🗞️ Weekly Shared Links newsletter for week 07/2023 is out! Read, like, and subscribe below.

It includes, but not only:

  • is investigating a cybersecurity incident on its network
  • : Hackers stole source code, installed in multi-year breach
  • Scandinavian Airlines says cyberattack caused passenger
  • says recent data leak stems from third-party vendor hack
  • Critical RCE Vulnerability Discovered in Open Source Antivirus Software
  • ’s February 2023 Security Updates Patch High-Severity Vulnerabilities
  • North Korea's APT37 Targeting Southern Counterpart with New M2RAT Malware
  • 9 New Bugs to Patch Now
  • Proof of Concept by the Security Advisory Team, exploiting the double-free vulnerability in server
  • hits Technion university, protests tech layoffs and Israel
  • New Ransomware Variant Emerges After CISA Releases Decryptor Tool

0x58.substack.com/p/my-shared-

#infosec #fbi #godaddy #malware #dataleak #atlassian #clamav #sap #microsoft #qualys #openssh #ransomware #esxiargs #cybersecurity

Last updated 2 years ago

Marco Ivaldi · @raptor
1696 followers · 943 posts · Server infosec.exchange

Of course the master heap at managed to achieve significant progress in the recent double-free in server 9.1 (CVE-2023-25136) 💚

“Quick update: we were able to gain arbitrary control of the rip register through this bug (i.e., we can jump wherever we want in sshd's address space) on an unpatched installation of OpenBSD 7.2 (which runs OpenSSH 9.1 by default). This is by no means the end of the story: this was only step 1, bypass the malloc and double-free protections.”

“The trick to bypass malloc's double-free and use-after-free protections is to re-allocate the memory that was occupied by options.kex_algorithms as soon as it is free: from malloc's point of view, no attempt is made to free, read, or write memory that is already free; from sshd's point of view, however, an aliasing attack occurs: two different pointers to two different objects refer to the same chunk of memory, and a write to one object overwrites the other object. This opens up a world of possibilities.”

seclists.org/oss-sec/2023/q1/9

#xdev #qualys #exploiting #vulnerability #openssh

Last updated 2 years ago

F0rm4t · @F0rm4t
11 followers · 17 posts · Server infosec.exchange

NEW Microsoft Sentinel SOAR solutions

We are launching 14 new solutions which adds 14 SOAR connectors and another 25+ playbooks to expand our SOAR capabilities in Multicloud SOAR, Vulnerability enrichment, Incident management, migration, and threat intelligence categories. With this, there are 330+ playbooks available in Microsoft Sentinel content hub either in the 50+ SOAR solutions or as standalone playbooks.

techcommunity.microsoft.com/t5

 

#microsoft #intelligence #soar #siem #playbook #automation #enrichment #cloud #multicloud #threat #threatintelligence #azure #aws #cgp #minemeld #qualys #rapid7 #opencti #CheckPhish #abuseipdb #URLhaus #servicenow #fortinet #threatx #logicapp #management #content

Last updated 2 years ago

John Fitzpatrick · @j0hn_f
113 followers · 93 posts · Server infosec.exchange

The research team's advisories are pretty good huh? Loads of detail and good to read.

This is their -2022-3328 advisory - a race condition in Snapd (default install on Ubuntu) which they've leveraged a couple of other vulns in order to get root: qualys.com/2022/11/30/cve-2022

#qualys #cve

Last updated 2 years ago

infosec-jobs.com · @infosec_jobs
1129 followers · 14498 posts · Server mastodon.social
WhatDoesKmean · @seercle
1 followers · 12 posts · Server red.niboe.info
Neurosploit · @neurosploit
28 followers · 66 posts · Server bitcoinhackers.org

RT @qualys
The Research Team has discovered an easily exploitable memory corruption vulnerability () in polkit a SUID-root program that allows any unprivileged local user to gain root privileges on all major linux systems in its default configuration: fal.cn/3lCr6

#pwnkit #qualys

Last updated 3 years ago

informapirata :privacypride: · @informapirata
3842 followers · 8765 posts · Server mastodon.uno

La vulnerabilità (chiamata così dalla società ) che garantisce agli aggressori i privilegi di root sui sistemi Linux, è stata rivelata in un'utilità di sistema chiamata .
L'exploit esiste da 12 anni, ma è emerso solo poche ore dopo la pubblicazione dei dettagli tecnici!
Di Ravie su
thehackernews.com/2022/01/12-y

#PwnKit #qualys #polkit #Lakshmanan #thehackernews

Last updated 3 years ago

Julien M. · @julm
485 followers · 4935 posts · Server framapiaf.org


> : A deep root in 's layer (-2021-33909)
> by creating, mounting, and deleting a deep
directory structure whose total path length exceeds 1GB [...]
> We [...] obtained full privileges on default installations
openwall.com/lists/oss-securit

#infosec #ebpf #root #cve #filesystem #linux #sequoia #securityadvisory #qualys

Last updated 3 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online
Shin.Ice :debian: · @ShinIce
111 followers · 1195 posts · Server social.tchncs.de

the company I'm working for decided to place the core products behinde , the fight to avoid this was futile 😒

now, months after this, new security concerns are popping up...unfortunately not from our "IT Security Manager" but from us: this "security" guy is pushing hard to install company wide and 🙈

I'm really sick of this 💩 Time to cut of with some wine in the weekend 🍷 and change thoughts!

#zscaler #qualys #cloudflare

Last updated 4 years ago

Julien M. · @julm
485 followers · 4935 posts · Server framapiaf.org


Heap-based buffer overflow in (-2021-3156)

"This :
- is by any local user (normal users and system users, sudoers and non-sudoers), without (i.e., the attacker does not need to know the user's password);
- was introduced in July 2011"
openwall.com/lists/oss-securit

#authentication #exploitable #vulnerability #cve #sudo #infosec #securityadvisory #qualys

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Microsoft Patch Tuesday, March 2020 Edition - Microsoft Corp. today released updates to plug more than 100 security holes in its various Windows o... more: krebsonsecurity.com/2020/03/mi -2020-0688 -2020-0852 -2020-0872

#qualys #animeshjain #timetopatch #cve #recordedfuture #applicationinspector

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Microsoft Patch Tuesday, February 2020 Edition - Microsoft today released updates to plug nearly 100 security holes in various versions of its Window... more: krebsonsecurity.com/2020/02/mi -2019-1280 -2020-0618 -2020-0674 -2020-0688

#qualys #alanliska #jimmygraham #timetopatch #cve #recordedfuture #microsoftpatchtuesdayfebruary2020

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Patch Tuesday, January 2020 Edition - Microsoft today released updates to plug 50 security holes in various flavors of Windows and related... more: krebsonsecurity.com/2020/01/pa -2020-0601

#qualys #mongodb #windows10 #timetopatch #matthewgreen #kennethwhite #cve #johnshopkinsuniversity

Last updated 5 years ago

Nomis · @nomis38
57 followers · 1387 posts · Server framapiaf.org
Thomas B. Rücker · @tbr
412 followers · 4965 posts · Server society.oftrolls.com