Redhotcyber · @redhotcyber
437 followers · 725 posts · Server mastodon.bida.im

I dispositivi di SonicWall vengono attaccati da malware che sopravvive anche dopo il riavvio

Secondo gli hacker cinesi stanno attaccando i dispositivi Secure Mobile Access () vulnerabili e li stanno infettando con che ruba le credenziali che può sopravvivere anche dopo un aggiornamento del .

I di Mandiant e il team SonicWall ritengono che dietro questi attacchi ci sia il gruppo di hacking cinese .

redhotcyber.com/post/i-disposi

#mandiant #sonicwall #sma #malware #firmware #ricercatori #psirt #UNC4540 #redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #privacy #infosecurity

Last updated 2 years ago

Redhotcyber · @redhotcyber
417 followers · 644 posts · Server mastodon.bida.im

Fortinet: un nuovo difetto critico su FortiOS e FortiProxy potrebbe fornire ai malintenzionati l’accesso remoto

Il 7 marzo 2023,# Fortinet ha rilasciato 15 nuovi avvisi relativi alle nei suoi prodotti.

Tra tutti gli avvisi, ce nè uno di severtity bassa, otto medi, cinque alti e uno con valutazione critica. Questi avvisi riguardano , FortiAnalyzer, FortiManager, FortiPortal, FortiSwitch, , , FortiRecorder, FortiSOAR e .

redhotcyber.com/post/fortinet-

#psirt #vulnerabilità #fortios #FortiNAC #FortiProxy #FortiWeb #redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #privacy #infosecurity

Last updated 2 years ago

FIRST.org · @firstdotorg
96 followers · 7 posts · Server infosec.exchange

That's a wrap - a great event in Kigali, Rwanda.

Min. Paula Ingabire (Minister of Information Communication Technology and Innovation) opened the FIRST, AfricaCERT and National Cyber Security Authority Rwanda symposium. 4 days of excellent content bringing together folks from 48 countries to collaborate, learn, build trust and discuss strategies to shape a secure internet for Africa.

#firstdotorg #collaboration #buildingtrust #csirt #psirt #firstaa23

Last updated 2 years ago

FIRST.org · @firstdotorg
94 followers · 5 posts · Server infosec.exchange

The for the Balkan Cybersecurity Days 2023 Symposium is open! May 16-18 in Orhid, North Macedonia. Event overview and CFP guidelines available at first.org/events/colloquia/ohr

@firstdotorg @DCAF_Geneva @MkdCirt @aecmk

#cfp #collaboration #buildingtrust #psirt #csirt

Last updated 2 years ago

FIRST.org · @firstdotorg
92 followers · 4 posts · Server infosec.exchange

The has proudly published its Techniques Matrix and has offered an introduction to the document on the . Check it out at: first.org/blog/20230228-DNS_Ab

#dnsabuse #sig #firstblog #firstdotorg #collaboration #buildingtrust #psirt #csirt

Last updated 2 years ago

FIRST.org · @firstdotorg
89 followers · 3 posts · Server infosec.exchange

The opening sessions at the FIRST & AfricaCERT Symposium in Kigali, co-hosted by @AfricaCERT and @National Cyber Security Authority Rwanda. 2 days of training followed by a plenary session on Thursday. FIRST doing what FIRST does best - working with great partners to make the internet safer.

#firstdotorg #collaboration #buildingtrust #psirt #csirt

Last updated 2 years ago

FIRST · @first
13 followers · 1 posts · Server infosec.exchange

This year's Incident Response Hall of Fame call for nominations closes on March 3rd. The IRHF recognizes visionaries, leaders, and luminaries who have significantly contributed to our industry. Find out more here t.co/mXC2TGtQw9.

#firstdotorg #collaboration #buildingtrust #csirt #psirt #irhof

Last updated 2 years ago

Brad Johnson · @bradintn
31 followers · 65 posts · Server noc.social

The latest PSIRT for has been released. This announcement has 4 known vulnerabilities.

CVE-2022-20964: tcpdump Feature Command Injection Vulnerability

CVE-2022-20966: tcpdump Stored Cross-Site Scripting Vulnerability

CVE-2022-20967: External RADIUS Server Feature Stored Cross-Site Scripting Vulnerability

CVE-2022-20965: Access Bypass Vulnerability

All are only exploitable by a valid/authorized management GUI user.

tools.cisco.com/security/cente

#psirt #vulnerability #CiscoISE #ISE #cisco

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

@da_667 @tinker @gaz @albinowax It's definitely not as easy as it sounds, said the guy

#psirt

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

While I've got this in the copy buffer, here's an excellent article by my distinguished colleague Omar Santos regarding counting.

TL;DR: Might more CVEs mean more product security maturity? FTW!

medium.com/@santosomar/increas

#cve #psirt

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

@jeffers00n @bryanbrake Reports of death are greatly exaggerated. There's still a very large incident response community using it for multiparty coordination, among other things.

#keybase #psirt

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

@jerry @johnoauth One word: ! There is not simply one monolithic Mastodon server (like Twitter). If your spidey sense 🦸 gets triggered by a particular admin or a particular server, it's just a jump to the left () to sign up for a different server.

Personally, I moved from the melting pot mastodon.social to infosec.exchange, and feel very, very comfortable here. But I'm a geek, so it makes sense.

P.S. @jerry rocks!

#federation #RockyHorror #psirt #infosec

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

@cadey ... and evil vendors incident response fatigue (e.g. "Is 6pm EDT too late for breakfast?")

#psirt

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

Hello Mastodon. I'm about.me/vipergeek
Feels like Twitter back in 2009. Kinda nice.

#introduction #cybersecurity #infosec #psirt #cvss

Last updated 2 years ago

Dave Dugal :mastodon:🔒 · @vipergeek
264 followers · 243 posts · Server infosec.exchange

@0xmrtn @jerry @DFIR_abrignoni There's still a strong community on . Great for just-in-time, only-if-you-can-help collaboration.

#psirt #keybase

Last updated 2 years ago