WordPress patched an unauth path traversal yesterday: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
This is now being exploited, a few hours later: https://x.com/ethicalhack3r/status/2102747373873004680
Happy announcement: My colleague and me will present a talk at hardwear.io NL 2026, "Vulnerabilities That Get Under Your Skin: Targeting the World’s Best-Selling Infusion Pumps". 100% human-brain VR 😛
Draw a fish and watch it swim in a tank with everyone else who's drawing them too 🐠🐟🐡
Silly, but also lovely
TIL a recent? Zed update shows you the JSON path to the item you have the cursor at.
poll: in Git, do you ever use any of the references `MERGE_HEAD`, `REBASE_HEAD`, `CHERRY_PICK_HEAD`, `ORIG_HEAD`, `FETCH_HEAD`, or `REVERT_HEAD` etc? (and if so, what do you use them for?)
SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/
periodic reminder that Wizard Zines has an educational use policy if you want to use them in your university courses! https://wizardzines.com/education/
RE: https://infosec.exchange/@cR0w/117315299719177302
Important: We have learned that this vulnerability has been exploited.
Poland's CERT has published its report on MikroTrik, the zero-day campaign that targeted MikroTik routers earlier this month
Praises LLM agents for helping with the research
https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/