ownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

The graphapi app bundled in ownCloud’s Docker deployment images exposed mail credentials, database passwords, and S3 keys to unauthenticated visitors — a mis-packaged dependency that became full infrastructure compromise. CISA KEV-listed it within ten days.

Continue ReadingownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

ChatGPT’s November 2023 DDoS Outages, Explained

For much of 8 November 2023, ChatGPT and parts of OpenAI’s API cycled in and out of service under a denial-of-service wave claimed by Anonymous Sudan, with smaller recurrences through the month. OpenAI confirmed the DDoS, rolled global WAF rules, and absorbed a false-positive tax on legitimate users. Nothing was breached — the story is availability risk wrapped around AI dependence. This post walks the campaign’s anatomy, Microsoft’s Storm-1359 telemetry link, and the business-continuity lessons for anyone running on AI vendors.

Continue ReadingChatGPT’s November 2023 DDoS Outages, Explained

F5 BIG-IP Request Smuggling 2023: The 9.8 Desync

CVE-2023-46747 let unauthenticated attackers smuggle requests through BIG-IP TMM into the iControl REST management plane — a framing bug that became full device compromise. Exploitation followed the October patch within days, and CISA put it on the KEV catalog before month end.

Continue ReadingF5 BIG-IP Request Smuggling 2023: The 9.8 Desync