PinnedPublished inInfoSec Write-upsBurn It With Fire: How to Eliminate an Industry-Wide Supply Chain VulnerabilityThe supply chain bug that couldn’t be ignored — so I torched it.Jul 2A response icon1Jul 2A response icon1
PinnedPublished inInfoSec Write-upsWhen Open Source Isn’t: How OpenRewrite Lost Its WayModerne quietly relicensed community-contributed OpenRewrite code from Apache 2.0 to a proprietary license.May 14A response icon5May 14A response icon5
PinnedPublished inInfoSec Write-ups5 Years, 160 Comments, and the Vulnerability That Refused to DieHow a 5-year-old deserialization flaw, a vacation phone call, and some persistence led to a safer Java ecosystemJun 6A response icon1Jun 6A response icon1
PinnedPublished inInfoSec Write-upsZoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!Vulnerability in the Mac Zoom Client allows any malicious website to enable your camera without your permission. The flaw potentially…Jul 8, 2019A response icon107Jul 8, 2019A response icon107
Published inInfoSec Write-upsThe CVE CNA 72 Hour Rules are InsaneThe bureaucracy of the CVE system continues to frustrate me. Next up: the publicly disclosed vulnerability 72 hour rule!Sep 15Sep 15
Published inInfoSec Write-upsWhat’s an OSS Vulnerability Janitor?What does it take to sweep up after the industries security vulnerabilities that have been left unpatched or undisclosed?Jul 31Jul 31
Falsehoods People Believe about CVE’sCVE ≠ Vulnerability (And 35 Other Confusions Regarding CVE)Apr 14A response icon1Apr 14A response icon1
You may want to be careful with your choice of `wkhtmltopdf`.https://wkhtmltopdf.org/status.htmlJul 8, 2024Jul 8, 2024
Published inInfoSec Write-upsUpdate: Want to take over the Java ecosystem? All you need is a MITM!January 13th-15th, 2020 will break over 21% of the industry’s Java build infrastructure. Six months since my initial article disclosing…Jan 8, 2020Jan 8, 2020
Need MDNS? Just Install iTunesOver 6 years ago I was working on a small project called WPILib. WPILib is a library used by High School FIRST Robotics teams to program…Oct 9, 2019Oct 9, 2019