ms2n7xf9ml2lnuedaxqqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkse7sumc</id>
    
      <title type="html">In my case: Windows 11 Enterprise with a local account initially ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvkjrezz6e0mv3knsz5qh424nx7tey0g6ms2n7xf9ml2lnuedaxqqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkse7sumc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq6hyeecyuhky9mz4uygvprhkvzzcpmyehhdz2ufaegqsckl83f9szux65y&#39;&gt;nevent1q…x65y&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;In my case:&lt;br/&gt;Windows 11 Enterprise with a local account initially (via BYPASSNRO)&lt;br/&gt;I added a Microsoft (hotmail.com) account.&lt;br/&gt;I then turned on RDP.&lt;br/&gt;That&amp;#39;s all. Absolutely nothing else.&lt;br/&gt;&lt;br/&gt;If I log in via that hotmail account to RDP, it will accept the original cached password even if I change my hotmail account password.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/429/420/945/735/068/original/f090a15060e8ba01.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/429/422/475/304/248/original/6caffd399e4feb41.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-30T23:07:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr72dz5sx652n9qd7pnze3feycmq2a9juhqnt5qsvd74fy6tkmcgqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4z9acm</id>
    
      <title type="html">Hm, that all sounds different than what I tested.</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr72dz5sx652n9qd7pnze3feycmq2a9juhqnt5qsvd74fy6tkmcgqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4z9acm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqf0x9zksg347qv5s7mlpzwktyqja8xl3fg29z7ppck5tjw0ccenqg0gwa8&#39;&gt;nevent1q…gwa8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hm, that all sounds different than what I tested.
    </content>
    <updated>2025-04-30T23:01:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspn4yl0a58aqdpgry8s5lklzyv36m50a8vmj9lug9r0dfqlv0s95szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks450gp6</id>
    
      <title type="html">Really? I found it quite easy: 1) log in to windows with a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspn4yl0a58aqdpgry8s5lklzyv36m50a8vmj9lug9r0dfqlv0s95szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks450gp6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy3ad6wnxsfwp2wa5tlm2skktas0hmjgnmdz9yn4jmg0fgtzylg2cmynh32&#39;&gt;nevent1q…nh32&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Really? I found it quite easy:&lt;br/&gt;1) log in to windows with a Microsoft account &lt;br/&gt;2) Turn on RDP&lt;br/&gt;🤷‍♂️
    </content>
    <updated>2025-04-30T22:11:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgcug22wp8s5mjdcsvxawnvkedx9xndxm9yxdcvrfgr8ynnnd7vjgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4s9sex</id>
    
      <title type="html">Yeah, I didn&amp;#39;t have a local AD ready to test. But I could ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgcug22wp8s5mjdcsvxawnvkedx9xndxm9yxdcvrfgr8ynnnd7vjgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks4s9sex" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqfrpm8lt9eyevyyelunzau5dvttzzza8j2lfpxqq9lhumswjaq7q7pajuh&#39;&gt;nevent1q…ajuh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah, I didn&amp;#39;t have a local AD ready to test.&lt;br/&gt;But I could definitely see a difference with authenticating RDP using a local account vs. an online account.&lt;br/&gt;With local accounts, the instant the password changes, the RDP client needs the new password.&lt;br/&gt;For online accounts, the old password still works, indefinitely.
    </content>
    <updated>2025-04-30T19:58:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszcksypjc43wxszcyd8ddy5gnvjnhcaj9vymjs4zqscfhn79v9sgczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks9lr6r9</id>
    
      <title type="html">I&amp;#39;ve seen no evidence that the RDP cred cache gets updated ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszcksypjc43wxszcyd8ddy5gnvjnhcaj9vymjs4zqscfhn79v9sgczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks9lr6r9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrwu8lj3htjm35ttqqldaxr47y79m4auuzmnkma5mmfpve87zn6ss828n3q&#39;&gt;nevent1q…8n3q&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve seen no evidence that the RDP cred cache gets updated ever.&lt;br/&gt;Granted, I only started looking at this very recently, but the reporter seems to indicate that this is the case.
    </content>
    <updated>2025-04-30T19:36:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswrllxnwag5dlvd7tyqwl3akvk6laaafwz8ap8flcedsam4rycgtszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkske7m0u</id>
    
      <title type="html">Google published a [blog post about 0days and the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswrllxnwag5dlvd7tyqwl3akvk6laaafwz8ap8flcedsam4rycgtszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkske7m0u" />
    <content type="html">
      Google published a [blog post about 0days and the like](&lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends&lt;/a&gt; ).  This jumped out at me:&lt;br/&gt;&lt;br/&gt;&amp;gt; Vendor investments in exploit mitigations are having a clear impact on where threat actors are able to find success.&lt;br/&gt;&lt;br/&gt;Stack canaries gained popularity in the Linux world in 2002. When did the Linux-based Ivanti ICS product get stack canaries, after years of ITW exploitation?  2025. That&amp;#39;s right. They decided to wait **TWENTY THREE YEARS** before deciding to turn on a compile-time flag that would have prevented successful exploitation of April&amp;#39;s CVE-2025-22457.&lt;br/&gt;&lt;br/&gt;We all know that comparing the security disposition of companies/products based on CVE counts is both foolish and futile, but sometimes they make it easy for us. 😂
    </content>
    <updated>2025-04-29T12:49:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv09eey7n8uvgwqpwlk3hadnllszesyhkz35kcf82jwvvgvr7fyrczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksztjl7s</id>
    
