<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NULL CATHEDRAL</title><link>https://nullcathedral.com/</link><description>Where nothing is sacred.</description><language>en-us</language><copyright>NULL CATHEDRAL</copyright><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate><lastBuildDate>Fri, 10 Apr 2026 18:00:00 +0000</lastBuildDate><docs>https://www.rssboard.org/rss-specification</docs><ttl>60</ttl><atom:link href="https://nullcathedral.com/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://nullcathedral.com/favicon.svg</url><title>NULL CATHEDRAL</title><link>https://nullcathedral.com/</link></image><item><title>Roundcube round two: three more sanitizer bypasses</title><link>https://nullcathedral.com/posts/2026-03-18-roundcube-round-two-three-more-sanitizer-bypasses/</link><description>Three more bypasses in Roundcube's HTML sanitizer: SMIL animation attributes load remote resources, unquoted body backgrounds enable CSS injection, and position:fixed !important enables phishing overlays.</description><category>vulnerability</category><category>roundcube</category><category>svg</category><category>css</category><category>email-security</category><guid isPermaLink="true">https://nullcathedral.com/posts/2026-03-18-roundcube-round-two-three-more-sanitizer-bypasses/</guid><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Perfex CRM &lt;=3.4.0 allows unauthenticated RCE via insecure deserialization</title><link>https://nullcathedral.com/posts/2026-03-16-perfex-crm-unauthenticated-rce-insecure-deserialization/</link><description>Perfex CRM passed the autologin cookie into unserialize() without validation, giving unauthenticated attackers remote code execution.</description><category>vulnerability</category><category>perfex-crm</category><category>deserialization</category><category>rce</category><category>php</category><guid isPermaLink="true">https://nullcathedral.com/posts/2026-03-16-perfex-crm-unauthenticated-rce-insecure-deserialization/</guid><pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Hello world</title><link>https://nullcathedral.com/posts/2026-02-10-hello-world/</link><description>About this blog and the author behind it.</description><category>meta</category><guid isPermaLink="true">https://nullcathedral.com/posts/2026-02-10-hello-world/</guid><pubDate>Tue, 10 Feb 2026 00:00:00 +0000</pubDate></item><item><title>Roundcube Webmail &lt;1.5.13 / &lt;1.6.13 allows attackers to force remote image loads via SVG feImage</title><link>https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/</link><description>Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens. (CVE-2026-25916)</description><category>vulnerability</category><category>roundcube</category><category>svg</category><category>email-security</category><guid isPermaLink="true">https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/</guid><pubDate>Sun, 08 Feb 2026 00:00:00 +0000</pubDate></item></channel></rss>