OpenBSD · ldapd(8) · CVE-2026-103547 · CVSS 4.0 9.2 Critical CVE-2026-103547 is a bug with no memory corruption and no exotic side channel. It is two processes agreeing to identify a client by a number that the operating system is…
Keycloak · SAML brokering · CVE-2026-1190 · CVSS 3.1 Low SAML has two places that tell you when an assertion stops being valid. Keycloak, acting as a SAML broker, checked one of them and quietly ignored the other. That is the whole bug.…
Tonight, April 16th 2026 at 19:20, i’m giving a talk at the Nuremberg Claude Code Meetup. The title: How I Accidentally Became #2 VDP Researcher for Germany on HackerOne Slides are here: no2vdp.bett.ag And yes, the #2 part is real. This…
one month ago, i wrote about pivoting from freelance development to AI-powered bug bounty hunting. i started with “valid duplicates.” here’s where the rig stands today. From Duplicates to CVEsCVE-2026-1190 (KeyCloak) my agents found a…
Let’s be real for a second. The project market for freelance developers in Germany right now? It’s basically dead. The economy is weird, budgets are frozen, and everyone is sitting on their hands. But i’m not the type to sit around. For…
FreeBSD is my favorite OS, not just recently but all the way back to 2003 when Linux didn’t cut it anymore for me. Given that Linux has more device drivers available, it also means more bugs, code duplication and generally speaking bad…
Kali Linux is a Penetration-Testing Distro basted on Linux. Most people reading my blog may already know that, but what you might have overheard when you’re not owning an Android-device, there is something called Kali NetHunter Linux,…
A few weeks back, i’ve had the pleasure to pentest a CentOS Server (or was it Fedora?). Anyway, some creepy RPM based distro. What really annoyed me was, that i had real troubles compiling certain exploits for this machine, since i was…