      <title type="html">Oh, what&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv09eey7n8uvgwqpwlk3hadnllszesyhkz35kcf82jwvvgvr7fyrczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksztjl7s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8d2jyzpa3gf72pknsw0x5dd6q4xn4g4q6u3y9k3rjtja0jc8j49qsfv545&#39;&gt;nevent1q…v545&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oh, what&amp;#39;s that?&amp;#39;NICIPConfigUpdateDeployment-1745511600265&amp;#39; is not valid&lt;br/&gt;?&lt;br/&gt;&lt;br/&gt;Oh, let me put my Azure translation hat on.  Ok, got it:&lt;br/&gt;&lt;br/&gt;&amp;gt; You have exceeded your limit of 10 publicly available IP addresses. Please &amp;gt; **first**&amp;gt;  Disassociate&amp;gt;  the IP address and &amp;gt; **then**&amp;gt;  delete it. Otherwise you will get another error message.&lt;br/&gt;&lt;br/&gt;Boy, this hat is useful.&lt;br/&gt;Just kidding. There&amp;#39;s no such hat.&lt;br/&gt;You need to trudge through things until you brute-force figure things out.&lt;br/&gt;&lt;br/&gt;Time to go touch grass...&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/394/045/439/163/623/original/30076432cca1f602.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-24T17:11:09Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8d2jyzpa3gf72pknsw0x5dd6q4xn4g4q6u3y9k3rjtja0jc8j49qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2yalh3</id>
    
      <title type="html">What&amp;#39;s that? The &amp;#34;Most used by Azure users&amp;#34; VM type ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8d2jyzpa3gf72pknsw0x5dd6q4xn4g4q6u3y9k3rjtja0jc8j49qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2yalh3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp9t4qdllm7fgl028qdqfnkhuh278njw3qgxzc82vap0js5k56ddg3jke4t&#39;&gt;nevent1q…ke4t&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What&amp;#39;s that?&lt;br/&gt;&lt;br/&gt;The &amp;#34;Most used by Azure users&amp;#34; VM type that I picked isn&amp;#39;t available?&lt;br/&gt;&lt;br/&gt;You know what, instead of Go Fish, maybe tell me what I can use?&lt;br/&gt;&lt;br/&gt;**Edit**: Azure Spot pricing apparently isn&amp;#39;t a thing.  No matter which Size &#43; Region combination you choose, you&amp;#39;ll get an error that says that the combo isn&amp;#39;t available where you want it.  🤦‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/393/820/926/795/345/original/5559760f76334056.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/393/821/371/981/644/original/c122cb0b6873f44a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-24T16:25:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp9t4qdllm7fgl028qdqfnkhuh278njw3qgxzc82vap0js5k56ddgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszj33kr</id>
    
      <title type="html">What&amp;#39;s that? I need to remove the number of data disks in my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp9t4qdllm7fgl028qdqfnkhuh278njw3qgxzc82vap0js5k56ddgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkszj33kr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst7g9paq94cm2rggs2wa5ny8ef4hju305m3tk5fm23xjupr5kastsrhcaep&#39;&gt;nevent1q…caep&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What&amp;#39;s that? I need to remove the number of data disks in my VM?  Maybe tell me how to do this?&lt;br/&gt;&lt;br/&gt;**Ohhhh**...   You&amp;#39;ve selected an Azure VM image that requires more than 4 disks, and the VM type currently selected has only 4 disks?   I&amp;#39;m no UI/UX expert, but maybe just **TELL ME THIS**?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/393/791/242/538/845/original/68441ab2dff3f3c5.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-24T16:12:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst7g9paq94cm2rggs2wa5ny8ef4hju305m3tk5fm23xjupr5kastszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7uusln</id>
    
      <title type="html">If you create an ARM VM in Azure, beware that your &amp;#34;Recently ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst7g9paq94cm2rggs2wa5ny8ef4hju305m3tk5fm23xjupr5kastszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks7uusln" />
    <content type="html">
      If you create an ARM VM in Azure, beware that your &amp;#34;Recently used size&amp;#34; will be ARM, and as such you will not be able to create any preconfigured x64 VMs.&lt;br/&gt;&lt;br/&gt;Because of course if your &amp;#34;Recently used size&amp;#34; is ARM, Microsoft will disable the ability to pick an x64 size.  🤦‍♂️&lt;br/&gt;&lt;br/&gt;Yes, I had to create a sacrificial x84 VM in Azure to work around this. Once my recently used size was x64, I was able to pick any size that I wanted.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/393/660/047/299/710/original/b8c83e056a7bd900.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/393/660/464/816/983/original/b2b5148efbc9de3f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-24T16:02:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ff3h55u0az8u6u6wj2paw65fve6g6l84fftpjv9jqg32w8jrf2szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksqns9qz</id>
    
