The Stack
A 10-line exploit is now widely available. Unpatched instances *will* come under attack.
Allianz more broadly has successfully ditched mainframe-based core IT applications for x67 servers with Linux operating systems.
Goodbye vSphere Hypervisor. Goodbye Aria Operations. Goodbye NCX. Goodbye HCX. Goodbye more acronyms than we know what to do with; though Broadcom does; at least as standalone SKUs...
Stateful. A Web UI. Customisable plugins. Six LLMs supported. Nice work, Microsoft.
VPN appliances "all appear to have been constructed with the code equivalent of string, stamped with the word ‘secure’ and then just left to decay for 20 years..."
GCP's somewhat limited move to drop "cloud switching" charges is aimed squarely at Microsoft.
"The SEC has not approved the listing and trading of spot bitcoin exchange-traded products"
Another arguably more potent example and one actively exploited in the wild is CVE-2023-46604 – a CVSS 10 RCE vulnerability in Apache ActiveMQ; an open source message broker written in Java.