#Unauthenticated
unauthenticated remote code execution
June 22, 2026 at 4:18 AM
CVE-2024-12727 Sophos coming in with an unauthenticated SQLi in their firewall appliance 👏
CVE-2023-34990 🤦‍♂️🤦‍♂️
December 22, 2024 at 8:43 AM
Came here to share the same screenshot.

This appears to be a rando with no qualifications who was using unauthenticated data he found online.
February 10, 2026 at 7:53 PM
wow twitter really did get rid of unauthenticated viewing huh, readding twitter to dns blocklist then
March 11, 2025 at 12:06 PM
Assuming the OPM email is as before:

1. It is unencrypted and unauthenticated

2. Asks you to send "what you did for your job, specifically?" info in plain text, unauthenticated reply with no confirmation where it went

An agency might use as a test of who falls for phishing attempts
Five bullet points? I have at least eight here
February 22, 2025 at 10:20 PM
"we are clean on opsec" I mumble while toggling !no-unauthenticated
December 9, 2025 at 1:45 PM
Them: I love a man who takes control
Me: Let me show you the set of devices I have unauthenticated RCE over
November 26, 2024 at 9:09 AM
devs are asleep post unauthenticated data
November 21, 2024 at 7:07 PM
`!no-unauthenticated` has some real `git update-index --no-assume-unchanged` vibes
March 12, 2024 at 8:15 PM
Heads up! Docker limits unauthenticated pulls to 10/HR/IP from Docker Hub, from March 1. #Docker #Linux #Sysadmin #Linux #DevOps
February 21, 2025 at 3:01 PM
discord is so fucking cool for ignoring !no-unauthenticated
November 22, 2024 at 9:29 AM
The reason given for terminating Mahdawi's removal proceeding was that the document submitted under Secretary Rubio's name purporting to establish Mahdawi's "foreign policy" removability was unauthenticated.
NEW: Today, an immigration judge terminated removal proceedings for Mohsen Mahdawi, the Columbia student, Palestinian activist, and U.S. permanent resident whom the Trump administration arrested in April 2025 and attempted to deport under the foreign policy provision.
February 17, 2026 at 9:24 PM
I've been unsuccessfully unauthenticated
August 24, 2023 at 1:50 PM
"40 systems were fully unauthenticated and controllable by anyone with a browser." 😬
Really excited to see this research go live. We found 400 web based HMIs for US Water facilities open on Censys. With the EPA, we helped reduced that exposure by over 94%.

https://censys.com/blog/turning-off-the-information-flow-working-with-the-epa-to-secure-hundreds-of-exposed-water-hmis
June 5, 2025 at 4:14 PM
deer social filters out no-unauthenticated labels now 😋
April 12, 2025 at 12:27 AM
Hey folks (at large) -- can anybody tell me what "!no-unauthenticated" means?
September 6, 2026 at 11:56 AM
Hard to argue they aren't a surveillance company..

Flock seeks to have security researchers’ map of Flock cameras taken down — Unauthenticated flaw exposed 335,701 camera locations nationwide

www.tomshardware.com/tech-industr...
Flock seeks to have security researchers' map of Flock cameras taken down — unauthenticated flaw exposed 335,701 camera locations nationwide
It could also potentially be used to track key personnel heading to and from sensitive sites like military bases, intelligence agencies, and law enforcement headquarters.
www.tomshardware.com
September 27, 2026 at 6:50 PM
It's way worse than that.

You can run a single XRPC call, unauthenticated, and get a user's entire repo (i.e., full posting history, all lists, everything) as a handy .car file.

Did I mention "unauthenticated"?
December 19, 2024 at 4:24 PM
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
www.bleepingcomputer.com
September 25, 2026 at 6:13 PM
Remote Unauthenticated Code Execution
In honor of spooky month, share a 4 word horror story that only someone in your profession would understand

I'll go first: Six page commercial lease.
October 12, 2025 at 6:13 PM
A perfect CVSS 10 🧑🏻‍🍳💋

CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components

The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0:

react-server-dom-webpack
react-server-dom-parcel
react-server-dom-turbopack

Upgrade immediately!
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
react.dev
December 3, 2025 at 4:23 PM