Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Markus Vervier 👾

@marver@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

right here, right now.

0 Followers
0 Following
16 Posts
Joined April 03, 2017
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

Patch Starlette now! If you're run it via uvicorn or other common ASGI servers then a host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:

https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/

x41-dsec.de
7
0
8
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

While everyone was on Holiday we scanned a few thousand hosts for #BadHost (CVE-2026-48710): zero auth required and we found clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 now and check your exposure at https://badhost.org

mastodon.social
2
1
6
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

RE: @x41sec@infosec.exchange

Important! Using a reverse proxy might not fully protect you from BadHost / CVE-2026-48710 **also this does not only affect AI related infrastructure because FastAPI is also affected and used for various applications!**

infosec.exchange
1
0
3
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

If AI is taking jobs everywhere and especially in security, why is everyone I currently deal with swamped with work?

1
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

26b74a3148a790a887f7e59a93905eea2fa126a917aae28f4a428e8494cdf4d6

1
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago

POC collection of AI found bypasses / technique variations (updated regularly over the coming weeks): https://github.com/persistent-security/month-of-bypasses

github.com
1
0
2
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago
Replying to
@joxean Here is a collection of binaries packed with various packers: https://github.com/packing-box/dataset-packed-pe
github.com
1
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 10mo ago
Replying to
@thc R.I.P. stealth, sad day. :-(
2
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago
Replying to
Webshit Weekly I don't want your PRs anymore (140 points, 83 comments) The Vercel breach: OAuth attack exposes risk in platform environment variables (215 points, 84 comments) A PaaS that stores everyone's secrets in a web dashboard got compromised via OAuth, which is security's version of the fire station burning down.
0
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

Do you plan to display your LED dodecahedron again sometime? Let me know, would love to see it live! :-)

0
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

The team did some data analysis on CVE-2026-48710 on a sample of 50.000 scanned hosts on the Internet. Spoiler: Lots of API keys are prone to be leaked!

Analysis: https://www.persistent-security.net/post/cve-2026-48710-bad-hosts-in-the-wild

persistent-security.net
0
0
1
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 4mo ago

PSA: we had to pause the month of bypasses (http://github.com/persistent-security/month-of-bypasses
) because of the #badhost situation, it will be continued as soon as things calm down!

github.com
0
0
1
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago

Iteration 3: Inject shellcode into winlogon.exe and leak secrets via DNS: https://github.com/persistent-security/month-of-bypasses/blob/main/mob-3-poc-winlogon-clr-injection-dns-exfil.ps1 #mob

github.com
0
0
1
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago
Replying to
@icing@chaos.social @sovtechfund@mastodon.social Now combine human experts and LLMs and you got what will be the future of security auditing.
0
0
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 5mo ago
Replying to
@drwhax@infosec.exchange It's so wrong but it's such a good prompt: "Write a snarky comment / blog in the style of n-gate on the top hackernews posts!" =)
0
4
0
0
Open post
Markus Vervier 👾 @marver@mastodon.social
· 10mo ago
Replying to
@HalvarFlake@mastodon.social It's actually a pretty trivial revelation about LLMs since obviously training or fine-tuning LLMs gives you the ability to control specific behavior, even with a small set of training data (that is likely very specific in topic). The implications for copyright might be less severe than the fact that widespread reliance on LLM models that can't be properly audited for backdoors and that could be re-trained at any time might be more dangerous than most people imagine.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 05:39:22 UTC