⚠️ Critical Web Exploit Unleashed: Remote OS Command Injection Holes Found in Totolink N300RH Devices, Public Exploit Rel

#CVE2026 #OSCommandInjection #RemoteExecution #TotolinkVulnerability #WebManagementInterfaceExploit #cve #cybersecurity #iso27001

I finally got around to writing a blog post that doesn't just say "Maybe I'll write some blog posts one day".

Read about a fun little #CI experiment I've been working on called Cicada, a tool which aims to provide instantaneous CI using sandboxed remote execution and caching (a la Bazel).

https://sotk.co.uk/posts/2026/cicada.html

#cicd #forgejo #remoteexecution

SotK

CI/CD Week Day 4! Sometimes, running on the same host isn't enough!

Meet Executor 4: SSH! Our trusty old friend lets you execute remote processes just like bareMetal, bwrap, or Container executors can, but on a different machine!

GitRoot makes it simple: it's all managed via SSH keys. Add the public key of your GitRoot instance to your remote server and let the CI/CD flow. Pro-tip: Combining executors will be possible (e.g., bwrap inside podman inside ssh!)

Tomorrow is the final day! Follow me to learn where each executor truly shines!

#CICD #DevOps #SSH #RemoteExecution #Automation

Spyder 6.0 comes with a very cool tech preview: it allows you to easily connect to remote servers and run code on them! 🖥️

Continue reading to find out how to start using it 🧵 (1/4)

#Spyder #Python #SSH #RemoteDevelopment #RemoteExecution

Patchday: Schadcode über Bluetooth auf Android-Geräte schieben

Es gibt wichtige Sicherheitsupdates für Android 10, 11, 12, 12L und 13. Google hat unter anderem vier kritische Lücken geschlossen.

heise online

Update SaltStack

Also, don't leave your request server open to the Internet

https://labs.f-secure.com/advisories/saltstack-authorization-bypass

#InfoSec #CVE #RemoteExecution #CVE-2020-11651 #CVE-2020-11652

SaltStack authorization bypass

some Cisco switches allow root shell, they have a default SSH key pair that can be exploited over IPv6

Cisco Nexus 9000 Series Application Centric Infrastructure (ACI)

no workaround, update available

<voice person="Oprah">You get a root shell and you get a root shell and you get a root shell</voice>

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1804

#InfoSec #CVE-2019-1804 #RemoteExecution

CVE - CVE-2019-1804

Common Vulnerabilities and Exposures (CVE®) is a list of entries — each containing an identification number, a description, and at least one public reference — for publicly known cybersecurity vulnerabilities. Assigned by CVE Numbering Authorities (CNAs) from around the world, use of CVE Entries ensures confidence among parties when used to discuss or share information about a unique software vulnerability, provides a baseline for tool evaluation, and enables data exchange for cybersecurity automation.