DEV Community

OnaEiuspkz profile picture

OnaEiuspkz

Practical software developer building side projects and sharing hands‑on technical notes with the developer community.

Joined Joined on 
Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Comments
2 min read

Want to connect with OnaEiuspkz?

Create an account to connect with OnaEiuspkz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Evidence for the Auditor: Proving Adobe Connect Reached 12.12

Evidence for the Auditor: Proving Adobe Connect Reached 12.12

Comments
3 min read
1,531,046 Internet-Reachable iSCSI Endpoints and Only 521 Confirmed Fingerprints

1,531,046 Internet-Reachable iSCSI Endpoints and Only 521 Confirmed Fingerprints

Comments
4 min read
AI Systems Became an Inventory Problem: What the NCSC 2027 Assessment Means for Exposure Discovery

AI Systems Became an Inventory Problem: What the NCSC 2027 Assessment Means for Exposure Discovery

Comments
3 min read
A self-hosted remote control relay is reachable by design, which is exactly why it needs a check

A self-hosted remote control relay is reachable by design, which is exactly why it needs a check

Comments
3 min read
CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

Comments
2 min read
The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed

The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed

Comments
4 min read
918,415 GitLab Assets on HTTP: Measuring the Source of Truth

918,415 GitLab Assets on HTTP: Measuring the Source of Truth

Comments
2 min read
Password Managers at Organisational Scale: The Recovery Problem Returns

Password Managers at Organisational Scale: The Recovery Problem Returns

Comments
2 min read
Visibility Before Detection: What the GeoServer Case Teaches About Out-of-Band Telemetry

Visibility Before Detection: What the GeoServer Case Teaches About Out-of-Band Telemetry

1
Comments
3 min read
Hardening a Self-Managed GitLab Instance After CVE-2026-85706

Hardening a Self-Managed GitLab Instance After CVE-2026-85706

2
Comments
2 min read
Why Patching CVE-2026-96369 Often Fails in Composer and Container Deployments

Why Patching CVE-2026-96369 Often Fails in Composer and Container Deployments

2
Comments
3 min read
PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

Comments
3 min read
Patch Priorities for CVE-2026-78249: What MFP Owners Should Do First

Patch Priorities for CVE-2026-78249: What MFP Owners Should Do First

Comments
2 min read
CVE-2026-65660: a SharePoint flaw that never writes a file to disk

CVE-2026-65660: a SharePoint flaw that never writes a file to disk

Comments
3 min read
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

Comments
2 min read
SonicWall SMA1000 exposure: what a CVSS 10.0 edge-device chain means for attack surface inventory

SonicWall SMA1000 exposure: what a CVSS 10.0 edge-device chain means for attack surface inventory

Comments
3 min read
Three Ways to Reach a Docker Daemon, and What Each One Looks Like Externally

Three Ways to Reach a Docker Daemon, and What Each One Looks Like Externally

Comments
3 min read
Which Drupal Modules an Automated Scanner Hits First After WID-SEC-2026-3554

Which Drupal Modules an Automated Scanner Hits First After WID-SEC-2026-3554

1
Comments
3 min read
GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

1
Comments
2 min read
5432 and 1433: two database ports, ten million answers, and the question of what answered

5432 and 1433: two database ports, ten million answers, and the question of what answered

1
Comments
3 min read
3,199 Apache Druid instances: an analytics engine with an administrative side

3,199 Apache Druid instances: an analytics engine with an administrative side

1
Comments
2 min read
CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution

CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution

1
Comments
2 min read
Messaging and Logging Layers: 143,047 ActiveMQ and 32,169 Graylog Matches

Messaging and Logging Layers: 143,047 ActiveMQ and 32,169 Graylog Matches

2
Comments
2 min read
Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

1
Comments
3 min read
GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

1
Comments
2 min read
Inventory gaps that CVE-2026-88773 will expose in most NetScaler estates

Inventory gaps that CVE-2026-88773 will expose in most NetScaler estates

1
Comments
2 min read
Graylog on the Internet: 14,061 Matches on a Platform That Centralises Every Log

Graylog on the Internet: 14,061 Matches on a Platform That Centralises Every Log

1
Comments
3 min read
Reading the Three LXD Advisories Together: CVE-2026-87799 and Its btrfs Siblings

Reading the Three LXD Advisories Together: CVE-2026-87799 and Its btrfs Siblings

1
Comments
3 min read
Runtime Detection with eBPF: What Kernel-Level Telemetry Adds to Container Security

Runtime Detection with eBPF: What Kernel-Level Telemetry Adds to Container Security

1
Comments
3 min read
GlobalProtect: 1.24 million title matches against 611 application fingerprints

GlobalProtect: 1.24 million title matches against 611 application fingerprints

Comments
2 min read
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

1
Comments
2 min read
Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Comments
3 min read
Reconciling external attack surface findings with what you already own

