0daysto.live

0daysto.live

0daystolive | @[email protected]

Opinions are those of my employer.
Computer Hacker.
Work @ https://sorcery.ie
Blog @ https://0daysto.live

@0xamit it was done publicly for propaganda, all very intentional

CEO salary: 6.9 million dollars
Marketing: 3k dollars and some cookies
Engineer salaries: 500 thousand dollars
Buying ad company: 5 million dollars

Can someone who is good at budgetting help me? My fucking browser is failing so hard I have got to sell user personal data

In our new report today, we detail the exploit chains in Linux kernel USB drivers that forensic traces show were likely used by Cellebrite to unlock Android phones in Serbia. We collaborated with Benoît Sevens @ Google TAG, who found and patched 3 kernel vulnerabilities.

This highlights the large attack surface presented by rogue USB devices to Android and other Linux devices. Some of the vulnerable code paths were introduced almost 15 years ago!

https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/

@lxo @mjg59 how could you possibly describe the war in Ukraine as a proxy war? Who is using Russia as a proxy?

R.I.P. western.romanempi.re, truly one of the greatest instances out there. Will miss you so much

@LivingCooki what's up?
EDIT: damn you got me

what if, appreciative code linter: Line 26: Newline before operator is very elegant indeed

@TarkabarkaHolgy yep, it's a thing in Ireland, part of the https://fleadhceoil.ie competition.

From the rules: "A story should not be confused with a recitation, a monologue or verse speaking. The idea of the old storyteller sitting by the fire, entertaining his or her neighbours, should be a good guideline as to what storytelling is."

is a non profit community hacking that is in its 10th year in Ireland, it pulls in folks from all levels and up to 130 teams have competed annually, they even accomodate secondary school level competitors at their events.

It takes place in Croke Park in March. They've had a tough year with company sponsorship, I've thrown my own company's hat in the ring but it would be great to get some larger companies on board

Appeal: https://www.linkedin.com/posts/activity-7294329748451680256-mZ03

Site: https://zerodays.ie/

@GossiTheDog I went and hashed the keys on https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/API%20Key%20Leaks/Files/MachineKeys.txt and compared. There's only 252 keys on Microsoft's list that aren't in this one

Old Soviet joke repurposed for 2025:
Several times daily, a woman opens a news website, glances at the screen, then closes it.

Her spouse, curious, asks what she's doing.

The woman explains she's looking for death notices.

The spouse says that the website only has headlines, not obituaries.

The woman replies, "Oh, the obituaries I'm praying for will be headlines."

Why is elden ring lore so gratuitously obtuse and complicated

The hidden DOM nodes of a shadow tree are generally not affected by anything applied outside the shadow tree, and vice versa. The shadow boundary, where the shadow DOM ends and the regular DOM begins, can be traversed, but only very intentionally:

@gf_256 there's a browser extension called Dearrow that makes titles less clickbaity and has user contributions

just learned about recency bias. my favourite type of bias for sure

@underthebreach this is fake https://sourceforge.net/p/sevenzip/bugs/2539/ much like the Twitter users previous tweets about getting 120k$ from Riotgames bugbounty I suspect

who decided on the name Secret Santa when Nondisclosure Claus was right there for the taking

@PogoWasRight if the compromise of one worker leads to the entire company going under I don't believe you "did everything right". It doesn't even sound like the worker was an IT admin so they didn't follow the Principle of Least Privilege and internally the network was insecure.

@roolyaboolya what part is non-deterministic? Is it the surplus ballot redistribution when candidates reach the threshold?

»