Yarn, Pip, Composer & co: Vulnerabilities in popular package managers
https://ift.tt/8r0nvCb
Submitted March 09, 2022 at 10:21PM by SonarPaul
via reddit https://ift.tt/YkEBPoj
https://ift.tt/8r0nvCb
Submitted March 09, 2022 at 10:21PM by SonarPaul
via reddit https://ift.tt/YkEBPoj
Sonarsource
Securing Developer Tools: Package Managers
Yarn, Pip, Composer & friends: Learn about 3 types of vulnerabilities we found in popular package managers that can be used by attackers to target developers.
IDA Pro plugin: query based xref finder for vulnerability research
https://ift.tt/mO1GSyX
Submitted March 09, 2022 at 10:02PM by Martypx00
via reddit https://ift.tt/I7MRAfw
https://ift.tt/mO1GSyX
Submitted March 09, 2022 at 10:02PM by Martypx00
via reddit https://ift.tt/I7MRAfw
GitHub
GitHub - Accenture/VulFi
Contribute to Accenture/VulFi development by creating an account on GitHub.
Branch History Injection - Circumventing Spectre-v2 Hardware Mitigations
https://ift.tt/2OjxnCd
Submitted March 10, 2022 at 12:06AM by LordAlfredo
via reddit https://ift.tt/OVipq4E
https://ift.tt/2OjxnCd
Submitted March 10, 2022 at 12:06AM by LordAlfredo
via reddit https://ift.tt/OVipq4E
VUSec
Branch History Injection - VUSec
BHI (or Spectre-BHB) is a revival of cross-privilege Spectre-v2 attacks on modern systems deploying in-hardware defenses. And we have a very neat end-to-end exploit leaking arbitrary kernel memory on modern Intel CPUs to prove it
CVE-2022-0847: “Dirty Pipe” Linux Local Privilege Escalation
https://ift.tt/XPRA1fa
Submitted March 10, 2022 at 07:27AM by MiguelHzBz
via reddit https://ift.tt/A5bl4sw
https://ift.tt/XPRA1fa
Submitted March 10, 2022 at 07:27AM by MiguelHzBz
via reddit https://ift.tt/A5bl4sw
Sysdig
CVE-2022-0847: “Dirty Pipe” Linux Local Privilege Escalation – Sysdig
Local privilege escalation flaw in the Linux Kernel was disclosed on Monday, nicknamed “Dirty Pipe” ID CVE-2022-0847.
CrowdSec releases first threat landscape report based completely on crowdsourced data from the community of CrowdSec users
https://ift.tt/fruXjoC
Submitted March 11, 2022 at 01:00AM by klausagnoletti
via reddit https://ift.tt/y5TVKrN
https://ift.tt/fruXjoC
Submitted March 11, 2022 at 01:00AM by klausagnoletti
via reddit https://ift.tt/y5TVKrN
The open-source & collaborative IPS
The CrowdSec Community report is out
Based on the CrowdSec data shared by the community, this first edition of the report provides an overview of the main cyber threats identified worldwide.
An unexpected Redis sandbox escape affecting only Debian, Ubuntu, and other Debian derivatives
https://ift.tt/vYFqSyO
Submitted March 11, 2022 at 02:49PM by albinowax
via reddit https://ift.tt/wekRoH3
https://ift.tt/vYFqSyO
Submitted March 11, 2022 at 02:49PM by albinowax
via reddit https://ift.tt/wekRoH3
reddit
An unexpected Redis sandbox escape affecting only Debian, Ubuntu,...
Posted in r/netsec by u/albinowax • 101 points and 0 comments
SATCOM terminals under attack in Europe: a plausible analysis.
https://ift.tt/SGt4Bav
Submitted March 12, 2022 at 02:01AM by eberkut
via reddit https://ift.tt/dWu0jcI
https://ift.tt/SGt4Bav
Submitted March 12, 2022 at 02:01AM by eberkut
via reddit https://ift.tt/dWu0jcI
Reversemode
SATCOM terminals under attack in Europe: a plausible analysis.
------ Update 03/12/2022 Reuters has published new information on this incident, which initially matches the proposed scenario. You can find...
