Plus récents

Earlier this week the Jenkins infrastructure team identified a successful attack against our deprecated Confluence service

jenkins.io/blog/2021/09/04/wik

This PoC in generates payload when exploited for a 0-day of GhostScript 9.50. This exploit affect to ImageMagick with the default settings from Ubuntu repository #

github.com/duc-nt/RCE-0-day-fo

(CVE-2021-38408) A stack-based buffer overflow vulnerability in Advantech WebAccess caused by a lack of proper validation of the length of user-supplied data may allow RCE.

us-cert.cisa.gov/ics/advisorie

💥 (CVE-2021-26084) was recently detected in exploits ITW (in the wild), a mass exploitation of Atlassian Confluence is ongoing & expected to accelerate

0-day RCE backdoor in Teradek IP video device firmwares - This is a report of a 0-day backdoor giving root shell (root:upsetdac).

an0n-r0.medium.com/full-disclo

(CVE-2021-26084) (PoC) - An OGNL injection vulnerability exists that would allow an authenticated user, and in some instances unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance.

github.com/alt3kx/CVE-2021-260

iOS 14.0 remote jailbreak using RCE + LPE exploit. « Don't stay on versions on or below iOS 14.3. If you click a malicious link, bad guys would steal everything on your »

https:/twitter.com/pattern_F_/status/1432599008757760000

Unauthenticated PetitPotam everywhere:

  • petitpotam to DC, target it to attacker host
  • ntlmrelay (using socks) to target
  • petitpotam again to target through socks (without supplying any passwords) using the relayed DC creds.

streamable.com/dzdmfb

CVE-2021-33766 (ProxyToken) An authentication bypass in Exchange server. Exchange Server continues to be an amazingly fertile area for vulnerability research.

zerodayinitiative.com/blog/202

« Worst cloud vulnerability you can imagine » discovered in . Microsoft only emailed 30% or so of its Cosmos DB customers about the vulnerability

arstechnica.com/information-te

warned thousands of its computing customers, including some of the world's largest companies, that intruders could have the ability to read, change or even delete their main databases. The vulnerability is in Microsoft Azure's flagship Cosmos DB database.

reuters.com/technology/exclusi

Plus anciens