Damus
Dr. Christopher Kunz profile picture
Dr. Christopher Kunz
@Dr. Christopher Kunz

Security (web, infra, app) nerd, has accepted that VR will never be a mass market, writer @heise Security

All toots are IMHO & not my employer's opinion.
PGP fingerprint: C882 8ED1 7DD1 9011 C088  EA50 5CFA 2EEB 397A CAC1

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Dr. Christopher Kunz profile picture
Heute lernte ich (dank @nprofile1q...), dass Stoßlüften offenbar ein neuer Trend in den USA ist. Und dort nennt man es wohl "house burping", also Hausrülpsen.

Was ja wohl aus verschiedenen Gründen indiskutabel ist, hauptsächlich aus physikalischen. Denn Rülpsen beinhaltet ja einen Druckausgleich und ich weiß nicht, wie das in den USA ist, aber hierzulande herrscht innen kein deutlicher Überdruck zu außen. Oder?
Kevin Beaumont · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqdyt7rahrhvmy300sk9jsr46enmzu08w5qkyyl4sp6dm2pc02kccq7jmej2 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq8w7uk4cll226wlw4ukykpu9xlxlvcdwfz7vcdx3k0rg47ynyg7lsnec808 not really.. occasionally it happens with things like LDAP and such in t...
Dr. Christopher Kunz profile picture
So apparently Mindgard reported a trivial RCE in Cursor (if a repo opened by Cursor includes a git.exe file, that file is executed) in December 2025 (!) via HackerOne, and getting Cursor's attention required calling them out on LinkedIn. They ghosted Mindgard, prompting them to disclose. This is a 7-month window for attackers.

Coordinated Disclosure is dead. Let's switch back to FD. Who owns securityfocus.com these days?

https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
Kevin Beaumont · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqdyt7rahrhvmy300sk9jsr46enmzu08w5qkyyl4sp6dm2pc02kccq7jmej2 Burnham's going to be the UK prime minister on Monday, James is probably going to be his chief of staff. His old business clients are trying to lobby him with policy ideas.