Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Hans-Martin Münch

@h0ng10@infosec.exchange
  • Open on infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

0 Followers
0 Following
15 Posts
Joined November 03, 2022
Twitter:
https://twitter.com/h0ng10
GitHub:
github.com/h0ng10
Website:
https://mogwailabs.de

Posts

Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Aug 07, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
Bugtraq is back: "I have acquired securityfocus.com and the Bugtraq name. Not to build a museum - to restart the conversation. The mission is unchanged: full disclosure, researcher-first, no corporate filter. The old archives, sourced from community copies of what was always public mailing list traffic, will be preserved and made accessible separately." https://lists.securityfocus.com/hyperkitty/list/bugtraq@securityfocus.com/thread/CHKLXLA7SJEWLDFHWXB3QU57ADOXGL2E/
lists.securityfocus.com

Bugtraq is back - Bugtraq - SecurityFocus Mailing Lists

0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 30, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
CVE-2026-16232 Check Point SmartConsole Authentication Bypass Technical Analysis from Rapid7: https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/ PoC Exploit: https://github.com/sfewer-r7/CVE-2026-16232
Rapid7
Rapid7

Rapid7

Root cause technical analysis of CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Check Point Security Management Server and Multi-Domain Security Management Server

0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 30, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
So @irsdl@infosec.exchange released a new version of YSoNet (a forge of ysoserial.net), with some cool new features / gadgets: ▸ DataTable + DataTableTypeSpoof Same-graph DataTable root carrier for RCE. No nested BinaryFormatter or extra binder boundary. TypeSpoof emits a real DataTable subclass, so blocking only the exact DataTable wire name may not prevent reconstruction. ▸ TypeConfuseDelegateFileOperations Five delegate-confusion variants for writing, copying, moving and truncating files. No child process, compiler or WPF required. ▸ AssemblyInstallerLoad Loads a specified DLL from a local or UNC path and instantiates [RunInstaller(true)] installer types. Supported by nine serializers. ▸ DynamicUpdateMapExtension Passes x:XData to NetDataContractSerializer without a binder, allowing a XAML-only sink to carry an NDCS gadget. 🔧 NOTABLE UPDATES ▸ TypeConfuseDelegate now supports SortedDictionary and TreeSet roots, useful for testing blocklists that match only the exact SortedSet wire name. ▸ WindowsIdentity and WindowsClaimsIdentity can carry the inner BinaryFormatter graph through actor, bootstrapContext, claims or WIF’s _actor sink. Variant numbering is now aligned across both gadgets and all serializers. 🔗 https://github.com/irsdl/ysonet http://ysonet.com | http://ysonet.net #AppSec #YSoNet
GitHub

GitHub - irsdl/ysonet: Deserialization payload generator for a variety of .NET formatters

Deserialization payload generator for a variety of .NET formatters - irsdl/ysonet

1
0
1
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 21, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
I know it's still a while away, but on November 12, 2026, I'll be speaking about “Private AI/Inference” at the "IT Kongress" in Neu-Ulm (Germany): Talk will be in German https://www.it-kongress.com/index.php/programm-und-anmeldung/ki-und-automatisierung-use-ai-because-nobody-is-watching/
0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 21, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
I am aware that bug bounty programs are overwhelmed by low-quality AI submissions, but I have also observed a general decline in the validation process, particularly when reporting issues that fall outside the web technology stack. I can generate highly detailed reports that describe the issue, include a proof of concept, and yet they often struggle to validate the finding.
0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 18, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
WordPress, the most widely used CMS, has just released an emergency update for a critical security vulnerability. Update your sites and blogs immediately. https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 15, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
Steven Fewer from (@Rapid7Official@infosec.exchange) killing it again as always, this time with SharePoint (CVE-2026-55040) https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/
0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 14, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
Replying to @buherator@infosec.place
@buherator@infosec.place @Rapid7Official@infosec.exchange @attackerkb@infosec.place I liked it as a resource for technical vulnerability analysis. The last times that I looked into it, I saw more and more stuff that looked like an incident / report. I don't know if this is actually the reason Rapid7 shuts it down, but it was the reason why I used it less often. But I don't consider myself as a "power-user"
0
1
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 14, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
So, @Rapid7Official@infosec.exchange is shutting down AttackerKB (https://attackerkb.com/) soon. I view this as a case where an initially promising idea became overwhelmed by low‑quality reports from contributors. Anyway, archive any data you wish to retain.
2
1
2
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 07, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
If you want to quickly burn tokens, let an LLM evaluate a CVSS rating.
1
1
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jul 03, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
So @nostarch@mastodon.social currently provides a summer sale (40 percent off).
0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Feb 02, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange

@lcamtuf@infosec.exchange Due to the EU Cyber Resilience Act, auto-updates will become mandatory, as products must provide an automatic update feature. Looking forward to all the vulnerabilities in auto-update services...

infosec.exchange

lcamtuf :verified: :verified: :verified: (@lcamtuf@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Jan 22, 2026
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange

RE: @mogwailabs_gmbh@infosec.exchange

I'm getting old. Instead of analyzing vulnerabilities, I analyze regulations 😩

3
0
1
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Sep 08, 2025
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
Replying to @Orca@nya.one
@Orca @micahflee I assume he is using Mantic (which is no longer supported as it only received security updates for nine months) https://launchpad.net/ubuntu/+source/apache2/2.4.57-2ubuntu2
0
1
0
0
Open post
h0ng10
Hans-Martin Münch @h0ng10@infosec.exchange · Sep 08, 2025
Hans-Martin Münch
@h0ng10@infosec.exchange

CEO of MOGWAI LABS GmbH and part time bboy.

infosec.exchange
Replying to @micahflee@infosec.exchange
@micahflee Please note that installing the latest Ubuntu security updates for Apache httpd does not necessarily upgrade Apache to the latest available version. Instead, security fixes are typically backported to the version included with the distribution. As a result, the displayed version remains unchanged. For example, even after fully updating Ubuntu 22.04 LTS, the Apache version shown in the Server header still appears as 2.4.52, despite being patched with the latest security fixes.
22
5
2
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:27:59 UTC