Damus
Dr. Christopher Kunz · 2w
So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
Graham Sutherland / Polynomial profile picture
@nprofile1q... there are reports of active exploitation in the wild but when I tried to track them back to a source it seems to be Belgium's CCB saying "source: trust me bro". which, y'know, it's Belgium's CCB, so maybe? but also zero actual proof, TTPs, IoCs, or useful info about the claimed exploitation, soooooo
1
Dr. Christopher Kunz · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7wkkj73azdfr23hmgd07fn0h39xvy0w72garahk5p8hg8jv8dx5s9v3tsk In the same vein, all CISA KEV entries are "source: trust me bro", lack proof and IoCs but serve as the basis for risk assessment and mitigation across all US federal government infrastr...