Julian Suleder

34 Followers
86 Following
41 Posts
it security @ERNW • medical informatics background

Three small announcements:
1. RFC 9839, a guide to which Unicode characters you should never use: https://www.rfc-editor.org/rfc/rfc9839.html
2. Blog piece with background and context, “RFC 9839 and Bad Unicode”: https://www.tbray.org/ongoing/When/202x/2025/08/14/RFC9839
3. A little Go library that implements 9839’s exclusion subsets: https://github.com/timbray/RFC9839

#Unicode

RFC 9839: Unicode Character Repertoire Subsets

This document discusses subsets of the Unicode character repertoire for use in protocols and data formats and specifies three subsets recommended for use in IETF specifications.

New post: Security Advisory: Airoha-based Bluetooth Headphones and Earbuds https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/
Security Advisory: Airoha-based Bluetooth Headphones and Earbuds – Insinuator.net

New post: Minor Security Issues in VMWare Carbon Black Cloud https://insinuator.net/2025/03/advistory-vmware-carbon-black-cloud/
CVE-2024-11035: Minor Security Issues in VMWare Carbon Black Cloud

We recently conducted a security assessment of VMWare Carbon Black Cloud, a unified SaaS solution that integrates endpoint detection and response (EDR), anti-virus, and vulnerability management capabilities. As part of our evaluation, we tested the solution's ability to detect and prevent malicious activity on Windows and Linux systems. Our analysis focused on the Carbon Black agents for the ...

Insinuator.net
New post: CVE-2025-20908: Use of insufficiently random values in Samsung’s Auracast implementation https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/
CVE-2025-20908: Use of insufficiently random values in Samsung’s Auracast implementation

As part of our research into the Auracast feature set in Bluetooth, we also started looking into vendor implementations. At the time we started with our research, there weren’t a lot of products on the market yet. But new products are coming out pretty frequently now. One of the vendors that had Auracast implemented pretty early was Samsung. At the time the Samsung Galaxy S23 and S24 phones w ...

Insinuator.net
New post: When Your Edge Browser Syncs Private Data to Your Employer https://insinuator.net/2025/02/when-your-edge-browser-syncs-private-data-to-your-employer/
When Your Edge Browser Syncs Private Data to Your Employer

Recently, one of our customers contacted us to investigate the extent of some unwanted and unexpected behavior regarding browsing data of employees. Employees started contacting IT support because private browser bookmarks, private login credentials etc. showed up on their work machines. All affected employees stated that they never created these bookmarks on work systems. And interestingly ...

Insinuator.net
New post: Jigsaw RDPuzzle: Piecing Attacker Actions Together https://insinuator.net/2025/01/jigsaw-rdpuzzle/
Jigsaw RDPuzzle: Piecing Attacker Actions Together

In a recent incident response project, we had the chance to virtually look over the attackers' shoulder and observe their activities. The attackers used the Remote Desktop Protocol (RDP) for lateral movement within the compromized environment and beyond (MITRE techniques T1570, T1021). As a matter of fact, RDP creates cache files that contain tiles of the transferred screen recording data. Whi ...

Insinuator.net
New post: Part I: Bluetooth Auracast from a Security Researcher’s Perspective https://insinuator.net/2025/01/auracast-part1/
Part I: Bluetooth Auracast from a Security Researcher’s Perspective

Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a potentially unlimited number of devices. It does not require pairing or interact ...

Insinuator.net
New post: Vulnerability Disclosure: Command Injection in Kemp LoadMaster Load Balancer (CVE-2024-7591) https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/
Vulnerability Disclosure: Command Injection in Kemp LoadMaster Load Balancer (CVE-2024-7591)

While conducting security research, I identified a critical vulnerability in Kemp’s LoadMaster Load Balancer. This vulnerability is a Command Injection and allows full system compromise. It requires no authentication and can be exploited remotely by having access to the Web User Interface (WUI). Kemp LoadMaster is a widely used Load Balancing Application that can commonly bee seen in custom ...

Insinuator.net

New post by a colleague of mine as result of a Pentest from a customer project performed by @ERNW: Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions < 1.32.5

https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5/

Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions < 1.32.5

During a penetration test for a customer, we briefly assessed Vaultwarden, an open-source online password safe. In June 2024, the German Federal Office for Information Security (BSI) published results1 of a static and dynamic test of the Vaultwarden server component. Therefore, only a partial source code audit was performed during our assessment. However, a quick look was needed to find some g ...

Insinuator.net
Hello #TROOPERS, we have opened the cfp (https://troopers.de/troopers25/contribute/) and ticket shop for next year's #TROOPERS25! Get your early bird until January 31st. Hope to see you in Heidelberg next near in June and looking forward to all your submissions!
TROOPERS25

TROOPERS is more than just an infoSec con. Hands-on, high-end knowledge sharing leaves you motivated and charged to