buherator
banner
buherator.bsky.social
buherator
@buherator.bsky.social
"I'm interested in all kinds of astronomy."

https://scrapco.de

Mostly cross-posting from Fediverse: @[email protected]
Please help making #TreeSitter Playground better by doing this little experiment:


tree-sitter.github.io ->

Write some JS, like `var x=1;`. Enable Query and provide the `(identifier) @foo` pattern in the new Query textbox.

Do you see the code
1/2
November 21, 2025 at 6:29 PM
[RSS] exploits.club Weekly(ish) Newsletter 92 - S23 N-Day PoCs, Printer Overflows, DNG OOB Writes, And More


blog.exploits.club ->


Original->
November 21, 2025 at 5:54 PM
[RSS] NSO Group argues WhatsApp injunction threatens existence, future U.S. government work


cyberscoop.com ->


Original->
November 21, 2025 at 2:23 PM
User-friendly GUI: please provide command line parameters in this text box!

Me, knowing that one of characters will need escaping:


Original->
November 21, 2025 at 2:08 PM
That's how I like my #Friday's: I came back from lunch and my code started working!

Time to push to prod...


Original->
November 21, 2025 at 1:22 PM
[RSS] How And Why We Hacked Cypherock Hardware Wallet: The Full Story


www.darknavy.org ->

"How did the U.S. government obtain LuBian%27s wallet private key?"


Original->
November 21, 2025 at 11:17 AM
what if we just forgot about DNS and start to address everything in IPv6-l33tspeak?


Original->
November 21, 2025 at 10:27 AM
[RSS] AI Coding Vibe Check


tamir.dev ->

/by @tmr232


Original->
November 20, 2025 at 5:04 PM
[RSS] Deleting the [Boot Configuration Data] through COM as low privileged user [CVE-2025-59253]


warpnet.nl ->


Original->
November 20, 2025 at 11:38 AM
[RSS] Deleting the [Boot Configuration Data] through COM as low privileged user [CVE-2025-59253]


warpnet.nl ->


Original->
November 20, 2025 at 11:33 AM
... what makes this esp. frustrating is that the code is _right there_ in the current virtualenv, but oh no, let's make those servers in us-east-1 work, we gotta pump those CO2 numbers up!

#python #uv


Original->
November 20, 2025 at 11:08 AM
The lesson for today is that you must always give your code weird ass names because tools tend to go online and fetch something completely unrelated if they can find the name :P


Original->
November 20, 2025 at 10:53 AM
November 20, 2025 at 7:37 AM
[RSS] Remotely crashing the Spooler service


incendium.rocks ->


Original->
November 20, 2025 at 7:27 AM
[RSS] LITE XL RCE (CVE-2025-12121)


bend0us.github.io ->


Original->
November 20, 2025 at 7:27 AM
Another humble #UX request:

I know dates look ugly, but "last month" is a pretty wide timeframe and when my brain sees "3 weeks ago" it will recall yesterdays dinner and the 1994 World Cup finals with equal probability.

Please display exact dates on frontends!


Original->
November 19, 2025 at 1:04 PM
TIL cURL only supports the lowercase http_proxy environment variable:


curl.se ->


Original->
November 19, 2025 at 12:34 PM
[RSS] dz6: vim-like hex editor


crates.io ->


Original->
November 19, 2025 at 11:49 AM
[RSS] "Astral-tokio-tar" / "uv" Arbitrary Write Path Traversal Vulnerability


github.com ->

This is CVE-2025-59825


Original->
November 19, 2025 at 11:49 AM
[RSS] HEX ADVENT 2025: Crack the Advent, Conquer the Threat


starlabs.sg ->


Original->
November 19, 2025 at 11:49 AM
Since yesterdays #AdTech link was received quite positively, I'm sharing again this collection from The Correspondent:

Debunking the science of advertising

thecorrespondent.com ->

The Correspondent was an incredible
1/2
November 19, 2025 at 7:56 AM
Cloudflare down is another teachable moment to think about your eggs and your baskets.


Original->
November 18, 2025 at 12:30 PM
reasoning_effort = 'none'


Original->
November 17, 2025 at 6:57 PM
Friendly advice for crisis communication:

"Our systems have been under attack for T days" doesn't mean that your system withstood the attack for that long. Hackers don't work with sledgehammers.

It means that you saw the attack but were unable to act on it for T days.
1/2
November 17, 2025 at 3:30 PM
This is a fun one: LLM inference creates a timing side channel that allows identifying sensitive topics by passively intercepting encrypted traffic:


www.microsoft.com ->

/via @jonny


Original->
November 17, 2025 at 10:09 AM