home.social

#activemq — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #activemq, aggregated by home.social.

fetched live
  1. JVNDB-2026-017541:Apache Software FoundationのApache ActiveMQ Artemis等の複数製品における不正な認証に関する脆弱性
    atlas.whatip.xyz/post.php?slug
    Breaking: <p>Apache
    #foundation #software #activemq #artemis

  2. Майский «В тренде VM»: громкие уязвимости в Linux, ActiveMQ, SharePoint и Acrobat Reader

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно смотрим на поток информации об уязвимостях из самых разных источников: бюллетени безопасности вендоров, соцсети, блоги, телеграм-каналы, репозитории кода, базы уязвимостей и эксплойтов. Из этого многообразия мы стараемся выделять самое важное - трендовые уязвимости, которые уже используются в реальных атаках или с высокой вероятностью будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили в общий список еще четыре трендовые уязвимости.

    habr.com/ru/companies/pt/artic

    #activemq #sharepoint #acrobat_reader #adobe_acrobat #уязвимости_и_их_эксплуатация

  3. CRITICAL: Apache ActiveMQ RCE vuln (CVE-2026-34197) disclosed. No patch yet — review your security posture & monitor vendor channels for updates. Remote attackers could fully compromise systems. radar.offseq.com/threat/recent #OffSeq #ActiveMQ #Vuln #InfoSec

  4. Шатаем ActiveMQ

    Пожалуйста обновите ActiveMQ после прочтения этой статьи. Рассказ об одной известной атаке на инфраструктуру крупных ИТ-проектов — брокер сообщений Apache ActiveMQ.

    habr.com/ru/articles/892450/

    #activemq #java #rce #cve

  5. had a really productive day mostly working for the overlord but actually got to do some public-facing #opensource stuff for once. the stuff I'm doing is not really all that likely to help anyone but our customers, not because our stuff is proprietary (it isn't) but because it's probably better SEOed elsewhere.

    Actually I'm not sure that #activemq article is anywhere else. there is some stuff in the docs but it's definitely not presented like that. I didn't think of it initially because...

  6. had a really productive day mostly working for the overlord but actually got to do some public-facing #opensource stuff for once. the stuff I'm doing is not really all that likely to help anyone but our customers, not because our stuff is proprietary (it isn't) but because it's probably better SEOed elsewhere.

    Actually I'm not sure that #activemq article is anywhere else. there is some stuff in the docs but it's definitely not presented like that. I didn't think of it initially because...

  7. The #s390x open source software team at IBM confirms the latest versions of various software packages run well on #Linux on #IBMZ & #LinuxONE

    In August of 2024 validation was maintained for over two dozen projects, including #Apache #ActiveMQ, #Grafana, and #Jenkins

    In the broader community, we saw s390x support added for R-hub containers (ci, containers), praat (ci, binaries), & Elvish (ci) 🎉

    Full report (and how your OSS community can get a VM too!): community.ibm.com/community/us

  8. The #s390x open source software team at IBM confirms the latest versions of various software packages run well on #Linux on #IBMZ & #LinuxONE

    In August of 2024 validation was maintained for over two dozen projects, including #Apache #ActiveMQ, #Grafana, and #Jenkins

    In the broader community, we saw s390x support added for R-hub containers (ci, containers), praat (ci, binaries), & Elvish (ci) 🎉

    Full report (and how your OSS community can get a VM too!): community.ibm.com/community/us

  9. Wiele aplikacji posiada obecnie asynchroniczną komunikację, będącą potrzebą z uwagi na mnogość komunikatów. I od razu część osób pomyśli o RabbitMQ. A jeszcze inni o Kafce. A niektórzy o ActiveMQ. Który wybrać? Jak zawsze, to zależy.

    dev.to/somadevtoo/difference-b

    #RabbitMQ #Kafka #ActiveMQ #communication #programowanie

  10. "Evaluating persistent, replicated message queues" mega article by @adamwarski et. al. is pure gold. softwaremill.com/mqperf/ Features and more

  11. Ok what the fuck.
    I know Apache #ActiveMQ
    I know Apache #Artemis
    What the fuck is Apache #Apollo? And why does the word "Apollo" not occur ONCE on activemq.apache.org/apollo ?

