DEV Community

StarkMan profile picture

StarkMan

404 bio not found

Joined Joined on 
The Unauthenticated Docker API: 298,430 Exposed Endpoints and Why Port 2375 Still Matters

The Unauthenticated Docker API: 298,430 Exposed Endpoints and Why Port 2375 Still Matters

Comments
3 min read

Want to connect with StarkMan?

Create an account to connect with StarkMan. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Tool-Call Injection in LLM Agents: Why Your MCP Server Is the New Attack Surface

Tool-Call Injection in LLM Agents: Why Your MCP Server Is the New Attack Surface

Comments
4 min read
15.6 Million Exposed RDP Endpoints: Why Remote Desktop Remains the Favourite Initial Access Vector

15.6 Million Exposed RDP Endpoints: Why Remote Desktop Remains the Favourite Initial Access Vector

Comments
4 min read
CVE-2026-87827 and the botnet supply chain behind cheap DVR hardware

CVE-2026-87827 and the botnet supply chain behind cheap DVR hardware

Comments
2 min read
CVE-2026-73807 and CVE-2026-82567: Missing Authorization in mySCADA myPRO Manager

CVE-2026-73807 and CVE-2026-82567: Missing Authorization in mySCADA myPRO Manager

Comments
2 min read
Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Comments
3 min read
When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

Comments
4 min read
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

1
Comments
4 min read
Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT

Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT

Comments
5 min read
Langflow CVE-2026-12944: How a Scanner Blocklist Gap Turns Into Root Code Execution

Langflow CVE-2026-12944: How a Scanner Blocklist Gap Turns Into Root Code Execution

Comments
4 min read
SonicWall SMA1000 Command Injection (CVE-2026-83549): Chained Zero-Day to Root on the Edge

SonicWall SMA1000 Command Injection (CVE-2026-83549): Chained Zero-Day to Root on the Edge

Comments
3 min read
The Management Plane Is the Attack Surface: What Cisco FMC's Exploited Zero-Day Teaches About Exposed Admin Interfaces

The Management Plane Is the Attack Surface: What Cisco FMC's Exploited Zero-Day Teaches About Exposed Admin Interfaces

Comments
5 min read
Exposed PLCs Are Still on the Internet: What CISA's Water Sector Alert Means for Attack Surface Management

Exposed PLCs Are Still on the Internet: What CISA's Water Sector Alert Means for Attack Surface Management

Comments
5 min read
Security Exposure Counts Need Context

Security Exposure Counts Need Context

Comments
1 min read
Use ZoomEye to find Jupyter servers without identity verification enabled

Use ZoomEye to find Jupyter servers without identity verification enabled

Comments
6 min read
Best Practices for Enhancing Attack Surface Management and Accelerating Vulnerability Response

Best Practices for Enhancing Attack Surface Management and Accelerating Vulnerability Response

Comments
2 min read
Shodan vs ZoomEye Query Syntax Comparison

Shodan vs ZoomEye Query Syntax Comparison

1
Comments
2 min read
A Complete Guide to the Latest ZoomEye Search Syntax

A Complete Guide to the Latest ZoomEye Search Syntax

2
Comments
6 min read
Top 5 Domain and IP Intelligence Tools in OSINT

Top 5 Domain and IP Intelligence Tools in OSINT

2
Comments
3 min read
The Hunter Behind the Hacker

The Hunter Behind the Hacker

Comments 1
3 min read
Top 5 Technical Asset Discovery Tools in OSINT

Top 5 Technical Asset Discovery Tools in OSINT

Comments
3 min read
loading...