      <title type="html">From over at the Bad Site ™ Both the vulnerability and the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ff3h55u0az8u6u6wj2paw65fve6g6l84fftpjv9jqg32w8jrf2szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksqns9qz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs850cw7atfevfqsarurmmp0euwpqxnjnrhvsj5kz57dy45wah2dnqjv8w98&#39;&gt;nevent1q…8w98&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;From over at the Bad Site ™&lt;br/&gt;Both the vulnerability and the &amp;#34;fix&amp;#34; for CVE-2025-21204 are quite silly.&lt;br/&gt;&lt;br/&gt;The scenario is:&amp;lt;li&amp;gt;Non-admin user creates &amp;lt;code&amp;gt;C:\inetpub\wwwroot&amp;lt;/code&amp;gt; directory and puts web content there&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Admin user at some point in the future enables IIS on the system.&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;The outcome is:&lt;br/&gt;The web content provided by the non-admin user (be it a web shell or whatnot) is served up by IIS.&lt;br/&gt;&lt;br/&gt;Maybe non-admin users shouldn&amp;#39;t be able to make directories or junctions (to directories or files) in C:\?&lt;br/&gt;NAH.&lt;br/&gt;&lt;br/&gt;Maybe installing IIS should provide a clean webroot when it&amp;#39;s installed?&lt;br/&gt;NAH.&lt;br/&gt;&lt;br/&gt;Just preemptively make a C:\inetpub directory that non-admin users can&amp;#39;t write to. That fixes the problem.  🤦‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/353/620/324/754/138/original/fcf2349753b50d90.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-17T13:50:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0knp2uvv2034w5q9akmwwzxxm7gz506x628fn7n7p0n0ngka7q6gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks5xldnt</id>
    
      <title type="html">Get your Apple updates folks. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0knp2uvv2034w5q9akmwwzxxm7gz506x628fn7n7p0n0ngka7q6gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks5xldnt" />
    <content type="html">
      Get your Apple updates folks.&lt;br/&gt;&lt;a href=&#34;https://support.apple.com/en-us/100100&#34;&gt;https://support.apple.com/en-us/100100&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;CVE-2025-31200 and CVE-2025-31201 are being exploited ITW.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/349/460/193/856/875/original/192ef3c5baac44a7.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T20:11:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs09vvnnwm0p2sn69pkpu2pxm3jxsft5yqvwacjlrsw6xp8xdelv5qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksau8r43</id>
    
      <title type="html">Microsoft blocks ActiveX by default in Microsoft 365, Office 2024 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs09vvnnwm0p2sn69pkpu2pxm3jxsft5yqvwacjlrsw6xp8xdelv5qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksau8r43" />
    <content type="html">
      Microsoft blocks ActiveX by default in Microsoft 365, Office 2024&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/microsoft/microsoft-blocks-activex-by-default-in-microsoft-365-office-2024/&#34;&gt;https://www.bleepingcomputer.com/news/microsoft/microsoft-blocks-activex-by-default-in-microsoft-365-office-2024/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;About damn time!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/345/323/808/365/253/original/5298a4f71037e0f1.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T02:39:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr23k855mux2f68luqdegft4guz5lve8x7e89x8utdweutmwpgpxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvpfer4</id>
    
      <title type="html">If I remember my testing properly, a junction to a folder does ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr23k855mux2f68luqdegft4guz5lve8x7e89x8utdweutmwpgpxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksvpfer4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswlf0wx4cs550wzkx6l5vttr6vynmh9dlys9pkncu5r6n8nrxumfs5t0crx&#39;&gt;nevent1q…0crx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If I remember my testing properly, a junction to a folder does not break the update. But a weird junction to a file (which Microsoft claims is not possible) does break the April update.&lt;br/&gt;&lt;br/&gt;Which mirrors the test that a C:\inetpub directory does not break the update but a C:\inetpub file **does** break things. Except that the junction variant is something a non-admin user can do.
    </content>
    <updated>2025-04-14T11:31:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs850cw7atfevfqsarurmmp0euwpqxnjnrhvsj5kz57dy45wah2dnqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksty8xqr</id>
    
      <title type="html">Would changing the ACLs to not allow non-admin users the ability ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs850cw7atfevfqsarurmmp0euwpqxnjnrhvsj5kz57dy45wah2dnqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksty8xqr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspmulz0krx4mxxrst68850qh0vxlln92ckp43m9csqxw3w57cqedq6unqve&#39;&gt;nevent1q…nqve&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Would changing the ACLs to not allow non-admin users the ability to create directories off of C:\ **really** have a real-world impact of limiting LPEs?&lt;br/&gt;&lt;br/&gt;Absolutely. When you write a tool to look for things (e.g. [Crassus](&lt;a href=&#34;https://github.com/vu-ls/crassus&#34;&gt;https://github.com/vu-ls/crassus&lt;/a&gt; )), you see things. Heck, I&amp;#39;ve seen a privileged service attempt to open files in C:\Program%20Files\, which any non-admin Windows user can create by default.&lt;br/&gt;&lt;br/&gt;But no, even despite being presented with evidence for how this could fix an entire **CLASS** of LPEs on Windows, MSRC was not interested.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/328/558/499/280/original/9f375a596e6be1fe.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/328/591/059/828/original/be09298e7e7ce5a8.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/328/622/114/978/original/142b3c0de51b5c9b.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/328/635/901/976/original/e1f0e54c4a14ddad.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-11T12:29:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg7xtp6vply0hxx5m5fuqk4tklz8d2kx862lst7jz6tn8mu5xh40qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksjcmysq</id>
    
