#securityflaw — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityflaw, aggregated by home.social.
-
🚀 Oh great, another "revolutionary" iPhone exploit by some self-proclaimed geniuses who probably high-fived each other for finding a bug that only affects outdated hardware. 🙄 But hey, they managed to cobble together a PoC—because who needs a functioning exploit, right? 📉
https://ps.tc/pages/blog-usbliter8.html #iPhoneExploit #outdatedHardware #securityFlaw #PoC #techNews #HackerNews #ngated -
🤔 Ah, the classic "same client" saga with CVE-2026-4020—because who needs originality in #hacking when you have a Google Cloud fleet playing dress-up with 3,299 user agents? 🌍📬 Apparently, exploiting Gravity #SMTP is a team sport, but only if your team is a single IP address with a personality disorder. What a performance! 🎭💻
https://honeylabs.net/blog/the-cloud-fleet-behind-cve-2026-4020 #CVE20264020 #GoogleCloud #SecurityFlaw #Cybersecurity #HackerNews #ngated -
@signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.
Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.
I feel
c o n t e m p t
towards Signal when it is designed this way.
#badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian
-
🚨 Breaking news: Decades of programming wisdom have officially been deemed misdirection 🚨 Paul Tarvydas has cracked the code, folks! Turns out we've been using type checking as a security blanket to hide our architectural shame 🙈. Who knew all those fancy algorithms were just smoke and mirrors? 🤡
https://programmingsimplicity.substack.com/p/type-checking-is-a-symptom-not-a #programmingwisdom #typechecking #architecturalshame #securityflaw #codingrevolution #HackerNews #ngated -
#WinRAR has a serious #securityflaw - worrying zero-day issue lets #hackers plant #malware, so patch right away
-
Windows Remote Desktop Protocol Allows Revoked Passwords; Microsoft Calls it a Feature
#Cybersecurity #Windows11 #RDP #Microsoft #SecurityFlaw #PasswordSecurity #InfoSec #CachedCredentials #WindowsSecurity #SysAdmin
-
🚨 BREAKING: Security flaw discovered in Erlang/OTP SSH server, but don't worry, you can't read about it because the server is too busy playing hide and seek with its own responses. 🙈🔐 Meanwhile, the tech world collectively pretends this is the first time a server has dropped the ball. 😂
https://nvd.nist.gov/vuln/detail/CVE-2025-32433 #ErlangSSH #SecurityFlaw #TechNews #ServerIssues #HideAndSeek #CyberSecurity #HackerNews #ngated -
Max severity RCE flaw discovered in widely used Apache Parquet
#HackerNews #MaxSeverity #RCE #ApacheParquet #SecurityFlaw #CyberSecurity #Vulnerability
-
This top #WordPress plugin could be hiding a worrying #securityflaw, so be on your guard
-
🚨Wow, someone discovered a security flaw! All hail the tech hero who bumbled upon a bug in software made to be unhackable.🛡️ It’s like accidentally finding a secret passage in a LEGO castle—totally intentional and absolutely deserving of a blog post with a self-indulgent menu.🍽️
https://mattsayar.com/how-i-hacked-my-companys-sso-provider/ #techhero #securityflaw #softwarebug #hackingnews #accidentaldiscovery #LEGOfinds #HackerNews #ngated -
A flaw in Microsoft Azure multi-factor authentication allowed attackers to brute-force accounts, exposing data in Teams, OneDrive, and more. #Microsoft #Cybersecurity #MFA #Authentication #DataSecurity #Microsoft365 #Azure #Hacking #Infosec #CloudSecurity #SecurityFlaw #Passwordless #CyberThreats #OasisSecurity #MicrosoftTeams
-
"He included a PoC that caused the ChatGPT app for macOS to send a verbatim copy of all user input and ChatGPT output to a server of his choice. All a target needed to do was instruct the LLM to view a web link that hosted a malicious image. From then on, all input and output to and from ChatGPT was sent to the attacker's website."
