frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: GhostSys: CET-Compliant Windows Syscalls

https://github.com/tlsbollei/GhostSys
2•bolik•2h ago
Windows 11 enforces Control-flow Enforcement Technology (CET), which breaks many classical syscall stubs and ROP chains used in red teaming. I spent the last few months investigating whether attackers can still invoke syscalls in a CET-compliant way without tripping EDRs , and how defenders can close those gaps.

Within GhostSys, I formalized a post-CET syscall threat model, Five CET-compliant syscall invocation techniques (Ghost Syscalls, RBP Pivot, Speculative Probe, KCT Smuggle, eBPF JIT) with 12,000-call evaluation, 0 CET violations, no detections across three EDRs

You will also find defender-focused recommendations. Check it out!

Note > Some techniques within GhostSys are known - its supposed to be a systematic, reproducible study of CET-compliant syscall invocation and detection coverage, not cutting edge (eBPF jit had a similiar talk, SickCodes DEF CON talk), Specter vuln has been seen in the Pafish++, but not turned towards syscall hook detection. Gadget scanning is essentially a much more rigorous SysWhispers + Halos Gate.

GitHub/spec-kit – Toolkit to help you get started with Spec-Driven Development

https://github.com/github/spec-kit
1•chrismustcode•2m ago•0 comments

Emacs China

https://emacs-china.org/
1•Igrom•2m ago•1 comments

A Lawless Nation – Friends don't let friends visit America

https://paulkrugman.substack.com/p/a-lawless-nation
1•xqcgrek2•4m ago•0 comments

Compiled AI #002

https://cmpld.ai/issues/002/
2•mantcz•7m ago•1 comments

Feedmaker: URL + CSS selectors = RSS feed

https://feedmaker.fly.dev
1•mustaphah•7m ago•0 comments

Ask HN: Why not have shoes that are just as loud as sports cars?

1•amichail•10m ago•1 comments

Redford and Newman: A Screen Partnership That Defined an Era

https://www.nytimes.com/2025/09/16/movies/robert-redford-paul-newman.html
1•prismatic•11m ago•0 comments

.YE ccTLD – Formal Redelegation Request to ICANN/IANA

4•FreeTheDotYE•12m ago•0 comments

Downsizing Done Right: A Guide for Empty Nesters and Retirees

https://estimateproperty.blogspot.com/2025/09/downsizing-done-right-guide-for-empty.html
1•Rebeccaui•17m ago•0 comments

How Beli Ate Yelp

https://www.nytimes.com/2025/09/15/dining/beli-restaurant-app.html
1•JumpCrisscross•18m ago•0 comments

Ask HN: Has anyone else been unemployed for over two years?

10•ncarlson•20m ago•4 comments

OpenAI's video generator Sora can mimic Netflix, TikTok and Twitch

https://www.washingtonpost.com/technology/interactive/2025/openai-training-data-sora/
2•tysone•23m ago•0 comments

Show HN: PayDroid – AI agents can now accept payments

https://paydroid.ai/
1•freebzns•25m ago•0 comments

Meme Generator

https://sundus.fun/memes
1•Spark88•25m ago•0 comments

Reflection: C++'s Decade-Defining Rocket Engine – CppCon 2025 [video]

https://www.youtube.com/watch?v=7z9NNrRDHQU
2•pjmlp•27m ago•0 comments

SaaS Fees Are Everywhere – Why Don't We Catch Them

3•fee_hunter•31m ago•0 comments

Trump Card – Pathway to American Citizenship

https://trumpcard.gov/
8•trothamel•33m ago•1 comments

Ask HN: Are you getting the new iPhone 17 series?

3•amrrs•34m ago•5 comments

Morgan and Morgan Sues Disney to Use "Steamboat Willy" in Their Commercials

https://www.reuters.com/legal/litigation/disney-sued-by-law-firm-morgan-morgan-over-steamboat-wil...
5•cool_dude85•34m ago•3 comments

Apple used AI, heart study data for Watch blood pressure feature

https://www.reuters.com/business/healthcare-pharmaceuticals/apple-used-ai-uncover-new-blood-press...
2•dctoedt•35m ago•0 comments

Ask HN: So Google blocked non-JS browsers, workarounds?

4•lynx97•36m ago•0 comments

Soft Skills for the 21st Century

https://link.springer.com/book/10.1007/978-3-031-89557-9
2•rramadass•37m ago•0 comments

NASA Selects Blue Origin to Deliver Viper Rover to Moon's South Pole

https://www.nasa.gov/news-release/nasa-selects-blue-origin-to-deliver-viper-rover-to-moons-south-...
2•ironyman•38m ago•0 comments

What GPT-OSS Leaks About OpenAI's Training Data

https://fi-le.net/oss/
3•fi-le•38m ago•0 comments

Themis (European Reusable Rocket) is assembled on launch pad

https://phys.org/news/2025-09-themis-pad-fully.html
4•theamk•38m ago•0 comments

TypePulse: Detecting type confusion bugs in Rust programs

https://dl.acm.org/doi/10.5555/3766078.3766435
2•fanf2•40m ago•0 comments

Show HN: fill harmonics, a crossword-themed music machine

https://fillharmonics.com/?grid=___---_-----__----------_---------------_---_---KICKERS_HISS-----...
3•thisisparker•42m ago•0 comments

'Revolutionary surveillance': 90% of Nicaraguans feel spied upon

https://english.elpais.com/international/2025-09-08/revolutionary-surveillance-90-of-nicaraguans-...
5•PaulHoule•44m ago•0 comments

Show HN: PlantDiagrams – AI-powered PlantUML editor

https://www.plantdiagrams.com
2•ivonellis•47m ago•0 comments

A Backdoor Disguised as a Job Interview

https://twitter.com/farezv/status/1969136304802644396
2•dabit3•50m ago•0 comments