Mastodon Digest
for the past
scorer
threshold
Posts

Not particularly related to this one, but the new CVE scoring system basically lets vendors set Exploit Maturity for every vuln to Unreported, as there's almost always no exploits before patch - which means you never get a CVE score above 8 for unauth RCEs any more as a vendor.

Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
security.paloaltonetworks.com/

HT @databeestje

Boosts

It's Friday! Woo hoo!

I've spent a fair bit of this week Quite Angry at the world, & it *may* have infiltrated into the dancers' routine this week. But I figure that if I want a vision of the future I could imagine a boot stamping on a human face forever, OR I could imagine punching far-right fuckwits in the face & making sparkles.

So yeah. I went with that.

As ever, have a good weekend, if you possibly can :HumphStomp:

#FridaySparklyDancers #sillyScribbles

Seen on the London Underground 🚇

Sign