toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

273
active users

#vulnerabilities

6 posts6 participants1 post today

Sunday, August 3, 2025

Russian troops resort to ‘total infiltration’ tactics in front-line Pokrovsk — Inside the Battle of Kostiantynivka, as Ukrainian forces brace for three-sided Russian assault — Ukrainian drones target Shahed storage site, industrial facilities in Russia — Ukraine’s drone strike reportedly sparks fire at oil depot in Russia’s Sochi … and more

activitypub.writeworks.uk/2025

Replied in thread

@spocko it’s #conspiracytheory. #Reuters reports #Microsoft is looking whether a leak from MAPP enabled #Chinese to exploit #SharePoint #vulnerabilities b4 fixes were fully in place.notifications went out on 6/24, 7/3, and 7/7; attack signs began on 7/7—the same day the final notification was issued. #TrendMicro called it the “likeliest scenario” that someone in the program weaponized that info. They pulled the trigger on the #exploit they had at hand bc time was running out.

Spying on People Through Airportr Luggage Delivery Service

Airportr is a service that allows passengers to have their luggage picked up, checked, and delivered to their destinations. As you might expect, it’s used by wealthy or important people. So if the company’s website is <a href="https:/... schneier.com/blog/archives/202

Schneier on Security · Spying on People Through Airportr Luggage Delivery Service - Schneier on SecurityAirportr is a service that allows passengers to have their luggage picked up, checked, and delivered to their destinations. As you might expect, it’s used by wealthy or important people. So if the company’s website is insecure, you’d be able to spy on lots of wealthy or important people. And maybe even steal their luggage. Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US...

Interesting. If on-board SRAM can be kept alive while rebooting the CPU, you can extract information stored in it.

"This paper presents Volt Boot, an attack that demonstrates a vulnerability of on-chip SRAM due to the physical separation common in modern system-on-chip power distribution networks."

cacm.acm.org/research-highligh

Communications of the ACM · SRAM Has No Chill: Exploiting Power Domain Separation to Steal On-Chip SecretsBy David Roman