121 Followers
109 Following
126 Posts
Security Engineer | Clicker of Links | Pusher of Buttons | Cat Dad
:butterflyhttps://bsky.app/profile/cydave.bsky.social
:github:https://github.com/cydave
✍️​https://0dave.ch/
Kanboard CVE-2026-33058 Writeup

Walkthrough of the discovery of an authenticated SQL injection in Kanboard version <= 1.2.50 tracked as CVE-2026-33058

0dave

Saw a new (to me) malware sample in teh logs. A python script scanning for exposed docker APIs deploying xmrig:

hxxps://pastebin[.]com/raw/1p7TJRDd

#malware #python #docker #xmrig

No bleed attempts in the last week.  

Either mongobleed is no longer popular or I'm doing something wrong... hrm.

Flying Whales in a Pot of Honey

What I’ve been up to in the last few weeks

0dave
Flying Whales in a Pot of Honey

What I’ve been up to in the last few weeks

0dave

One more side project?  
🥭 🩸 🍯

#mongobleed #CVE-2025-14847

CVE-2025-6004 tl;dr

A tl;dr about account lockout bypass (CVE-2025-6004) in Hashicorp Vault

0dave

Wrote about a funny little vulnerability in goreportcard I encountered just before publishing oauth-labs.

Give it a read if you have some time to kill :)

https://0dave.ch/posts/goreportcard/

#infosec #vulnerability #writeup

go report "a vulnerability" card

While publishing oauth-labs I stumbled upon a vulnerability in goreportcard

0dave

Quick http://ghmlwr.0dave.ch/ update:
I've included raw JSON data and an RSS feed (atom), check it out :)

(let me know if either of these two files are borked).

#github #malware #threatintel #update

ghmlwr | Suspects

It's sunday. You are very bored, you want to make the world a better place and report malicious repositories on GitHub.

You can: https://ghmlwr.0dave.ch/

 

#github #malware #threatintel #security

ghmlwr | Suspects