Hejto.pl
Dodaj post

Wpisz coś do wyszukania (minimum 2 znaki)

#informatyka

Osobistość

w IT

13piorunów

Zastanawiam się czy iść na magisterkę z IT. Mam inżyniera, dobrze zarabiam. Niby matka naciska żeby iść ale się zastanawiam na co mi to, czy to mi się do czegoś przyda jak już teraz mi dobrze

Cr

  • iść23% (36 głosów)
  • nie iść78% (124 głosy)

160 głosów

Fenomen1piorunów

@hapaczuri jeśli gdziekolwiek przyda Ci się mgr to idź. Jeśli nie, nie ma sensu. A jeśli potencjalnie czujesz że może Ci się przydać to lepiej wcześniej niż później, po latach człowiek jest odporny na system edukacji. Ale dla satysfakcji rodziców, średni pomysł. Mam jednego kumpla który ma mgr a jest informatykiem, dwóch skończyło na lic/inż i pracują w branży od lat

Inspirator0piorunów

@hapaczuri Ja powiem tak, mając tą magisterkę: Do tej pory nie było to absolutnie do niczego potrzebne, ale mamy rynek pracy jaki mamy, AI w rozwoju - nie wiadomo jak sytuacja będzie wyglądać za 2-3 lata. Może być tak że koszty AI wzrosną lawinowo i powróci eldorado, a może być tak że 50% z IT zostanie zwolnionych a ich obowiązki przejmą Ci co zostali, z większym doświadczeniem, lepszym wyszktałceniem i rojem agentów do dyspozycji. Czyli c⁎⁎j wie, dowiemy się po fakcie. Improvise, adapt, overcome.

Pokaż więcej komentarzy (21)

Fenomen

w Hydepark

1piorunów

Co ma wspólnego Twoja fotowoltaika z Hiszpanią

Certyfikowane firmy ruskich agentur w Szwajcarii

Na jakiej infrastrukturze został faktycznie postawiony KSEF

Polskie Wojska Obrony Cyberprzestrzeni jako istotny rodzaj sił zbrojnych

Dlaczego tak naprawdę chińskie samochody mają zakaz wjazdu na obiekty wojskowe w PL

Odpowiada Wiesław Paluszyński - konsultant ds. cyberbezpieczeństwa, prezes Polskiego Towarzystwa Informatycznego, wiceprezes PIIT oraz przewodniczący Sektorowej Rady ds. Kompetencji IT, Telekomunikacja i Cyberbezpieczeństwo

https://www.youtube.com/watch?v=OeVHYF4olQM

Pokaż więcej komentarzy (2)

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.10.03.md

Paint It Blue: Reversing Win32k's Callbacks - https://idov31.github.io/posts/paint-it-blue-reverse-win32k

Static Devirtualization of Tencent VM - https://aftermathlabs.net/blog/31/07/2026/

Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE - https://starlabs.sg/blog/2026/09-dirty-cert-cisco-smart-software-managers-silently-patched-rce/

Two DGX Sparks, 33 Local Models, One Question: Can Local AI Actually Red Team? - https://betheadversary.com/posts/dgx_spark_red_team_bench/

Is sandboxing sufficient to contain rogue agents? - https://blog.cryptographyengineering.com/2026/09/30/is-sandboxing-sufficient-to-contain-rogue-agents/

Gruba ryba0piorunów

@konik_polanowy skrót newsów niczym unknow news 😛

Który z was pierwszy wrzuci w końcu informację jak oszczędzać tokeny na antygravity? :d

Pokaż więcej komentarzy (2)

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.10.01.md

Exploiting Azure IMDS - https://cyberdom.blog/exploiting-azure-imds/

Windows Internals: Secure Calls - The Bridge Between The NT Kernel and Secure Kernel - https://connormcgarr.github.io/secure-calls-and-skbridge/

GDID: The Windows Global Device Identifier - https://zerotracelab.com/blog/gdid-windows-tracking

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) - https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/

WINDOWS PRIVILEGE ESCALATION USING NCSI ACTIVE PROBES - https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/

Fenomen

w Hydepark

7piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.29.md

Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) - https://securitylabs.datadoghq.com/articles/opencode-upgrade-remote-code-execution/

How I Could've Accessed 17 Trillion Microsoft Records - https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