Casper-fs is a Custom Hidden Linux Kernel Module generator. Each module works in the file system to protect and hide secret files.
https://ift.tt/TE20yst
Submitted March 12, 2022 at 10:37AM by CoolerVoid
via reddit https://ift.tt/o1URkAj
https://ift.tt/TE20yst
Submitted March 12, 2022 at 10:37AM by CoolerVoid
via reddit https://ift.tt/o1URkAj
GitHub
GitHub - CoolerVoid/casper-fs: Casper-fs is a Custom Hidden Linux Kernel Module generator. Each module works in the file system…
Casper-fs is a Custom Hidden Linux Kernel Module generator. Each module works in the file system to protect and hide secret files. - GitHub - CoolerVoid/casper-fs: Casper-fs is a Custom Hidden Linu...
KB4288: CVE-2022-26500 | CVE-2022-26501
https://ift.tt/UyXtc17
Submitted March 13, 2022 at 03:50AM by ghost-train
via reddit https://ift.tt/amjsSP2
https://ift.tt/UyXtc17
Submitted March 13, 2022 at 03:50AM by ghost-train
via reddit https://ift.tt/amjsSP2
Veeam Software
KB4288: CVE-2022-26500 | CVE-2022-26501
Multiple vulnerabilities (CVE-2022-26500, CVE-2022-26501) in Veeam Backup & Replication allow executing malicious code remotely without authentication. This may lead to gaining control over the target system.
An automated setup for fuzzing Redis w/ AFL++
https://ift.tt/UgE796e
Submitted March 13, 2022 at 05:15PM by pwntheplanet
via reddit https://ift.tt/mHCrp65
https://ift.tt/UgE796e
Submitted March 13, 2022 at 05:15PM by pwntheplanet
via reddit https://ift.tt/mHCrp65
GitHub
GitHub - 0xbigshaq/redis-afl: An automated setup for fuzzing Redis w/ AFL++
An automated setup for fuzzing Redis w/ AFL++. Contribute to 0xbigshaq/redis-afl development by creating an account on GitHub.
An automated setup for fuzzing Apache httpd w/ AFL++
https://ift.tt/GCX7taM
Submitted March 13, 2022 at 06:16PM by pwntheplanet
via reddit https://ift.tt/0bftKTX
https://ift.tt/GCX7taM
Submitted March 13, 2022 at 06:16PM by pwntheplanet
via reddit https://ift.tt/0bftKTX
GitHub
GitHub - 0xbigshaq/apache-afl: An automated setup for compiling & fuzzing Apache httpd server
An automated setup for compiling & fuzzing Apache httpd server - 0xbigshaq/apache-afl
Reverse Engineering a Netgear NDay
https://ift.tt/9qMXJxN
Submitted March 14, 2022 at 02:11AM by lightgrains
via reddit https://ift.tt/TYINBwd
https://ift.tt/9qMXJxN
Submitted March 14, 2022 at 02:11AM by lightgrains
via reddit https://ift.tt/TYINBwd
StarkeBlog
Reverse Engineering a Netgear Nday
CVE-ID: CVE-2021-34979 ZDI Identifier: ZDI-CAN-13512
FirmWire is a full-system baseband firmware emulation platform
https://ift.tt/FrdmqGs
Submitted March 14, 2022 at 12:57PM by domenukk
via reddit https://ift.tt/SaBt73e
https://ift.tt/FrdmqGs
Submitted March 14, 2022 at 12:57PM by domenukk
via reddit https://ift.tt/SaBt73e
GitHub
GitHub - FirmWire/FirmWire: FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause…
FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares - GitHub - FirmWire/FirmWire: FirmWire is a full-syst...
Making Sense Of The Dirty Pipe Vulnerability (CVE-2022-0847) - RedHunt Labs
https://ift.tt/CTuKrQ4
Submitted March 14, 2022 at 02:47PM by redhuntlabs
via reddit https://ift.tt/vwQnqC3
https://ift.tt/CTuKrQ4
Submitted March 14, 2022 at 02:47PM by redhuntlabs
via reddit https://ift.tt/vwQnqC3
RedHunt Labs
Making Sense Of The Dirty Pipe Vulnerability (CVE-2022-0847) - RedHunt Labs
CVE-2022-0847 or "Dirty Pipe", is a Linux kernel flaw that allows attackers to escalate privileges. We analyze the vulnerability in-depth in this blog.
