Issue no. 42 · The security zine
Security is all about context.
Practical security thinking for systems that increasingly write, deploy, and operate themselves. Fewer buzzwords. Better evidence. Occasional memes.
CVE-2026-102334 NginxProxyManager nginx-proxy-manager★CVE-2026-102361 gz-yami mall4j★CVE-2026-93348 Unsloth unsloth-zoo★CVE-2026-93355 BerriAI LiteLLM★CVE-2026-101007 aaPanel BaoTa★CVE-2026-101008 aaPanel BaoTa★CVE-2026-101009 aaPanel BaoTa★CVE-2026-100721 vm2 vm2★CVE-2026-100840 Project-MONAI MONAI★CVE-2026-100841 Project-MONAI MONAIPatch forecast · Sep 29
Known-exploited vulnerabilities are in the wild. Patch like it is raining.
Field report · sweep 03 · 42 contacts on the board
Advisory desk
Known exploitation already skipped the prioritization meeting.
NginxProxyManager nginx-proxy-manager
Nginx Proxy Manager through 2.16.0 has no rate limiting on the login and 2FA endpoints, so unauthenticated attackers can brute-force credentials and TOTP codes to gain full administrative control.
gz-yami mall4j
mall4j through 4.0 leaves PUT /user/updatePwd without authentication, letting anyone reset any storefront account password by supplying the target username in the request body.
Unsloth unsloth-zoo
Unsloth Zoo before 2026.8.14 builds a Python import statement from model_type values without an allowlist, so a crafted config.json newline injects arbitrary Python that runs when the model is loaded.
Live demo · try it right here
Find leaked secrets without leaking them.
Paste code, config, or logs below. 112 detectors run entirely in your browser and return redacted findings, reasoned risk scores, and rotation guidance. Nothing uploads. Nothing phones home.
Inspect source material
No upload step exists. Files are read by your browser, scanned in memory, and discarded when the tab closes.
Findings
Ready when you are.
Add source material on the left. Results are pattern matches, not proof that a credential is active.
Latest transmissions
For the work after the scanner finishes yelling.
A field guide to agentic vulnerability management (with an actual off switch)
A practical operating model for introducing agents without confusing automation, authority, and accountability.
Finding vulnerabilities is getting cheaper. The backlog has noticed.
AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.
The vulnerability ticket is an interface, not a filing cabinet
A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.
exhibit A: the backlog