A prompt that finds deep logic bugs, and the pipeline we built around it - https://workos.com/blog/vulnerability-analysis-pipeline

Even more privileged ADCS ESC_CES - https://adhdmurky.github.io/posts/post4/

I spent 3 years of my life building this tool- DIYFPV DRONE BUILDER - https://www.youtube.com/watch?v=uzM72CcgL0c

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.27.md

One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts - https://blog.doyensec.com/2026/09/24/chrome-ios-policy-bypass.html

Containers Are No Longer a Security Boundary - https://depthfirst.com/research/containers-are-no-longer-safe

ceasta a disassembler, decompiler and debugger in one — for windows and linux - https://github.com/ngwg/ceasta

How One Twitch Chat Message Became Code Execution on a Streamer’s PC - https://blog.scrt.ch/2026/09/22/how-one-twitch-chat-message-became-code-execution-on-a-streamers-pc/

Llama.cpp, an Ice Cold CORS Light, and Command Execution - Put it on my Tab! - https://g3tsyst3m.com/cors/Llama.cpp,-an-Ice-Cold-CORS-Light,-and-Command-Execution-Put-it-on-my-Tab!/

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.25.md

Testing race conditions with memory access tracing and stack-based delay injection - https://projectzero.google/2026/09/maccconc-race-condition.html

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug - https://donjon.ledger.com/blog/rp2350-secure-debug-laser-fault-injection/

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF - https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

CVE-2026-7162 Root Cause Analysis - https://blog.uhg.sg/cve/cve-2026-7162

LogonTracer v2 is a tool to investigate malicious logon by visualizing and analyzing Windows Active Directory event - https://github.com/JPCERTCC/LogonTracer

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.23.md

Evading Machine Learning Based Detections - https://msecops.de/blog/posts/ml-evasion/

Stop Using OpenCode - https://wren.wtf/shower-thoughts/stop-using-opencode/

AI studio Auth bypass - https://ndevtk.github.io/writeups/2026/07/28/ais-bypass/

Fileless ELF Execution via O_TMPFILE - https://matheuzsecurity.github.io/hacking/fileless-loader-bypassing-elastic-memfd/

Introducing Pretender - Your New Sidekick for Relaying Attacks - https://blog.redteam-pentesting.de/2022/introducing-pretender/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.21.md

A Brilliantly Simple Bug In V8 - https://qedaudit.io/blog/brilliantly-simple/

The QNAP Pattern - https://runiclabs.io/research/qnap-architecture/

How to Run a Windows Service Inside Svchost.exe - https://trainsec.net/library/malware-analysis/how-to-run-a-windows-service-inside-svchostexe-service-dll-walkthrough/

SQL Injection - Bypassing Baffin Bay WAF to Exploit PostgreSQL ORDER BY Injection - https://p3n7a90n.github.io/blogs/sql-injection-waf-bypass-postgresql-order-by/

Writing Beacon Object Files In Mythic Using Dark Agent For MacOS - https://umsundu.co.uk/posts/Writing-Beacon-Object-Files-In-Mythic-Using-Dark-Agent-For-Mac/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.19.md

When AI Makes 0-Days Feel Like N-Days - https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/

LazyDLLSideload - https://crates.io/crates/LazyDLLSideload

Inverse-square law - https://blog.coredump.cx/p/inverse-square-law

Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities - https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities

Behind the GitLab RCE: A depthfirst Journey into the Ruby Ecosystem - https://depthfirst.com/research/behind-the-gitlab-rce-a-depthfirst-journey-into-the-ruby-ecosystem

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.17.md

Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - https://cravaterouge.com/articles/resetnightmare/

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 - https://www.slcyber.io/research/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6

Microcode in Intel's 8087 floating-point chip: the scale instruction - https://www.righto.com/2026/09/8087-microcode-reverse-engineering-fscale.html

$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain - https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/

Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4⤍ESC1 Chain - https://secretmyth.blog/adcs/demystifying-mspki-certificate-name-flag/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.15.md

Chinese Implants in the Supply Chain - https://www.vulncheck.com/blog/zbt-darklantern-speakingstone

Process Parameter Poisoning - https://sensepost.com/blog/2026/process-parameter-poisoning/

AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/

Bluetooth Low Energy Security Testing, Consolidated: Introducing Caeruleus - https://www.praetorian.com/blog/ble-testing-caeruleus/

Fileless ELF Execution via Kernel Keyring - https://matheuzsecurity.github.io/hacking/linux-kernel-keyring-fileless-exec/

Osobistość

w Hydepark

33piorunów

Z wątku na reddicie pt. "Czy młodzież zrobiła się atechniczna czy mi się wydaje?"

