JSTGTECH
← All posts

Tagged “appsec”

3 posts

Java deserialization after Log4Shell: CVE-2023-46604

Apache ActiveMQ's unauthenticated RCE shows Java deserialization bugs never went away after Log4Shell — only the exploitation playbook got faster.

securityjavacveappsec

Leaked credentials in public repos get used in minutes

GitGuardian logged 28.65M secrets on public GitHub in 2025, and researchers have watched leaked AWS keys get abused in under five minutes.

securitygithubsecretsappsec

MOVEit and the MFT zero-day exploitation playbook

CVE-2023-34362 turned one SQL injection in MOVEit Transfer into 2,700+ breached organizations — and the same pattern keeps repeating against MFT software.

securitycveransomwareappsec