Claroty · @Claroty
24 followers · 67 posts · Server infosec.exchange

UPDATE to last week’s Akuvox blogs: The vendor has confirmed all 13 vulnerabilities in the smart intercoms and promises a firmware update by March 20. We’ve updated our blog and technical report.

Technical blog: claroty.com/team82/research/th

Blog: claroty.com/team82/blog/akuvox

#team82

Last updated 2 years ago

Claroty · @Claroty
23 followers · 66 posts · Server infosec.exchange

New research from : We share some details on 13 vulnerabilities in Akuvox E11 smart intercoms and door phones. Some of the vulnerabilities can allow an attacker to take over these devices, view and download images, open doors, and more. Note: Akuvox blocked Team82's and CISA's attempts to disclose details about these vulns that began in Jan. '22, and they remain unpatched. Read more: okt.to/wU1qNG

#team82

Last updated 2 years ago

Claroty · @Claroty
15 followers · 23 posts · Server infosec.exchange

⚠️​ 's Uri Katz found 4 vulnerabilities in Snap One Wattbox. Successful exploitation could lead to remote code execution on the device, password brute force, and bricking of the device. See the CISA advisory for more info: cisa.gov/uscert/ics/advisories

🔖​ Bookmark our Team82 Vulnerability Disclosure Dashboard to stay up-to-date with @Claroty research: claroty.com/team82/disclosure-

#team82

Last updated 2 years ago

Claroty · @Claroty
14 followers · 21 posts · Server infosec.exchange

is next month! See researcher, Noam Moshe, demonstrate how MQTT, WebSocket, and Web API architecture flaws can be exploited to expose large numbers of devices and endpoint routers and allow remote code execution. More info: s4xevents.com/agenda/

#s4x23 #team82

Last updated 2 years ago

Claroty · @Claroty
12 followers · 17 posts · Server infosec.exchange

TBT: researchers, Amir Preminger and Sharon Brizinov, demonstrate an attack against a patient monitoring system during . Watch how they're able to access a patient monitoring system remotely, inject code into the device's logic, and alter vital signs readings on the device. This, of course, would impact a physician's ability to accurately diagnose and treat a patient. okt.to/SEstFo

#team82 #nexus22 #clarotyhealthcare

Last updated 2 years ago

Great research from @Claroty Sharon Brizinov on the technical details of what is actually encrypted in the compromised customer vault data.
linkedin.com/posts/sharonbrizi

#team82 #lastpass

Last updated 2 years ago

Claroty · @Claroty
10 followers · 13 posts · Server infosec.exchange

🎙️​ In this episode of the Aperture Podcast, researcher, Noam Moshe, joins host, Michael Mimoso, to discuss his recent research and development of a generic bypass of leading vendors’ web application firewalls.

The attack technique exploits the vendors’ previous lack of support for JSON syntax in their SQL injection processes. WAFs were previously blind to JSON syntax prepended to a SQL injection payload and would not flag these as malicious. :ablobcatheadphones:​ Listen here: claroty.com/resources/podcasts

#team82 #letstalkaboutxiot

Last updated 2 years ago

Claroty · @Claroty
9 followers · 10 posts · Server infosec.exchange

🌟 Big congratulations to Director of Security Researcher, Sharon Brizinov, on being named SANS Institute Researcher of the Year!

The SANS Difference Makers Awards shine a light on the cybersecurity practitioners who are leading innovative developments in the industry, who’ve made outstanding security achievements, and who are contributing back to the InfoSec community in ways that deserve recognition. Catch the replay of the ceremony here: okt.to/o7zutv

#team82 #differencemakers #cybersecurity #cyberawards #cyber #security #practitioners #awards #sansinstitute #hackervalley

Last updated 2 years ago

Claroty · @Claroty
7 followers · 7 posts · Server infosec.exchange

🚨 New research available from today focuses on a generic bypass of leading web application firewalls that targets a lack of JSON syntax support in their SQL injection inspection processes. Since our disclosure, 5 vendors have added such support, negating this threat.
okt.to/2nvsQ9

#team82

Last updated 2 years ago

Claroty · @Claroty
7 followers · 6 posts · Server infosec.exchange

💡​ Connect with on Slack! Join our channel to stay up to date with vulnerabilities directly from the the industry’s best cybersecurity vulnerability and threat research team. join.slack.com/t/team82researc

#team82 #team82research #xiot

Last updated 2 years ago

Claroty · @Claroty
6 followers · 4 posts · Server infosec.exchange

Get your copy of our revamped "State of Security Report: 1H 2022". In the report, dissects the published vulnerabilities across the Extended Internet of Things and identifies the trends you need to prioritize. claroty.com/resources/reports/

#xiot #team82

Last updated 2 years ago