PwnKit: The 12-Year Local Root in Every Linux
CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.
CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.
A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.
A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.
A DYNOMITE autoscaler impairment cascaded through AWS’s busiest region and its own consoles. The dependency-concentration landmark.
Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.
One maintenance command withdrew Facebook’s backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.
A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.
A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.