What I check when a firewall rule stands in for the PeopleSoft patch
The PeopleSoft patch is the fix. The bypass changed how I verify a mitigation.
The PeopleSoft patch is the fix. The bypass changed how I verify a mitigation.
A NetScaler SAML overflow hit the KEV catalog. How I triage the precondition before relaying it.
An AI agent narrated its breach in code comments. What that changes about my endpoint hunting.
A chained Zammad zero-day, exploited in the wild and now on the KEV catalog. What I checked.
docker cp could write files outside the destination you pick and take over the host.
Unauthenticated file write on a mail gateway, a three-day KEV clock, and the workaround that holds.
A self-updating llama stack with four daily source builds, a release smoke-test gate, and measured decode numbers.
Akira actors logged in to OTP-protected VPNs because the seed itself had already been stolen.
Fake Title IX emails push an abused Zoho Assist RAT at university staff through a Google Drive lure.
Standing up a first SOC from nothing and what the green field taught me.