Posts

2026

Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name
RIPE NCC session fixation: poaching logins with an Atlas probe
1000 third parties could have stolen RIPE NCC session tokens - by design
Taking down a European network with a TLS certificate: my RIPE NCC RPKI exploit chain
Inside a 14-month responsible disclosure with the RIPE NCC
Root from the parking lot: OpenWrt XSS through SSID scanning (CVE-2026-32721)

2014

Hijacking iOS Keychain access groups through Apple’s provisioning portal