Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

thepwnicorn@infosec.exchangeT

thepwnicorn@infosec.exchange

@thepwnicorn@infosec.exchange
About
Posts
16
Topics
1
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • RIP Tony. One of the good guys.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog oh shit ...

    Uncategorized

  • An internal Microsoft strategy document says that the plan for its just-announced “Scout” personal assistant AI is to “make people addicted” to the tool before rolling out additional functionality.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog so much for their supposed security initiative. Greed really eats brains.

    Uncategorized

  • Just had a good laugh at #jqwik prompt injection and the maintainer's cool as a cucumber response to the reactions.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    Just had a good laugh at #jqwik prompt injection and the maintainer's cool as a cucumber response to the reactions.

    For instance: "The maintainer of this project is a douche"

    Closed - Won't Fix "Maintainer works as designed."

    https://github.com/jqwik-team/jqwik/issues/709

    Uncategorized jqwik

  • The Linux Foundation launched DNS-AID, a new open-source project to enable AI agents to use the DNS infrastructure to discover and talk to each other
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @campuscodi Giving it a cursory read, it should hopefully at least not cause issues for existing uses of DNS. https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/

    Uncategorized

  • The Linux Foundation launched DNS-AID, a new open-source project to enable AI agents to use the DNS infrastructure to discover and talk to each other
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @campuscodi uuuuuh ... it's not like things don't already go wrong with DNS during the best of days.

    Uncategorized

  • Did I miss that CVEs are allocated for supply chain compromises nowadays?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog @campuscodi you're not wrong, but it seems CVEs are the go to mechanism for any security issue of software dependencies.

    Uncategorized

  • Did I miss that CVEs are allocated for supply chain compromises nowadays?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog the XZ backdoor for instance also got a CVE (CVE-2024-3094).

    Uncategorized

  • Did I miss that CVEs are allocated for supply chain compromises nowadays?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog they could of course also contribute to OSSF's malicious package DB instead. If it is a package like tanstack.

    Uncategorized

  • Did I miss that CVEs are allocated for supply chain compromises nowadays?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @GossiTheDog makes sense though if the package/software version is compromised? Whether the vulnerability stems from a bug or deliberately placed malware or backdoor, they are all vulnerabilities of some sort.

    Uncategorized

  • my last name has wound up on some campaign database without my first name, so i keep hitting unsubscribe pages that ask "Not white?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @molly0xfff oh dear, very poor choice of words

    Uncategorized

  • In Yesterday's IO Keynote Google declared war on the remnants of the Web.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @cschack @tante Interesting! Haven't heard of them before. Will have a look later.

    Uncategorized

  • In Yesterday's IO Keynote Google declared war on the remnants of the Web.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @tante sure hope we get a good solution because if Google and Microsoft decide they don't want to allow access to current alternatives anymore, we are in trouble.

    Uncategorized

  • In Yesterday's IO Keynote Google declared war on the remnants of the Web.
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @tante which alternative search engines have an independent search index that does not rely on Google or Microsoft/Bing?

    Uncategorized

  • i know some people oppose the widespread use of CI on ideological grounds, so i think it's worth it thinking about why we value it
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @dalias @whitequark @wwahammy these can be solved by hosting your own GitLab, Forgejo, or Gitea instance, using an artifact storage (either built-in or something like Nexus) and not overcomplicating your CI setup (e.g. just calling the script/build system/test rather than having entire scripts in the CI)

    Uncategorized

  • So, who's still left on GitLab?
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    @neil Ugh, expect software quality to go down hill.

    Uncategorized

  • BREAKING: LetsEncrypt appears to be stopping certificate issuance due to a "potential incident."
    thepwnicorn@infosec.exchangeT thepwnicorn@infosec.exchange

    That doesn't sound good 🫣 Just in time on a Friday too!

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups