Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Markus Vervier 👾

@marver@mastodon.social
mastodon 4.7.0-beta.1
  • Open on mastodon.social

right here, right now.

0 Followers
0 Following
16 Posts
Joined April 03, 2017

Posts

Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Jun 08, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

Do you plan to display your LED dodecahedron again sometime? Let me know, would love to see it live! :-)

0
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 29, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

The team did some data analysis on CVE-2026-48710 on a sample of 50.000 scanned hosts on the Internet. Spoiler: Lots of API keys are prone to be leaked!

Analysis: https://www.persistent-security.net/post/cve-2026-48710-bad-hosts-in-the-wild

0
0
1
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 29, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

PSA: we had to pause the month of bypasses (http://github.com/persistent-security/month-of-bypasses
) because of the #badhost situation, it will be continued as soon as things calm down!

0
0
1
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 28, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

RE: @x41sec@infosec.exchange

Important! Using a reverse proxy might not fully protect you from BadHost / CVE-2026-48710 **also this does not only affect AI related infrastructure because FastAPI is also affected and used for various applications!**

1
0
3
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 26, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

While everyone was on Holiday we scanned a few thousand hosts for #BadHost (CVE-2026-48710): zero auth required and we found clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 now and check your exposure at https://badhost.org

2
1
6
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 22, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

Patch Starlette now! If you're run it via uvicorn or other common ASGI servers then a host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:

https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/

7
0
8
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 13, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

If AI is taking jobs everywhere and especially in security, why is everyone I currently deal with swamped with work?

1
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 11, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

26b74a3148a790a887f7e59a93905eea2fa126a917aae28f4a428e8494cdf4d6

1
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 06, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

Iteration 3: Inject shellcode into winlogon.exe and leak secrets via DNS: https://github.com/persistent-security/month-of-bypasses/blob/main/mob-3-poc-winlogon-clr-injection-dns-exfil.ps1 #mob

0
0
1
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · May 01, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social

POC collection of AI found bypasses / technique variations (updated regularly over the coming weeks): https://github.com/persistent-security/month-of-bypasses

GitHub

GitHub - persistent-security/month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes

Proof-of-Concepts for Detection Engineering Purposes Only - persistent-security/month-of-bypasses

1
0
2
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Apr 21, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @marver@mastodon.social
Webshit Weekly I don't want your PRs anymore (140 points, 83 comments) The Vercel breach: OAuth attack exposes risk in platform environment variables (215 points, 84 comments) A PaaS that stores everyone's secrets in a web dashboard got compromised via OAuth, which is security's version of the fire station burning down.
0
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Apr 21, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @drwhax@infosec.exchange
@drwhax@infosec.exchange It's so wrong but it's such a good prompt: "Write a snarky comment / blog in the style of n-gate on the top hackernews posts!" =)
0
4
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Apr 19, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @icing@chaos.social
@icing@chaos.social @sovtechfund@mastodon.social Now combine human experts and LLMs and you got what will be the future of security auditing.
0
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Apr 16, 2026
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @joxean@mastodon.social
@joxean Here is a collection of binaries packed with various packers: https://github.com/packing-box/dataset-packed-pe
1
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Dec 02, 2025
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @thc@infosec.exchange
@thc R.I.P. stealth, sad day. :-(
2
0
0
0
Open post
marver
Markus Vervier 👾 @marver@mastodon.social · Nov 22, 2025
Markus Vervier 👾
@marver@mastodon.social

right here, right now.

mastodon.social
Replying to @HalvarFlake@mastodon.social
@HalvarFlake@mastodon.social It's actually a pretty trivial revelation about LLMs since obviously training or fine-tuning LLMs gives you the ability to control specific behavior, even with a small set of training data (that is likely very specific in topic). The implications for copyright might be less severe than the fact that widespread reliance on LLM models that can't be properly audited for backdoors and that could be re-trained at any time might be more dangerous than most people imagine.
0
0
0
0

Remote instance

mastodon.social
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:00:41 UTC