DEV Community

kozhevniko profile picture

kozhevniko

Stay curious, keep researching.

Joined Joined on 
Bitwarden and self-hosted password vaults: 172,580 fingerprints, 84,687 titles

Bitwarden and self-hosted password vaults: 172,580 fingerprints, 84,687 titles

Comments
2 min read

Want to connect with kozhevniko?

Create an account to connect with kozhevniko. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Known issues to expect when you install the Exchange V2 security update

Known issues to expect when you install the Exchange V2 security update

Comments
2 min read
A refresh token with no expiry is a password that does not get rotated

A refresh token with no expiry is a password that does not get rotated

Comments
3 min read
AI assisted commits leak secrets at roughly twice the rate, and the fix is process rather than policy

AI assisted commits leak secrets at roughly twice the rate, and the fix is process rather than policy

Comments
2 min read
Industrial edge vendors under measurement: 2,805,294 Zyxel, 1,884,815 Draytek and 14,144 Moxa matches

Industrial edge vendors under measurement: 2,805,294 Zyxel, 1,884,815 Draytek and 14,144 Moxa matches

Comments
2 min read
Low-Code AI Builders: 40,653 Flowise and 10,860 Dify Title Matches

Low-Code AI Builders: 40,653 Flowise and 10,860 Dify Title Matches

Comments
2 min read
Sizing the S7comm Surface: What 262 Reachable Port 102 Services Actually Tell You

Sizing the S7comm Surface: What 262 Reachable Port 102 Services Actually Tell You

Comments
3 min read
Syslog on 973,278 hosts: the log channel that ships across every network boundary

Syslog on 973,278 hosts: the log channel that ships across every network boundary

Comments
4 min read
CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

Comments
2 min read
Frigate NVR surfaces: 4,999 fingerprinted instances and what a camera console exposes

Frigate NVR surfaces: 4,999 fingerprinted instances and what a camera console exposes

Comments
3 min read
CVE-2026-62911 and 22,000 Unpatched Exchange Servers

CVE-2026-62911 and 22,000 Unpatched Exchange Servers

Comments
2 min read
CVE-2026-93674 and the Credential Risk in Self-Hosted LLM Platforms

CVE-2026-93674 and the Credential Risk in Self-Hosted LLM Platforms

Comments
2 min read
Configuration decides exposure: mapping the NetScaler CVEs to the way appliances are deployed (CVE-2026-88776)

Configuration decides exposure: mapping the NetScaler CVEs to the way appliances are deployed (CVE-2026-88776)

Comments 1
3 min read
CVE-2026-103663 sits in the model delivery path, and that is what makes it dangerous

CVE-2026-103663 sits in the model delivery path, and that is what makes it dangerous

Comments 1
2 min read
Edge Servers as the Payload Delivery Surface: Sizing nginx and WordPress Exposure

Edge Servers as the Payload Delivery Surface: Sizing nginx and WordPress Exposure

Comments
2 min read
MikroTrick: How Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password

MikroTrick: How Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password

Comments
3 min read
What to look for when Twenty CRM credentials leak: detection ideas for CVE-2026-105763

What to look for when Twenty CRM credentials leak: detection ideas for CVE-2026-105763

Comments
3 min read
Detecting Exploitation Attempts Against NetScaler CVE-2026-88779

Detecting Exploitation Attempts Against NetScaler CVE-2026-88779

Comments
2 min read
176,926 Hosts on Port 5900: VNC's Persistent Place in the Exposed Service Inventory

176,926 Hosts on Port 5900: VNC's Persistent Place in the Exposed Service Inventory

Comments
3 min read
TASK#STOMP: A Windows Backdoor That Lives in Scheduled Tasks and VBS

TASK#STOMP: A Windows Backdoor That Lives in Scheduled Tasks and VBS

Comments
2 min read
1,393 sports-sector matches are exposure, not evidence of compromise

1,393 sports-sector matches are exposure, not evidence of compromise

Comments
2 min read
SectopRAT in Tampered Audio Software Components: A Loader That Uses the Host's Own Imports

SectopRAT in Tampered Audio Software Components: A Loader That Uses the Host's Own Imports

1
Comments 1
3 min read
FreeSWITCH mod_verto: a 2 MiB buffer and a 10 MiB Content-Length

FreeSWITCH mod_verto: a 2 MiB buffer and a 10 MiB Content-Length

Comments
4 min read
One shellcode, two names: what Volexity's UTA0560 finding says about attribution confidence

One shellcode, two names: what Volexity's UTA0560 finding says about attribution confidence

Comments
4 min read
The September 2026 KEV wave as an operations dataset, not a news cycle

The September 2026 KEV wave as an operations dataset, not a news cycle

Comments
2 min read
Apache Zeppelin on the Internet: 25,617 Fingerprint Matches and a Notebook With Cluster Credentials

Apache Zeppelin on the Internet: 25,617 Fingerprint Matches and a Notebook With Cluster Credentials

Comments
2 min read
1,897,463 MongoDB services: how unauthenticated data stores became routine

1,897,463 MongoDB services: how unauthenticated data stores became routine

Comments 1
2 min read
6,378,556 Hosts on Port 10250: The Cluster Node Interface That Assumes a Trusted Network

6,378,556 Hosts on Port 10250: The Cluster Node Interface That Assumes a Trusted Network

Comments
3 min read
GitOps control planes: the Argo CD exposure question

GitOps control planes: the Argo CD exposure question

1
Comments
2 min read
Group-IB's August 2026 APAC Ransomware Data: What 190 Incidents Actually Tell You

Group-IB's August 2026 APAC Ransomware Data: What 190 Incidents Actually Tell You

Comments
2 min read
Detection and verification for CVE-2026-102795 in Apache Traffic Server

Detection and verification for CVE-2026-102795 in Apache Traffic Server

Comments
2 min read
FusionAuth: 2,411 title matches on the authentication server that issues your tokens

FusionAuth: 2,411 title matches on the authentication server that issues your tokens

Comments
2 min read
CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt

CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt

Comments
2 min read
Container Registries and Orchestration: 57,017 Harbor and 78,059 Consul Fingerprints

Container Registries and Orchestration: 57,017 Harbor and 78,059 Consul Fingerprints

Comments
2 min read
Drupal Contributed Modules: 36 CVEs in One September 2026 Advisory Batch

Drupal Contributed Modules: 36 CVEs in One September 2026 Advisory Batch

Comments
2 min read
Jupyter Notebooks on the Open Internet: 408,240 Body Matches

Jupyter Notebooks on the Open Internet: 408,240 Body Matches

Comments
2 min read
Why vul.cve Returns Zero for CVE-2026-96365: Reading Exposure Data Honestly

Why vul.cve Returns Zero for CVE-2026-96365: Reading Exposure Data Honestly

Comments
2 min read
Triage Order After a Credential-Exposure Advisory: What to Fix First on Fortinet Edge Devices

Triage Order After a Credential-Exposure Advisory: What to Fix First on Fortinet Edge Devices

Comments
6 min read
One Console, Every Firewall: What Cisco FMC CVE-2026-20079 Teaches About Management-Plane Risk

One Console, Every Firewall: What Cisco FMC CVE-2026-20079 Teaches About Management-Plane Risk

Comments
4 min read
Hardening SSH Against Brute Force with Fail2ban and Rate Limiting

Hardening SSH Against Brute Force with Fail2ban and Rate Limiting

Comments
6 min read
Windows AppContainer: a sandbox that depends on how the application is written

Windows AppContainer: a sandbox that depends on how the application is written

Comments
3 min read
What the CISA KEV Listing for CVE-2026-104286 Tells Defenders

What the CISA KEV Listing for CVE-2026-104286 Tells Defenders

Comments
2 min read
Dot-Form Header Aliases: How Traefik ForwardAuth Identity Spoofing Reached Backends Before 2.11.56

Dot-Form Header Aliases: How Traefik ForwardAuth Identity Spoofing Reached Backends Before 2.11.56

Comments
3 min read
MFP Web Management Interfaces and CVE-2026-78249: Why Reachability Decides the Risk

MFP Web Management Interfaces and CVE-2026-78249: Why Reachability Decides the Risk

Comments
3 min read
Four Stages, One Payload: The Code Delivery Chain CERT Polska Unpacked

Four Stages, One Payload: The Code Delivery Chain CERT Polska Unpacked

Comments
5 min read
Telling Docker Daemons Apart from Other Docker-Facing Services

Telling Docker Daemons Apart from Other Docker-Facing Services

Comments
3 min read
Container Image Provenance: Signing Is Half the Control

Container Image Provenance: Signing Is Half the Control

Comments
2 min read
The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation

The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation

Comments
3 min read
A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap

A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap

Comments
3 min read
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

Comments
2 min read
SonarQube: 92,810 title matches on the platform that holds your source code and your pipeline tokens

SonarQube: 92,810 title matches on the platform that holds your source code and your pipeline tokens

Comments
2 min read
Continuous Monitoring of Public Assets: Turning a One-Off Scan into a Change Signal

Continuous Monitoring of Public Assets: Turning a One-Off Scan into a Change Signal

1
Comments
3 min read
The OAuth Grants Nobody Reviews: Governing Third-Party SaaS Access

The OAuth Grants Nobody Reviews: Governing Third-Party SaaS Access

Comments
4 min read
Tornado 6.5.9: A Symlink, a Response Ceiling, and a Query String

Tornado 6.5.9: A Symlink, a Response Ceiling, and a Query String

Comments
3 min read
CVE-2026-96358: A Module Inventory Checklist from the CERT-BUND Record

CVE-2026-96358: A Module Inventory Checklist from the CERT-BUND Record

Comments
2 min read
Sudo and the timezone that rewrites the clock: CVE-2026-96512

Sudo and the timezone that rewrites the clock: CVE-2026-96512

Comments
3 min read
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Comments
4 min read
Cross-Site Scripting in the WID-SEC-2026-3554 Batch: The CVE-2026-96369 Angle

Cross-Site Scripting in the WID-SEC-2026-3554 Batch: The CVE-2026-96369 Angle

Comments
3 min read
F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop

F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop

Comments
3 min read
Upgrading past CVE-2026-88772: version mapping and rollout order for NetScaler ADC and Gateway

Upgrading past CVE-2026-88772: version mapping and rollout order for NetScaler ADC and Gateway

Comments
3 min read
loading...