DEV Community

yutianle profile picture

yutianle

404 bio not found

Joined Joined on 
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Comments
2 min read

Want to connect with yutianle?

Create an account to connect with yutianle. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Twenty Wormable Bugs in One Patch Tuesday: What the September 2026 Microsoft Release Tells Us

Twenty Wormable Bugs in One Patch Tuesday: What the September 2026 Microsoft Release Tells Us

Comments 1
3 min read
Drupal Contributed Modules Under WID-SEC-2026-3554: A Patching Plan for CVE-2026-96359 and the Wider Batch

Drupal Contributed Modules Under WID-SEC-2026-3554: A Patching Plan for CVE-2026-96359 and the Wider Batch

1
Comments
3 min read
Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Comments
4 min read
Cisco FMC CVE-2026-20079: When the Management Plane Is the Attack Plane

Cisco FMC CVE-2026-20079: When the Management Plane Is the Attack Plane

Comments
4 min read
Clock synchronisation as a forensic prerequisite

Clock synchronisation as a forensic prerequisite

Comments
2 min read
Gerrit Code Review on the Open Internet: 2,508 Title Matches and the Credential Store Behind Them

Gerrit Code Review on the Open Internet: 2,508 Title Matches and the Credential Store Behind Them

Comments
2 min read
Detecting unexpected custom attributes after CVE-2026-96367

Detecting unexpected custom attributes after CVE-2026-96367

1
Comments
2 min read
CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

Comments
3 min read
981,494 FortiGate Fingerprints and 16.4 Million RDP Services: Measuring the Gunra Initial-Access Surface

981,494 FortiGate Fingerprints and 16.4 Million RDP Services: Measuring the Gunra Initial-Access Surface

Comments
3 min read
CVE-2026-26084: the sandbox appliance that answers questions it should refuse

CVE-2026-26084: the sandbox appliance that answers questions it should refuse

Comments 1
3 min read
What port 2375 says about Docker exposure that a product fingerprint does not

What port 2375 says about Docker exposure that a product fingerprint does not

Comments 1
3 min read
Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem

Comments 1
3 min read
From Patch Tuesday to KEV in Three Weeks: The CVE-2026-19490 NetScaler Timeline

From Patch Tuesday to KEV in Three Weeks: The CVE-2026-19490 NetScaler Timeline

Comments
3 min read
RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060

RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060

Comments
2 min read
Mapping VeloCloud Orchestrator Exposure: What ZoomEye Data Says About CVE-2026-93952

Mapping VeloCloud Orchestrator Exposure: What ZoomEye Data Says About CVE-2026-93952

Comments
2 min read
What CERT-BUND Published About CVE-2026-96361 and What the Record Leaves Open

What CERT-BUND Published About CVE-2026-96361 and What the Record Leaves Open

Comments
2 min read
414,009 ESXi hosts and 1,495,455 answers on port 902: sizing a hypervisor estate from outside

414,009 ESXi hosts and 1,495,455 answers on port 902: sizing a hypervisor estate from outside

Comments 1
3 min read
Adobe Connect 12.12: Why a 9.9 SQL Injection Deserves Its Own Patch Window

Adobe Connect 12.12: Why a 9.9 SQL Injection Deserves Its Own Patch Window

Comments 1
4 min read
Shared Hosting and CVE-2026-48842: When One Mail Server Holds Every Tenant

Shared Hosting and CVE-2026-48842: When One Mail Server Holds Every Tenant

Comments 1
3 min read
MISP Feed Redirects Before 2.5.45: When an Outbound Request Carries Credentials to Another Host

MISP Feed Redirects Before 2.5.45: When an Outbound Request Carries Credentials to Another Host

1
Comments
3 min read
132,707 Magento Matches and 5,314 Title Matches: Measuring a Commerce Platform Under Active Exploitation

132,707 Magento Matches and 5,314 Title Matches: Measuring a Commerce Platform Under Active Exploitation

1
Comments
3 min read
CVE-2026-76461: SQL injection in an email gateway reaches root on the appliance

CVE-2026-76461: SQL injection in an email gateway reaches root on the appliance

1
Comments
2 min read
73,105 Airflow instances, 11,673 SonarQube and 33,837 Nexus: fingerprinting the build and quality toolchain

73,105 Airflow instances, 11,673 SonarQube and 33,837 Nexus: fingerprinting the build and quality toolchain

Comments
3 min read
From Java Byte Stream to Root: Cisco ISE Remote Code Execution Flaws

From Java Byte Stream to Root: Cisco ISE Remote Code Execution Flaws

Comments
2 min read
CVE-2026-69676: Kerberos Authentication Bypass by Capture-Replay

CVE-2026-69676: Kerberos Authentication Bypass by Capture-Replay

Comments
2 min read
Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Authorization at the Object Level: Testing for BOLA Before Someone Else Does

Comments
4 min read
From OAuth Profile to Root: Tracing the CVE-2026-94127 Attack Path in F5 BIG-IP APM

From OAuth Profile to Root: Tracing the CVE-2026-94127 Attack Path in F5 BIG-IP APM

Comments
3 min read
A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

Comments
4 min read
Credentials in the Agent's Reach: The Codex Memory-Sharing Issue

Credentials in the Agent's Reach: The Codex Memory-Sharing Issue

1
Comments 1
3 min read
Cisco Secure Email Gateway Injection Bug CVE-2026-76443: What Administrators Should Do First

Cisco Secure Email Gateway Injection Bug CVE-2026-76443: What Administrators Should Do First

Comments
2 min read
The Virtualization Control Plane Is on the Internet: 414,092 ESXi and 140,746 Proxmox VE Fingerprints

