An unauthenticated attacker can run arbitrary commands on NetScaler ADC and Gateway devices below the listed fixed builds, and CISA confirms this is already being exploited in the wild.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
An unauthenticated, network-reachable memory buffer flaw in NetScaler ADC and Gateway can crash the appliance or let an attacker run code on it, and it’s already being exploited in the wild.
Microsoft SharePoint Code Injection Vulnerability
A logged-in SharePoint user with only basic privileges can send a crafted request that triggers code execution on the server, and attackers are already doing this.
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This …
WordPress Core Remote File Inclusion Vulnerability
An unauthenticated attacker can trick WordPress’s page-template lookup into loading a readable PHP file from outside the active theme, potentially leading to remote code execution on the server.
Adobe Commerce and Magento Incorrect Authorization Vulnerability
An unauthenticated attacker can bypass an authorization check in Adobe Commerce and Magento to read or alter sensitive data, no login or user action needed, and it’s already being exploited.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.