Tagged “appsec”
3 posts
Java deserialization after Log4Shell: CVE-2023-46604
Apache ActiveMQ's unauthenticated RCE shows Java deserialization bugs never went away after Log4Shell — only the exploitation playbook got faster.
securityjavacveappsec
Leaked credentials in public repos get used in minutes
GitGuardian logged 28.65M secrets on public GitHub in 2025, and researchers have watched leaked AWS keys get abused in under five minutes.
securitygithubsecretsappsec
MOVEit and the MFT zero-day exploitation playbook
CVE-2023-34362 turned one SQL injection in MOVEit Transfer into 2,700+ breached organizations — and the same pattern keeps repeating against MFT software.
securitycveransomwareappsec