DEV Community

jeffrey profile picture

jeffrey

Full-stack developer, love building side projects, write about what I learn, and connect with fellow coders.

Joined Joined on 
Detection engineering for CVE-2026-100382: hunting the External Data web shell

Detection engineering for CVE-2026-100382: hunting the External Data web shell

Comments
3 min read

Want to connect with jeffrey?

Create an account to connect with jeffrey. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link

Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link

Comments
4 min read
Request Smuggling in the ASGI Stack: Starlette and LiteLLM

Request Smuggling in the ASGI Stack: Starlette and LiteLLM

Comments
3 min read
A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments

A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments

Comments
2 min read
Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Comments
3 min read
Detection and verification limits for CVE-2026-96364 on a live Drupal estate

Detection and verification limits for CVE-2026-96364 on a live Drupal estate

Comments
3 min read
Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind

Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind

Comments
3 min read
WordPress CVE-2026-87902: an Unauthenticated Path Traversal That Escalates into Remote Code Execution

WordPress CVE-2026-87902: an Unauthenticated Path Traversal That Escalates into Remote Code Execution

Comments
3 min read
Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Comments
2 min read
What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows

What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows

Comments
3 min read
The Five-Month Gap: Zimbra Exposure Between Zero-Day Exploitation and Public Disclosure

The Five-Month Gap: Zimbra Exposure Between Zero-Day Exploitation and Public Disclosure

Comments
3 min read
OpenMediaVault: 123,886 title matches beside four fingerprints

OpenMediaVault: 123,886 title matches beside four fingerprints

Comments
3 min read
Rundeck on 4,729 hosts: a job scheduler that holds the credentials to run them

Rundeck on 4,729 hosts: a job scheduler that holds the credentials to run them

Comments
3 min read
Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

Comments
3 min read
What Click2Shell Teaches About Reporting a Parser Discrepancy

What Click2Shell Teaches About Reporting a Parser Discrepancy

Comments
2 min read
Shared and Managed Fortinet Estates: Whose Gateway Is It When Credentials Leak?

Shared and Managed Fortinet Estates: Whose Gateway Is It When Credentials Leak?

Comments
6 min read
CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators

CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators

1
Comments
3 min read
1,160,264 Mosquitto fingerprints: the MQTT broker that ends up on the public internet

1,160,264 Mosquitto fingerprints: the MQTT broker that ends up on the public internet

Comments
2 min read
F5 BIG-IP management interfaces: 1.58 million fingerprint matches and 55,390 on 443

F5 BIG-IP management interfaces: 1.58 million fingerprint matches and 55,390 on 443

1
Comments
2 min read
LXD Backup Import as an Attack Surface: CVE-2026-87799 and the btrfs Restore Path

LXD Backup Import as an Attack Surface: CVE-2026-87799 and the btrfs Restore Path

1
Comments
2 min read
Internet-Exposed Drupal Sites and the September 2026 Extension Advisory

Internet-Exposed Drupal Sites and the September 2026 Extension Advisory

Comments
3 min read
Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774

Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774

Comments
3 min read
1,890,595 MongoDB Service Matches: The Default-Configuration Problem at Internet Scale

1,890,595 MongoDB Service Matches: The Default-Configuration Problem at Internet Scale

1
Comments
2 min read
Browser extensions are an enterprise control problem, not a user hygiene problem

Browser extensions are an enterprise control problem, not a user hygiene problem

1
Comments
4 min read
DMARC aggregate reports as infrastructure change detection

DMARC aggregate reports as infrastructure change detection

1
Comments
2 min read
Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Comments
2 min read
Mapping CVE-2026-96361 to the Drupal Projects You Actually Run

Mapping CVE-2026-96361 to the Drupal Projects You Actually Run

1
Comments
2 min read
From Facebook Ad to Phone Bill: How the Android Toll Fraud Campaign Reached Victims

From Facebook Ad to Phone Bill: How the Android Toll Fraud Campaign Reached Victims

Comments
6 min read
CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

Comments
3 min read
Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday

Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday

Comments
4 min read
15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

Comments
2 min read
Dagster: 1,712 Title Matches and a Zero Fingerprint

Dagster: 1,712 Title Matches and a Zero Fingerprint

Comments
3 min read
OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

Comments
2 min read
Temporal at 1,992 Title Matches and 200 Application Fingerprints

Temporal at 1,992 Title Matches and 200 Application Fingerprints

1
Comments
3 min read
2590 MongoDB, 1469 Memcached and 387 CouchDB Results: Three Data Stores With Three Default Postures

2590 MongoDB, 1469 Memcached and 387 CouchDB Results: Three Data Stores With Three Default Postures

1
Comments
4 min read
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

1
Comments
4 min read
HDFS Web Interfaces: 24,511 Fingerprint Matches and 1,602,200 Answers on Port 9870

HDFS Web Interfaces: 24,511 Fingerprint Matches and 1,602,200 Answers on Port 9870

Comments 1
3 min read
CVE-2026-89078: What the Advisory Says and What It Does Not

CVE-2026-89078: What the Advisory Says and What It Does Not

Comments
2 min read
2,857,655 RouterOS Matches and 830,366 With SSH: Turning an Edge Device Baseline Into a Decision

2,857,655 RouterOS Matches and 830,366 With SSH: Turning an Edge Device Baseline Into a Decision

Comments 2
3 min read
CVE-2026-76442 and the Cost of an Unbounded Number in Cisco Secure Email Gateway

CVE-2026-76442 and the Cost of an Unbounded Number in Cisco Secure Email Gateway

Comments 1
3 min read
Public Exploit Code and No Patch: The D-Link DIR-822A L2TP Flaw in Context

Public Exploit Code and No Patch: The D-Link DIR-822A L2TP Flaw in Context

Comments 1
2 min read
Detecting and monitoring around CVE-2026-96360

Detecting and monitoring around CVE-2026-96360

Comments 1
2 min read
Replacing standing administrative access with brokered sessions

Replacing standing administrative access with brokered sessions

Comments
2 min read
Database Backups Are an Identity Problem Before They Are a Storage Problem

Database Backups Are an Identity Problem Before They Are a Storage Problem

Comments
4 min read
Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Comments
2 min read
CVE-2026-76441: Improper Access Control in Cisco Secure Email Gateway Exposes Restricted Functions

CVE-2026-76441: Improper Access Control in Cisco Secure Email Gateway Exposes Restricted Functions

Comments 1
4 min read
Exploitation Conditions in CVE-2026-75682: What a Low-Privileged Account Buys an Attacker

Exploitation Conditions in CVE-2026-75682: What a Low-Privileged Account Buys an Attacker

Comments 1
3 min read
CVE-2026-53266 Triage Guide: What the CISA KEV Listing Changes for Linux Kernel Patching

CVE-2026-53266 Triage Guide: What the CISA KEV Listing Changes for Linux Kernel Patching

Comments 1
3 min read
RouterOS Administrative Takeover Without Credentials: A Defensive Reading of CVE-2026-86060

RouterOS Administrative Takeover Without Credentials: A Defensive Reading of CVE-2026-86060

1
Comments
2 min read
Palo Alto Networks at internet scale: 20,383 services, and 613 GlobalProtect portals

Palo Alto Networks at internet scale: 20,383 services, and 613 GlobalProtect portals

1
Comments
3 min read
Two XenForo Flaws in One Release: Empty OAuth2 Credentials and a Passkey That Belonged to Someone Else

Two XenForo Flaws in One Release: Empty OAuth2 Credentials and a Passkey That Belonged to Someone Else

1
Comments
3 min read
Home and Small Business Storage on the Public Internet: Synology, QNAP and Plex

Home and Small Business Storage on the Public Internet: Synology, QNAP and Plex

Comments
3 min read
72,819 internet-reachable Samba servers: the file-sharing layer that never got an inventory

72,819 internet-reachable Samba servers: the file-sharing layer that never got an inventory

Comments
4 min read
JFrog Artifactory CVE-2026-82329: The Default Join Key as an Authentication Bypass

JFrog Artifactory CVE-2026-82329: The Default Join Key as an Authentication Bypass

Comments 1
3 min read
917,080 Hosts on Port 623: The Out-of-Band Controller Nobody Inventoried

917,080 Hosts on Port 623: The Out-of-Band Controller Nobody Inventoried

Comments
3 min read
5,102,346 Hosts on Port 5900: VNC and the Legacy Remote-Access Surface

5,102,346 Hosts on Port 5900: VNC and the Legacy Remote-Access Surface

Comments
2 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Comments
3 min read
CVE-2026-93616: Why Check Point Management Servers Need Network-Level Protection

CVE-2026-93616: Why Check Point Management Servers Need Network-Level Protection

Comments
3 min read
Kubernetes Admission Control: From Pod Security Standards to Policy-as-Code Gates

Kubernetes Admission Control: From Pod Security Standards to Policy-as-Code Gates

Comments
2 min read
Apache Tomcat CVE-2026-77762: A Stale HPACK Emitter Leaks Trailers Between HTTP/2 Requests

Apache Tomcat CVE-2026-77762: A Stale HPACK Emitter Leaks Trailers Between HTTP/2 Requests

Comments
3 min read
loading...