Markus Vervier

8.2K posts

Markus Vervier banner
Markus Vervier

Markus Vervier

@marver

Security Vulnerability Coach, responsible for @x41sec and @persistent_psi Tweets here are my own.

Right here Katılım Ocak 2009
601 Takip Edilen3.4K Takipçiler
Markus Vervier
Markus Vervier@marver·
Markus Vervier@marver

While everyone was on Holiday we scanned the Internet for #BadHost (CVE-2026-48710): zero auth required, affecting FastAPI, vLLM, LiteLLM, and many more - basically the whole AI infra stack! What we found is: clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 NOW and check your exposure at badhost.org

ZXX
0
0
0
130
Markus Vervier retweetledi
Alex Nguyen
Alex Nguyen@AlexNguyen65·
Millions of AI agents imperiled by critical vulnerability in open source package. “BadHost” was found in Starlette, a package with 325 million weekly downloads. arstechnica.com/information-te…
English
0
1
2
70
Markus Vervier
Markus Vervier@marver·
While everyone was on Holiday we scanned the Internet for #BadHost (CVE-2026-48710): zero auth required, affecting FastAPI, vLLM, LiteLLM, and many more - basically the whole AI infra stack! What we found is: clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 NOW and check your exposure at badhost.org
English
3
19
49
8.5K
Markus Vervier retweetledi
Shift
Shift@Shiftreduce·
We live in interesting times. Last month Linux patched a core uaf in the epoll subsystem, we rarely see these kind of bugs. As i like these kind of bugs, i wrote a few words about it here: guysrd.github.io
English
4
74
274
36.3K
Markus Vervier retweetledi
Python Programming
Python Programming@PythonPr·
Claude Code vs Developer 🤣🤣🤣
Français
45
290
2.5K
262.5K
Markus Vervier
Markus Vervier@marver·
Running FastAPI or another python ASGI framework? Then patch Starlette now, chances are high it's in your supply chain! A host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory: x41-dsec.de/lab/advisories…
English
1
0
1
274
Markus Vervier retweetledi
Saeed Abbasi
Saeed Abbasi@saeed4bbasi·
Our @qualys TRU advisory for CVE-2026-46333 is live. Local root impact in the Linux kernel ptrace path. The patch went public, PoCs followed, and defenders were left racing. The gap between patch and protection is becoming one of security’s defining problems, current disclosure was not built for this. cdn2.qualys.com/advisory/2026/…
English
1
12
25
6.7K
David Adrian
David Adrian@dadrian·
Tomorrow, I will drop Chrome exploit code showing how an attacker can execute arbitrary Javascript within the context of a domain they control.
English
15
28
406
74.1K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
anybody else getting older and noticing that you increasingly talk to yourself????
English
48
10
194
15K
Markus Vervier retweetledi
TrendAI Zero Day Initiative
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
TrendAI Zero Day Initiative tweet media
English
29
184
1.5K
260.3K
Markus Vervier
Markus Vervier@marver·
If AI is taking jobs everywhere and especially in security, why is everyone I currently deal with swamped with work?
English
1
0
1
171
Markus Vervier retweetledi
Haifei Li
Haifei Li@HaifeiLi·
CVE-2026-40361 (msrc.microsoft.com/update-guide/v…), patched today, is a critical 0-click UAF/RCE bug in Microsoft Outlook that I discovered back in Q1. You definitely want to patch this sooner rather than later. The danger of such 0-click bugs in Outlook is that they are triggered as soon as the victim reads or previews the email - no clicking of links or attachments is required. Since the bugs reside in Outlook's email rendering engine, it is difficult to mitigate or block (though specifically setting Outlook to render emails only in plain text format is a valid mitigation). Fun fact about the discovery: after the discovery of the #BadWinmail bug a decade ago, I wanted to run an experiment in Q1 to see if I could find another 0-click RCE in Outlook. The result? It wasn't easy — I even built a dedicated system for it — but I eventually found this one. :) To understand why such bugs are so critical, check out the #BadWinmail video demo I released a decade ago: youtube.com/watch?v=ngWVbc…. They share the same attack vector (though #BadWinmail was a working exploit, while this one was a PoC). Essentially, anyone could compromise a CEO or CFO just by sending an email. The threat perfectly bypasses enterprise firewalls and is delivered directly to the inbox. Furthermore, note that Outlook (Classic) lacks an application sandbox, making this attack vector even more dangerous. Regarding defense and detection: if you are concerned about Outlook 0-click 0-days, my EXPMON system (pub.expmon.com) provides cutting-edge detection against such advanced threats. When I designed the original system in 2020/2021, I developed this functionality specifically considering the impact of #BadWinmail. The system accepts .eml or .msg formats, and email samples are deeply tested within an Outlook sandbox. For enterprise users, emails can be "dumped" from the mail server, and EXPMON can be deployed in a private network. Contact me for more details. P.S. I just noted that the title of the Microsoft Security Update (msrc.microsoft.com/update-guide/v…) lists this as a Microsoft Word bug, which may or may not be entirely accurate. I demonstrated this bug to MSRC by showing that it works in a real, live Outlook + Exchange Server environment. My bet is that because the bug resides in wwlib.dll — a shared DLL used heavily by both Outlook and Word — it likely affects both Outlook (via email) and Word (via a document file). Regardless of the title, it is a genuine Outlook 0-click RCE. #CVE-2026-40361 #PatchTuesday #Outlook #0click #EmailSecurity #EnterpriseSecurity #expmon #ThreatIntel #ExploitDetection
YouTube video
YouTube
English
6
86
425
57.9K
Markus Vervier retweetledi
Dudes Posting Their W’s
Dudes Posting Their W’s@DudespostingWs·
This guy got so annoyed with spam callers that he wrote a script that endlessly calls them back and plays Rick Astley’s “Never Gonna Give You Up” on repeat until they finally block his number.
English
579
2.6K
21.8K
996.4K
blasty
blasty@bl4sty·
my prediction is we will finally properly crack down on these npm supply chain attacks once left-pad gets hit
English
1
0
12
2.2K
Markus Vervier
Markus Vervier@marver·
26b74a3148a790a887f7e59a93905eea2fa126a917aae28f4a428e8494cdf4d6
Português
0
0
1
82