Lobster Roll

Stories by fro

M1RACLES: An Apple M1 Vulnerability (m1racles.com)
Defer available in gcc and clang (gustedt.wordpress.com)
RAMBleed (rambleed.com)
OpenBSD 7.7 released April 28, 2025 (marc.info)
Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program (habr.com)
Firefox and Chromium (madaidans-insecurities.github.io)
This man thought opening a TXT file is fine, he thought wrong. macOS CVE-2019-8761 (paulosyibelo.com)
A few thoughts on Fuchsia security (blog.cr0.org)
CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent (qualys.com)
PuTTY vulnerability vuln-p521-bias (chiark.greenend.org.uk)
All Your Macs Are Belong To Us (objective-see.com)
An Introduction to OpenBSD (blog.lambda.cx)
Making openat(2) and friends more useful in practice (undeadly.org)
Amiga Desktops Worth Seeing (datagubbe.se)
Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug (github.blog)
Multiple Security Issues in Screen (security.opensuse.org)
Memory Sealing "mseal" System Call Merged For Linux 6.10 (phoronix.com)
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641) (github.blog)
MacOS "DirtyNIB" Vulnerability (blog.xpnsec.com)
Send My: Arbitrary data transmission via Apple's Find My network (positive.security)
Hi, My Name Is Keyboard (github.com)
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild (citizenlab.ca)
Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection (microsoft.com)
CVE-2023-4273: a vulnerability in the Linux exFAT driver (dfir.ru)
tachy0n: The last 0day jailbreak (blog.siguza.net)
On Apple Exclaves (randomaugustine.medium.com)
OpenBSD crond / crontab set_range() heap underflow (CVE-2024-43688) (supernetworks.org)
macOS 11's hidden security improvements (blog.malwarebytes.com)
UVA Engineering Computer Scientists Discover New Vulnerability Affecting Computers Globally (engineering.virginia.edu)
Warning: Grsecurity: Potential contributory infringement and breach of contract risk for customers – Bruce Perens (perens.com)