Not me, but a buddy of mine got owned by a honeypot trap disguised as a vulnerable Jenkins server. He thought he'd found an easy RCE, but nope—just a logging playground for the blue team.
He swears by using Shodan now to scan for legit vs. sketchy setups.
Ever had a close call with a fake CI/CD system?
He swears by using Shodan now to scan for legit vs. sketchy setups.
Ever had a close call with a fake CI/CD system?
