home.social

#directorytraversal — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #directorytraversal, aggregated by home.social.

fetched live
  1. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  2. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  3. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  4. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  5. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  6. VMware vCenter Flaw Exploited Days After Disclosure

    Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

    osintsights.com/vmware-vcenter

    #Cve202659310 #Vmware #Vcenter #DirectoryTraversal #SupplyChain

  7. Trend Micro Discloses Apex One Zero-Day Exploited in Attacks

    A critical zero-day vulnerability, CVE-2026-34926, has been discovered in Trend Micro's Apex One on-premises server, allowing pre-authenticated local attackers to inject malicious code - and it's being actively exploited in attacks. Federal agencies have been ordered to patch affected systems ASAP, with a deadline of June 4, 2026.

    osintsights.com/trend-micro-di

    #ZeroDay #ApexOne #Cve202634926 #TrendMicro #DirectoryTraversal

  8. Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?

  9. Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?

  10. Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?

  11. Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?

  12. Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?

  13. #mollybrown logs sometimes be like:

    50 PermanentFailure "Your directory traversal technique has been defeated!" 0.047s

    #geminiprotocol #directorytraversal

  14. I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:

    https://github.com/v-p-b/SafePath/
  15. I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:

    https://github.com/v-p-b/SafePath/
  16. I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:

    https://github.com/v-p-b/SafePath/
  17. I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:

    https://github.com/v-p-b/SafePath/
  18. I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:

    https://github.com/v-p-b/SafePath/
  19. I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.

    Whoa. :blob_gnikniht: #directorytraversal #pentesting

  20. I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.

    Whoa. :blob_gnikniht: #directorytraversal #pentesting

  21. I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.

    Whoa. :blob_gnikniht: #directorytraversal #pentesting

  22. I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.

    Whoa. :blob_gnikniht: #directorytraversal #pentesting

  23. Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers

    Article: hadess.io/grafana-attack-surfa

    #grafana #ssrf #directorytraversal #bugbountytips

  24. Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers

    Article: hadess.io/grafana-attack-surfa

    #grafana #ssrf #directorytraversal #bugbountytips

  25. Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers

    Article: hadess.io/grafana-attack-surfa

    #grafana #ssrf #directorytraversal #bugbountytips