DEV Community

StarkMan profile picture

StarkMan

404 bio not found

Joined Joined on 
Identity Is Now the Perimeter: Lessons From Credential-Based Intrusions

Identity Is Now the Perimeter: Lessons From Credential-Based Intrusions

Comments
2 min read

Want to connect with StarkMan?

Create an account to connect with StarkMan. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Measuring internet-exposed RDP surface and what it means for defenders

Measuring internet-exposed RDP surface and what it means for defenders

Comments
5 min read
Internet-Exposed Jenkins Controllers: Measuring a Persistent Attack Surface

Internet-Exposed Jenkins Controllers: Measuring a Persistent Attack Surface

Comments
3 min read
Grafana at Internet Scale: What 603,659 Exposed Instances Tell Us About Observability Security

Grafana at Internet Scale: What 603,659 Exposed Instances Tell Us About Observability Security

Comments
2 min read
Finding Codex Deployments After the Sandbox Escape Disclosures

Finding Codex Deployments After the Sandbox Escape Disclosures

Comments
3 min read
Mapping the Reachable Apple Surface: What ZoomEye Sees That an MDM Console Does Not

Mapping the Reachable Apple Surface: What ZoomEye Sees That an MDM Console Does Not

Comments
3 min read
Why the Cisco Secure Email Hardening Release Matters More Than One CVE

Why the Cisco Secure Email Hardening Release Matters More Than One CVE

Comments
2 min read
CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins for cPanel, WHM and Plesk

CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins for cPanel, WHM and Plesk

Comments
4 min read
1,551 Elasticsearch and 1,462 Memcached Endpoints: Two Cache Layers With Different Defaults

1,551 Elasticsearch and 1,462 Memcached Endpoints: Two Cache Layers With Different Defaults

Comments
3 min read
Port 6443 in the Wild: Measuring Public Kubernetes API Endpoint Exposure

Port 6443 in the Wild: Measuring Public Kubernetes API Endpoint Exposure

Comments
7 min read
Your AI Gateway Is an Identity Boundary: The LiteLLM MCP Authentication Bypass

Your AI Gateway Is an Identity Boundary: The LiteLLM MCP Authentication Bypass

1
Comments
3 min read
Detecting and Containing CVE-2026-20344: A Monitoring Plan for Cisco FMC SQL Injection

Detecting and Containing CVE-2026-20344: A Monitoring Plan for Cisco FMC SQL Injection

Comments
3 min read
CVE-2026-76460: Maximum-Severity Cisco ISE Authentication Bypass Under Active Exploitation

CVE-2026-76460: Maximum-Severity Cisco ISE Authentication Bypass Under Active Exploitation

Comments
3 min read
Sizing Self-Managed GitLab Exposure After CVE-2026-85706

Sizing Self-Managed GitLab Exposure After CVE-2026-85706

Comments
3 min read
Measuring the SonicWall Edge: 15,608 WorkPlace Interfaces and the Limits of That Number

Measuring the SonicWall Edge: 15,608 WorkPlace Interfaces and the Limits of That Number

Comments
3 min read
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

Comments
3 min read
Reading the Anthropic Threat Intelligence Report as a Defenders' Checklist, Not a News Cycle

Reading the Anthropic Threat Intelligence Report as a Defenders' Checklist, Not a News Cycle

Comments
3 min read
Patching Guide for CVE-2026-75650: Closing the Adobe Commerce RCE

Patching Guide for CVE-2026-75650: Closing the Adobe Commerce RCE

Comments
3 min read
MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication

MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication

Comments
2 min read
Default Credentials Are Still the Front Door: Reading the 2026 IoT Botnet Notices as an Asset Management Problem

Default Credentials Are Still the Front Door: Reading the 2026 IoT Botnet Notices as an Asset Management Problem

Comments
4 min read
DevOps and Data Platforms on the Open Internet: A ZoomEye Exposure Review

DevOps and Data Platforms on the Open Internet: A ZoomEye Exposure Review

Comments
3 min read
Proxmox VE 7 and the Authentication Bypass That Was Fixed by Accident in 2023

Proxmox VE 7 and the Authentication Bypass That Was Fixed by Accident in 2023

Comments
4 min read
Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call

Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call

Comments
3 min read
Virtual Patching for Edge Devices: When Firmware Fixes Arrive Too Slowly

Virtual Patching for Edge Devices: When Firmware Fixes Arrive Too Slowly

Comments
3 min read
MikroTrick: How Two SSH Flaws Let Attackers Take Over MikroTik Routers Without Credentials

MikroTrick: How Two SSH Flaws Let Attackers Take Over MikroTik Routers Without Credentials

Comments
4 min read
Unauthenticated access flaws in Cisco Secure Email Gateway: a defender's read of CVE-2026-76440

Unauthenticated access flaws in Cisco Secure Email Gateway: a defender's read of CVE-2026-76440

