<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I laughed at the description of &#96;sendmail&#96; as “... less a mail transfer agent and more a recurring CVE subscription.”]]></title><description><![CDATA[<p>I laughed at the description of `sendmail` as “... less a mail transfer agent and more a recurring CVE subscription.”</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://blog.calif.io/p/we-asked-claude-to-audit-sagredos" title="We Asked Claude to Audit Sagredo's qmail. It found a RCE.">
<img src="https://substackcdn.com/image/fetch/$s_!Nir7!,f_auto,q_auto:best,fl_progressive:steep/https%3A%2F%2Fcalif.substack.com%2Ftwitter%2Fsubscribe-card.jpg%3Fv%3D-1523730904%26version%3D9" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://blog.calif.io/p/we-asked-claude-to-audit-sagredos">
We Asked Claude to Audit Sagredo's qmail. It found a RCE.
</a>
</h5>
<p class="card-text line-clamp-3">One prompt, 101 minutes, and a working exploit against a widely deployed qmail fork.</p>
</div>
<a href="https://blog.calif.io/p/we-asked-claude-to-audit-sagredos" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://substackcdn.com/icons/substack/icon.svg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />







<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(blog.calif.io)</span></p>
</a>
</div><p></p><p><a href="https://mastodon.social/tags/qmail" rel="tag">#<span>qmail</span></a> <a href="https://mastodon.social/tags/security" rel="tag">#<span>security</span></a> <a href="https://mastodon.social/tags/risks" rel="tag">#<span>risks</span></a> <a href="https://mastodon.social/tags/mail" rel="tag">#<span>mail</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/09453d7b-4d26-4829-861e-c855393c78ff/i-laughed-at-the-description-of-sendmail-as-...-less-a-mail-transfer-agent-and-more-a-recurring-cve-subscription.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 00:22:06 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/09453d7b-4d26-4829-861e-c855393c78ff.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 20 Apr 2026 01:56:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I laughed at the description of &#96;sendmail&#96; as “... less a mail transfer agent and more a recurring CVE subscription.” on Mon, 20 Apr 2026 14:24:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/angusm%40mastodon.social" rel="nofollow noopener">@<span>angusm</span></a></span> </p><p>I don't know, you'd probably have to pay a human a <em>lot</em> to be willing to look at code like that...</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116437486235104363</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116437486235104363</guid><dc:creator><![CDATA[david_chisnall@infosec.exchange]]></dc:creator><pubDate>Mon, 20 Apr 2026 14:24:01 GMT</pubDate></item><item><title><![CDATA[Reply to I laughed at the description of &#96;sendmail&#96; as “... less a mail transfer agent and more a recurring CVE subscription.” on Mon, 20 Apr 2026 13:04:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/david_chisnall%40infosec.exchange">@<span>david_chisnall</span></a></span> Feels like the kind of vulnerability that you shouldn’t need 101 minutes of “AI” time to detect.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/angusm/statuses/116437175359207131</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/angusm/statuses/116437175359207131</guid><dc:creator><![CDATA[angusm@mastodon.social]]></dc:creator><pubDate>Mon, 20 Apr 2026 13:04:57 GMT</pubDate></item><item><title><![CDATA[Reply to I laughed at the description of &#96;sendmail&#96; as “... less a mail transfer agent and more a recurring CVE subscription.” on Mon, 20 Apr 2026 07:19:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/angusm%40mastodon.social" rel="nofollow noopener">@<span>angusm</span></a></span> </p><p>Is that code really using popen invoking touch to do the equivalent of open?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116435816643854018</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116435816643854018</guid><dc:creator><![CDATA[david_chisnall@infosec.exchange]]></dc:creator><pubDate>Mon, 20 Apr 2026 07:19:25 GMT</pubDate></item></channel></rss>