This appears to be a rando with no qualifications who was using unauthenticated data he found online.
This appears to be a rando with no qualifications who was using unauthenticated data he found online.
1. It is unencrypted and unauthenticated
2. Asks you to send "what you did for your job, specifically?" info in plain text, unauthenticated reply with no confirmation where it went
An agency might use as a test of who falls for phishing attempts
1. It is unencrypted and unauthenticated
2. Asks you to send "what you did for your job, specifically?" info in plain text, unauthenticated reply with no confirmation where it went
An agency might use as a test of who falls for phishing attempts
Me: Let me show you the set of devices I have unauthenticated RCE over
Me: Let me show you the set of devices I have unauthenticated RCE over
https://censys.com/blog/turning-off-the-information-flow-working-with-the-epa-to-secure-hundreds-of-exposed-water-hmis
Flock seeks to have security researchers’ map of Flock cameras taken down — Unauthenticated flaw exposed 335,701 camera locations nationwide
www.tomshardware.com/tech-industr...
Flock seeks to have security researchers’ map of Flock cameras taken down — Unauthenticated flaw exposed 335,701 camera locations nationwide
www.tomshardware.com/tech-industr...
You can run a single XRPC call, unauthenticated, and get a user's entire repo (i.e., full posting history, all lists, everything) as a handy .car file.
Did I mention "unauthenticated"?
You can run a single XRPC call, unauthenticated, and get a user's entire repo (i.e., full posting history, all lists, everything) as a handy .car file.
Did I mention "unauthenticated"?
I'll go first: Six page commercial lease.
CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components
The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0:
react-server-dom-webpack
react-server-dom-parcel
react-server-dom-turbopack
Upgrade immediately!
CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components
The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0:
react-server-dom-webpack
react-server-dom-parcel
react-server-dom-turbopack
Upgrade immediately!