NeuroWinter

@neurowinter.com

Reformed #AI & #MLOps tinkerer turned #SRE, now keeping #opensource databases alive. Long-time #AppSec enthusiast, accidental sysadmin, and fueled almost entirely by espresso. Blogging sporadically at NeuroWinter.com

JailCTF 2026 Format Write Up A pyjail with no output channel at all. You can only count prompts. `{0[N].__len__}` turns each character into an address, and ASLR moves whole pages, so the last 3 hex digits never move. #ctf #infosec #netsec #jailctf2026 blog.roblab.us/jailctf-2026...

jailCTF 2026: format Write Up

The jail prints nothing and swallows every exception, so all you can measure is how many prompts come back. CPython's one-character string cache is what makes that enough.

blog.roblab.us

Well rip. I’ve nearly gotten my #Nitropad set up just the way I like it with salt managing my appvms and templates and now I have a really bad rattling fan that stops often. Tried playing air into it, no luck. I got the tamper evident screws so I can’t even get into it to diagnose:(

I was always sent to primary school with a handkerchief in my pocket. But I don’t think I’ve touched one in years. Does anyone still use them ?!

A suspected crypto scammer has been arrested for stealing $220,000 by hiding malware inside Steam games FBI tracked him through his Uber Eats deliveries

BildBild

Recently read this interesting article. words.filippo.io/vuln-reports/ While we 100% have an issue with an influx of horrible reports, I still belive that each and every even mildly applicable report should be given special attention. It’s the ones that don’t that will split through the cracks.

Vulnerability Reports Are Not Special Anymore

We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?

words.filippo.io

Lesson learnt from this trip to AU. Early morning flights suck. Security doesn’t even open at Auckland airport until 4:30 am. Late night flights suck. Landing near midnight means your next day is ruined