Issue no. 42 · The security zine
Security is all about context.
Practical security thinking for systems that increasingly write, deploy, and operate themselves. Fewer buzzwords. Better evidence. Occasional memes.
CVE-2026-69435 Microsoft Azure SRE Agent★CVE-2026-77900 Microsoft Azure App Service for Linux★CVE-2026-83943 Microsoft Azure API Center★CVE-2026-88131 Microsoft Microsoft Dataverse★CVE-2026-94510 Microsoft Microsoft Bookings★CVE-2026-96207 Microsoft Microsoft Partner Center★CVE-2026-107639 ILIAS ILIAS★CVE-2026-107782 System Informer System Informer★CVE-2026-14502 IBM DataPower Gateway★CVE-2026-14905 IBM DataPower GatewayPatch forecast · Oct 9
Known-exploited vulnerabilities are in the wild. Patch like it is raining.
Field report · sweep 03 · 60 contacts on the board
Advisory desk
Known exploitation already skipped the prioritization meeting.
Microsoft Azure SRE Agent
Azure SRE Agent had a missing authorization check that an authenticated attacker could abuse over the network to elevate privileges, rated critical at CVSS 9.6.
Microsoft Azure App Service for Linux
A missing authentication check on a critical function in Azure App Service for Linux let attackers run code over the network without any credentials, rated critical at CVSS 9.8.
Microsoft Azure API Center
Azure API Center exposed sensitive information to unauthorized actors over the network, rated high at CVSS 8.7 with changed scope and high confidentiality and integrity impact.
Live demo · try it right here
Find leaked secrets without leaking them.
Paste code, config, or logs below. 112 detectors run entirely in your browser and return redacted findings, reasoned risk scores, and rotation guidance. Nothing uploads. Nothing phones home.
Inspect source material
No upload step exists. Files are read by your browser, scanned in memory, and discarded when the tab closes.
Findings
Ready when you are.
Add source material on the left. Results are pattern matches, not proof that a credential is active.
Latest transmissions
For the work after the scanner finishes yelling.
A field guide to agentic vulnerability management (with an actual off switch)
A practical operating model for introducing agents without confusing automation, authority, and accountability.
Finding vulnerabilities is getting cheaper. The backlog has noticed.
AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.
The vulnerability ticket is an interface, not a filing cabinet
A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.
exhibit A: the backlog