buherator
banner
buherator.bsky.social
buherator
@buherator.bsky.social
480 followers 250 following 2.5K posts
"I'm interested in all kinds of astronomy." https://scrapco.de Mostly cross-posting from Fediverse: @[email protected]
Posts Media Videos Starter Packs
[RSS] IBM i LIBL Autopwn: Kill the Vulnerability Class


blog.silentsignal.eu ->

#IBMi exploits go brrr


Original->
I guess Taszk tweaked their RSS a bit and a bunch of Mediatek reports fell into my reader. Some of them are old, these are from 2025:

CVE-2025-20725
CVE-2025-20726
CVE-2025-20727
CVE-2025-20678


labs.taszk.io ->


Original->
The QoS of this web server is apparently configured so that it gradually decreases my connections bandwidth so that my downloads ETA doesn't change.


Original->
AWS is down, but the Fediverse still keeps shitposting 💪


Original->
[RSS] Hacking the World Poker Tour: Inside ClubWPT Gold's Back Office


samcurry.net ->


Original->
[RSS] Dissecting a 1-Day Vulnerability in Linux's XFRM Subsystem


streypaws.github.io ->


Original->
Yesterday by *total accident* I went to the concert of a band that inspired some of the favorite bands of my youth. They play very rarely and I didn't even think about going out, but ran into some friends and one thing led to another...

It was incredible, and put "age" to a new
1/2
Me: Let's use this well established OSS project again after several years!
Project: We're in Dependency Hell since last month, builds don't work...

Why is it always like this with me?? #fml


Original->
TIL if you want to change the config of the logging module in PyGhidra you have to reastart #Ghidra for the new config to take effect...

Bonus: There is a predefined `writer` stream object that you can use to log to the GUI console.


Original->
I'm looking for publicly available reverse engineered program databases (idb, gpr, bndb, ... ), preferably for relatively small programs.

Any tips?

#ReverseEngineering


Original->
[RSS] Denial of Fuzzing: Rust in the Windows kernel


research.checkpoint.com ->


Original->
"Which of course makes perfect sense when you are in the business of breaking stuff so people have to pay you for fixing it."

This is an old article, but this one sentence explains so many things!


dzone.com ->


Original->
(fair warning: if you are a JSF author, you better not come to punching distance of me)


Original->
[RSS] exploits.club Weekly Newsletter 89 - iOS GPU Driver Bugs, Kernel Stack UAFs, Hardware Wallet Auth Bypasses, and More


blog.exploits.club ->


Original->
[RSS] I remember taking a screen shot of a video, and when I opened it in Paint, the video was playing in it! What witchcraft is this?


devblogs.microsoft.com ->


Original->
Windows ARM64 Internals: Deconstructing Pointer Authentication | Prelude

www.preludesecurity.com ->


Original->
Depicting an iOS Vulnerability – DFSEC Research

blog.dfsec.com ->


Original->
FTR: today's star of the show is #F5


Original->
Reposted by buherator
🚨 Save the Date for #offensivecon26

Mark your calendars, spread the word, and stay tuned for when registrations open!

📍 Hilton Berlin
🧠 Trainings: 11–14 May 2026
🎤 Conference: 15–16 May 2026

Visit 🔗offensivecon.org for more details.