DEV Community

jeffrey profile picture

jeffrey

Full-stack developer, love building side projects, write about what I learn, and connect with fellow coders.

Joined Joined on 
1,316,357 GitLab Matches and 456,436 Title Matches: Sizing a Self-Managed Code Host

1,316,357 GitLab Matches and 456,436 Title Matches: Sizing a Self-Managed Code Host

Comments
3 min read

Want to connect with jeffrey?

Create an account to connect with jeffrey. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Audiobookshelf: no app fingerprint and 13,963 title matches

Audiobookshelf: no app fingerprint and 13,963 title matches

Comments
2 min read
1538 Jenkins, 169 Harbor and 32 SonarQube Results: The Build Chain Has a Public Address

1538 Jenkins, 169 Harbor and 32 SonarQube Results: The Build Chain Has a Public Address

Comments
4 min read
Why Port 2375 Alone Overstates the Docker Problem

Why Port 2375 Alone Overstates the Docker Problem

Comments
2 min read
29,151,855 Matches on Port 5060: The Signalling Layer Nobody Maps

29,151,855 Matches on Port 5060: The Signalling Layer Nobody Maps

Comments
2 min read
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed

Comments
2 min read
603,475 Grafana and 77,968 Kibana Instances: Measuring the Observability Layer's Public Surface

603,475 Grafana and 77,968 Kibana Instances: Measuring the Observability Layer's Public Surface

Comments 1
3 min read
CVE-2026-70585: A Use-After-Free in the Windows NFS Client Stack

CVE-2026-70585: A Use-After-Free in the Windows NFS Client Stack

Comments
3 min read
Zabbix at 4,861 Matches: A Monitoring Frontend With Real Credentials Behind It

Zabbix at 4,861 Matches: A Monitoring Frontend With Real Credentials Behind It

Comments
2 min read
Four libxml2 Flaws, One Release: Why 2.15.4 Matters Beyond the Library Itself

Four libxml2 Flaws, One Release: Why 2.15.4 Matters Beyond the Library Itself

Comments
3 min read
What CVE-2026-84411 says about trusting perimeter assumptions on network devices

What CVE-2026-84411 says about trusting perimeter assumptions on network devices

Comments
2 min read
CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

Comments
2 min read
Detection engineering for CVE-2026-100382: hunting the External Data web shell

Detection engineering for CVE-2026-100382: hunting the External Data web shell

Comments
3 min read
Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link

Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link

Comments
4 min read
Request Smuggling in the ASGI Stack: Starlette and LiteLLM

Request Smuggling in the ASGI Stack: Starlette and LiteLLM

Comments
3 min read
A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments

A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments

Comments
2 min read
Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Comments
3 min read
Detection and verification limits for CVE-2026-96364 on a live Drupal estate

Detection and verification limits for CVE-2026-96364 on a live Drupal estate

Comments
3 min read
Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind

Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind

Comments
3 min read
WordPress CVE-2026-87902: an Unauthenticated Path Traversal That Escalates into Remote Code Execution

WordPress CVE-2026-87902: an Unauthenticated Path Traversal That Escalates into Remote Code Execution

Comments
3 min read
Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122

Comments
2 min read
What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows

What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows

Comments
3 min read
The Five-Month Gap: Zimbra Exposure Between Zero-Day Exploitation and Public Disclosure

The Five-Month Gap: Zimbra Exposure Between Zero-Day Exploitation and Public Disclosure

Comments
3 min read
OpenMediaVault: 123,886 title matches beside four fingerprints

OpenMediaVault: 123,886 title matches beside four fingerprints

Comments
3 min read
Rundeck on 4,729 hosts: a job scheduler that holds the credentials to run them

Rundeck on 4,729 hosts: a job scheduler that holds the credentials to run them

Comments
3 min read
Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

Comments
3 min read
What Click2Shell Teaches About Reporting a Parser Discrepancy

What Click2Shell Teaches About Reporting a Parser Discrepancy

Comments
2 min read
Shared and Managed Fortinet Estates: Whose Gateway Is It When Credentials Leak?

Shared and Managed Fortinet Estates: Whose Gateway Is It When Credentials Leak?

