Good morning folk and friends from far and near!
Today I wish you safety and comfort ✨
Good morning folk and friends from far and near!
Today I wish you safety and comfort ✨
Salesforce rolled out an extensive security overhaul of its Marketing Cloud platform to address a suite of vulnerabilities that could have allowed attackers to leak contacts and sent emails from any of the company's tenants
https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/
Let's talk about Windows .URL (InternetShortcut) files.
Last year there was discussion about a vulnerability in how Windows handles .URL files. Specifically, when a .URL file specifies a WorkingDirectory directive, an otherwise harmless app being launched would load DLLs from the remote (e.g. WebDAV) server specified. You know, being the current working directory of the app being launched and all. This vulnerability was being exploited in the wild, and it worked well because it bypassed annoying (to attackers) things like SmartScreen. Sure, it required the victim to click Open on a dialog saying Type: Unknown File Type (😂), but we all know that users are click-happy, so this is fine. Besides, the file clearly has a .pdf extension, so it should be safe (😂).
Microsoft recognized the vulnerability and published an update in the form of CVE-2025-33053.
If we were to believe the Microsoft documentation at the time,
When the user clicks the icon, the browser is launched and displays the site associated with the shortcut.
But wait...
How did this .URL file cause a program to be launched? The URL= parameter specifies a website address to be loaded in the browser.
Oh, naive child. Obviously a .URL file can directly point to code on a remote (e.g. WebDAV) server. This technique is also being exploited ITW as well.
I reported this to Microsoft, as this has the EXACT SAME IMPACT as CVE-2025-33053. So if that's a vulnerability, then this too is a vulnerability, right?
Bless your innocent soul. Per MSRC:
When the Shell invokes an app from a remote share, it's expected that you will see the legacy Windows Security prompt, not the SmartScreen one. SmartScreen Application Reputation (AppRep) evaluation applies to locally downloaded files that bear an Internet Zone mark of the web. It is not meant to apply to execution of files from Network Shares.
Okie dokie. I'm sure Windows users surely appreciate this. But what about the incorrect documentation? After my prodding, they updated the wording:
When the user clicks the icon, the URL path is opened by the handler application, typically the user's default web browser.
Leaving in the quite misleading first sentence:
The Internet shortcut object is used to create desktop shortcuts to Internet sites.
(An "Internet site" is a web page, right?)
How can CVE-2025-33053 warrant a CVE, while the behavior I described has the exact same trigger and impact is not CVE worthy? That's pretty easy. Microsoft assigns CVEs to updates, not vulnerabilities. They are the decider as to what is a vulnerability and what is not.
What can we do about it?
At the very least, turn off the Windows feature that hides file extensions, even if you have the option turned on to see file extensions. The disdain that Microsoft has for Windows users is tangible here. On what planet would I not want to see the actual extension of a file? Go to HKCU\InternetShortcut and delete the NeverShowExt value. After this, your pwned.pdf file will reveal its true self as being pwned.pdf.url.
More powerful protection would be to block the ability to receive .URL files via email, web browsers, etc. There is no workflow that I can imagine that requires a user to double-click on a .URL file that came from the internet.
This screen recording is a Windows 11 system that has no internet connectivity. The fact that no warning was displayed that SmartScreen cannot be reached is evidence that SmartScreen is not in play at all. And that dialog...Do you want to open this file?
andType: Unknown File Type
Do you think that users are presented with enough information to make an informed security decision? Of course not. But obviously we all know that we can't rely on users making informed security decisions in general. Don't put users in that position.
@wdormann We moved the handler of .js files from Windows Script Host to Notepad to neuter JS-based malware. Would a similar mitigation make sense here? I'm not aware of any real-world usage of .url files.
# Akkoma # Statistics 2026-05-07 17:00 CEST
Number of active instances: 676
Number of users: 20 329
Number of statuses: 9 111 876
Number of users last 4h: 5
Number of statuses last 4h: 1346

# Fediverse
Starting soon: Free Podcast Masterclass (virtual) (free) https://podnews.net/event/free-podcast-masterclass- #podevents
"I was doxxed by extremists, my home was doxxed, my children’s social media accounts were doxxed and exposed online, there were unmarked cars following them, and I’m not even here—I’m in Chicago, breaking quorum." https://www.texasobserver.org/the-interview-salman-bhojani/
@nuhn ty!
Alors moi je savais que l'IA c'était nul, mais saviez-vous que ça donnait le cancer ?!!
Reminder the Independent Green Voice in Scotland are fascist and not the official Scottish Green Party.
Screengrab from southern Scotland.
we joke that when the AI bubble pops and the managers can't afford the chatbot any more, the surviving companies will hire the people who know how shit works to clean up
but this is of course optimistic. observed behaviour is that they will instead do the stupidest and shortest-term thing they can do instead of ever doing it properly.
so what do you envision this might be?
for clarity, i think when the AI bubble pops, which I place as some time next year at the latest - and you can hear the screeching noises in 2026 - the current recession signs will turn into a full Great Depression 2, so those surviving companies will also be doing not so great
Good luck, Scotland! Get out there and vote like it matters.
A lot of these accounts have what appear to be randomly generated or LLM-assisted bios, and my current favourite is
"Farmer with a taste for cronut culture in Milwaukee"
@iftas Well that sounds grade-A 'merican to me. Yeee-Haw.
RE: https://mstdn.games/@noodlemaz/116533324278458171
While I really dislike tobacco, I can't help thinking that the people backing this move are deluded—did the (failed) US experiment with Prohibition of alcohol pass them by completely, or the equally failed war on drugs?
What this will produce is not a tobacco-free generation, but a new organized crime ecosystem (and probably new, more potent ways of ingesting nicotine).
@cstross in Australia they’re they’re trying to price it out. A packet now costs $50+
The only problem is that you can grow it here so import control doesn’t really work.
You can buy loose tobacco from any corner shop at 10% of official prices. Profits going mostly to bikie gangs who are handling the distribution effeciently.
Government is paralysed and has no idea how to handle it.
They never fucking learn 🙄
Krita’s Maintainer is awesome!
@NanoRaptor "I don't have a deadname, but I do have a 1900s name."
This is a good analogy
HOWEVER
Time to nitpick your Star Trek facts!!!
Kirk didn't have Scotty beam the tribbles to the ship, Scotty did that on his own, then nobody wanted to tell Kirk how they solved the problem
This feels like a lot of modern supply chain activities :)
@joshbressers I will amend the post, thanks for your nerdy input
GENTLENESS (1997)
Acrylic on Canvas - 11” x 13”
Not a classical Virtue, but based on observing my young son with our aging family cat. It's how I hope we'll care for all the earth's creatures.
Donald has been threatening to kill people for a very, very long time. And he HAS been killing people since his first day in office in his first term.
Also, fuck MTG. She’s a fascist boot licker who is also responsible for the deaths of many people. I don’t wish ill on her child. But she can eat shit. She deserves no kindness from us.
Her stupidity and hatred endangered so many marginalised ppl. And she's still a sleazebag.
The point here is to show how divided the far right are and to also shine the light on the level of murderous thuggery in the presidency towards Trump's supporters and former supporters. Hopefully all this will increase pressure to get rid of him (25th amendment or whtvr) and increase disgust for MAGA and mount pressure to dethrown them. So if every1 does their bit...
Starting soon: Free Podcast Masterclass (virtual) (free) https://podnews.net/event/free-podcast-masterclass- #podevents
Sorry, the app encountered an unexpected error