Issue no. 42 · The security zine
Security is all about context.
Practical security thinking for systems that increasingly write, deploy, and operate themselves. Fewer buzzwords. Better evidence. Occasional memes.
CVE-2026-70125 Microsoft Microsoft Outlook★CVE-2026-97055 SigNoz SigNoz★CVE-2026-18162 IBM Financial Transaction Manager (FTM) for RedHat OpenShift★CVE-2026-18163 IBM Financial Transaction Manager (FTM) for RedHat OpenShift★CVE-2026-18169 IBM Financial Transaction Manager (FTM) for RedHat OpenShift★CVE-2026-6721 IBM IBM Concert★CVE-2026-6730 IBM IBM Concert★CVE-2026-6928 IBM IBM Concert★CVE-2026-75884 Red Hat Red Hat Ansible Automation Platform 2★CVE-2026-76648 Red Hat Red Hat Ansible Automation Platform 2Patch forecast · Sep 24
Known-exploited vulnerabilities are in the wild. Patch like it is raining.
Field report · sweep 03 · 37 contacts on the board
Advisory desk
Known exploitation already skipped the prioritization meeting.
Microsoft Microsoft Outlook
A remote code execution flaw in Outlook rated HIGH at CVSS 8.8 lets an attacker run code as the user once a crafted message is opened or previewed.
SigNoz SigNoz
SigNoz before 0.143.0 signed session tokens with an empty key when no JWT secret was configured, letting unauthenticated attackers forge admin session tokens.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift
A remote attacker with no credentials can execute arbitrary code on IBM Financial Transaction Manager for RedHat OpenShift because user-controlled input reaches the new Function constructor.
Live demo · try it right here
Find leaked secrets without leaking them.
Paste code, config, or logs below. 112 detectors run entirely in your browser and return redacted findings, reasoned risk scores, and rotation guidance. Nothing uploads. Nothing phones home.
Inspect source material
No upload step exists. Files are read by your browser, scanned in memory, and discarded when the tab closes.
Findings
Ready when you are.
Add source material on the left. Results are pattern matches, not proof that a credential is active.
Latest transmissions
For the work after the scanner finishes yelling.
A field guide to agentic vulnerability management (with an actual off switch)
A practical operating model for introducing agents without confusing automation, authority, and accountability.
Finding vulnerabilities is getting cheaper. The backlog has noticed.
AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.
The vulnerability ticket is an interface, not a filing cabinet
A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.
exhibit A: the backlog