DEV Community

StarkMan profile picture

StarkMan

404 bio not found

Joined Joined on 
SeaweedFS and the Object Store You Forgot You Deployed: 6,345 Matches

SeaweedFS and the Object Store You Forgot You Deployed: 6,345 Matches

Comments
2 min read

Want to connect with StarkMan?

Create an account to connect with StarkMan. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it

Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it

Comments
4 min read
AI Agents as Intruders: What the JadePuffer Azure Cases Change About Incident Response

AI Agents as Intruders: What the JadePuffer Azure Cases Change About Incident Response

Comments
2 min read
Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

Comments
3 min read
CVE-2026-63292 Timeline and Technical Anatomy: An Apache mod_vhost_alias Buffer Overflow

CVE-2026-63292 Timeline and Technical Anatomy: An Apache mod_vhost_alias Buffer Overflow

1
Comments
2 min read
Telnet, SSH and Port 8080: Identifying the Device Layer Where Payloads Hide

Telnet, SSH and Port 8080: Identifying the Device Layer Where Payloads Hide

Comments
3 min read
Adobe Connect Android App 4.5: The Mobile Half of APSB26-150

Adobe Connect Android App 4.5: The Mobile Half of APSB26-150

Comments
2 min read
Detecting Data Exfiltration Over DNS: Signals That Survive Encrypted Transport

Detecting Data Exfiltration Over DNS: Signals That Survive Encrypted Transport

Comments
3 min read
Choosing Between rsync and btrfs receive in LXD: Exposure Differences Under CVE-2026-87799

Choosing Between rsync and btrfs receive in LXD: Exposure Differences Under CVE-2026-87799

Comments
3 min read
Field-level encryption: choosing the layer that has to hold

Field-level encryption: choosing the layer that has to hold

Comments
2 min read
Why CISA gave agencies three days to patch CVE-2026-7273 in Zyxel GS1900 switches

Why CISA gave agencies three days to patch CVE-2026-7273 in Zyxel GS1900 switches

Comments
4 min read
55,812 SonicWall SSL-VPN Assets on HTTP and the Management Plane Problem

55,812 SonicWall SSL-VPN Assets on HTTP and the Management Plane Problem

Comments
2 min read
Edge Appliances Keep Being Targeted: Where CVE-2026-88774 Fits

Edge Appliances Keep Being Targeted: Where CVE-2026-88774 Fits

Comments
3 min read
Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch

Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch

1
Comments
4 min read
Measuring NetScaler exposure: what a 239,277-asset count does and does not tell you about CVE-2026-88771

Measuring NetScaler exposure: what a 239,277-asset count does and does not tell you about CVE-2026-88771

1
Comments
2 min read
CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem

CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem

Comments
5 min read
What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials

What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials

1
Comments
2 min read
Detecting Trouble from CVE-2026-88775 When No Trigger Is Public

Detecting Trouble from CVE-2026-88775 When No Trigger Is Public

Comments
3 min read
Why "Zimbra Web Client" Appears Half a Million Times and Almost None of It Is a Mail Server

Why "Zimbra Web Client" Appears Half a Million Times and Almost None of It Is a Mail Server

Comments
3 min read
Why CVE-2026-77762 Shows a Vendor Low Rating and a Third-Party 8.1 Score

Why CVE-2026-77762 Shows a Vendor Low Rating and a Third-Party 8.1 Score

Comments
2 min read
Default Credentials on Exposed VPN and SSH Gateways: The Gunra Path With the Faintest Audit Trail

Default Credentials on Exposed VPN and SSH Gateways: The Gunra Path With the Faintest Audit Trail

Comments
3 min read
CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

Comments
3 min read
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

Comments
3 min read
Drupal's September 2026 Contrib Batch: Where CVE-2026-96366 Sits in a 36-CVE Advisory

Drupal's September 2026 Contrib Batch: Where CVE-2026-96366 Sits in a 36-CVE Advisory

1
Comments
2 min read
Apache Cassandra on the internet: where the exposed port is not the service

Apache Cassandra on the internet: where the exposed port is not the service

Comments
2 min read
Wazuh: 17,587 Fingerprint Matches on the Security Platform Watching Everything

Wazuh: 17,587 Fingerprint Matches on the Security Platform Watching Everything

Comments
3 min read
D-Link DIR-822A: no patch, a public exploit, and a router nobody owns

D-Link DIR-822A: no patch, a public exploit, and a router nobody owns

Comments
2 min read
11,011 Hosts on Port 3389: Reading an RDP Exposure Number Without Overreading It

11,011 Hosts on Port 3389: Reading an RDP Exposure Number Without Overreading It

Comments
3 min read
Inventory Work for CVE-2026-96357: Finding Affected Drupal Modules First

Inventory Work for CVE-2026-96357: Finding Affected Drupal Modules First

Comments
2 min read
Module inventory hygiene in the light of CVE-2026-96360

Module inventory hygiene in the light of CVE-2026-96360

Comments
2 min read
Java Application Servers Are Still the Internet's Largest Exposed Estate

Java Application Servers Are Still the Internet's Largest Exposed Estate

Comments
3 min read
917,169 Matches on Port 623 and 109,327 on app="IPMI": Two Views of the Out-of-Band Layer

917,169 Matches on Port 623 and 109,327 on app="IPMI": Two Views of the Out-of-Band Layer

Comments
3 min read
Windows Event Logging You Will Actually Use in an Investigation

