An unauthenticated attacker can send a single crafted email to a Cisco Secure Email Gateway and gain root control of the appliance through a SQL injection flaw in its message-parsing logic.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Cisco IOS XR Software Security Hardening Release: September 2026
A single Cisco advisory bundles seven internally-found IOS XR flaws by weakness class, two of them unauthenticated and remotely exploitable for full device compromise, with fixes spread across dozens of per-train SMUs.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
A flaw in ScreenConnect client software lets an attacker inside an active remote support session push files to the host and run them without the usual confirmation prompt.
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing …
JFrog Artifactory Improper Authentication Vulnerability
Artifactory can hand an unauthenticated caller a valid anonymous-user token even after anonymous access has been switched off, letting anyone who can reach it read sensitive artefacts.
JFrog Artifactory Incorrect Authorization Vulnerability
Artifactory checks a token’s signature and issuer but not its scope, letting a low-privilege token holder escalate to actions the token was never meant to permit.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.