dragosr's Avatar

dragosr

@dragostech.bsky.social

Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV

1,561 Followers  |  3,712 Following  |  1,133 Posts  |  Joined: 11.11.2024  |  2.0527

Latest posts by dragostech.bsky.social on Bluesky

Preview
Critical RCE Vulnerabilities Discovered in React & Next.js | Wiz Blog React and Next.js are exposed to critical unauthenticated RCE via CVE-2025-55182 and CVE-2025-66478. Learn which versions are impacted and how to mitigate.

39% of Cloud instances need to patch urgently for 100% reliable unauthenticated RCE in React and Next.js www.wiz.io/blog/critica...

03.12.2025 19:19 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
What to know about a recent Mixpanel security incident OpenAI shares details about a Mixpanel security incident involving limited API analytics data. No API content, credentials, or payment details were exposed. Learn what happened and how weโ€™re protectin...

Mixpanel was compromised. Includied some OpenAI usage data.

openai.com/index/mixpan...

28.11.2025 11:59 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A *huge* vaccine victory. I've been writing on this for years; Australia has seen remarkable progress in cervical cancer prevention with the HPV vaccine. I love seeing science triumph like this.

27.11.2025 18:12 โ€” ๐Ÿ‘ 4255    ๐Ÿ” 1265    ๐Ÿ’ฌ 21    ๐Ÿ“Œ 25

It's a funny quality/tell of GenX, from back when media was scarce and not infinitely accessible on the Internet, to define/describe oneself or characterize personality by music albums or concerts possessed or seen, because it took effort. They and older folks are the only ones that do that now.

27.11.2025 16:37 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Some of us have been advocating this going back since chatGPT launched. It also has other benefits: correcting someone else's work is actually a really good way to learn something yourself.

23.11.2025 21:24 โ€” ๐Ÿ‘ 1664    ๐Ÿ” 457    ๐Ÿ’ฌ 14    ๐Ÿ“Œ 10
Post image Post image Post image

So thereโ€™s a website called Deer Of St Nicholas which posts Christmas wish letters from Ukrainian children who had their childhood stolen by the war, anyone can pick a child and get them their present and itโ€™s that time of the year again to achingly scroll it for hours again

07.11.2025 08:21 โ€” ๐Ÿ‘ 740    ๐Ÿ” 378    ๐Ÿ’ฌ 15    ๐Ÿ“Œ 17
Three tiers of rustic wood shelves, lit by warm LED strips, display an extensive agave spirits collection; between the bottles are calavera skull flasks, small skeleton statues, and a La Catrina figurine, while a row of tall white-and-blue ceramic decanters lines the top shelf and boxes and bar tools sit on the counter below.

Three tiers of rustic wood shelves, lit by warm LED strips, display an extensive agave spirits collection; between the bottles are calavera skull flasks, small skeleton statues, and a La Catrina figurine, while a row of tall white-and-blue ceramic decanters lines the top shelf and boxes and bar tools sit on the counter below.

From a bar seat looking into an open kitchen: a round low tequila bottle with a black cap sits beside a square Herradura Anejo bottle on a wooden ledge amid glasses and a metal towel bucket, additional Don Julio bottles line the left edge, cooks work under hanging pans and warm strip lighting, and a windowed wall with shelves and equipment runs along the right.

From a bar seat looking into an open kitchen: a round low tequila bottle with a black cap sits beside a square Herradura Anejo bottle on a wooden ledge amid glasses and a metal towel bucket, additional Don Julio bottles line the left edge, cooks work under hanging pans and warm strip lighting, and a windowed wall with shelves and equipment runs along the right.

Close-up at a wooden bar: a handled yellow dish holds nachos covered in melted cheese, seasoned ground meat, pico de gallo, and a dollop of sour cream; behind it are Firelli and Cholula hot sauces, stacked plates, a skull-print container with napkins and cutlery, a menu labeled TEQUILA, and drinks including two small pours of clear liquor and a tall orange mixed drink.

