Perspectives on application security, cloud risk and the operational work of protecting digital services.
A technical analysis of CVE-2026-71309, a path traversal in rclone's restic-compatible REST server (rclone serve restic). A URL path starting with ../ could escape the operator's published root and read, create, overwrite, or delete objects outside it, depending on the storage backend. We break down the root cause (treating path canonicalization as containment), why the outcome depended on the backend, how exploitation worked, and the fix in rclone 1.75.0.
A transparent model for combining asset churn, severity, persistence, ownership confidence, and remediation delay into one directional metric.
An original operating model for connecting exposed assets, inbound decisions, browser-side changes, and outbound behavior during triage.