Brutkey

Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me

In love with the display in our table at #39c3 (we didn't plan anything lol)

Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me
Sven Slootweg (πŸ”œπŸ”œ WHY2025)
@joepie91@fedi.slightly.tech

FYI, looks like an zero-day exploit just dropped that allows unauthenticated extraction of secrets from the memory of any MongoDB version going back 10 years, over the internet, automated exploit included: https://github.com/joe-desimone/mongobleed

Going to have mixed feelings about this one, but I feel obliged to point out:
MongoDB is
particularly popular in the Silicon Valley tech industry
... including among the military contractors there, on whom it is now basically open season
... (but who are probably going to be
very upset if someone grabs their internal shit, and with considerable drive to get the perpetrator prosecuted, so y'know, personal safety and all that)

Edit: Apparently not a zero-day, seems to have been reported a couple days ago already (but still very likely unpatched in most places for now)

Niko (Martin) :heart_ace:
@martinligabue@tsukihi.me