Comments
2 min read
Prioritising the Cisco ISE Fixes: A Remediation Order for CVE-2026-76423 and Its Siblings

Prioritising the Cisco ISE Fixes: A Remediation Order for CVE-2026-76423 and Its Siblings

Comments
4 min read
Hardening Jenkins After the September 2026 Plugin Advisory: A Practical Guide

Hardening Jenkins After the September 2026 Plugin Advisory: A Practical Guide

Comments
4 min read
Patching the Check Point VPN flaws: a prioritized response plan for CVE-2026-85102 and CVE-2026-85103

Patching the Check Point VPN flaws: a prioritized response plan for CVE-2026-85102 and CVE-2026-85103

Comments
2 min read
Cisco Emergency Bundle Fixes 18 Secure Firewall Flaws Including sftunnel Root RCE

Cisco Emergency Bundle Fixes 18 Secure Firewall Flaws Including sftunnel Root RCE

Comments
3 min read
Sizing the Industrial Control Surface: What 41,601 Reachable EtherNet/IP Endpoints Tell Us About OT Exposure

Sizing the Industrial Control Surface: What 41,601 Reachable EtherNet/IP Endpoints Tell Us About OT Exposure

Comments
4 min read
When a Signature Check Fails Open: Inside the SAML Logic Behind CVE-2026-19490

When a Signature Check Fails Open: Inside the SAML Logic Behind CVE-2026-19490

Comments
3 min read
The Unauthenticated Docker API: 298,430 Exposed Endpoints and Why Port 2375 Still Matters

The Unauthenticated Docker API: 298,430 Exposed Endpoints and Why Port 2375 Still Matters

Comments
3 min read
Tool-Call Injection in LLM Agents: Why Your MCP Server Is the New Attack Surface

Tool-Call Injection in LLM Agents: Why Your MCP Server Is the New Attack Surface

1
Comments
4 min read
15.6 Million Exposed RDP Endpoints: Why Remote Desktop Remains the Favourite Initial Access Vector

15.6 Million Exposed RDP Endpoints: Why Remote Desktop Remains the Favourite Initial Access Vector

Comments
4 min read
CVE-2026-87827 and the botnet supply chain behind cheap DVR hardware

CVE-2026-87827 and the botnet supply chain behind cheap DVR hardware

Comments
2 min read
CVE-2026-73807 and CVE-2026-82567: Missing Authorization in mySCADA myPRO Manager

CVE-2026-73807 and CVE-2026-82567: Missing Authorization in mySCADA myPRO Manager

Comments
2 min read
Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Comments
3 min read
When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

Comments
4 min read
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

1
Comments
4 min read
Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT

Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT

Comments
5 min read
Langflow CVE-2026-12944: How a Scanner Blocklist Gap Turns Into Root Code Execution

Langflow CVE-2026-12944: How a Scanner Blocklist Gap Turns Into Root Code Execution

Comments
4 min read
SonicWall SMA1000 Command Injection (CVE-2026-83549): Chained Zero-Day to Root on the Edge

SonicWall SMA1000 Command Injection (CVE-2026-83549): Chained Zero-Day to Root on the Edge

Comments
3 min read
The Management Plane Is the Attack Surface: What Cisco FMC's Exploited Zero-Day Teaches About Exposed Admin Interfaces

The Management Plane Is the Attack Surface: What Cisco FMC's Exploited Zero-Day Teaches About Exposed Admin Interfaces

Comments
5 min read
Exposed PLCs Are Still on the Internet: What CISA's Water Sector Alert Means for Attack Surface Management

Exposed PLCs Are Still on the Internet: What CISA's Water Sector Alert Means for Attack Surface Management

Comments
5 min read
Security Exposure Counts Need Context

Security Exposure Counts Need Context

Comments
1 min read
Use ZoomEye to find Jupyter servers without identity verification enabled

Use ZoomEye to find Jupyter servers without identity verification enabled

Comments
6 min read
Best Practices for Enhancing Attack Surface Management and Accelerating Vulnerability Response

Best Practices for Enhancing Attack Surface Management and Accelerating Vulnerability Response

Comments
2 min read
Shodan vs ZoomEye Query Syntax Comparison

Shodan vs ZoomEye Query Syntax Comparison

1
Comments
2 min read
A Complete Guide to the Latest ZoomEye Search Syntax

A Complete Guide to the Latest ZoomEye Search Syntax

2
Comments
6 min read
Top 5 Domain and IP Intelligence Tools in OSINT

Top 5 Domain and IP Intelligence Tools in OSINT

2
Comments
3 min read
The Hunter Behind the Hacker

The Hunter Behind the Hacker

Comments 1
3 min read
Top 5 Technical Asset Discovery Tools in OSINT

Top 5 Technical Asset Discovery Tools in OSINT

Comments
3 min read
loading...