Latest ≠ Greatest? A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS from our very own @mwulftange.bsky.social who loves converting n-days to 0-days code-white.com/blog/wsus-cv...
29.10.2025 13:05 — 👍 5 🔁 4 💬 0 📌 1@m1tzzz.bsky.social
Web Security Expert | Bug Hunter | Käferjäger
Latest ≠ Greatest? A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS from our very own @mwulftange.bsky.social who loves converting n-days to 0-days code-white.com/blog/wsus-cv...
29.10.2025 13:05 — 👍 5 🔁 4 💬 0 📌 1Did you encounter the Supabase? Might wanna try my newest tooling or have a read about quickwins? There you go:
blog.m1tz.com/posts/2025/1...
Tired of dull, standard interviews? Talk to Kurt. Also, a few of my colleagues and I will be attending BruCON next week. Feel free to come and talk to us.
15.09.2025 07:44 — 👍 6 🔁 1 💬 0 📌 0Nice one! But see also blog.m1tz.com/posts/2025/0...
I covered some more misconfigurations targeting Firebase.
We've added a new demo to NewRemotingTricks that makes deploying a MarshalByRefObject (e.g., WebClient) even easier: System.Lazy<T> creates an instance of T on serialization, which is probably more likely to be allowed than a XAML gadget getting through. github.com/codewhitesec...
05.08.2025 15:11 — 👍 4 🔁 4 💬 0 📌 1Stumbled upon your next Firebase target? You might want to take a closer look at this.
blog.m1tz.com/posts/2025/0...
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-...
13.05.2025 06:45 — 👍 9 🔁 9 💬 0 📌 1My blog post on some vulns in GFI MailEssentials
frycos.github.io/vulns4free/2...
I do have quite a backlog of blog posts, so let's start with this one 😎
10.04.2025 14:54 — 👍 11 🔁 2 💬 0 📌 0Our crew members @mwulftange.bsky.social & @frycos.bsky.social discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam 's blacklist for CVE-2024-40711 & CVE-2025-23120 + further entry points after @sinsinology.bsky.social & @chudypb.bsky.social 's blog. Replace BinaryFormatter!
28.03.2025 16:35 — 👍 9 🔁 6 💬 0 📌 2Sexy
05.01.2025 13:31 — 👍 1 🔁 0 💬 0 📌 0Most of you know about Telerik or DevExpress but ever heard of Syncfusion as another big global player? I found some interesting vulnerabilities in it, fixed in version v27.1.55. Unfortunately, Syncfusion still tries to understand CVE assignments 😅
02.12.2024 08:46 — 👍 9 🔁 4 💬 0 📌 1Another live hacking event with the #kaeferjaeger . This time with #Intigriti in Heidelberg and the awesome target #Allegro . Had a great time and found a couple of bugs. #lhe #bughunting #bugbounty
24.11.2024 10:25 — 👍 10 🔁 0 💬 0 📌 1