Reverse Engineering AirPods Self-Calibration Test
https://ateliti99.substack.com/p/reverse-engineering-airpods-self?utm_source=app-post-stats-page&r=wsh8o&utm_medium=ios
@secharvester
https://ateliti99.substack.com/p/reverse-engineering-airpods-self?utm_source=app-post-stats-page&r=wsh8o&utm_medium=ios
@secharvester
Substack
Reverse Engineering AirPods Self-Calibration
After you close the case, AirPods Pro can play a quiet burst of tones.
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483)
https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
@secharvester
https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
@secharvester
LAVA
CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA
CVE-2026-47483 lets attackers crash NVIDIA DCGM Exporter via pprof. See what 2,000+ exposed GPU servers leaked and how to fix it.
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483)
https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
@secharvester
https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
@secharvester
LAVA
CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA
CVE-2026-47483 lets attackers crash NVIDIA DCGM Exporter via pprof. See what 2,000+ exposed GPU servers leaked and how to fix it.
How OSINT Helped Identify an Anonymous Online Harasser
https://kylesinvestigation.com/2026/10/08/how-osint-helped-identify-an-anonymous-online-harasser/
@secharvester
https://kylesinvestigation.com/2026/10/08/how-osint-helped-identify-an-anonymous-online-harasser/
@secharvester
KYLES INVESTIGATION
How OSINT Helped Identify an Anonymous Online Harasser - Nationwide Private Investigator & Skip Tracing | Knoxville TN Background…
This article is a composite scenario based on common patterns in harassment investigations. Names and details are fictionalized. When Sarah, the owner of a boutique marketing agency, started getting direct messages from a throwaway account called @ghost_watch_99…
Post-quantum authentication: Why organizations should start testing certificate ecosystems now | Microsoft Security Blog
https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/
@secharvester
https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/
@secharvester
Microsoft News
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness.
Getting old Macromedia Director Games to run on modern Hardware
https://werwolv.net/posts/macromedia_copy_protection/
@secharvester
https://werwolv.net/posts/macromedia_copy_protection/
@secharvester
WerWolv
Bypassing the Copy Protection of Old Macromedia Games | WerWolv
How I got many of my childhood games running on modern hardware again
FortiBleed Crisis: Why 86,644 Fortinet Firewalls Are Still Compromised — And Why a Password Reset Will Not Save You
https://www.zerohack.org/blog/fortibleed-crisis-86644-firewalls-compromised-password-reset-wont-save-you
@secharvester
https://www.zerohack.org/blog/fortibleed-crisis-86644-firewalls-compromised-password-reset-wont-save-you
@secharvester
🥴1
South Korea and Japan are buffeted by hacks as AI lowers bar for cybercriminals
https://www.nbcnews.com/world/asia/south-korea-japan-are-buffeted-hacks-ai-lowers-bar-cybercriminals-rcna602464
@secharvester
https://www.nbcnews.com/world/asia/south-korea-japan-are-buffeted-hacks-ai-lowers-bar-cybercriminals-rcna602464
@secharvester
NBC News
South Korea and Japan are buffeted by hacks as AI lowers bar for cybercriminals
Nine South Korean banks and two mega-churches are investigating cyberattacks that may have involved AI tools, while Japanese companies have been hit by a surge in cyber incidents.
FBI arrests key suspect in major hack of agents’ data
https://www.cnn.com/2026/10/09/politics/fbi-arrest-shinyhunters-hack?utm_medium=social&utm_campaign=missions&utm_source=reddit
@secharvester
https://www.cnn.com/2026/10/09/politics/fbi-arrest-shinyhunters-hack?utm_medium=social&utm_campaign=missions&utm_source=reddit
@secharvester
CNN
FBI arrests key suspect in major hack of agents’ data
The FBI arrested a man in Pennsylvania who officials believe helped orchestrate a recent damaging hack that exposed sensitive data of current and former FBI personnel, according to two sources familiar with the matter.
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
https://www.slcyber.io/research/a-jpeg-a-race-and-a-ghost-breaking-discourses-image-pipeline
@secharvester
https://www.slcyber.io/research/a-jpeg-a-race-and-a-ghost-breaking-discourses-image-pipeline
@secharvester
www.slcyber.io
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
We discovered an arbitrary file read vulnerability in Discourse's image pipeline by chaining a JPEG race condition with ImageMagick and Ghostscript.
Apple Watch connector for Android, Linux, Windows... It seems to be a world first
https://github.com/LordixDemon/apple_watch_connector
@secharvester
https://github.com/LordixDemon/apple_watch_connector
@secharvester
GitHub
GitHub - LordixDemon/apple_watch_connector
Contribute to LordixDemon/apple_watch_connector development by creating an account on GitHub.
Russian hackers publish stolen Shell, Philips data on dark web
https://nltimes.nl/2026/10/08/russian-hackers-publish-stolen-shell-philips-data-dark-web
@secharvester
https://nltimes.nl/2026/10/08/russian-hackers-publish-stolen-shell-philips-data-dark-web
@secharvester
NL Times
Russian hackers publish stolen Shell, Philips data on dark web
Russian ransomware gang Clop has published stolen data from Philips and Shell on the dark web, according to an investigation by the BNR news radio show. Clop alleges having obtained 89 gigabytes of data, including construction drawings, photos of facilities…
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
@secharvester
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
@secharvester
watchTowr Labs
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE…
Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into…
Four More States Accuse TP-Link of Concealing Ties to China
https://news.bloomberglaw.com/litigation/four-more-states-accuse-tp-link-of-hiding-china-ties-hack-risks
@secharvester
https://news.bloomberglaw.com/litigation/four-more-states-accuse-tp-link-of-hiding-china-ties-hack-risks
@secharvester
Bloomberglaw
Four More States Accuse TP-Link of Concealing Ties to China (1)
Four states allege in separate lawsuits that router company TP-Link Systems Inc. deceived consumers about its ties to China, and the company’s devices’ vulnerability to cyber attacks.
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
@secharvester
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
@secharvester
watchTowr Labs
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE…
Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into…
GitHub - gilnett/wstrace: Standalone zero-driver Windows system and API monitor in Rust
https://github.com/gilnett/wstrace
@secharvester
https://github.com/gilnett/wstrace
@secharvester
GitHub
GitHub - gilnett/wstrace: Standalone zero-driver Windows system and API monitor in Rust
Standalone zero-driver Windows system and API monitor in Rust - gilnett/wstrace
Open source firmware for a cheap USB C meter (KWS-X1) that shows way more PD info than stock
https://github.com/kralonur/kws-x1-standalone-rs
@secharvester
https://github.com/kralonur/kws-x1-standalone-rs
@secharvester
GitHub
GitHub - kralonur/kws-x1-standalone-rs: Open source Rust firmware for the KOWSI KWS-X1 USB C meter. It shows live power, lists…
Open source Rust firmware for the KOWSI KWS-X1 USB C meter. It shows live power, lists everything your charger offers over USB PD, lets you ask for fixed or PPS voltages and can test a cable at 5 A...
`AetherVM` is an LLVM-native binary analysis and emulation platform built around instruction lifting to `LLVM IR`. It unifies static, dynamic, and symbolic analysis through a common intermediate representation, enabling advanced instrumentation, runtime recovery, deobfuscation, etc....
https://github.com/AetherVM/AetherVM
@secharvester
https://github.com/AetherVM/AetherVM
@secharvester
GitHub
GitHub - AetherVM/AetherVM: AetherVM - Lift. Instrument. Emulate. Recover.
AetherVM - Lift. Instrument. Emulate. Recover. Contribute to AetherVM/AetherVM development by creating an account on GitHub.