An unauthenticated attacker can reach on-prem VeloCloud Orchestrator over the network and gain privileged access to the host, putting the whole SD-WAN management plane at risk.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Check Point Multiple Products Improper Certificate Validation Vulnerability
A flawed certificate check during VPN handshakes on Check Point Security Gateway and Spark Firewall lets an unauthenticated attacker on the network run arbitrary code on the Gateway itself.
Check Point Multiple Products Path Traversal Vulnerability
An unauthenticated attacker can abuse a directory traversal flaw in Check Point’s management servers and SmartEvent to upload and run arbitrary scripts, with no login or user action required.
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
An unauthenticated, network-reachable heap overflow in BIG-IP APM lets attackers achieve remote code execution on any virtual server combining an access policy with an OAuth profile.
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute …
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
A logic gap in the Linux kernel’s kTLS receive path lets a zero-length record on the rx_list slip past type checks, corrupting zero-copy and queuing assumptions for later records.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.