Comments
6 min read
CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators

CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators

1
Comments
3 min read
1,160,264 Mosquitto fingerprints: the MQTT broker that ends up on the public internet

1,160,264 Mosquitto fingerprints: the MQTT broker that ends up on the public internet

Comments
2 min read
F5 BIG-IP management interfaces: 1.58 million fingerprint matches and 55,390 on 443

F5 BIG-IP management interfaces: 1.58 million fingerprint matches and 55,390 on 443

1
Comments
2 min read
LXD Backup Import as an Attack Surface: CVE-2026-87799 and the btrfs Restore Path

LXD Backup Import as an Attack Surface: CVE-2026-87799 and the btrfs Restore Path

1
Comments
2 min read
Internet-Exposed Drupal Sites and the September 2026 Extension Advisory

Internet-Exposed Drupal Sites and the September 2026 Extension Advisory

Comments
3 min read
Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774

Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774

Comments
3 min read
1,890,595 MongoDB Service Matches: The Default-Configuration Problem at Internet Scale

1,890,595 MongoDB Service Matches: The Default-Configuration Problem at Internet Scale

1
Comments
2 min read
Browser extensions are an enterprise control problem, not a user hygiene problem

Browser extensions are an enterprise control problem, not a user hygiene problem

1
Comments
4 min read
DMARC aggregate reports as infrastructure change detection

DMARC aggregate reports as infrastructure change detection

1
Comments
2 min read
Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Comments
2 min read
Mapping CVE-2026-96361 to the Drupal Projects You Actually Run

Mapping CVE-2026-96361 to the Drupal Projects You Actually Run

1
Comments
2 min read
From Facebook Ad to Phone Bill: How the Android Toll Fraud Campaign Reached Victims

From Facebook Ad to Phone Bill: How the Android Toll Fraud Campaign Reached Victims

Comments
6 min read
CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

Comments
3 min read
Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday

Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday

Comments
4 min read
15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

Comments
2 min read
Dagster: 1,712 Title Matches and a Zero Fingerprint

Dagster: 1,712 Title Matches and a Zero Fingerprint

Comments
3 min read
OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

Comments
2 min read
Temporal at 1,992 Title Matches and 200 Application Fingerprints

Temporal at 1,992 Title Matches and 200 Application Fingerprints

1
Comments
3 min read
2590 MongoDB, 1469 Memcached and 387 CouchDB Results: Three Data Stores With Three Default Postures

2590 MongoDB, 1469 Memcached and 387 CouchDB Results: Three Data Stores With Three Default Postures

1
Comments
4 min read
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

1
Comments
4 min read
HDFS Web Interfaces: 24,511 Fingerprint Matches and 1,602,200 Answers on Port 9870

HDFS Web Interfaces: 24,511 Fingerprint Matches and 1,602,200 Answers on Port 9870

Comments 1
3 min read
CVE-2026-89078: What the Advisory Says and What It Does Not

CVE-2026-89078: What the Advisory Says and What It Does Not

Comments
2 min read
2,857,655 RouterOS Matches and 830,366 With SSH: Turning an Edge Device Baseline Into a Decision

2,857,655 RouterOS Matches and 830,366 With SSH: Turning an Edge Device Baseline Into a Decision

Comments 2
3 min read
CVE-2026-76442 and the Cost of an Unbounded Number in Cisco Secure Email Gateway

CVE-2026-76442 and the Cost of an Unbounded Number in Cisco Secure Email Gateway

Comments 1
3 min read
Public Exploit Code and No Patch: The D-Link DIR-822A L2TP Flaw in Context

Public Exploit Code and No Patch: The D-Link DIR-822A L2TP Flaw in Context

Comments 1
2 min read
Detecting and monitoring around CVE-2026-96360

Detecting and monitoring around CVE-2026-96360

Comments 1
2 min read
Replacing standing administrative access with brokered sessions

Replacing standing administrative access with brokered sessions

Comments
2 min read
Database Backups Are an Identity Problem Before They Are a Storage Problem

Database Backups Are an Identity Problem Before They Are a Storage Problem

Comments
4 min read
Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Comments
2 min read
CVE-2026-76441: Improper Access Control in Cisco Secure Email Gateway Exposes Restricted Functions

CVE-2026-76441: Improper Access Control in Cisco Secure Email Gateway Exposes Restricted Functions

Comments 1
4 min read
Exploitation Conditions in CVE-2026-75682: What a Low-Privileged Account Buys an Attacker

Exploitation Conditions in CVE-2026-75682: What a Low-Privileged Account Buys an Attacker

Comments 1
3 min read
CVE-2026-53266 Triage Guide: What the CISA KEV Listing Changes for Linux Kernel Patching

CVE-2026-53266 Triage Guide: What the CISA KEV Listing Changes for Linux Kernel Patching

Comments 1
3 min read
loading...