November 25, 2025
November 25, 2025
A ton of great info here about what Apple does for their secure boot chain: “A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture” https://t.co/ppQyOSRMwY
— Xeno Kovah (@XenoKovah) November 24, 2025
We've found a high-severity zero-day vulnerability in Firefox using @WeAreAisle's autonomous AI security system. It's now going by the name of CVE-2025-13016.
— Stanislav Fort (@stanislavfort) November 24, 2025
If you're interested, here's my detailed technical blog post: https://t.co/o13azuTBw0 pic.twitter.com/Jv3WbkChRH
Sha1-Hulud v 2.0 confirmed spreading. 28k infected repos so far. Growing at around 1k repos per hour.
— Gi7w0rm (@Gi7w0rm) November 24, 2025
Some important repos already affected (postman, posthog, asyncapi ...)https://t.co/FQpKi3JfhG https://t.co/wNXSWSuaOy
-
Just published a summary of "modern" Windows authentication reflection attacks. Turns out reflection never really died. 😅https://t.co/2YxXlaRMMC
— Andrea P (@decoder_it) November 24, 2025
In case you weren't there: Here's our talk with @theevilbit at @hexacon_frhttps://t.co/gq7CWe99x2
— Gergely Kalman (@gergely_kalman) November 24, 2025
Russia’s Intelligence Services After the War https://t.co/baMxU50LiS
— Michael Smith (@MickWSmith) November 24, 2025
Here’s cool ADSB website that makes visualization of aircraft and airspace pretty easy.
— Thenewarea51 (@thenewarea51) November 25, 2025
It’s call airloom. pic.twitter.com/lHIeKKW0HI
Good write-up on using macOS' CryptoTokenKit to generate hardware-bound, user-verified, SSH keys, protected by the Secure Enclave, without installing any additional software:https://t.co/RRoqTKRlCv
— Dino A. Dai Zovi (@dinodaizovi) November 24, 2025
These guys detect every building on Earth. Every three months 🤯https://t.co/ScFXjP61Mq pic.twitter.com/sw8i4Xs9LH
— Milos Makes Maps (@milosmakesmaps) November 24, 2025
Want to learn about how a fascinating XSS vulnerability found by @ethiack engine led to an interesting rabbit hole of bypassing WAFs and parameter injection?
— André Baptista (@0xacb) November 24, 2025
Read the blog post here 👇https://t.co/CcVdjyn30W
My HEXACON talk video is out! It covers a small race condition in the Linux kernel’s io_uring. I recommend watching it at 1.25× speed since I’m still not great at speaking 😅https://t.co/lMuweA7PyU
— Pumpkin 🎃 (@u1f383) November 25, 2025
Here is the slide!https://t.co/9jPoKMzxwL
Start the conversation: