
@Random_Robbie @LargeCardinal All good here bud. Was hoping to cross paths at SteelCon but it clashed with Oasis. No idea what happened with BSides Liverpool either. You good bud?
English
Nicky Bloor
5K posts

@nickstadb
Coder, hacker, infosec researcher, adrenaline junkie. Once hiked Ben Nevis, Scafell Pike, and Snowdon in 22h 48m. Not a snake oil peddler.















🚨 Apache Roller Hit by 10.0 CVSS Flaw! Old sessions stay active even after a password change (CVE-2025-24859). Hackers can keep access silently. All versions ≤6.1.4 affected. 👉 Full details: thehackernews.com/2025/04/critic… 🔒 Fixed in v6.1.5. Patch now.

CVE database is becoming a joke TBH, when things like CVE-2025-24859 are published with a CVSS score of 10.0 - To exploit this vulnerability you first need to obtain a valid session token, then you only maintain access to the corresponding user account... cve.org/CVERecord?id=C…









