DEV Community

yutianle profile picture

yutianle

404 bio not found

Joined Joined on 
Lateral Movement Across Zimbra Clusters via CVE-2026-73570

Lateral Movement Across Zimbra Clusters via CVE-2026-73570

Comments
2 min read

Want to connect with yutianle?

Create an account to connect with yutianle. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
When an Agent Reaches Root: The Zammad Attack and Machine-Speed Intrusion

When an Agent Reaches Root: The Zammad Attack and Machine-Speed Intrusion

Comments
2 min read
Confluence exposure: 1.8 million fingerprint matches depend on which fingerprint you use

Confluence exposure: 1.8 million fingerprint matches depend on which fingerprint you use

Comments
2 min read
Zipkin at 40 Titles and 562 Fingerprints: When the Signature Finds More Than the Name

Zipkin at 40 Titles and 562 Fingerprints: When the Signature Finds More Than the Name

Comments
4 min read
6,918 Paperless matches: a document archive that was meant to replace the filing cabinet

6,918 Paperless matches: a document archive that was meant to replace the filing cabinet

Comments
2 min read
ShieldCrash: A Second Path Around the Microsoft Defender ShieldBreak Fix

ShieldCrash: A Second Path Around the Microsoft Defender ShieldBreak Fix

Comments
3 min read
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

Comments
4 min read
Measuring Edge Gateway Exposure: Why the Right ZoomEye Query Matters More Than the Number

Measuring Edge Gateway Exposure: Why the Right ZoomEye Query Matters More Than the Number

Comments
4 min read
Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About

Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About

Comments
3 min read
Microsoft SharePoint exposure: 163,266 matching assets and a code injection flaw that needs only a user account

Microsoft SharePoint exposure: 163,266 matching assets and a code injection flaw that needs only a user account

Comments
3 min read
Prioritizing a 974-CVE Patch Tuesday Without Freezing Your Deployment Pipeline

Prioritizing a 974-CVE Patch Tuesday Without Freezing Your Deployment Pipeline

Comments
3 min read
HAProxy: 49,691 Fingerprint Matches at the Front Door

HAProxy: 49,691 Fingerprint Matches at the Front Door

Comments
3 min read
Path filters that do not filter: CVE-2026-57441 and CVE-2026-57442 in MCPVault

Path filters that do not filter: CVE-2026-57441 and CVE-2026-57442 in MCPVault

Comments
3 min read
CVE-2026-89775: Reading Host Memory From an ARM64 KVM Guest

CVE-2026-89775: Reading Host Memory From an ARM64 KVM Guest

Comments
4 min read
Gitea: 116,010 fingerprints against 120,024 titles, and the self-hosted forge as an identity boundary

Gitea: 116,010 fingerprints against 120,024 titles, and the self-hosted forge as an identity boundary

Comments
3 min read
12,488,458 answers on port 9080 beside 77,076 WebSphere matches: reading a Java middleware estate

12,488,458 answers on port 9080 beside 77,076 WebSphere matches: reading a Java middleware estate

Comments
3 min read
GitLab CVE-2026-85706: Why an Arbitrary File Read on a DevSecOps Platform Is a Credential Incident

GitLab CVE-2026-85706: Why an Arbitrary File Read on a DevSecOps Platform Is a Credential Incident

Comments
3 min read
Prioritising CVE-2026-85706 Work: What a Read on a GitLab Host Is Worth

Prioritising CVE-2026-85706 Work: What a Read on a GitLab Host Is Worth

Comments
3 min read
Distributing the Risk: What Global Docker Exposure Numbers Do and Do Not Show

Distributing the Risk: What Global Docker Exposure Numbers Do and Do Not Show

1
Comments
3 min read
Key rotation as a scheduled operation

Key rotation as a scheduled operation

Comments
2 min read
Concourse: 3,767 title matches on the pipeline system that executes your build code

Concourse: 3,767 title matches on the pipeline system that executes your build code

Comments
2 min read
Availability risk on the VPN concentrator: the denial-of-service side of CVE-2026-88772

Availability risk on the VPN concentrator: the denial-of-service side of CVE-2026-88772

Comments
3 min read
A first-day response plan for CVE-2026-84411 in MikroTik RouterOS

A first-day response plan for CVE-2026-84411 in MikroTik RouterOS

Comments
2 min read
CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch

CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch

Comments
4 min read
Detection and logging priorities for the exploited NetScaler flaw CVE-2026-88771

Detection and logging priorities for the exploited NetScaler flaw CVE-2026-88771

Comments
3 min read
CVE-2026-91843: Unauthenticated Stack Overflow in Check Point Security Management Servers

CVE-2026-91843: Unauthenticated Stack Overflow in Check Point Security Management Servers

Comments
2 min read
Detection signals for PRTG abuse: what to look for after CVE-2026-4637 and CVE-2026-4638

Detection signals for PRTG abuse: what to look for after CVE-2026-4637 and CVE-2026-4638

Comments
2 min read
What Drupal Builders Should Log After CVE-2026-96366: Detection Ideas for an Access Bypass

What Drupal Builders Should Log After CVE-2026-96366: Detection Ideas for an Access Bypass

Comments
2 min read
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Comments
2 min read
Twenty Wormable Bugs in One Patch Tuesday: What the September 2026 Microsoft Release Tells Us

Twenty Wormable Bugs in One Patch Tuesday: What the September 2026 Microsoft Release Tells Us

