Marco Ivaldi

When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.

Marco Ivaldi boosted:
nixCraft 🐧nixCraft
2025-05-03

👊

Tech humor meme. A man threatens a crying child with 'something to cry about,' which turns out to be a complex book titled 'The kubernetes networking guide.'
Marco Ivaldi boosted:
cR0w :cascadia:cR0w@infosec.exchange
2025-05-02

watchTowr labs published a good write-up on the EITW vulns in the SonicWALL SMA100 ( CVE-2024-38475 and CVE-2023-44221 ).

labs.watchtowr.com/sonicboom-f

2025-05-01

@storkk lol I know the feeling 😅 thank you for your kind feedback!

Marco Ivaldi boosted:
2025-05-01

Intel's 386 processor (1985) moved the x86 architecture to 32 bits, but it needed to be backward compatible with earlier 16 and 8-bit processors. As a result, it needed complicated circuitry for its internal registers: six different circuits for 30 registers. Let's look at the silicon circuits. 1/N

A die photo of the Intel 386 processor under the microscope. The die has complex patterns that make up the different parts of the chip. The various blocks are roughly rectangular with different textures.
The main functional blocks are labeled, including the paging unit, bus interface unit, prefetch unit, segment unit, instruction decode unit, protection test unit, data unit, and control unit. The register file, the subject of this thread, is in the lower left corner, highlighted by a red rectangle. This die photo image has a purple tint.
Marco Ivaldi boosted:
yossarian (1.3.6.1.4.1.55738)yossarian@infosec.exchange
2025-05-01

my colleague @DarkaMaul has put out a new post on the @trailofbits blog on how we worked with @pypi's maintainers to slash PyPI test run times from ~160s to ~30s despite overall test counts growing by 17% (3900 to 4700+):

blog.trailofbits.com/2025/05/0

this is some of my favorite kind of work: faster test suites means that developers run tests locally more often, and are less hesitant to add new tests (especially parametric ones). another great example of security and performance/reliability engineering dovetailing.

#opensource #security #python

2025-05-01

It looks like I’ll be attending TumpiCon again! If anyone in my network is coming, let’s meet there. infosec.exchange/@TumpiConIT/1

2025-05-01

A couple of days ago, I unearthed my first #computer, an #MSX straight from the ‘80s. It was lost in some box in the basement for who knows how long. Just feeling its power switch gave me the goosebumps…

This discovery came after sharing my hacker’s origin story with Nic Fillingham and Wendy Zenone in a new episode of Microsoft’s #BlueHat #Podcast.

thecyberwire.com/podcasts/the-

Join us while we chat about my first-ever #CVE, overlooked #vulnerabilities that continue to pose significant risks today, #ActiveDirectory and #password security, my unexpected journey into #bugbounty hunting and my involvement in the #ZeroDayQuest, how to learn new things, mentorship and positive leadership, and of course pineapple pizza 🍍🍕

This is how you make a hacker
Marco Ivaldi boosted:
2025-04-30

30 April 1945 | As Soviet forces neared his command bunker in Berlin Adolf Hitler shot himself.

Hitler's Thousand Year Reich lasted twelve years, four months & eight days.

We need to commemorate all the victims & remember where ideologies of hatred may lead humanity to.

A newspaper - The Stars and Stripes - informing about the death of Adolf Hitler.A photo of Adolf Hitler in an army uniform.
Marco Ivaldi boosted:
Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2025-04-30

#Mozilla: Multiple Vulnerabilities in Mozilla Products (Firefox, Firefox Updater, Thunderbird) Could Allow for Arbitrary Code Execution:
CVE-2025-2817, CVE-2025-4082, CVE-2025-4083:
👇
mozilla.org/en-US/security/adv

Marco Ivaldi boosted:
2025-04-30

TIL a programming bug caused Mazda infotainment systems to brick whenever someone tried to play the podcast, 99% Invisible, because the software recognized "% I" as an instruction and not a string

99percentinvisible.org/episode
#til #todayilearned
reddit.com/r/todayilearned/com

2025-04-30

@todayilearned @buherator a format string bug perhaps?

2025-04-30

Happy #Walpurgisnacht to all who celebrate!

Marco Ivaldi boosted:
2025-04-30
AI generate image of a can of password spray in the style of Axe Body Spray with the tag line “Hack The Hearts”
Marco Ivaldi boosted:
Vinoth (Mobile security)vinoth@infosec.exchange
2025-04-30

Good news on mobile zero-days in 2024:
- Zero day exploits in mobile fell YoY (~50%)
- Exploit chains with multiple zero day vulnerabilities are almost exclusively in mobile. Generally, this means mobiles are harder to break in.

The flip side:
- % of zero days in enterprise technologies (i.e not end-user facing) is increasing (37% ->44%)
- Much of that is due to zero days in *security* and networking products.
- Security and networking products are generally compromised with a single vulnerability, no exploit chain required. This is scary given the outsized impact of compromising these products.
- Actors conducting cyber espionage still lead the attributions

Google Threat Intelligence Group released their analysis of 2024 0-days that the group tracked:
cloud.google.com/blog/topics/t

Marco Ivaldi boosted:
Slashdot :verified:slashdot@mastodon.cloud
2025-04-29
Marco Ivaldi boosted:
joernchen :cute_dumpster_fire:joern@threatactor.club
2025-04-29
Marco Ivaldi boosted:
Alanna 🏳️‍🌈🏳️‍⚧️kelpana@mastodon.ie
2025-04-29

Significant event for many, many reasons. Especially the fact Sophie Wilson spoke at it considering what is going on in the UK right now. One of the world's most widely used chips wouldn't exist without her contribution.

theregister.com/2025/04/29/arm

#bbcmicro #arm

Marco Ivaldi boosted:
bert hubert 🇺🇦🇪🇺🇺🇦bert_hubert@fosstodon.org
2025-04-29

In 15 minutes Europe will hopefully launch its next climate satellite. The launch can however only be watched via YouTube since we apparently can’t do that ourselves and have to put our government info next to the antivax promo. esa.int/ESA_Multimedia/ESA_Web

Marco Ivaldi boosted:
2025-04-29
[RSS] Why did Windows 7, for a few months, log on slower if you have a solid color background?

https://devblogs.microsoft.com/oldnewthing/20250428-00/?p=111121
Marco Ivaldi boosted:
Lorenzo Stoakesljs@mastodonapp.uk
2025-04-29

I wrote a book on Linux Memory Management, published by @nostarch - it's a comprehensive 1300 page exploration of Linux 6.0's memory management code, depth-first, diving into the code and REALLY explaining how things work.

The idea is to avoid hand waving as much as possible and literally explore what the kernel _actually_ does.

It's full of diagrams and careful explanations of logic including a ton of stuff you just can't find anywhere else.

It's currently available in its entirety in draft form via early access when you pre-order.

It's available at nostarch.com/linux-memory-mana

:)

#linux #kernel #mm

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst