MC

Marcus Chen

Security Researcher

Vulnerability researcher focused on enterprise software and network security. Breaks things so they can be fixed.

Articles by Marcus(32)

Cisco Snort 3 Flaws Enable DoS and Data Leaks
Vulnerabilities3 min read

Cisco Snort 3 Flaws Enable DoS and Data Leaks

CVE-2026-20026 and CVE-2026-20027 allow remote attackers to crash Snort or extract sensitive data. No workarounds exist—patches are the only fix.

Marcus ChenJan 10, 2026
Coolify Command Injection Flaws Grant Root Access
Vulnerabilities4 min read

Coolify Command Injection Flaws Grant Root Access

Five critical vulnerabilities in the self-hosting platform allow authenticated users to execute arbitrary commands as root. Over 52,000 instances are exposed globally.

Marcus ChenJan 10, 2026
jsPDF Flaw Lets Attackers Embed Local Files in PDFs
Vulnerabilities4 min read

jsPDF Flaw Lets Attackers Embed Local Files in PDFs

CVE-2025-68428 enables path traversal in the popular JavaScript PDF library, allowing attackers to read arbitrary files from Node.js servers and exfiltrate them via generated documents.

Marcus ChenJan 9, 2026
Chrome Patches High-Severity WebView Policy Bypass
Vulnerabilities4 min read

Chrome Patches High-Severity WebView Policy Bypass

CVE-2026-0628 allowed malicious extensions to inject scripts into privileged pages through insufficient policy enforcement. Update to Chrome 143.0.7499.192.

Marcus ChenJan 7, 2026
IBM API Connect Auth Bypass Rated CVSS 9.8
Vulnerabilities4 min read

IBM API Connect Auth Bypass Rated CVSS 9.8

CVE-2025-13915 allows remote attackers to bypass authentication without credentials. Affects versions 10.0.8.0 through 10.0.8.5 and 10.0.11.0 used by major banks and airlines.

Marcus ChenJan 1, 2026
CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices
Vulnerabilities4 min read

CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices

CVE-2025-54322 enables unauthenticated root RCE on SD-WAN appliances and edge routers. Vendor has ignored seven months of disclosure attempts. No patch available.

Marcus ChenJan 1, 2026