Reconciling external attack surface findings with what you already own

1
Comments
2 min read
Remote Access Services at Internet Scale: RDP, VNC and Telnet Counts

Remote Access Services at Internet Scale: RDP, VNC and Telnet Counts

1
Comments
2 min read
2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

1
Comments 1
3 min read
Zimbra Behind a Reverse Proxy: Finding Mail Servers That Refuse to Identify Themselves

Zimbra Behind a Reverse Proxy: Finding Mail Servers That Refuse to Identify Themselves

Comments
3 min read
10,176 Siemens SIMATIC Matches and 41,591 Hosts on Port 502: Industrial Exposure in Two Views

10,176 Siemens SIMATIC Matches and 41,591 Hosts on Port 502: Industrial Exposure in Two Views

Comments
3 min read
44,076 Indexed Moodle Instances: Learning Platforms Hold More Than Course Content

44,076 Indexed Moodle Instances: Learning Platforms Hold More Than Course Content

Comments
3 min read
Healthcare Messaging at Internet Scale: 1.28 Million Mirth Connect Fingerprints

Healthcare Messaging at Internet Scale: 1.28 Million Mirth Connect Fingerprints

Comments
3 min read
Auditing OpenCTI Case Creation After CVE-2026-76822

Auditing OpenCTI Case Creation After CVE-2026-76822

Comments
2 min read
Hardening Against CVE-2026-32996: Veeam Agent Privilege Escalation in Focus

Hardening Against CVE-2026-32996: Veeam Agent Privilege Escalation in Focus

Comments
1 min read
Watching for Exploitation of the Adobe Campaign Classic Flaws While the Patch Is Pending

Watching for Exploitation of the Adobe Campaign Classic Flaws While the Patch Is Pending

Comments 1
2 min read
1,317,154 GitLab Fingerprints and Why Source Control Is a Supply Chain Target

1,317,154 GitLab Fingerprints and Why Source Control Is a Supply Chain Target

Comments
2 min read
3,028 Hosts on Port 6443: What Public Kubernetes API Servers Reveal About Cluster Control

3,028 Hosts on Port 6443: What Public Kubernetes API Servers Reveal About Cluster Control

Comments
3 min read
CVE-2026-66066: an image upload path that reads /proc/self/environ

CVE-2026-66066: an image upload path that reads /proc/self/environ

Comments
2 min read
One Key for Every PBX: The Issabel Framework Hardcoded JWT Flaw (CVE-2026-89026)

One Key for Every PBX: The Issabel Framework Hardcoded JWT Flaw (CVE-2026-89026)

Comments
2 min read
Juniper, Sophos, WatchGuard and Barracuda: reading four edge vendors together

Juniper, Sophos, WatchGuard and Barracuda: reading four edge vendors together

1
Comments
2 min read
CVE-2026-96358 and the Long Tail of Drupal Contributed Modules

CVE-2026-96358 and the Long Tail of Drupal Contributed Modules

Comments
2 min read
Reading the 9.8 Score for CVE-2026-96357 Correctly

Reading the 9.8 Score for CVE-2026-96357 Correctly

Comments
2 min read
Measuring the GitLab Attack Surface: What 1.31 Million Indexed Instances Say About Patch Urgency

Measuring the GitLab Attack Surface: What 1.31 Million Indexed Instances Say About Patch Urgency

Comments
3 min read
When a Certificate Becomes a Clue: Infrastructure Linking in the Toll Fraud Investigation

When a Certificate Becomes a Clue: Infrastructure Linking in the Toll Fraud Investigation

1
Comments 1
4 min read
Seven Days to Disconnect: What the Berlin Breach Says About Containment Speed

Seven Days to Disconnect: What the Berlin Breach Says About Containment Speed

Comments
4 min read
4,827 internet-reachable Zabbix deployments: when the monitoring system is the blind spot

4,827 internet-reachable Zabbix deployments: when the monitoring system is the blind spot

Comments
3 min read
Two Zero-Days on the VPN Gateway: SonicWall SMA1000 and the Cost of an Internet-Facing Management Interface

Two Zero-Days on the VPN Gateway: SonicWall SMA1000 and the Cost of an Internet-Facing Management Interface

Comments
3 min read
350,497 Elasticsearch Fingerprint Matches: Reading a Familiar Exposure Number Carefully

350,497 Elasticsearch Fingerprint Matches: Reading a Familiar Exposure Number Carefully

Comments
2 min read
Cloud Metadata Service Abuse: Turning SSRF Into Credentials in Modern Web Stacks

Cloud Metadata Service Abuse: Turning SSRF Into Credentials in Modern Web Stacks

Comments
2 min read
AI Gateways Are Becoming Attack Surface: Measuring Exposed LiteLLM Deployments

AI Gateways Are Becoming Attack Surface: Measuring Exposed LiteLLM Deployments

Comments
3 min read
90,626 Jupyter Notebooks Are Publicly Indexed: The Difference Between Sharing and Exposing

90,626 Jupyter Notebooks Are Publicly Indexed: The Difference Between Sharing and Exposing

Comments
2 min read
A Defender's Checklist for CVE-2026-75650 in Adobe Commerce and Magento Open Source

A Defender's Checklist for CVE-2026-75650 in Adobe Commerce and Magento Open Source

Comments
2 min read
loading...