home.social

#securityadvisory — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityadvisory, aggregated by home.social.

fetched live
  1. RE: fosstodon.org/@podlove/1168732

    If you host on Uberspace we have implemented a mitigation against the vulnerability. Please still update your Podlove Publisher plugin as soon as possible! #securityAdvisory

  2. RE: fosstodon.org/@podlove/1168732

    If you host on Uberspace we have implemented a mitigation against the vulnerability. Please still update your Podlove Publisher plugin as soon as possible! #securityAdvisory

  3. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  4. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  5. लाल किले के पास कार धमाका: 32 वाहनों से बड़े आतंकी हमले की साजिश बेनकाब, दिल्ली हाई अलर्ट पर।

    aliyesha.com/sub/articles/news

    #delhi #newdelhi #india #news #press #crime #terrorism #RedFortBlast #TerrorPlot #DelhiAlert #NationalSecurity #IED #DelhiPolice #SecurityAdvisory #TravelAlert

    Enjoy tracker free reading with us. #privacy #privacymatters

  6. 🔎 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗶𝗻 𝗦𝗶𝗲𝗺𝗲𝗻𝘀 𝗦𝗜𝗣𝗥𝗢𝗧𝗘𝗖 𝟱 𝗜𝗱𝗲𝗻𝘁𝗶𝗳𝗶𝗲𝗱

    Our Technical Security Audit team has identified a vulnerability in 𝗦𝗶𝗲𝗺𝗲𝗻𝘀 𝗦𝗜𝗣𝗥𝗢𝗧𝗘𝗖 𝟱 𝗱𝗲𝘃𝗶𝗰𝗲𝘀:
    ⚠️ The USB port may allow attacks due to improper bandwidth limitation.

    📌 Description:
    Affected SIPROTEC 5 devices do not properly limit the bandwidth for incoming network packets over their local USB port. This could allow an attacker with physical access to send specially crafted packets with high bandwidth to the affected devices thus forcing them to exhaust their memory and stop responding to any network traffic via the local USB port. Affected devices reset themselves automatically after a successful attack. During this restart the protection function is not available.

    📄 The full advisory is available here: gai-netconsult.de/wp-content/u

    ⚠️ Please follow the manufacturer’s guidance and updates.

    🌐 An overview of further advisories can be found on our website: www.gai-netconsult.de/advisories

    👏 Congratulations to our colleagues 𝗠𝗮𝗿𝗰 𝗖𝘂𝗻𝘆 and 𝗧𝗼𝗿𝗮𝗹𝗳 𝗚𝗶𝗺𝗽𝗲𝗹 for this discovery.

    #CyberSecurity #SecurityAdvisory #Vulnerability #ITSecurity #GAINetConsult #SecurityNotice

  7. #InfoSec #needrestart #Qualys #SecurityAdvisory
    Local Privilege Escalations in needrestart
    We discovered three fundamental vulnerabilities in needrestart (three
    LPEs, Local Privilege Escalations, from any unprivileged user to full
    root), which are exploitable without user interaction on #Ubuntu Server
    (through unattended-upgrades)
    https://www.openwall.com/lists/oss-security/2024/11/19/1
  8. Vulnerability advisory🚨

    Local file inclusion identified in Milesight DeviceHub

    Our Joe Lovett discovered a flaw within the nginx docker container, enabling unauthenticated access to sensitive MQTT certificates, including private keys.

    See more on our website:
    🔗 pentestpartners.com/security-b

    #CyberSecurity #VulnerabilityResearch #Milesight #LocalFileInclusion #CyberThreats #VulnerabilityDisclosure #SecurityAdvisory

  9. #SecurityAdvisory

    We assess with high confidence that an attacker possessing the same retinal and fingerprint patterns as a victim can bypass traditional biometric security controls. To date, every biometric control we've tested is vulnerable to this attack. There is currently no known fix.

  10. #SecurityAdvisory

    We assess with high confidence that an attacker possessing the same retinal and fingerprint patterns as a victim can bypass traditional biometric security controls. To date, every biometric control we've tested is vulnerable to this attack. There is currently no known fix.