      <title type="html">Hilarious. The two things that MSRC seems to aim to to achieve ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg7xtp6vply0hxx5m5fuqk4tklz8d2kx862lst7jz6tn8mu5xh40qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksjcmysq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8qcs2f77xdkcvm8erjk585jxf8h2956skk0a0p2vezag3e53yxucxjy29z&#39;&gt;nevent1q…y29z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hilarious.&lt;br/&gt;The two things that MSRC seems to aim to to achieve are:&amp;lt;li&amp;gt;Avoid saying anything about what their security updates do unless their hand is forced.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Take the path of &amp;#34;least resistance&amp;#34; as opposed to fixing the root cause of problems. (In this case, non-admins can create subdirectories directly off of &amp;lt;code&amp;gt;C:\&amp;lt;/code&amp;gt;)&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@wdormann/114319281111054638&#34;&gt;https://infosec.exchange/@wdormann/114319281111054638&lt;/a&gt;
    </content>
    <updated>2025-04-11T12:20:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspmulz0krx4mxxrst68850qh0vxlln92ckp43m9csqxw3w57cqedqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks085c44</id>
    
      <title type="html">So, apparently this is the &amp;#34;fix&amp;#34; for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspmulz0krx4mxxrst68850qh0vxlln92ckp43m9csqxw3w57cqedqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks085c44" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyn8vt095qxe8xmrume0lj8nkg7k6f3msetw9uxdpl64xceczyvfc4sunc4&#39;&gt;nevent1q…unc4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;So, apparently this is the &amp;#34;fix&amp;#34; for [CVE-2025-21204](&lt;a href=&#34;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204&#34;&gt;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204&lt;/a&gt; ).  Microsoft recently updated their advisory to say what the update does.&lt;br/&gt;&lt;br/&gt;Prior to everybody freaking out, the advisory for CVE-2025-21204 said nothing about what it does.&lt;br/&gt;&lt;br/&gt;Two gripes:&amp;lt;li&amp;gt;MSRC publishing content-free advisories has consequences, but they never seem to appreciate this.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;I told MSRC &amp;lt;strong&amp;gt;YEARS AGO&amp;lt;/strong&amp;gt; that they can avoid an entire class of LPE vulnerabilities in 3rd-party software &amp;lt;strong&amp;gt;and&amp;lt;/strong&amp;gt; their own software by not allowing non-admin users to be able to create directories off of &amp;lt;code&amp;gt;C:\&amp;lt;/code&amp;gt;.  They refused to make any change because it might &amp;#34;break things&amp;#34;.&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Great job, folks.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/275/744/743/060/original/dfdb200d561b058f.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/319/276/345/443/373/original/42bf117e3da87c7a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-11T12:16:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfkmxych9t4uemcjtvrlnl3qu0gv0s5rua3cwenm8j0xj6fshkf4gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2k76rg</id>
    
      <title type="html">Ah, you&amp;#39;d think that you couldn&amp;#39;t. But indeed you can! ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfkmxych9t4uemcjtvrlnl3qu0gv0s5rua3cwenm8j0xj6fshkf4gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2k76rg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsryxrdef7agxz8fch4edsxc5enk4uak6x6zuc0w0zp45le7k9jv6ggzv49d&#39;&gt;nevent1q…v49d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, you&amp;#39;d think that you couldn&amp;#39;t.&lt;br/&gt;But indeed you can!&lt;br/&gt;That is, a non-admin user can create a &amp;#34;directory&amp;#34; junction to a **file** target, which will have the result of April&amp;#39;s security updates failing to install.  😂&lt;br/&gt;&lt;br/&gt;It seems that this weird concept of a junction to a file achieves an unexpected double-standard:&amp;lt;li&amp;gt;It counts as a &amp;lt;strong&amp;gt;directory&amp;lt;/strong&amp;gt; when it comes to NTFS ACLs (a non-admin user can create a junction in &amp;lt;code&amp;gt;C:\&amp;lt;/code&amp;gt;)&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Depending on how the junction is accessed, it might count as a &amp;lt;strong&amp;gt;file&amp;lt;/strong&amp;gt; as opposed to being treated as a directory.&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;This seems like a problem. Obviously in the case of April&amp;#39;s updates here. But perhaps even more generically in that a junction to a file target seems to almost guarantee unexpected behavior.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/468/118/374/963/original/117737951bd66c59.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/468/098/079/634/original/231bb5eedc25ad85.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/494/751/134/719/original/1f3da3b5b4a3c3d9.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/468/576/264/239/original/637c727e33bcbaa2.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-10T20:26:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf9wmceqx40avnlus2a3tu64flf2azy37y3pfml4j6fd76gscs4rqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkse3zwdu</id>
    
      <title type="html">Just to be clear, while mklink /h can itself be used by a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf9wmceqx40avnlus2a3tu64flf2azy37y3pfml4j6fd76gscs4rqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkse3zwdu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9d7jkx43p7n5ygc7up8dq6mm8t8t24004kk063rsufthjuns0xsdh6lu7&#39;&gt;nevent1q…6lu7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Just to be clear, while mklink /h can itself be used by a non-admin user, that same non-admin user would not be able to create a hard link in C:\ as that would be the same as creating a file there. Which non-admin users can&amp;#39;t do.
    </content>
    <updated>2025-04-10T19:58:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdhuatehztkt6l0gl2937rarmhha287yk4paxyvqs3fyapqcylk6qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2z3zp3</id>
    