  12. Ok what the fuck.
    I know Apache #ActiveMQ
    I know Apache #Artemis
    What the fuck is Apache #Apollo? And why does the word "Apollo" not occur ONCE on activemq.apache.org/apollo ?

  13. Does anyone have a thorough walk through of #ActiveMQ transactions they can share? Specifically, JMS transactions

  14. Does anyone have a thorough walk through of #ActiveMQ transactions they can share? Specifically, JMS transactions

  15. Anyone use #ActiveMQ scheduling? Seems to be a little used feature. Cannot find much at all in the way of fixing problems with it. Also, if you use it, wondering what version you are on.

  16. Anyone use #ActiveMQ scheduling? Seems to be a little used feature. Cannot find much at all in the way of fixing problems with it. Also, if you use it, wondering what version you are on.

  17. In other words, hackers could avoid writing their tools to disk. They could have simply written their ransomware to Nashorn (or loaded the JAR class into memory) and stayed in memory.

    #Cybersecurity #Exploit #Apache #Vulnerability #ActiveMQ

    cybersec84.wordpress.com/2023/

  18. In other words, hackers could avoid writing their tools to disk. They could have simply written their ransomware to Nashorn (or loaded the JAR class into memory) and stayed in memory.

    #Cybersecurity #Exploit #Apache #Vulnerability #ActiveMQ

    cybersec84.wordpress.com/2023/

  19. It is difficult to say when I will next have a fire to put out, but recently my afternoon's have been free for learning/writing/projects.

    Is there anything that you would like to see written about enterprise #opensource? Enterprise is a weird term, since small orgs use the same tools as the biggest companies, but we don't play in the social network (Mastodon), or consumer communications (Jitsi) space.

    I am thinking things like #postgres, #Cassandra, #Kafka, #ActiveMQ, #RabbitMQ, #Tomcat, etc.

  20. This Week in Security: CVSS 4, OAuth, and ActiveMQ - We’ve talked a few times here about the issues with the CVSS system. We’ve seen CV... - hackaday.com/2023/11/03/this-w #hackadaycolumns #securityhacks #activemq #oauth #news #cvss

  21. This Week in Security: CVSS 4, OAuth, and ActiveMQ - We’ve talked a few times here about the issues with the CVSS system. We’ve seen CV... - hackaday.com/2023/11/03/this-w #hackadaycolumns #securityhacks #activemq #oauth #news #cvss

  22. ❗️#CERTWarnung❗️
    Die #Schwachstelle CVE-2023-46604 in Apache #ActiveMQ wird aktiv ausgenutzt. Entfernte Angreifende können ActiveMQ Server kompromittieren und Ransomware-Angriffe durchführen.
    Mehr dazu hier: 👉 bsi.bund.de/dok/1099178

    #PatchNow

  23. ❗️#CERTWarnung❗️
    Die #Schwachstelle CVE-2023-46604 in Apache #ActiveMQ wird aktiv ausgenutzt. Entfernte Angreifende können ActiveMQ Server kompromittieren und Ransomware-Angriffe durchführen.
    Mehr dazu hier: 👉 bsi.bund.de/dok/1099178

    #PatchNow

  24. Rapid7 MDR has identified what appears to be exploitation of Apache #ActiveMQ #CVE202346604 in customer environments. The attacker behavior our team has observed includes attempts to deploy #ransomware on victim systems. rapid7.com/blog/post/2023/11/0

  25. Rapid7 MDR has identified what appears to be exploitation of Apache #ActiveMQ #CVE202346604 in customer environments. The attacker behavior our team has observed includes attempts to deploy #ransomware on victim systems. rapid7.com/blog/post/2023/11/0

  26. New exploit out in the wild, this time it affects ActiveMQ:

    Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

    It's recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, to fix this issue.

    cve.org/CVERecord?id=CVE-2023-

    #activeMQ #exploit #cve

  27. New exploit out in the wild, this time it affects ActiveMQ:

    Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

    It's recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, to fix this issue.

    cve.org/CVERecord?id=CVE-2023-

    #activeMQ #exploit #cve

  28. I didn't really understand why Classic (5.x series) was still in use and in many cases favored over ActiveMQ , especially when Artemis has had 2.0 (and higher) support for years. Then I read this page: activemq.apache.org/activemq-a
    So ActiveMQ Classic does have several important features not (yet) found in ActiveMQ Artemis. This makes sense, considering Artemis was in its former life at .