Sign in

Dr. Christopher Kunz

@christopherkunz.bsky.social
606 followers 480 following 438 posts

Security and compliance nerd, sword fighter. Opinions are my own, not my employer's. Other social media profiles: Mastodon: @christopherkunz@chaos.social LinkedIn: www.linkedin.com/in/christopherkunz

PostsRepliesMedia
Dr. Christopher Kunz @christopherkunz.bsky.social · 20h
Hahah, that would have actually made sense. But this is Atlassian, so… No, it‘s public static String unescapeSlashes(String string) in http/Router.java, so there‘s that.
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 20h
Tagging @nynbinary for humorous memeing. [3/3]
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 20h
This is from CVE-2026-21589, labs.watchtowr.com/you-wont-hear-ab… The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup. [2/3]
labs.watchtowr.com
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the
210
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Kontextbasierte Werbung, Bosslevel. *chef‘s kiss*
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Bonusfrage: Was sagt das eigentlich über das Vertrauen der Verdächtigen in die geheimdienstlichen Fähigkeiten ihrer eigenen Kollegen und Mitarbeiter aus?
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Und wenn der ehemalige Behördenleiter diese VS als Consultant zu Geld machen konnte? Und was sagt das über das ethische Gedankengerüst eines solchen ehemaligen Spitzenbeamten aus? Der btw etwa 9K Ruhegehalt bekommen dürfte... [2/2]
110
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Wenn die Vorwürfe stimmen: Was sagt das eigentlich über die internen Kontrollmechanismen sowie über die parlamentarische Kontrolle des BND aus, wenn ein hochrangiger Mitarbeiter angeblich fünfzehn Jahre lang VS da raustragen konnte, ohne dass es jemand merkte? [1/2]
110
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Ich schlage hiermit offiziell vor, den 6. Oktober 2026 zum jährlichen "Kannste dir alles nicht ausdenken"-Tag zu ernennen. BND-Edition.
021
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Man, if not even federal agencies fix their vulns, this is all pointless. [3/3]
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published. [1/3]
111
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
The culprit is the kexguess2@matt.ucc.asn.au pseudo algorithm. Just in case you (or my future self) stumble upon this. [2/2]
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Trying to connect to a Dropbear SSH server may give the "** WARNING: connection is not using a post-quantum key exchange algorithm." warning. This might be a false positive, as this Github issue suggests: github.com/jtesta/ssh-audit/issues/… [1/2]
github.com
dropbear kexguess2 "algorithm" flagged as not postquantum-safe · Issue #375 · jtesta/ssh-audit
Dropbear has a "kexguess2@matt.ucc.asn.au" key exchange "algorithm" which does not correspond to an actual algorithm (data field NULL, https://github.com/mkj/dropbear/blob/59870ad43153fe8d4f1c96f5d...
120
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Viel skeptischer als Thomas Lohninger kann eine einzelne Person wohl nicht schauen.
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 06/10/2026
Ist heute eigentlich im deutschsprachigen Fediverse noch jemand anwesend oder sitzen alle in Raum 2.600? (Die Raumnummer ist super!)
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 04/10/2026
Es gibt nun Patches für Citrix Netscaler, meine Meldung ist entsprechend aktualisiert. Ran an die Firmwares! heise.de/-11474971
heise.de
Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung
Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden.
020
Dr. Christopher Kunz @christopherkunz.bsky.social · 04/10/2026
There are now patches for Citrix Netscaler available, I have updated my reporting. heise.de/-11474996
heise.de
Update Citrix Netscaler now: Zero-day causes crashes and code execution
Security researchers and administrators are reporting massive spontaneous reboots of affected devices. Updates are available and should be applied ASAP.
020
Dr. Christopher Kunz @christopherkunz.bsky.social · 03/10/2026
Yay, neuer Zero-Day in Citrix Netscaler: www.heise.de/news/Netscaler-Admins-…
heise.de
Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausführung
Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Diese waren auf dem neuesten Patchstand.
