<feed xmlns="http://www.w3.org/2005/Atom"> <id>/</id><title>Daniele Berardinelli</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-07-28T05:06:52+00:00</updated> <author> <name>Daniele Berardinelli</name> <uri>/</uri> </author><link rel="self" type="application/atom+xml" href="/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Daniele Berardinelli </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Printing Infinite Money on the Cosmos Blockchain</title><link href="/posts/cosmos/" rel="alternate" type="text/html" title="Printing Infinite Money on the Cosmos Blockchain" /><published>2026-07-28T00:00:00+00:00</published> <updated>2026-07-28T05:06:31+00:00</updated> <id>/posts/cosmos/</id> <content type="text/html" src="/posts/cosmos/" /> <author> <name>Daniele Berardinelli</name> </author> <category term="research" /> <summary>A uint256 underflow in cosmos blockchain</summary> </entry> <entry><title>Exploiting LangSmith: LangGhost RCE (CVE-2026-45134)</title><link href="/posts/langghost/" rel="alternate" type="text/html" title="Exploiting LangSmith: LangGhost RCE (CVE-2026-45134)" /><published>2026-05-11T00:00:00+00:00</published> <updated>2026-05-11T00:00:00+00:00</updated> <id>/posts/langghost/</id> <content type="text/html" src="/posts/langghost/" /> <author> <name>Daniele Berardinelli</name> </author> <category term="research" /> <summary>A technical breakdown of the RCE vulnerability in LangSmith</summary> </entry> <entry><title>Reverse Engineering AnyDesk</title><link href="/posts/anydesk/" rel="alternate" type="text/html" title="Reverse Engineering AnyDesk" /><published>2026-04-24T00:00:00+00:00</published> <updated>2026-05-11T22:59:58+00:00</updated> <id>/posts/anydesk/</id> <content type="text/html" src="/posts/anydesk/" /> <author> <name>Daniele Berardinelli</name> </author> <category term="rev" /> <summary>A deep dive into AnyDesk 9.7.0</summary> </entry> <entry><title>My thoughts on MongoBleed (CVE-2025-14847)</title><link href="/posts/mongobleed/" rel="alternate" type="text/html" title="My thoughts on MongoBleed (CVE-2025-14847)" /><published>2025-12-27T00:00:00+00:00</published> <updated>2025-12-27T00:00:00+00:00</updated> <id>/posts/mongobleed/</id> <content type="text/html" src="/posts/mongobleed/" /> <author> <name>Daniele Berardinelli</name> </author> <category term="research" /> <summary>MongoBleed (CVE-2025-14847) A parser-amplified uninitialized heap disclosure in MongoDB’s OP_COMPRESSED (zlib) path. MongoBleed is a vulnerability in the way that MongoDB processes zlib-compressed wire messages. If you follow the execution path a little further, you will see that it quietly turns a database into a heap oracle MongoDB shipped fixes across all supported branches and publis...</summary> </entry> </feed>
