<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Sedric Louissaint · Blog</title><description>Sedric Louissaint leads the penetration testing practice at CLA, advises organizations on real cyber risk, serves as an expert witness, and helps professionals build careers in security.</description><link>https://sedriclouissaint.com/</link><language>en-us</language><atom:link href="https://sedriclouissaint.com/rss.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Sat, 25 Jul 2026 00:00:00 GMT</lastBuildDate><item><title>One Exported Service, Six Free Rides: How I Found CVE-2026-12960 in the ASUS Router App</title><link>https://sedriclouissaint.com/blog/asus-router-app-exported-commandservice-cve-2026-12960/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/asus-router-app-exported-commandservice-cve-2026-12960/</guid><description>I went looking for something clever in the ASUS Router Android app and instead found a service sitting wide open with a sign on it. Here is the whole story: the manifest, the Parcelable, the six payloads, and the wait for a fix.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/asus-router-app-exported-commandservice-cve-2026-12960.jpg&quot; alt=&quot;CVE-2026-12960: three Android screenshots showing a browser, an SMS composer, and a dialer all launched by the ASUS Router app&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;I went looking for something clever in the ASUS Router Android app and instead found a service sitting wide open with a sign on it. Here is the whole story: the manifest, the Parcelable, the six payloads, and the wait for a fix.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/asus-router-app-exported-commandservice-cve-2026-12960.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/asus-router-app-exported-commandservice-cve-2026-12960.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Mobile Security</category><category>Penetration Testing</category><category>Vulnerability Disclosure</category><category>CVE-2026-12960</category><enclosure url="https://sedriclouissaint.com/blog/hero/asus-router-app-exported-commandservice-cve-2026-12960.jpg" length="53918" type="image/jpeg"/></item><item><title>Released Is Not the Same as Accessible: Why I Built a Searchable Archive of the Epstein Files</title><link>https://sedriclouissaint.com/blog/epstein-files-public-archive/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/epstein-files-public-archive/</guid><description>Millions of pages are public, and almost nobody can actually search them. That gap is why I built EpsteinFTA.com, a public archive for justice, transparency, and accountability.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/epstein-files-public-archive.jpg&quot; alt=&quot;Epstein Files Public Archive: Justice/Transparency/Accountability&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;Millions of pages are public, and almost nobody can actually search them. That gap is why I built EpsteinFTA.com, a public archive for justice, transparency, and accountability.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/epstein-files-public-archive.jpg" type="image/jpeg" medium="image" width="1200" height="675"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/epstein-files-public-archive.jpg" width="1200" height="675"/><category>Journalism</category><category>Justice</category><category>Surveillance</category><category>Transparency</category><enclosure url="https://sedriclouissaint.com/blog/hero/epstein-files-public-archive.jpg" length="141219" type="image/jpeg"/></item><item><title>The Stryker Incident Is a Warning: Every Organization Must Plan for Nation-State Adversaries</title><link>https://sedriclouissaint.com/blog/stryker-breach-nation-state-preparedness/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/stryker-breach-nation-state-preparedness/</guid><description>A cyber incident stopped Stryker&apos;s order processing, manufacturing, and shipping, and delayed some surgeries, without ever touching a medical device. Most organizations still plan for commodity ransomware. This is the other threat model.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/stryker-breach-nation-state-preparedness.jpg&quot; alt=&quot;The Stryker Incident Is a Warning: Every Organization Must Plan for Nation-State Adversaries&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;A cyber incident stopped Stryker&apos;s order processing, manufacturing, and shipping, and delayed some surgeries, without ever touching a medical device. Most organizations still plan for commodity ransomware. This is the other threat model.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/stryker-breach-nation-state-preparedness.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/stryker-breach-nation-state-preparedness.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Hacking</category><category>Supply Chain</category><enclosure url="https://sedriclouissaint.com/blog/hero/stryker-breach-nation-state-preparedness.jpg" length="115752" type="image/jpeg"/></item><item><title>The Axios npm Supply Chain Attack Is a Warning Shot for the Entire JavaScript Ecosystem</title><link>https://sedriclouissaint.com/blog/axios-npm-supply-chain-attack/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/axios-npm-supply-chain-attack/</guid><description>Two malicious versions of Axios reached npm through a compromised maintainer account, each carrying a dependency whose only job was to drop a remote access trojan at install time. The target was never your users. It was your build machine.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/axios-npm-supply-chain-attack.jpg&quot; alt=&quot;The Axios npm Supply Chain Attack Is a Warning Shot for the Entire JavaScript Ecosystem&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;Two malicious versions of Axios reached npm through a compromised maintainer account, each carrying a dependency whose only job was to drop a remote access trojan at install time. The target was never your users. It was your build machine.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/axios-npm-supply-chain-attack.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/axios-npm-supply-chain-attack.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Hacking</category><category>Supply Chain</category><enclosure url="https://sedriclouissaint.com/blog/hero/axios-npm-supply-chain-attack.jpg" length="104374" type="image/jpeg"/></item><item><title>When an Algorithm Can Steal Months of Your Life, We Need to Rethink What We Are Accepting</title><link>https://sedriclouissaint.com/blog/when-ai-gets-it-wrong/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/when-ai-gets-it-wrong/</guid><description>A facial recognition match put a Tennessee grandmother in jail for months over a crime in a state she had never visited. She lost her home, her car, and her dog. The bank records that cleared her were available the entire time.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/when-ai-gets-it-wrong.jpg&quot; alt=&quot;When an Algorithm Can Steal Months of Your Life, We Need to Rethink What We Are Accepting&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;A facial recognition match put a Tennessee grandmother in jail for months over a crime in a state she had never visited. She lost her home, her car, and her dog. The bank records that cleared her were available the entire time.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/when-ai-gets-it-wrong.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/when-ai-gets-it-wrong.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Privacy</category><category>Surveillance</category><enclosure url="https://sedriclouissaint.com/blog/hero/when-ai-gets-it-wrong.jpg" length="114506" type="image/jpeg"/></item><item><title>Unseen Eyes: Navigating Privacy and Security with Flock Cameras</title><link>https://sedriclouissaint.com/blog/flock-cameras-privacy-surveillance/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/flock-cameras-privacy-surveillance/</guid><description>Flock&apos;s cameras can zoom in close enough to read your phone screen, and the researcher who found more than 50 vulnerabilities in the network behind them lost his job for saying so. This is what surveillance at national scale looks like without oversight.</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/flock-cameras-privacy-surveillance.jpg&quot; alt=&quot;Unseen Eyes: Navigating Privacy and Security with Flock Cameras&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;Flock&apos;s cameras can zoom in close enough to read your phone screen, and the researcher who found more than 50 vulnerabilities in the network behind them lost his job for saying so. This is what surveillance at national scale looks like without oversight.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/flock-cameras-privacy-surveillance.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/flock-cameras-privacy-surveillance.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Privacy</category><category>Surveillance</category><enclosure url="https://sedriclouissaint.com/blog/hero/flock-cameras-privacy-surveillance.jpg" length="118870" type="image/jpeg"/></item><item><title>Job and Investment Scams Are Becoming More Sophisticated</title><link>https://sedriclouissaint.com/blog/job-and-investment-scams/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/job-and-investment-scams/</guid><description>Someone I know was groomed for six months before the fake trading platform ever came up. Modern job and investment scams run on patience, your digital footprint, and AI, and some of them are staffed by people who answered a fake job ad themselves.</description><pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/job-and-investment-scams.jpg&quot; alt=&quot;Job and Investment Scams Are Becoming More Sophisticated&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;Someone I know was groomed for six months before the fake trading platform ever came up. Modern job and investment scams run on patience, your digital footprint, and AI, and some of them are staffed by people who answered a fake job ad themselves.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/job-and-investment-scams.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/job-and-investment-scams.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Hacking</category><enclosure url="https://sedriclouissaint.com/blog/hero/job-and-investment-scams.jpg" length="145930" type="image/jpeg"/></item><item><title>Anyone, Please Interact: Two APIs That Never Asked Who I Was</title><link>https://sedriclouissaint.com/blog/api-security-fundamentals/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/api-security-fundamentals/</guid><description>Two penetration tests, two APIs that never checked. One handed HIPAA-protected medical records to the open internet. The other let anyone pull live card data from an app the bank swore was still in development. Same bug, two costumes.</description><pubDate>Sun, 27 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/api-security-fundamentals.jpg&quot; alt=&quot;Anyone, Please Interact: two wide-open APIs, medical records and live card data&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;Two penetration tests, two APIs that never checked. One handed HIPAA-protected medical records to the open internet. The other let anyone pull live card data from an app the bank swore was still in development. Same bug, two costumes.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/api-security-fundamentals.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/api-security-fundamentals.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Ethical Hacking</category><category>Hacking</category><category>HIPAA</category><category>PCI DSS</category><category>Penetration Testing</category><enclosure url="https://sedriclouissaint.com/blog/hero/api-security-fundamentals.jpg" length="133401" type="image/jpeg"/></item><item><title>SqlNow: How One Apostrophe in DeliverNow Turned Into CVE-2021-26837</title><link>https://sedriclouissaint.com/blog/delivernow-sql-injection-cve-2021-26837/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/delivernow-sql-injection-cve-2021-26837/</guid><description>I typed a single quote into a log search box on an internal pentest and DeliverNow told me everything. Here is the whole story: the confession in the error message, the xp_dirtree callback, the sa account, and the CVE that came out of it.</description><pubDate>Wed, 16 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/delivernow-sql-injection-cve-2021-26837.jpg&quot; alt=&quot;SqlNow: SQL Injection in DeliverNow, CVE-2021-26837&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;I typed a single quote into a log search box on an internal pentest and DeliverNow told me everything. Here is the whole story: the confession in the error message, the xp_dirtree callback, the sa account, and the CVE that came out of it.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/delivernow-sql-injection-cve-2021-26837.jpg" type="image/jpeg" medium="image" width="1200" height="675"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/delivernow-sql-injection-cve-2021-26837.jpg" width="1200" height="675"/><category>Cybersecurity</category><category>Ethical Hacking</category><category>Hacking</category><category>Penetration Testing</category><category>CVE-2021-26837</category><enclosure url="https://sedriclouissaint.com/blog/hero/delivernow-sql-injection-cve-2021-26837.jpg" length="134863" type="image/jpeg"/></item><item><title>AuthForce: Single Sign-On, Single Sign-Over, and the curl That Became CVE-2020-5148</title><link>https://sedriclouissaint.com/blog/sonicwall-utm-sso-forced-authentication-cve-2020-5148/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/sonicwall-utm-sso-forced-authentication-cve-2020-5148/</guid><description>SonicWall&apos;s SSO Agent runs as Domain Admin and authenticates to any workstation it is told about, without ever checking who that is. One curl command through the firewall, one Domain Admin hash. Here is the whole story.</description><pubDate>Wed, 16 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/sonicwall-utm-sso-forced-authentication-cve-2020-5148.jpg&quot; alt=&quot;AuthForce: SonicWall UTM SSO Forced Authentication, CVE-2020-5148&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;SonicWall&apos;s SSO Agent runs as Domain Admin and authenticates to any workstation it is told about, without ever checking who that is. One curl command through the firewall, one Domain Admin hash. Here is the whole story.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/sonicwall-utm-sso-forced-authentication-cve-2020-5148.jpg" type="image/jpeg" medium="image" width="1200" height="800"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/sonicwall-utm-sso-forced-authentication-cve-2020-5148.jpg" width="1200" height="800"/><category>Cybersecurity</category><category>Ethical Hacking</category><category>Hacking</category><category>Penetration Testing</category><category>CVE-2020-5148</category><enclosure url="https://sedriclouissaint.com/blog/hero/sonicwall-utm-sso-forced-authentication-cve-2020-5148.jpg" length="130096" type="image/jpeg"/></item><item><title>SqlSpark: The Wheels on the Bus Went SELECT * FROM, and That Became CVE-2021-3262</title><link>https://sedriclouissaint.com/blog/tripspark-veo-sql-injection-cve-2021-3262/</link><guid isPermaLink="true">https://sedriclouissaint.com/blog/tripspark-veo-sql-injection-cve-2021-3262/</guid><description>An internet-facing page where parents look up their child&apos;s school bus turned out to take SQL. Here is how one unauthenticated form field became a foothold, a service account, and eventually an entire Active Directory forest.</description><pubDate>Wed, 16 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;img src=&quot;https://sedriclouissaint.com/blog/hero/tripspark-veo-sql-injection-cve-2021-3262.jpg&quot; alt=&quot;SqlSpark: SQL Injection in TripSpark VEO Transportation, CVE-2021-3262&quot; width=&quot;600&quot; style=&quot;display:block;width:100%;max-width:600px;height:auto;border-radius:10px;border:1px solid #1e2536;margin:0 0 20px;&quot; /&gt;&lt;p style=&quot;margin:0 0 20px;color:#e6eaf2;font-family:Arial,&apos;Helvetica Neue&apos;,Helvetica,sans-serif;font-size:16px;line-height:1.6;&quot;&gt;An internet-facing page where parents look up their child&apos;s school bus turned out to take SQL. Here is how one unauthenticated form field became a foothold, a service account, and eventually an entire Active Directory forest.&lt;/p&gt;</content:encoded><dc:creator>Sedric Louissaint</dc:creator><media:content url="https://sedriclouissaint.com/blog/hero/tripspark-veo-sql-injection-cve-2021-3262.jpg" type="image/jpeg" medium="image" width="1200" height="675"/><media:thumbnail url="https://sedriclouissaint.com/blog/hero/tripspark-veo-sql-injection-cve-2021-3262.jpg" width="1200" height="675"/><category>Cybersecurity</category><category>Ethical Hacking</category><category>Hacking</category><category>Penetration Testing</category><category>CVE-2021-3262</category><enclosure url="https://sedriclouissaint.com/blog/hero/tripspark-veo-sql-injection-cve-2021-3262.jpg" length="123606" type="image/jpeg"/></item></channel></rss>