The Virtualization Control Plane Is on the Internet: 414,092 ESXi and 140,746 Proxmox VE Fingerprints

Comments
4 min read
Ports and Services: Why FortiGate Exposure Numbers Depend on the Question You Ask

Ports and Services: Why FortiGate Exposure Numbers Depend on the Question You Ask

Comments
5 min read
Sizing Linux Kernel Exposure for CVE-2026-53266: Why Asset Inventory Beats a CVE Search

Sizing Linux Kernel Exposure for CVE-2026-53266: Why Asset Inventory Beats a CVE Search

1
Comments 1
3 min read
Arista VeloCloud Orchestrator CVE-2026-93952: Why the SD-WAN Control Plane Is a High-Value Target

Arista VeloCloud Orchestrator CVE-2026-93952: Why the SD-WAN Control Plane Is a High-Value Target

Comments
3 min read
161,907 Hosts on Port 102 and 173 Siemens S7 Fingerprints: Reading Two Numbers From the Same Internet

161,907 Hosts on Port 102 and 173 Siemens S7 Fingerprints: Reading Two Numbers From the Same Internet

Comments
4 min read
336 N-able Matches, 93,431 ScreenConnect Matches and 183 Conductor Matches: Measuring the Managed Services Layer

336 N-able Matches, 93,431 ScreenConnect Matches and 183 Conductor Matches: Measuring the Managed Services Layer

Comments
3 min read
Cisco Identity Services Engine CVE-2026-76460: When the Policy Engine Uses Privileged APIs Incorrectly

Cisco Identity Services Engine CVE-2026-76460: When the Policy Engine Uses Privileged APIs Incorrectly

Comments
3 min read
Patching BIND Without an Outage: A Practical Plan for CIVN-2026-0467

Patching BIND Without an Outage: A Practical Plan for CIVN-2026-0467

Comments
3 min read
Sanitization Leaves Traces: What Exposed AI Gateway Panels Reveal About Their Operators After AA26-251A

Sanitization Leaves Traces: What Exposed AI Gateway Panels Reveal About Their Operators After AA26-251A

Comments
1 min read
14,913 Kubernetes Dashboard Matches: Why the Management UI Is the Wrong Thing to Expose

14,913 Kubernetes Dashboard Matches: Why the Management UI Is the Wrong Thing to Expose

Comments
2 min read
Two Bugs and an Exposed SSH Port: The MikroTik RouterOS MikroTrick Chain

Two Bugs and an Exposed SSH Port: The MikroTik RouterOS MikroTrick Chain

Comments
3 min read
D-Link DIR-822A Routers Expose Critical DHCP and L2TP Flaws With Public PoC

D-Link DIR-822A Routers Expose Critical DHCP and L2TP Flaws With Public PoC

Comments
2 min read
When the Access Controller Is the Target: Reading Cisco ISE CVE-2026-76460

When the Access Controller Is the Target: Reading Cisco ISE CVE-2026-76460

Comments
3 min read
1659 MQTT, 2503 InfluxDB and 45150 ClickHouse Results: The Data Pipeline Layer

1659 MQTT, 2503 InfluxDB and 45150 ClickHouse Results: The Data Pipeline Layer

Comments
4 min read
Rolling out phishing-resistant multi-factor authentication

Rolling out phishing-resistant multi-factor authentication

Comments
5 min read
Prioritizing zero-day patching when you cannot patch everything

Prioritizing zero-day patching when you cannot patch everything

Comments
5 min read
CVE-2026-81657: Assessing Risk in IBM Guardium Data Protection Deployments

CVE-2026-81657: Assessing Risk in IBM Guardium Data Protection Deployments

Comments
2 min read
NetScaler and the SAML Bypass: Measuring Gateway Exposure with ZoomEye

NetScaler and the SAML Bypass: Measuring Gateway Exposure with ZoomEye

Comments
4 min read
Ransomware Incident-Response Hardening: A Practical Playbook for Defenders

Ransomware Incident-Response Hardening: A Practical Playbook for Defenders

Comments
4 min read
Industrial Protocols on the Open Internet: A ZoomEye Measurement of Modbus and EtherNet/IP

Industrial Protocols on the Open Internet: A ZoomEye Measurement of Modbus and EtherNet/IP

Comments
3 min read
What 1,817 Exposed TeamCity Servers Say About CI/CD as an Attack Target

What 1,817 Exposed TeamCity Servers Say About CI/CD as an Attack Target

Comments
3 min read
Why the Cisco FMC Attack Surface Is Hard to See From Outside

Why the Cisco FMC Attack Surface Is Hard to See From Outside

Comments
4 min read
Cisco Secure Firewall Management Center sftunnel Flaw (CVE-2026-20324) Explained

Cisco Secure Firewall Management Center sftunnel Flaw (CVE-2026-20324) Explained

Comments
2 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
PivotC2 on 178 FortiGate Devices: Why Edge Appliances Are the Quietest Place to Hide

PivotC2 on 178 FortiGate Devices: Why Edge Appliances Are the Quietest Place to Hide

Comments
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

Comments
4 min read
The Wider Adobe Patch Wave Behind CVE-2026-75650

The Wider Adobe Patch Wave Behind CVE-2026-75650

Comments
3 min read
How Many MikroTik Devices Are Actually Reachable From the Internet?

How Many MikroTik Devices Are Actually Reachable From the Internet?

Comments
3 min read
Reading a 1.2 Million PaperCut Fingerprint Count Correctly

Reading a 1.2 Million PaperCut Fingerprint Count Correctly

Comments
3 min read
loading...