Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
vulnerabilitymanagement
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain
yutianle
yutianle
yutianle
Follow
Oct 3
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain
#
pathtraversal
#
devsecops
#
credentialexposure
#
vulnerabilitymanagement
Comments
Add Comment
4 min read
The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation
kozhevniko
kozhevniko
kozhevniko
Follow
Oct 3
The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation
#
security
#
applicationsecurity
#
vulnerabilitymanagement
Comments
Add Comment
3 min read
Penetration Test Findings That Never Get Fixed: Running a Retest Programme
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 30
Penetration Test Findings That Never Get Fixed: Running a Retest Programme
#
security
#
vulnerabilitymanagement
#
governance
Comments
Add Comment
2 min read
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint
StarkMan
StarkMan
StarkMan
Follow
Sep 30
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint
#
security
#
supplychain
#
vulnerabilitymanagement
Comments
Add Comment
3 min read
When the AI Gateway Becomes the Weakest Link: Command Execution in LiteLLM's MCP Test Endpoints
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 30
When the AI Gateway Becomes the Weakest Link: Command Execution in LiteLLM's MCP Test Endpoints
#
cybersecurity
#
aiinfrastructure
#
vulnerabilitymanagement
#
litellm
Comments
Add Comment
4 min read
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route
jeffrey
jeffrey
jeffrey
Follow
Sep 29
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route
#
vulnerabilitymanagement
#
kestra
#
commandinjection
#
cve202649869
1
 reaction
Comments
Add Comment
4 min read
A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways
yutianle
yutianle
yutianle
Follow
Sep 25
A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways
#
security
#
aisecurity
#
vulnerabilitymanagement
Comments
Add Comment
4 min read
Edge Appliance Zero-Days: What the SonicWall SMA1000 Chain Teaches About Patch Windows
jeffrey
jeffrey
jeffrey
Follow
Sep 21
Edge Appliance Zero-Days: What the SonicWall SMA1000 Chain Teaches About Patch Windows
#
vulnerabilitymanagement
#
edgesecurity
#
ssrf
#
commandinjection
Comments
Add Comment
4 min read
The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 21
The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders
#
security
#
vulnerabilitymanagement
#
networksecurity
#
exploitedinthewild
Comments
Add Comment
4 min read
Extended Support Isn't Extended Security: Managing Vulnerabilities in ELS Linux Environments
Ayush Singh
Ayush Singh
Ayush Singh
Follow
Sep 20
Extended Support Isn't Extended Security: Managing Vulnerabilities in ELS Linux Environments
#
cybersecurity
#
infosec
#
linux
#
vulnerabilitymanagement
5
 reactions
Comments
Add Comment
7 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
jeffrey
jeffrey
jeffrey
Follow
Sep 20
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
#
vulnerabilitymanagement
#
msp
#
rmm
#
supplychain
Comments
Add Comment
3 min read
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento
StarkMan
StarkMan
StarkMan
Follow
Sep 19
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento
#
cybersecurity
#
ecommercesecurity
#
vulnerabilitymanagement
Comments
Add Comment
3 min read
The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter
OnaEiuspkz
OnaEiuspkz
OnaEiuspkz
Follow
Sep 19
The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter
#
cybersecurity
#
vulnerabilitymanagement
#
networksecurity
Comments
Add Comment
4 min read
Using CISA KEV Deadlines as a Triage Clock for Vulnerability Backlogs
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 18
Using CISA KEV Deadlines as a Triage Clock for Vulnerability Backlogs
#
security
#
vulnerabilitymanagement
Comments
Add Comment
2 min read
Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call
StarkMan
StarkMan
StarkMan
Follow
Sep 18
Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call
#
cisa
#
vulnerabilitymanagement
#
securebydesign
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account