Plus récents

RCE on Spip

  • Preauth custom SSTI on icalendar generation
  • Postauth email content eval
  • Postauth code injection in MediaBox as a WebMestre
  • Postauth php file upload // t0
  • DNS Rebinding on the file upload feature // t0

thinkloveshare.com/hacking/rce

🇨🇭 Un expert informatique a identifié une faille de sécurité sur l'une plateforme des Chemins de Fer Fédéraux suisses (cff.ch) lui permettant d'accéder aux données de 500 000 clients Swisspass. Aujourd'hui, on apprend que les chemins de fer étaient au courant de cette faille depuis 2018

ictjournal.ch/news/2022-08-19/

A vulnerability allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account. No passwords were exposed.

privacy.twitter.com/en/blog/20

🔥 CVE-2022-20842 | CVE-2022-20827 | CVE-2022-20841

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS)

tools.cisco.com/security/cente

  • 🔥 CVE-2022-29154

A critical arbitrary file write vulnerability in the Rsync (before 3.2.5) utility that allows malicious remote servers to write arbitrary files inside th directories of connecting peers.

🛠 Appliquez le correctif de sécurité dans les plus brefs délais.

nvd.nist.gov/vuln/detail/CVE-2

Microsoft Security Response Center found a Private-Sector Offensive Actor. PSOAs also refers to as cyber mercenaries, sell hacking tools or services. KNOTWEED, developed malware called Subzero.

microsoft.com/security/blog/20

🐧 (CVE-2022-32250) Linux Kernel use-after-free write in netfilterallows a local user (able to create user/net namespaces) to escalate privileges to root

🛠 Game Of Active Directory

GOAD is a vulnerable Active Directory environement for pentesters.

github.com/Orange-Cyberdefense

cloudvulndb is an open project to list all known vulnerabilities and security issues.

History: cloud providers don't issue CVEs for security vulnerabilities, so there's no transparency about issues.

cloudvulndb.org

(CVE-2022-30333) - An attacker is able to create files outside of the target extraction directory when an application or victim user extracts an untrusted RAR archive. If they can write to a known location, they are likely to be able to leverage it in a way leading to the execution of arbitrary commands on the system.

blog.sonarsource.com/zimbra-pr

🛠 DFSCoerce : PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot() method

github.com/Wh04m1001/DFSCoerce

🇮🇳 An indian government website (pmkisan.gov.in) was exposing the Aadhaar numbers of India's farmers, potentially amounting to hundreds of millions of people.

techcrunch.com/2022/06/13/aadh

CVE-2022-23088 - FreeBSD patched a 13-year-old heap overflow in the Wi-Fi stack that could allow network-adjacent attackers to execute arbitrary code on affected installations of FreeBSD Kernel.

zerodayinitiative.com/blog/202

💀 Hertzbleed Side-Channel Attack allows to remotely steal encryption keys from (CVE-2022-23823) & (CVE-2022-24436) chips.

hertzbleed.com

Plus anciens