-
Major Flaw in Microsoft Mac Apps Could Let Hackers Spy Through Mic and Camera https://thecyberexpress.com/microsoft-apps-macs-hackers-flaw/ #TheCyberExpressNews #VulnerabilityNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #Vulnerability #securityflaw #Cyberattack #databreach #Microphone #Microsoft #Hackers #malware #Privacy #Camera #macOS
-
Cisco discloses a 10.0 CVSS rating vulnerability in SSM On-Prem
https://stackdiary.com/cisco-discloses-cve-2024-20419-for-ssm-on-prem/
#Cisco #Security #Vulnerability #Cybersecurity #CVSS #Hackers #Exploitation #ITsecurity #DataBreach #Software #TechNews #SecurityFlaw #NetworkSecurity #CriticalUpdate #Admins #DataProtection #PatchNow #Infosec #CyberThreats #SecureNetworks #TechUpdate #DigitalSafety #SoftwareBug #CyberDefense #CriticalVulnerability #ITupdate #SystemAdmin #SecureSoftware #NetworkAdmin #CyberAlert #CVE
-
Multiple Cryptocurrency Firms Fall Victim to Squarespace Domain Hijacking https://thecyberexpress.com/cryptocurrency-squarespace-domain-hijacking/ #Squarespacedomainhijacking #MultifactorAuthentication #TheCyberExpressNews #CybersecurityNews #TheCyberExpress #DataBreachNews #cryptocurrency #FirewallDaily #GoogleDomains #HackerClaims #securityflaw #Squarespace #HackerNews #Phishing
-
Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/
#Linksys #Velop #WiFi #Router #Security #DataBreach #Cybersecurity #Privacy #Encryption #Hackers #MeshNetwork #TechNews #ConsumerAlert #Testaankoop #Amazon #Plaintext #SSID #Password #Firmware #Vulnerability #CyberAttack #NetworkSecurity #DigitalPrivacy #TechSafety #UserData #WiFiSecurity #InternetSafety #HomeNetwork #ITsecurity #TechAlert #SecurityFlaw
-
Mastodon: Security flaw allows unauthorized access to posts
https://stackdiary.com/mastodon-security-flaw-allows-unauthorized-access-to-posts/
#Mastodon #Security #Vulnerability #Update #Cybersecurity #Privacy #Software #Patch #Server #HighRisk #Hackers #DataProtection #Infosec #TechNews #BugFix #CriticalUpdate #DigitalSafety #MastodonUpdate #CyberAttack #UserSafety #DataBreach #SecurityAlert #NetworkSecurity #OnlineSafety #SecurityFlaw #SecureUpdate #ITSecurity #TechAlert #MastodonPatch #SystemUpdate #CVE
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Critical GitHub Enterprise Server Flaw Allows Authentication Bypass
Date: May 21, 2024
CVE: [[CVE-2024-4985]]
Vulnerability Type: Improper Authentication
CWE: [[CWE-287]]
Sources: Cyber Security News, SecurityWeek, The Hacker NewsIssue Summary
A critical vulnerability in GitHub Enterprise Server, identified as CVE-2024-4985, was discovered that allows attackers to bypass authentication. This flaw, found in versions 3.9.14, 3.10.11, 3.11.9, and 3.12.3, permits unauthorized access to repositories and sensitive data by exploiting a weakness in the SAML SSO authentication process.
Technical Key Findings
The vulnerability arises from a logic error in the SAML SSO authentication process, where the server fails to verify the validity of digital signatures on SAML responses properly. Attackers can craft SAML assertions with any certificate, which the server incorrectly accepts, allowing the spoofing of user identities, including admin accounts.
Vulnerable Products
- GitHub Enterprise Server versions 3.9.14
- GitHub Enterprise Server versions 3.10.11
- GitHub Enterprise Server versions 3.11.9
- GitHub Enterprise Server versions 3.12.3
Impact Assessment
Exploitation of this vulnerability could lead to unauthorized access to private repositories, sensitive data, and administrative controls. This can result in data breaches, code tampering, and potential intellectual property theft.
Patches or Workaround
GitHub has released patched versions (3.9.15, 3.10.12, 3.11.10, and 3.12.4) to address this issue. As an interim measure, enabling SAML certificate pinning can mitigate the risk. Additionally, auditing access logs for suspicious activity and rotating credentials is advised.
Tags
#GitHub #CVE20244985 #SAML #AuthenticationBypass #SecurityFlaw #EnterpriseSecurity #DataBreach #PatchUpdate #CyberSecurity
-
#Anycubic users say their #3Dprinters were hacked to warn of a #securityflaw
This #vulnerability allegedly enables potential attackers to control any Anycubic #3Dprinter affected by this vulnerability using the company's #MQTT service #API.