Źródło.

Gruba ryba10piorunów

@Klockobar nie dziwi mnie. młodzi ludzie coraz częściej nie mają komputerów, bo telefon wystarcza im do wszystkiego. a jeśli człowiek nigdy nie korzystał z excela to nie dziwi mnie, że zna nawet podstawowych funkcjonalności.

Fenomen3piorunów

To mi przypomniało historię na Erasmusie lata temu. Na wykładzie laska zwróciła się oburzona do wykładowcy, że wysłał pdf źle obrócony. I ona przy wszystkich kładzie lapka na boku, że teraz musi tego pdf tak czytać na lapku 😂 więc zawsze się ktoś znajdzie.

Pokaż więcej komentarzy (11)

Zawodowiec

w Programowanie

5piorunów

Entity i Value Object w Domain-Driven Design - devszczepaniak.pl

Entity i Value Object to jedne z podstawowych building blocks taktycznego Domain-Driven Design. W artykule pokazuję, czym się różnią, jak wykorzystać je do pilnowania inwariantów oraz w jaki sposób można je wykorzystać, by ograniczyć problem Primitive Obsession.\ #programowanie

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.13.md

Beyond Lazarus: Organization of DPRK cyber capabilities - https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities

Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

Testing race conditions with memory access tracing and stack-based delay injection - https://projectzero.google/2026/09/maccconc-race-condition.html

From P-Code to GNN: extract binary code semantics - https://blog.quarkslab.com/from-p-code-to-gnn-extract-binary-code-semantics.html

NetNTLMv1 Is Dead. Long Live NetNTLMv1 - https://www.outflank.nl/blog/2026/09/08/netntlmv1-is-dead-long-live-netntlmv1/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.11.md

Anatomy of SystemOptimizer - A BYOVD EDR Killer with a UAC Bypass - https://cham1ndux.github.io/posts/BYOVD-EDR-killer-with-a-UAC-bypass-and-a-lying-comment-block/

Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint - https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-AppPool-to-NT-AuthoritySYSTEM-via-AD-CS-RPC-endpoint.html

Dissecting a PHP web server rootkit - https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit

Trust no one: are one-way trusts really one way? - https://offsec.almond.consulting/trust-no-one_are-one-way-trusts-really-one-way.html

AdaptixC2: Fingerprinting an Open-Source C2 Framework at Scale - https://censys.com/blog/adaptixc2-open-source-c2-framework

Lider

w Technologia

33piorunów

Pokaż więcej komentarzy (8)

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.09.md

Can local open-weight LLMs detect vulnerabilities, or do they mostly just guess? - https://martinativadar.github.io/posts/llm-vulnerability-research.html

Why you Shouldn’t bypass MFA for your office IP adresses - https://ourcloudnetwork.com/why-you-shouldnt-bypass-mfa-for-your-office-ip-adresses/

DragonForce Ransomware Analysis: Inside a Verified Windows Locker - https://darkatlas.io/blog/dragonforce-ransomware-analysis-windows-locker

Token Theft in Microsoft Entra ID (Part 1 of 4): Threat Landscape and Attack Techniques - https://insinuator.net/2026/08/token-theft-in-microsoft-entra-id-part-1-of-4-threat-landscape-and-attack-techniques/

Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials - https://www.guidepointsecurity.com/blog/attacking-and-defending-scom/

Fenomen

w Hydepark

7piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2026.09.07.md

Awesome Large Language Models for Vulnerability Detection - https://github.com/huhusmang/Awesome-LLMs-for-Vulnerability-Detection

Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools - https://blog.nullze.net/posts/peeling-the-sentinel/

UAC Bypass - CMSTPLUA COM Exploitation - https://0xsec.gitbook.io/0xsec/windows/uac-bypass-cmstplua-com-exploitation

Something is jamming GPS over Europe. Here's what we found - https://www.youtube.com/watch?v=tz23G_UXCGA

Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL - https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql