DEV Community

OnaEiuspkz profile picture

OnaEiuspkz

Practical software developer building side projects and sharing hands‑on technical notes with the developer community.

Joined Joined on 
CVE-2026-103552: How a Deeply Nested LDAP Filter Overflows the Apache Directory LDAP API Stack

CVE-2026-103552: How a Deeply Nested LDAP Filter Overflows the Apache Directory LDAP API Stack

Comments 1
3 min read

Want to connect with OnaEiuspkz?

Create an account to connect with OnaEiuspkz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
The npm Worm Era: Why Package Signatures Did Not Stop Shai-Hulud

The npm Worm Era: Why Package Signatures Did Not Stop Shai-Hulud

Comments
3 min read
40,059 Keycloak Servers: Where the Identity Provider Is the Asset

40,059 Keycloak Servers: Where the Identity Provider Is the Asset

Comments 1
3 min read
902,191 on Port 1911 and 816,986 on Port 4911: The Niagara Supervisor Layer

902,191 on Port 1911 and 816,986 on Port 4911: The Niagara Supervisor Layer

Comments
4 min read
Apache httpd 2.4.68 to 2.4.69: Upgrade Notes for the CVE-2026-63292 Fix and Companion Advisories

Apache httpd 2.4.68 to 2.4.69: Upgrade Notes for the CVE-2026-63292 Fix and Companion Advisories

Comments
2 min read
What CVE-2026-76266 shows about trusting installation content in package scripts

What CVE-2026-76266 shows about trusting installation content in package scripts

Comments
2 min read
The Initial Access Broker Economy Behind Gunra: Why Your Boundary Is Someone Else's Product

The Initial Access Broker Economy Behind Gunra: Why Your Boundary Is Someone Else's Product

Comments
3 min read
Drupal Webform XSS (CVE-2026-96367): what site builders need to check first

Drupal Webform XSS (CVE-2026-96367): what site builders need to check first

Comments
2 min read
SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279

SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279

Comments
3 min read
CVE-2026-104467: YesWiki protects its administrator API with a check that never runs

CVE-2026-104467: YesWiki protects its administrator API with a check that never runs

Comments
2 min read
Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact

Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact

Comments
2 min read
Tandoor Recipes: 170 title matches and a small sample to read carefully

Tandoor Recipes: 170 title matches and a small sample to read carefully

Comments
2 min read
Exposed Web Applications and Shadow IT in Legal Firms: Reading a Sector's Visible Estate

Exposed Web Applications and Shadow IT in Legal Firms: Reading a Sector's Visible Estate

Comments
4 min read
An LLM observability platform stores prompts, and prompts are the application

An LLM observability platform stores prompts, and prompts are the application

Comments
3 min read
After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway

After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway

Comments
3 min read
Why code execution in an LLM orchestrator carries more weight than its CVSS score

Why code execution in an LLM orchestrator carries more weight than its CVSS score

Comments
2 min read
Detecting Trust Abuse Around CVE-2026-67278 on RouterOS Devices

Detecting Trust Abuse Around CVE-2026-67278 on RouterOS Devices

Comments
2 min read
Check Point's September: A VPN Certificate Flaw, a Management Server Gap, and Sixty-One Days

Check Point's September: A VPN Certificate Flaw, a Management Server Gap, and Sixty-One Days

Comments
3 min read
Seccomp profiles for real workloads, not for demos

Seccomp profiles for real workloads, not for demos

Comments
3 min read
Blast Radius of an SD-WAN Controller Takeover: What CVE-2026-76504 Means for Network Operations

Blast Radius of an SD-WAN Controller Takeover: What CVE-2026-76504 Means for Network Operations

1
Comments 1
4 min read
Repeating the Measurement: What Changed Between Two ZoomEye Snapshots

Repeating the Measurement: What Changed Between Two ZoomEye Snapshots

Comments
3 min read
Finding WordPress Click2Shell Exposure Starts With Knowing Where WordPress Runs

Finding WordPress Click2Shell Exposure Starts With Knowing Where WordPress Runs

Comments
2 min read
Apache NiFi at 6,093 observed hosts: a data flow controller and the credentials it holds

Apache NiFi at 6,093 observed hosts: a data flow controller and the credentials it holds

Comments
2 min read
Plane at three fields and three answers: 12,510 titles, 358 fingerprints and 72 product matches

Plane at three fields and three answers: 12,510 titles, 358 fingerprints and 72 product matches

Comments
2 min read
Metabase on 116,913 observed hosts: business intelligence as an unguarded data path

Metabase on 116,913 observed hosts: business intelligence as an unguarded data path

Comments
2 min read
After CVE-2026-104286: A Compromise Assessment Plan for FortiMail

After CVE-2026-104286: A Compromise Assessment Plan for FortiMail

Comments
2 min read
CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

Comments
2 min read
Rancher on 23,600 observed hosts: a management console with credentials for many clusters

Rancher on 23,600 observed hosts: a management console with credentials for many clusters

Comments
2 min read
Subdomain Takeover: The Dangling Record That Keeps Handing Out Your Brand

Subdomain Takeover: The Dangling Record That Keeps Handing Out Your Brand

Comments
3 min read
Auditing file-serving permission checks, using CVE-2026-100727 as the model

Auditing file-serving permission checks, using CVE-2026-100727 as the model

Comments
3 min read
Server-side request forgery: the redirect that walks past your allowlist

Server-side request forgery: the redirect that walks past your allowlist

Comments
2 min read
oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order

oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order

Comments
2 min read
Nexus Repository Manager: 81,550 title matches and 33,844 fingerprints on the artefact pipeline everything depends on

Nexus Repository Manager: 81,550 title matches and 33,844 fingerprints on the artefact pipeline everything depends on

Comments
2 min read
Shai-Hulud 2.0 and the npm Maintainer Account Problem

Shai-Hulud 2.0 and the npm Maintainer Account Problem

Comments
3 min read
Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Comments
2 min read
Evidence for the Auditor: Proving Adobe Connect Reached 12.12

Evidence for the Auditor: Proving Adobe Connect Reached 12.12

Comments
3 min read
1,531,046 Internet-Reachable iSCSI Endpoints and Only 521 Confirmed Fingerprints

1,531,046 Internet-Reachable iSCSI Endpoints and Only 521 Confirmed Fingerprints

Comments
4 min read
AI Systems Became an Inventory Problem: What the NCSC 2027 Assessment Means for Exposure Discovery

AI Systems Became an Inventory Problem: What the NCSC 2027 Assessment Means for Exposure Discovery

Comments
3 min read
A self-hosted remote control relay is reachable by design, which is exactly why it needs a check

A self-hosted remote control relay is reachable by design, which is exactly why it needs a check

Comments
3 min read
CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

Comments
2 min read
The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed

The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed

Comments
4 min read
918,415 GitLab Assets on HTTP: Measuring the Source of Truth

918,415 GitLab Assets on HTTP: Measuring the Source of Truth

Comments
2 min read
Password Managers at Organisational Scale: The Recovery Problem Returns

Password Managers at Organisational Scale: The Recovery Problem Returns

Comments
2 min read
Visibility Before Detection: What the GeoServer Case Teaches About Out-of-Band Telemetry

Visibility Before Detection: What the GeoServer Case Teaches About Out-of-Band Telemetry

1
Comments
3 min read
Hardening a Self-Managed GitLab Instance After CVE-2026-85706

Hardening a Self-Managed GitLab Instance After CVE-2026-85706

2
Comments
2 min read
Why Patching CVE-2026-96369 Often Fails in Composer and Container Deployments

Why Patching CVE-2026-96369 Often Fails in Composer and Container Deployments

2
Comments
3 min read
PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

Comments
3 min read
Patch Priorities for CVE-2026-78249: What MFP Owners Should Do First

Patch Priorities for CVE-2026-78249: What MFP Owners Should Do First

Comments
2 min read
CVE-2026-65660: a SharePoint flaw that never writes a file to disk

CVE-2026-65660: a SharePoint flaw that never writes a file to disk

Comments
3 min read
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

Comments
2 min read
SonicWall SMA1000 exposure: what a CVSS 10.0 edge-device chain means for attack surface inventory

SonicWall SMA1000 exposure: what a CVSS 10.0 edge-device chain means for attack surface inventory

Comments
3 min read
Three Ways to Reach a Docker Daemon, and What Each One Looks Like Externally

Three Ways to Reach a Docker Daemon, and What Each One Looks Like Externally

Comments
3 min read
Which Drupal Modules an Automated Scanner Hits First After WID-SEC-2026-3554

Which Drupal Modules an Automated Scanner Hits First After WID-SEC-2026-3554

1
Comments
3 min read
GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

1
Comments
2 min read
5432 and 1433: two database ports, ten million answers, and the question of what answered

5432 and 1433: two database ports, ten million answers, and the question of what answered

1
Comments
3 min read
3,199 Apache Druid instances: an analytics engine with an administrative side

3,199 Apache Druid instances: an analytics engine with an administrative side

1
Comments
2 min read
CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution

CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution

1
Comments
2 min read
Messaging and Logging Layers: 143,047 ActiveMQ and 32,169 Graylog Matches

Messaging and Logging Layers: 143,047 ActiveMQ and 32,169 Graylog Matches

2
Comments
2 min read
Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

1
Comments
3 min read
GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

1
Comments
2 min read
loading...