DEV Community

OnaEiuspkz profile picture

OnaEiuspkz

Practical software developer building side projects and sharing hands‑on technical notes with the developer community.

Joined Joined on 
Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

Comment2Shell CVE-2026-93485: An Anonymous Comment That Reaches the Server

Comments
3 min read

Want to connect with OnaEiuspkz?

Create an account to connect with OnaEiuspkz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

GitLab Self-Managed Patch Guide: Moving to 19.4.1, 19.3.3, or 19.2.7

Comments
2 min read
Inventory gaps that CVE-2026-88773 will expose in most NetScaler estates

Inventory gaps that CVE-2026-88773 will expose in most NetScaler estates

Comments
2 min read
Graylog on the Internet: 14,061 Matches on a Platform That Centralises Every Log

Graylog on the Internet: 14,061 Matches on a Platform That Centralises Every Log

1
Comments
3 min read
Reading the Three LXD Advisories Together: CVE-2026-87799 and Its btrfs Siblings

Reading the Three LXD Advisories Together: CVE-2026-87799 and Its btrfs Siblings

1
Comments
3 min read
Runtime Detection with eBPF: What Kernel-Level Telemetry Adds to Container Security

Runtime Detection with eBPF: What Kernel-Level Telemetry Adds to Container Security

1
Comments
3 min read
GlobalProtect: 1.24 million title matches against 611 application fingerprints

GlobalProtect: 1.24 million title matches against 611 application fingerprints

Comments
2 min read
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

1
Comments
2 min read
Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Comments
3 min read
Reconciling external attack surface findings with what you already own

Reconciling external attack surface findings with what you already own

1
Comments
2 min read
Remote Access Services at Internet Scale: RDP, VNC and Telnet Counts

Remote Access Services at Internet Scale: RDP, VNC and Telnet Counts

1
Comments
2 min read
2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

1
Comments 1
3 min read
Zimbra Behind a Reverse Proxy: Finding Mail Servers That Refuse to Identify Themselves

Zimbra Behind a Reverse Proxy: Finding Mail Servers That Refuse to Identify Themselves

Comments
3 min read
10,176 Siemens SIMATIC Matches and 41,591 Hosts on Port 502: Industrial Exposure in Two Views

10,176 Siemens SIMATIC Matches and 41,591 Hosts on Port 502: Industrial Exposure in Two Views

Comments
3 min read
44,076 Indexed Moodle Instances: Learning Platforms Hold More Than Course Content

44,076 Indexed Moodle Instances: Learning Platforms Hold More Than Course Content

Comments
3 min read
Healthcare Messaging at Internet Scale: 1.28 Million Mirth Connect Fingerprints

Healthcare Messaging at Internet Scale: 1.28 Million Mirth Connect Fingerprints

Comments
3 min read
Auditing OpenCTI Case Creation After CVE-2026-76822

Auditing OpenCTI Case Creation After CVE-2026-76822

Comments
2 min read
Hardening Against CVE-2026-32996: Veeam Agent Privilege Escalation in Focus

Hardening Against CVE-2026-32996: Veeam Agent Privilege Escalation in Focus

Comments
1 min read
Watching for Exploitation of the Adobe Campaign Classic Flaws While the Patch Is Pending

Watching for Exploitation of the Adobe Campaign Classic Flaws While the Patch Is Pending

Comments 1
2 min read
1,317,154 GitLab Fingerprints and Why Source Control Is a Supply Chain Target

1,317,154 GitLab Fingerprints and Why Source Control Is a Supply Chain Target

Comments
2 min read
3,028 Hosts on Port 6443: What Public Kubernetes API Servers Reveal About Cluster Control

3,028 Hosts on Port 6443: What Public Kubernetes API Servers Reveal About Cluster Control

Comments
3 min read
CVE-2026-66066: an image upload path that reads /proc/self/environ

CVE-2026-66066: an image upload path that reads /proc/self/environ

Comments
2 min read
One Key for Every PBX: The Issabel Framework Hardcoded JWT Flaw (CVE-2026-89026)

One Key for Every PBX: The Issabel Framework Hardcoded JWT Flaw (CVE-2026-89026)

Comments
2 min read
Juniper, Sophos, WatchGuard and Barracuda: reading four edge vendors together

Juniper, Sophos, WatchGuard and Barracuda: reading four edge vendors together

1
Comments
2 min read
CVE-2026-96358 and the Long Tail of Drupal Contributed Modules

CVE-2026-96358 and the Long Tail of Drupal Contributed Modules

Comments
2 min read
Reading the 9.8 Score for CVE-2026-96357 Correctly

Reading the 9.8 Score for CVE-2026-96357 Correctly

Comments
2 min read
Measuring the GitLab Attack Surface: What 1.31 Million Indexed Instances Say About Patch Urgency

Measuring the GitLab Attack Surface: What 1.31 Million Indexed Instances Say About Patch Urgency

Comments
3 min read
When a Certificate Becomes a Clue: Infrastructure Linking in the Toll Fraud Investigation

When a Certificate Becomes a Clue: Infrastructure Linking in the Toll Fraud Investigation

Comments
4 min read
Seven Days to Disconnect: What the Berlin Breach Says About Containment Speed

Seven Days to Disconnect: What the Berlin Breach Says About Containment Speed

Comments
4 min read
4,827 internet-reachable Zabbix deployments: when the monitoring system is the blind spot

4,827 internet-reachable Zabbix deployments: when the monitoring system is the blind spot

Comments
3 min read
Two Zero-Days on the VPN Gateway: SonicWall SMA1000 and the Cost of an Internet-Facing Management Interface

Two Zero-Days on the VPN Gateway: SonicWall SMA1000 and the Cost of an Internet-Facing Management Interface

Comments
3 min read
350,497 Elasticsearch Fingerprint Matches: Reading a Familiar Exposure Number Carefully

350,497 Elasticsearch Fingerprint Matches: Reading a Familiar Exposure Number Carefully

Comments
2 min read
Cloud Metadata Service Abuse: Turning SSRF Into Credentials in Modern Web Stacks

Cloud Metadata Service Abuse: Turning SSRF Into Credentials in Modern Web Stacks

Comments
2 min read
AI Gateways Are Becoming Attack Surface: Measuring Exposed LiteLLM Deployments

AI Gateways Are Becoming Attack Surface: Measuring Exposed LiteLLM Deployments

Comments
3 min read
90,626 Jupyter Notebooks Are Publicly Indexed: The Difference Between Sharing and Exposing

90,626 Jupyter Notebooks Are Publicly Indexed: The Difference Between Sharing and Exposing

Comments
2 min read
A Defender's Checklist for CVE-2026-75650 in Adobe Commerce and Magento Open Source

A Defender's Checklist for CVE-2026-75650 in Adobe Commerce and Magento Open Source

Comments
2 min read
Exchange Server Exposure: 8,471 Observed Instances and a Decade of Targeted Exploitation

Exchange Server Exposure: 8,471 Observed Instances and a Decade of Targeted Exploitation

Comments
2 min read
1,539 Jenkins Matches and 212 GitLab Matches: Measuring CI/CD Controllers as an Attack Surface

1,539 Jenkins Matches and 212 GitLab Matches: Measuring CI/CD Controllers as an Attack Surface

Comments
3 min read
What Exposure Counts Do Not Prove: A Methodology Note on the Fortinet Credential Advisory

What Exposure Counts Do Not Prove: A Methodology Note on the Fortinet Credential Advisory

Comments
5 min read
CVE-2026-76443 and the Injection Risk in Email Security Appliances

CVE-2026-76443 and the Injection Risk in Email Security Appliances

Comments
2 min read
AI Gateways on the Public Internet: 35,130 Indexed LiteLLM Endpoints and the Credentials Behind Them

AI Gateways on the Public Internet: 35,130 Indexed LiteLLM Endpoints and the Credentials Behind Them

Comments 1
3 min read
Why Exposed Build Servers Remain the Quietest Way Into a Software Supply Chain

Why Exposed Build Servers Remain the Quietest Way Into a Software Supply Chain

Comments
3 min read
Defending DIR-822A Deployments Against CVE-2026-86510 Without a Vendor Patch

Defending DIR-822A Deployments Against CVE-2026-86510 Without a Vendor Patch

Comments
2 min read
When a CVE Query Returns Zero: Interpreting ZoomEye's vul.cve Field Correctly

When a CVE Query Returns Zero: Interpreting ZoomEye's vul.cve Field Correctly

Comments
4 min read
Lessons From CVE-2026-93952: Securing SD-WAN Controllers Before the Next Zero-Day

Lessons From CVE-2026-93952: Securing SD-WAN Controllers Before the Next Zero-Day

Comments
3 min read
ISC BIND's September 2026 Patch Batch: 14 CVEs, One DNS Server, and a Wide Blast Radius

ISC BIND's September 2026 Patch Batch: 14 CVEs, One DNS Server, and a Wide Blast Radius

Comments
5 min read
Building a Patch Prioritization Rule When a Single Vendor Ships 970 Fixes in a Month

Building a Patch Prioritization Rule When a Single Vendor Ships 970 Fixes in a Month

Comments
4 min read
Logging and Detection: Why Most Breaches Are Found by Someone Else

Logging and Detection: Why Most Breaches Are Found by Someone Else

1
Comments 2
2 min read
Crypto Inventory Before Cryptography Change: A Practical Post-Quantum Migration Start

Crypto Inventory Before Cryptography Change: A Practical Post-Quantum Migration Start

Comments
4 min read
Measuring leaked .env configuration files on the open web

Measuring leaked .env configuration files on the open web

Comments
5 min read
ConnectWise ScreenConnect CVE-2026-84869: Remote Support Software as an Attacker Delivery Channel

ConnectWise ScreenConnect CVE-2026-84869: Remote Support Software as an Attacker Delivery Channel

Comments
3 min read
When the VPN Gateway Becomes the Foothold: Lessons from the SonicWall SMA1000 Zero-Day Chain

When the VPN Gateway Becomes the Foothold: Lessons from the SonicWall SMA1000 Zero-Day Chain

Comments
4 min read
17,881 Artifactory Instances Are Observable Online: Turning the CVE-2026-82329 KEV Deadline into a Checkable Query

17,881 Artifactory Instances Are Observable Online: Turning the CVE-2026-82329 KEV Deadline into a Checkable Query

Comments
3 min read
Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Comments
3 min read
GitLab CVE-2026-85706: Why the Patch Is Only Step One

GitLab CVE-2026-85706: Why the Patch Is Only Step One

Comments
4 min read
From Unauthenticated RCE to Ransomware: The vCenter Syslog Flaw That Reached 47 Countries

From Unauthenticated RCE to Ransomware: The vCenter Syslog Flaw That Reached 47 Countries

Comments
3 min read
The September 2026 KEV Wave: Reading Exposure Across Six Exploited Products

The September 2026 KEV Wave: Reading Exposure Across Six Exploited Products

Comments
4 min read
9,941 Reachable N-central Interfaces: Sizing the RMM Surface Behind CVE-2026-86218

9,941 Reachable N-central Interfaces: Sizing the RMM Surface Behind CVE-2026-86218

Comments
4 min read
Securing Check Point Security Management and Log Servers Against CVE-2026-91843

Securing Check Point Security Management and Log Servers Against CVE-2026-91843

Comments
1 min read
Measuring the MikroTik Attack Surface Behind the MikroTrick Campaign

Measuring the MikroTik Attack Surface Behind the MikroTrick Campaign

Comments
3 min read
loading...