      <title type="html">You can? Non-admin users don&amp;#39;t have ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdhuatehztkt6l0gl2937rarmhha287yk4paxyvqs3fyapqcylk6qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2z3zp3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxlrkjd2ufx9h787fcj4mltstfwz22asv8d5n25g42rw2pseyfaegttl7sk&#39;&gt;nevent1q…l7sk&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can?&lt;br/&gt;Non-admin users don&amp;#39;t have SeCreateSymbolicLinkPrivilege, so I don&amp;#39;t believe you.  😀&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/339/916/620/405/original/0ac365f918db7466.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-10T19:35:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs07ykxcujsn4290w3x5vemlzf69cahjg53v952qs0dda3lawvg8sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksq7slqa</id>
    
      <title type="html">Ah, that&amp;#39;d do it! But at the same time, creating files in the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs07ykxcujsn4290w3x5vemlzf69cahjg53v952qs0dda3lawvg8sqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksq7slqa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszrh8u9zftzcmc445gn9f262hhsy7wtep6h0j3e5djjcwgxfty5tsdjpyum&#39;&gt;nevent1q…pyum&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, that&amp;#39;d do it!&lt;br/&gt;But at the same time, creating files in the root directory requires admin privileges.&lt;br/&gt;And if you&amp;#39;re a trigger-happy admin, there are plenty of footguns that you can use.  🤷‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/306/010/556/017/original/4edcd62c718580ca.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/312/018/694/860/original/c76890f4e4d646cb.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-10T19:28:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsykzxjflt7cavm4grtesvmlrs3veu3s5v3290mxvwa3xh6wccmq0qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2pjdsm</id>
    
      <title type="html">Specifically, I&amp;#39;ve seen all April updates install even when ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsykzxjflt7cavm4grtesvmlrs3veu3s5v3290mxvwa3xh6wccmq0qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks2pjdsm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsguh30j3k55wa05un3e37fm5uu9n2w8lkh3ntehr3yfhxygzd34hsv5n362&#39;&gt;nevent1q…n362&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Specifically, I&amp;#39;ve seen all April updates install even when C:\inetpub exists ahead of time.&lt;br/&gt;&lt;br/&gt;I should have known better than to attribute the correlation of C:\inetpub in a VM  before updates to the causation of a failed update.&lt;br/&gt;&lt;br/&gt;What happens with C:\inetpub is tough to see, as it either happens before the Procmon boot driver loads, or Procmon is otherwise foiled by the updates occurring. But either way, there&amp;#39;s a bit of a blind spot between pre-reboot C:\inetpub not being there and it being there post-reboot.  A Procmon boot log sees nothing.  😕&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/085/369/818/791/original/2e70f29df7d7ed13.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/315/096/002/788/236/original/c73ec6e4493404ac.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-10T18:32:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqphnjz8zv4dejedkcqmwyh98dwhqhp5ernuchqcx0nmkecf3dlwczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksnm648s</id>
    
      <title type="html">If IIS is truly installed, KB5057589 installs fine. Presumably ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqphnjz8zv4dejedkcqmwyh98dwhqhp5ernuchqcx0nmkecf3dlwczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksnm648s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspd45xvx8e486wz9zgrew88043685xprqtcd334zzcvuf35mmhegc3y3ajp&#39;&gt;nevent1q…3ajp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;If IIS is truly installed, KB5057589 installs fine.&lt;br/&gt;Presumably the failed installation is due to unexpected permissions on C:\inetpub?
    </content>
    <updated>2025-04-10T15:37:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfmr84uvjlhna2dkzx9awd0xs3l0j0m87f2myejxsvyxfu5cgxmnqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa68xr6</id>
    
      <title type="html">Yeah, so this is interesting. I was skeptical, but I can confirm ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfmr84uvjlhna2dkzx9awd0xs3l0j0m87f2myejxsvyxfu5cgxmnqzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa68xr6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs888ua5mmnvf6m28f23cg76amhdm6r7p5wyjn23edgvggprx9dnsc2qkqh2&#39;&gt;nevent1q…kqh2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah, so this is interesting. I was skeptical, but I can confirm that [KB5057589](&lt;a href=&#34;https://support.microsoft.com/en-us/topic/kb5057589-windows-recovery-environment-update-for-windows-10-version-21h2-and-22h2-april-8-2025-74bc2baa-4ac6-40d0-8dde-4a8462b8f7e7&#34;&gt;https://support.microsoft.com/en-us/topic/kb5057589-windows-recovery-environment-update-for-windows-10-version-21h2-and-22h2-april-8-2025-74bc2baa-4ac6-40d0-8dde-4a8462b8f7e7&lt;/a&gt; ) (which installs [KB5055674](&lt;a href=&#34;https://support.microsoft.com/en-us/topic/kb5055674-safe-os-dynamic-update-for-windows-10-version-21h2-and-22h2-april-8-2025-bccc4714-2dca-4d07-be7b-1f38d9eb3e5b&#34;&gt;https://support.microsoft.com/en-us/topic/kb5055674-safe-os-dynamic-update-for-windows-10-version-21h2-and-22h2-april-8-2025-bccc4714-2dca-4d07-be7b-1f38d9eb3e5b&lt;/a&gt; )) for Windows 10 will fail to install if there is a C:\inetpub directory present ahead of time, which a non-admin user can fulfill.&lt;br/&gt;&lt;br/&gt;I wouldn&amp;#39;t expect the update to be so fragile that the mere presence of a C:\inetpub directory prevents its installation. While KB5057589 is indeed listed as a &amp;#34;Security Update&amp;#34;, I can find no information of what CVE(s) it fixes.  🤔&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/314/084/290/005/673/original/1046fbf3d5631702.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/314/084/912/020/799/original/ada09b9ca13f641b.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/314/085/867/522/689/original/e8d5cf1eaac1fb90.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-10T14:17:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyn8vt095qxe8xmrume0lj8nkg7k6f3msetw9uxdpl64xceczyvfczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa5lg9f</id>
    
