CitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA’s Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.

Continue ReadingCitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

F5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

On November 6, 2024, F5 disclosed a pair of critical bugs in BIG-IP Next Central Manager shipped in its SPK fabric: CVE-2024-23327, an unauthenticated privilege-escalation path reachable via REST API, and CVE-2024-23328, a missing-authentication flaw letting attackers create arbitrary administrator accounts. Together they enable full takeover of a management node that itself commands a fleet of application delivery hardware. This account walks both paths, the same-day patches, and the uncomfortable lineage going back to CVE-2022-1388’s iControl REST flaw.

Continue ReadingF5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

Ivanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

On October 16, 2024, Ivanti disclosed two vulnerabilities in Endpoint Manager (EPM) chained for pre-auth remote code execution: CVE-2024-29224, an unauthenticated SSRF rated 9.6, and CVE-2024-29226, a path traversal in a downstream service. The week’s disclosure calendar placed it days after FortiManager’s FortiJump and amid a year of Ivanti security crises — from January’s Connect Secure zero-days to September’s Cloud Service Appliance flaw. This account explains the chain mechanics, why consortium defenders pushed urgent patching, and the management-plane pattern of 2024.

Continue ReadingIvanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

FortiManager Zero-Day (FortiJump): CISA Escalation Explained

On October 23, 2024, Fortinet confirmed CVE-2024-47575 — a CVSS 9.8 missing-authentication flaw in the FortiManager FGFM protocol that China-nexus actor UNC5850 had exploited since summer to jump from exposed managers into fleets of managed FortiGates with a custom DeepMove implant. CISA KEV-listed it within days, forcing two-week patch deadlines across federal and enterprise fleets. This account reconstructs the protocol bug, the DeepMove persistence, the fleet-jump blast radius, and the management-plane hardening it made mandatory.

Continue ReadingFortiManager Zero-Day (FortiJump): CISA Escalation Explained

CUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

In late September 2024, researcher Simone Margaritelli disclosed a chain of CUPS vulnerabilities — CVE-2024-47076, CVE-2024-47176 and siblings — allowing same-network attackers to register malicious printers and achieve code execution as the lp user via broadcast-trusting auto-configuration. Preceded by a hype-teaser countdown that split the community, the episode became the year’s clearest study in disclosure-process dysfunction, severity theater, and the quiet ubiquity of trust-the-LAN daemons. This account covers the chain mechanics, the honest exposure math, and what to disable today.

Continue ReadingCUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

SolarWinds Web Help Desk RCE: The Name That Hurts Again

On August 21-22, 2024, SolarWinds shipped 12.8.3 HF1 for Web Help Desk and disclosed CVE-2024-28986 — an unauthenticated Java deserialization flaw rated CVSS 9.8 that delivers pre-auth remote code execution on internet-facing instances. Within days PoC code circulated in exploitation attempts, and on August 26 CISA added it to the Known Exploited Vulnerabilities catalog, making patching mandatory across federal networks. This account covers the bug mechanics, the four-day disclosure-to-KEV sprint, and the uncomfortable optics of a SolarWinds product back in emergency-cycle headlines.

Continue ReadingSolarWinds Web Help Desk RCE: The Name That Hurts Again

Polyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare’s mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.

Continue ReadingPolyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script