#directorytraversal — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #directorytraversal, aggregated by home.social.
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
VMware vCenter Flaw Exploited Days After Disclosure
Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.
#Cve202659310 #Vmware #Vcenter #DirectoryTraversal #SupplyChain
-
A new Exim vulnerability lets a local attacker escape the spool directory and escalate privileges. Upgrade to Exim 4.99.5 to close the hole now.
#Exim #DirectoryTraversal #PrivilegeEscalation #MailServer #InfoSec #Linux
-
A new Exim vulnerability lets a local attacker escape the spool directory and escalate privileges. Upgrade to Exim 4.99.5 to close the hole now.
#Exim #DirectoryTraversal #PrivilegeEscalation #MailServer #InfoSec #Linux
-
Trend Micro Discloses Apex One Zero-Day Exploited in Attacks
A critical zero-day vulnerability, CVE-2026-34926, has been discovered in Trend Micro's Apex One on-premises server, allowing pre-authenticated local attackers to inject malicious code - and it's being actively exploited in attacks. Federal agencies have been ordered to patch affected systems ASAP, with a deadline of June 4, 2026.
#ZeroDay #ApexOne #Cve202634926 #TrendMicro #DirectoryTraversal
-
Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?
-
Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?
-
Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?
-
Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?
-
Hey #directorytraversal folks. Love the memes. Is dotdotpwn still the zen tool for testing?
-
#mollybrown logs sometimes be like:
50 PermanentFailure "Your directory traversal technique has been defeated!" 0.047s -
-
-
-
-
-
I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:
https://github.com/v-p-b/SafePath/ -
I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:
https://github.com/v-p-b/SafePath/ -
I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:
https://github.com/v-p-b/SafePath/ -
I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:
https://github.com/v-p-b/SafePath/ -
I've been wondering for a long time if #DirectoryTraversal vulnerabilities could be mitigated by a safe path handling library (similarly to e.g. ORM's). As a side-quest, I stared to implement a prototype for Python, and I'm super interested in your unfiltered opinions:
https://github.com/v-p-b/SafePath/ -
SolarWinds Serv-U Vulnerability Let Attackers Access sensitive files https://gbhackers.com/solarwinds-serv-u-vulnerability-access-sensitive-files/ #VulnerabilityRemediation #directorytraversal #CVE/vulnerability #CyberSecurityNews #IncidentResponse #NetworkSecurity #SolarWindsServU #CVE202428995
-
SolarWinds Serv-U Vulnerability Let Attackers Access sensitive files https://gbhackers.com/solarwinds-serv-u-vulnerability-access-sensitive-files/ #VulnerabilityRemediation #directorytraversal #CVE/vulnerability #CyberSecurityNews #IncidentResponse #NetworkSecurity #SolarWindsServU #CVE202428995
-
SolarWinds Serv-U Vulnerability Let Attackers Access sensitive files https://gbhackers.com/solarwinds-serv-u-vulnerability-access-sensitive-files/ #VulnerabilityRemediation #directorytraversal #CVE/vulnerability #CyberSecurityNews #IncidentResponse #NetworkSecurity #SolarWindsServU #CVE202428995
-
SolarWinds Serv-U Vulnerability Let Attackers Access sensitive files https://gbhackers.com/solarwinds-serv-u-vulnerability-access-sensitive-files/ #VulnerabilityRemediation #directorytraversal #CVE/vulnerability #CyberSecurityNews #IncidentResponse #NetworkSecurity #SolarWindsServU #CVE202428995
-
I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.
Whoa. :blob_gnikniht: #directorytraversal #pentesting
-
I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.
Whoa. :blob_gnikniht: #directorytraversal #pentesting
-
I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.
Whoa. :blob_gnikniht: #directorytraversal #pentesting
-
I was today years old when I first learned that windows hosts accept both ..\ *and* ../ for executing local file inclusion.
Whoa. :blob_gnikniht: #directorytraversal #pentesting
-
Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers
-
Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers
-
Grafana Attack Surface: How a Visualization and Monitoring Platform Can Expose Your Organization's Data and File System to Attackers
-
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html -
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html -
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html -
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html -
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html