      <title type="html">After installing April&amp;#39;s updates, Windows 10 and 11 systems ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyn8vt095qxe8xmrume0lj8nkg7k6f3msetw9uxdpl64xceczyvfczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksa5lg9f" />
    <content type="html">
      After installing April&amp;#39;s updates, Windows 10 and 11 systems now have an empty C:\inetpub directory.&lt;br/&gt;&lt;br/&gt;This seems... unexpected?&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/308/855/978/617/969/original/add7da11cee02475.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-09T16:05:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw3swtaf6zlrdfk4qyz039vysju9ahj898jq62mu8lrn5lqtlsycczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksmyfu4d</id>
    
      <title type="html">Vulnerability thoughts:&amp;lt;li&amp;gt;Most attacks these days rely on ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw3swtaf6zlrdfk4qyz039vysju9ahj898jq62mu8lrn5lqtlsycczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksmyfu4d" />
    <content type="html">
      Vulnerability thoughts:&amp;lt;li&amp;gt;Most attacks these days rely on &amp;lt;strong&amp;gt;chains&amp;lt;/strong&amp;gt; of vulnerabilities.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Things that get CVSS scores are almost exclusively CVEs, which are &amp;lt;strong&amp;gt;individual&amp;lt;/strong&amp;gt; vulnerabilities.&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;It&amp;#39;s the vulnerability chains that matter, but the numbers that people are looking at are the individual vulnerability &amp;#34;links&amp;#34;. And as a result, we ironically benefit by people **not** following the rules and assigning a CVSS for the whole chain to an individual link. Case in point:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@wdormann/114275453831928356&#34;&gt;https://infosec.exchange/@wdormann/114275453831928356&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/308/629/954/933/414/original/6216600d2af4e4d9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-09T15:09:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszyl7gmtklmm8u48jph6mrptflqgquzww90gg8vk0wlgjgltkp3lczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksyh53mz</id>
    
      <title type="html">Yeah, the funny/scary thing about all of this is that these ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszyl7gmtklmm8u48jph6mrptflqgquzww90gg8vk0wlgjgltkp3lczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksyh53mz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg9egpm5uum9dsnzqtynjtw3g5htr47d7skjk54yamhuqfhzlkmjsgur6cm&#39;&gt;nevent1q…r6cm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah, the funny/scary thing about all of this is that these recent cases were all based on &amp;#34;we saw that the device was compromised by the failed ICT test&amp;#34;&lt;br/&gt;&lt;br/&gt;That right there is evidence that the attacker was **SO BAD** that they didn&amp;#39;t even bother to **hide their tracks**. Imagine what the good ones are up to. 😂&lt;br/&gt;&lt;br/&gt;Yes, the same thing could be said for any attack, but the Ivanti case is somewhat special based on how trivial it is to subvert both the external ICT and also the factory reset process.
    </content>
    <updated>2025-04-05T12:59:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr57envhey968pegqygz76tp5e5x65ajhv9qk8krrcwnsf8mcwy3qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz2j3xm</id>
    
      <title type="html">I mean, this would be discoverable with the dumbest of dumb HTTP ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr57envhey968pegqygz76tp5e5x65ajhv9qk8krrcwnsf8mcwy3qzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksz2j3xm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9ajf75rs25pd4h6j6jwtnydntam0d6cvjhv3wvjs6wh6eg69es7sf4g8px&#39;&gt;nevent1q…g8px&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I mean, this would be discoverable with the dumbest of dumb HTTP fuzzing.&lt;br/&gt;You&amp;#39;d need to know **absolutely nothing** about the target app or what it expects.
    </content>
    <updated>2025-04-04T18:57:16Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr54ed5sneerf4qplwj89fs35qqwl9eqy7aqp6vfgtcnny9ymve6gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksnj3rs9</id>
    
      <title type="html">And [per the excellent folks at ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr54ed5sneerf4qplwj89fs35qqwl9eqy7aqp6vfgtcnny9ymve6gzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksnj3rs9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdcqdrdxw7xv0eseh95ywsjqgeyxzfnvu2fhlc45ysp0hyptxhqxc5fvtgx&#39;&gt;nevent1q…vtgx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And [per the excellent folks at watchTowr](&lt;a href=&#34;https://labs.watchtowr.com/is-the-sofistication-in-the-room-with-us-x-forwarded-for-and-ivanti-connect-secure-cve-2025-22457/&#34;&gt;https://labs.watchtowr.com/is-the-sofistication-in-the-room-with-us-x-forwarded-for-and-ivanti-connect-secure-cve-2025-22457/&lt;/a&gt; ), we can see what the vulnerability is:&lt;br/&gt;A stack buffer overflow in X-Forwarded-For&lt;br/&gt;&lt;br/&gt;No need to find a specific endpoint or do something clever. Simply make a web request to **anywhere** on an ICS system with a large X-Forwarded-For HTTP header and you&amp;#39;ll get a stack buffer overflow on the system.  🤦‍♂️&lt;br/&gt;&lt;br/&gt;And due to the fact that the Ivanti web server does a fork() without a corresponding exec(), we get the same memory layout every single time.&lt;br/&gt;&lt;br/&gt;Now, about Ivanti&amp;#39;s use of remediated... The function where the overflow happens just happens to have been rewritten in a way that avoids the overflow.&lt;br/&gt;&lt;br/&gt;Did Ivanti recognize the possibility of a stack buffer overflow and not recognize it as a security issue? Or did they just happen to change code to accidentally avoid the overflow (and decide to use exploit mitigations as well).&lt;br/&gt;&lt;br/&gt;You decide...&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/140/413/280/971/original/0ad30e70a74288ae.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/141/105/205/085/original/68fe07f0072d0c64.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/192/527/118/331/original/44446d921b84ffc5.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/280/146/260/123/934/original/dccbbd6e0aa12435.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-04T14:25:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9wzwvprgrs9em2994z3l4qp0360lh6t6msh8gk9gylq5dshfu7cgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkswvt35z</id>
    
      <title type="html">There&amp;#39;s this magical thinking that the CVE ID is what gives ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9wzwvprgrs9em2994z3l4qp0360lh6t6msh8gk9gylq5dshfu7cgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkswvt35z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdey5hdfurq0udlxv84pssx6gq7y0fdgfkm0nuukaxuvwv6cw3k4smmva3v&#39;&gt;nevent1q…va3v&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;There&amp;#39;s this magical thinking that the CVE ID is what gives attackers the ability to compromise systems.&lt;br/&gt;&lt;br/&gt;If you say that your software is vulnerable but fail to assign CVEs, you&amp;#39;re only helping the **attackers**.&lt;br/&gt;&lt;br/&gt;I remember the time that Microsoft got mad at me for &amp;#34;leaking&amp;#34; one of their CVEs to the public before the update was available. As in their world, CVE IDs were for Microsoft updates. Not for identifying vulnerabilities. 🤦‍♂️&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/279/610/521/759/845/original/8f190a43dddeb82b.jpeg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/279/610/521/686/617/original/6d2aabcc66a7daea.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-04T12:10:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdey5hdfurq0udlxv84pssx6gq7y0fdgfkm0nuukaxuvwv6cw3k4szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks27jmxa</id>
    
      <title type="html">Apparently the CVE system is for bickering. 🤷‍♂️ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdey5hdfurq0udlxv84pssx6gq7y0fdgfkm0nuukaxuvwv6cw3k4szypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks27jmxa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvfc2yflqsahudfcenu4khva0al9la6rfptjdsrka0ch6sdc2dzpchfju8p&#39;&gt;nevent1q…ju8p&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Apparently the CVE system is for bickering. 🤷‍♂️&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/details-emerge-on-cve-controversy-around-exploited-crushftp-vulnerability/&#34;&gt;https://www.securityweek.com/details-emerge-on-cve-controversy-around-exploited-crushftp-vulnerability/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/279/568/311/468/701/original/c44506e0803e839c.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-04T11:58:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdcqdrdxw7xv0eseh95ywsjqgeyxzfnvu2fhlc45ysp0hyptxhqxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkscnha0e</id>
    
      <title type="html">Now, regarding the &amp;#34;silent fix&amp;#34; of CVE-2025-22457, which ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdcqdrdxw7xv0eseh95ywsjqgeyxzfnvu2fhlc45ysp0hyptxhqxczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkscnha0e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8k773dzrfqh43a0e5wr97e6j42augtraewngvp37v675ugq95jkcdq8hnp&#39;&gt;nevent1q…8hnp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Now, regarding the &amp;#34;silent fix&amp;#34; of CVE-2025-22457, which per Ivanti:&lt;br/&gt;&lt;br/&gt;&amp;gt; This vulnerability has been remediated in Ivanti Connect Secure 22.7R2.6 (released February 11, 2025)&lt;br/&gt;&lt;br/&gt;That word remediated...&lt;br/&gt;&lt;br/&gt;Careful readers will see that Ivanti didn&amp;#39;t **fix** the vulnerability in 22.7R2.6.&lt;br/&gt;&lt;br/&gt;What changed in 22.7R2.6? With this version, Ivanti compiled **some** of the ICS binaries with exploit mitigations that have been around for 20 years. And wouldn&amp;#39;t you know it, it paid off already?  Everybody&amp;#39;s gotta learn sometime...&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/275/552/878/380/322/original/545a16fc157c657d.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/275/562/489/795/107/original/21b3dd2357824bab.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-03T18:57:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8k773dzrfqh43a0e5wr97e6j42augtraewngvp37v675ugq95jkczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks52q97n</id>
    
