Matthias Luft
banner
uchi-mata.bsky.social
Matthias Luft
@uchi-mata.bsky.social
Infosec Enthusiast & Practitioner. Opinions are my own. Pentest→Research→Leading→Security Engineering. Love Martial Arts, Outdoors, Dogs.

infosec.exchange/@uchi_mata

www.rational-security.io
#NoKings in Munich, Germany.
June 14, 2025 at 7:51 PM
Not from the US, but is that this “why did the chicken cross the road” thing?
i’m here you fuckaas bitch
May 29, 2025 at 6:19 AM
Reposted by Matthias Luft
Well well well...
It's all starting to make sense now!
May 28, 2025 at 6:39 PM
#TACO started by @megancnbc.bsky.social - and she has way too few followers for that, let’s change that.
May 29, 2025 at 6:12 AM
Reposted by Matthias Luft
TACO.
May 29, 2025 at 2:20 AM
Reposted by Matthias Luft
If you read the post about O3 finding a SMB bug in the Linux Kernel, I did a few tests and I what I suspected looks true: Gemini 2.5 PRO can more easily identify the vulnerability. My success rate is so high that running the following prompt a few times is enough: gist.github.com/antirez/8b76...
linux_smb_vunlerability_prompt.txt
linux_smb_vunlerability_prompt.txt. GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
May 25, 2025 at 10:06 AM
Reposted by Matthias Luft
It’s funny that you can go through 20 years of schooling without ever seeing the idea that writing is a tool for thinking.
May 20, 2025 at 2:31 PM
Reposted by Matthias Luft
YES!
May 3, 2025 at 2:37 AM
Reposted by Matthias Luft
Most companies are getting AI implementation wrong.

They’re focused on using it to *replace* humans rather than *enhance* humans.

The ones that recognize this now will gain a massive lead in this race.
April 28, 2025 at 2:44 PM
Reposted by Matthias Luft
I wrote up some more information on the differences between adding SYS_ADMIN and CAP_SYS_ADMIN to pods in Kubernetes. It highlights some new things I learned about how the CRI you use can affect how pods are run. raesene.github.io/blog/2025/04...
Cap or no cap
raesene.github.io
April 23, 2025 at 10:43 AM
Reposted by Matthias Luft
Trustworthy and Responsible AI....it's a real thing!

www.youtube.com/watch?v=fhcY...
Staying Ahead of AI Policy and Governance with a Global Framework
YouTube video by World Wide Technology
www.youtube.com
April 10, 2025 at 12:21 PM
I didn't even think about this yet, but linting file- and directory names in project structures makes a lot of sense - and there is of course a tool for it:

ls-lint.org
ls-lint
An extremely fast file and directory name linter - Bring some structure to your project filesystem
ls-lint.org
April 10, 2025 at 7:39 AM
Alright AKS, pick a lane:

Kubenet: Pods receive IP from an overlay network. Retires March 2028

Azure CNI Standard: Pods receive IP from VNET

Azure CNI Overlay: Pods receive IP from an overlay network.
April 2, 2025 at 9:00 AM
Great article on using GitHub as a workflow platform:

github.blog/engineering/...

Can absolutely recommend for security workflows and management as well!
IssueOps: Automate CI/CD (and more!) with GitHub Issues and Actions
A look into building IssueOps workflows on GitHub to do everything from CI/CD to handling approvals and more.
github.blog
April 1, 2025 at 1:00 PM
Reposted by Matthias Luft
March 30, 2025 at 2:25 AM
Great #IngressNightmare CVE-2025-1974 write-up:
securitylabs.datadoghq.com/articles/ing...

Key point missing from many other sources: Exploitation from Internet is non-default and unlikely, but privilege escalation within cluster is by default possible.
The 'IngressNightmare' vulnerabilities in the Kubernetes Ingress NGINX Controller: Overview, detection, and remediation | Datadog Security Labs
Learn how the Kubernetes Ingress NGINX Controller vulnerabilities work, how to detect and remediate them.
securitylabs.datadoghq.com
March 26, 2025 at 11:09 AM
Reposted by Matthias Luft
Last week we launched a free webapp that shows the tens of thousands of UK companies whose ownership is being hidden, in most cases unlawfully.

It's now easier to use, faster, and has way more features. Quick thread.
March 24, 2025 at 9:34 AM
Reposted by Matthias Luft
TIL that because the FFmpeg project has gained so much experience in hand-writing assembly code to provide huge speedups, they now are putting together a series of lessons for learning assembly:

Vibe coding is fun and all, but this is probably a better use of time!

github.com/FFmpeg/asm-l...
GitHub - FFmpeg/asm-lessons: FFMPEG Assembly Language Lessons
FFMPEG Assembly Language Lessons. Contribute to FFmpeg/asm-lessons development by creating an account on GitHub.
github.com
March 24, 2025 at 6:24 AM
Wow, GitHub not supporting IPv6 for Webhooks:

docs.github.com/en/webhooks/...
About webhooks - GitHub Docs
Webhooks provide a way for notifications to be delivered to an external web server whenever certain events occur on GitHub.
docs.github.com
March 18, 2025 at 7:02 AM
Reposted by Matthias Luft
In an effort to bring here what little of value is still on the birdsite, allow me to present some absolutely bonkers corporate espionage, in which Deel's execs had a spy at rival Rippling. The complaint is a gripping must-read! rippling2.imgix.net/Complaint.pdf
rippling2.imgix.net
March 17, 2025 at 7:19 PM
I updated my #Kubernetes resource exhaustion testing tool to include inode exhaustion:
github.com/uchi-mata/do...
GitHub - uchi-mata/dostainer
Contribute to uchi-mata/dostainer development by creating an account on GitHub.
github.com
March 11, 2025 at 7:52 AM
Reposted by Matthias Luft
February 26, 2025 at 2:19 AM