The hacked_machine_readme.gcode file received by the impacted devices also asks Anycubic to open-source their 3D printers because the company's software "is lacking." The file claims 2,934,635 devices downloaded this warning .
https://techcrunch.com/2024/02/28/anycubic-users-3d-printers-hacked-warning/ -
"🔐 #KeyTrap DoS: The DNSSEC Dilemma - A 25-Year-Old Design Flaw Exposed 🚨"
In a groundbreaking discovery, researchers from the National Research Center for Applied Cybersecurity ATHENE have unveiled #KeyTrap (CVE-2023-50387), a critical flaw in DNSSEC's design that could bring the internet to its knees. With a severity rating of 7.5/10, this flaw in DNSSEC has been lurking since 1999, and affects 31% of global DNSSEC-validating DNS resolvers, risking widespread internet service disruptions. KeyTrap, an Algorithmic Complexity Attack, can overload a DNS server with a single packet, stalling major DNS providers like Google and Cloudflare for up to 16 hours. This vulnerability not only jeopardizes internet access but could also cripple essential security mechanisms like anti-spam defenses and PKI. Despite patches being rolled out, a permanent fix may necessitate a DNSSEC standard overhaul. 🌍💻🛡️
Tags: #CyberSecurity #DNSSEC #Vulnerability #InternetSafety #PatchNow #TechNews #InfoSecExchange #SecurityFlaw #DigitalInfrastructure 🚀🔒💡
Source: ATHENE Press Portal
-
This is one worth sharing folks
A serious flaw in bluetooth from versions 4.2 onwards has been discovered.
It CANNOT be fixed as it's the architectural design and is NOT a software flaw that can be patched.
It doesn't matter what device you are using, anything from 2014 onwards, using 4.2 to the latest 5.4 is vulnerable to attack and decryption of data being transferred.
Even apple airdrop is vulnerable as that uses bluetooth for file transfers.
-
"🚨 ShellTorch Attack: A Fiery Threat to PyTorch Models 🚨"
🔥 The #ShellTorch attack exposes millions of #PyTorch systems to critical Remote Code Execution (RCE) vulnerabilities! Researchers from Oligo Security have unveiled a series of vulnerabilities within the PyTorch Model Server, aka TorchServe. 🤖🛑
A series of critical vulnerabilities, known as 'ShellTorch,' has been discovered in the TorchServe AI model-serving tool, widely used by organizations such as Amazon, OpenAI, Tesla, Azure, Google, and Intel. These flaws can potentially allow unauthorized access and remote code execution on vulnerable servers. The vulnerabilities affect TorchServe versions 0.3.0 through 0.8.1.
One of the vulnerabilities stems from a misconfiguration in the management interface API, which exposes it to external requests without proper authentication, enabling malicious model uploads from external sources. Another issue is a remote server-side request forgery (SSRF) that can lead to remote code execution, as all domains are accepted by default. The third vulnerability involves Java deserialization, allowing attackers to execute remote code.
🔗 Vulnerabilities include:
- Unauthenticated Management Interface API Misconfiguration
- CVE-2023-43654: SSRF leading to RCE
- CVE-2022-1471: Java Deserialization RCE due to SnakeYAML library misuse
🌐 Affected organizations include giants like Walmart, Amazon, OpenAI, Tesla, Azure, Google Cloud, and Intel. The vulnerabilities allow attackers to execute code remotely with high privileges, potentially affecting thousands of IP addresses globally. 🌎🔓
🛡️ Mitigation steps:
- Update to TorchServe v0.8.2 or above 🔄
- Configure the Management Console 🛠️
- Control Model Fetching 🚫
🔗 Source: HackRead, The Hacker News
🏷️ Tags: #Cybersecurity #Vulnerability #AI #ML #PyTorch #ShellTorch #RCE #CyberAttack #InfoSec #SecurityFlaw #MachineLearning #Artificial
-
Security researchers at #Mandiant say #China-backed #hackers are likely behind the mass-exploitation of a recently discovered #zeroday #securityflaw in #BarracudaNetworks' #email security gear, which prompted a warning to customers to remove and replace affected devices. Their goal was to spy on #government and #academic accounts https://techcrunch.com/2023/06/15/mandiant-china-hackers-barracuda-espionage-governments/
-
Time to hit Ye Ole "Yum Update"!
That's righ! I said "Yum"!
You may want to run system updates, after a recent sudo security flaw https://www.gamingonlinux.com/2023/02/you-may-want-to-run-system-updates-after-a-recent-sudo-security-flaw/
#Update #Sudo #SecurityFlaw #Linux #SteamDeck #InfoSec #OpenSource #TechNews
-
Got an old iOS device?
Time to patch that up, too!
Apple just updated iOS 12 to patch a critical security flaw https://www.macworld.com/article/1483041/ios-12-5-7-iphone-6-security-update-zero-day.html
-
This one's fairly fresh and hasn't seen much coverage: CloudSek has discovered a cookie-stealing authentication bypass that works against a bunch of Atlassian products: Jira, Confluence, Trello and BitBucket. No word as yet from Atlassian on a patch. Keep an eye out.
Not super easy to exploit, but still troubling.
#Atlassian #Jira #Confluence #Trello #BitBucket #SecurityFlaw #exploit