011
Dr. Christopher Kunz @christopherkunz.bsky.social · 01/10/2026
I have questions about lots of of this. For example how the claim "Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost." would technically work at all. [3/3]
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 01/10/2026
RE: infosec.exchange/@josephcox/1173658… [1/3]
infosec.exchange
Joseph Cox (@josephcox@infosec.exchange)
New: iPhones have an automatic reboot feature which quietly reboots the phone after a certain time; cops were freaking out about this when we revealed it in 2024. Now, phone hackers have a way around it, according to a leaked video https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/
100
Dr. Christopher Kunz @christopherkunz.bsky.social · 01/10/2026
I somehow feel that this specific part of the cyberwar documentary "Midnight in the War Room" aged kinda badly. It's framed as "China / North Korea stealing intellectual property", but... well...
023
Dr. Christopher Kunz @christopherkunz.bsky.social · 30/09/2026
In our daily episode of "security appliance jeopardy", we are asking: "What is %6a_security_check?" www.heise.de/en/news/Patch-now-Atta…
heise.de
Patch now: Attackers bypass login on Cisco Catalyst SD-WAN Manager
Cybercriminals exploit a loophole in the login system for admin privileges. Admins should patch devices and take further action.
021
Dr. Christopher Kunz @christopherkunz.bsky.social · 30/09/2026
%6a_security_check
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 30/09/2026
Was machen die da?
001
Dr. Christopher Kunz @christopherkunz.bsky.social · 29/09/2026
Make it happen.
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 27/09/2026
Thank you! I‘m juggling weekend and Citrix tasks rn.
020
Dr. Christopher Kunz @christopherkunz.bsky.social · 26/09/2026
I‘m so done. Seriously. Every single time today when I turned on the PC to just play ten quiet minutes of No Man‘s Sky, a new fire in the PKI and Infosec world popped up. Can we just stop doing this on the weekend?
031
Dr. Christopher Kunz @christopherkunz.bsky.social · 26/09/2026
RE: infosec.exchange/@watchTowr/1173383… And the next "turn off your appliances NAU" type of advisory, if one can believe the rumors.
infosec.exchange
watchTowr (@watchTowr@infosec.exchange)
Angehängt: 1 Bild We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the limited information available is credible, and we are thus imploring organizations to take it seriously. Active watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
021
Dr. Christopher Kunz @christopherkunz.bsky.social · 25/09/2026
Yes. We also have confirmation by the Kiteworks CISO.
110
Dr. Christopher Kunz @christopherkunz.bsky.social · 25/09/2026
Kiteworks-CISO an Kiteworks-Kunden: Abschalten. Und zwar morgen von 04:00 bis 10:00 CEST. Details hier: www.heise.de/news/Bevorstehender-Ze… Video: chaos.social/@christopherkunz/11733…
111
Dr. Christopher Kunz @christopherkunz.bsky.social · 25/09/2026
Soooooo.... any KiteWorks customers in my network?
200
Dr. Christopher Kunz @christopherkunz.bsky.social · 23/09/2026
There's an account here that posts "directory traversal" memes and recent vulns of that type. I can't seem to find it - anyone got an idea?
001
Dr. Christopher Kunz @christopherkunz.bsky.social · 23/09/2026
"Vertrauen ist der neue Perimeter". Im Vorfeld der it-sa sammeln sich die Binsenweisheiten in meiner Inbox, nebst Gesprächsangeboten. Was ist bis jetzt Eure beste it-sa-PR-Binse?
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 22/09/2026
And did you know that the exact same type of lock has been in use at the Bundeswehr until recently - for example in transport boxes for medical equipment? Now you do. And this tidbit probably overwrote the memory of your first schoolday. Thank me later.
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 22/09/2026
Also, the stamp "Klappe schliessen!" is sometimes stamped in a serif font, sometimes it seems to be in DIN-1451. And there's sometimes a rectangle around the stamp, sometimes there isn't. Intriguing. [2/2]
100
Dr. Christopher Kunz @christopherkunz.bsky.social · 22/09/2026
I see your niche hyperfocus and I raise you one niche hyperfocus. In the wooden boxes for Enigma encryption machines, the position of the lock varies between different models and/or manufacturers. Sometimes, the lock is in the lid, sometimes the pin is in the lid. [1/2]
100
Dr. Christopher Kunz @christopherkunz.bsky.social · 22/09/2026
Ich möchte auch gern die Zukunft von " " vorantreiben.
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 22/09/2026
heise-conferences.de/webinar/zweite… [2/2]
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 21/09/2026
If I restarted blogging semi-regularly (and that's a big "if"), what would you like to read? Poll: chaos.social/@christopherkunz/11730…
chaos.social
Dr. Christopher Kunz (@christopherkunz@chaos.social)
If I restarted blogging semi-regularly (and that's a big "if"), what would you like to read? [ ] News of the week type articles [ ] In-depth commentary on specific topics [ ] nerdy stuff that interests 12 ppl worldwide [ ] "Building my HA web server setup" type admin stuff
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 21/09/2026
Nerdflohmarkt in der Bürgerschule in Hannover am 18.10.: www.stadtteil-zentrum-nordstadt.de/…
Nerdflohmarkt-Flyer an einer Laterne in der Nordstadt.
020
Dr. Christopher Kunz @christopherkunz.bsky.social · 21/09/2026
Suche für ein Experiment einen Rest PEBA-Filament. 50 Gramm oder sowas sollten reichen, Farbe egal. Hat da jemand was?
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 16/09/2026
NightmareEclipse is Abdelhamid Naceri, a former MSFT employee from Germany. I called it in April: echo "Abdelhamid Naceri"|sha256 7bc241eaf173d9d0728abecfb71706c04586a82d7eb743d946aea69899a54dc8 www.christopher-kunz.de/about-night…
christopher-kunz.de
About Nightmare Eclipse
Just in case they get uncovered eventually
011
Dr. Christopher Kunz @christopherkunz.bsky.social · 16/09/2026
gt/grJ3s ) das Unternehmen "DPT - Data Privacy Trust" jahrelang unverlangte Mails zuschicken kann und darin Datenschutzdienstleistungen bewirbt? Eingeliefert natürlich über einen US-Maildienstleister, alleine das ist IMHO schon ein DSGVO-Verstoß. Wie geht man dagegen wirksam vor? [2/2]
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 16/09/2026
"Security Silverbacks" is a pretty neat name for the guys who published SAPMAP ("Like Bloodhound but for SAP"). But take a look who's apparently a "Security Silverback" now... (Source: github.com/SecuritySilverbacks/SAPM… )
011
Dr. Christopher Kunz @christopherkunz.bsky.social · 16/09/2026
I guess I could build my own PowerDNS and have it be a hidden primary for my authoritatives, but that's not my favorite solution. [2/2]
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 15/09/2026
Kontextbasierte und zielgruppenorientierte Werbung, hier: Spiegel Online. Lovin' it!
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 14/09/2026
Jetzt noch anmelden, am besten gleich fürs Doppelpack: heise-conferences.de/webinar/zweite… [3/3]
000
Dr. Christopher Kunz @christopherkunz.bsky.social · 14/09/2026
Security Posture für Kubernetes entwickeln und eigene Container blueteamen, darum geht's mit Felix Roider von iSecNG. 100% redaktionell, keine Werbung, reines Knowhow. [2/3]
100
Dr. Christopher Kunz @christopherkunz.bsky.social · 12/09/2026
In meiner Erinnerung waren wir in der TIB. Und nachmittags war ich bei heise und las im IRC die Entwicklungen live mit. Niemand wusste, was da gerade passiert, die Gerüchte und Spekulationen waren wild.
011
Dr. Christopher Kunz @christopherkunz.bsky.social · 11/09/2026
Wir liefern mit der CySecMed in 40 Vorträgen das Forum für den fachlichen Austausch. Wenn Du dabei sein willst, kriegst du mit dem Vouchercode hinter dem Shortlink 20% Rabatt. Wann: 13.-14.10. in Unterhaching Vouchercode: heise.de/s/lwv45 Programm: cysecmed.de/programm [2/2]
cysecmed.de
Die CySecMed ist die spezialisierte Fachkonferenz für Cyber Security in der Medizintechnik
Sie richtet sich an Unternehmen, deren Produkte softwaregetrieben, vernetzt und sicherheitskritisch sind. Damit sind sie unmittelbar Teil der kritischen Infrastruktur.
010
Dr. Christopher Kunz @christopherkunz.bsky.social · 11/09/2026
Noch heute gruselt es mich bei dem Gedanken an die Headline "Kriminelle veröffentlichen Fotos von Krebspatientinnen". Security muss als zentrales Thema in der Medizin verankert bleiben. [1/2]
111