Blog
Raw thoughts from the man behind the beard.
-
Pwn’d or Patched, you choose. Unifi, Log4J, and PwnKit
Pwn’d or Patched using CVE 2021-44228 (Log4Shell) and CVE 2021-4034 (PwnKit). If you read my initial writeup on the Unifi unpatched status you will know this is still a HUGE issue that needs to be solved.
-
State of Security… Patch people, Patch. Log4J and Unifi, the horror
Most people patch quickly, right?… right?… right??? I demonstrated the Log4Unifi GitHub repo for easily attacking CVE-2021-44228 on YouTube, then went looking for how many unpatched Unifi controllers are still out there.
-
Live Compromised
Threat actors will always win. Let that sink in for a second — it is proven time and again that a concerted actor will gain access to your systems and assets if the reward is high enough or the order is given.