<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>Mutantgun</title>
<subtitle>Independent projects in security and software — the method, the measurements, and what they actually cost.</subtitle>
<link href="https://mutantgun.com/feed.xml" rel="self"/>
<link href="https://mutantgun.com/"/>
<updated>2026-09-05T00:00:00Z</updated>
<id>https://mutantgun.com/</id>
<author><name>Mutantgun</name></author>
<entry>
<title>My first CVE, and it paid nothing</title>
<link href="https://mutantgun.com/crucible/first-cve-paid-nothing/"/>
<id>https://mutantgun.com/crucible/first-cve-paid-nothing/</id>
<updated>2026-09-05T00:00:00Z</updated>
<summary>The first CVE this project was ever assigned was published today as CVE-2026-18056. Wordfence validated it, credited me, and paid nothing. Reading the vendor&#39;s fix turned out to be the interesting part.</summary>
</entry>
<entry>
<title>Reading the patches for two of my own findings</title>
<link href="https://mutantgun.com/crucible/checking-the-patch/"/>
<id>https://mutantgun.com/crucible/checking-the-patch/</id>
<updated>2026-09-03T00:00:00Z</updated>
<summary>Two findings of mine published as CVEs this week, both marked fixed. An advisory saying &#39;fixed in version X&#39; is someone else&#39;s claim until you open the release and look, so I opened both.</summary>
</entry>
</feed>
