Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

dragosr@chaos.socialD

dragosr@chaos.social

@dragosr@chaos.social
About
Posts
4
Topics
3
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • It's no secret that I've been struggling, and my therapist said I need to find things to keep me busy, so I created the @cdnspace Artemis II dashboard.
    dragosr@chaos.socialD dragosr@chaos.social

    @chad @cdnspace

    Heh, those Claude style sheets are so distinct now. It does a good job on UI elements. One of the few areas GPT 5.4 hasn't surpassed it yet.

    Uncategorized nasa artemis csa artemisii artemis2

  • I've watched LLMs write full exploit chains for years.
    dragosr@chaos.socialD dragosr@chaos.social

    I've watched LLMs write full exploit chains for years. The amazement fades fast once you hit context limits and spend hours steering the model past every hard corner. But the industry is packed with people who just arrived and are still in that first rush. This Calif post is a good example — real result, soft target (no KASLR, no canaries), 44 human prompts. The gap between demo and production hardened targets is the part nobody wants to talk about yet.

    Link Preview Image
    MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)

    To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.

    favicon

    (blog.calif.io)

    Uncategorized

  • PSA for Azure users who automate deploys and skip Portal banners: default outbound access is going away for subnets.
    dragosr@chaos.socialD dragosr@chaos.social

    PSA for Azure users who automate deploys and skip Portal banners: default outbound access is going away for subnets.

    Pre-April 1st subnets are grandfathered. New ones are private by default - you can re-enable old outbound behaviour explicitly, or deploy a NAT Gateway (~$36/mo) as the better architecture.

    How many folks will find out when their deploy scripts and connectivity breaks April 1st? Private-by-default is the right security move though.

    Link Preview Image
    Default Outbound Access in Azure - Azure Virtual Network

    Learn about default outbound access in Azure.

    favicon

    (learn.microsoft.com)

    Uncategorized

  • Your UEFI firmware can inject a PE binary into Windows on every boot via WPBT (Windows Platform Binary Table).
    dragosr@chaos.socialD dragosr@chaos.social

    Your UEFI firmware can inject a PE binary into Windows on every boot via WPBT (Windows Platform Binary Table). smss.exe extracts it to disk and runs it as SYSTEM. OEMs use this to survive OS reinstalls. Attackers use it the same way.

    One registry key tells Windows to ignore the table entirely:

    reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v DisableWpbtExecution /d 1 /t REG_DWORD /f

    Won't stop real firmware implants, but kills a whole class of cheap persistence for free.

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups