Two things live here.

Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.

The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.

Latest advisories

TrueConf Server Code Injection Vulnerability

An unauthenticated attacker reaching TrueConf Server’s port 4307/TCP can send a crafted script that escapes the server’s sandboxed execution and runs arbitrary code on the host, and it’s already being exploited.

Read more →

All 152 advisories →

From the workshop

All posts →