Matthias Luft
@uchi-mata.bsky.social
Infosec Enthusiast & Practitioner. Opinions are my own. Pentest→Research→Leading→Security Engineering. Love Martial Arts, Outdoors, Dogs. infosec.exchange/@uchi_mata www.rational-security.io
Not from the US, but is that this “why did the chicken cross the road” thing?
i’m here you fuckaas bitch
Well well well... It's all starting to make sense now!
#TACO started by @megancnbc.bsky.social - and she has way too few followers for that, let’s change that.
If you read the post about O3 finding a SMB bug in the Linux Kernel, I did a few tests and I what I suspected looks true: Gemini 2.5 PRO can more easily identify the vulnerability. My success rate is so high that running the following prompt a few times is enough: gist.github.com/antirez/8b76...
linux_smb_vunlerability_prompt.txt
linux_smb_vunlerability_prompt.txt. GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
It’s funny that you can go through 20 years of schooling without ever seeing the idea that writing is a tool for thinking.
Most companies are getting AI implementation wrong. They’re focused on using it to *replace* humans rather than *enhance* humans. The ones that recognize this now will gain a massive lead in this race.
I wrote up some more information on the differences between adding SYS_ADMIN and CAP_SYS_ADMIN to pods in Kubernetes. It highlights some new things I learned about how the CRI you use can affect how pods are run. raesene.github.io/blog/2025/04...
Cap or no cap
raesene.github.io
Trustworthy and Responsible AI....it's a real thing! www.youtube.com/watch?v=fhcY...
Staying Ahead of AI Policy and Governance with a Global Framework
YouTube video by World Wide Technology
youtube.com
I didn't even think about this yet, but linting file- and directory names in project structures makes a lot of sense - and there is of course a tool for it: ls-lint.org
ls-lint
An extremely fast file and directory name linter - Bring some structure to your project filesystem
ls-lint.org
Alright AKS, pick a lane: Kubenet: Pods receive IP from an overlay network. Retires March 2028 Azure CNI Standard: Pods receive IP from VNET Azure CNI Overlay: Pods receive IP from an overlay network.
Great article on using GitHub as a workflow platform: github.blog/engineering/... Can absolutely recommend for security workflows and management as well!
IssueOps: Automate CI/CD (and more!) with GitHub Issues and Actions
A look into building IssueOps workflows on GitHub to do everything from CI/CD to handling approvals and more.
github.blog
Quite some #IngressNightmare #CVE-2025-1974 PoCs on GitHub now that look good at a cursory review: github.com/hakaioffsec/... github.com/yoshino-s/CV... github.com/Esonhugh/ing... github.com/hi-unc1e/CVE... github.com/lufeirider/I... github.com/zwxxb/CVE-20... github.com/rjhaikal/POC...
GitHub - hakaioffsec/IngressNightmare-PoC: This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974). - hakaioffsec/IngressNightmare-PoC
github.com
I wrote up some details on exploiting #IngressNightmare #CVE-2025-1974: www.averlon.ai/blog/kuberne... Where are we at with releasing a full PoC?
IngressNightmare: Kubernetes Ingress-NGINX Vulnerabilities Explained | Averlon
Discover how IngressNightmare — including CVE-2025-1974 — exploits internal exposure in Kubernetes. See what’s at risk and how to secure your ingress path.
averlon.ai
Great #IngressNightmare CVE-2025-1974 write-up: securitylabs.datadoghq.com/articles/ing... Key point missing from many other sources: Exploitation from Internet is non-default and unlikely, but privilege escalation within cluster is by default possible.
The 'IngressNightmare' vulnerabilities in the Kubernetes Ingress NGINX Controller: Overview, detection, and remediation | Datadog Security Labs
Learn how the Kubernetes Ingress NGINX Controller vulnerabilities work, how to detect and remediate them.
securitylabs.datadoghq.com
Last week we launched a free webapp that shows the tens of thousands of UK companies whose ownership is being hidden, in most cases unlawfully. It's now easier to use, faster, and has way more features. Quick thread.
TIL that because the FFmpeg project has gained so much experience in hand-writing assembly code to provide huge speedups, they now are putting together a series of lessons for learning assembly: Vibe coding is fun and all, but this is probably a better use of time! github.com/FFmpeg/asm-l...
GitHub - FFmpeg/asm-lessons: FFMPEG Assembly Language Lessons
FFMPEG Assembly Language Lessons. Contribute to FFmpeg/asm-lessons development by creating an account on GitHub.
github.com
In an effort to bring here what little of value is still on the birdsite, allow me to present some absolutely bonkers corporate espionage, in which Deel's execs had a spy at rival Rippling. The complaint is a gripping must-read! rippling2.imgix.net/Complaint.pdf
rippling2.imgix.net
I updated my #Kubernetes resource exhaustion testing tool to include inode exhaustion: github.com/uchi-mata/do...
GitHub - uchi-mata/dostainer
Contribute to uchi-mata/dostainer development by creating an account on GitHub.
github.com
I'm retired. I got a phone call at home a few weeks ago from someone reimplementing code I wrote over 20 years ago. There was a comment "now for the tricky bit" followed by about 250 lines of confusing perl. No feature description. No reason. Just my name and a smiley at the end. Sorry.
I just finished our #shmoocon talk on container security. Here's my seccomp bpf disassembler and diffing tool. github.com/antitree/sec...
GitHub - antitree/seccomp-diff
Contribute to antitree/seccomp-diff development by creating an account on GitHub.
github.com
I just discovered @signal.org is available on Linux Desktop. 📢 EVERYBODY! LISTEN UP!! Use Signal. </end>
Download Signal for Linux
To use the Signal desktop app, Signal must first be installed on your phone.
signal.org