DEV Community

OnaEiuspkz profile picture

OnaEiuspkz

Practical software developer building side projects and sharing hands‑on technical notes with the developer community.

Joined Joined on 
ISC BIND's September 2026 Patch Batch: 14 CVEs, One DNS Server, and a Wide Blast Radius

ISC BIND's September 2026 Patch Batch: 14 CVEs, One DNS Server, and a Wide Blast Radius

Comments
5 min read

Want to connect with OnaEiuspkz?

Create an account to connect with OnaEiuspkz. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Building a Patch Prioritization Rule When a Single Vendor Ships 970 Fixes in a Month

Building a Patch Prioritization Rule When a Single Vendor Ships 970 Fixes in a Month

Comments
4 min read
Logging and Detection: Why Most Breaches Are Found by Someone Else

Logging and Detection: Why Most Breaches Are Found by Someone Else

Comments 1
2 min read
Crypto Inventory Before Cryptography Change: A Practical Post-Quantum Migration Start

Crypto Inventory Before Cryptography Change: A Practical Post-Quantum Migration Start

Comments
4 min read
Measuring leaked .env configuration files on the open web

Measuring leaked .env configuration files on the open web

Comments
5 min read
ConnectWise ScreenConnect CVE-2026-84869: Remote Support Software as an Attacker Delivery Channel

ConnectWise ScreenConnect CVE-2026-84869: Remote Support Software as an Attacker Delivery Channel

Comments
3 min read
When the VPN Gateway Becomes the Foothold: Lessons from the SonicWall SMA1000 Zero-Day Chain

When the VPN Gateway Becomes the Foothold: Lessons from the SonicWall SMA1000 Zero-Day Chain

Comments
4 min read
17,881 Artifactory Instances Are Observable Online: Turning the CVE-2026-82329 KEV Deadline into a Checkable Query

17,881 Artifactory Instances Are Observable Online: Turning the CVE-2026-82329 KEV Deadline into a Checkable Query

Comments
3 min read
Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Comments
3 min read
GitLab CVE-2026-85706: Why the Patch Is Only Step One

GitLab CVE-2026-85706: Why the Patch Is Only Step One

Comments
4 min read
From Unauthenticated RCE to Ransomware: The vCenter Syslog Flaw That Reached 47 Countries

From Unauthenticated RCE to Ransomware: The vCenter Syslog Flaw That Reached 47 Countries

Comments
3 min read
The September 2026 KEV Wave: Reading Exposure Across Six Exploited Products

The September 2026 KEV Wave: Reading Exposure Across Six Exploited Products

Comments
4 min read
9,941 Reachable N-central Interfaces: Sizing the RMM Surface Behind CVE-2026-86218

9,941 Reachable N-central Interfaces: Sizing the RMM Surface Behind CVE-2026-86218

Comments
4 min read
Securing Check Point Security Management and Log Servers Against CVE-2026-91843

Securing Check Point Security Management and Log Servers Against CVE-2026-91843

Comments
1 min read
Measuring the MikroTik Attack Surface Behind the MikroTrick Campaign

Measuring the MikroTik Attack Surface Behind the MikroTrick Campaign

Comments
3 min read
Detecting CVE-2026-86060 Exploitation Attempts in MikroTik RouterOS SSH Logs

Detecting CVE-2026-86060 Exploitation Attempts in MikroTik RouterOS SSH Logs

Comments
2 min read
SonicWall SMA 1000 Remains a Small but Critical Edge Exposure After September's KEV Additions

SonicWall SMA 1000 Remains a Small but Critical Edge Exposure After September's KEV Additions

Comments
4 min read
Reading AA26-231A as an Asset-Exposure Problem, Not a Patch Problem

Reading AA26-231A as an Asset-Exposure Problem, Not a Patch Problem

Comments
4 min read
The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter

The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter

Comments
4 min read
Redis, MySQL and PostgreSQL on the Open Internet: 529,000 Reachable Database Ports

Redis, MySQL and PostgreSQL on the Open Internet: 529,000 Reachable Database Ports

Comments
3 min read
What a resource lifetime flaw actually is, using CVE-2026-20353 as the example

What a resource lifetime flaw actually is, using CVE-2026-20353 as the example

Comments
3 min read
From path traversal to denial of service: the full CVE set behind Cisco's email gateway patch

From path traversal to denial of service: the full CVE set behind Cisco's email gateway patch

Comments
2 min read
What CVE-2026-76441 Reveals About Access Control in Email Security Appliances

What CVE-2026-76441 Reveals About Access Control in Email Security Appliances

Comments
3 min read
The September 2026 Patch Tuesday Record: What 974 CVEs Means for Triage

The September 2026 Patch Tuesday Record: What 974 CVEs Means for Triage

Comments
4 min read
174 Unauthenticated Docker Daemons: Why a Small Number Is Still Worth Acting On

174 Unauthenticated Docker Daemons: Why a Small Number Is Still Worth Acting On

Comments
3 min read
Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423

Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423

Comments
4 min read
Measuring the Check Point VPN exposure: what internet scanning shows after CVE-2026-85102 and CVE-2026-85103

Measuring the Check Point VPN exposure: what internet scanning shows after CVE-2026-85102 and CVE-2026-85103

Comments
2 min read
Exposure Check: What the Cisco Secure Firewall Patch Wave Means for Internet-Facing Edge Devices

Exposure Check: What the Cisco Secure Firewall Patch Wave Means for Internet-Facing Edge Devices

Comments
2 min read
Why Groovy Compile-Time Annotations Break the Jenkins Script Security Sandbox

Why Groovy Compile-Time Annotations Break the Jenkins Script Security Sandbox

Comments
4 min read
Finding the Exposed Controllers: Using ZoomEye to Locate Internet-Reachable EtherNet/IP Assets

Finding the Exposed Controllers: Using ZoomEye to Locate Internet-Reachable EtherNet/IP Assets

Comments
5 min read
Modbus and S7 on the Public Internet: 202,686 Reachable Industrial Ports and What They Actually Expose

Modbus and S7 on the Public Internet: 202,686 Reachable Industrial Ports and What They Actually Expose

Comments
4 min read
Stolen OAuth Tokens Outlive Password Resets: Hardening Session Material in SaaS Estates

Stolen OAuth Tokens Outlive Password Resets: Hardening Session Material in SaaS Estates

Comments
3 min read
Binding to 0.0.0.0: the design decision behind CVE-2026-87827

Binding to 0.0.0.0: the design decision behind CVE-2026-87827

Comments
2 min read
mySCADA myPRO Manager: Two Missing-Authorization Flaws in an ICS Management Platform (Operational View)

mySCADA myPRO Manager: Two Missing-Authorization Flaws in an ICS Management Platform (Operational View)

Comments
2 min read
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

Comments
4 min read
The Advisory That Was Not a Patch: Reading AA26-231A and the AI-Assisted Reconnaissance of Siemens S7 PLCs

The Advisory That Was Not a Patch: Reading AA26-231A and the AI-Assisted Reconnaissance of Siemens S7 PLCs

Comments
5 min read
How I Understand Modern AI as a Developer

How I Understand Modern AI as a Developer

2
Comments
1 min read
My First Technical Note on DEV.to

My First Technical Note on DEV.to

Comments
1 min read
loading...