Ghosted: Surviving CVE-2026-26980 Because I Actually Configured Nginx
We all know what happens when you leave edge software unpatched. Earlier this year, I was keeping an eye on CVE-2026-24778. It was an XSS flaw in the Ghost members Portal
We all know what happens when you leave edge software unpatched. Earlier this year, I was keeping an eye on CVE-2026-24778. It was an XSS flaw in the Ghost members Portal
Designing identity systems that keep pace with AI-driven development Thesis: Identity systems designed for human-paced development are failing in AI-accelerated environments. To secure modern infrastructure, identity must be default-closed,
Cache was a medium rated Linux box where enumerating a website found some hard-coded creds and a vhost that contained an Electronic Medical Records application. This EMR app had some SQL injection
Admirer was an easy rated Linux machine that had a lot more steps than I expected, given the rating. A robots.txt file hinted at the presence of credentials which were found with
Quick was a hard rated Linux box and man, did it earn that rating. A website was accessed via the QUIC protocol and a password was retrieved. A list of potential usernames was
Magic was a medium rated Linux box that required you to find a hidden upload function then bypass its upload restrictions to execute code and catch a shell as www-data. From here,