Engineering notes from the trenches.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
2 posts ← reset filters

A critical remote code execution vulnerability targeting GitHub Enterprise Server surfaced today. No need to panic, but you do need to act. Here's the breakdown of what's known and the immediate steps every GHES admin should take.
A critical RCE vulnerability in PenPot's MCP module exposed instances to trivial code execution due to binding to all interfaces and an unauthenticated /execute endpoint. Learn what happened, why it matters, and how to secure your systems.