Evariste
@evaristegal0is
🏳️🌈🦄 don't drink and root 🦄🏳️🌈 uccidiamo i mostri sacri
I got feedback from Dublin BSides attenders, and I am officially good at making jokes in my non-native language :)
This technique is similar to a payload I wrote 2/3 years ago for Foxit Reader, but it works better on Adobe Reader lol I am surprised it was not exploited earlier
ormai la moderazione è stata completamente abbandonata; questi sono i suggerimenti su google, non l'ultimo degli arrivati, palese black seo. (no, non gioco d'azzardo, nemmeno occasionalmente, non ho seguo il calcio o gli sport in generale, potrebbe essere basato sulla posizione ma mi pare strano)
Però ChatGPT è arrivato solo a tardo 2022 (Nov.), StackOverflow era malato da tempo.
1. github.com/pymupdf/PyMu... 2. github.com/pdfcpu/pdfcp... Path traversal in font extraction via font name
Feels like CVE-2025-64512 is underrated. It can literally be used to run arbitrary code in markitdown (84k ⭐️ on GitHub) and other projects, ingesting a crafted file. github.com/luigigubello...
Io non scherzavo mica ieri, ho riso moltissimo per sto meme (la coda invece la possono vedere pochi fortunati)
My cat died today. His name was Cosimo Frattini: Cosimo in honor of Italo Calvino's "The Baron in the Trees", and Frattini in honor of the Italian mathematician Giovanni Frattini. This day sucks.
[🧵 short] This is an RCE in the Granola app for macOS, I found in December 2024 (patched). Every time I have an Electron-based app that integrates AI, I am quite confident that developers trust AI output, because AI is not a user (untrusted input), but if you act like a user, you are a user. 1/
Feel free to have fun and report this to Microsoft (user-interaction required, XSS in OneDrive using Firefox)
See you in Kraków to talk about a niche topic: PDF, web applications, and JavaScript injections! :)
Ogni volta che si utilizza un'analogia militare per la sicurezza informatica, un pezzettino di me muore, sono praticamente uno zombie ormai
What I know until now: - On 9th Dec, a data leak was shared on the XSS forum, apparently the entire AWS infrastructure was compromised [1]; - On 12th Dec, Arduino communicated "no evidence that the incident can result in harm to the security of our Arduino Web and Cloud services" [2]
🧵 [1/2] If you are an Arduino customer and use their online service, you should probably know that it could be compromised - but I am waiting for official updates. Arduino sent an e-mail today communicating they are rotating *all* the IoT devices' credentials, for all customers.
Q: Ciao, giornalismo italiano, come te la passi? A: Bene, dai, "intervisto" large language models e pubblico questa "intervista" dietro paywall. L'informazione è finita, morta, non vedo davvero speranza.
Magari hanno ragione, ma - almeno nel mio lavoro - gli imprevisti, e gli incidenti, me li aspetto statisticamente dal lunedì al venerdì dalle 9:00 alle 17:00, cioè esattamente quando ci sono più eventi legittimi che accadono sull'infrastruttura. E non con origine dolosa.
What should happen in your browser if you open this HTML file locally? 1. The browser blocks the script 2. The browser loads the script 3. Browsers, except Safari, block the script
🚨 At least 143 high-value phishing domains were registered in the last two months by the actor leonidbo4kariev@gmail.com. All the domains were registered on the registrar GMO Internet Group. These domains have multiple subdomains. They are not detected on VT. List: viewdns.info/reversewhois...
Post a pic YOU took (no description) to bring some zen to the timeline