#authentication_bypass — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #authentication_bypass, aggregated by home.social.
-
User Profile Builder Vulnerability: 40,000 WordPress Sites at Risk of Admin Takeover - https://www.redpacketsecurity.com/wordpress-plugin-flaw-exposes-40-000-sites-to-admin-takeover/
#threatintel #User_Profile_Builder #WordPress #authentication_bypass
-
Critical SimpleHelp Vulnerability Exploited: Malware Delivered via Forged OpenID Token (CVE-2026-48558) - https://www.redpacketsecurity.com/critical-simplehelp-vulnerability-exploited-for-malware-delivery/
#threatintel #SimpleHelp #authentication_bypass #credential_theft
-
We Hacked Burger King: How Auth Bypass Led to Drive-Thru Audio Surveillance
https://bobdahacker.com/blog/rbi-hacked-drive-thrus/
#ycombinator #security_research #authentication_bypass #burger_king #tim_hortons #popeyes #restaurant_brands_international #rbi #graphql_vulnerabilities #aws_cognito #drive_thru_security #privacy_breach #voice_recordings #responsible_disclosure #api_security #privilege_escalation #retail_security #fast_food_tech -
JetBrains TeamCity CI/CD CVE-2024-27198
В феврале 2024 года группа исследователей уязвимостей Rapid7 выявила уязвимость, затрагивающую сервер JetBrains TeamCity CI/CD и представляющую собой обход аутентификации в веб-компоненте TeamCity. Уязвимость получила идентификатор CVE-2024-27198 и балл CVSS равный 9,8 (критический). Наличие данного недостатка позволяет полностью скомпрометировать сервер TeamCity, не имея аутентифицированного доступа, включая удаленное исполнение команд. Компрометация сервера TeamCity позволяет злоумышленнику получить полный контроль над всеми проектами, сборками, агентами и артефактами TeamCity, что может являться подходящим вектором для атаки на цепочку поставок.
https://habr.com/ru/articles/802293/
#CVE202427198 #teamcity #jetbrains #уязвимость #authentication_bypass
-
Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited - https://www.redpacketsecurity.com/ransomware-warning-as-cvss-screenconnect-bug-is-exploited/
#threatintel #ScreenConnect_vulnerability #Patching_servers #Authentication_bypass
-
New Ivanti Vulnerability Observed as Widespread Security Concerns Grow - https://www.redpacketsecurity.com/new-ivanti-vulnerability-observed-as-widespread-security-concerns-grow/
#threatintel #Ivanti_vulnerabilities #Authentication_bypass #Remote_exploitation