Three bugs in vinext's alpha, Cloudflare's AI-built Next.js replacement
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
A white-box audit of the end-to-end encrypted booking platform OpenReception found 16 vulnerabilities, four of them critical.
How missing authorization checks in Zammad's REST API let agents execute group-restricted AI text tools and inject unauthorized ticket context into AI prompts.
How I bypassed Wazuh's UNC path mitigation in Windows OSQuery using extended-length UNC paths (\\?\UNC\), leaking NetNTLMv2 hashes despite the original CVE-2025-30201 fix.
A PowerShell-based triage script to check systems for indicators of compromise related to the Notepad++ supply chain attack attributed to Lotus Blossom APT.