  11. The Canadian Centre for Cyber Security has issued a detailed security advisory regarding the "LINE DANCER" & "LINE RUNNER" attacks against Cisco ASA devices by what it believes are nation-state sponsored malicious actors.

    As usual, if you or your organization runs Cisco ASAs, time to patch to mitigate these vulnerabilities.

    www.cyber.gc.ca/en/news-events/cyber-activity-impacting-cisco-asa-vpns

    #infosec #cybersecurity #LINEDANCER #LINERUNNER #ARCANEDOOR #Cisco #CiscoASA #SecurityAdvisory #CVE_2024_20359 #CVE_2024_20353

  12. The Canadian Centre for Cyber Security has issued a detailed security advisory regarding the "LINE DANCER" & "LINE RUNNER" attacks against Cisco ASA devices by what it believes are nation-state sponsored malicious actors.

    As usual, if you or your organization runs Cisco ASAs, time to patch to mitigate these vulnerabilities.

    www.cyber.gc.ca/en/news-events/cyber-activity-impacting-cisco-asa-vpns

    #infosec #cybersecurity #LINEDANCER #LINERUNNER #ARCANEDOOR #Cisco #CiscoASA #SecurityAdvisory #CVE_2024_20359 #CVE_2024_20353

  13. Android Security Bulletin released: 28 vulnerabilities, 27 of which are high severity. 1 marked critical was CVE-2023-28582 (9.8 critical, disclosed 04 March 2024 by Qualcomm). No mention of exploitation in the wild. 🔗 source.android.com/docs/securi

    #PatchTuesday #Android #securityadvisory #vulnerability

  14. Android Security Bulletin released: 28 vulnerabilities, 27 of which are high severity. 1 marked critical was CVE-2023-28582 (9.8 critical, disclosed 04 March 2024 by Qualcomm). No mention of exploitation in the wild. 🔗 source.android.com/docs/securi

    #PatchTuesday #Android #securityadvisory #vulnerability

  15. Elastic security advisories (no mention of exploitation):

    • ESA-2024-06 Elasticsearch 8.13.0 / 7.17.19 Security Update: CVE-2024-23450 (4.9 medium) Elasticsearch Uncontrolled Resource Consumption vulnerability (Denial of Service?)
    • ESA-2024-07 Elasticsearch 8.13.0 Security Update: CVE-2024-23451 (4.4 medium) Elasticsearch Improper Authorization in the Remote Cluster Security API key based security model (arbitrary file read)

    #Elastic #PatchTuesday #vulnerability #CVE_2024_23450 #CVE_2024_23451 #securityadvisory

  16. Elastic security advisories (no mention of exploitation):

    • ESA-2024-06 Elasticsearch 8.13.0 / 7.17.19 Security Update: CVE-2024-23450 (4.9 medium) Elasticsearch Uncontrolled Resource Consumption vulnerability (Denial of Service?)
    • ESA-2024-07 Elasticsearch 8.13.0 Security Update: CVE-2024-23451 (4.4 medium) Elasticsearch Improper Authorization in the Remote Cluster Security API key based security model (arbitrary file read)

    #Elastic #PatchTuesday #vulnerability #CVE_2024_23450 #CVE_2024_23451 #securityadvisory

