Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
ProtonVPN Windows client BSOD reports

https://protonstatus.com/incidents/124
Heap-based buffer overflow in Sudo (CVE-2021-3156)

This vulnerability:

- is exploitable by any local user (normal users and system users,
sudoers and non-sudoers), without authentication (i.e., the attacker
does not need to know the user's password);


https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Security Bulletin: NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB - January 2021

The update addresses security issues that may lead to denial of service, data loss, and information disclosure

https://nvidia.custhelp.com/app/answers/detail/a_id/5147
The ESXi ransomware post-mortem

https://www.reddit.com/r/sysadmin/comments/kysqsc/the_esxi_ransomware_postmortem/

Ссылка не моя, за что отдельное спасибо подписчику ✌️
New campaign targeting security researchers

Кампания, нацеленная на исследователей безопасности.

Тот случай, когда сам security research'ер становится объектом исследования. В помощь приходит социальная инженерия, соц. сети, фейковые эксплоиты...

https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/

Спасибо за ссылку на интересное исследование Sabyrzhan T. (@novitoll)
Security Researcher in Spectre Security Group
Fuji Electric Tellus Lite V-Simulator and V-Server Lite

Vulnerabilities: Stack-based Buffer Overflow, Out-of-Bounds Read, Out-of-Bounds Write, Access of Uninitialized Pointer, Heap-based Buffer Overflow

ICS Advisory (ICSA-21-026-01):

https://us-cert.cisa.gov/ics/advisories/icsa-21-026-01