ITX Mike · @mspsadmin
144 followers · 1117 posts · Server msps.io

I wonder how many people are going to run into issues on October 10th related to CVE-2022-37967 and patch

That's when the KrbtgtFullPacSignature Audit gets removed and the setting locks to Enforced.

ioc.exchange/@miketheitguy/109

#kb5020805 #CVE #windows #windowsserver #InfoTech #infosec #sysadmin #kerberos #activedirectory

Last updated 1 year ago

madomado · @madomado
20 followers · 171 posts · Server floss.social

Management is hard but fixing an issue is easy. -2020-19909

#curl #CVE

Last updated 1 year ago

Aida Akl · @AAKL
398 followers · 696 posts · Server noc.social

CollectionRAT seems to do it all, in addition to using 's Microsoft Foundation Class framework. But why? Is this a one-stop shopping spree? Or are they looking for something specific?

North Korea's APT actors use public ManageEngine exploit to breach internet org -2022-47966 bleepingcomputer.com/news/secu @BleepingComputer @billtoulas

#CVE #malware #lazarus #infosec #cybersecurity #microsoft

Last updated 1 year ago

dispatch · @dispatch
568 followers · 3291 posts · Server ioc.exchange
adlerweb // BitBastelei · @adlerweb
658 followers · 4932 posts · Server social.adlerweb.info

Es gibt wohl mal wieder einen neuen in Prozessoren von - -2022-40982 aka INTEL-SA-00828 erlaubt es Daten anderer Nutzer auf dem selben System auszulesen. Betroffen sind CPUs zwischen und . As usual gibt es für supportete CPUs einen neuen Microcode, der einen Workaround implementiert (und Performance kostet)

downfall.page/
intel.com/content/www/us/en/se

#cpubug #intel #CVE #Skylake #tigerlage

Last updated 1 year ago

Dimitris Kardarakos · @dimitrisk
303 followers · 194 posts · Server floss.social

The most efficient way to fix a security vulnerability: prevent testers from verifying the fix.

"It now appears that it's either fixed, or we are blocked from testing. We don't know the fix, or mitigation, so hard to say if it's truly fixed, or Microsoft put a control in place like a firewall rule or ACL to block us."

arstechnica.com/security/2023/

#Azure #Microsoft #security #CVE #cloud

Last updated 1 year ago

Code Intelligence · @CodeIntelligence
103 followers · 52 posts · Server ioc.exchange

How we found a Prototype Pollution in protobuf.js - Live Demo 🚨

Our team has recently found a prototype pollution vulnerability in protobuf.js (CVE-2023-36665).

With a high CVSS Score of 9.8, this vulnerability would have put affected applications at risk of remote code execution and denial of service attacks.

Our colleague Peter Samarin wrote the bug detector behind it all, and will be giving a live demo of how this CVE was found.

Thursday, August 10th at 4:00 PM CEST/ 10:00 AM EDT

Sign up and reserve your spot today. ⏰

code-intelligence.com/webinar/

#javascript #CVE #cybersecurity

Last updated 1 year ago

Carlos Mogas da Silva · @r3pek
331 followers · 1624 posts · Server mastodon.r3pek.org
dispatch · @dispatch
558 followers · 3231 posts · Server ioc.exchange
Code Intelligence · @CodeIntelligence
103 followers · 49 posts · Server ioc.exchange

We found a prototype pollution vulnerability in protobufjs: CVE-2023-36665 🚨
Snyk CVSS Score: 8.6 (high)

Affected applications are at risk of remote code execution and denial of service attacks. The vulnerability was found by our open-source JavaScript fuzzer Jazzer.js, running in Google's OSS-Fuzz.

Mitigation:
Versions from 6.10.0 to 7.2.4 are affected and hence vulnerable to prototype pollution. The maintainer issued an update that fixed this vulnerability on April 18, 2023. We strongly recommend that impacted users upgrade to newer versions that include the fixes, i.e., version 7.2.4 and above.

Hats off to our colleague Peter for writing the bug detector and disclosing the vulnerability to the project maintainer 🙌

More info in our blog: code-intelligence.com/blog/cve

#javascript #jazzerjs #CVE #opensource #protobufjs

Last updated 1 year ago

DeltaLima 🐧 · @DeltaLima
142 followers · 2609 posts · Server social.la10cy.net

Short reminder to : Have you already installed the latest version 4.1.3 of ? It fixes a very high scored CVE, which allows attackers to get a webshell on your mastodon system 😱

github.com/mastodon/mastodon/r

cyberplace.social/@GossiTheDog

#mastoadmin #mastodon #tootroot #CVE #security #patch

Last updated 1 year ago

dispatch · @dispatch
551 followers · 3179 posts · Server ioc.exchange
dispatch · @dispatch
551 followers · 3175 posts · Server ioc.exchange
dispatch · @dispatch
546 followers · 3165 posts · Server ioc.exchange
Emory L. · @emory
161 followers · 1394 posts · Server soc.kvet.ch

users of browser that are worried about -2023-2033 (and you should be) it's easy to get version strings mixed up so in Edge (and presumably Brave and Vivalidi and any other Chrome-engine browser), make sure in `about://` that the chromium version is not older than 112.0.5615.121!

#microsoft #edge #CVE #infosec #bestPractices

Last updated 1 year ago

dispatch · @dispatch
533 followers · 3033 posts · Server ioc.exchange
Marcos Paulo de Souza · @mpdesouza
73 followers · 96 posts · Server floss.social

At SUSE, we from the Kernel Livepatching team need to make sure that live patches work properly, but how to test a live patch when you don't have a vulnerability reproducer for the bug? You create one!

mpdesouza.com/blog/from-zero-t

#Linux #kernel #ltp #CVE #livepatch

Last updated 1 year ago

dispatch · @dispatch
528 followers · 2981 posts · Server ioc.exchange
Jeff the Alien · @hackdefendr
340 followers · 3316 posts · Server defenders.town

old but a new.

Did you know that the MS13-98 was updated last year and actually still impacts a number of server releases up to 2019?

It's true! Ask me how I know?

vulnerabilitycenter.com/#!vul=

#infosec #CVE #vulnerability #windows #Server

Last updated 1 year ago

dispatch · @dispatch
527 followers · 2916 posts · Server ioc.exchange