A long-standing flaw in Apache Struts lets unauthenticated attackers run commands on the server by abusing the method: prefix when Dynamic Method Invocation is switched on.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
ISC BIND Data Processing Errors Vulnerability
A single crafted TKEY query can crash the BIND named daemon on unpatched 9.9.x and 9.10.x servers, knocking out DNS resolution or authority with no login required.
ONLYOFFICE Docs Server Path Traversal Vulnerability
A directory traversal bug in ONLYOFFICE Document Server’s upload endpoint lets a remote, unauthenticated attacker write files outside the upload folder and potentially run code on the host.
ProFTPD Improper Access Control Vulnerability
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Listed in CISA KEV …
Strapi Cleartext Storage of Sensitive Information Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The …
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
An unauthenticated, network-reachable flaw in NetScaler ADC and Gateway lets attackers crash or disrupt the appliance without logging in, and it’s already listed as exploited in the wild.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.