Blog
Blog & Insights
In-depth articles on CMS, DevSecOps, process automation, and digital transformation.
Kategorie
DevSecOps
CI/CD-Pipelines, Container-Security, Code-Audits, Patch-Workflows, eBPF-Detection — operative Sicherheit über den gesamten Build-Run-Stack.
98 Beiträge
Fake Claude Code installer (ClickFix/polyglot)
Weiterlesen →Symfony CVE-2026-48736 (SSRF bypass)
Weiterlesen →Symfony CVE-2026-48489 (Firewall Bypass)
Weiterlesen →
Chromium 148 Stable (127 fixes)
Weiterlesen →
Keycloak CVE-2026-9795 (FGAPv2 PrivEsc)
Weiterlesen →
rpmuncompress CVE-2026-44604 (command injection)
Weiterlesen →
KubeVirt CVE-2026-9804 (symlink traversal)
Weiterlesen →
OpenShift Router double (SSRF + mTLS)
Weiterlesen →Kernel wave CVE-2026-46227 (SCTP)
Weiterlesen →
Project Lightwell (IBM/Red Hat)
Weiterlesen →
Samba CVE-2026-4408 (SAMR RCE)
Weiterlesen →
vpmdhaj npm Typosquat (OpenSearch/Elastic)
Weiterlesen →
TinyMCE CVE-2026-47759 (data-mce Bypass)
Weiterlesen →![Overhead still life on a matte dark slate surface, the working table of a routing auditor. At centre, a low circular brushed-brass sorting tray with a thin central bar dividing the tray into two pigeonholes — the left one stamped /public/discovery, the right one stamped /admin/settings, both in monospaced letterpress. Lying across the central bar, a single paper-cream letter: its upper half stamped Host: example.com/.well-known/ protrudes into the /public pigeonhole, while its lower half with the slip path: /admin/settings protrudes into the /admin pigeonhole. On the upper /public half of the letter sits a single deep oxblood wax drop, pressed with a brushed-brass embossing seal as the auth stamp. Lower left, an open linen-bound audit ledger with three monospaced pencil entries, one of them legibly reading scope["path"], beside a paper-cream index card with the monospaced letterpress label CWE-444. Upper right, within the negative space, a brushed-brass embossing stamp with a walnut handle and a second paper-cream index card with the letterpress label Starlette 1.0.1. Cool studio key light from upper left, gentle warm rim light from lower right; the background fades into slate grey and near-black at the right edge, leaving room for a title overlay.](/fileadmin/_processed_/0/c/csm_mcp-bad-host_ff09033cdf.png)
BadHost CVE-2026-48710 (Starlette/MCP)
Weiterlesen →
Anthropic Messages as inter-vendor layer
Weiterlesen →
Composer 2.10 & Packagist roadmap
Weiterlesen →
Abliteration Open-Weight Models
Weiterlesen →
TYPO3 14.3.2 + 13.4.30 (maintenance)
Weiterlesen →
AI tool install as trap (SEO poisoning)
Weiterlesen →
Drupal CVE-2026-9082 (parser-differential class)
Weiterlesen →
Project Glasswing 30 Days
Weiterlesen →
Twin Composer Incident on 22 May 2026 — Laravel-Lang Tag Injection (Aikido) and Postinstall Wave in 8 Composer Packages + 700+ GitHub Repositories (Socket)
Weiterlesen →![[Translate to English:] Halb geöffnete Betontür eines modernen Rechenzentrums — davor ein dunkles Slate-Plinth mit einem aufgerollten oxblood-Kabel und einem Rack-Modul mit Kraft-Paper-Etikett, im Hintergrund die Mosel-Weinberghänge.](/fileadmin/_processed_/a/3/csm_pcq-rfc-9964_1d08925ef7.png)
Post-Quantum Security Is Not a Future Problem — RFC 9964, ML-DSA and What We Already Run in Production
Weiterlesen →