-

Twitter avatar for @julianor
Juliano Rizzo @julianor
Microsoft downplays padding oracle exploitability 12 years after "THE" ASP .NET bug (CVE-2010-3332): “attacker would need to perform 128 attempts per byte of plain text to decrypt .. We view putting this combination of qualifiers together for an attack to be rare”(CVE-2022-30187)

-

Twitter avatar for @Aditi_muses
Aditi Agrawal @Aditi_muses
🧵There are multiple red flags in The Wire's reports.

I spoke to @debayan0, @alexstamos, @elegant_wallaby and @matthew_d_green to understand the biggest ones.

🚩1. Entire process relies on screenshots and videos that can be easily faked.

Twitter avatar for @newslaundry
newslaundry @newslaundry
#TheWire’s reporting on #Meta's content moderation processes and subsequent explanations raised questions, with experts pointing out inconsistencies and supposed fabrications.

So, what precisely were the problems?

@Aditi_muses asked four domain experts.https://t.co/xUapshZLTk

-

Twitter avatar for @LouisStaples
Louis Staples @LouisStaples
thoughts and prayers to the authors of this book. out December 8th!
Image

-

Twitter avatar for @mchmarny
Mark Chmarny @mchmarny
Super excited to announce that @Google donated ko, tool for simple, fast, and secure container image building, to @CloudNativeFdn. We are excited to see how the broader open source community will continue innovating with the ko project.

-

Twitter avatar for @fryan
Fergus Ryan @fryan
If you spent any time on China-watching Twitter in 2021, you probably came across these two women.

Party-state media, Chinese diplomats & foreign vloggers tried to make out they were just an ordinary account.

We took a closer look & found out that wasn't quite right. 🧵

-

-

I’m way behind on the offensive cyber services market, but this stuff is pretty cool.

https://grayhatwarfare.com/

-

-

-

He's four months old.

-

-

-

-

A case that illuminates the ways in which cyber infrastructure intersects with society. People became used to having anonymity via multiple accounts on the app. Then all the account data ends up public and now all those “secret” accounts are being linked tougher.

Anonymity is hard.


-

Ppl don't need to know how face recognition works to know that it harms them.

Twitter avatar for @scottjshapiro
Scott Shapiro @scottjshapiro
I beg you, if you work on the Ethics of AI, please learn something about AI.

-

Twitter avatar for @hkashfi
Hamid @hkashfi
“Golang’s core team released a patch that fundamentally changes how that language parses URLs. Before version 1.17, Golang considered semicolons within a URL query portion as a valid delimiter”

Easy to miss but good vector for auth/authorization bypass!

-

Twitter avatar for @not_matthias
Matthias @not_matthias
TIL that you can bypass Windows Defender by setting your computer name to HAL9TH. Who the hell thought this was a good idea?
Image

Source:

-

Twitter avatar for @Imi_Ahmed
Imran Ahmed @Imi_Ahmed

-

Twitter avatar for @Aristot73
Aristotle Tzafalias @Aristot73
Image

-

Don't miss what's next. Subscribe to the grugq's newsletter: