A maximum-severity flaw in Microsoft Entra ID lets an attacker execute code over the network with no credentials or user interaction, and it is already being exploited.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
An unauthenticated attacker can send a crafted SMTP request to Zimbra Collaboration Suite and run operating system commands as the Zimbra user, with active exploitation already confirmed.
TrueConf Server Code Injection Vulnerability
An unauthenticated attacker reaching TrueConf Server’s port 4307/TCP can send a crafted script that escapes the server’s sandboxed execution and runs arbitrary code on the host, and it’s already being exploited.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server exposes a critical function on port 4307/TCP with no authentication check, letting a remote attacker run arbitrary scripts without credentials or user interaction.
MLflow Server-Side Request Forgery Vulnerability
An unauthenticated attacker can make MLflow fetch internal URLs or cloud metadata endpoints and hand back the response, exposing credentials or config from systems behind it.
Apple macOS Improper Authentication Vulnerability
A flaw in macOS Screen Sharing lets a network attacker log in without a password, and CISA confirms it’s already being used in attacks against unpatched Macs.
From the workshop
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.
Running image and speech generation at home
What a single consumer GPU can and cannot do for image, video and voice generation, and why the licence on a model matters more than its benchmark scores.