blog.evan.lat (corporate-friendly)
dark
security research & vulnerability analysis — main site at
evan.lat
. pgp for sensitive stuff:
here
.
2026-09-14
The Weakest Link: Breaching Enterprise Infrastructure Through Contractor Misconfigurations
2026-09-04
msrc disc. (placeholder)
2026-08-05
You've Got Mail(ware): Chaining Stored XSS and Arbitrary File Read to Wormable Pre-Auth RCE in Horde Groupware
2026-07-30
Failing the Audit: Java Deserialization RCE Across Higher Education Infrastructure (CVE-2026-94109)
2026-07-10
Wide Area Network, Narrow Attack Surface: Authenticated Heap Buffer Overflow in Cisco Catalyst SD-WAN (CSCwu48719)
2026-05-31
A Hole in the Perimeter: Blind XPath Injection and Credential Extraction in OPNsense (CVE-2026-53582)
2026-04-07
Dead Code Walking: Unauthenticated RCE via a Deprecated Cisco ASA Upload Endpoint
2026-03-26
End of Life, Not End of Risk: Privilege Escalation Through Forgotten Enterprise Infrastructure
2026-02-07
Curl Up and Die: OS Command Injection in the Tenda G300-F WAN Diagnostic Interface (CVE-2026-25857)
2025-10-29
Return to Sender: Hijacking Reserved Outlook Addresses and Abusing Domain Control Validation
2025-10-01
Insufficient Funds (for Security): Chaining CORS Misconfiguration, IDOR, and SSRF in a Consumer Payment Processor