Windows Event Logging You Will Actually Use in an Investigation

Comments
3 min read
132,792 Matches for Magento and 10.0 CVSS: Sizing the Commerce Surface Behind CVE-2026-75650

132,792 Matches for Magento and 10.0 CVSS: Sizing the Commerce Surface Behind CVE-2026-75650

Comments
2 min read
48,183 and 42,025: Building and Industrial Protocols on the Public Internet

48,183 and 42,025: Building and Industrial Protocols on the Public Internet

Comments
2 min read
MikroTrick and the SSH key check that forgot the exponent

MikroTrick and the SSH key check that forgot the exponent

Comments
3 min read
4,526,693 Answers on Port 20000: DNP3 and the Confidence Problem in Grid Telemetry

4,526,693 Answers on Port 20000: DNP3 and the Confidence Problem in Grid Telemetry

Comments
3 min read
Object Storage Access Reviews: Turning a Bucket List into Evidence

Object Storage Access Reviews: Turning a Bucket List into Evidence

Comments 1
3 min read
D-Link DIR-822A Routers Expose Critical DHCP and L2TP Flaws With Public PoC

D-Link DIR-822A Routers Expose Critical DHCP and L2TP Flaws With Public PoC

Comments 1
2 min read
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Comments 1
3 min read
Agency Patch Workflows for CVE-2026-96365: Coordinating 16 Module Updates Across Client Sites

Agency Patch Workflows for CVE-2026-96365: Coordinating 16 Module Updates Across Client Sites

Comments
2 min read
Two PRTG Bugs, One Release: The 26.2.120.1449 Fix for CVE-2026-4637 and CVE-2026-4638

Two PRTG Bugs, One Release: The 26.2.120.1449 Fix for CVE-2026-4637 and CVE-2026-4638

Comments
3 min read
16,456,122 RDP Matches and 9,173,905 VNC Matches: The Remote Access Baseline

16,456,122 RDP Matches and 9,173,905 VNC Matches: The Remote Access Baseline

Comments
2 min read
Click2Shell Exposure: What 7.9 Million WordPress Assets Do and Do Not Tell You

Click2Shell Exposure: What 7.9 Million WordPress Assets Do and Do Not Tell You

Comments 1
2 min read
Mattermost: 736,893 Fingerprint Matches on Self-Hosted Collaboration

Mattermost: 736,893 Fingerprint Matches on Self-Hosted Collaboration

Comments
3 min read
CVE-2026-86510: An Out-of-Bounds Write in the D-Link DIR-822A L2TP Daemon

CVE-2026-86510: An Out-of-Bounds Write in the D-Link DIR-822A L2TP Daemon

Comments
3 min read
CVE-2026-66302: External Path Control in Skype for Business Server

CVE-2026-66302: External Path Control in Skype for Business Server

Comments
2 min read
Analyzing the Impact of Heartbleed on Legacy Infrastructure

Analyzing the Impact of Heartbleed on Legacy Infrastructure

Comments
6 min read
Artifact repositories as attack surface: 17,883 JFrog Artifactory assets and the supply chain behind them

Artifact repositories as attack surface: 17,883 JFrog Artifactory assets and the supply chain behind them

1
Comments
3 min read
TLS Certificates as Corroborating Evidence on Internet-Facing FortiGate Gateways

TLS Certificates as Corroborating Evidence on Internet-Facing FortiGate Gateways

1
Comments
5 min read
The Operational Risk of a Pre-Auth Mail Flaw: CVE-2026-48842 in Context

The Operational Risk of a Pre-Auth Mail Flaw: CVE-2026-48842 in Context

1
Comments
3 min read
Two Resolvers, Two Advisories: The Unbound DNSKEY Overflow (CVE-2026-81642) and the BIND SIG(0) Crash

Two Resolvers, Two Advisories: The Unbound DNSKEY Overflow (CVE-2026-81642) and the BIND SIG(0) Crash

1
Comments
2 min read
The Exploited Zero-Day Had No CVSS Score: Reading the September 2026 Patch Tuesday by Exploitation, Not Severity

The Exploited Zero-Day Had No CVSS Score: Reading the September 2026 Patch Tuesday by Exploitation, Not Severity

Comments
3 min read
Metabase CVE-2026-72898: an unauthenticated SQL injection that hands over the data warehouse

Metabase CVE-2026-72898: an unauthenticated SQL injection that hands over the data warehouse

Comments
4 min read
Incident Readiness for CVE-2026-93952: A Tabletop Scenario for SD-WAN Teams

Incident Readiness for CVE-2026-93952: A Tabletop Scenario for SD-WAN Teams

Comments
3 min read
Check Point CVE-2026-85102 and CVE-2026-93616: Two Flaws, One Gateway, One Deadline

Check Point CVE-2026-85102 and CVE-2026-93616: Two Flaws, One Gateway, One Deadline

Comments
3 min read
9,112 Indexed Kafka Endpoints Against 1,377,501 Services on Port 9092

9,112 Indexed Kafka Endpoints Against 1,377,501 Services on Port 9092

Comments
3 min read
1,770 Matches for Cisco Secure Email Gateway: The Mail Filter That Parses What Attacks It

1,770 Matches for Cisco Secure Email Gateway: The Mail Filter That Parses What Attacks It

Comments
2 min read
4,076 Cisco ISE Fingerprint Matches: The Management Plane on the Internet

4,076 Cisco ISE Fingerprint Matches: The Management Plane on the Internet

Comments
3 min read
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

Comments
3 min read
loading...