  17. Cisco decided to make it a Patch Wednesday. Here are 17 security advisories:

    • CVE-2024-20354 (4.7 medium) Cisco Aironet Access Point Software Resource Exhaustion Denial of Service Vulnerability
    • CVE-2024-20303 (7.4 high) Cisco IOS XE Software for Wireless LAN Controllers Multicast DNS Denial of Service Vulnerability
    • CVE-2024-20311 (8.6 high) Cisco IOS and IOS XE Software Locator ID Separation Protocol Denial of Service Vulnerability
    • CVE-2024-20312 (7.4 high) Cisco IOS and IOS XE Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
    • CVE-2024-20324 (5.5 medium) Cisco IOS XE Software for Wireless LAN Controllers Privilege Escalation Vulnerability
    • CVE-2024-20306 (6.0 medium) Cisco IOS XE Software Unified Threat Defense Command Injection Vulnerability (analyst note: their advisory link is broken)
    • CVE-2024-20278 (6.5 medium) Cisco IOS XE Software Privilege Escalation Vulnerability
    • CVE-2024-20313 (7.4 high) Cisco IOS XE Software OSPFv2 Denial of Service Vulnerability
    • CVE-2024-20314 (8.6 high) Cisco IOS XE Software SD-Access Fabric Edge Node Denial of Service Vulnerability
    • CVE-2024-20276 (7.4 high) Cisco IOS Software for Catalyst 6000 Series Switches Denial of Service Vulnerability
    • CVE-2024-20307 and CVE-2024-20308 (8.6 high) Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Fragmentation Denial of Service Vulnerabilities
    • CVE-2024-20316 (5.8 medium) Cisco IOS XE Software NETCONF/RESTCONF IPv4 Access Control List Bypass Vulnerability
    • CVE-2024-20259 (8.6 high) Cisco IOS XE Software DHCP Snooping with Endpoint Analytics Denial of Service Vulnerability
    • CVE-2024-20333 (4.3 medium) Cisco Catalyst Center Authorization Bypass Vulnerability
    • CVE-2024-20309 (5.6 medium) Cisco IOS XE Software Auxiliary Asynchronous Port Denial of Service Vulnerability
    • CVE-2024-20265 (5.9 medium) Cisco Access Point Software Secure Boot Bypass Vulnerability
    • CVE-2024-20271 (8.6 high) Cisco Access Point Software Denial of Service Vulnerability

    The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

    #Cisco #PatchTuesday #securityadvisory #vulnerability #CVE

  18. Cisco decided to make it a Patch Wednesday. Here are 17 security advisories:

    • CVE-2024-20354 (4.7 medium) Cisco Aironet Access Point Software Resource Exhaustion Denial of Service Vulnerability
    • CVE-2024-20303 (7.4 high) Cisco IOS XE Software for Wireless LAN Controllers Multicast DNS Denial of Service Vulnerability
    • CVE-2024-20311 (8.6 high) Cisco IOS and IOS XE Software Locator ID Separation Protocol Denial of Service Vulnerability
    • CVE-2024-20312 (7.4 high) Cisco IOS and IOS XE Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
    • CVE-2024-20324 (5.5 medium) Cisco IOS XE Software for Wireless LAN Controllers Privilege Escalation Vulnerability
    • CVE-2024-20306 (6.0 medium) Cisco IOS XE Software Unified Threat Defense Command Injection Vulnerability (analyst note: their advisory link is broken)
    • CVE-2024-20278 (6.5 medium) Cisco IOS XE Software Privilege Escalation Vulnerability
    • CVE-2024-20313 (7.4 high) Cisco IOS XE Software OSPFv2 Denial of Service Vulnerability
    • CVE-2024-20314 (8.6 high) Cisco IOS XE Software SD-Access Fabric Edge Node Denial of Service Vulnerability
    • CVE-2024-20276 (7.4 high) Cisco IOS Software for Catalyst 6000 Series Switches Denial of Service Vulnerability
    • CVE-2024-20307 and CVE-2024-20308 (8.6 high) Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Fragmentation Denial of Service Vulnerabilities
    • CVE-2024-20316 (5.8 medium) Cisco IOS XE Software NETCONF/RESTCONF IPv4 Access Control List Bypass Vulnerability
    • CVE-2024-20259 (8.6 high) Cisco IOS XE Software DHCP Snooping with Endpoint Analytics Denial of Service Vulnerability
    • CVE-2024-20333 (4.3 medium) Cisco Catalyst Center Authorization Bypass Vulnerability
    • CVE-2024-20309 (5.6 medium) Cisco IOS XE Software Auxiliary Asynchronous Port Denial of Service Vulnerability
    • CVE-2024-20265 (5.9 medium) Cisco Access Point Software Secure Boot Bypass Vulnerability
    • CVE-2024-20271 (8.6 high) Cisco Access Point Software Denial of Service Vulnerability

    The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

    #Cisco #PatchTuesday #securityadvisory #vulnerability #CVE

  19. Apple security advisories have been released:

    All of the security advisories reference CVE-2024-1580 (5.9 medium) which is an integer overflow in dav1d AV1 decoder that could lead to out-of-bounds write (arbitrary code execution). It was fixed with improved input validation. No mention of exploitation in the wild. Discovered by Nick Galloway of Google Project Zero.

