Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ Vulnerability Spotlight: How an attacker could chain several vulnerabilities in an industrial wireless router to gain root access

InHand Networks’ InRouter302 that could allow an attacker to escalate their privileges on the targeted device from a non-privileged user to a privileged one:

https://blog.talosintelligence.com/2022/05/blog-post-.html
/ Interactive Phishing: Using Chatbot-like Web Applications to Harvest Information

https://www.trustwave.com/media/18693/capture3.png
/ CVE-2022-1729: race condition in Linux perf subsystem leads to local privilege escalation

https://www.openwall.com/lists/oss-security/2022/05/20/2
/ Note: BLD DNS server 135.125.204.230 set to maintenance mode up to ~10 minutes

up: done
/ New Research Paper: Pre-hijacking Attacks on Web User Accounts

https://msrc-blog.microsoft.com/2022/05/23/pre-hijacking-attacks/
/ New Linux-Based Ransomware Cheerscrypt Targets ESXi Devices

Cheerscrypt, a new ransomware family, that has been targeting a customer’s ESXi server used to manage VMware files.

In the past, ESXi servers were also attacked by other known ransomware families such as LockBit, Hive, and RansomEXX as an efficient way to infect many computers with ransomware

- Link to PoC article