Shodan: Introducing the InternetDB API
https://ift.tt/dfR31qF
Submitted March 14, 2022 at 10:03PM by D4r1
via reddit https://ift.tt/U7OmTHV
https://ift.tt/dfR31qF
Submitted March 14, 2022 at 10:03PM by D4r1
via reddit https://ift.tt/U7OmTHV
reddit
Shodan: Introducing the InternetDB API
Posted in r/netsec by u/D4r1 • 208 points and 7 comments
AWS/GitLab Self-Hosted CTF
https://ift.tt/rIhnEmF
Submitted March 15, 2022 at 12:27AM by RedTermSession
via reddit https://ift.tt/JNHZFAo
https://ift.tt/rIhnEmF
Submitted March 15, 2022 at 12:27AM by RedTermSession
via reddit https://ift.tt/JNHZFAo
hackingthe.cloud
CI/CDon't - Hacking The Cloud
An AWS/GitLab CICD themed CTF.
NSA, CISA Release Updated Kubernetes Hardening Guidance
https://ift.tt/ye17utx
Submitted March 15, 2022 at 11:05PM by sanitybit
via reddit https://ift.tt/BML9ukP
https://ift.tt/ye17utx
Submitted March 15, 2022 at 11:05PM by sanitybit
via reddit https://ift.tt/BML9ukP
National Security Agency/Central Security Service
NSA, CISA release Kubernetes Hardening Guidance
The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) released a Cybersecurity Technical Report, “Kubernetes Hardening Guidance,” today. This report
OpenSSL CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates
https://ift.tt/xEvSNMi
Submitted March 15, 2022 at 11:14PM by yawkat
via reddit https://ift.tt/nO2Bprt
https://ift.tt/xEvSNMi
Submitted March 15, 2022 at 11:14PM by yawkat
via reddit https://ift.tt/nO2Bprt
reddit
OpenSSL CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable...
Posted in r/netsec by u/yawkat • 0 points and 0 comments
CVE-2022-25636 : New Linux Bug in Netfilter Firewall Module Lets Attackers Gain Root Access
https://ift.tt/KRPbcSu
Submitted March 16, 2022 at 07:45AM by Late_Ice_9288
via reddit https://ift.tt/GtkhMUz
https://ift.tt/KRPbcSu
Submitted March 16, 2022 at 07:45AM by Late_Ice_9288
via reddit https://ift.tt/GtkhMUz
reddit
CVE-2022-25636 : New Linux Bug in Netfilter Firewall Module Lets...
Posted in r/netsec by u/Late_Ice_9288 • 63 points and 3 comments
7 RCE and DoS vulnerabilities Found in ClickHouse DBMS
https://ift.tt/YHOlbTh
Submitted March 16, 2022 at 12:48PM by SRMish3
via reddit https://ift.tt/1Yas2XR
https://ift.tt/YHOlbTh
Submitted March 16, 2022 at 12:48PM by SRMish3
via reddit https://ift.tt/1Yas2XR
JFrog
Security Vulnerabilities Found in ClickHouse Open-Source Software
JFrog’s Security Research team discovered 7 vulnerabilities in the ClickHouse database management software. Learn about the issues and how to mitigate the risks.
Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) - Whilst analysing the patch for CVE-2021-30833, an additional vulnerability was identified which could allow for arbitrary file-write when unpacking a malicious XAR archive using the xar utility.
https://ift.tt/VY1CUbD
Submitted March 16, 2022 at 02:26PM by digicat
via reddit https://ift.tt/n80RukT
https://ift.tt/VY1CUbD
Submitted March 16, 2022 at 02:26PM by digicat
via reddit https://ift.tt/n80RukT
NCC Group Research
Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582)
In October 2021, Apple released a fix for CVE-2021-30833. This was an arbitrary file-write vulnerability in the xar utility and was due to improper handling of path separation (forward-slash) characters when processing files contained within directory symlinks.…