Close-up at a wooden bar: a handled yellow dish holds nachos covered in melted cheese, seasoned ground meat, pico de gallo, and a dollop of sour cream; behind it are Firelli and Cholula hot sauces, stacked plates, a skull-print container with napkins and cutlery, a menu labeled TEQUILA, and drinks including two small pours of clear liquor and a tall orange mixed drink.

Printed sign in Japanese and English promoting a "UKRAINE SUPPORT CHARITY DRINK" titled "SLAVA UKRAINE," price 400 yen (440 yen with tax); the center image shows tall shot glasses layered yellow and blue, each topped with a lime slice and ignited; footer note states a 200 yen donation per drink.

Printed sign in Japanese and English promoting a "UKRAINE SUPPORT CHARITY DRINK" titled "SLAVA UKRAINE," price 400 yen (440 yen with tax); the center image shows tall shot glasses layered yellow and blue, each topped with a lime slice and ignited; footer note states a 200 yen donation per drink.

I have a new favorite place in Shibuya, Tokyo - Taco Fanatico, amazing tequila collection. Delicious!

ๆธ‹่ฐทใงๆ–ฐใ—ใ„ใŠๆฐ—ใซๅ…ฅใ‚Šใฎๅบ—ใ‚’่ฆ‹ใคใ‘ใŸ - Taco Fanaticoใ€‚ใƒ†ใ‚ญใƒผใƒฉใฎๅ“ๆƒใˆใŒๅ……ๅฎŸใ—ใฆใ„ใ‚‹ใ€‚ใŠใ„ใ—ใ„๏ผ

09.11.2025 05:57 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Are these commies in the room with you right now?

08.11.2025 02:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

That domain was registered in Korea and has been out in "client hold." However that also means no DKIM, SPF, DMARC - so IF YOUR MAILSERVER IS MISCONFIGURED it can still be used as source of spoofed mail.

But if you are seeing that mail, you need to fix your mailserver.

29.10.2025 19:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

AI watermarking is security theater. Every watermark scheme has an accessible neutralization process. Adversarial watermarks like Fawkes don't solve thisโ€”they're just as easily defeated. The attacker's computational advantage makes this an unwinnable arms race.

29.10.2025 01:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

We trusted images because they were hard to fake. That assumption is dead. Authentication must shift to cryptographic signatures from photographers and publishers. Trust becomes transitive: you trust the image only to the extent you trust its signer.

29.10.2025 01:33 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

CAD $59.99 = USD 42.84 = EUR 36.86

26.10.2025 18:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
A product image of the IKEA DEJSA table lamp from IKEA Canada. The lamp has a rounded white glass shade shaped like a dome or mushroom cap, sitting on a cylindrical beige base. The image shows the lampโ€™s power cord extending to the right. Text below lists the price as $59.99 CAD, a 4.5-star rating from 551 reviews, and the seller as IKEA Canada.

A product image of the IKEA DEJSA table lamp from IKEA Canada. The lamp has a rounded white glass shade shaped like a dome or mushroom cap, sitting on a cylindrical beige base. The image shows the lampโ€™s power cord extending to the right. Text below lists the price as $59.99 CAD, a 4.5-star rating from 551 reviews, and the seller as IKEA Canada.

Let's figure out what the duties & tariffs impact is in various parts of the world.

Reply with your country's price.

26.10.2025 18:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
President Reagan's Address to Canadian Parliament on April 6, 1987
YouTube video by Reagan Library President Reagan's Address to Canadian Parliament on April 6, 1987

youtu.be/_THYKIbT-sE

26.10.2025 14:59 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Revealing the Cascading Impacts of the AWS Outage | Ooklaยฎ Explore the global impact of the Oct 2025 AWS US-EAST-1 outage, with 16M+ reports, a DNS root cause, and clear guidance to contain future failures.