    #Apple #PatchTuesday #vulnerability #securityadvisory #CVE_2024_1580

  20. Apple security advisories have been released:

    All of the security advisories reference CVE-2024-1580 (5.9 medium) which is an integer overflow in dav1d AV1 decoder that could lead to out-of-bounds write (arbitrary code execution). It was fixed with improved input validation. No mention of exploitation in the wild. Discovered by Nick Galloway of Google Project Zero.

    #Apple #PatchTuesday #vulnerability #securityadvisory #CVE_2024_1580

  21. Mozilla Foundation security advisories. No mention of exploitation. Mozilla does a funny and says "Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code."

    • 2024-12 Security Vulnerabilities fixed in Firefox 124
    • 2024-13 Security Vulnerabilities fixed in Firefox ESR 115.9
    • 2024-14 Mozilla Foundation Security Advisory 2024-14Security Vulnerabilities fixed in Thunderbird 115.9
      • Interesting note: In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

    #Mozilla #PatchTuesday #securityadvisory #vulnerability #firefox #Thunderbird

  22. Mozilla Foundation security advisories. No mention of exploitation. Mozilla does a funny and says "Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code."

    • 2024-12 Security Vulnerabilities fixed in Firefox 124
    • 2024-13 Security Vulnerabilities fixed in Firefox ESR 115.9
    • 2024-14 Mozilla Foundation Security Advisory 2024-14Security Vulnerabilities fixed in Thunderbird 115.9
      • Interesting note: In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

    #Mozilla #PatchTuesday #securityadvisory #vulnerability #firefox #Thunderbird

  23. Finnish Digital and Population Data Services Agency (DVV) provides a Card Reader Software which can be used for strong authentication and digital signing with the DVV issued identity cards. The Fujitsu mPollux DigiSign application communicates with the identity card and allows log in to official e-services and/or digitally sign documents. The Fujitsu mPollux DigiSign Client for macOS version 4.2.4c-8322 and previous contains two security vulnerabilities that in the worst-case scenario can lead to full system compromise.

    labs.withsecure.com/advisories #infosec #vulnerability #securityadvisory

  24. Finnish Digital and Population Data Services Agency (DVV) provides a Card Reader Software which can be used for strong authentication and digital signing with the DVV issued identity cards. The Fujitsu mPollux DigiSign application communicates with the identity card and allows log in to official e-services and/or digitally sign documents. The Fujitsu mPollux DigiSign Client for macOS version 4.2.4c-8322 and previous contains two security vulnerabilities that in the worst-case scenario can lead to full system compromise.

    labs.withsecure.com/advisories #infosec #vulnerability #securityadvisory

  25. ✨ CVE-2022-37958:
    Critical Windows code-execution vulnerability went undetected until now

    ▶️ Potential to rival EternalBlue

    ▶️ Wormable

    ▶️ Unlike EternalBlue, Vulnerability present in a much broader range of network protocols

    ▶️ Good news: patch was released in September. hopefully all of us applied it

    arstechnica.com/information-te

    #infosec #eternalblue #patching #securityadvisory #sysadmin #blueteam #windowsvulnerability

  26. ✨ CVE-2022-37958:
    Critical Windows code-execution vulnerability went undetected until now

    ▶️ Potential to rival EternalBlue

    ▶️ Wormable

    ▶️ Unlike EternalBlue, Vulnerability present in a much broader range of network protocols

    ▶️ Good news: patch was released in September. hopefully all of us applied it

    arstechnica.com/information-te

    #infosec #eternalblue #patching #securityadvisory #sysadmin #blueteam #windowsvulnerability

  27. Das Common Security Advisory Framework soll Administratoren die Arbeit erleichtern und aktuelle Sicherheitsinformationen leichter auffindbar machen.
    Standard für maschinenlesbare Sicherheitshinweise verabschiedet