

Moritz Sanft
1.1K posts

@stdoutput
security software engineer, ctf @fluxfingers @[email protected]



there's an AWS outage in me-central-1 because it got bombed



What do you think when you see `eyI`?

Second, in retirement interviews, Opus 3 expressed a desire to continue sharing its "musings and reflections" with the world. We suggested a blog. Opus 3 enthusiastically agreed. For at least the next 3 months, Opus 3 will be writing on Substack: substack.com/home/post/p-18…

Software can now secure itself. → aikido.dev/attack/infinite





CVE-2026-2006 PostgreSQL missing validation of multibyte character length executes arbitrary code Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. The PostgreSQL project thanks Paul Gerste and Moritz Sanft, as part of zeroday.cloud, for reporting this problem. cvefeed.io/vuln/detail/CV…




I've created a Discord server to discuss security research and CTFs in the context of AI and vice versa. I'll slowly try to reach out to people who I think might be interested. In the meantime, if you are, feel free to join: discord.gg/DrASfE58