Comments 1
3 min read
Drupal Contributed Modules Under WID-SEC-2026-3554: A Patching Plan for CVE-2026-96359 and the Wider Batch

Drupal Contributed Modules Under WID-SEC-2026-3554: A Patching Plan for CVE-2026-96359 and the Wider Batch

1
Comments
3 min read
Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Comments
4 min read
Cisco FMC CVE-2026-20079: When the Management Plane Is the Attack Plane

Cisco FMC CVE-2026-20079: When the Management Plane Is the Attack Plane

Comments
4 min read
Clock synchronisation as a forensic prerequisite

Clock synchronisation as a forensic prerequisite

Comments
2 min read
Gerrit Code Review on the Open Internet: 2,508 Title Matches and the Credential Store Behind Them

Gerrit Code Review on the Open Internet: 2,508 Title Matches and the Credential Store Behind Them

Comments
2 min read
Detecting unexpected custom attributes after CVE-2026-96367

Detecting unexpected custom attributes after CVE-2026-96367

1
Comments
2 min read
CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

Comments
3 min read
981,494 FortiGate Fingerprints and 16.4 Million RDP Services: Measuring the Gunra Initial-Access Surface

981,494 FortiGate Fingerprints and 16.4 Million RDP Services: Measuring the Gunra Initial-Access Surface

Comments
3 min read
CVE-2026-26084: the sandbox appliance that answers questions it should refuse

CVE-2026-26084: the sandbox appliance that answers questions it should refuse

Comments 1
3 min read
What port 2375 says about Docker exposure that a product fingerprint does not

What port 2375 says about Docker exposure that a product fingerprint does not

Comments 1
3 min read
Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

Comments 1
3 min read
From Patch Tuesday to KEV in Three Weeks: The CVE-2026-19490 NetScaler Timeline

From Patch Tuesday to KEV in Three Weeks: The CVE-2026-19490 NetScaler Timeline

Comments
3 min read
RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060

RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060

Comments
2 min read
Mapping VeloCloud Orchestrator Exposure: What ZoomEye Data Says About CVE-2026-93952

Mapping VeloCloud Orchestrator Exposure: What ZoomEye Data Says About CVE-2026-93952

Comments
2 min read
What CERT-BUND Published About CVE-2026-96361 and What the Record Leaves Open

What CERT-BUND Published About CVE-2026-96361 and What the Record Leaves Open

Comments
2 min read
414,009 ESXi hosts and 1,495,455 answers on port 902: sizing a hypervisor estate from outside

414,009 ESXi hosts and 1,495,455 answers on port 902: sizing a hypervisor estate from outside

Comments 1
3 min read
Adobe Connect 12.12: Why a 9.9 SQL Injection Deserves Its Own Patch Window

Adobe Connect 12.12: Why a 9.9 SQL Injection Deserves Its Own Patch Window

Comments 1
4 min read
Shared Hosting and CVE-2026-48842: When One Mail Server Holds Every Tenant

Shared Hosting and CVE-2026-48842: When One Mail Server Holds Every Tenant

Comments 1
3 min read
MISP Feed Redirects Before 2.5.45: When an Outbound Request Carries Credentials to Another Host

MISP Feed Redirects Before 2.5.45: When an Outbound Request Carries Credentials to Another Host

1
Comments
3 min read
132,707 Magento Matches and 5,314 Title Matches: Measuring a Commerce Platform Under Active Exploitation

132,707 Magento Matches and 5,314 Title Matches: Measuring a Commerce Platform Under Active Exploitation

1
Comments
3 min read
CVE-2026-76461: SQL injection in an email gateway reaches root on the appliance

CVE-2026-76461: SQL injection in an email gateway reaches root on the appliance

1
Comments
2 min read
73,105 Airflow instances, 11,673 SonarQube and 33,837 Nexus: fingerprinting the build and quality toolchain

73,105 Airflow instances, 11,673 SonarQube and 33,837 Nexus: fingerprinting the build and quality toolchain

Comments
3 min read
From Java Byte Stream to Root: Cisco ISE Remote Code Execution Flaws

From Java Byte Stream to Root: Cisco ISE Remote Code Execution Flaws

Comments
2 min read
CVE-2026-69676: Kerberos Authentication Bypass by Capture-Replay

CVE-2026-69676: Kerberos Authentication Bypass by Capture-Replay

Comments
2 min read
Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Comments
4 min read
From OAuth Profile to Root: Tracing the CVE-2026-94127 Attack Path in F5 BIG-IP APM

From OAuth Profile to Root: Tracing the CVE-2026-94127 Attack Path in F5 BIG-IP APM

Comments
3 min read
A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

Comments
4 min read
Credentials in the Agent's Reach: The Codex Memory-Sharing Issue

Credentials in the Agent's Reach: The Codex Memory-Sharing Issue

1
Comments 1
3 min read
Cisco Secure Email Gateway Injection Bug CVE-2026-76443: What Administrators Should Do First

Cisco Secure Email Gateway Injection Bug CVE-2026-76443: What Administrators Should Do First

Comments
2 min read
The Virtualization Control Plane Is on the Internet: 414,092 ESXi and 140,746 Proxmox VE Fingerprints

The Virtualization Control Plane Is on the Internet: 414,092 ESXi and 140,746 Proxmox VE Fingerprints

Comments
4 min read
loading...