      <title type="html">Given that the web server on an ICS runs as the limited nr user, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8k773dzrfqh43a0e5wr97e6j42augtraewngvp37v675ugq95jkczypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rks52q97n" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswp5s5dfvzmyehh3mcslggacjag0z2qkqgkn5sgw43tqhutl084js8m3s75&#39;&gt;nevent1q…3s75&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Given that the web server on an ICS runs as the limited nr user, both the Ivanti and the Mandiant advisory are missing any indication whatsoever how the threat actors are gaining root privileges.&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve reported 4 different ICS LPEs to Ivanti recently, but none of them have been fixed yet.&lt;br/&gt;&lt;br/&gt;Back in the CVE-2025-0282 days, Ivanti made up a CVE-2025-0283 CVE to capture the LPE aspect of attacks happening in the wild. I say &amp;#34;made up&amp;#34; because I&amp;#39;ve seen no evidence whatsoever that any LPE was fixed between 22.7R2.5 and 22.7R2.6.&lt;br/&gt;&lt;br/&gt;Knowing what&amp;#39;s going on in an ICS device is a huge blind spot, but apparently seeing how attackers are LPE&amp;#39;ing is even blind-er.
    </content>
    <updated>2025-04-03T18:30:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswp5s5dfvzmyehh3mcslggacjag0z2qkqgkn5sgw43tqhutl084jszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksmrh6rs</id>
    
      <title type="html">Ivanti CVE-2025-22457 is being exploited ITW. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswp5s5dfvzmyehh3mcslggacjag0z2qkqgkn5sgw43tqhutl084jszypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rksmrh6rs" />
    <content type="html">
      Ivanti CVE-2025-22457 is being exploited ITW.&lt;br/&gt;&lt;a href=&#34;https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457&#34;&gt;https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Per [Mandiant](&lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability&#34;&gt;https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability&lt;/a&gt; ):&lt;br/&gt;&lt;br/&gt;&amp;gt; We assess it is likely the threat actor studied the patch for the vulnerability in ICS 22.7R2.6 and uncovered through a complicated process, it was possible to exploit 22.7R2.5 and earlier to achieve remote code execution.&lt;br/&gt;&lt;br/&gt;Gee, who could have imagined that attackers are looking at patches?  🤔&lt;br/&gt;&lt;br/&gt;1) This apparently was silently fixed for ICS in 22.7R2.6, as the fix for this was released in February.  Ivanti Policy Secure and ZTA gateways are expected to receive a patch in late April.&lt;br/&gt;&lt;br/&gt;2) The advisory still conveys the magical thinking if **if** your device shows signs of compromise, then you should perform a &amp;#34;factory reset.&amp;#34;  This is magical in that the [ICT won&amp;#39;t catch a compromise nor will the &amp;#34;factory reset&amp;#34; reset to factory condition if the attacker is bothering to try](&lt;a href=&#34;https://infosec.exchange/@wdormann/113805254385223581&#34;&gt;https://infosec.exchange/@wdormann/113805254385223581&lt;/a&gt; ).&lt;br/&gt;&lt;br/&gt;While Mandiant also parrots the magical thinking of running the ICT tool, which I guess is the best advice if you&amp;#39;re not going to throw the device in the trash since there isn&amp;#39;t an official integrity checking tool that is sound, they do throw out a tidbit of:&lt;br/&gt;&lt;br/&gt;&amp;gt; ... and conduct anomaly detection of client TLS certificates presented to the appliance.&lt;br/&gt;&lt;br/&gt;Bets on whether CVE-2025-22457 is an overflow in the handling of a field in a client-provided certificate?  😂&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/275/335/314/017/398/original/c8817f4a63e90e8d.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-03T18:06:02Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstqdx974rjkwjvpsccrj4xlh09udwq4fe3n4pfv7gzu5rclk6ehmgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkstavc27</id>
    
      <title type="html">FWIW, I did some testing with the eicar string in an ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstqdx974rjkwjvpsccrj4xlh09udwq4fe3n4pfv7gzu5rclk6ehmgzypg6uyqfu3qrmqslc8qju99lfdqdu3x8m3sh0zvggr9pa70ea0rkstavc27" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszqk9mt809vg37aa3rv5fekvry4rhsqkege78tpf8ze80m66qj5cslp3h2a&#39;&gt;nevent1q…3h2a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;FWIW, I did some testing with the eicar string in an AES-encrypted zip (via 7-zip)&amp;lt;li&amp;gt;EICAR as &amp;lt;code&amp;gt;eicar.com&amp;lt;/code&amp;gt; : Blocked&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;EICAR as &amp;lt;code&amp;gt;hello.txt&amp;lt;/code&amp;gt; : Allowed&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;EICAR with an appended &amp;lt;code&amp;gt;A&amp;lt;/code&amp;gt; as &amp;lt;code&amp;gt;eicar.com&amp;lt;/code&amp;gt; : Blocked&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;CRC32 collision as &amp;lt;code&amp;gt;eicar.com&amp;lt;/code&amp;gt;: Blocked&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;CRC32 collision as &amp;lt;code&amp;gt;hello.txt&amp;lt;/code&amp;gt;: Allowed&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;So at least as of this specific test, it may be that the Gmail SMTP server is perhaps just using filenames for &amp;#34;blocking&amp;#34; the sending of mail.&lt;br/&gt;&lt;br/&gt;And again, I use scare quotes around &amp;#34;blocked&amp;#34; as while the SMTP server does say that the message was blocked &amp;#34;because its content presents a potential security issue.&amp;#34; But the email is indeed sent to the recipient., despite the warning.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/268/465/099/733/873/original/a728f1552bfe07a2.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-02T12:53:40Z</updated>
  </entry>

</feed>