This is a good deep dive on what really happened with AWS
www.ookla.com/articles/aws...

22.10.2025 16:53 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Are old browsers really that much of a problem?
Can I Use reports 94.18% global availability caniuse.com/mdn-http_hea...

16.10.2025 06:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Inside NVIDIA GPUs: Anatomy of high performance matmul kernels - Aleksa Gordiฤ‡ From GPU architecture and PTX/SASS to warp-tiling and deep asynchronous tensor core pipelines.

This is the best GPU internals write-up I've seen in a long time.
www.aleksagordic.com/blog/matmul

16.10.2025 02:46 โ€” ๐Ÿ‘ 9    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

You're mostly detecting Claude there. It's also easy to turn off and has lots of advantages to removing it, esp. for some languages that get messed up easily by Unicode. YMMV

13.10.2025 04:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - OpenDevicePartnership/patina: Patina Firmware Patina Firmware. Contribute to OpenDevicePartnership/patina development by creating an account on GitHub.

Open source pure Rust UEFI BIOS
Native Rust not just wrappers on old risky C code.
github.com/openDevicePa...

10.10.2025 14:10 โ€” ๐Ÿ‘ 8    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

If you are doing it right, you should have at least three or more.

06.10.2025 20:57 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Mic-E-Mouse Your computer mouse has big ears. Image courtesy of GPT4/Dall-E-3, generated using the keywords "computer mouse with big ears and a microphone as a scroll wheel."

Speech recognition through high frequency mouse sensors. sites.google.com/view/mic-e-m...

06.10.2025 20:54 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Check your answers includes using a different AI model and a problem restatement to see if it comes to a similar conclusion.

06.10.2025 19:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
crates.io: Malicious crates faster_log and async_println | Rust Blog Empowering everyone to build reliable and efficient software.

Malicious Rust crate updates, faster_log and async_println, cryptocurrency key scanners.

blog.rust-lang.org/2025/09/24/c...

24.09.2025 21:19 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
A young, blond white woman sitting in a wheelchair smiles into the camera. Behind her is the capsule of a Blue Origin suborbital spacecraft

A young, blond white woman sitting in a wheelchair smiles into the camera. Behind her is the capsule of a Blue Origin suborbital spacecraft

I want to tell you about a friend of mine real quick. I've mentioned her on here before, but you don't know any details yet, and she's about to make history in a very real sense.

Meet Michi Benthaus:

01.09.2025 19:10 โ€” ๐Ÿ‘ 200    ๐Ÿ” 64    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 3
Preview
Vaccine for Pancreatic Cancer and CRC Sparks Early Hope While phase 1 data suggest the novel vaccine can boost immunity and reduce relapse in pancreatic and colorectal cancer, experts remain cautious at this initial stage.

www.medscape.com/viewarticle/...

02.09.2025 01:36 โ€” ๐Ÿ‘ 529    ๐Ÿ” 119    ๐Ÿ’ฌ 20    ๐Ÿ“Œ 11

Now this is real convenient, especially on machines where it's impossible to hit the right key fast enough to enter the UEFI BIOS settings.

On #OpenBSD/amd64, you can now type "machine fwsetup" at the boot> prompt in efiboot(8).

marc.info?l=openbsd-cv...

27.08.2025 15:08 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3

Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3

25.08.2025 19:23 โ€” ๐Ÿ‘ 11    ๐Ÿ” 7    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

It was even on the internet of that time: alberta!dragos

25.08.2025 20:45 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Yeah ok, this is Linux's birthday in 1991. I was running Unix on my home IBM PC clone 80286 using sources I compiled from SysVr2 code two years before that in 1989.

25.08.2025 20:40 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

rust is a language in which you can borrow a cow

24.08.2025 23:05 โ€” ๐Ÿ‘ 30    ๐Ÿ” 4    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

@dragostech is following 20 prominent accounts