OpenBSD · ldapd(8) · CVE-2026-103547 · CVSS 4.0 9.2 Critical CVE-2026-103547 is a bug with no memory corruption and no exotic side channel. It is two processes agreeing to identify a client by a number that the operating system is…
Keycloak · SAML brokering · CVE-2026-1190 · CVSS 3.1 Low SAML has two places that tell you when an assertion stops being valid. Keycloak, acting as a SAML broker, checked one of them and quietly ignored the other. That is the whole bug.…
COMPFEST CTF 2026 · Reverse Engineering chall.exe is a 3,072 byte PE32 that barely does anything on its own. It allocates RWX memory, copies 674 bytes into it and calls the result. That little blob is the actual challenge. It starts in…
Tonight, April 16th 2026 at 19:20, i’m giving a talk at the Nuremberg Claude Code Meetup. The title: How I Accidentally Became #2 VDP Researcher for Germany on HackerOne Slides are here: no2vdp.bett.ag And yes, the #2 part is real. This…
Dear Peter, Kleine Katze, Mogli and Fussel, I don’t think people really understand what losing each of you did to me. With every one of you that died, something in me got worse. Something got darker. My humor turned another notch…
one month ago, i wrote about pivoting from freelance development to AI-powered bug bounty hunting. i started with “valid duplicates.” here’s where the rig stands today. From Duplicates to CVEsCVE-2026-1190 (KeyCloak) my agents found a…
Let’s be real for a second. The project market for freelance developers in Germany right now? It’s basically dead. The economy is weird, budgets are frozen, and everyone is sitting on their hands. But i’m not the type to sit around. For…
Over the last few years, i’ve immersed myself completely in the AI landscape. I’m not just talking about playing with ChatGPT for fun; i’m talking about high-level consulting, training and running my own models in my own racks here in…