home.social

#censysresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #censysresearch, aggregated by home.social.

fetched live
  1. *cracks knuckles*

    Okay, here we go.

    On June 25, 2024, Progress Software disclosed two auth bypass vulnerabilities in the SFTP module of their #MOVEit software:

    ✴️ CVE-2024-5806, in MOVEit Transfer (CVSS 7.4)
    ✴️ CVE-2024-5085, in MOVEit Gateway (CVSS 9.1)

    We took this opportunity to examine MOVEit Transfer exposure, roughly one year after Clop began a mass exploitation campaign against the file transfer software.

    More details in our blog ⤵️
    censys.com/moveit-transfer-aut

    #CensysResearch #security

  2. *cracks knuckles*

    Okay, here we go.

    On June 25, 2024, Progress Software disclosed two auth bypass vulnerabilities in the SFTP module of their #MOVEit software:

    ✴️ CVE-2024-5806, in MOVEit Transfer (CVSS 7.4)
    ✴️ CVE-2024-5085, in MOVEit Gateway (CVSS 9.1)

    We took this opportunity to examine MOVEit Transfer exposure, roughly one year after Clop began a mass exploitation campaign against the file transfer software.

    More details in our blog ⤵️
    censys.com/moveit-transfer-aut

    #CensysResearch #security

  3. HI EVERYONE ARE YOU GOING TO RSA BECAUSE I'M GOING TO RSA AND WOULD LOVE TO CONN--

    Sorry, wrong platform. Ahem.

    Next Tuesday, I'll be giving a little talk about last year's ESXiArgs ransomware campaign in the South Expo Briefing Center at RSA. While not particularly lucrative, there are other broad takeaways from this campaign:

    ➡️ As researchers, we must always be open to challenging our initial assumptions about an event.
    ➡️ We must also balance transparency in our findings with avoiding tipping off the adversaries.

    (Yes, this is a sponsored briefing, but I'll be talking about real research.)

    Details here: rsaconference.com/usa/agenda/s

    #rsa #rsac #CensysResearch

  4. HI EVERYONE ARE YOU GOING TO RSA BECAUSE I'M GOING TO RSA AND WOULD LOVE TO CONN--

    Sorry, wrong platform. Ahem.

    Next Tuesday, I'll be giving a little talk about last year's ESXiArgs ransomware campaign in the South Expo Briefing Center at RSA. While not particularly lucrative, there are other broad takeaways from this campaign:

    ➡️ As researchers, we must always be open to challenging our initial assumptions about an event.
    ➡️ We must also balance transparency in our findings with avoiding tipping off the adversaries.

    (Yes, this is a sponsored briefing, but I'll be talking about real research.)

    Details here: rsaconference.com/usa/agenda/s

    #rsa #rsac #CensysResearch

  5. Following the disclosure of the Sisense security incident, our team @censys took a quick look at some Sisense instances visible to our scanners to better understand what industries might be affected:

    censys.com/sisense-a-look-at-i

    #securityResearch #infosec #CensysResearch

  6. Following the disclosure of the Sisense security incident, our team @censys took a quick look at some Sisense instances visible to our scanners to better understand what industries might be affected:

    censys.com/sisense-a-look-at-i

    #securityResearch #infosec #CensysResearch

  7. Shared my thoughts on the couple of new vulnerabilities in #MOVEit announced last week in this piece by Matt Kapko at #Cybersecurity Dive. Honestly, I'd rather learn about such #vulnerabilities through vendor advisories than breaking news of exploitation, so this doesn't feel like the *worst* news possible.

    #CensysResearch #security

    cybersecuritydive.com/news/pro

  8. Shared my thoughts on the couple of new vulnerabilities in #MOVEit announced last week in this piece by Matt Kapko at #Cybersecurity Dive. Honestly, I'd rather learn about such #vulnerabilities through vendor advisories than breaking news of exploitation, so this doesn't feel like the *worst* news possible.

    #CensysResearch #security

    cybersecuritydive.com/news/pro